github-advanced-security[bot] commented on code in PR #74211:
URL: https://github.com/apache/airflow/pull/74211#discussion_r4181078169


##########
providers/ssh/tests/unit/ssh/hooks/test_ssh.py:
##########
@@ -103,6 +108,84 @@
 TEST_CIPHERS = ["aes128-ctr", "aes192-ctr", "aes256-ctr"]
 
 
+class _ExecServer(paramiko.ServerInterface):
+    """Answers every exec request with stdout, stderr and exit status 3, then 
closes the channel."""
+
+    def get_allowed_auths(self, username):
+        return "password"
+
+    def check_auth_password(self, username, password):
+        return paramiko.AUTH_SUCCESSFUL
+
+    def check_channel_request(self, kind, chanid):
+        return paramiko.OPEN_SUCCEEDED
+
+    def check_channel_exec_request(self, channel, command):
+        def respond():
+            # Give the client time to see the exec request succeed before the 
channel closes.
+            threading.Event().wait(0.2)
+            channel.sendall(b"out-1\n")
+            channel.sendall_stderr(b"err-1\n")
+            channel.sendall(b"out-2\n")
+            channel.send_exit_status(3)
+            channel.close()
+
+        threading.Thread(target=respond, daemon=True).start()
+        return True
+
+
[email protected]
+def in_process_ssh_client():
+    """Yield an SSH client connected to an in-process paramiko server over a 
loopback socket."""
+    listener = socket.socket()
+    listener.bind(("127.0.0.1", 0))
+    listener.listen(1)
+    transports = []
+
+    def serve():
+        sock, _ = listener.accept()
+        transport = paramiko.Transport(sock)
+        transport.add_server_key(paramiko.RSAKey.generate(2048))
+        transport.start_server(server=_ExecServer())
+        transports.append(transport)
+
+    server_thread = threading.Thread(target=serve, daemon=True)
+    server_thread.start()
+    client = paramiko.SSHClient()
+    client.set_missing_host_key_policy(paramiko.AutoAddPolicy())

Review Comment:
   ## CodeQL / Accepting unknown SSH host keys when using Paramiko
   
   Setting missing host key policy to AutoAddPolicy may be unsafe.
   
   [Show more 
details](https://github.com/apache/airflow/security/code-scanning/675)



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to