From: AdrianF <adrian.freihofer@siemens.com>
To: openembedded-core@lists.openembedded.org
Cc: Adrian Freihofer <adrian.freihofer@siemens.com>
Subject: [PATCH v2 09/25] devtool: ide-sdk: auto-disable ssh host key checking for loopback targets
Date: Sun, 30 Aug 2026 23:48:31 +0200 [thread overview]
Message-ID: <20260830214912.1346063-10-adrian.freihofer@siemens.com> (raw)
In-Reply-To: <20260830214912.1346063-1-adrian.freihofer@siemens.com>
From: Adrian Freihofer <adrian.freihofer@siemens.com>
QEMU instances reached via slirp/hostfwd (e.g. root@localhost) get a new
ephemeral ssh host key on every boot, so StrictHostKeyChecking would
fail on the second and later runs unless --no-host-check is passed
explicitly. Detect loopback targets (localhost, 127.0.0.1, ::1) and
disable host key checking automatically, both in TargetDevice and in
the generated do_install-through-bitbake script that re-parses the
target args on the build host.
Signed-off-by: Adrian Freihofer <adrian.freihofer@siemens.com>
---
scripts/lib/devtool/ide_sdk.py | 50 ++++++++++++++++++++++++++--------
1 file changed, 38 insertions(+), 12 deletions(-)
diff --git a/scripts/lib/devtool/ide_sdk.py b/scripts/lib/devtool/ide_sdk.py
index 719648a3eb..e45752aff1 100755
--- a/scripts/lib/devtool/ide_sdk.py
+++ b/scripts/lib/devtool/ide_sdk.py
@@ -45,22 +45,24 @@ class DevtoolIdeMode(Enum):
shared = 'shared'
+# Hosts a ssh target is considered to loop back to the local machine, e.g. a
+# QEMU instance reached through slirp/hostfwd port forwarding (root@localhost)
+# which has an ephemeral ssh host key that changes on every boot.
+LOOPBACK_HOSTS = ('localhost', '127.0.0.1', '::1')
+
+
+def target_host(target):
+ return target.split('@')[-1]
+
+
+def is_loopback_target(target):
+ return target_host(target) in LOOPBACK_HOSTS
+
+
class TargetDevice:
"""SSH remote login parameters"""
def __init__(self, args):
- self.extraoptions = []
- if args.no_host_check:
- self.extraoptions += ['-o', 'UserKnownHostsFile=/dev/null', '-o', 'StrictHostKeyChecking=no']
- self.ssh_sshexec = 'ssh'
- if args.ssh_exec:
- self.ssh_sshexec = args.ssh_exec
- self.ssh_port = []
- if args.port:
- self.ssh_port = ['-p', args.port]
- if args.key:
- self.extraoptions += ['-i', args.key]
-
self.target = args.target
target_sp = args.target.split('@')
if len(target_sp) == 1:
@@ -72,6 +74,25 @@ class TargetDevice:
else:
logger.error("Invalid target argument: %s" % args.target)
+ no_host_check = args.no_host_check
+ if not no_host_check and is_loopback_target(args.target):
+ logger.debug(
+ "Target %s is a loopback address, disabling ssh host key checking "
+ "(assuming a QEMU instance with an ephemeral host key)." % args.target)
+ no_host_check = True
+
+ self.extraoptions = []
+ if no_host_check:
+ self.extraoptions += ['-o', 'UserKnownHostsFile=/dev/null', '-o', 'StrictHostKeyChecking=no']
+ self.ssh_sshexec = 'ssh'
+ if args.ssh_exec:
+ self.ssh_sshexec = args.ssh_exec
+ self.ssh_port = []
+ if args.port:
+ self.ssh_port = ['-p', args.port]
+ if args.key:
+ self.extraoptions += ['-i', args.key]
+
class RecipeNative:
"""Base class for calling bitbake to provide a -native recipe"""
@@ -1324,6 +1345,8 @@ class RecipeModified:
'no_preserve', 'port', 'show_status', 'ssh_exec', 'strip', 'target']
filtered_args_dict = {key: value for key, value in vars(
args).items() if key in args_filter}
+ if is_loopback_target(filtered_args_dict['target']):
+ filtered_args_dict['no_host_check'] = True
cmd_lines.append('filtered_args_dict = %s' % str(filtered_args_dict))
cmd_lines.append('class Dict2Class(object):')
cmd_lines.append(' def __init__(self, my_dict):')
@@ -1340,6 +1363,9 @@ class RecipeModified:
cmd_lines.append(' i += 2')
cmd_lines.append(' else:')
cmd_lines.append(' i += 1')
+ cmd_lines.append(
+ "if filtered_args.target.split('@')[-1] in %s:" % str(LOOPBACK_HOSTS))
+ cmd_lines.append(' filtered_args.no_host_check = True')
cmd_lines.append(
'setattr(filtered_args, "recipename", "%s")' % self.bpn)
cmd_lines.append('deploy_no_d("%s", "%s", "%s", "%s", "%s", "%s", %d, "%s", "%s", filtered_args)' %
--
2.55.0
next prev parent reply other threads:[~2026-08-30 21:49 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-30 21:48 [PATCH v2 00/25] devtool: ide-sdk: NFS/slirp support, deploy filtering, and robustness fixes AdrianF
2026-08-30 21:48 ` [PATCH v2 01/25] runqemu-extract-sdk: set PSEUDO_INCLUDE_PATHS for the extraction AdrianF
2026-08-30 21:48 ` [PATCH v2 02/25] devtool: ide-sdk: dedupe solib_search_path entries AdrianF
2026-09-03 11:18 ` [OE-core] " Richard Purdie
2026-09-03 16:06 ` Freihofer, Adrian
2026-09-03 20:21 ` Richard Purdie
2026-08-30 21:48 ` [PATCH v2 03/25] devtool: ide-sdk: VSCode IntelliSense for rootfs-dbg sources AdrianF
2026-08-30 21:48 ` [PATCH v2 04/25] cpp-example: fix stuck breakpoints when attaching and daemonize properly AdrianF
2026-08-30 21:48 ` [PATCH v2 05/25] devtool: ide-sdk: auto-write image debug settings to bbappend AdrianF
2026-08-30 21:48 ` [PATCH v2 06/25] oe-selftest: devtool ide-sdk: adapt tests for auto-written image debug settings AdrianF
2026-08-30 21:48 ` [PATCH v2 07/25] oeqa: QemuTarget: set use_slirp when slirp is in runqemuparams AdrianF
2026-08-30 21:48 ` [PATCH v2 08/25] devtool: ide-sdk: support runqemu slirp AdrianF
2026-08-30 21:48 ` AdrianF [this message]
2026-08-30 21:48 ` [PATCH v2 10/25] oe-selftest: devtool ide-sdk: add slirp networking test AdrianF
2026-08-30 21:48 ` [PATCH v2 11/25] devtool: deploy-target: add --package/--file-glob filters AdrianF
2026-08-30 22:11 ` Patchtest results for " patchtest
2026-08-30 21:48 ` [PATCH v2 12/25] oe-selftest: devtool deploy-target: test " AdrianF
2026-08-30 21:48 ` [PATCH v2 13/25] devtool: ide-sdk: forward --package/--file-glob deploy filters AdrianF
2026-08-30 21:48 ` [PATCH v2 14/25] oe-selftest: devtool ide-sdk: cover --package filters AdrianF
2026-08-30 21:48 ` [PATCH v2 15/25] runqemu-extract-sdk: refactor in Python AdrianF
2026-09-03 11:36 ` [OE-core] " Richard Purdie
2026-08-30 21:48 ` [PATCH v2 16/25] runqemu-export-rootfs: " AdrianF
2026-08-30 21:48 ` [PATCH v2 17/25] devtool: deploy: split ssh deployment into a separate function AdrianF
2026-08-30 21:48 ` [PATCH v2 18/25] devtool: deploy-target: allow deploying directly into a local rootfs AdrianF
2026-08-30 21:48 ` [PATCH v2 19/25] oe-selftest: devtool deploy-target: test deploying into a local rootfs path AdrianF
2026-08-30 21:48 ` [PATCH v2 20/25] oe-selftest: tinfoil: test prepared task runner AdrianF
2026-08-30 21:48 ` [PATCH v2 21/25] devtool: ide-sdk: run do_install through BitBake AdrianF
2026-08-30 21:48 ` [PATCH v2 22/25] oe-selftest: devtool ide-sdk: test install task AdrianF
2026-08-30 21:48 ` [PATCH v2 23/25] devtool: ide-sdk: support NFS rootfs AdrianF
2026-08-30 21:48 ` [PATCH v2 24/25] oe-selftest: devtool ide-sdk: test NFS debug rootfs AdrianF
2026-08-30 21:48 ` [PATCH v2 25/25] devtool: ide-sdk: fix GDB loading stale libs instead of recipe's own build AdrianF
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260830214912.1346063-10-adrian.freihofer@siemens.com \
--to=adrian.freihofer@siemens.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox