Closing a stale SSH connection
davidisaksson.dev
davidisaksson.dev
> (Note that escapes are only recognized immediately after newline.)
This means that it is easy to pick up a habit to smash the enter-button a few times before doing this dance, and as noted on a nordic layout it can be a bit tricky and since you might seldom do it you might do it a few times.
Problem can be that sometimes the connection is only broken one way, what you are typing goes to the server but the responses don't. So you might end up wreaking some kind of havoc on the remote server when you just want to kill the session. Maybe you had a half-written command. Maybe you had just done an up-arrow to get to the previous command, maybe you redid that up-arrow one or more times before you realized that the connection was broken. If you press enter now you will re-run one of your previous commands. Could be quite scary.
To save you from some of that, you could do a ctrl+c which will clear your current line, before pressing enter. But whether that is a good idea depends on the context...
The most apparent issue this has been for me is if on the remote you have IRC or something and you type a bunch of garbage to whatever channel you are on. No biggie, but the old restart the terminal isn't too bad either.
Incidentally, while testing on Windows (in both WSL and cmd.exe) with a Finnish layout: you do not need a space after typing out the tilde.
A US ANSI keyboard has all programming symbols in the right place. Yet it makes Latin/Nordic and other symbols easy to type via compose key (e.g. Right Alt), or similar.
For example, Compose a + ' = á, a + e = æ, o + / = ø, s + s = ß, s + o = §, etc.
An annoying issue is that most brands won't sell ANSI keyboards abroad. Apple is one of the few that get this right. A trick is to import from countries where ANSI is the default, such as NL.
I am able to write 120 words per minute, not so special, but good enough for me. I find the ansi/qwerty too slow with its compose system (I tried on the canadian-intl layout made for Québec).
My point was that ANSI is more ergonomic than ISO for programming, and all local characters are still easy to type.
Personally I always found that ^] for various terminal commands was much more of a hassle, to the point where it's easier to just close the terminal window.
Some Danes will just use a US keyboard layout, but that's not really as common as sites like HN will have you believe. In terms of programming it does make a little sense though. The 8 and 9 key is doing a lot of heavy lifting, Shift + 8 is (, Option + 8 is [ and Shift + Option + 8 is { and the matching close characters on 9.
There's not a lot of room for special characters on a Nordic keyboard, all most all of the require a modifier key. I don't know if that makes Nordic keyboard users more adverse to the use of these characters in commands and programming languages.
Yeah, tell me ’bout it. Back when I used Windows at work, a friend told me that instead of Ctrl ] one should press Ctrl ¨ – because on a regular Swedish keyboard, ¨ is on the same location that has ] on a US keyboard. (Not sure if this works with Linux/Mac, never tried there.)
So nowadays I only use `~` when I'm navigating in an interactive shell session, and never in commands or config files.
I had to switch over 25 years ago when moving. I just considered it a minor inconvenience. I don't think my programming output really suffers, there are so many other factors. Some (very few) people (native or foreigners) do use different keyboards for that reason. I have not noted that they would be better or faster programmers for that. I would claim the correlation between programming fast and introducing more bugs is much clearer.
As for the dead key, pressing tilde space is not the optimal solution. Especially if you are using ssh over ssh. That means you need to produce 2 tilde characters to control the inner ssh. I prefer pressing tilde tilde. With nested ssh that makes 4 tilde characters. Much easier to type than tilde space because you just hold the AltGr key during all for 4 key presses.
Many network engineers who have to deal with asynchronous routing have had to deal with this particular issue. You got into the habit of doing a ctrl+u ctrl+k just in case, and you get hyper-aware that pressing the enter key has consequences.
("control up-arrow Q" song playing in the background.)
[0] https://sshmenu.sourceforge.net/articles/transparent-mulitho...
Bonus points to anyone who can find one and get it to work. I want one, but it's a huge investment (both in price and effort)
Edit: Found this https://zork.net/~st/jottings/Real-VT102-emulation-with-MAME...
http://www.bitsavers.org/pdf/dec/terminal/
https://github.com/larsbrinkhoff/terminal-simulator/issues/1
https://www.mail-archive.com/simh@trailing-edge.com/msg09086...
https://forums.bannister.org/ubbthreads.php?ubb=showflat&Num...
https://simh.trailing-edge.narkive.com/qgzCvrl8/dec-vt-emula...
The command that I ended up using was:
mame -rp . vt240 -window -nothrottle -host null_modem -bitb socket.foo.com:23What users do nowadays is rely on alternatives such as https://tldr.inbrowser.app/
[0]: https://mosh.org/
SSH uses TCP and if the session is gone it will be an invalid session in iptables/nftables and likely have timed out on the remote end depending on state table timeouts and how long your laptop were offline. If there were no firewall in the path then one could play with long SO_KEEPALIVE sessions which I have done in the past when rebooting datacenter-wide diskless NFS clients and NAS's but I dont believe this will work with SSH due to session keys. As you alluded to, Mosh is the best current way to deal with broken or roaming sessions as Mosh uses a nonce and is designed to be stateless.
If the sshd and ssh client timeouts are high enough, a UDP VPN can at times work around intermittent timeouts.
should be "alluded to"; eluded: evaded / dodged, vs alluded to: mentioned / referred to
NOT being pedantic about spelling, just trying to be helpful (esp. for non-native English readers).
The Hayes modem protocol specifies that a significant pause must be inserted after "+++" for it to have signaling effect.
https://en.wikipedia.org/wiki/Hayes_AT_command_set#Hayes'_so...
It’s so annoying that the connection is lost when going to sleep or network issues. And the solutions to fix this are not really worth the effort.
The cryptography is standard AES-128 in OCB3 mode. It's been around long enough, and has had enough security scrutiny to at least discover a few minor DoS vulnerabilities, that it isn't entirely unreviewed.
For the cipher itself, see https://en.wikipedia.org/wiki/OCB_mode#Attacks
Mosh has been effectively unmaintained since long before QUIC even existed. It should be rewritten to use QUIC, except that QUIC's requirement for TLS certificates rather than generic asymmetric cryptography basically breaks any integrations like this.
And as a side-benefit, if your SSH daemon only listens on the WireGuard interface, that's another layer of defense you get for free (not to mention you'll stop getting noise in your logs).
Ironically though, here you actually need to know about `<Enter>~.` because if the remote host actually goes down, WG will keep trying to contact the remote peer for some time; this is the same behavior that allows you to keep a connection open even when roaming, but seen from the other side.
Use case is bouncing through to an RDS that only allows access from specific EC2 instances. The RDS endpoint in question is highly specific to the EC2 - not a big deal to hit ~L and create the forward manually, but doing this automatically would be great.
Most debug/config is done via sqlcl which is straight forward as that's run from the ec2 and so has access to the DB, but sometimes I need to fall back to eg TOAD or sqldeveloper which require the forward to be setup - either adhoc via ~L or -L or via .ssh/config
Each ec2 knows it's RDS end point and I have an extracted list which I use to generate a list of .ssh/config entries periodically to automatically set up the forwards, but just being able to run a command from the ec2s that translates to eg:
~L > 1521:<extracted rds endpoint from app config:1521
would make my life marginally easier
I think you would have to do something like have the script on the remote ec2 instance emit some pattern that you configure your local terminal emulator to watch for and then somehow tell your terminal to emit the ~L sequence of keystrokes.
iterm2 can do this kind of thing, see https://iterm2.com/triggers.html .
For clarification regarding what I mean with menu and output will not display the disconnect command will still work but there will be no feedback. So disconnecting will work but one won't get the menu or feedback on changing verbosity or dropping to a command line or displaying forwarded connections, etc... and a few of the sub-commands will not work.
[1] - https://superuser.com/questions/985437/ssh-escape-key-only-w...
For example, running `systemctl suspend` will not terminate active SSH connections before putting the destination machine into a sleep state, and thus Ctrl+C (which isn't processed by SSH) will do nothing until the remote host is woken up by some mechanism.
Otherwise how could you send a control-C without any special guard sequence while ssh-ing?