Close the ssh askpass helper before ssh executes it - #73427
Open
MichalJaroslawKrzywanski-TomTom wants to merge 5 commits into
Open
MichalJaroslawKrzywanski-TomTom wants to merge 5 commits into
MichalJaroslawKrzywanski-TomTom wants to merge 5 commits into
Conversation
|
Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
|
MalgorzataDrygala-TomTom
approved these changes
Sep 21, 2026
GitHook writes the SSH_ASKPASS helper that unlocks a passphrase-protected private key with NamedTemporaryFile(delete=True) and keeps the handle open for writing while ssh runs. Linux refuses to exec a file that is still open for writing (ETXTBSY, "Text file busy"), so a clone or fetch with a passphrase-protected key fails with "cannot exec ...: Text file busy" and then falls back to prompting for the passphrase. macOS does not enforce this, which hid the bug. Write the helper through a small module-level context manager that closes the file before yielding its path and unlinks it in finally. The added test runs the helper through configure_hook_env and asserts its output; on Linux it fails without the fix with "OSError: [Errno 26] Text file busy". The token path hit the same constraint. apache#64105 fixed it there by replacing GIT_ASKPASS with a credential helper written and closed before git runs, which is why this change is now limited to SSH_ASKPASS. related: apache#73425 related: apache#64105 Co-Authored-By: krzywans <MichalJaroslaw.Krzywanski@tomtom.com> Co-Authored-By: Claude <noreply@anthropic.com>
MichalJaroslawKrzywanski-TomTom
force-pushed
the
fix-git-askpass-etxtbsy
branch
from
September 22, 2026 03:18
749ea2f to
2f1cce1
Compare
2 tasks
Contributor
|
@MichalJaroslawKrzywanski-TomTom Please do not merge from |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GitHookwrites theSSH_ASKPASShelper that unlocks a passphrase-protected private key withNamedTemporaryFile(delete=True)and keeps the handle open for writing while ssh runs. Linux refuses to exec a file that is still open for writing (ETXTBSY, "Text file busy"), so a clone or fetch with a passphrase-protected key fails withcannot exec '/tmp/tmpXXXX.sh': Text file busyand then falls back to prompting for the passphrase. macOS does not enforce this, which hid the bug.The fix writes the helper through a small module-level context manager (
_executable_script) that closes the file before yielding its path and unlinks it infinally.Scope changed after a rebase on main
This PR originally fixed the same bug on both askpass paths. #64105 has since replaced
GIT_ASKPASSwith a credential helper that is written and closed before git runs, which fixes the token path upstream, so onlySSH_ASKPASSis left to fix here. The test that exercised the old GitHub App askpass script is dropped with the mechanism it tested; #64105's own tests cover the credential helper.That also means #73425, which reported the failure on the GitHub App path, is already fixed on main by #64105 rather than by this PR — hence
related:instead ofcloses:.Verification
Run in
apache/airflow:3.2.2-python3.10(Debian 12, git 2.39.5) against the rebased branch:With
main's unpatched hook, the added test fails there:ruff checkandruff format --checkare clean on both changed files.related: #73425
related: #64105
Was generative AI tooling used to co-author this PR?
Generated-by: Claude Code following the guidelines. The diagnosis, the fix, the tests and the rebase resolution were reviewed by hand; the ETXTBSY reproduction and the test runs above were executed by me.