ssh-mcp refuses to start if its config is group/world readable (mode & 0o077 → throws, requiring dir 0700 / file 0600). A GUI user has no idea what chmod 600 means — they get a dead server. Generalise: any config file that carries credentials should be permission-checked.
What
Check the mode of a server's credential-bearing config/sidecar.
Pure-core mode check + fix helper (skip/degrade gracefully on Windows where POSIX modes don't apply), unit-tested (fixture: config at 0644 → block + explain + offer fix). Minimal GUI surface. Depends on ServerSpec/sidecar paths (#91) to know which file to check.
Part of the ssh-mcp field-notes epic.
## Why (P1 — validation)
`ssh-mcp` refuses to start if its config is group/world readable (`mode & 0o077` → throws, requiring dir `0700` / file `0600`). A GUI user has no idea what `chmod 600` means — they get a dead server. Generalise: **any** config file that carries credentials should be permission-checked.
## What
- Check the mode of a server's credential-bearing config/sidecar.
- Explain in plain language what's wrong.
- Offer a one-click "fix permissions" button (chmod 600 file / 700 dir).
## Acceptance
Pure-core mode check + fix helper (skip/degrade gracefully on Windows where POSIX modes don't apply), unit-tested (fixture: config at 0644 → block + explain + offer fix). Minimal GUI surface. Depends on ServerSpec/sidecar paths (#91) to know which file to check.
Part of the ssh-mcp field-notes epic.
the_og
added the P1 label 2026-08-12 02:34:28 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Why (P1 — validation)
ssh-mcprefuses to start if its config is group/world readable (mode & 0o077→ throws, requiring dir0700/ file0600). A GUI user has no idea whatchmod 600means — they get a dead server. Generalise: any config file that carries credentials should be permission-checked.What
Acceptance
Pure-core mode check + fix helper (skip/degrade gracefully on Windows where POSIX modes don't apply), unit-tested (fixture: config at 0644 → block + explain + offer fix). Minimal GUI surface. Depends on ServerSpec/sidecar paths (#91) to know which file to check.
Part of the ssh-mcp field-notes epic.