From 627c6a1a144ae59c2be0746ca513518b0313deb1 Mon Sep 17 00:00:00 2001 From: Randall Winkhart Date: Wed, 14 Dec 2022 02:40:13 -0500 Subject: [PATCH] Update documentation for release v1.3.0 Former-commit-id: ac89c761d964360d80863c926f908d937ed00865 [formerly 697f7a870d85611610e5bd23ff7f752d908887c7] Former-commit-id: fde0008b65ef6135476a448dd1cc768a7e511cb8 --- README.md | 8 ++--- extra/changelog-total | 48 ++++++++++++++++++++++++++ extra/manpage | 2 +- lib/sshyp.py | 10 +++--- share/doc/sshyp/changelog | 71 ++++++++++++++++++--------------------- 5 files changed, 89 insertions(+), 50 deletions(-) diff --git a/README.md b/README.md index 4b7d49e..225fbbb 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,5 @@ ![sshyp](https://github.com/rwinkhart/sshyp-labs/blob/main/extra/artwork/sshyp-banner.png) - -[![CodeQL](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml/badge.svg?branch=main)](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml) +![release](https://img.shields.io/github/v/release/rwinkhart/sshyp)![python](https://img.shields.io/badge/python-3.7--3.11-yellow)![downloads](https://img.shields.io/github/downloads/rwinkhart/sshyp/total)[![CodeQL](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml/badge.svg?branch=main)](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml) pronounced as: 'sheep', 'shēp' @@ -91,9 +90,8 @@ man sshyp # Roadmap Short-term Goals: -- create minimal GUI app (Linux x86_64, Linux aarch64) - being done as an [extension](https://github.com/rwinkhart/sshyp-labs) -- significant optimizations -- vaious bug fixes +- a minimal GUI app - being made as an [extension](https://github.com/rwinkhart/sshyp-labs) +- improved extension integration (allow extensions to add new arguments) Long-term Goals: diff --git a/extra/changelog-total b/extra/changelog-total index 9756f69..f88bdee 100644 --- a/extra/changelog-total +++ b/extra/changelog-total @@ -1,3 +1,51 @@ +sshyp v1.3.0 + +the serious shepherd update + +this release ties up many of sshyp's loose ends where there was +room for major performance, compatibility, and security improvements + +compatibility-breaking changes: + +- due to a near full re-write of the syncing functionality, all clients and servers +must be updated to this release (v1.3.0 is not backwards compatible with any prior release) +- it is recommended to either delete the contents of ~/.config/sshyp/deleted (on the server-side) +or sync all of your clients before updating + ^ old entries in this folder will throw errors with v1.3.0 + +user-facing features: + +- none - all changes were under-the-hood - the user experience should be +exactly the same as v1.2.0 - just faster, less buggy, and more secure + +major fixes/optimizations: + +- a near full re-write of the syncing functionality + ^ all syncing logic has been moved into sshync.py (from sshyp.py and sshypRemote.py) + ^ in my setup, a dry, local "sshyp sync" went from 2.00+ seconds (v1.2.0) to 0.36 seconds (v1.3.0) + ^ the performance improvements are even greater when syncing from outside your local network +- the following character sequences will no longer break the syncing logic: "@", "^&*", and "*&^" + ^ ASCII separator characters 29-31 are now used, instead +- os.system has been replaced with subprocess.run in all cases, shell=True is no longer used with subprocess.run + ^ this protects against shell escape attacks and potentially makes sshyp more compatible with some environments +- replaced shell commands with python built-in library functions where applicable + ^ this brings speed and compatibility improvements +- sshyp should no longer incorrectly assume an X11 environment when Wayland is in use + ^ this fixes clipboard support in some Wayland environments, such as Sway (Plasma/Gnome/Phosh were unaffected) +- sshyp now uses the default pinentry on Haiku thanks to haikuports/haikuports#7457 + ^ this brings the Haiku port in-line with the other sshyp packages in terms of security +- "python3" is now called over ssh, rather than "python" + ^ some environments do not have a "python" symlink, or it links to "python2" - changing this increases compatibility +- fixed an issue from v1.2.0 where renaming threw an error if not in offline mode + +other notable changes: + +- quick-unlock password input is now hidden while the user is typing + ^ user input is now invisible to prevent snooping +- lots of smaller optimizations not listed here + +<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><> + sshyp v1.2.0 the brisk bahh update diff --git a/extra/manpage b/extra/manpage index 05e0bce..cf4e252 100644 --- a/extra/manpage +++ b/extra/manpage @@ -1,4 +1,4 @@ -.TH sshyp 1 "07 December 2022" "v1.3.0" "sshyp man page" +.TH sshyp 1 "14 December 2022" "v1.3.0" "sshyp man page" .SH NAME sshyp \- A very simple self-hosted, synchronized password manager for UNIX(-like) systems. Alternative to (and compatible with) pass/password-store. .SH SYNOPSIS diff --git a/lib/sshyp.py b/lib/sshyp.py index 604cc6f..aa6111a 100755 --- a/lib/sshyp.py +++ b/lib/sshyp.py @@ -399,9 +399,9 @@ def print_info(): # prints help text based on argument elif argument_list[1] == 'version' or argument_list[1] == '-v': print('\nsshyp is a simple, self-hosted, sftp-synchronized password manager\nfor unix(-like) systems (haiku/' 'freebsd/linux/termux)\n\nsshyp is a viable alternative to (and compatible with) pass/password-store\n') - print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;13m" + print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;10m" "♥♥♥♥♥♥♥\u001b[0m /()\\''.''.\n * : \u001b[38;5;9m♥♥♥♥♥\u001b[0m : *" - "\n `..'..' \u001b[38;5;13m♥♥♥\u001b[0m `..'..'\n // \\\\ " + "\n `..'..' \u001b[38;5;10m♥♥♥\u001b[0m `..'..'\n // \\\\ " "\u001b[38;5;9m♥\u001b[0m // \\\\") print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m') print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m ' @@ -410,10 +410,10 @@ def print_info(): # prints help text based on argument 'randall winkhart\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m') print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m ' '\u001b[38;5;7;48;5;8m/\u001b[0m') - print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.2.0' + print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.3.0' '\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m') - print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe brisk bahh ' - 'update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m') + print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe serious shepherd ' + 'update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m') print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m ' '\u001b[38;5;7;48;5;8m/\u001b[0m') print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m\n') diff --git a/share/doc/sshyp/changelog b/share/doc/sshyp/changelog index be9ab3d..7694d3b 100644 --- a/share/doc/sshyp/changelog +++ b/share/doc/sshyp/changelog @@ -1,55 +1,48 @@ -sshyp v1.2.0 +sshyp v1.3.0 -the brisk bahh update +the serious shepherd update -this release focuses on speeding up the sshyp user experience by adding -new features that reduce wasted time +this release ties up many of sshyp's loose ends where there was +room for major performance, compatibility, and security improvements compatibility-breaking changes: -- new configuration options (quick-unlock, offline mode) have been added and -the configuration files have been reorganized - ^ simply running "sshyp tweak" and following the setup wizard will correct any compatibility - issues -- for quick-unlock security, device names have been replaced with more secure device ids - ^ older device names are still compatible, but for security reasons it is recommended - to delete any pre-existing device names from the server and allow "sshyp tweak" to re-register - your devices +- due to a near full re-write of the syncing functionality, all clients and servers +must be updated to this release (v1.3.0 is not backwards compatible with any prior release) +- it is recommended to either delete the contents of ~/.config/sshyp/deleted (on the server-side) +or sync all of your clients before updating + ^ old entries in this folder will throw errors with v1.3.0 user-facing features: -- quick-unlock mode has been added - ^ this allows you to use a shortened version of your password by verifying that your device - is whitelisted on your sshyp server - it's both faster and more secure than standard unlock, - but it requires an active connection to your sshyp server to authenticate (otherwise it will - fall back to standard unlock) -- full support for offline usage - ^ though sshyp could be used without a server before, it now can be configured to not attempt - to find one ever - this saves time and hides sync failure error messages -- bash completions have been added - ^ if you have bash-completion installed, you can now use the tab key in bash to auto-complete - sshyp arguments and entry names (client only, not added for server-specific arguments) - ^ if you do not have bash-completion installed, you can source - /usr/share/bash-completion/completions/sshyp (Linux/BSD) or - /boot/system/data/bash-completion/completions/sshyp (Haiku) in your ~/.bashrc to - use this feature +- none - all changes were under-the-hood - the user experience should be +exactly the same as v1.2.0 - just faster, less buggy, and more secure -fixes/optimizations: +major fixes/optimizations: -- fixed entries with multi-word titles failing to decrypt -- password generation is now much faster and more resource efficient -- there is no longer a length limit on generated passwords -- improved visual consistency of help menus -- rarely used modules are now imported only when needed -- sshyp now uses one fewer configuration file +- a near full re-write of the syncing functionality + ^ all syncing logic has been moved into sshync.py (from sshyp.py and sshypRemote.py) + ^ in my setup, a dry, local "sshyp sync" went from 2.00+ seconds (v1.2.0) to 0.36 seconds (v1.3.0) + ^ the performance improvements are even greater when syncing from outside your local network +- the following character sequences will no longer break the syncing logic: "@", "^&*", and "*&^" + ^ ASCII separator characters 29-31 are now used, instead +- os.system has been replaced with subprocess.run in all cases, shell=True is no longer used with subprocess.run + ^ this protects against shell escape attacks and potentially makes sshyp more compatible with some environments +- replaced shell commands with python built-in library functions where applicable + ^ this brings speed and compatibility improvements +- sshyp should no longer incorrectly assume an X11 environment when Wayland is in use + ^ this fixes clipboard support in some Wayland environments, such as Sway (Plasma/Gnome/Phosh were unaffected) +- sshyp now uses the default pinentry on Haiku thanks to haikuports/haikuports#7457 + ^ this brings the Haiku port in-line with the other sshyp packages in terms of security +- "python3" is now called over ssh, rather than "python" + ^ some environments do not have a "python" symlink, or it links to "python2" - changing this increases compatibility +- fixed an issue from v1.2.0 where renaming threw an error if not in offline mode other notable changes: -- sshyp is now specifically licensed under the GPL-3.0-only (keyword: only) -- sshyp now has some possible arguments and its own help menu when running in server mode -- temporary files in /dev/shm are now generated with more complex names -- sshyp now installs in /usr/lib/sshyp (Linux/BSD) or /system/lib/sshyp (Haiku) instead of -/usr/bin or /bin (it is still symlinked to the old directories) +- quick-unlock password input is now hidden while the user is typing + ^ user input is now invisible to prevent snooping +- lots of smaller optimizations not listed here <><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>