# Changelog ## 0.9.0 - 2026-08-21 - Add reviewed, agent-callable `ssh_connect` for explicitly imported hosts. - Remove the user-side `/ssh` command, `--ssh` startup flag, session-resume reconnect, and remote user-`!` override. - Route connection authorization through the existing `pi-permission-system` and AutoReview chain with a non-secret target preview. - Disconnect active transports at session shutdown and require an explicit reviewed connection in each session. ## 0.8.0 - 2026-08-20 - Replace the OpenSSH subprocess, ControlMaster, and persistent PTY implementation with a pure `ssh2` transport. - Add password, keyboard-interactive, private-key, and encrypted-private-key authentication. - Add selective `ssh -G` host import through the root `ssh_config.sh` helper. - Add an AES-256-GCM host vault with an adjacent owner-only random key. - Pin and verify SHA256 SSH host-key fingerprints. - Move remote file operations to SFTP and keep dedicated collision-free `ssh_*` tools. - Restrict runtime connections to explicitly imported host IDs and reject ProxyJump/ProxyCommand in this release. - Remove automatic remote project instruction discovery and preserve the existing permission-system/auto-review integration. - Add reviewed `ssh_find` and `ssh_grep` tools with bounded `fd`/Git/POSIX fallback pipelines and no remote installation. - Route `ssh_bash` output through RTK's Bash compaction alias while leaving remote command rewriting and structured search/read output disabled. - Preserve adaptive-search backend exit status through bounded pipelines, treating genuine no-match results as success while surfacing invalid regexes, missing roots, and backend failures. - Add regression coverage for private-key/passphrase and keyboard-interactive authentication, pinned-key probing, SFTP reads/access/writes/rename fallback, image detection, aborts, timeouts, and disconnect fail-closed behavior.