TRAMP multi-hop connection retry behavior during privilege escalation
0 reputation · 09 Jun 2024, 01:50 UTC
TRAMP Connection Retries and Sudo Boundaries
Emacs TRAMP handles transient failures by automatically retrying operations based on the tramp-retry-connection-attempts setting. In multi-hop configurations, such as /ssh:user@host|sudo:root@host:/path, TRAMP maintains a cached connection to the primary host and a subprocess for the escalated user.
A potential conflict arises when a write operation fails due to a transient network error or a timeout. TRAMP may trigger a retry that re-establishes the sudo session. If the remote sudo configuration has a short timestamp_timeout or requires a TTY, this retry can trigger an unexpected password prompt mid-operation without verifying if the previous write attempt partially succeeded.
Currently, tramp-retry-connection-attempts applies globally to both read and write operations, providing no mechanism to suppress retries specifically for non-idempotent write actions across permission boundaries.
- Is there a configuration to disable automatic retries specifically for write operations while maintaining them for reads?
- How can TRAMP be configured to prevent redundant sudo authentication prompts during a retry sequence?