You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Jumphost连接SSH主机时遇PTY allocation失败错误求助

SSH跳板机连接目标主机时PTY分配失败问题排查

通过跳板机SSH连接目标主机myHost,身份验证已通过,但出现错误PTY allocation request failed on channel 0,会话随即关闭。直接从跳板机连接该目标主机可正常运行。

当前.ssh/config配置

Host jumphost
    Port 2352
    Hostname <jumphost_IPADDRESS>
    User myUsername

Host myHost
    User myUsername
    Hostname <IPADDRESS>
    ProxyCommand ssh -W %h:%p jumphost

SSH会话调试日志

❯ ssh -v myHost
OpenSSH_9.1p1, OpenSSL 3.0.6 11 Oct 2022
debug1: Reading configuration data /Users/myUsername/.ssh/config
debug1: /Users/myUsername/.ssh/config line 37: Applying options for myHost
debug1: Reading configuration data /Users/myUsername/.fig/ssh
debug1: Executing command: 'command -v fig && fig _ generate-ssh myUsername'
debug1: Reading configuration data /Users/myUsername/.fig/ssh_inner
debug1: Reading configuration data /opt/local/etc/ssh/ssh_config
debug1: /opt/local/etc/ssh/ssh_config line 20: Applying options for *
debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling
debug1: Executing proxy command: exec ssh -W <IPADDRESS>:22 jumphost
debug1: identity file /Users/myUsername/.ssh/id_rsa type 0
debug1: identity file /Users/myUsername/.ssh/id_rsa-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_ecdsa type -1
debug1: identity file /Users/myUsername/.ssh/id_ecdsa-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_ecdsa_sk type -1
debug1: identity file /Users/myUsername/.ssh/id_ecdsa_sk-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_ed25519 type -1
debug1: identity file /Users/myUsername/.ssh/id_ed25519-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_ed25519_sk type -1
debug1: identity file /Users/myUsername/.ssh/id_ed25519_sk-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_xmss type -1
debug1: identity file /Users/myUsername/.ssh/id_xmss-cert type -1
debug1: identity file /Users/myUsername/.ssh/id_dsa type -1
debug1: identity file /Users/myUsername/.ssh/id_dsa-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_9.1
myUsername@jumphost's password:
debug1: Remote protocol version 2.0, remote software version SSH
debug1: compat_banner: no match: SSH
debug1: Authenticating to <IPADDRESS>:22 as 'myUsername'
debug1: load_hostkeys: fopen /Users/myUsername/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: diffie-hellman-group-exchange-sha256
debug1: kex: host key algorithm: rsa-sha2-512
debug1: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256 compression: none
debug1: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256 compression: none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(2048<8192<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_GROUP received
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: SSH2_MSG_KEX_DH_GEX_REPLY received
debug1: Server host key: ssh-rsa SHA256:pmnt0weWX0MB2jaD6F+YfUo3kGcwGM2sRJV2TypHTW0
debug1: load_hostkeys: fopen /Users/myUsername/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host '<IPADDRESS>' is known and matches the RSA host key.
debug1: Found key in /Users/myUsername/.ssh/known_hosts:30
debug1: rekey out after 4294967296 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 4294967296 blocks
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: ssh_fetch_identitylist: agent contains no identities
debug1: Will attempt key: /Users/myUsername/.ssh/id_rsa RSA SHA256:9M18alruYmtIxO1EHnQihCPW9G+oBFcOBlRyfJhE4uc
debug1: Will attempt key: /Users/myUsername/.ssh/id_ecdsa
debug1: Will attempt key: /Users/myUsername/.ssh/id_ecdsa_sk
debug1: Will attempt key: /Users/myUsername/.ssh/id_ed25519
debug1: Will attempt key: /Users/myUsername/.ssh/id_ed25519_sk
debug1: Will attempt key: /Users/myUsername/.ssh/id_xmss
debug1: Will attempt key: /Users/myUsername/.ssh/id_dsa
debug1: SSH2_MSG_SERVICE_ACCEPT received
***********************       WARNING      **************************
You must have prior authorization to access this system. All
connections are logged and monitored.By connecting to this system you
fully consent to all monitoring. Unauthorized access or use will be
prosecuted to the  full extent of the law. You have been warned.

*************************************************************************
debug1: Authentications that can continue: password
debug1: Next authentication method: password
myUsername@<IPADDRESS>'s password:
Authenticated to <IPADDRESS> (via proxy) using "password".
debug1: channel 0: new [client-session]
debug1: Entering interactive session.
debug1: pledge: filesystem
debug1: Sending environment.
debug1: channel 0: setting env LC_FIG_SET_PARENT = "90039a7f-7428-4791-8a24-1e5aeac56fec"
debug1: channel 0: setting env LC_CTYPE = "UTF-8"
PTY allocation request failed on channel 0
debug1: channel 0: free: client-session, nchannels 1
Connection to <IPADDRESS> closed.
Transferred: sent 3400, received 4040 bytes, in 0.7 seconds
Bytes per second: sent 4975.8, received 5912.4
debug1: Exit status -1

排查方案

1. 禁用Fig环境变量干扰

从日志可见,连接时自动注入了LC_FIG_SET_PARENT环境变量,这是Fig工具生成的,可能导致目标主机PTY分配异常。

  • 临时测试:执行命令时跳过环境变量发送
    ssh -v -o SendEnv="" myHost
    
  • 永久配置:在.ssh/config的myHost块中添加
    SendEnv ""
    

2. 强制分配PTY

尝试强制要求分配终端,绕过可能的配置限制:

  • 临时测试:
    ssh -v -t myHost
    
  • 永久配置:在.ssh/config的myHost块中添加
    RequestTTY force
    

3. 调整OpenSSH兼容性设置

本地使用OpenSSH 9.1,目标主机SSH版本未明确显示,可能存在算法兼容性问题。在.ssh/config的myHost块中添加:

KexAlgorithms +diffie-hellman-group-exchange-sha256

内容的提问来源于stack exchange,提问作者Tony Frbezar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 05:25:07