disabling local-to-local transfers?

Theo de Raadt deraadt at openbsd.org
Sat Jul 25 00:33:50 AEST 2026


Samuel Thibault <samuel.thibault at ens-lyon.org> wrote:

> Hello,
> 
> Are local-to-local "transfers" really a useful feature?
> 
>   scp foo my.server.com
> 
> forgetting to type the trailing ':' creates a "my.server.com" file
> instead of producing an error.
> 
> I have *never* seen this feature useful to me, while I get hit by the
> issue from times to times, and I have to remove the "my.server.com"
> file getting created. Worse, it did cost me a lot of time this morning
> because I didn't notice that the file didn't actually get transferred,
> and thus I used a previous version, which submitted 3 days of work to my
> server...
> 
> Could there at least be an option which we can put in one's default
> config or shell aliases to disable the local-to-local transfer and
> produce an error instead?

No way.  scp(1) is a a derivative of the old CSRG rcp(1) codebase,
and this behaviour has existed for decades, and we have no idea how many
scripts happen to be using this.  We simply don't know, and we cannot
break those scripts.

Additionally, this is clearly documented:

     The source and target may be specified as a local pathname, a remote host
     with optional path in the form [user@]host:[path], or a URI in the form
     scp://[user@]host[:port][/path].  Local file names can be made explicit
     using absolute or relative pathnames to avoid scp treating file names
     containing `:' as host specifiers.

This does not impose a wierd limitation like "either the source or the
target needs to be remote".

Improve your typing skills.


More information about the openssh-unix-dev mailing list