Reject option-like SSH destinations and terminate ssh options
Commit

sshInvocationArgs built ssh -o BatchMode=yes [-p port] <destination> <command>
with no -- separator and no validation of the destination, which comes
straight from the URL. A URL like ssh://-oProxyCommand=evil/repo made ssh
parse the destination as an option — ProxyCommand means arbitrary local command
execution (git's CVE-2017-1000117 class).
Reject any host, username, or port that begins with - (the portable primary
guard, matching git's own fix), and insert -- before the destination as
defense in depth so options can never run past it. Update the ssh test shim to
skip the new -- so the invocation assertions are unchanged, and add coverage
for both the rejection and the -- placement.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 191ffd473fdb