mirror of
https://github.com/ohmyzsh/ohmyzsh.git
synced 2024-12-23 21:01:58 +00:00
a206271460
* ssh-agent: lock this script with a mkdir style mutex This script is a kind of singleton pattern and is not reentrant. If several shells are oppened in a fast sequence, then several independent ssh-agents would be created, which is not acceptable. A mutex is required. Signed-off-by: Nuno Goncalves <nunojpg@gmail.com> * ssh-agent: only start agent if .ssh dir exists To use the same profile system-wide, it might happen that the .ssh directory does not exist (typically $HOME/.ssh/). This would trigger a error. Creating the directory would be a option, but it usually will not make sense to do so because it means the user doesn't have ssh keys or config. Signed-off-by: Nuno Goncalves <nunojpg@gmail.com> * ssh-agent: adds lazy option to disable key loading on start Option is documented on updated README.md Signed-off-by: Nuno Goncalves <nunojpg@gmail.com> * ssh-agent: simplify agent-forwarding checking Signed-off-by: Nuno Goncalves <nunojpg@gmail.com> Co-authored-by: Robby Russell <robby@planetargon.com>
97 lines
2.7 KiB
Bash
97 lines
2.7 KiB
Bash
lockdir=/tmp/oh-my-zsh-ssh-agent.lock
|
|
|
|
while true; do
|
|
if mkdir "$lockdir" 2>/dev/null
|
|
then # directory did not exist, but was created successfully
|
|
trap 'rm -rf "$lockdir"' 0 # remove directory when script finishes
|
|
break # continue with script
|
|
else
|
|
sleep 0.1 # sleep for 0.2 and try again
|
|
fi
|
|
done
|
|
|
|
typeset _ssh_env_cache
|
|
|
|
function _start_agent() {
|
|
local lifetime
|
|
zstyle -s :omz:plugins:ssh-agent lifetime lifetime
|
|
|
|
# start ssh-agent and setup environment
|
|
echo Starting ssh-agent...
|
|
ssh-agent -s ${lifetime:+-t} ${lifetime} | sed 's/^echo/#echo/' >! $_ssh_env_cache
|
|
chmod 600 $_ssh_env_cache
|
|
. $_ssh_env_cache > /dev/null
|
|
}
|
|
|
|
function _add_identities() {
|
|
local id line sig lines
|
|
local -a identities loaded_sigs loaded_ids not_loaded
|
|
zstyle -a :omz:plugins:ssh-agent identities identities
|
|
|
|
# check for .ssh folder presence
|
|
if [[ ! -d $HOME/.ssh ]]; then
|
|
return
|
|
fi
|
|
|
|
# add default keys if no identities were set up via zstyle
|
|
# this is to mimic the call to ssh-add with no identities
|
|
if [[ ${#identities} -eq 0 ]]; then
|
|
# key list found on `ssh-add` man page's DESCRIPTION section
|
|
for id in id_rsa id_dsa id_ecdsa id_ed25519 identity; do
|
|
# check if file exists
|
|
[[ -f "$HOME/.ssh/$id" ]] && identities+=$id
|
|
done
|
|
fi
|
|
|
|
# get list of loaded identities' signatures and filenames
|
|
if lines=$(ssh-add -l); then
|
|
for line in ${(f)lines}; do
|
|
loaded_sigs+=${${(z)line}[2]}
|
|
loaded_ids+=${${(z)line}[3]}
|
|
done
|
|
fi
|
|
|
|
# add identities if not already loaded
|
|
for id in $identities; do
|
|
# check for filename match, otherwise try for signature match
|
|
if [[ ${loaded_ids[(I)$HOME/.ssh/$id]} -le 0 ]]; then
|
|
sig="$(ssh-keygen -lf "$HOME/.ssh/$id" | awk '{print $2}')"
|
|
[[ ${loaded_sigs[(I)$sig]} -le 0 ]] && not_loaded+="$HOME/.ssh/$id"
|
|
fi
|
|
done
|
|
|
|
local args
|
|
zstyle -a :omz:plugins:ssh-agent ssh-add-args args
|
|
[[ -n "$not_loaded" ]] && ssh-add "${args[@]}" ${^not_loaded}
|
|
}
|
|
|
|
# Get the filename to store/lookup the environment from
|
|
_ssh_env_cache="$HOME/.ssh/environment-$SHORT_HOST"
|
|
|
|
if zstyle -t :omz:plugins:ssh-agent agent-forwarding && [[ -n "$SSH_AUTH_SOCK" ]]; then
|
|
# Add a nifty symlink for screen/tmux if agent forwarding
|
|
[[ -L $SSH_AUTH_SOCK ]] || ln -sf "$SSH_AUTH_SOCK" /tmp/ssh-agent-$USERNAME-screen
|
|
elif [[ -f "$_ssh_env_cache" ]]; then
|
|
# Source SSH settings, if applicable
|
|
. $_ssh_env_cache > /dev/null
|
|
if [[ $USERNAME == "root" ]]; then
|
|
FILTER="ax"
|
|
else
|
|
FILTER="x"
|
|
fi
|
|
ps $FILTER | grep ssh-agent | grep -q $SSH_AGENT_PID || {
|
|
_start_agent
|
|
}
|
|
elif [[ -d $HOME/.ssh ]]; then
|
|
_start_agent
|
|
fi
|
|
|
|
if ! zstyle -t :omz:plugins:ssh-agent lazy; then
|
|
_add_identities
|
|
fi
|
|
|
|
# tidy up after ourselves
|
|
unset _ssh_env_cache
|
|
unfunction _start_agent _add_identities
|
|
|
|
rm -rf "$lockdir"
|