2023-02-08 08:06:03 +00:00
|
|
|
# $OpenBSD: agent-getpeereid.sh,v 1.15 2023/02/08 08:06:03 dtucker Exp $
|
2021-09-01 00:50:27 +00:00
|
|
|
# $OpenBSD: agent-getpeereid.sh,v 1.13 2021/09/01 00:50:27 dtucker Exp $
|
2003-01-22 06:53:16 +00:00
|
|
|
# Placed in the Public Domain.
|
|
|
|
|
|
|
|
tid="disallow agent attach from other uid"
|
|
|
|
|
|
|
|
UNPRIV=nobody
|
|
|
|
ASOCK=${OBJ}/agent
|
2008-03-12 12:58:55 +00:00
|
|
|
SSH_AUTH_SOCK=/nonexistent
|
2022-12-01 02:19:29 +00:00
|
|
|
>$OBJ/ssh-agent.log
|
|
|
|
>$OBJ/ssh-add.log
|
2003-01-22 06:53:16 +00:00
|
|
|
|
2011-01-17 06:53:56 +00:00
|
|
|
if config_defined HAVE_GETPEEREID HAVE_GETPEERUCRED HAVE_SO_PEERCRED ; then
|
|
|
|
:
|
|
|
|
else
|
2021-09-01 00:50:27 +00:00
|
|
|
skip "skipped (not supported on this platform)"
|
2003-09-04 03:49:30 +00:00
|
|
|
fi
|
2022-02-21 10:27:20 +00:00
|
|
|
if test "x$USER" = "xroot"; then
|
|
|
|
skip "skipped (running as root)"
|
|
|
|
fi
|
2016-05-03 14:41:04 +00:00
|
|
|
case "x$SUDO" in
|
|
|
|
xsudo) sudo=1;;
|
2021-07-29 15:34:09 +00:00
|
|
|
xdoas|xdoas\ *) ;;
|
2016-05-03 14:41:04 +00:00
|
|
|
x)
|
2021-09-01 00:50:27 +00:00
|
|
|
skip "need SUDO to switch to uid $UNPRIV" ;;
|
2016-05-03 14:41:04 +00:00
|
|
|
*)
|
2021-09-01 00:50:27 +00:00
|
|
|
skip "unsupported $SUDO - "doas" and "sudo" are allowed" ;;
|
2016-05-03 14:41:04 +00:00
|
|
|
esac
|
2006-07-24 05:31:41 +00:00
|
|
|
|
2003-01-22 06:53:16 +00:00
|
|
|
trace "start agent"
|
2022-12-01 02:19:29 +00:00
|
|
|
eval `${SSHAGENT} ${EXTRA_AGENT_ARGS} -s -a ${ASOCK}` >$OBJ/ssh-agent.log 2>&1
|
2003-01-22 06:53:16 +00:00
|
|
|
r=$?
|
|
|
|
if [ $r -ne 0 ]; then
|
|
|
|
fail "could not start ssh-agent: exit code $r"
|
|
|
|
else
|
|
|
|
chmod 644 ${SSH_AUTH_SOCK}
|
|
|
|
|
2022-12-01 02:19:29 +00:00
|
|
|
${SSHADD} -vvv -l >>$OBJ/ssh-add.log 2>&1
|
2003-01-22 06:53:16 +00:00
|
|
|
r=$?
|
|
|
|
if [ $r -ne 1 ]; then
|
|
|
|
fail "ssh-add failed with $r != 1"
|
|
|
|
fi
|
2016-05-03 14:41:04 +00:00
|
|
|
if test -z "$sudo" ; then
|
|
|
|
# doas
|
2017-01-06 02:51:16 +00:00
|
|
|
${SUDO} -n -u ${UNPRIV} ${SSHADD} -l 2>/dev/null
|
2016-05-03 14:41:04 +00:00
|
|
|
else
|
|
|
|
# sudo
|
2022-12-01 02:19:29 +00:00
|
|
|
< /dev/null ${SUDO} -S -u ${UNPRIV} ${SSHADD} -vvv -l >>$OBJ/ssh-add.log 2>&1
|
2016-05-03 14:41:04 +00:00
|
|
|
fi
|
2003-01-22 06:53:16 +00:00
|
|
|
r=$?
|
|
|
|
if [ $r -lt 2 ]; then
|
|
|
|
fail "ssh-add did not fail for ${UNPRIV}: $r < 2"
|
2022-12-01 02:19:29 +00:00
|
|
|
cat $OBJ/ssh-add.log
|
2003-01-22 06:53:16 +00:00
|
|
|
fi
|
|
|
|
|
|
|
|
trace "kill agent"
|
2023-02-08 08:06:03 +00:00
|
|
|
${SSHAGENT} -k >>$OBJ/ssh-agent.log 2>&1
|
2003-01-22 06:53:16 +00:00
|
|
|
fi
|
|
|
|
|
|
|
|
rm -f ${OBJ}/agent
|