2023-05-12 06:37:42 +00:00
|
|
|
# $OpenBSD: sftp-chroot.sh,v 1.9 2023/05/12 06:37:42 djm Exp $
|
2013-05-16 23:35:26 +00:00
|
|
|
# Placed in the Public Domain.
|
|
|
|
|
|
|
|
tid="sftp in chroot"
|
|
|
|
|
|
|
|
CHROOT=/var/run
|
2018-11-22 08:48:32 +00:00
|
|
|
FILENAME=testdata_${USER}.$$
|
2013-05-16 23:35:26 +00:00
|
|
|
PRIVDATA=${CHROOT}/${FILENAME}
|
2018-11-22 08:48:32 +00:00
|
|
|
trap "${SUDO} rm -f ${PRIVDATA}" 0
|
2013-05-16 23:35:26 +00:00
|
|
|
|
2016-09-26 21:34:38 +00:00
|
|
|
if [ -z "$SUDO" -a ! -w /var/run ]; then
|
2021-09-01 00:50:27 +00:00
|
|
|
skip "need SUDO to create file in /var/run, test won't work without"
|
2013-05-16 23:35:26 +00:00
|
|
|
fi
|
|
|
|
|
2016-02-23 05:12:13 +00:00
|
|
|
if ! $OBJ/check-perm -m chroot "$CHROOT" ; then
|
2021-09-01 00:50:27 +00:00
|
|
|
skip "$CHROOT is unsuitable as ChrootDirectory"
|
2016-02-23 05:12:13 +00:00
|
|
|
fi
|
|
|
|
|
2013-05-16 23:35:26 +00:00
|
|
|
$SUDO sh -c "echo mekmitastdigoat > $PRIVDATA" || \
|
|
|
|
fatal "create $PRIVDATA failed"
|
|
|
|
|
2023-05-12 06:37:42 +00:00
|
|
|
echo "ForceCommand internal-sftp -d /" >> $OBJ/sshd_config
|
|
|
|
|
|
|
|
start_sshd -oChrootDirectory=$CHROOT
|
2013-05-16 23:35:26 +00:00
|
|
|
|
|
|
|
verbose "test $tid: get"
|
2014-02-27 23:19:11 +00:00
|
|
|
${SFTP} -S "$SSH" -F $OBJ/ssh_config host:/${FILENAME} $COPY \
|
2014-02-27 23:19:51 +00:00
|
|
|
>>$TEST_REGRESS_LOGFILE 2>&1 || \
|
2013-05-16 23:35:26 +00:00
|
|
|
fatal "Fetch ${FILENAME} failed"
|
|
|
|
cmp $PRIVDATA $COPY || fail "$PRIVDATA $COPY differ"
|
2023-05-12 06:37:42 +00:00
|
|
|
|
|
|
|
stop_sshd
|
|
|
|
|
|
|
|
verbose "test $tid: match"
|
|
|
|
cat << EOF >> $OBJ/sshd_config
|
|
|
|
Match All
|
|
|
|
ChrootDirectory $CHROOT
|
|
|
|
EOF
|
|
|
|
start_sshd
|
|
|
|
$SUDO sh -c "echo orpheanbeholder > $PRIVDATA" || \
|
|
|
|
fatal "create $PRIVDATA failed"
|
|
|
|
${SFTP} -S "$SSH" -F $OBJ/ssh_config host:/${FILENAME} $COPY \
|
|
|
|
>>$TEST_REGRESS_LOGFILE 2>&1 || \
|
|
|
|
fatal "Fetch ${FILENAME} failed"
|
|
|
|
cmp $PRIVDATA $COPY || fail "$PRIVDATA $COPY differ"
|
|
|
|
|
|
|
|
stop_sshd
|