Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f6663e4df2 | ||
|
|
860e590114 |
@@ -94,22 +94,24 @@ Adds the `pub` line to `~/.ssh/authorized_keys` on the host. No command is run
|
|||||||
on the host: the file is fetched, changed here, and written back with the
|
on the host: the file is fetched, changed here, and written back with the
|
||||||
system `sftp` client in batch mode.
|
system `sftp` client in batch mode.
|
||||||
|
|
||||||
The first connection fetches `~/.ssh/authorized_keys`. The file reads as empty
|
The first connection lists `~/.ssh` and then fetches
|
||||||
only when `sftp` reported that file as not being there — the one line naming
|
`~/.ssh/authorized_keys` from it. The file reads as empty in two cases only:
|
||||||
that path. The same wording anywhere else in the session does not count: `ssh`
|
`sftp` reported `~/.ssh` itself as not being there, or the listing came up and
|
||||||
writes `No such file or directory` about an `-i` it cannot find, on a session
|
the file was not in it. Any other outcome of that connection fails the run — a
|
||||||
that then authenticates through the agent. When `sftp` failed for any other
|
`~/.ssh` that is there but cannot be entered, an `authorized_keys` that is there
|
||||||
reason — the file is there and cannot be read, the connection did not come up —
|
but cannot be read, or a connection that did not come up — and the tool prints
|
||||||
the tool prints what `sftp` said and exits with status 1 without writing
|
what `sftp` said and exits with status 1 without writing anything, rather than
|
||||||
anything, rather than put a file back holding the new key alone. What `sftp`
|
put a file back holding the new key alone. The listing is what tells a missing
|
||||||
cannot tell apart is a missing file and one in a directory it cannot enter, so a
|
directory from one shut to the user, which `sftp` reports on a fetch the same
|
||||||
`~/.ssh` whose mode shuts the user out reads as a host with no file; the second
|
way; the wording of a missing file elsewhere does not count either, since `ssh`
|
||||||
connection sets that mode to `0700` and writes, as on a host that has none. If
|
writes `No such file or directory` about an `-i` it cannot find on a session
|
||||||
an identical line is already in the file, the tool prints
|
that then authenticates through the agent. If an identical line is already in
|
||||||
`already present` and connects no further. Otherwise the line is added (after a
|
the file, the tool prints `already present` and connects no further. Otherwise
|
||||||
newline, if the file did not end with one) and a second connection:
|
the line is added (after a newline, if the file did not end with one) and a
|
||||||
|
second connection:
|
||||||
|
|
||||||
- creates `~/.ssh` and sets it to mode `0700`;
|
- makes `~/.ssh` and sets it to mode `0700`, but only when the first connection
|
||||||
|
found none; a `~/.ssh` that was already there keeps the mode it had;
|
||||||
- uploads the new file as `~/.ssh/authorized_keys.keyfunc-<random>` and sets it
|
- uploads the new file as `~/.ssh/authorized_keys.keyfunc-<random>` and sets it
|
||||||
to mode `0600`;
|
to mode `0600`;
|
||||||
- renames that file over `~/.ssh/authorized_keys`.
|
- renames that file over `~/.ssh/authorized_keys`.
|
||||||
|
|||||||
@@ -1,27 +1,27 @@
|
|||||||
module git.eeqj.de/sneak/keyfunc
|
module git.eeqj.de/sneak/keyfunc
|
||||||
|
|
||||||
go 1.26
|
go 1.26.0
|
||||||
|
|
||||||
require (
|
require (
|
||||||
filippo.io/age v1.2.1
|
filippo.io/age v1.3.2
|
||||||
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd
|
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd
|
||||||
github.com/btcsuite/btcd v0.24.2
|
github.com/btcsuite/btcd v0.25.0
|
||||||
github.com/btcsuite/btcd/btcutil v1.1.6
|
github.com/btcsuite/btcd/btcutil v1.2.0
|
||||||
github.com/spf13/cobra v1.9.1
|
github.com/spf13/cobra v1.10.2
|
||||||
github.com/stretchr/testify v1.8.4
|
github.com/stretchr/testify v1.12.1
|
||||||
github.com/tyler-smith/go-bip39 v1.1.0
|
github.com/tyler-smith/go-bip39 v1.1.0
|
||||||
golang.org/x/crypto v0.38.0
|
golang.org/x/crypto v0.57.0
|
||||||
golang.org/x/term v0.32.0
|
golang.org/x/term v0.46.0
|
||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/btcsuite/btcd/btcec/v2 v2.1.3 // indirect
|
filippo.io/hpke v0.4.0 // indirect
|
||||||
github.com/btcsuite/btcd/chaincfg/chainhash v1.1.0 // indirect
|
github.com/btcsuite/btcd/btcec/v2 v2.5.0 // indirect
|
||||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
github.com/btcsuite/btcd/chaincfg/chainhash v1.2.0 // indirect
|
||||||
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.0.1 // indirect
|
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
|
||||||
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
||||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
github.com/kcalvinalvin/anet v0.0.0-20251112173137-d8ddc1f6dbee // indirect
|
||||||
github.com/spf13/pflag v1.0.6 // indirect
|
github.com/spf13/pflag v1.0.9 // indirect
|
||||||
golang.org/x/sys v0.33.0 // indirect
|
go.yaml.in/yaml/v3 v3.0.5 // indirect
|
||||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
golang.org/x/sys v0.48.0 // indirect
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -1,136 +1,50 @@
|
|||||||
c2sp.org/CCTV/age v0.0.0-20240306222714-3ec4d716e805 h1:u2qwJeEvnypw+OCPUHmoZE3IqwfuN5kgDfo5MLzpNM0=
|
c2sp.org/CCTV/age v0.0.0-20260829155415-4448f2097b2d h1:Blprhc2SbChNZtWcU+BLTM4YdoqYAS9V7cJgOwJKyAs=
|
||||||
c2sp.org/CCTV/age v0.0.0-20240306222714-3ec4d716e805/go.mod h1:FomMrUJ2Lxt5jCLmZkG3FHa72zUprnhd3v/Z18Snm4w=
|
c2sp.org/CCTV/age v0.0.0-20260829155415-4448f2097b2d/go.mod h1:SrHC2C7r5GkDk8R+NFVzYy/sdj0Ypg9htaPXQq5Cqeo=
|
||||||
filippo.io/age v1.2.1 h1:X0TZjehAZylOIj4DubWYU1vWQxv9bJpo+Uu2/LGhi1o=
|
filippo.io/age v1.3.2 h1:r6RSZLFSMm6rzKepZ7ZAYkKCu14f3/Me8c7uKYh7C8c=
|
||||||
filippo.io/age v1.2.1/go.mod h1:JL9ew2lTN+Pyft4RiNGguFfOpewKwSHm5ayKD/A4004=
|
filippo.io/age v1.3.2/go.mod h1:TH/Yr2sSRhCKbaH4XPxpUV0Us8Gv6txYUpiZQWz8Evk=
|
||||||
|
filippo.io/hpke v0.4.0 h1:p575VVQ6ted4pL+it6M00V/f2qTZITO0zgmdKCkd5+A=
|
||||||
|
filippo.io/hpke v0.4.0/go.mod h1:EmAN849/P3qdeK+PCMkDpDm83vRHM5cDipBJ8xbQLVY=
|
||||||
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd h1:6YFV6horz2wDFPWWhour8qx8gLGyO0qoplwEeOuQ2J4=
|
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd h1:6YFV6horz2wDFPWWhour8qx8gLGyO0qoplwEeOuQ2J4=
|
||||||
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd/go.mod h1:gKCcMZvlBOqusn/BxR8IyFmSJQr6R4vvjJ926iNpOSI=
|
git.eeqj.de/sneak/secret v0.0.0-20260810132333-41cea400a7fd/go.mod h1:gKCcMZvlBOqusn/BxR8IyFmSJQr6R4vvjJ926iNpOSI=
|
||||||
github.com/aead/siphash v1.0.1/go.mod h1:Nywa3cDsYNNK3gaciGTWPwHt0wlpNV15vwmswBAUSII=
|
github.com/btcsuite/btcd v0.25.0 h1:JPbjwvHGpSywBRuorFFqTjaVP4y6Qw69XJ1nQ6MyWJM=
|
||||||
github.com/btcsuite/btcd v0.20.1-beta/go.mod h1:wVuoA8VJLEcwgqHBwHmzLRazpKxTv13Px/pDuV7OomQ=
|
github.com/btcsuite/btcd v0.25.0/go.mod h1:qbPE+pEiR9643E1s1xu57awsRhlCIm1ZIi6FfeRA4KE=
|
||||||
github.com/btcsuite/btcd v0.22.0-beta.0.20220111032746-97732e52810c/go.mod h1:tjmYdS6MLJ5/s0Fj4DbLgSbDHbEqLJrtnHecBFkdz5M=
|
github.com/btcsuite/btcd/btcec/v2 v2.5.0 h1:KioMXOWa76b86sTZZOmbzv/ldaQCmB8KFAyn5PbB8E8=
|
||||||
github.com/btcsuite/btcd v0.23.5-0.20231215221805-96c9fd8078fd/go.mod h1:nm3Bko6zh6bWP60UxwoT5LzdGJsQJaPo6HjduXq9p6A=
|
github.com/btcsuite/btcd/btcec/v2 v2.5.0/go.mod h1:+K/MYXcLBtHEQjRbjHuJChuybk4LCgjdjgRwil+e+Kk=
|
||||||
github.com/btcsuite/btcd v0.24.2 h1:aLmxPguqxza+4ag8R1I2nnJjSu2iFn/kqtHTIImswcY=
|
github.com/btcsuite/btcd/btcutil v1.2.0 h1:p3+S2g3Q+7G5NOh4Ji+2UrBOrg5Z0Q4ykzShWG1Dhgs=
|
||||||
github.com/btcsuite/btcd v0.24.2/go.mod h1:5C8ChTkl5ejr3WHj8tkQSCmydiMEPB0ZhQhehpq7Dgg=
|
github.com/btcsuite/btcd/btcutil v1.2.0/go.mod h1:/Taflm113pYjUpbWKKQEfa6XOtI/+WS8awxeMZpY75k=
|
||||||
github.com/btcsuite/btcd/btcec/v2 v2.1.0/go.mod h1:2VzYrv4Gm4apmbVVsSq5bqf1Ec8v56E48Vt0Y/umPgA=
|
github.com/btcsuite/btcd/chaincfg/chainhash v1.2.0 h1:yMIg99+4aBvqfl/HzJRKfxTX9rGfikoI9uvFzterhc8=
|
||||||
github.com/btcsuite/btcd/btcec/v2 v2.1.3 h1:xM/n3yIhHAhHy04z4i43C8p4ehixJZMsnrVJkgl+MTE=
|
github.com/btcsuite/btcd/chaincfg/chainhash v1.2.0/go.mod h1:Y72Ren9gfhlEvnwnT78BGcSNO2UMphTKLn9AorF+5rg=
|
||||||
github.com/btcsuite/btcd/btcec/v2 v2.1.3/go.mod h1:ctjw4H1kknNJmRN4iP1R7bTQ+v3GJkZBd6mui8ZsAZE=
|
|
||||||
github.com/btcsuite/btcd/btcutil v1.0.0/go.mod h1:Uoxwv0pqYWhD//tfTiipkxNfdhG9UrLwaeswfjfdF0A=
|
|
||||||
github.com/btcsuite/btcd/btcutil v1.1.0/go.mod h1:5OapHB7A2hBBWLm48mmw4MOHNJCcUBTwmWH/0Jn8VHE=
|
|
||||||
github.com/btcsuite/btcd/btcutil v1.1.5/go.mod h1:PSZZ4UitpLBWzxGd5VGOrLnmOjtPP/a6HaFo12zMs00=
|
|
||||||
github.com/btcsuite/btcd/btcutil v1.1.6 h1:zFL2+c3Lb9gEgqKNzowKUPQNb8jV7v5Oaodi/AYFd6c=
|
|
||||||
github.com/btcsuite/btcd/btcutil v1.1.6/go.mod h1:9dFymx8HpuLqBnsPELrImQeTQfKBQqzqGbbV3jK55aE=
|
|
||||||
github.com/btcsuite/btcd/chaincfg/chainhash v1.0.0/go.mod h1:7SFka0XMvUgj3hfZtydOrQY2mwhPclbT2snogU7SQQc=
|
|
||||||
github.com/btcsuite/btcd/chaincfg/chainhash v1.0.1/go.mod h1:7SFka0XMvUgj3hfZtydOrQY2mwhPclbT2snogU7SQQc=
|
|
||||||
github.com/btcsuite/btcd/chaincfg/chainhash v1.1.0 h1:59Kx4K6lzOW5w6nFlA0v5+lk/6sjybR934QNHSJZPTQ=
|
|
||||||
github.com/btcsuite/btcd/chaincfg/chainhash v1.1.0/go.mod h1:7SFka0XMvUgj3hfZtydOrQY2mwhPclbT2snogU7SQQc=
|
|
||||||
github.com/btcsuite/btclog v0.0.0-20170628155309-84c8d2346e9f/go.mod h1:TdznJufoqS23FtqVCzL0ZqgP5MqXbb4fg/WgDys70nA=
|
|
||||||
github.com/btcsuite/btcutil v0.0.0-20190425235716-9e5f4b9a998d/go.mod h1:+5NJ2+qvTyV9exUAL/rxXi3DcLg2Ts+ymUAY5y4NvMg=
|
|
||||||
github.com/btcsuite/go-socks v0.0.0-20170105172521-4720035b7bfd/go.mod h1:HHNXQzUsZCxOoE+CPiyCTO6x34Zs86zZUiwtpXoGdtg=
|
|
||||||
github.com/btcsuite/goleveldb v0.0.0-20160330041536-7834afc9e8cd/go.mod h1:F+uVaaLLH7j4eDXPRvw78tMflu7Ie2bzYOH4Y8rRKBY=
|
|
||||||
github.com/btcsuite/goleveldb v1.0.0/go.mod h1:QiK9vBlgftBg6rWQIj6wFzbPfRjiykIEhBH4obrXJ/I=
|
|
||||||
github.com/btcsuite/snappy-go v0.0.0-20151229074030-0bdef8d06723/go.mod h1:8woku9dyThutzjeg+3xrA5iCpBRH8XEEg3lh6TiUghc=
|
|
||||||
github.com/btcsuite/snappy-go v1.0.0/go.mod h1:8woku9dyThutzjeg+3xrA5iCpBRH8XEEg3lh6TiUghc=
|
|
||||||
github.com/btcsuite/websocket v0.0.0-20150119174127-31079b680792/go.mod h1:ghJtEyQwv5/p4Mg4C0fgbePVuGr935/5ddU9Z3TmDRY=
|
|
||||||
github.com/btcsuite/winsvc v1.0.0/go.mod h1:jsenWakMcC0zFBFurPLEAyrnc/teJEM1O46fmI40EZs=
|
|
||||||
github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g=
|
github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g=
|
||||||
github.com/davecgh/go-spew v0.0.0-20171005155431-ecdeabc65495/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
|
||||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
|
||||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/decred/dcrd/crypto/blake256 v1.0.0/go.mod h1:sQl2p6Y26YV+ZOcSTP6thNdn47hh8kt6rqSlvmrXFAc=
|
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 h1:NMZiJj8QnKe1LgsbDayM4UoHwbvwDRwnI3hwNaAHRnc=
|
||||||
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.0.1 h1:YLtO71vCjJRCBcrPMtQ9nqBsqpA1m5sE92cU+pd5Mcc=
|
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0/go.mod h1:ZXNYxsqcloTdSy/rNShjYzMhyjf0LaoftYK0p+A3h40=
|
||||||
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.0.1/go.mod h1:hyedUtir6IdtD/7lIxGeCxkaw7y45JueMRL4DIyJDKs=
|
|
||||||
github.com/decred/dcrd/lru v1.0.0/go.mod h1:mxKOwFd7lFjN2GZYsiz/ecgqR6kkYAl+0pz0tEMk218=
|
|
||||||
github.com/fsnotify/fsnotify v1.4.7/go.mod h1:jwhsz4b93w/PPRr/qN1Yymfu8t87LnFCMoQvtojpjFo=
|
|
||||||
github.com/fsnotify/fsnotify v1.4.9/go.mod h1:znqG4EE+3YCdAaPaxE2ZRY/06pZUdp0tY4IgpuI1SZQ=
|
|
||||||
github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
|
|
||||||
github.com/golang/protobuf v1.4.0-rc.1/go.mod h1:ceaxUfeHdC40wWswd/P6IGgMaK3YpKi5j83Wpe3EHw8=
|
|
||||||
github.com/golang/protobuf v1.4.0-rc.1.0.20200221234624-67d41d38c208/go.mod h1:xKAWHe0F5eneWXFV3EuXVDTCmh+JuBKY0li0aMyXATA=
|
|
||||||
github.com/golang/protobuf v1.4.0-rc.2/go.mod h1:LlEzMj4AhA7rCAGe4KMBDvJI+AwstrUpVNzEA03Pprs=
|
|
||||||
github.com/golang/protobuf v1.4.0-rc.4.0.20200313231945-b860323f09d0/go.mod h1:WU3c8KckQ9AFe+yFwt9sWVRKCVIyN9cPHBJSNnbL67w=
|
|
||||||
github.com/golang/protobuf v1.4.0/go.mod h1:jodUvKwWbYaEsadDk5Fwe5c77LiNKVO9IDvqG2KuDX0=
|
|
||||||
github.com/golang/protobuf v1.4.2/go.mod h1:oDoupMAO8OvCJWAcko0GGGIgR6R6ocIYbsSw735rRwI=
|
|
||||||
github.com/golang/snappy v0.0.4/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEWrmP2Q=
|
|
||||||
github.com/google/go-cmp v0.3.0/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU=
|
|
||||||
github.com/google/go-cmp v0.3.1/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU=
|
|
||||||
github.com/google/go-cmp v0.4.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
|
||||||
github.com/gorilla/websocket v1.5.0/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE=
|
|
||||||
github.com/hpcloud/tail v1.0.0/go.mod h1:ab1qPbhIpdTxEkNHXyeSf5vhxWSCs/tWer42PpOxQnU=
|
|
||||||
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
|
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
|
||||||
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
|
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
|
||||||
github.com/jessevdk/go-flags v0.0.0-20141203071132-1679536dcc89/go.mod h1:4FA24M0QyGHXBuZZK/XkWh8h0e1EYbRYJSGM75WSRxI=
|
github.com/kcalvinalvin/anet v0.0.0-20251112173137-d8ddc1f6dbee h1:FPP9HDkBbPyniu+u7FHZg+kKFX1WW0gxOGteJ0h3AJk=
|
||||||
github.com/jessevdk/go-flags v1.4.0/go.mod h1:4FA24M0QyGHXBuZZK/XkWh8h0e1EYbRYJSGM75WSRxI=
|
github.com/kcalvinalvin/anet v0.0.0-20251112173137-d8ddc1f6dbee/go.mod h1:N6sz6HwJAenJ6d+/xmSl0ikfV05ZrVGmjt1ryy/WOtE=
|
||||||
github.com/jrick/logrotate v1.0.0/go.mod h1:LNinyqDIJnpAur+b8yyulnQw/wDuN1+BYKlTRt3OuAQ=
|
|
||||||
github.com/kkdai/bstream v0.0.0-20161212061736-f391b8402d23/go.mod h1:J+Gs4SYgM6CZQHDETBtE9HaSEkGmuNXF86RwHhHUvq4=
|
|
||||||
github.com/nxadm/tail v1.4.4/go.mod h1:kenIhsEOeOJmVchQTgglprH7qJGnHDVpk1VPCcaMI8A=
|
|
||||||
github.com/onsi/ginkgo v1.6.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+WWjE=
|
|
||||||
github.com/onsi/ginkgo v1.7.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+WWjE=
|
|
||||||
github.com/onsi/ginkgo v1.12.1/go.mod h1:zj2OWP4+oCPe1qIXoGWkgMRwljMUYCdkwsT2108oapk=
|
|
||||||
github.com/onsi/ginkgo v1.14.0/go.mod h1:iSB4RoI2tjJc9BBv4NKIKWKya62Rps+oPG/Lv9klQyY=
|
|
||||||
github.com/onsi/gomega v1.4.1/go.mod h1:C1qb7wdrVGGVU+Z6iS04AVkA3Q65CEZX59MT0QO5uiA=
|
|
||||||
github.com/onsi/gomega v1.4.3/go.mod h1:ex+gbHU/CVuBBDIJjb2X0qEXbFg53c61hWP/1CpauHY=
|
|
||||||
github.com/onsi/gomega v1.7.1/go.mod h1:XdKZgCCFLUoM/7CFJVPcG8C1xQ1AJ0vpAezJrB7JYyY=
|
|
||||||
github.com/onsi/gomega v1.10.1/go.mod h1:iN09h71vgCQne3DLsj+A5owkum+a2tYe+TOCB1ybHNo=
|
|
||||||
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
|
||||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
|
||||||
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
||||||
github.com/spf13/cobra v1.9.1 h1:CXSaggrXdbHK9CF+8ywj8Amf7PBRmPCOJugH954Nnlo=
|
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
|
||||||
github.com/spf13/cobra v1.9.1/go.mod h1:nDyEzZ8ogv936Cinf6g1RU9MRY64Ir93oCnqb9wxYW0=
|
github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4=
|
||||||
github.com/spf13/pflag v1.0.6 h1:jFzHGLGAlb3ruxLB8MhbI6A8+AQX/2eW4qeyNZXNp2o=
|
github.com/spf13/pflag v1.0.9 h1:9exaQaMOCwffKiiiYk6/BndUBv+iRViNW+4lEMi0PvY=
|
||||||
github.com/spf13/pflag v1.0.6/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
||||||
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
|
||||||
github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
|
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
|
||||||
github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo=
|
|
||||||
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
|
||||||
github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
|
||||||
github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
|
|
||||||
github.com/stretchr/testify v1.8.4 h1:CcVxjf3Q8PM0mHUKJCdn+eZZtm5yQwehR5yeSVQQcUk=
|
|
||||||
github.com/stretchr/testify v1.8.4/go.mod h1:sz/lmYIOXD/1dqDmKjjqLyZ2RngseejIcXlSw2iwfAo=
|
|
||||||
github.com/syndtr/goleveldb v1.0.1-0.20210819022825-2ae1ddf74ef7/go.mod h1:q4W45IWZaF22tdD+VEXcAWRA037jwmWEB5VWYORlTpc=
|
|
||||||
github.com/tyler-smith/go-bip39 v1.1.0 h1:5eUemwrMargf3BSLRRCalXT93Ns6pQJIjYQN2nyfOP8=
|
github.com/tyler-smith/go-bip39 v1.1.0 h1:5eUemwrMargf3BSLRRCalXT93Ns6pQJIjYQN2nyfOP8=
|
||||||
github.com/tyler-smith/go-bip39 v1.1.0/go.mod h1:gUYDtqQw1JS3ZJ8UWVcGTGqqr6YIN3CWg+kkNaLt55U=
|
github.com/tyler-smith/go-bip39 v1.1.0/go.mod h1:gUYDtqQw1JS3ZJ8UWVcGTGqqr6YIN3CWg+kkNaLt55U=
|
||||||
golang.org/x/crypto v0.0.0-20170930174604-9419663f5a44/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4=
|
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
|
||||||
|
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
|
||||||
|
go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
|
||||||
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
||||||
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
||||||
golang.org/x/crypto v0.38.0 h1:jt+WWG8IZlBnVbomuhg2Mdq0+BBQaHbtqHEFEigjUV8=
|
golang.org/x/crypto v0.57.0 h1:3ZVCjf8Ggz7zneR/EHRVx68Ctf+2pmIMP2UFhh9cC6M=
|
||||||
golang.org/x/crypto v0.38.0/go.mod h1:MvrbAqul58NNYPKnOra203SB9vpuZW0e+RRZV+Ggqjw=
|
golang.org/x/crypto v0.57.0/go.mod h1:Fdz0i5U6CoizGwLda9DttjSk6qlZo25zYNtR+ycvuZA=
|
||||||
golang.org/x/net v0.0.0-20180719180050-a680a1efc54d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
|
||||||
golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
|
||||||
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
||||||
golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A=
|
|
||||||
golang.org/x/net v0.0.0-20200813134508-3edf25e44fcc/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
|
|
||||||
golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
|
||||||
golang.org/x/sys v0.0.0-20180909124046-d0be0721c37e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
|
||||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||||
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20190904154756-749cb33beabd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo=
|
||||||
golang.org/x/sys v0.0.0-20191005200804-aed5e4c7ecf9/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og=
|
||||||
golang.org/x/sys v0.0.0-20191120155948-bd437916bb0e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/term v0.46.0 h1:3+OXuTbaKDgwk8jTi3aSLHRlmWqHEUDUtxnbFigO4YE=
|
||||||
golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/term v0.46.0/go.mod h1:+K02xbkittuwc0Am4abfA3Fc+XRGXkvBXNO88NCXPoc=
|
||||||
golang.org/x/sys v0.0.0-20200519105757-fe76b779f299/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
|
||||||
golang.org/x/sys v0.0.0-20200814200057-3d37ad5750ed/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
|
||||||
golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw=
|
|
||||||
golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
|
|
||||||
golang.org/x/term v0.32.0 h1:DR4lr0TjUs3epypdhTOkMmuF5CDFJ/8pOnbzMZPQ7bg=
|
|
||||||
golang.org/x/term v0.32.0/go.mod h1:uZG1FhGx848Sqfsq4/DlJr3xGGsYMu/L5GW4abiaEPQ=
|
|
||||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||||
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
|
|
||||||
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
|
||||||
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
|
||||||
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
|
||||||
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
|
||||||
google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8=
|
|
||||||
google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0=
|
|
||||||
google.golang.org/protobuf v0.0.0-20200228230310-ab0ca4ff8a60/go.mod h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM=
|
|
||||||
google.golang.org/protobuf v1.20.1-0.20200309200217-e05f789c0967/go.mod h1:A+miEFZTKqfCUM6K7xSMQL9OKL/b6hQv+e19PK+JZNE=
|
|
||||||
google.golang.org/protobuf v1.21.0/go.mod h1:47Nbq4nVaFHyn7ilMalzfO3qCViNmqZ2kzikPIcrTAo=
|
|
||||||
google.golang.org/protobuf v1.23.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU=
|
|
||||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=
|
|
||||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
gopkg.in/fsnotify.v1 v1.4.7/go.mod h1:Tz8NjZHkW78fSQdbUxIjBTcgA1z1m8ZHf0WmKUhAMys=
|
|
||||||
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7/go.mod h1:dt/ZhP58zS4L8KSrWDmTeBkI65Dw0HsyUHuEVlX15mw=
|
|
||||||
gopkg.in/yaml.v2 v2.2.1/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
|
||||||
gopkg.in/yaml.v2 v2.2.4/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
|
||||||
gopkg.in/yaml.v2 v2.3.0/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
|
||||||
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
|
||||||
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
|
||||||
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
|
||||||
|
|||||||
+80
-17
@@ -76,7 +76,7 @@ func add(cmd *cobra.Command, host string, options []string, line string) error {
|
|||||||
|
|
||||||
defer func() { _ = os.RemoveAll(work) }()
|
defer func() { _ = os.RemoveAll(work) }()
|
||||||
|
|
||||||
content, err := fetch(cmd, host, options,
|
content, present, err := fetch(cmd, host, options,
|
||||||
filepath.Join(work, "authorized_keys"),
|
filepath.Join(work, "authorized_keys"),
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -88,16 +88,18 @@ func add(cmd *cobra.Command, host string, options []string, line string) error {
|
|||||||
return write(cmd, "already present\n")
|
return write(cmd, "already present\n")
|
||||||
}
|
}
|
||||||
|
|
||||||
return upload(cmd, host, options, work, merged)
|
return upload(cmd, host, options, work, merged, present)
|
||||||
}
|
}
|
||||||
|
|
||||||
// upload writes the new file to the host and renames it over
|
// upload writes the new file to the host and renames it over
|
||||||
// authorized_keys, which is the step that either happens or does not.
|
// authorized_keys, which is the step that either happens or does not.
|
||||||
// Nothing is removed when a step fails: the file left behind is named
|
// Nothing is removed when a step fails: the file left behind is named
|
||||||
// so that it can be looked at and cleared away by hand.
|
// so that it can be looked at and cleared away by hand. The directory
|
||||||
|
// is made and set to its mode only when the read found none: an .ssh
|
||||||
|
// that was already there is left with the mode it had.
|
||||||
func upload(
|
func upload(
|
||||||
cmd *cobra.Command, host string, options []string,
|
cmd *cobra.Command, host string, options []string,
|
||||||
work, merged string,
|
work, merged string, present bool,
|
||||||
) error {
|
) error {
|
||||||
local := filepath.Join(work, "authorized_keys.merged")
|
local := filepath.Join(work, "authorized_keys.merged")
|
||||||
|
|
||||||
@@ -111,14 +113,24 @@ func upload(
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
// The mkdir may fail: the directory is usually there already.
|
var batch []string
|
||||||
said, err := session(cmd, host, options, []string{
|
|
||||||
|
if !present {
|
||||||
|
// The mkdir is allowed to fail in case the directory appeared
|
||||||
|
// between the read and now; the chmod then sets its mode.
|
||||||
|
batch = append(batch,
|
||||||
"-mkdir "+directory,
|
"-mkdir "+directory,
|
||||||
"chmod "+directoryMode+" "+directory,
|
"chmod "+directoryMode+" "+directory,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
batch = append(batch,
|
||||||
"put "+quoted(local)+" "+sidecar,
|
"put "+quoted(local)+" "+sidecar,
|
||||||
"chmod "+fileMode+" "+sidecar,
|
"chmod "+fileMode+" "+sidecar,
|
||||||
"rename "+sidecar+" "+authorized,
|
"rename "+sidecar+" "+authorized,
|
||||||
})
|
)
|
||||||
|
|
||||||
|
said, err := session(cmd, host, options, batch)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// sftp echoes each command as it runs it and stops at the
|
// sftp echoes each command as it runs it and stops at the
|
||||||
// first that fails, so the name is in what it said only once
|
// first that fails, so the name is in what it said only once
|
||||||
@@ -185,31 +197,82 @@ func merge(content, line string) (string, bool) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// fetch brings the host's authorized_keys into the given path and
|
// fetch brings the host's authorized_keys into the given path and
|
||||||
// returns what is in it. A host that has no such file reads as empty,
|
// returns what is in it, and whether the .ssh directory was already
|
||||||
// but only when that is what sftp said about it: a file that is there
|
// there. The one session lists .ssh and then gets the file, so the
|
||||||
// and cannot be read fails the run, because writing back over it
|
// listing settles the state of the directory before the get is read.
|
||||||
// would leave the host with the new key and nothing else.
|
//
|
||||||
|
// The file reads as empty in just two cases: sftp reported .ssh itself
|
||||||
|
// as not there, or the listing succeeded and the get then reported the
|
||||||
|
// file as not there. Anything else — the listing refused, the file
|
||||||
|
// there but unreadable, the connection down — fails the run and writes
|
||||||
|
// nothing, because writing back over what was not read would leave the
|
||||||
|
// host with the new key and nothing else. sftp cannot tell a missing
|
||||||
|
// file from one in a directory it cannot enter, so the listing does:
|
||||||
|
// a directory that is there but cannot be read is a failure, not an
|
||||||
|
// empty file.
|
||||||
func fetch(
|
func fetch(
|
||||||
cmd *cobra.Command, host string, options []string, into string,
|
cmd *cobra.Command, host string, options []string, into string,
|
||||||
) (string, error) {
|
) (string, bool, error) {
|
||||||
said, err := session(cmd, host, options, []string{
|
said, err := session(cmd, host, options, []string{
|
||||||
|
"ls -1 " + directory,
|
||||||
"get " + authorized + " " + quoted(into),
|
"get " + authorized + " " + quoted(into),
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if absent(said) {
|
if directoryAbsent(said) {
|
||||||
return "", nil
|
return "", false, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
return "", err
|
if absent(said) {
|
||||||
|
return "", true, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
return "", false, err
|
||||||
}
|
}
|
||||||
|
|
||||||
//nolint:gosec // the path is a temporary file of the tool's own
|
//nolint:gosec // the path is a temporary file of the tool's own
|
||||||
content, err := os.ReadFile(into)
|
content, err := os.ReadFile(into)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", fmt.Errorf("reading the fetched file: %w", err)
|
return "", false, fmt.Errorf("reading the fetched file: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
return string(content), nil
|
return string(content), true, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// directoryAbsent says whether sftp reported .ssh itself as not being
|
||||||
|
// there, which is the one listing failure read as a host that has no
|
||||||
|
// authorized_keys yet. The reading is taken only from the line in which
|
||||||
|
// sftp reports on that directory: any other failure of the listing, in
|
||||||
|
// particular a directory that is there but cannot be entered, is left
|
||||||
|
// as a failure, so that no key is written to a host whose keys were
|
||||||
|
// never read.
|
||||||
|
func directoryAbsent(said string) bool {
|
||||||
|
for line := range strings.Lines(said) {
|
||||||
|
named, is := reportedCannotList(strings.TrimSpace(line))
|
||||||
|
if is && (named == directory ||
|
||||||
|
strings.HasSuffix(named, "/"+directory)) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// reportedCannotList returns the path an sftp line reports it cannot
|
||||||
|
// list for want of the directory, and whether the line is such a
|
||||||
|
// report. The client writes this one wording when the directory a
|
||||||
|
// listing names is not there, giving the path the server expanded.
|
||||||
|
func reportedCannotList(line string) (string, bool) {
|
||||||
|
const (
|
||||||
|
before = `Can't ls: "`
|
||||||
|
after = `" not found`
|
||||||
|
)
|
||||||
|
|
||||||
|
if !strings.HasPrefix(line, before) ||
|
||||||
|
!strings.HasSuffix(line, after) {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
|
||||||
|
return strings.TrimSuffix(strings.TrimPrefix(line, before), after), true
|
||||||
}
|
}
|
||||||
|
|
||||||
// absent says whether sftp reported the file that was asked for as
|
// absent says whether sftp reported the file that was asked for as
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ import "testing"
|
|||||||
const (
|
const (
|
||||||
echoed = `sftp> get .ssh/authorized_keys "/tmp/keyfunc/authorized_keys"
|
echoed = `sftp> get .ssh/authorized_keys "/tmp/keyfunc/authorized_keys"
|
||||||
`
|
`
|
||||||
|
listed = "sftp> ls -1 .ssh\n"
|
||||||
warning = `Warning: Identity file /gone not accessible: ` +
|
warning = `Warning: Identity file /gone not accessible: ` +
|
||||||
"No such file or directory.\n"
|
"No such file or directory.\n"
|
||||||
)
|
)
|
||||||
@@ -76,3 +77,57 @@ func TestAbsenceIsReadOnlyFromWhatSFTPSaidAboutAuthorizedKeys(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestTheDirectoryIsReadAsAbsentOnlyFromTheListingSayingSo holds the
|
||||||
|
// wordings the OpenSSH client was seen to use when a listing fails: a
|
||||||
|
// directory it cannot find is reported one way, and one it cannot enter
|
||||||
|
// another, and only the first is read as a host with no .ssh yet.
|
||||||
|
func TestTheDirectoryIsReadAsAbsentOnlyFromTheListingSayingSo(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
listings := map[string]struct {
|
||||||
|
said string
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
"the directory is not there": {
|
||||||
|
said: listed + `Can't ls: "/home/someone/.ssh" not found` + "\n",
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
"the directory is not there, named as it was asked for": {
|
||||||
|
said: listed + `Can't ls: ".ssh" not found` + "\n",
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
"the directory is not there and an identity file is not either": {
|
||||||
|
said: warning + listed +
|
||||||
|
`Can't ls: "/home/someone/.ssh" not found` + "\n",
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
"the directory is there and cannot be entered": {
|
||||||
|
said: listed +
|
||||||
|
`remote readdir("/home/someone/.ssh/"): Permission denied` + "\n",
|
||||||
|
want: false,
|
||||||
|
},
|
||||||
|
"some other directory is not there": {
|
||||||
|
said: listed + `Can't ls: "/home/someone/.config" not found` + "\n",
|
||||||
|
want: false,
|
||||||
|
},
|
||||||
|
"the connection did not come up": {
|
||||||
|
said: "ssh: connect to host example.com port 22: " +
|
||||||
|
"Connection refused\nConnection closed\n",
|
||||||
|
want: false,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for name, listing := range listings {
|
||||||
|
t.Run(name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
if directoryAbsent(listing.said) != listing.want {
|
||||||
|
t.Errorf(
|
||||||
|
"read as absent: %t, wanted %t, from:\n%s",
|
||||||
|
!listing.want, listing.want, listing.said,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+122
-21
@@ -68,13 +68,18 @@ const keyLine = vectorZero + " keyfunc/ssh/0\n"
|
|||||||
// work. A command that begins with a dash may fail; any other failure
|
// work. A command that begins with a dash may fail; any other failure
|
||||||
// ends the session, as it does in sftp's own batch mode.
|
// ends the session, as it does in sftp's own batch mode.
|
||||||
//
|
//
|
||||||
// The two ways a get can fail are worded as the OpenSSH client words
|
// The listing and the two ways a get can fail are worded as the
|
||||||
// them, both naming the path the server expanded: a file that is not
|
// OpenSSH client words them, each naming the path the server expanded.
|
||||||
// there, which is the one failure the tool reads as an empty file, and
|
// A listing fails one way when .ssh is not there and another when it is
|
||||||
// a file that is there and cannot be read, which is not. An -i naming
|
// there but shut to the user; the first is the only failure read as a
|
||||||
// a file that is not here draws the warning ssh writes for it, which
|
// host with no file. A get fails one way for a file that is not there,
|
||||||
// carries the wording of a missing file into a session that goes on to
|
// which after a listing that came up empty is also read as no file, and
|
||||||
// authenticate.
|
// another for a file that is there and cannot be read, which is a
|
||||||
|
// failure. A directory shut to the user is stood in for by mode 000,
|
||||||
|
// which the listing reads off the mode itself so that the test does not
|
||||||
|
// turn on the user it runs as. An -i naming a file that is not here
|
||||||
|
// draws the warning ssh writes for it, which carries the wording of a
|
||||||
|
// missing file into a session that goes on to authenticate.
|
||||||
const installer = `
|
const installer = `
|
||||||
previous=
|
previous=
|
||||||
for argument in "$@"; do
|
for argument in "$@"; do
|
||||||
@@ -99,6 +104,23 @@ while IFS= read -r line; do
|
|||||||
eval "set -- $line"
|
eval "set -- $line"
|
||||||
worked=yes
|
worked=yes
|
||||||
case "$1" in
|
case "$1" in
|
||||||
|
ls)
|
||||||
|
dir=$2
|
||||||
|
[ "$dir" = -1 ] && dir=$3
|
||||||
|
if [ ! -e "$home/$dir" ]; then
|
||||||
|
worked=no
|
||||||
|
printf 'Can'\''t ls: "%s" not found\n' "$home/$dir" >&2
|
||||||
|
elif [ -d "$home/$dir" ] && [ "$(stat -c '%a' "$home/$dir")" = 0 ]; then
|
||||||
|
worked=no
|
||||||
|
printf 'remote readdir("%s/"): Permission denied\n' \
|
||||||
|
"$home/$dir" >&2
|
||||||
|
else
|
||||||
|
for entry in "$home/$dir"/*; do
|
||||||
|
[ -e "$entry" ] || continue
|
||||||
|
printf '%s/%s\n' "$dir" "$(basename "$entry")"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
;;
|
||||||
get)
|
get)
|
||||||
if [ ! -e "$home/$2" ]; then
|
if [ ! -e "$home/$2" ]; then
|
||||||
worked=no
|
worked=no
|
||||||
@@ -176,8 +198,8 @@ func TestAKeyThatIsAlreadyThereIsLeftAlone(t *testing.T) {
|
|||||||
require.Equal(t, "already present\n", install(t, host))
|
require.Equal(t, "already present\n", install(t, host))
|
||||||
require.Equal(t, "somebody else\n"+keyLine, read(t, path))
|
require.Equal(t, "somebody else\n"+keyLine, read(t, path))
|
||||||
|
|
||||||
// The fetch and nothing after it: the tool did not connect again.
|
// The read and nothing after it: the tool did not connect again.
|
||||||
require.Len(t, recorded(t, pretend.batch), 1)
|
require.Equal(t, 1, connections(t, pretend))
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestAnEmptyFileGetsTheKeyAndNoBlankLineBeforeIt(t *testing.T) {
|
func TestAnEmptyFileGetsTheKeyAndNoBlankLineBeforeIt(t *testing.T) {
|
||||||
@@ -218,7 +240,9 @@ func TestTheFileIsUploadedBesideTheOldOneAndThenRenamedOverIt(t *testing.T) {
|
|||||||
strings.HasPrefix(beside, ".ssh/authorized_keys.keyfunc-"),
|
strings.HasPrefix(beside, ".ssh/authorized_keys.keyfunc-"),
|
||||||
)
|
)
|
||||||
|
|
||||||
require.True(t, strings.HasPrefix(sent[0], "get .ssh/authorized_keys "))
|
// The listing fails on a host with no .ssh, so the get never runs;
|
||||||
|
// the write session then makes the directory and puts the file.
|
||||||
|
require.Equal(t, "ls -1 .ssh", sent[0])
|
||||||
require.Equal(t, "-mkdir .ssh", sent[1])
|
require.Equal(t, "-mkdir .ssh", sent[1])
|
||||||
require.Equal(t, "chmod 700 .ssh", sent[2])
|
require.Equal(t, "chmod 700 .ssh", sent[2])
|
||||||
require.Equal(t, "put", strings.Fields(sent[3])[0])
|
require.Equal(t, "put", strings.Fields(sent[3])[0])
|
||||||
@@ -237,12 +261,57 @@ func TestAFileThatCannotBeReadIsNotWrittenOver(t *testing.T) {
|
|||||||
require.Empty(t, printed)
|
require.Empty(t, printed)
|
||||||
require.Contains(t, said, "Permission denied")
|
require.Contains(t, said, "Permission denied")
|
||||||
|
|
||||||
// The fetch and nothing after it, and what was on the host is
|
// The read and nothing after it, and what was on the host is
|
||||||
// still what is on the host.
|
// still what is on the host.
|
||||||
require.Len(t, recorded(t, pretend.batch), 1)
|
require.Equal(t, 1, connections(t, pretend))
|
||||||
require.DirExists(t, unreadable)
|
require.DirExists(t, unreadable)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAnUnreadableDirectoryIsNotWrittenInto(t *testing.T) {
|
||||||
|
t.Setenv(mnemonic.Variable, example())
|
||||||
|
|
||||||
|
pretend := pretendHost(t)
|
||||||
|
unlistable(t, pretend)
|
||||||
|
|
||||||
|
// The listing is refused, which is not the same as no directory, so
|
||||||
|
// the tool writes nothing rather than treat a directory it cannot
|
||||||
|
// enter as a host with no file.
|
||||||
|
printed, said, err := attempt(t, host)
|
||||||
|
require.Error(t, err)
|
||||||
|
require.Empty(t, printed)
|
||||||
|
require.Contains(t, said, "Permission denied")
|
||||||
|
|
||||||
|
// The read and nothing after it: no second connection wrote a key.
|
||||||
|
require.Equal(t, 1, connections(t, pretend))
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAnExistingDirectoryKeepsItsModeAndIsNotRemade(t *testing.T) {
|
||||||
|
t.Setenv(mnemonic.Variable, example())
|
||||||
|
|
||||||
|
pretend := pretendHost(t)
|
||||||
|
|
||||||
|
// A directory that is there but holds no file yet, made with a mode
|
||||||
|
// of its own so that a stray chmod would show.
|
||||||
|
const ownMode = 0o755
|
||||||
|
|
||||||
|
directory := filepath.Join(pretend.home, keptUnder)
|
||||||
|
require.NoError(t, os.Mkdir(directory, ownMode))
|
||||||
|
|
||||||
|
require.Equal(t, "added\n", install(t, host))
|
||||||
|
|
||||||
|
// The key is added and the directory keeps the mode it had: the
|
||||||
|
// write session neither made it nor set its mode.
|
||||||
|
require.Equal(t, keyLine, read(t, filepath.Join(directory, keptIn)))
|
||||||
|
|
||||||
|
kept, err := os.Stat(directory)
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, os.FileMode(ownMode), kept.Mode().Perm())
|
||||||
|
|
||||||
|
sent := recorded(t, pretend.batch)
|
||||||
|
require.NotContains(t, sent, "-mkdir .ssh")
|
||||||
|
require.NotContains(t, sent, "chmod 700 .ssh")
|
||||||
|
}
|
||||||
|
|
||||||
func TestAWarningAboutAnotherFileIsNotTakenForTheOneAskedFor(t *testing.T) {
|
func TestAWarningAboutAnotherFileIsNotTakenForTheOneAskedFor(t *testing.T) {
|
||||||
t.Setenv(mnemonic.Variable, example())
|
t.Setenv(mnemonic.Variable, example())
|
||||||
|
|
||||||
@@ -259,7 +328,7 @@ func TestAWarningAboutAnotherFileIsNotTakenForTheOneAskedFor(t *testing.T) {
|
|||||||
require.Contains(t, said, "No such file or directory")
|
require.Contains(t, said, "No such file or directory")
|
||||||
require.Contains(t, said, "Permission denied")
|
require.Contains(t, said, "Permission denied")
|
||||||
|
|
||||||
require.Len(t, recorded(t, pretend.batch), 1)
|
require.Equal(t, 1, connections(t, pretend))
|
||||||
require.DirExists(t, unreadable)
|
require.DirExists(t, unreadable)
|
||||||
|
|
||||||
// The same run again, this way for the status it ends with.
|
// The same run again, this way for the status it ends with.
|
||||||
@@ -279,9 +348,9 @@ func TestAFailedStepNamesTheUploadedFileAndChangesNothing(t *testing.T) {
|
|||||||
|
|
||||||
pretend := pretendHost(t)
|
pretend := pretendHost(t)
|
||||||
|
|
||||||
// A file where the .ssh directory belongs: nothing is there to
|
// A file where the .ssh directory belongs: the listing shows it and
|
||||||
// fetch, and then the put has nowhere to put anything, so the
|
// so the directory reads as already there, but then the put has
|
||||||
// write session ends at the put.
|
// nowhere to put anything, so the write session ends at the put.
|
||||||
inTheWay := filepath.Join(pretend.home, keptUnder)
|
inTheWay := filepath.Join(pretend.home, keptUnder)
|
||||||
require.NoError(t,
|
require.NoError(t,
|
||||||
os.WriteFile(inTheWay, []byte(notADirectory), fileMode),
|
os.WriteFile(inTheWay, []byte(notADirectory), fileMode),
|
||||||
@@ -292,12 +361,12 @@ func TestAFailedStepNamesTheUploadedFileAndChangesNothing(t *testing.T) {
|
|||||||
require.Empty(t, printed)
|
require.Empty(t, printed)
|
||||||
require.Contains(t, said, "put failed")
|
require.Contains(t, said, "put failed")
|
||||||
|
|
||||||
// The put is the last command the session got to, and the file it
|
// The put is the first and last command the write session got to,
|
||||||
// was uploading is the one the message names.
|
// and the file it was uploading is the one the message names.
|
||||||
sent := recorded(t, pretend.batch)
|
sent := recorded(t, pretend.batch)
|
||||||
require.Len(t, sent, 4)
|
require.Len(t, sent, 3)
|
||||||
require.Equal(t, "put", strings.Fields(sent[3])[0])
|
require.Equal(t, "put", strings.Fields(sent[2])[0])
|
||||||
require.Contains(t, err.Error(), strings.Fields(sent[3])[2])
|
require.Contains(t, err.Error(), strings.Fields(sent[2])[2])
|
||||||
|
|
||||||
require.Equal(t, notADirectory, read(t, inTheWay))
|
require.Equal(t, notADirectory, read(t, inTheWay))
|
||||||
|
|
||||||
@@ -455,6 +524,38 @@ func unfetchable(t *testing.T, pretend pretended) string {
|
|||||||
return path
|
return path
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// unlistable puts a .ssh on the stand-in host that is there but shut to
|
||||||
|
// the user, a directory of mode 000, and gives back its path. Its mode
|
||||||
|
// is put back before the temporary directory is cleared so that it can
|
||||||
|
// be.
|
||||||
|
func unlistable(t *testing.T, pretend pretended) string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
directory := filepath.Join(pretend.home, keptUnder)
|
||||||
|
require.NoError(t, os.Mkdir(directory, directoryMode))
|
||||||
|
require.NoError(t, os.Chmod(directory, 0))
|
||||||
|
|
||||||
|
t.Cleanup(func() { _ = os.Chmod(directory, directoryMode) })
|
||||||
|
|
||||||
|
return directory
|
||||||
|
}
|
||||||
|
|
||||||
|
// connections returns how many times the tool ran sftp, counted from
|
||||||
|
// the -b that opens each session's arguments.
|
||||||
|
func connections(t *testing.T, pretend pretended) int {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
count := 0
|
||||||
|
|
||||||
|
for _, argument := range recorded(t, pretend.arguments) {
|
||||||
|
if argument == "-b" {
|
||||||
|
count++
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return count
|
||||||
|
}
|
||||||
|
|
||||||
// pretendCall puts the to stand-in on the path and gives back the file
|
// pretendCall puts the to stand-in on the path and gives back the file
|
||||||
// the arguments are written down in and the file the agent socket is
|
// the arguments are written down in and the file the agent socket is
|
||||||
// noted in.
|
// noted in.
|
||||||
|
|||||||
Reference in New Issue
Block a user