blob: 34bced154f726ecf48249a5790d7068bd82b7167 [file] [log] [blame]
djm@openbsd.org01cfaa22017-01-06 02:51:16 +00001# $OpenBSD: agent-getpeereid.sh,v 1.8 2017/01/06 02:51:16 djm Exp $
Damien Miller8b9cde72003-01-22 17:53:16 +11002# Placed in the Public Domain.
3
4tid="disallow agent attach from other uid"
5
6UNPRIV=nobody
7ASOCK=${OBJ}/agent
Damien Millerd666d8e2008-03-12 23:58:55 +11008SSH_AUTH_SOCK=/nonexistent
Damien Miller8b9cde72003-01-22 17:53:16 +11009
Tim Rice6dfcd342011-01-16 22:53:56 -080010if config_defined HAVE_GETPEEREID HAVE_GETPEERUCRED HAVE_SO_PEERCRED ; then
11 :
12else
Darren Tucker2297ac42003-09-04 13:49:30 +100013 echo "skipped (not supported on this platform)"
14 exit 0
15fi
djm@openbsd.org07d56082016-05-03 14:41:04 +000016case "x$SUDO" in
17 xsudo) sudo=1;;
18 xdoas) ;;
19 x)
20 echo "need SUDO to switch to uid $UNPRIV"
21 exit 0 ;;
22 *)
23 echo "unsupported $SUDO - "doas" and "sudo" are allowed"
24 exit 0 ;;
25esac
Damien Miller7b1877c2006-07-24 15:31:41 +100026
Damien Miller8b9cde72003-01-22 17:53:16 +110027trace "start agent"
28eval `${SSHAGENT} -s -a ${ASOCK}` > /dev/null
29r=$?
30if [ $r -ne 0 ]; then
31 fail "could not start ssh-agent: exit code $r"
32else
33 chmod 644 ${SSH_AUTH_SOCK}
34
djm@openbsd.org01cfaa22017-01-06 02:51:16 +000035 ${SSHADD} -l > /dev/null 2>&1
Damien Miller8b9cde72003-01-22 17:53:16 +110036 r=$?
37 if [ $r -ne 1 ]; then
38 fail "ssh-add failed with $r != 1"
39 fi
djm@openbsd.org07d56082016-05-03 14:41:04 +000040 if test -z "$sudo" ; then
41 # doas
djm@openbsd.org01cfaa22017-01-06 02:51:16 +000042 ${SUDO} -n -u ${UNPRIV} ${SSHADD} -l 2>/dev/null
djm@openbsd.org07d56082016-05-03 14:41:04 +000043 else
44 # sudo
djm@openbsd.org01cfaa22017-01-06 02:51:16 +000045 < /dev/null ${SUDO} -S -u ${UNPRIV} ${SSHADD} -l 2>/dev/null
djm@openbsd.org07d56082016-05-03 14:41:04 +000046 fi
Damien Miller8b9cde72003-01-22 17:53:16 +110047 r=$?
48 if [ $r -lt 2 ]; then
49 fail "ssh-add did not fail for ${UNPRIV}: $r < 2"
50 fi
51
52 trace "kill agent"
53 ${SSHAGENT} -k > /dev/null
54fi
55
56rm -f ${OBJ}/agent