ssh-agent: improvements (#6309)
* ssh-agent: lock this script with a mkdir style mutex
This script is a kind of singleton pattern and is not reentrant.
If several shells are oppened in a fast sequence, then several
independent ssh-agents would be created, which is not acceptable.
A mutex is required.
Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>
* ssh-agent: only start agent if .ssh dir exists
To use the same profile system-wide, it might happen
that the .ssh directory does not exist
(typically $HOME/.ssh/). This would trigger a error.
Creating the directory would be a option, but it
usually will not make sense to do so because it means
the user doesn't have ssh keys or config.
Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>
* ssh-agent: adds lazy option to disable key loading on start
Option is documented on updated README.md
Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>
* ssh-agent: simplify agent-forwarding checking
Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>
Co-authored-by: Robby Russell <robby@planetargon.com>
Diff
1diff --git a/plugins/ssh-agent/README.md b/plugins/ssh-agent/README.md
2index 8765a9c7ea9aaaa7229996570aef96317bf77930..aa96f9cc9eeb413238d71100a44bb8e89b1ca332 100644
3--- a/plugins/ssh-agent/README.md
4+++ b/plugins/ssh-agent/README.md
5@@ -19,9 +19,17 @@ To enable **agent forwarding support** add the following to your zshrc file:
6 zstyle :omz:plugins:ssh-agent agent-forwarding on
7 ```
8 9-----
10+To **NOT load any identities on start** use the `lazy` style.
11+This is particularly usefull when combined with the AddKeysToAgent
12+(available from OpenSSH 7.2), since it allows to enter the password only
13+on first use.
14+
15+```zsh
16+zstyle :omz:plugins:ssh-agent lazy yes
17+```
1819-To **load multiple identities** use the `identities` style, For example:
20+To **load multiple identities** use the `identities` style. This have no
21+effect if `lazy` is enabled.
2223 ```zsh
24 zstyle :omz:plugins:ssh-agent identities id_rsa id_rsa2 id_github
25diff --git a/plugins/ssh-agent/ssh-agent.plugin.zsh b/plugins/ssh-agent/ssh-agent.plugin.zsh
26index d45406f63837dfc7adc770e73855df4aa436e3da..494cf1393db61fffda3cec6f473df6f1b9d738fa 100644
27--- a/plugins/ssh-agent/ssh-agent.plugin.zsh
28+++ b/plugins/ssh-agent/ssh-agent.plugin.zsh
29@@ -1,4 +1,16 @@
30-typeset _agent_forwarding _ssh_env_cache
31+lockdir=/tmp/oh-my-zsh-ssh-agent.lock
32+
33+while true; do
34+ if mkdir "$lockdir" 2>/dev/null
35+ then # directory did not exist, but was created successfully
36+ trap 'rm -rf "$lockdir"' 0 # remove directory when script finishes
37+ break # continue with script
38+ else
39+ sleep 0.1 # sleep for 0.2 and try again
40+ fi
41+done
42+
43+typeset _ssh_env_cache
4445 function _start_agent() {
46 local lifetime
47@@ -56,10 +68,7 @@ function _add_identities() {
48 # Get the filename to store/lookup the environment from
49 _ssh_env_cache="$HOME/.ssh/environment-$SHORT_HOST"
5051-# test if agent-forwarding is enabled
52-zstyle -b :omz:plugins:ssh-agent agent-forwarding _agent_forwarding
53-
54-if [[ $_agent_forwarding == "yes" && -n "$SSH_AUTH_SOCK" ]]; then
55+if zstyle -t :omz:plugins:ssh-agent agent-forwarding && [[ -n "$SSH_AUTH_SOCK" ]]; then
56 # Add a nifty symlink for screen/tmux if agent forwarding
57 [[ -L $SSH_AUTH_SOCK ]] || ln -sf "$SSH_AUTH_SOCK" /tmp/ssh-agent-$USERNAME-screen
58 elif [[ -f "$_ssh_env_cache" ]]; then
59@@ -73,12 +82,16 @@ elif [[ -f "$_ssh_env_cache" ]]; then
60 ps $FILTER | grep ssh-agent | grep -q $SSH_AGENT_PID || {
61 _start_agent
62 }
63-else
64+elif [[ -d $HOME/.ssh ]]; then
65 _start_agent
66 fi
6768-_add_identities
69+if ! zstyle -t :omz:plugins:ssh-agent lazy; then
70+ _add_identities
71+fi
7273 # tidy up after ourselves
74-unset _agent_forwarding _ssh_env_cache
75+unset _ssh_env_cache
76 unfunction _start_agent _add_identities
77+
78+rm -rf "$lockdir"