a206271460ce49e842b1b410c0424b8c9a0a3d14

Author
Nuno Goncalves <nunojpg@gmail.com>
Committer
GitHub <noreply@github.com>
Date

Message

ssh-agent: improvements (#6309)

* ssh-agent: lock this script with a mkdir style mutex

This script is a kind of singleton pattern and is not reentrant.
If several shells are oppened in a fast sequence, then several
independent ssh-agents would be created, which is not acceptable.
A mutex is required.

Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>

* ssh-agent: only start agent if .ssh dir exists

To use the same profile system-wide, it might happen
that the .ssh directory does not exist
(typically $HOME/.ssh/). This would trigger a error.

Creating the directory would be a option, but it
usually will not make sense to do so because it means
the user doesn't have ssh keys or config.

Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>

* ssh-agent: adds lazy option to disable key loading on start

Option is documented on updated README.md

Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>

* ssh-agent: simplify agent-forwarding checking

Signed-off-by: Nuno Goncalves <nunojpg@gmail.com>

Co-authored-by: Robby Russell <robby@planetargon.com>

Diff

 1diff --git a/plugins/ssh-agent/README.md b/plugins/ssh-agent/README.md
 2index 8765a9c7ea9aaaa7229996570aef96317bf77930..aa96f9cc9eeb413238d71100a44bb8e89b1ca332 100644
 3--- a/plugins/ssh-agent/README.md
 4+++ b/plugins/ssh-agent/README.md
 5@@ -19,9 +19,17 @@ To enable **agent forwarding support** add the following to your zshrc file:
 6 zstyle :omz:plugins:ssh-agent agent-forwarding on
 7 ```
 8 
 9-----
10+To **NOT load any identities on start** use the `lazy` style.
11+This is particularly usefull when combined with the AddKeysToAgent
12+(available from OpenSSH 7.2), since it allows to enter the password only
13+on first use.
14+
15+```zsh
16+zstyle :omz:plugins:ssh-agent lazy yes
17+```
18 
19-To **load multiple identities** use the `identities` style, For example:
20+To **load multiple identities** use the `identities` style. This have no
21+effect if `lazy` is enabled.
22 
23 ```zsh
24 zstyle :omz:plugins:ssh-agent identities id_rsa id_rsa2 id_github
25diff --git a/plugins/ssh-agent/ssh-agent.plugin.zsh b/plugins/ssh-agent/ssh-agent.plugin.zsh
26index d45406f63837dfc7adc770e73855df4aa436e3da..494cf1393db61fffda3cec6f473df6f1b9d738fa 100644
27--- a/plugins/ssh-agent/ssh-agent.plugin.zsh
28+++ b/plugins/ssh-agent/ssh-agent.plugin.zsh
29@@ -1,4 +1,16 @@
30-typeset _agent_forwarding _ssh_env_cache
31+lockdir=/tmp/oh-my-zsh-ssh-agent.lock
32+
33+while true; do
34+    if mkdir "$lockdir" 2>/dev/null
35+    then    # directory did not exist, but was created successfully
36+        trap 'rm -rf "$lockdir"' 0    # remove directory when script finishes
37+        break    # continue with script
38+    else
39+        sleep 0.1  # sleep for 0.2 and try again
40+    fi
41+done
42+
43+typeset _ssh_env_cache
44 
45 function _start_agent() {
46 	local lifetime
47@@ -56,10 +68,7 @@ function _add_identities() {
48 # Get the filename to store/lookup the environment from
49 _ssh_env_cache="$HOME/.ssh/environment-$SHORT_HOST"
50 
51-# test if agent-forwarding is enabled
52-zstyle -b :omz:plugins:ssh-agent agent-forwarding _agent_forwarding
53-
54-if [[ $_agent_forwarding == "yes" && -n "$SSH_AUTH_SOCK" ]]; then
55+if zstyle -t :omz:plugins:ssh-agent agent-forwarding && [[ -n "$SSH_AUTH_SOCK" ]]; then
56 	# Add a nifty symlink for screen/tmux if agent forwarding
57 	[[ -L $SSH_AUTH_SOCK ]] || ln -sf "$SSH_AUTH_SOCK" /tmp/ssh-agent-$USERNAME-screen
58 elif [[ -f "$_ssh_env_cache" ]]; then
59@@ -73,12 +82,16 @@ elif [[ -f "$_ssh_env_cache" ]]; then
60 	ps $FILTER | grep ssh-agent | grep -q $SSH_AGENT_PID || {
61 		_start_agent
62 	}
63-else
64+elif [[ -d $HOME/.ssh ]]; then
65 	_start_agent
66 fi
67 
68-_add_identities
69+if ! zstyle -t :omz:plugins:ssh-agent lazy; then
70+	_add_identities
71+fi
72 
73 # tidy up after ourselves
74-unset _agent_forwarding _ssh_env_cache
75+unset _ssh_env_cache
76 unfunction _start_agent _add_identities
77+
78+rm -rf "$lockdir"