ssh-agent: check for loaded id filenames first (#7521)
This change makes the plugin check if an identity is loaded by looking
first at the key filename reported by `ssh-add -l`. This fixes the use
case where ssh-keygen is not able to output the fingerprint of a key,
such as the one reported on #7516.
Now, for an identity to be passed onto ssh-add, it has to fail the
match for a loaded identity, both filename and signature.
Diff
1diff --git a/plugins/ssh-agent/ssh-agent.plugin.zsh b/plugins/ssh-agent/ssh-agent.plugin.zsh
2index 0a204309e303886af9e831be40406a9c46acb2d7..a7a4ee33add10a9978e2f7df2baeb4464e9a1705 100644
3--- a/plugins/ssh-agent/ssh-agent.plugin.zsh
4+++ b/plugins/ssh-agent/ssh-agent.plugin.zsh
5@@ -13,7 +13,7 @@ function _start_agent() {
6 7 function _add_identities() {
8 local id line sig
9- local -a identities loaded not_loaded signatures
10+ local -a identities loaded_sigs loaded_ids not_loaded
11 zstyle -a :omz:plugins:ssh-agent identities identities
1213 # check for .ssh folder presence
14@@ -31,19 +31,19 @@ function _add_identities() {
15 done
16 fi
1718- # get list of loaded identities' signatures
19- for line in ${(f)"$(ssh-add -l)"}; do loaded+=${${(z)line}[2]}; done
20-
21- # get signatures of private keys
22- for id in $identities; do
23- signatures+="$(ssh-keygen -lf "$HOME/.ssh/$id" | awk '{print $2}') $id"
24+ # get list of loaded identities' signatures and filenames
25+ for line in ${(f)"$(ssh-add -l)"}; do
26+ loaded_sigs+=${${(z)line}[2]}
27+ loaded_ids+=${${(z)line}[3]}
28 done
2930 # add identities if not already loaded
31- for sig in $signatures; do
32- id="$(cut -f2 <<< $sig)"
33- sig="$(cut -f1 <<< $sig)"
34- [[ ${loaded[(I)$sig]} -le 0 ]] && not_loaded+="$HOME/.ssh/$id"
35+ for id in $identities; do
36+ # check for filename match, otherwise try for signature match
37+ if [[ ${loaded_ids[(I)$HOME/.ssh/$id]} -le 0 ]]; then
38+ sig="$(ssh-keygen -lf "$HOME/.ssh/$id" | awk '{print $2}')"
39+ [[ ${loaded_sigs[(I)$sig]} -le 0 ]] && not_loaded+="$HOME/.ssh/$id"
40+ fi
41 done
4243 [[ -n "$not_loaded" ]] && ssh-add ${^not_loaded}