From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp11.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms9.migadu.com with LMTPS id QC5lDm34QGQ1GQAASxT56A (envelope-from ) for ; Thu, 20 Apr 2023 10:31:41 +0200 Received: from aspmx1.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp11.migadu.com with LMTPS id uKJ4Dm34QGTdawEA9RJhRA (envelope-from ) for ; Thu, 20 Apr 2023 10:31:41 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 9FA9F3670A for ; Thu, 20 Apr 2023 10:31:40 +0200 (CEST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ppPh2-00040g-IR; Thu, 20 Apr 2023 04:31:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ppPh0-0003z9-Rf for guix-patches@gnu.org; Thu, 20 Apr 2023 04:31:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1ppPh0-0008HR-Jc for guix-patches@gnu.org; Thu, 20 Apr 2023 04:31:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ppPh0-00020m-GC for guix-patches@gnu.org; Thu, 20 Apr 2023 04:31:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#62461] [PATCH v2 1/4] gnu: home-openssh-configuration: Add field add-keys-to-agent. References: <87bkkfaa2x.fsf@ngraves.fr> In-Reply-To: <87bkkfaa2x.fsf@ngraves.fr> Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Thu, 20 Apr 2023 08:31:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 62461 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 62461@debbugs.gnu.org Cc: ngraves@ngraves.fr Received: via spool by 62461-submit@debbugs.gnu.org id=B62461.16819794197625 (code B ref 62461); Thu, 20 Apr 2023 08:31:02 +0000 Received: (at 62461) by debbugs.gnu.org; 20 Apr 2023 08:30:19 +0000 Received: from localhost ([127.0.0.1]:36469 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ppPgJ-0001yu-3l for submit@debbugs.gnu.org; Thu, 20 Apr 2023 04:30:19 -0400 Received: from 4.mo560.mail-out.ovh.net ([87.98.172.75]:41131) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ppPgG-0001yk-Ll for 62461@debbugs.gnu.org; Thu, 20 Apr 2023 04:30:18 -0400 Received: from director11.ghost.mail-out.ovh.net (unknown [10.108.16.31]) by mo560.mail-out.ovh.net (Postfix) with ESMTP id 01EF62259B for <62461@debbugs.gnu.org>; Thu, 20 Apr 2023 08:30:14 +0000 (UTC) Received: from ghost-submission-6684bf9d7b-hvph2 (unknown [10.108.20.29]) by director11.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 515381FE5F; Thu, 20 Apr 2023 08:30:14 +0000 (UTC) Received: from ngraves.fr ([37.59.142.103]) by ghost-submission-6684bf9d7b-hvph2 with ESMTPSA id MWyHChb4QGSvlQMA80Xfbw (envelope-from ); Thu, 20 Apr 2023 08:30:14 +0000 X-OVh-ClientIp: 81.67.140.142 Date: Thu, 20 Apr 2023 10:30:07 +0200 Message-Id: <20230420083010.12285-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.39.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 17876475770965517026 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvhedrfedtvddgtdefucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffogggtgfesthekredtredtjeenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeetveehffevvdfgtddthedvhfeguefggeffteetueeliedvhffhjeegudehleegheenucfkphepuddvjedrtddrtddruddpkedurdeijedrudegtddrudegvddpfeejrdehledrudegvddruddtfeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqpdhnsggprhgtphhtthhopedupdhrtghpthhtohepiedvgeeiudesuggvsggsuhhgshdrghhnuhdrohhrghdpoffvtefjohhsthepmhhoheeitddpmhhouggvpehsmhhtphhouhht X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches From: Nicolas Graves via Guix-patches via Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Country: US X-Migadu-Flow: FLOW_IN ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=none) header.from=gnu.org ARC-Seal: i=1; s=key1; d=yhetil.org; t=1681979501; a=rsa-sha256; cv=none; b=slGBKinHfca9PxRfV+yBIwqGm3aPwssG35WQnWti6/U42ttqkj5R7yHLy4KAI/+SU4q7wj Y957WDDr3JxwjeqAENhXy0c7lnEqPXrcqTf+0fEF8XtD9OD/Kk/5tb8q1JX3/fnLNxNraJ rv37pE+GLwt+YNXa14vEqqG4D6yTabZZliohxnJETEV+/WBMBQ1q3Pzhv6czeWOZ9dIiHJ N7PcPrdTgbVYWaXrNQCWwJqj+wr1gfikZbY/smaiCNpnjhUVioN9oDpbM863i3c6mxF+j8 SGxH7UBk1XOez2bqZ2j4IzuBmg2aBMTfYsMPqjNdpKhhJc867ajMMc4uXbKshw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1681979501; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post; bh=QSoU0558Mc21gBrrm1Zp92ikRmEiWoIbLpW5JBmtM/0=; b=dmm+yF/gUgBvwQxKM9ubpvJa34mU5s+yR372/a1CIvaYhzofrI5LhFY6YwOlOBkP2fmFOP Lk1tRq5f7X5M5ezTx1om/rq6hOlAmz8I7pQhauQRra8oB++9V6pOEffXYbyAI60i5qONsT CTnvXAdZjIWdQhssSo3PnoHAmyHg75p/KR/l7iz+gRfveBd2ng+R9W0LtMEZZTWDWIG0Ne 4IUOrVyJ5BNbCY7l4hZqJvSlDr0Ci9fQp9E/Xbd2Pmr1BL6miosVJrLmuPRcoxyYKYEBka oomIJESMmNN9nc10u4dcrYIMwR2QWVVpuYeuITy6cIA1CwAgVZxPk1MNWtNaLQ== X-Migadu-Spam-Score: -4.51 X-Spam-Score: -4.51 X-Migadu-Queue-Id: 9FA9F3670A X-Migadu-Scanner: scn0.migadu.com Authentication-Results: aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=none) header.from=gnu.org X-TUID: 6/CBJ/7WSk+A --- doc/guix.texi | 14 +++++++++++++ gnu/home/services/ssh.scm | 44 +++++++++++++++++++++++++++++++-------- 2 files changed, 49 insertions(+), 9 deletions(-) diff --git a/doc/guix.texi b/doc/guix.texi index 5973ea86cc..daefe63074 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -42601,6 +42601,20 @@ Concretely, these files are concatenated and made available as running on this machine, then it @emph{may} take this file into account: this is what @command{sshd} does by default, but be aware that it can also be configured to ignore it. + +@item @code{add-keys-to-agent} (default: @code{``no''}) +This string specifies whether keys should be automatically added to a +running ssh-agent. If this option is set to @code{``yes''} and a key is +loaded from a file, the key and its passphrase are added to the agent +with the default lifetime, as if by @code{ssh-add}. If this option is +set to @code{``ask''}, @code{ssh} will require confirmation. If this +option is set to @code{``confirm''}, each use of the key must be +confirmed. If this option is set to @code{``no''}, no keys are added to +the agent. Alternately, this option may be specified as a time interval +to specify the key's lifetime in @code{ssh-agent}, after which it will +automatically be removed. The argument must be @code{``no''}, +@code{``yes''}, @code{``confirm''} (optionally followed by a time +interval), @code{``ask''} or a time interval. @end table @end deftp diff --git a/gnu/home/services/ssh.scm b/gnu/home/services/ssh.scm index 01917a29cd..4ab2adb292 100644 --- a/gnu/home/services/ssh.scm +++ b/gnu/home/services/ssh.scm @@ -1,6 +1,7 @@ ;;; GNU Guix --- Functional package management for GNU ;;; Copyright © 2022 Ludovic Courtès ;;; Copyright © 2023 Janneke Nieuwenhuizen +;;; Copyright © 2023 Nicolas Graves ;;; ;;; This file is part of GNU Guix. ;;; @@ -39,6 +40,7 @@ (define-module (gnu home services ssh) home-openssh-configuration-authorized-keys home-openssh-configuration-known-hosts home-openssh-configuration-hosts + home-openssh-configuration-add-keys-to-agent home-ssh-agent-configuration openssh-host @@ -185,17 +187,41 @@ (define (openssh-host-name-field? field) (define-record-type* home-openssh-configuration make-home-openssh-configuration home-openssh-configuration? - (authorized-keys home-openssh-configuration-authorized-keys ;list of file-like - (default '())) - (known-hosts home-openssh-configuration-known-hosts ;unspec | list of file-like - (default *unspecified*)) - (hosts home-openssh-configuration-hosts ;list of - (default '()))) + (authorized-keys home-openssh-configuration-authorized-keys ;list of file-like + (default '())) + (known-hosts home-openssh-configuration-known-hosts ;unspec | list of file-like + (default *unspecified*)) + (hosts home-openssh-configuration-hosts ;list of + (default '())) + (add-keys-to-agent home-openssh-configuration-add-keys-to-agent ;string with limited values + (default "no"))) + +(define (serialize-add-keys-to-agent value) + (define (is-valid-time-string? str) + (and (> (string-length str) 0) + (eq? + (cdr (vector-ref + (string-match "\ +[0-9]+|([0-9]+[Ww])?([0-9]+[Dd])?([0-9]+[Hh])?([0-9]+[Mm])?([0-9]+[Ss])?" str) + 1)) + (string-length str)))) + + (string-append "AddKeysToAgent " + (cond ((member value '("yes" "no" "confirm" "ask")) value) + ((is-valid-time-string? value) value) + ((and (string-prefix? "confirm" value) + (is-valid-time-string? + (cdr (string-split value #\ )))) value) + ;; The 'else' branch is unreachable. + (else (raise (condition (&error))))))) (define (openssh-configuration->string config) - (string-join (map serialize-openssh-host - (home-openssh-configuration-hosts config)) - "\n")) + (string-join + (cons* (serialize-add-keys-to-agent + (home-openssh-configuration-add-keys-to-agent config)) + (map serialize-openssh-host + (home-openssh-configuration-hosts config))) + "\n")) (define* (file-join name files #:optional (delimiter " ")) "Return a file in the store called @var{name} that is the concatenation -- 2.39.2