2023-05-12 08:37:42 +02:00
|
|
|
# $OpenBSD: sftp-chroot.sh,v 1.9 2023/05/12 06:37:42 djm Exp $
|
2013-05-17 01:35:26 +02:00
|
|
|
# Placed in the Public Domain.
|
|
|
|
|
|
|
|
tid="sftp in chroot"
|
|
|
|
|
|
|
|
CHROOT=/var/run
|
2018-11-22 09:48:32 +01:00
|
|
|
FILENAME=testdata_${USER}.$$
|
2013-05-17 01:35:26 +02:00
|
|
|
PRIVDATA=${CHROOT}/${FILENAME}
|
2018-11-22 09:48:32 +01:00
|
|
|
trap "${SUDO} rm -f ${PRIVDATA}" 0
|
2013-05-17 01:35:26 +02:00
|
|
|
|
2016-09-26 23:34:38 +02:00
|
|
|
if [ -z "$SUDO" -a ! -w /var/run ]; then
|
2021-09-01 02:50:27 +02:00
|
|
|
skip "need SUDO to create file in /var/run, test won't work without"
|
2013-05-17 01:35:26 +02:00
|
|
|
fi
|
|
|
|
|
2016-02-23 06:12:13 +01:00
|
|
|
if ! $OBJ/check-perm -m chroot "$CHROOT" ; then
|
2021-09-01 02:50:27 +02:00
|
|
|
skip "$CHROOT is unsuitable as ChrootDirectory"
|
2016-02-23 06:12:13 +01:00
|
|
|
fi
|
|
|
|
|
2013-05-17 01:35:26 +02:00
|
|
|
$SUDO sh -c "echo mekmitastdigoat > $PRIVDATA" || \
|
|
|
|
fatal "create $PRIVDATA failed"
|
|
|
|
|
2023-05-12 08:37:42 +02:00
|
|
|
echo "ForceCommand internal-sftp -d /" >> $OBJ/sshd_config
|
|
|
|
|
|
|
|
start_sshd -oChrootDirectory=$CHROOT
|
2013-05-17 01:35:26 +02:00
|
|
|
|
|
|
|
verbose "test $tid: get"
|
2014-02-28 00:19:11 +01:00
|
|
|
${SFTP} -S "$SSH" -F $OBJ/ssh_config host:/${FILENAME} $COPY \
|
2014-02-28 00:19:51 +01:00
|
|
|
>>$TEST_REGRESS_LOGFILE 2>&1 || \
|
2013-05-17 01:35:26 +02:00
|
|
|
fatal "Fetch ${FILENAME} failed"
|
|
|
|
cmp $PRIVDATA $COPY || fail "$PRIVDATA $COPY differ"
|
2023-05-12 08:37:42 +02:00
|
|
|
|
|
|
|
stop_sshd
|
|
|
|
|
|
|
|
verbose "test $tid: match"
|
|
|
|
cat << EOF >> $OBJ/sshd_config
|
|
|
|
Match All
|
|
|
|
ChrootDirectory $CHROOT
|
|
|
|
EOF
|
|
|
|
start_sshd
|
|
|
|
$SUDO sh -c "echo orpheanbeholder > $PRIVDATA" || \
|
|
|
|
fatal "create $PRIVDATA failed"
|
|
|
|
${SFTP} -S "$SSH" -F $OBJ/ssh_config host:/${FILENAME} $COPY \
|
|
|
|
>>$TEST_REGRESS_LOGFILE 2>&1 || \
|
|
|
|
fatal "Fetch ${FILENAME} failed"
|
|
|
|
cmp $PRIVDATA $COPY || fail "$PRIVDATA $COPY differ"
|
|
|
|
|
|
|
|
stop_sshd
|