2008-03-12 13:58:55 +01:00
|
|
|
# $OpenBSD: agent-getpeereid.sh,v 1.4 2007/11/25 15:35:09 jmc Exp $
|
2003-01-22 07:53:16 +01:00
|
|
|
# Placed in the Public Domain.
|
|
|
|
|
|
|
|
tid="disallow agent attach from other uid"
|
|
|
|
|
|
|
|
UNPRIV=nobody
|
|
|
|
ASOCK=${OBJ}/agent
|
2008-03-12 13:58:55 +01:00
|
|
|
SSH_AUTH_SOCK=/nonexistent
|
2003-01-22 07:53:16 +01:00
|
|
|
|
2007-03-21 11:45:48 +01:00
|
|
|
if grep "#undef.*HAVE_GETPEEREID" ${BUILDDIR}/config.h >/dev/null 2>&1 && \
|
|
|
|
grep "#undef.*HAVE_GETPEERUCRED" ${BUILDDIR}/config.h >/dev/null && \
|
|
|
|
grep "#undef.*HAVE_SO_PEERCRED" ${BUILDDIR}/config.h >/dev/null
|
2003-09-04 05:49:30 +02:00
|
|
|
then
|
|
|
|
echo "skipped (not supported on this platform)"
|
|
|
|
exit 0
|
|
|
|
fi
|
2006-07-24 07:31:41 +02:00
|
|
|
if [ -z "$SUDO" ]; then
|
|
|
|
echo "skipped: need SUDO to switch to uid $UNPRIV"
|
|
|
|
exit 0
|
|
|
|
fi
|
|
|
|
|
2003-09-04 05:49:30 +02:00
|
|
|
|
2003-01-22 07:53:16 +01:00
|
|
|
trace "start agent"
|
|
|
|
eval `${SSHAGENT} -s -a ${ASOCK}` > /dev/null
|
|
|
|
r=$?
|
|
|
|
if [ $r -ne 0 ]; then
|
|
|
|
fail "could not start ssh-agent: exit code $r"
|
|
|
|
else
|
|
|
|
chmod 644 ${SSH_AUTH_SOCK}
|
|
|
|
|
|
|
|
ssh-add -l > /dev/null 2>&1
|
|
|
|
r=$?
|
|
|
|
if [ $r -ne 1 ]; then
|
|
|
|
fail "ssh-add failed with $r != 1"
|
|
|
|
fi
|
|
|
|
|
2006-01-31 12:02:16 +01:00
|
|
|
< /dev/null ${SUDO} -S -u ${UNPRIV} ssh-add -l > /dev/null 2>&1
|
2003-01-22 07:53:16 +01:00
|
|
|
r=$?
|
|
|
|
if [ $r -lt 2 ]; then
|
|
|
|
fail "ssh-add did not fail for ${UNPRIV}: $r < 2"
|
|
|
|
fi
|
|
|
|
|
|
|
|
trace "kill agent"
|
|
|
|
${SSHAGENT} -k > /dev/null
|
|
|
|
fi
|
|
|
|
|
|
|
|
rm -f ${OBJ}/agent
|