2024-04-12 12:21:05 +02:00
|
|
|
package ssh
|
2023-09-19 21:31:41 +02:00
|
|
|
|
|
|
|
import (
|
2024-04-12 12:21:05 +02:00
|
|
|
"fmt"
|
2023-09-23 17:12:35 +02:00
|
|
|
"io"
|
|
|
|
"net"
|
|
|
|
|
2024-10-26 14:56:17 +02:00
|
|
|
"github.com/semaphoreui/semaphore/pkg/task_logger"
|
2023-09-19 21:31:41 +02:00
|
|
|
"golang.org/x/crypto/ssh"
|
|
|
|
"golang.org/x/crypto/ssh/agent"
|
|
|
|
)
|
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
type AgentKey struct {
|
2023-09-19 21:31:41 +02:00
|
|
|
Key []byte
|
|
|
|
Passphrase []byte
|
2023-09-23 17:12:35 +02:00
|
|
|
}
|
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
type Agent struct {
|
|
|
|
Keys []AgentKey
|
2024-04-12 12:32:54 +02:00
|
|
|
Logger task_logger.Logger
|
2023-09-19 21:31:41 +02:00
|
|
|
listener net.Listener
|
2023-09-23 17:12:35 +02:00
|
|
|
SocketFile string
|
2023-09-19 21:31:41 +02:00
|
|
|
done chan struct{}
|
|
|
|
}
|
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
func NewAgent() Agent {
|
|
|
|
return Agent{}
|
|
|
|
}
|
2023-09-23 17:12:35 +02:00
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
func (a *Agent) Listen() error {
|
2023-09-19 21:31:41 +02:00
|
|
|
keyring := agent.NewKeyring()
|
2023-09-23 17:12:35 +02:00
|
|
|
|
|
|
|
for _, k := range a.Keys {
|
2024-04-12 12:21:05 +02:00
|
|
|
var (
|
|
|
|
key interface{}
|
|
|
|
err error
|
|
|
|
)
|
2023-09-23 17:12:35 +02:00
|
|
|
|
|
|
|
if len(k.Passphrase) == 0 {
|
|
|
|
key, err = ssh.ParseRawPrivateKey(k.Key)
|
|
|
|
} else {
|
|
|
|
key, err = ssh.ParseRawPrivateKeyWithPassphrase(k.Key, k.Passphrase)
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
2024-04-12 12:21:05 +02:00
|
|
|
return fmt.Errorf("parsing private key: %w", err)
|
2023-09-23 17:12:35 +02:00
|
|
|
}
|
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
if err := keyring.Add(agent.AddedKey{
|
|
|
|
PrivateKey: key,
|
|
|
|
}); err != nil {
|
|
|
|
return fmt.Errorf("adding private key: %w", err)
|
2023-09-23 17:12:35 +02:00
|
|
|
}
|
2023-09-19 21:31:41 +02:00
|
|
|
}
|
2023-09-23 17:12:35 +02:00
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
l, err := net.ListenUnix(
|
|
|
|
"unix",
|
|
|
|
&net.UnixAddr{
|
|
|
|
Net: "unix",
|
|
|
|
Name: a.SocketFile,
|
|
|
|
},
|
|
|
|
)
|
|
|
|
|
2023-09-19 21:31:41 +02:00
|
|
|
if err != nil {
|
2024-04-12 12:21:05 +02:00
|
|
|
return fmt.Errorf("listening on socket %q: %w", a.SocketFile, err)
|
2023-09-19 21:31:41 +02:00
|
|
|
}
|
2024-04-12 12:21:05 +02:00
|
|
|
|
2023-09-19 21:31:41 +02:00
|
|
|
l.SetUnlinkOnClose(true)
|
|
|
|
a.listener = l
|
|
|
|
a.done = make(chan struct{})
|
|
|
|
|
|
|
|
go func() {
|
|
|
|
for {
|
|
|
|
conn, err := a.listener.Accept()
|
2024-04-12 12:21:05 +02:00
|
|
|
|
2023-09-19 21:31:41 +02:00
|
|
|
if err != nil {
|
|
|
|
select {
|
|
|
|
case <-a.done:
|
|
|
|
return
|
|
|
|
default:
|
2024-04-12 12:21:05 +02:00
|
|
|
a.Logger.Logf("error accepting socket connection: %w", err)
|
2023-09-19 21:31:41 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
go func(conn net.Conn) {
|
|
|
|
defer conn.Close()
|
|
|
|
|
|
|
|
if err := agent.ServeAgent(keyring, conn); err != nil && err != io.EOF {
|
2024-04-12 12:21:05 +02:00
|
|
|
a.Logger.Logf("error serving SSH agent listener: %w", err)
|
2023-09-19 21:31:41 +02:00
|
|
|
}
|
|
|
|
}(conn)
|
|
|
|
}
|
|
|
|
}()
|
2024-04-12 12:21:05 +02:00
|
|
|
|
2023-09-19 21:31:41 +02:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2024-04-12 12:21:05 +02:00
|
|
|
func (a *Agent) Close() error {
|
2023-09-19 21:31:41 +02:00
|
|
|
close(a.done)
|
|
|
|
return a.listener.Close()
|
|
|
|
}
|