ssh-agent.plugin.zsh 2.27 KB
Newer Older
1
typeset _agent_forwarding _ssh_env_cache
gwjo's avatar
gwjo committed
2

3
4
5
function _start_agent() {
	local lifetime
	zstyle -s :omz:plugins:ssh-agent lifetime lifetime
6

7
	# start ssh-agent and setup environment
8
	echo Starting ssh-agent...
9
	ssh-agent -s ${lifetime:+-t} ${lifetime} | sed 's/^echo/#echo/' >! $_ssh_env_cache
10
11
	chmod 600 $_ssh_env_cache
	. $_ssh_env_cache > /dev/null
12
}
13

14
function _add_identities() {
15
	local id line sig
16
	local -a identities loaded_sigs loaded_ids not_loaded
17
18
	zstyle -a :omz:plugins:ssh-agent identities identities

19
20
21
22
23
	# check for .ssh folder presence
	if [[ ! -d $HOME/.ssh ]]; then
		return
	fi

24
25
26
27
28
29
30
31
32
33
	# add default keys if no identities were set up via zstyle
	# this is to mimic the call to ssh-add with no identities
	if [[ ${#identities} -eq 0 ]]; then
		# key list found on `ssh-add` man page's DESCRIPTION section
		for id in id_rsa id_dsa id_ecdsa id_ed25519 identity; do
			# check if file exists
			[[ -f "$HOME/.ssh/$id" ]] && identities+=$id
		done
	fi

34
35
36
37
	# get list of loaded identities' signatures and filenames
	for line in ${(f)"$(ssh-add -l)"}; do
		loaded_sigs+=${${(z)line}[2]}
		loaded_ids+=${${(z)line}[3]}
38
	done
39
40

	# add identities if not already loaded
41
42
43
44
45
46
	for id in $identities; do
		# check for filename match, otherwise try for signature match
		if [[ ${loaded_ids[(I)$HOME/.ssh/$id]} -le 0 ]]; then
			sig="$(ssh-keygen -lf "$HOME/.ssh/$id" | awk '{print $2}')"
			[[ ${loaded_sigs[(I)$sig]} -le 0 ]] && not_loaded+="$HOME/.ssh/$id"
		fi
47
	done
48

49
	[[ -n "$not_loaded" ]] && ssh-add ${^not_loaded}
gwjo's avatar
gwjo committed
50
51
}

52
# Get the filename to store/lookup the environment from
53
_ssh_env_cache="$HOME/.ssh/environment-$SHORT_HOST"
54

gwjo's avatar
gwjo committed
55
# test if agent-forwarding is enabled
56
57
58
59
60
61
62
63
zstyle -b :omz:plugins:ssh-agent agent-forwarding _agent_forwarding

if [[ $_agent_forwarding == "yes" && -n "$SSH_AUTH_SOCK" ]]; then
	# Add a nifty symlink for screen/tmux if agent forwarding
	[[ -L $SSH_AUTH_SOCK ]] || ln -sf "$SSH_AUTH_SOCK" /tmp/ssh-agent-$USER-screen
elif [[ -f "$_ssh_env_cache" ]]; then
	# Source SSH settings, if applicable
	. $_ssh_env_cache > /dev/null
64
65
66
67
68
69
	if [[ $USER == "root" ]]; then
		FILTER="ax"
	else
		FILTER="x"
	fi
	ps $FILTER | grep ssh-agent | grep -q $SSH_AGENT_PID || {
70
71
		_start_agent
	}
gwjo's avatar
gwjo committed
72
else
73
	_start_agent
gwjo's avatar
gwjo committed
74
75
fi

76
77
_add_identities

gwjo's avatar
gwjo committed
78
# tidy up after ourselves
79
unset _agent_forwarding _ssh_env_cache
80
unfunction _start_agent _add_identities