* Add SSH Agent as an optional service install Enables gcr-ssh-agent (already shipped via the gnome-keyring dependency) so passphrase-protected SSH keys work from any context: the agent prompts graphically on first use, with opt-in passphrase storage in the keyring. Adds install/remove commands and Install > Service / Remove > Service menu entries. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BReZWvvLsDRUaqgjiRzvZ5 * Clear the agent's SSH_AUTH_SOCK when removing the SSH agent service The socket's ExecStartPost exports SSH_AUTH_SOCK into the user manager with set-environment, which disabling the socket does not undo, so apps launched after removal still pointed at a stopped agent. The environment.d file also has to be deleted before disable reloads the manager, or the generator re-exports it. Only an SSH_AUTH_SOCK pointing at gcr is cleared, so another agent's stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Move SSH Agent setup to Setup > Security Turning on an SSH agent is security configuration of the machine rather than installing software, so it sits with SSHD and the other Setup > Security entries. It hides once enabled, as Sudoless Docker does, and Remove > Service > SSH Agent turns it back off. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: David Heinemeier Hansson <david@hey.com>
55 lines
1.9 KiB
Bash
Executable File
55 lines
1.9 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
set -euo pipefail
|
|
|
|
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
|
|
|
|
test_tmp=$(mktemp -d)
|
|
trap 'rm -rf "$test_tmp"' EXIT
|
|
|
|
mock_bin="$test_tmp/bin"
|
|
mkdir -p "$mock_bin"
|
|
|
|
# A user manager with systemd's two environment blocks: set-environment's, which
|
|
# outlives the socket that wrote it, and the generator's, re-read from
|
|
# environment.d on every reload, which disable triggers.
|
|
cat >"$mock_bin/systemctl" <<'SH'
|
|
#!/bin/bash
|
|
state=$OMARCHY_TEST_MANAGER
|
|
case $2 in
|
|
disable)
|
|
if [[ -f $HOME/.config/environment.d/90-gcr-ssh-agent.conf ]]; then
|
|
echo "SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/gcr/ssh" >"$state/generated"
|
|
else
|
|
: >"$state/generated"
|
|
fi
|
|
;;
|
|
unset-environment) : >"$state/explicit" ;;
|
|
show-environment) cat "$state/generated" "$state/explicit" ;;
|
|
esac
|
|
exit 0
|
|
SH
|
|
chmod +x "$mock_bin/systemctl"
|
|
|
|
run_remove() {
|
|
local explicit="$1"
|
|
|
|
export HOME="$test_tmp/home" XDG_RUNTIME_DIR="$test_tmp/run" OMARCHY_TEST_MANAGER="$test_tmp/manager"
|
|
rm -rf "$HOME" "$OMARCHY_TEST_MANAGER"
|
|
mkdir -p "$HOME/.config/environment.d" "$OMARCHY_TEST_MANAGER"
|
|
echo 'SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/gcr/ssh' >"$HOME/.config/environment.d/90-gcr-ssh-agent.conf"
|
|
echo "SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/gcr/ssh" >"$OMARCHY_TEST_MANAGER/generated"
|
|
echo "$explicit" >"$OMARCHY_TEST_MANAGER/explicit"
|
|
|
|
PATH="$mock_bin:$PATH" "$ROOT/bin/omarchy-remove-service-ssh-agent" >/dev/null
|
|
PATH="$mock_bin:$PATH" systemctl --user show-environment
|
|
}
|
|
|
|
env_after=$(run_remove "SSH_AUTH_SOCK=$test_tmp/run/gcr/ssh")
|
|
[[ -z $env_after ]] || fail "removal leaves no SSH_AUTH_SOCK pointing at the stopped agent" "$env_after"
|
|
pass "removal leaves no SSH_AUTH_SOCK pointing at the stopped agent"
|
|
|
|
env_after=$(run_remove "SSH_AUTH_SOCK=$test_tmp/run/other-agent.sock")
|
|
[[ $env_after == "SSH_AUTH_SOCK=$test_tmp/run/other-agent.sock" ]] || fail "removal keeps an SSH_AUTH_SOCK another agent set" "$env_after"
|
|
pass "removal keeps an SSH_AUTH_SOCK another agent set"
|