From patchwork Mon Jun 5 12:34:45 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 50688 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 287D627BBE9; Mon, 5 Jun 2023 13:35:40 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=BAYES_00,MAILING_LIST_MULTI, SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 5CC1327BBE2 for ; Mon, 5 Jun 2023 13:35:38 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1q69QN-0005OC-MJ; Mon, 05 Jun 2023 08:35:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1q69QM-0005Nn-Lb for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1q69QM-0003LM-BT for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1q69QM-0003mx-7Y for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#62461] [PATCH v3 1/4] gnu: home-openssh-configuration: Add field add-keys-to-agent. References: <87bkkfaa2x.fsf@ngraves.fr> In-Reply-To: <87bkkfaa2x.fsf@ngraves.fr> Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 05 Jun 2023 12:35:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 62461 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 62461@debbugs.gnu.org Cc: ngraves@ngraves.fr Received: via spool by 62461-submit@debbugs.gnu.org id=B62461.168596849814530 (code B ref 62461); Mon, 05 Jun 2023 12:35:02 +0000 Received: (at 62461) by debbugs.gnu.org; 5 Jun 2023 12:34:58 +0000 Received: from localhost ([127.0.0.1]:48372 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QI-0003mD-0Q for submit@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:58 -0400 Received: from 2.mo583.mail-out.ovh.net ([178.33.109.111]:34307) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QE-0003le-6v for 62461@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:55 -0400 Received: from director8.ghost.mail-out.ovh.net (unknown [10.109.146.240]) by mo583.mail-out.ovh.net (Postfix) with ESMTP id 3EC1027F08 for <62461@debbugs.gnu.org>; Mon, 5 Jun 2023 12:34:52 +0000 (UTC) Received: from ghost-submission-6684bf9d7b-zv2bm (unknown [10.110.103.36]) by director8.ghost.mail-out.ovh.net (Postfix) with ESMTPS id C2B761FEC7; Mon, 5 Jun 2023 12:34:51 +0000 (UTC) Received: from ngraves.fr ([37.59.142.96]) by ghost-submission-6684bf9d7b-zv2bm with ESMTPSA id 7f95KWvWfWQOGQAAzuo5lw (envelope-from ); Mon, 05 Jun 2023 12:34:51 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-96R001e830973b-8155-400c-8fd3-f2263fd004a0, 24BD45A8C995C08D5395E1BF3FBF1E19C8C2E420) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 81.67.140.142 Date: Mon, 5 Jun 2023 14:34:45 +0200 Message-Id: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> X-Mailer: git-send-email 2.40.1 MIME-Version: 1.0 X-Ovh-Tracer-Id: 15450724424086971106 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvhedrfeelledgheefucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffogggtgfesthekredtredtjeenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeetveehffevvdfgtddthedvhfeguefggeffteetueeliedvhffhjeegudehleegheenucfkphepuddvjedrtddrtddruddpkedurdeijedrudegtddrudegvddpfeejrdehledrudegvddrleeinecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpeeonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqedpnhgspghrtghpthhtohepuddprhgtphhtthhopeeivdegieduseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkeefpdhmohguvgepshhmthhpohhuth X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches --- doc/guix.texi | 14 ++++++++++++ gnu/home/services/ssh.scm | 48 +++++++++++++++++++++++++++++++-------- 2 files changed, 53 insertions(+), 9 deletions(-) base-commit: eed55a6544d5bda2245ec853e5fa4b28e1865bea prerequisite-patch-id: a057b35ab55298bad50caab186b3e692a25230e1 prerequisite-patch-id: fb9054f780e6f97b92f00fdbe56058d1188ccf0a prerequisite-patch-id: ca2f2591980b80c5cf27846e59e323bdc5a06b00 prerequisite-patch-id: ae5ad13b181ebb3c31d529af50622e3b78641442 prerequisite-patch-id: 34ed6acb0a1e5f79b5f6d18a6d4ef70cd97bf7ad prerequisite-patch-id: 10d52b209b6e9c771050eef67ce566e79ab55c49 prerequisite-patch-id: e78e2a6daf59564caf5d2affe04ea7dde07f76c6 prerequisite-patch-id: 6aad4df7b83bfd5c2da38d9c2f80fba749f607b5 prerequisite-patch-id: da6a2d63ebb0ba1abb0b7c569d353724d900f95f prerequisite-patch-id: 6279cff75e76e262f6ec82518db1fdf4c1810303 prerequisite-patch-id: 44453fcf2f2c38212a47d45d43ddcfa98167fabe prerequisite-patch-id: 641eae2fa3842045ebe6072ad78214002f818221 prerequisite-patch-id: c19de9ee8c57210cbffc79945e69a858639f39bf prerequisite-patch-id: 9833a747398a641803e203f8293382f55ad24ed1 prerequisite-patch-id: 94d5340918e3626726b6d32d93bf47425751898f prerequisite-patch-id: e18164416e2c070b0b71f770c90d4c04af2635c1 prerequisite-patch-id: 31e98ea035053a965e87ad0164030cf909922d9e prerequisite-patch-id: a1cf1f5c4a0ff2804fac986a69ffbc0328300afe prerequisite-patch-id: 2a54e276f79fb57113a0be11e1ea2c07fdc2727d prerequisite-patch-id: a463de1ba17ecb39588dfbd46c3bc5f9e0fb1b1c prerequisite-patch-id: 3188de66dfc4bcb71f90601822428701528f4a98 prerequisite-patch-id: 6c93f771a1eca0747fd92a770fe750e2f15d8e52 prerequisite-patch-id: 12b76e9c2751da73ed64c9489b15f74ff17568cf prerequisite-patch-id: eb618ab7b10483d917c308a38792af98baa517e2 prerequisite-patch-id: a471a4b7839bfb0ee9a3fd53ed962d729d38bd94 prerequisite-patch-id: 5e58202cc87a257c78033dafa62ffae4383e3718 prerequisite-patch-id: cd7f69695aa47b7e1b1160841fe842a3acd160e7 prerequisite-patch-id: b542cf4087eeee1ee3f7fc03b7c39896417bc7b5 prerequisite-patch-id: 843773f53ca319821185f9f9bc43ad905f081ee7 prerequisite-patch-id: a2dfb2fba1e1a3c8e270823022b6f462d27f17c8 diff --git a/doc/guix.texi b/doc/guix.texi index f620d0eb35..d5f81f6fcd 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -43102,6 +43102,20 @@ Secure Shell running on this machine, then it @emph{may} take this file into account: this is what @command{sshd} does by default, but be aware that it can also be configured to ignore it. + +@item @code{add-keys-to-agent} (default: @code{``no''}) +This string specifies whether keys should be automatically added to a +running ssh-agent. If this option is set to @code{``yes''} and a key is +loaded from a file, the key and its passphrase are added to the agent +with the default lifetime, as if by @code{ssh-add}. If this option is +set to @code{``ask''}, @code{ssh} will require confirmation. If this +option is set to @code{``confirm''}, each use of the key must be +confirmed. If this option is set to @code{``no''}, no keys are added to +the agent. Alternately, this option may be specified as a time interval +to specify the key's lifetime in @code{ssh-agent}, after which it will +automatically be removed. The argument must be @code{``no''}, +@code{``yes''}, @code{``confirm''} (optionally followed by a time +interval), @code{``ask''} or a time interval. @end table @end deftp diff --git a/gnu/home/services/ssh.scm b/gnu/home/services/ssh.scm index 628dc743ae..2de78eb1c4 100644 --- a/gnu/home/services/ssh.scm +++ b/gnu/home/services/ssh.scm @@ -1,6 +1,7 @@ ;;; GNU Guix --- Functional package management for GNU ;;; Copyright © 2022 Ludovic Courtès ;;; Copyright © 2023 Janneke Nieuwenhuizen +;;; Copyright © 2023 Nicolas Graves ;;; ;;; This file is part of GNU Guix. ;;; @@ -42,6 +43,7 @@ (define-module (gnu home services ssh) home-openssh-configuration-authorized-keys home-openssh-configuration-known-hosts home-openssh-configuration-hosts + home-openssh-configuration-add-keys-to-agent home-ssh-agent-configuration openssh-host @@ -248,17 +250,45 @@ (define (serialize-openssh-host config) (define-record-type* home-openssh-configuration make-home-openssh-configuration home-openssh-configuration? - (authorized-keys home-openssh-configuration-authorized-keys ;list of file-like - (default #f)) - (known-hosts home-openssh-configuration-known-hosts ;unspec | list of file-like - (default *unspecified*)) - (hosts home-openssh-configuration-hosts ;list of - (default '()))) + (authorized-keys home-openssh-configuration-authorized-keys ;list of file-like + (default #f)) + (known-hosts home-openssh-configuration-known-hosts ;unspec | list of file-like + (default *unspecified*)) + (hosts home-openssh-configuration-hosts ;list of + (default '())) + (add-keys-to-agent home-openssh-configuration-add-keys-to-agent ;string with limited values + (default "no"))) + +(define (serialize-add-keys-to-agent value) + (define (valid-time-string? str) + (and (> (string-length str) 0) + (equal? + str + (match:substring + (string-match "\ +[0-9]+|([0-9]+[Ww])?([0-9]+[Dd])?([0-9]+[Hh])?([0-9]+[Mm])?([0-9]+[Ss])?" + str))))) + + (string-append "AddKeysToAgent " + (cond ((member value '("yes" "no" "confirm" "ask")) value) + ((valid-time-string? value) value) + ((and (string-prefix? "confirm" value) + (valid-time-string? + (cdr (string-split value #\ )))) value) + ;; The 'else' branch is unreachable. + (else + (raise + (formatted-message + (G_ "~s: invalid 'add-keys-to-agent' value") + value)))))) (define (openssh-configuration->string config) - (string-join (map serialize-openssh-host - (home-openssh-configuration-hosts config)) - "\n")) + (string-join + (cons* (serialize-add-keys-to-agent + (home-openssh-configuration-add-keys-to-agent config)) + (map serialize-openssh-host + (home-openssh-configuration-hosts config))) + "\n")) (define* (file-join name files #:optional (delimiter " ")) "Return a file in the store called @var{name} that is the concatenation From patchwork Mon Jun 5 12:34:46 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 50689 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 679BE27BBEA; Mon, 5 Jun 2023 13:35:46 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=BAYES_00,MAILING_LIST_MULTI, SPF_HELO_PASS autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 3BFB127BBE2 for ; Mon, 5 Jun 2023 13:35:45 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1q69QN-0005OB-Lm; Mon, 05 Jun 2023 08:35:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1q69QM-0005Ne-68 for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1q69QL-0003L4-TE for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:01 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1q69QL-0003mq-OS for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:01 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#62461] [PATCH v3 2/4] gnu: openssh-host: Add option match-criteria. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 05 Jun 2023 12:35:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 62461 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 62461@debbugs.gnu.org Cc: ngraves@ngraves.fr Received: via spool by 62461-submit@debbugs.gnu.org id=B62461.168596849814524 (code B ref 62461); Mon, 05 Jun 2023 12:35:01 +0000 Received: (at 62461) by debbugs.gnu.org; 5 Jun 2023 12:34:58 +0000 Received: from localhost ([127.0.0.1]:48370 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QH-0003m5-DG for submit@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:57 -0400 Received: from 19.mo583.mail-out.ovh.net ([46.105.35.78]:50975) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QE-0003lf-71 for 62461@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:55 -0400 Received: from director5.ghost.mail-out.ovh.net (unknown [10.109.143.223]) by mo583.mail-out.ovh.net (Postfix) with ESMTP id DBDCE27EF6 for <62461@debbugs.gnu.org>; Mon, 5 Jun 2023 12:34:52 +0000 (UTC) Received: from ghost-submission-6684bf9d7b-4bkl9 (unknown [10.110.115.222]) by director5.ghost.mail-out.ovh.net (Postfix) with ESMTPS id AA6E61FEDA; Mon, 5 Jun 2023 12:34:52 +0000 (UTC) Received: from ngraves.fr ([37.59.142.101]) by ghost-submission-6684bf9d7b-4bkl9 with ESMTPSA id Fqs5KGzWfWT+/RwA+WDKPw (envelope-from ); Mon, 05 Jun 2023 12:34:52 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-101G0049967e2d1-9c97-4ec1-bf8b-b75b09343d76, 24BD45A8C995C08D5395E1BF3FBF1E19C8C2E420) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 81.67.140.142 Date: Mon, 5 Jun 2023 14:34:46 +0200 Message-Id: X-Mailer: git-send-email 2.40.1 In-Reply-To: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> References: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> MIME-Version: 1.0 X-Ovh-Tracer-Id: 15450724424003609314 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvhedrfeelledgheefucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepiedtteetteekfeetheethfduvedvgeevkeeljedvleeigeeuuedtgedvheetieejnecuffhomhgrihhnpegvgigrmhhplhgvrdhorhhgnecukfhppeduvdejrddtrddtrddupdekuddrieejrddugedtrddugedvpdefjedrheelrddugedvrddutddunecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpeeonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqedpnhgspghrtghpthhtohepuddprhgtphhtthhopeeivdegieduseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkeefpdhmohguvgepshhmthhpohhuth X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches --- doc/guix.texi | 12 +++++++- gnu/home/services/ssh.scm | 58 ++++++++++++++++++++++++++++++++++----- 2 files changed, 62 insertions(+), 8 deletions(-) diff --git a/doc/guix.texi b/doc/guix.texi index d5f81f6fcd..a3d5f8446d 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -43126,11 +43126,21 @@ Secure Shell @table @asis @item @code{name} (type: string) -Name of this host declaration. +Name of this host declaration. A @code{openssh-host} must define only +@code{name} or @code{match-criteria}. Use host-name @code{\"*\"} for +top-level options. @item @code{host-name} (type: maybe-string) Host name---e.g., @code{"foo.example.org"} or @code{"192.168.1.2"}. +@item @code{match-criteria} (type: maybe-match-criteria) +When specified, this string denotes the set of hosts to which the entry +applies, superseding the @code{host-name} field. Its first element must be +all or one of @code{ssh-match-keywords}. The rest of the elements are +arguments for the keyword, or other criteria. A @code{openssh-host} must +define only @code{name} or @code{match-criteria}. Other host configuration +options will apply to all hosts matching @code{match-criteria}. + @item @code{address-family} (type: maybe-address-family) Address family to use when connecting to this host: one of @code{AF_INET} (for IPv4 only), @code{AF_INET6} (for IPv6 only). diff --git a/gnu/home/services/ssh.scm b/gnu/home/services/ssh.scm index 2de78eb1c4..017bbbc2dd 100644 --- a/gnu/home/services/ssh.scm +++ b/gnu/home/services/ssh.scm @@ -48,6 +48,7 @@ (define-module (gnu home services ssh) openssh-host openssh-host-host-name + openssh-host-match-criteria openssh-host-identity-file openssh-host-name openssh-host-port @@ -95,7 +96,11 @@ (define (serialize-address-family field family) (cond ((= family AF_INET) "inet") ((= family AF_INET6) "inet6") ;; The 'else' branch is unreachable. - (else (raise (condition (&error))))) + (else + (raise + (formatted-message + (G_ "~s: invalid 'address-family' value") + value)))) "\n") "")) @@ -173,13 +178,40 @@ (define (sanitize-proxy-command properties) (configuration-field-error (source-properties->location properties) 'proxy-command value)) value)) +(define ssh-match-keywords + '(canonical final exec host originalhost user localuser)) + +(define (match-criteria? str) + ;; Rule out the case of "all" keyword. + (if (member str '("all" + "canonical all" + "final all")) + #t + (let* ((first (string-take str (string-index str #\ ))) + (keyword (string->symbol (if (string-prefix? "!" first) + (string-drop first 1) + first)))) + (memq keyword ssh-match-keywords)))) + +(define-maybe match-criteria) + (define-configuration openssh-host (name - (string) - "Name of this host declaration.") + maybe-string + "Name of this host declaration. A @code{openssh-host} must define only +@code{name} or @code{match-criteria}. Use host-name @code{\"*\"} for +top-level options.") (host-name maybe-string "Host name---e.g., @code{\"foo.example.org\"} or @code{\"192.168.1.2\"}.") + (match-criteria ;TODO implement stricter match-criteria rules + maybe-match-criteria + "When specified, this string denotes the set of hosts to which the entry +applies, superseding the @code{host-name} field. Its first element must be +all or one of @code{ssh-match-keywords}. The rest of the elements are +arguments for the keyword, or other criteria. A @code{openssh-host} must +define only @code{name} or @code{match-criteria}. Other host configuration +options will apply to all hosts matching @code{match-criteria}.") (address-family maybe-address-family "Address family to use when connecting to this host: one of @@ -234,17 +266,29 @@ (define-configuration openssh-host @file{~/.ssh/config}.")) (define (serialize-openssh-host config) - (define (openssh-host-name-field? field) - (eq? (configuration-field-name field) 'name)) + (define (openssh-host-name-or-match-field? field) + (or (eq? (configuration-field-name field) 'name) + (eq? (configuration-field-name field) 'match-criteria))) (string-append - "Host " (openssh-host-name config) "\n" + (if (maybe-value-set? (openssh-host-name config)) + (if (maybe-value-set? (openssh-host-match-criteria config)) + (raise + (formatted-message + (G_ "You must either define name or match-criteria, not both."))) + (string-append "Host " (openssh-host-name config) "\n")) + (if (maybe-value-set? (openssh-host-match-criteria config)) + (string-append + "Match " (string-join (openssh-host-match-criteria config) " ") "\n") + (raise + (formatted-message + (G_ "You must either define name or match-criteria once."))))) (string-concatenate (map (lambda (field) ((configuration-field-serializer field) (configuration-field-name field) ((configuration-field-getter field) config))) - (remove openssh-host-name-field? + (remove openssh-host-name-or-match-field? openssh-host-fields))))) (define-record-type* From patchwork Mon Jun 5 12:34:47 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 50687 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 0224D27BBE9; Mon, 5 Jun 2023 13:35:27 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=BAYES_00,MAILING_LIST_MULTI, SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 9333E27BBE2 for ; Mon, 5 Jun 2023 13:35:25 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1q69QQ-0005P7-4z; Mon, 05 Jun 2023 08:35:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1q69QN-0005Nu-2T for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:03 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1q69QM-0003LT-Os for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1q69QM-0003n5-KF for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#62461] [PATCH v3 3/4] gnu: ssh: Export configuration predicates. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 05 Jun 2023 12:35:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 62461 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 62461@debbugs.gnu.org Cc: ngraves@ngraves.fr Received: via spool by 62461-submit@debbugs.gnu.org id=B62461.168596850114540 (code B ref 62461); Mon, 05 Jun 2023 12:35:02 +0000 Received: (at 62461) by debbugs.gnu.org; 5 Jun 2023 12:35:01 +0000 Received: from localhost ([127.0.0.1]:48374 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QK-0003mR-Mf for submit@debbugs.gnu.org; Mon, 05 Jun 2023 08:35:00 -0400 Received: from 5.mo560.mail-out.ovh.net ([87.98.181.248]:44869) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QF-0003lh-G3 for 62461@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:56 -0400 Received: from director5.ghost.mail-out.ovh.net (unknown [10.109.146.240]) by mo560.mail-out.ovh.net (Postfix) with ESMTP id 0404B272F4 for <62461@debbugs.gnu.org>; Mon, 5 Jun 2023 12:34:53 +0000 (UTC) Received: from ghost-submission-6684bf9d7b-264qh (unknown [10.110.103.53]) by director5.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 6E7921FEB0; Mon, 5 Jun 2023 12:34:53 +0000 (UTC) Received: from ngraves.fr ([37.59.142.98]) by ghost-submission-6684bf9d7b-264qh with ESMTPSA id 7agnGW3WfWQqzwAA5scIhA (envelope-from ); Mon, 05 Jun 2023 12:34:53 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-98R0026c410208-30f3-450c-8245-d6963315b05f, 24BD45A8C995C08D5395E1BF3FBF1E19C8C2E420) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 81.67.140.142 Date: Mon, 5 Jun 2023 14:34:47 +0200 Message-Id: <81f8bc18e5c5fd461dbec41308fa3ecf84264b7f.1685968477.git.ngraves@ngraves.fr> X-Mailer: git-send-email 2.40.1 In-Reply-To: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> References: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> MIME-Version: 1.0 X-Ovh-Tracer-Id: 15451005900218295010 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvhedrfeelledgheefucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepleffjeetueethfefkeffffefvddukeejkefgleduiedthfekvefhiedvhfffgeegnecukfhppeduvdejrddtrddtrddupdekuddrieejrddugedtrddugedvpdefjedrheelrddugedvrdelkeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqpdhnsggprhgtphhtthhopedupdhrtghpthhtohepiedvgeeiudesuggvsggsuhhgshdrghhnuhdrohhrghdpoffvtefjohhsthepmhhoheeitddpmhhouggvpehsmhhtphhouhht X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches --- gnu/home/services/ssh.scm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gnu/home/services/ssh.scm b/gnu/home/services/ssh.scm index 017bbbc2dd..4ff3395e06 100644 --- a/gnu/home/services/ssh.scm +++ b/gnu/home/services/ssh.scm @@ -44,7 +44,9 @@ (define-module (gnu home services ssh) home-openssh-configuration-known-hosts home-openssh-configuration-hosts home-openssh-configuration-add-keys-to-agent + home-openssh-configuration? home-ssh-agent-configuration + home-ssh-agent-configuration? openssh-host openssh-host-host-name From patchwork Mon Jun 5 12:34:48 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 50686 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id C187A27BBE9; Mon, 5 Jun 2023 13:35:16 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=BAYES_00,MAILING_LIST_MULTI, SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 8C1D027BBE2 for ; Mon, 5 Jun 2023 13:35:15 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1q69QP-0005P3-VW; Mon, 05 Jun 2023 08:35:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1q69QN-0005O8-H4 for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:03 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1q69QN-0003La-7p for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:03 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1q69QN-0003nC-42 for guix-patches@gnu.org; Mon, 05 Jun 2023 08:35:03 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#62461] [PATCH v3 4/4] gnu: ssh: Export home-ssh-agent variables. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 05 Jun 2023 12:35:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 62461 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 62461@debbugs.gnu.org Cc: ngraves@ngraves.fr Received: via spool by 62461-submit@debbugs.gnu.org id=B62461.168596850114553 (code B ref 62461); Mon, 05 Jun 2023 12:35:03 +0000 Received: (at 62461) by debbugs.gnu.org; 5 Jun 2023 12:35:01 +0000 Received: from localhost ([127.0.0.1]:48376 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QK-0003mT-V7 for submit@debbugs.gnu.org; Mon, 05 Jun 2023 08:35:01 -0400 Received: from 11.mo550.mail-out.ovh.net ([188.165.48.29]:40125) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1q69QG-0003lk-73 for 62461@debbugs.gnu.org; Mon, 05 Jun 2023 08:34:57 -0400 Received: from director9.ghost.mail-out.ovh.net (unknown [10.108.20.212]) by mo550.mail-out.ovh.net (Postfix) with ESMTP id E0D4B23A44 for <62461@debbugs.gnu.org>; Mon, 5 Jun 2023 12:34:54 +0000 (UTC) Received: from ghost-submission-6684bf9d7b-qzgcb (unknown [10.110.115.32]) by director9.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 86B0E1FECB; Mon, 5 Jun 2023 12:34:54 +0000 (UTC) Received: from ngraves.fr ([37.59.142.109]) by ghost-submission-6684bf9d7b-qzgcb with ESMTPSA id fQUkGW7WfWQdGQAAfdoIHA (envelope-from ); Mon, 05 Jun 2023 12:34:54 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-109S0037d9146de-195a-4e63-a59b-fc162f0403e7, 24BD45A8C995C08D5395E1BF3FBF1E19C8C2E420) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 81.67.140.142 Date: Mon, 5 Jun 2023 14:34:48 +0200 Message-Id: <301925a934e8b44f00e6f421dc678c6d4bbe0590.1685968477.git.ngraves@ngraves.fr> X-Mailer: git-send-email 2.40.1 In-Reply-To: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> References: <6e0836e1ad23b625b912f2aa0893c2c0b1f4e37c.1685968477.git.ngraves@ngraves.fr> MIME-Version: 1.0 X-Ovh-Tracer-Id: 15451287372113830626 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvhedrfeelledgheegucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepleffjeetueethfefkeffffefvddukeejkefgleduiedthfekvefhiedvhfffgeegnecukfhppeduvdejrddtrddtrddupdekuddrieejrddugedtrddugedvpdefjedrheelrddugedvrddutdelnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpeeonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqedpnhgspghrtghpthhtohepuddprhgtphhtthhopeeivdegieduseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehhedtpdhmohguvgepshhmthhpohhuth X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches --- gnu/home/services/ssh.scm | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/gnu/home/services/ssh.scm b/gnu/home/services/ssh.scm index 4ff3395e06..3053a88fad 100644 --- a/gnu/home/services/ssh.scm +++ b/gnu/home/services/ssh.scm @@ -45,7 +45,11 @@ (define-module (gnu home services ssh) home-openssh-configuration-hosts home-openssh-configuration-add-keys-to-agent home-openssh-configuration? + home-ssh-agent-configuration + home-ssh-agent-openssh + home-ssh-agent-socket-directory + home-ssh-agent-extra-options home-ssh-agent-configuration? openssh-host