1#	$OpenBSD: agent-getpeereid.sh,v 1.11 2019/11/26 23:43:10 djm Exp $
2#	Placed in the Public Domain.
3
4tid="disallow agent attach from other uid"
5
6UNPRIV=nobody
7ASOCK=${OBJ}/agent
8SSH_AUTH_SOCK=/nonexistent
9
10case "x$SUDO" in
11	xsudo) sudo=1;;
12	xdoas) ;;
13	x)
14		if [ -x /usr/local/bin/sudo -a -f /etc/sudoers ]; then
15			sudo=1
16			SUDO=/usr/local/sbin/sudo
17		elif [ -f /etc/doas.conf ]; then
18			SUDO=/usr/bin/doas
19		else
20			echo neither sudo and sudoers nor doas.conf exist
21			echo SKIPPED
22			exit 0
23		fi ;;
24	*) fatal 'unsupported $SUDO - "doas" and "sudo" are allowed' ;;
25esac
26
27trace "start agent"
28eval `${SSHAGENT} ${EXTRA_AGENT_ARGS} -s -a ${ASOCK}` > /dev/null
29r=$?
30if [ $r -ne 0 ]; then
31	fail "could not start ssh-agent: exit code $r"
32else
33	chmod 644 ${SSH_AUTH_SOCK}
34
35	${SSHADD} -l > /dev/null 2>&1
36	r=$?
37	if [ $r -ne 1 ]; then
38		fail "ssh-add failed with $r != 1"
39	fi
40	if test -z "$sudo" ; then
41		# doas
42		${SUDO} -n -u ${UNPRIV} ${SSHADD} -l 2>/dev/null
43	else
44		# sudo
45		< /dev/null ${SUDO} -S -u ${UNPRIV} ${SSHADD} -l 2>/dev/null
46	fi
47	r=$?
48	if [ $r -lt 2 ]; then
49		fail "ssh-add did not fail for ${UNPRIV}: $r < 2"
50	fi
51
52	trace "kill agent"
53	${SSHAGENT} -k > /dev/null
54fi
55
56rm -f ${OBJ}/agent
57