regress test for ExposeAuthInfo
authordjm <djm@openbsd.org>
Sat, 24 Jun 2017 06:35:24 +0000 (06:35 +0000)
committerdjm <djm@openbsd.org>
Sat, 24 Jun 2017 06:35:24 +0000 (06:35 +0000)
regress/usr.bin/ssh/Makefile
regress/usr.bin/ssh/authinfo.sh [new file with mode: 0644]

index 8a9cb58..80de10c 100644 (file)
@@ -1,4 +1,4 @@
-#      $OpenBSD: Makefile,v 1.94 2016/12/16 03:51:19 dtucker Exp $
+#      $OpenBSD: Makefile,v 1.95 2017/06/24 06:35:24 djm Exp $
 
 .ifndef SKIP_UNIT
 SUBDIR=                unittests
@@ -72,7 +72,8 @@ LTESTS=       connect \
                principals-command \
                cert-file \
                cfginclude \
-               allow-deny-users
+               allow-deny-users \
+               authinfo
 
 INTEROP_TESTS= putty-transfer putty-ciphers putty-kex conch-ciphers
 #INTEROP_TESTS+=ssh-com ssh-com-client ssh-com-keygen ssh-com-sftp
diff --git a/regress/usr.bin/ssh/authinfo.sh b/regress/usr.bin/ssh/authinfo.sh
new file mode 100644 (file)
index 0000000..e725296
--- /dev/null
@@ -0,0 +1,17 @@
+#      $OpenBSD: authinfo.sh,v 1.1 2017/06/24 06:35:24 djm Exp $
+#      Placed in the Public Domain.
+
+tid="authinfo"
+
+# Ensure the environment variable doesn't leak when ExposeAuthInfo=no.
+verbose "ExposeAuthInfo=no"
+env SSH_USER_AUTH=blah ${SSH} -F $OBJ/ssh_proxy x \
+       'test -z "$SSH_USER_AUTH"' || fail "SSH_USER_AUTH present"
+
+verbose "ExposeAuthInfo=yes"
+echo ExposeAuthInfo=yes >> $OBJ/sshd_proxy
+${SSH} -F $OBJ/ssh_proxy x \
+       'grep ^publickey "$SSH_USER_AUTH" /dev/null >/dev/null' ||
+       fail "ssh with ExposeAuthInfo failed"
+
+# XXX test multiple auth and key contents