Bug#1070725: ssh-agent: take flock on socket file/dir in /tmp

Luca Boccassi <[email protected]>
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <89b9beba914aed05fc5950e0bef08fa4cced654c.camel__18423.7233990402$1715126975$gmane$org@debian.org>
Package: openssh-client
Severity: important

Hi,

The default tmpfiles.d/tmp.conf will soon start cleaning up /tmp/ once
a day, automatically deleting files older than 10 days
(ctime/mtime/atime are all taken into account).

In order to avoid the ssh auth socket in /tmp being deleted while
in use (e.g.: long term session), please patch ssh-agent to take a
flock(2) on the /tmp/ssh-xxx directory while it's running, as per
documentation:

https://www.freedesktop.org/software/systemd/man/latest/tmpfiles.d.html#Age

Aside from this, it would be better to switch the location to
XDG_RUNTIME_DIR (/run/user/UID), as that's more appropriate for per-
user-session ephemeral state. The ssh agent provided by gnupg already
switched some time ago:

SSH_AUTH_SOCK=/run/user/1000/gnupg/S.gpg-agent.ssh

-- 
Kind regards,
Luca Boccassi
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEErCSqx93EIPGOymuRKGv37813JB4FAmY6whMACgkQKGv37813
JB7A3A/9EC2CzfWMcDO/fi9DyK3qBJbbXv/Mlw0xbzToSIVZsJmeYDGEm7Gz/31P
20Ognk6GoqhCXHfudf1RJt3TyIb5u7DxBnLAa0ggYbai2tZd0mFrQsRCxG0EBKlr
A+ZCWUwcrfoHuNIaZ8I2prngARNqOgs7flQgHVD7cr47Ixf9mjDPbgn+MRB3wtQk
22LiaOvZ4PTRn+4JoSJ9naZSd2Tq0gMHx2+mm0LDMNU7sZU+krG+fb/PeWnMWL6t
cXdrvv77dXGMtLrSSGk2/BGWdlUpfNVc15Q9RIv0710upXsVWKB6pO7APZPbL6sS
zAcYCztR3thzx6XILzyduejHrL1db90bAMZkM7S75+3Rr3nUtC3o6WJoqcfYsmKD
EnucfpBNPB+MSoPXC+zaTNnyHiJKVY4XFvJjO2GFaq3i7KLZoap1IRCjW8kwMME6
JeiHW3hDdhbvHonBz0HDzqfmT4sVJ8z9ME1tntxVzVUtfaDUZGPyGz5fUhfsSWMA
XuSOVKJsRH0ti2u2XDqncYAmNw/ILMCa6cyZcPSRvfMiRLIZLXPsNJ8R+wOBK2J4
xqQ4UlCN3OSRuA0erH94L+0NuJdmqnUfBkaRAAkocpLfrnOS2LGMVMY/rjaV8kL4
TFqe0e2wbD59mS0FZPi6WQLhRPwXkV1FEjtQaP5TA30gpf2lejQ=
=MObd
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.