From 0a7afa2d1e576f05253b62c6b17e5e4873fbdebc Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Tue, 4 Aug 2026 20:01:06 +0530 Subject: feat: moved gpg data directory, other gopass ssh keys, script builder - Using ~/.local/share/gnupg/ for storing the data for gnupg, and made the necessary changes in all places to that effect - Additional ssh keys can be added to gopass under ssh/, which is on top of the git servers that already existed - Using pkgs.writeShellApplication for creating the scripts, stopped setting path for each dependency (creating a long PATH variable and thus finding binaries may take longer), instead using the inbuild dependency (runtimeInputs) for the scripts --- modules/scripts/gopass-ssh-load/default.nix | 16 ++++++++++++ modules/scripts/gopass-ssh-load/script.sh | 39 +++++++++++++++++++---------- modules/scripts/lib.nix | 34 ++++++++----------------- modules/scripts/neomutt-sync/script.sh | 4 +-- modules/scripts/usque-warp/script.sh | 25 +++++++++--------- modules/scripts/yazi-file-chooser/script.sh | 4 +-- 6 files changed, 70 insertions(+), 52 deletions(-) (limited to 'modules/scripts') diff --git a/modules/scripts/gopass-ssh-load/default.nix b/modules/scripts/gopass-ssh-load/default.nix index 002a4ac..e0a4615 100644 --- a/modules/scripts/gopass-ssh-load/default.nix +++ b/modules/scripts/gopass-ssh-load/default.nix @@ -6,10 +6,26 @@ }: let inherit ((import ../lib.nix { inherit lib pkgs; })) mkScriptModule; + + gitPlatformKeys = [ + "github" + "gitlab" + "bitbucket" + "codeberg" + "srht" + ]; + + gopassKeys = + lib.optionals config.development.git.useSSH gitPlatformKeys ++ config.security.ssh.extraGopassKeys; + base = mkScriptModule { name = "gopass-ssh-load"; path = ./script.sh; description = "Load SSH keys from gopass password store"; + env = { + GNUPGHOME = config.home.sessionVariables.GNUPGHOME; + GOPASS_SSH_KEYS = lib.concatStringsSep " " gopassKeys; + }; deps = with pkgs; [ config.security.gopass.package gnupg diff --git a/modules/scripts/gopass-ssh-load/script.sh b/modules/scripts/gopass-ssh-load/script.sh index e8bc0ee..43c83b0 100644 --- a/modules/scripts/gopass-ssh-load/script.sh +++ b/modules/scripts/gopass-ssh-load/script.sh @@ -1,5 +1,12 @@ -export SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +set -o errexit +set -o nounset +set -o pipefail +# Load SSH keys from gopass password store +export GNUPGHOME="${GNUPGHOME:-$HOME/.local/share/gnupg}" + +SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +export SSH_AUTH_SOCK if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 exit 1 @@ -9,25 +16,31 @@ if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then exit 0 fi -for key in github gitlab bitbucket codeberg sourcehut; do +# GOPASS_SSH_KEYS: space-separated list of gopass entry names under ssh/ +# e.g. GOPASS_SSH_KEYS="github gitlab work-server" +if [ -z "${GOPASS_SSH_KEYS:-}" ]; then + echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 + exit 1 +fi + +# shellcheck disable=SC2086 +read -r -a keys <<< "$GOPASS_SSH_KEYS" + +for key in "${keys[@]}"; do if gopass cat "ssh/$key" > /dev/null 2>&1; then tmpdir=$(mktemp -d) keyfile="$tmpdir/key" gopass cat "ssh/$key" > "$keyfile" 2>/dev/null chmod 600 "$keyfile" - if ! ssh-add "$keyfile" 2>/dev/null; then - passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null) - if [ -n "$passphrase" ]; then - tmpcopy=$(mktemp) - cp "$keyfile" "$tmpcopy" - chmod 600 "$tmpcopy" - if ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then - ssh-add "$tmpcopy" 2>/dev/null - fi - rm -f "$tmpcopy" - fi + passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null || true) + if [ -n "$passphrase" ]; then + ssh-keygen -p -P "$passphrase" -N "" -f "$keyfile" 2>/dev/null fi + + ssh-add "$keyfile" 2>/dev/null rm -rf "$tmpdir" + else + echo "Warning: no gopass entry ssh/$key" >&2 fi done diff --git a/modules/scripts/lib.nix b/modules/scripts/lib.nix index 2d2aed3..70affba 100644 --- a/modules/scripts/lib.nix +++ b/modules/scripts/lib.nix @@ -8,31 +8,19 @@ let descLines = lib.filter (s: s != "") (lib.splitString "\n" description); descComment = if descLines == [ ] then "" else lib.concatMapStringsSep "\n" (line: "# ${line}") descLines + "\n"; - envVars = lib.concatStringsSep "\n" (lib.mapAttrsToList (n: v: "${n}=\"${toString v}\"") env); - wrappedScript = pkgs.writeTextFile { - name = name; - executable = true; - destination = "/bin/${name}"; - text = '' - #!${shell} - ${descComment}${envVars} - ${builtins.readFile path} - ''; - }; + envVars = lib.concatStringsSep "\n" ( + lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg (toString v)}") env + ); in - pkgs.runCommand name - { - nativeBuildInputs = [ pkgs.makeWrapper ]; - meta.mainProgram = name; - } - '' - mkdir -p $out/bin - cp ${wrappedScript}/bin/${name} $out/bin/${name} - chmod +x $out/bin/${name} - - wrapProgram $out/bin/${name} \ - --prefix PATH : ${lib.makeBinPath deps} + pkgs.writeShellApplication { + inherit name; + runtimeInputs = deps; + text = '' + #!${shell} + ${descComment}${envVars} + ${builtins.readFile path} ''; + }; mkScriptModule = { diff --git a/modules/scripts/neomutt-sync/script.sh b/modules/scripts/neomutt-sync/script.sh index 96d866d..b2db42a 100644 --- a/modules/scripts/neomutt-sync/script.sh +++ b/modules/scripts/neomutt-sync/script.sh @@ -1,7 +1,7 @@ -export DIALOGRC=$(mktemp) +DIALOGRC=$(mktemp) NOTMUCH_LOG=$(mktemp) TITLE="[SYNCING MAIL]" -BACK_TITLE= +export DIALOGRC trap 'rm -f "$DIALOGRC" "$NOTMUCH_LOG"' EXIT # Clean up everything on exit cat << 'EOF' > "$DIALOGRC" diff --git a/modules/scripts/usque-warp/script.sh b/modules/scripts/usque-warp/script.sh index 5736018..01b298e 100644 --- a/modules/scripts/usque-warp/script.sh +++ b/modules/scripts/usque-warp/script.sh @@ -1,3 +1,4 @@ +#!/usr/bin/env bash set -euo pipefail CONFIG_DIR="$HOME/.cache/usque" CONFIG="$CONFIG_DIR/config.json" @@ -23,13 +24,13 @@ is_running() { [[ -f "$PID_FILE" ]] || return 1 local pid pid=$(cat "$PID_FILE" 2>/dev/null || true) - [[ -n "$pid" ]] && kill -0 "$pid" 2>/dev/null + [[ -n "$pid" ]] || return 1 + sudo kill -0 "$pid" 2>/dev/null } ensure_config() { echo "Creating $CONFIG_DIR..." mkdir -p "$CONFIG_DIR" - rm -f "$CONFIG" echo "Registering Cloudflare WARP account..." usque -c "$CONFIG" register < <(yes) if [[ ! -f "$CONFIG" ]]; then @@ -44,7 +45,7 @@ remove_tun_default_routes() { while ip route show | grep -qE "^default .*dev $dev"; do ROUTE=$(ip route show | grep -E "^default .*dev $dev" | head -n1) echo "Removing route: $ROUTE" - sudo ip route del $ROUTE || true + sudo ip route del "$ROUTE" || break done } @@ -52,7 +53,7 @@ connect() { ensure_config if [[ -f "$PID_FILE" ]]; then OLD_PID=$(cat "$PID_FILE") - if kill -0 "$OLD_PID" 2>/dev/null; then + if sudo kill -0 "$OLD_PID" 2>/dev/null; then echo "usque-warp is already running (PID $OLD_PID)" exit 1 else @@ -73,12 +74,12 @@ connect() { BEFORE_IFACES=$(list_tun_ifaces) echo "Starting usque..." - sudo usque nativetun -c "$CONFIG" >"$LOG_FILE" 2>&1 & + sudo usque nativetun -c "$CONFIG" 2>&1 | sudo tee "$LOG_FILE" >/dev/null & echo $! > "$PID_FILE" echo "Waiting for MASQUE connection..." MASQUE_IP="" - for i in {1..30}; do + for _ in {1..30}; do MASQUE_IP=$(grep -oP 'MASQUE connection to \K[0-9.]+(?=:443)' "$LOG_FILE" 2>/dev/null || true) if [[ -n "$MASQUE_IP" ]]; then break @@ -87,14 +88,14 @@ connect() { done if [[ -z "$MASQUE_IP" ]]; then echo "Failed to detect MASQUE endpoint" - kill "$(cat "$PID_FILE")" 2>/dev/null || true + sudo kill "$(cat "$PID_FILE")" 2>/dev/null || true rm -f "$PID_FILE" exit 1 fi echo "Waiting for usque interface..." TUN_DEV="" - for i in {1..30}; do + for _ in {1..30}; do AFTER_IFACES=$(list_tun_ifaces) TUN_DEV=$(comm -13 <(echo "$BEFORE_IFACES" | sort) <(echo "$AFTER_IFACES" | sort) | head -n1) [[ -n "$TUN_DEV" ]] && break @@ -102,7 +103,7 @@ connect() { done if [[ -z "$TUN_DEV" ]]; then echo "Failed to detect usque interface" - kill "$(cat "$PID_FILE")" 2>/dev/null || true + sudo kill "$(cat "$PID_FILE")" 2>/dev/null || true rm -f "$PID_FILE" exit 1 fi @@ -115,7 +116,7 @@ connect() { echo "Cannot determine gateway/interface" exit 1 fi - echo "$MASQUE_IP $GATEWAY $INTERFACE" >> "$STATE_FILE" + echo "MASQUE_IP=$MASQUE_IP GATEWAY=$GATEWAY INTERFACE=$INTERFACE" >> "$STATE_FILE" echo "Allowing MASQUE endpoint outside tunnel..." sudo ip route replace \ @@ -146,7 +147,7 @@ disconnect() { fi if [[ -f "$STATE_FILE" ]]; then - MASQUE_IP=$(grep -oP '[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+' "$STATE_FILE" | head -n1 || true) + MASQUE_IP=$(grep -oP 'MASQUE_IP=\K[0-9.]+' "$STATE_FILE" || true) if [[ -n "$MASQUE_IP" ]]; then echo "Removing MASQUE route: $MASQUE_IP" sudo ip route del "$MASQUE_IP" 2>/dev/null || true @@ -156,7 +157,7 @@ disconnect() { if [[ -f "$PID_FILE" ]]; then PID=$(cat "$PID_FILE") - if kill -0 "$PID" 2>/dev/null; then + if sudo kill -0 "$PID" 2>/dev/null; then echo "Stopping usque..." sudo kill "$PID" 2>/dev/null || true fi diff --git a/modules/scripts/yazi-file-chooser/script.sh b/modules/scripts/yazi-file-chooser/script.sh index a2f9166..e02c742 100644 --- a/modules/scripts/yazi-file-chooser/script.sh +++ b/modules/scripts/yazi-file-chooser/script.sh @@ -4,9 +4,9 @@ # $4 = initial directory path # $5 = output path file (where portal expects selected paths) -multiple="$1" +# multiple="$1" directory="$2" -save="$3" +# save="$3" path="$4" out="$5" -- cgit v1.2.3