pinwheel: set ASKPASS
And cache the git signing key
This commit is contained in:
@@ -6,6 +6,38 @@
|
||||
}:
|
||||
let
|
||||
enabled = config.mod.git.enable;
|
||||
|
||||
# Wrapper around `ssh-keygen` used as git's SSH signing program. Before a
|
||||
# signing operation it ensures the passphrase-protected signing key is loaded
|
||||
# into the agent — `ssh-keygen -Y sign` reads the key from disk and re-prompts
|
||||
# every commit otherwise, since `AddKeysToAgent` only ever caches auth keys.
|
||||
# Loading it once (through the GUI askpass) lets later commits reuse the
|
||||
# cached key from the agent. Verification and every other op pass straight
|
||||
# through to the real ssh-keygen untouched.
|
||||
sshSignWrapper = pkgs.writeShellApplication {
|
||||
name = "git-ssh-sign";
|
||||
runtimeInputs = [
|
||||
pkgs.openssh
|
||||
pkgs.gawk
|
||||
pkgs.gnugrep
|
||||
];
|
||||
text = ''
|
||||
key="${config.age.secrets."alex.pinwheel-github.com-signing".path}"
|
||||
|
||||
case " $* " in
|
||||
*" -Y sign "*)
|
||||
fp=""
|
||||
fp="$(ssh-keygen -lf "$key.pub" 2>/dev/null | awk '{print $2}')" || true
|
||||
if [ -n "$fp" ] && ! ssh-add -l 2>/dev/null | grep -qF "$fp"; then
|
||||
# </dev/null detaches stdin so ssh-add uses SSH_ASKPASS (the GUI).
|
||||
ssh-add "$key" </dev/null || true
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
|
||||
exec ssh-keygen "$@"
|
||||
'';
|
||||
};
|
||||
in
|
||||
{
|
||||
options = {
|
||||
@@ -33,6 +65,11 @@ in
|
||||
|
||||
# Tells Git to use SSH instead of the default GPG
|
||||
gpg.format = "ssh";
|
||||
|
||||
# Sign via a wrapper that loads the signing key into the agent on
|
||||
# first use, so subsequent signed commits reuse the cached key
|
||||
# instead of re-prompting for the passphrase every time.
|
||||
gpg.ssh.program = "${sshSignWrapper}/bin/git-ssh-sign";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user