fix: pass pubkey to tank-side.sh via env, not ssh command arg
ssh re-splits remote command args on spaces, so -- "$PUB" arrived as $1=ssh-ed25519 (the key body and comment became $2/$3). The loose validation passed and grep -qF matched any ed25519 key -> false '[skip] key present'; the key was never added. Pass PUB via env (safe inside remote single-quotes) and require 'ssh-ed25519 AAAA*'. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -29,5 +29,5 @@ ssh -o BatchMode=yes mac 'test ! -e /etc/sudoers.d/mac-setup && echo "[ok] temp
|
|||||||
mkdir -p .backup/mac && rsync -a mac:.mac-setup-backup/ .backup/mac/
|
mkdir -p .backup/mac && rsync -a mac:.mac-setup-backup/ .backup/mac/
|
||||||
[[ ${1:-} == --no-tank ]] && exit 0
|
[[ ${1:-} == --no-tank ]] && exit 0
|
||||||
PUB=$(ssh mac cat .ssh/id_ed25519.pub)
|
PUB=$(ssh mac cat .ssh/id_ed25519.pub)
|
||||||
ssh pve173 'bash -s' -- "$PUB" < scripts/tank-side.sh
|
ssh pve173 "PUB='$PUB' bash -s" < scripts/tank-side.sh
|
||||||
echo "tank side done; test: ssh mac ~/mac/scripts/backup.sh"
|
echo "tank side done; test: ssh mac ~/mac/scripts/backup.sh"
|
||||||
|
|||||||
@@ -1,8 +1,10 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# Run on pve173: ssh pve173 'bash -s' -- "<pubkey>" < scripts/tank-side.sh
|
# Run on pve173: ssh pve173 "PUB='<pubkey line>' bash -s" < scripts/tank-side.sh
|
||||||
|
# PUB comes via env (not a command arg) so ssh's remote-side re-splitting can't truncate the
|
||||||
|
# space-separated key line. $1 kept as a fallback for a local run.
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
PUB=${1:?pubkey line required}
|
PUB=${PUB:-${1:-}}
|
||||||
[[ $PUB == ssh-ed25519* ]] || { echo "not a pubkey: $PUB"; exit 1; }
|
[[ $PUB == ssh-ed25519\ AAAA* ]] || { echo "not a full pubkey line: '$PUB'"; exit 1; }
|
||||||
DS=tank/backups/mac; TS=$(date +%s)
|
DS=tank/backups/mac; TS=$(date +%s)
|
||||||
if zfs list "$DS" >/dev/null 2>&1; then echo "[skip] dataset $DS"; else zfs create "$DS"; echo "[set] created $DS"; fi
|
if zfs list "$DS" >/dev/null 2>&1; then echo "[skip] dataset $DS"; else zfs create "$DS"; echo "[set] created $DS"; fi
|
||||||
if grep -q "^\[$DS\]" /etc/sanoid/sanoid.conf; then echo "[skip] sanoid stanza"; else
|
if grep -q "^\[$DS\]" /etc/sanoid/sanoid.conf; then echo "[skip] sanoid stanza"; else
|
||||||
|
|||||||
Reference in New Issue
Block a user