Skip to main content

Module askpass

Module askpass 

Source
Expand description

SSH_ASKPASS handler for passphrase prompts.

When SSH tools (like ssh-add) need a passphrase, they check the SSH_ASKPASS environment variable for a program to run. This module provides AskpassHandler, which creates a temporary script that outputs a stored passphrase, enabling non-interactive key loading from a TUI or other automated context.

§How it works

  1. Call AskpassHandler::new with the passphrase string.
  2. A temporary executable script is written to disk that echoes the passphrase to stdout.
  3. Call AskpassHandler::apply_to_command to inject the SSH_ASKPASS, SSH_ASKPASS_REQUIRE, and DISPLAY environment variables into a duct::Expression command.
  4. Drop the handler (or call AskpassHandler::cleanup explicitly) to remove the temporary script from disk.

§Security considerations

  • The temporary script file is created with 0o700 permissions on Unix so only the current user can read it.
  • The file is created in a system temp directory (std::env::temp_dir()); the script’s final executable mode (0o700 on Unix) is set atomically at creation time and the bytes are flushed to disk before the file is handed out, which avoids the ETXTBSY (“Text file busy”) race that would otherwise occur if a caller execs the script while a deferred write is still in flight.
  • Callers should drop the handler as soon as the passphrase is no longer needed to minimize the window during which the script exists on disk.
  • The passphrase is embedded in the script content; anyone who can read the file can recover it.
  • The owned copy of the passphrase used to build the script is overwritten with zeros (via zeroize) once the script has been written and flushed, so it is not left resident in memory beyond the construction call.
  • On Windows the script is created with OpenOptions::create_new(true) (CREATE_NEW) so a name collision fails loudly rather than silently overwriting another handler’s file; per-file ACL hardening relies on the per-user %TEMP% directory ACL.
  • The passphrase never appears in process argv, parent stdout/stderr, or CommandFailed error strings — only the script’s filesystem path is included in errors.

Structs§

AskpassHandler
A temporary SSH_ASKPASS script that outputs a stored passphrase.