Expand description
SSH_ASKPASS handler for passphrase prompts.
When SSH tools (like ssh-add) need a passphrase, they check the
SSH_ASKPASS environment variable for a program to run. This module
provides AskpassHandler, which creates a temporary script that outputs
a stored passphrase, enabling non-interactive key loading from a TUI or
other automated context.
§How it works
- Call
AskpassHandler::newwith the passphrase string. - A temporary executable script is written to disk that echoes the passphrase to stdout.
- Call
AskpassHandler::apply_to_commandto inject theSSH_ASKPASS,SSH_ASKPASS_REQUIRE, andDISPLAYenvironment variables into aduct::Expressioncommand. - Drop the handler (or call
AskpassHandler::cleanupexplicitly) to remove the temporary script from disk.
§Security considerations
- The temporary script file is created with
0o700permissions on Unix so only the current user can read it. - The file is created in a system temp directory (
std::env::temp_dir()); the script’s final executable mode (0o700on Unix) is set atomically at creation time and the bytes are flushed to disk before the file is handed out, which avoids theETXTBSY(“Text file busy”) race that would otherwise occur if a caller execs the script while a deferred write is still in flight. - Callers should drop the handler as soon as the passphrase is no longer needed to minimize the window during which the script exists on disk.
- The passphrase is embedded in the script content; anyone who can read the file can recover it.
- The owned copy of the passphrase used to build the script is overwritten
with zeros (via
zeroize) once the script has been written and flushed, so it is not left resident in memory beyond the construction call. - On Windows the script is created with
OpenOptions::create_new(true)(CREATE_NEW) so a name collision fails loudly rather than silently overwriting another handler’s file; per-file ACL hardening relies on the per-user%TEMP%directory ACL. - The passphrase never appears in process
argv, parent stdout/stderr, orCommandFailederror strings — only the script’s filesystem path is included in errors.
Structs§
- Askpass
Handler - A temporary
SSH_ASKPASSscript that outputs a stored passphrase.