diff --git a/cmd/climc/shell/compute/sshkeypairs.go b/cmd/climc/shell/compute/sshkeypairs.go index 9fcfb3efa0..7a0f6a13cd 100644 --- a/cmd/climc/shell/compute/sshkeypairs.go +++ b/cmd/climc/shell/compute/sshkeypairs.go @@ -102,7 +102,7 @@ func init() { oldKeys = string(output) } pubKeys := &deployapi.SSHKeys{AdminPublicKey: pubKey} - newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys) + newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys, true) if output, err := procutils.NewCommand( "sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil { return errors.Wrapf(err, "write public keys: %s", output) diff --git a/pkg/hostman/guestfs/fsdriver/base.go b/pkg/hostman/guestfs/fsdriver/base.go index bb2cd3642a..24dfb121db 100644 --- a/pkg/hostman/guestfs/fsdriver/base.go +++ b/pkg/hostman/guestfs/fsdriver/base.go @@ -153,13 +153,13 @@ const ( modeAuthorizedKeysRW = syscall.S_IRUSR | syscall.S_IWUSR ) -func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool) error { +func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error { var oldKeys = "" if !replace { bOldKeys, _ := rootFs.FileGetContents(authFile, false) oldKeys = string(bOldKeys) } - newKeys := MergeAuthorizedKeys(oldKeys, pubkeys) + newKeys := MergeAuthorizedKeys(oldKeys, pubkeys, admin) if err := rootFs.FilePutContents(authFile, newKeys, false, false); err != nil { return fmt.Errorf("Put keys to %s: %v", authFile, err) } @@ -172,7 +172,7 @@ func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, return nil } -func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool) error { +func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error { usrStat := rootFs.Stat(usrDir, false) if usrStat != nil { sshDir := path.Join(usrDir, ".ssh") @@ -192,18 +192,24 @@ func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deploya return err } } - return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace) + return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, admin) } return nil } -func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string { +const sshKeySignature = "@yunioncloudpods" + +func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys, isAdmin bool) string { var allkeys = make(map[string]string) if len(oldKeys) > 0 { for _, line := range strings.Split(oldKeys, "\n") { line = strings.TrimSpace(line) dat := strings.Split(line, " ") if len(dat) > 1 { + if len(dat) > 2 && dat[2] == sshKeySignature { + // skip ssh keys with signature + continue + } if _, ok := allkeys[dat[1]]; !ok { allkeys[dat[1]] = line } @@ -218,13 +224,19 @@ func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string { } } } - for _, k := range []string{pubkeys.PublicKey, pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey} { + var candiateKeys []string + if isAdmin { + candiateKeys = []string{pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey} + } else { + candiateKeys = []string{pubkeys.PublicKey} + } + for _, k := range candiateKeys { if len(k) > 0 { k = strings.TrimSpace(k) dat := strings.Split(k, " ") if len(dat) > 1 { if _, ok := allkeys[dat[1]]; !ok { - allkeys[dat[1]] = k + allkeys[dat[1]] = strings.Join([]string{dat[0], dat[1], sshKeySignature}, " ") } } } @@ -265,7 +277,7 @@ func DeployAdminAuthorizedKeys(s *mcclient.ClientSession) error { } oldKeys = string(output) } - newKeys := MergeAuthorizedKeys(oldKeys, pubKeys) + newKeys := MergeAuthorizedKeys(oldKeys, pubKeys, true) if output, err := procutils.NewRemoteCommandAsFarAsPossible( "sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil { return errors.Wrapf(err, "write public keys: %s", output) diff --git a/pkg/hostman/guestfs/fsdriver/base_test.go b/pkg/hostman/guestfs/fsdriver/base_test.go index 52c717739e..c07efd9b80 100644 --- a/pkg/hostman/guestfs/fsdriver/base_test.go +++ b/pkg/hostman/guestfs/fsdriver/base_test.go @@ -26,22 +26,33 @@ func TestMergeAuthorizedKeys(t *testing.T) { pubkeys *deployapi.SSHKeys } tests := []struct { - name string - args args - want string + name string + args args + admin bool + want string }{ { name: "MergeAuthorizedKeys", args: args{ - oldKeys: "Test KEY", + oldKeys: "ssh-rsa KEY", pubkeys: &deployapi.SSHKeys{}, }, - want: "Test KEY\n", + admin: true, + want: "ssh-rsa KEY\n", + }, + { + name: "MergeAuthorizedKeys", + args: args{ + oldKeys: "ssh-rsa KEY " + sshKeySignature, + pubkeys: &deployapi.SSHKeys{}, + }, + admin: true, + want: "\n", }, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { - if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys); got != tt.want { + if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys, tt.admin); got != tt.want { t.Errorf("MergeAuthorizedKeys() = %v, want %v", got, tt.want) } }) diff --git a/pkg/hostman/guestfs/fsdriver/linux.go b/pkg/hostman/guestfs/fsdriver/linux.go index 0e89bc4b72..15145e61eb 100644 --- a/pkg/hostman/guestfs/fsdriver/linux.go +++ b/pkg/hostman/guestfs/fsdriver/linux.go @@ -222,7 +222,7 @@ func (l *sLinuxRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, pub } else { usrDir = path.Join("/home", selUsr) } - return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false) + return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false, false) } func (d *SCoreOsRootFs) DeployQgaBlackList(rootFs IDiskPartition) error { @@ -276,7 +276,7 @@ func (l *sLinuxRootFs) DeployYunionroot(rootFs IDiskPartition, pubkeys *deployap return errors.Wrap(err, "unable to CheckOrAddUser") } log.Infof("DeployYunionroot %s home %s", yunionroot, rootdir) - err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true) + err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true, true) if err != nil { log.Infof("DeployAuthorizedKeys error: %s", err.Error()) return fmt.Errorf("DeployAuthorizedKeys: %v", err) @@ -1858,7 +1858,7 @@ func (d *SOpenWrtRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, p gid = 0 replace = false ) - return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace) + return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, false) } return d.sLinuxRootFs.DeployPublicKey(rootFs, selUsr, pubkeys) } diff --git a/pkg/hostman/guestfs/fsdriver/macos.go b/pkg/hostman/guestfs/fsdriver/macos.go index cb9ccf4db6..d051f36e75 100644 --- a/pkg/hostman/guestfs/fsdriver/macos.go +++ b/pkg/hostman/guestfs/fsdriver/macos.go @@ -75,7 +75,7 @@ func (m *SMacOSRootFs) RootSignatures() []string { func (m *SMacOSRootFs) DeployPublicKey(rootfs IDiskPartition, uname string, pubkeys *deployapi.SSHKeys) error { usrDir := fmt.Sprintf("/Users/%s", uname) - return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false) + return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false, false) } func (m *SMacOSRootFs) addScripts(lines []string) {