Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1269719 > unrolled thread

Bug#1079246: gcr4: Environment variable SSH_AUTH_SOCK is hijacked by gcr-ssh-agent

Started byRaphael Hertzog <hertzog@debian.org>
First post2025-11-10 14:50 +0100
Last post2025-11-10 16:30 +0100
Articles 2 — 1 participant

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1079246: gcr4: Environment variable SSH_AUTH_SOCK is hijacked by gcr-ssh-agent Raphael Hertzog <hertzog@debian.org> - 2025-11-10 14:50 +0100
    Bug#1079246: gcr4: Environment variable SSH_AUTH_SOCK is hijacked by gcr-ssh-agent Raphael Hertzog <hertzog@debian.org> - 2025-11-10 16:30 +0100

#1269719 — Bug#1079246: gcr4: Environment variable SSH_AUTH_SOCK is hijacked by gcr-ssh-agent

FromRaphael Hertzog <hertzog@debian.org>
Date2025-11-10 14:50 +0100
SubjectBug#1079246: gcr4: Environment variable SSH_AUTH_SOCK is hijacked by gcr-ssh-agent
Message-ID<LPArn-bUWK-7@gated-at.bofh.it>
Package: gcr4
Version: 4.4.0.1-7
Followup-For: Bug #1079246
Control: severity -1 important

gcr4 goes to great length to actually override the SSH_AUTH_SOCK set by
gpg-agent-ssh but that's not a useful thing to do.

I refer specifically to this change that landed this summer:
"Add proposed patch to ensure gcr4 is the default ssh-agent provider" by
Alessandro:
https://salsa.debian.org/gnome-team/gcr4/-/commit/2f9e7e82f03b985e7ccbb8218ead0a15e0bc5660

--- a/gcr/gcr-ssh-agent.socket.in
+++ b/gcr/gcr-ssh-agent.socket.in
@@ -1,5 +1,7 @@
 [Unit]
 Description=GCR ssh-agent wrapper
+# If gcr is installed, take priority in setting SSH_AUTH_SOCK over gpg-agent
+After=gpg-agent-ssh.socket


The ssh-agent provided by gpg-agent is disabled by default. The user needs
to add enable-ssh-agent in ~/.gnupg/gpg-agent.conf to actually enable it. When
the user does this, we ought to try to respect his choice instead of
voluntarily override it.

My reason to use gpg-agent is because my SSH key is a GPG subkey in a Yubikey.

Please let me use it without having to resort to complicated hacks. It
took me multiple tries until I figured out how to get this properly
disabled. Hint:
* "systemctl --user disable gcr-ssh-agent.socket" does not work because
  it's enabled globally via some links in
  /etc/systemd/user/grapgraphical-session-pre.target.wants/
* then you figure out that you need the same command under sudo with "--global"
  instead of "--user", but it still does not work
* so I try again with "systemctl --user disable" and it's now accepted but
  it still doesn't help because
  /usr/lib/systemd/user/gnome-session@gnome.target.d/gnome.session.conf
  has Wants=gcr-ssh-agent.socket
* finally I figure out that I really need to "systemctl --global
  mask gcr-ssh-agent.socket" to have something that works to not execute
  the code that overrides SSH_AUTH_SOCK

So my suggestion at this point is to actually do the opposite and use
"Before=gpg-agent-ssh.socket" because gpg-agent-ssh.socket is a no-op in
the default case, and when it's not a no-op, it's best to respect the
user's choice.

-- System Information:
Debian Release: forky/sid
  APT prefers stable-security
  APT policy: (500, 'stable-security'), (500, 'oldstable-security'), (500, 'unstable'), (500, 'stable'), (500, 'oldstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 6.17.7+deb14+1-amd64 (SMP w/24 CPU threads; PREEMPT)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages gcr4 depends on:
ii  dbus-user-session [default-dbus-session-bus]  1.16.2-2
ii  gcr                                           3.41.2-5
ii  init-system-helpers                           1.69
ii  libc6                                         2.41-12
ii  libgck-2-2                                    4.4.0.1-7
ii  libgcr-4-4                                    4.4.0.1-7
ii  libglib2.0-0t64                               2.86.1-2
ii  libgtk-4-1                                    4.20.2+ds-2
ii  libpango-1.0-0                                1.56.3-2
ii  libsecret-1-0                                 0.21.7-2
ii  libsystemd0                                   258.1-2

gcr4 recommends no packages.

gcr4 suggests no packages.

-- no debconf information

-- 
  ⢀⣴⠾⠻⢶⣦⠀   Raphaël Hertzog <hertzog@debian.org>
  ⣾⠁⢠⠒⠀⣿⡁
  ⢿⡄⠘⠷⠚⠋    The Debian Handbook: https://debian-handbook.info/get/
  ⠈⠳⣄⠀⠀⠀⠀   Debian Long Term Support: https://deb.li/LTS

[toc] | [next] | [standalone]


#1269729

FromRaphael Hertzog <hertzog@debian.org>
Date2025-11-10 16:30 +0100
Message-ID<LPC09-bW8e-9@gated-at.bofh.it>
In reply to#1269719
On Mon, 10 Nov 2025, Raphael Hertzog wrote:
> So my suggestion at this point is to actually do the opposite and use
> "Before=gpg-agent-ssh.socket" because gpg-agent-ssh.socket is a no-op in
> the default case, and when it's not a no-op, it's best to respect the
> user's choice.

FWIW I tried this and it seems to work but only if gcr-ssh-agent.socket is
explicitly enabled (as is the case by default). Otherwise it's started as
a dependency of gcr-agent.service and again overwrites the operation
performed by gpg-agent-ssh.socket.

Note that with the suggested "Before" setting I get this ordering (it's in
chronological order):

nov. 10 16:08:39 fr13-buxy systemd[26418]: Starting dbus.socket - D-Bus User Message Bus Socket...
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on dirmngr.socket - GnuPG network certificate management daemon.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Starting gcr-ssh-agent.socket - GCR ssh-agent wrapper...
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gnome-keyring-daemon.socket - GNOME Keyring daemon.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gpg-agent-browser.socket - GnuPG cryptographic agent and passphrase cache (access for web browsers).
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gpg-agent-extra.socket - GnuPG cryptographic agent and passphrase cache (restricted).
nov. 10 16:08:39 fr13-buxy systemd[26418]: Starting gpg-agent.socket - GnuPG cryptographic agent and passphrase cache...
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on keyboxd.socket - GnuPG public key management service.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on pipewire-pulse.socket - PipeWire PulseAudio.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on pipewire.socket - PipeWire Multimedia System Sockets.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on pk-debconf-helper.socket - debconf communication socket.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on snapd.session-agent.socket - REST API socket for snapd user session agent.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on speech-dispatcher.socket - Speech Dispatcher Socket.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Starting ssh-agent.socket - OpenSSH Agent socket...
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on systemd-ask-password.socket - Query the User Interactively for a Password.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on yubikey-touch-detector.socket - Unix socket activation for YubiKey touch detector service.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on dbus.socket - D-Bus User Message Bus Socket.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gcr-ssh-agent.socket - GCR ssh-agent wrapper.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on ssh-agent.socket - OpenSSH Agent socket.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gpg-agent.socket - GnuPG cryptographic agent and passphrase cache.
nov. 10 16:08:39 fr13-buxy systemd[26418]: Starting gpg-agent-ssh.socket - GnuPG cryptographic agent (ssh-agent emulation)...
nov. 10 16:08:39 fr13-buxy systemd[26418]: Listening on gpg-agent-ssh.socket - GnuPG cryptographic agent (ssh-agent emulation).
nov. 10 16:08:39 fr13-buxy systemd[26418]: Reached target sockets.target - Sockets.

It shows that gpg-agent.socket would also overwrite SSH_AUTH_SOCK, so
maybe you want to add an extra "After=ssh-agent.socket" since that one
is not smarter than the gcr one and overwrites the same variable
unconditionally.

Cheers,
-- 
  ⢀⣴⠾⠻⢶⣦⠀   Raphaël Hertzog <hertzog@debian.org>
  ⣾⠁⢠⠒⠀⣿⡁
  ⢿⡄⠘⠷⠚⠋    The Debian Handbook: https://debian-handbook.info/get/
  ⠈⠳⣄⠀⠀⠀⠀   Debian Long Term Support: https://deb.li/LTS

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web