#!/usr/bin/env bash set -euo pipefail sshd_config=/run/luci-sshd.conf ssh_command=/run/luci-ssh-command write_sshd_config() { local name value escaped cat >"${sshd_config}" <<'SSHD_CONFIG' Port 2223 HostKey /data/ci/ssh/ssh_host_ed25519_key PasswordAuthentication no KbdInteractiveAuthentication no AuthenticationMethods publickey PermitRootLogin prohibit-password AuthorizedKeysFile /data/ci/authorized_keys ForceCommand /run/luci-ssh-command DisableForwarding yes AllowTcpForwarding no X11Forwarding no PermitTTY no SSHD_CONFIG printf '%s\n' '#!/usr/bin/env bash' >"${ssh_command}" for name in \ LUCI_DATA_DIR \ LUCI_REPO_ROOTS \ LUCI_HTTP_ADDR \ LUCI_BASE_URL \ LUCI_INBOX_DIR \ LUCI_PODMAN_SOCKET \ LUCI_SSH_ADDR \ LUCI_SSH_AUTHORIZED_KEYS \ LUCI_THEME_CSS \ LUCI_DEFAULT_TIMEOUT \ LUCI_DEFAULT_MEMORY \ LUCI_DEFAULT_CPUS \ LUCI_CACHE_MAX_VERSIONS \ LUCI_CACHE_MAX_BYTES \ LUCI_LOG_LEVEL \ LUCI_PUBLISH_REGISTRY_AUTH_FILE \ LUCI_PUBLISH_PKG_ROOT \ LUCI_PUBLISH_SITE_ROOT; do value="${!name:-}" [[ -n "${value}" ]] || continue [[ "${value}" != *$'\n'* && "${value}" != *$'\r'* ]] || { echo "invalid newline in ${name}" >&2 exit 1 } escaped="${value//\\/\\\\}" escaped="${escaped//\"/\\\"}" printf 'SetEnv %s="%s"\n' "${name}" "${escaped}" >>"${sshd_config}" printf 'export %s=%q\n' "${name}" "${value}" >>"${ssh_command}" done printf '%s\n' 'exec /usr/local/bin/luci ssh' >>"${ssh_command}" chmod 0755 "${ssh_command}" } stop_children() { kill "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true wait "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true } trap 'stop_children; exit 0' INT TERM install -d -m 0700 /data/ci/ssh /run/sshd if [[ ! -f /data/ci/ssh/ssh_host_ed25519_key ]]; then ssh-keygen -q -t ed25519 -N '' -f /data/ci/ssh/ssh_host_ed25519_key fi /usr/local/bin/luci env-check write_sshd_config /usr/sbin/sshd -t -f "${sshd_config}" /usr/sbin/sshd -D -e -f "${sshd_config}" & sshd_pid=$! /usr/local/bin/luci serve & luci_pid=$! set +e wait -n "${sshd_pid}" "${luci_pid}" status=$? set -e stop_children exit "${status}"