Skip to content

Add SSH-Agent plugin - #419

Draft
martasskv5 wants to merge 5 commits into
noctalia-dev:mainfrom
martasskv5:main
Draft

Add SSH-Agent plugin#419
martasskv5 wants to merge 5 commits into
noctalia-dev:mainfrom
martasskv5:main

Conversation

@martasskv5

Copy link
Copy Markdown

Plugin

  • Id: martasskv5/ssh-agent
  • New plugin
  • Update to an existing plugin (version bumped in plugin.toml)

What it does

Manage your SSH keys and saved sessions directly from the Noctalia bar. This plugin keeps a small SSH agent running in the background, lets you add or remove keys, and provides a panel for quick session management. Similar to PuTTY pagaent on Windows.

External dependencies

  • ssh - used for opening sessions
  • ssh-agent - agent running in background managing keys
  • ssh-add - for adding keys
  • zenity - used for browsing and selecting private ssh key file
  • mkdir - for creating non-existing directories
  • pkill - for stopping the ssh-agent proccess

For passphrase prompts:

  • ksshaskpass
  • ssh-askpass
  • lxqt-openssh-askpass

Agent socket is saved in /tmp directory by default

Testing

Opened the panel from bar and using IPC. Added the key using the Browse button. Verified key presence using ssh-add -l and by opening a new remote session.
Added new session using New Session button. Edited the save and then connected.
Everything works as intended.

  • Tested on Niri
  • Tested on Hyprland
  • Tested on Sway
  • Tested on another compositor:
  • Noctalia version tested against: 5.0.0_beta.8-1
  • Plugin API level: 9

Screenshots / Videos

thumbnail

Checklist

  • The directory name matches the part of id after the / in plugin.toml exactly.
  • It ships plugin.toml, README.md, thumbnail.webp, and translations/en.json.
  • README.md follows the
    README template, documents
    every entry id and dependency, and includes exact panel IPC commands and launcher prefixes where applicable.
  • I created thumbnail.webp with the thumbnail generator.
  • version follows semver and is bumped in this PR; plugin_api is the oldest API level this plugin requires.
  • Every non-English translation in this PR uses a locale supported by Noctalia core, and I can read, write, and
    understand that language well enough to review and maintain it (no unreviewed machine/LLM translations).
  • I did not edit catalog.toml; CI generates it.
  • This PR touches exactly one plugin directory.

Code review attestation

  • The code is readable and not obfuscated, minified, or generated.
  • It does not download and execute remote code.
  • Every network call, filesystem write, and spawned process is something the description above accounts for.
  • I have the right to publish this code under the license declared in plugin.toml.

@martasskv5
martasskv5 marked this pull request as draft August 20, 2026 14:08
@martasskv5
martasskv5 marked this pull request as ready for review August 20, 2026 14:10
@ItsLemmy

Copy link
Copy Markdown
Contributor
  1. blocking - ssh-agent/service.luau:143

The service treats the comment from ssh-add -l as an identity path, then passes it to ssh-add -d at
ssh-agent/service.luau:245. This breaks per-key removal for ordinary keys whose comments are not file
paths.

Reproduction with an ED25519 key commented review-comment: ssh-add -l returned review-comment, and
the resulting ssh-add -d review-comment exited 1 with Bad key file review-comment: No such file or directory. Resolve the selected identity to its public key or another form accepted by ssh-add -d,
rather than using the display comment.

  1. blocking - ssh-agent/panel.luau:281

default_key_browse_path is interpolated into a shell command without shell escaping at
ssh-agent/panel.luau:283, ssh-agent/panel.luau:289, and ssh-agent/panel.luau:293. Embedded quotes and shell
operators can terminate the --filename argument and execute an additional command when the user clicks
Browse. Treat the path strictly as data by safely quoting it or using an argument-vector process API.

  1. blocking - ssh-agent/service.luau:283

The persisted extra_args session field is appended directly to the SSH shell command at
ssh-agent/service.luau:289 and executed at ssh-agent/service.luau:298 or ssh-agent/service.luau:299. A
value containing shell syntax, such as -v; command, executes that command instead of remaining SSH
arguments. Parse and quote individual arguments, or use an argument-vector process API.

@ItsLemmy
ItsLemmy marked this pull request as draft August 23, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants