From 5df230fc09904bb09d8325b36fcb53e7f1137b99 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Mon, 5 Oct 2026 12:48:16 -0700 Subject: [PATCH] slab: ac-ssh routes a host's passphrase requests to the native modal on this Mac ac-passphrase now honours AC_DAEMON_SOCK; ac-ssh tunnels a one-off socket on the host back to the local daemon and sets it. First use unlocked poorslice's vault from neo while poorslice sat at its lock screen. --- slab/bin/ac-passphrase | 4 ++++ slab/bin/ac-ssh | 33 +++++++++++++++++++++++++++++++++ slab/menubar-swift/README.md | 12 ++++++++++++ 3 files changed, 49 insertions(+) create mode 100755 slab/bin/ac-ssh diff --git a/slab/bin/ac-passphrase b/slab/bin/ac-passphrase index 8adc3a9b33..af547a18c8 100755 --- a/slab/bin/ac-passphrase +++ b/slab/bin/ac-passphrase @@ -8,8 +8,12 @@ # # The daemon caches by label (default 600s TTL) so repeated calls within # a deploy don't re-prompt. See slab/menubar-swift/README.md. +# +# AC_DAEMON_SOCK points it at another daemon's socket. `ac-ssh` sets it to a +# tunnel back to the caller's machine, so the modal opens where you sit. set sock "$HOME/.ac-daemon.sock" +set -q AC_DAEMON_SOCK; and set sock $AC_DAEMON_SOCK if not test -S $sock echo "ac-passphrase: daemon socket not found at $sock" >&2 diff --git a/slab/bin/ac-ssh b/slab/bin/ac-ssh new file mode 100755 index 0000000000..e5233bb7de --- /dev/null +++ b/slab/bin/ac-ssh @@ -0,0 +1,33 @@ +#!/usr/bin/env fish +# ac-ssh — run a command on a fleet host with passphrase requests routed home. +# +# Usage: ac-ssh +# +# Tunnels a socket on back to this machine's slab daemon and sets +# AC_DAEMON_SOCK for the command, so any `ac-passphrase` it runs opens the +# native modal HERE. The secret travels the ssh connection only; nothing is +# cached on beyond what the command itself does with it. +# +# Example — unlock poorslice's vault from neo: +# ac-ssh poorslice 'cd ~/aesthetic-computer/aesthetic-computer-vault && +# ac-passphrase gpg-vault | gpg --batch --pinentry-mode loopback \ +# --passphrase-fd 0 -d lith/.env.gpg >/dev/null && fish vault-tool.fish unlock' + +if test (count $argv) -lt 2 + echo "usage: ac-ssh " >&2 + exit 2 +end + +set host $argv[1] +set local_sock "$HOME/.ac-daemon.sock" +if not test -S $local_sock + echo "ac-ssh: no slab daemon socket at $local_sock — is the menubar app running here?" >&2 + exit 2 +end + +# A fresh path per call: sshd will not replace a stale socket file by default. +set remote_sock /tmp/ac-daemon-(random 100000 999999).sock +set remote_path 'export PATH=/opt/homebrew/bin:$HOME/.local/bin:$HOME/node/bin:$PATH' + +ssh -t -o ExitOnForwardFailure=yes -R $remote_sock:$local_sock $host \ + "$remote_path; export AC_DAEMON_SOCK=$remote_sock; trap 'rm -f $remote_sock' EXIT; $argv[2..-1]" diff --git a/slab/menubar-swift/README.md b/slab/menubar-swift/README.md index 33409ad1c2..b19479c51f 100644 --- a/slab/menubar-swift/README.md +++ b/slab/menubar-swift/README.md @@ -232,6 +232,18 @@ set phrase (echo $resp | jq -r '.secret // empty') The modal is a native `NSAlert` + `NSSecureTextField`, brought to the front with `NSApp.activate(ignoringOtherApps:)`. +### Asking from another machine + +`ac-ssh ` runs a command on a fleet host with its passphrase requests routed home: it tunnels a one-off socket on the host back to this Mac's daemon and sets `AC_DAEMON_SOCK`, which `ac-passphrase` prefers over its own socket. The modal opens where you sit, the host's lock screen doesn't matter, and the secret travels only the ssh connection. + +```fish +ac-ssh poorslice 'cd ~/aesthetic-computer/aesthetic-computer-vault && + ac-passphrase gpg-vault | gpg --batch --pinentry-mode loopback --passphrase-fd 0 -d lith/.env.gpg >/dev/null && + fish vault-tool.fish unlock' +``` + +`vault-tool unlock` skips files that already have plaintext, so a host with an old `.env` keeps it; compare the decrypted `.gpg` against the plaintext before trusting either. + ## Fleet parity (same menu bar on every Mac) `slab/bin/menubar-parity.mjs` (`npm run menubar:parity -- `) keeps -- 2.51.2