iTerm2 Shell Integration
iterm2.com
iterm2.com
Also, credit goes to FinalTerm for the inspiration. RIP.
I couldn't find a way to customise the shortcut in options. Sorry if I was too stupid to find it.
Great work otherwise.
"\e\e[D": backward-word
"\e\e[C": forward-word
I'd love to switch to an american keyboard, because lots of Unix things seems impossible to type with my current keyboard, but maybe I am just being stupid.How should we think about the security story when sshing from a more trusted to a less trusted host?
When installing, especially on an untrusted host, follow the manual installation instructions. The menu item will just output a curl|bash command (currently; this will likely change in the future).
If the host is really untrusted you're screwed, of course. Bad guys could modify your ~/.iterm2_shell_integration.bash and you'd never know. But this script is not special in any way (except that it's kinda complex and is run automatically). Maybe hash it from time to time if you're really paranoid.
The scripts assume that various things in your path are safe to run. printf, hostname, sed, echo, etc. If those are compromised you're in a bad way, and I don't think shell integration exposes anything that ordinary use wouldn't.
If you've been compromised badly enough that an attacker can decrypt your ssh session, your current directory will be revealed at each prompt. But it probably is since most people have that in their $PS1 anyway. Also the host's idea of its fully-qualified domain name.
Probably the most risky aspect of shell integration is the secure copy feature. It's possible that there's a bug in my use of libssh2 or that there are unpatched vulnerabilities in an out-of-date build of iTerm2 (or an up-to-date version of iTerm2 with an out-of-date libssh2). I try to stay on top of changes to libssh2 but I am human and Sparkle (the auto-updater) is not flawless either.
That's all that comes to mind. I'm sure other folks on here can think of more interesting attacks or vulnerabilities.
I don't have a great solution to suggest for this. One option is to add some sort of per-user static password to the escape sequence, and insert it in the file that's copied to each (trusted) host, but that just seems questionable. A better one might be to make the communication use a socket instead of an escape sequence, and forward the socket (recent OpenSSH can forward UNIX domain sockets) to trusted hosts, but that's its own mess.
This is such a useful feature, though, especially with remote hosts. It'd be a pity if it can't be done securely. :/
(While we're on the subject of security, there's an obscure attack involving interrupting the download of a `curl | sh` script -- which a MITM can do, even over SSH -- and relying on the shell to execute a partial command line. I learned about this from the Sandstorm folks, who have a workaround in https://install.sandstorm.io/ involving the sh equivalent of an IIFE.)
Your password idea would work. It would be nearly impossible to establish a shared secret, unfortunately. It's really hard to do any kind of authentication over a one-way channel, which you almost always have to assume is what you've got in the world of terminal emulation. Key management retains its title as the worst part of crypto. The socket thing doesn't work (at least as the default mode) because nobody knows how to forward sockets and 99% of users would choose to forego the feature over learning a new ssh flag and making it work everywhere. There are gnarly race conditions there, too. How do you correlate prompts with messages on the socket?
I'm open to suggestions, but I don't see a way to make it both convenient enough to be generally useful and bulletproof.
I do plan to nuke the curl|bash thing. It was a shortcut to ship faster and to make it easy to update scripts in the field quickly when bugs were found. I did imagine everyone on hacker news scowling at me when I wrote that code, FWIW.
I suspect that you can do this with SSH configuration (LocalForward ~/.something:~/.something), but I haven't tested it. It mostly depends on whether you're willing to configure this, but perhaps the installer can put that at the top of ~/.ssh/config, so it's global, with a comment saying "If you don't want this globally, delete it or put it after a `Host example.com` line". Even if you trusted all SSH hosts, this would protect you from the git-clone attack.
You could probably also abuse X11 forwarding for this, which has the advantage that trusted X11 forwarding is basically the right security boundary and is just `ssh -Y`, and the disadvantage that now you're relying on X11 (or worse, a custom X11-speaking proxy so you can avoid requiring the server or client) on both sides.
> There are gnarly race conditions there, too. How do you correlate prompts with messages on the socket?
Send a token or hash in-band, and send the actual command out-of-band. If you receive an unknown token, ignore it.
> I do plan to nuke the curl|bash thing. It was a shortcut to ship faster and to make it easy to update scripts in the field quickly when bugs were found. I did imagine everyone on hacker news scowling at me when I wrote that code, FWIW.
:-)
curl https:// | sh is IMO a perfectly reasonable way to install software (at least in a world where ./configure && make install is reasonable; I don't know any humans who can audit the output of GNU autoconf). It just has this one weird problem. I sort of dislike the stigmatization of it precisely because it's hard to talk about how to do it well.
>iTerm2 respsects ssh_config files, but only a subset of the commands are understood:
Just trying to be constructive!
I used to use cygwin on windows with screen, it kinda works, just everything is so slow. Every time I create a new screen window I had to peek HN for latest posts. LoL
Also I don't really understand the difference between the main configuration interface (cmd-,) and the "Edit Session..." interface (right click on iterm2 menu). Possibly related, I have a custom command configured in Advanced -> Semantic History but it keeps reverting back to no command and I just don't understand why.
I would love not to have to use a graphical interface to configure it, I would like a plain text file instead. I think I'm being dumb and a couple hours consideration would lead me to understand any issues I'm having but the fact remains that after years of use its configuration is something I find really painful.
I haven't had a chance to test it yet, but I believe fish 2.2 will allow the baking to finish. Fish cleverly parses the prompt to figure out how long it is (vs bash which requires you to wrap nonprinting sequences in \[ and \]). Unfortunately fish's support for OSC codes was incomplete. This was a problem because shell integration uses them to report the current directory, hostname, prompt location, etc., so fish would wrap at the wrong location. I submitted a patch a while back, but I can't very well ask people to run a hacked version of their shell. So until a few days ago it was half baked. Now it's like 90% baked :)
But all in all, sounds like an awesome set of features, will have to try tonight. Thanks!
PS: On an unrelated note, if later on you could add native support for pop out window to appear in full screen apps, and maybe do a check, so that if you are in full screen app mode, it pops over with 0 y offset, but if it's in a norma screen, it pops up with offset to accommodate the menu bar, that would be awesome. But no rush :), thanks for all the awesome work!
BTW if you're using iTerm, be aware that ⌘+clicking on a link will open the link in browser or ⌘+clicking a file in `ls` result will open the file with default app.
It's really interesting how OS X is the one that has a terminal emulator with the most features out there.
iTerm2 now comes with 24-bit colors, command completion popup, notifications, triggers, profiles, mouseless copy, split panes, search, and you can even have inline images/gifs all out of the box with zero or minimal configuration required. That's just awesome.
All of these features and iTerm2 still feels much faster than Terminator to me.
In my experience, the vast majority of web developers use OS X. Those of us doing server side and devops work spend a lot of time in the terminal
Actually that will be Windows with ConEmu. You can even run GUI apps inside the terminal with it.
Notably, keyboard-select allows you to cut/paste things into the X buffer from anywhere in the terminal scrollback using only keyboard shortcuts. url-select, conversely, allows you to cycle through any visible URLs and either open them in an external browser or copy them to the X buffer.
I like iTerm2 a lot, but one day when i coincidentally started using the normal Terminal i noticed how fast it was/how slow iTerm2 was, which is the reason i stopped using iTerm2 and switched to TotalTerminal (a plugin for Terminal.app).
I use a similar script/Automator app to "Open this directory in iterm" by dragging it into the Finder toolbar http://pastebin.com/1at3CXvP http://i.imgur.com/QGqQSOJ.png
brew installs and bundle installs and the like will be a joy now!
Linking to the alternativeto page for it, since it's free, but closed source...
http://www.hanselman.com/blog/Windows10GetsAFreshCommandProm...
I use screen a lot (yes I know, I should switch to tmux one day!) and shell integration doesn't seem to work properly with sessions inside screen. Works perfectly if I ssh directly. Is it going to be supported eventually or is this the ultimate signal for me to switch to tmux?
The easiest way to install shell integration is to select the iTerm2>Install Shell Integration menu item. It will download and run a shell script as described below.
...you'll see: "Don't care for piping curl to bash? Do it by hand. First, download the right script for your shell...."Also, is there a zsh version of this file? zsh is extremely popular on osx.
However i feel that it might somehow fuck up some things, as it is using some rather unconventional stuff.
# proxy n02 connections through bastion
host n02.university.edu
ProxyCommand ssh bastion.university.edu -W %h:%p 2> /dev/null
Almost all my remote shells require a similar setup.I have over 300 hosts defined in my .ssh/config file and it's indispensable to have all these options, especially when mixing in 2FA jump hosts into the mix.
- reusing ControlMaster bg connections
- smartcard auth
- agent support
- ssh_config support, including
- proxycommand
- Cipher selection
- KDF advances for on-disk key encryption
The list is long and expansive. You'd do better to submit a patch upstream for machine-readable progress output in OpenSSH's 'scp', and bundling that.
For folks who have setups where iTerm2's scp implementation can't connect, you can always download files over an existing ssh connection with this script:
https://raw.githubusercontent.com/gnachman/iTerm2/master/tes...
Upload is a little trickier, but you can copy a file to the pasteboard (e.g., in Finder) and then paste it base64-encoded (Edit > Paste Special > Paste File Base64-Encoded) into base64 -D >> filename.