使用Here-Document自动化yubikey-luks-enroll命令时终端卡住,无法接收EOF输入
我之前在Stack Overflow上发过这个问题,被友好地引导到这里来啦,希望这次找对地方了😉
我想自动化我的Mint系统安装,其中一个关键步骤是用LUKS分区加密整个磁盘。为了能用Yubikey解锁设备,我需要运行这条命令:
yubikey-luks-enroll -d /dev/sda3 -s 7
这个命令可以通过sudo apt install yubikey-luks安装,单独运行的时候完全没问题,但用here-document来自动化执行就不行了。
当我手动执行sudo yubikey-luks-enroll -d /dev/sda3 -s 7时,会被要求输入三次内容:
setting disk to /dev/sda3.
setting slot to 7.
This script will utilize slot 7 on drive /dev/sda3. If this is not what you intended, exit now!
Adding yubikey to initrd
Please enter the yubikey challenge password. This is the password that will only work while your yubikey is installed in your computer:
Please enter the yubikey challenge password again:
Please provide an existing passphrase. This is NOT the passphrase you just entered, this is the passphrase that you currently use to unlock your LUKS encrypted drive:
我本来想用下面的bash脚本来自动化这个步骤:
read PART read -s DISKPWD read -s PWD1 read -s PWD2 sudo yubikey-luks-enroll -d $PART -s 7 <<-EOF $PWD1 $PWD2 $DISKPWD EOF
但运行这个脚本后,只会输出这些内容:
setting disk to /dev/sda3.
setting slot to 7.
This script will utilize slot 7 on drive /dev/sda3. If this is not what you intended, exit now!
Adding yubikey to initrd
更糟的是终端会卡住——可以输入内容但完全没反应,只能用CTRL + Z退出。
用Anaconda的安装脚本自动化时我也遇到过同样的问题。我试过在终端里不用here-document直接运行命令,没问题;但在终端里用here-document运行就会出现和脚本里一样的错误;把脚本里的here-document去掉,命令又能正常工作了。
顺便提一下,我需要给多个Yubikey设置相同的凭据,所以才想自动化这个流程。
有Stack Overflow的用户说这可能是因为这个安装脚本直接读取终端输出而不是标准输入(stdin)。如果是这样的话,有没有类似here-document的方法来给终端输入传值呢?我目前还没找到。
我不是经验丰富的Linux用户,可能只是犯了个简单的错误或者有概念误解,真的很想搞清楚到底哪里出问题了😊
备注:内容来源于stack exchange,提问作者133U

