2
0

ssh.h 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283
  1. #ifndef HEADER_CURL_SSH_H
  2. #define HEADER_CURL_SSH_H
  3. /***************************************************************************
  4. * _ _ ____ _
  5. * Project ___| | | | _ \| |
  6. * / __| | | | |_) | |
  7. * | (__| |_| | _ <| |___
  8. * \___|\___/|_| \_\_____|
  9. *
  10. * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
  11. *
  12. * This software is licensed as described in the file COPYING, which
  13. * you should have received as part of this distribution. The terms
  14. * are also available at https://curl.se/docs/copyright.html.
  15. *
  16. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  17. * copies of the Software, and permit persons to whom the Software is
  18. * furnished to do so, under the terms of the COPYING file.
  19. *
  20. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  21. * KIND, either express or implied.
  22. *
  23. * SPDX-License-Identifier: curl
  24. *
  25. ***************************************************************************/
  26. #include "curl_setup.h"
  27. #if defined(USE_LIBSSH2)
  28. #include <libssh2.h>
  29. #include <libssh2_sftp.h>
  30. #elif defined(USE_LIBSSH)
  31. /* in 0.10.0 or later, ignore deprecated warnings */
  32. #define SSH_SUPPRESS_DEPRECATED
  33. #include <libssh/libssh.h>
  34. #include <libssh/sftp.h>
  35. #elif defined(USE_WOLFSSH)
  36. #include <wolfssh/ssh.h>
  37. #include <wolfssh/wolfsftp.h>
  38. #endif
  39. #include "curl_path.h"
  40. /****************************************************************************
  41. * SSH unique setup
  42. ***************************************************************************/
  43. typedef enum {
  44. SSH_NO_STATE = -1, /* Used for "nextState" so say there is none */
  45. SSH_STOP = 0, /* do nothing state, stops the state machine */
  46. SSH_INIT, /* First state in SSH-CONNECT */
  47. SSH_S_STARTUP, /* Session startup */
  48. SSH_HOSTKEY, /* verify hostkey */
  49. SSH_AUTHLIST,
  50. SSH_AUTH_PKEY_INIT,
  51. SSH_AUTH_PKEY,
  52. SSH_AUTH_PASS_INIT,
  53. SSH_AUTH_PASS,
  54. SSH_AUTH_AGENT_INIT, /* initialize then wait for connection to agent */
  55. SSH_AUTH_AGENT_LIST, /* ask for list then wait for entire list to come */
  56. SSH_AUTH_AGENT, /* attempt one key at a time */
  57. SSH_AUTH_HOST_INIT,
  58. SSH_AUTH_HOST,
  59. SSH_AUTH_KEY_INIT,
  60. SSH_AUTH_KEY,
  61. SSH_AUTH_GSSAPI,
  62. SSH_AUTH_DONE,
  63. SSH_SFTP_INIT,
  64. SSH_SFTP_REALPATH, /* Last state in SSH-CONNECT */
  65. SSH_SFTP_QUOTE_INIT, /* First state in SFTP-DO */
  66. SSH_SFTP_POSTQUOTE_INIT, /* (Possibly) First state in SFTP-DONE */
  67. SSH_SFTP_QUOTE,
  68. SSH_SFTP_NEXT_QUOTE,
  69. SSH_SFTP_QUOTE_STAT,
  70. SSH_SFTP_QUOTE_SETSTAT,
  71. SSH_SFTP_QUOTE_SYMLINK,
  72. SSH_SFTP_QUOTE_MKDIR,
  73. SSH_SFTP_QUOTE_RENAME,
  74. SSH_SFTP_QUOTE_RMDIR,
  75. SSH_SFTP_QUOTE_UNLINK,
  76. SSH_SFTP_QUOTE_STATVFS,
  77. SSH_SFTP_GETINFO,
  78. SSH_SFTP_FILETIME,
  79. SSH_SFTP_TRANS_INIT,
  80. SSH_SFTP_UPLOAD_INIT,
  81. SSH_SFTP_CREATE_DIRS_INIT,
  82. SSH_SFTP_CREATE_DIRS,
  83. SSH_SFTP_CREATE_DIRS_MKDIR,
  84. SSH_SFTP_READDIR_INIT,
  85. SSH_SFTP_READDIR,
  86. SSH_SFTP_READDIR_LINK,
  87. SSH_SFTP_READDIR_BOTTOM,
  88. SSH_SFTP_READDIR_DONE,
  89. SSH_SFTP_DOWNLOAD_INIT,
  90. SSH_SFTP_DOWNLOAD_STAT, /* Last state in SFTP-DO */
  91. SSH_SFTP_CLOSE, /* Last state in SFTP-DONE */
  92. SSH_SFTP_SHUTDOWN, /* First state in SFTP-DISCONNECT */
  93. SSH_SCP_TRANS_INIT, /* First state in SCP-DO */
  94. SSH_SCP_UPLOAD_INIT,
  95. SSH_SCP_DOWNLOAD_INIT,
  96. SSH_SCP_DOWNLOAD,
  97. SSH_SCP_DONE,
  98. SSH_SCP_SEND_EOF,
  99. SSH_SCP_WAIT_EOF,
  100. SSH_SCP_WAIT_CLOSE,
  101. SSH_SCP_CHANNEL_FREE, /* Last state in SCP-DONE */
  102. SSH_SESSION_DISCONNECT, /* First state in SCP-DISCONNECT */
  103. SSH_SESSION_FREE, /* Last state in SCP/SFTP-DISCONNECT */
  104. SSH_QUIT,
  105. SSH_LAST /* never used */
  106. } sshstate;
  107. #define CURL_PATH_MAX 1024
  108. /* this struct is used in the HandleData struct which is part of the
  109. Curl_easy, which means this is used on a per-easy handle basis.
  110. Everything that is strictly related to a connection is banned from this
  111. struct. */
  112. struct SSHPROTO {
  113. char *path; /* the path we operate on */
  114. #ifdef USE_LIBSSH2
  115. struct dynbuf readdir_link;
  116. struct dynbuf readdir;
  117. char readdir_filename[CURL_PATH_MAX + 1];
  118. char readdir_longentry[CURL_PATH_MAX + 1];
  119. LIBSSH2_SFTP_ATTRIBUTES quote_attrs; /* used by the SFTP_QUOTE state */
  120. /* Here's a set of struct members used by the SFTP_READDIR state */
  121. LIBSSH2_SFTP_ATTRIBUTES readdir_attrs;
  122. #endif
  123. };
  124. /* ssh_conn is used for struct connection-oriented data in the connectdata
  125. struct */
  126. struct ssh_conn {
  127. const char *authlist; /* List of auth. methods, managed by libssh2 */
  128. /* common */
  129. const char *passphrase; /* pass-phrase to use */
  130. char *rsa_pub; /* strdup'ed public key file */
  131. char *rsa; /* strdup'ed private key file */
  132. bool authed; /* the connection has been authenticated fine */
  133. bool acceptfail; /* used by the SFTP_QUOTE (continue if
  134. quote command fails) */
  135. sshstate state; /* always use ssh.c:state() to change state! */
  136. sshstate nextstate; /* the state to goto after stopping */
  137. CURLcode actualcode; /* the actual error code */
  138. struct curl_slist *quote_item; /* for the quote option */
  139. char *quote_path1; /* two generic pointers for the QUOTE stuff */
  140. char *quote_path2;
  141. char *homedir; /* when doing SFTP we figure out home dir in the
  142. connect phase */
  143. /* end of READDIR stuff */
  144. int secondCreateDirs; /* counter use by the code to see if the
  145. second attempt has been made to change
  146. to/create a directory */
  147. int orig_waitfor; /* default READ/WRITE bits wait for */
  148. char *slash_pos; /* used by the SFTP_CREATE_DIRS state */
  149. #if defined(USE_LIBSSH)
  150. char *readdir_linkPath;
  151. size_t readdir_len;
  152. struct dynbuf readdir_buf;
  153. /* our variables */
  154. unsigned kbd_state; /* 0 or 1 */
  155. ssh_key privkey;
  156. ssh_key pubkey;
  157. unsigned int auth_methods;
  158. ssh_session ssh_session;
  159. ssh_scp scp_session;
  160. sftp_session sftp_session;
  161. sftp_file sftp_file;
  162. sftp_dir sftp_dir;
  163. unsigned sftp_recv_state; /* 0 or 1 */
  164. #if LIBSSH_VERSION_INT > SSH_VERSION_INT(0, 11, 0)
  165. sftp_aio sftp_aio;
  166. unsigned sftp_send_state; /* 0 or 1 */
  167. #endif
  168. int sftp_file_index; /* for async read */
  169. sftp_attributes readdir_attrs; /* used by the SFTP readdir actions */
  170. sftp_attributes readdir_link_attrs; /* used by the SFTP readdir actions */
  171. sftp_attributes quote_attrs; /* used by the SFTP_QUOTE state */
  172. const char *readdir_filename; /* points within readdir_attrs */
  173. const char *readdir_longentry;
  174. char *readdir_tmp;
  175. #elif defined(USE_LIBSSH2)
  176. LIBSSH2_SESSION *ssh_session; /* Secure Shell session */
  177. LIBSSH2_CHANNEL *ssh_channel; /* Secure Shell channel handle */
  178. LIBSSH2_SFTP *sftp_session; /* SFTP handle */
  179. LIBSSH2_SFTP_HANDLE *sftp_handle;
  180. #ifndef CURL_DISABLE_PROXY
  181. /* for HTTPS proxy storage */
  182. Curl_recv *tls_recv;
  183. Curl_send *tls_send;
  184. #endif
  185. #ifdef HAVE_LIBSSH2_AGENT_API
  186. LIBSSH2_AGENT *ssh_agent; /* proxy to ssh-agent/pageant */
  187. struct libssh2_agent_publickey *sshagent_identity,
  188. *sshagent_prev_identity;
  189. #endif
  190. /* note that HAVE_LIBSSH2_KNOWNHOST_API is a define set in the libssh2.h
  191. header */
  192. #ifdef HAVE_LIBSSH2_KNOWNHOST_API
  193. LIBSSH2_KNOWNHOSTS *kh;
  194. #endif
  195. #elif defined(USE_WOLFSSH)
  196. WOLFSSH *ssh_session;
  197. WOLFSSH_CTX *ctx;
  198. word32 handleSz;
  199. byte handle[WOLFSSH_MAX_HANDLE];
  200. curl_off_t offset;
  201. #endif /* USE_LIBSSH */
  202. };
  203. #if defined(USE_LIBSSH2)
  204. /* Feature detection based on version numbers to better work with
  205. non-configure platforms */
  206. #if !defined(LIBSSH2_VERSION_NUM) || (LIBSSH2_VERSION_NUM < 0x001000)
  207. # error "SCP/SFTP protocols require libssh2 0.16 or later"
  208. #endif
  209. #if LIBSSH2_VERSION_NUM >= 0x010000
  210. #define HAVE_LIBSSH2_SFTP_SEEK64 1
  211. #endif
  212. #if LIBSSH2_VERSION_NUM >= 0x010100
  213. #define HAVE_LIBSSH2_VERSION 1
  214. #endif
  215. #if LIBSSH2_VERSION_NUM >= 0x010205
  216. #define HAVE_LIBSSH2_INIT 1
  217. #define HAVE_LIBSSH2_EXIT 1
  218. #endif
  219. #if LIBSSH2_VERSION_NUM >= 0x010206
  220. #define HAVE_LIBSSH2_KNOWNHOST_CHECKP 1
  221. #define HAVE_LIBSSH2_SCP_SEND64 1
  222. #endif
  223. #if LIBSSH2_VERSION_NUM >= 0x010208
  224. #define HAVE_LIBSSH2_SESSION_HANDSHAKE 1
  225. #endif
  226. #ifdef HAVE_LIBSSH2_VERSION
  227. /* get it runtime if possible */
  228. #define CURL_LIBSSH2_VERSION libssh2_version(0)
  229. #else
  230. /* use build-time if runtime not possible */
  231. #define CURL_LIBSSH2_VERSION LIBSSH2_VERSION
  232. #endif
  233. #endif /* USE_LIBSSH2 */
  234. #ifdef USE_SSH
  235. extern const struct Curl_handler Curl_handler_scp;
  236. extern const struct Curl_handler Curl_handler_sftp;
  237. /* generic SSH backend functions */
  238. CURLcode Curl_ssh_init(void);
  239. void Curl_ssh_cleanup(void);
  240. void Curl_ssh_version(char *buffer, size_t buflen);
  241. void Curl_ssh_attach(struct Curl_easy *data,
  242. struct connectdata *conn);
  243. #else
  244. /* for non-SSH builds */
  245. #define Curl_ssh_cleanup()
  246. #define Curl_ssh_attach(x,y)
  247. #define Curl_ssh_init() 0
  248. #endif
  249. #endif /* HEADER_CURL_SSH_H */