2
0

ssh.h 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. #ifndef HEADER_CURL_SSH_H
  2. #define HEADER_CURL_SSH_H
  3. /***************************************************************************
  4. * _ _ ____ _
  5. * Project ___| | | | _ \| |
  6. * / __| | | | |_) | |
  7. * | (__| |_| | _ <| |___
  8. * \___|\___/|_| \_\_____|
  9. *
  10. * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
  11. *
  12. * This software is licensed as described in the file COPYING, which
  13. * you should have received as part of this distribution. The terms
  14. * are also available at https://curl.se/docs/copyright.html.
  15. *
  16. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  17. * copies of the Software, and permit persons to whom the Software is
  18. * furnished to do so, under the terms of the COPYING file.
  19. *
  20. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  21. * KIND, either express or implied.
  22. *
  23. * SPDX-License-Identifier: curl
  24. *
  25. ***************************************************************************/
  26. #include "curl_setup.h"
  27. #if defined(USE_LIBSSH2)
  28. #include <libssh2.h>
  29. #include <libssh2_sftp.h>
  30. #elif defined(USE_LIBSSH)
  31. #include <libssh/libssh.h>
  32. #include <libssh/sftp.h>
  33. #elif defined(USE_WOLFSSH)
  34. #include <wolfssh/ssh.h>
  35. #include <wolfssh/wolfsftp.h>
  36. #endif
  37. /****************************************************************************
  38. * SSH unique setup
  39. ***************************************************************************/
  40. typedef enum {
  41. SSH_NO_STATE = -1, /* Used for "nextState" so say there is none */
  42. SSH_STOP = 0, /* do nothing state, stops the state machine */
  43. SSH_INIT, /* First state in SSH-CONNECT */
  44. SSH_S_STARTUP, /* Session startup */
  45. SSH_HOSTKEY, /* verify hostkey */
  46. SSH_AUTHLIST,
  47. SSH_AUTH_PKEY_INIT,
  48. SSH_AUTH_PKEY,
  49. SSH_AUTH_PASS_INIT,
  50. SSH_AUTH_PASS,
  51. SSH_AUTH_AGENT_INIT, /* initialize then wait for connection to agent */
  52. SSH_AUTH_AGENT_LIST, /* ask for list then wait for entire list to come */
  53. SSH_AUTH_AGENT, /* attempt one key at a time */
  54. SSH_AUTH_HOST_INIT,
  55. SSH_AUTH_HOST,
  56. SSH_AUTH_KEY_INIT,
  57. SSH_AUTH_KEY,
  58. SSH_AUTH_GSSAPI,
  59. SSH_AUTH_DONE,
  60. SSH_SFTP_INIT,
  61. SSH_SFTP_REALPATH, /* Last state in SSH-CONNECT */
  62. SSH_SFTP_QUOTE_INIT, /* First state in SFTP-DO */
  63. SSH_SFTP_POSTQUOTE_INIT, /* (Possibly) First state in SFTP-DONE */
  64. SSH_SFTP_QUOTE,
  65. SSH_SFTP_NEXT_QUOTE,
  66. SSH_SFTP_QUOTE_STAT,
  67. SSH_SFTP_QUOTE_SETSTAT,
  68. SSH_SFTP_QUOTE_SYMLINK,
  69. SSH_SFTP_QUOTE_MKDIR,
  70. SSH_SFTP_QUOTE_RENAME,
  71. SSH_SFTP_QUOTE_RMDIR,
  72. SSH_SFTP_QUOTE_UNLINK,
  73. SSH_SFTP_QUOTE_STATVFS,
  74. SSH_SFTP_GETINFO,
  75. SSH_SFTP_FILETIME,
  76. SSH_SFTP_TRANS_INIT,
  77. SSH_SFTP_UPLOAD_INIT,
  78. SSH_SFTP_CREATE_DIRS_INIT,
  79. SSH_SFTP_CREATE_DIRS,
  80. SSH_SFTP_CREATE_DIRS_MKDIR,
  81. SSH_SFTP_READDIR_INIT,
  82. SSH_SFTP_READDIR,
  83. SSH_SFTP_READDIR_LINK,
  84. SSH_SFTP_READDIR_BOTTOM,
  85. SSH_SFTP_READDIR_DONE,
  86. SSH_SFTP_DOWNLOAD_INIT,
  87. SSH_SFTP_DOWNLOAD_STAT, /* Last state in SFTP-DO */
  88. SSH_SFTP_CLOSE, /* Last state in SFTP-DONE */
  89. SSH_SFTP_SHUTDOWN, /* First state in SFTP-DISCONNECT */
  90. SSH_SCP_TRANS_INIT, /* First state in SCP-DO */
  91. SSH_SCP_UPLOAD_INIT,
  92. SSH_SCP_DOWNLOAD_INIT,
  93. SSH_SCP_DOWNLOAD,
  94. SSH_SCP_DONE,
  95. SSH_SCP_SEND_EOF,
  96. SSH_SCP_WAIT_EOF,
  97. SSH_SCP_WAIT_CLOSE,
  98. SSH_SCP_CHANNEL_FREE, /* Last state in SCP-DONE */
  99. SSH_SESSION_DISCONNECT, /* First state in SCP-DISCONNECT */
  100. SSH_SESSION_FREE, /* Last state in SCP/SFTP-DISCONNECT */
  101. SSH_QUIT,
  102. SSH_LAST /* never used */
  103. } sshstate;
  104. /* this struct is used in the HandleData struct which is part of the
  105. Curl_easy, which means this is used on a per-easy handle basis.
  106. Everything that is strictly related to a connection is banned from this
  107. struct. */
  108. struct SSHPROTO {
  109. char *path; /* the path we operate on */
  110. #ifdef USE_LIBSSH2
  111. struct dynbuf readdir_link;
  112. struct dynbuf readdir;
  113. char *readdir_filename;
  114. char *readdir_longentry;
  115. LIBSSH2_SFTP_ATTRIBUTES quote_attrs; /* used by the SFTP_QUOTE state */
  116. /* Here's a set of struct members used by the SFTP_READDIR state */
  117. LIBSSH2_SFTP_ATTRIBUTES readdir_attrs;
  118. #endif
  119. };
  120. /* ssh_conn is used for struct connection-oriented data in the connectdata
  121. struct */
  122. struct ssh_conn {
  123. const char *authlist; /* List of auth. methods, managed by libssh2 */
  124. /* common */
  125. const char *passphrase; /* pass-phrase to use */
  126. char *rsa_pub; /* strdup'ed public key file */
  127. char *rsa; /* strdup'ed private key file */
  128. bool authed; /* the connection has been authenticated fine */
  129. bool acceptfail; /* used by the SFTP_QUOTE (continue if
  130. quote command fails) */
  131. sshstate state; /* always use ssh.c:state() to change state! */
  132. sshstate nextstate; /* the state to goto after stopping */
  133. CURLcode actualcode; /* the actual error code */
  134. struct curl_slist *quote_item; /* for the quote option */
  135. char *quote_path1; /* two generic pointers for the QUOTE stuff */
  136. char *quote_path2;
  137. char *homedir; /* when doing SFTP we figure out home dir in the
  138. connect phase */
  139. /* end of READDIR stuff */
  140. int secondCreateDirs; /* counter use by the code to see if the
  141. second attempt has been made to change
  142. to/create a directory */
  143. int orig_waitfor; /* default READ/WRITE bits wait for */
  144. char *slash_pos; /* used by the SFTP_CREATE_DIRS state */
  145. #if defined(USE_LIBSSH)
  146. char *readdir_linkPath;
  147. size_t readdir_len;
  148. struct dynbuf readdir_buf;
  149. /* our variables */
  150. unsigned kbd_state; /* 0 or 1 */
  151. ssh_key privkey;
  152. ssh_key pubkey;
  153. unsigned int auth_methods;
  154. ssh_session ssh_session;
  155. ssh_scp scp_session;
  156. sftp_session sftp_session;
  157. sftp_file sftp_file;
  158. sftp_dir sftp_dir;
  159. unsigned sftp_recv_state; /* 0 or 1 */
  160. int sftp_file_index; /* for async read */
  161. sftp_attributes readdir_attrs; /* used by the SFTP readdir actions */
  162. sftp_attributes readdir_link_attrs; /* used by the SFTP readdir actions */
  163. sftp_attributes quote_attrs; /* used by the SFTP_QUOTE state */
  164. const char *readdir_filename; /* points within readdir_attrs */
  165. const char *readdir_longentry;
  166. char *readdir_tmp;
  167. #elif defined(USE_LIBSSH2)
  168. LIBSSH2_SESSION *ssh_session; /* Secure Shell session */
  169. LIBSSH2_CHANNEL *ssh_channel; /* Secure Shell channel handle */
  170. LIBSSH2_SFTP *sftp_session; /* SFTP handle */
  171. LIBSSH2_SFTP_HANDLE *sftp_handle;
  172. #ifndef CURL_DISABLE_PROXY
  173. /* for HTTPS proxy storage */
  174. Curl_recv *tls_recv;
  175. Curl_send *tls_send;
  176. #endif
  177. #ifdef HAVE_LIBSSH2_AGENT_API
  178. LIBSSH2_AGENT *ssh_agent; /* proxy to ssh-agent/pageant */
  179. struct libssh2_agent_publickey *sshagent_identity,
  180. *sshagent_prev_identity;
  181. #endif
  182. /* note that HAVE_LIBSSH2_KNOWNHOST_API is a define set in the libssh2.h
  183. header */
  184. #ifdef HAVE_LIBSSH2_KNOWNHOST_API
  185. LIBSSH2_KNOWNHOSTS *kh;
  186. #endif
  187. #elif defined(USE_WOLFSSH)
  188. WOLFSSH *ssh_session;
  189. WOLFSSH_CTX *ctx;
  190. word32 handleSz;
  191. byte handle[WOLFSSH_MAX_HANDLE];
  192. curl_off_t offset;
  193. #endif /* USE_LIBSSH */
  194. };
  195. #if defined(USE_LIBSSH2)
  196. /* Feature detection based on version numbers to better work with
  197. non-configure platforms */
  198. #if !defined(LIBSSH2_VERSION_NUM) || (LIBSSH2_VERSION_NUM < 0x001000)
  199. # error "SCP/SFTP protocols require libssh2 0.16 or later"
  200. #endif
  201. #if LIBSSH2_VERSION_NUM >= 0x010000
  202. #define HAVE_LIBSSH2_SFTP_SEEK64 1
  203. #endif
  204. #if LIBSSH2_VERSION_NUM >= 0x010100
  205. #define HAVE_LIBSSH2_VERSION 1
  206. #endif
  207. #if LIBSSH2_VERSION_NUM >= 0x010205
  208. #define HAVE_LIBSSH2_INIT 1
  209. #define HAVE_LIBSSH2_EXIT 1
  210. #endif
  211. #if LIBSSH2_VERSION_NUM >= 0x010206
  212. #define HAVE_LIBSSH2_KNOWNHOST_CHECKP 1
  213. #define HAVE_LIBSSH2_SCP_SEND64 1
  214. #endif
  215. #if LIBSSH2_VERSION_NUM >= 0x010208
  216. #define HAVE_LIBSSH2_SESSION_HANDSHAKE 1
  217. #endif
  218. #ifdef HAVE_LIBSSH2_VERSION
  219. /* get it runtime if possible */
  220. #define CURL_LIBSSH2_VERSION libssh2_version(0)
  221. #else
  222. /* use build-time if runtime not possible */
  223. #define CURL_LIBSSH2_VERSION LIBSSH2_VERSION
  224. #endif
  225. #endif /* USE_LIBSSH2 */
  226. #ifdef USE_SSH
  227. extern const struct Curl_handler Curl_handler_scp;
  228. extern const struct Curl_handler Curl_handler_sftp;
  229. /* generic SSH backend functions */
  230. CURLcode Curl_ssh_init(void);
  231. void Curl_ssh_cleanup(void);
  232. void Curl_ssh_version(char *buffer, size_t buflen);
  233. void Curl_ssh_attach(struct Curl_easy *data,
  234. struct connectdata *conn);
  235. #else
  236. /* for non-SSH builds */
  237. #define Curl_ssh_cleanup()
  238. #define Curl_ssh_attach(x,y)
  239. #define Curl_ssh_init() 0
  240. #endif
  241. #endif /* HEADER_CURL_SSH_H */