| 1 | #ifndef HEADER_CURL_SSH_H |
| 2 | #define |
| 3 | /*************************************************************************** |
| 4 | * _ _ ____ _ |
| 5 | * Project ___| | | | _ \| | |
| 6 | * / __| | | | |_) | | |
| 7 | * | (__| |_| | _ <| |___ |
| 8 | * \___|\___/|_| \_\_____| |
| 9 | * |
| 10 | * Copyright (C) 1998 - 2021, Daniel Stenberg, <daniel@haxx.se>, et al. |
| 11 | * |
| 12 | * This software is licensed as described in the file COPYING, which |
| 13 | * you should have received as part of this distribution. The terms |
| 14 | * are also available at https://curl.se/docs/copyright.html. |
| 15 | * |
| 16 | * You may opt to use, copy, modify, merge, publish, distribute and/or sell |
| 17 | * copies of the Software, and permit persons to whom the Software is |
| 18 | * furnished to do so, under the terms of the COPYING file. |
| 19 | * |
| 20 | * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY |
| 21 | * KIND, either express or implied. |
| 22 | * |
| 23 | ***************************************************************************/ |
| 24 | |
| 25 | #include "curl_setup.h" |
| 26 | |
| 27 | #if defined(HAVE_LIBSSH2_H) |
| 28 | #include <libssh2.h> |
| 29 | #include <libssh2_sftp.h> |
| 30 | #elif defined(HAVE_LIBSSH_LIBSSH_H) |
| 31 | #include <libssh/libssh.h> |
| 32 | #include <libssh/sftp.h> |
| 33 | #elif defined(USE_WOLFSSH) |
| 34 | #include <wolfssh/ssh.h> |
| 35 | #include <wolfssh/wolfsftp.h> |
| 36 | #endif |
| 37 | |
| 38 | /**************************************************************************** |
| 39 | * SSH unique setup |
| 40 | ***************************************************************************/ |
| 41 | typedef enum { |
| 42 | SSH_NO_STATE = -1, /* Used for "nextState" so say there is none */ |
| 43 | SSH_STOP = 0, /* do nothing state, stops the state machine */ |
| 44 | |
| 45 | SSH_INIT, /* First state in SSH-CONNECT */ |
| 46 | SSH_S_STARTUP, /* Session startup */ |
| 47 | SSH_HOSTKEY, /* verify hostkey */ |
| 48 | SSH_AUTHLIST, |
| 49 | SSH_AUTH_PKEY_INIT, |
| 50 | SSH_AUTH_PKEY, |
| 51 | SSH_AUTH_PASS_INIT, |
| 52 | SSH_AUTH_PASS, |
| 53 | SSH_AUTH_AGENT_INIT, /* initialize then wait for connection to agent */ |
| 54 | SSH_AUTH_AGENT_LIST, /* ask for list then wait for entire list to come */ |
| 55 | SSH_AUTH_AGENT, /* attempt one key at a time */ |
| 56 | SSH_AUTH_HOST_INIT, |
| 57 | SSH_AUTH_HOST, |
| 58 | SSH_AUTH_KEY_INIT, |
| 59 | SSH_AUTH_KEY, |
| 60 | SSH_AUTH_GSSAPI, |
| 61 | SSH_AUTH_DONE, |
| 62 | SSH_SFTP_INIT, |
| 63 | SSH_SFTP_REALPATH, /* Last state in SSH-CONNECT */ |
| 64 | |
| 65 | SSH_SFTP_QUOTE_INIT, /* First state in SFTP-DO */ |
| 66 | SSH_SFTP_POSTQUOTE_INIT, /* (Possibly) First state in SFTP-DONE */ |
| 67 | SSH_SFTP_QUOTE, |
| 68 | SSH_SFTP_NEXT_QUOTE, |
| 69 | SSH_SFTP_QUOTE_STAT, |
| 70 | SSH_SFTP_QUOTE_SETSTAT, |
| 71 | SSH_SFTP_QUOTE_SYMLINK, |
| 72 | SSH_SFTP_QUOTE_MKDIR, |
| 73 | SSH_SFTP_QUOTE_RENAME, |
| 74 | SSH_SFTP_QUOTE_RMDIR, |
| 75 | SSH_SFTP_QUOTE_UNLINK, |
| 76 | SSH_SFTP_QUOTE_STATVFS, |
| 77 | SSH_SFTP_GETINFO, |
| 78 | SSH_SFTP_FILETIME, |
| 79 | SSH_SFTP_TRANS_INIT, |
| 80 | SSH_SFTP_UPLOAD_INIT, |
| 81 | SSH_SFTP_CREATE_DIRS_INIT, |
| 82 | SSH_SFTP_CREATE_DIRS, |
| 83 | SSH_SFTP_CREATE_DIRS_MKDIR, |
| 84 | SSH_SFTP_READDIR_INIT, |
| 85 | SSH_SFTP_READDIR, |
| 86 | SSH_SFTP_READDIR_LINK, |
| 87 | SSH_SFTP_READDIR_BOTTOM, |
| 88 | SSH_SFTP_READDIR_DONE, |
| 89 | SSH_SFTP_DOWNLOAD_INIT, |
| 90 | SSH_SFTP_DOWNLOAD_STAT, /* Last state in SFTP-DO */ |
| 91 | SSH_SFTP_CLOSE, /* Last state in SFTP-DONE */ |
| 92 | SSH_SFTP_SHUTDOWN, /* First state in SFTP-DISCONNECT */ |
| 93 | SSH_SCP_TRANS_INIT, /* First state in SCP-DO */ |
| 94 | SSH_SCP_UPLOAD_INIT, |
| 95 | SSH_SCP_DOWNLOAD_INIT, |
| 96 | SSH_SCP_DOWNLOAD, |
| 97 | SSH_SCP_DONE, |
| 98 | SSH_SCP_SEND_EOF, |
| 99 | SSH_SCP_WAIT_EOF, |
| 100 | SSH_SCP_WAIT_CLOSE, |
| 101 | SSH_SCP_CHANNEL_FREE, /* Last state in SCP-DONE */ |
| 102 | SSH_SESSION_DISCONNECT, /* First state in SCP-DISCONNECT */ |
| 103 | SSH_SESSION_FREE, /* Last state in SCP/SFTP-DISCONNECT */ |
| 104 | SSH_QUIT, |
| 105 | SSH_LAST /* never used */ |
| 106 | } sshstate; |
| 107 | |
| 108 | /* this struct is used in the HandleData struct which is part of the |
| 109 | Curl_easy, which means this is used on a per-easy handle basis. |
| 110 | Everything that is strictly related to a connection is banned from this |
| 111 | struct. */ |
| 112 | struct SSHPROTO { |
| 113 | char *path; /* the path we operate on */ |
| 114 | #ifdef USE_LIBSSH2 |
| 115 | struct dynbuf readdir_link; |
| 116 | struct dynbuf readdir; |
| 117 | char *readdir_filename; |
| 118 | char *readdir_longentry; |
| 119 | |
| 120 | LIBSSH2_SFTP_ATTRIBUTES quote_attrs; /* used by the SFTP_QUOTE state */ |
| 121 | |
| 122 | /* Here's a set of struct members used by the SFTP_READDIR state */ |
| 123 | LIBSSH2_SFTP_ATTRIBUTES readdir_attrs; |
| 124 | #endif |
| 125 | }; |
| 126 | |
| 127 | /* ssh_conn is used for struct connection-oriented data in the connectdata |
| 128 | struct */ |
| 129 | struct ssh_conn { |
| 130 | const char *authlist; /* List of auth. methods, managed by libssh2 */ |
| 131 | |
| 132 | /* common */ |
| 133 | const char *passphrase; /* pass-phrase to use */ |
| 134 | char *rsa_pub; /* path name */ |
| 135 | char *rsa; /* path name */ |
| 136 | bool authed; /* the connection has been authenticated fine */ |
| 137 | bool acceptfail; /* used by the SFTP_QUOTE (continue if |
| 138 | quote command fails) */ |
| 139 | sshstate state; /* always use ssh.c:state() to change state! */ |
| 140 | sshstate nextstate; /* the state to goto after stopping */ |
| 141 | CURLcode actualcode; /* the actual error code */ |
| 142 | struct curl_slist *quote_item; /* for the quote option */ |
| 143 | char *quote_path1; /* two generic pointers for the QUOTE stuff */ |
| 144 | char *quote_path2; |
| 145 | |
| 146 | char *homedir; /* when doing SFTP we figure out home dir in the |
| 147 | connect phase */ |
| 148 | char *readdir_line; |
| 149 | /* end of READDIR stuff */ |
| 150 | |
| 151 | int secondCreateDirs; /* counter use by the code to see if the |
| 152 | second attempt has been made to change |
| 153 | to/create a directory */ |
| 154 | int orig_waitfor; /* default READ/WRITE bits wait for */ |
| 155 | char *slash_pos; /* used by the SFTP_CREATE_DIRS state */ |
| 156 | |
| 157 | #if defined(USE_LIBSSH) |
| 158 | char *readdir_linkPath; |
| 159 | size_t readdir_len, readdir_totalLen, readdir_currLen; |
| 160 | /* our variables */ |
| 161 | unsigned kbd_state; /* 0 or 1 */ |
| 162 | ssh_key privkey; |
| 163 | ssh_key pubkey; |
| 164 | int auth_methods; |
| 165 | ssh_session ssh_session; |
| 166 | ssh_scp scp_session; |
| 167 | sftp_session sftp_session; |
| 168 | sftp_file sftp_file; |
| 169 | sftp_dir sftp_dir; |
| 170 | |
| 171 | unsigned sftp_recv_state; /* 0 or 1 */ |
| 172 | int sftp_file_index; /* for async read */ |
| 173 | sftp_attributes readdir_attrs; /* used by the SFTP readdir actions */ |
| 174 | sftp_attributes readdir_link_attrs; /* used by the SFTP readdir actions */ |
| 175 | sftp_attributes quote_attrs; /* used by the SFTP_QUOTE state */ |
| 176 | |
| 177 | const char *readdir_filename; /* points within readdir_attrs */ |
| 178 | const char *readdir_longentry; |
| 179 | char *readdir_tmp; |
| 180 | #elif defined(USE_LIBSSH2) |
| 181 | LIBSSH2_SESSION *ssh_session; /* Secure Shell session */ |
| 182 | LIBSSH2_CHANNEL *ssh_channel; /* Secure Shell channel handle */ |
| 183 | LIBSSH2_SFTP *sftp_session; /* SFTP handle */ |
| 184 | LIBSSH2_SFTP_HANDLE *sftp_handle; |
| 185 | |
| 186 | #ifndef CURL_DISABLE_PROXY |
| 187 | /* for HTTPS proxy storage */ |
| 188 | Curl_recv *tls_recv; |
| 189 | Curl_send *tls_send; |
| 190 | #endif |
| 191 | |
| 192 | #ifdef HAVE_LIBSSH2_AGENT_API |
| 193 | LIBSSH2_AGENT *ssh_agent; /* proxy to ssh-agent/pageant */ |
| 194 | struct libssh2_agent_publickey *sshagent_identity, |
| 195 | *sshagent_prev_identity; |
| 196 | #endif |
| 197 | |
| 198 | /* note that HAVE_LIBSSH2_KNOWNHOST_API is a define set in the libssh2.h |
| 199 | header */ |
| 200 | #ifdef HAVE_LIBSSH2_KNOWNHOST_API |
| 201 | LIBSSH2_KNOWNHOSTS *kh; |
| 202 | #endif |
| 203 | #elif defined(USE_WOLFSSH) |
| 204 | WOLFSSH *ssh_session; |
| 205 | WOLFSSH_CTX *ctx; |
| 206 | word32 handleSz; |
| 207 | byte handle[WOLFSSH_MAX_HANDLE]; |
| 208 | curl_off_t offset; |
| 209 | #endif /* USE_LIBSSH */ |
| 210 | }; |
| 211 | |
| 212 | #if defined(USE_LIBSSH) |
| 213 | |
| 214 | #define CURL_LIBSSH_VERSION ssh_version(0) |
| 215 | |
| 216 | #elif defined(USE_LIBSSH2) |
| 217 | |
| 218 | /* Feature detection based on version numbers to better work with |
| 219 | non-configure platforms */ |
| 220 | |
| 221 | #if !defined(LIBSSH2_VERSION_NUM) || (LIBSSH2_VERSION_NUM < 0x001000) |
| 222 | # error "SCP/SFTP protocols require libssh2 0.16 or later" |
| 223 | #endif |
| 224 | |
| 225 | #if LIBSSH2_VERSION_NUM >= 0x010000 |
| 226 | #define HAVE_LIBSSH2_SFTP_SEEK64 1 |
| 227 | #endif |
| 228 | |
| 229 | #if LIBSSH2_VERSION_NUM >= 0x010100 |
| 230 | #define HAVE_LIBSSH2_VERSION 1 |
| 231 | #endif |
| 232 | |
| 233 | #if LIBSSH2_VERSION_NUM >= 0x010205 |
| 234 | #define HAVE_LIBSSH2_INIT 1 |
| 235 | #define HAVE_LIBSSH2_EXIT 1 |
| 236 | #endif |
| 237 | |
| 238 | #if LIBSSH2_VERSION_NUM >= 0x010206 |
| 239 | #define HAVE_LIBSSH2_KNOWNHOST_CHECKP 1 |
| 240 | #define HAVE_LIBSSH2_SCP_SEND64 1 |
| 241 | #endif |
| 242 | |
| 243 | #if LIBSSH2_VERSION_NUM >= 0x010208 |
| 244 | #define HAVE_LIBSSH2_SESSION_HANDSHAKE 1 |
| 245 | #endif |
| 246 | |
| 247 | #ifdef HAVE_LIBSSH2_VERSION |
| 248 | /* get it run-time if possible */ |
| 249 | #define CURL_LIBSSH2_VERSION libssh2_version(0) |
| 250 | #else |
| 251 | /* use build-time if run-time not possible */ |
| 252 | #define CURL_LIBSSH2_VERSION LIBSSH2_VERSION |
| 253 | #endif |
| 254 | |
| 255 | #endif /* USE_LIBSSH2 */ |
| 256 | |
| 257 | #ifdef USE_SSH |
| 258 | |
| 259 | extern const struct Curl_handler Curl_handler_scp; |
| 260 | extern const struct Curl_handler Curl_handler_sftp; |
| 261 | |
| 262 | /* generic SSH backend functions */ |
| 263 | CURLcode Curl_ssh_init(void); |
| 264 | void Curl_ssh_cleanup(void); |
| 265 | void Curl_ssh_version(char *buffer, size_t buflen); |
| 266 | void Curl_ssh_attach(struct Curl_easy *data, |
| 267 | struct connectdata *conn); |
| 268 | #else |
| 269 | /* for non-SSH builds */ |
| 270 | #define Curl_ssh_cleanup() |
| 271 | #define Curl_ssh_attach(x,y) |
| 272 | #endif |
| 273 | |
| 274 | #endif /* HEADER_CURL_SSH_H */ |
| 275 | |