summaryrefslogtreecommitdiff
path: root/packet.h
diff options
context:
space:
mode:
authorColin Watson <cjwatson@debian.org>2015-08-19 14:23:51 +0100
committerColin Watson <cjwatson@debian.org>2015-08-19 16:48:11 +0100
commit0f0841b2d28b7463267d4d91577e72e3340a1d3a (patch)
treeba55fcd2b6e2cc22b30f5afb561dbb3da4c8b6c7 /packet.h
parentf2a5f5dae656759efb0b76c3d94890b65c197a02 (diff)
parent8698446b972003b63dfe5dcbdb86acfe986afb85 (diff)
New upstream release (6.8p1).
Diffstat (limited to 'packet.h')
-rw-r--r--packet.h284
1 files changed, 181 insertions, 103 deletions
diff --git a/packet.h b/packet.h
index e7b5fcba9..7b06544e8 100644
--- a/packet.h
+++ b/packet.h
@@ -1,4 +1,4 @@
1/* $OpenBSD: packet.h,v 1.61 2014/05/03 17:20:34 markus Exp $ */ 1/* $OpenBSD: packet.h,v 1.66 2015/01/30 01:13:33 djm Exp $ */
2 2
3/* 3/*
4 * Author: Tatu Ylonen <ylo@cs.hut.fi> 4 * Author: Tatu Ylonen <ylo@cs.hut.fi>
@@ -18,111 +18,189 @@
18 18
19#include <termios.h> 19#include <termios.h>
20 20
21#include <openssl/bn.h> 21#ifdef WITH_OPENSSL
22#ifdef OPENSSL_HAS_ECC 22# include <openssl/bn.h>
23#include <openssl/ec.h> 23# ifdef OPENSSL_HAS_ECC
24#endif 24# include <openssl/ec.h>
25 25# else /* OPENSSL_HAS_ECC */
26void packet_set_connection(int, int); 26# define EC_KEY void
27void packet_set_timeout(int, int); 27# define EC_GROUP void
28void packet_set_nonblocking(void); 28# define EC_POINT void
29int packet_get_connection_in(void); 29# endif /* OPENSSL_HAS_ECC */
30int packet_get_connection_out(void); 30#else /* WITH_OPENSSL */
31void packet_close(void); 31# define BIGNUM void
32void packet_set_encryption_key(const u_char *, u_int, int); 32# define EC_KEY void
33u_int packet_get_encryption_key(u_char *); 33# define EC_GROUP void
34void packet_set_protocol_flags(u_int); 34# define EC_POINT void
35u_int packet_get_protocol_flags(void); 35#endif /* WITH_OPENSSL */
36void packet_start_compression(int); 36
37void packet_set_interactive(int, int, int); 37#include <signal.h>
38int packet_is_interactive(void); 38#include "openbsd-compat/sys-queue.h"
39void packet_set_server(void); 39
40void packet_set_authenticated(void); 40struct kex;
41 41struct sshkey;
42void packet_start(u_char); 42struct sshbuf;
43void packet_put_char(int ch); 43struct session_state; /* private session data */
44void packet_put_int(u_int value); 44
45void packet_put_int64(u_int64_t value); 45#include "dispatch.h" /* typedef, DISPATCH_MAX */
46void packet_put_bignum(BIGNUM * value); 46
47void packet_put_bignum2(BIGNUM * value); 47struct key_entry {
48#ifdef OPENSSL_HAS_ECC 48 TAILQ_ENTRY(key_entry) next;
49void packet_put_ecpoint(const EC_GROUP *, const EC_POINT *); 49 struct sshkey *key;
50#endif 50};
51void packet_put_string(const void *buf, u_int len); 51
52void packet_put_cstring(const char *str); 52struct ssh {
53void packet_put_raw(const void *buf, u_int len); 53 /* Session state */
54void packet_send(void); 54 struct session_state *state;
55 55
56int packet_read(void); 56 /* Key exchange */
57void packet_read_expect(int type); 57 struct kex *kex;
58void packet_process_incoming(const char *buf, u_int len); 58
59int packet_read_seqnr(u_int32_t *seqnr_p); 59 /* cached remote ip address and port*/
60int packet_read_poll_seqnr(u_int32_t *seqnr_p); 60 char *remote_ipaddr;
61 61 int remote_port;
62u_int packet_get_char(void); 62
63u_int packet_get_int(void); 63 /* Dispatcher table */
64u_int64_t packet_get_int64(void); 64 dispatch_fn *dispatch[DISPATCH_MAX];
65void packet_get_bignum(BIGNUM * value); 65 /* number of packets to ignore in the dispatcher */
66void packet_get_bignum2(BIGNUM * value); 66 int dispatch_skip_packets;
67#ifdef OPENSSL_HAS_ECC 67
68void packet_get_ecpoint(const EC_GROUP *, EC_POINT *); 68 /* datafellows */
69#endif 69 int compat;
70void *packet_get_raw(u_int *length_ptr); 70
71void *packet_get_string(u_int *length_ptr); 71 /* Lists for private and public keys */
72char *packet_get_cstring(u_int *length_ptr); 72 TAILQ_HEAD(, key_entry) private_keys;
73const void *packet_get_string_ptr(u_int *length_ptr); 73 TAILQ_HEAD(, key_entry) public_keys;
74void packet_disconnect(const char *fmt,...) __attribute__((noreturn)) __attribute__((format(printf, 1, 2))); 74
75void packet_send_debug(const char *fmt,...) __attribute__((format(printf, 1, 2))); 75 /* APP data */
76 76 void *app_data;
77void set_newkeys(int mode); 77};
78int packet_get_keyiv_len(int); 78
79void packet_get_keyiv(int, u_char *, u_int); 79struct ssh *ssh_alloc_session_state(void);
80int packet_get_keycontext(int, u_char *); 80struct ssh *ssh_packet_set_connection(struct ssh *, int, int);
81void packet_set_keycontext(int, u_char *); 81void ssh_packet_set_timeout(struct ssh *, int, int);
82void packet_get_state(int, u_int32_t *, u_int64_t *, u_int32_t *, u_int64_t *); 82int ssh_packet_stop_discard(struct ssh *);
83void packet_set_state(int, u_int32_t, u_int64_t, u_int32_t, u_int64_t); 83int ssh_packet_connection_af(struct ssh *);
84int packet_get_ssh1_cipher(void); 84void ssh_packet_set_nonblocking(struct ssh *);
85void packet_set_iv(int, u_char *); 85int ssh_packet_get_connection_in(struct ssh *);
86void *packet_get_newkeys(int); 86int ssh_packet_get_connection_out(struct ssh *);
87 87void ssh_packet_close(struct ssh *);
88void packet_write_poll(void); 88void ssh_packet_set_encryption_key(struct ssh *, const u_char *, u_int, int);
89void packet_write_wait(void); 89void ssh_packet_set_protocol_flags(struct ssh *, u_int);
90int packet_have_data_to_write(void); 90u_int ssh_packet_get_protocol_flags(struct ssh *);
91int packet_not_very_much_data_to_write(void); 91int ssh_packet_start_compression(struct ssh *, int);
92 92void ssh_packet_set_tos(struct ssh *, int);
93int packet_connection_is_on_socket(void); 93void ssh_packet_set_interactive(struct ssh *, int, int, int);
94int packet_remaining(void); 94int ssh_packet_is_interactive(struct ssh *);
95void packet_send_ignore(int); 95void ssh_packet_set_server(struct ssh *);
96void packet_add_padding(u_char); 96void ssh_packet_set_authenticated(struct ssh *);
97
98int ssh_packet_send1(struct ssh *);
99int ssh_packet_send2_wrapped(struct ssh *);
100int ssh_packet_send2(struct ssh *);
101
102int ssh_packet_read(struct ssh *);
103int ssh_packet_read_expect(struct ssh *, u_int type);
104int ssh_packet_read_poll(struct ssh *);
105int ssh_packet_read_poll1(struct ssh *, u_char *);
106int ssh_packet_read_poll2(struct ssh *, u_char *, u_int32_t *seqnr_p);
107int ssh_packet_process_incoming(struct ssh *, const char *buf, u_int len);
108int ssh_packet_read_seqnr(struct ssh *, u_char *, u_int32_t *seqnr_p);
109int ssh_packet_read_poll_seqnr(struct ssh *, u_char *, u_int32_t *seqnr_p);
110
111const void *ssh_packet_get_string_ptr(struct ssh *, u_int *length_ptr);
112void ssh_packet_disconnect(struct ssh *, const char *fmt, ...)
113 __attribute__((format(printf, 2, 3)))
114 __attribute__((noreturn));
115void ssh_packet_send_debug(struct ssh *, const char *fmt, ...) __attribute__((format(printf, 2, 3)));
116
117int ssh_set_newkeys(struct ssh *, int mode);
118void ssh_packet_get_bytes(struct ssh *, u_int64_t *, u_int64_t *);
119
120typedef void *(ssh_packet_comp_alloc_func)(void *, u_int, u_int);
121typedef void (ssh_packet_comp_free_func)(void *, void *);
122void ssh_packet_set_compress_hooks(struct ssh *, void *,
123 ssh_packet_comp_alloc_func *, ssh_packet_comp_free_func *);
124
125int ssh_packet_write_poll(struct ssh *);
126int ssh_packet_write_wait(struct ssh *);
127int ssh_packet_have_data_to_write(struct ssh *);
128int ssh_packet_not_very_much_data_to_write(struct ssh *);
129
130int ssh_packet_connection_is_on_socket(struct ssh *);
131int ssh_packet_remaining(struct ssh *);
132void ssh_packet_send_ignore(struct ssh *, int);
97 133
98void tty_make_modes(int, struct termios *); 134void tty_make_modes(int, struct termios *);
99void tty_parse_modes(int, int *); 135void tty_parse_modes(int, int *);
100 136
101void packet_set_alive_timeouts(int); 137void ssh_packet_set_alive_timeouts(struct ssh *, int);
102int packet_inc_alive_timeouts(void); 138int ssh_packet_inc_alive_timeouts(struct ssh *);
103int packet_set_maxsize(u_int); 139int ssh_packet_set_maxsize(struct ssh *, u_int);
104u_int packet_get_maxsize(void); 140u_int ssh_packet_get_maxsize(struct ssh *);
105 141
106/* don't allow remaining bytes after the end of the message */ 142int ssh_packet_get_state(struct ssh *, struct sshbuf *);
107#define packet_check_eom() \ 143int ssh_packet_set_state(struct ssh *, struct sshbuf *);
108do { \ 144
109 int _len = packet_remaining(); \ 145const char *ssh_remote_ipaddr(struct ssh *);
110 if (_len > 0) { \ 146
111 logit("Packet integrity error (%d bytes remaining) at %s:%d", \ 147int ssh_packet_need_rekeying(struct ssh *);
112 _len ,__FILE__, __LINE__); \ 148void ssh_packet_set_rekey_limits(struct ssh *, u_int32_t, time_t);
113 packet_disconnect("Packet integrity error."); \ 149time_t ssh_packet_get_rekey_timeout(struct ssh *);
114 } \ 150
115} while (0) 151/* XXX FIXME */
116 152void ssh_packet_backup_state(struct ssh *, struct ssh *);
117int packet_need_rekeying(void); 153void ssh_packet_restore_state(struct ssh *, struct ssh *);
118void packet_set_rekey_limits(u_int32_t, time_t); 154
119time_t packet_get_rekey_timeout(void); 155void *ssh_packet_get_input(struct ssh *);
120 156void *ssh_packet_get_output(struct ssh *);
121void packet_backup_state(void); 157
122void packet_restore_state(void); 158/* new API */
123void packet_set_postauth(void); 159int sshpkt_start(struct ssh *ssh, u_char type);
124 160int sshpkt_send(struct ssh *ssh);
125void *packet_get_input(void); 161int sshpkt_disconnect(struct ssh *, const char *fmt, ...)
126void *packet_get_output(void); 162 __attribute__((format(printf, 2, 3)));
163int sshpkt_add_padding(struct ssh *, u_char);
164void sshpkt_fatal(struct ssh *ssh, const char *tag, int r);
165
166int sshpkt_put(struct ssh *ssh, const void *v, size_t len);
167int sshpkt_putb(struct ssh *ssh, const struct sshbuf *b);
168int sshpkt_put_u8(struct ssh *ssh, u_char val);
169int sshpkt_put_u32(struct ssh *ssh, u_int32_t val);
170int sshpkt_put_u64(struct ssh *ssh, u_int64_t val);
171int sshpkt_put_string(struct ssh *ssh, const void *v, size_t len);
172int sshpkt_put_cstring(struct ssh *ssh, const void *v);
173int sshpkt_put_stringb(struct ssh *ssh, const struct sshbuf *v);
174int sshpkt_put_ec(struct ssh *ssh, const EC_POINT *v, const EC_GROUP *g);
175int sshpkt_put_bignum1(struct ssh *ssh, const BIGNUM *v);
176int sshpkt_put_bignum2(struct ssh *ssh, const BIGNUM *v);
177
178int sshpkt_get(struct ssh *ssh, void *valp, size_t len);
179int sshpkt_get_u8(struct ssh *ssh, u_char *valp);
180int sshpkt_get_u32(struct ssh *ssh, u_int32_t *valp);
181int sshpkt_get_u64(struct ssh *ssh, u_int64_t *valp);
182int sshpkt_get_string(struct ssh *ssh, u_char **valp, size_t *lenp);
183int sshpkt_get_string_direct(struct ssh *ssh, const u_char **valp, size_t *lenp);
184int sshpkt_get_cstring(struct ssh *ssh, char **valp, size_t *lenp);
185int sshpkt_get_ec(struct ssh *ssh, EC_POINT *v, const EC_GROUP *g);
186int sshpkt_get_bignum1(struct ssh *ssh, BIGNUM *v);
187int sshpkt_get_bignum2(struct ssh *ssh, BIGNUM *v);
188int sshpkt_get_end(struct ssh *ssh);
189const u_char *sshpkt_ptr(struct ssh *, size_t *lenp);
190
191/* OLD API */
192extern struct ssh *active_state;
193#include "opacket.h"
194
195#if !defined(WITH_OPENSSL)
196# undef BIGNUM
197# undef EC_KEY
198# undef EC_GROUP
199# undef EC_POINT
200#elif !defined(OPENSSL_HAS_ECC)
201# undef EC_KEY
202# undef EC_GROUP
203# undef EC_POINT
204#endif
127 205
128#endif /* PACKET_H */ 206#endif /* PACKET_H */