xref: /dflybsd-src/crypto/openssh/misc.h (revision ba1276acd1c8c22d225b1bcf370a14c878644f44)
1*ba1276acSMatthew Dillon /* $OpenBSD: misc.h,v 1.109 2024/06/06 17:15:25 djm Exp $ */
218de8d7fSPeter Avalos 
318de8d7fSPeter Avalos /*
418de8d7fSPeter Avalos  * Author: Tatu Ylonen <ylo@cs.hut.fi>
518de8d7fSPeter Avalos  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
618de8d7fSPeter Avalos  *                    All rights reserved
718de8d7fSPeter Avalos  *
818de8d7fSPeter Avalos  * As far as I am concerned, the code I have written for this software
918de8d7fSPeter Avalos  * can be used freely for any purpose.  Any derived versions of this
1018de8d7fSPeter Avalos  * software must be clearly marked as such, and if the derived work is
1118de8d7fSPeter Avalos  * incompatible with the protocol description in the RFC file, it must be
1218de8d7fSPeter Avalos  * called by a name other than "ssh" or "Secure Shell".
1318de8d7fSPeter Avalos  */
1418de8d7fSPeter Avalos 
1518de8d7fSPeter Avalos #ifndef _MISC_H
1618de8d7fSPeter Avalos #define _MISC_H
1718de8d7fSPeter Avalos 
18ce74bacaSMatthew Dillon #include <sys/time.h>
19ce74bacaSMatthew Dillon #include <sys/types.h>
20664f4763Szrj #include <sys/socket.h>
2150a69bb5SSascha Wildner #include <stdio.h>
22*ba1276acSMatthew Dillon #include <signal.h>
23*ba1276acSMatthew Dillon 
24*ba1276acSMatthew Dillon /* special-case port number meaning allow any port */
25*ba1276acSMatthew Dillon #define FWD_PERMIT_ANY_PORT	0
26*ba1276acSMatthew Dillon 
27*ba1276acSMatthew Dillon /* special-case wildcard meaning allow any host */
28*ba1276acSMatthew Dillon #define FWD_PERMIT_ANY_HOST	"*"
29ce74bacaSMatthew Dillon 
3036e94dc5SPeter Avalos /* Data structure for representing a forwarding request. */
3136e94dc5SPeter Avalos struct Forward {
3236e94dc5SPeter Avalos 	char	 *listen_host;		/* Host (address) to listen on. */
3336e94dc5SPeter Avalos 	int	  listen_port;		/* Port to forward. */
3436e94dc5SPeter Avalos 	char	 *listen_path;		/* Path to bind domain socket. */
3536e94dc5SPeter Avalos 	char	 *connect_host;		/* Host to connect. */
3636e94dc5SPeter Avalos 	int	  connect_port;		/* Port to connect on connect_host. */
3736e94dc5SPeter Avalos 	char	 *connect_path;		/* Path to connect domain socket. */
3836e94dc5SPeter Avalos 	int	  allocated_port;	/* Dynamically allocated listen port */
3936e94dc5SPeter Avalos 	int	  handle;		/* Handle for dynamic listen ports */
4036e94dc5SPeter Avalos };
4136e94dc5SPeter Avalos 
42e9778795SPeter Avalos int forward_equals(const struct Forward *, const struct Forward *);
43*ba1276acSMatthew Dillon int permitopen_port(const char *p);
44*ba1276acSMatthew Dillon 
45ce74bacaSMatthew Dillon int daemonized(void);
46e9778795SPeter Avalos 
4736e94dc5SPeter Avalos /* Common server and client forwarding options. */
4836e94dc5SPeter Avalos struct ForwardOptions {
4936e94dc5SPeter Avalos 	int	 gateway_ports; /* Allow remote connects to forwarded ports. */
5036e94dc5SPeter Avalos 	mode_t	 streamlocal_bind_mask; /* umask for streamlocal binds */
5136e94dc5SPeter Avalos 	int	 streamlocal_bind_unlink; /* unlink socket before bind */
5236e94dc5SPeter Avalos };
5336e94dc5SPeter Avalos 
5418de8d7fSPeter Avalos /* misc.c */
5518de8d7fSPeter Avalos 
5618de8d7fSPeter Avalos char	*chop(char *);
5750a69bb5SSascha Wildner void	 rtrim(char *);
580cbfa66cSDaniel Fojt void	skip_space(char **);
5918de8d7fSPeter Avalos char	*strdelim(char **);
60664f4763Szrj char	*strdelimw(char **);
6118de8d7fSPeter Avalos int	 set_nonblock(int);
6218de8d7fSPeter Avalos int	 unset_nonblock(int);
6318de8d7fSPeter Avalos void	 set_nodelay(int);
64664f4763Szrj int	 set_reuseaddr(int);
65664f4763Szrj char	*get_rdomain(int);
66664f4763Szrj int	 set_rdomain(int, const char *);
6750a69bb5SSascha Wildner int	 get_sock_af(int);
6850a69bb5SSascha Wildner void	 set_sock_tos(int, int);
69*ba1276acSMatthew Dillon int	 waitrfd(int, int *, volatile sig_atomic_t *);
70664f4763Szrj int	 timeout_connect(int, const struct sockaddr *, socklen_t, int *);
7118de8d7fSPeter Avalos int	 a2port(const char *);
7218de8d7fSPeter Avalos int	 a2tun(const char *, int *);
7318de8d7fSPeter Avalos char	*put_host_port(const char *, u_short);
74664f4763Szrj char	*hpdelim2(char **, char *);
7518de8d7fSPeter Avalos char	*hpdelim(char **);
7618de8d7fSPeter Avalos char	*cleanhostname(char *);
7718de8d7fSPeter Avalos char	*colon(char *);
78664f4763Szrj int	 parse_user_host_path(const char *, char **, char **, char **);
79e9778795SPeter Avalos int	 parse_user_host_port(const char *, char **, char **, int *);
80664f4763Szrj int	 parse_uri(const char *, const char *, char **, char **, int *, char **);
8150a69bb5SSascha Wildner int	 convtime(const char *);
8250a69bb5SSascha Wildner const char *fmt_timeframe(time_t t);
8350a69bb5SSascha Wildner int	 tilde_expand(const char *, uid_t, char **);
8418de8d7fSPeter Avalos char	*tilde_expand_filename(const char *, uid_t);
8550a69bb5SSascha Wildner 
8650a69bb5SSascha Wildner char	*dollar_expand(int *, const char *string, ...);
8718de8d7fSPeter Avalos char	*percent_expand(const char *, ...) __attribute__((__sentinel__));
8850a69bb5SSascha Wildner char	*percent_dollar_expand(const char *, ...) __attribute__((__sentinel__));
8918de8d7fSPeter Avalos char	*tohex(const void *, size_t);
900cbfa66cSDaniel Fojt void	 xextendf(char **s, const char *sep, const char *fmt, ...)
910cbfa66cSDaniel Fojt     __attribute__((__format__ (printf, 3, 4))) __attribute__((__nonnull__ (3)));
9218de8d7fSPeter Avalos void	 sanitise_stdfd(void);
9318de8d7fSPeter Avalos void	 ms_subtract_diff(struct timeval *, int *);
94ee116499SAntonio Huete Jimenez void	 ms_to_timespec(struct timespec *, int);
95664f4763Szrj void	 monotime_ts(struct timespec *);
96664f4763Szrj void	 monotime_tv(struct timeval *);
9736e94dc5SPeter Avalos time_t	 monotime(void);
98e9778795SPeter Avalos double	 monotime_double(void);
9936e94dc5SPeter Avalos void	 lowercase(char *s);
10036e94dc5SPeter Avalos int	 unix_listener(const char *, int, int);
101664f4763Szrj int	 valid_domain(char *, int, const char **);
102664f4763Szrj int	 valid_env_name(const char *);
103664f4763Szrj const char *atoi_err(const char *, int *);
104664f4763Szrj int	 parse_absolute_time(const char *, uint64_t *);
105664f4763Szrj void	 format_absolute_time(uint64_t, char *, size_t);
106*ba1276acSMatthew Dillon int	 parse_pattern_interval(const char *, char **, int *);
107664f4763Szrj int	 path_absolute(const char *);
10850a69bb5SSascha Wildner int	 stdfd_devnull(int, int, int);
109*ba1276acSMatthew Dillon int	 lib_contains_symbol(const char *, const char *);
11036e94dc5SPeter Avalos 
111856ea928SPeter Avalos void	 sock_set_v6only(int);
11218de8d7fSPeter Avalos 
11318de8d7fSPeter Avalos struct passwd *pwcopy(struct passwd *);
11418de8d7fSPeter Avalos const char *ssh_gai_strerror(int);
11518de8d7fSPeter Avalos 
11650a69bb5SSascha Wildner typedef void privdrop_fn(struct passwd *);
11750a69bb5SSascha Wildner typedef void privrestore_fn(void);
11850a69bb5SSascha Wildner #define	SSH_SUBPROCESS_STDOUT_DISCARD	(1)     /* Discard stdout */
11950a69bb5SSascha Wildner #define	SSH_SUBPROCESS_STDOUT_CAPTURE	(1<<1)  /* Redirect stdout */
12050a69bb5SSascha Wildner #define	SSH_SUBPROCESS_STDERR_DISCARD	(1<<2)  /* Discard stderr */
12150a69bb5SSascha Wildner #define	SSH_SUBPROCESS_UNSAFE_PATH	(1<<3)	/* Don't check for safe cmd */
12250a69bb5SSascha Wildner #define	SSH_SUBPROCESS_PRESERVE_ENV	(1<<4)	/* Keep parent environment */
12350a69bb5SSascha Wildner pid_t subprocess(const char *, const char *, int, char **, FILE **, u_int,
12450a69bb5SSascha Wildner     struct passwd *, privdrop_fn *, privrestore_fn *);
12550a69bb5SSascha Wildner 
12618de8d7fSPeter Avalos typedef struct arglist arglist;
12718de8d7fSPeter Avalos struct arglist {
12818de8d7fSPeter Avalos 	char    **list;
12918de8d7fSPeter Avalos 	u_int   num;
13018de8d7fSPeter Avalos 	u_int   nalloc;
13118de8d7fSPeter Avalos };
13218de8d7fSPeter Avalos void	 addargs(arglist *, char *, ...)
13318de8d7fSPeter Avalos 	    __attribute__((format(printf, 2, 3)));
13418de8d7fSPeter Avalos void	 replacearg(arglist *, u_int, char *, ...)
13518de8d7fSPeter Avalos 	    __attribute__((format(printf, 3, 4)));
13618de8d7fSPeter Avalos void	 freeargs(arglist *);
13718de8d7fSPeter Avalos 
138664f4763Szrj int	 tun_open(int, int, char **);
13918de8d7fSPeter Avalos 
14018de8d7fSPeter Avalos /* Common definitions for ssh tunnel device forwarding */
14118de8d7fSPeter Avalos #define SSH_TUNMODE_NO		0x00
14218de8d7fSPeter Avalos #define SSH_TUNMODE_POINTOPOINT	0x01
14318de8d7fSPeter Avalos #define SSH_TUNMODE_ETHERNET	0x02
14418de8d7fSPeter Avalos #define SSH_TUNMODE_DEFAULT	SSH_TUNMODE_POINTOPOINT
14518de8d7fSPeter Avalos #define SSH_TUNMODE_YES		(SSH_TUNMODE_POINTOPOINT|SSH_TUNMODE_ETHERNET)
14618de8d7fSPeter Avalos 
14718de8d7fSPeter Avalos #define SSH_TUNID_ANY		0x7fffffff
14818de8d7fSPeter Avalos #define SSH_TUNID_ERR		(SSH_TUNID_ANY - 1)
14918de8d7fSPeter Avalos #define SSH_TUNID_MAX		(SSH_TUNID_ANY - 2)
15018de8d7fSPeter Avalos 
15136e94dc5SPeter Avalos /* Fake port to indicate that host field is really a path. */
15236e94dc5SPeter Avalos #define PORT_STREAMLOCAL	-2
15336e94dc5SPeter Avalos 
15418de8d7fSPeter Avalos /* Functions to extract or store big-endian words of various sizes */
15518de8d7fSPeter Avalos u_int64_t	get_u64(const void *)
15618de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 8)));
15718de8d7fSPeter Avalos u_int32_t	get_u32(const void *)
15818de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 4)));
15918de8d7fSPeter Avalos u_int16_t	get_u16(const void *)
16018de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 2)));
16118de8d7fSPeter Avalos void		put_u64(void *, u_int64_t)
16218de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 8)));
16318de8d7fSPeter Avalos void		put_u32(void *, u_int32_t)
16418de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 4)));
16518de8d7fSPeter Avalos void		put_u16(void *, u_int16_t)
16618de8d7fSPeter Avalos     __attribute__((__bounded__( __minbytes__, 1, 2)));
16718de8d7fSPeter Avalos 
16836e94dc5SPeter Avalos /* Little-endian store/load, used by umac.c */
16936e94dc5SPeter Avalos u_int32_t	get_u32_le(const void *)
17036e94dc5SPeter Avalos     __attribute__((__bounded__(__minbytes__, 1, 4)));
17136e94dc5SPeter Avalos void		put_u32_le(void *, u_int32_t)
17236e94dc5SPeter Avalos     __attribute__((__bounded__(__minbytes__, 1, 4)));
17336e94dc5SPeter Avalos 
1749f304aafSPeter Avalos struct bwlimit {
1759f304aafSPeter Avalos 	size_t buflen;
176664f4763Szrj 	u_int64_t rate;		/* desired rate in kbit/s */
177664f4763Szrj 	u_int64_t thresh;	/* threshold after which we'll check timers */
178664f4763Szrj 	u_int64_t lamt;		/* amount written in last timer interval */
1799f304aafSPeter Avalos 	struct timeval bwstart, bwend;
1809f304aafSPeter Avalos };
1819f304aafSPeter Avalos 
1829f304aafSPeter Avalos void bandwidth_limit_init(struct bwlimit *, u_int64_t, size_t);
1839f304aafSPeter Avalos void bandwidth_limit(struct bwlimit *, size_t);
1849f304aafSPeter Avalos 
1859f304aafSPeter Avalos int parse_ipqos(const char *);
1861c188a7fSPeter Avalos const char *iptos2str(int);
1879f304aafSPeter Avalos void mktemp_proto(char *, size_t);
18818de8d7fSPeter Avalos 
189ce74bacaSMatthew Dillon void	 child_set_env(char ***envp, u_int *envsizep, const char *name,
190ce74bacaSMatthew Dillon 	    const char *value);
19150a69bb5SSascha Wildner const char *lookup_env_in_list(const char *env,
19250a69bb5SSascha Wildner 	    char * const *envs, size_t nenvs);
193ee116499SAntonio Huete Jimenez const char *lookup_setenv_in_list(const char *env,
194ee116499SAntonio Huete Jimenez 	    char * const *envs, size_t nenvs);
195ce74bacaSMatthew Dillon 
19650a69bb5SSascha Wildner int	 argv_split(const char *, int *, char ***, int);
197ce74bacaSMatthew Dillon char	*argv_assemble(int, char **argv);
19850a69bb5SSascha Wildner char	*argv_next(int *, char ***);
19950a69bb5SSascha Wildner void	 argv_consume(int *);
20050a69bb5SSascha Wildner void	 argv_free(char **, int);
20150a69bb5SSascha Wildner 
202ce74bacaSMatthew Dillon int	 exited_cleanly(pid_t, const char *, const char *, int);
203ce74bacaSMatthew Dillon 
204ce74bacaSMatthew Dillon struct stat;
205ce74bacaSMatthew Dillon int	 safe_path(const char *, struct stat *, const char *, uid_t,
206ce74bacaSMatthew Dillon 	    char *, size_t);
207ce74bacaSMatthew Dillon int	 safe_path_fd(int, const char *, struct passwd *,
208ce74bacaSMatthew Dillon 	    char *err, size_t errlen);
209ce74bacaSMatthew Dillon 
2100cbfa66cSDaniel Fojt /* authorized_key-style options parsing helpers */
2110cbfa66cSDaniel Fojt int	opt_flag(const char *opt, int allow_negate, const char **optsp);
2120cbfa66cSDaniel Fojt char	*opt_dequote(const char **sp, const char **errstrp);
2130cbfa66cSDaniel Fojt int	opt_match(const char **opts, const char *term);
2140cbfa66cSDaniel Fojt 
21550a69bb5SSascha Wildner /* readconf/servconf option lists */
21650a69bb5SSascha Wildner void	opt_array_append(const char *file, const int line,
21750a69bb5SSascha Wildner 	    const char *directive, char ***array, u_int *lp, const char *s);
21850a69bb5SSascha Wildner void	opt_array_append2(const char *file, const int line,
21950a69bb5SSascha Wildner 	    const char *directive, char ***array, int **iarray, u_int *lp,
22050a69bb5SSascha Wildner 	    const char *s, int i);
221*ba1276acSMatthew Dillon void	opt_array_free2(char **array, int **iarray, u_int l);
222*ba1276acSMatthew Dillon 
223*ba1276acSMatthew Dillon struct timespec;
224*ba1276acSMatthew Dillon void ptimeout_init(struct timespec *pt);
225*ba1276acSMatthew Dillon void ptimeout_deadline_sec(struct timespec *pt, long sec);
226*ba1276acSMatthew Dillon void ptimeout_deadline_ms(struct timespec *pt, long ms);
227*ba1276acSMatthew Dillon void ptimeout_deadline_monotime_tsp(struct timespec *pt, struct timespec *when);
228*ba1276acSMatthew Dillon void ptimeout_deadline_monotime(struct timespec *pt, time_t when);
229*ba1276acSMatthew Dillon int ptimeout_get_ms(struct timespec *pt);
230*ba1276acSMatthew Dillon struct timespec *ptimeout_get_tsp(struct timespec *pt);
231*ba1276acSMatthew Dillon int ptimeout_isset(struct timespec *pt);
23250a69bb5SSascha Wildner 
23318de8d7fSPeter Avalos /* readpass.c */
23418de8d7fSPeter Avalos 
23518de8d7fSPeter Avalos #define RP_ECHO			0x0001
23618de8d7fSPeter Avalos #define RP_ALLOW_STDIN		0x0002
23718de8d7fSPeter Avalos #define RP_ALLOW_EOF		0x0004
23818de8d7fSPeter Avalos #define RP_USE_ASKPASS		0x0008
23918de8d7fSPeter Avalos 
2400cbfa66cSDaniel Fojt struct notifier_ctx;
2410cbfa66cSDaniel Fojt 
24218de8d7fSPeter Avalos char	*read_passphrase(const char *, int);
24318de8d7fSPeter Avalos int	 ask_permission(const char *, ...) __attribute__((format(printf, 1, 2)));
2440cbfa66cSDaniel Fojt struct notifier_ctx *notify_start(int, const char *, ...)
2450cbfa66cSDaniel Fojt 	__attribute__((format(printf, 2, 3)));
24650a69bb5SSascha Wildner void	notify_complete(struct notifier_ctx *, const char *, ...)
24750a69bb5SSascha Wildner 	__attribute__((format(printf, 2, 3)));
24818de8d7fSPeter Avalos 
249ce74bacaSMatthew Dillon #define MINIMUM(a, b)	(((a) < (b)) ? (a) : (b))
250ce74bacaSMatthew Dillon #define MAXIMUM(a, b)	(((a) > (b)) ? (a) : (b))
251ce74bacaSMatthew Dillon #define ROUNDUP(x, y)   ((((x)+((y)-1))/(y))*(y))
252ce74bacaSMatthew Dillon 
2530cbfa66cSDaniel Fojt typedef void (*sshsig_t)(int);
2540cbfa66cSDaniel Fojt sshsig_t ssh_signal(int, sshsig_t);
255*ba1276acSMatthew Dillon int signal_is_crash(int);
256*ba1276acSMatthew Dillon 
257*ba1276acSMatthew Dillon /* On OpenBSD time_t is int64_t which is long long. */
258*ba1276acSMatthew Dillon /* #define SSH_TIME_T_MAX LLONG_MAX */
25950a69bb5SSascha Wildner 
26018de8d7fSPeter Avalos #endif /* _MISC_H */
261