1 /* $NetBSD: monitor.h,v 1.15 2025/04/09 15:49:32 christos Exp $ */ 2 /* $OpenBSD: monitor.h,v 1.25 2024/10/14 01:57:50 djm Exp $ */ 3 4 /* 5 * Copyright 2002 Niels Provos <provos@citi.umich.edu> 6 * All rights reserved. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 1. Redistributions of source code must retain the above copyright 12 * notice, this list of conditions and the following disclaimer. 13 * 2. Redistributions in binary form must reproduce the above copyright 14 * notice, this list of conditions and the following disclaimer in the 15 * documentation and/or other materials provided with the distribution. 16 * 17 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 18 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 19 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 20 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 21 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 22 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 23 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 24 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 27 */ 28 29 #ifndef _MONITOR_H_ 30 #define _MONITOR_H_ 31 32 /* Please keep *_REQ_* values on even numbers and *_ANS_* on odd numbers */ 33 enum monitor_reqtype { 34 MONITOR_REQ_MODULI = 0, MONITOR_ANS_MODULI = 1, 35 MONITOR_REQ_FREE = 2, 36 MONITOR_REQ_AUTHSERV = 4, 37 MONITOR_REQ_SIGN = 6, MONITOR_ANS_SIGN = 7, 38 MONITOR_REQ_PWNAM = 8, MONITOR_ANS_PWNAM = 9, 39 MONITOR_REQ_AUTH2_READ_BANNER = 10, MONITOR_ANS_AUTH2_READ_BANNER = 11, 40 MONITOR_REQ_AUTHPASSWORD = 12, MONITOR_ANS_AUTHPASSWORD = 13, 41 MONITOR_REQ_BSDAUTHQUERY = 14, MONITOR_ANS_BSDAUTHQUERY = 15, 42 MONITOR_REQ_BSDAUTHRESPOND = 16, MONITOR_ANS_BSDAUTHRESPOND = 17, 43 MONITOR_REQ_SKEYQUERY = 18, MONITOR_ANS_SKEYQUERY = 19, 44 MONITOR_REQ_SKEYRESPOND = 20, MONITOR_ANS_SKEYRESPOND = 21, 45 MONITOR_REQ_KEYALLOWED = 22, MONITOR_ANS_KEYALLOWED = 23, 46 MONITOR_REQ_KEYVERIFY = 24, MONITOR_ANS_KEYVERIFY = 25, 47 MONITOR_REQ_KEYEXPORT = 26, 48 MONITOR_REQ_PTY = 28, MONITOR_ANS_PTY = 29, 49 MONITOR_REQ_PTYCLEANUP = 30, 50 MONITOR_REQ_SESSKEY = 32, MONITOR_ANS_SESSKEY = 33, 51 MONITOR_REQ_SESSID = 34, 52 MONITOR_REQ_RSAKEYALLOWED = 36, MONITOR_ANS_RSAKEYALLOWED = 37, 53 MONITOR_REQ_RSACHALLENGE = 38, MONITOR_ANS_RSACHALLENGE = 39, 54 MONITOR_REQ_RSARESPONSE = 40, MONITOR_ANS_RSARESPONSE = 41, 55 MONITOR_REQ_GSSSETUP = 42, MONITOR_ANS_GSSSETUP = 43, 56 MONITOR_REQ_GSSSTEP = 44, MONITOR_ANS_GSSSTEP = 45, 57 MONITOR_REQ_GSSUSEROK = 46, MONITOR_ANS_GSSUSEROK = 47, 58 MONITOR_REQ_GSSCHECKMIC = 48, MONITOR_ANS_GSSCHECKMIC = 49, 59 MONITOR_REQ_TERM = 50, 60 MONITOR_REQ_STATE = 51, MONITOR_ANS_STATE = 52, 61 62 MONITOR_REQ_PAM_START = 100, 63 MONITOR_REQ_PAM_ACCOUNT = 102, MONITOR_ANS_PAM_ACCOUNT = 103, 64 MONITOR_REQ_PAM_INIT_CTX = 104, MONITOR_ANS_PAM_INIT_CTX = 105, 65 MONITOR_REQ_PAM_QUERY = 106, MONITOR_ANS_PAM_QUERY = 107, 66 MONITOR_REQ_PAM_RESPOND = 108, MONITOR_ANS_PAM_RESPOND = 109, 67 MONITOR_REQ_PAM_FREE_CTX = 110, MONITOR_ANS_PAM_FREE_CTX = 111, 68 MONITOR_REQ_AUDIT_EVENT = 112, MONITOR_REQ_AUDIT_COMMAND = 113, 69 70 MONITOR_REQ_KRB4 = 200, MONITOR_ANS_KRB4 = 201, 71 MONITOR_REQ_KRB5 = 202, MONITOR_ANS_KRB5 = 203, 72 }; 73 74 struct ssh; 75 struct sshbuf; 76 77 struct monitor { 78 int m_recvfd; 79 int m_sendfd; 80 int m_log_recvfd; 81 int m_log_sendfd; 82 struct kex **m_pkex; 83 pid_t m_pid; 84 }; 85 86 struct monitor *monitor_init(void); 87 void monitor_reinit(struct monitor *); 88 89 struct Authctxt; 90 void monitor_child_preauth(struct ssh *, struct monitor *); 91 void monitor_child_postauth(struct ssh *, struct monitor *) 92 __attribute__((__noreturn__)); 93 94 void monitor_clear_keystate(struct ssh *, struct monitor *); 95 void monitor_apply_keystate(struct ssh *, struct monitor *); 96 97 /* Prototypes for request sending and receiving */ 98 void mm_request_send(int, enum monitor_reqtype, struct sshbuf *); 99 void mm_request_receive(int, struct sshbuf *); 100 void mm_request_receive_expect(int, enum monitor_reqtype, struct sshbuf *); 101 void mm_get_keystate(struct ssh *, struct monitor *); 102 103 /* XXX: should be returned via a monitor call rather than config_fd */ 104 void mm_encode_server_options(struct sshbuf *); 105 106 struct sshbuf *pack_hostkeys(void); 107 108 #endif /* _MONITOR_H_ */ 109