xref: /freebsd/crypto/openssh/monitor_wrap.h (revision 2574974648c68c738aec3ff96644d888d7913a37)
1 /* $OpenBSD: monitor_wrap.h,v 1.54 2026/03/02 02:40:15 djm Exp $ */
2 
3 /*
4  * Copyright 2002 Niels Provos <provos@citi.umich.edu>
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
21  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
25  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26  */
27 
28 #ifndef _MM_WRAP_H_
29 #define _MM_WRAP_H_
30 
31 #define MONITOR_MAX_MSGLEN		(4 * 1024 * 1024)
32 /* The configuration has to fit in a monitor message along with other state */
33 #define MONITOR_MAX_CFGLEN		(MONITOR_MAX_MSGLEN - (64 * 1024))
34 
35 enum mm_keytype { MM_NOKEY, MM_HOSTKEY, MM_USERKEY };
36 
37 struct ssh;
38 struct monitor;
39 struct Authctxt;
40 struct sshkey;
41 struct sshauthopt;
42 struct sshkey_sig_details;
43 
44 void mm_log_handler(LogLevel, int, const char *, void *);
45 int mm_is_monitor(void);
46 #ifdef WITH_OPENSSL
47 DH *mm_choose_dh(int, int, int);
48 #endif
49 void mm_sshkey_setcompat(struct ssh *);
50 int mm_sshkey_sign(struct ssh *, struct sshkey *, u_char **, size_t *,
51     const u_char *, size_t, const char *, const char *,
52     const char *, u_int compat);
53 void mm_inform_authserv(char *, char *);
54 struct passwd *mm_getpwnamallow(struct ssh *, const char *);
55 char *mm_auth2_read_banner(void);
56 int mm_auth_password(struct ssh *, char *);
57 int mm_key_allowed(enum mm_keytype, const char *, const char *, struct sshkey *,
58     int, struct sshauthopt **);
59 int mm_user_key_allowed(struct ssh *ssh, struct passwd *, struct sshkey *, int,
60     struct sshauthopt **);
61 int mm_hostbased_key_allowed(struct ssh *, struct passwd *, const char *,
62     const char *, struct sshkey *);
63 int mm_sshkey_verify(const struct sshkey *, const u_char *, size_t,
64     const u_char *, size_t, const char *, u_int, struct sshkey_sig_details **);
65 
66 void mm_decode_activate_server_options(struct ssh *ssh, struct sshbuf *m);
67 
68 #ifdef GSSAPI
69 OM_uint32 mm_ssh_gssapi_server_ctx(Gssctxt **, gss_OID);
70 OM_uint32 mm_ssh_gssapi_accept_ctx(Gssctxt *,
71    gss_buffer_desc *, gss_buffer_desc *, OM_uint32 *);
72 int mm_ssh_gssapi_userok(char *user);
73 OM_uint32 mm_ssh_gssapi_checkmic(Gssctxt *, gss_buffer_t, gss_buffer_t);
74 #endif
75 
76 #ifdef USE_PAM
77 void mm_start_pam(struct ssh *ssh);
78 u_int mm_do_pam_account(void);
79 void *mm_sshpam_init_ctx(struct Authctxt *);
80 int mm_sshpam_query(void *, char **, char **, u_int *, char ***, u_int **);
81 int mm_sshpam_respond(void *, u_int, char **);
82 void mm_sshpam_free_ctx(void *);
83 #endif
84 
85 #ifdef SSH_AUDIT_EVENTS
86 #include "audit.h"
87 void mm_audit_event(struct ssh *, ssh_audit_event_t);
88 void mm_audit_run_command(const char *);
89 #endif
90 
91 struct Session;
92 void mm_terminate(void);
93 int mm_pty_allocate(int *, int *, char *, size_t);
94 void mm_session_pty_cleanup2(struct Session *);
95 
96 void mm_send_keystate(struct ssh *, struct monitor*);
97 
98 /* state */
99 struct include_list;
100 void mm_get_state(struct ssh *, struct include_list *, struct sshbuf *,
101     struct sshbuf **, uint64_t *, struct sshbuf **, struct sshbuf **,
102     u_char **, struct sshbuf **, struct sshbuf **);
103 
104 /* bsdauth */
105 int mm_bsdauth_query(void *, char **, char **, u_int *, char ***, u_int **);
106 int mm_bsdauth_respond(void *, u_int, char **);
107 
108 /* config / channels glue */
109 void	 server_process_permitopen(struct ssh *);
110 void	 server_process_channel_timeouts(struct ssh *ssh);
111 struct connection_info *
112 	 server_get_connection_info(struct ssh *, int, int);
113 
114 #endif /* _MM_WRAP_H_ */
115