1 /* $OpenBSD: hostfile.h,v 1.29 2021/01/26 00:51:30 djm Exp $ */
4 * Author: Tatu Ylonen <ylo@cs.hut.fi>
5 * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
8 * As far as I am concerned, the code I have written for this software
9 * can be used freely for any purpose. Any derived versions of this
10 * software must be clearly marked as such, and if the derived work is
11 * incompatible with the protocol description in the RFC file, it must be
12 * called by a name other than "ssh" or "Secure Shell".
18 HOST_OK
, HOST_NEW
, HOST_CHANGED
, HOST_REVOKED
, HOST_FOUND
22 MRK_ERROR
, MRK_NONE
, MRK_REVOKE
, MRK_CA
25 struct hostkey_entry
{
31 u_int note
; /* caller-specific note/flag */
34 struct hostkey_entry
*entries
;
38 struct hostkeys
*init_hostkeys(void);
39 void load_hostkeys(struct hostkeys
*, const char *,
41 void load_hostkeys_file(struct hostkeys
*, const char *,
42 const char *, FILE *, u_int note
);
43 void free_hostkeys(struct hostkeys
*);
45 HostStatus
check_key_in_hostkeys(struct hostkeys
*, struct sshkey
*,
46 const struct hostkey_entry
**);
47 int lookup_key_in_hostkeys_by_type(struct hostkeys
*, int, int,
48 const struct hostkey_entry
**);
49 int lookup_marker_in_hostkeys(struct hostkeys
*, int);
51 int hostfile_read_key(char **, u_int
*, struct sshkey
*);
52 int add_host_to_hostfile(const char *, const char *,
53 const struct sshkey
*, int);
55 int hostfile_replace_entries(const char *filename
,
56 const char *host
, const char *ip
, struct sshkey
**keys
, size_t nkeys
,
57 int store_hash
, int quiet
, int hash_alg
);
59 #define HASH_MAGIC "|1|"
60 #define HASH_DELIM '|'
62 #define CA_MARKER "@cert-authority"
63 #define REVOKE_MARKER "@revoked"
65 char *host_hash(const char *, const char *, u_int
);
68 * Iterate through a hostkeys file, optionally parsing keys and matching
69 * hostnames. Allows access to the raw keyfile lines to allow
70 * streaming edits to the file to take place.
72 #define HKF_WANT_MATCH (1) /* return only matching hosts/addrs */
73 #define HKF_WANT_PARSE_KEY (1<<1) /* need key parsed */
75 #define HKF_STATUS_OK 0 /* Line parsed, didn't match host */
76 #define HKF_STATUS_INVALID 1 /* line had parse error */
77 #define HKF_STATUS_COMMENT 2 /* valid line contained no key */
78 #define HKF_STATUS_MATCHED 3 /* hostname or IP matched */
80 #define HKF_MATCH_HOST (1) /* hostname matched */
81 #define HKF_MATCH_IP (1<<1) /* address matched */
82 #define HKF_MATCH_HOST_HASHED (1<<2) /* hostname was hashed */
83 #define HKF_MATCH_IP_HASHED (1<<3) /* address was hashed */
84 /* XXX HKF_MATCH_KEY_TYPE? */
87 * The callback function receives this as an argument for each matching
88 * hostkey line. The callback may "steal" the 'key' field by setting it to NULL.
89 * If a parse error occurred, then "hosts" and subsequent options may be NULL.
91 struct hostkey_foreach_line
{
92 const char *path
; /* Path of file */
93 u_long linenum
; /* Line number */
94 u_int status
; /* One of HKF_STATUS_* */
95 u_int match
; /* Zero or more of HKF_MATCH_* OR'd together */
96 char *line
; /* Entire key line; mutable by callback */
97 int marker
; /* CA/revocation markers; indicated by MRK_* value */
98 const char *hosts
; /* Raw hosts text, may be hashed or list multiple */
99 const char *rawkey
; /* Text of key and any comment following it */
100 int keytype
; /* Type of key; KEY_UNSPEC for invalid/comment lines */
101 struct sshkey
*key
; /* Key, if parsed ok and HKF_WANT_MATCH_HOST set */
102 const char *comment
; /* Any comment following the key */
103 u_int note
; /* caller-specified note copied from arguments */
107 * Callback fires for each line (or matching line if a HKF_WANT_* option
108 * is set). The foreach loop will terminate if the callback returns a non-
111 typedef int hostkeys_foreach_fn(struct hostkey_foreach_line
*l
, void *ctx
);
113 /* Iterate over a hostkeys file */
114 int hostkeys_foreach(const char *path
,
115 hostkeys_foreach_fn
*callback
, void *ctx
,
116 const char *host
, const char *ip
, u_int options
, u_int note
);
117 int hostkeys_foreach_file(const char *path
, FILE *f
,
118 hostkeys_foreach_fn
*callback
, void *ctx
,
119 const char *host
, const char *ip
, u_int options
, u_int note
);
121 void hostfile_create_user_ssh_dir(const char *, int);