ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
common.h File Reference

Root infrastructure: fixed widths, serializers, opcodes and sizes, for every layer above. More...

#include "cellularum_laboro/cellularum_laboro.h"
#include "crypto/aead/chachapoly/chachapoly.h"
#include "crypto/asymmetric/bignum/bignum.h"
#include "crypto/cipher/aes256ctr/aes256ctr.h"
#include "crypto/mac/hmac_sha256/hmac_sha256.h"
#include "crypto/pqc/sntrup761/sntrup761.h"
#include "memoria_operor/memoria_operor.h"
#include "network_drivers/presentation/ssh/transport/ssh_kexhash/ssh_kexhash.h"
#include "octetus_introitus_exitus/octetus_introitus_exitus.h"
#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  Rd
 

Macros

#define SSH_VERSION_MAX   256
 Max stored length of an SSH identification string (RFC 4253 sec 4.2: 255).
 
#define SSH_VERSION_CONTENT_MAX   253
 Longest identification string RFC 4253 sec 4.2 admits: 255 on the wire, CR and LF counted.
 
#define PROTOCORE_SSH_KEXINIT_S_MAX   704
 Max stored size of our own KEXINIT (I_S). Sized for the full advertised suite: the kex list (mlkem + dh + ecdsa-nistp256 + curve25519 x2 + ext-info-s), all three host-key types, the cipher (chacha + 2x aes) and MAC (2x aes + 2x plain) lists, and zlib s2c compression (worst case ~580 bytes; 704 leaves headroom for future algorithm additions).
 
#define PROTOCORE_SSH_I_C_MAX   SSH_KEXINIT_MAX
 Capacity of I_C and I_S. A buffer takes the peer bound in the role that receives into it, our own bound in the role that writes it.
 
#define PROTOCORE_SSH_I_S_MAX   PROTOCORE_SSH_KEXINIT_S_MAX
 
#define SSH_SERVER_VERSION   "SSH-2.0-1.0"
 Server identification string (no CR LF; appended on the wire).
 
#define SSH_CLIENT_VERSION   "SSH-2.0-PROTOCORE_client_1.0"
 Client identification string (no CR LF; appended on the wire).
 
#define SSH_OFF_GCM_C2S   0u
 The connection's memory map: every byte it uses, at a named offset from its slot base.
 
#define SSH_OFF_GCM_S2C   (SSH_OFF_GCM_C2S + PROTOCORE_AESGCM_BORROW)
 
#define SSH_OFF_CHACHA_C2S   (SSH_OFF_GCM_S2C + PROTOCORE_AESGCM_BORROW)
 
#define SSH_OFF_CHACHA_S2C   (SSH_OFF_CHACHA_C2S + PROTOCORE_CHACHAPOLY_KEY_LEN)
 
#define SSH_OFF_MAC_C2S   (SSH_OFF_CHACHA_S2C + PROTOCORE_CHACHAPOLY_KEY_LEN)
 
#define SSH_OFF_MAC_S2C   (SSH_OFF_MAC_C2S + 64u)
 
#define SSH_OFF_AES_KEY_C2S   (SSH_OFF_MAC_S2C + 64u)
 
#define SSH_OFF_AES_KEY_S2C   (SSH_OFF_AES_KEY_C2S + PROTOCORE_AES256CTR_KEY_LEN)
 
#define SSH_OFF_AES_IV_C2S   (SSH_OFF_AES_KEY_S2C + PROTOCORE_AES256CTR_KEY_LEN)
 
#define SSH_OFF_AES_IV_S2C   (SSH_OFF_AES_IV_C2S + PROTOCORE_AES256CTR_CTR_LEN)
 
#define SSH_EPOCH_STRIDE   (SSH_OFF_AES_IV_S2C + PROTOCORE_AES256CTR_CTR_LEN)
 
#define SSH_OFF_WIRE   0u
 
#define SSH_OFF_V_C   (SSH_OFF_WIRE + SSH_WIRE_CAP)
 
#define SSH_OFF_V_S   (SSH_OFF_V_C + SSH_VERSION_MAX)
 
#define SSH_OFF_SESSION_ID   (SSH_OFF_V_S + SSH_VERSION_MAX)
 
#define SSH_OFF_EPOCH_0   (SSH_OFF_SESSION_ID + SSH_KEXHASH_MAX_LEN)
 
#define SSH_OFF_EPOCH_1   (SSH_OFF_EPOCH_0 + SSH_EPOCH_STRIDE)
 
#define SSH_SESSION_END   (SSH_OFF_EPOCH_1 + SSH_EPOCH_STRIDE)
 
#define SSH_OFF_IDENT   SSH_SESSION_END
 
#define SSH_OFF_I_C   (SSH_OFF_IDENT + SSH_VERSION_MAX)
 
#define SSH_OFF_I_S   (SSH_OFF_I_C + PROTOCORE_SSH_I_C_MAX)
 
#define SSH_OFF_KEXINIT   (SSH_OFF_I_S + PROTOCORE_SSH_I_S_MAX)
 
#define SSH_OFF_CPUB   (SSH_OFF_KEXINIT + PROTOCORE_SSH_KEXINIT_S_MAX)
 
#define SSH_OFF_DH_Y   (SSH_OFF_CPUB + PROTOCORE_SSH_CPUB_MAX)
 
#define SSH_OFF_DH_F   (SSH_OFF_DH_Y + sizeof(protocore_bignum))
 
#define SSH_OFF_DH_K   (SSH_OFF_DH_F + sizeof(protocore_bignum))
 
#define SSH_OFF_ECDH_SK   (SSH_OFF_DH_K + sizeof(protocore_bignum))
 
#define SSH_OFF_ECDH_PK   (SSH_OFF_ECDH_SK + 32u)
 
#define SSH_ECDH_PAIR_LEN   64u
 The ECDH ephemeral pair, private then public: what one wipe covers.
 
#define SSH_OFF_CRYPTO_WORK   (SSH_OFF_ECDH_PK + 32u)
 
#define SSH_EXCHANGE_END   (SSH_OFF_CRYPTO_WORK + PROTOCORE_CRYPTO_BORROW_MAX)
 
#define SSH_OFF_MAC_WORK   SSH_EXCHANGE_END
 
#define SSH_OFF_CIPHER_WORK   (SSH_OFF_MAC_WORK + PROTOCORE_HMAC_SHA256_BORROW)
 
#define SSH_CIPHER_WORK_LEN   PROTOCORE_AES256CTR_BORROW
 
#define SSH_PACKET_END   (SSH_OFF_CIPHER_WORK + SSH_CIPHER_WORK_LEN)
 
#define SSH_OFF_RX_READ   SSH_PACKET_END
 
#define SSH_OFF_RX_ASM   (SSH_OFF_RX_READ + RX_BUF_SIZE)
 
#define SSH_RX_ASM_CAP   ((size_t)SSH_RFC_MAX_PAYLOAD)
 Capacity of the reassembly region at SSH_OFF_RX_ASM: what rx_buf actually spans.
 
#define SSH_SLOT_BORROW   (SSH_OFF_RX_ASM + SSH_RX_ASM_CAP)
 One connection's whole span, and the stride between slots.
 
#define SSH_SESSION_SIZE   (SSH_SESSION_END - SSH_OFF_V_C)
 
#define SSH_EXCHANGE_SIZE   (SSH_EXCHANGE_END - SSH_OFF_IDENT)
 
#define SSH_PACKET_SIZE   (SSH_PACKET_END - SSH_OFF_MAC_WORK)
 
#define SSH_RX_SIZE   (SSH_SLOT_BORROW - SSH_OFF_RX_READ)
 
#define SSH_SEQ_CLOSE_THRESHOLD   0xFFFFFFF0u
 Close the connection when seq_no reaches this value.
 
#define SSH_MAX_EFFECTIVE_PAYLOAD   (SSH_RFC_MAX_PAYLOAD)
 
#define SSH_MAX_PAD   32
 
#define SSH_MAX_MAC   64
 
#define SSH_PKT_WIRE_MAX   ((size_t)(4 + 1 + SSH_MAX_EFFECTIVE_PAYLOAD + SSH_MAX_PAD + SSH_MAX_MAC))
 
#define SSH_RFC_MAX_PAYLOAD   32768u
 Uncompressed payload RFC 4253 sec 6.1 requires an implementation to process.
 
#define SSH_RFC_MAX_PACKET   35000u
 Largest total packet RFC 4253 sec 6.1 requires an implementation to process.
 
#define SSH_WIRE_CAP   ((size_t)131072u)
 
#define PROTOCORE_PLAINTEXT_WORK_SSH_TRANSPORT   ((size_t)(SSH_PKT_BUF_SIZE + 64))
 
#define SSH_WIRE_PAYLOAD_OFF   5
 Where a payload sits inside a wire buffer: past packet_length and padding_length.
 

Typedefs

typedef PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED SshMsgId
 Protocol opcodes, by the number each RFC assigns it (RFC 4250 sec 4.1.2).
 
typedef enum PROTO_ENUM_PACKED SshDisconnectReason
 Disconnect reason codes (RFC 4253 sec 11.1, numbered by RFC 4250 sec 4.2.2).
 
typedef enum PROTO_ENUM_PACKED SshOpenFailureReason
 Channel open failure reason codes (RFC 4254 sec 5.1).
 

Enumerations

enum  PROTO_ENUM_PACKED {
  SSH_MSG_DISCONNECT = 1 , SSH_MSG_IGNORE = 2 , SSH_MSG_UNIMPLEMENTED = 3 , SSH_MSG_DEBUG = 4 ,
  SSH_MSG_SERVICE_REQUEST = 5 , SSH_MSG_SERVICE_ACCEPT = 6 , SSH_MSG_EXT_INFO = 7 , SSH_MSG_KEXINIT = 20 ,
  SSH_MSG_NEWKEYS = 21 , SSH_MSG_KEXDH_INIT = 30 , SSH_MSG_KEXDH_REPLY = 31 , SSH_MSG_USERAUTH_REQUEST = 50 ,
  SSH_MSG_USERAUTH_FAILURE = 51 , SSH_MSG_USERAUTH_SUCCESS = 52 , SSH_MSG_USERAUTH_BANNER = 53 , SSH_MSG_USERAUTH_PK_OK = 60 ,
  SSH_MSG_USERAUTH_INFO_REQUEST = 60 , SSH_MSG_USERAUTH_INFO_RESPONSE = 61 , SSH_MSG_GLOBAL_REQUEST = 80 , SSH_MSG_REQUEST_SUCCESS = 81 ,
  SSH_MSG_REQUEST_FAILURE = 82 , SSH_MSG_CHANNEL_OPEN = 90 , SSH_MSG_CHANNEL_OPEN_CONFIRMATION = 91 , SSH_MSG_CHANNEL_OPEN_FAILURE = 92 ,
  SSH_MSG_CHANNEL_WINDOW_ADJUST = 93 , SSH_MSG_CHANNEL_DATA = 94 , SSH_MSG_CHANNEL_EXTENDED_DATA = 95 , SSH_MSG_CHANNEL_EOF = 96 ,
  SSH_MSG_CHANNEL_CLOSE = 97 , SSH_MSG_CHANNEL_REQUEST = 98 , SSH_MSG_CHANNEL_SUCCESS = 99 , SSH_MSG_CHANNEL_FAILURE = 100 ,
  SSH_DISCONNECT_PROTOCOL_ERROR = 2 , SSH_DISCONNECT_MAC_ERROR = 5 , SSH_DISCONNECT_SERVICE_NOT_AVAILABLE = 7 , SSH_DISCONNECT_BY_APPLICATION = 11 ,
  SSH_DISCONNECT_TOO_MANY_CONNECTIONS = 12 , SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE = 14 , SSH_OPEN_ADMINISTRATIVELY_PROHIBITED = 1 , SSH_OPEN_CONNECT_FAILED = 2 ,
  SSH_OPEN_UNKNOWN_CHANNEL_TYPE = 3 , SSH_OPEN_RESOURCE_SHORTAGE = 4
}
 Protocol opcodes, by the number each RFC assigns it (RFC 4250 sec 4.1.2). More...
 
enum  PROTO_ENUM_PACKED {
  SSH_MSG_DISCONNECT = 1 , SSH_MSG_IGNORE = 2 , SSH_MSG_UNIMPLEMENTED = 3 , SSH_MSG_DEBUG = 4 ,
  SSH_MSG_SERVICE_REQUEST = 5 , SSH_MSG_SERVICE_ACCEPT = 6 , SSH_MSG_EXT_INFO = 7 , SSH_MSG_KEXINIT = 20 ,
  SSH_MSG_NEWKEYS = 21 , SSH_MSG_KEXDH_INIT = 30 , SSH_MSG_KEXDH_REPLY = 31 , SSH_MSG_USERAUTH_REQUEST = 50 ,
  SSH_MSG_USERAUTH_FAILURE = 51 , SSH_MSG_USERAUTH_SUCCESS = 52 , SSH_MSG_USERAUTH_BANNER = 53 , SSH_MSG_USERAUTH_PK_OK = 60 ,
  SSH_MSG_USERAUTH_INFO_REQUEST = 60 , SSH_MSG_USERAUTH_INFO_RESPONSE = 61 , SSH_MSG_GLOBAL_REQUEST = 80 , SSH_MSG_REQUEST_SUCCESS = 81 ,
  SSH_MSG_REQUEST_FAILURE = 82 , SSH_MSG_CHANNEL_OPEN = 90 , SSH_MSG_CHANNEL_OPEN_CONFIRMATION = 91 , SSH_MSG_CHANNEL_OPEN_FAILURE = 92 ,
  SSH_MSG_CHANNEL_WINDOW_ADJUST = 93 , SSH_MSG_CHANNEL_DATA = 94 , SSH_MSG_CHANNEL_EXTENDED_DATA = 95 , SSH_MSG_CHANNEL_EOF = 96 ,
  SSH_MSG_CHANNEL_CLOSE = 97 , SSH_MSG_CHANNEL_REQUEST = 98 , SSH_MSG_CHANNEL_SUCCESS = 99 , SSH_MSG_CHANNEL_FAILURE = 100 ,
  SSH_DISCONNECT_PROTOCOL_ERROR = 2 , SSH_DISCONNECT_MAC_ERROR = 5 , SSH_DISCONNECT_SERVICE_NOT_AVAILABLE = 7 , SSH_DISCONNECT_BY_APPLICATION = 11 ,
  SSH_DISCONNECT_TOO_MANY_CONNECTIONS = 12 , SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE = 14 , SSH_OPEN_ADMINISTRATIVELY_PROHIBITED = 1 , SSH_OPEN_CONNECT_FAILED = 2 ,
  SSH_OPEN_UNKNOWN_CHANNEL_TYPE = 3 , SSH_OPEN_RESOURCE_SHORTAGE = 4
}
 Disconnect reason codes (RFC 4253 sec 11.1, numbered by RFC 4250 sec 4.2.2). More...
 
enum  PROTO_ENUM_PACKED {
  SSH_MSG_DISCONNECT = 1 , SSH_MSG_IGNORE = 2 , SSH_MSG_UNIMPLEMENTED = 3 , SSH_MSG_DEBUG = 4 ,
  SSH_MSG_SERVICE_REQUEST = 5 , SSH_MSG_SERVICE_ACCEPT = 6 , SSH_MSG_EXT_INFO = 7 , SSH_MSG_KEXINIT = 20 ,
  SSH_MSG_NEWKEYS = 21 , SSH_MSG_KEXDH_INIT = 30 , SSH_MSG_KEXDH_REPLY = 31 , SSH_MSG_USERAUTH_REQUEST = 50 ,
  SSH_MSG_USERAUTH_FAILURE = 51 , SSH_MSG_USERAUTH_SUCCESS = 52 , SSH_MSG_USERAUTH_BANNER = 53 , SSH_MSG_USERAUTH_PK_OK = 60 ,
  SSH_MSG_USERAUTH_INFO_REQUEST = 60 , SSH_MSG_USERAUTH_INFO_RESPONSE = 61 , SSH_MSG_GLOBAL_REQUEST = 80 , SSH_MSG_REQUEST_SUCCESS = 81 ,
  SSH_MSG_REQUEST_FAILURE = 82 , SSH_MSG_CHANNEL_OPEN = 90 , SSH_MSG_CHANNEL_OPEN_CONFIRMATION = 91 , SSH_MSG_CHANNEL_OPEN_FAILURE = 92 ,
  SSH_MSG_CHANNEL_WINDOW_ADJUST = 93 , SSH_MSG_CHANNEL_DATA = 94 , SSH_MSG_CHANNEL_EXTENDED_DATA = 95 , SSH_MSG_CHANNEL_EOF = 96 ,
  SSH_MSG_CHANNEL_CLOSE = 97 , SSH_MSG_CHANNEL_REQUEST = 98 , SSH_MSG_CHANNEL_SUCCESS = 99 , SSH_MSG_CHANNEL_FAILURE = 100 ,
  SSH_DISCONNECT_PROTOCOL_ERROR = 2 , SSH_DISCONNECT_MAC_ERROR = 5 , SSH_DISCONNECT_SERVICE_NOT_AVAILABLE = 7 , SSH_DISCONNECT_BY_APPLICATION = 11 ,
  SSH_DISCONNECT_TOO_MANY_CONNECTIONS = 12 , SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE = 14 , SSH_OPEN_ADMINISTRATIVELY_PROHIBITED = 1 , SSH_OPEN_CONNECT_FAILED = 2 ,
  SSH_OPEN_UNKNOWN_CHANNEL_TYPE = 3 , SSH_OPEN_RESOURCE_SHORTAGE = 4
}
 Channel open failure reason codes (RFC 4254 sec 5.1). More...
 

Functions

PROTOCORE_INLINE void protocore_ssh_wr_str (mmgr_span *w, const void *data, size_t n)
 Append a string: uint32 length, then n bytes of data.
 
PROTOCORE_INLINE void protocore_ssh_wr_cstr (mmgr_span *w, const char *s)
 Append a NUL-terminated s as a string, its length taken up to the span's capacity.
 
PROTOCORE_INLINE void protocore_ssh_wr_mpint (mmgr_span *w, const uint8_t *be, size_t len)
 Append len big-endian bytes as an mpint: leading zero bytes stripped, a 0x00 prepended when the top bit is set, and a zero value written as the empty string.
 
PROTOCORE_INLINE uint8_t protocore_ssh_rd_u8 (Rd *r)
 
PROTOCORE_INLINE uint32_t protocore_ssh_rd_u32 (Rd *r)
 
PROTOCORE_INLINE const uint8_t * protocore_ssh_rd_string (Rd *r, uint32_t *n)
 

Detailed Description

Root infrastructure: fixed widths, serializers, opcodes and sizes, for every layer above.

Definition in file common.h.

Macro Definition Documentation

◆ SSH_VERSION_MAX

#define SSH_VERSION_MAX   256

Max stored length of an SSH identification string (RFC 4253 sec 4.2: 255).

Definition at line 29 of file common.h.

◆ SSH_VERSION_CONTENT_MAX

#define SSH_VERSION_CONTENT_MAX   253

Longest identification string RFC 4253 sec 4.2 admits: 255 on the wire, CR and LF counted.

Definition at line 32 of file common.h.

◆ PROTOCORE_SSH_KEXINIT_S_MAX

#define PROTOCORE_SSH_KEXINIT_S_MAX   704

Max stored size of our own KEXINIT (I_S). Sized for the full advertised suite: the kex list (mlkem + dh + ecdsa-nistp256 + curve25519 x2 + ext-info-s), all three host-key types, the cipher (chacha + 2x aes) and MAC (2x aes + 2x plain) lists, and zlib s2c compression (worst case ~580 bytes; 704 leaves headroom for future algorithm additions).

Definition at line 40 of file common.h.

◆ PROTOCORE_SSH_I_C_MAX

#define PROTOCORE_SSH_I_C_MAX   SSH_KEXINIT_MAX

Capacity of I_C and I_S. A buffer takes the peer bound in the role that receives into it, our own bound in the role that writes it.

Definition at line 53 of file common.h.

◆ PROTOCORE_SSH_I_S_MAX

#define PROTOCORE_SSH_I_S_MAX   PROTOCORE_SSH_KEXINIT_S_MAX

Definition at line 54 of file common.h.

◆ SSH_SERVER_VERSION

#define SSH_SERVER_VERSION   "SSH-2.0-1.0"

Server identification string (no CR LF; appended on the wire).

Definition at line 58 of file common.h.

◆ SSH_CLIENT_VERSION

#define SSH_CLIENT_VERSION   "SSH-2.0-PROTOCORE_client_1.0"

Client identification string (no CR LF; appended on the wire).

Definition at line 61 of file common.h.

◆ SSH_OFF_GCM_C2S

#define SSH_OFF_GCM_C2S   0u

The connection's memory map: every byte it uses, at a named offset from its slot base.

Laid out kmt | constants | control packet | data packet, each offset the previous one plus that member's size. The storage is ssh.c's; a translation unit takes its pointer as ssh_conn_slot(i) + the offset and already knows the member's size.

Definition at line 139 of file common.h.

◆ SSH_OFF_GCM_S2C

#define SSH_OFF_GCM_S2C   (SSH_OFF_GCM_C2S + PROTOCORE_AESGCM_BORROW)

Definition at line 140 of file common.h.

◆ SSH_OFF_CHACHA_C2S

#define SSH_OFF_CHACHA_C2S   (SSH_OFF_GCM_S2C + PROTOCORE_AESGCM_BORROW)

Definition at line 141 of file common.h.

◆ SSH_OFF_CHACHA_S2C

#define SSH_OFF_CHACHA_S2C   (SSH_OFF_CHACHA_C2S + PROTOCORE_CHACHAPOLY_KEY_LEN)

Definition at line 142 of file common.h.

◆ SSH_OFF_MAC_C2S

#define SSH_OFF_MAC_C2S   (SSH_OFF_CHACHA_S2C + PROTOCORE_CHACHAPOLY_KEY_LEN)

Definition at line 143 of file common.h.

◆ SSH_OFF_MAC_S2C

#define SSH_OFF_MAC_S2C   (SSH_OFF_MAC_C2S + 64u)

Definition at line 144 of file common.h.

◆ SSH_OFF_AES_KEY_C2S

#define SSH_OFF_AES_KEY_C2S   (SSH_OFF_MAC_S2C + 64u)

Definition at line 145 of file common.h.

◆ SSH_OFF_AES_KEY_S2C

#define SSH_OFF_AES_KEY_S2C   (SSH_OFF_AES_KEY_C2S + PROTOCORE_AES256CTR_KEY_LEN)

Definition at line 146 of file common.h.

◆ SSH_OFF_AES_IV_C2S

#define SSH_OFF_AES_IV_C2S   (SSH_OFF_AES_KEY_S2C + PROTOCORE_AES256CTR_KEY_LEN)

Definition at line 147 of file common.h.

◆ SSH_OFF_AES_IV_S2C

#define SSH_OFF_AES_IV_S2C   (SSH_OFF_AES_IV_C2S + PROTOCORE_AES256CTR_CTR_LEN)

Definition at line 148 of file common.h.

◆ SSH_EPOCH_STRIDE

#define SSH_EPOCH_STRIDE   (SSH_OFF_AES_IV_S2C + PROTOCORE_AES256CTR_CTR_LEN)

Definition at line 149 of file common.h.

◆ SSH_OFF_WIRE

#define SSH_OFF_WIRE   0u

Definition at line 169 of file common.h.

◆ SSH_OFF_V_C

#define SSH_OFF_V_C   (SSH_OFF_WIRE + SSH_WIRE_CAP)

Definition at line 175 of file common.h.

◆ SSH_OFF_V_S

#define SSH_OFF_V_S   (SSH_OFF_V_C + SSH_VERSION_MAX)

Definition at line 176 of file common.h.

◆ SSH_OFF_SESSION_ID

#define SSH_OFF_SESSION_ID   (SSH_OFF_V_S + SSH_VERSION_MAX)

Definition at line 177 of file common.h.

◆ SSH_OFF_EPOCH_0

#define SSH_OFF_EPOCH_0   (SSH_OFF_SESSION_ID + SSH_KEXHASH_MAX_LEN)

Definition at line 178 of file common.h.

◆ SSH_OFF_EPOCH_1

#define SSH_OFF_EPOCH_1   (SSH_OFF_EPOCH_0 + SSH_EPOCH_STRIDE)

Definition at line 179 of file common.h.

◆ SSH_SESSION_END

#define SSH_SESSION_END   (SSH_OFF_EPOCH_1 + SSH_EPOCH_STRIDE)

Definition at line 180 of file common.h.

◆ SSH_OFF_IDENT

#define SSH_OFF_IDENT   SSH_SESSION_END

Definition at line 185 of file common.h.

◆ SSH_OFF_I_C

#define SSH_OFF_I_C   (SSH_OFF_IDENT + SSH_VERSION_MAX)

Definition at line 186 of file common.h.

◆ SSH_OFF_I_S

#define SSH_OFF_I_S   (SSH_OFF_I_C + PROTOCORE_SSH_I_C_MAX)

Definition at line 187 of file common.h.

◆ SSH_OFF_KEXINIT

#define SSH_OFF_KEXINIT   (SSH_OFF_I_S + PROTOCORE_SSH_I_S_MAX)

Definition at line 188 of file common.h.

◆ SSH_OFF_CPUB

#define SSH_OFF_CPUB   (SSH_OFF_KEXINIT + PROTOCORE_SSH_KEXINIT_S_MAX)

Definition at line 189 of file common.h.

◆ SSH_OFF_DH_Y

#define SSH_OFF_DH_Y   (SSH_OFF_CPUB + PROTOCORE_SSH_CPUB_MAX)

Definition at line 190 of file common.h.

◆ SSH_OFF_DH_F

#define SSH_OFF_DH_F   (SSH_OFF_DH_Y + sizeof(protocore_bignum))

Definition at line 191 of file common.h.

◆ SSH_OFF_DH_K

#define SSH_OFF_DH_K   (SSH_OFF_DH_F + sizeof(protocore_bignum))

Definition at line 192 of file common.h.

◆ SSH_OFF_ECDH_SK

#define SSH_OFF_ECDH_SK   (SSH_OFF_DH_K + sizeof(protocore_bignum))

Definition at line 193 of file common.h.

◆ SSH_OFF_ECDH_PK

#define SSH_OFF_ECDH_PK   (SSH_OFF_ECDH_SK + 32u)

Definition at line 194 of file common.h.

◆ SSH_ECDH_PAIR_LEN

#define SSH_ECDH_PAIR_LEN   64u

The ECDH ephemeral pair, private then public: what one wipe covers.

Definition at line 196 of file common.h.

◆ SSH_OFF_CRYPTO_WORK

#define SSH_OFF_CRYPTO_WORK   (SSH_OFF_ECDH_PK + 32u)

Definition at line 197 of file common.h.

◆ SSH_EXCHANGE_END

#define SSH_EXCHANGE_END   (SSH_OFF_CRYPTO_WORK + PROTOCORE_CRYPTO_BORROW_MAX)

Definition at line 198 of file common.h.

◆ SSH_OFF_MAC_WORK

#define SSH_OFF_MAC_WORK   SSH_EXCHANGE_END

Definition at line 204 of file common.h.

◆ SSH_OFF_CIPHER_WORK

#define SSH_OFF_CIPHER_WORK   (SSH_OFF_MAC_WORK + PROTOCORE_HMAC_SHA256_BORROW)

Definition at line 205 of file common.h.

◆ SSH_CIPHER_WORK_LEN

#define SSH_CIPHER_WORK_LEN   PROTOCORE_AES256CTR_BORROW

Definition at line 210 of file common.h.

◆ SSH_PACKET_END

#define SSH_PACKET_END   (SSH_OFF_CIPHER_WORK + SSH_CIPHER_WORK_LEN)

Definition at line 212 of file common.h.

◆ SSH_OFF_RX_READ

#define SSH_OFF_RX_READ   SSH_PACKET_END

Definition at line 216 of file common.h.

◆ SSH_OFF_RX_ASM

#define SSH_OFF_RX_ASM   (SSH_OFF_RX_READ + RX_BUF_SIZE)

Definition at line 217 of file common.h.

◆ SSH_RX_ASM_CAP

#define SSH_RX_ASM_CAP   ((size_t)SSH_RFC_MAX_PAYLOAD)

Capacity of the reassembly region at SSH_OFF_RX_ASM: what rx_buf actually spans.

Definition at line 220 of file common.h.

◆ SSH_SLOT_BORROW

#define SSH_SLOT_BORROW   (SSH_OFF_RX_ASM + SSH_RX_ASM_CAP)

One connection's whole span, and the stride between slots.

Definition at line 223 of file common.h.

◆ SSH_SESSION_SIZE

#define SSH_SESSION_SIZE   (SSH_SESSION_END - SSH_OFF_V_C)

Definition at line 228 of file common.h.

◆ SSH_EXCHANGE_SIZE

#define SSH_EXCHANGE_SIZE   (SSH_EXCHANGE_END - SSH_OFF_IDENT)

Definition at line 229 of file common.h.

◆ SSH_PACKET_SIZE

#define SSH_PACKET_SIZE   (SSH_PACKET_END - SSH_OFF_MAC_WORK)

Definition at line 230 of file common.h.

◆ SSH_RX_SIZE

#define SSH_RX_SIZE   (SSH_SLOT_BORROW - SSH_OFF_RX_READ)

Definition at line 231 of file common.h.

◆ SSH_SEQ_CLOSE_THRESHOLD

#define SSH_SEQ_CLOSE_THRESHOLD   0xFFFFFFF0u

Close the connection when seq_no reaches this value.

Set to 0xFFFFFFF0 (16 below the 32-bit wrap) as a conservative margin. This prevents CTR keystream reuse that would occur at wrap. The counter is never reset; a re-key at SSH_REKEY_PACKET_THRESHOLD keeps it far from here.

Definition at line 310 of file common.h.

◆ SSH_MAX_EFFECTIVE_PAYLOAD

#define SSH_MAX_EFFECTIVE_PAYLOAD   (SSH_RFC_MAX_PAYLOAD)

Definition at line 325 of file common.h.

◆ SSH_MAX_PAD

#define SSH_MAX_PAD   32

Definition at line 327 of file common.h.

◆ SSH_MAX_MAC

#define SSH_MAX_MAC   64

Definition at line 328 of file common.h.

◆ SSH_PKT_WIRE_MAX

#define SSH_PKT_WIRE_MAX   ((size_t)(4 + 1 + SSH_MAX_EFFECTIVE_PAYLOAD + SSH_MAX_PAD + SSH_MAX_MAC))

Definition at line 329 of file common.h.

◆ SSH_RFC_MAX_PAYLOAD

#define SSH_RFC_MAX_PAYLOAD   32768u

Uncompressed payload RFC 4253 sec 6.1 requires an implementation to process.

"All implementations MUST be able to process packets with an uncompressed payload length of 32768 bytes or less". This tree sizes its own spans on this rather than on SSH_PKT_BUF_SIZE, which the pre-move tree still shares.

Definition at line 338 of file common.h.

◆ SSH_RFC_MAX_PACKET

#define SSH_RFC_MAX_PACKET   35000u

Largest total packet RFC 4253 sec 6.1 requires an implementation to process.

Definition at line 341 of file common.h.

◆ SSH_WIRE_CAP

#define SSH_WIRE_CAP   ((size_t)131072u)

Definition at line 347 of file common.h.

◆ PROTOCORE_PLAINTEXT_WORK_SSH_TRANSPORT

#define PROTOCORE_PLAINTEXT_WORK_SSH_TRANSPORT   ((size_t)(SSH_PKT_BUF_SIZE + 64))

Definition at line 362 of file common.h.

◆ SSH_WIRE_PAYLOAD_OFF

#define SSH_WIRE_PAYLOAD_OFF   5

Where a payload sits inside a wire buffer: past packet_length and padding_length.

Every cipher mode lays those two fields down ahead of the payload and encrypts from there, so a caller that writes its message at this offset hands ssh_pkt_send_at() a packet the framer never has to move. A pipe (forwarding, a channel data pump) reads its source straight into that slot and the bytes are copied once, into the packet they leave in.

Definition at line 401 of file common.h.

Typedef Documentation

◆ SshMsgId

Protocol opcodes, by the number each RFC assigns it (RFC 4250 sec 4.1.2).

◆ SshDisconnectReason

Disconnect reason codes (RFC 4253 sec 11.1, numbered by RFC 4250 sec 4.2.2).

◆ SshOpenFailureReason

Channel open failure reason codes (RFC 4254 sec 5.1).

Enumeration Type Documentation

◆ PROTO_ENUM_PACKED [1/3]

Protocol opcodes, by the number each RFC assigns it (RFC 4250 sec 4.1.2).

Enumerator
SSH_MSG_DISCONNECT 
SSH_MSG_IGNORE 
SSH_MSG_UNIMPLEMENTED 
SSH_MSG_DEBUG 
SSH_MSG_SERVICE_REQUEST 
SSH_MSG_SERVICE_ACCEPT 
SSH_MSG_EXT_INFO 
SSH_MSG_KEXINIT 
SSH_MSG_NEWKEYS 
SSH_MSG_KEXDH_INIT 
SSH_MSG_KEXDH_REPLY 
SSH_MSG_USERAUTH_REQUEST 
SSH_MSG_USERAUTH_FAILURE 
SSH_MSG_USERAUTH_SUCCESS 
SSH_MSG_USERAUTH_BANNER 
SSH_MSG_USERAUTH_PK_OK 
SSH_MSG_USERAUTH_INFO_REQUEST 
SSH_MSG_USERAUTH_INFO_RESPONSE 
SSH_MSG_GLOBAL_REQUEST 
SSH_MSG_REQUEST_SUCCESS 
SSH_MSG_REQUEST_FAILURE 
SSH_MSG_CHANNEL_OPEN 
SSH_MSG_CHANNEL_OPEN_CONFIRMATION 
SSH_MSG_CHANNEL_OPEN_FAILURE 
SSH_MSG_CHANNEL_WINDOW_ADJUST 
SSH_MSG_CHANNEL_DATA 
SSH_MSG_CHANNEL_EXTENDED_DATA 
SSH_MSG_CHANNEL_EOF 
SSH_MSG_CHANNEL_CLOSE 
SSH_MSG_CHANNEL_REQUEST 
SSH_MSG_CHANNEL_SUCCESS 
SSH_MSG_CHANNEL_FAILURE 
SSH_DISCONNECT_PROTOCOL_ERROR 
SSH_DISCONNECT_MAC_ERROR 
SSH_DISCONNECT_SERVICE_NOT_AVAILABLE 
SSH_DISCONNECT_BY_APPLICATION 
SSH_DISCONNECT_TOO_MANY_CONNECTIONS 
SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE 
SSH_OPEN_ADMINISTRATIVELY_PROHIBITED 
SSH_OPEN_CONNECT_FAILED 
SSH_OPEN_UNKNOWN_CHANNEL_TYPE 
SSH_OPEN_RESOURCE_SHORTAGE 

Definition at line 66 of file common.h.

◆ PROTO_ENUM_PACKED [2/3]

Disconnect reason codes (RFC 4253 sec 11.1, numbered by RFC 4250 sec 4.2.2).

Enumerator
SSH_MSG_DISCONNECT 
SSH_MSG_IGNORE 
SSH_MSG_UNIMPLEMENTED 
SSH_MSG_DEBUG 
SSH_MSG_SERVICE_REQUEST 
SSH_MSG_SERVICE_ACCEPT 
SSH_MSG_EXT_INFO 
SSH_MSG_KEXINIT 
SSH_MSG_NEWKEYS 
SSH_MSG_KEXDH_INIT 
SSH_MSG_KEXDH_REPLY 
SSH_MSG_USERAUTH_REQUEST 
SSH_MSG_USERAUTH_FAILURE 
SSH_MSG_USERAUTH_SUCCESS 
SSH_MSG_USERAUTH_BANNER 
SSH_MSG_USERAUTH_PK_OK 
SSH_MSG_USERAUTH_INFO_REQUEST 
SSH_MSG_USERAUTH_INFO_RESPONSE 
SSH_MSG_GLOBAL_REQUEST 
SSH_MSG_REQUEST_SUCCESS 
SSH_MSG_REQUEST_FAILURE 
SSH_MSG_CHANNEL_OPEN 
SSH_MSG_CHANNEL_OPEN_CONFIRMATION 
SSH_MSG_CHANNEL_OPEN_FAILURE 
SSH_MSG_CHANNEL_WINDOW_ADJUST 
SSH_MSG_CHANNEL_DATA 
SSH_MSG_CHANNEL_EXTENDED_DATA 
SSH_MSG_CHANNEL_EOF 
SSH_MSG_CHANNEL_CLOSE 
SSH_MSG_CHANNEL_REQUEST 
SSH_MSG_CHANNEL_SUCCESS 
SSH_MSG_CHANNEL_FAILURE 
SSH_DISCONNECT_PROTOCOL_ERROR 
SSH_DISCONNECT_MAC_ERROR 
SSH_DISCONNECT_SERVICE_NOT_AVAILABLE 
SSH_DISCONNECT_BY_APPLICATION 
SSH_DISCONNECT_TOO_MANY_CONNECTIONS 
SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE 
SSH_OPEN_ADMINISTRATIVELY_PROHIBITED 
SSH_OPEN_CONNECT_FAILED 
SSH_OPEN_UNKNOWN_CHANNEL_TYPE 
SSH_OPEN_RESOURCE_SHORTAGE 

Definition at line 110 of file common.h.

◆ PROTO_ENUM_PACKED [3/3]

Channel open failure reason codes (RFC 4254 sec 5.1).

Enumerator
SSH_MSG_DISCONNECT 
SSH_MSG_IGNORE 
SSH_MSG_UNIMPLEMENTED 
SSH_MSG_DEBUG 
SSH_MSG_SERVICE_REQUEST 
SSH_MSG_SERVICE_ACCEPT 
SSH_MSG_EXT_INFO 
SSH_MSG_KEXINIT 
SSH_MSG_NEWKEYS 
SSH_MSG_KEXDH_INIT 
SSH_MSG_KEXDH_REPLY 
SSH_MSG_USERAUTH_REQUEST 
SSH_MSG_USERAUTH_FAILURE 
SSH_MSG_USERAUTH_SUCCESS 
SSH_MSG_USERAUTH_BANNER 
SSH_MSG_USERAUTH_PK_OK 
SSH_MSG_USERAUTH_INFO_REQUEST 
SSH_MSG_USERAUTH_INFO_RESPONSE 
SSH_MSG_GLOBAL_REQUEST 
SSH_MSG_REQUEST_SUCCESS 
SSH_MSG_REQUEST_FAILURE 
SSH_MSG_CHANNEL_OPEN 
SSH_MSG_CHANNEL_OPEN_CONFIRMATION 
SSH_MSG_CHANNEL_OPEN_FAILURE 
SSH_MSG_CHANNEL_WINDOW_ADJUST 
SSH_MSG_CHANNEL_DATA 
SSH_MSG_CHANNEL_EXTENDED_DATA 
SSH_MSG_CHANNEL_EOF 
SSH_MSG_CHANNEL_CLOSE 
SSH_MSG_CHANNEL_REQUEST 
SSH_MSG_CHANNEL_SUCCESS 
SSH_MSG_CHANNEL_FAILURE 
SSH_DISCONNECT_PROTOCOL_ERROR 
SSH_DISCONNECT_MAC_ERROR 
SSH_DISCONNECT_SERVICE_NOT_AVAILABLE 
SSH_DISCONNECT_BY_APPLICATION 
SSH_DISCONNECT_TOO_MANY_CONNECTIONS 
SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE 
SSH_OPEN_ADMINISTRATIVELY_PROHIBITED 
SSH_OPEN_CONNECT_FAILED 
SSH_OPEN_UNKNOWN_CHANNEL_TYPE 
SSH_OPEN_RESOURCE_SHORTAGE 

Definition at line 121 of file common.h.

Function Documentation

◆ protocore_ssh_wr_str()

PROTOCORE_INLINE void protocore_ssh_wr_str ( mmgr_span *  w,
const void *  data,
size_t  n 
)

Append a string: uint32 length, then n bytes of data.

Definition at line 253 of file common.h.

Referenced by protocore_ssh_wr_cstr().

◆ protocore_ssh_wr_cstr()

PROTOCORE_INLINE void protocore_ssh_wr_cstr ( mmgr_span *  w,
const char *  s 
)

Append a NUL-terminated s as a string, its length taken up to the span's capacity.

A comma-separated name-list (RFC 4253 sec 7.1) is one of these.

Definition at line 264 of file common.h.

References protocore_ssh_wr_str().

◆ protocore_ssh_wr_mpint()

PROTOCORE_INLINE void protocore_ssh_wr_mpint ( mmgr_span *  w,
const uint8_t *  be,
size_t  len 
)

Append len big-endian bytes as an mpint: leading zero bytes stripped, a 0x00 prepended when the top bit is set, and a zero value written as the empty string.

Definition at line 273 of file common.h.

◆ protocore_ssh_rd_u8()

PROTOCORE_INLINE uint8_t protocore_ssh_rd_u8 ( Rd *  r)

Definition at line 415 of file common.h.

References Rd::buf, Rd::len, Rd::off, Rd::ok, and PROTO_FALSE.

◆ protocore_ssh_rd_u32()

PROTOCORE_INLINE uint32_t protocore_ssh_rd_u32 ( Rd *  r)

Definition at line 424 of file common.h.

References Rd::buf, Rd::len, Rd::off, Rd::ok, and PROTO_FALSE.

◆ protocore_ssh_rd_string()

PROTOCORE_INLINE const uint8_t * protocore_ssh_rd_string ( Rd *  r,
uint32_t *  n 
)

Definition at line 437 of file common.h.

References Rd::buf, Rd::len, Rd::off, Rd::ok, and PROTO_FALSE.