| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 1 | /* | 
 | 2 |  * Copyright 1995, 1996 by David Mazieres <dm@lcs.mit.edu>. | 
 | 3 |  * | 
 | 4 |  * Modification and redistribution in source and binary forms is | 
 | 5 |  * permitted provided that due credit is given to the author and the | 
| Ben Lindstrom | a238f6e | 2001-06-09 01:30:39 +0000 | [diff] [blame] | 6 |  * OpenBSD project by leaving this copyright notice intact. | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 7 |  */ | 
 | 8 |  | 
 | 9 | #include "includes.h" | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 10 | RCSID("$OpenBSD: ssh-keyscan.c,v 1.51 2005/03/01 10:41:28 djm Exp $"); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 11 |  | 
| Damien Miller | 9b48151 | 2002-09-12 10:43:29 +1000 | [diff] [blame] | 12 | #include "openbsd-compat/sys-queue.h" | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 13 |  | 
 | 14 | #include <openssl/bn.h> | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 15 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 16 | #include <setjmp.h> | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 17 | #include "xmalloc.h" | 
 | 18 | #include "ssh.h" | 
| Ben Lindstrom | 226cfa0 | 2001-01-22 05:34:40 +0000 | [diff] [blame] | 19 | #include "ssh1.h" | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 20 | #include "key.h" | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 21 | #include "kex.h" | 
 | 22 | #include "compat.h" | 
 | 23 | #include "myproposal.h" | 
 | 24 | #include "packet.h" | 
 | 25 | #include "dispatch.h" | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 26 | #include "buffer.h" | 
 | 27 | #include "bufaux.h" | 
| Ben Lindstrom | 226cfa0 | 2001-01-22 05:34:40 +0000 | [diff] [blame] | 28 | #include "log.h" | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 29 | #include "atomicio.h" | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 30 | #include "misc.h" | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 31 | #include "hostfile.h" | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 32 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 33 | /* Flag indicating whether IPv4 or IPv6.  This can be set on the command line. | 
 | 34 |    Default value is AF_UNSPEC means both IPv4 and IPv6. */ | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 35 | int IPv4or6 = AF_UNSPEC; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 36 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 37 | int ssh_port = SSH_DEFAULT_PORT; | 
| Kevin Steves | 76e7d9b | 2001-09-20 20:30:09 +0000 | [diff] [blame] | 38 |  | 
 | 39 | #define KT_RSA1	1 | 
 | 40 | #define KT_DSA	2 | 
 | 41 | #define KT_RSA	4 | 
 | 42 |  | 
 | 43 | int get_keytypes = KT_RSA1;	/* Get only RSA1 keys by default */ | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 44 |  | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 45 | int hash_hosts = 0;		/* Hash hostname on output */ | 
 | 46 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 47 | #define MAXMAXFD 256 | 
 | 48 |  | 
 | 49 | /* The number of seconds after which to give up on a TCP connection */ | 
 | 50 | int timeout = 5; | 
 | 51 |  | 
 | 52 | int maxfd; | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 53 | #define MAXCON (maxfd - 10) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 54 |  | 
| Kevin Steves | ec84dc1 | 2000-12-13 17:45:15 +0000 | [diff] [blame] | 55 | extern char *__progname; | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 56 | fd_set *read_wait; | 
 | 57 | size_t read_wait_size; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 58 | int ncon; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 59 | int nonfatal_fatal = 0; | 
 | 60 | jmp_buf kexjmp; | 
| Ben Lindstrom | 520b55c | 2001-09-12 18:05:05 +0000 | [diff] [blame] | 61 | Key *kexjmp_key; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 62 |  | 
 | 63 | /* | 
 | 64 |  * Keep a connection structure for each file descriptor.  The state | 
 | 65 |  * associated with file descriptor n is held in fdcon[n]. | 
 | 66 |  */ | 
 | 67 | typedef struct Connection { | 
| Ben Lindstrom | 46c1622 | 2000-12-22 01:43:59 +0000 | [diff] [blame] | 68 | 	u_char c_status;	/* State of connection on this file desc. */ | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 69 | #define CS_UNUSED 0		/* File descriptor unused */ | 
 | 70 | #define CS_CON 1		/* Waiting to connect/read greeting */ | 
 | 71 | #define CS_SIZE 2		/* Waiting to read initial packet size */ | 
 | 72 | #define CS_KEYS 3		/* Waiting to read public key packet */ | 
 | 73 | 	int c_fd;		/* Quick lookup: c->c_fd == c - fdcon */ | 
 | 74 | 	int c_plen;		/* Packet length field for ssh packet */ | 
 | 75 | 	int c_len;		/* Total bytes which must be read. */ | 
 | 76 | 	int c_off;		/* Length of data read so far. */ | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 77 | 	int c_keytype;		/* Only one of KT_RSA1, KT_DSA, or KT_RSA */ | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 78 | 	char *c_namebase;	/* Address to free for c_name and c_namelist */ | 
 | 79 | 	char *c_name;		/* Hostname of connection for errors */ | 
 | 80 | 	char *c_namelist;	/* Pointer to other possible addresses */ | 
 | 81 | 	char *c_output_name;	/* Hostname of connection for output */ | 
 | 82 | 	char *c_data;		/* Data read from this fd */ | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 83 | 	Kex *c_kex;		/* The key-exchange struct for ssh2 */ | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 84 | 	struct timeval c_tv;	/* Time at which connection gets aborted */ | 
 | 85 | 	TAILQ_ENTRY(Connection) c_link;	/* List of connections in timeout order. */ | 
 | 86 | } con; | 
 | 87 |  | 
 | 88 | TAILQ_HEAD(conlist, Connection) tq;	/* Timeout Queue */ | 
 | 89 | con *fdcon; | 
 | 90 |  | 
 | 91 | /* | 
 | 92 |  *  This is just a wrapper around fgets() to make it usable. | 
 | 93 |  */ | 
 | 94 |  | 
 | 95 | /* Stress-test.  Increase this later. */ | 
 | 96 | #define LINEBUF_SIZE 16 | 
 | 97 |  | 
 | 98 | typedef struct { | 
 | 99 | 	char *buf; | 
| Ben Lindstrom | 46c1622 | 2000-12-22 01:43:59 +0000 | [diff] [blame] | 100 | 	u_int size; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 101 | 	int lineno; | 
 | 102 | 	const char *filename; | 
 | 103 | 	FILE *stream; | 
 | 104 | 	void (*errfun) (const char *,...); | 
 | 105 | } Linebuf; | 
 | 106 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 107 | static Linebuf * | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 108 | Linebuf_alloc(const char *filename, void (*errfun) (const char *,...)) | 
 | 109 | { | 
 | 110 | 	Linebuf *lb; | 
 | 111 |  | 
 | 112 | 	if (!(lb = malloc(sizeof(*lb)))) { | 
 | 113 | 		if (errfun) | 
| Ben Lindstrom | 04f9af7 | 2002-07-04 00:03:56 +0000 | [diff] [blame] | 114 | 			(*errfun) ("linebuf (%s): malloc failed\n", | 
 | 115 | 			    filename ? filename : "(stdin)"); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 116 | 		return (NULL); | 
 | 117 | 	} | 
 | 118 | 	if (filename) { | 
 | 119 | 		lb->filename = filename; | 
 | 120 | 		if (!(lb->stream = fopen(filename, "r"))) { | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 121 | 			xfree(lb); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 122 | 			if (errfun) | 
 | 123 | 				(*errfun) ("%s: %s\n", filename, strerror(errno)); | 
 | 124 | 			return (NULL); | 
 | 125 | 		} | 
 | 126 | 	} else { | 
 | 127 | 		lb->filename = "(stdin)"; | 
 | 128 | 		lb->stream = stdin; | 
 | 129 | 	} | 
 | 130 |  | 
 | 131 | 	if (!(lb->buf = malloc(lb->size = LINEBUF_SIZE))) { | 
 | 132 | 		if (errfun) | 
 | 133 | 			(*errfun) ("linebuf (%s): malloc failed\n", lb->filename); | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 134 | 		xfree(lb); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 135 | 		return (NULL); | 
 | 136 | 	} | 
 | 137 | 	lb->errfun = errfun; | 
 | 138 | 	lb->lineno = 0; | 
 | 139 | 	return (lb); | 
 | 140 | } | 
 | 141 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 142 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 143 | Linebuf_free(Linebuf * lb) | 
 | 144 | { | 
 | 145 | 	fclose(lb->stream); | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 146 | 	xfree(lb->buf); | 
 | 147 | 	xfree(lb); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 148 | } | 
 | 149 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 150 | #if 0 | 
 | 151 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 152 | Linebuf_restart(Linebuf * lb) | 
 | 153 | { | 
 | 154 | 	clearerr(lb->stream); | 
 | 155 | 	rewind(lb->stream); | 
 | 156 | 	lb->lineno = 0; | 
 | 157 | } | 
 | 158 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 159 | static int | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 160 | Linebuf_lineno(Linebuf * lb) | 
 | 161 | { | 
 | 162 | 	return (lb->lineno); | 
 | 163 | } | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 164 | #endif | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 165 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 166 | static char * | 
| Ben Lindstrom | c791beb | 2001-02-10 23:18:11 +0000 | [diff] [blame] | 167 | Linebuf_getline(Linebuf * lb) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 168 | { | 
 | 169 | 	int n = 0; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 170 | 	void *p; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 171 |  | 
 | 172 | 	lb->lineno++; | 
 | 173 | 	for (;;) { | 
 | 174 | 		/* Read a line */ | 
 | 175 | 		if (!fgets(&lb->buf[n], lb->size - n, lb->stream)) { | 
 | 176 | 			if (ferror(lb->stream) && lb->errfun) | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 177 | 				(*lb->errfun)("%s: %s\n", lb->filename, | 
| Ben Lindstrom | b0a4cd8 | 2001-03-05 04:54:49 +0000 | [diff] [blame] | 178 | 				    strerror(errno)); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 179 | 			return (NULL); | 
 | 180 | 		} | 
 | 181 | 		n = strlen(lb->buf); | 
 | 182 |  | 
 | 183 | 		/* Return it or an error if it fits */ | 
 | 184 | 		if (n > 0 && lb->buf[n - 1] == '\n') { | 
 | 185 | 			lb->buf[n - 1] = '\0'; | 
 | 186 | 			return (lb->buf); | 
 | 187 | 		} | 
 | 188 | 		if (n != lb->size - 1) { | 
 | 189 | 			if (lb->errfun) | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 190 | 				(*lb->errfun)("%s: skipping incomplete last line\n", | 
| Ben Lindstrom | b0a4cd8 | 2001-03-05 04:54:49 +0000 | [diff] [blame] | 191 | 				    lb->filename); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 192 | 			return (NULL); | 
 | 193 | 		} | 
 | 194 | 		/* Double the buffer if we need more space */ | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 195 | 		lb->size *= 2; | 
 | 196 | 		if ((p = realloc(lb->buf, lb->size)) == NULL) { | 
 | 197 | 			lb->size /= 2; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 198 | 			if (lb->errfun) | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 199 | 				(*lb->errfun)("linebuf (%s): realloc failed\n", | 
| Ben Lindstrom | b0a4cd8 | 2001-03-05 04:54:49 +0000 | [diff] [blame] | 200 | 				    lb->filename); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 201 | 			return (NULL); | 
 | 202 | 		} | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 203 | 		lb->buf = p; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 204 | 	} | 
 | 205 | } | 
 | 206 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 207 | static int | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 208 | fdlim_get(int hard) | 
 | 209 | { | 
| Ben Lindstrom | 5adbad2 | 2000-12-27 07:06:21 +0000 | [diff] [blame] | 210 | #if defined(HAVE_GETRLIMIT) && defined(RLIMIT_NOFILE) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 211 | 	struct rlimit rlfd; | 
| Ben Lindstrom | b0a4cd8 | 2001-03-05 04:54:49 +0000 | [diff] [blame] | 212 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 213 | 	if (getrlimit(RLIMIT_NOFILE, &rlfd) < 0) | 
 | 214 | 		return (-1); | 
 | 215 | 	if ((hard ? rlfd.rlim_max : rlfd.rlim_cur) == RLIM_INFINITY) | 
| Damien Miller | e00074a | 2003-11-24 13:07:45 +1100 | [diff] [blame] | 216 | 		return SSH_SYSFDMAX; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 217 | 	else | 
 | 218 | 		return hard ? rlfd.rlim_max : rlfd.rlim_cur; | 
| Ben Lindstrom | 2c467a2 | 2000-12-27 04:57:41 +0000 | [diff] [blame] | 219 | #else | 
| Damien Miller | e00074a | 2003-11-24 13:07:45 +1100 | [diff] [blame] | 220 | 	return SSH_SYSFDMAX; | 
| Ben Lindstrom | 2c467a2 | 2000-12-27 04:57:41 +0000 | [diff] [blame] | 221 | #endif | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 222 | } | 
 | 223 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 224 | static int | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 225 | fdlim_set(int lim) | 
 | 226 | { | 
| Ben Lindstrom | 5adbad2 | 2000-12-27 07:06:21 +0000 | [diff] [blame] | 227 | #if defined(HAVE_SETRLIMIT) && defined(RLIMIT_NOFILE) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 228 | 	struct rlimit rlfd; | 
| Ben Lindstrom | 2c467a2 | 2000-12-27 04:57:41 +0000 | [diff] [blame] | 229 | #endif | 
| Ben Lindstrom | 5c98db5 | 2002-07-07 22:25:29 +0000 | [diff] [blame] | 230 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 231 | 	if (lim <= 0) | 
 | 232 | 		return (-1); | 
| Ben Lindstrom | 5adbad2 | 2000-12-27 07:06:21 +0000 | [diff] [blame] | 233 | #if defined(HAVE_SETRLIMIT) && defined(RLIMIT_NOFILE) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 234 | 	if (getrlimit(RLIMIT_NOFILE, &rlfd) < 0) | 
 | 235 | 		return (-1); | 
 | 236 | 	rlfd.rlim_cur = lim; | 
 | 237 | 	if (setrlimit(RLIMIT_NOFILE, &rlfd) < 0) | 
 | 238 | 		return (-1); | 
| Ben Lindstrom | 2c467a2 | 2000-12-27 04:57:41 +0000 | [diff] [blame] | 239 | #elif defined (HAVE_SETDTABLESIZE) | 
| Kevin Steves | 28a7f26 | 2001-02-05 15:43:59 +0000 | [diff] [blame] | 240 | 	setdtablesize(lim); | 
| Ben Lindstrom | 2c467a2 | 2000-12-27 04:57:41 +0000 | [diff] [blame] | 241 | #endif | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 242 | 	return (0); | 
 | 243 | } | 
 | 244 |  | 
 | 245 | /* | 
 | 246 |  * This is an strsep function that returns a null field for adjacent | 
 | 247 |  * separators.  This is the same as the 4.4BSD strsep, but different from the | 
 | 248 |  * one in the GNU libc. | 
 | 249 |  */ | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 250 | static char * | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 251 | xstrsep(char **str, const char *delim) | 
 | 252 | { | 
 | 253 | 	char *s, *e; | 
 | 254 |  | 
 | 255 | 	if (!**str) | 
 | 256 | 		return (NULL); | 
 | 257 |  | 
 | 258 | 	s = *str; | 
 | 259 | 	e = s + strcspn(s, delim); | 
 | 260 |  | 
 | 261 | 	if (*e != '\0') | 
 | 262 | 		*e++ = '\0'; | 
 | 263 | 	*str = e; | 
 | 264 |  | 
 | 265 | 	return (s); | 
 | 266 | } | 
 | 267 |  | 
 | 268 | /* | 
 | 269 |  * Get the next non-null token (like GNU strsep).  Strsep() will return a | 
 | 270 |  * null token for two adjacent separators, so we may have to loop. | 
 | 271 |  */ | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 272 | static char * | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 273 | strnnsep(char **stringp, char *delim) | 
 | 274 | { | 
 | 275 | 	char *tok; | 
 | 276 |  | 
 | 277 | 	do { | 
 | 278 | 		tok = xstrsep(stringp, delim); | 
 | 279 | 	} while (tok && *tok == '\0'); | 
 | 280 | 	return (tok); | 
 | 281 | } | 
 | 282 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 283 | static Key * | 
 | 284 | keygrab_ssh1(con *c) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 285 | { | 
 | 286 | 	static Key *rsa; | 
 | 287 | 	static Buffer msg; | 
 | 288 |  | 
 | 289 | 	if (rsa == NULL) { | 
 | 290 | 		buffer_init(&msg); | 
 | 291 | 		rsa = key_new(KEY_RSA1); | 
 | 292 | 	} | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 293 | 	buffer_append(&msg, c->c_data, c->c_plen); | 
 | 294 | 	buffer_consume(&msg, 8 - (c->c_plen & 7));	/* padding */ | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 295 | 	if (buffer_get_char(&msg) != (int) SSH_SMSG_PUBLIC_KEY) { | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 296 | 		error("%s: invalid packet type", c->c_name); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 297 | 		buffer_clear(&msg); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 298 | 		return NULL; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 299 | 	} | 
 | 300 | 	buffer_consume(&msg, 8);		/* cookie */ | 
 | 301 |  | 
 | 302 | 	/* server key */ | 
 | 303 | 	(void) buffer_get_int(&msg); | 
 | 304 | 	buffer_get_bignum(&msg, rsa->rsa->e); | 
 | 305 | 	buffer_get_bignum(&msg, rsa->rsa->n); | 
 | 306 |  | 
 | 307 | 	/* host key */ | 
 | 308 | 	(void) buffer_get_int(&msg); | 
 | 309 | 	buffer_get_bignum(&msg, rsa->rsa->e); | 
 | 310 | 	buffer_get_bignum(&msg, rsa->rsa->n); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 311 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 312 | 	buffer_clear(&msg); | 
 | 313 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 314 | 	return (rsa); | 
 | 315 | } | 
 | 316 |  | 
 | 317 | static int | 
 | 318 | hostjump(Key *hostkey) | 
 | 319 | { | 
| Ben Lindstrom | 520b55c | 2001-09-12 18:05:05 +0000 | [diff] [blame] | 320 | 	kexjmp_key = hostkey; | 
 | 321 | 	longjmp(kexjmp, 1); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 322 | } | 
 | 323 |  | 
 | 324 | static int | 
 | 325 | ssh2_capable(int remote_major, int remote_minor) | 
 | 326 | { | 
 | 327 | 	switch (remote_major) { | 
 | 328 | 	case 1: | 
 | 329 | 		if (remote_minor == 99) | 
 | 330 | 			return 1; | 
 | 331 | 		break; | 
 | 332 | 	case 2: | 
 | 333 | 		return 1; | 
 | 334 | 	default: | 
 | 335 | 		break; | 
 | 336 | 	} | 
 | 337 | 	return 0; | 
 | 338 | } | 
 | 339 |  | 
 | 340 | static Key * | 
 | 341 | keygrab_ssh2(con *c) | 
 | 342 | { | 
 | 343 | 	int j; | 
 | 344 |  | 
 | 345 | 	packet_set_connection(c->c_fd, c->c_fd); | 
 | 346 | 	enable_compat20(); | 
 | 347 | 	myproposal[PROPOSAL_SERVER_HOST_KEY_ALGS] = c->c_keytype == KT_DSA? | 
 | 348 | 	    "ssh-dss": "ssh-rsa"; | 
 | 349 | 	c->c_kex = kex_setup(myproposal); | 
| Damien Miller | 8e7fb33 | 2003-02-24 12:03:03 +1100 | [diff] [blame] | 350 | 	c->c_kex->kex[KEX_DH_GRP1_SHA1] = kexdh_client; | 
| Damien Miller | f675fc4 | 2004-06-15 10:30:09 +1000 | [diff] [blame] | 351 | 	c->c_kex->kex[KEX_DH_GRP14_SHA1] = kexdh_client; | 
| Damien Miller | 8e7fb33 | 2003-02-24 12:03:03 +1100 | [diff] [blame] | 352 | 	c->c_kex->kex[KEX_DH_GEX_SHA1] = kexgex_client; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 353 | 	c->c_kex->verify_host_key = hostjump; | 
 | 354 |  | 
 | 355 | 	if (!(j = setjmp(kexjmp))) { | 
 | 356 | 		nonfatal_fatal = 1; | 
 | 357 | 		dispatch_run(DISPATCH_BLOCK, &c->c_kex->done, c->c_kex); | 
 | 358 | 		fprintf(stderr, "Impossible! dispatch_run() returned!\n"); | 
 | 359 | 		exit(1); | 
 | 360 | 	} | 
 | 361 | 	nonfatal_fatal = 0; | 
 | 362 | 	xfree(c->c_kex); | 
 | 363 | 	c->c_kex = NULL; | 
 | 364 | 	packet_close(); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 365 |  | 
| Ben Lindstrom | 520b55c | 2001-09-12 18:05:05 +0000 | [diff] [blame] | 366 | 	return j < 0? NULL : kexjmp_key; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 367 | } | 
 | 368 |  | 
 | 369 | static void | 
 | 370 | keyprint(con *c, Key *key) | 
 | 371 | { | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 372 | 	char *host = c->c_output_name ? c->c_output_name : c->c_name; | 
 | 373 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 374 | 	if (!key) | 
 | 375 | 		return; | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 376 | 	if (hash_hosts && (host = host_hash(host, NULL, 0)) == NULL) | 
 | 377 | 		fatal("host_hash failed"); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 378 |  | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 379 | 	fprintf(stdout, "%s ", host); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 380 | 	key_write(key, stdout); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 381 | 	fputs("\n", stdout); | 
 | 382 | } | 
 | 383 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 384 | static int | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 385 | tcpconnect(char *host) | 
 | 386 | { | 
 | 387 | 	struct addrinfo hints, *ai, *aitop; | 
 | 388 | 	char strport[NI_MAXSERV]; | 
 | 389 | 	int gaierr, s = -1; | 
 | 390 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 391 | 	snprintf(strport, sizeof strport, "%d", ssh_port); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 392 | 	memset(&hints, 0, sizeof(hints)); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 393 | 	hints.ai_family = IPv4or6; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 394 | 	hints.ai_socktype = SOCK_STREAM; | 
 | 395 | 	if ((gaierr = getaddrinfo(host, strport, &hints, &aitop)) != 0) | 
 | 396 | 		fatal("getaddrinfo %s: %s", host, gai_strerror(gaierr)); | 
 | 397 | 	for (ai = aitop; ai; ai = ai->ai_next) { | 
| Damien Miller | 2372ace | 2003-05-14 13:42:23 +1000 | [diff] [blame] | 398 | 		s = socket(ai->ai_family, ai->ai_socktype, ai->ai_protocol); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 399 | 		if (s < 0) { | 
 | 400 | 			error("socket: %s", strerror(errno)); | 
 | 401 | 			continue; | 
 | 402 | 		} | 
| Damien Miller | 232711f | 2004-06-15 10:35:30 +1000 | [diff] [blame] | 403 | 		if (set_nonblock(s) == -1) | 
 | 404 | 			fatal("%s: set_nonblock(%d)", __func__, s); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 405 | 		if (connect(s, ai->ai_addr, ai->ai_addrlen) < 0 && | 
 | 406 | 		    errno != EINPROGRESS) | 
 | 407 | 			error("connect (`%s'): %s", host, strerror(errno)); | 
 | 408 | 		else | 
 | 409 | 			break; | 
 | 410 | 		close(s); | 
 | 411 | 		s = -1; | 
 | 412 | 	} | 
 | 413 | 	freeaddrinfo(aitop); | 
 | 414 | 	return s; | 
 | 415 | } | 
 | 416 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 417 | static int | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 418 | conalloc(char *iname, char *oname, int keytype) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 419 | { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 420 | 	char *namebase, *name, *namelist; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 421 | 	int s; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 422 |  | 
 | 423 | 	namebase = namelist = xstrdup(iname); | 
 | 424 |  | 
 | 425 | 	do { | 
 | 426 | 		name = xstrsep(&namelist, ","); | 
 | 427 | 		if (!name) { | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 428 | 			xfree(namebase); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 429 | 			return (-1); | 
 | 430 | 		} | 
 | 431 | 	} while ((s = tcpconnect(name)) < 0); | 
 | 432 |  | 
 | 433 | 	if (s >= maxfd) | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 434 | 		fatal("conalloc: fdno %d too high", s); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 435 | 	if (fdcon[s].c_status) | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 436 | 		fatal("conalloc: attempt to reuse fdno %d", s); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 437 |  | 
 | 438 | 	fdcon[s].c_fd = s; | 
 | 439 | 	fdcon[s].c_status = CS_CON; | 
 | 440 | 	fdcon[s].c_namebase = namebase; | 
 | 441 | 	fdcon[s].c_name = name; | 
 | 442 | 	fdcon[s].c_namelist = namelist; | 
 | 443 | 	fdcon[s].c_output_name = xstrdup(oname); | 
 | 444 | 	fdcon[s].c_data = (char *) &fdcon[s].c_plen; | 
 | 445 | 	fdcon[s].c_len = 4; | 
 | 446 | 	fdcon[s].c_off = 0; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 447 | 	fdcon[s].c_keytype = keytype; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 448 | 	gettimeofday(&fdcon[s].c_tv, NULL); | 
 | 449 | 	fdcon[s].c_tv.tv_sec += timeout; | 
 | 450 | 	TAILQ_INSERT_TAIL(&tq, &fdcon[s], c_link); | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 451 | 	FD_SET(s, read_wait); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 452 | 	ncon++; | 
 | 453 | 	return (s); | 
 | 454 | } | 
 | 455 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 456 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 457 | confree(int s) | 
 | 458 | { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 459 | 	if (s >= maxfd || fdcon[s].c_status == CS_UNUSED) | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 460 | 		fatal("confree: attempt to free bad fdno %d", s); | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 461 | 	close(s); | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 462 | 	xfree(fdcon[s].c_namebase); | 
 | 463 | 	xfree(fdcon[s].c_output_name); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 464 | 	if (fdcon[s].c_status == CS_KEYS) | 
| Ben Lindstrom | bf555ba | 2001-01-18 02:04:35 +0000 | [diff] [blame] | 465 | 		xfree(fdcon[s].c_data); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 466 | 	fdcon[s].c_status = CS_UNUSED; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 467 | 	fdcon[s].c_keytype = 0; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 468 | 	TAILQ_REMOVE(&tq, &fdcon[s], c_link); | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 469 | 	FD_CLR(s, read_wait); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 470 | 	ncon--; | 
 | 471 | } | 
 | 472 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 473 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 474 | contouch(int s) | 
 | 475 | { | 
 | 476 | 	TAILQ_REMOVE(&tq, &fdcon[s], c_link); | 
 | 477 | 	gettimeofday(&fdcon[s].c_tv, NULL); | 
 | 478 | 	fdcon[s].c_tv.tv_sec += timeout; | 
 | 479 | 	TAILQ_INSERT_TAIL(&tq, &fdcon[s], c_link); | 
 | 480 | } | 
 | 481 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 482 | static int | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 483 | conrecycle(int s) | 
 | 484 | { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 485 | 	con *c = &fdcon[s]; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 486 | 	int ret; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 487 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 488 | 	ret = conalloc(c->c_namelist, c->c_output_name, c->c_keytype); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 489 | 	confree(s); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 490 | 	return (ret); | 
 | 491 | } | 
 | 492 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 493 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 494 | congreet(int s) | 
 | 495 | { | 
| Damien Miller | 3b51301 | 2004-03-08 23:13:00 +1100 | [diff] [blame] | 496 | 	int remote_major = 0, remote_minor = 0, n = 0; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 497 | 	char buf[256], *cp; | 
| Damien Miller | 83c02ef | 2001-12-21 12:45:43 +1100 | [diff] [blame] | 498 | 	char remote_version[sizeof buf]; | 
| Ben Lindstrom | 884a4ac | 2001-03-06 03:33:04 +0000 | [diff] [blame] | 499 | 	size_t bufsiz; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 500 | 	con *c = &fdcon[s]; | 
 | 501 |  | 
| Ben Lindstrom | 884a4ac | 2001-03-06 03:33:04 +0000 | [diff] [blame] | 502 | 	bufsiz = sizeof(buf); | 
 | 503 | 	cp = buf; | 
| Darren Tucker | fe6649d | 2004-08-13 21:19:37 +1000 | [diff] [blame] | 504 | 	while (bufsiz-- && (n = atomicio(read, s, cp, 1)) == 1 && *cp != '\n') { | 
| Ben Lindstrom | de8fc6f | 2001-08-06 22:43:50 +0000 | [diff] [blame] | 505 | 		if (*cp == '\r') | 
 | 506 | 			*cp = '\n'; | 
| Ben Lindstrom | 884a4ac | 2001-03-06 03:33:04 +0000 | [diff] [blame] | 507 | 		cp++; | 
| Ben Lindstrom | de8fc6f | 2001-08-06 22:43:50 +0000 | [diff] [blame] | 508 | 	} | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 509 | 	if (n < 0) { | 
 | 510 | 		if (errno != ECONNREFUSED) | 
 | 511 | 			error("read (%s): %s", c->c_name, strerror(errno)); | 
 | 512 | 		conrecycle(s); | 
 | 513 | 		return; | 
 | 514 | 	} | 
| Ben Lindstrom | 6b28c35 | 2002-03-05 01:54:52 +0000 | [diff] [blame] | 515 | 	if (n == 0) { | 
 | 516 | 		error("%s: Connection closed by remote host", c->c_name); | 
 | 517 | 		conrecycle(s); | 
 | 518 | 		return; | 
 | 519 | 	} | 
| Ben Lindstrom | 884a4ac | 2001-03-06 03:33:04 +0000 | [diff] [blame] | 520 | 	if (*cp != '\n' && *cp != '\r') { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 521 | 		error("%s: bad greeting", c->c_name); | 
 | 522 | 		confree(s); | 
 | 523 | 		return; | 
 | 524 | 	} | 
| Ben Lindstrom | 884a4ac | 2001-03-06 03:33:04 +0000 | [diff] [blame] | 525 | 	*cp = '\0'; | 
| Damien Miller | 83c02ef | 2001-12-21 12:45:43 +1100 | [diff] [blame] | 526 | 	if (sscanf(buf, "SSH-%d.%d-%[^\n]\n", | 
 | 527 | 	    &remote_major, &remote_minor, remote_version) == 3) | 
 | 528 | 		compat_datafellows(remote_version); | 
 | 529 | 	else | 
 | 530 | 		datafellows = 0; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 531 | 	if (c->c_keytype != KT_RSA1) { | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 532 | 		if (!ssh2_capable(remote_major, remote_minor)) { | 
 | 533 | 			debug("%s doesn't support ssh2", c->c_name); | 
 | 534 | 			confree(s); | 
 | 535 | 			return; | 
 | 536 | 		} | 
| Damien Miller | 83c02ef | 2001-12-21 12:45:43 +1100 | [diff] [blame] | 537 | 	} else if (remote_major != 1) { | 
 | 538 | 		debug("%s doesn't support ssh1", c->c_name); | 
 | 539 | 		confree(s); | 
 | 540 | 		return; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 541 | 	} | 
| Ben Lindstrom | de8fc6f | 2001-08-06 22:43:50 +0000 | [diff] [blame] | 542 | 	fprintf(stderr, "# %s %s\n", c->c_name, chop(buf)); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 543 | 	n = snprintf(buf, sizeof buf, "SSH-%d.%d-OpenSSH-keyscan\r\n", | 
 | 544 | 	    c->c_keytype == KT_RSA1? PROTOCOL_MAJOR_1 : PROTOCOL_MAJOR_2, | 
 | 545 | 	    c->c_keytype == KT_RSA1? PROTOCOL_MINOR_1 : PROTOCOL_MINOR_2); | 
| Darren Tucker | 9f63f22 | 2003-07-03 13:46:56 +1000 | [diff] [blame] | 546 | 	if (atomicio(vwrite, s, buf, n) != n) { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 547 | 		error("write (%s): %s", c->c_name, strerror(errno)); | 
 | 548 | 		confree(s); | 
 | 549 | 		return; | 
 | 550 | 	} | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 551 | 	if (c->c_keytype != KT_RSA1) { | 
 | 552 | 		keyprint(c, keygrab_ssh2(c)); | 
 | 553 | 		confree(s); | 
 | 554 | 		return; | 
 | 555 | 	} | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 556 | 	c->c_status = CS_SIZE; | 
 | 557 | 	contouch(s); | 
 | 558 | } | 
 | 559 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 560 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 561 | conread(int s) | 
 | 562 | { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 563 | 	con *c = &fdcon[s]; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 564 | 	int n; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 565 |  | 
 | 566 | 	if (c->c_status == CS_CON) { | 
 | 567 | 		congreet(s); | 
 | 568 | 		return; | 
 | 569 | 	} | 
| Darren Tucker | fe6649d | 2004-08-13 21:19:37 +1000 | [diff] [blame] | 570 | 	n = atomicio(read, s, c->c_data + c->c_off, c->c_len - c->c_off); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 571 | 	if (n < 0) { | 
 | 572 | 		error("read (%s): %s", c->c_name, strerror(errno)); | 
 | 573 | 		confree(s); | 
 | 574 | 		return; | 
 | 575 | 	} | 
 | 576 | 	c->c_off += n; | 
 | 577 |  | 
 | 578 | 	if (c->c_off == c->c_len) | 
 | 579 | 		switch (c->c_status) { | 
 | 580 | 		case CS_SIZE: | 
 | 581 | 			c->c_plen = htonl(c->c_plen); | 
 | 582 | 			c->c_len = c->c_plen + 8 - (c->c_plen & 7); | 
 | 583 | 			c->c_off = 0; | 
 | 584 | 			c->c_data = xmalloc(c->c_len); | 
 | 585 | 			c->c_status = CS_KEYS; | 
 | 586 | 			break; | 
 | 587 | 		case CS_KEYS: | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 588 | 			keyprint(c, keygrab_ssh1(c)); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 589 | 			confree(s); | 
 | 590 | 			return; | 
 | 591 | 			break; | 
 | 592 | 		default: | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 593 | 			fatal("conread: invalid status %d", c->c_status); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 594 | 			break; | 
 | 595 | 		} | 
 | 596 |  | 
 | 597 | 	contouch(s); | 
 | 598 | } | 
 | 599 |  | 
| Ben Lindstrom | bba8121 | 2001-06-25 05:01:22 +0000 | [diff] [blame] | 600 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 601 | conloop(void) | 
 | 602 | { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 603 | 	struct timeval seltime, now; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 604 | 	fd_set *r, *e; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 605 | 	con *c; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 606 | 	int i; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 607 |  | 
 | 608 | 	gettimeofday(&now, NULL); | 
| Ben Lindstrom | 61c183b | 2002-06-21 00:09:54 +0000 | [diff] [blame] | 609 | 	c = TAILQ_FIRST(&tq); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 610 |  | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 611 | 	if (c && (c->c_tv.tv_sec > now.tv_sec || | 
 | 612 | 	    (c->c_tv.tv_sec == now.tv_sec && c->c_tv.tv_usec > now.tv_usec))) { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 613 | 		seltime = c->c_tv; | 
 | 614 | 		seltime.tv_sec -= now.tv_sec; | 
 | 615 | 		seltime.tv_usec -= now.tv_usec; | 
| Ben Lindstrom | c791beb | 2001-02-10 23:18:11 +0000 | [diff] [blame] | 616 | 		if (seltime.tv_usec < 0) { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 617 | 			seltime.tv_usec += 1000000; | 
 | 618 | 			seltime.tv_sec--; | 
 | 619 | 		} | 
 | 620 | 	} else | 
 | 621 | 		seltime.tv_sec = seltime.tv_usec = 0; | 
 | 622 |  | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 623 | 	r = xmalloc(read_wait_size); | 
 | 624 | 	memcpy(r, read_wait, read_wait_size); | 
 | 625 | 	e = xmalloc(read_wait_size); | 
 | 626 | 	memcpy(e, read_wait, read_wait_size); | 
 | 627 |  | 
 | 628 | 	while (select(maxfd, r, NULL, e, &seltime) == -1 && | 
| Ben Lindstrom | f945251 | 2001-02-15 03:12:08 +0000 | [diff] [blame] | 629 | 	    (errno == EAGAIN || errno == EINTR)) | 
 | 630 | 		; | 
 | 631 |  | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 632 | 	for (i = 0; i < maxfd; i++) { | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 633 | 		if (FD_ISSET(i, e)) { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 634 | 			error("%s: exception!", fdcon[i].c_name); | 
 | 635 | 			confree(i); | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 636 | 		} else if (FD_ISSET(i, r)) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 637 | 			conread(i); | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 638 | 	} | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 639 | 	xfree(r); | 
 | 640 | 	xfree(e); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 641 |  | 
| Ben Lindstrom | 61c183b | 2002-06-21 00:09:54 +0000 | [diff] [blame] | 642 | 	c = TAILQ_FIRST(&tq); | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 643 | 	while (c && (c->c_tv.tv_sec < now.tv_sec || | 
 | 644 | 	    (c->c_tv.tv_sec == now.tv_sec && c->c_tv.tv_usec < now.tv_usec))) { | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 645 | 		int s = c->c_fd; | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 646 |  | 
| Ben Lindstrom | 61c183b | 2002-06-21 00:09:54 +0000 | [diff] [blame] | 647 | 		c = TAILQ_NEXT(c, c_link); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 648 | 		conrecycle(s); | 
 | 649 | 	} | 
 | 650 | } | 
 | 651 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 652 | static void | 
 | 653 | do_host(char *host) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 654 | { | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 655 | 	char *name = strnnsep(&host, " \t\n"); | 
 | 656 | 	int j; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 657 |  | 
| Ben Lindstrom | eaffb9d | 2001-12-06 16:28:19 +0000 | [diff] [blame] | 658 | 	if (name == NULL) | 
 | 659 | 		return; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 660 | 	for (j = KT_RSA1; j <= KT_RSA; j *= 2) { | 
 | 661 | 		if (get_keytypes & j) { | 
 | 662 | 			while (ncon >= MAXCON) | 
 | 663 | 				conloop(); | 
 | 664 | 			conalloc(name, *host ? host : name, j); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 665 | 		} | 
 | 666 | 	} | 
 | 667 | } | 
 | 668 |  | 
| Ben Lindstrom | 9c8edc9 | 2002-02-26 17:52:14 +0000 | [diff] [blame] | 669 | void | 
 | 670 | fatal(const char *fmt,...) | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 671 | { | 
| Ben Lindstrom | 9c8edc9 | 2002-02-26 17:52:14 +0000 | [diff] [blame] | 672 | 	va_list args; | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 673 |  | 
| Ben Lindstrom | 9c8edc9 | 2002-02-26 17:52:14 +0000 | [diff] [blame] | 674 | 	va_start(args, fmt); | 
 | 675 | 	do_log(SYSLOG_LEVEL_FATAL, fmt, args); | 
 | 676 | 	va_end(args); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 677 | 	if (nonfatal_fatal) | 
 | 678 | 		longjmp(kexjmp, -1); | 
| Ben Lindstrom | 9c8edc9 | 2002-02-26 17:52:14 +0000 | [diff] [blame] | 679 | 	else | 
| Darren Tucker | 3d32622 | 2003-09-22 21:11:20 +1000 | [diff] [blame] | 680 | 		exit(255); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 681 | } | 
 | 682 |  | 
 | 683 | static void | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 684 | usage(void) | 
 | 685 | { | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 686 | 	fprintf(stderr, "usage: %s [-Hv46] [-p port] [-T timeout] [-t type] [-f file]\n" | 
| Ben Lindstrom | 965710f | 2002-07-07 22:17:22 +0000 | [diff] [blame] | 687 | 	    "\t\t   [host | addrlist namelist] [...]\n", | 
| Ben Lindstrom | ddfb1e3 | 2001-08-06 22:06:35 +0000 | [diff] [blame] | 688 | 	    __progname); | 
| Ben Lindstrom | ddfb1e3 | 2001-08-06 22:06:35 +0000 | [diff] [blame] | 689 | 	exit(1); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 690 | } | 
 | 691 |  | 
 | 692 | int | 
 | 693 | main(int argc, char **argv) | 
 | 694 | { | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 695 | 	int debug_flag = 0, log_level = SYSLOG_LEVEL_INFO; | 
 | 696 | 	int opt, fopt_count = 0; | 
 | 697 | 	char *tname; | 
| Kevin Steves | 76e7d9b | 2001-09-20 20:30:09 +0000 | [diff] [blame] | 698 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 699 | 	extern int optind; | 
 | 700 | 	extern char *optarg; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 701 |  | 
| Damien Miller | 59d3d5b | 2003-08-22 09:34:41 +1000 | [diff] [blame] | 702 | 	__progname = ssh_get_progname(argv[0]); | 
| Ben Lindstrom | 4e088e4 | 2001-10-10 20:45:43 +0000 | [diff] [blame] | 703 | 	init_rng(); | 
 | 704 | 	seed_rng(); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 705 | 	TAILQ_INIT(&tq); | 
 | 706 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 707 | 	if (argc <= 1) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 708 | 		usage(); | 
 | 709 |  | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 710 | 	while ((opt = getopt(argc, argv, "Hv46p:T:t:f:")) != -1) { | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 711 | 		switch (opt) { | 
| Damien Miller | db7b817 | 2005-03-01 21:48:03 +1100 | [diff] [blame^] | 712 | 		case 'H': | 
 | 713 | 			hash_hosts = 1; | 
 | 714 | 			break; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 715 | 		case 'p': | 
 | 716 | 			ssh_port = a2port(optarg); | 
 | 717 | 			if (ssh_port == 0) { | 
 | 718 | 				fprintf(stderr, "Bad port '%s'\n", optarg); | 
 | 719 | 				exit(1); | 
 | 720 | 			} | 
 | 721 | 			break; | 
 | 722 | 		case 'T': | 
| Ben Lindstrom | edd098b | 2002-07-04 00:07:13 +0000 | [diff] [blame] | 723 | 			timeout = convtime(optarg); | 
 | 724 | 			if (timeout == -1 || timeout == 0) { | 
 | 725 | 				fprintf(stderr, "Bad timeout '%s'\n", optarg); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 726 | 				usage(); | 
| Ben Lindstrom | edd098b | 2002-07-04 00:07:13 +0000 | [diff] [blame] | 727 | 			} | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 728 | 			break; | 
 | 729 | 		case 'v': | 
 | 730 | 			if (!debug_flag) { | 
 | 731 | 				debug_flag = 1; | 
 | 732 | 				log_level = SYSLOG_LEVEL_DEBUG1; | 
 | 733 | 			} | 
 | 734 | 			else if (log_level < SYSLOG_LEVEL_DEBUG3) | 
 | 735 | 				log_level++; | 
 | 736 | 			else | 
 | 737 | 				fatal("Too high debugging level."); | 
 | 738 | 			break; | 
| Kevin Steves | 76e7d9b | 2001-09-20 20:30:09 +0000 | [diff] [blame] | 739 | 		case 'f': | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 740 | 			if (strcmp(optarg, "-") == 0) | 
 | 741 | 				optarg = NULL; | 
 | 742 | 			argv[fopt_count++] = optarg; | 
 | 743 | 			break; | 
 | 744 | 		case 't': | 
 | 745 | 			get_keytypes = 0; | 
 | 746 | 			tname = strtok(optarg, ","); | 
 | 747 | 			while (tname) { | 
 | 748 | 				int type = key_type_from_name(tname); | 
 | 749 | 				switch (type) { | 
 | 750 | 				case KEY_RSA1: | 
 | 751 | 					get_keytypes |= KT_RSA1; | 
 | 752 | 					break; | 
 | 753 | 				case KEY_DSA: | 
 | 754 | 					get_keytypes |= KT_DSA; | 
 | 755 | 					break; | 
 | 756 | 				case KEY_RSA: | 
 | 757 | 					get_keytypes |= KT_RSA; | 
 | 758 | 					break; | 
 | 759 | 				case KEY_UNSPEC: | 
| Ben Lindstrom | 28c603b | 2001-12-06 16:45:10 +0000 | [diff] [blame] | 760 | 					fatal("unknown key type %s", tname); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 761 | 				} | 
 | 762 | 				tname = strtok(NULL, ","); | 
 | 763 | 			} | 
 | 764 | 			break; | 
 | 765 | 		case '4': | 
 | 766 | 			IPv4or6 = AF_INET; | 
 | 767 | 			break; | 
 | 768 | 		case '6': | 
 | 769 | 			IPv4or6 = AF_INET6; | 
 | 770 | 			break; | 
 | 771 | 		case '?': | 
 | 772 | 		default: | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 773 | 			usage(); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 774 | 		} | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 775 | 	} | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 776 | 	if (optind == argc && !fopt_count) | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 777 | 		usage(); | 
 | 778 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 779 | 	log_init("ssh-keyscan", log_level, SYSLOG_FACILITY_USER, 1); | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 780 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 781 | 	maxfd = fdlim_get(1); | 
 | 782 | 	if (maxfd < 0) | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 783 | 		fatal("%s: fdlim_get: bad value", __progname); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 784 | 	if (maxfd > MAXMAXFD) | 
 | 785 | 		maxfd = MAXMAXFD; | 
| Ben Lindstrom | d20b855 | 2001-03-05 07:01:18 +0000 | [diff] [blame] | 786 | 	if (MAXCON <= 0) | 
| Kevin Steves | fa72dda | 2000-12-15 18:39:12 +0000 | [diff] [blame] | 787 | 		fatal("%s: not enough file descriptors", __progname); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 788 | 	if (maxfd > fdlim_get(0)) | 
 | 789 | 		fdlim_set(maxfd); | 
 | 790 | 	fdcon = xmalloc(maxfd * sizeof(con)); | 
| Ben Lindstrom | c791beb | 2001-02-10 23:18:11 +0000 | [diff] [blame] | 791 | 	memset(fdcon, 0, maxfd * sizeof(con)); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 792 |  | 
| Ben Lindstrom | c1e0421 | 2001-03-05 07:04:38 +0000 | [diff] [blame] | 793 | 	read_wait_size = howmany(maxfd, NFDBITS) * sizeof(fd_mask); | 
 | 794 | 	read_wait = xmalloc(read_wait_size); | 
 | 795 | 	memset(read_wait, 0, read_wait_size); | 
 | 796 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 797 | 	if (fopt_count) { | 
 | 798 | 		Linebuf *lb; | 
 | 799 | 		char *line; | 
 | 800 | 		int j; | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 801 |  | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 802 | 		for (j = 0; j < fopt_count; j++) { | 
 | 803 | 			lb = Linebuf_alloc(argv[j], error); | 
| Ben Lindstrom | 78bbd9e | 2001-09-12 17:10:40 +0000 | [diff] [blame] | 804 | 			if (!lb) | 
 | 805 | 				continue; | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 806 | 			while ((line = Linebuf_getline(lb)) != NULL) | 
 | 807 | 				do_host(line); | 
 | 808 | 			Linebuf_free(lb); | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 809 | 		} | 
| Ben Lindstrom | 325e70c | 2001-08-06 22:41:30 +0000 | [diff] [blame] | 810 | 	} | 
 | 811 |  | 
 | 812 | 	while (optind < argc) | 
 | 813 | 		do_host(argv[optind++]); | 
 | 814 |  | 
| Ben Lindstrom | b6434ae | 2000-12-05 01:15:09 +0000 | [diff] [blame] | 815 | 	while (ncon > 0) | 
 | 816 | 		conloop(); | 
 | 817 |  | 
 | 818 | 	return (0); | 
 | 819 | } |