Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,7 @@ jobs:
example:
- ssh-forwardagent
- ssh-localforward
- ssh-proxy-protocol
- ssh-pty
- ssh-publickey
- ssh-remoteforward
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-forwardagent/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-forwardagent/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-localforward/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-localforward/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
15 changes: 15 additions & 0 deletions _examples/ssh-proxy-protocol/go.mod
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
module github.com/engity-com/ssh-server-go/_examples/ssh-proxy-protocol

go 1.27.0

replace github.com/engity-com/ssh-server-go => ../..

require github.com/engity-com/ssh-server-go v0.0.0

require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
16 changes: 16 additions & 0 deletions _examples/ssh-proxy-protocol/go.sum
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFIImctFaOjnTIavg87rW78vTPkQqLI8=
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
24 changes: 24 additions & 0 deletions _examples/ssh-proxy-protocol/proxy_protocol.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
package main

import (
"fmt"
"log"

"github.com/engity-com/ssh-server-go"
)

const listenAddress = "127.0.0.1:2222"

func main() {
server := &ssh.Server{
Addr: listenAddress,
Handler: func(session ssh.Session) {
_, _ = fmt.Fprintf(session, "Your address is %s\n", session.RemoteAddr())
},
ProxyProtocol: &ssh.ProxyProtocolConfig{},
}

log.Println("DEVELOPMENT ONLY: anonymous authentication, an ephemeral host key and trusts the PROXY protocol from everywhere.")
log.Printf("starting PROXY-aware SSH server on %s", listenAddress)
log.Fatal(server.ListenAndServe())
}
1 change: 1 addition & 0 deletions _examples/ssh-pty/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ require (
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-pty/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ github.com/creack/pty v1.1.24 h1:bJrF4RRfyJnbTJqzRLHzcGaZK1NeM5kTC9jGgovnR1s=
github.com/creack/pty v1.1.24/go.mod h1:08sCNb52WyoAwi2QDyzUCTgcvVFhUzewun7wtTfvcwE=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-publickey/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -12,5 +12,6 @@ require (
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-publickey/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-remoteforward/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-remoteforward/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-sftpserver/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-sftpserver/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-simple/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-simple/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-streamlocal/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-streamlocal/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions _examples/ssh-timeouts/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require github.com/engity-com/ssh-server-go v0.0.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
github.com/echocat/slf4g v1.8.4 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
2 changes: 2 additions & 0 deletions _examples/ssh-timeouts/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
1 change: 1 addition & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ go 1.27.0
require (
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be
github.com/echocat/slf4g v1.8.4
github.com/pires/go-proxyproto v0.15.0
github.com/stretchr/testify v1.12.1
golang.org/x/crypto v0.55.0
golang.org/x/sys v0.47.0
Expand Down
2 changes: 2 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be h1:9AeTilPcZAjCFI
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
github.com/echocat/slf4g v1.8.4 h1:wWHO1xJRtzzWrgKUnmTA8CEv/SL+pJTzkyPbnKh1apA=
github.com/echocat/slf4g v1.8.4/go.mod h1:YvF/d1TcPvT+/xiHStLHPI4xPT1GGeEmPczn2MSljNA=
github.com/pires/go-proxyproto v0.15.0 h1:dTshmNbFm/D+0+sbrxUuddPOZ5Y0B7c5NhtsBkm6LqI=
github.com/pires/go-proxyproto v0.15.0/go.mod h1:OXsCrKwrK2tXS9YrI5tkHx5xaQlO8FH3lFW76orFh24=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
Expand Down
19 changes: 19 additions & 0 deletions options.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
package ssh

import (
"errors"
"os"

gossh "golang.org/x/crypto/ssh"
Expand Down Expand Up @@ -82,3 +83,21 @@ func WrapConn(fn ConnCallback) Option {
return nil
}
}

// EnableProxyProtocol returns a functional option that enables PROXY protocol
// processing. With no configuration, every connection must supply a PROXY
// header and the header is trusted from any peer. At most one configuration
// may be supplied.
func EnableProxyProtocol(config ...ProxyProtocolConfig) Option {
return func(srv *Server) error {
if len(config) > 1 {
return errors.New("ssh: enable proxy protocol accepts at most one configuration")
}
configured := ProxyProtocolConfig{}
if len(config) == 1 {
configured = config[0]
}
srv.ProxyProtocol = &configured
return nil
}
}
72 changes: 72 additions & 0 deletions proxyproto.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
package ssh

import (
"errors"
"net"
"time"

"github.com/pires/go-proxyproto"
)

var errProxyProtocolAlreadyWrapped = errors.New("ssh: connection is already wrapped for PROXY protocol")

// ProxyProtocolConfig configures PROXY protocol processing for accepted
// connections. A nil ConnPolicy requires a PROXY header but trusts the source
// information supplied by every peer. Listeners reachable by untrusted peers
// should configure a policy such as [proxyproto.TrustProxyHeaderFrom] or
// [proxyproto.TrustProxyHeaderFromRanges]. Connections are wrapped before
// ConnCallback, while the header is processed lazily on first I/O or address
// access. A callback can type-assert the connection to *proxyproto.Conn and use
// Raw to inspect the transport peer instead of the address supplied by the
// header. It must retain or wrap the supplied connection for PROXY processing
// to remain effective.
type ProxyProtocolConfig struct {
// ConnPolicy decides whether a connection may supply a PROXY header and how
// that header is handled. It must return promptly.
ConnPolicy proxyproto.ConnPolicyFunc
// ValidateHeader performs application-specific validation after parsing. It
// must return promptly.
ValidateHeader proxyproto.Validator
// ReadHeaderTimeout bounds PROXY header processing. Zero uses the
// go-proxyproto default; a negative value disables its header timeout.
ReadHeaderTimeout time.Duration
// ReadBufferSize controls the per-connection header buffer. A nonpositive
// value uses the go-proxyproto default. Values below 107 bytes break maximum
// length version 1 headers.
ReadBufferSize int
}

func wrapProxyProtocolConn(conn net.Conn, config ProxyProtocolConfig) (net.Conn, error) {
if _, ok := conn.(*proxyproto.Conn); ok {
return nil, errProxyProtocolAlreadyWrapped
}

policy := proxyproto.REQUIRE
if config.ConnPolicy != nil {
var err error
policy, err = config.ConnPolicy(proxyproto.ConnPolicyOptions{
Upstream: conn.RemoteAddr(),
Downstream: conn.LocalAddr(),
})
if err != nil {
return nil, err
}
if policy == proxyproto.SKIP {
return conn, nil
}
}

options := []func(*proxyproto.Conn){proxyproto.WithPolicy(policy)}
if config.ValidateHeader != nil {
options = append(options, proxyproto.ValidateHeader(config.ValidateHeader))
}
if config.ReadHeaderTimeout < 0 {
options = append(options, proxyproto.SetReadHeaderTimeout(0))
} else if config.ReadHeaderTimeout > 0 {
options = append(options, proxyproto.SetReadHeaderTimeout(config.ReadHeaderTimeout))
}
if config.ReadBufferSize > 0 {
options = append(options, proxyproto.WithBufferSize(config.ReadBufferSize))
}
return proxyproto.NewConn(conn, options...), nil
}
Loading