Viel neues

This commit is contained in:
Sven Steinert
2026-04-30 12:06:00 +02:00
parent 118809bfae
commit fce31ebcd7
1274 changed files with 181255 additions and 0 deletions

View File

@@ -0,0 +1,44 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
/**
* http://tools.ietf.org/html/draft-ietf-secsh-filexfer-13#section-7.1
* the order, in this case, matters quite a lot - see \phpseclib3\Net\SFTP::_parseAttributes() to understand why
*
* @internal
*/
abstract class Attribute
{
public const SIZE = 0x00000001;
public const UIDGID = 0x00000002; // defined in SFTPv3, removed in SFTPv4+
public const OWNERGROUP = 0x00000080; // defined in SFTPv4+
public const PERMISSIONS = 0x00000004;
public const ACCESSTIME = 0x00000008;
public const CREATETIME = 0x00000010; // SFTPv4+
public const MODIFYTIME = 0x00000020;
public const ACL = 0x00000040;
public const SUBSECOND_TIMES = 0x00000100;
public const BITS = 0x00000200; // SFTPv5+
public const ALLOCATION_SIZE = 0x00000400; // SFTPv6+
public const TEXT_HINT = 0x00000800;
public const MIME_TYPE = 0x00001000;
public const LINK_COUNT = 0x00002000;
public const UNTRANSLATED_NAME = 0x00004000;
public const CTIME = 0x00008000;
// 0x80000000 will yield a floating point on 32-bit systems and converting floating points to integers
// yields inconsistent behavior depending on how php is compiled. so we left shift -1 (which, in
// two's compliment, consists of all 1 bits) by 31. on 64-bit systems this'll yield 0xFFFFFFFF80000000.
// that's not a problem, however, and 'anded' and a 32-bit number, as all the leading 1 bits are ignored.
public const EXTENDED = PHP_INT_SIZE == 4 ? (-1 << 31) : 0x80000000;
/**
*/
public static function getConstants(): array
{
$reflectionClass = new \ReflectionClass(static::class);
return $reflectionClass->getConstants();
}
}

View File

@@ -0,0 +1,26 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
/**
* http://tools.ietf.org/html/draft-ietf-secsh-filexfer-04#section-5.2
* see \phpseclib3\Net\SFTP::_parseLongname() for an explanation
*
* @internal
*/
abstract class FileType
{
public const REGULAR = 1;
public const DIRECTORY = 2;
public const SYMLINK = 3;
public const SPECIAL = 4;
public const UNKNOWN = 5;
// the following types were first defined for use in SFTPv5+
// http://tools.ietf.org/html/draft-ietf-secsh-filexfer-05#section-5.2
public const SOCKET = 6;
public const CHAR_DEVICE = 7;
public const BLOCK_DEVICE = 8;
public const FIFO = 9;
}

View File

@@ -0,0 +1,23 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
/**
* http://tools.ietf.org/html/draft-ietf-secsh-filexfer-04#section-6.3
* the flag definitions change somewhat in SFTPv5+. if SFTPv5+ support is added to this library, maybe name
* the array for that $this->open5_flags and similarly alter the constant names.
*
* @internal
*/
abstract class OpenFlag
{
public const READ = 0x00000001;
public const WRITE = 0x00000002;
public const APPEND = 0x00000004;
public const CREATE = 0x00000008;
public const TRUNCATE = 0x00000010;
public const EXCL = 0x00000020;
public const TEXT = 0x00000040; // defined in SFTPv4
}

View File

@@ -0,0 +1,34 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
/**
* SFTPv5+ changed the flags up: https://datatracker.ietf.org/doc/html/draft-ietf-secsh-filexfer-13#section-8.1.1.3
*
* @internal
*/
abstract class OpenFlag5
{
// when SSH_FXF_ACCESS_DISPOSITION is a 3 bit field that controls how the file is opened
public const CREATE_NEW = 0x00000000;
public const CREATE_TRUNCATE = 0x00000001;
public const OPEN_EXISTING = 0x00000002;
public const OPEN_OR_CREATE = 0x00000003;
public const TRUNCATE_EXISTING = 0x00000004;
// the rest of the flags are not supported
public const APPEND_DATA = 0x00000008; // "the offset field of SS_FXP_WRITE requests is ignored"
public const APPEND_DATA_ATOMIC = 0x00000010;
public const TEXT_MODE = 0x00000020;
public const BLOCK_READ = 0x00000040;
public const BLOCK_WRITE = 0x00000080;
public const BLOCK_DELETE = 0x00000100;
public const BLOCK_ADVISORY = 0x00000200;
public const NOFOLLOW = 0x00000400;
public const DELETE_ON_CLOSE = 0x00000800;
public const ACCESS_AUDIT_ALARM_INFO = 0x00001000;
public const ACCESS_BACKUP = 0x00002000;
public const BACKUP_STREAM = 0x00004000;
public const OVERRIDE_OWNER = 0x00008000;
}

View File

@@ -0,0 +1,45 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
use phpseclib3\Common\ConstantUtilityTrait;
/**
* @internal
*/
abstract class PacketType
{
use ConstantUtilityTrait;
public const INIT = 1;
public const VERSION = 2;
public const OPEN = 3;
public const CLOSE = 4;
public const READ = 5;
public const WRITE = 6;
public const LSTAT = 7;
public const SETSTAT = 9;
public const FSETSTAT = 10;
public const OPENDIR = 11;
public const READDIR = 12;
public const REMOVE = 13;
public const MKDIR = 14;
public const RMDIR = 15;
public const REALPATH = 16;
public const STAT = 17;
public const RENAME = 18;
public const READLINK = 19;
public const SYMLINK = 20;
public const LINK = 21;
public const STATUS = 101;
public const HANDLE = 102;
public const DATA = 103;
public const NAME = 104;
public const ATTRS = 105;
public const EXTENDED = 200;
public const EXTENDED_REPLY = 201;
}

View File

@@ -0,0 +1,48 @@
<?php
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
use phpseclib3\Common\ConstantUtilityTrait;
/**
* @internal
*/
abstract class StatusCode
{
use ConstantUtilityTrait;
public const OK = 0;
public const EOF = 1;
public const NO_SUCH_FILE = 2;
public const PERMISSION_DENIED = 3;
public const FAILURE = 4;
public const BAD_MESSAGE = 5;
public const NO_CONNECTION = 6;
public const CONNECTION_LOST = 7;
public const OP_UNSUPPORTED = 8;
public const INVALID_HANDLE = 9;
public const NO_SUCH_PATH = 10;
public const FILE_ALREADY_EXISTS = 11;
public const WRITE_PROTECT = 12;
public const NO_MEDIA = 13;
public const NO_SPACE_ON_FILESYSTEM = 14;
public const QUOTA_EXCEEDED = 15;
public const UNKNOWN_PRINCIPAL = 16;
public const LOCK_CONFLICT = 17;
public const DIR_NOT_EMPTY = 18;
public const NOT_A_DIRECTORY = 19;
public const INVALID_FILENAME = 20;
public const LINK_LOOP = 21;
public const CANNOT_DELETE = 22;
public const INVALID_PARAMETER = 23;
public const FILE_IS_A_DIRECTORY = 24;
public const BYTE_RANGE_LOCK_CONFLICT = 25;
public const BYTE_RANGE_LOCK_REFUSED = 26;
public const DELETE_PENDING = 27;
public const FILE_CORRUPT = 28;
public const OWNER_INVALID = 29;
public const GROUP_INVALID = 30;
public const NO_MATCHING_BYTE_RANGE_LOCK = 31;
}

View File

@@ -0,0 +1,667 @@
<?php
/**
* SFTP Stream Wrapper
*
* Creates an sftp:// protocol handler that can be used with, for example, fopen(), dir(), etc.
*
* PHP version 5
*
* @author Jim Wigginton <terrafrost@php.net>
* @copyright 2013 Jim Wigginton
* @license http://www.opensource.org/licenses/mit-license.html MIT License
* @link http://phpseclib.sourceforge.net
*/
declare(strict_types=1);
namespace phpseclib3\Net\SFTP;
use phpseclib3\Crypt\Common\PrivateKey;
use phpseclib3\Net\SFTP;
use phpseclib3\Net\SSH2;
use phpseclib3\Net\SSH2\MessageType as SSH2MessageType;
/**
* SFTP Stream Wrapper
*
* @author Jim Wigginton <terrafrost@php.net>
*/
class Stream
{
/**
* SFTP instances
*
* Rather than re-create the connection we re-use instances if possible
*/
public static array $instances;
/**
* SFTP instance
*/
private SFTP $sftp;
/**
* Path
*/
private string $path;
/**
* Mode
*/
private string $mode;
/**
* Position
*/
private int $pos;
/**
* Size
*/
private int|false $size;
/**
* Directory entries
*/
private array $entries;
/**
* EOF flag
*/
private bool $eof;
/**
* Context resource
*
* Technically this needs to be publicly accessible so PHP can set it directly
*
* @var resource
*/
public $context;
/**
* Notification callback function
*
* @var callable
*/
private $notification;
/**
* Registers this class as a URL wrapper.
*
* @param string $protocol The wrapper name to be registered.
* @return bool True on success, false otherwise.
*/
public static function register(string $protocol = 'sftp'): bool
{
if (in_array($protocol, stream_get_wrappers(), true)) {
return false;
}
return stream_wrapper_register($protocol, get_called_class());
}
/**
* The Constructor
*/
public function __construct()
{
if (defined('NET_SFTP_STREAM_LOGGING')) {
echo "__construct()\r\n";
}
}
/**
* Path Parser
*
* Extract a path from a URI and actually connect to an SSH server if appropriate
*
* If "notification" is set as a context parameter the message code for successful login is
* SSHMsg::USERAUTH_SUCCESS. For a failed login it's SSHMsg::USERAUTH_FAILURE.
*
* @return string
*/
protected function parse_path(string $path)
{
$orig = $path;
extract(parse_url($path) + ['port' => 22]);
if (isset($query)) {
$path .= '?' . $query;
} elseif (preg_match('/(\?|\?#)$/', $orig)) {
$path .= '?';
}
if (isset($fragment)) {
$path .= '#' . $fragment;
} elseif ($orig[-1] == '#') {
$path .= '#';
}
if (!isset($host)) {
return false;
}
if (isset($this->context)) {
$context = stream_context_get_params($this->context);
if (isset($context['notification'])) {
$this->notification = $context['notification'];
}
}
if (preg_match('/^{[a-z0-9]+}$/i', $host)) {
$host = SSH2::getConnectionByResourceId($host);
if ($host === null) {
return false;
}
$this->sftp = $host;
} else {
if (isset($this->context)) {
$context = stream_context_get_options($this->context);
}
if (isset($context[$scheme]['session'])) {
$sftp = $context[$scheme]['session'];
}
if (isset($context[$scheme]['sftp'])) {
$sftp = $context[$scheme]['sftp'];
}
if (isset($sftp) && $sftp instanceof SFTP) {
$this->sftp = $sftp;
return $path;
}
if (isset($context[$scheme]['username'])) {
$user = $context[$scheme]['username'];
}
if (isset($context[$scheme]['password'])) {
$pass = $context[$scheme]['password'];
}
if (isset($context[$scheme]['privkey']) && $context[$scheme]['privkey'] instanceof PrivateKey) {
$pass = $context[$scheme]['privkey'];
}
if (!isset($user) || !isset($pass)) {
return false;
}
// casting $pass to a string is necessary in the event that it's a \phpseclib3\Crypt\RSA object
if (isset(self::$instances[$host][$port][$user][(string) $pass])) {
$this->sftp = self::$instances[$host][$port][$user][(string) $pass];
} else {
$this->sftp = new SFTP($host, $port);
$this->sftp->disableStatCache();
if (isset($this->notification) && is_callable($this->notification)) {
/* if !is_callable($this->notification) we could do this:
user_error('fopen(): failed to call user notifier', E_USER_WARNING);
the ftp wrapper gives errors like that when the notifier isn't callable.
i've opted not to do that, however, since the ftp wrapper gives the line
on which the fopen occurred as the line number - not the line that the
user_error is on.
*/
call_user_func($this->notification, STREAM_NOTIFY_CONNECT, STREAM_NOTIFY_SEVERITY_INFO, '', 0, 0, 0);
call_user_func($this->notification, STREAM_NOTIFY_AUTH_REQUIRED, STREAM_NOTIFY_SEVERITY_INFO, '', 0, 0, 0);
if (!$this->sftp->login($user, $pass)) {
call_user_func($this->notification, STREAM_NOTIFY_AUTH_RESULT, STREAM_NOTIFY_SEVERITY_ERR, 'Login Failure', SSH2MessageType::USERAUTH_FAILURE, 0, 0);
return false;
}
call_user_func($this->notification, STREAM_NOTIFY_AUTH_RESULT, STREAM_NOTIFY_SEVERITY_INFO, 'Login Success', SSH2MessageType::USERAUTH_SUCCESS, 0, 0);
} else {
if (!$this->sftp->login($user, $pass)) {
return false;
}
}
self::$instances[$host][$port][$user][(string) $pass] = $this->sftp;
}
}
return $path;
}
/**
* Opens file or URL
*/
private function _stream_open(string $path, string $mode): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
$this->path = $path;
$this->size = $this->sftp->filesize($path);
$this->mode = preg_replace('#[bt]$#', '', $mode);
$this->eof = false;
if ($this->size === false) {
if ($this->mode[0] == 'r') {
return false;
} else {
$this->sftp->touch($path);
$this->size = 0;
}
} else {
switch ($this->mode[0]) {
case 'x':
return false;
case 'w':
$this->sftp->truncate($path, 0);
$this->size = 0;
}
}
$this->pos = $this->mode[0] != 'a' ? 0 : $this->size;
return true;
}
/**
* Read from stream
*/
private function _stream_read(int $count)
{
switch ($this->mode) {
case 'w':
case 'a':
case 'x':
case 'c':
return false;
}
// commented out because some files - eg. /dev/urandom - will say their size is 0 when in fact it's kinda infinite
//if ($this->pos >= $this->size) {
// $this->eof = true;
// return false;
//}
$result = $this->sftp->get($this->path, false, $this->pos, $count);
if (isset($this->notification) && is_callable($this->notification)) {
if ($result === false) {
call_user_func($this->notification, STREAM_NOTIFY_FAILURE, STREAM_NOTIFY_SEVERITY_ERR, $this->sftp->getLastSFTPError(), PacketType::OPEN, 0, 0);
return 0;
}
// seems that PHP calls stream_read in 8k chunks
call_user_func($this->notification, STREAM_NOTIFY_PROGRESS, STREAM_NOTIFY_SEVERITY_INFO, '', 0, strlen($result), $this->size);
}
if (empty($result)) { // ie. false or empty string
$this->eof = true;
return false;
}
$this->pos += strlen($result);
return $result;
}
/**
* Write to stream
*
* @return int|false
*/
private function _stream_write(string $data)
{
switch ($this->mode) {
case 'r':
return false;
}
$result = $this->sftp->put($this->path, $data, SFTP::SOURCE_STRING, $this->pos);
if (isset($this->notification) && is_callable($this->notification)) {
if (!$result) {
call_user_func($this->notification, STREAM_NOTIFY_FAILURE, STREAM_NOTIFY_SEVERITY_ERR, $this->sftp->getLastSFTPError(), PacketType::OPEN, 0, 0);
return 0;
}
// seems that PHP splits up strings into 8k blocks before calling stream_write
call_user_func($this->notification, STREAM_NOTIFY_PROGRESS, STREAM_NOTIFY_SEVERITY_INFO, '', 0, strlen($data), strlen($data));
}
if ($result === false) {
return false;
}
$this->pos += strlen($data);
if ($this->pos > $this->size) {
$this->size = $this->pos;
}
$this->eof = false;
return strlen($data);
}
/**
* Retrieve the current position of a stream
*/
private function _stream_tell(): int
{
return $this->pos;
}
/**
* Tests for end-of-file on a file pointer
*
* In my testing there are four classes functions that normally effect the pointer:
* fseek, fputs / fwrite, fgets / fread and ftruncate.
*
* Only fgets / fread, however, results in feof() returning true. do fputs($fp, 'aaa') on a blank file and feof()
* will return false. do fread($fp, 1) and feof() will then return true. do fseek($fp, 10) on ablank file and feof()
* will return false. do fread($fp, 1) and feof() will then return true.
*/
private function _stream_eof(): bool
{
return $this->eof;
}
/**
* Seeks to specific location in a stream
*/
private function _stream_seek(int $offset, int $whence): bool
{
switch ($whence) {
case SEEK_SET:
if ($offset < 0) {
return false;
}
break;
case SEEK_CUR:
$offset += $this->pos;
break;
case SEEK_END:
$offset += $this->size;
}
$this->pos = $offset;
$this->eof = false;
return true;
}
/**
* Change stream options
*/
private function _stream_metadata(string $path, int $option, $var): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
// stream_metadata was introduced in PHP 5.4.0 but as of 5.4.11 the constants haven't been defined
// see http://www.php.net/streamwrapper.stream-metadata and https://bugs.php.net/64246
// and https://github.com/php/php-src/blob/master/main/php_streams.h#L592
switch ($option) {
case 1: // PHP_STREAM_META_TOUCH
$time = $var[0] ?? null;
$atime = $var[1] ?? null;
return $this->sftp->touch($path, $time, $atime);
case 2: // PHP_STREAM_OWNER_NAME
case 3: // PHP_STREAM_GROUP_NAME
return false;
case 4: // PHP_STREAM_META_OWNER
return $this->sftp->chown($path, $var);
case 5: // PHP_STREAM_META_GROUP
return $this->sftp->chgrp($path, $var);
case 6: // PHP_STREAM_META_ACCESS
return $this->sftp->chmod($path, $var) !== false;
}
}
/**
* Retrieve the underlaying resource
*
* @return resource
*/
private function _stream_cast(int $cast_as)
{
return $this->sftp->fsock;
}
/**
* Advisory file locking
*/
private function _stream_lock(int $operation): bool
{
return false;
}
/**
* Renames a file or directory
*
* Attempts to rename oldname to newname, moving it between directories if necessary.
* If newname exists, it will be overwritten. This is a departure from what \phpseclib3\Net\SFTP
* does.
*/
private function _rename(string $path_from, string $path_to): bool
{
$path1 = parse_url($path_from);
$path2 = parse_url($path_to);
unset($path1['path'], $path2['path']);
if ($path1 != $path2) {
return false;
}
$path_from = $this->parse_path($path_from);
$path_to = parse_url($path_to);
if ($path_from === false) {
return false;
}
$path_to = $path_to['path']; // the $component part of parse_url() was added in PHP 5.1.2
// "It is an error if there already exists a file with the name specified by newpath."
// -- http://tools.ietf.org/html/draft-ietf-secsh-filexfer-02#section-6.5
if (!$this->sftp->rename($path_from, $path_to)) {
if ($this->sftp->stat($path_to)) {
return $this->sftp->delete($path_to, true) && $this->sftp->rename($path_from, $path_to);
}
return false;
}
return true;
}
/**
* Open directory handle
*
* The only $options is "whether or not to enforce safe_mode (0x04)". Since safe mode was deprecated in 5.3 and
* removed in 5.4 I'm just going to ignore it.
*
* Also, nlist() is the best that this function is realistically going to be able to do. When an SFTP client
* sends a SSH_FXP_READDIR packet you don't generally get info on just one file but on multiple files. Quoting
* the SFTP specs:
*
* The SSH_FXP_NAME response has the following format:
*
* uint32 id
* uint32 count
* repeats count times:
* string filename
* string longname
* ATTRS attrs
*/
private function _dir_opendir(string $path, int $options): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
$this->pos = 0;
$this->entries = $this->sftp->nlist($path);
return $this->entries !== false;
}
/**
* Read entry from directory handle
*/
private function _dir_readdir()
{
if (isset($this->entries[$this->pos])) {
return $this->entries[$this->pos++];
}
return false;
}
/**
* Rewind directory handle
*/
private function _dir_rewinddir(): bool
{
$this->pos = 0;
return true;
}
/**
* Close directory handle
*/
private function _dir_closedir(): bool
{
return true;
}
/**
* Create a directory
*
* Only valid $options is STREAM_MKDIR_RECURSIVE
*/
private function _mkdir(string $path, int $mode, int $options): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
return $this->sftp->mkdir($path, $mode, $options & STREAM_MKDIR_RECURSIVE);
}
/**
* Removes a directory
*
* Only valid $options is STREAM_MKDIR_RECURSIVE per <http://php.net/streamwrapper.rmdir>, however,
* <http://php.net/rmdir> does not have a $recursive parameter as mkdir() does so I don't know how
* STREAM_MKDIR_RECURSIVE is supposed to be set. Also, when I try it out with rmdir() I get 8 as
* $options. What does 8 correspond to?
*/
private function _rmdir(string $path, int $options): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
return $this->sftp->rmdir($path);
}
/**
* Flushes the output
*
* See <http://php.net/fflush>. Always returns true because \phpseclib3\Net\SFTP doesn't cache stuff before writing
*/
private function _stream_flush(): bool
{
return true;
}
/**
* Retrieve information about a file resource
*/
private function _stream_stat(): bool
{
$results = $this->sftp->stat($this->path);
if ($results === false) {
return false;
}
return $results;
}
/**
* Delete a file
*/
private function _unlink(string $path): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
return $this->sftp->delete($path, false);
}
/**
* Retrieve information about a file
*
* Ignores the STREAM_URL_STAT_QUIET flag because the entirety of \phpseclib3\Net\SFTP\Stream is quiet by default
* might be worthwhile to reconstruct bits 12-16 (ie. the file type) if mode doesn't have them but we'll
* cross that bridge when and if it's reached
*/
private function _url_stat(string $path, int $flags): bool
{
$path = $this->parse_path($path);
if ($path === false) {
return false;
}
$results = $flags & STREAM_URL_STAT_LINK ? $this->sftp->lstat($path) : $this->sftp->stat($path);
if ($results === false) {
return false;
}
return $results;
}
/**
* Truncate stream
*/
private function _stream_truncate(int $new_size): bool
{
if (!$this->sftp->truncate($this->path, $new_size)) {
return false;
}
$this->eof = false;
$this->size = $new_size;
return true;
}
/**
* Change stream options
*
* STREAM_OPTION_WRITE_BUFFER isn't supported for the same reason stream_flush isn't.
* The other two aren't supported because of limitations in \phpseclib3\Net\SFTP.
*/
private function _stream_set_option(int $option, int $arg1, int $arg2): bool
{
return false;
}
/**
* Close an resource
*/
private function _stream_close(): void
{
}
/**
* __call Magic Method
*
* When you're utilizing an SFTP stream you're not calling the methods in this class directly - PHP is calling them for you.
* Which kinda begs the question... what methods is PHP calling and what parameters is it passing to them? This function
* lets you figure that out.
*
* If NET_SFTP_STREAM_LOGGING is defined all calls will be output on the screen and then (regardless of whether or not
* NET_SFTP_STREAM_LOGGING is enabled) the parameters will be passed through to the appropriate method.
*/
public function __call(string $name, array $arguments)
{
if (defined('NET_SFTP_STREAM_LOGGING')) {
echo $name . '(';
$last = count($arguments) - 1;
foreach ($arguments as $i => $argument) {
var_export($argument);
if ($i != $last) {
echo ',';
}
}
echo ")\r\n";
}
$name = '_' . $name;
if (!method_exists($this, $name)) {
return false;
}
return $this->$name(...$arguments);
}
}