Early release (0.1.x). The protocol core is thoroughly tested, but the algorithm set is deliberately small and some conveniences are missing — see Algorithms & Limitations. Feedback is welcome.
SSHClient is a pure-APL SSH-2 client for Dyalog. It implements the SSH-2
protocol (RFC 4251–4254) directly on top of a raw TCP socket: Conga
provides the transport, and the cryptography (SHA-256, HMAC-SHA-256,
AES-128-CTR, RSA, Diffie–Hellman) is driven through ⎕NA bindings to the
nettle/GMP library that ships inside Conga's SSL plugin. Nothing beyond a
standard Dyalog installation is required — no external ssh binaries, no
extra libraries.
⎕FIX 'file://SSHClient.aplc'
c←⎕NEW SSHClient ('server.example.com' 22 'alice' 'secret')
c.Connect
[rc: 0 | msg: | host: server.example.com:22 | ≢Data: 0]
(c.Exec 'uname -sr').Data
Linux 6.6.87
c.GetFile '/var/log/app.log' '/tmp/app.log'
[rc: 0 | msg: | host: :22 | ≢Data: 12]
c.CloseOr as a one-liner:
(SSHClient.Do 'server.example.com' 'alice' 'secret' 'uptime').Data
15:04:32 up 41 days, 3:12, 1 user, load average: 0.08, 0.06, 0.01- Full SSH-2 handshake — banner exchange, algorithm negotiation, Diffie–Hellman group14 key exchange, AES-128-CTR + HMAC-SHA-256 transport
- Server verification — host-key signature checking and known_hosts
trust with OpenSSH
accept-newsemantics by default: a man-in-the-middle presenting its own key is refused before any credentials are sent - Authentication — password, or RSA public key (OpenSSH key files)
- Exec — run remote commands and capture stdout, stderr, and the exit status (UTF-8 aware, binary-safe)
- SFTP — upload, download, list, stat; byte-exact transfers, UTF-8 paths
- Cross-platform: Linux, macOS, Windows
Dyalog APL 18.2+ (Unicode edition) with Conga — i.e. any standard Dyalog installation. Tested with Dyalog 19.0–21.0 against OpenSSH.
Full documentation lives in docs/ and is published to
GitHub Pages by the Docs workflow
(a Zensical site — zensical serve to preview
locally). Start with:
- Getting Started
- Host Key Verification — read this before using the client on an untrusted network
- Security Model — what is protected, the evidence, and the current limitations
- API Reference
A self-contained 52-test suite (crypto primitives against NIST/RFC vectors, RSA cross-validated against OpenSSL, and live integration against real OpenSSH servers — including a man-in-the-middle refusal test) runs in GitHub Actions on every push. To run it locally:
cd Tests
dyalogscript RunTests.apls unit # no network needed
eval "$(bash setup_sshd.sh | grep '^export')" # throwaway local sshd
dyalogscript RunTests.apls # full suiteSee Tests/README.md and
Testing & CI.
SSHClient.aplc the client - a single self-contained class
Tests/ test suite + throwaway sshd setup (see Tests/README.md)
docs/ documentation (Zensical/MkDocs form)
zensical.toml documentation site config
.github/workflows tests (Dyalog container) and docs build + Pages deploy