174 Commits

Author SHA1 Message Date
matt335672 45f62bdedd CVE-2026-33145: Default AllowAlternateShell to 'no' 2026-03-18 09:26:07 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
matt335672 90a027851a PassShellAsEnv: Update docs 2025-10-28 10:04:03 +00:00
matt335672 6b6edca8ca session management: Allow for restricted shells
Allows the AlternateShell specified by the user in the TS_INFO_PACKET
to be passed to startwm.sh as an environment variable.
2025-10-28 10:04:03 +00:00
matt335672 4d2c4ae8a5 Add FuseRootReportMaxFree option
Add an option to allow effectively disable file system space checks for
some file managers before copying files to remote drives.

This is a temporary solution. A better solution is to provide each
remote drive with its own mountpoint, so that the xrdp FUSE filesystem
becomes POSIX compliant.
2025-10-06 11:45:43 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 cf202d618b Add AlwaysRunReconnect config option
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
2025-07-14 19:39:26 +01:00
matt335672 8bcb14f79d Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
2025-07-14 19:39:26 +01:00
matt335672 8547744dec Address review comments 2025-05-08 14:57:25 +01:00
matt335672 f5aa00be63 Updated manpage 2025-05-08 12:38:01 +01:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 5cf0ec8f34 Add a StartupWaitTime parameter
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
2025-03-29 17:52:47 +00:00
matt335672 86c7fa63b9 Give privilege to users in TerminalServerAdmins
Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
2025-03-14 17:13:41 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 6979df55ee Add new session type SCP_SESSION_TYPE_XVNC_UDS
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.

This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
2025-03-08 11:45:26 +00:00
matt335672 e8a0699bb4 Merge pull request #3393 from matt335672/xauth_in_sysdir
Add XAuthorityInSystemDir option
2025-03-03 13:38:09 +00:00
Matthias von Faber 6a92ee1697 xrdp.8.in: Fix "SEE ALSO" refs to xrdp-sesman, xrdp-sesrun 2025-01-19 12:41:25 +01:00
matt335672 ff70842174 Update manpage after review 2025-01-14 11:38:21 +00:00
matt335672 d2e96fe2d2 Add XAuthorityInSystemDir option
Add an option to allow XAUTHORITY to be moved away from $HOME.

This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
2025-01-13 11:51:27 +00:00
matt335672 b61dfb1096 Fix minor typo in sesman.ini(5) 2025-01-13 11:51:27 +00:00
Constantin Kulikov 151c555fc0 Add sesman.ini FuseMountNameColonCharReplacement option 2025-01-08 16:23:14 +03:00
metalefty bd56127d5b Merge pull request #3370 from metalefty/x264-threads
make x264 threads configurable
2024-12-31 21:23:46 +09:00
Koichiro Iwao 65a02d05a7 x264: minor modifications to docs about x264 multithreading
(cherry picked from commit 85b4c97920e2a4997a778e61b8c42f23fc2af1ee)
2024-12-31 14:02:10 +09:00
metalefty 4e378c9a91 Merge pull request #3368 from metalefty/sysconfsubdir
Allow to change config file (sub)directory
2024-12-29 11:00:16 +09:00
Koichiro Iwao 6c3738f434 x264: update docs for x264 threads
(cherry picked from commit c086a89391fb11f5529b0285649daa5991e1aff5)
2024-12-27 11:16:44 +09:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
Koichiro Iwao c722cb5bb7 docs: fix typos and revise the man page of gfx.toml 2024-12-22 11:52:24 +09:00
Koichiro Iwao 61271b1ee8 docs: update man page for H.264 stuff
- Update man page for xrdp.ini for newly added frame capture interval
- Add man page for new config file gfx.toml
2024-12-20 23:43:15 +09:00
matt335672 162153ab6f Move LogFilePath parameter to [ChansrvLogging]
This seems a better fit than having it in the [Chansrv] section.

Also fixed a minor logging error relating to the parameter in
chansrv_config.c

(cherry picked from commit 6d2fd1be8451418f01dfbb203929e2838c1a979f)
2024-12-16 10:55:30 +00:00
matt335672 2f7be3f634 Allow a path to be specified for the chansrv log
This is useful for NFS-mounted home directories, where hosts
may otherwise produce colliding chansrv log file names

(cherry picked from commit cfc2e362b47103bc2c786252f331bb26b6ddecb5)
2024-12-16 10:55:21 +00:00
matt335672 d17d12d078 Add optional UID to DISPLAY() in chansrvport
The code to determine the socket address of chansrv when using
a manually started xrdp-chansrv may need some help determining
the UID of the session.

This commit allows a UID to be optionally specified in the
DISPLAY() function, if the code is unable to determine the
UID automatically from the connection parameters.

If a manual chansrvport is entered, xrdp now logs what it is
connecting to, to assist in debugging.
2024-10-22 12:21:25 +01:00
Bob Carroll 89a4a1b8f7 update man page and fix code style issue 2024-09-24 18:03:40 -07:00
matt335672 ba1d93930a Allow keycode set to be specified for the X server
This commit allows a keycode_set to be specified as a module parameter
in xrdp.ini. This has the following effects:-
1) xrdp loads the specified keycode set for mapping RDP scancodes to
   X11 keycodes. These are then passed to xorgxrdp as part of key press/
   key release events.
2) The name of the XKB rules which use the specified keycode set are
   passed to xorgxrdp so that XKB can be configured with rules which
   match the chosen keycodes.

The effect is to remove all keycode set dependencies from xorgxrdp.
Normally evdev rules and evdev keycodes will be used but base rules and
base keycodes can be used instead for applications that require them.
Also, any systems which do not ship the evdev rules can be made to
work with base rules.
2024-08-05 10:58:09 +01:00
metalefty 19c111c74c Merge pull request from GHSA-7w22-h4w7-8j5j
Enforce no login screen if require_credentials is set
2024-07-11 09:37:12 +09:00
Koichiro Iwao ab383ed713 docs: always include docs/man/xrdp-mkfv1.8.in to dist tarball
Files included in distribution tarball must always be enumerated,
not be enumerated conditionally.

Resolves:   #3149
(cherry picked from commit e83dcc52eb7703da2ae73f4adcca0cffa0e0370d)
2024-07-08 21:31:53 +09:00
matt335672 48255da29a Add xrdp-chkpriv script to check xrdp privileges 2024-07-01 11:11:21 +01:00
matt335672 17a56567d2 Add params to allow xrdp to be run as non-root
runtime_user and runtime_group are added to the xrdp.ini file
so that the service knows how to reduce privilege
2024-07-01 11:11:21 +01:00
matt335672 8ac2f6db34 Enforce no login screen if require_credentials is set
If the setting require_credentials is true, there should be no way
for the user to get to a login screen.

This commit makes the following changes if this flag is active:-
- Makes the checks around TS_INFO_PACKET more explicit.
- Closes the connection if the first login attempt fails.
2024-06-27 11:53:52 +01:00
matt335672 8ffd75e8d1 Update manpages for new mapping files
A new manpage describing the new file format for the keyboard mapping
files is added.
2024-05-24 16:34:30 +01:00
matt335672 b23d6f89d5 Improve performance on long fat networks (LFNs)
On Linux, the TCP send buffer size is increased to 32768 if it is less
that this (which it normally is). This however has the effect of disabling
dynamic buffer sizing, leading to a maximum available bandwidth of

max_bandwidth = 262144 (bits) / round_trip_time (secs)

This is not noticeable on a LAN with an RTT of around 0.5ms, but
very noticeable on a WAN with an RTT of 0.25s.

Comments in the config file and manpage in this area are improved, as
is the logging if the parameters are actually set.
2024-01-11 11:53:54 +00:00
matt335672 c51ec2e8e9 Remove sesmanruntimedir
Now we've made the XRDP_SOCKET_PATH only writeable by root, it's
safe to move the sesman socket back into this directory. We no longer
need a separate sesmanruntimedir
2023-10-23 18:14:46 +01:00
matt335672 675dd77807 Parameterise the sockdir with the UID of the user
The top level socket directory is now called XRDP_SOCKET_ROOT_PATH.
Below that are user-specific directories referred to with the
XRDP_SOCKET_PATH macro - this name is hard-coded into xorgxrdp and
the audio modules as an environment variable.

XRDP_SOCKET_PATH now looks like $XRDP_SOCKET_ROOT_PATH/<uid>

XRDP_SOCKET_PATH is only writeable by the user, and readable by the user
and the xrdp process.
2023-10-23 18:14:46 +01:00
Daniel Richard G fdfe47668b Add XorgNoNewPrivileges configuration option
This allows Linux's no_new_privs restriction to be disabled when starting
the X server, which may be desirable if xrdp is running inside a kernel
confinement framework such as AppArmor or SELinux.
2023-05-15 17:40:46 -04:00
matt335672 06580ec448 sesman config: Add MaxDisplayNumber
When allocating a display number, we should be aware that
IANA only allow TCP displays up to :63. This PR adds that restriction in
to sesman.ini as a default, to prevent us allocating unavailable TCP
ports.

By default TCP ports are not enabled for X servers, but users can easily
change this if they wish to access X displays directly over the network.

This restriction is in addition to the MaxSessions limit already present
in sesman.ini
2023-05-02 11:55:22 +01:00
Lennart Sauerbeck 5741653900 sesman: Prevent the use of 'alternate shell'
By setting the new config value 'AllowAlternateShell' to 'no' it is now
possible to prevent the use of an alternate shell, which can be set by
the connecting user.
The default remains unchanged and any shell is allowed if the config
value is not specified. It can also be set explicitly to 'yes' to achieve
the same outcome.

Fixes: #850
2023-04-19 10:16:56 +01:00
Hiero32 9fe9ae3bc0 Support to set parameters from sesman.ini. 2023-03-28 21:20:54 +09:00
Michael Saxl 367a045f00 [chansrv-fuse] update documentation 2023-01-31 20:13:34 +01:00
akarl10 5bcac32bf1 [chansrv-fuse] update documentation 2023-01-31 19:41:17 +01:00
matt335672 af69606e0b Remove support for x11rdp
X11rdp has been deprecated now since xrdp v0.9.7 (June 2018). This
commit removes support for it from xrdp itself.
2023-01-05 11:26:44 +00:00