Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
The ulalaca module for Mac is suffering from a lack of maintenance
currently, and its inclusion is holding up the introduction of some
code quality changes. This PR removes the module for now.
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
- #define for MAX_PORT_STR length
- create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
- add chars host and service which are primarily used for debug logging of attempted connection points
- calls get_socket_family to discover family of socket
- add switch case logic for AF_INET6/4:
- v4: just calls addr_is_ipv6 so we don't fail on a hostname input
- v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
- if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
- getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
- before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely: this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
The Kerberos module and pam_userpass modules are now unused:
1) On all supported systems, PAM provides a far superior way to
integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
(which is a lovely idea) is no longer maintained.