Commit Graph

1278 Commits

Author SHA1 Message Date
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 fe32e2e2d4 xorgxrdp: Add logging hint
Add commented out lines to the [Xorg] stanza in sesman.ini to get full
logging for xorgxrdp
2026-02-26 19:12:48 +00:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 94c0024c3b passwd_unix: Change salt if password is changed 2026-02-20 16:02:05 +01:00
matt335672 8b252fb462 VNC auth: Do not try to create empty file
When using UDS mode for VNC, the following error has been reported:

[WARN ] Cannot write VNC password hash to file (null): Bad address

This prevents an attempt to create a file with a NULL name.
2026-02-12 11:50:09 +00:00
matt335672 7fcec1e6da Harden env_check_password_file()
env_check_password_file() does not check its parameters are non-NULL.
This commit simply adds those checks.
2026-02-12 11:48:54 +00:00
matt335672 b3ab2c28d8 Merge pull request #3695 from akarl10/user-shell-environment-fix
User shell environment fix
2026-02-12 11:26:52 +00:00
matt335672 661fe2eb0e Merge pull request #3686 from lcniel/add_port_discriminator
Allow sessions to be distinguished based on XRDP instance_name configuration by using new policy
2026-01-26 09:47:02 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
akarl10 c1ed8b8eb6 [sesexec] pass_shell_as_env only if user sets a shell
set environment variable only if the user actually requests a specific
shell.
2026-01-18 10:27:47 +01:00
matt335672 6a5d858dce xrdpapi: Add a way to get client connect status
Functions are added to xrdpapi to allows the connection status
to be determimed. These functions are modelled on the Windows API
functions, but are not compatible with them. In particular, the error
handling is different.

A way for an application to receive events is also provided. At present,
only connect/disconnected events are implemented.
2025-12-15 11:26:21 +00:00
matt335672 d63fedf239 Merge pull request #3663 from matt335672/clarify_xorg_path
sesman.ini: Update well-known paths for Xorg
2025-11-07 13:42:57 +00:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
matt335672 5abd51b675 Code quality: Fix expansion-to-defined warning
Fixes a gcc compiler warning regarding a potentially unportable
use of 'defined()' in a macro
2025-11-05 13:51:49 +01:00
matt335672 0d3122d82f sesman.ini: Update well-known paths for Xorg
Include explicit references for AlmaLinux and Rocky, and remove
references to CentOS to better suit current audiences.
2025-11-05 11:00:39 +00:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 d95893a8c3 Coverity: Fix CHECKED_RETURN warning 2025-10-31 14:20:02 +00:00
matt335672 90a027851a PassShellAsEnv: Update docs 2025-10-28 10:04:03 +00:00
matt335672 6b6edca8ca session management: Allow for restricted shells
Allows the AlternateShell specified by the user in the TS_INFO_PACKET
to be passed to startwm.sh as an environment variable.
2025-10-28 10:04:03 +00:00
matt335672 43a0c91aa2 Merge pull request #3632 from matt335672/add_fuse_root_report_max_free
Add FuseRootReportMaxFree option
2025-10-15 16:20:58 +01:00
Alejandro González 0ae672d200 Fix PAM_TTY item being set to uninitialized data in PAM userpass lib
The local variable it referenced was never initialized before use. I
replaced it with a reference to the seemingly intended `SERVICE`
preprocessor constant, which is also used in the `pam_start` call
slightly above.
2025-10-13 21:18:13 +02:00
matt335672 4d2c4ae8a5 Add FuseRootReportMaxFree option
Add an option to allow effectively disable file system space checks for
some file managers before copying files to remote drives.

This is a temporary solution. A better solution is to provide each
remote drive with its own mountpoint, so that the xrdp FUSE filesystem
becomes POSIX compliant.
2025-10-06 11:45:43 +01:00
matt335672 4ae0cb75b9 Fix regression in PAM groups handling
Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.

(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
2025-08-25 13:22:31 +01:00
matt335672 7b4d673c94 Fix stray carriage returns in xrdp-sesadmin output
The ctime() function adds a carriage return to its output, and this
has not properly been taken into account with recent additions.
2025-08-11 09:50:41 +01:00
matt335672 8099299ab0 Allow for empty UTF8_STRING to be pasted
The current code doesn't allow for an empty string to be pasted to the
clipboard on the X11 side.  This is done by some lock screen programs
to prevent information leakage.
2025-08-04 11:25:54 +01:00
matt335672 416a5e66e5 Fix compilation failure in Deepin 20 2025-07-23 09:56:31 +01:00
matt335672 159947ca9b Minor logging improvement 2025-07-21 11:30:14 +01:00
matt335672 f371876e8c Set XRDP_CLIENT_xx variables for the reconnect script 2025-07-21 11:30:14 +01:00
matt335672 cd98b013f1 Add logging of connect/disconnect times
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.

xrdp-sesadmin can now access the connection data from sesman
2025-07-21 11:30:14 +01:00
matt335672 db50a27089 Remove unnecessary include from session.h 2025-07-21 11:30:14 +01:00
matt335672 d88cf53453 Add CCP support to sesexec
sesexec can now tell the xrdp process to exit, and is aware when
the xrdp process exits.
2025-07-21 11:30:14 +01:00
matt335672 b5ba5635e1 Replace unneeded callback data value 2025-07-21 11:30:14 +01:00
matt335672 02eae9f3ba Fix Coverity warnings
Two problems were found:-
1) A useless test in scp_list.c - testing an unsigned int was >= 0.
2) Flow control issues in scp.c:scp_get_connect_session_response() meant
   that file descriptors could be leaked. A helper function has been
   used to simplify the code.
2025-07-15 11:46:57 +01:00
matt335672 cf202d618b Add AlwaysRunReconnect config option
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
2025-07-14 19:39:26 +01:00
matt335672 8bcb14f79d Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
2025-07-14 19:39:26 +01:00
matt335672 d0a876ed47 Update xrdp-sesrun for new SCP interface
The SCP connection is now still open after a create session call,
and needs to be explicitly closed to prevent errors being logged.
2025-07-14 19:39:26 +01:00
matt335672 09e4a99bac Plumb connect_session call into sesman and sesexec 2025-07-14 19:39:26 +01:00
matt335672 3e38d9be80 Rework the start session method in SCP
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.

This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
2025-07-07 20:09:20 +01:00
matt335672 ee8739a3f5 Update scp_list.h 2025-07-07 15:02:51 +01:00
matt335672 4d990cfc16 Rename the pre-session list to the SCP list
The name pre-session list makes no sense now, as we need items
to remain on the list after starting the session and before
connecting.
2025-07-07 15:02:51 +01:00
matt335672 539eb33795 Prevent possible double-free on chansrv exit 2025-06-21 14:38:06 +01:00
matt335672 554515e39c Refactor static channel name handling
1) Remove 'magic numbers' related to static channel name lengths, and
   replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
   the [Channels] section of xrdp.ini.

(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
2025-04-26 17:06:10 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 5cf0ec8f34 Add a StartupWaitTime parameter
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
2025-03-29 17:52:47 +00:00
matt335672 343e84a76a Remove SIGTERM race in chansrv
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
2025-03-29 17:15:45 +00:00
matt335672 86c7fa63b9 Give privilege to users in TerminalServerAdmins
Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
2025-03-14 17:13:41 +00:00
matt335672 dd020e971b Rename sesman privilege detection function
access_login_mng_allowed() -> access_login_is_admin()
2025-03-12 17:06:01 +00:00
matt335672 0e2f03e925 Log session state transitions to E_SESSION_RUNNING
A log message has been added so that during session discovery
a list of discovered sessions can be generated.
2025-03-12 11:38:37 +00:00
matt335672 0806b2b978 Fix missing displays on sesman restart 2025-03-12 11:08:03 +00:00
matt335672 9225fe0686 Fill in discovery module
Add functionality to sesexec discovery module to enable sesman
restarts.
2025-03-12 11:08:03 +00:00