The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.
This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
Keyboard layout values from the client such as 00010416 (Brazil ABNT2)
may not have a matching entry in xrdp_keyboard.ini. For these clients,
we map a US keyboard as a fallback.
Before falling back to US, we should first try to match on the lower
16-bits of the layout, which in this case is 0416 (ABNT). This is more
likely to result in something usable.
We already implement this functionality for the keyboard files
used by the login screen and VNC back-end.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
The KillMode of process allows an xrdp connection to survive a
reatart of the xrdp process. This is of minimal benefit, as a
user can always simply reconnect - the session will survive the
restart. The downside is that xrdp will not benefit from any
security fixes, and may well end up out-of-sync with sesman.
The module is a dummy to be filled in later
Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
be robust enough to stay up for the lifetime of the session so that
the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
doesn't work, as SIGCHLD is not processed while we are waiting for
the session to finish. This needs fixing.
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.
This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS