Commit Graph

5332 Commits

Author SHA1 Message Date
matt335672 8bfc79a0bc Update security reporting instructions in SECURITY.md
Clarified instructions for reporting security vulnerabilities and emphasized that the email address is not secure for such reports.
2026-03-23 14:41:33 +00:00
Matt Cunningham fcc5bd79ea g_tcp_connect fix:
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
  - #define for MAX_PORT_STR length
  - create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
  - add chars host and service which are primarily used for debug logging of attempted connection points
  - calls get_socket_family to discover family of socket
  - add switch case logic for AF_INET6/4:
    - v4: just calls addr_is_ipv6 so we don't fail on a hostname input
    - v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
    - if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
  - getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
  - before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely:  this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
2026-03-23 08:21:29 -04:00
matt335672 0f2dc88541 sesman: Remove unused authentication methods
The Kerberos module and pam_userpass modules are now unused:

1) On all supported systems, PAM provides a far superior way to
   integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
   (which is a lovely idea) is no longer maintained.
2026-03-23 11:24:19 +00:00
matt335672 b9742d94f7 Merge pull request #3764 from matt335672/regression_smartcard_removal
regression: Fix client issues with no smartcard
2026-03-18 20:24:05 +00:00
matt335672 7d618945b1 regression: Fix client issues with no smartcard
57609d4aa7 introduced an issue where
the numCapabilities field in the DR_CORE_CAPABILITY_REQ PDU
was incorrect unless --enable-smartcard was specified.

This commit also improves the logic around handling clients who
advertise a smartcard even if we do not support it.
2026-03-18 19:56:29 +00:00
matt335672 7f6e198b06 Merge pull request #3761 from matt335672/update_actions
CI: Upgrade to latest github action versions
2026-03-18 10:38:15 +00:00
matt335672 e2148a360c CI: Upgrade to latest github action versions
This has been prompted by the following deprecation messages:

> Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@v4, actions/checkout@v4.
2026-03-18 09:53:46 +00:00
matt335672 45f62bdedd CVE-2026-33145: Default AllowAlternateShell to 'no' 2026-03-18 09:26:07 +00:00
matt335672 1737f19485 Merge pull request #3758 from matt335672/disable_smartcard_code
Disable smartcard code by default
2026-03-18 09:17:08 +00:00
matt335672 57609d4aa7 smartcard: Update redirector smartcard capability
Only announce a smartcard capability in the redirector if we can
support it.
2026-03-17 15:22:11 +00:00
matt335672 7a2ac0c177 security: Disable smartcard code by default
The smartcard code contains a number of security vulnerabilities and
does not work at the moment.

The code has been left in the source tree, but moved behind an
'--enable-smartcard' configure flag which is clearly marked as not
for production use.
2026-03-17 15:22:11 +00:00
matt335672 458944983f Merge pull request #3757 from matt335672/fix_audio_modules
regression: Audio modules
2026-03-16 11:13:03 +00:00
matt335672 3444f9a1e0 regression: Audio modules
Following on from the display number removal, the code to set
the environment variables for the audio modules has been discovered
to be incorrect.
2026-03-16 10:47:46 +00:00
matt335672 b73f0f1c75 Merge pull request #3753 from matt335672/display_num_regressions
regression: Display number related issues
2026-03-16 10:00:37 +00:00
matt335672 3f0f7df6ff CVE-2026-32623: vulns in neutrinordp fragment reassembly
This PR addresses potential buffer overflows in fragment reassembly in
the neutrinordp shim by adding length and status checks.
2026-03-14 11:28:19 +00:00
matt335672 f1a2bec415 CVE-2026-32624: buffer overflow if domain sep used
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672 a11ee461a7 resizing: Simplify GFX resizing
For GFX, we currently resize the client with a deactivation-reactivation
sequence. This is unnecessary, as the GFX RESET_GRAPHICS command does
all the work for us, and avoids the need to teardown and reestablish the
GFX channel.
2026-03-12 17:32:55 +00:00
matt335672 03b5d2cccb Code quality: Improve HMAC logging for security
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672 187d22cef8 security: Check HMAC on non-FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672 759104912c security: Check HMAC on non-FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672 0d8cf57e9d security: Check HMAC on FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672 2a411f7525 security: Check HMAC on FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
matt335672 defb1bcba4 regression: Display number related issues
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.

   pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
   session type. This mapping is no longer done. We could re-introduce
   this code for X11, but there is no such code to detect a wayland
   display type. We try to fix this in a forward-looking way by setting
   XDG_SESSION_TYPE explicity before starting the PAM session.

2) utmp is not being updated correctly.

   The code for setting ut_id in the utmp[x] structure was setting the
   same value for all X11 displays, thus preventing utmp from being able
   to see more than one xrdp user

Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
2026-03-11 13:17:33 +00:00
matt335672 90275daf6d Merge pull request #3747 from firewave/cppcheck-cv
enabled and fixed `constVariable` Cppcheck warnings
2026-03-06 11:01:56 +00:00
firewave 64154ea66d enabled and fixed constVariable Cppcheck warnings 2026-03-04 15:49:29 +01:00
matt335672 2dfe8bbce2 Merge pull request #3729 from matt335672/remove_display_num
Remove X11 display number from xrdp interfaces
2026-03-04 14:45:56 +00:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 0c92f5f5a2 xorgxrdp: Rename socket files 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
matt335672 d56408a891 authentication: Replace display number with string
The display number is a concept which won't exist for Wayland displays.
We use a display nuimber instead.
2026-03-04 14:32:21 +00:00
matt335672 656a125cc0 utmp: Remove display number from interface
The display number will not be a valid concept for Wayland, so the
display number parameter is replaced with a display string.
2026-03-04 14:32:21 +00:00
matt335672 fd43cd5d85 CI: Prevent some format truncation errors 2026-03-04 14:32:21 +00:00
matt335672 fea345d75a Merge pull request #3739 from firewave/cppcheck-style-xxx
fixed some `unreadVariable` Cppcheck warnings
2026-03-04 14:25:59 +00:00
matt335672 65ab126b95 Merge pull request #3659 from firewave/ubsan
build.yml: added sanitized build with UndefinedBehaviorSanitizer
2026-03-04 13:43:16 +00:00
firewave fd4af1b346 build.yml: added sanitized build with UndefinedBehaviorSanitizer 2026-03-03 16:40:38 +01:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 3db1c993bf Merge pull request #3743 from matt335672/cppcheck_2_20
cppcheck: Bump version to 2.20
2026-03-03 15:14:37 +00:00
matt335672 237821f2e1 Merge pull request #3741 from matt335672/logging_comment
xorgxrdp: Add logging hint
2026-03-03 11:16:17 +00:00
matt335672 32810ecbbb cppcheck: Bump version to 2.20 2026-03-03 11:15:41 +00:00
matt335672 fe32e2e2d4 xorgxrdp: Add logging hint
Add commented out lines to the [Xorg] stanza in sesman.ini to get full
logging for xorgxrdp
2026-02-26 19:12:48 +00:00
matt335672 916b6a1667 Merge pull request #3738 from matt335672/fix_ulalaca_char16_t
ulalaca: Don't redefine char16_t and char32_t
2026-02-23 15:00:27 +00:00
matt335672 5fd81ae9cb ulalaca: Don't redefine char16_t and char32_t
On MacOS, stdint.h is provided by the compiler for C, and by
the SDK for C++.

OSX 14.4 appears to define char16_t and char32_t within stdint.h for
C++.  Defining them again results in:

```
../common/arch.h:53:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least16_t char16_t;
                       ^
../common/arch.h:53:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least16_t char16_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
../common/arch.h:54:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least32_t char32_t;
                       ^
../common/arch.h:54:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least32_t char32_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
```
2026-02-23 14:22:05 +00:00
matt335672 352edc3dba Merge pull request #3731 from firewave/cppcheck-portability
enabled and fixed cppcheck `portability` checks
2026-02-20 15:55:08 +00:00
matt335672 e5d990ca3e Code quality: Prevent undefined shifting behavour
This commit addresses cppcheck errors such as the following:

portability: Shifting a negative value is technically undefined behaviour [shiftNegativeLHS]

Affected variable types are replaced with corresponding unsigned types
2026-02-20 16:02:05 +01:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 94c0024c3b passwd_unix: Change salt if password is changed 2026-02-20 16:02:05 +01:00
firewave 416aa53157 enabled cppcheck portability checks 2026-02-20 16:02:05 +01:00
matt335672 ce501dff70 Merge pull request #3732 from firewave/cppcheck-style
enabled and fixed some cppcheck `style` checks
2026-02-20 13:53:57 +00:00
matt335672 588fac89f2 Merge pull request #3734 from tsz8899/tsz/coverity-fix-recent-regressions-0x18
coverity fix recent regressions
2026-02-18 17:32:24 +00:00
tsz8899 d5b3b6a20a xrdp_mm: apply firewave suggestion in setup_mod2 2026-02-18 23:47:16 +08:00