This is required, as on Debian, pam_limits is not automatically included
for common sessions, and only for "login" sessions and session managers.
So, xrdp has to include it explicitly to make limits take effect.
See https://wiki.debian.org/Limits for details.
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.
Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
This is not year 2038 compliant on systems with 32-bit integers.
The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
This seems a better fit than having it in the [Chansrv] section.
Also fixed a minor logging error relating to the parameter in
chansrv_config.c
(cherry picked from commit 6d2fd1be8451418f01dfbb203929e2838c1a979f)
This is useful for NFS-mounted home directories, where hosts
may otherwise produce colliding chansrv log file names
(cherry picked from commit cfc2e362b47103bc2c786252f331bb26b6ddecb5)
While here, drop exec permission from xrdp-chkpriv.in. The exec
permission will be granted to substituted xrdp-chkpriv script
during `make install` process.
Commit 80fab03198 introduced a way to
prevent waitforx going to the network when trying to open a display,
and hence potentially blocking.
This method turned out to be invalidated by libxcb version 1.16 and
1.17
This change adds an explicit check that the Unix socket for the display
in /tmp/.X11-unix/Xn is open before trying to connect to display ':n'.
This has the same effect.
1) Changed alarm message from "Timed out waiting for RandR outputs" to
"Timed out waiting for X display". The former was confusing, and the
times where this message was triggered were nothing to do with
RandR
2) Don't try to open a display of the form ":n" or ":n.m" directly
(n,m >= 0). If the X server hasn't yet opened its local socket,
the XOpenDisplay() call can go to the network and possibly block
for a long time. Instead, use the (undocumented) "unix:n" display
specification, whih never goes to the network, and doesn't block.
The mismatched versions are now displayed to the user rathe than being
buried in the log. This should aid fault reporting and help users find
distro-introduced problems with an Internet search.
This commit adds a stage into the Xorg connection status to wait for
the capabilities message from the Xorg server. This allows us to move
the xorgxrdp version check to xrdp from the X server for better
reporting to the user.
The login screen uses hardcoded scancode values to identify particular
keys. This is changed for the backspace key for Colemak support, as
the caps lock key has been re-purposed as a backspace key. We now
identify a backspace request by looking at the keysym for the key.
The Colemak keyboard does not have a Caps Lock key:-
1) Keyboard files have a caps_lock_supported flag added to the [General]
section. This is set to false if the keyboardlayout does not have a
Caps Lock key.
2) The caps_lock_supported flag is parsed when reading keymap files
for the login screen/VNC.
3) The flag is also checked when telling xorgxrdp what the scancode for
the caps lock key is.
Colemak is unusual in that it doesn't have a Caps Lock key.
This means we don't need to generate capslock sections in the keymap
file. We add a flag to the keymap file [General] section to indicate
these sections are missing.
A change is also made to the way the Dvorak keymap file (00010409) is
generated, for consistency with Colemak.
Chromium 130 won't save to our filesystem if we don't return a
max filename length.
Dummy parameters were tried for inode counts, but these do not seem to
be necessary. Not also that btrfs foes not return values for these
fields.
Some desktop environments are now checking for free space before
copying files to a destination.
To support this, the FUSE filesystem needs to convert the statvfs()
system call to the relevent PDUs from [MS-RDPEFS]
SSL_CTX_set_ecdh_auto() was introduced for OpenSSL 1.0.2. It
has no effect for OpenSSL 1.1.0 and later. For versions before
1.0.2 and after (and including 1.1.0) it should not be called.
The macro was erroneously being called twice for OpenSSL 3.0.0 and
later - this has also been remedied