Commit Graph

5078 Commits

Author SHA1 Message Date
matt335672 4b2155b6cf Restructure VNC lib_mod_connect()
1) Restructure lib_mod_connect() along the lines of the PDUs documented
   in RFC 6143.
2) Logging in lib_mod_connect() has been revised and improved.
3) Wrinkles around version 3.7 and 3.8 of the RFB protocol are
   now addressed.
4) Some new definitions are added to rfb.h to replace the use
   of magic numbers.
2025-03-17 18:39:36 +00:00
Jesse Bakker 527d21b0a1 Add support for RFB protocol version 3.7 and 3.8
(cherry picked from commit 69cb53266f5b2536e22a4ece7a5eacb6e5ec69d9)
2025-03-15 09:49:37 +00:00
matt335672 2b226364a3 Merge pull request #3351 from matt335672/admin_users
Give privilege to users in TerminalServerAdmins
2025-03-15 08:56:33 +00:00
matt335672 86c7fa63b9 Give privilege to users in TerminalServerAdmins
Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
2025-03-14 17:13:41 +00:00
matt335672 dd020e971b Rename sesman privilege detection function
access_login_mng_allowed() -> access_login_is_admin()
2025-03-12 17:06:01 +00:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 a999337bdd Merge pull request #3390 from matt335672/fix_xserver_check
Add g_sck_set_reuseaddr()
2025-03-12 11:39:48 +00:00
matt335672 0e2f03e925 Log session state transitions to E_SESSION_RUNNING
A log message has been added so that during session discovery
a list of discovered sessions can be generated.
2025-03-12 11:38:37 +00:00
matt335672 0220fa46c3 Add commented out KillMode=process to xrdp-service
The KillMode of process allows an xrdp connection to survive a
reatart of the xrdp process. This is of minimal benefit, as a
user can always simply reconnect - the session will survive the
restart. The downside is that xrdp will not benefit from any
security fixes, and may well end up out-of-sync with sesman.
2025-03-12 11:08:03 +00:00
matt335672 0806b2b978 Fix missing displays on sesman restart 2025-03-12 11:08:03 +00:00
matt335672 9225fe0686 Fill in discovery module
Add functionality to sesexec discovery module to enable sesman
restarts.
2025-03-12 11:08:03 +00:00
matt335672 0a584204a2 Add sesexec_set_ecp_transport/sesexec_is_ecp_active()
These sesexec functions are needed for the discovery module to
function.
2025-03-12 11:08:03 +00:00
matt335672 bee806d3af Add sesexec discover module
The module is a dummy to be filled in later

Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
   causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
   be robust enough to stay up for the lifetime of the session so that
   the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
   doesn't work, as SIGCHLD is not processed while we are waiting for
   the session to finish. This needs fixing.
2025-03-12 11:08:03 +00:00
matt335672 eadbb6a190 Add session_get_parameters()
Also add useful comment to session_send_term()
2025-03-12 11:08:03 +00:00
matt335672 7268580f24 Add sesman restart module
Adds a module which can be used when sesman is restarting. This is
initially used to rediscover sessions from a previous run.
2025-03-12 11:08:03 +00:00
matt335672 7fb1f4732b Add warning if listen_port changes 2025-03-12 10:06:24 +00:00
matt335672 44a83c8b38 Make listen_port smaller than XRDP_SOCKETS_MAXPATH 2025-03-12 10:06:24 +00:00
matt335672 627ebea34d Add session_list_get_count_by_state() to session list 2025-03-12 10:06:24 +00:00
matt335672 f7f64c8db2 Add ercp_connect() call to ERCP interface
This is used by sesman to connect to sockets in the restart
directory.
2025-03-12 10:06:24 +00:00
matt335672 360d23f922 Add g_socket_exist() to OS calls 2025-03-12 10:06:24 +00:00
matt335672 f9a9ed2a68 Add g_readdir_entries() to OS calls 2025-03-12 10:06:22 +00:00
matt335672 d55c7e7cb7 Remove commented-out code
The function sesexce_scp_data_in in sesexec.c is a development
artefact and can safely be removed
2025-03-12 10:03:15 +00:00
matt335672 a341d44e1b Remove unused variable g_con_list 2025-03-12 10:03:15 +00:00
matt335672 43e960bffd Restrict scope of sesman_close_all()
This function does not need to have global scope.
2025-03-12 10:03:15 +00:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 984a0b2767 Merge pull request #3454 from matt335672/coverity_fix
Fix coverity warning concerning unchecked return
2025-03-10 20:53:43 +00:00
matt335672 f618965eb7 Fix coverity warning concerning unchecked return
Coverity insists the return value from read() is unchecked. This seems
to not be true to me, but adding a complete sanity check seems to fix
it.
2025-03-10 20:48:05 +00:00
matt335672 0115e9c806 Merge pull request #3452 from matt335672/vnc_local_sock_connection
Add new session type SCP_SESSION_TYPE_XVNC_UDS
2025-03-10 09:56:55 +00:00
matt335672 39a178902e Improve logging on failed connect attempt 2025-03-08 11:45:26 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 6979df55ee Add new session type SCP_SESSION_TYPE_XVNC_UDS
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.

This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
2025-03-08 11:45:26 +00:00
matt335672 e8a0699bb4 Merge pull request #3393 from matt335672/xauth_in_sysdir
Add XAuthorityInSystemDir option
2025-03-03 13:38:09 +00:00
matt335672 f5634269f2 Merge pull request #3442 from matt335672/coverity_scan
Fix more coverity warnings
2025-02-28 14:47:42 +00:00
matt335672 f187d2314c Coverity CID 468117 2025-02-28 14:34:26 +00:00
matt335672 2805572601 Coverity CID 468112 2025-02-28 14:34:26 +00:00
matt335672 8b449868fe Coverity CID 468108
Repeated constant WAVE_FORMAT_MULAW in conditional
2025-02-28 14:34:26 +00:00
matt335672 621920e3f0 Coverity CID 468103 2025-02-28 14:34:26 +00:00
matt335672 a7ab8ecd9a Coverity CID 468102 2025-02-28 14:34:26 +00:00
matt335672 4a95185dc6 Coverity CID 475385 2025-02-28 11:18:58 +00:00
matt335672 a4209c1c34 Merge pull request #3439 from matt335672/update_cppcheck
Add support for cppcheck 2.17.x
2025-02-27 15:15:04 +00:00
matt335672 82de537221 Rebase cppcheck 2.17.0 -> 2.17.1 2025-02-27 15:04:11 +00:00
matt335672 3cc1265adc Add test suite calls for list16
Following a re-write of the list16 module to avoid memory allocation
issues, a test suite is added for the module.
2025-02-27 15:04:11 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00
jsorg71 3446614961 Merge pull request #3320 from jsorg71/nvenc
add support for nvenc and accel_assist
2025-02-21 22:39:57 -08:00
Jay Sorg 75b9304304 add grid options to sesman.ini 2025-02-16 17:34:51 -08:00
Jay Sorg 6dcb8ffe79 add support for nvenc and accel_assist 2025-02-16 17:34:51 -08:00
matt335672 6889a0731d Merge pull request #3433 from matt335672/coverity_scan
Address Coverity mutex issues
2025-02-14 17:09:53 +00:00
matt335672 67fbccc539 Address Coverity mutex issues
Coverity has generated a number of 'Data race condition' and 'Double
lock' false positives. A lot of these seem to be caused by the NULL
guard in tc_mutex_unlock() not being paired with a NULL guard in
tc_mutex_lock(). This PR adds a NULL guard to tc_mutex_lock().

It should be noted, that on Linux at least, passing NULL to
tc_mutex_lock() causes a segfault. We clearly aren't doing this at the
moment, or we'd know about it. A log message is generated if a NULL
call is made, rather than failing silently.
2025-02-14 11:57:42 +00:00
matt335672 fa9cc88389 Merge pull request #3413 from matt335672/detect_noopenh264
Cope with broken OpenH264 encoder
2025-02-13 11:29:28 +00:00
matt335672 8c69cb00ef Merge pull request #3429 from matt335672/add_hu_kbd
Add Hungarian keyboard
2025-02-12 09:44:32 +00:00