Commit Graph

1287 Commits

Author SHA1 Message Date
matt335672 3444f9a1e0 regression: Audio modules
Following on from the display number removal, the code to set
the environment variables for the audio modules has been discovered
to be incorrect.
2026-03-16 10:47:46 +00:00
matt335672 defb1bcba4 regression: Display number related issues
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.

   pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
   session type. This mapping is no longer done. We could re-introduce
   this code for X11, but there is no such code to detect a wayland
   display type. We try to fix this in a forward-looking way by setting
   XDG_SESSION_TYPE explicity before starting the PAM session.

2) utmp is not being updated correctly.

   The code for setting ut_id in the utmp[x] structure was setting the
   same value for all X11 displays, thus preventing utmp from being able
   to see more than one xrdp user

Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
2026-03-11 13:17:33 +00:00
matt335672 90275daf6d Merge pull request #3747 from firewave/cppcheck-cv
enabled and fixed `constVariable` Cppcheck warnings
2026-03-06 11:01:56 +00:00
firewave 64154ea66d enabled and fixed constVariable Cppcheck warnings 2026-03-04 15:49:29 +01:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 0c92f5f5a2 xorgxrdp: Rename socket files 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
matt335672 d56408a891 authentication: Replace display number with string
The display number is a concept which won't exist for Wayland displays.
We use a display nuimber instead.
2026-03-04 14:32:21 +00:00
matt335672 656a125cc0 utmp: Remove display number from interface
The display number will not be a valid concept for Wayland, so the
display number parameter is replaced with a display string.
2026-03-04 14:32:21 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 fe32e2e2d4 xorgxrdp: Add logging hint
Add commented out lines to the [Xorg] stanza in sesman.ini to get full
logging for xorgxrdp
2026-02-26 19:12:48 +00:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 94c0024c3b passwd_unix: Change salt if password is changed 2026-02-20 16:02:05 +01:00
matt335672 8b252fb462 VNC auth: Do not try to create empty file
When using UDS mode for VNC, the following error has been reported:

[WARN ] Cannot write VNC password hash to file (null): Bad address

This prevents an attempt to create a file with a NULL name.
2026-02-12 11:50:09 +00:00
matt335672 7fcec1e6da Harden env_check_password_file()
env_check_password_file() does not check its parameters are non-NULL.
This commit simply adds those checks.
2026-02-12 11:48:54 +00:00
matt335672 b3ab2c28d8 Merge pull request #3695 from akarl10/user-shell-environment-fix
User shell environment fix
2026-02-12 11:26:52 +00:00
matt335672 661fe2eb0e Merge pull request #3686 from lcniel/add_port_discriminator
Allow sessions to be distinguished based on XRDP instance_name configuration by using new policy
2026-01-26 09:47:02 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
akarl10 c1ed8b8eb6 [sesexec] pass_shell_as_env only if user sets a shell
set environment variable only if the user actually requests a specific
shell.
2026-01-18 10:27:47 +01:00
matt335672 6a5d858dce xrdpapi: Add a way to get client connect status
Functions are added to xrdpapi to allows the connection status
to be determimed. These functions are modelled on the Windows API
functions, but are not compatible with them. In particular, the error
handling is different.

A way for an application to receive events is also provided. At present,
only connect/disconnected events are implemented.
2025-12-15 11:26:21 +00:00
matt335672 d63fedf239 Merge pull request #3663 from matt335672/clarify_xorg_path
sesman.ini: Update well-known paths for Xorg
2025-11-07 13:42:57 +00:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
matt335672 5abd51b675 Code quality: Fix expansion-to-defined warning
Fixes a gcc compiler warning regarding a potentially unportable
use of 'defined()' in a macro
2025-11-05 13:51:49 +01:00
matt335672 0d3122d82f sesman.ini: Update well-known paths for Xorg
Include explicit references for AlmaLinux and Rocky, and remove
references to CentOS to better suit current audiences.
2025-11-05 11:00:39 +00:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 d95893a8c3 Coverity: Fix CHECKED_RETURN warning 2025-10-31 14:20:02 +00:00
matt335672 90a027851a PassShellAsEnv: Update docs 2025-10-28 10:04:03 +00:00
matt335672 6b6edca8ca session management: Allow for restricted shells
Allows the AlternateShell specified by the user in the TS_INFO_PACKET
to be passed to startwm.sh as an environment variable.
2025-10-28 10:04:03 +00:00
matt335672 43a0c91aa2 Merge pull request #3632 from matt335672/add_fuse_root_report_max_free
Add FuseRootReportMaxFree option
2025-10-15 16:20:58 +01:00
Alejandro González 0ae672d200 Fix PAM_TTY item being set to uninitialized data in PAM userpass lib
The local variable it referenced was never initialized before use. I
replaced it with a reference to the seemingly intended `SERVICE`
preprocessor constant, which is also used in the `pam_start` call
slightly above.
2025-10-13 21:18:13 +02:00
matt335672 4d2c4ae8a5 Add FuseRootReportMaxFree option
Add an option to allow effectively disable file system space checks for
some file managers before copying files to remote drives.

This is a temporary solution. A better solution is to provide each
remote drive with its own mountpoint, so that the xrdp FUSE filesystem
becomes POSIX compliant.
2025-10-06 11:45:43 +01:00
matt335672 4ae0cb75b9 Fix regression in PAM groups handling
Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.

(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
2025-08-25 13:22:31 +01:00
matt335672 7b4d673c94 Fix stray carriage returns in xrdp-sesadmin output
The ctime() function adds a carriage return to its output, and this
has not properly been taken into account with recent additions.
2025-08-11 09:50:41 +01:00
matt335672 8099299ab0 Allow for empty UTF8_STRING to be pasted
The current code doesn't allow for an empty string to be pasted to the
clipboard on the X11 side.  This is done by some lock screen programs
to prevent information leakage.
2025-08-04 11:25:54 +01:00
matt335672 416a5e66e5 Fix compilation failure in Deepin 20 2025-07-23 09:56:31 +01:00
matt335672 159947ca9b Minor logging improvement 2025-07-21 11:30:14 +01:00
matt335672 f371876e8c Set XRDP_CLIENT_xx variables for the reconnect script 2025-07-21 11:30:14 +01:00
matt335672 cd98b013f1 Add logging of connect/disconnect times
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.

xrdp-sesadmin can now access the connection data from sesman
2025-07-21 11:30:14 +01:00
matt335672 db50a27089 Remove unnecessary include from session.h 2025-07-21 11:30:14 +01:00
matt335672 d88cf53453 Add CCP support to sesexec
sesexec can now tell the xrdp process to exit, and is aware when
the xrdp process exits.
2025-07-21 11:30:14 +01:00
matt335672 b5ba5635e1 Replace unneeded callback data value 2025-07-21 11:30:14 +01:00
matt335672 02eae9f3ba Fix Coverity warnings
Two problems were found:-
1) A useless test in scp_list.c - testing an unsigned int was >= 0.
2) Flow control issues in scp.c:scp_get_connect_session_response() meant
   that file descriptors could be leaked. A helper function has been
   used to simplify the code.
2025-07-15 11:46:57 +01:00
matt335672 cf202d618b Add AlwaysRunReconnect config option
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
2025-07-14 19:39:26 +01:00
matt335672 8bcb14f79d Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
2025-07-14 19:39:26 +01:00
matt335672 d0a876ed47 Update xrdp-sesrun for new SCP interface
The SCP connection is now still open after a create session call,
and needs to be explicitly closed to prevent errors being logged.
2025-07-14 19:39:26 +01:00
matt335672 09e4a99bac Plumb connect_session call into sesman and sesexec 2025-07-14 19:39:26 +01:00
matt335672 3e38d9be80 Rework the start session method in SCP
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.

This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
2025-07-07 20:09:20 +01:00
matt335672 ee8739a3f5 Update scp_list.h 2025-07-07 15:02:51 +01:00
matt335672 4d990cfc16 Rename the pre-session list to the SCP list
The name pre-session list makes no sense now, as we need items
to remain on the list after starting the session and before
connecting.
2025-07-07 15:02:51 +01:00
matt335672 539eb33795 Prevent possible double-free on chansrv exit 2025-06-21 14:38:06 +01:00