Commit Graph

5067 Commits

Author SHA1 Message Date
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 45ccd2d356 Merge pull request #3509 from matt335672/devel_sps_investigations
Refactor static channel name handling
2025-04-28 10:48:35 +01:00
matt335672 554515e39c Refactor static channel name handling
1) Remove 'magic numbers' related to static channel name lengths, and
   replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
   the [Channels] section of xrdp.ini.

(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
2025-04-26 17:06:10 +01:00
matt335672 44acc46db4 Merge pull request #3505 from matt335672/coverity_fixes
Coverity fixes
2025-04-22 14:58:59 +01:00
matt335672 d30f5fe22b Coverity CID 468156
Coverity is complaining about 32-bits being truncated to 16-bits.
Make the data conversion to unsigned short explicit.
2025-04-22 14:51:26 +01:00
matt335672 c6fb510892 Coverity CID 468139
Cater for xrdp_mm_get_value() returning NULL in a couple of places.

Also:-
- The function parse_chansrvport() now checks that passed-in value
  isn't NULL.
- Unnecessary uses of g_strncpy replaced with strlcpy()
2025-04-22 14:51:26 +01:00
matt335672 ffe9ac9122 Coverity CID 468130
g_bitmask_to_str() can return < 0 on error. This is not adequately
catered for.
2025-04-22 14:51:26 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 f2dd3fb3dc Coverity CID 468126
The datasize variable is an unsigned in, so comparing it to < 0 will
never be true. There is also a printf sequence for the variable which
should be %u rather than %d
2025-04-18 16:16:07 +01:00
matt335672 c198b321a2 Fix Coverity CID 468122
Missing break statement in a switch intoduced by commit
54acca43cf

The results of this are benign, as the extra code which is run is
unlikely to do anything.
2025-04-18 16:16:07 +01:00
matt335672 fc30a5f576 Merge pull request #3503 from matt335672/fix_systemd_regression
Only add systemd-dev for systemd versions >= 255
2025-04-15 12:29:35 +01:00
matt335672 857a5bd262 Only add systemd-dev for systemd versions >= 255
(cherry picked from commit 93871c9182c139452af4e2f8f40b1b592ffa7092)
2025-04-15 12:21:21 +01:00
matt335672 91b60b8a7a Merge pull request #3501 from matt335672/add_systemd_dev_dependency
Improve systemd support
2025-04-15 11:59:47 +01:00
matt335672 ceb16198a2 Merge pull request #3500 from matt335672/fix_typo
Fix typo in CI build
2025-04-15 11:48:28 +01:00
matt335672 ae8d4a90ec Improve systemd support
Later versions of Ubuntu (e.g. 24.10 and later) do not install
the systemd-dev package by default. This breaks the systemd-detection
mechanism.

Add this package in for non-systemd-based Debian distributions. Also
log what we are doing for systemd as part of the configure.
2025-04-15 11:43:18 +01:00
matt335672 730dfdeeef Fix typo in CI build
--with-x264 should be --enable-x264
2025-04-15 10:07:07 +01:00
matt335672 6b5c6350b6 Merge pull request #3488 from matt335672/modernise_lang_c
Use strlcpy() in xrdp_init_xkb_layout()
2025-04-03 16:47:20 +01:00
matt335672 38b1d65956 xrdp_keyboard.ini : Provide defaults
At present, in the unlikely event the xrdp_keyboard.ini file is damaged,
sensible defaults are not provided for the values in the [defaults]
section.
2025-04-01 11:13:20 +01:00
matt335672 f1f2ce50f1 Use strlcpy() in xrdp_init_xkb_layout()
Replace uses of g_strncpy() in xrdp_init_xkb_layout() with the more
correct strlcpy().

In addition, some values and pointers which do not need to be
writeable have been made const.
2025-04-01 10:29:38 +01:00
matt335672 d73ce4644b Merge pull request #3483 from matt335672/add_startup_wait_time
Add a StartupWaitTime parameter
2025-04-01 10:22:09 +01:00
matt335672 c65c73495a Merge pull request #3460 from matt335672/vnc_upgrade
Upgrade VNC module to support later RFB versions
2025-04-01 10:15:18 +01:00
matt335672 73bc82afc2 Merge pull request #3487 from matt335672/fix_g_htoi
Rationalise g_htoi() / xrdp_wm_htoi()
2025-03-31 16:09:36 +01:00
matt335672 de0c704022 Clarify info message
The entries on xrdp_keyboard.ini use '0x' prefixes, and so we
should use these when reporting information about that file.
2025-03-31 15:57:34 +01:00
matt335672 bc0e169451 Rationalise g_htoi() / xrdp_wm_htoi()
xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
  characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
  whitespace, but terminating on unrecognised characters

An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)

An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.

Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.

The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
2025-03-31 15:36:51 +01:00
matt335672 267443e90d Merge pull request #3477 from matt335672/add_strlcpy
Add support for strlcpy()
2025-03-31 14:00:25 +01:00
matt335672 5de642c8c2 Address review comment
Add space after a comma for consistency in 'enum scp_create_status'
2025-03-31 13:56:44 +01:00
matt335672 5cf0ec8f34 Add a StartupWaitTime parameter
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
2025-03-29 17:52:47 +00:00
matt335672 6613d663ad Merge pull request #3481 from matt335672/chansrv_race_condition
Remove SIGTERM race in chansrv
2025-03-29 17:20:54 +00:00
matt335672 343e84a76a Remove SIGTERM race in chansrv
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
2025-03-29 17:15:45 +00:00
metalefty eac6a7130b Merge pull request #3480 from metalefty/actions-release-tarball
Add GitHub Actions to generate release tarball
2025-03-28 22:38:45 +09:00
Koichiro Iwao 5a7d9a263b Exit if no tarballs found 2025-03-28 22:25:24 +09:00
Koichiro Iwao 8213dd27ea Add GitHub Actions to generate release tarball 2025-03-28 22:21:53 +09:00
matt335672 aeb0b6d8af Merge pull request #3476 from matt335672/kbd_fallback
Add support for 16-bit layout fallback for xorgxrdp
2025-03-26 09:33:02 +00:00
matt335672 960ea7ce05 Add support for strlcpy()
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.

This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
2025-03-25 11:08:16 +00:00
matt335672 c8f5888e63 Add support for 16-bit layout fallback for xorgxrdp
Keyboard layout values from the client such as 00010416 (Brazil ABNT2)
may not have a matching entry in xrdp_keyboard.ini. For these clients,
we map a US keyboard as a fallback.

Before falling back to US, we should first try to match on the lower
16-bits of the layout, which in this case is 0416 (ABNT). This is more
likely to result in something usable.

We already implement this functionality for the keyboard files
used by the login screen and VNC back-end.
2025-03-25 10:48:30 +00:00
jsorg71 aac4946558 Merge pull request #3469 from jsorg71/system_pointer
add system pointer
2025-03-24 11:37:02 -07:00
matt335672 7d8a267c37 Merge pull request #3474 from matt335672/add_minus_y_to_apt_upgrade
Add a '-y' switch to apt-get upgrade
2025-03-24 16:18:37 +00:00
matt335672 d81f5a411d Add a '-y' switch to apt-get upgrade 2025-03-24 16:06:54 +00:00
Jay Sorg 522b5750d9 add system pointer 2025-03-21 23:04:15 -07:00
matt335672 4b2155b6cf Restructure VNC lib_mod_connect()
1) Restructure lib_mod_connect() along the lines of the PDUs documented
   in RFC 6143.
2) Logging in lib_mod_connect() has been revised and improved.
3) Wrinkles around version 3.7 and 3.8 of the RFB protocol are
   now addressed.
4) Some new definitions are added to rfb.h to replace the use
   of magic numbers.
2025-03-17 18:39:36 +00:00
Jesse Bakker 527d21b0a1 Add support for RFB protocol version 3.7 and 3.8
(cherry picked from commit 69cb53266f5b2536e22a4ece7a5eacb6e5ec69d9)
2025-03-15 09:49:37 +00:00
matt335672 2b226364a3 Merge pull request #3351 from matt335672/admin_users
Give privilege to users in TerminalServerAdmins
2025-03-15 08:56:33 +00:00
matt335672 86c7fa63b9 Give privilege to users in TerminalServerAdmins
Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
2025-03-14 17:13:41 +00:00
matt335672 dd020e971b Rename sesman privilege detection function
access_login_mng_allowed() -> access_login_is_admin()
2025-03-12 17:06:01 +00:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 a999337bdd Merge pull request #3390 from matt335672/fix_xserver_check
Add g_sck_set_reuseaddr()
2025-03-12 11:39:48 +00:00
matt335672 0e2f03e925 Log session state transitions to E_SESSION_RUNNING
A log message has been added so that during session discovery
a list of discovered sessions can be generated.
2025-03-12 11:38:37 +00:00
matt335672 0220fa46c3 Add commented out KillMode=process to xrdp-service
The KillMode of process allows an xrdp connection to survive a
reatart of the xrdp process. This is of minimal benefit, as a
user can always simply reconnect - the session will survive the
restart. The downside is that xrdp will not benefit from any
security fixes, and may well end up out-of-sync with sesman.
2025-03-12 11:08:03 +00:00
matt335672 0806b2b978 Fix missing displays on sesman restart 2025-03-12 11:08:03 +00:00
matt335672 9225fe0686 Fill in discovery module
Add functionality to sesexec discovery module to enable sesman
restarts.
2025-03-12 11:08:03 +00:00