1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
1) Remove 'magic numbers' related to static channel name lengths, and
replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
the [Channels] section of xrdp.ini.
(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
Cater for xrdp_mm_get_value() returning NULL in a couple of places.
Also:-
- The function parse_chansrvport() now checks that passed-in value
isn't NULL.
- Unnecessary uses of g_strncpy replaced with strlcpy()
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.
An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
The datasize variable is an unsigned in, so comparing it to < 0 will
never be true. There is also a printf sequence for the variable which
should be %u rather than %d
Missing break statement in a switch intoduced by commit
54acca43cf
The results of this are benign, as the extra code which is run is
unlikely to do anything.
Later versions of Ubuntu (e.g. 24.10 and later) do not install
the systemd-dev package by default. This breaks the systemd-detection
mechanism.
Add this package in for non-systemd-based Debian distributions. Also
log what we are doing for systemd as part of the configure.
Replace uses of g_strncpy() in xrdp_init_xkb_layout() with the more
correct strlcpy().
In addition, some values and pointers which do not need to be
writeable have been made const.
xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
whitespace, but terminating on unrecognised characters
An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)
An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.
Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.
The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.
This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
Keyboard layout values from the client such as 00010416 (Brazil ABNT2)
may not have a matching entry in xrdp_keyboard.ini. For these clients,
we map a US keyboard as a fallback.
Before falling back to US, we should first try to match on the lower
16-bits of the layout, which in this case is 0416 (ABNT). This is more
likely to result in something usable.
We already implement this functionality for the keyboard files
used by the login screen and VNC back-end.
1) Restructure lib_mod_connect() along the lines of the PDUs documented
in RFC 6143.
2) Logging in lib_mod_connect() has been revised and improved.
3) Wrinkles around version 3.7 and 3.8 of the RFB protocol are
now addressed.
4) Some new definitions are added to rfb.h to replace the use
of magic numbers.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
The KillMode of process allows an xrdp connection to survive a
reatart of the xrdp process. This is of minimal benefit, as a
user can always simply reconnect - the session will survive the
restart. The downside is that xrdp will not benefit from any
security fixes, and may well end up out-of-sync with sesman.