1) Remove 'magic numbers' related to static channel name lengths, and
replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
the [Channels] section of xrdp.ini.
(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.
An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
The module is a dummy to be filled in later
Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
be robust enough to stay up for the lifetime of the session so that
the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
doesn't work, as SIGCHLD is not processed while we are waiting for
the session to finish. This needs fixing.
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.
This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.
We do this quite a lot.
I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.
Many of these checks are in test programs or example programs.
I've modified the list16 module to handle out-of-memory conditions.
This Coverity issue was encountered in a private build, but does not
appear to be in the Github CI build. Coverity is suspecting a copy-paste
betweem these lines in sound.c:-
1838: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], i);
1844: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], g_bytes_in_stream);
An inspection of the code shows this to bre a false positive
Add an option to allow XAUTHORITY to be moved away from $HOME.
This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
The errors in sesman/chansrv/chansrv_fuse.c appear to be false positives
caused by allocating xhandle->dir_handle, and then
casting xhandle to an integer in xfuse_handle_to_fuse_handle(), thus
hiding xhandle->dir_handle
For both occurrences, the logic has been simplified and made the same,
and a comment has been added to suppress the error.
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.
Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
This is not year 2038 compliant on systems with 32-bit integers.
The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
This seems a better fit than having it in the [Chansrv] section.
Also fixed a minor logging error relating to the parameter in
chansrv_config.c
(cherry picked from commit 6d2fd1be8451418f01dfbb203929e2838c1a979f)
This is useful for NFS-mounted home directories, where hosts
may otherwise produce colliding chansrv log file names
(cherry picked from commit cfc2e362b47103bc2c786252f331bb26b6ddecb5)
Commit 80fab03198 introduced a way to
prevent waitforx going to the network when trying to open a display,
and hence potentially blocking.
This method turned out to be invalidated by libxcb version 1.16 and
1.17
This change adds an explicit check that the Unix socket for the display
in /tmp/.X11-unix/Xn is open before trying to connect to display ':n'.
This has the same effect.
Chromium 130 won't save to our filesystem if we don't return a
max filename length.
Dummy parameters were tried for inode counts, but these do not seem to
be necessary. Not also that btrfs foes not return values for these
fields.