Commit Graph

282 Commits

Author SHA1 Message Date
Matt Cunningham fcc5bd79ea g_tcp_connect fix:
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
  - #define for MAX_PORT_STR length
  - create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
  - add chars host and service which are primarily used for debug logging of attempted connection points
  - calls get_socket_family to discover family of socket
  - add switch case logic for AF_INET6/4:
    - v4: just calls addr_is_ipv6 so we don't fail on a hostname input
    - v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
    - if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
  - getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
  - before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely:  this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
2026-03-23 08:21:29 -04:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 092e430512 Fix Psssible race condition in g_create_path()
(cherry picked from commit 2e597120443c7dcb0b32f6078999098a364f9543)
2025-12-03 11:00:28 +00:00
matt335672 c31c499372 os_calls: Add NULL_WAIT_OBJ
The wait_obj calls (mostly) ignore objects with a value of zero. This
is codified, so that user code can explicitly make use of this.
2025-11-21 12:33:38 +00:00
firewave d580c8d339 adjusted some includes 2025-11-04 13:41:26 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 21f663150e Get getgrouplist() compiling on MacOS
(cherry picked from commit 846a268cdcb691adf51e039b21ff201226b6b47b)
2025-07-23 11:38:11 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 360d23f922 Add g_socket_exist() to OS calls 2025-03-12 10:06:24 +00:00
matt335672 f9a9ed2a68 Add g_readdir_entries() to OS calls 2025-03-12 10:06:22 +00:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 f618965eb7 Fix coverity warning concerning unchecked return
Coverity insists the return value from read() is unchecked. This seems
to not be true to me, but adding a complete sanity check seems to fix
it.
2025-03-10 20:48:05 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 f187d2314c Coverity CID 468117 2025-02-28 14:34:26 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00
Jay Sorg 6dcb8ffe79 add support for nvenc and accel_assist 2025-02-16 17:34:51 -08:00
matt335672 2a4b40a20c Address some Coverity warnings 2025-01-13 15:24:33 +00:00
matt335672 e3d502ca06 Merge pull request #3328 from matt335672/fix_time_calls
Remove/replace time calls
2025-01-06 10:22:40 +00:00
peter15914 e70d316afc Fix possible memory leak 2025-01-05 00:03:34 +05:00
matt335672 1f79eb1c01 Replace g_time3() with g_get_elapsed_ms()
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.

Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
2024-12-16 16:13:15 +00:00
matt335672 90798cdeaa Remove g_time2() call
This is currently unused in xrdp
2024-12-16 16:13:15 +00:00
matt335672 b02689ab44 Remove g_time1() call
This is not year 2038 compliant on systems with 32-bit integers.

The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
2024-12-16 16:13:15 +00:00
matt335672 ce355fc235 Allow for xrdp not being able to delete PID file
If xrdp is running with dropped privileges it won't be able to delete
the PID file it's created. Places where xrdp is stopped need to cater
for this.

It's prefereable to do this than make the PID file writeable by xrdp
with dropped privileges, as this can still lead to DoS attacks if an
attacker manages to modify the PID file from a compromised xrdp
process.
2024-07-01 11:11:21 +01:00
matt335672 b1d8428579 Add code to drop privileges of xrdp daemon 2024-07-01 11:11:21 +01:00
matt335672 fb34d742bb Merge pull request #2910 from matt335672/fix_lfn_performance
Improve performance on long fat networks (LFNs)
2024-03-22 12:07:58 +00:00
Derek Schrock 5afbca4954 Fall back to IPv4 if IPv6 capable but don't have an IPv6 address set
When xrdp is built with IPv6 support it will only fall back to IPv4 if
IPv6 is not supported (EAFNOSUPPORT).  However, if the system is IPv6
capable but doesn't have an IPv6 address set (at least inside a FreeBSD
jail) EPROTONOSUPPORT is returned from socket().
2024-02-25 17:53:44 -05:00
matt335672 bc9b35c38c Rename struct exit_status in os_calls
This conflicts with struct exit_status in <utmp.h>
2024-02-21 09:24:48 +00:00
jsorg71 c961563403 GFX: sort versions, flags to return the highest version we support in… (#2911)
* GFX: sort versions, flags to return the highest version we support in caps advertise

* GFX: simpify swtich in caps_advertise

* GFX: log skipped capability versions in caps_advertise
2024-01-31 19:08:29 -05:00
Nexarian 584a894490 Add 0 as valid g_obj_wait timeout instead of having it be equivalent to -1. 2024-01-31 19:08:29 -05:00
matt335672 b23d6f89d5 Improve performance on long fat networks (LFNs)
On Linux, the TCP send buffer size is increased to 32768 if it is less
that this (which it normally is). This however has the effect of disabling
dynamic buffer sizing, leading to a maximum available bandwidth of

max_bandwidth = 262144 (bits) / round_trip_time (secs)

This is not noticeable on a LAN with an RTT of around 0.5ms, but
very noticeable on a WAN with an RTT of 0.25s.

Comments in the config file and manpage in this area are improved, as
is the logging if the parameters are actually set.
2024-01-11 11:53:54 +00:00
matt335672 b80f07d2a7 Improve portability
- Use clearenv() if it exists
- Don't rely on <limits.h> being pulled in by <sys/param.h>
- Rename the DEFAULT_TYPE macro in sesrun.c.  This name appears to be
  used on Solaris. It's not a good choice.
2024-01-11 11:16:06 +00:00
matt335672 50cff2eb75 Merge pull request #2794 from matt335672/utf_changes_new
Improve Unicode support
2023-11-02 10:57:39 +00:00
matt335672 547c619c2f Move g_mk_socket_path() to sesman
The sockdir is only used when sesman is active. The
call g_mk_socket_path() is removed from os_calls and moved to
sesman.

We also change the permissions on this directory to
0755 rather than 01777 (01000 is the 'sticky bit', S_ISVTX).

The behaviour of g_create_dir() has been modified to not
set S_ISVTX on Linux directories. This is implementation-defined
behaviour according to 1003.1, and is no longer required for the
sockdir.
2023-10-23 15:51:17 +01:00
matt335672 f5f67e2e80 Remove g_mbstowcs() and g_wcstombs()
These calls are now replaced with explicit UTF conversion routines in
the common/string_calls.[hc] and common/parse.[hc] modules.

Also removed:-
- The support code in common/os_calls.c to set the locale to use
  these routines.
- The twchar type in arch.h
2023-10-23 14:19:49 +01:00
matt335672 d11617adbe Remove dependency on signal() function
Replaces uses of signal() with sigaction() which should be far
more portable.
2023-10-09 14:05:29 +01:00
matt335672 cf677da22c Add getgrouplist() support to os_calls
On enterprise systems, using getgrouplist() (if available)
is more efficient than iterating over the members of the group,
and is also more likely to work
2023-10-04 11:02:07 +01:00
Keith Gable 9305008ba8 Tolerate XRDP_ENABLE_VSOCK being defined but the platform is neither FreeBSD nor Linux 2023-09-24 12:32:10 -07:00
Keith Gable 5ffca14b2f Change indent style to allman 2023-09-24 12:27:00 -07:00
Keith Gable 572ee7686d On FreeBSD, use AF_HYPERV in place of vsock 2023-09-23 21:28:24 -07:00
Jay Sorg c250529e8e add large cursor support, posix shm 2023-05-16 10:20:24 -07:00
Daniel Richard G b191d87e33 Move Linux's no_new_privs call into os_calls
This helps keep the application code free of platform-specific cruft.
Also remove a needless #include<sys/prctl.h> from sesman/session_list.c.
2023-05-15 17:40:46 -04:00
Daniel Richard G 1c0c923ad1 Split g_file_open() into _ro() and _rw() variants
Rename g_file_open() to g_file_open_rw(), and add a new g_file_open_ro()
call that wraps the common g_file_open_ex(file, 1, 0, 0, 0) idiom. This
will make the file access mode more explicit in the code.

Change all calls to g_file_open() to the _ro() or _rw() variant as
appropriate, and replace g_file_open_ex(file, 1, 0, 0, 0) with the _ro()
call.

Lastly, add tests for the two new calls to test_os_calls.c (code
courteously provided by matt335672).
2023-05-15 17:38:31 -04:00
matt335672 e96d77bac1 Remove g_mk_socket_path() from codepaths
The socket dir is only used if we are starting a session
with sesman. Consequently, it only makes sense to create
this directory within sesman itself.
2023-05-02 11:55:22 +01:00
matt335672 cf5e1961d3 os_calls: Add g_setpgid() 2023-05-02 11:55:22 +01:00
matt335672 65ff618479 os_calls: Add g_executable_exist() 2023-05-02 11:55:22 +01:00
matt335672 ff24984cf3 os_calls: Add g_file_is_open() 2023-05-02 11:55:22 +01:00
matt335672 f08355a325 Ensure commonly used file descriptors are close-on-exec 2023-04-24 14:20:14 +01:00
matt335672 d712f3527a os_calls: Add g_get_open_fds() 2023-04-24 11:57:38 +01:00
matt335672 b811fdb36b os_calls: Add g_file_{get,set}_cloexec() functions
Allows us to avoid file descriptor leaks when running a new executable
2023-04-24 11:11:04 +01:00