Commit Graph

855 Commits

Author SHA1 Message Date
matt335672 661fe2eb0e Merge pull request #3686 from lcniel/add_port_discriminator
Allow sessions to be distinguished based on XRDP instance_name configuration by using new policy
2026-01-26 09:47:02 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
matt335672 6a5d858dce xrdpapi: Add a way to get client connect status
Functions are added to xrdpapi to allows the connection status
to be determimed. These functions are modelled on the Windows API
functions, but are not compatible with them. In particular, the error
handling is different.

A way for an application to receive events is also provided. At present,
only connect/disconnected events are implemented.
2025-12-15 11:26:21 +00:00
matt335672 092e430512 Fix Psssible race condition in g_create_path()
(cherry picked from commit 2e597120443c7dcb0b32f6078999098a364f9543)
2025-12-03 11:00:28 +00:00
matt335672 c31c499372 os_calls: Add NULL_WAIT_OBJ
The wait_obj calls (mostly) ignore objects with a value of zero. This
is codified, so that user code can explicitly make use of this.
2025-11-21 12:33:38 +00:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
matt335672 0bf09425c5 Merge pull request #3657 from firewave/missinclude
enabled and fixed `missingInclude` Cppcheck warnings
2025-11-06 11:20:17 +00:00
firewave 6b816d0c64 common/list.c: fixed -Wcalloc-transposed-args GCC warning
```
/home/user/CLionProjects/xrdp/common/list.c: In function ‘list_create_sized’:
/home/user/CLionProjects/xrdp/common/list.c:50:41: error: ‘calloc’ sizes specified with ‘sizeof’ in the earlier argument and not in the later argument [-Werror=calloc-transposed-args]
   50 |     self = (struct list *)calloc(sizeof(struct list), 1);
      |                                         ^~~~~~
/home/user/CLionProjects/xrdp/common/list.c:50:41: note: earlier argument should specify number of elements, later size of each element
```
2025-11-05 13:51:49 +01:00
firewave d580c8d339 adjusted some includes 2025-11-04 13:41:26 +01:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 733990e9ed Pre-master secret file: Change location for permission setting
Coverity scan picked up on the result on g_chmod_hex() not being
checked. This call has now been moved to the place where the file is
checked for writeability, as we only really need to make it when the
file is created.
2025-09-15 18:28:35 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 0a13316e6a ms-rdpbcgr.h: Rename incorrect slow path constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672 2759680b8b ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672 557b580cb0 ms-rdpbcgr.h : Rename incorrect pointer update constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672 3700867e87 Add timers module
Allows a polled timer to be set for a future event. The timeout
values are suitable for passing to g_obj_wait() or poll().
2025-08-22 12:29:20 +01:00
matt335672 21f663150e Get getgrouplist() compiling on MacOS
(cherry picked from commit 846a268cdcb691adf51e039b21ff201226b6b47b)
2025-07-23 11:38:11 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672 7433ded30d Use correct symbolic names for TS_SET_ERROR_INFO_PDU 2025-07-21 11:30:14 +01:00
matt335672 7baa27a59f Add set_int type
This type can be used to store sets of integers. It is intended to
be used to keep track of the display numbers allocated to sessions and
SCP connections.

A test suite for the new type is also added.
2025-07-07 15:02:51 +01:00
matt335672 4508de05c3 Add macro GUID_ARE_EQUAL for comparing GUIDs 2025-07-07 15:02:51 +01:00
matt335672 dd173d4e9e Merge pull request #3534 from matt335672/factor_out_client_info3
Factor out xup_client_info for xorgxrdp
2025-06-30 10:13:44 +01:00
matt335672 9cd7310d79 Add clarifying note to struct xrdp_client_info 2025-06-30 10:02:24 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 41d4eb5558 Check for xrdp being terminated during SSL_accept BIO loop 2025-05-22 18:03:00 +01:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 d30f5fe22b Coverity CID 468156
Coverity is complaining about 32-bits being truncated to 16-bits.
Make the data conversion to unsigned short explicit.
2025-04-22 14:51:26 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 bc0e169451 Rationalise g_htoi() / xrdp_wm_htoi()
xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
  characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
  whitespace, but terminating on unrecognised characters

An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)

An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.

Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.

The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
2025-03-31 15:36:51 +01:00
matt335672 960ea7ce05 Add support for strlcpy()
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.

This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
2025-03-25 11:08:16 +00:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 360d23f922 Add g_socket_exist() to OS calls 2025-03-12 10:06:24 +00:00
matt335672 f9a9ed2a68 Add g_readdir_entries() to OS calls 2025-03-12 10:06:22 +00:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 f618965eb7 Fix coverity warning concerning unchecked return
Coverity insists the return value from read() is unchecked. This seems
to not be true to me, but adding a complete sanity check seems to fix
it.
2025-03-10 20:48:05 +00:00
matt335672 39a178902e Improve logging on failed connect attempt 2025-03-08 11:45:26 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 f187d2314c Coverity CID 468117 2025-02-28 14:34:26 +00:00
matt335672 3cc1265adc Add test suite calls for list16
Following a re-write of the list16 module to avoid memory allocation
issues, a test suite is added for the module.
2025-02-27 15:04:11 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00
Jay Sorg 6dcb8ffe79 add support for nvenc and accel_assist 2025-02-16 17:34:51 -08:00
matt335672 67fbccc539 Address Coverity mutex issues
Coverity has generated a number of 'Data race condition' and 'Double
lock' false positives. A lot of these seem to be caused by the NULL
guard in tc_mutex_unlock() not being paired with a NULL guard in
tc_mutex_lock(). This PR adds a NULL guard to tc_mutex_lock().

It should be noted, that on Linux at least, passing NULL to
tc_mutex_lock() causes a segfault. We clearly aren't doing this at the
moment, or we'd know about it. A log message is generated if a NULL
call is made, rather than failing silently.
2025-02-14 11:57:42 +00:00
matt335672 0f46b7961c Fix Coverity error triggered in utf8_get_next_char() 2025-01-24 11:21:32 +00:00
matt335672 2a4b40a20c Address some Coverity warnings 2025-01-13 15:24:33 +00:00
matt335672 e3d502ca06 Merge pull request #3328 from matt335672/fix_time_calls
Remove/replace time calls
2025-01-06 10:22:40 +00:00
peter15914 e70d316afc Fix possible memory leak 2025-01-05 00:03:34 +05:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 1f79eb1c01 Replace g_time3() with g_get_elapsed_ms()
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.

Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
2024-12-16 16:13:15 +00:00