matt335672
6831249bed
CVE-2026-33516 : Address potential OOB read
...
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
matt335672
2dfe8bbce2
Merge pull request #3729 from matt335672/remove_display_num
...
Remove X11 display number from xrdp interfaces
2026-03-04 14:45:56 +00:00
matt335672
12102934b3
code quality: Address Copilot review comments
2026-03-04 14:34:34 +00:00
matt335672
0c92f5f5a2
xorgxrdp: Rename socket files
2026-03-04 14:34:34 +00:00
matt335672
c4727ad8f3
Replace X11 display number with a display string
...
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
matt335672
d56408a891
authentication: Replace display number with string
...
The display number is a concept which won't exist for Wayland displays.
We use a display nuimber instead.
2026-03-04 14:32:21 +00:00
matt335672
656a125cc0
utmp: Remove display number from interface
...
The display number will not be a valid concept for Wayland, so the
display number parameter is replaced with a display string.
2026-03-04 14:32:21 +00:00
matt335672
fd43cd5d85
CI: Prevent some format truncation errors
2026-03-04 14:32:21 +00:00
matt335672
fea345d75a
Merge pull request #3739 from firewave/cppcheck-style-xxx
...
fixed some `unreadVariable` Cppcheck warnings
2026-03-04 14:25:59 +00:00
matt335672
65ab126b95
Merge pull request #3659 from firewave/ubsan
...
build.yml: added sanitized build with UndefinedBehaviorSanitizer
2026-03-04 13:43:16 +00:00
firewave
fd4af1b346
build.yml: added sanitized build with UndefinedBehaviorSanitizer
2026-03-03 16:40:38 +01:00
firewave
214cf50df5
fixed some unreadVariable Cppcheck warnings
2026-03-03 16:33:51 +01:00
matt335672
3db1c993bf
Merge pull request #3743 from matt335672/cppcheck_2_20
...
cppcheck: Bump version to 2.20
2026-03-03 15:14:37 +00:00
matt335672
237821f2e1
Merge pull request #3741 from matt335672/logging_comment
...
xorgxrdp: Add logging hint
2026-03-03 11:16:17 +00:00
matt335672
32810ecbbb
cppcheck: Bump version to 2.20
2026-03-03 11:15:41 +00:00
matt335672
fe32e2e2d4
xorgxrdp: Add logging hint
...
Add commented out lines to the [Xorg] stanza in sesman.ini to get full
logging for xorgxrdp
2026-02-26 19:12:48 +00:00
matt335672
916b6a1667
Merge pull request #3738 from matt335672/fix_ulalaca_char16_t
...
ulalaca: Don't redefine char16_t and char32_t
2026-02-23 15:00:27 +00:00
matt335672
5fd81ae9cb
ulalaca: Don't redefine char16_t and char32_t
...
On MacOS, stdint.h is provided by the compiler for C, and by
the SDK for C++.
OSX 14.4 appears to define char16_t and char32_t within stdint.h for
C++. Defining them again results in:
```
../common/arch.h:53:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least16_t char16_t;
^
../common/arch.h:53:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least16_t char16_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
../common/arch.h:54:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least32_t char32_t;
^
../common/arch.h:54:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least32_t char32_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
```
2026-02-23 14:22:05 +00:00
matt335672
352edc3dba
Merge pull request #3731 from firewave/cppcheck-portability
...
enabled and fixed cppcheck `portability` checks
2026-02-20 15:55:08 +00:00
matt335672
e5d990ca3e
Code quality: Prevent undefined shifting behavour
...
This commit addresses cppcheck errors such as the following:
portability: Shifting a negative value is technically undefined behaviour [shiftNegativeLHS]
Affected variable types are replaced with corresponding unsigned types
2026-02-20 16:02:05 +01:00
matt335672
d3bfe802cc
Code quality: Fix some cppcheck messages
...
This commit addresses these kind of errors:
portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]
Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672
94c0024c3b
passwd_unix: Change salt if password is changed
2026-02-20 16:02:05 +01:00
firewave
416aa53157
enabled cppcheck portability checks
2026-02-20 16:02:05 +01:00
matt335672
ce501dff70
Merge pull request #3732 from firewave/cppcheck-style
...
enabled and fixed some cppcheck `style` checks
2026-02-20 13:53:57 +00:00
matt335672
588fac89f2
Merge pull request #3734 from tsz8899/tsz/coverity-fix-recent-regressions-0x18
...
coverity fix recent regressions
2026-02-18 17:32:24 +00:00
tsz8899
d5b3b6a20a
xrdp_mm: apply firewave suggestion in setup_mod2
2026-02-18 23:47:16 +08:00
firewave
2fb807391a
enabled and fixed unassignedVariable Cppcheck warnings
2026-02-18 11:26:45 +01:00
tsz8899
f2b1b21b6c
Coverity: fix recent regressions 0x18 error
2026-02-18 13:25:23 +08:00
matt335672
ea7cea2a97
Coverity: fix recent regressions
2026-02-18 13:25:23 +08:00
firewave
077dbbcba9
enabled some cppcheck style checks
2026-02-17 19:01:19 +01:00
matt335672
bbd950d552
Merge pull request #3726 from matt335672/rfb_auth_fixes
...
RFB authentication: Undefined behaviour fix
2026-02-12 12:20:09 +00:00
matt335672
8b252fb462
VNC auth: Do not try to create empty file
...
When using UDS mode for VNC, the following error has been reported:
[WARN ] Cannot write VNC password hash to file (null): Bad address
This prevents an attempt to create a file with a NULL name.
2026-02-12 11:50:09 +00:00
matt335672
7fcec1e6da
Harden env_check_password_file()
...
env_check_password_file() does not check its parameters are non-NULL.
This commit simply adds those checks.
2026-02-12 11:48:54 +00:00
matt335672
b3ab2c28d8
Merge pull request #3695 from akarl10/user-shell-environment-fix
...
User shell environment fix
2026-02-12 11:26:52 +00:00
matt335672
eb4514210d
Merge pull request #3719 from tsz8899/fix/segfault-at-0x18-robustness
...
Fix: Segfault at 0x18 due to race condition between UI destruction and event dispatching
2026-02-06 11:54:11 +00:00
tsz8899
8a393c9d0d
Fix: Segfault at 0x18 - Upstream Review V3 (Final)
...
- Removes all redundant NULL checks as per latest feedback.
- Retains C99 inline variable declarations.
- Finalizes local variable snapshotting for race condition safety.
2026-02-06 19:41:11 +08:00
jsorg71
4d9dde8ea0
Merge pull request #3714 from jsorg71/move_cursor
...
add move_cursor
2026-02-02 21:15:03 -08:00
Jay Sorg
5637721f5a
add move_cursor
2026-01-30 18:54:57 -08:00
metalefty
488c8c7d4d
Merge commit from fork
...
CVE-2025-68670
2026-01-27 18:17:29 +09:00
matt335672
661fe2eb0e
Merge pull request #3686 from lcniel/add_port_discriminator
...
Allow sessions to be distinguished based on XRDP instance_name configuration by using new policy
2026-01-26 09:47:02 +00:00
Leonard Nielsen
0edde4c090
Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
...
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
akarl10
c1ed8b8eb6
[sesexec] pass_shell_as_env only if user sets a shell
...
set environment variable only if the user actually requests a specific
shell.
2026-01-18 10:27:47 +01:00
metalefty
c7b83c47b3
Merge pull request #3700 from matt335672/cppcheck_2_19
...
cppcheck: Bump version to 2.19.1
2026-01-15 20:35:02 +09:00
matt335672
311a88f1fc
cppcheck: Bump version to 2.19.1
2026-01-13 10:31:38 +00:00
matt335672
1cab2d91da
Merge pull request #3694 from matt335672/coverity_fix
...
Coverity: Fix TAINTED_SCALAR warning
2025-12-29 11:24:02 +00:00
matt335672
28c1cbea97
Coverity: Fix TAINTED_SCALAR warning
2025-12-29 11:02:21 +00:00
matt335672
846a32a6b4
Merge pull request #3640 from matt335672/xrdpapi_connect_status
...
xrdpapi: Add a way to monitor connect/disconnect events
2025-12-28 11:39:07 +00:00
matt335672
9c5ee210cd
xrdpapi: Fix simple test regression
2025-12-28 11:34:06 +00:00
matt335672
756d415bbc
strncpy: Replace some instances
...
Instances of g_strncpy() in xrdp_wm_parse_domain_information() are
replaced with strlcpy()
2025-12-24 16:57:53 +00:00
matt335672
dd4b56c987
CVE-2025-68670: Buffer overflow parsing domain
...
A potential overflow in xrdp_wm_parse_domain_information() is
addressed
2025-12-24 16:56:32 +00:00