Commit Graph

846 Commits

Author SHA1 Message Date
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 733990e9ed Pre-master secret file: Change location for permission setting
Coverity scan picked up on the result on g_chmod_hex() not being
checked. This call has now been moved to the place where the file is
checked for writeability, as we only really need to make it when the
file is created.
2025-09-15 18:28:35 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 0a13316e6a ms-rdpbcgr.h: Rename incorrect slow path constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672 2759680b8b ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672 557b580cb0 ms-rdpbcgr.h : Rename incorrect pointer update constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672 3700867e87 Add timers module
Allows a polled timer to be set for a future event. The timeout
values are suitable for passing to g_obj_wait() or poll().
2025-08-22 12:29:20 +01:00
matt335672 21f663150e Get getgrouplist() compiling on MacOS
(cherry picked from commit 846a268cdcb691adf51e039b21ff201226b6b47b)
2025-07-23 11:38:11 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672 7433ded30d Use correct symbolic names for TS_SET_ERROR_INFO_PDU 2025-07-21 11:30:14 +01:00
matt335672 7baa27a59f Add set_int type
This type can be used to store sets of integers. It is intended to
be used to keep track of the display numbers allocated to sessions and
SCP connections.

A test suite for the new type is also added.
2025-07-07 15:02:51 +01:00
matt335672 4508de05c3 Add macro GUID_ARE_EQUAL for comparing GUIDs 2025-07-07 15:02:51 +01:00
matt335672 dd173d4e9e Merge pull request #3534 from matt335672/factor_out_client_info3
Factor out xup_client_info for xorgxrdp
2025-06-30 10:13:44 +01:00
matt335672 9cd7310d79 Add clarifying note to struct xrdp_client_info 2025-06-30 10:02:24 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 41d4eb5558 Check for xrdp being terminated during SSL_accept BIO loop 2025-05-22 18:03:00 +01:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 d30f5fe22b Coverity CID 468156
Coverity is complaining about 32-bits being truncated to 16-bits.
Make the data conversion to unsigned short explicit.
2025-04-22 14:51:26 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 bc0e169451 Rationalise g_htoi() / xrdp_wm_htoi()
xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
  characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
  whitespace, but terminating on unrecognised characters

An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)

An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.

Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.

The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
2025-03-31 15:36:51 +01:00
matt335672 960ea7ce05 Add support for strlcpy()
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.

This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
2025-03-25 11:08:16 +00:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 360d23f922 Add g_socket_exist() to OS calls 2025-03-12 10:06:24 +00:00
matt335672 f9a9ed2a68 Add g_readdir_entries() to OS calls 2025-03-12 10:06:22 +00:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 f618965eb7 Fix coverity warning concerning unchecked return
Coverity insists the return value from read() is unchecked. This seems
to not be true to me, but adding a complete sanity check seems to fix
it.
2025-03-10 20:48:05 +00:00
matt335672 39a178902e Improve logging on failed connect attempt 2025-03-08 11:45:26 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 f187d2314c Coverity CID 468117 2025-02-28 14:34:26 +00:00
matt335672 3cc1265adc Add test suite calls for list16
Following a re-write of the list16 module to avoid memory allocation
issues, a test suite is added for the module.
2025-02-27 15:04:11 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00
Jay Sorg 6dcb8ffe79 add support for nvenc and accel_assist 2025-02-16 17:34:51 -08:00
matt335672 67fbccc539 Address Coverity mutex issues
Coverity has generated a number of 'Data race condition' and 'Double
lock' false positives. A lot of these seem to be caused by the NULL
guard in tc_mutex_unlock() not being paired with a NULL guard in
tc_mutex_lock(). This PR adds a NULL guard to tc_mutex_lock().

It should be noted, that on Linux at least, passing NULL to
tc_mutex_lock() causes a segfault. We clearly aren't doing this at the
moment, or we'd know about it. A log message is generated if a NULL
call is made, rather than failing silently.
2025-02-14 11:57:42 +00:00
matt335672 0f46b7961c Fix Coverity error triggered in utf8_get_next_char() 2025-01-24 11:21:32 +00:00
matt335672 2a4b40a20c Address some Coverity warnings 2025-01-13 15:24:33 +00:00
matt335672 e3d502ca06 Merge pull request #3328 from matt335672/fix_time_calls
Remove/replace time calls
2025-01-06 10:22:40 +00:00
peter15914 e70d316afc Fix possible memory leak 2025-01-05 00:03:34 +05:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 1f79eb1c01 Replace g_time3() with g_get_elapsed_ms()
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.

Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
2024-12-16 16:13:15 +00:00
matt335672 90798cdeaa Remove g_time2() call
This is currently unused in xrdp
2024-12-16 16:13:15 +00:00
matt335672 b02689ab44 Remove g_time1() call
This is not year 2038 compliant on systems with 32-bit integers.

The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
2024-12-16 16:13:15 +00:00
matt335672 31a09f5100 Merge pull request #3304 from matt335672/add_statfs_to_fuse
Add support for statvfs() to FUSE
2024-12-13 11:41:09 +00:00
matt335672 2a190a2264 Fix regression in opening local display in waitforx
Commit 80fab03198 introduced a way to
prevent waitforx going to the network when trying to open a display,
and hence potentially blocking.

This method turned out to be invalidated by libxcb version 1.16 and
1.17

This change adds an explicit check that the Unix socket for the display
in /tmp/.X11-unix/Xn is open before trying to connect to display ':n'.
This has the same effect.
2024-12-11 11:52:06 +00:00
Koichiro Iwao 1964dab4dc Frame capture intervals are not private to xrdp
(cherry picked from commit 56b4ca051e31650c836cab76eaf3e195117269bb)
2024-11-21 20:52:13 +09:00
Koichiro Iwao 7214afb132 Add DEFAULT_ prefix for default frame capture intervals
(cherry picked from commit 65f9ae4afbd5c8c4c608a9014177542d7d4f51a6)
2024-11-21 20:51:57 +09:00
Koichiro Iwao 5fb59a7c38 Set different frame capture interval for H.264 and RFX
and pass them to xorgxrdp.

(cherry picked from commit c55694c51b570d84ad63bfb5dc7bdec75fee57da)
2024-11-18 23:19:35 +09:00
matt335672 5dc4fdbc2c Add support for statvfs() to FUSE
Some desktop environments are now checking for free space before
copying files to a destination.

To support this, the FUSE filesystem needs to convert the statvfs()
system call to the relevent PDUs from [MS-RDPEFS]
2024-11-08 15:57:40 +00:00
matt335672 a958e37e20 Remove calls to SSL_CTX_set_ecdh_auto()
SSL_CTX_set_ecdh_auto() was introduced for  OpenSSL 1.0.2. It
has no effect for OpenSSL 1.1.0 and later. For versions before
1.0.2 and after (and including 1.1.0) it should not be called.

The macro was erroneously being called twice for OpenSSL 3.0.0 and
later - this has also been remedied
2024-10-28 14:15:38 +00:00