The Kerberos module and pam_userpass modules are now unused:
1) On all supported systems, PAM provides a far superior way to
integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
(which is a lovely idea) is no longer maintained.
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.
pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
session type. This mapping is no longer done. We could re-introduce
this code for X11, but there is no such code to detect a wayland
display type. We try to fix this in a forward-looking way by setting
XDG_SESSION_TYPE explicity before starting the PAM session.
2) utmp is not being updated correctly.
The code for setting ut_id in the utmp[x] structure was setting the
same value for all X11 displays, thus preventing utmp from being able
to see more than one xrdp user
Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
The local variable it referenced was never initialized before use. I
replaced it with a reference to the seemingly intended `SERVICE`
preprocessor constant, which is also used in the `pam_start` call
slightly above.
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.
An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
Add an option to allow XAUTHORITY to be moved away from $HOME.
This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
This is not year 2038 compliant on systems with 32-bit integers.
The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
The top level socket directory is now called XRDP_SOCKET_ROOT_PATH.
Below that are user-specific directories referred to with the
XRDP_SOCKET_PATH macro - this name is hard-coded into xorgxrdp and
the audio modules as an environment variable.
XRDP_SOCKET_PATH now looks like $XRDP_SOCKET_ROOT_PATH/<uid>
XRDP_SOCKET_PATH is only writeable by the user, and readable by the user
and the xrdp process.
Improve the built-in access checks for sesman/sesexec:-
- Group existence is checked for at login-time rather than program
start time
- The name of the group is now included in the message
Also, check for UID == 0 when checking for root, rather than just
checking the name (which might be an alias)
This allows Linux's no_new_privs restriction to be disabled when starting
the X server, which may be desirable if xrdp is running inside a kernel
confinement framework such as AppArmor or SELinux.
Rename g_file_open() to g_file_open_rw(), and add a new g_file_open_ro()
call that wraps the common g_file_open_ex(file, 1, 0, 0, 0) idiom. This
will make the file access mode more explicit in the code.
Change all calls to g_file_open() to the _ro() or _rw() variant as
appropriate, and replace g_file_open_ex(file, 1, 0, 0, 0) with the _ro()
call.
Lastly, add tests for the two new calls to test_os_calls.c (code
courteously provided by matt335672).
Now that authentication/authorization and session creation are
happening in the same process, there is no need for a separate call
to finish an auth session. This change prevents the upper software
layers from needing to track whether auth_start_session() has been
called or not.
When allocating a display number, we should be aware that
IANA only allow TCP displays up to :63. This PR adds that restriction in
to sesman.ini as a default, to prevent us allocating unavailable TCP
ports.
By default TCP ports are not enabled for X servers, but users can easily
change this if they wish to access X displays directly over the network.
This restriction is in addition to the MaxSessions limit already present
in sesman.ini
By setting the new config value 'AllowAlternateShell' to 'no' it is now
possible to prevent the use of an alternate shell, which can be set by
the connecting user.
The default remains unchanged and any shell is allowed if the config
value is not specified. It can also be set explicitly to 'yes' to achieve
the same outcome.
Fixes: #850