The current code doesn't allow for an empty string to be pasted to the
clipboard on the X11 side. This is done by some lock screen programs
to prevent information leakage.
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.
xrdp-sesadmin can now access the connection data from sesman
Two problems were found:-
1) A useless test in scp_list.c - testing an unsigned int was >= 0.
2) Flow control issues in scp.c:scp_get_connect_session_response() meant
that file descriptors could be leaked. A helper function has been
used to simplify the code.
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.
This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
1) Remove 'magic numbers' related to static channel name lengths, and
replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
the [Channels] section of xrdp.ini.
(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.
An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
The module is a dummy to be filled in later
Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
be robust enough to stay up for the lifetime of the session so that
the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
doesn't work, as SIGCHLD is not processed while we are waiting for
the session to finish. This needs fixing.
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.
This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.
We do this quite a lot.
I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.
Many of these checks are in test programs or example programs.
I've modified the list16 module to handle out-of-memory conditions.
This Coverity issue was encountered in a private build, but does not
appear to be in the Github CI build. Coverity is suspecting a copy-paste
betweem these lines in sound.c:-
1838: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], i);
1844: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], g_bytes_in_stream);
An inspection of the code shows this to bre a false positive