Commit Graph

863 Commits

Author SHA1 Message Date
gpotter2 42b830f124 Rename RDP_INFO flags to spec names, add missing 2026-03-31 21:22:33 +02:00
Matt Cunningham fcc5bd79ea g_tcp_connect fix:
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
  - #define for MAX_PORT_STR length
  - create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
  - add chars host and service which are primarily used for debug logging of attempted connection points
  - calls get_socket_family to discover family of socket
  - add switch case logic for AF_INET6/4:
    - v4: just calls addr_is_ipv6 so we don't fail on a hostname input
    - v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
    - if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
  - getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
  - before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely:  this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
2026-03-23 08:21:29 -04:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 916b6a1667 Merge pull request #3738 from matt335672/fix_ulalaca_char16_t
ulalaca: Don't redefine char16_t and char32_t
2026-02-23 15:00:27 +00:00
matt335672 5fd81ae9cb ulalaca: Don't redefine char16_t and char32_t
On MacOS, stdint.h is provided by the compiler for C, and by
the SDK for C++.

OSX 14.4 appears to define char16_t and char32_t within stdint.h for
C++.  Defining them again results in:

```
../common/arch.h:53:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least16_t char16_t;
                       ^
../common/arch.h:53:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least16_t char16_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
../common/arch.h:54:24: error: cannot combine with previous 'type-name' declaration specifier
typedef uint_least32_t char32_t;
                       ^
../common/arch.h:54:1: warning: typedef requires a name [-Wmissing-declarations]
typedef uint_least32_t char32_t;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
```
2026-02-23 14:22:05 +00:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 661fe2eb0e Merge pull request #3686 from lcniel/add_port_discriminator
Allow sessions to be distinguished based on XRDP instance_name configuration by using new policy
2026-01-26 09:47:02 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
matt335672 6a5d858dce xrdpapi: Add a way to get client connect status
Functions are added to xrdpapi to allows the connection status
to be determimed. These functions are modelled on the Windows API
functions, but are not compatible with them. In particular, the error
handling is different.

A way for an application to receive events is also provided. At present,
only connect/disconnected events are implemented.
2025-12-15 11:26:21 +00:00
matt335672 092e430512 Fix Psssible race condition in g_create_path()
(cherry picked from commit 2e597120443c7dcb0b32f6078999098a364f9543)
2025-12-03 11:00:28 +00:00
matt335672 c31c499372 os_calls: Add NULL_WAIT_OBJ
The wait_obj calls (mostly) ignore objects with a value of zero. This
is codified, so that user code can explicitly make use of this.
2025-11-21 12:33:38 +00:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
matt335672 0bf09425c5 Merge pull request #3657 from firewave/missinclude
enabled and fixed `missingInclude` Cppcheck warnings
2025-11-06 11:20:17 +00:00
firewave 6b816d0c64 common/list.c: fixed -Wcalloc-transposed-args GCC warning
```
/home/user/CLionProjects/xrdp/common/list.c: In function ‘list_create_sized’:
/home/user/CLionProjects/xrdp/common/list.c:50:41: error: ‘calloc’ sizes specified with ‘sizeof’ in the earlier argument and not in the later argument [-Werror=calloc-transposed-args]
   50 |     self = (struct list *)calloc(sizeof(struct list), 1);
      |                                         ^~~~~~
/home/user/CLionProjects/xrdp/common/list.c:50:41: note: earlier argument should specify number of elements, later size of each element
```
2025-11-05 13:51:49 +01:00
firewave d580c8d339 adjusted some includes 2025-11-04 13:41:26 +01:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 733990e9ed Pre-master secret file: Change location for permission setting
Coverity scan picked up on the result on g_chmod_hex() not being
checked. This call has now been moved to the place where the file is
checked for writeability, as we only really need to make it when the
file is created.
2025-09-15 18:28:35 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 0a13316e6a ms-rdpbcgr.h: Rename incorrect slow path constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672 2759680b8b ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672 557b580cb0 ms-rdpbcgr.h : Rename incorrect pointer update constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672 3700867e87 Add timers module
Allows a polled timer to be set for a future event. The timeout
values are suitable for passing to g_obj_wait() or poll().
2025-08-22 12:29:20 +01:00
matt335672 21f663150e Get getgrouplist() compiling on MacOS
(cherry picked from commit 846a268cdcb691adf51e039b21ff201226b6b47b)
2025-07-23 11:38:11 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672 7433ded30d Use correct symbolic names for TS_SET_ERROR_INFO_PDU 2025-07-21 11:30:14 +01:00
matt335672 7baa27a59f Add set_int type
This type can be used to store sets of integers. It is intended to
be used to keep track of the display numbers allocated to sessions and
SCP connections.

A test suite for the new type is also added.
2025-07-07 15:02:51 +01:00
matt335672 4508de05c3 Add macro GUID_ARE_EQUAL for comparing GUIDs 2025-07-07 15:02:51 +01:00
matt335672 dd173d4e9e Merge pull request #3534 from matt335672/factor_out_client_info3
Factor out xup_client_info for xorgxrdp
2025-06-30 10:13:44 +01:00
matt335672 9cd7310d79 Add clarifying note to struct xrdp_client_info 2025-06-30 10:02:24 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 41d4eb5558 Check for xrdp being terminated during SSL_accept BIO loop 2025-05-22 18:03:00 +01:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 d30f5fe22b Coverity CID 468156
Coverity is complaining about 32-bits being truncated to 16-bits.
Make the data conversion to unsigned short explicit.
2025-04-22 14:51:26 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 bc0e169451 Rationalise g_htoi() / xrdp_wm_htoi()
xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
  characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
  whitespace, but terminating on unrecognised characters

An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)

An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.

Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.

The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
2025-03-31 15:36:51 +01:00
matt335672 960ea7ce05 Add support for strlcpy()
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.

This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
2025-03-25 11:08:16 +00:00
matt335672 03c42df566 Merge pull request #3346 from matt335672/restart_sesman
Add restartability to sesman
2025-03-12 11:56:15 +00:00
matt335672 360d23f922 Add g_socket_exist() to OS calls 2025-03-12 10:06:24 +00:00
matt335672 f9a9ed2a68 Add g_readdir_entries() to OS calls 2025-03-12 10:06:22 +00:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 f618965eb7 Fix coverity warning concerning unchecked return
Coverity insists the return value from read() is unchecked. This seems
to not be true to me, but adding a complete sanity check seems to fix
it.
2025-03-10 20:48:05 +00:00
matt335672 39a178902e Improve logging on failed connect attempt 2025-03-08 11:45:26 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 f187d2314c Coverity CID 468117 2025-02-28 14:34:26 +00:00
matt335672 3cc1265adc Add test suite calls for list16
Following a re-write of the list16 module to avoid memory allocation
issues, a test suite is added for the module.
2025-02-27 15:04:11 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00