The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.
pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
session type. This mapping is no longer done. We could re-introduce
this code for X11, but there is no such code to detect a wayland
display type. We try to fix this in a forward-looking way by setting
XDG_SESSION_TYPE explicity before starting the PAM session.
2) utmp is not being updated correctly.
The code for setting ut_id in the utmp[x] structure was setting the
same value for all X11 displays, thus preventing utmp from being able
to see more than one xrdp user
Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
This commit addresses these kind of errors:
portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]
Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
When using UDS mode for VNC, the following error has been reported:
[WARN ] Cannot write VNC password hash to file (null): Bad address
This prevents an attempt to create a file with a NULL name.
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.
(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.
xrdp-sesadmin can now access the connection data from sesman
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.
This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.
An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
The module is a dummy to be filled in later
Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
be robust enough to stay up for the lifetime of the session so that
the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
doesn't work, as SIGCHLD is not processed while we are waiting for
the session to finish. This needs fixing.
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.
This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
Add an option to allow XAUTHORITY to be moved away from $HOME.
This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
This is not year 2038 compliant on systems with 32-bit integers.
The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
g_strncpy() is the wrong function for copying strings in struct utmp[x]
as it always terminates strings.
strncpy() itself would be a good choice, but is marked by many compilers
as being unsafe to use.
str2memcpy() is taken from util-linux, and is exactly right for this
application.
POSIX.1 doesn't define ut_host in struct utmpx. Also, Linux has support
for an exit status value in ut_exit. This commit adds conditional code
for both ut_host and ut_exit to maximise portability.