Commit Graph

75 Commits

Author SHA1 Message Date
matt335672 53bc57cf59 security: Exit on failure of env_set_user()
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
matt335672 3444f9a1e0 regression: Audio modules
Following on from the display number removal, the code to set
the environment variables for the audio modules has been discovered
to be incorrect.
2026-03-16 10:47:46 +00:00
matt335672 defb1bcba4 regression: Display number related issues
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.

   pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
   session type. This mapping is no longer done. We could re-introduce
   this code for X11, but there is no such code to detect a wayland
   display type. We try to fix this in a forward-looking way by setting
   XDG_SESSION_TYPE explicity before starting the PAM session.

2) utmp is not being updated correctly.

   The code for setting ut_id in the utmp[x] structure was setting the
   same value for all X11 displays, thus preventing utmp from being able
   to see more than one xrdp user

Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
2026-03-11 13:17:33 +00:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 0c92f5f5a2 xorgxrdp: Rename socket files 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
matt335672 d56408a891 authentication: Replace display number with string
The display number is a concept which won't exist for Wayland displays.
We use a display nuimber instead.
2026-03-04 14:32:21 +00:00
matt335672 656a125cc0 utmp: Remove display number from interface
The display number will not be a valid concept for Wayland, so the
display number parameter is replaced with a display string.
2026-03-04 14:32:21 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 8b252fb462 VNC auth: Do not try to create empty file
When using UDS mode for VNC, the following error has been reported:

[WARN ] Cannot write VNC password hash to file (null): Bad address

This prevents an attempt to create a file with a NULL name.
2026-02-12 11:50:09 +00:00
matt335672 7fcec1e6da Harden env_check_password_file()
env_check_password_file() does not check its parameters are non-NULL.
This commit simply adds those checks.
2026-02-12 11:48:54 +00:00
matt335672 b3ab2c28d8 Merge pull request #3695 from akarl10/user-shell-environment-fix
User shell environment fix
2026-02-12 11:26:52 +00:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
akarl10 c1ed8b8eb6 [sesexec] pass_shell_as_env only if user sets a shell
set environment variable only if the user actually requests a specific
shell.
2026-01-18 10:27:47 +01:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 d95893a8c3 Coverity: Fix CHECKED_RETURN warning 2025-10-31 14:20:02 +00:00
matt335672 6b6edca8ca session management: Allow for restricted shells
Allows the AlternateShell specified by the user in the TS_INFO_PACKET
to be passed to startwm.sh as an environment variable.
2025-10-28 10:04:03 +00:00
matt335672 4ae0cb75b9 Fix regression in PAM groups handling
Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.

(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
2025-08-25 13:22:31 +01:00
matt335672 416a5e66e5 Fix compilation failure in Deepin 20 2025-07-23 09:56:31 +01:00
matt335672 159947ca9b Minor logging improvement 2025-07-21 11:30:14 +01:00
matt335672 f371876e8c Set XRDP_CLIENT_xx variables for the reconnect script 2025-07-21 11:30:14 +01:00
matt335672 cd98b013f1 Add logging of connect/disconnect times
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.

xrdp-sesadmin can now access the connection data from sesman
2025-07-21 11:30:14 +01:00
matt335672 db50a27089 Remove unnecessary include from session.h 2025-07-21 11:30:14 +01:00
matt335672 d88cf53453 Add CCP support to sesexec
sesexec can now tell the xrdp process to exit, and is aware when
the xrdp process exits.
2025-07-21 11:30:14 +01:00
matt335672 b5ba5635e1 Replace unneeded callback data value 2025-07-21 11:30:14 +01:00
matt335672 cf202d618b Add AlwaysRunReconnect config option
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
2025-07-14 19:39:26 +01:00
matt335672 09e4a99bac Plumb connect_session call into sesman and sesexec 2025-07-14 19:39:26 +01:00
matt335672 3e38d9be80 Rework the start session method in SCP
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.

This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
2025-07-07 20:09:20 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 5cf0ec8f34 Add a StartupWaitTime parameter
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
2025-03-29 17:52:47 +00:00
matt335672 9225fe0686 Fill in discovery module
Add functionality to sesexec discovery module to enable sesman
restarts.
2025-03-12 11:08:03 +00:00
matt335672 0a584204a2 Add sesexec_set_ecp_transport/sesexec_is_ecp_active()
These sesexec functions are needed for the discovery module to
function.
2025-03-12 11:08:03 +00:00
matt335672 bee806d3af Add sesexec discover module
The module is a dummy to be filled in later

Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
   causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
   be robust enough to stay up for the lifetime of the session so that
   the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
   doesn't work, as SIGCHLD is not processed while we are waiting for
   the session to finish. This needs fixing.
2025-03-12 11:08:03 +00:00
matt335672 eadbb6a190 Add session_get_parameters()
Also add useful comment to session_send_term()
2025-03-12 11:08:03 +00:00
matt335672 d55c7e7cb7 Remove commented-out code
The function sesexce_scp_data_in in sesexec.c is a development
artefact and can safely be removed
2025-03-12 10:03:15 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 6979df55ee Add new session type SCP_SESSION_TYPE_XVNC_UDS
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.

This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
2025-03-08 11:45:26 +00:00
matt335672 e8a0699bb4 Merge pull request #3393 from matt335672/xauth_in_sysdir
Add XAuthorityInSystemDir option
2025-03-03 13:38:09 +00:00
matt335672 2a4b40a20c Address some Coverity warnings 2025-01-13 15:24:33 +00:00
matt335672 d2e96fe2d2 Add XAuthorityInSystemDir option
Add an option to allow XAUTHORITY to be moved away from $HOME.

This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
2025-01-13 11:51:27 +00:00
matt335672 e3d502ca06 Merge pull request #3328 from matt335672/fix_time_calls
Remove/replace time calls
2025-01-06 10:22:40 +00:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 b02689ab44 Remove g_time1() call
This is not year 2038 compliant on systems with 32-bit integers.

The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
2024-12-16 16:13:15 +00:00
firewave fb9c175b11 enabled and fixed -Wmissing-prototypes compiler warnings
Co-authored-by: matt335672 <30179339+matt335672@users.noreply.github.com>
2024-04-23 18:38:20 +02:00
matt335672 8cea9b03ab Replace g_strncpy() with str2memcpy()
g_strncpy() is the wrong function for copying strings in struct utmp[x]
as it always terminates strings.

strncpy() itself would be a good choice, but is marked by many compilers
as being unsafe to use.

str2memcpy() is taken from util-linux, and is exactly right for this
application.
2024-02-21 09:24:48 +00:00
matt335672 b53c683edf Allow some utmpx fields to be optional
POSIX.1 doesn't define ut_host in struct utmpx. Also, Linux has support
for an exit status value in ut_exit. This commit adds conditional code
for both ut_host and ut_exit to maximise portability.
2024-02-21 09:24:48 +00:00
matt335672 04c67a5039 Set ut_id field
The utmp record is generally looked up by the ut_id field. Setting
this field means we can use a blank username and host when the
session exits
2024-02-21 09:24:48 +00:00
matt335672 98d6545566 Don't use DEAD_PROCESS/USER_PROCESS for add_xtmp_entry
If we're not compiling with USE_UTMP, these defines will not
be available
2024-02-21 09:24:48 +00:00
matt335672 3b6c9bcba3 Add --enable-utmp to configure.ac 2024-02-21 09:24:48 +00:00