Commit Graph

5367 Commits

Author SHA1 Message Date
Liyi Meng 92fdb09959 chansrv: Fix stale engine handling and cross-thread ibus commit
A few follow-on fixes found while testing the ibus reconnect changes
in a live session:

- xrdp_input_unicode_init() failed outright if ibus had no default
  global engine yet at connect time, which is a normal state on a
  fresh session (nothing has chosen one yet), not an error. Since
  nothing else used the return value, this permanently killed unicode
  input for the whole session over a spurious check.

- ibus can disable our engine instance (e.g. on a focus change) while
  leaving the global engine name as "XrdpIme", since those are tracked
  separately. xrdp_input_enable()'s fast path only checked the name,
  so it could skip re-asserting and leave xrdp_input_send_unicode()
  committing text through a disabled g_engine. Clear g_engine on
  disable and require it to be set for the fast path to apply.

- ibus_engine_commit_text() was being called from chansrv's own
  thread, not the thread pumping the glib main loop that owns the
  engine's D-Bus connection (xrdp_input_main_loop). Marshal the actual
  commit through g_main_context_invoke() onto the correct thread.

None of these are the full fix for intermittent dropped commits during
real pinyin input testing - that's still open, with the current lead
being ibus Reset calls interleaved with commit bursts, likely from the
FocusOut/FocusIn churn caused by passing every raw keystroke through
engine_process_key_event_cb. To be continued.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-17 20:38:20 +00:00
Liyi Meng 38c8db8293 chansrv: Reconnect ibus when the cached connection has gone stale
Fixes #3230. The static `bus` global was only ever checked for
non-NULL, not for whether the underlying connection was still alive.
If ibus disconnected (daemon restart, stale socket) or the initial
connect attempt failed, `bus` was left set to a dead/freed connection,
so every later call to xrdp_input_unicode_init() took the "already
initialized" fast path and operated on it.

- Null out bus/g_engine in the "disconnected" signal handler instead
  of leaving them dangling after g_object_unref().
- Check ibus_bus_is_connected() before trusting a cached bus, and
  tear down + reconnect if it's stale.
- Unref and clear bus on a failed connect attempt instead of leaving
  it set.
- Guard the unrefs in xrdp_input_unicode_destroy() now that bus/
  g_engine can legitimately already be NULL.
2026-08-17 08:59:18 +00:00
Liyi Meng 913ea383d7 Add dev container 2026-08-17 08:58:29 +00:00
matt335672 a02ed62782 Merge pull request #3845 from matt335672/rdpedyc_data_fragments
dechunker: Add support for dynamic virtual channels.
2026-08-14 12:19:49 +01:00
matt335672 a6d80e17ab Code quality: Address Copilot review comments
All accesses to g_drdynvcs[] in chansrv.c have been checked for
unbounded access.
2026-08-14 12:07:48 +01:00
matt335672 f4249b3ca6 chansrv: Use common dynamic dechunker
Addresses CVE-2026-69169

The dynamic channel processing in chansrv is updated to allow
the dechunker to be invoked automatically if the 'data_first' proc
is set to NULL. This mirrors a change made to the xrdp_channel.c.

The processor for the AUDIO_IN channel is updated to take advantage of
this, significantly simplifing the code.
2026-08-14 12:06:20 +01:00
matt335672 77d9b49432 chansrv: Use streams for dynamic channel processing
Change the dynamic channel processing to use streams rather than
a data pointer and a length. This mirrors an earlier commit for
xrdp.

The reason for the change is to make it easier to check for buffer
overflows using standard stream features.
2026-08-12 11:31:47 +01:00
matt335672 63afb676e6 drdynvc: Improve dynamic channel support
The dynamic channel handler in xrdp_channel.c is updated to allow
the procs `data_first` pointer to be NULL. If this is done, the
channel handler performs all the dechunking necessary for the channel,
and only complete data PDUs are passed to procs 'data' callback.

This facility is applied to the dynamic channels supported by xrdp_mm.c.
The incoming callbacks for these channels now provide complete support
for the specification in [MS-RDPEDYC]. The existing channels were
incomplete in these respects:
1) The "Microsoft::Windows::RDS::Graphics" channel handler did not
   support incoming PDUs between 1591 and 1600 bytes. The specification
   calls for these to be sent as a single DATA_FIRST PDU.
2) The "Microsoft::Windows::RDS::DisplayControl" channel handler did
   not support incoming PDUs over 1590 bytes.
2026-08-12 11:31:47 +01:00
matt335672 f745c9152d drdynvc: Change channel processing to use streams
The channel processor in xrdp_channel.c for dynamic streams uses
a data pointer and a length for passing PDUs or PDU fragments. We
replace this with a standard stream pointer, so that the usual
facilities can be used for checking length violcations.
2026-08-12 11:31:47 +01:00
matt335672 e4b0621229 tests: Add tests for dynamic dechunker 2026-08-12 11:19:47 +01:00
matt335672 0a986869cc dechunker: Add handler for Dynamic channels 2026-08-11 15:02:49 +01:00
matt335672 fe850a22c0 Merge pull request #3839 from matt335672/add_dechunker
Add dechunker module
2026-07-28 10:46:27 +01:00
matt335672 3d137431a9 Merge pull request #3837 from the-deniss/fix/trans_force_read_s-bounds-check-uses-wrong-pointer
Fix for trans_force_read_s Bounds Check Uses Wrong Pointer
2026-07-28 10:10:45 +01:00
Denis Skvortsov b36ad7b2d0 Cast to size_t in bounds macros; drop resulting dead check 2026-07-27 15:35:26 +03:00
Denis Skvortsov e4f4364c9b Remove check to avoid -Wtype-limits 2026-07-25 18:47:19 +03:00
Denis Skvortsov 5ae11e2a37 Harden stream bounds checks against pointer-arithmetic overflow 2026-07-25 17:46:28 +03:00
matt335672 2e8a4a82e1 test suite: Add way to run individual common tests 2026-07-23 19:20:28 +01:00
matt335672 3ef2f8830a Dechunker: Add tests 2026-07-23 19:20:28 +01:00
matt335672 be95ba3017 dechunker: Create separate module for dechunking
The code in xrdp_channel.c to handle dechunking on a virtual channel is
moved to a separate module to allow for better sharing of logic.
2026-07-23 19:20:28 +01:00
Denis Skvortsov a2d130bc5b Fix for trans_force_read_s Bounds Check Uses Wrong Pointer 2026-07-22 12:03:58 +03:00
matt335672 de284747ae Merge pull request #3836 from matt335672/update_gfx_state_machine
code quality: Forward-port code review comments
2026-07-20 14:14:39 +01:00
matt335672 a5975210f0 code quality: Forward-port code comments
Minor change to the GFX resize state machine following
review comments on backport to v0.10:

https://github.com/neutrinolabs/xrdp/pull/3834

There are no functional changes as a result of this commit

(cherry picked from commit a2fd7b7ef7c7f7c67b429634d2a1749492198cf2)
2026-07-20 11:35:32 +01:00
matt335672 8812646d0f Merge pull request #3829 from the-deniss/fix/dynvc-multi-chunk-reassembly-logic-defects
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-16 10:47:51 +01:00
matt335672 c73c827e5a compilation: Fix errors
Fix compilation issues with b824c93b86
2026-07-16 10:41:40 +01:00
Denis Skvortsov b824c93b86 Fix for DYNVC Multi-Chunk Reassembly Logic Defects 2026-07-15 17:24:30 +03:00
metalefty 3af31df3fc Merge commit from fork
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-07-02 17:33:45 +09:00
metalefty bb0c5984c2 Merge commit from fork
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty 5642decb5f Merge commit from fork
CVE-2026-41521: lib_framebuffer_update int overflow
2026-07-02 17:24:29 +09:00
metalefty 4bf38e3d8e Merge commit from fork
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
2026-07-02 17:22:04 +09:00
metalefty 2c2eff3b59 Merge commit from fork
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty 0aae834802 Merge commit from fork
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty 0af3b1ecf8 Merge commit from fork
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty b3e1a5f17d Merge commit from fork
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
metalefty 9627823a1b Merge commit from fork
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-07-01 08:51:16 +09:00
Koichiro Iwao f76a30b577 CVE-2026-55626: Disable Xvnc TCP listning in UDS mode 2026-06-24 08:42:09 +09:00
matt335672 492bd7ed4d Merge pull request #3813 from matt335672/update_librfxcodec
librfxcodec: Update to latest version in devel
2026-06-23 09:45:17 +01:00
matt335672 fea7f56280 librfxcodec: Update to latest version in devel
Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
2026-06-23 09:27:21 +01:00
matt335672 21d38d0c1e Merge pull request #3811 from matt335672/fix_cve_2026_42218_regression
sesexec: Fix CVE-2026-42218 regression
2026-06-17 10:08:51 +01:00
matt335672 d4d20fc82d sesexec: Fix CVE-2026-42218 regression
cppcheck has picked up on the use of an unitialised variable in
the implementation of the fix for CVE-2026-42218
2026-06-17 09:54:06 +01:00
matt335672 6cb996e355 Merge pull request #3698 from lcniel/enable_token_with_auto_logon
Allow username-affixed token to be used with INFO_AUTOLOGON flag set in client
2026-06-17 09:36:43 +01:00
matt335672 4aa8bdf1ea CVE-2026-55238: Possible OOB reads in capability processing
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672 9d16ec4e75 CVE-2026-55639: OOB read in GCC Conference Create Request 2026-06-17 09:18:20 +01:00
matt335672 b1edb60c1d CVE-2026-55645: OOB read in Client Control PDU processing 2026-06-17 09:14:18 +01:00
matt335672 2394084bf4 CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER 2026-06-16 09:50:01 +01:00
matt335672 a85e108cdf xrdp.ini: Remove [vnc-any] as a default section
As it stands, this is not suitable for production environments, as
the attached CVE shows.
2026-06-15 10:12:43 +01:00
matt335672 9834a58ca6 CVE-2026-41252: lib_palette_update Heap Buffer Overflow 2026-06-15 10:12:00 +01:00
metalefty c56a3ea202 Merge commit from fork
CVE-2026-42218: Ensure auth fails take a fixed time
2026-06-15 15:40:24 +09:00
Leonard Nielsen 40c1a316f4 Allow for token logon even with INFO_AUTOLOGON flag set 2026-06-11 14:40:59 +02:00
matt335672 f94ae70148 Use symbols for desktop size limits 2026-06-08 11:12:07 +01:00
matt335672 2a94fc9674 CVE-2026-41521: lib_framebuffer_update int overflow
An integer overflow can lead to possible heap info leak and ASLR
bypass.
2026-05-12 10:23:11 +01:00