Change the dynamic channel processing to use streams rather than
a data pointer and a length. This mirrors an earlier commit for
xrdp.
The reason for the change is to make it easier to check for buffer
overflows using standard stream features.
The dynamic channel handler in xrdp_channel.c is updated to allow
the procs `data_first` pointer to be NULL. If this is done, the
channel handler performs all the dechunking necessary for the channel,
and only complete data PDUs are passed to procs 'data' callback.
This facility is applied to the dynamic channels supported by xrdp_mm.c.
The incoming callbacks for these channels now provide complete support
for the specification in [MS-RDPEDYC]. The existing channels were
incomplete in these respects:
1) The "Microsoft::Windows::RDS::Graphics" channel handler did not
support incoming PDUs between 1591 and 1600 bytes. The specification
calls for these to be sent as a single DATA_FIRST PDU.
2) The "Microsoft::Windows::RDS::DisplayControl" channel handler did
not support incoming PDUs over 1590 bytes.
The channel processor in xrdp_channel.c for dynamic streams uses
a data pointer and a length for passing PDUs or PDU fragments. We
replace this with a standard stream pointer, so that the usual
facilities can be used for checking length violcations.
Minor change to the GFX resize state machine following
review comments on backport to v0.10:
https://github.com/neutrinolabs/xrdp/pull/3834
There are no functional changes as a result of this commit
(cherry picked from commit a2fd7b7ef7c7f7c67b429634d2a1749492198cf2)
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
For GFX, we currently resize the client with a deactivation-reactivation
sequence. This is unnecessary, as the GFX RESET_GRAPHICS command does
all the work for us, and avoids the need to teardown and reestablish the
GFX channel.
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
This commit addresses cppcheck errors such as the following:
portability: Shifting a negative value is technically undefined behaviour [shiftNegativeLHS]
Affected variable types are replaced with corresponding unsigned types
This commit addresses these kind of errors:
portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]
Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
- Removes all redundant NULL checks as per latest feedback.
- Retains C99 inline variable declarations.
- Finalizes local variable snapshotting for race condition safety.
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
If we're adding a new client request to the queue, and the item
immediately before it is also a client request which is not yet actioned,
we can remove the previous item, as it has been superceded.
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.
This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.
The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.
xrdp-sesadmin can now access the connection data from sesman
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
This allows sesexec to send a reason for a connection close
request to xrdp.
xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.