Commit Graph

1086 Commits

Author SHA1 Message Date
matt335672 a6d80e17ab Code quality: Address Copilot review comments
All accesses to g_drdynvcs[] in chansrv.c have been checked for
unbounded access.
2026-08-14 12:07:48 +01:00
matt335672 77d9b49432 chansrv: Use streams for dynamic channel processing
Change the dynamic channel processing to use streams rather than
a data pointer and a length. This mirrors an earlier commit for
xrdp.

The reason for the change is to make it easier to check for buffer
overflows using standard stream features.
2026-08-12 11:31:47 +01:00
matt335672 63afb676e6 drdynvc: Improve dynamic channel support
The dynamic channel handler in xrdp_channel.c is updated to allow
the procs `data_first` pointer to be NULL. If this is done, the
channel handler performs all the dechunking necessary for the channel,
and only complete data PDUs are passed to procs 'data' callback.

This facility is applied to the dynamic channels supported by xrdp_mm.c.
The incoming callbacks for these channels now provide complete support
for the specification in [MS-RDPEDYC]. The existing channels were
incomplete in these respects:
1) The "Microsoft::Windows::RDS::Graphics" channel handler did not
   support incoming PDUs between 1591 and 1600 bytes. The specification
   calls for these to be sent as a single DATA_FIRST PDU.
2) The "Microsoft::Windows::RDS::DisplayControl" channel handler did
   not support incoming PDUs over 1590 bytes.
2026-08-12 11:31:47 +01:00
matt335672 f745c9152d drdynvc: Change channel processing to use streams
The channel processor in xrdp_channel.c for dynamic streams uses
a data pointer and a length for passing PDUs or PDU fragments. We
replace this with a standard stream pointer, so that the usual
facilities can be used for checking length violcations.
2026-08-12 11:31:47 +01:00
matt335672 a5975210f0 code quality: Forward-port code comments
Minor change to the GFX resize state machine following
review comments on backport to v0.10:

https://github.com/neutrinolabs/xrdp/pull/3834

There are no functional changes as a result of this commit

(cherry picked from commit a2fd7b7ef7c7f7c67b429634d2a1749492198cf2)
2026-07-20 11:35:32 +01:00
metalefty 3af31df3fc Merge commit from fork
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-07-02 17:33:45 +09:00
matt335672 a85e108cdf xrdp.ini: Remove [vnc-any] as a default section
As it stands, this is not suitable for production environments, as
the attached CVE shows.
2026-06-15 10:12:43 +01:00
matt335672 3e39be9c8e CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
Some xrdp -> chansrv messages allocate a fixed-size buffer which
can be overflowed by a malicious RDP client.
2026-05-06 10:32:39 +01:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 084eb2237e Merge commit from fork
CVE-2026-33689: Fix length check on channel open
2026-04-14 16:43:27 +09:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 3c131a9f5e CVE-2026-33689: Fix length check on channel open
A check for at least two bytes remaining in a buffer should be 4 bytes.
2026-03-23 17:38:38 +00:00
matt335672 a11ee461a7 resizing: Simplify GFX resizing
For GFX, we currently resize the client with a deactivation-reactivation
sequence. This is unnecessary, as the GFX RESET_GRAPHICS command does
all the work for us, and avoids the need to teardown and reestablish the
GFX channel.
2026-03-12 17:32:55 +00:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
matt335672 e5d990ca3e Code quality: Prevent undefined shifting behavour
This commit addresses cppcheck errors such as the following:

portability: Shifting a negative value is technically undefined behaviour [shiftNegativeLHS]

Affected variable types are replaced with corresponding unsigned types
2026-02-20 16:02:05 +01:00
matt335672 d3bfe802cc Code quality: Fix some cppcheck messages
This commit addresses these kind of errors:

portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]

Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
2026-02-20 16:02:05 +01:00
matt335672 ce501dff70 Merge pull request #3732 from firewave/cppcheck-style
enabled and fixed some cppcheck `style` checks
2026-02-20 13:53:57 +00:00
tsz8899 d5b3b6a20a xrdp_mm: apply firewave suggestion in setup_mod2 2026-02-18 23:47:16 +08:00
firewave 2fb807391a enabled and fixed unassignedVariable Cppcheck warnings 2026-02-18 11:26:45 +01:00
tsz8899 f2b1b21b6c Coverity: fix recent regressions 0x18 error 2026-02-18 13:25:23 +08:00
matt335672 ea7cea2a97 Coverity: fix recent regressions 2026-02-18 13:25:23 +08:00
tsz8899 8a393c9d0d Fix: Segfault at 0x18 - Upstream Review V3 (Final)
- Removes all redundant NULL checks as per latest feedback.
- Retains C99 inline variable declarations.
- Finalizes local variable snapshotting for race condition safety.
2026-02-06 19:41:11 +08:00
Jay Sorg 5637721f5a add move_cursor 2026-01-30 18:54:57 -08:00
metalefty 488c8c7d4d Merge commit from fork
CVE-2025-68670
2026-01-27 18:17:29 +09:00
Leonard Nielsen 0edde4c090 Introduce instance_name field into xrdp.ini and xrdp-sesrun, along with
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
2026-01-20 12:03:15 +01:00
matt335672 756d415bbc strncpy: Replace some instances
Instances of g_strncpy() in xrdp_wm_parse_domain_information() are
replaced with strlcpy()
2025-12-24 16:57:53 +00:00
matt335672 dd4b56c987 CVE-2025-68670: Buffer overflow parsing domain
A potential overflow in xrdp_wm_parse_domain_information() is
addressed
2025-12-24 16:56:32 +00:00
matt335672 ec604732fd resize_queue: Create before drdynvc is available
If drdynvc is not available for some reason, the resize queue is not
created. This results in a coredump if the display server requests a
resize.
2025-11-24 11:47:27 +00:00
matt335672 834ab918f7 resize queue: Drop unprocessed client requests
If we're adding a new client request to the queue, and the item
immediately before it is also a client request which is not yet actioned,
we can remove the previous item, as it has been superceded.
2025-11-21 12:33:38 +00:00
matt335672 6c90bc2493 Delay processing of the resize queue
Processing of the resize queue is delayed until we've connected to a
session, as the login screen is currently unable to cope with these
requests.
2025-11-21 12:33:38 +00:00
matt335672 64a7c13a77 Tag all resize_queue items with a source
Add a source tag for all the resize_queue items, so we can make
some decisions about queue optimisations.
2025-11-21 12:33:38 +00:00
shua21 ba36dacf95 do not change xvnc port when not using sesman 2025-11-19 22:51:42 +09:00
matt335672 2be66424d2 Add Slovenian keyboard defs for xorgxrdp 2025-11-14 11:12:50 +00:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 9d46ae763d Merge pull request #3658 from matt335672/remove_xrdp_process_casts
Code quality: Remove 'struct xrdp_process *' casts
2025-11-04 09:19:53 +00:00
matt335672 c646002779 Code quality: Remove 'struct xrdp_process *' casts
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.

This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.

The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
2025-11-03 10:34:42 +00:00
matt335672 5853a781b9 Update to cppcheck 2.18.0 2025-10-31 20:30:24 +00:00
Jay Sorg 1cecd786f7 do not delete pid file unless this current pid matches the daemon pid 2025-10-27 10:48:14 -07:00
Jay Sorg 74c2cf31d2 pass frame id back to main thread in jpeg encode 2025-10-27 09:48:33 -07:00
matt335672 1c1a5ebe0f Merge pull request #3600 from matt335672/rfx_segv
Ignore Frame ACKs when the encoder is deleted
2025-10-21 12:02:27 +01:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 127a95e254 struct xrdp_session: Remove void * pointers
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
2025-09-09 15:16:32 +01:00
matt335672 e38a5d0d7d Wording change following review 2025-09-01 09:55:14 +01:00
matt335672 1b1e2317ff xrdp: Don't try to drop privs if we are already unprivileged 2025-08-29 11:33:19 +01:00
matt335672 0afefbbc46 Ignore Frame ACKs when the encoder is deleted
Ignore late frame ACKs from the client if the encoder is mssing.
2025-08-29 11:06:04 +01:00
matt335672 cd98b013f1 Add logging of connect/disconnect times
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.

xrdp-sesadmin can now access the connection data from sesman
2025-07-21 11:30:14 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00