xrdp contains two functions which do similar things:-
- g_htoi() converts a hex string to an integer, ignoring unrecognised
characters
- xrdp_wm_htoi() converts a hex string to an integer, ignoring leading
whitespace, but terminating on unrecognised characters
An analysis of the uses of g_htoi() shows that the only place where
unrecognised characters might be encountered is parsing lines from
xrdp_keyboard.ini, where all values have an '0x' prefix (i.e. the 'x'
is unrecognised)
An analysis of xrdp_wm_htoi() shows that the functionality to ignore
leading whitespace is not used.
Both functions are replaced with a re-written g_htoi() which is const-
correct and provided with test cases. This function behaves in
the same way as the atoi() library function, in that it terminates on
an unexpected character.
The use of g_htoi() in parsing lines from xrdp_keyboard.ini is replaced
with a call to g_atoix() which handles the '0x' prefix correctly.
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
Too many places in xrdp use strncpy() to copy strings to fixed-length
buffers, when this is not the correct function to use.
This PR makes sure strlcpy() from the BSDs is available as a saner
alternative. This function is available by default on Linux and FreeBSD.
Keyboard layout values from the client such as 00010416 (Brazil ABNT2)
may not have a matching entry in xrdp_keyboard.ini. For these clients,
we map a US keyboard as a fallback.
Before falling back to US, we should first try to match on the lower
16-bits of the layout, which in this case is 0416 (ABNT). This is more
likely to result in something usable.
We already implement this functionality for the keyboard files
used by the login screen and VNC back-end.
1) Restructure lib_mod_connect() along the lines of the PDUs documented
in RFC 6143.
2) Logging in lib_mod_connect() has been revised and improved.
3) Wrinkles around version 3.7 and 3.8 of the RFB protocol are
now addressed.
4) Some new definitions are added to rfb.h to replace the use
of magic numbers.
Revives the currently unused TerminalServerAdmins group.
Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
The KillMode of process allows an xrdp connection to survive a
reatart of the xrdp process. This is of minimal benefit, as a
user can always simply reconnect - the session will survive the
restart. The downside is that xrdp will not benefit from any
security fixes, and may well end up out-of-sync with sesman.
The module is a dummy to be filled in later
Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
be robust enough to stay up for the lifetime of the session so that
the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
doesn't work, as SIGCHLD is not processed while we are waiting for
the session to finish. This needs fixing.
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.
This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS