The Kerberos module and pam_userpass modules are now unused:
1) On all supported systems, PAM provides a far superior way to
integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
(which is a lovely idea) is no longer maintained.
57609d4aa7 introduced an issue where
the numCapabilities field in the DR_CORE_CAPABILITY_REQ PDU
was incorrect unless --enable-smartcard was specified.
This commit also improves the logic around handling clients who
advertise a smartcard even if we do not support it.
The smartcard code contains a number of security vulnerabilities and
does not work at the moment.
The code has been left in the source tree, but moved behind an
'--enable-smartcard' configure flag which is clearly marked as not
for production use.
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.
pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
session type. This mapping is no longer done. We could re-introduce
this code for X11, but there is no such code to detect a wayland
display type. We try to fix this in a forward-looking way by setting
XDG_SESSION_TYPE explicity before starting the PAM session.
2) utmp is not being updated correctly.
The code for setting ut_id in the utmp[x] structure was setting the
same value for all X11 displays, thus preventing utmp from being able
to see more than one xrdp user
Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
This commit addresses these kind of errors:
portability: Passing NULL after the last typed argument to a variadic function leads to undefined behaviour. [varFuncNullUB]
Reason is that C does not guarantee that all pointer types are the same
size. See C99 6.2.5(27). cppcheck requires some sort of cast when NULL
is used as the last argument in a variadic list.
When using UDS mode for VNC, the following error has been reported:
[WARN ] Cannot write VNC password hash to file (null): Bad address
This prevents an attempt to create a file with a NULL name.
the N policy in sesman.ini, allowing xrdp sessions to be tagged with an
instance name to enable persistent association with a specific
xrdp instance, to allow experiences where users reconnect to specific
sessions based on e.g. the xrdp listening port used.
Functions are added to xrdpapi to allows the connection status
to be determimed. These functions are modelled on the Windows API
functions, but are not compatible with them. In particular, the error
handling is different.
A way for an application to receive events is also provided. At present,
only connect/disconnected events are implemented.
The local variable it referenced was never initialized before use. I
replaced it with a reference to the seemingly intended `SERVICE`
preprocessor constant, which is also used in the `pam_start` call
slightly above.
Add an option to allow effectively disable file system space checks for
some file managers before copying files to remote drives.
This is a temporary solution. A better solution is to provide each
remote drive with its own mountpoint, so that the xrdp FUSE filesystem
becomes POSIX compliant.
Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.
(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
The current code doesn't allow for an empty string to be pasted to the
clipboard on the X11 side. This is done by some lock screen programs
to prevent information leakage.
on connection, client IP and name are passed from xrdp to sesman to
sesexec, and then back to sesman again.
xrdp-sesadmin can now access the connection data from sesman
Two problems were found:-
1) A useless test in scp_list.c - testing an unsigned int was >= 0.
2) Flow control issues in scp.c:scp_get_connect_session_response() meant
that file descriptors could be leaked. A helper function has been
used to simplify the code.
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.