Commit Graph

5154 Commits

Author SHA1 Message Date
matt335672 93707e976f Merge pull request #3547 from matt335672/scp_changes
SCP updates : connect session message
2025-07-21 11:29:05 +01:00
matt335672 02eae9f3ba Fix Coverity warnings
Two problems were found:-
1) A useless test in scp_list.c - testing an unsigned int was >= 0.
2) Flow control issues in scp.c:scp_get_connect_session_response() meant
   that file descriptors could be leaked. A helper function has been
   used to simplify the code.
2025-07-15 11:46:57 +01:00
matt335672 cf202d618b Add AlwaysRunReconnect config option
This allows the system administrator to specify whether the
reconnectwm.sh script should only be run on reconnects, or should
be run for all connections to a session.
2025-07-14 19:39:26 +01:00
matt335672 8bcb14f79d Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
2025-07-14 19:39:26 +01:00
matt335672 d0a876ed47 Update xrdp-sesrun for new SCP interface
The SCP connection is now still open after a create session call,
and needs to be explicitly closed to prevent errors being logged.
2025-07-14 19:39:26 +01:00
matt335672 c1a42af7a2 Plumb file descriptors from sesman into xrdp
If sesman sends file descriptors for the display server and
chansrv, use these in preference to trans_connect() calls.
2025-07-14 19:39:26 +01:00
matt335672 3425ab6166 Add optional fd parameter to mod_connect() method
The fd parameter can be used to immediately connect to a display
server, if an fd was obtained from sesman
2025-07-14 19:39:26 +01:00
matt335672 09e4a99bac Plumb connect_session call into sesman and sesexec 2025-07-14 19:39:26 +01:00
matt335672 602f3b495b Add session connect to libipm sesexec interfaces 2025-07-07 20:09:20 +01:00
matt335672 f52f4778eb Update SCP with connect session calls 2025-07-07 20:09:20 +01:00
matt335672 3e38d9be80 Rework the start session method in SCP
The start session method is reworked to pass a response back to the
client.
If the method was successful, a session list entry is created. This
is different to the provious behaviour, where we created the
session list entry unconditionally.

This new arrangement means that we need a different way to avoid
a race condition where two users may try to create a session at the
same time, and end up with the same display. We do this by keeping
track of newly allocated displays as part of the SCP connections. When
we allocate a display, the SCP connection displays are also taken
into account.
2025-07-07 20:09:20 +01:00
matt335672 7baa27a59f Add set_int type
This type can be used to store sets of integers. It is intended to
be used to keep track of the display numbers allocated to sessions and
SCP connections.

A test suite for the new type is also added.
2025-07-07 15:02:51 +01:00
matt335672 4508de05c3 Add macro GUID_ARE_EQUAL for comparing GUIDs 2025-07-07 15:02:51 +01:00
matt335672 ee8739a3f5 Update scp_list.h 2025-07-07 15:02:51 +01:00
matt335672 4d990cfc16 Rename the pre-session list to the SCP list
The name pre-session list makes no sense now, as we need items
to remain on the list after starting the session and before
connecting.
2025-07-07 15:02:51 +01:00
matt335672 fb77c37a61 Merge pull request #3564 from matt335672/refactor_server_methods
Remove global mod server methods from xrdp.h
2025-07-07 15:00:33 +01:00
matt335672 0680ac54ef Remove mod server methods from xrdp.h
The server methods listed in xrdp.h do not need to be global, and
can simply be statics within xrdp_mm.c
2025-07-07 14:33:31 +01:00
matt335672 dd173d4e9e Merge pull request #3534 from matt335672/factor_out_client_info3
Factor out xup_client_info for xorgxrdp
2025-06-30 10:13:44 +01:00
matt335672 9cd7310d79 Add clarifying note to struct xrdp_client_info 2025-06-30 10:02:24 +01:00
matt335672 2e8230686b Merge pull request #3531 from matt335672/fix_ssl_tls_accept
Check for xrdp being terminated during SSL_accept BIO loop
2025-06-30 09:54:37 +01:00
matt335672 7c2154fba3 Merge pull request #3545 from matt335672/chansrv_double_free
Prevent possible double-free on chansrv exit
2025-06-21 14:52:33 +01:00
matt335672 539eb33795 Prevent possible double-free on chansrv exit 2025-06-21 14:38:06 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 41d4eb5558 Check for xrdp being terminated during SSL_accept BIO loop 2025-05-22 18:03:00 +01:00
matt335672 322b6c2642 Merge pull request #3512 from matt335672/xrdp_keyboard_ini_to_toml
Xrdp keyboard ini to toml
2025-05-21 11:47:38 +01:00
matt335672 8c130d0b89 Replace xrdp_keyboard.ini with xrdp_keyboard.toml 2025-05-21 11:38:21 +01:00
matt335672 312d9b88db Update TOML C99 library
From https://github.com/cktan/tomlc99, merge commits after
894902820a3ea2f1ec470cd7fe338bde54045cf5 (2022-09-12) up to and including
df627177cd1e80176c7a5245f26fd3b8e6187368 (2025-05-01)
2025-05-21 11:34:34 +01:00
matt335672 c2e543ae0b Merge pull request #3518 from matt335672/latvian_keyboard
Add Latvian keyboards
2025-05-21 09:56:17 +01:00
matt335672 cbf7131826 Add Latvian keyboard defs for xorgxrdp 2025-05-21 09:45:03 +01:00
matt335672 1177ff1240 Add Latvian keyboard definitions
The Latvian keyboard corresponding to code 0x426 is totally different
from the keyboard for 0x10426 (Latvian(QWERTY)) and 0x20426
(Latvian(Standard)). We set up new definitions for 0x426 and 0x10426 and
symlink 0x20426 to 0x10426.
2025-05-21 09:45:03 +01:00
matt335672 c62167ecd5 Merge pull request #3514 from gpotter2/hyperv-modes
vmconnect mode: support all security modes when used in a Hyper-V environment
2025-05-08 15:17:11 +01:00
matt335672 8547744dec Address review comments 2025-05-08 14:57:25 +01:00
matt335672 f5aa00be63 Updated manpage 2025-05-08 12:38:01 +01:00
matt335672 6ba1503b6a Disable vmconnect mode for non-vsock connections 2025-05-08 11:51:32 +01:00
gpotter2 09e1173259 Apply suggestions
Co-Authored-By: matt335672 <30179339+matt335672@users.noreply.github.com>
2025-05-08 06:45:05 +02:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 b2d4077fb2 Merge pull request #3455 from matt335672/additional_fips_checks
Security improvements
2025-05-06 12:05:19 +01:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 45ccd2d356 Merge pull request #3509 from matt335672/devel_sps_investigations
Refactor static channel name handling
2025-04-28 10:48:35 +01:00
matt335672 554515e39c Refactor static channel name handling
1) Remove 'magic numbers' related to static channel name lengths, and
   replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
   the [Channels] section of xrdp.ini.

(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
2025-04-26 17:06:10 +01:00
matt335672 44acc46db4 Merge pull request #3505 from matt335672/coverity_fixes
Coverity fixes
2025-04-22 14:58:59 +01:00
matt335672 d30f5fe22b Coverity CID 468156
Coverity is complaining about 32-bits being truncated to 16-bits.
Make the data conversion to unsigned short explicit.
2025-04-22 14:51:26 +01:00
matt335672 c6fb510892 Coverity CID 468139
Cater for xrdp_mm_get_value() returning NULL in a couple of places.

Also:-
- The function parse_chansrvport() now checks that passed-in value
  isn't NULL.
- Unnecessary uses of g_strncpy replaced with strlcpy()
2025-04-22 14:51:26 +01:00
matt335672 ffe9ac9122 Coverity CID 468130
g_bitmask_to_str() can return < 0 on error. This is not adequately
catered for.
2025-04-22 14:51:26 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 f2dd3fb3dc Coverity CID 468126
The datasize variable is an unsigned in, so comparing it to < 0 will
never be true. There is also a printf sequence for the variable which
should be %u rather than %d
2025-04-18 16:16:07 +01:00
matt335672 c198b321a2 Fix Coverity CID 468122
Missing break statement in a switch intoduced by commit
54acca43cf

The results of this are benign, as the extra code which is run is
unlikely to do anything.
2025-04-18 16:16:07 +01:00
matt335672 fc30a5f576 Merge pull request #3503 from matt335672/fix_systemd_regression
Only add systemd-dev for systemd versions >= 255
2025-04-15 12:29:35 +01:00
matt335672 857a5bd262 Only add systemd-dev for systemd versions >= 255
(cherry picked from commit 93871c9182c139452af4e2f8f40b1b592ffa7092)
2025-04-15 12:21:21 +01:00
matt335672 91b60b8a7a Merge pull request #3501 from matt335672/add_systemd_dev_dependency
Improve systemd support
2025-04-15 11:59:47 +01:00