Commit Graph

24 Commits

Author SHA1 Message Date
firewave 64154ea66d enabled and fixed constVariable Cppcheck warnings 2026-03-04 15:49:29 +01:00
matt335672 8bcb14f79d Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
2025-07-14 19:39:26 +01:00
matt335672 cad52028e0 Add g_sck_set_reuseaddr()
Only set SO_REUSEADDR where it is actually required, which is
before most (but not all) bind() calls.
2025-03-12 10:01:27 +00:00
matt335672 e169733e1e Update TCP proxy to address Coverity errors
Coverity seems to have some problems with the loop(s) copying data from
one socket to another, in that it assume that eventually an integer
overflow will occur. It's not obvious why this should be flagged, but
this seems likely to be a false positive.

This commit avoids the integer issue by using a simple pointer + count
mechanism.

The socket copy code has been placed in a separate function - before it
was duplicated. Minor fixes have been made to error reporting around the
connection code.
2025-02-04 12:23:24 +00:00
matt335672 c122e0563d Coverity CID 468110/468131 - fix newly detected error
THe previous commit unmasked another potential error in Coverity,
which is addressed by tightening up return value restrictions.
2025-02-03 15:32:55 +00:00
matt335672 2d2934241c Coverity CID 468110/468131
file descriptors cannot be zero when not in use. This commit
enforces that for the test TCP proxy.
2025-02-03 15:32:55 +00:00
metalefty 4e378c9a91 Merge pull request #3368 from metalefty/sysconfsubdir
Allow to change config file (sub)directory
2024-12-29 11:00:16 +09:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 ae6b1ed8a8 xrdp-droppriv erroneous includes
xrdp-droppriv.c is erroneously including os_calls.c rather than
os_calls.h

This leads to a link failure on Ubuntu 20.04:-

/usr/bin/ld: xrdp-droppriv.o: undefined reference to symbol 'dlclose@@GLIBC_2.2.5'

The error does not happen with later glibc versions, as libdl is
included in libc for these versions.

(cherry picked from commit b914d3e997ee70544db5fd2e28509bbcae32ddc6)
2024-12-23 11:19:30 +00:00
Koichiro Iwao a857f0b7ea tools: make the output of xrdp-chkpriv fancy
While here, drop exec permission from xrdp-chkpriv.in. The exec
permission will be granted to substituted xrdp-chkpriv script
during `make install` process.
2024-12-12 23:35:10 +09:00
Koichiro Iwao f61a59166e tools: fix for make dist
- Do not include substitutedd xrdp-chkpriv into tarball
- Dot not install xrdp-chkpriv.in

While here, drop exec permission from *.c source file.
2024-12-12 23:28:06 +09:00
Jay Sorg ce27b373c1 link error dlclose, use DLOPEN_LIBS 2024-07-13 12:13:52 -07:00
Koichiro Iwao c2b8cbf19e chkpriv: respect $sysconfdir for config files directory
While here, ignore build artifacts of chkpriv tools.

Follow-up to:   #2974
2024-07-12 11:11:06 +09:00
matt335672 0ebf4cff13 Check unprivileged user can't write TLS files
The unprivileged user needs to be able to read the certificate and
key files to offer TLS, but should not be able to write to then.

This commit checks the TLS files are read-only, rather than
simply readable
2024-07-01 14:25:23 +01:00
matt335672 48255da29a Add xrdp-chkpriv script to check xrdp privileges 2024-07-01 11:11:21 +01:00
firewave fb9c175b11 enabled and fixed -Wmissing-prototypes compiler warnings
Co-authored-by: matt335672 <30179339+matt335672@users.noreply.github.com>
2024-04-23 18:38:20 +02:00
firewave 27d34e784d fixed Cppcheck unusedVariable warnings 2023-09-04 23:47:56 +02:00
Daniel Richard G 42d32e7496 Use config_ac.h consistently and correctly 2023-05-12 13:49:53 -04:00
matt335672 78fa1c15b2 Replace select() system call with poll()
poll() is specified in POSIX.1-2001 as a simpler interface for
multiplexed file descriptors than select(). It also provides more
functionality.

This PR replaces the select() calls used in xrdp with poll()
equivalents.
2023-02-13 14:28:29 +00:00
matt335672 cd58d14cef Fix compilation on OpenBSD 2023-01-05 10:52:08 +00:00
matt335672 79bec8110c Unify connection fields for the connected client
The connected client is currently described in two places in
the xrdp_client_info structure:-

1) In the connection_description field. This was introduced as
   field client_ip by commit d797b2cf49
   for xrdp v0.6.0

2) In the client_addr and client_port fields introduced by commit
   25369460a1 for xrdp v0.8.0

This commit unifies these two sets of fields into a single
set of fields describing the connection IP and port (for
AF_INET/AF_INET6 connections only) and a connection description
for all connection types.

The code in os_calls to provide client logging has been simplified
somewhat which should make it easier to add new connection types (e.g.
AF_VSOCK).

The old connection_description field used to be passed to sesman to
inform sesman of the IP address of the client, and also to provide
a string for 'C' field session policy matching. 'C' field session policy
matching does not actually need this string (see #2239), and so now only
the IP field is passed to sesman.
2022-05-18 12:35:07 +01:00
matt335672 52a52daddd Split development option into separate things 2021-05-28 10:57:12 +01:00
Koichiro IWAO 1637c38cba do not install test & development tool
These tools shouldn't be delivered to end-users, included in distro
packages. Also the execuable names "memtest" and "tcp_proxy" are too
general to install into sbin dir.
2021-04-13 18:43:33 +09:00
Alexandre Quesnel 16fe9a021a Moving gtcp_proxy and tcp_proxy to the tools/devel directory 2021-03-26 14:16:00 +00:00