Commit Graph

1240 Commits

Author SHA1 Message Date
matt335672 ee8739a3f5 Update scp_list.h 2025-07-07 15:02:51 +01:00
matt335672 4d990cfc16 Rename the pre-session list to the SCP list
The name pre-session list makes no sense now, as we need items
to remain on the list after starting the session and before
connecting.
2025-07-07 15:02:51 +01:00
matt335672 539eb33795 Prevent possible double-free on chansrv exit 2025-06-21 14:38:06 +01:00
matt335672 554515e39c Refactor static channel name handling
1) Remove 'magic numbers' related to static channel name lengths, and
   replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
   the [Channels] section of xrdp.ini.

(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
2025-04-26 17:06:10 +01:00
matt335672 417076b215 Coverity CIDs 468127 468134 468148
These Coverity warnings all relate to the user of g_setenv() where the
return result isn't checked.

An additional void function g_setenv_log() is provided which logs
failures to set environment variables, and returns no status. This is
used in all the places where g_setenv_is currently called.
2025-04-22 14:51:26 +01:00
matt335672 5cf0ec8f34 Add a StartupWaitTime parameter
This allows sesman to detect failed sessions before it tells xrdp
that all is OK with the session. This is a fairly common failure mode
which can now be reported on the login screen.
2025-03-29 17:52:47 +00:00
matt335672 343e84a76a Remove SIGTERM race in chansrv
The signal handlers for SIGTERM are put in place before the
sigterm object is created. If a SIGTERM is received between the
two, it is ignored and chansrv will not exit.
2025-03-29 17:15:45 +00:00
matt335672 86c7fa63b9 Give privilege to users in TerminalServerAdmins
Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
2025-03-14 17:13:41 +00:00
matt335672 dd020e971b Rename sesman privilege detection function
access_login_mng_allowed() -> access_login_is_admin()
2025-03-12 17:06:01 +00:00
matt335672 0e2f03e925 Log session state transitions to E_SESSION_RUNNING
A log message has been added so that during session discovery
a list of discovered sessions can be generated.
2025-03-12 11:38:37 +00:00
matt335672 0806b2b978 Fix missing displays on sesman restart 2025-03-12 11:08:03 +00:00
matt335672 9225fe0686 Fill in discovery module
Add functionality to sesexec discovery module to enable sesman
restarts.
2025-03-12 11:08:03 +00:00
matt335672 0a584204a2 Add sesexec_set_ecp_transport/sesexec_is_ecp_active()
These sesexec functions are needed for the discovery module to
function.
2025-03-12 11:08:03 +00:00
matt335672 bee806d3af Add sesexec discover module
The module is a dummy to be filled in later

Other structural changes to sesexec:-
1) A failure of sesman needs to be detected and handled without
   causing sesexec to exit
2) If sesexec exits, the session can never be rediscovered. sesexec must
   be robust enough to stay up for the lifetime of the session so that
   the discovery function always works.
3) There is a mechanism for sesexec to terminate the session, but it
   doesn't work, as SIGCHLD is not processed while we are waiting for
   the session to finish. This needs fixing.
2025-03-12 11:08:03 +00:00
matt335672 eadbb6a190 Add session_get_parameters()
Also add useful comment to session_send_term()
2025-03-12 11:08:03 +00:00
matt335672 7268580f24 Add sesman restart module
Adds a module which can be used when sesman is restarting. This is
initially used to rediscover sessions from a previous run.
2025-03-12 11:08:03 +00:00
matt335672 7fb1f4732b Add warning if listen_port changes 2025-03-12 10:06:24 +00:00
matt335672 44a83c8b38 Make listen_port smaller than XRDP_SOCKETS_MAXPATH 2025-03-12 10:06:24 +00:00
matt335672 627ebea34d Add session_list_get_count_by_state() to session list 2025-03-12 10:06:24 +00:00
matt335672 d55c7e7cb7 Remove commented-out code
The function sesexce_scp_data_in in sesexec.c is a development
artefact and can safely be removed
2025-03-12 10:03:15 +00:00
matt335672 a341d44e1b Remove unused variable g_con_list 2025-03-12 10:03:15 +00:00
matt335672 43e960bffd Restrict scope of sesman_close_all()
This function does not need to have global scope.
2025-03-12 10:03:15 +00:00
matt335672 39ec7089ac Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
2025-03-08 11:45:26 +00:00
matt335672 6979df55ee Add new session type SCP_SESSION_TYPE_XVNC_UDS
This PR adds a new session type, which is a VNC session using a
Unix Domain Socket connection rather than a TCP connection.

This is necessary for FIPS_based deployments using VNC, as the classic
VNC password algorithm is not supported by FIPS
2025-03-08 11:45:26 +00:00
matt335672 e8a0699bb4 Merge pull request #3393 from matt335672/xauth_in_sysdir
Add XAuthorityInSystemDir option
2025-03-03 13:38:09 +00:00
matt335672 8b449868fe Coverity CID 468108
Repeated constant WAVE_FORMAT_MULAW in conditional
2025-02-28 14:34:26 +00:00
matt335672 4a95185dc6 Coverity CID 475385 2025-02-28 11:18:58 +00:00
matt335672 2f46ef27a2 Add support for cppcheck 2.17.0
cppcheck 2.17.0 adds checks that a NULL pointer returned from malloc() and
calloc() is not used.

We do this quite a lot.

I've addressed this by adding functions g_malloc_nofail() and
g_calloc_nofail() which either allocate memory or abort.
functions are now called in places where we are not making these
checks.

Many of these checks are in test programs or example programs.

I've modified the list16 module to handle out-of-memory conditions.
2025-02-27 15:04:11 +00:00
Jay Sorg 75b9304304 add grid options to sesman.ini 2025-02-16 17:34:51 -08:00
Jay Sorg 6dcb8ffe79 add support for nvenc and accel_assist 2025-02-16 17:34:51 -08:00
matt335672 8769481136 Coverity CID 468118 2025-02-10 15:31:34 +00:00
matt335672 cb90458609 Coverity CID 468116 2025-02-10 15:31:19 +00:00
matt335672 6088ba3f3b Address offline Coverity issue
This Coverity issue was encountered in a private build, but does not
appear to be in the Github CI build. Coverity is suspecting a copy-paste
betweem these lines in sound.c:-

1838: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], i);
1844: xstream_copyin(s, &g_stream_inp->data[g_stream_inp->size - g_bytes_in_stream], g_bytes_in_stream);

An inspection of the code shows this to bre a false positive
2025-02-10 15:26:55 +00:00
matt335672 f7543c2586 Coverity CID 468100 2025-02-10 15:26:34 +00:00
matt335672 eff8ba75ee Coverity CID 468140 2025-02-03 15:32:55 +00:00
matt335672 db32f9c6a3 Coverity CID 468119
Add additional check to prevent Coverity assuming the worst
2025-02-03 15:32:55 +00:00
matt335672 201cdc1aea Fix coverity warning over mem leak in smartcard code 2025-01-24 11:36:40 +00:00
matt335672 2a4b40a20c Address some Coverity warnings 2025-01-13 15:24:33 +00:00
matt335672 d2e96fe2d2 Add XAuthorityInSystemDir option
Add an option to allow XAUTHORITY to be moved away from $HOME.

This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
2025-01-13 11:51:27 +00:00
matt335672 b04743066d Fix coverity-reported issues
The errors in sesman/chansrv/chansrv_fuse.c appear to be false positives
caused by allocating xhandle->dir_handle, and then
casting xhandle to an integer in xfuse_handle_to_fuse_handle(), thus
hiding xhandle->dir_handle

For both occurrences, the logic has been simplified and made the same,
and a comment has been added to suppress the error.
2025-01-13 10:27:29 +00:00
Constantin Kulikov 151c555fc0 Add sesman.ini FuseMountNameColonCharReplacement option 2025-01-08 16:23:14 +03:00
matt335672 e3d502ca06 Merge pull request #3328 from matt335672/fix_time_calls
Remove/replace time calls
2025-01-06 10:22:40 +00:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 1f79eb1c01 Replace g_time3() with g_get_elapsed_ms()
The function as specified used gettimeofday() which is susceptible
to manual time changes, and is obsoleted in POSIX.1-2008. The
replacement uses clock_gettime(CLOCK_MONOTONIC, ) which is not
susceptible to manual time changes (at least on Linux) and cannot run
backwards.

Also, on systems with 32-bit integers, the value returned by this
function wraps around every 49.7 days. To cope with a wraparound in
a way compliant with the C standard, this value needs to return an
unsigned integer type rather than a signed integer type.
2024-12-16 16:13:15 +00:00
matt335672 90798cdeaa Remove g_time2() call
This is currently unused in xrdp
2024-12-16 16:13:15 +00:00
matt335672 b02689ab44 Remove g_time1() call
This is not year 2038 compliant on systems with 32-bit integers.

The call can be replaced with the standard C time() call. On
POSIX systems, time_t is guaranteed to be an integer type.
2024-12-16 16:13:15 +00:00
matt335672 162153ab6f Move LogFilePath parameter to [ChansrvLogging]
This seems a better fit than having it in the [Chansrv] section.

Also fixed a minor logging error relating to the parameter in
chansrv_config.c

(cherry picked from commit 6d2fd1be8451418f01dfbb203929e2838c1a979f)
2024-12-16 10:55:30 +00:00
matt335672 2f7be3f634 Allow a path to be specified for the chansrv log
This is useful for NFS-mounted home directories, where hosts
may otherwise produce colliding chansrv log file names

(cherry picked from commit cfc2e362b47103bc2c786252f331bb26b6ddecb5)
2024-12-16 10:55:21 +00:00
matt335672 31a09f5100 Merge pull request #3304 from matt335672/add_statfs_to_fuse
Add support for statvfs() to FUSE
2024-12-13 11:41:09 +00:00
matt335672 2a190a2264 Fix regression in opening local display in waitforx
Commit 80fab03198 introduced a way to
prevent waitforx going to the network when trying to open a display,
and hence potentially blocking.

This method turned out to be invalidated by libxcb version 1.16 and
1.17

This change adds an explicit check that the Unix socket for the display
in /tmp/.X11-unix/Xn is open before trying to connect to display ':n'.
This has the same effect.
2024-12-11 11:52:06 +00:00