summaryrefslogtreecommitdiffstats
path: root/common
diff options
context:
space:
mode:
authorLaxmikant Rashinkar <LK.Rashinkar@gmail.com>2014-07-26 13:33:44 -0700
committerLaxmikant Rashinkar <LK.Rashinkar@gmail.com>2014-07-26 13:33:44 -0700
commit56e43c4a3899f9efd4c02f8a2abc0407691b20b5 (patch)
tree02f28e8bb0b93e4a1916bb39eba27893aedde777 /common
parent27055d5762d23ae3996e7e41ef45ef6454fa2d65 (diff)
parent0f9bd232d91a431f68853a308b768e782ab37ff1 (diff)
downloadxrdp-proprietary-56e43c4a3899f9efd4c02f8a2abc0407691b20b5.tar.gz
xrdp-proprietary-56e43c4a3899f9efd4c02f8a2abc0407691b20b5.zip
Merge branch 'devel' of github.com:NeutrinoLabs/xrdp into devel
Diffstat (limited to 'common')
-rw-r--r--common/Makefile.am5
-rw-r--r--common/fifo.c17
-rw-r--r--common/fifo.h12
-rw-r--r--common/file_loc.h4
-rw-r--r--common/list.h18
-rw-r--r--common/log.c76
-rw-r--r--common/log.h60
-rw-r--r--common/parse.h292
-rw-r--r--common/trans.c106
-rw-r--r--common/trans.h39
-rw-r--r--common/xrdp_client_info.h3
-rw-r--r--common/xrdp_rail.h100
-rw-r--r--common/xrdp_tls.c435
13 files changed, 861 insertions, 306 deletions
diff --git a/common/Makefile.am b/common/Makefile.am
index ab9c2bd5..9feac9fb 100644
--- a/common/Makefile.am
+++ b/common/Makefile.am
@@ -17,7 +17,7 @@ EXTRA_DIST = \
trans.h \
xrdp_client_info.h \
xrdp_constants.h \
- xrdp_rail.h
+ xrdp_rail.h
AM_CFLAGS = \
-DXRDP_CFG_PATH=\"${sysconfdir}/xrdp\" \
@@ -39,7 +39,8 @@ libcommon_la_SOURCES = \
os_calls.c \
ssl_calls.c \
thread_calls.c \
- trans.c
+ trans.c \
+ xrdp_tls.c
libcommon_la_LIBADD = \
-lcrypto \
diff --git a/common/fifo.c b/common/fifo.c
index 5e94694d..ebd1ef4d 100644
--- a/common/fifo.c
+++ b/common/fifo.c
@@ -19,7 +19,7 @@
*/
#include "fifo.h"
-#include "common/os_calls.h"
+#include "os_calls.h"
/**
* Create new fifo data struct
@@ -27,7 +27,8 @@
* @return pointer to new FIFO or NULL if system out of memory
*****************************************************************************/
-FIFO *fifo_create()
+FIFO * APP_CC
+fifo_create(void)
{
return (FIFO *) g_malloc(sizeof(FIFO), 1);
}
@@ -36,7 +37,8 @@ FIFO *fifo_create()
* Delete specified FIFO
*****************************************************************************/
-void fifo_delete(FIFO *self)
+void APP_CC
+fifo_delete(FIFO *self)
{
USER_DATA *udp;
@@ -85,7 +87,8 @@ void fifo_delete(FIFO *self)
* @return 0 on success, -1 on error
*****************************************************************************/
-int fifo_add_item(FIFO *self, void *item)
+int APP_CC
+fifo_add_item(FIFO *self, void *item)
{
USER_DATA *udp;
@@ -121,7 +124,8 @@ int fifo_add_item(FIFO *self, void *item)
* @return top item from FIFO or NULL if FIFO is empty
*****************************************************************************/
-void *fifo_remove_item(FIFO *self)
+void * APP_CC
+fifo_remove_item(FIFO *self)
{
void *item;
USER_DATA *udp;
@@ -155,7 +159,8 @@ void *fifo_remove_item(FIFO *self)
* @return true if FIFO is empty, false otherwise
*****************************************************************************/
-int fifo_is_empty(FIFO *self)
+int APP_CC
+fifo_is_empty(FIFO *self)
{
if (!self)
return 1;
diff --git a/common/fifo.h b/common/fifo.h
index 134227d8..813154a4 100644
--- a/common/fifo.h
+++ b/common/fifo.h
@@ -21,6 +21,8 @@
#ifndef _FIFO_H
#define _FIFO_H
+#include "arch.h"
+
typedef struct user_data USER_DATA;
struct user_data
@@ -36,10 +38,10 @@ typedef struct fifo
int auto_free;
} FIFO;
-FIFO *fifo_create();
-void fifo_delete(FIFO *self);
-int fifo_add_item(FIFO *self, void *item);
-void *fifo_remove_item(FIFO *self);
-int fifo_is_empty();
+FIFO * APP_CC fifo_create(void);
+void APP_CC fifo_delete(FIFO *self);
+int APP_CC fifo_add_item(FIFO *self, void *item);
+void * APP_CC fifo_remove_item(FIFO *self);
+int APP_CC fifo_is_empty(FIFO *self);
#endif
diff --git a/common/file_loc.h b/common/file_loc.h
index 36821304..3b408e43 100644
--- a/common/file_loc.h
+++ b/common/file_loc.h
@@ -41,4 +41,8 @@
#define XRDP_LIB_PATH "/usr/local/lib/xrdp"
#endif
+#if !defined(XRDP_LOG_PATH)
+#define XRDP_LOG_PATH "/var/log"
+#endif
+
#endif
diff --git a/common/list.h b/common/list.h
index 23bc5092..cdc545a0 100644
--- a/common/list.h
+++ b/common/list.h
@@ -26,11 +26,11 @@
/* list */
struct list
{
- tbus* items;
- int count;
- int alloc_size;
- int grow_by;
- int auto_free;
+ tintptr* items;
+ int count;
+ int alloc_size;
+ int grow_by;
+ int auto_free;
};
struct list* APP_CC
@@ -38,17 +38,17 @@ list_create(void);
void APP_CC
list_delete(struct list* self);
void APP_CC
-list_add_item(struct list* self, tbus item);
-tbus APP_CC
+list_add_item(struct list* self, tintptr item);
+tintptr APP_CC
list_get_item(struct list* self, int index);
void APP_CC
list_clear(struct list* self);
int APP_CC
-list_index_of(struct list* self, tbus item);
+list_index_of(struct list* self, tintptr item);
void APP_CC
list_remove_item(struct list* self, int index);
void APP_CC
-list_insert_item(struct list* self, int index, tbus item);
+list_insert_item(struct list* self, int index, tintptr item);
void APP_CC
list_append_list_strdup(struct list* self, struct list* dest, int start_index);
void APP_CC
diff --git a/common/log.c b/common/log.c
index d7594d67..97053178 100644
--- a/common/log.c
+++ b/common/log.c
@@ -36,7 +36,7 @@
#include "log.h"
/* Here we store the current state and configuration of the log */
-static struct log_config *staticLogConfig = NULL;
+static struct log_config *g_staticLogConfig = NULL;
/* This file first start with all private functions.
In the end of the file the public functions is defined */
@@ -297,7 +297,7 @@ internalReadConfiguration(const char *inFilename, const char *applicationName)
param_v->auto_free = 1;
/* read logging config */
- ret = internal_config_read_logging(fd, staticLogConfig, param_n,
+ ret = internal_config_read_logging(fd, g_staticLogConfig, param_n,
param_v, applicationName);
if (ret != LOG_STARTUP_OK)
@@ -394,12 +394,12 @@ enum logReturns DEFAULT_CC
internalInitAndAllocStruct(void)
{
enum logReturns ret = LOG_GENERAL_ERROR;
- staticLogConfig = g_malloc(sizeof(struct log_config), 1);
+ g_staticLogConfig = g_malloc(sizeof(struct log_config), 1);
- if (staticLogConfig != NULL)
+ if (g_staticLogConfig != NULL)
{
- staticLogConfig->fd = -1;
- staticLogConfig->enable_syslog = 0;
+ g_staticLogConfig->fd = -1;
+ g_staticLogConfig->enable_syslog = 0;
ret = LOG_STARTUP_OK;
}
else
@@ -420,7 +420,7 @@ log_start_from_param(const struct log_config *iniParams)
{
enum logReturns ret = LOG_GENERAL_ERROR;
- if (staticLogConfig != NULL)
+ if (g_staticLogConfig != NULL)
{
log_message(LOG_LEVEL_ALWAYS, "Log already initialized");
return ret;
@@ -442,24 +442,24 @@ log_start_from_param(const struct log_config *iniParams)
return ret;
}
- staticLogConfig->enable_syslog = iniParams->enable_syslog;
- staticLogConfig->fd = iniParams->fd;
- staticLogConfig->log_file = g_strdup(iniParams->log_file);
- staticLogConfig->log_level = iniParams->log_level;
- staticLogConfig->log_lock = iniParams->log_lock;
- staticLogConfig->log_lock_attr = iniParams->log_lock_attr;
- staticLogConfig->program_name = g_strdup(iniParams->program_name);
- staticLogConfig->syslog_level = iniParams->syslog_level;
- ret = internal_log_start(staticLogConfig);
+ g_staticLogConfig->enable_syslog = iniParams->enable_syslog;
+ g_staticLogConfig->fd = iniParams->fd;
+ g_staticLogConfig->log_file = g_strdup(iniParams->log_file);
+ g_staticLogConfig->log_level = iniParams->log_level;
+ g_staticLogConfig->log_lock = iniParams->log_lock;
+ g_staticLogConfig->log_lock_attr = iniParams->log_lock_attr;
+ g_staticLogConfig->program_name = g_strdup(iniParams->program_name);
+ g_staticLogConfig->syslog_level = iniParams->syslog_level;
+ ret = internal_log_start(g_staticLogConfig);
if (ret != LOG_STARTUP_OK)
{
g_writeln("Could not start log");
- if (staticLogConfig != NULL)
+ if (g_staticLogConfig != NULL)
{
- g_free(staticLogConfig);
- staticLogConfig = NULL;
+ g_free(g_staticLogConfig);
+ g_staticLogConfig = NULL;
}
}
}
@@ -489,16 +489,16 @@ log_start(const char *iniFile, const char *applicationName)
if (ret == LOG_STARTUP_OK)
{
- ret = internal_log_start(staticLogConfig);
+ ret = internal_log_start(g_staticLogConfig);
if (ret != LOG_STARTUP_OK)
{
g_writeln("Could not start log");
- if (staticLogConfig != NULL)
+ if (g_staticLogConfig != NULL)
{
- g_free(staticLogConfig);
- staticLogConfig = NULL;
+ g_free(g_staticLogConfig);
+ g_staticLogConfig = NULL;
}
}
}
@@ -519,12 +519,12 @@ enum logReturns DEFAULT_CC
log_end(void)
{
enum logReturns ret = LOG_GENERAL_ERROR;
- ret = internal_log_end(staticLogConfig);
+ ret = internal_log_end(g_staticLogConfig);
- if (staticLogConfig != NULL)
+ if (g_staticLogConfig != NULL)
{
- g_free(staticLogConfig);
- staticLogConfig = NULL;
+ g_free(g_staticLogConfig);
+ g_staticLogConfig = NULL;
}
return ret;
@@ -541,13 +541,13 @@ log_message(const enum logLevels lvl, const char *msg, ...)
time_t now_t;
struct tm *now;
- if (staticLogConfig == NULL)
+ if (g_staticLogConfig == NULL)
{
g_writeln("The log reference is NULL - log not initialized properly");
return LOG_ERROR_NO_CFG;
}
- if (0 > staticLogConfig->fd && staticLogConfig->enable_syslog == 0)
+ if (0 > g_staticLogConfig->fd && g_staticLogConfig->enable_syslog == 0)
{
return LOG_ERROR_FILE_NOT_OPEN;
}
@@ -586,7 +586,7 @@ log_message(const enum logLevels lvl, const char *msg, ...)
#endif
#endif
- if (staticLogConfig->enable_syslog && (lvl <= staticLogConfig->syslog_level))
+ if (g_staticLogConfig->enable_syslog && (lvl <= g_staticLogConfig->syslog_level))
{
/* log to syslog*/
/* %s fix compiler warning 'not a string literal' */
@@ -594,19 +594,19 @@ log_message(const enum logLevels lvl, const char *msg, ...)
tc_get_threadid(), buff + 20);
}
- if (lvl <= staticLogConfig->log_level)
+ if (lvl <= g_staticLogConfig->log_level)
{
/* log to console */
g_printf("%s", buff);
/* log to application logfile */
#ifdef LOG_ENABLE_THREAD
- pthread_mutex_lock(&(staticLogConfig->log_lock));
+ pthread_mutex_lock(&(g_staticLogConfig->log_lock));
#endif
- if (staticLogConfig->fd > 0)
+ if (g_staticLogConfig->fd > 0)
{
- writereply = g_file_write(staticLogConfig->fd, buff, g_strlen(buff));
+ writereply = g_file_write(g_staticLogConfig->fd, buff, g_strlen(buff));
if (writereply <= 0)
{
@@ -615,7 +615,7 @@ log_message(const enum logLevels lvl, const char *msg, ...)
}
#ifdef LOG_ENABLE_THREAD
- pthread_mutex_unlock(&(staticLogConfig->log_lock));
+ pthread_mutex_unlock(&(g_staticLogConfig->log_lock));
#endif
}
@@ -629,11 +629,11 @@ log_message(const enum logLevels lvl, const char *msg, ...)
char *DEFAULT_CC
getLogFile(char *replybuf, int bufsize)
{
- if (staticLogConfig)
+ if (g_staticLogConfig)
{
- if (staticLogConfig->log_file)
+ if (g_staticLogConfig->log_file)
{
- g_strncpy(replybuf, staticLogConfig->log_file, bufsize);
+ g_strncpy(replybuf, g_staticLogConfig->log_file, bufsize);
}
else
{
diff --git a/common/log.h b/common/log.h
index 6bb6180a..b95c615a 100644
--- a/common/log.h
+++ b/common/log.h
@@ -29,23 +29,23 @@
/* logging levels */
enum logLevels
{
- LOG_LEVEL_ALWAYS = 0,
- LOG_LEVEL_ERROR,
- LOG_LEVEL_WARNING,
- LOG_LEVEL_INFO,
- LOG_LEVEL_DEBUG
+ LOG_LEVEL_ALWAYS = 0,
+ LOG_LEVEL_ERROR,
+ LOG_LEVEL_WARNING,
+ LOG_LEVEL_INFO,
+ LOG_LEVEL_DEBUG
};
/* startup return values */
enum logReturns
{
- LOG_STARTUP_OK = 0,
- LOG_ERROR_MALLOC,
- LOG_ERROR_NULL_FILE,
- LOG_ERROR_FILE_OPEN,
- LOG_ERROR_NO_CFG,
- LOG_ERROR_FILE_NOT_OPEN,
- LOG_GENERAL_ERROR
+ LOG_STARTUP_OK = 0,
+ LOG_ERROR_MALLOC,
+ LOG_ERROR_NULL_FILE,
+ LOG_ERROR_FILE_OPEN,
+ LOG_ERROR_NO_CFG,
+ LOG_ERROR_FILE_NOT_OPEN,
+ LOG_GENERAL_ERROR
};
#define SESMAN_CFG_LOGGING "Logging"
@@ -65,14 +65,14 @@ enum logReturns
struct log_config
{
- char* program_name;
- char* log_file;
- int fd;
- unsigned int log_level;
- int enable_syslog;
- unsigned int syslog_level;
- pthread_mutex_t log_lock;
- pthread_mutexattr_t log_lock_attr;
+ char *program_name;
+ char *log_file;
+ int fd;
+ unsigned int log_level;
+ int enable_syslog;
+ unsigned int syslog_level;
+ pthread_mutex_t log_lock;
+ pthread_mutexattr_t log_lock_attr;
};
/* internal functions, only used in log.c if this ifdef is defined.*/
@@ -86,7 +86,7 @@ struct log_config
*
*/
enum logReturns DEFAULT_CC
-internal_log_start(struct log_config* l_cfg);
+internal_log_start(struct log_config *l_cfg);
/**
*
@@ -95,7 +95,7 @@ internal_log_start(struct log_config* l_cfg);
*
*/
enum logReturns DEFAULT_CC
-internal_log_end(struct log_config* l_cfg);
+internal_log_end(struct log_config *l_cfg);
/**
* Converts a log level to a string
@@ -103,7 +103,7 @@ internal_log_end(struct log_config* l_cfg);
* @param str pointer where the string will be stored.
*/
void DEFAULT_CC
-internal_log_lvl2str(const enum logLevels lvl, char* str);
+internal_log_lvl2str(const enum logLevels lvl, char *str);
/**
*
@@ -113,7 +113,7 @@ internal_log_lvl2str(const enum logLevels lvl, char* str);
*
*/
enum logLevels DEFAULT_CC
-internal_log_text2level(char* s);
+internal_log_text2level(char *s);
/**
* A function that init our struct that holds all state and
@@ -133,9 +133,9 @@ internalInitAndAllocStruct(void);
* @return
*/
enum logReturns DEFAULT_CC
-internal_config_read_logging(int file, struct log_config* lc,
- struct list* param_n,
- struct list* param_v,
+internal_config_read_logging(int file, struct log_config *lc,
+ struct list *param_n,
+ struct list *param_v,
const char *applicationName);
/*End of internal functions*/
#endif
@@ -147,7 +147,7 @@ internal_config_read_logging(int file, struct log_config* lc,
* @return LOG_STARTUP_OK on success
*/
enum logReturns DEFAULT_CC
-log_start(const char* iniFile, const char* applicationName);
+log_start(const char *iniFile, const char *applicationName);
/**
* An alternative log_start where the caller gives the params directly.
@@ -171,7 +171,7 @@ log_end(void);
* @return
*/
enum logReturns DEFAULT_CC
-log_message(const enum logLevels lvl, const char* msg, ...);
+log_message(const enum logLevels lvl, const char *msg, ...);
/**
*
@@ -181,7 +181,7 @@ log_message(const enum logLevels lvl, const char* msg, ...);
* @return 0 on success, 1 on failure
*
*/
-int APP_CC text2bool(char* s);
+int APP_CC text2bool(char *s);
/**
* This function returns the configured file name for the logfile
diff --git a/common/parse.h b/common/parse.h
index 34170a41..2ae3927b 100644
--- a/common/parse.h
+++ b/common/parse.h
@@ -36,17 +36,17 @@
/* parser state */
struct stream
{
- char* p;
- char* end;
- char* data;
- int size;
- /* offsets of various headers */
- char* iso_hdr;
- char* mcs_hdr;
- char* sec_hdr;
- char* rdp_hdr;
- char* channel_hdr;
- char* next_packet;
+ char *p;
+ char *end;
+ char *data;
+ int size;
+ /* offsets of various headers */
+ char *iso_hdr;
+ char *mcs_hdr;
+ char *sec_hdr;
+ char *rdp_hdr;
+ char *channel_hdr;
+ char *next_packet;
};
/******************************************************************************/
@@ -63,58 +63,58 @@ struct stream
/******************************************************************************/
#define make_stream(s) \
- (s) = (struct stream*)g_malloc(sizeof(struct stream), 1)
+ (s) = (struct stream*)g_malloc(sizeof(struct stream), 1)
/******************************************************************************/
#define init_stream(s, v) do \
{ \
- if ((v) > (s)->size) \
- { \
- g_free((s)->data); \
- (s)->data = (char*)g_malloc((v), 0); \
- (s)->size = (v); \
- } \
- (s)->p = (s)->data; \
- (s)->end = (s)->data; \
- (s)->next_packet = 0; \
+ if ((v) > (s)->size) \
+ { \
+ g_free((s)->data); \
+ (s)->data = (char*)g_malloc((v), 0); \
+ (s)->size = (v); \
+ } \
+ (s)->p = (s)->data; \
+ (s)->end = (s)->data; \
+ (s)->next_packet = 0; \
} while (0)
/******************************************************************************/
#define free_stream(s) do \
{ \
- if ((s) != 0) \
- { \
- g_free((s)->data); \
- } \
- g_free((s)); \
+ if ((s) != 0) \
+ { \
+ g_free((s)->data); \
+ } \
+ g_free((s)); \
} while (0)
/******************************************************************************/
#define s_push_layer(s, h, n) do \
{ \
- (s)->h = (s)->p; \
- (s)->p += (n); \
+ (s)->h = (s)->p; \
+ (s)->p += (n); \
} while (0)
/******************************************************************************/
#define s_pop_layer(s, h) \
- (s)->p = (s)->h
+ (s)->p = (s)->h
/******************************************************************************/
#define s_mark_end(s) \
- (s)->end = (s)->p
+ (s)->end = (s)->p
#define in_sint8(s, v) do \
{ \
- (v) = *((signed char*)((s)->p)); \
- (s)->p++; \
+ (v) = *((signed char*)((s)->p)); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
#define in_uint8(s, v) do \
{ \
- (v) = *((unsigned char*)((s)->p)); \
- (s)->p++; \
+ (v) = *((unsigned char*)((s)->p)); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
#define in_uint8_peek(s, v) do { v = *s->p; } while (0)
@@ -122,18 +122,18 @@ struct stream
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define in_sint16_le(s, v) do \
{ \
- (v) = (signed short) \
- ( \
- (*((unsigned char*)((s)->p + 0)) << 0) | \
- (*((unsigned char*)((s)->p + 1)) << 8) \
- ); \
- (s)->p += 2; \
+ (v) = (signed short) \
+ ( \
+ (*((unsigned char*)((s)->p + 0)) << 0) | \
+ (*((unsigned char*)((s)->p + 1)) << 8) \
+ ); \
+ (s)->p += 2; \
} while (0)
#else
#define in_sint16_le(s, v) do \
{ \
- (v) = *((signed short*)((s)->p)); \
- (s)->p += 2; \
+ (v) = *((signed short*)((s)->p)); \
+ (s)->p += 2; \
} while (0)
#endif
@@ -141,49 +141,49 @@ struct stream
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define in_uint16_le(s, v) do \
{ \
- (v) = (unsigned short) \
- ( \
- (*((unsigned char*)((s)->p + 0)) << 0) | \
- (*((unsigned char*)((s)->p + 1)) << 8) \
- ); \
- (s)->p += 2; \
+ (v) = (unsigned short) \
+ ( \
+ (*((unsigned char*)((s)->p + 0)) << 0) | \
+ (*((unsigned char*)((s)->p + 1)) << 8) \
+ ); \
+ (s)->p += 2; \
} while (0)
#else
#define in_uint16_le(s, v) do \
{ \
- (v) = *((unsigned short*)((s)->p)); \
- (s)->p += 2; \
+ (v) = *((unsigned short*)((s)->p)); \
+ (s)->p += 2; \
} while (0)
#endif
/******************************************************************************/
#define in_uint16_be(s, v) do \
{ \
- (v) = *((unsigned char*)((s)->p)); \
- (s)->p++; \
- (v) <<= 8; \
- (v) |= *((unsigned char*)((s)->p)); \
- (s)->p++; \
+ (v) = *((unsigned char*)((s)->p)); \
+ (s)->p++; \
+ (v) <<= 8; \
+ (v) |= *((unsigned char*)((s)->p)); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define in_uint32_le(s, v) do \
{ \
- (v) = (unsigned int) \
- ( \
- (*((unsigned char*)((s)->p + 0)) << 0) | \
- (*((unsigned char*)((s)->p + 1)) << 8) | \
- (*((unsigned char*)((s)->p + 2)) << 16) | \
- (*((unsigned char*)((s)->p + 3)) << 24) \
- ); \
- (s)->p += 4; \
+ (v) = (unsigned int) \
+ ( \
+ (*((unsigned char*)((s)->p + 0)) << 0) | \
+ (*((unsigned char*)((s)->p + 1)) << 8) | \
+ (*((unsigned char*)((s)->p + 2)) << 16) | \
+ (*((unsigned char*)((s)->p + 3)) << 24) \
+ ); \
+ (s)->p += 4; \
} while (0)
#else
#define in_uint32_le(s, v) do \
{ \
- (v) = *((unsigned int*)((s)->p)); \
- (s)->p += 4; \
+ (v) = *((unsigned int*)((s)->p)); \
+ (s)->p += 4; \
} while (0)
#endif
@@ -191,41 +191,41 @@ struct stream
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define in_uint64_le(s, v) do \
{ \
- (v) = (tui64) \
- ( \
- (((tui64)(*((unsigned char*)((s)->p + 0)))) << 0) | \
- (((tui64)(*((unsigned char*)((s)->p + 1)))) << 8) | \
- (((tui64)(*((unsigned char*)((s)->p + 2)))) << 16) | \
- (((tui64)(*((unsigned char*)((s)->p + 3)))) << 24) | \
- (((tui64)(*((unsigned char*)((s)->p + 4)))) << 32) | \
- (((tui64)(*((unsigned char*)((s)->p + 5)))) << 40) | \
- (((tui64)(*((unsigned char*)((s)->p + 6)))) << 48) | \
- (((tui64)(*((unsigned char*)((s)->p + 7)))) << 56) \
- ); \
- (s)->p += 8; \
+ (v) = (tui64) \
+ ( \
+ (((tui64)(*((unsigned char*)((s)->p + 0)))) << 0) | \
+ (((tui64)(*((unsigned char*)((s)->p + 1)))) << 8) | \
+ (((tui64)(*((unsigned char*)((s)->p + 2)))) << 16) | \
+ (((tui64)(*((unsigned char*)((s)->p + 3)))) << 24) | \
+ (((tui64)(*((unsigned char*)((s)->p + 4)))) << 32) | \
+ (((tui64)(*((unsigned char*)((s)->p + 5)))) << 40) | \
+ (((tui64)(*((unsigned char*)((s)->p + 6)))) << 48) | \
+ (((tui64)(*((unsigned char*)((s)->p + 7)))) << 56) \
+ ); \
+ (s)->p += 8; \
} while (0)
#else
#define in_uint64_le(s, v) do \
{ \
- (v) = *((tui64*)((s)->p)); \
- (s)->p += 8; \
+ (v) = *((tui64*)((s)->p)); \
+ (s)->p += 8; \
} while (0)
#endif
/******************************************************************************/
#define in_uint32_be(s, v) do \
{ \
- (v) = *((unsigned char*)((s)->p)); \
- (s)->p++; \
- (v) <<= 8; \
- (v) |= *((unsigned char*)((s)->p)); \
- (s)->p++; \
- (v) <<= 8; \
- (v) |= *((unsigned char*)((s)->p)); \
- (s)->p++; \
- (v) <<= 8; \
- (v) |= *((unsigned char*)((s)->p)); \
- (s)->p++; \
+ (v) = *((unsigned char*)((s)->p)); \
+ (s)->p++; \
+ (v) <<= 8; \
+ (v) |= *((unsigned char*)((s)->p)); \
+ (s)->p++; \
+ (v) <<= 8; \
+ (v) |= *((unsigned char*)((s)->p)); \
+ (s)->p++; \
+ (v) <<= 8; \
+ (v) |= *((unsigned char*)((s)->p)); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
@@ -239,46 +239,46 @@ struct stream
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define out_uint16_le(s, v) do \
{ \
- *((s)->p) = (unsigned char)((v) >> 0); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 8); \
- (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 0); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 8); \
+ (s)->p++; \
} while (0)
#else
#define out_uint16_le(s, v) do \
{ \
- *((unsigned short*)((s)->p)) = (unsigned short)(v); \
- (s)->p += 2; \
+ *((unsigned short*)((s)->p)) = (unsigned short)(v); \
+ (s)->p += 2; \
} while (0)
#endif
/******************************************************************************/
#define out_uint16_be(s, v) do \
{ \
- *((s)->p) = (unsigned char)((v) >> 8); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 0); \
- (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 8); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 0); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define out_uint32_le(s, v) do \
{ \
- *((s)->p) = (unsigned char)((v) >> 0); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 8); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 16); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 24); \
- (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 0); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 8); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 16); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 24); \
+ (s)->p++; \
} while (0)
#else
#define out_uint32_le(s, v) do \
{ \
- *((unsigned int*)((s)->p)) = (v); \
- (s)->p += 4; \
+ *((unsigned int*)((s)->p)) = (v); \
+ (s)->p += 4; \
} while (0)
#endif
@@ -286,78 +286,78 @@ struct stream
#if defined(B_ENDIAN) || defined(NEED_ALIGN)
#define out_uint64_le(s, v) do \
{ \
- *((s)->p) = (unsigned char)((v) >> 0); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 8); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 16); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 24); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 32); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 40); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 48); \
- (s)->p++; \
- *((s)->p) = (unsigned char)((v) >> 56); \
- (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 0); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 8); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 16); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 24); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 32); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 40); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 48); \
+ (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 56); \
+ (s)->p++; \
} while (0)
#else
#define out_uint64_le(s, v) do \
{ \
- *((tui64*)((s)->p)) = (v); \
- (s)->p += 8; \
+ *((tui64*)((s)->p)) = (v); \
+ (s)->p += 8; \
} while (0)
#endif
/******************************************************************************/
#define out_uint32_be(s, v) do \
{ \
- *((s)->p) = (unsigned char)((v) >> 24); \
- s->p++; \
- *((s)->p) = (unsigned char)((v) >> 16); \
- s->p++; \
- *((s)->p) = (unsigned char)((v) >> 8); \
- s->p++; \
- *((s)->p) = (unsigned char)(v); \
- (s)->p++; \
+ *((s)->p) = (unsigned char)((v) >> 24); \
+ s->p++; \
+ *((s)->p) = (unsigned char)((v) >> 16); \
+ s->p++; \
+ *((s)->p) = (unsigned char)((v) >> 8); \
+ s->p++; \
+ *((s)->p) = (unsigned char)(v); \
+ (s)->p++; \
} while (0)
/******************************************************************************/
#define in_uint8p(s, v, n) do \
{ \
- (v) = (s)->p; \
- (s)->p += (n); \
+ (v) = (s)->p; \
+ (s)->p += (n); \
} while (0)
/******************************************************************************/
#define in_uint8a(s, v, n) do \
{ \
- g_memcpy((v), (s)->p, (n)); \
- (s)->p += (n); \
+ g_memcpy((v), (s)->p, (n)); \
+ (s)->p += (n); \
} while (0)
/******************************************************************************/
#define in_uint8s(s, n) \
- (s)->p += (n)
+ (s)->p += (n)
/******************************************************************************/
#define out_uint8p(s, v, n) do \
{ \
- g_memcpy((s)->p, (v), (n)); \
- (s)->p += (n); \
+ g_memcpy((s)->p, (v), (n)); \
+ (s)->p += (n); \
} while (0)
/******************************************************************************/
#define out_uint8a(s, v, n) \
- out_uint8p((s), (v), (n))
+ out_uint8p((s), (v), (n))
/******************************************************************************/
#define out_uint8s(s, n) do \
{ \
- g_memset((s)->p, 0, (n)); \
- (s)->p += (n); \
+ g_memset((s)->p, 0, (n)); \
+ (s)->p += (n); \
} while (0)
/*
diff --git a/common/trans.c b/common/trans.c
index aa75e5f1..e9fc7bd5 100644
--- a/common/trans.c
+++ b/common/trans.c
@@ -24,12 +24,13 @@
#include "parse.h"
/*****************************************************************************/
-struct trans *APP_CC
+struct trans *
+APP_CC
trans_create(int mode, int in_size, int out_size)
{
- struct trans *self = (struct trans *)NULL;
+ struct trans *self = (struct trans *) NULL;
- self = (struct trans *)g_malloc(sizeof(struct trans), 1);
+ self = (struct trans *) g_malloc(sizeof(struct trans), 1);
if (self != NULL)
{
@@ -38,6 +39,10 @@ trans_create(int mode, int in_size, int out_size)
make_stream(self->out_s);
init_stream(self->out_s, out_size);
self->mode = mode;
+ self->tls = 0;
+ /* assign tcp functions */
+ self->trans_read_call = trans_tcp_force_read_s;
+ self->trans_write_call = trans_tcp_force_write_s;
}
return self;
@@ -68,6 +73,11 @@ trans_delete(struct trans *self)
g_free(self->listen_filename);
}
+ if (self->tls != 0)
+ {
+ xrdp_tls_delete(self->tls);
+ }
+
g_free(self);
}
@@ -92,8 +102,7 @@ trans_get_wait_objs(struct trans *self, tbus *objs, int *count)
/*****************************************************************************/
int APP_CC
-trans_get_wait_objs_rw(struct trans *self,
- tbus *robjs, int *rcount,
+trans_get_wait_objs_rw(struct trans *self, tbus *robjs, int *rcount,
tbus *wobjs, int *wcount)
{
if (self == 0)
@@ -174,8 +183,8 @@ send_waiting(struct trans *self, int block)
int APP_CC
trans_check_wait_objs(struct trans *self)
{
- tbus in_sck = (tbus)0;
- struct trans *in_trans = (struct trans *)NULL;
+ tbus in_sck = (tbus) 0;
+ struct trans *in_trans = (struct trans *) NULL;
int read_bytes = 0;
int to_read = 0;
int read_so_far = 0;
@@ -224,8 +233,10 @@ trans_check_wait_objs(struct trans *self)
in_trans->type1 = TRANS_TYPE_SERVER;
in_trans->status = TRANS_STATUS_UP;
in_trans->is_term = self->is_term;
- g_strncpy(in_trans->addr, self->addr, sizeof(self->addr) - 1);
- g_strncpy(in_trans->port, self->port, sizeof(self->port) - 1);
+ g_strncpy(in_trans->addr, self->addr,
+ sizeof(self->addr) - 1);
+ g_strncpy(in_trans->port, self->port,
+ sizeof(self->port) - 1);
if (self->trans_conn_in(self, in_trans) != 0)
{
@@ -243,7 +254,7 @@ trans_check_wait_objs(struct trans *self)
{
if (g_tcp_can_recv(self->sck, 0))
{
- read_so_far = (int)(self->in_s->end - self->in_s->data);
+ read_so_far = (int) (self->in_s->end - self->in_s->data);
to_read = self->header_size - read_so_far;
if (to_read > 0)
@@ -275,7 +286,7 @@ trans_check_wait_objs(struct trans *self)
}
}
- read_so_far = (int)(self->in_s->end - self->in_s->data);
+ read_so_far = (int) (self->in_s->end - self->in_s->data);
if (read_so_far == self->header_size)
{
@@ -299,11 +310,16 @@ trans_check_wait_objs(struct trans *self)
return rv;
}
-
/*****************************************************************************/
int APP_CC
trans_force_read_s(struct trans *self, struct stream *in_s, int size)
{
+ return self->trans_read_call(self, in_s, size);
+}
+/*****************************************************************************/
+int APP_CC
+trans_tcp_force_read_s(struct trans *self, struct stream *in_s, int size)
+{
int rcvd;
if (self->status != TRANS_STATUS_UP)
@@ -318,7 +334,9 @@ trans_force_read_s(struct trans *self, struct stream *in_s, int size)
{
return 1;
}
+
rcvd = g_tcp_recv(self->sck, in_s->end, size, 0);
+
if (rcvd == -1)
{
if (g_tcp_last_error_would_block(self->sck))
@@ -371,6 +389,12 @@ trans_force_read(struct trans *self, int size)
int APP_CC
trans_force_write_s(struct trans *self, struct stream *out_s)
{
+ return self->trans_write_call(self, out_s);
+}
+/*****************************************************************************/
+int APP_CC
+trans_tcp_force_write_s(struct trans *self, struct stream *out_s)
+{
int size;
int total;
int sent;
@@ -380,7 +404,7 @@ trans_force_write_s(struct trans *self, struct stream *out_s)
return 1;
}
- size = (int)(out_s->end - out_s->data);
+ size = (int) (out_s->end - out_s->data);
total = 0;
if (send_waiting(self, 1) != 0)
@@ -455,7 +479,7 @@ trans_write_copy(struct trans *self)
}
out_s = self->out_s;
- size = (int)(out_s->end - out_s->data);
+ size = (int) (out_s->end - out_s->data);
make_stream(wait_s);
init_stream(wait_s, size);
out_uint8a(wait_s, out_s->data, size);
@@ -610,14 +634,15 @@ trans_listen(struct trans *self, char *port)
}
/*****************************************************************************/
-struct stream *APP_CC
+struct stream *
+APP_CC
trans_get_in_s(struct trans *self)
{
- struct stream *rv = (struct stream *)NULL;
+ struct stream *rv = (struct stream *) NULL;
if (self == NULL)
{
- rv = (struct stream *)NULL;
+ rv = (struct stream *) NULL;
}
else
{
@@ -628,14 +653,15 @@ trans_get_in_s(struct trans *self)
}
/*****************************************************************************/
-struct stream *APP_CC
+struct stream *
+APP_CC
trans_get_out_s(struct trans *self, int size)
{
- struct stream *rv = (struct stream *)NULL;
+ struct stream *rv = (struct stream *) NULL;
if (self == NULL)
{
- rv = (struct stream *)NULL;
+ rv = (struct stream *) NULL;
}
else
{
@@ -645,3 +671,43 @@ trans_get_out_s(struct trans *self, int size)
return rv;
}
+/*****************************************************************************/
+/* returns error */
+int APP_CC
+trans_set_tls_mode(struct trans *self, const char *key, const char *cert)
+{
+ self->tls = xrdp_tls_create(self, key, cert);
+ if (self->tls == NULL)
+ {
+ g_writeln("trans_set_tls_mode: xrdp_tls_create malloc error");
+ return 1;
+ }
+
+ if (xrdp_tls_accept(self->tls) != 0)
+ {
+ g_writeln("trans_set_tls_mode: xrdp_tls_accept failed");
+ return 1;
+ }
+
+ /* assign tls functions */
+ self->trans_read_call = xrdp_tls_force_read_s;
+ self->trans_write_call = xrdp_tls_force_write_s;
+
+ return 0;
+}
+/*****************************************************************************/
+/* returns error */
+int APP_CC
+trans_shutdown_tls_mode(struct trans *self)
+{
+ if (self->tls != NULL)
+ {
+ return xrdp_tls_disconnect(self->tls);
+ }
+
+ /* set callback back to tcp
+ self->trans_read_call = trans_tcp_force_read_s;
+ self->trans_write_call = trans_tcp_force_write_s;
+ */
+ return 0;
+}
diff --git a/common/trans.h b/common/trans.h
index 4a8b249c..c28d420b 100644
--- a/common/trans.h
+++ b/common/trans.h
@@ -23,6 +23,7 @@
#include "arch.h"
#include "parse.h"
+#include <openssl/ssl.h>
#define TRANS_MODE_TCP 1
#define TRANS_MODE_UNIX 2
@@ -35,11 +36,14 @@
#define TRANS_STATUS_UP 1
struct trans; /* forward declaration */
+struct xrdp_tls;
typedef int (DEFAULT_CC *ttrans_data_in)(struct trans* self);
typedef int (DEFAULT_CC *ttrans_conn_in)(struct trans* self,
struct trans* new_self);
typedef int (DEFAULT_CC *tis_term)(void);
+typedef int (APP_CC *trans_read_call) (struct trans *self, struct stream *in_s, int size);
+typedef int (APP_CC *trans_write_call) (struct trans *self, struct stream *out_s);
struct trans
{
@@ -60,8 +64,35 @@ struct trans
char port[256];
int no_stream_init_on_data_in;
int extra_flags; /* user defined */
+ struct xrdp_tls *tls;
+ trans_read_call trans_read_call;
+ trans_write_call trans_write_call;
};
+/* xrdp_tls */
+struct xrdp_tls
+{
+ SSL *ssl;
+ SSL_CTX *ctx;
+ char *cert;
+ char *key;
+ struct trans *trans;
+};
+
+/* xrdp_tls.c */
+struct xrdp_tls *APP_CC
+xrdp_tls_create(struct trans *trans, const char *key, const char *cert);
+int APP_CC
+xrdp_tls_accept(struct xrdp_tls *self);
+int APP_CC
+xrdp_tls_disconnect(struct xrdp_tls *self);
+void APP_CC
+xrdp_tls_delete(struct xrdp_tls *self);
+int APP_CC
+xrdp_tls_force_read_s(struct trans *self, struct stream *in_s, int size);
+int APP_CC
+xrdp_tls_force_write_s(struct trans *self, struct stream *out_s);
+
struct trans* APP_CC
trans_create(int mode, int in_size, int out_size);
void APP_CC
@@ -95,5 +126,13 @@ struct stream* APP_CC
trans_get_in_s(struct trans* self);
struct stream* APP_CC
trans_get_out_s(struct trans* self, int size);
+int APP_CC
+trans_set_tls_mode(struct trans *self, const char *key, const char *cert);
+int APP_CC
+trans_shutdown_tls_mode(struct trans *self);
+int APP_CC
+trans_tcp_force_read_s(struct trans *self, struct stream *in_s, int size);
+int APP_CC
+trans_tcp_force_write_s(struct trans *self, struct stream *out_s);
#endif
diff --git a/common/xrdp_client_info.h b/common/xrdp_client_info.h
index bccb4436..59915f37 100644
--- a/common/xrdp_client_info.h
+++ b/common/xrdp_client_info.h
@@ -125,6 +125,9 @@ struct xrdp_client_info
int capture_code;
int capture_format;
+ char certificate[1024];
+ char key_file[1024];
+
};
#endif
diff --git a/common/xrdp_rail.h b/common/xrdp_rail.h
index 26605cd9..b93672be 100644
--- a/common/xrdp_rail.h
+++ b/common/xrdp_rail.h
@@ -72,76 +72,76 @@
struct rail_icon_info
{
- int bpp;
- int width;
- int height;
- int cmap_bytes;
- int mask_bytes;
- int data_bytes;
- char* mask;
- char* cmap;
- char* data;
+ int bpp;
+ int width;
+ int height;
+ int cmap_bytes;
+ int mask_bytes;
+ int data_bytes;
+ char *mask;
+ char *cmap;
+ char *data;
};
struct rail_window_rect
{
- short left;
- short top;
- short right;
- short bottom;
+ short left;
+ short top;
+ short right;
+ short bottom;
};
struct rail_notify_icon_infotip
{
- int timeout;
- int flags;
- char* text;
- char* title;
+ int timeout;
+ int flags;
+ char *text;
+ char *title;
};
struct rail_window_state_order
{
- int owner_window_id;
- int style;
- int extended_style;
- int show_state;
- char* title_info;
- int client_offset_x;
- int client_offset_y;
- int client_area_width;
- int client_area_height;
- int rp_content;
- int root_parent_handle;
- int window_offset_x;
- int window_offset_y;
- int window_client_delta_x;
- int window_client_delta_y;
- int window_width;
- int window_height;
- int num_window_rects;
- struct rail_window_rect* window_rects;
- int visible_offset_x;
- int visible_offset_y;
- int num_visibility_rects;
- struct rail_window_rect* visibility_rects;
+ int owner_window_id;
+ int style;
+ int extended_style;
+ int show_state;
+ char *title_info;
+ int client_offset_x;
+ int client_offset_y;
+ int client_area_width;
+ int client_area_height;
+ int rp_content;
+ int root_parent_handle;
+ int window_offset_x;
+ int window_offset_y;
+ int window_client_delta_x;
+ int window_client_delta_y;
+ int window_width;
+ int window_height;
+ int num_window_rects;
+ struct rail_window_rect *window_rects;
+ int visible_offset_x;
+ int visible_offset_y;
+ int num_visibility_rects;
+ struct rail_window_rect *visibility_rects;
};
struct rail_notify_state_order
{
- int version;
- char* tool_tip;
- struct rail_notify_icon_infotip infotip;
- int state;
- int icon_cache_entry;
- int icon_cache_id;
- struct rail_icon_info icon_info;
+ int version;
+ char *tool_tip;
+ struct rail_notify_icon_infotip infotip;
+ int state;
+ int icon_cache_entry;
+ int icon_cache_id;
+ struct rail_icon_info icon_info;
};
struct rail_monitored_desktop_order
{
- int active_window_id;
- int num_window_ids;
- int* window_ids;
+ int active_window_id;
+ int num_window_ids;
+ int *window_ids;
};
#endif
diff --git a/common/xrdp_tls.c b/common/xrdp_tls.c
new file mode 100644
index 00000000..48f6b827
--- /dev/null
+++ b/common/xrdp_tls.c
@@ -0,0 +1,435 @@
+/**
+ * xrdp: A Remote Desktop Protocol server.
+ *
+ * Copyright (C) Idan Freiberg 2013-2014
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ *
+ * transport layer security
+ */
+
+#include "trans.h"
+#include "ssl_calls.h"
+
+/*****************************************************************************/
+struct xrdp_tls *
+APP_CC
+xrdp_tls_create(struct trans *trans, const char *key, const char *cert)
+{
+ struct xrdp_tls *self;
+ self = (struct xrdp_tls *) g_malloc(sizeof(struct xrdp_tls), 1);
+
+ if (self != NULL)
+ {
+ self->trans = trans;
+ self->cert = (char *) cert;
+ self->key = (char *) key;
+ }
+
+ return self;
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_accept(struct xrdp_tls *self)
+{
+ int connection_status;
+ long options = 0;
+
+ /**
+ * SSL_OP_NO_SSLv2:
+ *
+ * We only want SSLv3 and TLSv1, so disable SSLv2.
+ * SSLv3 is used by, eg. Microsoft RDC for Mac OS X.
+ */
+ options |= SSL_OP_NO_SSLv2;
+
+ /**
+ * SSL_OP_NO_COMPRESSION:
+ *
+ * The Microsoft RDP server does not advertise support
+ * for TLS compression, but alternative servers may support it.
+ * This was observed between early versions of the FreeRDP server
+ * and the FreeRDP client, and caused major performance issues,
+ * which is why we're disabling it.
+ */
+ options |= SSL_OP_NO_COMPRESSION;
+
+ /**
+ * SSL_OP_TLS_BLOCK_PADDING_BUG:
+ *
+ * The Microsoft RDP server does *not* support TLS padding.
+ * It absolutely needs to be disabled otherwise it won't work.
+ */
+ options |= SSL_OP_TLS_BLOCK_PADDING_BUG;
+
+ /**
+ * SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS:
+ *
+ * Just like TLS padding, the Microsoft RDP server does not
+ * support empty fragments. This needs to be disabled.
+ */
+ options |= SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS;
+
+ self->ctx = SSL_CTX_new(SSLv23_server_method());
+ /* set context options */
+ SSL_CTX_set_mode(self->ctx,
+ SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER |
+ SSL_MODE_ENABLE_PARTIAL_WRITE);
+ SSL_CTX_set_options(self->ctx, options);
+ SSL_CTX_set_read_ahead(self->ctx, 1);
+
+ if (self->ctx == NULL)
+ {
+ g_writeln("xrdp_tls_accept: SSL_CTX_new failed");
+ return 1;
+ }
+
+ if (SSL_CTX_use_RSAPrivateKey_file(self->ctx, self->key, SSL_FILETYPE_PEM)
+ <= 0)
+ {
+ g_writeln("xrdp_tls_accept: SSL_CTX_use_RSAPrivateKey_file failed");
+ return 1;
+ }
+
+ self->ssl = SSL_new(self->ctx);
+
+ if (self->ssl == NULL)
+ {
+ g_writeln("xrdp_tls_accept: SSL_new failed");
+ return 1;
+ }
+
+ if (SSL_use_certificate_file(self->ssl, self->cert, SSL_FILETYPE_PEM) <= 0)
+ {
+ g_writeln("xrdp_tls_accept: SSL_use_certificate_file failed");
+ return 1;
+ }
+
+ if (SSL_set_fd(self->ssl, self->trans->sck) < 1)
+ {
+ g_writeln("xrdp_tls_accept: SSL_set_fd failed");
+ return 1;
+ }
+
+ connection_status = SSL_accept(self->ssl);
+
+ if (connection_status <= 0)
+ {
+ if (xrdp_tls_print_error("SSL_accept", self->ssl, connection_status))
+ {
+ return 1;
+ }
+ }
+
+ g_writeln("xrdp_tls_accept: TLS connection accepted");
+
+ return 0;
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_print_error(char *func, SSL *connection, int value)
+{
+ switch (SSL_get_error(connection, value))
+ {
+ case SSL_ERROR_ZERO_RETURN:
+ g_writeln("xrdp_tls_print_error: %s: Server closed TLS connection",
+ func);
+ return 1;
+
+ case SSL_ERROR_WANT_READ:
+ g_writeln("xrdp_tls_print_error: SSL_ERROR_WANT_READ");
+ return 0;
+
+ case SSL_ERROR_WANT_WRITE:
+ g_writeln("xrdp_tls_print_error: SSL_ERROR_WANT_WRITE");
+ return 0;
+
+ case SSL_ERROR_SYSCALL:
+ g_writeln("xrdp_tls_print_error: %s: I/O error", func);
+ return 1;
+
+ case SSL_ERROR_SSL:
+ g_writeln(
+ "xrdp_tls_print_error: %s: Failure in SSL library (protocol error?)",
+ func);
+ return 1;
+
+ default:
+ g_writeln("xrdp_tls_print_error: %s: Unknown error", func);
+ return 1;
+ }
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_disconnect(struct xrdp_tls *self)
+{
+ int status = SSL_shutdown(self->ssl);
+ while (status != 1)
+ {
+ status = SSL_shutdown(self->ssl);
+
+ if (status <= 0)
+ {
+ if (xrdp_tls_print_error("SSL_shutdown", self->ssl, status))
+ {
+ return 1;
+ }
+ }
+ }
+ return 0;
+}
+/*****************************************************************************/
+void APP_CC
+xrdp_tls_delete(struct xrdp_tls *self)
+{
+ if (self != NULL)
+ {
+ if (self->ssl)
+ SSL_free(self->ssl);
+
+ if (self->ctx)
+ SSL_CTX_free(self->ctx);
+
+ g_free(self);
+ }
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_read(struct xrdp_tls *tls, unsigned char *data, int length)
+{
+ int status;
+
+ status = SSL_read(tls->ssl, data, length);
+
+ switch (SSL_get_error(tls->ssl, status))
+ {
+ case SSL_ERROR_NONE:
+ break;
+
+ case SSL_ERROR_WANT_READ:
+ case SSL_ERROR_WANT_WRITE:
+ status = 0;
+ break;
+
+ default:
+ xrdp_tls_print_error("SSL_read", tls->ssl, status);
+ status = -1;
+ break;
+ }
+
+ return status;
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_write(struct xrdp_tls *tls, unsigned char *data, int length)
+{
+ int status;
+
+ status = SSL_write(tls->ssl, data, length);
+
+ switch (SSL_get_error(tls->ssl, status))
+ {
+ case SSL_ERROR_NONE:
+ break;
+
+ case SSL_ERROR_WANT_READ:
+ case SSL_ERROR_WANT_WRITE:
+ status = 0;
+ break;
+
+ default:
+ xrdp_tls_print_error("SSL_write", tls->ssl, status);
+ status = -1;
+ break;
+ }
+
+ return status;
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_force_read_s(struct trans *self, struct stream *in_s, int size)
+{
+ int rcvd;
+
+ if (self->status != TRANS_STATUS_UP)
+ {
+ return 1;
+ }
+
+ while (size > 0)
+ {
+ /* make sure stream has room */
+ if ((in_s->end + size) > (in_s->data + in_s->size))
+ {
+ return 1;
+ }
+
+ rcvd = xrdp_tls_read(self->tls, in_s->end, size);
+
+ if (rcvd == -1)
+ {
+ if (g_tcp_last_error_would_block(self->sck))
+ {
+ if (!g_tcp_can_recv(self->sck, 100))
+ {
+ /* check for term here */
+ if (self->is_term != 0)
+ {
+ if (self->is_term())
+ {
+ /* term */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ }
+ }
+ }
+ else
+ {
+ /* error */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ }
+ else if (rcvd == 0)
+ {
+ /* error */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ else
+ {
+ in_s->end += rcvd;
+ size -= rcvd;
+ }
+ }
+
+ return 0;
+}
+
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_force_write_s(struct trans *self, struct stream *out_s)
+{
+ int size;
+ int total;
+ int sent;
+
+ if (self->status != TRANS_STATUS_UP)
+ {
+ return 1;
+ }
+
+ size = (int) (out_s->end - out_s->data);
+ total = 0;
+
+ if (xrdp_tls_send_waiting(self, 1) != 0)
+ {
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+
+ while (total < size)
+ {
+ sent = xrdp_tls_write(self->tls, out_s->data + total, size - total);
+
+ if (sent == -1)
+ {
+ if (g_tcp_last_error_would_block(self->sck))
+ {
+ if (!g_tcp_can_send(self->sck, 100))
+ {
+ /* check for term here */
+ if (self->is_term != 0)
+ {
+ if (self->is_term())
+ {
+ /* term */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ }
+ }
+ }
+ else
+ {
+ /* error */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ }
+ else if (sent == 0)
+ {
+ /* error */
+ self->status = TRANS_STATUS_DOWN;
+ return 1;
+ }
+ else
+ {
+ total = total + sent;
+ }
+ }
+
+ return 0;
+}
+/*****************************************************************************/
+int APP_CC
+xrdp_tls_send_waiting(struct trans *self, int block)
+{
+ struct stream *temp_s;
+ int bytes;
+ int sent;
+ int timeout;
+ int cont;
+
+ timeout = block ? 100 : 0;
+ cont = 1;
+ while (cont)
+ {
+ if (self->wait_s != 0)
+ {
+ temp_s = self->wait_s;
+ if (g_tcp_can_send(self->sck, timeout))
+ {
+ bytes = (int) (temp_s->end - temp_s->p);
+ sent = xrdp_tls_write(self->tls, temp_s->p, bytes);
+ if (sent > 0)
+ {
+ temp_s->p += sent;
+ if (temp_s->p >= temp_s->end)
+ {
+ self->wait_s = (struct stream *) (temp_s->next_packet);
+ free_stream(temp_s);
+ }
+ }
+ else if (sent == 0)
+ {
+ return 1;
+ }
+ else
+ {
+ if (!g_tcp_last_error_would_block(self->sck))
+ {
+ return 1;
+ }
+ }
+ }
+ }
+ else
+ {
+ break;
+ }
+ cont = block;
+ }
+ return 0;
+}