FreeRDP
Loading...
Searching...
No Matches
fastpath.c
1
23#include <freerdp/config.h>
24
25#include "settings.h"
26
27#include <stdio.h>
28#include <stdlib.h>
29#include <string.h>
30
31#include <winpr/crt.h>
32#include <winpr/assert.h>
33#include <winpr/stream.h>
34
35#include <freerdp/api.h>
36#include <freerdp/log.h>
37#include <freerdp/crypto/per.h>
38
39#include "orders.h"
40#include "update.h"
41#include "surface.h"
42#include "fastpath.h"
43#include "rdp.h"
44
45#include "../cache/pointer.h"
46#include "../cache/palette.h"
47#include "../cache/bitmap.h"
48
49#define TAG FREERDP_TAG("core.fastpath")
50
51enum FASTPATH_INPUT_ENCRYPTION_FLAGS
52{
53 FASTPATH_INPUT_SECURE_CHECKSUM = 0x1,
54 FASTPATH_INPUT_ENCRYPTED = 0x2
55};
56
57enum FASTPATH_OUTPUT_ENCRYPTION_FLAGS
58{
59 FASTPATH_OUTPUT_SECURE_CHECKSUM = 0x1,
60 FASTPATH_OUTPUT_ENCRYPTED = 0x2
61};
62
63struct rdp_fastpath
64{
65 rdpRdp* rdp;
66 wStream* fs;
67 BYTE encryptionFlags;
68 BYTE numberEvents;
69 wStream* updateData;
70 int fragmentation;
71};
72
83static const char* const FASTPATH_UPDATETYPE_STRINGS[] = {
84 "Orders", /* 0x0 */
85 "Bitmap", /* 0x1 */
86 "Palette", /* 0x2 */
87 "Synchronize", /* 0x3 */
88 "Surface Commands", /* 0x4 */
89 "System Pointer Hidden", /* 0x5 */
90 "System Pointer Default", /* 0x6 */
91 "???", /* 0x7 */
92 "Pointer Position", /* 0x8 */
93 "Color Pointer", /* 0x9 */
94 "Cached Pointer", /* 0xA */
95 "New Pointer", /* 0xB */
96};
97
98static const char* fastpath_update_to_string(UINT8 update)
99{
100 if (update >= ARRAYSIZE(FASTPATH_UPDATETYPE_STRINGS))
101 return "UNKNOWN";
102
103 return FASTPATH_UPDATETYPE_STRINGS[update];
104}
105
106static BOOL fastpath_read_update_header(wStream* s, BYTE* updateCode, BYTE* fragmentation,
107 BYTE* compression)
108{
109 BYTE updateHeader = 0;
110
111 if (!s || !updateCode || !fragmentation || !compression)
112 return FALSE;
113
114 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
115 return FALSE;
116
117 Stream_Read_UINT8(s, updateHeader);
118 *updateCode = updateHeader & 0x0F;
119 *fragmentation = (updateHeader >> 4) & 0x03;
120 *compression = (updateHeader >> 6) & 0x03;
121 return TRUE;
122}
123
124static BOOL fastpath_write_update_header(wStream* s, const FASTPATH_UPDATE_HEADER* fpUpdateHeader)
125{
126 BYTE updateHeader = 0;
127 WINPR_ASSERT(fpUpdateHeader);
128
129 updateHeader |= fpUpdateHeader->updateCode & 0x0F;
130 updateHeader |= (fpUpdateHeader->fragmentation & 0x03) << 4;
131 updateHeader |= (fpUpdateHeader->compression & 0x03) << 6;
132
133 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 1))
134 return FALSE;
135 Stream_Write_UINT8(s, updateHeader);
136
137 if (fpUpdateHeader->compression)
138 {
139 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 1))
140 return FALSE;
141
142 Stream_Write_UINT8(s, fpUpdateHeader->compressionFlags);
143 }
144
145 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 2))
146 return FALSE;
147
148 Stream_Write_UINT16(s, fpUpdateHeader->size);
149 return TRUE;
150}
151
152static UINT32 fastpath_get_update_header_size(FASTPATH_UPDATE_HEADER* fpUpdateHeader)
153{
154 WINPR_ASSERT(fpUpdateHeader);
155 return (fpUpdateHeader->compression) ? 4 : 3;
156}
157
158static BOOL fastpath_write_update_pdu_header(wStream* s,
159 const FASTPATH_UPDATE_PDU_HEADER* fpUpdatePduHeader,
160 rdpRdp* rdp)
161{
162 BYTE fpOutputHeader = 0;
163 WINPR_ASSERT(fpUpdatePduHeader);
164 WINPR_ASSERT(rdp);
165
166 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 3))
167 return FALSE;
168
169 fpOutputHeader |= (fpUpdatePduHeader->action & 0x03);
170 fpOutputHeader |= (fpUpdatePduHeader->secFlags & 0x03) << 6;
171 Stream_Write_UINT8(s, fpOutputHeader); /* fpOutputHeader (1 byte) */
172 Stream_Write_UINT8(s, 0x80 | (fpUpdatePduHeader->length >> 8)); /* length1 */
173 Stream_Write_UINT8(s, fpUpdatePduHeader->length & 0xFF); /* length2 */
174
175 if (fpUpdatePduHeader->secFlags)
176 {
177 WINPR_ASSERT(rdp->settings);
178 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
179 ENCRYPTION_METHOD_FIPS)
180 {
181 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 4))
182 return FALSE;
183
184 Stream_Write(s, fpUpdatePduHeader->fipsInformation, 4);
185 }
186
187 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 8))
188 return FALSE;
189
190 Stream_Write(s, fpUpdatePduHeader->dataSignature, 8);
191 }
192
193 return TRUE;
194}
195
196static UINT32 fastpath_get_update_pdu_header_size(FASTPATH_UPDATE_PDU_HEADER* fpUpdatePduHeader,
197 rdpRdp* rdp)
198{
199 UINT32 size = 3; /* fpUpdatePduHeader + length1 + length2 */
200
201 if (!fpUpdatePduHeader || !rdp)
202 return 0;
203
204 if (fpUpdatePduHeader->secFlags)
205 {
206 size += 8; /* dataSignature */
207
208 WINPR_ASSERT(rdp->settings);
209 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
210 ENCRYPTION_METHOD_FIPS)
211 size += 4; /* fipsInformation */
212 }
213
214 return size;
215}
216
217BOOL fastpath_read_header_rdp(rdpFastPath* fastpath, wStream* s, UINT16* length)
218{
219 BYTE header = 0;
220
221 if (!s || !length)
222 return FALSE;
223
224 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
225 return FALSE;
226
227 Stream_Read_UINT8(s, header);
228
229 if (fastpath)
230 {
231 fastpath->encryptionFlags = (header & 0xC0) >> 6;
232 fastpath->numberEvents = (header & 0x3C) >> 2;
233 }
234
235 if (!per_read_length(s, length))
236 return FALSE;
237
238 const size_t pos = Stream_GetPosition(s);
239 if (pos > *length)
240 return FALSE;
241
242 *length = *length - (UINT16)pos;
243 return TRUE;
244}
245
246static BOOL fastpath_recv_orders(rdpUpdate* update, wStream* s)
247{
248 UINT16 numberOrders = 0;
249
250 if (!s)
251 {
252 WLog_ERR(TAG, "Invalid arguments");
253 return FALSE;
254 }
255
256 if (!update)
257 {
258 WLog_ERR(TAG, "Invalid configuration");
259 return FALSE;
260 }
261
262 if (!Stream_CheckAndLogRequiredLength(TAG, s, 2))
263 return FALSE;
264
265 Stream_Read_UINT16(s, numberOrders); /* numberOrders (2 bytes) */
266
267 while (numberOrders > 0)
268 {
269 if (!update_recv_order(update, s))
270 return FALSE;
271
272 numberOrders--;
273 }
274
275 return TRUE;
276}
277
278static BOOL fastpath_recv_update_common(rdpUpdate* update, wStream* s)
279{
280 BOOL rc = FALSE;
281 UINT16 updateType = 0;
282 BOOL defaultReturn = 0;
283
284 rdp_update_internal* up = update_cast(update);
285 if (!s)
286 return FALSE;
287
288 if (!update || !update->context)
289 return FALSE;
290
291 rdpContext* context = update->context;
292
293 defaultReturn = freerdp_settings_get_bool(context->settings, FreeRDP_DeactivateClientDecoding);
294
295 if (!Stream_CheckAndLogRequiredLength(TAG, s, 2))
296 return FALSE;
297
298 Stream_Read_UINT16(s, updateType); /* updateType (2 bytes) */
299 switch (updateType)
300 {
301 case UPDATE_TYPE_BITMAP:
302 {
303 BITMAP_UPDATE* bitmap_update = update_read_bitmap_update(update, s);
304
305 if (!bitmap_update)
306 return FALSE;
307
308 up->stats.base[RDP_STATS_BITMAP_UPDATE]++;
309 rc = IFCALLRESULT(defaultReturn, update->BitmapUpdate, context, bitmap_update);
310 free_bitmap_update(context, bitmap_update);
311 }
312 break;
313
314 case UPDATE_TYPE_PALETTE:
315 {
316 PALETTE_UPDATE* palette_update = update_read_palette(update, s);
317
318 if (!palette_update)
319 return FALSE;
320
321 up->stats.base[RDP_STATS_PALETTE]++;
322 rc = IFCALLRESULT(defaultReturn, update->Palette, context, palette_update);
323 free_palette_update(context, palette_update);
324 }
325 break;
326
327 default:
328 break;
329 }
330
331 return rc;
332}
333
334static BOOL fastpath_recv_update_synchronize(WINPR_ATTR_UNUSED rdpFastPath* fastpath, wStream* s)
335{
336 /* server 2008 can send invalid synchronize packet with missing padding,
337 so don't return FALSE even if the packet is invalid */
338 WINPR_ASSERT(fastpath);
339 WINPR_ASSERT(s);
340
341 const size_t len = Stream_GetRemainingLength(s);
342 const size_t skip = MIN(2, len);
343 return Stream_SafeSeek(s, skip); /* size (2 bytes), MUST be set to zero */
344}
345
346static BOOL fastpath_recv_update_paint_block(rdpUpdate* update, wStream* s,
347 BOOL (*fkt)(rdpUpdate*, wStream*))
348{
349 WINPR_ASSERT(fkt);
350 if (!update_begin_paint(update))
351 return FALSE;
352
353 BOOL res = fkt(update, s);
354 if (!update_end_paint(update))
355 return FALSE;
356 return res;
357}
358
359static int fastpath_recv_update(rdpFastPath* fastpath, BYTE updateCode, wStream* s)
360{
361 BOOL rc = FALSE;
362 int status = 0;
363
364 if (!fastpath || !fastpath->rdp || !s)
365 return -1;
366
367 Stream_SealLength(s);
368 Stream_ResetPosition(s);
369
370 rdpUpdate* update = fastpath->rdp->update;
371
372 if (!update || !update->pointer || !update->context)
373 return -1;
374
375 rdp_update_internal* up = update_cast(update);
376
377 rdpContext* context = update->context;
378 WINPR_ASSERT(context);
379
380 rdpPointerUpdate* pointer = update->pointer;
381 WINPR_ASSERT(pointer);
382
383#ifdef WITH_DEBUG_RDP
384 DEBUG_RDP(fastpath->rdp, "recv Fast-Path %s Update (0x%02" PRIX8 "), length:%" PRIuz "",
385 fastpath_update_to_string(updateCode), updateCode, Stream_GetRemainingLength(s));
386#endif
387
388 const BOOL defaultReturn =
389 freerdp_settings_get_bool(context->settings, FreeRDP_DeactivateClientDecoding);
390 switch (updateCode)
391 {
392 case FASTPATH_UPDATETYPE_ORDERS:
393 rc = fastpath_recv_update_paint_block(update, s, fastpath_recv_orders);
394 break;
395
396 case FASTPATH_UPDATETYPE_BITMAP:
397 case FASTPATH_UPDATETYPE_PALETTE:
398 rc = fastpath_recv_update_paint_block(update, s, fastpath_recv_update_common);
399 break;
400
401 case FASTPATH_UPDATETYPE_SYNCHRONIZE:
402 if (!fastpath_recv_update_synchronize(fastpath, s))
403 WLog_ERR(TAG, "fastpath_recv_update_synchronize failure but we continue");
404 else
405 {
406 up->stats.base[RDP_STATS_SYNC]++;
407 rc = IFCALLRESULT(TRUE, update->Synchronize, context);
408 }
409
410 break;
411
412 case FASTPATH_UPDATETYPE_SURFCMDS:
413 status = fastpath_recv_update_paint_block(update, s, update_recv_surfcmds);
414 rc = (status >= 0);
415 break;
416
417 case FASTPATH_UPDATETYPE_PTR_NULL:
418 {
419 POINTER_SYSTEM_UPDATE pointer_system = WINPR_C_ARRAY_INIT;
420 pointer_system.type = SYSPTR_NULL;
421 up->stats.base[RDP_STATS_POINTER_SYSTEM]++;
422 rc = IFCALLRESULT(defaultReturn, pointer->PointerSystem, context, &pointer_system);
423 }
424 break;
425
426 case FASTPATH_UPDATETYPE_PTR_DEFAULT:
427 {
428 POINTER_SYSTEM_UPDATE pointer_system = WINPR_C_ARRAY_INIT;
429 pointer_system.type = SYSPTR_DEFAULT;
430 up->stats.base[RDP_STATS_POINTER_DEFAULT]++;
431 rc = IFCALLRESULT(defaultReturn, pointer->PointerSystem, context, &pointer_system);
432 }
433 break;
434
435 case FASTPATH_UPDATETYPE_PTR_POSITION:
436 {
437 POINTER_POSITION_UPDATE* pointer_position = update_read_pointer_position(update, s);
438
439 if (pointer_position)
440 {
441 up->stats.base[RDP_STATS_POINTER_POSITION]++;
442 rc = IFCALLRESULT(defaultReturn, pointer->PointerPosition, context,
443 pointer_position);
444 free_pointer_position_update(context, pointer_position);
445 }
446 }
447 break;
448
449 case FASTPATH_UPDATETYPE_COLOR:
450 {
451 POINTER_COLOR_UPDATE* pointer_color = update_read_pointer_color(update, s, 24);
452
453 if (pointer_color)
454 {
455 up->stats.base[RDP_STATS_POINTER_COLOR]++;
456 rc = IFCALLRESULT(defaultReturn, pointer->PointerColor, context, pointer_color);
457 free_pointer_color_update(context, pointer_color);
458 }
459 }
460 break;
461
462 case FASTPATH_UPDATETYPE_CACHED:
463 {
464 POINTER_CACHED_UPDATE* pointer_cached = update_read_pointer_cached(update, s);
465
466 if (pointer_cached)
467 {
468 up->stats.base[RDP_STATS_POINTER_CACHED]++;
469 rc = IFCALLRESULT(defaultReturn, pointer->PointerCached, context, pointer_cached);
470 free_pointer_cached_update(context, pointer_cached);
471 }
472 }
473 break;
474
475 case FASTPATH_UPDATETYPE_POINTER:
476 {
477 POINTER_NEW_UPDATE* pointer_new = update_read_pointer_new(update, s);
478
479 if (pointer_new)
480 {
481 up->stats.base[RDP_STATS_POINTER_NEW]++;
482 rc = IFCALLRESULT(defaultReturn, pointer->PointerNew, context, pointer_new);
483 free_pointer_new_update(context, pointer_new);
484 }
485 }
486 break;
487
488 case FASTPATH_UPDATETYPE_LARGE_POINTER:
489 {
490 POINTER_LARGE_UPDATE* pointer_large = update_read_pointer_large(update, s);
491
492 if (pointer_large)
493 {
494 up->stats.base[RDP_STATS_POINTER_LARGE]++;
495 rc = IFCALLRESULT(defaultReturn, pointer->PointerLarge, context, pointer_large);
496 free_pointer_large_update(context, pointer_large);
497 }
498 }
499 break;
500 default:
501 break;
502 }
503
504 Stream_ResetPosition(s);
505 if (!rc)
506 {
507 WLog_ERR(TAG, "Fastpath update %s [%" PRIx8 "] failed, status %d",
508 fastpath_update_to_string(updateCode), updateCode, status);
509 const BOOL ignore =
510 freerdp_settings_get_bool(context->settings, FreeRDP_AllowUnanouncedOrdersFromServer);
511 if (ignore)
512 return 0;
513 return -1;
514 }
515
516 return status;
517}
518
519static int fastpath_recv_update_data(rdpFastPath* fastpath, wStream* s)
520{
521 int status = 0;
522 UINT16 size = 0;
523 BYTE updateCode = 0;
524 BYTE fragmentation = 0;
525 BYTE compression = 0;
526 BYTE compressionFlags = 0;
527 UINT32 DstSize = 0;
528 const BYTE* pDstData = nullptr;
529
530 if (!fastpath || !s)
531 return -1;
532
533 rdpRdp* rdp = fastpath->rdp;
534
535 if (!rdp)
536 return -1;
537
538 rdpTransport* transport = rdp->transport;
539
540 if (!transport)
541 return -1;
542
543 if (!fastpath_read_update_header(s, &updateCode, &fragmentation, &compression))
544 return -1;
545
546 if (compression == FASTPATH_OUTPUT_COMPRESSION_USED)
547 {
548 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
549 return -1;
550
551 Stream_Read_UINT8(s, compressionFlags);
552 }
553 else
554 compressionFlags = 0;
555
556 if (!Stream_CheckAndLogRequiredLength(TAG, s, 2))
557 return -1;
558
559 Stream_Read_UINT16(s, size);
560
561 if (!Stream_CheckAndLogRequiredLength(TAG, s, size))
562 return -1;
563
564 const int bulkStatus =
565 bulk_decompress(rdp->bulk, Stream_Pointer(s), size, &pDstData, &DstSize, compressionFlags);
566 Stream_Seek(s, size);
567
568 if (bulkStatus < 0)
569 {
570 WLog_ERR(TAG, "bulk_decompress() failed");
571 return -1;
572 }
573
574 if (!Stream_EnsureRemainingCapacity(fastpath->updateData, DstSize))
575 return -1;
576
577 Stream_Write(fastpath->updateData, pDstData, DstSize);
578
579 if (fragmentation == FASTPATH_FRAGMENT_SINGLE)
580 {
581 if (fastpath->fragmentation != -1)
582 {
583 WLog_ERR(TAG, "Unexpected FASTPATH_FRAGMENT_SINGLE");
584 goto out_fail;
585 }
586
587 status = fastpath_recv_update(fastpath, updateCode, fastpath->updateData);
588
589 if (status < 0)
590 {
591 WLog_ERR(TAG, "fastpath_recv_update() - %i", status);
592 goto out_fail;
593 }
594 }
595 else
596 {
597 rdpContext* context = nullptr;
598 const size_t totalSize = Stream_GetPosition(fastpath->updateData);
599
600 context = transport_get_context(transport);
601 WINPR_ASSERT(context);
602 WINPR_ASSERT(context->settings);
603
604 if (totalSize >
605 freerdp_settings_get_uint32(context->settings, FreeRDP_MultifragMaxRequestSize))
606 {
607 WLog_ERR(
608 TAG, "Total size (%" PRIuz ") exceeds MultifragMaxRequestSize (%" PRIu32 ")",
609 totalSize,
610 freerdp_settings_get_uint32(context->settings, FreeRDP_MultifragMaxRequestSize));
611 goto out_fail;
612 }
613
614 if (fragmentation == FASTPATH_FRAGMENT_FIRST)
615 {
616 if (fastpath->fragmentation != -1)
617 {
618 WLog_ERR(TAG, "Unexpected FASTPATH_FRAGMENT_FIRST");
619 goto out_fail;
620 }
621
622 fastpath->fragmentation = FASTPATH_FRAGMENT_FIRST;
623 }
624 else if (fragmentation == FASTPATH_FRAGMENT_NEXT)
625 {
626 if ((fastpath->fragmentation != FASTPATH_FRAGMENT_FIRST) &&
627 (fastpath->fragmentation != FASTPATH_FRAGMENT_NEXT))
628 {
629 WLog_ERR(TAG, "Unexpected FASTPATH_FRAGMENT_NEXT");
630 goto out_fail;
631 }
632
633 fastpath->fragmentation = FASTPATH_FRAGMENT_NEXT;
634 }
635 else if (fragmentation == FASTPATH_FRAGMENT_LAST)
636 {
637 if ((fastpath->fragmentation != FASTPATH_FRAGMENT_FIRST) &&
638 (fastpath->fragmentation != FASTPATH_FRAGMENT_NEXT))
639 {
640 WLog_ERR(TAG, "Unexpected FASTPATH_FRAGMENT_LAST");
641 goto out_fail;
642 }
643
644 fastpath->fragmentation = -1;
645 status = fastpath_recv_update(fastpath, updateCode, fastpath->updateData);
646
647 if (status < 0)
648 {
649 WLog_ERR(TAG, "fastpath_recv_update() - %i", status);
650 goto out_fail;
651 }
652 }
653 }
654
655 return status;
656out_fail:
657 return -1;
658}
659
660state_run_t fastpath_recv_updates(rdpFastPath* fastpath, wStream* s)
661{
662 state_run_t rc = STATE_RUN_FAILED;
663
664 WINPR_ASSERT(s);
665 WINPR_ASSERT(fastpath);
666 WINPR_ASSERT(fastpath->rdp);
667
668 while (Stream_GetRemainingLength(s) >= 3)
669 {
670 if (fastpath_recv_update_data(fastpath, s) < 0)
671 {
672 WLog_ERR(TAG, "fastpath_recv_update_data() fail");
673 rc = STATE_RUN_FAILED;
674 goto fail;
675 }
676 }
677
678 rc = STATE_RUN_SUCCESS;
679fail:
680
681 return rc;
682}
683
684static BOOL fastpath_read_input_event_header(wStream* s, BYTE* eventFlags, BYTE* eventCode)
685{
686 BYTE eventHeader = 0;
687
688 WINPR_ASSERT(s);
689 WINPR_ASSERT(eventFlags);
690 WINPR_ASSERT(eventCode);
691
692 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
693 return FALSE;
694
695 Stream_Read_UINT8(s, eventHeader); /* eventHeader (1 byte) */
696 *eventFlags = (eventHeader & 0x1F);
697 *eventCode = (eventHeader >> 5);
698 return TRUE;
699}
700
701static BOOL fastpath_recv_input_event_scancode(rdpFastPath* fastpath, wStream* s, BYTE eventFlags)
702{
703 WINPR_ASSERT(fastpath);
704 WINPR_ASSERT(fastpath->rdp);
705 WINPR_ASSERT(fastpath->rdp->input);
706 WINPR_ASSERT(s);
707
708 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
709 return FALSE;
710
711 rdpInput* input = fastpath->rdp->input;
712
713 const UINT8 code = Stream_Get_UINT8(s); /* keyCode (1 byte) */
714
715 UINT16 flags = 0;
716 if ((eventFlags & FASTPATH_INPUT_KBDFLAGS_RELEASE))
717 flags |= KBD_FLAGS_RELEASE;
718
719 if ((eventFlags & FASTPATH_INPUT_KBDFLAGS_EXTENDED))
720 flags |= KBD_FLAGS_EXTENDED;
721
722 if ((eventFlags & FASTPATH_INPUT_KBDFLAGS_PREFIX_E1))
723 flags |= KBD_FLAGS_EXTENDED1;
724
725 return IFCALLRESULT(TRUE, input->KeyboardEvent, input, flags, code);
726}
727
728static BOOL fastpath_recv_input_event_mouse(rdpFastPath* fastpath, wStream* s,
729 WINPR_ATTR_UNUSED BYTE eventFlags)
730{
731 rdpInput* input = nullptr;
732 UINT16 pointerFlags = 0;
733 UINT16 xPos = 0;
734 UINT16 yPos = 0;
735 WINPR_ASSERT(fastpath);
736 WINPR_ASSERT(fastpath->rdp);
737 WINPR_ASSERT(fastpath->rdp->input);
738 WINPR_ASSERT(s);
739
740 if (!Stream_CheckAndLogRequiredLength(TAG, s, 6))
741 return FALSE;
742
743 input = fastpath->rdp->input;
744
745 Stream_Read_UINT16(s, pointerFlags); /* pointerFlags (2 bytes) */
746 Stream_Read_UINT16(s, xPos); /* xPos (2 bytes) */
747 Stream_Read_UINT16(s, yPos); /* yPos (2 bytes) */
748 return IFCALLRESULT(TRUE, input->MouseEvent, input, pointerFlags, xPos, yPos);
749}
750
751static BOOL fastpath_recv_input_event_relmouse(rdpFastPath* fastpath, wStream* s,
752 WINPR_ATTR_UNUSED BYTE eventFlags)
753{
754 rdpInput* input = nullptr;
755 UINT16 pointerFlags = 0;
756 INT16 xDelta = 0;
757 INT16 yDelta = 0;
758 WINPR_ASSERT(fastpath);
759 WINPR_ASSERT(fastpath->rdp);
760 WINPR_ASSERT(fastpath->rdp->context);
761 WINPR_ASSERT(fastpath->rdp->input);
762 WINPR_ASSERT(s);
763
764 if (!Stream_CheckAndLogRequiredLength(TAG, s, 6))
765 return FALSE;
766
767 input = fastpath->rdp->input;
768
769 Stream_Read_UINT16(s, pointerFlags); /* pointerFlags (2 bytes) */
770 Stream_Read_INT16(s, xDelta); /* xDelta (2 bytes) */
771 Stream_Read_INT16(s, yDelta); /* yDelta (2 bytes) */
772
773 if (!freerdp_settings_get_bool(input->context->settings, FreeRDP_HasRelativeMouseEvent))
774 {
775 WLog_ERR(TAG,
776 "Received relative mouse event(flags=0x%04" PRIx16 ", xPos=%" PRId16
777 ", yPos=%" PRId16 "), but we did not announce support for that",
778 pointerFlags, xDelta, yDelta);
779 return FALSE;
780 }
781
782 return IFCALLRESULT(TRUE, input->RelMouseEvent, input, pointerFlags, xDelta, yDelta);
783}
784
785static BOOL fastpath_recv_input_event_qoe(rdpFastPath* fastpath, wStream* s,
786 WINPR_ATTR_UNUSED BYTE eventFlags)
787{
788 WINPR_ASSERT(fastpath);
789 WINPR_ASSERT(fastpath->rdp);
790 WINPR_ASSERT(fastpath->rdp->context);
791 WINPR_ASSERT(fastpath->rdp->input);
792 WINPR_ASSERT(s);
793
794 if (!Stream_CheckAndLogRequiredLength(TAG, s, 4))
795 return FALSE;
796
797 rdpInput* input = fastpath->rdp->input;
798
799 UINT32 timestampMS = 0;
800 Stream_Read_UINT32(s, timestampMS); /* timestamp (4 bytes) */
801
802 if (!freerdp_settings_get_bool(input->context->settings, FreeRDP_HasQoeEvent))
803 {
804 WLog_ERR(TAG,
805 "Received qoe event(timestamp=%" PRIu32
806 "ms), but we did not announce support for that",
807 timestampMS);
808 return FALSE;
809 }
810
811 return IFCALLRESULT(TRUE, input->QoEEvent, input, timestampMS);
812}
813
814static BOOL fastpath_recv_input_event_mousex(rdpFastPath* fastpath, wStream* s,
815 WINPR_ATTR_UNUSED BYTE eventFlags)
816{
817 rdpInput* input = nullptr;
818 UINT16 pointerFlags = 0;
819 UINT16 xPos = 0;
820 UINT16 yPos = 0;
821
822 WINPR_ASSERT(fastpath);
823 WINPR_ASSERT(fastpath->rdp);
824 WINPR_ASSERT(fastpath->rdp->context);
825 WINPR_ASSERT(fastpath->rdp->input);
826 WINPR_ASSERT(s);
827
828 if (!Stream_CheckAndLogRequiredLength(TAG, s, 6))
829 return FALSE;
830
831 input = fastpath->rdp->input;
832
833 Stream_Read_UINT16(s, pointerFlags); /* pointerFlags (2 bytes) */
834 Stream_Read_UINT16(s, xPos); /* xPos (2 bytes) */
835 Stream_Read_UINT16(s, yPos); /* yPos (2 bytes) */
836
837 if (!freerdp_settings_get_bool(input->context->settings, FreeRDP_HasExtendedMouseEvent))
838 {
839 WLog_ERR(TAG,
840 "Received extended mouse event(flags=0x%04" PRIx16 ", xPos=%" PRIu16
841 ", yPos=%" PRIu16 "), but we did not announce support for that",
842 pointerFlags, xPos, yPos);
843 return FALSE;
844 }
845
846 return IFCALLRESULT(TRUE, input->ExtendedMouseEvent, input, pointerFlags, xPos, yPos);
847}
848
849static BOOL fastpath_recv_input_event_sync(rdpFastPath* fastpath, WINPR_ATTR_UNUSED wStream* s,
850 BYTE eventFlags)
851{
852 rdpInput* input = nullptr;
853
854 WINPR_ASSERT(fastpath);
855 WINPR_ASSERT(fastpath->rdp);
856 WINPR_ASSERT(fastpath->rdp->input);
857 WINPR_ASSERT(s);
858
859 input = fastpath->rdp->input;
860 return IFCALLRESULT(TRUE, input->SynchronizeEvent, input, eventFlags);
861}
862
863static BOOL fastpath_recv_input_event_unicode(rdpFastPath* fastpath, wStream* s, BYTE eventFlags)
864{
865 UINT16 unicodeCode = 0;
866 UINT16 flags = 0;
867
868 WINPR_ASSERT(fastpath);
869 WINPR_ASSERT(s);
870
871 if (!Stream_CheckAndLogRequiredLength(TAG, s, 2))
872 return FALSE;
873
874 Stream_Read_UINT16(s, unicodeCode); /* unicodeCode (2 bytes) */
875 flags = 0;
876
877 if ((eventFlags & FASTPATH_INPUT_KBDFLAGS_RELEASE))
878 flags |= KBD_FLAGS_RELEASE;
879
880 WINPR_ASSERT(fastpath->rdp);
881 WINPR_ASSERT(fastpath->rdp);
882 WINPR_ASSERT(fastpath->rdp->input);
883 return IFCALLRESULT(FALSE, fastpath->rdp->input->UnicodeKeyboardEvent, fastpath->rdp->input,
884 flags, unicodeCode);
885}
886
887static BOOL fastpath_recv_input_event(rdpFastPath* fastpath, wStream* s)
888{
889 BYTE eventFlags = 0;
890 BYTE eventCode = 0;
891
892 WINPR_ASSERT(fastpath);
893 WINPR_ASSERT(s);
894
895 if (!fastpath_read_input_event_header(s, &eventFlags, &eventCode))
896 return FALSE;
897
898 switch (eventCode)
899 {
900 case FASTPATH_INPUT_EVENT_SCANCODE:
901 if (!fastpath_recv_input_event_scancode(fastpath, s, eventFlags))
902 return FALSE;
903
904 break;
905
906 case FASTPATH_INPUT_EVENT_MOUSE:
907 if (!fastpath_recv_input_event_mouse(fastpath, s, eventFlags))
908 return FALSE;
909
910 break;
911
912 case FASTPATH_INPUT_EVENT_MOUSEX:
913 if (!fastpath_recv_input_event_mousex(fastpath, s, eventFlags))
914 return FALSE;
915
916 break;
917
918 case FASTPATH_INPUT_EVENT_SYNC:
919 if (!fastpath_recv_input_event_sync(fastpath, s, eventFlags))
920 return FALSE;
921
922 break;
923
924 case FASTPATH_INPUT_EVENT_UNICODE:
925 if (!fastpath_recv_input_event_unicode(fastpath, s, eventFlags))
926 return FALSE;
927
928 break;
929
930 case TS_FP_RELPOINTER_EVENT:
931 if (!fastpath_recv_input_event_relmouse(fastpath, s, eventFlags))
932 return FALSE;
933
934 break;
935
936 case TS_FP_QOETIMESTAMP_EVENT:
937 if (!fastpath_recv_input_event_qoe(fastpath, s, eventFlags))
938 return FALSE;
939 break;
940
941 default:
942 WLog_ERR(TAG, "Unknown eventCode %" PRIu8 "", eventCode);
943 break;
944 }
945
946 return TRUE;
947}
948
949state_run_t fastpath_recv_inputs(rdpFastPath* fastpath, wStream* s)
950{
951 WINPR_ASSERT(fastpath);
952 WINPR_ASSERT(s);
953
954 if (fastpath->numberEvents == 0)
955 {
960 if (!Stream_CheckAndLogRequiredLength(TAG, s, 1))
961 return STATE_RUN_FAILED;
962
963 Stream_Read_UINT8(s, fastpath->numberEvents); /* eventHeader (1 byte) */
964 }
965
966 for (BYTE i = 0; i < fastpath->numberEvents; i++)
967 {
968 if (!fastpath_recv_input_event(fastpath, s))
969 return STATE_RUN_FAILED;
970 }
971
972 return STATE_RUN_SUCCESS;
973}
974
975static UINT32 fastpath_get_sec_bytes(rdpRdp* rdp)
976{
977 UINT32 sec_bytes = 0;
978
979 if (!rdp)
980 return 0;
981
982 if (rdp->do_crypt)
983 {
984 sec_bytes = 8;
985
986 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
987 ENCRYPTION_METHOD_FIPS)
988 sec_bytes += 4;
989 }
990
991 return sec_bytes;
992}
993
994wStream* fastpath_input_pdu_init_header(rdpFastPath* fastpath, UINT16* sec_flags)
995{
996 if (!fastpath || !fastpath->rdp)
997 return nullptr;
998
999 rdpRdp* rdp = fastpath->rdp;
1000 wStream* s = transport_send_stream_init(rdp->transport, 256);
1001
1002 if (!s)
1003 return nullptr;
1004
1005 Stream_Seek(s, 3); /* fpInputHeader, length1 and length2 */
1006
1007 if (rdp->do_crypt)
1008 {
1009 *sec_flags |= SEC_ENCRYPT;
1010
1011 if (rdp->do_secure_checksum)
1012 *sec_flags |= SEC_SECURE_CHECKSUM;
1013 }
1014
1015 Stream_Seek(s, fastpath_get_sec_bytes(rdp));
1016 return s;
1017}
1018
1019wStream* fastpath_input_pdu_init(rdpFastPath* fastpath, BYTE eventFlags, BYTE eventCode,
1020 UINT16* sec_flags)
1021{
1022 wStream* s = nullptr;
1023 s = fastpath_input_pdu_init_header(fastpath, sec_flags);
1024
1025 if (!s)
1026 return nullptr;
1027
1028 WINPR_ASSERT(eventCode < 8);
1029 WINPR_ASSERT(eventFlags < 0x20);
1030 Stream_Write_UINT8(s, (UINT8)(eventFlags | (eventCode << 5))); /* eventHeader (1 byte) */
1031 return s;
1032}
1033
1034BOOL fastpath_send_multiple_input_pdu(rdpFastPath* fastpath, wStream* s, size_t iNumEvents,
1035 UINT16 sec_flags)
1036{
1037 BOOL rc = FALSE;
1038 BYTE eventHeader = 0;
1039 BOOL should_unlock = FALSE;
1040 rdpRdp* rdp = nullptr;
1041
1042 WINPR_ASSERT(iNumEvents > 0);
1043 if (!s)
1044 return FALSE;
1045
1046 if (!fastpath)
1047 goto fail;
1048
1049 rdp = fastpath->rdp;
1050 WINPR_ASSERT(rdp);
1051
1052 {
1053 const CONNECTION_STATE state = rdp_get_state(rdp);
1054 if (!rdp_is_active_state(rdp))
1055 {
1056 WLog_WARN(TAG, "called before activation [%s]", rdp_state_string(state));
1057 goto fail;
1058 }
1059 }
1060
1061 /*
1062 * A maximum of 15 events are allowed per request
1063 * if the optional numEvents field isn't used
1064 * see MS-RDPBCGR 2.2.8.1.2 for details
1065 */
1066 if (iNumEvents > 15)
1067 goto fail;
1068
1069 {
1070 size_t length = Stream_GetPosition(s);
1071
1072 if (length >= (2u << 14))
1073 {
1074 WLog_ERR(TAG, "Maximum FastPath PDU length is 32767");
1075 goto fail;
1076 }
1077
1078 eventHeader = FASTPATH_INPUT_ACTION_FASTPATH;
1079 eventHeader |= (iNumEvents << 2); /* numberEvents */
1080
1081 if (sec_flags & SEC_ENCRYPT)
1082 eventHeader |= (FASTPATH_INPUT_ENCRYPTED << 6);
1083
1084 if (sec_flags & SEC_SECURE_CHECKSUM)
1085 eventHeader |= (FASTPATH_INPUT_SECURE_CHECKSUM << 6);
1086
1087 Stream_ResetPosition(s);
1088 Stream_Write_UINT8(s, eventHeader);
1089 /* Write length later, RDP encryption might add a padding */
1090 Stream_Seek(s, 2);
1091
1092 if (sec_flags & SEC_ENCRYPT)
1093 {
1094 security_lock(rdp);
1095 should_unlock = TRUE;
1096
1097 const size_t sec_bytes = fastpath_get_sec_bytes(fastpath->rdp);
1098 if (sec_bytes + 3ULL > length)
1099 goto fail;
1100
1101 BYTE* fpInputEvents = Stream_PointerAs(s, BYTE) + sec_bytes;
1102 const UINT16 fpInputEvents_length = (UINT16)(length - 3 - sec_bytes);
1103
1104 WINPR_ASSERT(rdp->settings);
1105 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
1106 ENCRYPTION_METHOD_FIPS)
1107 {
1108 BYTE pad = 0;
1109
1110 if ((pad = 8 - (fpInputEvents_length % 8)) == 8)
1111 pad = 0;
1112
1113 Stream_Write_UINT16(s, 0x10); /* length */
1114 Stream_Write_UINT8(s, 0x1); /* TSFIPS_VERSION 1*/
1115 Stream_Write_UINT8(s, pad); /* padding */
1116
1117 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 8))
1118 goto fail;
1119
1120 if (!security_hmac_signature(fpInputEvents, fpInputEvents_length, Stream_Pointer(s),
1121 8, rdp))
1122 goto fail;
1123
1124 if (pad)
1125 memset(fpInputEvents + fpInputEvents_length, 0, pad);
1126
1127 if (!security_fips_encrypt(fpInputEvents, fpInputEvents_length + pad, rdp))
1128 goto fail;
1129
1130 length += pad;
1131 }
1132 else
1133 {
1134 BOOL res = 0;
1135 if (!Stream_CheckAndLogRequiredCapacity(TAG, s, 8))
1136 goto fail;
1137 if (sec_flags & SEC_SECURE_CHECKSUM)
1138 res = security_salted_mac_signature(rdp, fpInputEvents, fpInputEvents_length,
1139 TRUE, Stream_Pointer(s), 8);
1140 else
1141 res = security_mac_signature(rdp, fpInputEvents, fpInputEvents_length,
1142 Stream_Pointer(s), 8);
1143
1144 if (!res || !security_encrypt(fpInputEvents, fpInputEvents_length, rdp))
1145 goto fail;
1146 }
1147 }
1148
1149 /*
1150 * We always encode length in two bytes, even though we could use
1151 * only one byte if length <= 0x7F. It is just easier that way,
1152 * because we can leave room for fixed-length header, store all
1153 * the data first and then store the header.
1154 */
1155 WINPR_ASSERT(length < UINT16_MAX);
1156 if (!Stream_SetPosition(s, 1))
1157 goto fail;
1158 Stream_Write_UINT16_BE(s, 0x8000 | (UINT16)length);
1159 if (!Stream_SetPosition(s, length))
1160 goto fail;
1161 Stream_SealLength(s);
1162 }
1163
1164 if (transport_write(rdp->transport, s) < 0)
1165 goto fail;
1166
1167 rc = TRUE;
1168fail:
1169 if (should_unlock)
1170 security_unlock(rdp);
1171 Stream_Release(s);
1172 return rc;
1173}
1174
1175BOOL fastpath_send_input_pdu(rdpFastPath* fastpath, wStream* s, UINT16 sec_flags)
1176{
1177 return fastpath_send_multiple_input_pdu(fastpath, s, 1, sec_flags);
1178}
1179
1180wStream* fastpath_update_pdu_init(rdpFastPath* fastpath)
1181{
1182 return transport_send_stream_init(fastpath->rdp->transport, FASTPATH_MAX_PACKET_SIZE);
1183}
1184
1185wStream* fastpath_update_pdu_init_new(WINPR_ATTR_UNUSED rdpFastPath* fastpath)
1186{
1187 wStream* s = nullptr;
1188 s = Stream_New(nullptr, FASTPATH_MAX_PACKET_SIZE);
1189 return s;
1190}
1191
1192BOOL fastpath_send_update_pdu(rdpFastPath* fastpath, BYTE updateCode, wStream* s,
1193 BOOL skipCompression)
1194{
1195 BOOL status = TRUE;
1196 wStream* fs = nullptr;
1197 rdpSettings* settings = nullptr;
1198 rdpRdp* rdp = nullptr;
1199 UINT32 fpHeaderSize = 6;
1200 UINT32 fpUpdatePduHeaderSize = 0;
1201 UINT32 fpUpdateHeaderSize = 0;
1202 FASTPATH_UPDATE_PDU_HEADER fpUpdatePduHeader = WINPR_C_ARRAY_INIT;
1203 FASTPATH_UPDATE_HEADER fpUpdateHeader = WINPR_C_ARRAY_INIT;
1204 UINT16 sec_flags = 0;
1205
1206 if (!fastpath || !fastpath->rdp || !fastpath->fs || !s)
1207 return FALSE;
1208
1209 rdp = fastpath->rdp;
1210 fs = fastpath->fs;
1211 settings = rdp->settings;
1212
1213 if (!settings)
1214 return FALSE;
1215
1216 UINT16 maxLength = FASTPATH_MAX_PACKET_SIZE - 20;
1217
1218 if (freerdp_settings_get_bool(rdp->settings, FreeRDP_CompressionEnabled) && !skipCompression)
1219 {
1220 const UINT16 CompressionMaxSize = bulk_compression_max_size(rdp->bulk);
1221 maxLength = (maxLength < CompressionMaxSize) ? maxLength : CompressionMaxSize;
1222 maxLength -= 20;
1223 }
1224
1225 size_t totalLength = Stream_GetPosition(s);
1226 Stream_ResetPosition(s);
1227
1228 /* check if fast path output is possible */
1229 if (!freerdp_settings_get_bool(rdp->settings, FreeRDP_FastPathOutput))
1230 {
1231 WLog_ERR(TAG, "client does not support fast path output");
1232 return FALSE;
1233 }
1234
1235 /* check if the client's fast path pdu buffer is large enough */
1236 if (totalLength > freerdp_settings_get_uint32(settings, FreeRDP_MultifragMaxRequestSize))
1237 {
1238 WLog_ERR(TAG,
1239 "fast path update size (%" PRIuz
1240 ") exceeds the client's maximum request size (%" PRIu32 ")",
1241 totalLength,
1242 freerdp_settings_get_uint32(settings, FreeRDP_MultifragMaxRequestSize));
1243 return FALSE;
1244 }
1245
1246 if (rdp->do_crypt)
1247 {
1248 sec_flags |= SEC_ENCRYPT;
1249
1250 if (rdp->do_secure_checksum)
1251 sec_flags |= SEC_SECURE_CHECKSUM;
1252 }
1253
1254 for (int fragment = 0; (totalLength > 0) || (fragment == 0); fragment++)
1255 {
1256 UINT32 DstSize = 0;
1257 const BYTE* pDstData = nullptr;
1258 UINT32 compressionFlags = 0;
1259 BYTE pad = 0;
1260 BYTE* pSignature = nullptr;
1261 fpUpdatePduHeader.action = 0;
1262 fpUpdatePduHeader.secFlags = 0;
1263 fpUpdateHeader.compression = 0;
1264 fpUpdateHeader.compressionFlags = 0;
1265 fpUpdateHeader.updateCode = updateCode;
1266 fpUpdateHeader.size = (UINT16)(totalLength > maxLength) ? maxLength : (UINT16)totalLength;
1267 const BYTE* pSrcData = Stream_Pointer(s);
1268 UINT32 SrcSize = DstSize = fpUpdateHeader.size;
1269 BOOL should_unlock = FALSE;
1270
1271 if (sec_flags & SEC_ENCRYPT)
1272 fpUpdatePduHeader.secFlags |= FASTPATH_OUTPUT_ENCRYPTED;
1273
1274 if (sec_flags & SEC_SECURE_CHECKSUM)
1275 fpUpdatePduHeader.secFlags |= FASTPATH_OUTPUT_SECURE_CHECKSUM;
1276
1277 if (freerdp_settings_get_bool(settings, FreeRDP_CompressionEnabled) && !skipCompression)
1278 {
1279 if (bulk_compress(rdp->bulk, pSrcData, SrcSize, &pDstData, &DstSize,
1280 &compressionFlags) >= 0)
1281 {
1282 if (compressionFlags)
1283 {
1284 WINPR_ASSERT(compressionFlags <= UINT8_MAX);
1285 fpUpdateHeader.compressionFlags = (UINT8)compressionFlags;
1286 fpUpdateHeader.compression = FASTPATH_OUTPUT_COMPRESSION_USED;
1287 }
1288 }
1289 }
1290
1291 if (!fpUpdateHeader.compression)
1292 {
1293 pDstData = Stream_Pointer(s);
1294 DstSize = fpUpdateHeader.size;
1295 }
1296
1297 if (DstSize > UINT16_MAX)
1298 return FALSE;
1299 fpUpdateHeader.size = (UINT16)DstSize;
1300 totalLength -= SrcSize;
1301
1302 if (totalLength == 0)
1303 fpUpdateHeader.fragmentation =
1304 (fragment == 0) ? FASTPATH_FRAGMENT_SINGLE : FASTPATH_FRAGMENT_LAST;
1305 else
1306 fpUpdateHeader.fragmentation =
1307 (fragment == 0) ? FASTPATH_FRAGMENT_FIRST : FASTPATH_FRAGMENT_NEXT;
1308
1309 fpUpdateHeaderSize = fastpath_get_update_header_size(&fpUpdateHeader);
1310 fpUpdatePduHeaderSize = fastpath_get_update_pdu_header_size(&fpUpdatePduHeader, rdp);
1311 fpHeaderSize = fpUpdateHeaderSize + fpUpdatePduHeaderSize;
1312
1313 if (sec_flags & SEC_ENCRYPT)
1314 {
1315 pSignature = Stream_Buffer(fs) + 3;
1316
1317 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
1318 ENCRYPTION_METHOD_FIPS)
1319 {
1320 pSignature += 4;
1321
1322 if ((pad = 8 - ((DstSize + fpUpdateHeaderSize) % 8)) == 8)
1323 pad = 0;
1324
1325 fpUpdatePduHeader.fipsInformation[0] = 0x10;
1326 fpUpdatePduHeader.fipsInformation[1] = 0x00;
1327 fpUpdatePduHeader.fipsInformation[2] = 0x01;
1328 fpUpdatePduHeader.fipsInformation[3] = pad;
1329 }
1330 }
1331
1332 const size_t len = fpUpdateHeader.size + fpHeaderSize + pad;
1333 if (len > UINT16_MAX)
1334 return FALSE;
1335
1336 fpUpdatePduHeader.length = (UINT16)len;
1337 Stream_ResetPosition(fs);
1338 if (!fastpath_write_update_pdu_header(fs, &fpUpdatePduHeader, rdp))
1339 return FALSE;
1340 if (!fastpath_write_update_header(fs, &fpUpdateHeader))
1341 return FALSE;
1342
1343 if (!Stream_CheckAndLogRequiredCapacity(TAG, (fs), (size_t)DstSize + pad))
1344 return FALSE;
1345 Stream_Write(fs, pDstData, DstSize);
1346
1347 if (pad)
1348 Stream_Zero(fs, pad);
1349
1350 BOOL res = FALSE;
1351 if (sec_flags & SEC_ENCRYPT)
1352 {
1353 security_lock(rdp);
1354
1355 should_unlock = TRUE;
1356 UINT32 dataSize = fpUpdateHeaderSize + DstSize + pad;
1357 BYTE* data = Stream_PointerAs(fs, BYTE) - dataSize;
1358
1359 if (freerdp_settings_get_uint32(rdp->settings, FreeRDP_EncryptionMethods) ==
1360 ENCRYPTION_METHOD_FIPS)
1361 {
1362 // TODO: Ensure stream capacity
1363 if (!security_hmac_signature(data, dataSize - pad, pSignature, 8, rdp))
1364 goto unlock;
1365
1366 if (!security_fips_encrypt(data, dataSize, rdp))
1367 goto unlock;
1368 }
1369 else
1370 {
1371 // TODO: Ensure stream capacity
1372 if (sec_flags & SEC_SECURE_CHECKSUM)
1373 status =
1374 security_salted_mac_signature(rdp, data, dataSize, TRUE, pSignature, 8);
1375 else
1376 status = security_mac_signature(rdp, data, dataSize, pSignature, 8);
1377
1378 if (!status || !security_encrypt(data, dataSize, rdp))
1379 goto unlock;
1380 }
1381 }
1382 res = TRUE;
1383
1384 Stream_SealLength(fs);
1385
1386 if (transport_write(rdp->transport, fs) < 0)
1387 {
1388 status = FALSE;
1389 }
1390
1391 unlock:
1392 if (should_unlock)
1393 security_unlock(rdp);
1394
1395 if (!res || !status)
1396 return FALSE;
1397
1398 Stream_Seek(s, SrcSize);
1399 }
1400
1401 return status;
1402}
1403
1404rdpFastPath* fastpath_new(rdpRdp* rdp)
1405{
1406 rdpFastPath* fastpath = nullptr;
1407
1408 WINPR_ASSERT(rdp);
1409
1410 fastpath = (rdpFastPath*)calloc(1, sizeof(rdpFastPath));
1411
1412 if (!fastpath)
1413 return nullptr;
1414
1415 fastpath->rdp = rdp;
1416 fastpath->fragmentation = -1;
1417 fastpath->fs = Stream_New(nullptr, FASTPATH_MAX_PACKET_SIZE);
1418 fastpath->updateData = Stream_New(nullptr, FASTPATH_MAX_PACKET_SIZE);
1419
1420 if (!fastpath->fs || !fastpath->updateData)
1421 goto out_free;
1422
1423 return fastpath;
1424out_free:
1425 fastpath_free(fastpath);
1426 return nullptr;
1427}
1428
1429void fastpath_free(rdpFastPath* fastpath)
1430{
1431 if (fastpath)
1432 {
1433 Stream_Free(fastpath->updateData, TRUE);
1434 Stream_Free(fastpath->fs, TRUE);
1435 free(fastpath);
1436 }
1437}
1438
1439BYTE fastpath_get_encryption_flags(rdpFastPath* fastpath)
1440{
1441 WINPR_ASSERT(fastpath);
1442 return fastpath->encryptionFlags;
1443}
1444
1445BOOL fastpath_decrypt(rdpFastPath* fastpath, wStream* s, UINT16* length)
1446{
1447 WINPR_ASSERT(fastpath);
1448 if (fastpath_get_encryption_flags(fastpath) & FASTPATH_OUTPUT_ENCRYPTED)
1449 {
1450 const UINT16 flags =
1451 (fastpath_get_encryption_flags(fastpath) & FASTPATH_OUTPUT_SECURE_CHECKSUM)
1452 ? SEC_SECURE_CHECKSUM
1453 : 0;
1454
1455 if (!rdp_decrypt(fastpath->rdp, s, length, flags))
1456 return FALSE;
1457 }
1458
1459 return TRUE;
1460}
WINPR_ATTR_NODISCARD FREERDP_API UINT32 freerdp_settings_get_uint32(const rdpSettings *settings, FreeRDP_Settings_Keys_UInt32 id)
Returns a UINT32 settings value.
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_get_bool(const rdpSettings *settings, FreeRDP_Settings_Keys_Bool id)
Returns a boolean settings value.