FreeRDP
Loading...
Searching...
No Matches
rdp.c
1
21#include <freerdp/config.h>
22
23#include "settings.h"
24
25#include <winpr/crt.h>
26#include <winpr/string.h>
27#include <winpr/synch.h>
28#include <winpr/assert.h>
29#include <winpr/cast.h>
30#include <winpr/json.h>
31#include <winpr/ssl.h>
32
33#include "rdp.h"
34
35#include "state.h"
36#include "info.h"
37#include "utils.h"
38#include "mcs.h"
39#include "redirection.h"
40
41#include <freerdp/codec/bulk.h>
42#include <freerdp/crypto/per.h>
43#include <freerdp/log.h>
44#include <freerdp/buildflags.h>
45
46#define RDP_TAG FREERDP_TAG("core.rdp")
47
48typedef struct
49{
50 const char* file;
51 const char* fkt;
52 size_t line;
53 DWORD level;
54} log_line_t;
55
56static const char* DATA_PDU_TYPE_STRINGS[80] = {
57 "?",
58 "?", /* 0x00 - 0x01 */
59 "Update", /* 0x02 */
60 "?",
61 "?",
62 "?",
63 "?",
64 "?",
65 "?",
66 "?",
67 "?", /* 0x03 - 0x0A */
68 "?",
69 "?",
70 "?",
71 "?",
72 "?",
73 "?",
74 "?",
75 "?",
76 "?", /* 0x0B - 0x13 */
77 "Control", /* 0x14 */
78 "?",
79 "?",
80 "?",
81 "?",
82 "?",
83 "?", /* 0x15 - 0x1A */
84 "Pointer", /* 0x1B */
85 "Input", /* 0x1C */
86 "?",
87 "?", /* 0x1D - 0x1E */
88 "Synchronize", /* 0x1F */
89 "?", /* 0x20 */
90 "Refresh Rect", /* 0x21 */
91 "Play Sound", /* 0x22 */
92 "Suppress Output", /* 0x23 */
93 "Shutdown Request", /* 0x24 */
94 "Shutdown Denied", /* 0x25 */
95 "Save Session Info", /* 0x26 */
96 "Font List", /* 0x27 */
97 "Font Map", /* 0x28 */
98 "Set Keyboard Indicators", /* 0x29 */
99 "?", /* 0x2A */
100 "Bitmap Cache Persistent List", /* 0x2B */
101 "Bitmap Cache Error", /* 0x2C */
102 "Set Keyboard IME Status", /* 0x2D */
103 "Offscreen Cache Error", /* 0x2E */
104 "Set Error Info", /* 0x2F */
105 "Draw Nine Grid Error", /* 0x30 */
106 "Draw GDI+ Error", /* 0x31 */
107 "ARC Status", /* 0x32 */
108 "?",
109 "?",
110 "?", /* 0x33 - 0x35 */
111 "Status Info", /* 0x36 */
112 "Monitor Layout", /* 0x37 */
113 "FrameAcknowledge",
114 "?",
115 "?", /* 0x38 - 0x40 */
116 "?",
117 "?",
118 "?",
119 "?",
120 "?",
121 "?" /* 0x41 - 0x46 */
122};
123
124#define rdp_check_monitor_layout_pdu_state(rdp, expected) \
125 rdp_check_monitor_layout_pdu_state_(rdp, expected, __FILE__, __func__, __LINE__)
126
127static BOOL rdp_check_monitor_layout_pdu_state_(const rdpRdp* rdp, BOOL expected, const char* file,
128 const char* fkt, size_t line)
129{
130 WINPR_ASSERT(rdp);
131 if (expected != rdp->monitor_layout_pdu)
132 {
133 const DWORD log_level = WLOG_ERROR;
134 if (WLog_IsLevelActive(rdp->log, log_level))
135 {
136 WLog_PrintTextMessage(rdp->log, log_level, line, file, fkt,
137 "Expected rdp->monitor_layout_pdu == %s",
138 expected ? "TRUE" : "FALSE");
139 }
140 return FALSE;
141 }
142 return TRUE;
143}
144
145#define rdp_set_monitor_layout_pdu_state(rdp, expected) \
146 rdp_set_monitor_layout_pdu_state_(rdp, expected, __FILE__, __func__, __LINE__)
147static BOOL rdp_set_monitor_layout_pdu_state_(rdpRdp* rdp, BOOL value, const char* file,
148 const char* fkt, size_t line)
149{
150
151 WINPR_ASSERT(rdp);
152 if (value && (value == rdp->monitor_layout_pdu))
153 {
154 const DWORD log_level = WLOG_WARN;
155 if (WLog_IsLevelActive(rdp->log, log_level))
156 {
157 WLog_PrintTextMessage(rdp->log, log_level, line, file, fkt,
158 "rdp->monitor_layout_pdu == TRUE, expected FALSE");
159 }
160 return FALSE;
161 }
162 rdp->monitor_layout_pdu = value;
163 return TRUE;
164}
165
166const char* data_pdu_type_to_string(UINT8 type)
167{
168 if (type >= ARRAYSIZE(DATA_PDU_TYPE_STRINGS))
169 return "???";
170 return DATA_PDU_TYPE_STRINGS[type];
171}
172
173static BOOL rdp_read_flow_control_pdu(rdpRdp* rdp, wStream* s, UINT16* type, UINT16* channel_id);
174static BOOL rdp_write_share_control_header(rdpRdp* rdp, wStream* s, size_t length, UINT16 type,
175 UINT16 channel_id);
176static BOOL rdp_write_share_data_header(rdpRdp* rdp, wStream* s, size_t length, BYTE type,
177 UINT32 share_id);
178
189BOOL rdp_read_security_header(rdpRdp* rdp, wStream* s, UINT16* flags, UINT16* length)
190{
191 char buffer[256] = WINPR_C_ARRAY_INIT;
192 WINPR_ASSERT(s);
193 WINPR_ASSERT(flags);
194 WINPR_ASSERT(rdp);
195
196 /* Basic Security Header */
197 if ((length && (*length < 4)))
198 {
199 WLog_Print(rdp->log, WLOG_WARN,
200 "invalid security header length, have %" PRIu16 ", must be >= 4", *length);
201 return FALSE;
202 }
203 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
204 return FALSE;
205
206 *flags = Stream_Get_UINT16(s); /* flags */
207 const uint16_t flagsHi = Stream_Get_UINT16(s); /* flagsHi (unused) */
208 if ((*flags & SEC_FLAGSHI_VALID) != 0)
209 {
210 WLog_Print(rdp->log, WLOG_WARN,
211 "[MS-RDPBCGR] 2.2.8.1.1.2.1 Basic (TS_SECURITY_HEADER) SEC_FLAGSHI_VALID field "
212 "set: flagsHi=0x%04" PRIx16,
213 flagsHi);
214 }
215 WLog_Print(rdp->log, WLOG_TRACE, "%s",
216 rdp_security_flag_string(*flags, buffer, sizeof(buffer)));
217 if (length)
218 *length -= 4;
219
220 return TRUE;
221}
222
232BOOL rdp_write_security_header(rdpRdp* rdp, wStream* s, UINT16 flags)
233{
234 char buffer[256] = WINPR_C_ARRAY_INIT;
235 WINPR_ASSERT(s);
236 WINPR_ASSERT(rdp);
237
238 if (!Stream_CheckAndLogRequiredCapacityWLog(rdp->log, (s), 4))
239 return FALSE;
240
241 WLog_Print(rdp->log, WLOG_TRACE, "%s", rdp_security_flag_string(flags, buffer, sizeof(buffer)));
242 /* Basic Security Header */
243 WINPR_ASSERT((flags & SEC_FLAGSHI_VALID) == 0); /* SEC_FLAGSHI_VALID is unsupported */
244 Stream_Write_UINT16(s, flags); /* flags */
245 Stream_Write_UINT16(s, 0); /* flagsHi (unused) */
246 return TRUE;
247}
248
249BOOL rdp_read_share_control_header(rdpRdp* rdp, wStream* s, UINT16* tpktLength,
250 UINT16* remainingLength, UINT16* type, UINT16* channel_id)
251{
252 UINT16 len = 0;
253 UINT16 tmp = 0;
254
255 WINPR_ASSERT(rdp);
256 WINPR_ASSERT(s);
257 WINPR_ASSERT(type);
258 WINPR_ASSERT(channel_id);
259
260 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 2))
261 return FALSE;
262
263 /* Share Control Header */
264 Stream_Read_UINT16(s, len); /* totalLength */
265
266 /* If length is 0x8000 then we actually got a flow control PDU that we should ignore
267 http://msdn.microsoft.com/en-us/library/cc240576.aspx */
268 if (len == 0x8000)
269 {
270 if (!rdp_read_flow_control_pdu(rdp, s, type, channel_id))
271 return FALSE;
272 *channel_id = 0;
273 if (tpktLength)
274 *tpktLength = 8; /* Flow control PDU is 8 bytes */
275 if (remainingLength)
276 *remainingLength = 0;
277
278 char buffer[128] = WINPR_C_ARRAY_INIT;
279 WLog_Print(rdp->log, WLOG_DEBUG,
280 "[Flow control PDU] type=%s, tpktLength=%" PRIu16 ", remainingLength=%" PRIu16,
281 pdu_type_to_str(*type, buffer, sizeof(buffer)), tpktLength ? *tpktLength : 0u,
282 remainingLength ? *remainingLength : 0u);
283 return TRUE;
284 }
285
286 if (len < 4U)
287 {
288 WLog_Print(rdp->log, WLOG_ERROR,
289 "Invalid share control header, length is %" PRIu16 ", must be >4", len);
290 return FALSE;
291 }
292
293 if (tpktLength)
294 *tpktLength = len;
295
296 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 2))
297 return FALSE;
298
299 Stream_Read_UINT16(s, tmp); /* pduType */
300 *type = tmp & 0x0F; /* type is in the 4 least significant bits */
301
302 size_t remLen = len - 4;
303 if (len > 5)
304 {
305 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 2))
306 return FALSE;
307
308 Stream_Read_UINT16(s, *channel_id); /* pduSource */
309 remLen = len - 6;
310 }
311 else
312 *channel_id = 0; /* Windows XP can send such short DEACTIVATE_ALL PDUs. */
313
314 char buffer[128] = WINPR_C_ARRAY_INIT;
315 WLog_Print(rdp->log, WLOG_DEBUG, "type=%s, tpktLength=%" PRIu16 ", remainingLength=%" PRIuz,
316 pdu_type_to_str(*type, buffer, sizeof(buffer)), len, remLen);
317 if (remainingLength)
318 {
319 WINPR_ASSERT(remLen <= UINT16_MAX);
320 *remainingLength = (UINT16)remLen;
321 }
322 return Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, remLen);
323}
324
325BOOL rdp_write_share_control_header(rdpRdp* rdp, wStream* s, size_t length, UINT16 type,
326 UINT16 channel_id)
327{
328 WINPR_ASSERT(s);
329 WINPR_ASSERT(rdp);
330 if (length > UINT16_MAX)
331 return FALSE;
332
333 if (length < RDP_PACKET_HEADER_MAX_LENGTH)
334 return FALSE;
335 if (!Stream_CheckAndLogRequiredCapacityWLog(rdp->log, (s), 6))
336 return FALSE;
337 length -= RDP_PACKET_HEADER_MAX_LENGTH;
338 /* Share Control Header */
339 Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, length)); /* totalLength */
340 Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, type | 0x10)); /* pduType */
341 Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, channel_id)); /* pduSource */
342 return TRUE;
343}
344
345BOOL rdp_read_share_data_header(rdpRdp* rdp, wStream* s, UINT16* length, BYTE* type,
346 UINT32* shareId, BYTE* compressedType, UINT16* compressedLength)
347{
348 WINPR_ASSERT(s);
349 WINPR_ASSERT(rdp);
350
351 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 12))
352 return FALSE;
353
354 /* Share Data Header */
355 Stream_Read_UINT32(s, *shareId); /* shareId (4 bytes) */
356 Stream_Seek_UINT8(s); /* pad1 (1 byte) */
357 Stream_Seek_UINT8(s); /* streamId (1 byte) */
358 Stream_Read_UINT16(s, *length); /* uncompressedLength (2 bytes) */
359 Stream_Read_UINT8(s, *type); /* pduType2, Data PDU Type (1 byte) */
360 Stream_Read_UINT8(s, *compressedType); /* compressedType (1 byte) */
361 Stream_Read_UINT16(s, *compressedLength); /* compressedLength (2 bytes) */
362 return TRUE;
363}
364
365BOOL rdp_write_share_data_header(rdpRdp* rdp, wStream* s, size_t length, BYTE type, UINT32 share_id)
366{
367 const size_t headerLen = RDP_PACKET_HEADER_MAX_LENGTH + RDP_SHARE_CONTROL_HEADER_LENGTH +
368 RDP_SHARE_DATA_HEADER_LENGTH;
369
370 WINPR_ASSERT(s);
371 WINPR_ASSERT(rdp);
372 if (length > UINT16_MAX)
373 return FALSE;
374
375 if (length < headerLen)
376 return FALSE;
377 length -= headerLen;
378 if (!Stream_CheckAndLogRequiredCapacityWLog(rdp->log, (s), 12))
379 return FALSE;
380
381 /* Share Data Header */
382 Stream_Write_UINT32(s, share_id); /* shareId (4 bytes) */
383 Stream_Write_UINT8(s, 0); /* pad1 (1 byte) */
384 Stream_Write_UINT8(s, STREAM_LOW); /* streamId (1 byte) */
385 Stream_Write_UINT16(
386 s, WINPR_ASSERTING_INT_CAST(uint16_t, length)); /* uncompressedLength (2 bytes) */
387 Stream_Write_UINT8(s, type); /* pduType2, Data PDU Type (1 byte) */
388 Stream_Write_UINT8(s, 0); /* compressedType (1 byte) */
389 Stream_Write_UINT16(s, 0); /* compressedLength (2 bytes) */
390 return TRUE;
391}
392
393static BOOL rdp_security_stream_init(rdpRdp* rdp, wStream* s, BOOL sec_header, UINT16* sec_flags)
394{
395 WINPR_ASSERT(rdp);
396 WINPR_ASSERT(s);
397 WINPR_ASSERT(sec_flags);
398
399 if (rdp->do_crypt)
400 {
401 if (!Stream_SafeSeek(s, 12))
402 return FALSE;
403
404 if (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_FIPS)
405 {
406 if (!Stream_SafeSeek(s, 4))
407 return FALSE;
408 }
409
410 *sec_flags |= SEC_ENCRYPT;
411
412 if (rdp->do_secure_checksum)
413 *sec_flags |= SEC_SECURE_CHECKSUM;
414 }
415 else if (*sec_flags != 0 || sec_header)
416 {
417 if (!Stream_SafeSeek(s, 4))
418 return FALSE;
419 }
420
421 return TRUE;
422}
423
424wStream* rdp_send_stream_init(rdpRdp* rdp, UINT16* sec_flags)
425{
426 wStream* s = nullptr;
427
428 WINPR_ASSERT(rdp);
429 WINPR_ASSERT(rdp->transport);
430
431 s = transport_send_stream_init(rdp->transport, 4096);
432
433 if (!s)
434 return nullptr;
435
436 if (!Stream_SafeSeek(s, RDP_PACKET_HEADER_MAX_LENGTH))
437 goto fail;
438
439 if (!rdp_security_stream_init(rdp, s, FALSE, sec_flags))
440 goto fail;
441
442 return s;
443fail:
444 Stream_Release(s);
445 return nullptr;
446}
447
448wStream* rdp_send_stream_pdu_init(rdpRdp* rdp, UINT16* sec_flags)
449{
450 wStream* s = rdp_send_stream_init(rdp, sec_flags);
451
452 if (!s)
453 return nullptr;
454
455 if (!Stream_SafeSeek(s, RDP_SHARE_CONTROL_HEADER_LENGTH))
456 goto fail;
457
458 return s;
459fail:
460 Stream_Release(s);
461 return nullptr;
462}
463
464wStream* rdp_data_pdu_init(rdpRdp* rdp, UINT16* sec_flags)
465{
466 wStream* s = rdp_send_stream_pdu_init(rdp, sec_flags);
467
468 if (!s)
469 return nullptr;
470
471 if (!Stream_SafeSeek(s, RDP_SHARE_DATA_HEADER_LENGTH))
472 goto fail;
473
474 return s;
475fail:
476 Stream_Release(s);
477 return nullptr;
478}
479
480BOOL rdp_set_error_info(rdpRdp* rdp, UINT32 errorInfo)
481{
482 BOOL rc = TRUE;
483 WINPR_ASSERT(rdp);
484
485 rdp->errorInfo = errorInfo;
486
487 if (rdp->errorInfo != ERRINFO_SUCCESS)
488 {
489 rdpContext* context = rdp->context;
490 WINPR_ASSERT(context);
491
492 rdp_print_errinfo(rdp->errorInfo);
493
494 if (context)
495 {
496 freerdp_set_last_error_log(context, MAKE_FREERDP_ERROR(ERRINFO, errorInfo));
497
498 if (context->pubSub)
499 {
500 ErrorInfoEventArgs e = WINPR_C_ARRAY_INIT;
501 EventArgsInit(&e, "freerdp");
502 e.code = rdp->errorInfo;
503 rc = PubSub_OnErrorInfo(context->pubSub, context, &e) >= 0;
504 }
505 }
506 else
507 WLog_Print(rdp->log, WLOG_ERROR, "missing context=%p", (void*)context);
508 }
509 else
510 {
511 freerdp_set_last_error_log(rdp->context, FREERDP_ERROR_SUCCESS);
512 }
513
514 return rc;
515}
516
517wStream* rdp_message_channel_pdu_init(rdpRdp* rdp, UINT16* sec_flags)
518{
519 wStream* s = nullptr;
520
521 WINPR_ASSERT(rdp);
522
523 s = transport_send_stream_init(rdp->transport, 4096);
524
525 if (!s)
526 return nullptr;
527
528 if (!Stream_SafeSeek(s, RDP_PACKET_HEADER_MAX_LENGTH))
529 goto fail;
530
531 if (!rdp_security_stream_init(rdp, s, TRUE, sec_flags))
532 goto fail;
533
534 return s;
535fail:
536 Stream_Release(s);
537 return nullptr;
538}
539
550BOOL rdp_read_header(rdpRdp* rdp, wStream* s, UINT16* length, UINT16* channelId)
551{
552 BYTE li = 0;
553 BYTE code = 0;
554 BYTE choice = 0;
555 UINT16 initiator = 0;
556
557 WINPR_ASSERT(rdp);
558 WINPR_ASSERT(rdp->settings);
559 WINPR_ASSERT(s);
560 DomainMCSPDU MCSPDU = (rdp->settings->ServerMode) ? DomainMCSPDU_SendDataRequest
561 : DomainMCSPDU_SendDataIndication;
562
563 *channelId = 0; /* Initialize in case of early abort */
564 if (!tpkt_read_header(s, length))
565 return FALSE;
566
567 if (!tpdu_read_header(s, &code, &li, *length))
568 return FALSE;
569
570 if (code != X224_TPDU_DATA)
571 {
572 if (code == X224_TPDU_DISCONNECT_REQUEST)
573 {
574 WLog_Print(rdp->log, WLOG_WARN, "Received X224_TPDU_DISCONNECT_REQUEST, terminating");
575 utils_abort_connect(rdp);
576 return TRUE;
577 }
578
579 WLog_Print(rdp->log, WLOG_WARN,
580 "Unexpected X224 TPDU type %s [%08" PRIx32 "] instead of %s",
581 tpdu_type_to_string(code), code, tpdu_type_to_string(X224_TPDU_DATA));
582 return FALSE;
583 }
584
585 if (!per_read_choice(s, &choice))
586 return FALSE;
587
588 const DomainMCSPDU domainMCSPDU = (DomainMCSPDU)(choice >> 2);
589
590 if (domainMCSPDU != MCSPDU)
591 {
592 if (domainMCSPDU != DomainMCSPDU_DisconnectProviderUltimatum)
593 {
594 WLog_Print(rdp->log, WLOG_WARN, "Received %s instead of %s",
595 mcs_domain_pdu_string(domainMCSPDU), mcs_domain_pdu_string(MCSPDU));
596 return FALSE;
597 }
598 }
599
600 MCSPDU = domainMCSPDU;
601
602 if (*length < 8U)
603 {
604 WLog_Print(rdp->log, WLOG_WARN, "TPDU invalid length, got %" PRIu16 ", expected at least 8",
605 *length);
606 return FALSE;
607 }
608
609 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, *length - 8))
610 return FALSE;
611
612 if (MCSPDU == DomainMCSPDU_DisconnectProviderUltimatum)
613 {
614 int reason = 0;
615 TerminateEventArgs e = WINPR_C_ARRAY_INIT;
616
617 if (!mcs_recv_disconnect_provider_ultimatum(rdp->mcs, s, &reason))
618 return FALSE;
619
620 rdpContext* context = rdp->context;
621 WINPR_ASSERT(context);
622 context->disconnectUltimatum = reason;
623
624 if (rdp->errorInfo == ERRINFO_SUCCESS)
625 {
631 UINT32 errorInfo = ERRINFO_RPC_INITIATED_DISCONNECT;
632 if (reason == Disconnect_Ultimatum_provider_initiated)
633 errorInfo = ERRINFO_RPC_INITIATED_DISCONNECT;
634 else if (reason == Disconnect_Ultimatum_user_requested)
635 errorInfo = ERRINFO_LOGOFF_BY_USER;
636
637 if (!rdp_set_error_info(rdp, errorInfo))
638 return FALSE;
639 }
640
641 WLog_Print(rdp->log, WLOG_DEBUG, "DisconnectProviderUltimatum: reason: %d", reason);
642 utils_abort_connect(rdp);
643 EventArgsInit(&e, "freerdp");
644 e.code = 0;
645 return PubSub_OnTerminate(rdp->pubSub, context, &e) >= 0;
646 }
647
648 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 5))
649 return FALSE;
650
651 if (!per_read_integer16(s, &initiator, MCS_BASE_CHANNEL_ID)) /* initiator (UserId) */
652 return FALSE;
653
654 if (!per_read_integer16(s, channelId, 0)) /* channelId */
655 return FALSE;
656
657 const uint8_t dataPriority = Stream_Get_UINT8(s); /* dataPriority + Segmentation (0x70) */
658 WLog_Print(rdp->log, WLOG_TRACE, "dataPriority=%" PRIu8, dataPriority);
659
660 if (!per_read_length(s, length)) /* userData (OCTET_STRING) */
661 return FALSE;
662
663 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, *length))
664 return FALSE;
665
666 return TRUE;
667}
668
679BOOL rdp_write_header(rdpRdp* rdp, wStream* s, size_t length, UINT16 channelId, UINT16 sec_flags)
680{
681 WINPR_ASSERT(rdp);
682 WINPR_ASSERT(rdp->settings);
683 WINPR_ASSERT(s);
684 WINPR_ASSERT(length >= RDP_PACKET_HEADER_MAX_LENGTH);
685 if (length > UINT16_MAX)
686 return FALSE;
687
688 DomainMCSPDU MCSPDU = (rdp->settings->ServerMode) ? DomainMCSPDU_SendDataIndication
689 : DomainMCSPDU_SendDataRequest;
690
691 if ((sec_flags & SEC_ENCRYPT) && (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_FIPS))
692 {
693 const UINT16 body_length = (UINT16)length - RDP_PACKET_HEADER_MAX_LENGTH;
694 const UINT16 pad = 8 - (body_length % 8);
695
696 if (pad != 8)
697 length += pad;
698 }
699
700 if (!mcs_write_domain_mcspdu_header(s, MCSPDU, (UINT16)length, 0))
701 return FALSE;
702 if (!per_write_integer16(s, rdp->mcs->userId, MCS_BASE_CHANNEL_ID)) /* initiator */
703 return FALSE;
704 if (!per_write_integer16(s, channelId, 0)) /* channelId */
705 return FALSE;
706 if (!Stream_EnsureRemainingCapacity(s, 3))
707 return FALSE;
708 Stream_Write_UINT8(s, 0x70); /* dataPriority + segmentation */
709 /*
710 * We always encode length in two bytes, even though we could use
711 * only one byte if length <= 0x7F. It is just easier that way,
712 * because we can leave room for fixed-length header, store all
713 * the data first and then store the header.
714 */
715 length = (length - RDP_PACKET_HEADER_MAX_LENGTH) | 0x8000;
716 Stream_Write_UINT16_BE(
717 s, WINPR_ASSERTING_INT_CAST(uint16_t, length)); /* userData (OCTET_STRING) */
718 return TRUE;
719}
720
721static BOOL rdp_security_stream_out(rdpRdp* rdp, wStream* s, size_t length, UINT16 sec_flags,
722 UINT32* pad)
723{
724 BOOL status = 0;
725 WINPR_ASSERT(rdp);
726 if (length > UINT16_MAX)
727 return FALSE;
728
729 *pad = 0;
730
731 if (sec_flags != 0)
732 {
733 WINPR_ASSERT(sec_flags <= UINT16_MAX);
734 if (!rdp_write_security_header(rdp, s, sec_flags))
735 return FALSE;
736
737 if (sec_flags & SEC_ENCRYPT)
738 {
739 if (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_FIPS)
740 {
741 BYTE* data = Stream_PointerAs(s, BYTE) + 12;
742 const size_t size = WINPR_ASSERTING_INT_CAST(size_t, (data - Stream_Buffer(s)));
743 if (size > length)
744 return FALSE;
745
746 length -= size;
747
748 Stream_Write_UINT16(s, 0x10); /* length */
749 Stream_Write_UINT8(s, 0x1); /* TSFIPS_VERSION 1*/
750 /* handle padding */
751 *pad = 8 - (length % 8);
752
753 if (*pad == 8)
754 *pad = 0;
755
756 if (*pad)
757 memset(data + length, 0, *pad);
758
759 Stream_Write_UINT8(s, WINPR_ASSERTING_INT_CAST(uint8_t, *pad));
760
761 if (!Stream_CheckAndLogRequiredCapacityWLog(rdp->log, s, 8))
762 return FALSE;
763 if (!security_hmac_signature(data, length, Stream_Pointer(s), 8, rdp))
764 return FALSE;
765
766 Stream_Seek(s, 8);
767 if (!security_fips_encrypt(data, length + *pad, rdp))
768 return FALSE;
769 }
770 else
771 {
772 const BYTE* data = Stream_PointerAs(s, const BYTE) + 8;
773 const size_t diff = Stream_GetPosition(s) + 8ULL;
774 if (diff > length)
775 return FALSE;
776 length -= diff;
777
778 if (!Stream_CheckAndLogRequiredCapacityWLog(rdp->log, s, 8))
779 return FALSE;
780 if (sec_flags & SEC_SECURE_CHECKSUM)
781 status = security_salted_mac_signature(rdp, data, (UINT32)length, TRUE,
782 Stream_Pointer(s), 8);
783 else
784 status = security_mac_signature(rdp, data, (UINT32)length,
785 Stream_PointerAs(s, BYTE), 8);
786
787 if (!status)
788 return FALSE;
789
790 Stream_Seek(s, 8);
791
792 if (!security_encrypt(Stream_Pointer(s), length, rdp))
793 return FALSE;
794 }
795 }
796 }
797
798 return TRUE;
799}
800
801static UINT32 rdp_get_sec_bytes(rdpRdp* rdp, UINT16 sec_flags)
802{
803 UINT32 sec_bytes = 0;
804
805 if (sec_flags & SEC_ENCRYPT)
806 {
807 sec_bytes = 12;
808
809 if (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_FIPS)
810 sec_bytes += 4;
811 }
812 else if (sec_flags != 0)
813 {
814 sec_bytes = 4;
815 }
816 else
817 {
818 sec_bytes = 0;
819 }
820
821 return sec_bytes;
822}
823
824BOOL rdp_send(rdpRdp* rdp, wStream* s, UINT16 channelId, UINT16 sec_flags)
825{
826 BOOL rc = FALSE;
827 UINT32 pad = 0;
828 BOOL should_unlock = FALSE;
829
830 if (!s)
831 return FALSE;
832
833 if (!rdp)
834 goto fail;
835
836 if (sec_flags & SEC_ENCRYPT)
837 {
838 security_lock(rdp);
839 should_unlock = TRUE;
840 }
841
842 {
843 size_t length = Stream_GetPosition(s);
844 Stream_ResetPosition(s);
845 if (!rdp_write_header(rdp, s, length, channelId, sec_flags))
846 goto fail;
847
848 if (!rdp_security_stream_out(rdp, s, length, sec_flags, &pad))
849 goto fail;
850
851 length += pad;
852 if (!Stream_SetPosition(s, length))
853 goto fail;
854 Stream_SealLength(s);
855 }
856
857 if (transport_write(rdp->transport, s) < 0)
858 goto fail;
859
860 rc = TRUE;
861fail:
862 if (should_unlock)
863 security_unlock(rdp);
864 Stream_Release(s);
865 return rc;
866}
867
868BOOL rdp_send_pdu(rdpRdp* rdp, wStream* s, UINT16 type, UINT16 channel_id, UINT16 sec_flags)
869{
870 BOOL rc = FALSE;
871 UINT32 sec_bytes = 0;
872 size_t sec_hold = 0;
873 UINT32 pad = 0;
874 BOOL should_unlock = FALSE;
875
876 if (!s)
877 return FALSE;
878
879 if (!rdp)
880 goto fail;
881
882 if (sec_flags & SEC_ENCRYPT)
883 {
884 security_lock(rdp);
885 should_unlock = TRUE;
886 }
887
888 {
889 size_t length = Stream_GetPosition(s);
890 Stream_ResetPosition(s);
891 if (!rdp_write_header(rdp, s, length, MCS_GLOBAL_CHANNEL_ID, sec_flags))
892 goto fail;
893 sec_bytes = rdp_get_sec_bytes(rdp, sec_flags);
894 sec_hold = Stream_GetPosition(s);
895 Stream_Seek(s, sec_bytes);
896 if (!rdp_write_share_control_header(rdp, s, length - sec_bytes, type, channel_id))
897 goto fail;
898 if (!Stream_SetPosition(s, sec_hold))
899 goto fail;
900
901 if (!rdp_security_stream_out(rdp, s, length, sec_flags, &pad))
902 goto fail;
903
904 length += pad;
905 if (!Stream_SetPosition(s, length))
906 goto fail;
907 Stream_SealLength(s);
908 }
909
910 if (transport_write(rdp->transport, s) < 0)
911 goto fail;
912
913 rc = TRUE;
914fail:
915 if (should_unlock)
916 security_unlock(rdp);
917 return rc;
918}
919
920BOOL rdp_send_data_pdu(rdpRdp* rdp, wStream* s, BYTE type, UINT16 channel_id, UINT16 sec_flags)
921{
922 BOOL rc = FALSE;
923 UINT32 sec_bytes = 0;
924 size_t sec_hold = 0;
925 UINT32 pad = 0;
926 BOOL should_unlock = FALSE;
927
928 if (!s)
929 return FALSE;
930
931 if (!rdp)
932 goto fail;
933
934 if (sec_flags & SEC_ENCRYPT)
935 {
936 security_lock(rdp);
937 should_unlock = TRUE;
938 }
939
940 {
941 size_t length = Stream_GetPosition(s);
942 Stream_ResetPosition(s);
943 if (!rdp_write_header(rdp, s, length, MCS_GLOBAL_CHANNEL_ID, sec_flags))
944 goto fail;
945 sec_bytes = rdp_get_sec_bytes(rdp, sec_flags);
946 sec_hold = Stream_GetPosition(s);
947 Stream_Seek(s, sec_bytes);
948 if (!rdp_write_share_control_header(rdp, s, length - sec_bytes, PDU_TYPE_DATA, channel_id))
949 goto fail;
950 if (!rdp_write_share_data_header(rdp, s, length - sec_bytes, type, rdp->settings->ShareId))
951 goto fail;
952 if (!Stream_SetPosition(s, sec_hold))
953 goto fail;
954
955 if (!rdp_security_stream_out(rdp, s, length, sec_flags, &pad))
956 goto fail;
957
958 length += pad;
959 if (!Stream_SetPosition(s, length))
960 goto fail;
961 Stream_SealLength(s);
962 }
963 WLog_Print(rdp->log, WLOG_DEBUG,
964 "sending data (type=0x%x size=%" PRIuz " channelId=%" PRIu16 ")", type,
965 Stream_Length(s), channel_id);
966
967 rdp->outPackets++;
968 if (transport_write(rdp->transport, s) < 0)
969 goto fail;
970
971 rc = TRUE;
972fail:
973 if (should_unlock)
974 security_unlock(rdp);
975 Stream_Release(s);
976 return rc;
977}
978
979BOOL rdp_send_message_channel_pdu(rdpRdp* rdp, wStream* s, UINT16 sec_flags)
980{
981 BOOL rc = FALSE;
982 UINT32 pad = 0;
983 BOOL should_unlock = FALSE;
984
985 WINPR_ASSERT(rdp);
986 WINPR_ASSERT(s);
987
988 if (sec_flags & SEC_ENCRYPT)
989 {
990 security_lock(rdp);
991 should_unlock = TRUE;
992 }
993
994 {
995 size_t length = Stream_GetPosition(s);
996 Stream_ResetPosition(s);
997 if (!rdp_write_header(rdp, s, length, rdp->mcs->messageChannelId, sec_flags))
998 goto fail;
999
1000 if (!rdp_security_stream_out(rdp, s, length, sec_flags, &pad))
1001 goto fail;
1002
1003 length += pad;
1004 if (!Stream_SetPosition(s, length))
1005 goto fail;
1006 }
1007 Stream_SealLength(s);
1008
1009 if (transport_write(rdp->transport, s) < 0)
1010 goto fail;
1011
1012 rc = TRUE;
1013fail:
1014 if (should_unlock)
1015 security_unlock(rdp);
1016
1017 Stream_Release(s);
1018 return rc;
1019}
1020
1021static BOOL rdp_recv_server_shutdown_denied_pdu(WINPR_ATTR_UNUSED rdpRdp* rdp,
1022 WINPR_ATTR_UNUSED wStream* s)
1023{
1024 return TRUE;
1025}
1026
1027static BOOL rdp_recv_server_set_keyboard_indicators_pdu(rdpRdp* rdp, wStream* s)
1028{
1029 WINPR_ASSERT(rdp);
1030 WINPR_ASSERT(s);
1031
1032 rdpContext* context = rdp->context;
1033 WINPR_ASSERT(context);
1034 WINPR_ASSERT(context->update);
1035
1036 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
1037 return FALSE;
1038
1039 const uint16_t unitId = Stream_Get_UINT16(s); /* unitId (2 bytes) */
1040 if (unitId != 0)
1041 {
1042 WLog_Print(rdp->log, WLOG_WARN,
1043 "[MS-RDPBCGR] 2.2.8.2.1.1 Set Keyboard Indicators PDU Data "
1044 "(TS_SET_KEYBOARD_INDICATORS_PDU)::unitId should be 0, is %" PRIu16,
1045 unitId);
1046 }
1047 const UINT16 ledFlags = Stream_Get_UINT16(s); /* ledFlags (2 bytes) */
1048 return IFCALLRESULT(TRUE, context->update->SetKeyboardIndicators, context, ledFlags);
1049}
1050
1051static BOOL rdp_recv_server_set_keyboard_ime_status_pdu(rdpRdp* rdp, wStream* s)
1052{
1053 if (!rdp || !rdp->input)
1054 return FALSE;
1055
1056 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 10))
1057 return FALSE;
1058
1059 const uint16_t unitId = Stream_Get_UINT16(s); /* unitId (2 bytes) */
1060 if (unitId != 0)
1061 {
1062 WLog_Print(rdp->log, WLOG_WARN,
1063 "[MS-RDPBCGR] 2.2.8.2.2.1 Set Keyboard IME Status PDU Data "
1064 "(TS_SET_KEYBOARD_IME_STATUS_PDU)::unitId should be 0, is %" PRIu16,
1065 unitId);
1066 }
1067 const uint32_t imeState = Stream_Get_UINT32(s); /* imeState (4 bytes) */
1068 const uint32_t imeConvMode = Stream_Get_UINT32(s); /* imeConvMode (4 bytes) */
1069 return IFCALLRESULT(TRUE, rdp->update->SetKeyboardImeStatus, rdp->context, unitId, imeState,
1070 imeConvMode);
1071}
1072
1073static BOOL rdp_recv_set_error_info_data_pdu(rdpRdp* rdp, wStream* s)
1074{
1075 UINT32 errorInfo = 0;
1076
1077 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
1078 return FALSE;
1079
1080 Stream_Read_UINT32(s, errorInfo); /* errorInfo (4 bytes) */
1081 return rdp_set_error_info(rdp, errorInfo);
1082}
1083
1084static BOOL rdp_recv_server_auto_reconnect_status_pdu(rdpRdp* rdp, wStream* s)
1085{
1086 UINT32 arcStatus = 0;
1087
1088 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
1089 return FALSE;
1090
1091 Stream_Read_UINT32(s, arcStatus); /* arcStatus (4 bytes) */
1092 WLog_Print(rdp->log, WLOG_WARN, "AutoReconnectStatus: 0x%08" PRIX32 "", arcStatus);
1093 return TRUE;
1094}
1095
1096static BOOL rdp_recv_server_status_info_pdu(rdpRdp* rdp, wStream* s)
1097{
1098 UINT32 statusCode = 0;
1099
1100 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
1101 return FALSE;
1102
1103 Stream_Read_UINT32(s, statusCode); /* statusCode (4 bytes) */
1104
1105 if (rdp->update->ServerStatusInfo)
1106 return rdp->update->ServerStatusInfo(rdp->context, statusCode);
1107
1108 return TRUE;
1109}
1110
1111static void log_monitor(size_t idx, const MONITOR_DEF* monitor, wLog* log, DWORD level)
1112{
1113 WINPR_ASSERT(monitor);
1114
1115 WLog_Print(log, level, "[%" PRIuz "] {%dx%d-%dx%d} [0x%08" PRIx32 "]", idx, monitor->left,
1116 monitor->top, monitor->right, monitor->bottom, monitor->flags);
1117}
1118
1119static void log_monitor_configuration(wLog* log, const MONITOR_DEF* monitors, size_t count)
1120{
1121 const DWORD level = WLOG_DEBUG;
1122 WLog_Print(log, level, "[BEGIN] RemoteMonitors[%" PRIuz "]", count);
1123 for (size_t x = 0; x < count; x++)
1124 {
1125 const MONITOR_DEF* monitor = &monitors[x];
1126 log_monitor(x, monitor, log, level);
1127 }
1128 WLog_Print(log, level, "[END] RemoteMonitors[%" PRIuz "]", count);
1129}
1130
1131static BOOL rdp_recv_monitor_layout_pdu(rdpRdp* rdp, wStream* s)
1132{
1133 BOOL ret = TRUE;
1134
1135 WINPR_ASSERT(rdp);
1136 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 4))
1137 return FALSE;
1138
1139 const UINT32 monitorCount = Stream_Get_UINT32(s); /* monitorCount (4 bytes) */
1140
1141 if (!Stream_CheckAndLogRequiredLengthOfSizeWLog(rdp->log, s, monitorCount, 20ull))
1142 return FALSE;
1143
1144 MONITOR_DEF* monitorDefArray = (MONITOR_DEF*)calloc(monitorCount, sizeof(MONITOR_DEF));
1145
1146 if (!monitorDefArray)
1147 return FALSE;
1148
1149 for (UINT32 index = 0; index < monitorCount; index++)
1150 {
1151 MONITOR_DEF* monitor = &monitorDefArray[index];
1152 Stream_Read_INT32(s, monitor->left); /* left (4 bytes) */
1153 Stream_Read_INT32(s, monitor->top); /* top (4 bytes) */
1154 Stream_Read_INT32(s, monitor->right); /* right (4 bytes) */
1155 Stream_Read_INT32(s, monitor->bottom); /* bottom (4 bytes) */
1156 Stream_Read_UINT32(s, monitor->flags); /* flags (4 bytes) */
1157 }
1158
1159 log_monitor_configuration(rdp->log, monitorDefArray, monitorCount);
1160 IFCALLRET(rdp->update->RemoteMonitors, ret, rdp->context, monitorCount, monitorDefArray);
1161 free(monitorDefArray);
1162 if (!ret)
1163 return FALSE;
1164 return rdp_set_monitor_layout_pdu_state(rdp, TRUE);
1165}
1166
1167state_run_t rdp_recv_data_pdu(rdpRdp* rdp, wStream* s)
1168{
1169 BYTE type = 0;
1170 wStream* cs = nullptr;
1171 UINT16 length = 0;
1172 UINT32 shareId = 0;
1173 BYTE compressedType = 0;
1174 UINT16 compressedLength = 0;
1175
1176 WINPR_ASSERT(rdp);
1177 if (!rdp_read_share_data_header(rdp, s, &length, &type, &shareId, &compressedType,
1178 &compressedLength))
1179 {
1180 WLog_Print(rdp->log, WLOG_ERROR, "rdp_read_share_data_header() failed");
1181 return STATE_RUN_FAILED;
1182 }
1183
1184 cs = s;
1185
1186 if (compressedType & PACKET_COMPRESSED)
1187 {
1188 if (compressedLength < 18)
1189 {
1190 WLog_Print(rdp->log, WLOG_ERROR,
1191 "bulk_decompress: not enough bytes for compressedLength %" PRIu16 "",
1192 compressedLength);
1193 return STATE_RUN_FAILED;
1194 }
1195
1196 UINT32 DstSize = 0;
1197 const BYTE* pDstData = nullptr;
1198 UINT16 SrcSize = compressedLength - 18;
1199
1200 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, SrcSize))
1201 {
1202 WLog_Print(rdp->log, WLOG_ERROR,
1203 "bulk_decompress: not enough bytes for compressedLength %" PRIu16 "",
1204 compressedLength);
1205 return STATE_RUN_FAILED;
1206 }
1207
1208 if (bulk_decompress(rdp->bulk, Stream_ConstPointer(s), SrcSize, &pDstData, &DstSize,
1209 compressedType))
1210 {
1211 cs = transport_take_from_pool(rdp->transport, DstSize);
1212 if (!cs)
1213 {
1214 WLog_Print(rdp->log, WLOG_ERROR, "Couldn't take stream from pool");
1215 return STATE_RUN_FAILED;
1216 }
1217
1218 Stream_ResetPosition(cs);
1219 Stream_Write(cs, pDstData, DstSize);
1220 Stream_SealLength(cs);
1221 Stream_ResetPosition(cs);
1222 }
1223 else
1224 {
1225 WLog_Print(rdp->log, WLOG_ERROR, "bulk_decompress() failed");
1226 return STATE_RUN_FAILED;
1227 }
1228
1229 Stream_Seek(s, SrcSize);
1230 }
1231
1232 WLog_Print(rdp->log, WLOG_DEBUG, "recv %s Data PDU (0x%02" PRIX8 "), length: %" PRIu16 "",
1233 data_pdu_type_to_string(type), type, length);
1234
1235 switch (type)
1236 {
1237 case DATA_PDU_TYPE_UPDATE:
1238 if (!update_recv(rdp->update, cs))
1239 {
1240 WLog_Print(rdp->log, WLOG_ERROR, "DATA_PDU_TYPE_UPDATE - update_recv() failed");
1241 goto out_fail;
1242 }
1243
1244 break;
1245
1246 case DATA_PDU_TYPE_CONTROL:
1247 if (!rdp_recv_server_control_pdu(rdp, cs))
1248 {
1249 WLog_Print(rdp->log, WLOG_ERROR,
1250 "DATA_PDU_TYPE_CONTROL - rdp_recv_server_control_pdu() failed");
1251 goto out_fail;
1252 }
1253
1254 break;
1255
1256 case DATA_PDU_TYPE_POINTER:
1257 if (!update_recv_pointer(rdp->update, cs))
1258 {
1259 WLog_Print(rdp->log, WLOG_ERROR,
1260 "DATA_PDU_TYPE_POINTER - update_recv_pointer() failed");
1261 goto out_fail;
1262 }
1263
1264 break;
1265
1266 case DATA_PDU_TYPE_SYNCHRONIZE:
1267 if (!rdp_recv_server_synchronize_pdu(rdp, cs))
1268 {
1269 WLog_Print(rdp->log, WLOG_ERROR,
1270 "DATA_PDU_TYPE_SYNCHRONIZE - rdp_recv_synchronize_pdu() failed");
1271 goto out_fail;
1272 }
1273
1274 break;
1275
1276 case DATA_PDU_TYPE_PLAY_SOUND:
1277 if (!update_recv_play_sound(rdp->update, cs))
1278 {
1279 WLog_Print(rdp->log, WLOG_ERROR,
1280 "DATA_PDU_TYPE_PLAY_SOUND - update_recv_play_sound() failed");
1281 goto out_fail;
1282 }
1283
1284 break;
1285
1286 case DATA_PDU_TYPE_SHUTDOWN_DENIED:
1287 if (!rdp_recv_server_shutdown_denied_pdu(rdp, cs))
1288 {
1289 WLog_Print(
1290 rdp->log, WLOG_ERROR,
1291 "DATA_PDU_TYPE_SHUTDOWN_DENIED - rdp_recv_server_shutdown_denied_pdu() failed");
1292 goto out_fail;
1293 }
1294
1295 break;
1296
1297 case DATA_PDU_TYPE_SAVE_SESSION_INFO:
1298 if (!rdp_recv_save_session_info(rdp, cs))
1299 {
1300 WLog_Print(rdp->log, WLOG_ERROR,
1301 "DATA_PDU_TYPE_SAVE_SESSION_INFO - rdp_recv_save_session_info() failed");
1302 goto out_fail;
1303 }
1304
1305 break;
1306
1307 case DATA_PDU_TYPE_FONT_MAP:
1308 if (!rdp_recv_font_map_pdu(rdp, cs))
1309 {
1310 WLog_Print(rdp->log, WLOG_ERROR,
1311 "DATA_PDU_TYPE_FONT_MAP - rdp_recv_font_map_pdu() failed");
1312 goto out_fail;
1313 }
1314
1315 break;
1316
1317 case DATA_PDU_TYPE_SET_KEYBOARD_INDICATORS:
1318 if (!rdp_recv_server_set_keyboard_indicators_pdu(rdp, cs))
1319 {
1320 WLog_Print(rdp->log, WLOG_ERROR,
1321 "DATA_PDU_TYPE_SET_KEYBOARD_INDICATORS - "
1322 "rdp_recv_server_set_keyboard_indicators_pdu() failed");
1323 goto out_fail;
1324 }
1325
1326 break;
1327
1328 case DATA_PDU_TYPE_SET_KEYBOARD_IME_STATUS:
1329 if (!rdp_recv_server_set_keyboard_ime_status_pdu(rdp, cs))
1330 {
1331 WLog_Print(rdp->log, WLOG_ERROR,
1332 "DATA_PDU_TYPE_SET_KEYBOARD_IME_STATUS - "
1333 "rdp_recv_server_set_keyboard_ime_status_pdu() failed");
1334 goto out_fail;
1335 }
1336
1337 break;
1338
1339 case DATA_PDU_TYPE_SET_ERROR_INFO:
1340 if (!rdp_recv_set_error_info_data_pdu(rdp, cs))
1341 {
1342 WLog_Print(
1343 rdp->log, WLOG_ERROR,
1344 "DATA_PDU_TYPE_SET_ERROR_INFO - rdp_recv_set_error_info_data_pdu() failed");
1345 goto out_fail;
1346 }
1347
1348 break;
1349
1350 case DATA_PDU_TYPE_ARC_STATUS:
1351 if (!rdp_recv_server_auto_reconnect_status_pdu(rdp, cs))
1352 {
1353 WLog_Print(rdp->log, WLOG_ERROR,
1354 "DATA_PDU_TYPE_ARC_STATUS - "
1355 "rdp_recv_server_auto_reconnect_status_pdu() failed");
1356 goto out_fail;
1357 }
1358
1359 break;
1360
1361 case DATA_PDU_TYPE_STATUS_INFO:
1362 if (!rdp_recv_server_status_info_pdu(rdp, cs))
1363 {
1364 WLog_Print(rdp->log, WLOG_ERROR,
1365 "DATA_PDU_TYPE_STATUS_INFO - rdp_recv_server_status_info_pdu() failed");
1366 goto out_fail;
1367 }
1368
1369 break;
1370
1371 case DATA_PDU_TYPE_MONITOR_LAYOUT:
1372 if (!rdp_recv_monitor_layout_pdu(rdp, cs))
1373 {
1374 WLog_Print(rdp->log, WLOG_ERROR,
1375 "DATA_PDU_TYPE_MONITOR_LAYOUT - rdp_recv_monitor_layout_pdu() failed");
1376 goto out_fail;
1377 }
1378
1379 break;
1380
1381 default:
1382 WLog_Print(rdp->log, WLOG_WARN,
1383 "[UNHANDLED] %s Data PDU (0x%02" PRIX8 "), length: %" PRIu16 "",
1384 data_pdu_type_to_string(type), type, length);
1385 break;
1386 }
1387
1388 if (cs != s)
1389 Stream_Release(cs);
1390
1391 return STATE_RUN_SUCCESS;
1392out_fail:
1393
1394 if (cs != s)
1395 Stream_Release(cs);
1396
1397 return STATE_RUN_FAILED;
1398}
1399
1400state_run_t rdp_recv_message_channel_pdu(rdpRdp* rdp, wStream* s, UINT16 securityFlags)
1401{
1402 WINPR_ASSERT(rdp);
1403 WINPR_ASSERT(s);
1404
1405 if (securityFlags & SEC_AUTODETECT_REQ)
1406 {
1407 /* Server Auto-Detect Request PDU */
1408 return autodetect_recv_request_packet(rdp->autodetect, RDP_TRANSPORT_TCP, s);
1409 }
1410
1411 if (securityFlags & SEC_AUTODETECT_RSP)
1412 {
1413 /* Client Auto-Detect Response PDU */
1414 return autodetect_recv_response_packet(rdp->autodetect, RDP_TRANSPORT_TCP, s);
1415 }
1416
1417 if (securityFlags & SEC_HEARTBEAT)
1418 {
1419 /* Heartbeat PDU */
1420 return rdp_recv_heartbeat_packet(rdp, s);
1421 }
1422
1423 if (securityFlags & SEC_TRANSPORT_REQ)
1424 {
1425 return multitransport_recv_request(rdp->multitransport, s);
1426 }
1427
1428 if (securityFlags & SEC_TRANSPORT_RSP)
1429 {
1430 return multitransport_recv_response(rdp->multitransport, s);
1431 }
1432
1433 if (securityFlags & SEC_LICENSE_PKT)
1434 {
1435 return license_recv(rdp->license, s);
1436 }
1437
1438 if (securityFlags & SEC_LICENSE_ENCRYPT_CS)
1439 {
1440 return license_recv(rdp->license, s);
1441 }
1442
1443 if (securityFlags & SEC_LICENSE_ENCRYPT_SC)
1444 {
1445 return license_recv(rdp->license, s);
1446 }
1447
1448 return STATE_RUN_SUCCESS;
1449}
1450
1451state_run_t rdp_recv_out_of_sequence_pdu(rdpRdp* rdp, wStream* s, UINT16 pduType, UINT16 length)
1452{
1453 state_run_t rc = STATE_RUN_FAILED;
1454 WINPR_ASSERT(rdp);
1455
1456 switch (pduType)
1457 {
1458 case PDU_TYPE_DATA:
1459 rc = rdp_recv_data_pdu(rdp, s);
1460 break;
1461 case PDU_TYPE_SERVER_REDIRECTION:
1462 rc = rdp_recv_enhanced_security_redirection_packet(rdp, s);
1463 break;
1464 case PDU_TYPE_FLOW_RESPONSE:
1465 case PDU_TYPE_FLOW_STOP:
1466 case PDU_TYPE_FLOW_TEST:
1467 rc = STATE_RUN_SUCCESS;
1468 break;
1469 default:
1470 {
1471 char buffer1[256] = WINPR_C_ARRAY_INIT;
1472 char buffer2[256] = WINPR_C_ARRAY_INIT;
1473
1474 WLog_Print(rdp->log, WLOG_ERROR, "expected %s, got %s",
1475 pdu_type_to_str(PDU_TYPE_DEMAND_ACTIVE, buffer1, sizeof(buffer1)),
1476 pdu_type_to_str(pduType, buffer2, sizeof(buffer2)));
1477 rc = STATE_RUN_FAILED;
1478 }
1479 break;
1480 }
1481
1482 if (!tpkt_ensure_stream_consumed(rdp->log, s, length))
1483 return STATE_RUN_FAILED;
1484 return rc;
1485}
1486
1487BOOL rdp_read_flow_control_pdu(rdpRdp* rdp, wStream* s, UINT16* type, UINT16* channel_id)
1488{
1489 /*
1490 * Read flow control PDU - documented in FlowPDU section in T.128
1491 * http://www.itu.int/rec/T-REC-T.128-199802-S/en
1492 * The specification for the PDU has pad8bits listed BEFORE pduTypeFlow.
1493 * However, so far pad8bits has always been observed to arrive AFTER pduTypeFlow.
1494 * Switched the order of these two fields to match this observation.
1495 */
1496 UINT8 pduType = 0;
1497
1498 WINPR_ASSERT(rdp);
1499 WINPR_ASSERT(s);
1500 WINPR_ASSERT(type);
1501 WINPR_ASSERT(channel_id);
1502
1503 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 6))
1504 return FALSE;
1505 Stream_Read_UINT8(s, pduType); /* pduTypeFlow */
1506 *type = pduType;
1507 Stream_Seek_UINT8(s); /* pad8bits */
1508 Stream_Seek_UINT8(s); /* flowIdentifier */
1509 Stream_Seek_UINT8(s); /* flowNumber */
1510 Stream_Read_UINT16(s, *channel_id); /* pduSource */
1511 return TRUE;
1512}
1513
1525BOOL rdp_decrypt(rdpRdp* rdp, wStream* s, UINT16* pLength, UINT16 securityFlags)
1526{
1527 BOOL res = FALSE;
1528 BYTE cmac[8] = WINPR_C_ARRAY_INIT;
1529 BYTE wmac[8] = WINPR_C_ARRAY_INIT;
1530 BOOL status = FALSE;
1531
1532 WINPR_ASSERT(rdp);
1533 WINPR_ASSERT(rdp->settings);
1534 WINPR_ASSERT(s);
1535 WINPR_ASSERT(pLength);
1536
1537 security_lock(rdp);
1538
1539 INT32 length = *pLength;
1540 if (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_NONE)
1541 {
1542 res = TRUE;
1543 goto unlock;
1544 }
1545
1546 if (rdp->settings->EncryptionMethods == ENCRYPTION_METHOD_FIPS)
1547 {
1548 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, 12))
1549 goto unlock;
1550
1551 UINT16 len = 0;
1552 Stream_Read_UINT16(s, len); /* 0x10 */
1553 if (len != 0x10)
1554 WLog_Print(rdp->log, WLOG_WARN, "ENCRYPTION_METHOD_FIPS length %" PRIu16 " != 0x10",
1555 len);
1556
1557 UINT16 version = 0;
1558 Stream_Read_UINT8(s, version); /* 0x1 */
1559 if (version != 1)
1560 WLog_Print(rdp->log, WLOG_WARN, "ENCRYPTION_METHOD_FIPS version %" PRIu16 " != 1",
1561 version);
1562
1563 BYTE pad = 0;
1564 Stream_Read_UINT8(s, pad);
1565 const BYTE* sig = Stream_ConstPointer(s);
1566 Stream_Seek(s, 8); /* signature */
1567 length -= 12;
1568 const INT32 padLength = length - pad;
1569
1570 if ((length <= 0) || (padLength <= 0) || (padLength > UINT16_MAX))
1571 {
1572 WLog_Print(rdp->log, WLOG_ERROR, "FATAL: invalid pad length %" PRId32, padLength);
1573 goto unlock;
1574 }
1575
1576 if (!security_fips_decrypt(Stream_Pointer(s), (size_t)length, rdp))
1577 goto unlock;
1578
1579 if (!security_fips_check_signature(Stream_ConstPointer(s), (size_t)padLength, sig, 8, rdp))
1580 goto unlock;
1581
1582 if (!Stream_SetLength(s, Stream_Length(s) - pad))
1583 goto unlock;
1584
1585 *pLength = (UINT16)padLength;
1586 }
1587 else
1588 {
1589 if (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, sizeof(wmac)))
1590 goto unlock;
1591
1592 Stream_Read(s, wmac, sizeof(wmac));
1593 length -= sizeof(wmac);
1594
1595 if (length <= 0)
1596 {
1597 WLog_Print(rdp->log, WLOG_ERROR, "FATAL: invalid length field");
1598 goto unlock;
1599 }
1600
1601 if (!security_decrypt(Stream_PointerAs(s, BYTE), (size_t)length, rdp))
1602 goto unlock;
1603
1604 if (securityFlags & SEC_SECURE_CHECKSUM)
1605 status = security_salted_mac_signature(rdp, Stream_ConstPointer(s), (UINT32)length,
1606 FALSE, cmac, sizeof(cmac));
1607 else
1608 status = security_mac_signature(rdp, Stream_ConstPointer(s), (UINT32)length, cmac,
1609 sizeof(cmac));
1610
1611 if (!status)
1612 goto unlock;
1613
1614 if (memcmp(wmac, cmac, sizeof(wmac)) != 0)
1615 {
1616 WLog_Print(rdp->log, WLOG_ERROR, "WARNING: invalid packet signature");
1617 /*
1618 * Because Standard RDP Security is totally broken,
1619 * and cannot protect against MITM, don't treat signature
1620 * verification failure as critical. This at least enables
1621 * us to work with broken RDP clients and servers that
1622 * generate invalid signatures.
1623 */
1624 // return FALSE;
1625 }
1626
1627 *pLength = (UINT16)length;
1628 }
1629 res = TRUE;
1630unlock:
1631 security_unlock(rdp);
1632 return res;
1633}
1634
1635const char* pdu_type_to_str(UINT16 pduType, char* buffer, size_t length)
1636{
1637 const char* str = nullptr;
1638 switch (pduType)
1639 {
1640 case PDU_TYPE_DEMAND_ACTIVE:
1641 str = "PDU_TYPE_DEMAND_ACTIVE";
1642 break;
1643 case PDU_TYPE_CONFIRM_ACTIVE:
1644 str = "PDU_TYPE_CONFIRM_ACTIVE";
1645 break;
1646 case PDU_TYPE_DEACTIVATE_ALL:
1647 str = "PDU_TYPE_DEACTIVATE_ALL";
1648 break;
1649 case PDU_TYPE_DATA:
1650 str = "PDU_TYPE_DATA";
1651 break;
1652 case PDU_TYPE_SERVER_REDIRECTION:
1653 str = "PDU_TYPE_SERVER_REDIRECTION";
1654 break;
1655 case PDU_TYPE_FLOW_TEST:
1656 str = "PDU_TYPE_FLOW_TEST";
1657 break;
1658 case PDU_TYPE_FLOW_RESPONSE:
1659 str = "PDU_TYPE_FLOW_RESPONSE";
1660 break;
1661 case PDU_TYPE_FLOW_STOP:
1662 str = "PDU_TYPE_FLOW_STOP";
1663 break;
1664 default:
1665 str = "PDU_TYPE_UNKNOWN";
1666 break;
1667 }
1668
1669 winpr_str_append(str, buffer, length, "");
1670 {
1671 char msg[32] = WINPR_C_ARRAY_INIT;
1672 (void)_snprintf(msg, sizeof(msg), "[0x%08" PRIx32 "]", pduType);
1673 winpr_str_append(msg, buffer, length, "");
1674 }
1675 return buffer;
1676}
1677
1684static state_run_t rdp_recv_tpkt_pdu(rdpRdp* rdp, wStream* s)
1685{
1686 state_run_t rc = STATE_RUN_SUCCESS;
1687 UINT16 length = 0;
1688 UINT16 pduType = 0;
1689 UINT16 pduSource = 0;
1690 UINT16 channelId = 0;
1691 UINT16 securityFlags = 0;
1692
1693 WINPR_ASSERT(rdp);
1694 WINPR_ASSERT(rdp->context);
1695 WINPR_ASSERT(s);
1696
1697 freerdp* instance = rdp->context->instance;
1698 WINPR_ASSERT(instance);
1699
1700 if (!rdp_read_header(rdp, s, &length, &channelId))
1701 return STATE_RUN_FAILED;
1702
1703 if (freerdp_shall_disconnect_context(rdp->context))
1704 return STATE_RUN_SUCCESS;
1705
1706 if (rdp->autodetect->bandwidthMeasureStarted)
1707 {
1708 rdp->autodetect->bandwidthMeasureByteCount += length;
1709 }
1710
1711 if (rdp->mcs->messageChannelId && (channelId == rdp->mcs->messageChannelId))
1712 {
1713 rdp->inPackets++;
1714 return rdp_handle_message_channel(rdp, s, channelId, length);
1715 }
1716
1717 if (rdp->settings->UseRdpSecurityLayer)
1718 {
1719 if (!rdp_read_security_header(rdp, s, &securityFlags, &length))
1720 return STATE_RUN_FAILED;
1721
1722 if (securityFlags & (SEC_ENCRYPT | SEC_REDIRECTION_PKT))
1723 {
1724 if (!rdp_decrypt(rdp, s, &length, securityFlags))
1725 return STATE_RUN_FAILED;
1726 }
1727
1728 if (securityFlags & SEC_REDIRECTION_PKT)
1729 {
1730 /*
1731 * [MS-RDPBCGR] 2.2.13.2.1
1732 * - no share control header, nor the 2 byte pad
1733 */
1734 Stream_Rewind(s, 2);
1735 rdp->inPackets++;
1736
1737 rc = rdp_recv_enhanced_security_redirection_packet(rdp, s);
1738 goto out;
1739 }
1740 }
1741
1742 if (channelId == MCS_GLOBAL_CHANNEL_ID)
1743 {
1744 while (Stream_GetRemainingLength(s) > 3)
1745 {
1746 wStream subbuffer;
1747 wStream* sub = nullptr;
1748 size_t diff = 0;
1749 UINT16 remain = 0;
1750
1751 if (!rdp_read_share_control_header(rdp, s, nullptr, &remain, &pduType, &pduSource))
1752 return STATE_RUN_FAILED;
1753
1754 sub = Stream_StaticInit(&subbuffer, Stream_Pointer(s), remain);
1755 if (!Stream_SafeSeek(s, remain))
1756 return STATE_RUN_FAILED;
1757
1758 rdp->settings->PduSource = pduSource;
1759 rdp->inPackets++;
1760
1761 switch (pduType)
1762 {
1763 case PDU_TYPE_DATA:
1764 rc = rdp_recv_data_pdu(rdp, sub);
1765 if (state_run_failed(rc))
1766 return rc;
1767 break;
1768
1769 case PDU_TYPE_DEACTIVATE_ALL:
1770 if (!rdp_recv_deactivate_all(rdp, sub))
1771 {
1772 WLog_Print(rdp->log, WLOG_ERROR,
1773 "rdp_recv_tpkt_pdu: rdp_recv_deactivate_all() fail");
1774 return STATE_RUN_FAILED;
1775 }
1776
1777 break;
1778
1779 case PDU_TYPE_SERVER_REDIRECTION:
1780 return rdp_recv_enhanced_security_redirection_packet(rdp, sub);
1781
1782 case PDU_TYPE_FLOW_RESPONSE:
1783 case PDU_TYPE_FLOW_STOP:
1784 case PDU_TYPE_FLOW_TEST:
1785 WLog_Print(rdp->log, WLOG_DEBUG, "flow message 0x%04" PRIX16 "", pduType);
1786 /* http://msdn.microsoft.com/en-us/library/cc240576.aspx */
1787 if (!Stream_SafeSeek(sub, remain))
1788 return STATE_RUN_FAILED;
1789 break;
1790
1791 default:
1792 {
1793 char buffer[256] = WINPR_C_ARRAY_INIT;
1794 WLog_Print(rdp->log, WLOG_ERROR, "incorrect PDU type: %s",
1795 pdu_type_to_str(pduType, buffer, sizeof(buffer)));
1796 }
1797 break;
1798 }
1799
1800 diff = Stream_GetRemainingLength(sub);
1801 if (diff > 0)
1802 {
1803 char buffer[256] = WINPR_C_ARRAY_INIT;
1804 WLog_Print(rdp->log, WLOG_WARN,
1805 "pduType %s not properly parsed, %" PRIuz
1806 " bytes remaining unhandled. Skipping.",
1807 pdu_type_to_str(pduType, buffer, sizeof(buffer)), diff);
1808 }
1809 }
1810 }
1811 else
1812 {
1813 rdp->inPackets++;
1814
1815 if (!freerdp_channel_process(instance, s, channelId, length))
1816 return STATE_RUN_FAILED;
1817 }
1818
1819out:
1820 if (!tpkt_ensure_stream_consumed(rdp->log, s, length))
1821 return STATE_RUN_FAILED;
1822 return rc;
1823}
1824
1825static state_run_t rdp_recv_fastpath_pdu(rdpRdp* rdp, wStream* s)
1826{
1827 UINT16 length = 0;
1828
1829 WINPR_ASSERT(rdp);
1830 rdpFastPath* fastpath = rdp->fastpath;
1831
1832 if (!fastpath_read_header_rdp(fastpath, s, &length))
1833 {
1834 WLog_Print(rdp->log, WLOG_ERROR, "rdp_recv_fastpath_pdu: fastpath_read_header_rdp() fail");
1835 return STATE_RUN_FAILED;
1836 }
1837
1838 if ((length == 0) || (!Stream_CheckAndLogRequiredLengthWLog(rdp->log, s, length)))
1839 {
1840 WLog_Print(rdp->log, WLOG_ERROR, "incorrect FastPath PDU header length %" PRIu16 "",
1841 length);
1842 return STATE_RUN_FAILED;
1843 }
1844
1845 if (rdp->autodetect->bandwidthMeasureStarted)
1846 {
1847 rdp->autodetect->bandwidthMeasureByteCount += length;
1848 }
1849
1850 if (!fastpath_decrypt(fastpath, s, &length))
1851 return STATE_RUN_FAILED;
1852
1853 return fastpath_recv_updates(rdp->fastpath, s);
1854}
1855
1856static state_run_t rdp_recv_pdu(rdpRdp* rdp, wStream* s)
1857{
1858 const int rc = tpkt_verify_header(s);
1859 if (rc > 0)
1860 return rdp_recv_tpkt_pdu(rdp, s);
1861 else if (rc == 0)
1862 return rdp_recv_fastpath_pdu(rdp, s);
1863 else
1864 return STATE_RUN_FAILED;
1865}
1866
1867static state_run_t rdp_handle_sc_flags(rdpRdp* rdp, wStream* s, UINT32 flag,
1868 CONNECTION_STATE nextState)
1869{
1870 const UINT32 mask = FINALIZE_SC_SYNCHRONIZE_PDU | FINALIZE_SC_CONTROL_COOPERATE_PDU |
1871 FINALIZE_SC_CONTROL_GRANTED_PDU | FINALIZE_SC_FONT_MAP_PDU;
1872 WINPR_ASSERT(rdp);
1873 state_run_t status = rdp_recv_pdu(rdp, s);
1874 if (state_run_success(status))
1875 {
1876 const UINT32 flags = rdp->finalize_sc_pdus & mask;
1877 if ((flags & flag) == flag)
1878 {
1879 if (!rdp_client_transition_to_state(rdp, nextState))
1880 status = STATE_RUN_FAILED;
1881 else
1882 status = STATE_RUN_SUCCESS;
1883 }
1884 else
1885 {
1886 char flag_buffer[256] = WINPR_C_ARRAY_INIT;
1887 char mask_buffer[256] = WINPR_C_ARRAY_INIT;
1888 WLog_Print(rdp->log, WLOG_WARN,
1889 "[%s] unexpected server message, expected flag %s [have %s]",
1890 rdp_get_state_string(rdp),
1891 rdp_finalize_flags_to_str(flag, flag_buffer, sizeof(flag_buffer)),
1892 rdp_finalize_flags_to_str(flags, mask_buffer, sizeof(mask_buffer)));
1893 }
1894 }
1895 return status;
1896}
1897
1898static state_run_t rdp_client_exchange_monitor_layout(rdpRdp* rdp, wStream* s)
1899{
1900 WINPR_ASSERT(rdp);
1901
1902 if (!rdp_check_monitor_layout_pdu_state(rdp, FALSE))
1903 return STATE_RUN_FAILED;
1904
1905 /* We might receive unrelated messages from the server (channel traffic),
1906 * so only proceed if some flag changed
1907 */
1908 const UINT32 old = rdp->finalize_sc_pdus;
1909 state_run_t status = rdp_recv_pdu(rdp, s);
1910 const UINT32 now = rdp->finalize_sc_pdus;
1911 const BOOL changed = (old != now) || rdp->monitor_layout_pdu;
1912
1913 /* This PDU is optional, so if we received a finalize PDU continue there */
1914 if (state_run_success(status) && changed)
1915 {
1916 if (!rdp->monitor_layout_pdu)
1917 {
1918 if (!rdp_finalize_is_flag_set(rdp, FINALIZE_SC_SYNCHRONIZE_PDU))
1919 return STATE_RUN_FAILED;
1920 }
1921
1922 status = rdp_client_connect_finalize(rdp);
1923 if (state_run_success(status) && !rdp->monitor_layout_pdu)
1924 status = STATE_RUN_TRY_AGAIN;
1925 }
1926 return status;
1927}
1928
1929static state_run_t rdp_recv_callback_int(WINPR_ATTR_UNUSED rdpTransport* transport, wStream* s,
1930 void* extra)
1931{
1932 state_run_t status = STATE_RUN_SUCCESS;
1933 rdpRdp* rdp = (rdpRdp*)extra;
1934
1935 WINPR_ASSERT(transport);
1936 WINPR_ASSERT(rdp);
1937 WINPR_ASSERT(s);
1938
1939 switch (rdp_get_state(rdp))
1940 {
1941 case CONNECTION_STATE_NEGO:
1942 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_CREATE_REQUEST))
1943 status = STATE_RUN_FAILED;
1944 else
1945 status = STATE_RUN_CONTINUE;
1946 break;
1947 case CONNECTION_STATE_NLA:
1948 if (nla_get_state(rdp->nla) < NLA_STATE_AUTH_INFO)
1949 {
1950 if (nla_recv_pdu(rdp->nla, s) < 1)
1951 {
1952 WLog_Print(rdp->log, WLOG_ERROR, "%s - nla_recv_pdu() fail",
1953 rdp_get_state_string(rdp));
1954 status = STATE_RUN_FAILED;
1955 }
1956 }
1957 else if (nla_get_state(rdp->nla) == NLA_STATE_POST_NEGO)
1958 {
1959 if (nego_recv(rdp->transport, s, (void*)rdp->nego) < 0)
1960 return STATE_RUN_FAILED;
1961
1962 if (!nego_update_settings_from_state(rdp->nego, rdp->settings))
1963 return STATE_RUN_FAILED;
1964
1965 if (nego_get_state(rdp->nego) != NEGO_STATE_FINAL)
1966 {
1967 WLog_Print(rdp->log, WLOG_ERROR, "%s - nego_recv() fail",
1968 rdp_get_state_string(rdp));
1969 status = STATE_RUN_FAILED;
1970 }
1971 else if (!nla_set_state(rdp->nla, NLA_STATE_FINAL))
1972 status = STATE_RUN_FAILED;
1973 }
1974
1975 if (state_run_success(status))
1976 {
1977 if (nla_get_state(rdp->nla) == NLA_STATE_AUTH_INFO)
1978 {
1979 transport_set_nla_mode(rdp->transport, FALSE);
1980
1981 if (rdp->settings->VmConnectMode)
1982 {
1983 if (!nego_set_state(rdp->nego, NEGO_STATE_NLA))
1984 status = STATE_RUN_FAILED;
1985 else if (!nego_set_requested_protocols(rdp->nego,
1986 PROTOCOL_HYBRID | PROTOCOL_SSL))
1987 status = STATE_RUN_FAILED;
1988 else if (!nego_send_negotiation_request(rdp->nego))
1989 status = STATE_RUN_FAILED;
1990 else if (!nla_set_state(rdp->nla, NLA_STATE_POST_NEGO))
1991 status = STATE_RUN_FAILED;
1992 }
1993 else
1994 {
1995 if (!nla_set_state(rdp->nla, NLA_STATE_FINAL))
1996 status = STATE_RUN_FAILED;
1997 }
1998 }
1999 }
2000 if (state_run_success(status))
2001 {
2002
2003 if (nla_get_state(rdp->nla) == NLA_STATE_FINAL)
2004 {
2005 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_CREATE_REQUEST))
2006 status = STATE_RUN_FAILED;
2007 else
2008 status = STATE_RUN_CONTINUE;
2009 }
2010 }
2011 break;
2012
2013 case CONNECTION_STATE_AAD:
2014 if (aad_recv(rdp->aad, s) < 1)
2015 {
2016 WLog_Print(rdp->log, WLOG_ERROR, "%s - aad_recv() fail", rdp_get_state_string(rdp));
2017 status = STATE_RUN_FAILED;
2018 }
2019 if (state_run_success(status))
2020 {
2021 if (aad_get_state(rdp->aad) == AAD_STATE_FINAL)
2022 {
2023 transport_set_aad_mode(rdp->transport, FALSE);
2024 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_CREATE_REQUEST))
2025 status = STATE_RUN_FAILED;
2026 else
2027 status = STATE_RUN_CONTINUE;
2028 }
2029 }
2030 break;
2031
2032 case CONNECTION_STATE_MCS_CREATE_REQUEST:
2033 if (!mcs_client_begin(rdp->mcs))
2034 {
2035 WLog_Print(rdp->log, WLOG_ERROR, "%s - mcs_client_begin() fail",
2036 rdp_get_state_string(rdp));
2037 status = STATE_RUN_FAILED;
2038 }
2039 else if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_CREATE_RESPONSE))
2040 status = STATE_RUN_FAILED;
2041 else if (Stream_GetRemainingLength(s) > 0)
2042 status = STATE_RUN_CONTINUE;
2043 break;
2044
2045 case CONNECTION_STATE_MCS_CREATE_RESPONSE:
2046 if (!mcs_recv_connect_response(rdp->mcs, s))
2047 {
2048 WLog_Print(rdp->log, WLOG_ERROR, "mcs_recv_connect_response failure");
2049 status = STATE_RUN_FAILED;
2050 }
2051 else
2052 {
2053 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_ERECT_DOMAIN))
2054 status = STATE_RUN_FAILED;
2055 else if (!mcs_send_erect_domain_request(rdp->mcs))
2056 {
2057 WLog_Print(rdp->log, WLOG_ERROR, "mcs_send_erect_domain_request failure");
2058 status = STATE_RUN_FAILED;
2059 }
2060 else if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_ATTACH_USER))
2061 status = STATE_RUN_FAILED;
2062 else if (!mcs_send_attach_user_request(rdp->mcs))
2063 {
2064 WLog_Print(rdp->log, WLOG_ERROR, "mcs_send_attach_user_request failure");
2065 status = STATE_RUN_FAILED;
2066 }
2067 else if (!rdp_client_transition_to_state(rdp,
2068 CONNECTION_STATE_MCS_ATTACH_USER_CONFIRM))
2069 status = STATE_RUN_FAILED;
2070 }
2071 break;
2072
2073 case CONNECTION_STATE_MCS_ATTACH_USER_CONFIRM:
2074 if (!mcs_recv_attach_user_confirm(rdp->mcs, s))
2075 {
2076 WLog_Print(rdp->log, WLOG_ERROR, "mcs_recv_attach_user_confirm failure");
2077 status = STATE_RUN_FAILED;
2078 }
2079 else if (!freerdp_settings_get_bool(rdp->settings, FreeRDP_SupportSkipChannelJoin))
2080 {
2081 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_MCS_CHANNEL_JOIN_REQUEST))
2082 status = STATE_RUN_FAILED;
2083 else if (!mcs_send_channel_join_request(rdp->mcs, rdp->mcs->userId))
2084 {
2085 WLog_Print(rdp->log, WLOG_ERROR, "mcs_send_channel_join_request failure");
2086 status = STATE_RUN_FAILED;
2087 }
2088 else if (!rdp_client_transition_to_state(
2089 rdp, CONNECTION_STATE_MCS_CHANNEL_JOIN_RESPONSE))
2090 status = STATE_RUN_FAILED;
2091 }
2092 else
2093 {
2094 /* SKIP_CHANNELJOIN is active, consider channels to be joined */
2095 if (!rdp_client_skip_mcs_channel_join(rdp))
2096 status = STATE_RUN_FAILED;
2097 }
2098 break;
2099
2100 case CONNECTION_STATE_MCS_CHANNEL_JOIN_RESPONSE:
2101 if (!rdp_client_connect_mcs_channel_join_confirm(rdp, s))
2102 {
2103 WLog_Print(rdp->log, WLOG_ERROR,
2104 "%s - "
2105 "rdp_client_connect_mcs_channel_join_confirm() fail",
2106 rdp_get_state_string(rdp));
2107 status = STATE_RUN_FAILED;
2108 }
2109
2110 break;
2111
2112 case CONNECTION_STATE_CONNECT_TIME_AUTO_DETECT_REQUEST:
2113 if (!rdp_client_connect_auto_detect(rdp, s, WLOG_DEBUG))
2114 {
2115 if (!rdp_client_transition_to_state(rdp, CONNECTION_STATE_LICENSING))
2116 status = STATE_RUN_FAILED;
2117 else
2118 status = STATE_RUN_TRY_AGAIN;
2119 }
2120 break;
2121
2122 case CONNECTION_STATE_LICENSING:
2123 status = rdp_client_connect_license(rdp, s);
2124
2125 if (state_run_failed(status))
2126 {
2127 char buffer[64] = WINPR_C_ARRAY_INIT;
2128 WLog_Print(rdp->log, WLOG_DEBUG, "%s - rdp_client_connect_license() - %s",
2129 rdp_get_state_string(rdp),
2130 state_run_result_string(status, buffer, ARRAYSIZE(buffer)));
2131 }
2132
2133 break;
2134
2135 case CONNECTION_STATE_MULTITRANSPORT_BOOTSTRAPPING_REQUEST:
2136 if (!rdp_client_connect_auto_detect(rdp, s, WLOG_DEBUG))
2137 {
2138 if (!rdp_client_transition_to_state(
2139 rdp, CONNECTION_STATE_CAPABILITIES_EXCHANGE_DEMAND_ACTIVE))
2140 status = STATE_RUN_FAILED;
2141 else
2142 status = STATE_RUN_TRY_AGAIN;
2143 }
2144 break;
2145
2146 case CONNECTION_STATE_CAPABILITIES_EXCHANGE_DEMAND_ACTIVE:
2147 status = rdp_client_connect_demand_active(rdp, s);
2148
2149 if (state_run_failed(status))
2150 {
2151 char buffer[64] = WINPR_C_ARRAY_INIT;
2152 WLog_Print(rdp->log, WLOG_DEBUG,
2153 "%s - "
2154 "rdp_client_connect_demand_active() - %s",
2155 rdp_get_state_string(rdp),
2156 state_run_result_string(status, buffer, ARRAYSIZE(buffer)));
2157 }
2158 else if (status == STATE_RUN_ACTIVE)
2159 {
2160 if (!rdp_client_transition_to_state(
2161 rdp, CONNECTION_STATE_CAPABILITIES_EXCHANGE_CONFIRM_ACTIVE))
2162 status = STATE_RUN_FAILED;
2163 else
2164 status = STATE_RUN_CONTINUE;
2165 }
2166 break;
2167
2168 case CONNECTION_STATE_CAPABILITIES_EXCHANGE_MONITOR_LAYOUT:
2169 status = rdp_client_exchange_monitor_layout(rdp, s);
2170 break;
2171
2172 case CONNECTION_STATE_CAPABILITIES_EXCHANGE_CONFIRM_ACTIVE:
2173 status = rdp_client_connect_confirm_active(rdp, s);
2174 break;
2175
2176 case CONNECTION_STATE_FINALIZATION_CLIENT_SYNC:
2177 status = rdp_handle_sc_flags(rdp, s, FINALIZE_SC_SYNCHRONIZE_PDU,
2178 CONNECTION_STATE_FINALIZATION_CLIENT_COOPERATE);
2179 break;
2180 case CONNECTION_STATE_FINALIZATION_CLIENT_COOPERATE:
2181 status = rdp_handle_sc_flags(rdp, s, FINALIZE_SC_CONTROL_COOPERATE_PDU,
2182 CONNECTION_STATE_FINALIZATION_CLIENT_GRANTED_CONTROL);
2183 break;
2184 case CONNECTION_STATE_FINALIZATION_CLIENT_GRANTED_CONTROL:
2185 status = rdp_handle_sc_flags(rdp, s, FINALIZE_SC_CONTROL_GRANTED_PDU,
2186 CONNECTION_STATE_FINALIZATION_CLIENT_FONT_MAP);
2187 break;
2188 case CONNECTION_STATE_FINALIZATION_CLIENT_FONT_MAP:
2189 status = rdp_handle_sc_flags(rdp, s, FINALIZE_SC_FONT_MAP_PDU, CONNECTION_STATE_ACTIVE);
2190 break;
2191
2192 case CONNECTION_STATE_ACTIVE:
2193 status = rdp_recv_pdu(rdp, s);
2194
2195 if (state_run_failed(status))
2196 {
2197 char buffer[64] = WINPR_C_ARRAY_INIT;
2198 WLog_Print(rdp->log, WLOG_DEBUG, "%s - rdp_recv_pdu() - %s",
2199 rdp_get_state_string(rdp),
2200 state_run_result_string(status, buffer, ARRAYSIZE(buffer)));
2201 }
2202 break;
2203
2204 default:
2205 WLog_Print(rdp->log, WLOG_ERROR, "%s state %u", rdp_get_state_string(rdp),
2206 rdp_get_state(rdp));
2207 status = STATE_RUN_FAILED;
2208 break;
2209 }
2210
2211 if (state_run_failed(status))
2212 {
2213 char buffer[64] = WINPR_C_ARRAY_INIT;
2214 WLog_Print(rdp->log, WLOG_ERROR, "%s status %s", rdp_get_state_string(rdp),
2215 state_run_result_string(status, buffer, ARRAYSIZE(buffer)));
2216 }
2217 return status;
2218}
2219
2220state_run_t rdp_recv_callback(rdpTransport* transport, wStream* s, void* extra)
2221{
2222 char buffer[64] = WINPR_C_ARRAY_INIT;
2223 state_run_t rc = STATE_RUN_FAILED;
2224 const size_t start = Stream_GetPosition(s);
2225 const rdpContext* context = transport_get_context(transport);
2226
2227 WINPR_ASSERT(context);
2228 do
2229 {
2230 const rdpRdp* rdp = context->rdp;
2231 WINPR_ASSERT(rdp);
2232
2233 if (rc == STATE_RUN_TRY_AGAIN)
2234 {
2235 if (!Stream_SetPosition(s, start))
2236 return STATE_RUN_FAILED;
2237 }
2238
2239 const char* old = rdp_get_state_string(rdp);
2240 const size_t orem = Stream_GetRemainingLength(s);
2241 rc = rdp_recv_callback_int(transport, s, extra);
2242
2243 const char* now = rdp_get_state_string(rdp);
2244 const size_t rem = Stream_GetRemainingLength(s);
2245
2246 WLog_Print(rdp->log, WLOG_TRACE,
2247 "(client)[%s -> %s] current return %s [feeding %" PRIuz " bytes, %" PRIuz
2248 " bytes not processed]",
2249 old, now, state_run_result_string(rc, buffer, sizeof(buffer)), orem, rem);
2250 } while ((rc == STATE_RUN_TRY_AGAIN) || (rc == STATE_RUN_CONTINUE));
2251 return rc;
2252}
2253
2254BOOL rdp_send_channel_data(rdpRdp* rdp, UINT16 channelId, const BYTE* data, size_t size)
2255{
2256 return freerdp_channel_send(rdp, channelId, data, size);
2257}
2258
2259BOOL rdp_channel_send_packet(rdpRdp* rdp, UINT16 channelId, size_t totalSize, UINT32 flags,
2260 const BYTE* data, size_t chunkSize)
2261{
2262 return freerdp_channel_send_packet(rdp, channelId, totalSize, flags, data, chunkSize);
2263}
2264
2265BOOL rdp_send_error_info(rdpRdp* rdp)
2266{
2267 UINT16 sec_flags = 0;
2268 wStream* s = nullptr;
2269 BOOL status = 0;
2270
2271 if (rdp->errorInfo == ERRINFO_SUCCESS)
2272 return TRUE;
2273
2274 s = rdp_data_pdu_init(rdp, &sec_flags);
2275
2276 if (!s)
2277 return FALSE;
2278
2279 Stream_Write_UINT32(s, rdp->errorInfo); /* error id (4 bytes) */
2280 status = rdp_send_data_pdu(rdp, s, DATA_PDU_TYPE_SET_ERROR_INFO, 0, sec_flags);
2281 return status;
2282}
2283
2284int rdp_check_fds(rdpRdp* rdp)
2285{
2286 int status = 0;
2287 rdpTsg* tsg = nullptr;
2288 rdpTransport* transport = nullptr;
2289
2290 WINPR_ASSERT(rdp);
2291 transport = rdp->transport;
2292
2293 tsg = transport_get_tsg(transport);
2294 if (tsg)
2295 {
2296 if (!tsg_check_event_handles(tsg))
2297 {
2298 WLog_Print(rdp->log, WLOG_ERROR, "rdp_check_fds: tsg_check_event_handles()");
2299 return -1;
2300 }
2301
2302 if (tsg_get_state(tsg) != TSG_STATE_PIPE_CREATED)
2303 return 1;
2304 }
2305
2306 status = transport_check_fds(transport);
2307
2308 if (status == 1)
2309 {
2310 if (!rdp_client_redirect(rdp)) /* session redirection */
2311 return -1;
2312 }
2313
2314 if (status < 0)
2315 WLog_Print(rdp->log, WLOG_DEBUG, "transport_check_fds() - %i", status);
2316 else
2317 status = freerdp_timer_poll(rdp->timer);
2318
2319 return status;
2320}
2321
2322BOOL freerdp_get_stats(const rdpRdp* rdp, UINT64* inBytes, UINT64* outBytes, UINT64* inPackets,
2323 UINT64* outPackets)
2324{
2325 if (!rdp)
2326 return FALSE;
2327
2328 if (inBytes)
2329 *inBytes = rdp->inBytes;
2330 if (outBytes)
2331 *outBytes = rdp->outBytes;
2332 if (inPackets)
2333 *inPackets = rdp->inPackets;
2334 if (outPackets)
2335 *outPackets = rdp->outPackets;
2336
2337 return TRUE;
2338}
2339
2340static bool rdp_new_common(rdpRdp* rdp)
2341{
2342 WINPR_ASSERT(rdp);
2343
2344 bool rc = false;
2345 rdp->transport = transport_new(rdp->context);
2346 if (!rdp->transport)
2347 goto fail;
2348
2349 if (rdp->io)
2350 {
2351 if (!transport_set_io_callbacks(rdp->transport, rdp->io))
2352 goto fail;
2353 }
2354
2355 rdp->aad = aad_new(rdp->context);
2356 if (!rdp->aad)
2357 goto fail;
2358
2359 rdp->nego = nego_new(rdp->transport);
2360 if (!rdp->nego)
2361 goto fail;
2362
2363 rdp->mcs = mcs_new(rdp->context);
2364 if (!rdp->mcs)
2365 goto fail;
2366
2367 rdp->license = license_new(rdp);
2368 if (!rdp->license)
2369 goto fail;
2370
2371 rdp->fastpath = fastpath_new(rdp);
2372 if (!rdp->fastpath)
2373 goto fail;
2374
2375 rc = true;
2376fail:
2377 return rc;
2378}
2379
2385rdpRdp* rdp_new(rdpContext* context)
2386{
2387 DWORD flags = 0;
2388 rdpRdp* rdp = (rdpRdp*)calloc(1, sizeof(rdpRdp));
2389
2390 if (!rdp)
2391 return nullptr;
2392
2393 rdp->log = WLog_Create(RDP_TAG, WLog_GetRoot());
2394 if (!rdp->log)
2395 goto fail;
2396
2397 (void)_snprintf(rdp->log_context, sizeof(rdp->log_context), "%p", (void*)context);
2398 if (!WLog_SetContext(rdp->log, nullptr, rdp->log_context))
2399 goto fail;
2400
2401 InitializeCriticalSection(&rdp->critical);
2402 rdp->context = context;
2403 WINPR_ASSERT(rdp->context);
2404
2405 if (context->ServerMode)
2407
2408 if (!context->settings)
2409 {
2410 context->settings = rdp->settings = freerdp_settings_new(flags);
2411
2412 if (!rdp->settings)
2413 goto fail;
2414 }
2415 else
2416 rdp->settings = context->settings;
2417
2418 /* Keep a backup copy of settings for later comparisons */
2419 if (!rdp_set_backup_settings(rdp))
2420 goto fail;
2421
2422 rdp->settings->instance = context->instance;
2423
2424 context->settings = rdp->settings;
2425 if (context->instance)
2426 context->settings->instance = context->instance;
2427 else if (context->peer)
2428 {
2429 rdp->settings->instance = context->peer;
2430
2431#if defined(WITH_FREERDP_DEPRECATED)
2432 context->peer->settings = rdp->settings;
2433#endif
2434 }
2435
2436 if (!rdp_new_common(rdp))
2437 goto fail;
2438
2439 {
2440 const rdpTransportIo* io = transport_get_io_callbacks(rdp->transport);
2441 if (!io)
2442 goto fail;
2443 rdp->io = calloc(1, sizeof(rdpTransportIo));
2444 if (!rdp->io)
2445 goto fail;
2446 *rdp->io = *io;
2447 }
2448
2449 rdp->input = input_new(rdp);
2450
2451 if (!rdp->input)
2452 goto fail;
2453
2454 rdp->update = update_new(rdp);
2455
2456 if (!rdp->update)
2457 goto fail;
2458
2459 rdp->redirection = redirection_new();
2460
2461 if (!rdp->redirection)
2462 goto fail;
2463
2464 rdp->autodetect = autodetect_new(rdp->context);
2465
2466 if (!rdp->autodetect)
2467 goto fail;
2468
2469 rdp->heartbeat = heartbeat_new();
2470
2471 if (!rdp->heartbeat)
2472 goto fail;
2473
2474 rdp->multitransport = multitransport_new(rdp, INITIATE_REQUEST_PROTOCOL_UDPFECL |
2475 INITIATE_REQUEST_PROTOCOL_UDPFECR);
2476
2477 if (!rdp->multitransport)
2478 goto fail;
2479
2480 rdp->bulk = bulk_new(context);
2481
2482 if (!rdp->bulk)
2483 goto fail;
2484
2485 rdp->pubSub = PubSub_New(TRUE);
2486 if (!rdp->pubSub)
2487 goto fail;
2488
2489 rdp->abortEvent = CreateEvent(nullptr, TRUE, FALSE, nullptr);
2490 if (!rdp->abortEvent)
2491 goto fail;
2492
2493 rdp->timer = freerdp_timer_new(rdp);
2494 if (!rdp->timer)
2495 goto fail;
2496
2497 return rdp;
2498
2499fail:
2500 WINPR_PRAGMA_DIAG_PUSH
2501 WINPR_PRAGMA_DIAG_IGNORED_MISMATCHED_DEALLOC
2502 rdp_free(rdp);
2503 WINPR_PRAGMA_DIAG_POP
2504 return nullptr;
2505}
2506
2507static void rdp_reset_free(rdpRdp* rdp)
2508{
2509 WINPR_ASSERT(rdp);
2510
2511 security_lock(rdp);
2512 rdp_free_rc4_decrypt_keys(rdp);
2513 rdp_free_rc4_encrypt_keys(rdp);
2514
2515 winpr_Cipher_Free(rdp->fips_encrypt);
2516 winpr_Cipher_Free(rdp->fips_decrypt);
2517 rdp->fips_encrypt = nullptr;
2518 rdp->fips_decrypt = nullptr;
2519 security_unlock(rdp);
2520
2521 aad_free(rdp->aad);
2522 mcs_free(rdp->mcs);
2523 nego_free(rdp->nego);
2524 license_free(rdp->license);
2525 transport_free(rdp->transport);
2526 fastpath_free(rdp->fastpath);
2527
2528 rdp->aad = nullptr;
2529 rdp->mcs = nullptr;
2530 rdp->nego = nullptr;
2531 rdp->license = nullptr;
2532 rdp->transport = nullptr;
2533 rdp->fastpath = nullptr;
2534}
2535
2536BOOL rdp_reset(rdpRdp* rdp)
2537{
2538 BOOL rc = TRUE;
2539
2540 WINPR_ASSERT(rdp);
2541
2542 rdpSettings* settings = rdp->settings;
2543 WINPR_ASSERT(settings);
2544
2545 bulk_reset(rdp->bulk);
2546
2547 rdp_reset_free(rdp);
2548
2549 if (!freerdp_settings_set_pointer_len(settings, FreeRDP_ServerRandom, nullptr, 0))
2550 rc = FALSE;
2551
2552 if (!freerdp_settings_set_pointer_len(settings, FreeRDP_ServerCertificate, nullptr, 0))
2553 rc = FALSE;
2554
2555 if (!freerdp_settings_set_string(settings, FreeRDP_ClientAddress, nullptr))
2556 rc = FALSE;
2557
2558 if (!rc)
2559 goto fail;
2560
2561 rc = rdp_new_common(rdp);
2562 if (!rc)
2563 goto fail;
2564
2565 if (!transport_set_layer(rdp->transport, TRANSPORT_LAYER_TCP))
2566 goto fail;
2567
2568 rdp->errorInfo = 0;
2569 rc = rdp_finalize_reset_flags(rdp, TRUE);
2570
2571fail:
2572 return rc;
2573}
2574
2580void rdp_free(rdpRdp* rdp)
2581{
2582 if (rdp)
2583 {
2584 freerdp_timer_free(rdp->timer);
2585 rdp_reset_free(rdp);
2586
2587 freerdp_settings_free(rdp->settings);
2588 freerdp_settings_free(rdp->originalSettings);
2589 freerdp_settings_free(rdp->remoteSettings);
2590
2591 input_free(rdp->input);
2592 update_free(rdp->update);
2593 nla_free(rdp->nla);
2594 redirection_free(rdp->redirection);
2595 autodetect_free(rdp->autodetect);
2596 heartbeat_free(rdp->heartbeat);
2597 multitransport_free(rdp->multitransport);
2598 bulk_free(rdp->bulk);
2599 free(rdp->io);
2600 PubSub_Free(rdp->pubSub);
2601 if (rdp->abortEvent)
2602 (void)CloseHandle(rdp->abortEvent);
2603 aad_free(rdp->aad);
2604 WINPR_JSON_Delete(rdp->wellknown);
2605 DeleteCriticalSection(&rdp->critical);
2606 WLog_Discard(rdp->log);
2607 free(rdp);
2608 }
2609}
2610
2611BOOL rdp_io_callback_set_event(rdpRdp* rdp, BOOL set)
2612{
2613 if (!rdp)
2614 return FALSE;
2615 return transport_io_callback_set_event(rdp->transport, set);
2616}
2617
2618const rdpTransportIo* rdp_get_io_callbacks(rdpRdp* rdp)
2619{
2620 if (!rdp)
2621 return nullptr;
2622 return rdp->io;
2623}
2624
2625BOOL rdp_set_io_callbacks(rdpRdp* rdp, const rdpTransportIo* io_callbacks)
2626{
2627 if (!rdp)
2628 return FALSE;
2629 free(rdp->io);
2630 rdp->io = nullptr;
2631 if (io_callbacks)
2632 {
2633 rdp->io = malloc(sizeof(rdpTransportIo));
2634 if (!rdp->io)
2635 return FALSE;
2636 *rdp->io = *io_callbacks;
2637 return transport_set_io_callbacks(rdp->transport, rdp->io);
2638 }
2639 return TRUE;
2640}
2641
2642BOOL rdp_set_io_callback_context(rdpRdp* rdp, void* usercontext)
2643{
2644 WINPR_ASSERT(rdp);
2645 rdp->ioContext = usercontext;
2646 return TRUE;
2647}
2648
2649void* rdp_get_io_callback_context(rdpRdp* rdp)
2650{
2651 WINPR_ASSERT(rdp);
2652 return rdp->ioContext;
2653}
2654
2655const char* rdp_finalize_flags_to_str(UINT32 flags, char* buffer, size_t size)
2656{
2657 char number[32] = WINPR_C_ARRAY_INIT;
2658 const UINT32 mask =
2659 (uint32_t)~(FINALIZE_SC_SYNCHRONIZE_PDU | FINALIZE_SC_CONTROL_COOPERATE_PDU |
2660 FINALIZE_SC_CONTROL_GRANTED_PDU | FINALIZE_SC_FONT_MAP_PDU |
2661 FINALIZE_CS_SYNCHRONIZE_PDU | FINALIZE_CS_CONTROL_COOPERATE_PDU |
2662 FINALIZE_CS_CONTROL_REQUEST_PDU | FINALIZE_CS_PERSISTENT_KEY_LIST_PDU |
2663 FINALIZE_CS_FONT_LIST_PDU | FINALIZE_DEACTIVATE_REACTIVATE);
2664
2665 if (flags & FINALIZE_SC_SYNCHRONIZE_PDU)
2666 winpr_str_append("FINALIZE_SC_SYNCHRONIZE_PDU", buffer, size, "|");
2667 if (flags & FINALIZE_SC_CONTROL_COOPERATE_PDU)
2668 winpr_str_append("FINALIZE_SC_CONTROL_COOPERATE_PDU", buffer, size, "|");
2669 if (flags & FINALIZE_SC_CONTROL_GRANTED_PDU)
2670 winpr_str_append("FINALIZE_SC_CONTROL_GRANTED_PDU", buffer, size, "|");
2671 if (flags & FINALIZE_SC_FONT_MAP_PDU)
2672 winpr_str_append("FINALIZE_SC_FONT_MAP_PDU", buffer, size, "|");
2673 if (flags & FINALIZE_CS_SYNCHRONIZE_PDU)
2674 winpr_str_append("FINALIZE_CS_SYNCHRONIZE_PDU", buffer, size, "|");
2675 if (flags & FINALIZE_CS_CONTROL_COOPERATE_PDU)
2676 winpr_str_append("FINALIZE_CS_CONTROL_COOPERATE_PDU", buffer, size, "|");
2677 if (flags & FINALIZE_CS_CONTROL_REQUEST_PDU)
2678 winpr_str_append("FINALIZE_CS_CONTROL_REQUEST_PDU", buffer, size, "|");
2679 if (flags & FINALIZE_CS_PERSISTENT_KEY_LIST_PDU)
2680 winpr_str_append("FINALIZE_CS_PERSISTENT_KEY_LIST_PDU", buffer, size, "|");
2681 if (flags & FINALIZE_CS_FONT_LIST_PDU)
2682 winpr_str_append("FINALIZE_CS_FONT_LIST_PDU", buffer, size, "|");
2683 if (flags & FINALIZE_DEACTIVATE_REACTIVATE)
2684 winpr_str_append("FINALIZE_DEACTIVATE_REACTIVATE", buffer, size, "|");
2685 if (flags & mask)
2686 winpr_str_append("UNKNOWN_FLAG", buffer, size, "|");
2687 if (flags == 0)
2688 winpr_str_append("NO_FLAG_SET", buffer, size, "|");
2689 (void)_snprintf(number, sizeof(number), " [0x%08" PRIx32 "]", flags);
2690 winpr_str_append(number, buffer, size, "");
2691 return buffer;
2692}
2693
2694BOOL rdp_finalize_reset_flags(rdpRdp* rdp, BOOL clearAll)
2695{
2696 WINPR_ASSERT(rdp);
2697 WLog_Print(rdp->log, WLOG_DEBUG, "[%s] reset finalize_sc_pdus", rdp_get_state_string(rdp));
2698 if (clearAll)
2699 rdp->finalize_sc_pdus = 0;
2700 else
2701 rdp->finalize_sc_pdus &= FINALIZE_DEACTIVATE_REACTIVATE;
2702
2703 return rdp_set_monitor_layout_pdu_state(rdp, FALSE);
2704}
2705
2706BOOL rdp_finalize_set_flag(rdpRdp* rdp, UINT32 flag)
2707{
2708 char buffer[1024] = WINPR_C_ARRAY_INIT;
2709
2710 WINPR_ASSERT(rdp);
2711
2712 WLog_Print(rdp->log, WLOG_DEBUG, "[%s] received flag %s", rdp_get_state_string(rdp),
2713 rdp_finalize_flags_to_str(flag, buffer, sizeof(buffer)));
2714 rdp->finalize_sc_pdus |= flag;
2715 return TRUE;
2716}
2717
2718BOOL rdp_finalize_is_flag_set(rdpRdp* rdp, UINT32 flag)
2719{
2720 WINPR_ASSERT(rdp);
2721 return (rdp->finalize_sc_pdus & flag) == flag;
2722}
2723
2724BOOL rdp_reset_rc4_encrypt_keys(rdpRdp* rdp)
2725{
2726 WINPR_ASSERT(rdp);
2727 rdp_free_rc4_encrypt_keys(rdp);
2728 rdp->rc4_encrypt_key = winpr_RC4_New(rdp->encrypt_key, rdp->rc4_key_len);
2729
2730 rdp->encrypt_use_count = 0;
2731 return rdp->rc4_encrypt_key != nullptr;
2732}
2733
2734void rdp_free_rc4_encrypt_keys(rdpRdp* rdp)
2735{
2736 WINPR_ASSERT(rdp);
2737 winpr_RC4_Free(rdp->rc4_encrypt_key);
2738 rdp->rc4_encrypt_key = nullptr;
2739}
2740
2741void rdp_free_rc4_decrypt_keys(rdpRdp* rdp)
2742{
2743 WINPR_ASSERT(rdp);
2744 winpr_RC4_Free(rdp->rc4_decrypt_key);
2745 rdp->rc4_decrypt_key = nullptr;
2746}
2747
2748BOOL rdp_reset_rc4_decrypt_keys(rdpRdp* rdp)
2749{
2750 WINPR_ASSERT(rdp);
2751 rdp_free_rc4_decrypt_keys(rdp);
2752 rdp->rc4_decrypt_key = winpr_RC4_New(rdp->decrypt_key, rdp->rc4_key_len);
2753
2754 rdp->decrypt_use_count = 0;
2755 return rdp->rc4_decrypt_key != nullptr;
2756}
2757
2758const char* rdp_security_flag_string(UINT32 securityFlags, char* buffer, size_t size)
2759{
2760 if (securityFlags & SEC_EXCHANGE_PKT)
2761 winpr_str_append("SEC_EXCHANGE_PKT", buffer, size, "|");
2762 if (securityFlags & SEC_TRANSPORT_REQ)
2763 winpr_str_append("SEC_TRANSPORT_REQ", buffer, size, "|");
2764 if (securityFlags & SEC_TRANSPORT_RSP)
2765 winpr_str_append("SEC_TRANSPORT_RSP", buffer, size, "|");
2766 if (securityFlags & SEC_ENCRYPT)
2767 winpr_str_append("SEC_ENCRYPT", buffer, size, "|");
2768 if (securityFlags & SEC_RESET_SEQNO)
2769 winpr_str_append("SEC_RESET_SEQNO", buffer, size, "|");
2770 if (securityFlags & SEC_IGNORE_SEQNO)
2771 winpr_str_append("SEC_IGNORE_SEQNO", buffer, size, "|");
2772 if (securityFlags & SEC_INFO_PKT)
2773 winpr_str_append("SEC_INFO_PKT", buffer, size, "|");
2774 if (securityFlags & SEC_LICENSE_PKT)
2775 winpr_str_append("SEC_LICENSE_PKT", buffer, size, "|");
2776 if (securityFlags & SEC_LICENSE_ENCRYPT_CS)
2777 winpr_str_append("SEC_LICENSE_ENCRYPT_CS", buffer, size, "|");
2778 if (securityFlags & SEC_LICENSE_ENCRYPT_SC)
2779 winpr_str_append("SEC_LICENSE_ENCRYPT_SC", buffer, size, "|");
2780 if (securityFlags & SEC_REDIRECTION_PKT)
2781 winpr_str_append("SEC_REDIRECTION_PKT", buffer, size, "|");
2782 if (securityFlags & SEC_SECURE_CHECKSUM)
2783 winpr_str_append("SEC_SECURE_CHECKSUM", buffer, size, "|");
2784 if (securityFlags & SEC_AUTODETECT_REQ)
2785 winpr_str_append("SEC_AUTODETECT_REQ", buffer, size, "|");
2786 if (securityFlags & SEC_AUTODETECT_RSP)
2787 winpr_str_append("SEC_AUTODETECT_RSP", buffer, size, "|");
2788 if (securityFlags & SEC_HEARTBEAT)
2789 winpr_str_append("SEC_HEARTBEAT", buffer, size, "|");
2790 if (securityFlags & SEC_FLAGSHI_VALID)
2791 winpr_str_append("SEC_FLAGSHI_VALID", buffer, size, "|");
2792 {
2793 char msg[32] = WINPR_C_ARRAY_INIT;
2794
2795 (void)_snprintf(msg, sizeof(msg), "[0x%08" PRIx32 "]", securityFlags);
2796 winpr_str_append(msg, buffer, size, "");
2797 }
2798 return buffer;
2799}
2800
2801static BOOL rdp_reset_remote_settings(rdpRdp* rdp)
2802{
2803 UINT32 flags = FREERDP_SETTINGS_REMOTE_MODE;
2804 WINPR_ASSERT(rdp);
2805 freerdp_settings_free(rdp->remoteSettings);
2806
2807 if (!freerdp_settings_get_bool(rdp->settings, FreeRDP_ServerMode))
2809 rdp->remoteSettings = freerdp_settings_new(flags);
2810 return rdp->remoteSettings != nullptr;
2811}
2812
2813BOOL rdp_set_backup_settings(rdpRdp* rdp)
2814{
2815 WINPR_ASSERT(rdp);
2816 freerdp_settings_free(rdp->originalSettings);
2817 rdp->originalSettings = freerdp_settings_clone(rdp->settings);
2818 if (!rdp->originalSettings)
2819 return FALSE;
2820 return rdp_reset_remote_settings(rdp);
2821}
2822
2823BOOL rdp_reset_runtime_settings(rdpRdp* rdp)
2824{
2825 WINPR_ASSERT(rdp);
2826 WINPR_ASSERT(rdp->context);
2827
2828 freerdp_settings_free(rdp->settings);
2829 rdp->context->settings = rdp->settings = freerdp_settings_clone(rdp->originalSettings);
2830
2831 if (!rdp->settings)
2832 return FALSE;
2833 return rdp_reset_remote_settings(rdp);
2834}
2835
2836static BOOL starts_with(const char* tok, const char* val)
2837{
2838 const size_t len = strlen(val);
2839 if (strncmp(tok, val, len) != 0)
2840 return FALSE;
2841 if (tok[len] != '=')
2842 return FALSE;
2843 return TRUE;
2844}
2845
2846static BOOL option_equals(const char* what, const char* val)
2847{
2848 return _stricmp(what, val) == 0;
2849}
2850
2851static BOOL parse_on_off_option(const char* value)
2852{
2853 WINPR_ASSERT(value);
2854 const char* sep = strchr(value, '=');
2855 if (!sep)
2856 return TRUE;
2857 if (option_equals("on", &sep[1]))
2858 return TRUE;
2859 if (option_equals("true", &sep[1]))
2860 return TRUE;
2861 if (option_equals("off", &sep[1]))
2862 return FALSE;
2863 if (option_equals("false", &sep[1]))
2864 return FALSE;
2865
2866 errno = 0;
2867 long val = strtol(value, nullptr, 0);
2868 if (errno == 0)
2869 return (val != 0);
2870
2871 return FALSE;
2872}
2873
2874#define STR(x) #x
2875
2876static BOOL option_is_runtime_checks(WINPR_ATTR_UNUSED wLog* log, const char* tok)
2877{
2878 const char* experimental[] = { STR(WITH_VERBOSE_WINPR_ASSERT) };
2879 for (size_t x = 0; x < ARRAYSIZE(experimental); x++)
2880 {
2881 const char* opt = experimental[x];
2882 if (starts_with(tok, opt))
2883 {
2884 return parse_on_off_option(tok);
2885 }
2886 }
2887 return FALSE;
2888}
2889
2890static BOOL option_is_experimental(WINPR_ATTR_UNUSED wLog* log, const char* tok)
2891{
2892 const char* experimental[] = { STR(WITH_DSP_EXPERIMENTAL), STR(WITH_VAAPI),
2893 STR(WITH_GFX_AV1), STR(WITH_VAAPI_H264_ENCODING),
2894 STR(WITH_MEDIACODEC), STR(WITH_CLIENT_SDL2),
2895 STR(WITH_OPENCL), STR(WITH_LIBRESSL),
2896 STR(WITH_MBEDTLS), STR(WITH_MEDIA_FOUNDATION),
2897 STR(WITH_KRB5_HEIMDAL), STR(WITH_VIDEOTOOLBOX) };
2898 for (size_t x = 0; x < ARRAYSIZE(experimental); x++)
2899 {
2900 const char* opt = experimental[x];
2901 if (starts_with(tok, opt))
2902 {
2903 return parse_on_off_option(tok);
2904 }
2905 }
2906 return FALSE;
2907}
2908
2909static BOOL option_is_debug(wLog* log, const char* tok)
2910{
2911 WINPR_ASSERT(log);
2912 const char* debug[] = { STR(WITH_DEBUG_ALL),
2913 STR(WITH_DEBUG_CERTIFICATE),
2914 STR(WITH_DEBUG_CAPABILITIES),
2915 STR(WITH_DEBUG_CHANNELS),
2916 STR(WITH_DEBUG_CLIPRDR),
2917 STR(WITH_DEBUG_CODECS),
2918 STR(WITH_DEBUG_DVC),
2919 STR(WITH_DEBUG_TSMF),
2920 STR(WITH_DEBUG_KBD),
2921 STR(WITH_DEBUG_LICENSE),
2922 STR(WITH_DEBUG_NEGO),
2923 STR(WITH_DEBUG_NLA),
2924 STR(WITH_DEBUG_TSG),
2925 STR(WITH_DEBUG_RAIL),
2926 STR(WITH_DEBUG_RDP),
2927 STR(WITH_DEBUG_RDPEI),
2928 STR(WITH_DEBUG_REDIR),
2929 STR(WITH_DEBUG_RDPDR),
2930 STR(WITH_DEBUG_RFX),
2931 STR(WITH_DEBUG_SCARD),
2932 STR(WITH_DEBUG_SND),
2933 STR(WITH_DEBUG_SVC),
2934 STR(WITH_DEBUG_TRANSPORT),
2935 STR(WITH_DEBUG_TIMEZONE),
2936 STR(WITH_DEBUG_WND),
2937 STR(WITH_DEBUG_RINGBUFFER),
2938 STR(WITH_DEBUG_SYMBOLS),
2939 STR(WITH_DEBUG_EVENTS),
2940 STR(WITH_DEBUG_MUTEX),
2941 STR(WITH_DEBUG_NTLM),
2942 STR(WITH_DEBUG_SDL_KBD_EVENTS),
2943 STR(WITH_DEBUG_SDL_KBD_EVENTS),
2944 STR(WITH_DEBUG_THREADS),
2945 STR(WITH_DEBUG_URBDRC) };
2946
2947 for (size_t x = 0; x < ARRAYSIZE(debug); x++)
2948 {
2949 const char* opt = debug[x];
2950 if (starts_with(tok, opt))
2951 return parse_on_off_option(tok);
2952 }
2953
2954 if (starts_with(tok, "WITH_DEBUG"))
2955 {
2956 WLog_Print(log, WLOG_WARN, "[BUG] Unmapped Debug-Build option '%s'.", tok);
2957 return parse_on_off_option(tok);
2958 }
2959
2960 return FALSE;
2961}
2962
2963static void log_build_warn(rdpRdp* rdp, const char* what, const char* msg,
2964 BOOL (*cmp)(wLog* log, const char* tok))
2965{
2966 WINPR_ASSERT(rdp);
2967 WINPR_PRAGMA_DIAG_PUSH
2968 WINPR_PRAGMA_DIAG_IGNORED_OVERLENGTH_STRINGS
2969
2970 size_t len = sizeof(FREERDP_BUILD_CONFIG);
2971 char* list = calloc(len, sizeof(char));
2972 char* config = _strdup(FREERDP_BUILD_CONFIG);
2973 WINPR_PRAGMA_DIAG_POP
2974
2975 if (config && list)
2976 {
2977 char* saveptr = nullptr;
2978 char* tok = strtok_s(config, " ", &saveptr);
2979 while (tok)
2980 {
2981 if (cmp(rdp->log, tok))
2982 winpr_str_append(tok, list, len, " ");
2983
2984 tok = strtok_s(nullptr, " ", &saveptr);
2985 }
2986 }
2987 free(config);
2988
2989 if (list)
2990 {
2991 if (strlen(list) > 0)
2992 {
2993 WLog_Print(rdp->log, WLOG_WARN, "*************************************************");
2994 WLog_Print(rdp->log, WLOG_WARN, "This build is using [%s] build options:", what);
2995
2996 char* saveptr = nullptr;
2997 char* tok = strtok_s(list, " ", &saveptr);
2998 while (tok)
2999 {
3000 WLog_Print(rdp->log, WLOG_WARN, "* '%s'", tok);
3001 tok = strtok_s(nullptr, " ", &saveptr);
3002 }
3003 WLog_Print(rdp->log, WLOG_WARN, "*");
3004 WLog_Print(rdp->log, WLOG_WARN, "[%s] build options %s", what, msg);
3005 WLog_Print(rdp->log, WLOG_WARN, "*************************************************");
3006 }
3007 }
3008 free(list);
3009}
3010
3011#define print_first_line(log, firstLine, what) \
3012 print_first_line_int((log), (firstLine), (what), __FILE__, __func__, __LINE__)
3013static void print_first_line_int(wLog* log, log_line_t* firstLine, const char* what,
3014 const char* file, const char* fkt, size_t line)
3015{
3016 WINPR_ASSERT(firstLine);
3017 if (!firstLine->fkt)
3018 {
3019 const DWORD level = WLOG_WARN;
3020 if (WLog_IsLevelActive(log, level))
3021 {
3022 WLog_PrintTextMessage(log, level, line, file, fkt,
3023 "*************************************************");
3024 WLog_PrintTextMessage(log, level, line, file, fkt,
3025 "[SSL] {%s} build or configuration missing:", what);
3026 }
3027 firstLine->line = line;
3028 firstLine->file = file;
3029 firstLine->fkt = fkt;
3030 firstLine->level = level;
3031 }
3032}
3033
3034static void print_last_line(wLog* log, const log_line_t* firstLine)
3035{
3036 WINPR_ASSERT(firstLine);
3037 if (firstLine->fkt)
3038 {
3039 if (WLog_IsLevelActive(log, firstLine->level))
3040 WLog_PrintTextMessage(log, firstLine->level, firstLine->line, firstLine->file,
3041 firstLine->fkt,
3042 "*************************************************");
3043 }
3044}
3045
3046static void log_build_warn_cipher(rdpRdp* rdp, log_line_t* firstLine, WINPR_CIPHER_TYPE md,
3047 const char* what, BOOL allowFIPS)
3048{
3049 BOOL haveCipher = FALSE;
3050
3051 char key[WINPR_CIPHER_MAX_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
3052 char iv[WINPR_CIPHER_MAX_IV_LENGTH] = WINPR_C_ARRAY_INIT;
3053
3054 /* RC4 only exists in the compatibility functions winpr_RC4_*
3055 * winpr_Cipher_* does not support that. */
3056 if (md == WINPR_CIPHER_ARC4_128)
3057 {
3058 WINPR_RC4_CTX* enc = nullptr;
3059 if (allowFIPS)
3060 enc = winpr_RC4_New_Allow_FIPS(key, sizeof(key));
3061 else
3062 enc = winpr_RC4_New(key, sizeof(key));
3063 haveCipher = enc != nullptr;
3064 winpr_RC4_Free(enc);
3065 }
3066 else
3067 {
3068 WINPR_CIPHER_CTX* enc =
3069 winpr_Cipher_NewEx(md, WINPR_ENCRYPT, key, sizeof(key), iv, sizeof(iv));
3070 WINPR_CIPHER_CTX* dec =
3071 winpr_Cipher_NewEx(md, WINPR_DECRYPT, key, sizeof(key), iv, sizeof(iv));
3072 if (enc && dec)
3073 haveCipher = TRUE;
3074
3075 winpr_Cipher_Free(enc);
3076 winpr_Cipher_Free(dec);
3077 }
3078
3079 if (!haveCipher)
3080 {
3081 print_first_line(rdp->log, firstLine, "Cipher");
3082 WLog_Print(rdp->log, WLOG_WARN, "* %s: %s", winpr_cipher_type_to_string(md), what);
3083 }
3084}
3085
3086static void log_build_warn_hmac(rdpRdp* rdp, log_line_t* firstLine, WINPR_MD_TYPE md,
3087 const char* what)
3088{
3089 BOOL haveHmacX = FALSE;
3090 WINPR_HMAC_CTX* hmac = winpr_HMAC_New();
3091 if (hmac)
3092 {
3093 /* We need some key length, but there is no real limit here.
3094 * just take the cipher maximum key length as we already have that available.
3095 */
3096 char key[WINPR_CIPHER_MAX_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
3097 haveHmacX = winpr_HMAC_Init(hmac, md, key, sizeof(key));
3098 }
3099 winpr_HMAC_Free(hmac);
3100
3101 if (!haveHmacX)
3102 {
3103 print_first_line(rdp->log, firstLine, "HMAC");
3104 WLog_Print(rdp->log, WLOG_WARN, " * %s: %s", winpr_md_type_to_string(md), what);
3105 }
3106}
3107
3108static void log_build_warn_hash(rdpRdp* rdp, log_line_t* firstLine, WINPR_MD_TYPE md,
3109 const char* what, BOOL allowFIPS)
3110{
3111 BOOL haveDigestX = FALSE;
3112 WINPR_DIGEST_CTX* digest = winpr_Digest_New();
3113 if (digest)
3114 {
3115 if (allowFIPS)
3116 haveDigestX = winpr_Digest_Init_Allow_FIPS(digest, md);
3117 else
3118 haveDigestX = winpr_Digest_Init(digest, md);
3119 }
3120 winpr_Digest_Free(digest);
3121
3122 if (!haveDigestX)
3123 {
3124 print_first_line(rdp->log, firstLine, "Digest");
3125 WLog_Print(rdp->log, WLOG_WARN, " * %s: %s", winpr_md_type_to_string(md), what);
3126 }
3127}
3128
3129static void log_build_warn_ssl(rdpRdp* rdp)
3130{
3131 WINPR_ASSERT(rdp);
3132
3133 const BOOL fips = winpr_FIPSMode();
3134
3135 if (fips)
3136 {
3137 WLog_Print(rdp->log, WLOG_INFO,
3138 "FIPS mode active: non-approved algorithms are unavailable "
3139 "as expected. NTLM, autoreconnect cookies, assistance files "
3140 "with encrypted passwords and RDP security will not work.");
3141 }
3142
3143 log_line_t firstHashLine = WINPR_C_ARRAY_INIT;
3144 if (!fips)
3145 {
3146 log_build_warn_hash(rdp, &firstHashLine, WINPR_MD_MD4, "NTLM support not available", FALSE);
3147 log_build_warn_hash(rdp, &firstHashLine, WINPR_MD_MD5,
3148 "NTLM, assistance files with encrypted passwords "
3149 " and autoreconnect cookies will not work",
3150 FALSE);
3151 }
3152 log_build_warn_hash(rdp, &firstHashLine, WINPR_MD_MD5,
3153 "RDP licensing and RDP security will not work", TRUE);
3154 log_build_warn_hash(rdp, &firstHashLine, WINPR_MD_SHA1,
3155 "assistance files with encrypted passwords, Kerberos, Smartcard Logon, RDP "
3156 "security support not available",
3157 FALSE);
3158 log_build_warn_hash(rdp, &firstHashLine, WINPR_MD_SHA256,
3159 "file clipboard, AAD gateway, NLA security and certificates might not work",
3160 FALSE);
3161 print_last_line(rdp->log, &firstHashLine);
3162
3163 if (!fips)
3164 {
3165 log_line_t firstHmacLine = WINPR_C_ARRAY_INIT;
3166 log_build_warn_hmac(rdp, &firstHmacLine, WINPR_MD_MD5,
3167 "Autoreconnect cookie not supported");
3168 log_build_warn_hmac(rdp, &firstHmacLine, WINPR_MD_SHA1, "RDP security not supported");
3169 print_last_line(rdp->log, &firstHmacLine);
3170 }
3171
3172 log_line_t firstCipherLine = WINPR_C_ARRAY_INIT;
3173 if (!fips)
3174 {
3175 log_build_warn_cipher(rdp, &firstCipherLine, WINPR_CIPHER_ARC4_128,
3176 "assistance files with encrypted passwords, NTLM "
3177 "and autoreconnect cookies will not work",
3178 FALSE);
3179 }
3180 log_build_warn_cipher(rdp, &firstCipherLine, WINPR_CIPHER_ARC4_128,
3181 "RDP licensing and RDP security will not work", TRUE);
3182 if (!fips)
3183 log_build_warn_cipher(rdp, &firstCipherLine, WINPR_CIPHER_DES_EDE3_CBC,
3184 "RDP security will not work", TRUE);
3185 log_build_warn_cipher(
3186 rdp, &firstCipherLine, WINPR_CIPHER_AES_128_CBC,
3187 "assistance file encrypted LHTicket will not work and ARM gateway might not", FALSE);
3188 log_build_warn_cipher(rdp, &firstCipherLine, WINPR_CIPHER_AES_192_CBC,
3189 "ARM gateway might not work", FALSE);
3190 log_build_warn_cipher(rdp, &firstCipherLine, WINPR_CIPHER_AES_256_CBC,
3191 "ARM gateway might not work", FALSE);
3192 print_last_line(rdp->log, &firstCipherLine);
3193}
3194
3195void rdp_log_build_warnings(rdpRdp* rdp)
3196{
3197 static unsigned count = 0;
3198
3199 WINPR_ASSERT(rdp);
3200 /* Since this function is called in context creation routines stop logging
3201 * this issue repeatedly. This is required for proxy, which would otherwise
3202 * spam the log with these. */
3203 if (count > 0)
3204 return;
3205 count++;
3206 log_build_warn(rdp, "experimental", "might crash the application", option_is_experimental);
3207 log_build_warn(rdp, "debug", "might leak sensitive information (credentials, ...)",
3208 option_is_debug);
3209 log_build_warn(rdp, "runtime-check", "might slow down the application",
3210 option_is_runtime_checks);
3211 log_build_warn_ssl(rdp);
3212}
3213
3214size_t rdp_get_event_handles(rdpRdp* rdp, HANDLE* handles, uint32_t count)
3215{
3216 size_t nCount = transport_get_event_handles(rdp->transport, handles, count);
3217
3218 if (nCount == 0)
3219 return 0;
3220
3221 if (count < nCount + 2UL)
3222 return 0;
3223
3224 handles[nCount++] = utils_get_abort_event(rdp);
3225 handles[nCount++] = freerdp_timer_get_event(rdp->timer);
3226 return nCount;
3227}
WINPR_API void WINPR_JSON_Delete(WINPR_JSON *item)
Delete a WinPR JSON wrapper object.
Definition c-json.c:103
FREERDP_API rdpSettings * freerdp_settings_new(DWORD flags)
creates a new setting struct
FREERDP_API rdpSettings * freerdp_settings_clone(const rdpSettings *settings)
Creates a deep copy of settings.
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_set_pointer_len(rdpSettings *settings, FreeRDP_Settings_Keys_Pointer id, const void *data, size_t len)
Set a pointer to value data.
FREERDP_API void freerdp_settings_free(rdpSettings *settings)
Free a settings struct with all data in it.
#define FREERDP_SETTINGS_SERVER_MODE
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_set_string(rdpSettings *settings, FreeRDP_Settings_Keys_String id, const char *val)
Sets a string settings value. The param is copied.
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_get_bool(const rdpSettings *settings, FreeRDP_Settings_Keys_Bool id)
Returns a boolean settings value.