diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index e8a8c2b..586a68d 100644 --- a/.gitignore +++ b/.gitignore @@ -1,21 +1,2 @@ -/gnome-remote-desktop-0.1.*.tar.xz -/gnome-remote-desktop-40.beta.tar.xz -/gnome-remote-desktop-40.rc.tar.xz -/gnome-remote-desktop-40.0.tar.xz -/gnome-remote-desktop-40.1.tar.xz -/gnome-remote-desktop-41.rc.tar.xz -/gnome-remote-desktop-41.0.tar.xz -/gnome-remote-desktop-41.1.tar.xz -/gnome-remote-desktop-41.2.tar.xz -/gnome-remote-desktop-42.beta.tar.xz -/gnome-remote-desktop-42.rc.tar.xz -/gnome-remote-desktop-42.0.tar.xz -/gnome-remote-desktop-42.1.tar.xz -/gnome-remote-desktop-42.1.1.tar.xz -/gnome-remote-desktop-42.2.tar.xz -/gnome-remote-desktop-42.3.tar.xz -/gnome-remote-desktop-43.alpha.tar.xz -/gnome-remote-desktop-43.beta.tar.xz -/gnome-remote-desktop-43.0.tar.xz -/gnome-remote-desktop-43.1.tar.xz -/gnome-remote-desktop-43.2.tar.xz +/gnome-remote-desktop-*.tar.xz +/gnome-remote-desktop-*-build diff --git a/gnome-remote-desktop.spec b/gnome-remote-desktop.spec index efb5341..5d15c82 100644 --- a/gnome-remote-desktop.spec +++ b/gnome-remote-desktop.spec @@ -1,22 +1,24 @@ -%global systemd_unit gnome-remote-desktop.service +%global systemd_unit_handover gnome-remote-desktop-handover.service +%global systemd_unit_headless gnome-remote-desktop-headless.service +%global systemd_unit_system gnome-remote-desktop.service +%global systemd_unit_user gnome-remote-desktop.service %global tarball_version %%(echo %{version} | tr '~' '.') -# In RHEL/ELN FreeRDP is built without server support -%if 0%{?rhel} >= 9 -%global enable_rdp 0 -%else -%global enable_rdp 1 -%endif +%bcond rdp %[0%{?fedora} || 0%{?rhel} >= 10] +%bcond vnc %[0%{?fedora} || 0%{?rhel} < 10] + +%global libei_version 1.0.901 +%global pipewire_version 0.3.49 Name: gnome-remote-desktop -Version: 43.2 -Release: 1%{?dist} +Version: 49.2 +Release: %autorelease Summary: GNOME Remote Desktop screen share service -License: GPLv2+ +License: GPL-2.0-or-later URL: https://gitlab.gnome.org/GNOME/gnome-remote-desktop -Source0: https://download.gnome.org/sources/%{name}/43/%{name}-%{tarball_version}.tar.xz +Source0: https://download.gnome.org/sources/%{name}/49/%{name}-%{tarball_version}.tar.xz # Adds encryption support (requires patched LibVNCServer) Patch0: gnutls-anontls.patch @@ -27,12 +29,19 @@ BuildRequires: meson >= 0.47.0 BuildRequires: systemd-rpm-macros BuildRequires: pkgconfig(cairo) BuildRequires: pkgconfig(epoxy) +BuildRequires: pkgconfig(dbus-1) BuildRequires: pkgconfig(ffnvcodec) -%if 0%{?enable_rdp} +%if %{with rdp} +BuildRequires: glslc +BuildRequires: spirv-tools BuildRequires: pkgconfig(fdk-aac) -BuildRequires: pkgconfig(freerdp2) +BuildRequires: pkgconfig(freerdp3) BuildRequires: pkgconfig(fuse3) -BuildRequires: pkgconfig(winpr2) +BuildRequires: pkgconfig(libva) +BuildRequires: pkgconfig(opus) +BuildRequires: pkgconfig(polkit-gobject-1) +BuildRequires: pkgconfig(vulkan) +BuildRequires: pkgconfig(winpr3) %endif BuildRequires: pkgconfig(gbm) BuildRequires: pkgconfig(glib-2.0) >= 2.68 @@ -40,10 +49,13 @@ BuildRequires: pkgconfig(gio-unix-2.0) BuildRequires: pkgconfig(gnutls) BuildRequires: pkgconfig(gudev-1.0) BuildRequires: pkgconfig(libdrm) +BuildRequires: pkgconfig(libei-1.0) >= %{libei_version} BuildRequires: pkgconfig(libnotify) BuildRequires: pkgconfig(libpipewire-0.3) BuildRequires: pkgconfig(libsecret-1) +%if %{with vnc} BuildRequires: pkgconfig(libvncserver) >= 0.9.11-7 +%endif BuildRequires: pkgconfig(systemd) BuildRequires: pkgconfig(xkbcommon) BuildRequires: pkgconfig(tss2-esys) @@ -51,7 +63,8 @@ BuildRequires: pkgconfig(tss2-mu) BuildRequires: pkgconfig(tss2-rc) BuildRequires: pkgconfig(tss2-tctildr) -Requires: pipewire%{?_isa} >= 0.3.0 +Requires: libei%{?_isa} >= %{libei_version} +Requires: pipewire%{?_isa} >= %{pipewire_version} Obsoletes: vino < 3.22.0-21 @@ -66,15 +79,18 @@ GNOME desktop environment. %build %meson \ -%if 0%{?enable_rdp} +%if %{with rdp} -Drdp=true \ - -Dfdk_aac=true \ %else -Drdp=false \ - -Dfdk_aac=false \ +%endif +%if %{with vnc} + -Dvnc=true \ +%else + -Dvnc=false \ %endif -Dsystemd=true \ - -Dvnc=true + -Dtests=false %meson_build @@ -85,15 +101,24 @@ GNOME desktop environment. %post -%systemd_user_post %{systemd_unit} +%systemd_post %{systemd_unit_system} +%systemd_user_post %{systemd_unit_handover} +%systemd_user_post %{systemd_unit_headless} +%systemd_user_post %{systemd_unit_user} %preun -%systemd_user_preun %{systemd_unit} +%systemd_preun %{systemd_unit_system} +%systemd_user_preun %{systemd_unit_handover} +%systemd_user_preun %{systemd_unit_headless} +%systemd_user_preun %{systemd_unit_user} %postun -%systemd_user_postun_with_restart %{systemd_unit} +%systemd_postun_with_restart %{systemd_unit_system} +%systemd_user_postun_with_restart %{systemd_unit_handover} +%systemd_user_postun_with_restart %{systemd_unit_headless} +%systemd_user_postun_with_restart %{systemd_unit_user} %files -f %{name}.lang @@ -101,179 +126,29 @@ GNOME desktop environment. %doc README.md %{_bindir}/grdctl %{_libexecdir}/gnome-remote-desktop-daemon -%{_userunitdir}/%{systemd_unit} +%{_libexecdir}/gnome-remote-desktop-enable-service +%{_libexecdir}/gnome-remote-desktop-configuration-daemon +%{_userunitdir}/%{systemd_unit_user} +%{_userunitdir}/%{systemd_unit_headless} +%{_userunitdir}/%{systemd_unit_handover} +%{_unitdir}/%{systemd_unit_system} +%{_unitdir}/gnome-remote-desktop-configuration.service +%{_datadir}/applications/org.gnome.RemoteDesktop.Handover.desktop +%{_datadir}/dbus-1/system-services/org.gnome.RemoteDesktop.Configuration.service +%{_datadir}/dbus-1/system.d/org.gnome.RemoteDesktop.conf %{_datadir}/glib-2.0/schemas/org.gnome.desktop.remote-desktop.gschema.xml %{_datadir}/glib-2.0/schemas/org.gnome.desktop.remote-desktop.enums.xml -%if 0%{?enable_rdp} +%{_datadir}/polkit-1/actions/org.gnome.remotedesktop.configure-system-daemon.policy +%{_datadir}/polkit-1/actions/org.gnome.remotedesktop.enable-system-daemon.policy +%{_datadir}/polkit-1/rules.d/20-gnome-remote-desktop.rules +%{_sysusersdir}/gnome-remote-desktop-sysusers.conf +%{_tmpfilesdir}/gnome-remote-desktop-tmpfiles.conf + +%if %{with rdp} %{_datadir}/gnome-remote-desktop/ %endif %{_mandir}/man1/grdctl.1* %changelog -* Thu Dec 08 2022 David King - 43.2-1 -- Update to 43.2 - -* Tue Nov 08 2022 Stephen Gallagher - 43.1-2 -- Fix build on RHEL 9+/ELN - -* Thu Oct 27 2022 David King - 43.1-1 -- Update to 43.1 - -* Tue Sep 20 2022 Jonas Ådahl - 43.0 -- Update to 43.0 - -* Thu Aug 18 2022 Jonas Ådahl - 43~beta-4 -- Drop dependency on tpm2-abrmd - -* Tue Aug 16 2022 Kalev Lember - 43~beta-3 -- Avoid manual requires on tss2* and rely on automatic soname deps instead - -* Mon Aug 15 2022 Simone Caronni - 43~beta-2 -- Rebuild for updated FreeRDP. - -* Thu Aug 11 2022 Jonas Ådahl - 43~beta -- Update to 43.beta - -* Fri Jul 29 2022 Tomas Popela - 43~alpha-2 -- FreeRDP is built without server support in RHEL and ELN so we should disable - the RDP there - -* Thu Jul 28 2022 Jonas Ådahl - 43~alpha -- Update to 43.alpha - -* Thu Jul 21 2022 Fedora Release Engineering - 42.3-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Thu Jul 07 2022 David King - 42.3-1 -- Update to 43.3 (#2091415) - -* Sun May 29 2022 David King - 42.2-1 -- Update to 42.2 - -* Wed May 11 2022 David King - 42.1.1-1 -- Update to 42.1.1 (#2061546) - -* Wed Apr 27 2022 David King - 42.1-2 -- Fix isa macro in Requires - -* Tue Apr 26 2022 David King - 42.1-1 -- Update to 42.1 (#2061546) - -* Mon Mar 21 2022 Jonas Ådahl - 42.0 -- Update to 42.0 - -* Mon Mar 14 2022 Jonas Ådahl - 42~rc-1 -- Update to 42.rc - -* Wed Feb 16 2022 Jonas Ådahl - 42~beta-1 -- Update to 42.beta - -* Thu Jan 20 2022 Fedora Release Engineering - 41.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Wed Dec 08 2021 Jonas Ådahl - 41.2-1 -- Update to 41.2 - -* Mon Nov 01 2021 Kalev Lember - 41.1-1 -- Update to 41.1 - -* Mon Sep 20 2021 Kalev Lember - 41.0-1 -- Update to 41.0 - -* Tue Sep 07 2021 Jonas Ådahl - 41~rc-1 -- Bump to 41.rc - -* Wed Aug 04 2021 Kalev Lember - 40.1-3 -- Avoid systemd_requires as per updated packaging guidelines - -* Thu Jul 22 2021 Fedora Release Engineering - 40.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Mon May 03 2021 Jonas Ådahl - 40.1-1 -- Bump to 40.1 - -* Thu Apr 15 2021 Simone Caronni - 40.0-2 -- Rebuild for updated FreeRDP. - -* Mon Mar 22 2021 Kalev Lember - 40.0-1 -- Update to 40.0 - -* Thu Mar 18 2021 Michael Catanzaro - 40.0~rc-2 -- Add Obsoletes: vino - -* Mon Mar 15 2021 Kalev Lember - 40.0~rc-1 -- Update to 40.rc - -* Thu Mar 04 2021 Jonas Ådahl - 40.0~beta-1 -- Bump to 40.beta - -* Tue Jan 26 2021 Fedora Release Engineering - 0.1.9-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Mon Sep 14 2020 Jonas Ådahl - 0.1.9-2 -- Copy using the right destination stride - -* Mon Sep 14 2020 Jonas Ådahl - 0.1.9-1 -- Update to 0.1.9 -- Backport race condition crash fix -- Rebase anon-tls patches - -* Thu Aug 27 2020 Ray Strode - 0.1.8-3 -- Fix crash - Related: #1844993 - -* Mon Jun 1 2020 Felipe Borges - 0.1.8-2 -- Fix black screen issue in remote connections on Wayland - -* Wed Mar 11 2020 Jonas Ådahl - 0.1.8-1 -- Update to 0.1.8 - -* Tue Jan 28 2020 Fedora Release Engineering - 0.1.7-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Thu Jul 25 2019 Fedora Release Engineering - 0.1.7-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Mon Mar 4 2019 Jonas Ådahl - 0.1.7-1 -- Update to 0.1.7 - -* Thu Jan 31 2019 Fedora Release Engineering - 0.1.6-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Tue Oct 2 2018 Jonas Ådahl - 0.1.6-2 -- Don't crash when PipeWire disconnects (rhbz#1632781) - -* Tue Aug 7 2018 Jonas Ådahl - 0.1.6 -- Update to 0.1.6 -- Apply ANON-TLS patch -- Depend on pipewire 0.2.2 - -* Fri Jul 13 2018 Fedora Release Engineering - 0.1.4-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild - -* Wed May 30 2018 Jonas Ådahl - 0.1.4-1 -- Update to new version - -* Fri Feb 09 2018 Igor Gnatenko - 0.1.2-5 -- Escape macros in %%changelog - -* Wed Feb 07 2018 Fedora Release Engineering - 0.1.2-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - -* Tue Aug 29 2017 Jonas Ådahl - 0.1.2-3 -- Use %%autosetup -- Install licence file - -* Tue Aug 22 2017 Jonas Ådahl - 0.1.2-2 -- Remove gschema compilation step as that had been deprecated - -* Mon Aug 21 2017 Jonas Ådahl - 0.1.2-1 -- Update to 0.1.2 -- Changed tabs to spaces -- Added systemd user macros -- Install to correct systemd user unit directory -- Compile gsettings schemas after install and uninstall - -* Mon Aug 21 2017 Jonas Ådahl - 0.1.1-1 -- First packaged version +%autochangelog diff --git a/gnutls-anontls.patch b/gnutls-anontls.patch index 12f9dff..6151d72 100644 --- a/gnutls-anontls.patch +++ b/gnutls-anontls.patch @@ -1,4 +1,4 @@ -From adf2ee8c9745b3aecd2b909de67b03b178b06f4c Mon Sep 17 00:00:00 2001 +From 005617f3e2cb59241dc02c2db714c2b934553acb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Thu, 14 Jun 2018 12:21:37 +0200 Subject: [PATCH 1/7] vnc: Add anonymous TLS encryption support @@ -13,22 +13,22 @@ VNC connection. src/grd-enums.h | 6 + src/grd-session-vnc.c | 120 ++++- src/grd-session-vnc.h | 17 + - src/grd-settings.c | 28 ++ - src/grd-settings.h | 2 + - src/grd-vnc-server.c | 47 ++ + src/grd-settings-user.c | 4 + + src/grd-settings.c | 18 + + src/grd-vnc-server.c | 49 ++ src/grd-vnc-tls.c | 444 ++++++++++++++++++ src/grd-vnc-tls.h | 28 ++ src/meson.build | 3 + ...nome.desktop.remote-desktop.gschema.xml.in | 10 + - 11 files changed, 680 insertions(+), 26 deletions(-) + 11 files changed, 674 insertions(+), 26 deletions(-) create mode 100644 src/grd-vnc-tls.c create mode 100644 src/grd-vnc-tls.h diff --git a/meson.build b/meson.build -index 70a3ef3..2a92588 100644 +index 5dcb77c3..269238c0 100644 --- a/meson.build +++ b/meson.build -@@ -63,6 +63,7 @@ endif +@@ -70,6 +70,7 @@ endif if have_vnc libvncclient_dep = dependency('libvncclient') libvncserver_dep = dependency('libvncserver') @@ -37,12 +37,12 @@ index 70a3ef3..2a92588 100644 prefix = get_option('prefix') diff --git a/src/grd-enums.h b/src/grd-enums.h -index 44b181d..de0d0f8 100644 +index 25b42661..f4438764 100644 --- a/src/grd-enums.h +++ b/src/grd-enums.h -@@ -39,4 +39,10 @@ typedef enum - GRD_VNC_SCREEN_SHARE_MODE_EXTEND, - } GrdVncScreenShareMode; +@@ -32,6 +32,12 @@ typedef enum + GRD_VNC_AUTH_METHOD_PASSWORD + } GrdVncAuthMethod; +typedef enum +{ @@ -50,12 +50,14 @@ index 44b181d..de0d0f8 100644 + GRD_VNC_ENCRYPTION_TLS_ANON = 1 << 1, +} GrdVncEncryption; + - #endif /* GRD_ENUMS_H */ + typedef enum + { + GRD_VNC_SCREEN_SHARE_MODE_MIRROR_PRIMARY, diff --git a/src/grd-session-vnc.c b/src/grd-session-vnc.c -index d310706..d145b8d 100644 +index f7e14080..b5e4fe13 100644 --- a/src/grd-session-vnc.c +++ b/src/grd-session-vnc.c -@@ -45,7 +45,9 @@ struct _GrdSessionVnc +@@ -46,7 +46,9 @@ struct _GrdSessionVnc { GrdSession parent; @@ -65,7 +67,7 @@ index d310706..d145b8d 100644 GSource *source; rfbScreenInfoPtr rfb_screen; rfbClientPtr rfb_client; -@@ -586,6 +588,12 @@ check_rfb_password (rfbClientPtr rfb_client, +@@ -608,6 +610,12 @@ check_rfb_password (rfbClientPtr rfb_client, } } @@ -78,7 +80,7 @@ index d310706..d145b8d 100644 int grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, int width) -@@ -593,6 +601,18 @@ grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, +@@ -615,6 +623,18 @@ grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, return width * BGRX_BYTES_PER_PIXEL; } @@ -97,7 +99,7 @@ index d310706..d145b8d 100644 static void init_vnc_session (GrdSessionVnc *session_vnc) { -@@ -667,44 +687,85 @@ init_vnc_session (GrdSessionVnc *session_vnc) +@@ -689,44 +709,85 @@ init_vnc_session (GrdSessionVnc *session_vnc) rfbProcessEvents (rfb_screen, 0); } @@ -208,7 +210,7 @@ index d310706..d145b8d 100644 } return G_SOURCE_CONTINUE; -@@ -717,7 +778,10 @@ grd_session_vnc_attach_source (GrdSessionVnc *session_vnc) +@@ -739,7 +800,10 @@ grd_session_vnc_attach_source (GrdSessionVnc *session_vnc) socket = g_socket_connection_get_socket (session_vnc->connection); session_vnc->source = g_socket_create_source (socket, @@ -220,7 +222,7 @@ index d310706..d145b8d 100644 NULL); g_source_set_callback (session_vnc->source, (GSourceFunc) handle_socket_data, -@@ -748,11 +812,13 @@ grd_session_vnc_new (GrdVncServer *vnc_server, +@@ -780,6 +844,7 @@ grd_session_vnc_new (GrdVncServer *vnc_server, "context", context, NULL); @@ -228,13 +230,15 @@ index d310706..d145b8d 100644 session_vnc->connection = g_object_ref (connection); settings = grd_context_get_settings (context); - session_vnc->screen_share_mode = grd_settings_get_vnc_screen_share_mode (settings); +@@ -792,6 +857,7 @@ grd_session_vnc_new (GrdVncServer *vnc_server, + G_CALLBACK (on_view_only_changed), + session_vnc); + grd_session_vnc_grab_socket (session_vnc, vnc_socket_grab_func); grd_session_vnc_attach_source (session_vnc); init_vnc_session (session_vnc); -@@ -767,6 +833,8 @@ grd_session_vnc_dispose (GObject *object) +@@ -806,6 +872,8 @@ grd_session_vnc_dispose (GObject *object) g_assert (!session_vnc->rfb_screen); @@ -244,10 +248,10 @@ index d310706..d145b8d 100644 G_OBJECT_CLASS (grd_session_vnc_parent_class)->dispose (object); diff --git a/src/grd-session-vnc.h b/src/grd-session-vnc.h -index be79cf4..ffc8d27 100644 +index 8fc71850..3c08f812 100644 --- a/src/grd-session-vnc.h +++ b/src/grd-session-vnc.h -@@ -37,6 +37,9 @@ G_DECLARE_FINAL_TYPE (GrdSessionVnc, +@@ -36,6 +36,9 @@ G_DECLARE_FINAL_TYPE (GrdSessionVnc, GRD, SESSION_VNC, GrdSession) @@ -257,7 +261,7 @@ index be79cf4..ffc8d27 100644 GrdSessionVnc *grd_session_vnc_new (GrdVncServer *vnc_server, GSocketConnection *connection); -@@ -63,6 +66,20 @@ void grd_session_vnc_set_client_clipboard_text (GrdSessionVnc *session_vnc, +@@ -62,4 +65,18 @@ void grd_session_vnc_set_client_clipboard_text (GrdSessionVnc *session_vnc, int grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, int width); @@ -266,7 +270,7 @@ index be79cf4..ffc8d27 100644 +int grd_session_vnc_get_framebuffer_stride (GrdSessionVnc *session_vnc); + gboolean grd_session_vnc_is_client_gone (GrdSessionVnc *session_vnc); - ++ +rfbClientPtr grd_session_vnc_get_rfb_client (GrdSessionVnc *session_vnc); + +void grd_session_vnc_grab_socket (GrdSessionVnc *session_vnc, @@ -276,96 +280,81 @@ index be79cf4..ffc8d27 100644 + GrdVncSocketGrabFunc grab_func); + +GrdVncServer * grd_session_vnc_get_vnc_server (GrdSessionVnc *session_vnc); +diff --git a/src/grd-settings-user.c b/src/grd-settings-user.c +index 1bd679e4..c54e0b80 100644 +--- a/src/grd-settings-user.c ++++ b/src/grd-settings-user.c +@@ -91,6 +91,10 @@ grd_settings_user_constructed (GObject *object) + g_settings_bind (settings->vnc_settings, "screen-share-mode", + settings, "vnc-screen-share-mode", + G_SETTINGS_BIND_DEFAULT); ++ g_settings_bind (settings->vnc_settings, "encryption", ++ settings, "vnc-encryption", ++ G_SETTINGS_BIND_DEFAULT); + - #endif /* GRD_SESSION_VNC_H */ + + G_OBJECT_CLASS (grd_settings_user_parent_class)->constructed (object); + } diff --git a/src/grd-settings.c b/src/grd-settings.c -index a95628f..15d2ad2 100644 +index 8393ace5..a65385ef 100644 --- a/src/grd-settings.c +++ b/src/grd-settings.c -@@ -74,6 +74,7 @@ struct _GrdSettings - GrdVncAuthMethod auth_method; - int port; - GrdVncScreenShareMode screen_share_mode; -+ GrdVncEncryption encryption; - } vnc; +@@ -58,6 +58,7 @@ enum + PROP_RDP_SERVER_CERT_PATH, + PROP_RDP_SERVER_KEY_PATH, + PROP_VNC_AUTH_METHOD, ++ PROP_VNC_ENCRYPTION, }; -@@ -248,6 +249,12 @@ grd_settings_get_vnc_auth_method (GrdSettings *settings) - return settings->vnc.auth_method; - } + typedef struct _GrdSettingsPrivate +@@ -84,6 +85,7 @@ typedef struct _GrdSettingsPrivate + gboolean view_only; + GrdVncScreenShareMode screen_share_mode; + GrdVncAuthMethod auth_method; ++ GrdVncEncryption encryption; + } vnc; + } GrdSettingsPrivate; -+GrdVncEncryption -+grd_settings_get_vnc_encryption (GrdSettings *settings) -+{ -+ return settings->vnc.encryption; -+} -+ - static void - update_screen_share_mode (GrdSettings *settings) - { -@@ -313,6 +320,13 @@ update_vnc_auth_method (GrdSettings *settings) - "auth-method"); - } - -+static void -+update_vnc_encryption (GrdSettings *settings) -+{ -+ settings->vnc.encryption = g_settings_get_flags (settings->vnc.settings, -+ "encryption"); -+} -+ - static void - on_rdp_settings_changed (GSettings *rdp_settings, - const char *key, -@@ -370,6 +384,11 @@ on_vnc_settings_changed (GSettings *vnc_settings, - update_vnc_auth_method (settings); - g_signal_emit (settings, signals[VNC_AUTH_METHOD_CHANGED], 0); +@@ -426,6 +428,9 @@ grd_settings_get_property (GObject *object, + else + g_value_set_enum (value, priv->vnc.auth_method); + break; ++ case PROP_VNC_ENCRYPTION: ++ g_value_set_flags (value, priv->vnc.encryption); ++ break; + default: + G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec); } -+ else if (strcmp (key, "encryption") == 0) -+ { -+ update_vnc_encryption (settings); -+ g_signal_emit (settings, signals[VNC_ENCRYPTION_CHANGED], 0); -+ } +@@ -563,6 +568,9 @@ grd_settings_set_property (GObject *object, + case PROP_VNC_AUTH_METHOD: + priv->vnc.auth_method = g_value_get_enum (value); + break; ++ case PROP_VNC_ENCRYPTION: ++ priv->vnc.encryption = g_value_get_flags (value); ++ break; + default: + G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec); + } +@@ -744,4 +752,14 @@ grd_settings_class_init (GrdSettingsClass *klass) + G_PARAM_READWRITE | + G_PARAM_CONSTRUCT | + G_PARAM_STATIC_STRINGS)); ++ g_object_class_install_property (object_class, ++ PROP_VNC_ENCRYPTION, ++ g_param_spec_flags ("vnc-encryption", ++ "vnc encryption", ++ "vnc encryption", ++ GRD_TYPE_VNC_ENCRYPTION, ++ GRD_VNC_ENCRYPTION_TLS_ANON, ++ G_PARAM_READWRITE | ++ G_PARAM_CONSTRUCT | ++ G_PARAM_STATIC_STRINGS)); } - - GrdSettings * -@@ -419,6 +438,8 @@ grd_settings_init (GrdSettings *settings) - - settings->rdp.port = GRD_RDP_SERVER_PORT; - settings->vnc.port = GRD_VNC_SERVER_PORT; -+ -+ update_vnc_encryption (settings); - } - - static void -@@ -491,4 +512,11 @@ grd_settings_class_init (GrdSettingsClass *klass) - 0, - NULL, NULL, NULL, - G_TYPE_NONE, 0); -+ signals[VNC_ENCRYPTION_CHANGED] = -+ g_signal_new ("vnc-encryption-changed", -+ G_TYPE_FROM_CLASS (klass), -+ G_SIGNAL_RUN_LAST, -+ 0, -+ NULL, NULL, NULL, -+ G_TYPE_NONE, 0); - } -diff --git a/src/grd-settings.h b/src/grd-settings.h -index 1fe6419..b45f839 100644 ---- a/src/grd-settings.h -+++ b/src/grd-settings.h -@@ -68,4 +68,6 @@ gboolean grd_settings_get_vnc_view_only (GrdSettings *settings); - - GrdVncAuthMethod grd_settings_get_vnc_auth_method (GrdSettings *settings); - -+GrdVncEncryption grd_settings_get_vnc_encryption (GrdSettings *settings); -+ - #endif /* GRD_SETTINGS_H */ diff --git a/src/grd-vnc-server.c b/src/grd-vnc-server.c -index 70efab1..9280dfb 100644 +index 83220655..2f8229b2 100644 --- a/src/grd-vnc-server.c +++ b/src/grd-vnc-server.c -@@ -24,12 +24,14 @@ +@@ -24,6 +24,7 @@ #include "grd-vnc-server.h" @@ -373,14 +362,15 @@ index 70efab1..9280dfb 100644 #include #include - #include "grd-context.h" +@@ -31,6 +32,7 @@ #include "grd-debug.h" #include "grd-session-vnc.h" + #include "grd-utils.h" +#include "grd-vnc-tls.h" enum { -@@ -129,6 +131,43 @@ on_incoming (GSocketService *service, +@@ -130,6 +132,45 @@ on_incoming (GSocketService *service, return TRUE; } @@ -392,7 +382,9 @@ index 70efab1..9280dfb 100644 + GrdVncEncryption encryption; + + tls_security_handler = grd_vnc_tls_get_security_handler (); -+ encryption = grd_settings_get_vnc_encryption (settings); ++ g_object_get (G_OBJECT (settings), ++ "vnc-encryption", &encryption, ++ NULL); + + if (encryption == (GRD_VNC_ENCRYPTION_NONE | GRD_VNC_ENCRYPTION_TLS_ANON)) + { @@ -424,7 +416,7 @@ index 70efab1..9280dfb 100644 gboolean grd_vnc_server_start (GrdVncServer *vnc_server, GError **error) -@@ -216,11 +255,19 @@ grd_vnc_server_dispose (GObject *object) +@@ -242,11 +283,19 @@ grd_vnc_server_dispose (GObject *object) static void grd_vnc_server_constructed (GObject *object) { @@ -436,7 +428,7 @@ index 70efab1..9280dfb 100644 else rfbLogEnable (0); -+ g_signal_connect (settings, "vnc-encryption-changed", ++ g_signal_connect (settings, "notify::vnc-encryption", + G_CALLBACK (on_vnc_encryption_changed), + vnc_server); + sync_encryption_settings (vnc_server); @@ -446,7 +438,7 @@ index 70efab1..9280dfb 100644 diff --git a/src/grd-vnc-tls.c b/src/grd-vnc-tls.c new file mode 100644 -index 0000000..ec4758e +index 00000000..ec4758e0 --- /dev/null +++ b/src/grd-vnc-tls.c @@ -0,0 +1,444 @@ @@ -896,7 +888,7 @@ index 0000000..ec4758e +} diff --git a/src/grd-vnc-tls.h b/src/grd-vnc-tls.h new file mode 100644 -index 0000000..135ef8c +index 00000000..135ef8c7 --- /dev/null +++ b/src/grd-vnc-tls.h @@ -0,0 +1,28 @@ @@ -929,10 +921,10 @@ index 0000000..135ef8c + +#endif /* GRD_VNC_TLS_H */ diff --git a/src/meson.build b/src/meson.build -index 9f9b9b7..bc82252 100644 +index 1b2cb93d..6b8b517e 100644 --- a/src/meson.build +++ b/src/meson.build -@@ -153,10 +153,13 @@ if have_vnc +@@ -274,10 +274,13 @@ if have_vnc 'grd-vnc-pipewire-stream.h', 'grd-vnc-server.c', 'grd-vnc-server.h', @@ -947,10 +939,10 @@ index 9f9b9b7..bc82252 100644 endif diff --git a/src/org.gnome.desktop.remote-desktop.gschema.xml.in b/src/org.gnome.desktop.remote-desktop.gschema.xml.in -index 5b39a5d..c6dc2ab 100644 +index 2986a0e5..a0169789 100644 --- a/src/org.gnome.desktop.remote-desktop.gschema.xml.in +++ b/src/org.gnome.desktop.remote-desktop.gschema.xml.in -@@ -116,5 +116,15 @@ +@@ -173,6 +173,16 @@ configuration updates. @@ -965,12 +957,13 @@ index 5b39a5d..c6dc2ab 100644 + + - + + -- -2.37.1 +2.51.0 -From f91f9a17e8277f15a44720eb180bf22bd91307c6 Mon Sep 17 00:00:00 2001 +From bc65e13fb3687b2f79433c880525333810d6ba31 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Wed, 27 Nov 2019 11:02:09 +0100 Subject: [PATCH 2/7] session-vnc: Add paused/resumed signals @@ -983,10 +976,10 @@ out-of-socket source. 1 file changed, 65 insertions(+), 7 deletions(-) diff --git a/src/grd-session-vnc.c b/src/grd-session-vnc.c -index d145b8d..e7a77d5 100644 +index b5e4fe13..79de30d4 100644 --- a/src/grd-session-vnc.c +++ b/src/grd-session-vnc.c -@@ -41,14 +41,27 @@ +@@ -42,14 +42,27 @@ #define BGRX_SAMPLES_PER_PIXEL 3 #define BGRX_BYTES_PER_PIXEL 4 @@ -1014,7 +1007,7 @@ index d145b8d..e7a77d5 100644 rfbScreenInfoPtr rfb_screen; rfbClientPtr rfb_client; -@@ -79,7 +92,7 @@ struct _GrdSessionVnc +@@ -81,7 +94,7 @@ struct _GrdSessionVnc G_DEFINE_TYPE (GrdSessionVnc, grd_session_vnc, GRD_TYPE_SESSION) static void @@ -1023,7 +1016,7 @@ index d145b8d..e7a77d5 100644 static gboolean close_session_idle (gpointer user_data); -@@ -246,7 +259,8 @@ handle_client_gone (rfbClientPtr rfb_client) +@@ -248,7 +261,8 @@ handle_client_gone (rfbClientPtr rfb_client) g_debug ("VNC client gone"); @@ -1033,16 +1026,16 @@ index d145b8d..e7a77d5 100644 maybe_queue_close_session_idle (session_vnc); session_vnc->rfb_client = NULL; } -@@ -315,7 +329,7 @@ handle_new_client (rfbClientPtr rfb_client) - session_vnc->prompt_cancellable, - prompt_response_callback, - session_vnc); +@@ -338,7 +352,7 @@ handle_new_client (rfbClientPtr rfb_client) + { + case GRD_VNC_AUTH_METHOD_PROMPT: + show_sharing_desktop_prompt (session_vnc, rfb_client->host); - grd_session_vnc_detach_source (session_vnc); + grd_session_vnc_pause (session_vnc); return RFB_CLIENT_ON_HOLD; case GRD_VNC_AUTH_METHOD_PASSWORD: session_vnc->rfb_screen->passwordCheck = check_rfb_password; -@@ -579,7 +593,7 @@ check_rfb_password (rfbClientPtr rfb_client, +@@ -601,7 +615,7 @@ check_rfb_password (rfbClientPtr rfb_client, if (memcmp (challenge_encrypted, response_encrypted, len) == 0) { grd_session_start (GRD_SESSION (session_vnc)); @@ -1051,7 +1044,7 @@ index d145b8d..e7a77d5 100644 return TRUE; } else -@@ -799,6 +813,36 @@ grd_session_vnc_detach_source (GrdSessionVnc *session_vnc) +@@ -821,6 +835,36 @@ grd_session_vnc_detach_source (GrdSessionVnc *session_vnc) g_clear_pointer (&session_vnc->source, g_source_unref); } @@ -1085,10 +1078,10 @@ index d145b8d..e7a77d5 100644 + g_signal_emit (session_vnc, signals[RESUMED], 0); +} + - GrdSessionVnc * - grd_session_vnc_new (GrdVncServer *vnc_server, - GSocketConnection *connection) -@@ -820,6 +864,7 @@ grd_session_vnc_new (GrdVncServer *vnc_server, + static void + on_view_only_changed (GrdSettings *settings, + GParamSpec *pspec, +@@ -859,6 +903,7 @@ grd_session_vnc_new (GrdVncServer *vnc_server, grd_session_vnc_grab_socket (session_vnc, vnc_socket_grab_func); grd_session_vnc_attach_source (session_vnc); @@ -1096,16 +1089,16 @@ index d145b8d..e7a77d5 100644 init_vnc_session (session_vnc); -@@ -849,7 +894,7 @@ grd_session_vnc_stop (GrdSession *session) - - g_clear_object (&session_vnc->pipewire_stream); +@@ -893,7 +938,7 @@ grd_session_vnc_stop (GrdSession *session) + g_clear_object (&session_vnc->stream); + } - grd_session_vnc_detach_source (session_vnc); + grd_session_vnc_pause (session_vnc); g_clear_object (&session_vnc->connection); g_clear_object (&session_vnc->clipboard_vnc); -@@ -936,8 +981,8 @@ grd_session_vnc_stream_ready (GrdSession *session, +@@ -984,8 +1029,8 @@ on_stream_ready (GrdStream *stream, G_CALLBACK (on_pipewire_stream_closed), session_vnc); @@ -1116,10 +1109,10 @@ index d145b8d..e7a77d5 100644 } static void -@@ -958,4 +1003,17 @@ grd_session_vnc_class_init (GrdSessionVncClass *klass) - session_class->remote_desktop_session_started = - grd_session_vnc_remote_desktop_session_started; - session_class->stream_ready = grd_session_vnc_stream_ready; +@@ -1021,4 +1066,17 @@ grd_session_vnc_class_init (GrdSessionVncClass *klass) + + session_class->stop = grd_session_vnc_stop; + session_class->on_stream_created = grd_session_vnc_on_stream_created; + + signals[PAUSED] = g_signal_new ("paused", + G_TYPE_FROM_CLASS (klass), @@ -1135,10 +1128,10 @@ index d145b8d..e7a77d5 100644 + G_TYPE_NONE, 0); } -- -2.37.1 +2.51.0 -From 5856f0b5da2b3f71d8424db96e777001a8250137 Mon Sep 17 00:00:00 2001 +From aabc0245e247fbffe9ae6b8281cbf2bccc9ab882 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Wed, 27 Nov 2019 11:03:46 +0100 Subject: [PATCH 3/7] session-vnc: Add grd_session_vnc_dispatch() helper @@ -1151,10 +1144,10 @@ available that is not visible to the socket source. 2 files changed, 18 insertions(+), 10 deletions(-) diff --git a/src/grd-session-vnc.c b/src/grd-session-vnc.c -index e7a77d5..67308a2 100644 +index 79de30d4..b48b9017 100644 --- a/src/grd-session-vnc.c +++ b/src/grd-session-vnc.c -@@ -749,6 +749,21 @@ vnc_socket_grab_func (GrdSessionVnc *session_vnc, +@@ -771,6 +771,21 @@ vnc_socket_grab_func (GrdSessionVnc *session_vnc, return TRUE; } @@ -1176,7 +1169,7 @@ index e7a77d5..67308a2 100644 static gboolean handle_socket_data (GSocket *socket, GIOCondition condition, -@@ -765,16 +780,7 @@ handle_socket_data (GSocket *socket, +@@ -787,16 +802,7 @@ handle_socket_data (GSocket *socket, } else if (condition & G_IO_IN) { @@ -1195,23 +1188,21 @@ index e7a77d5..67308a2 100644 else { diff --git a/src/grd-session-vnc.h b/src/grd-session-vnc.h -index ffc8d27..a86d61d 100644 +index 3c08f812..f230887e 100644 --- a/src/grd-session-vnc.h +++ b/src/grd-session-vnc.h -@@ -80,6 +80,8 @@ void grd_session_vnc_grab_socket (GrdSessionVnc *session_vnc, +@@ -79,4 +79,6 @@ void grd_session_vnc_grab_socket (GrdSessionVnc *session_vnc, void grd_session_vnc_ungrab_socket (GrdSessionVnc *session_vnc, GrdVncSocketGrabFunc grab_func); +void grd_session_vnc_dispatch (GrdSessionVnc *session_vnc); + GrdVncServer * grd_session_vnc_get_vnc_server (GrdSessionVnc *session_vnc); - - #endif /* GRD_SESSION_VNC_H */ -- -2.37.1 +2.51.0 -From b8a59836a2348ab10fed0ff1590e12690ea427de Mon Sep 17 00:00:00 2001 +From 2d43f0586ae24b202beda4d283b25fec3e722af7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Wed, 27 Nov 2019 11:05:13 +0100 Subject: [PATCH 4/7] vnc/tls: Add some logging @@ -1223,7 +1214,7 @@ protocol rather than the session itself. 1 file changed, 9 insertions(+) diff --git a/src/grd-vnc-tls.c b/src/grd-vnc-tls.c -index ec4758e..ac6c35f 100644 +index ec4758e0..ac6c35f6 100644 --- a/src/grd-vnc-tls.c +++ b/src/grd-vnc-tls.c @@ -67,6 +67,7 @@ grd_vnc_tls_context_new (void) @@ -1285,10 +1276,10 @@ index ec4758e..ac6c35f 100644 { g_warning ("TLS handshake failed: %s", error->message); -- -2.37.1 +2.51.0 -From 26a824eede76c1d06ac6eb11cb0dd016ec66c739 Mon Sep 17 00:00:00 2001 +From 62e04d794eaf2c0acfc16af0b0968fead4bb4df1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Wed, 27 Nov 2019 11:07:40 +0100 Subject: [PATCH 5/7] vnc/tls: Dispatch also when data is pending outside of @@ -1305,10 +1296,10 @@ long as there is data to read in those buffers. 2 files changed, 86 insertions(+), 6 deletions(-) diff --git a/src/grd-session-vnc.h b/src/grd-session-vnc.h -index a86d61d..5db388b 100644 +index f230887e..9dd33442 100644 --- a/src/grd-session-vnc.h +++ b/src/grd-session-vnc.h -@@ -80,6 +80,8 @@ void grd_session_vnc_grab_socket (GrdSessionVnc *session_vnc, +@@ -79,6 +79,8 @@ void grd_session_vnc_grab_socket (GrdSessionVnc *session_vnc, void grd_session_vnc_ungrab_socket (GrdSessionVnc *session_vnc, GrdVncSocketGrabFunc grab_func); @@ -1318,7 +1309,7 @@ index a86d61d..5db388b 100644 GrdVncServer * grd_session_vnc_get_vnc_server (GrdSessionVnc *session_vnc); diff --git a/src/grd-vnc-tls.c b/src/grd-vnc-tls.c -index ac6c35f..312b6b9 100644 +index ac6c35f6..312b6b92 100644 --- a/src/grd-vnc-tls.c +++ b/src/grd-vnc-tls.c @@ -41,6 +41,12 @@ typedef enum _GrdTlsHandshakeState @@ -1455,10 +1446,10 @@ index ac6c35f..312b6b9 100644 } -- -2.37.1 +2.51.0 -From 879b9a26595c338cee40aa919596e439be910f4b Mon Sep 17 00:00:00 2001 +From 799e2b287bd055c46709d0063436b819894200e6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Wed, 27 Nov 2019 16:48:00 +0100 Subject: [PATCH 6/7] session-vnc: Set our own password handling function up @@ -1477,10 +1468,10 @@ password prompt. 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/src/grd-session-vnc.c b/src/grd-session-vnc.c -index 67308a2..39b3a56 100644 +index b48b9017..87cc7d86 100644 --- a/src/grd-session-vnc.c +++ b/src/grd-session-vnc.c -@@ -97,11 +97,6 @@ grd_session_vnc_pause (GrdSessionVnc *session_vnc); +@@ -99,11 +99,6 @@ grd_session_vnc_pause (GrdSessionVnc *session_vnc); static gboolean close_session_idle (gpointer user_data); @@ -1492,7 +1483,7 @@ index 67308a2..39b3a56 100644 static void swap_uint8 (uint8_t *a, uint8_t *b) -@@ -332,7 +327,6 @@ handle_new_client (rfbClientPtr rfb_client) +@@ -355,7 +350,6 @@ handle_new_client (rfbClientPtr rfb_client) grd_session_vnc_pause (session_vnc); return RFB_CLIENT_ON_HOLD; case GRD_VNC_AUTH_METHOD_PASSWORD: @@ -1500,7 +1491,7 @@ index 67308a2..39b3a56 100644 /* * authPasswdData needs to be non NULL in libvncserver to trigger * password authentication. -@@ -697,6 +691,8 @@ init_vnc_session (GrdSessionVnc *session_vnc) +@@ -719,6 +713,8 @@ init_vnc_session (GrdSessionVnc *session_vnc) session_vnc->monitor_config->connectors = connectors; } @@ -1510,10 +1501,10 @@ index 67308a2..39b3a56 100644 rfbProcessEvents (rfb_screen, 0); } -- -2.37.1 +2.51.0 -From 7b0523bd3f6981225d2614956f297a698e846c1a Mon Sep 17 00:00:00 2001 +From b74286bdb8876d27d279c725357d73a23a3316b4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jonas=20=C3=85dahl?= Date: Mon, 12 Oct 2020 17:34:30 +0200 Subject: [PATCH 7/7] vnc: Copy pixels using the right destination stride @@ -1531,10 +1522,10 @@ dropped. 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/grd-session-vnc.h b/src/grd-session-vnc.h -index 5db388b..c4f4e8d 100644 +index 9dd33442..98c73451 100644 --- a/src/grd-session-vnc.h +++ b/src/grd-session-vnc.h -@@ -68,7 +68,8 @@ int grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, +@@ -67,7 +67,8 @@ int grd_session_vnc_get_stride_for_width (GrdSessionVnc *session_vnc, int grd_session_vnc_get_fd (GrdSessionVnc *session_vnc); @@ -1545,5 +1536,6 @@ index 5db388b..c4f4e8d 100644 gboolean grd_session_vnc_is_client_gone (GrdSessionVnc *session_vnc); -- -2.37.1 +2.51.0 + diff --git a/plans/main.fmf b/plans/main.fmf new file mode 100644 index 0000000..ae0c305 --- /dev/null +++ b/plans/main.fmf @@ -0,0 +1,6 @@ +summary: Run all tests +execute: + how: tmt +discover: + how: fmf + diff --git a/sources b/sources index a820d04..d817ea5 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (gnome-remote-desktop-43.2.tar.xz) = e7e9c36e04a7273cb1700859d59ab8130bca7103c3def7f51a6df31b98f6021b9ceb15d2f9e71fef2464141dcd01d467e126731028d7dd6b6ec843dd52b1e8d4 +SHA512 (gnome-remote-desktop-49.2.tar.xz) = b678ee125e1b5f6d58e85f57a332cf02ee6b5dee654469e66f496f9467e6512a701a3e37a9580562e0b064320380d2df4ca6b15e20bd35b1605b4bd9de73827c diff --git a/tests/got-audit/got-audit.gdb b/tests/got-audit/got-audit.gdb new file mode 100644 index 0000000..6661297 --- /dev/null +++ b/tests/got-audit/got-audit.gdb @@ -0,0 +1,2 @@ +gef config gef.disable_color True +got-audit --all diff --git a/tests/got-audit/main.fmf b/tests/got-audit/main.fmf new file mode 100644 index 0000000..25caf1d --- /dev/null +++ b/tests/got-audit/main.fmf @@ -0,0 +1,10 @@ +summary: Audit the GOT for signs of tampering +description: | + Pointers in the server process GOT will be checked to ensure that + each function pointer's value is within a shared object file + that exports a symbol of that name, and that no shared object + files export conflicting symbols. +contact: Gordon Messmer +require+: + - gdb-gef # needed to test got-audit + - gnome-remote-desktop diff --git a/tests/got-audit/runtest.sh b/tests/got-audit/runtest.sh new file mode 100755 index 0000000..c4b9b29 --- /dev/null +++ b/tests/got-audit/runtest.sh @@ -0,0 +1,41 @@ +#!/bin/bash +# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/gnome-remote-desktop/Sanity/got-audit +# Description: Check pointers in the server process GOT for signs of tampering +# Author: Gordon Messmer +# + +# Include Beaker environment +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +rlJournalStart + rlPhaseStartSetup + rlRun "systemctl start --user gnome-remote-desktop-headless" + rlRun "TestDir=\$(pwd)" + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlRun "auditfile=\$(mktemp --tmpdir=${TmpDir})" + rlPhaseEnd + + rlPhaseStartTest "Run GEF got-audit" + rlRun "SERVICE_PID=\$( systemctl show --property=MainPID --user gnome-remote-desktop-headless.service | cut -f2 -d= )" + rlRun "echo SERVICE_PID is '$SERVICE_PID'" + [ -n "$SERVICE_PID" ] || rlFail "No service pid was found" + rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'" + # Basic test: ensure that at least one symbol is found in libc.so, + # to verify that the report looks plausible. + rlAssertGrep " : /.*/libc.so" "$auditfile" + # Ensure the got-audit did not report any errors + rlAssertNotGrep " :: ERROR" "$auditfile" + rlRun "cp '$auditfile' '$TMT_TEST_DATA'/got-audit.txt" + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "systemctl stop --user gnome-remote-desktop-headless" + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalPrintText +rlJournalEnd diff --git a/tests/main.fmf b/tests/main.fmf new file mode 100644 index 0000000..f225a72 --- /dev/null +++ b/tests/main.fmf @@ -0,0 +1,2 @@ +test: ./runtest.sh +framework: beakerlib