Compare commits

...
Sign in to create a new pull request.

76 commits

Author SHA1 Message Date
Bojan Smojver
ded6843d0a Bump release for rebuild 2026-07-18 08:09:58 +10:00
Bojan Smojver
950bca1572 Replace m-dashes with hyphens 2026-07-18 08:06:58 +10:00
Bojan Smojver
da773d7b96 Fix epoch/release bump 2026-07-17 18:13:33 +10:00
Bojan Smojver
840ef696de Fix changelog 2026-07-17 18:06:43 +10:00
Bojan Smojver
7691357362 Fix bug #2499948
Update to 0.10.6.1
CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
CVE-2026-55639, CVE-2026-55645
2026-07-17 18:03:54 +10:00
Bojan Smojver
94b6f4aba2 Upload new source tarball 2026-07-07 19:49:14 +10:00
Bojan Smojver
f339e61176 Update to 0.10.6.1
CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
CVE-2026-55639, CVE-2026-55645
2026-07-07 19:33:24 +10:00
Bojan Smojver
8206f1cde6 Revert "Close TCP port in default Xvnc config, Unix domain socket only"
This reverts commit abcf261e6c.
2026-07-07 19:18:11 +10:00
Bojan Smojver
5c0c4355e8 Revert "close TCP port in default Xvnc config, Unix domain socket only"
This reverts commit 9da935c087.
2026-07-07 19:02:39 +10:00
Yaakov Selkowitz
15b67bfea5 Rebuilt for openssl 4.0 2026-06-12 20:08:57 -04:00
Bojan Smojver
9da935c087 close TCP port in default Xvnc config, Unix domain socket only 2026-05-22 05:15:19 +10:00
Bojan Smojver
abcf261e6c Close TCP port in default Xvnc config, Unix domain socket only 2026-05-22 05:11:45 +10:00
Bojan Smojver
13a9c73444 Update to 0.10.6 2026-04-18 08:23:21 +10:00
Bojan Smojver
500f161a30 Update to 0.10.5 2026-01-28 18:41:05 +11:00
Fedora Release Engineering
e70d849749 Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild 2026-01-17 20:52:58 +00:00
Tom spot Callaway
31a153d643 rebuild for new fuse3 2025-11-04 16:52:43 -05:00
Fedora Release Engineering
8473a1b002 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 21:03:48 +00:00
Bojan Smojver
bfa74ff263 Add vmconnect patch 2025-07-07 20:41:58 +10:00
Bojan Smojver
a468304b66 Patch upstream issue #3558, fix by matt335672 2025-07-07 20:33:56 +10:00
Bojan Smojver
fc1c271a1f Update to 0.10.4 2025-07-04 07:16:35 +10:00
Bojan Smojver
58d96b27c6 Enable Xvnc over Unix domain socket 2025-04-01 21:15:51 +11:00
Bojan Smojver
8631180d0b Update to 0.10.3 2025-04-01 21:00:15 +11:00
Bojan Smojver
253e64e7ca Rebuild for noopenh264 2.6.0, once more 2025-03-26 06:29:12 +11:00
Fabio Valentini
be9a73e597
Rebuild for noopenh264 2.6.0 2025-03-13 18:49:20 +01:00
Bojan Smojver
48c3c0c869 Add fuse3 dependency 2025-03-06 15:20:41 +11:00
63cd7fae8e Drop call to %sysusers_create_compat
After https://fedoraproject.org/wiki/Changes/RPMSuportForSystemdSysusers,
rpm will handle account creation automatically.
2025-02-11 18:03:12 +01:00
Bojan Smojver
bb831b9e36 Add utmp support contributed upstream by Magnus Lewis-Smith 2025-02-06 11:46:11 +11:00
mlewissmith
560f7a2003 Add utmp support
Addresses RHBZ#2339004

- Backport https://github.com/neutrinolabs/xrdp/pull/3400
- Build with necessary build flag '--enable-utmp'
- Update xrdp-sesman.pamd accordingly
2025-02-06 11:43:15 +11:00
Bojan Smojver
0a6bb02d7a Document KDE Plasma specific info 2025-01-25 16:27:06 +11:00
Fedora Release Engineering
301178bcb7 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 16:16:31 +00:00
Bojan Smojver
0fb0287ee9 Comment out generic RDP proxy in xrdp.ini 2025-01-05 21:21:58 +11:00
Bojan Smojver
9bea902969 Remove noopenh264 dep, adjust permissions of SSL related files 2025-01-05 14:13:43 +11:00
Bojan Smojver
a6aced6f40 Correct README.md source 2024-12-27 07:39:27 +11:00
Bojan Smojver
7ee2e171cd Adjust ownership/permissions of certs/keys for unprivileged user 2024-12-27 07:26:15 +11:00
Bojan Smojver
00ae909eea If openh264 is not present, require noopenh264 instead 2024-12-26 16:55:06 +11:00
Bojan Smojver
7f62e9d274 Add unprivileged user section to README file 2024-12-26 15:56:21 +11:00
Bojan Smojver
52c9861931 Add sysusers file, do not build with H264 on EPEL8 2024-12-25 22:58:17 +11:00
Bojan Smojver
2d02bc5324 Add xrdp sysusers 2024-12-25 22:43:39 +11:00
Bojan Smojver
bbe715feef Run as unprivileged user 2024-12-25 22:41:32 +11:00
Koichiro Iwao
c80b7cb47c Enable OpenH264 2024-12-25 06:15:04 +00:00
Bojan Smojver
b51e0d04c7 Do not expand macro in comment 2024-12-25 07:39:32 +11:00
Bojan Smojver
a26ce0ad01 Update to 0.10.2 2024-12-25 07:37:18 +11:00
Bojan Smojver
a9de146d17 Update to 0.10.2-rc.1 2024-12-24 08:13:31 +11:00
Miroslav Suchý
ee4d59ab85 convert license to SPDX
This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4
2024-09-04 22:57:36 +02:00
Bojan Smojver
6548d8b7d3 Update to 0.10.1 2024-08-01 00:09:28 +10:00
Fedora Release Engineering
25fb61557c Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-20 10:26:46 +00:00
Bojan Smojver
e33983fa06 Fix release number 2024-06-01 20:23:12 +10:00
Bojan Smojver
0ab794b1a6 Explain downgrades from 0.10.x to 0.9.x in README.Fedora 2024-06-01 20:21:07 +10:00
Bojan Smojver
5004123f25 Do not fail if systemd-tmpfiles fails 2024-05-14 23:18:28 +10:00
Bojan Smojver
3bbe3491d8 Bump release for rebuild 2024-05-14 22:58:03 +10:00
Bojan Smojver
61320c3a12 Only require systemd-tmpfiles on Fedora 2024-05-14 22:56:21 +10:00
Bojan Smojver
bdb793303a Fix changelog order 2024-05-14 19:41:17 +10:00
Bojan Smojver
60542e6e4c Explicitly run systemd-tmpfiles --remove on package removal 2024-05-14 18:37:45 +10:00
Bojan Smojver
6b29715e1a Revert "Add upstream PR 2994"
This reverts commit d09880d4ca.
2024-05-14 15:58:57 +10:00
Bojan Smojver
dd8024580d Merge branch '0.10.0' into rawhide 2024-05-14 15:33:34 +10:00
Bojan Smojver
33857e65c9 Update to 0.10.0 final, add tmpfiles.conf 2024-05-14 15:23:45 +10:00
Bojan Smojver
9e82f0d656 Update to 0.10.0-beta.2 2024-04-03 11:14:41 +11:00
Bojan Smojver
d09880d4ca Add upstream PR 2994 2024-03-13 13:17:49 +11:00
Bojan Smojver
d2f8963baa Update to 0.9.25 2024-03-12 09:59:41 +11:00
Bojan Smojver
05b4d9a5b9 Initial work on build of 0.10.0 2024-03-12 09:29:28 +11:00
Fedora Release Engineering
4252753eb9 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-27 10:08:54 +00:00
Bojan Smojver
add9bfa264 Remove already applied patch affecting compilation on EL7 2023-12-31 11:49:46 +11:00
Bojan Smojver
14612e89c8 Update to 0.9.24 2023-12-31 09:51:24 +11:00
Bojan Smojver
014fe42d67 Update to 0.9.23.1. CVE-2023-42822. 2023-09-28 08:59:14 +10:00
Bojan Smojver
3f2b82ce95 Update to 0.9.23. CVE-2023-40184. 2023-09-01 03:47:14 +10:00
Fedora Release Engineering
2cc1f025f7 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-22 19:16:19 +00:00
Leigh Scott
8d30860c48 Rebuild fo new imlib2 2023-06-13 16:58:08 +01:00
Bojan Smojver
2891d49a53 Add explicit Requires to xrdp-devel package as found by fedora-ci 2023-05-31 10:34:28 +10:00
Bojan Smojver
abdf2ecbef Remove C99 loop initialisation on EPEL7. 2023-05-23 12:39:28 +10:00
Bojan Smojver
4b80fc3c5f Include librfxencode.so again. 2023-05-23 11:52:13 +10:00
Bojan Smojver
8abd3891e4 Update to 0.9.22.1. 2023-05-23 11:18:19 +10:00
Bojan Smojver
7a1d427dc2 Patch session chooser segfault. 2023-05-19 09:27:28 +10:00
Bojan Smojver
c6eb32c54e Fix changelog entry. 2023-05-17 11:23:31 +10:00
Bojan Smojver
8b1e0da00e Fix domain in my email address. 2023-05-17 10:59:56 +10:00
Bojan Smojver
05857b9224 Put what look like devel .so files into -devel package. 2023-05-17 10:56:24 +10:00
Bojan Smojver
812ea7eda5 Put back .so files into %libdir/xrdp directory. 2023-05-17 10:42:38 +10:00
18 changed files with 655 additions and 346 deletions

14
.gitignore vendored
View file

@ -26,3 +26,17 @@ xrdp-cvs-03-17-2010.tar.gz
/xrdp-0.9.20.tar.gz
/xrdp-0.9.21.tar.gz
/xrdp-0.9.22.tar.gz
/xrdp-0.9.22.1.tar.gz
/xrdp-0.9.23.tar.gz
/xrdp-0.9.23.1.tar.gz
/xrdp-0.9.24.tar.gz
/xrdp-0.9.25.tar.gz
/xrdp-0.10.0.tar.gz
/xrdp-0.10.1.tar.gz
/xrdp-0.10.2-rc.1.tar.gz
/xrdp-0.10.2.tar.gz
/xrdp-0.10.3.tar.gz
/xrdp-0.10.4.tar.gz
/xrdp-0.10.5.tar.gz
/xrdp-0.10.6.tar.gz
/xrdp-0.10.6.1.tar.gz

View file

@ -1,72 +0,0 @@
Restarts
========
Service restarts after RPM package upgrades have been disabled on purpose.
This is to avoid a situation where an update is performed from within a
session running on xrdp, which can then cause dnf to only perform part of the
transaction and leave the system in a state that requires further manual
intervention, including removal of duplicate packages etc.
So, it will be up to the user/admin to restart xrdp service after any RPM
package upgrade. This is in line with what other GUI systems like Xorg and
Wayland do.
xorgxrdp
========
Note that xorgxrdp is not installed and configured by default. Each build
depends on specific binary version of Xorg, which tends to create very strict
installation dependencies that can be an inconvenience in EPEL.
SELinux
=======
Please note that you may need to install xrdp-selinux package in order to get
the required SELinux policy that will allow xrdp and associated processes to
run successfully if SELinux is enabled. On versions of Fedora and RHEL that
support weak dependencies, xrdp-selinux will be a recommended package.
WARNING: The policy module contains a rule that permits unconfined_service_t
processes to transition into unconfined_t. If xrdp is not the only service
that runs as unconfined_service_t on your system, this policy will allow any
other such service to transition as well.
Default configuration in /etc/pam.d/xrdp-sesman uses password-auth for auth,
account, password and session. This may result in an incorrect context for
the processes in the session. Please adjust this file to match your desktop
environment. An example for Gnome desktop is given in the file.
TigerVNC >= 1.8.0
=================
TigerVNC 1.8.0 enables clipboard support by default (i.e. no need to run
vncconfig), which may cause disconnections in xrdp. To avoid the issue, these
can be added to [Xvnc] stanza in /etc/xrdp/sesman.ini:
param=-AcceptCutText=0
param=-SendCutText=0
param=-SendPrimary=0
param=-SetPrimary=0
Of course, cut and paste support will not work with these set.
Runlevel
========
If the system is configured to boot into graphical target, you may experience
problems with xrdp Gnome sessions. In order to avoid this, put the system into
multi user target. Like this:
systemctl set-default multi-user.target
Then reboot.
VSOCK
========
An example of a how to set up xrdp with VSOCK can be found here:
https://bugzilla.redhat.com/show_bug.cgi?id=1787953#c22
Please note that polkit rules for active sessions, allowing access to colord
and repository updates are already shipped, but in a current, JavaScript
format.

114
README.md Normal file
View file

@ -0,0 +1,114 @@
Downgrade from 0.10.x to 0.9.x
==
Version 0.10.x requires different permissions of `/run/xrdp` directory than
version 0.9.x. When 0.10.x is fully uninstalled, this directory is removed
and subsequent installation of 0.9.x should work fine.
However, if 0.10.x is downgraded to 0.9.x, the directory is preserved,
because we could have xrdp and its sessions still running, so subsequent start
or restart will fail, unless the permissions of `/run/xrdp` directory are
changed to 1777 beforehand.
Unprivileged xrdp user in 0.10.2 and up
==
Recent builds of xrdp (0.10.2 and above) create local unprivileged xrdp user,
which is used to run xrdp daemon. Script `/usr/share/xrdp/xrdp-chkpriv` checks
whether `/etc/xrdp/key.pem`, `/etc/xrdp/cert.pem` and `/etc/xrdp/rsakeys.ini`
files have correct ownership and permissions. It also makes sure
`/etc/xrdp/xrdp.ini` and `/etc/xrdp/sesman.ini` agree on which group is used
for unprivileged user.
If you are upgrading from previous version of xrdp and you already have all
these files, you may need to adjust them by hand after running this script.
For clean installs, these files should be created with correct ownership and
permissions.
Restarts
==
Service restarts after RPM package upgrades have been disabled on purpose.
This is to avoid a situation where an update is performed from within a
session running on xrdp, which can then cause dnf to only perform part of the
transaction and leave the system in a state that requires further manual
intervention, including removal of duplicate packages etc.
So, it will be up to the user/admin to restart xrdp service after any RPM
package upgrade. This is in line with what other GUI systems like Xorg and
Wayland do.
xorgxrdp
==
Note that xorgxrdp is not installed and configured by default. Each build
depends on specific binary version of Xorg. If you wish to use it, install
it by hand or its glamor build.
SELinux
==
You may need to install xrdp-selinux package in order to get the required
SELinux policy that will allow xrdp and associated processes to run
successfully if SELinux is enabled. On versions of Fedora and RHEL that support
weak dependencies, xrdp-selinux will be a recommended package.
**WARNING**: The policy module contains a rule that permits
unconfined_service_t processes to transition into unconfined_t. If xrdp is not
the only service that runs as unconfined_service_t on your system, this policy
will allow any other such service to transition as well. This transition is
exercised on every xrdp session (see below), not just latent in the policy.
The default `/etc/pam.d/xrdp-sesman` configuration invokes `pam_selinux.so`,
`pam_loginuid.so`, `pam_namespace.so` and `pam_keyinit.so` around the shared
`password-auth` stack, so session processes get the correct `unconfined_t`
context instead of remaining `unconfined_service_t` (rhbz#2499948).
If you are running a GNOME session over xrdp, comment out the generic block
in `/etc/pam.d/xrdp-sesman` and uncomment the Gnome-specific block instead.
This routes auth/session handling through `gdm-password`, which already
carries the correct SELinux/session ordering and additionally unlocks GNOME
Keyring automatically at login, so you won't be prompted to unlock it a
second time inside the session.
TigerVNC >= 1.8.0
==
TigerVNC 1.8.0 enables clipboard support by default (i.e. no need to run
vncconfig), which may cause disconnections in xrdp. To avoid the issue, these
can be added to [Xvnc] stanza in `/etc/xrdp/sesman.ini`:
```
param=-AcceptCutText=0
param=-SendCutText=0
param=-SendPrimary=0
param=-SetPrimary=0
```
Of course, cut and paste support will not work with these set.
Runlevel
==
If the system is configured to boot into graphical target, you may experience
problems with xrdp Gnome sessions. In order to avoid this, put the system into
multi user target. Like this:
```
systemctl set-default multi-user.target
```
Then reboot.
GNOME on X11 is no longer part of Fedora, so GNOME is no longer a supported
desktop for xrdp sessions on Fedora. If you need RDP access to a GNOME
desktop, use GNOME's built-in headless GNOME Remote Desktop instead of xrdp -
it speaks RDP natively, is Wayland-based, and doesn't need any of the
X11/PAM workarounds this document describes. xrdp remains the right choice
for XFCE, KDE Plasma, and other X11-based desktops on Fedora.
VSOCK
==
An example of a how to set up xrdp with VSOCK can be found here:
https://bugzilla.redhat.com/show_bug.cgi?id=1787953#c22
Polkit rules for active sessions, allowing access to colord and repository
updates are already shipped, but in a current, JavaScript format.
KDE Plasma
==
If you are using plasma-workspace package with xrdp, be sure to install
plasma-workspace-x11 to get full functionality. See this for more details:
https://github.com/neutrinolabs/xrdp/issues/3395

View file

@ -1 +1 @@
SHA512 (xrdp-0.9.22.tar.gz) = 9bef87d7fdf1fe0321c5091471f17b3148891a7ef9036ec08f84e4193b4ccb104879e2fcb556672f50d1f6d0e2c49e6193d142ff3ec756b20bc3929b928dfe78
SHA512 (xrdp-0.10.6.1.tar.gz) = 14fc2bdc7d450b0194d48244450fee2dc40d248bf0d7d64538959827919d517bda90cda5985014e6b5adf101cbb584e83cf72e5181adcff78b3131653937e108

View file

@ -0,0 +1,38 @@
--- xrdp-0.10.0-beta.1/sesman/libsesman/sesman_config.c.o 2024-03-11 14:21:33.295277249 +1100
+++ xrdp-0.10.0-beta.1/sesman/libsesman/sesman_config.c 2024-03-11 14:24:16.114048106 +1100
@@ -249,14 +249,14 @@ config_read_globals(int file, struct con
cf->default_wm = g_strdup("startwm.sh");
}
/* if default_wm doesn't begin with '/', it's a relative path to
- * XRDP_CFG_PATH */
+ * /usr/libexec/xrdp */
if (cf->default_wm[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- int length = (sizeof(XRDP_CFG_PATH) +
+ int length = (sizeof("/usr/libexec/xrdp") +
g_strlen(cf->default_wm) + 1); /* '/' */
char *buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->default_wm);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->default_wm);
g_free(cf->default_wm);
cf->default_wm = buf;
}
@@ -267,14 +267,14 @@ config_read_globals(int file, struct con
cf->reconnect_sh = g_strdup("reconnectwm.sh");
}
/* if reconnect_sh doesn't begin with '/', it's a relative path to
- * XRDP_CFG_PATH */
+ * /usr/libexec/xrdp */
if (cf->reconnect_sh[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- int length = (sizeof(XRDP_CFG_PATH) +
+ int length = (sizeof("/usr/libexec/xrdp") +
g_strlen(cf->reconnect_sh) + 1); /* '/' */
char *buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->reconnect_sh);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->reconnect_sh);
g_free(cf->reconnect_sh);
cf->reconnect_sh = buf;
}

13
xrdp-0.10.1-service.patch Normal file
View file

@ -0,0 +1,13 @@
diff -ruNp xrdp-0.10.1-v/instfiles/xrdp-sesman.service.in xrdp-0.10.1/instfiles/xrdp-sesman.service.in
--- xrdp-0.10.1-v/instfiles/xrdp-sesman.service.in 2024-07-31 22:55:03.000000000 +1000
+++ xrdp-0.10.1/instfiles/xrdp-sesman.service.in 2024-07-31 23:58:48.247323165 +1000
@@ -1,7 +1,8 @@
[Unit]
Description=xrdp session manager
Documentation=man:xrdp-sesman(8) man:sesman.ini(5)
-After=network.target
+Wants=network-online.target nss-lookup.target nss-user-lookup.target
+After=network-online.target nss-lookup.target nss-user-lookup.target
StopWhenUnneeded=true
BindsTo=xrdp.service

11
xrdp-0.10.2-sesman.patch Normal file
View file

@ -0,0 +1,11 @@
--- xrdp-0.10.2-rc.1/sesman/sesman.ini.in.org 2024-12-24 00:36:22.000000000 +1100
+++ xrdp-0.10.2-rc.1/sesman/sesman.ini.in 2024-12-24 07:06:20.309329448 +1100
@@ -7,7 +7,7 @@ EnableUserWindowManager=true
; Give in relative path to user's home directory
UserWindowManager=startwm.sh
; Give in full path or relative path to @sesmansysconfdir@
-DefaultWindowManager=startwm.sh
+DefaultWindowManager=startwm-bash.sh
; Give in full path or relative path to @sesmansysconfdir@
ReconnectScript=reconnectwm.sh

102
xrdp-0.10.3-xrdp-ini.patch Normal file
View file

@ -0,0 +1,102 @@
--- xrdp-0.10.3/xrdp/xrdp.ini.in.org 2025-04-01 21:11:30.997621951 +1100
+++ xrdp-0.10.3/xrdp/xrdp.ini.in 2025-04-01 21:13:18.881162132 +1100
@@ -30,8 +30,8 @@ use_vsock=false
; Unprivileged User name and group to run the xrdp daemon.
; It is HIGHLY RECOMMENDED you set these values. See the xrdp.ini(5)
; manpage for more information on setting and checking these.
-#runtime_user=xrdp
-#runtime_group=xrdp
+runtime_user=xrdp
+runtime_group=xrdp
; regulate if the listening socket use socket option tcp_nodelay
; no buffering will be performed in the TCP stack
@@ -241,24 +241,24 @@ xrdpvr=true
; Some session types such as Xorg and Xvnc start a display server.
; Startup command-line parameters for the display server are configured
; in sesman.ini. See and configure also sesman.ini.
-[Xorg]
-name=Xorg
-lib=libxup.@lib_extension@
-username=ask
-password=ask
-port=-1
-code=20
+#[Xorg]
+#name=Xorg
+#lib=libxup.@lib_extension@
+#username=ask
+#password=ask
+#port=-1
+#code=20
; Frame capture interval (milliseconds)
-h264_frame_interval=16
-rfx_frame_interval=32
-normal_frame_interval=40
+#h264_frame_interval=16
+#rfx_frame_interval=32
+#normal_frame_interval=40
[Xvnc]
name=Xvnc
lib=libvnc.@lib_extension@
username=ask
password=ask
-ip=127.0.0.1
+#ip=127.0.0.1
; port is -1 (sesman controlled), numeric (TCP connection) or an
; absolute path (UDS connection).
port=-1
@@ -277,7 +277,7 @@ port=-1
; VNC password files is no longer considered secure by FIPS
;
; The default value is 0 on non-FIPS systems, and 1 on FIPS-based systems.
-#code=0
+code=1
#xserverbpp=24
#delay_ms=2000
; Disable requested encodings to support buggy VNC servers
@@ -287,13 +287,13 @@ port=-1
; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name.
-[vnc-any]
-name=vnc-any
-lib=libvnc.@lib_extension@
-ip=ask
-port=ask5900
-username=na
-password=ask
+#[vnc-any]
+#name=vnc-any
+#lib=libvnc.@lib_extension@
+#ip=ask
+#port=ask5900
+#username=na
+#password=ask
#pamusername=asksame
#pampassword=asksame
#delay_ms=2000
@@ -310,15 +310,15 @@ password=ask
; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting
; a suitable name.
-[neutrinordp-any]
-name=neutrinordp-any
+#[neutrinordp-any]
+#name=neutrinordp-any
; To use this section, you should build xrdp with configure option
; --enable-neutrinordp.
-lib=libxrdpneutrinordp.@lib_extension@
-ip=ask
-port=ask3389
-username=ask
-password=ask
+#lib=libxrdpneutrinordp.@lib_extension@
+#ip=ask
+#port=ask3389
+#username=ask
+#password=ask
; Uncomment the following lines to enable PAM authentication for proxy
; connections.
#pamusername=ask

View file

@ -0,0 +1,20 @@
--- xrdp-0.10.2-rc.1/sesman/sesman.ini.in.org 2024-12-24 07:11:02.643702480 +1100
+++ xrdp-0.10.2-rc.1/sesman/sesman.ini.in 2024-12-24 07:12:42.372540720 +1100
@@ -48,7 +48,7 @@ RestrictInboundClipboard=none
; local sockets for the session are created.
; This MUST be the same as runtime_group in xrdp.ini, or xrdp will not
; be able to connect to your sessions.
-#SessionSockdirGroup=xrdp
+SessionSockdirGroup=xrdp
[Sessions]
@@ -143,7 +143,7 @@ EnableSyslog=true
; Arch Linux : param=/usr/lib/Xorg
; FreeBSD (from 2022Q4) : param=/usr/local/libexec/Xorg
;
-param=Xorg
+param=/usr/libexec/Xorg
; Leave the rest parameters as-is unless you understand what will happen.
param=-config
param=xrdp/xorg.conf

View file

@ -1,37 +0,0 @@
diff -ruN xrdp-0.9.10-v/sesman/config.c xrdp-0.9.10/sesman/config.c
--- xrdp-0.9.10-v/sesman/config.c 2019-04-18 15:38:26.000000000 +1000
+++ xrdp-0.9.10/sesman/config.c 2019-05-03 07:59:36.784643398 +1000
@@ -179,13 +179,13 @@
g_free(cf->default_wm);
cf->default_wm = g_strdup("startwm.sh");
}
- /* if default_wm doesn't begin with '/', it's a relative path to XRDP_CFG_PATH */
+ /* if default_wm doesn't begin with '/', it's a relative path to /usr/libexec/xrdp */
if (cf->default_wm[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- length = sizeof(XRDP_CFG_PATH) + g_strlen(cf->default_wm) + 1; /* '/' */
+ length = sizeof("/usr/libexec/xrdp") + g_strlen(cf->default_wm) + 1; /* '/' */
buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->default_wm);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->default_wm);
g_free(cf->default_wm);
cf->default_wm = g_strdup(buf);
g_free(buf);
@@ -200,13 +200,13 @@
g_free(cf->reconnect_sh);
cf->reconnect_sh = g_strdup("reconnectwm.sh");
}
- /* if reconnect_sh doesn't begin with '/', it's a relative path to XRDP_CFG_PATH */
+ /* if reconnect_sh doesn't begin with '/', it's a relative path to /usr/libexec/xrdp */
if (cf->reconnect_sh[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- length = sizeof(XRDP_CFG_PATH) + g_strlen(cf->reconnect_sh) + 1; /* '/' */
+ length = sizeof("/usr/libexec/xrdp") + g_strlen(cf->reconnect_sh) + 1; /* '/' */
buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->reconnect_sh);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->reconnect_sh);
g_free(cf->reconnect_sh);
cf->reconnect_sh = g_strdup(buf);
g_free(buf);

View file

@ -1,70 +0,0 @@
diff -ruN xrdp-0.9.17-v/xrdp/xrdp.ini xrdp-0.9.17/xrdp/xrdp.ini
--- xrdp-0.9.17-v/xrdp/xrdp.ini 2021-09-01 11:32:12.000000000 +1000
+++ xrdp-0.9.17/xrdp/xrdp.ini 2021-09-01 13:06:55.525816406 +1000
@@ -203,14 +203,14 @@
; Some session types such as Xorg, X11rdp and Xvnc start a display server.
; Startup command-line parameters for the display server are configured
; in sesman.ini. See and configure also sesman.ini.
-[Xorg]
-name=Xorg
-lib=libxup.so
-username=ask
-password=ask
-ip=127.0.0.1
-port=-1
-code=20
+#[Xorg]
+#name=Xorg
+#lib=libxup.so
+#username=ask
+#password=ask
+#ip=127.0.0.1
+#port=-1
+#code=20
[Xvnc]
name=Xvnc
@@ -232,13 +232,13 @@
; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name.
-[vnc-any]
-name=vnc-any
-lib=libvnc.so
-ip=ask
-port=ask5900
-username=na
-password=ask
+#[vnc-any]
+#name=vnc-any
+#lib=libvnc.so
+#ip=ask
+#port=ask5900
+#username=na
+#password=ask
#pamusername=asksame
#pampassword=asksame
#pamsessionmng=127.0.0.1
@@ -247,15 +247,15 @@
; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting
; a suitable name.
-[neutrinordp-any]
-name=neutrinordp-any
+#[neutrinordp-any]
+#name=neutrinordp-any
; To use this section, you should build xrdp with configure option
; --enable-neutrinordp.
-lib=libxrdpneutrinordp.so
-ip=ask
-port=ask3389
-username=ask
-password=ask
+#lib=libxrdpneutrinordp.so
+#ip=ask
+#port=ask3389
+#username=ask
+#password=ask
; Uncomment the following lines to enable PAM authentication for proxy
; connections.
#pamusername=ask

View file

@ -1,12 +0,0 @@
diff -ruN xrdp-0.9.20-v/sesman/sesman.ini xrdp-0.9.20/sesman/sesman.ini
--- xrdp-0.9.20-v/sesman/sesman.ini 2022-09-15 15:59:55.000000000 +1000
+++ xrdp-0.9.20/sesman/sesman.ini 2022-09-15 17:40:10.032704634 +1000
@@ -111,7 +111,7 @@
; CentOS 8 : param=/usr/libexec/Xorg
; FreeBSD (from 2022Q4) : param=/usr/local/libexec/Xorg
;
-param=Xorg
+param=/usr/libexec/Xorg
; Leave the rest parameters as-is unless you understand what will happen.
param=-config
param=xrdp/xorg.conf

View file

@ -1,47 +0,0 @@
diff -ruN xrdp-0.9.4-v/instfiles/xrdp.service.in xrdp-0.9.4/instfiles/xrdp.service.in
--- xrdp-0.9.4-v/instfiles/xrdp.service.in 2017-07-19 14:23:49.000000000 +1000
+++ xrdp-0.9.4/instfiles/xrdp.service.in 2017-10-06 14:29:13.910973750 +1100
@@ -2,15 +2,11 @@
Description=xrdp daemon
Documentation=man:xrdp(8) man:xrdp.ini(5)
Requires=xrdp-sesman.service
-After=network.target xrdp-sesman.service
+After=xrdp-sesman.service
[Service]
-Type=forking
-PIDFile=@localstatedir@/run/xrdp.pid
-EnvironmentFile=-@sysconfdir@/sysconfig/xrdp
-EnvironmentFile=-@sysconfdir@/default/xrdp
-ExecStart=@sbindir@/xrdp $XRDP_OPTIONS
-ExecStop=@sbindir@/xrdp $XRDP_OPTIONS --kill
+EnvironmentFile=@sysconfdir@/sysconfig/xrdp
+ExecStart=@sbindir@/xrdp $XRDP_OPTIONS --nodaemon
[Install]
WantedBy=multi-user.target
diff -ruN xrdp-0.9.4-v/instfiles/xrdp-sesman.service.in xrdp-0.9.4/instfiles/xrdp-sesman.service.in
--- xrdp-0.9.4-v/instfiles/xrdp-sesman.service.in 2017-07-19 14:23:49.000000000 +1000
+++ xrdp-0.9.4/instfiles/xrdp-sesman.service.in 2017-10-06 14:29:13.910973750 +1100
@@ -1,17 +1,14 @@
[Unit]
Description=xrdp session manager
Documentation=man:xrdp-sesman(8) man:sesman.ini(5)
-After=network.target
+Wants=network-online.target nss-lookup.target nss-user-lookup.target
+After=network-online.target nss-lookup.target nss-user-lookup.target
StopWhenUnneeded=true
BindsTo=xrdp.service
[Service]
-Type=forking
-PIDFile=@localstatedir@/run/xrdp-sesman.pid
-EnvironmentFile=-@sysconfdir@/sysconfig/xrdp
-EnvironmentFile=-@sysconfdir@/default/xrdp
-ExecStart=@sbindir@/xrdp-sesman $SESMAN_OPTIONS
-ExecStop=@sbindir@/xrdp-sesman $SESMAN_OPTIONS --kill
+EnvironmentFile=@sysconfdir@/sysconfig/xrdp
+ExecStart=@sbindir@/xrdp-sesman $SESMAN_OPTIONS --nodaemon
[Install]
WantedBy=multi-user.target

View file

@ -1,12 +0,0 @@
diff -ruN xrdp-0.9.9-v/sesman/sesman.ini xrdp-0.9.9/sesman/sesman.ini
--- xrdp-0.9.9-v/sesman/sesman.ini 2018-12-25 15:49:32.000000000 +1100
+++ xrdp-0.9.9/sesman/sesman.ini 2019-01-11 19:19:42.253947862 +1100
@@ -7,7 +7,7 @@
; Give in relative path to user's home directory
UserWindowManager=startwm.sh
; Give in full path or relative path to /etc/xrdp
-DefaultWindowManager=startwm.sh
+DefaultWindowManager=startwm-bash.sh
; Give in full path or relative path to /etc/xrdp
ReconnectScript=reconnectwm.sh

View file

@ -1,11 +1,30 @@
#%PAM-1.0
# Generic Fedora config
# Generic Fedora/RHEL config - use this unless you are running xrdp
# sessions into a GNOME desktop, in which case use the Gnome-specific
# config below instead, which also unlocks GNOME Keyring automatically.
auth include password-auth
account include password-auth
password include password-auth
session include password-auth
# Gnome specific Fedora config
# pam_selinux.so close must be the first session rule so any
# prior context is torn down before we set up the new one.
session required pam_selinux.so close
session required pam_loginuid.so
# pam_selinux.so open must run before any module below that
# should execute in the user's context. Without this pair,
# session processes are left running as unconfined_service_t
# instead of unconfined_t. See rhbz#2499948.
session required pam_selinux.so open
session required pam_namespace.so
session optional pam_keyinit.so force revoke
session include password-auth
session optional pam_lastlog.so silent
# Gnome specific config. Uncomment this block and comment out the
# generic block above if you are running xrdp sessions into a GNOME
# desktop. This uses GDM's own PAM stack, which already includes the
# correct pam_selinux.so/pam_namespace.so ordering and additionally
# unlocks GNOME Keyring automatically at login.
#auth include gdm-password
#account include gdm-password
#password include gdm-password

2
xrdp-tmpfiles.conf Normal file
View file

@ -0,0 +1,2 @@
d /run/xrdp 0755 root root -
R /run/xrdp 0755 root root -

410
xrdp.spec
View file

@ -1,3 +1,5 @@
#%%global prerelease -rc.1
%global _hardened_build 1
%global selinux_types %(%{__awk} '/^#[[:space:]]*SELINUXTYPE=/,/^[^#]/ { if ($3 == "-") printf "%s ", $2 }' /etc/selinux/config 2>/dev/null)
@ -13,30 +15,36 @@
%global _missing_braces -Wno-error=missing-braces
%endif
%ifarch %{ix86}
%global _file_offset_bits -D_FILE_OFFSET_BITS=64
%endif
Summary: Open source remote desktop protocol (RDP) server
Name: xrdp
Epoch: 1
Version: 0.9.22
Version: 0.10.6.1
Release: 3%{?dist}
License: ASL 2.0 and GPLv2+ and MIT
# Automatically converted from old format: ASL 2.0 and GPLv2+ and MIT - review is highly recommended.
License: Apache-2.0 AND GPL-2.0-or-later AND LicenseRef-Callaway-MIT
URL: http://www.xrdp.org/
Source0: https://github.com/neutrinolabs/xrdp/releases/download/v%{version}/xrdp-%{version}.tar.gz
Source0: https://github.com/neutrinolabs/xrdp/releases/download/v%{version}%{?prerelease}/xrdp-%{version}%{?prerelease}.tar.gz
Source1: xrdp-sesman.pamd
Source2: xrdp.sysconfig
Source3: xrdp.logrotate
Source4: openssl.conf
Source5: README.Fedora
Source5: README.md
Source6: xrdp.te
Source7: xrdp-polkit-1.rules
Patch0: xrdp-0.9.9-sesman.patch
Patch1: xrdp-0.9.17-xrdp-ini.patch
Patch2: xrdp-0.9.4-service.patch
Patch3: xrdp-0.9.10-scripts-libexec.patch
Source8: %{name}-tmpfiles.conf
Source9: %{name}.sysusers
Patch0: xrdp-0.10.2-sesman.patch
Patch2: xrdp-0.10.1-service.patch
Patch3: xrdp-0.10.0-scripts-libexec.patch
Patch4: xrdp-0.9.6-script-interpreter.patch
Patch5: xrdp-0.9.16-arch.patch
Patch6: xrdp-0.9.18-vnc-uninit.patch
%if 0%{?fedora} >= 32 || 0%{?rhel} >= 8
Patch7: xrdp-0.9.20-sesman-ini.patch
Patch8: xrdp-0.10.5-sesman-ini.patch
%endif
BuildRequires: make
@ -48,20 +56,29 @@ BuildRequires: libXrandr-devel
BuildRequires: imlib2-devel
BuildRequires: openssl
BuildRequires: pam-devel
BuildRequires: pkgconfig(fuse)
BuildRequires: pkgconfig(fuse3)
BuildRequires: pkgconfig(openssl)
BuildRequires: pkgconfig(pixman-1)
BuildRequires: pkgconfig(systemd)
BuildRequires: nasm
%if 0%{?fedora} || 0%{?rhel} > 8
BuildRequires: noopenh264-devel
%endif
BuildRequires: checkpolicy, selinux-policy-devel
BuildRequires: %{_hardlink}
BuildRequires: systemd-rpm-macros
%if 0%{?fedora} < 42 || 0%{?rhel}
%{?sysusers_requires_compat}
%endif
# tigervnc-server-minimal provides Xvnc (default for now)
# xorgxrdp is another back end, depends on specific Xorg binary, omit
Requires: tigervnc-server-minimal
Requires: xorg-x11-xinit
Requires: util-linux
Requires: fuse3
%if 0%{?fedora} || 0%{?rhel} >= 8
Recommends: %{name}-selinux = %{epoch}:%{version}-%{release}
@ -72,12 +89,17 @@ Requires(post): systemd-sysv
Requires(post): /sbin/ldconfig
Requires(posttrans): openssl
Requires(preun): systemd
%if 0%{?fedora}
Requires(preun): systemd-tmpfiles
%endif
Requires(posttrans): systemd
%package devel
Summary: Headers and pkg-config files needed to compile xrdp backends
Requires: %{name} = %{epoch}:%{version}-%{release}
%description
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.
@ -90,7 +112,9 @@ talk to xrdp.
Summary: SELinux policy module required tu run xrdp
Requires: %{name} = %{epoch}:%{version}-%{release}
%if "%{_selinux_policy_version}" != ""
Requires: selinux-policy >= %{_selinux_policy_version}
%endif
Requires(post): /usr/sbin/semodule
Requires(postun): /usr/sbin/semodule
@ -98,7 +122,7 @@ Requires(postun): /usr/sbin/semodule
This package contains SELinux policy module necessary to run xrdp.
%prep
%autosetup -p1
%autosetup -p1 -n %{name}-%{version}%{?prerelease}
%{__cp} %{SOURCE5} .
# SELinux policy module
@ -111,9 +135,19 @@ echo '#!/bin/bash -l
%build
autoreconf -vif
CFLAGS="$RPM_OPT_FLAGS %{?_missing_braces}" \
%configure --enable-fuse --enable-pixman --enable-painter --enable-vsock \
--enable-ipv6 --with-socketdir=%{_rundir}/%{name} --with-imlib2
CFLAGS="$RPM_OPT_FLAGS %{?_missing_braces} %{?_file_offset_bits}" \
%configure --enable-fuse \
--enable-pixman \
--enable-painter \
--enable-vsock \
--enable-ipv6 \
%if 0%{?fedora} || 0%{?rhel} > 8
--enable-openh264 \
%endif
--enable-utmp \
--with-socketdir=%{_rundir}/%{name} \
--with-imlib2
%make_build
# SELinux policy module
@ -151,6 +185,10 @@ cd -
#install xrdp.rules /usr/share/polkit-1/rules.d
%{__install} -Dp -m 644 %{SOURCE7} %{buildroot}%{_datadir}/polkit-1/rules.d/xrdp.rules
# Temporary files for socket
%{__mkdir_p} %{buildroot}%{_tmpfilesdir}
%{__install} -m 0644 %{SOURCE8} %{buildroot}%{_tmpfilesdir}/%{name}.conf
# SELinux policy module
for selinuxvariant in %{selinux_variants}
do
@ -160,6 +198,13 @@ do
done
%{_hardlink} -cv %{buildroot}%{_datadir}/selinux
%{__install} -p -D -m 0644 %{SOURCE9} %{buildroot}%{_sysusersdir}/xrdp.conf
%if 0%{?fedora} < 42 || 0%{?rhel}
%pre
%sysusers_create_compat %{SOURCE9}
%endif
%post
%{?ldconfig}
%systemd_post xrdp.service
@ -168,36 +213,42 @@ done
%systemd_preun xrdp.service
if [ $1 -eq 0 ]; then
# Stop services on package removal (see bug 1349083)
systemctl stop xrdp.service > /dev/null 2>&1 || :
systemctl stop xrdp.service &>/dev/null || :
systemd-tmpfiles --remove %{name}.conf &>/dev/null || :
fi
%triggerun -- xrdp < 0.6.0-1
systemd-sysv-convert --save xrdp >/dev/null 2>&1 ||:
systemd-sysv-convert --save xrdp &>/dev/null || :
# If the package is allowed to autostart:
systemctl preset xrdp.service >/dev/null 2>&1 ||:
systemctl preset xrdp.service &>/dev/null || :
# Run these because the SysV package being removed won't do them
/sbin/chkconfig --del xrdp >/dev/null 2>&1 || :
/sbin/chkconfig --del xrdp &>/dev/null || :
if [ "`systemctl is-active xrdp.service`" = 'active' ]; then
systemctl stop xrdp.service >/dev/null 2>&1 || :
systemctl start xrdp.service >/dev/null 2>&1 || :
systemctl stop xrdp.service &>/dev/null || :
systemctl start xrdp.service &>/dev/null || :
fi
%ldconfig_postun
%posttrans
if [ ! -s %{_sysconfdir}/xrdp/rsakeys.ini ]; then
(umask 377; touch %{_sysconfdir}/xrdp/rsakeys.ini; %{_bindir}/xrdp-keygen xrdp %{_sysconfdir}/xrdp/rsakeys.ini &>/dev/null)
(umask 0137
%{_bindir}/xrdp-keygen xrdp %{_sysconfdir}/xrdp/rsakeys.ini &>/dev/null)
fi
if [ ! -s %{_sysconfdir}/xrdp/cert.pem ]; then
(umask 377; openssl req -x509 -newkey rsa:2048 -sha256 -nodes -days 3652 \
-keyout %{_sysconfdir}/xrdp/key.pem \
-out %{_sysconfdir}/xrdp/cert.pem \
-config %{_sysconfdir}/xrdp/openssl.conf >/dev/null 2>&1)
(umask 0337
openssl req -x509 -newkey rsa:2048 -nodes -days 3652 \
-keyout %{_sysconfdir}/xrdp/key.pem \
-out %{_sysconfdir}/xrdp/cert.pem \
-config %{_sysconfdir}/xrdp/openssl.conf &>/dev/null)
fi
chgrp xrdp %{_sysconfdir}/xrdp/{rsakeys.ini,{key,cert}.pem}
chmod 0640 %{_sysconfdir}/xrdp/{rsakeys.ini,{key,cert}.pem}
%post selinux
for selinuxvariant in %{selinux_variants}
do
@ -215,12 +266,14 @@ fi
%files
%doc COPYING README.Fedora
%doc COPYING README.md
%dir %{_libdir}/xrdp
%dir %{_sysconfdir}/xrdp
%dir %{_sysconfdir}/xrdp/pulse
%dir %{_datadir}/xrdp
%dir %{_libexecdir}/xrdp
%{_tmpfilesdir}/%{name}.conf
%{_sysusersdir}/xrdp.conf
%config(noreplace) %{_sysconfdir}/xrdp/xrdp.ini
%config(noreplace) %{_sysconfdir}/pam.d/xrdp-sesman
%config(noreplace) %{_sysconfdir}/logrotate.d/xrdp
@ -229,16 +282,21 @@ fi
%config(noreplace) %{_sysconfdir}/xrdp/km*.ini
%config(noreplace) %{_sysconfdir}/xrdp/openssl.conf
%config(noreplace) %{_sysconfdir}/xrdp/xrdp_keyboard.ini
%config(noreplace) %{_sysconfdir}/xrdp/gfx.toml
%config(noreplace) %{_sysconfdir}/xrdp/pulse/default.pa
%exclude %ghost %{_sysconfdir}/xrdp/*.pem
%exclude %ghost %{_sysconfdir}/xrdp/rsakeys.ini
%{_libexecdir}/xrdp/startwm*.sh
%{_libexecdir}/xrdp/reconnectwm.sh
%{_libexecdir}/xrdp/waitforx
%{_libexecdir}/xrdp/xrdp-sesexec
%{_libexecdir}/xrdp/xrdp-droppriv
%{_bindir}/xrdp-genkeymap
%{_bindir}/xrdp-sesadmin
%{_bindir}/xrdp-keygen
%{_bindir}/xrdp-sesrun
%{_bindir}/xrdp-dis
%{_bindir}/xrdp-dumpfv1
%{_sbindir}/xrdp-chansrv
%{_sbindir}/xrdp
%{_sbindir}/xrdp-sesman
@ -247,15 +305,21 @@ fi
%{_datadir}/xrdp/cursor1.cur
%{_datadir}/xrdp/xrdp256.bmp
%{_datadir}/xrdp/sans-10.fv1
%{_datadir}/xrdp/sans-18.fv1
%{_datadir}/xrdp/ad24b.bmp
%{_datadir}/xrdp/xrdp24b.bmp
%{_datadir}/xrdp/xrdp_logo.bmp
%{_datadir}/xrdp/xrdp_logo.png
%{_datadir}/xrdp/xrdp-chkpriv
%{_datadir}/xrdp/README.logo
%{_datadir}/polkit-1/rules.d/xrdp.rules
%{_mandir}/man5/*
%{_mandir}/man8/*
%{_mandir}/man1/*
%{_libdir}/xrdp/lib*.so.*
%exclude %{_libdir}/xrdp/lib*.so
%{_libdir}/xrdp/lib*.so*
%exclude %{_libdir}/xrdp/libcommon.so
%exclude %{_libdir}/xrdp/libxrdp.so
%exclude %{_libdir}/xrdp/libxrdpapi.so
%{_unitdir}/xrdp-sesman.service
%{_unitdir}/xrdp.service
%exclude %{_includedir}/painter.h
@ -275,6 +339,10 @@ fi
%{_includedir}/ms-*
%{_includedir}/xrdp*
%{_includedir}/rfxcodec_*.h
%{_libdir}/xrdp/libcommon.so
%{_libdir}/xrdp/libxrdp.so
%{_libdir}/xrdp/libxrdpapi.so
%{_libdir}/pkgconfig/rfxcodec.pc
%{_libdir}/pkgconfig/xrdp.pc
%files selinux
@ -282,90 +350,246 @@ fi
%{_datadir}/selinux/*/%{name}.pp
%changelog
* Mon May 8 2023 Bojan Smojver <bojan@rexurive.com> - 1:0.9.22-3
* Sat Jul 18 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6.1-3
- Fix bug #2499948
* Tue Jul 07 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6.1-1
- Update to 0.10.6.1
- CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
- CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
- CVE-2026-55639, CVE-2026-55645
* Sat Jun 13 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1:0.10.6-3
- Rebuilt for openssl 4.0
* Fri May 22 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6-2
- close TCP port in default Xvnc config, Unix domain socket only
* Sat Apr 18 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6-1
- Update to 0.10.6
- CVE-2026-32105, CVE-2026-32107, CVE-2026-32623, CVE-2026-32624
- CVE-2026-33145, CVE-2026-33516, CVE-2026-33689, CVE-2026-35512
* Wed Jan 28 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.5-1
- Update to 0.10.5
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.4-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Tue Nov 4 2025 Tom Callaway <spot@fedoraproject.org> - 1:0.10.4-4
- rebuild for new fuse3
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 7 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.4-2
- Patch upstream issue #3558, fix by matt335672
* Thu Jul 3 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.4-1
- Update to 0.10.4
* Tue Apr 1 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.3-1
- Update to 0.10.3
- Enable Xvnc over Unix domain socket
* Wed Mar 26 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-13
- Rebuild for noopenh264 2.6.0, once more
* Thu Mar 13 2025 Fabio Valentini <decathorpe@gmail.com> - 1:0.10.2-12
- Rebuild for noopenh264 2.6.0
* Thu Mar 6 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-11
- Drop call to %sysusers_create_compat only in Fedora 42 and above
- Add fuse3 dependency BZ#2350108
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 1:0.10.2-10
- Drop call to %sysusers_create_compat
* Thu Feb 6 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-9
- Add utmp support contributed upstream by Magnus Lewis-Smith
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.2-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Sun Jan 5 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-7
- Comment out generic RDP proxy in xrdp.ini
* Sun Jan 5 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-6
- Set permissions of cert, key and rsakeys.ini to 0640
- Revert optional dependency on noopenh264, library dependency exists
* Fri Dec 27 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-5
- Move README.Fedora to README.md
- Adjust ownership/permissions of certs/keys for unprivileged user
* Thu Dec 26 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-4
- If openh264 is not present, require noopenh264 instead
* Wed Dec 25 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-3
- Run as unprivileged user
* Wed Dec 25 2024 Koichiro Iwao <meta@almalinux.org> - 1:0.10.2-2
- Enable OpenH264
* Wed Dec 25 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-1
- Update to 0.10.2
* Tue Dec 24 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2~0.rc1.1
- Update to 0.10.2-rc.1
* Wed Sep 4 2024 Miroslav Suchý <msuchy@redhat.com> - 1:0.10.1-2
- convert license to SPDX
* Wed Jul 31 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.1-1
- Update to 0.10.1
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sat Jun 1 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-4
- Explain downgrades from 0.10.x to 0.9.x in README.Fedora
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-3
- Only require systemd-tmpfiles on Fedora
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-2
- Explicitly run systemd-tmpfiles --remove on package removal BZ#2279775
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-1
- Update to 0.10.0
- Revert PR 2994
* Wed Apr 03 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-0.beta.2
- Update to 0.10.0-beta.2
* Wed Mar 13 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.9.25-2
- Add upstream PR 2994
* Tue Mar 12 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.9.25-1
- Update to 0.9.25
* Mon Mar 11 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-0.beta.1
- Update to 0.10.0-beta.1
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.24-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Dec 31 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.24-1
- Update to 0.9.24
- Remove already applied patch affecting compilation on EL7
* Thu Sep 28 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.23.1-1
- Update to 0.9.23.1
- CVE-2023-42822
* Fri Sep 1 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.23-1
- Update to 0.9.23
- CVE-2023-40184
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.22.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Tue Jun 13 2023 Leigh Scott <leigh123linux@gmail.com> - 1:0.9.22.1-3
- Rebuild fo new imlib2
* Tue May 23 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22.1-2
- Remove C99 loop initialisation on EPEL7
* Tue May 23 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22.1-1
- Update to 0.9.22.1
* Fri May 19 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22-5
- Patch session chooser segfault
- Bugs #2208015 and #2208248
* Wed May 17 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22-4
- Put back .so files into %%_libdir/xrdp directory
- Bug #2207733
* Mon May 8 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22-3
- Exclude rfxcodec.pc - shared library no longer created
* Sun May 7 2023 Bojan Smojver <bojan@rexurive.com> - 1:0.9.22-2
* Sun May 7 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22-2
- Explicitly exclude .la files on RHEL
* Sun May 7 2023 Bojan Smojver <bojan@rexurive.com> - 1:0.9.22-1
* Sun May 7 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.22-1
- Bump up to 0.9.22
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.21-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sun Dec 11 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.21-1
* Sun Dec 11 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.21-1
- Bump up to 0.9.21
- CVE-2022-23468 CVE-2022-23477 CVE-2022-23478 CVE-2022-23479 CVE-2022-23480
- CVE-2022-23481 CVE-2022-23483 CVE-2022-23482 CVE-2022-23484 CVE-2022-23493
* Thu Sep 15 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.20-1
* Thu Sep 15 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.20-1
- Bump up to 0.9.20
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.19-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Mar 17 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.19-1
* Thu Mar 17 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.19-1
- Bump up to 0.9.19
* Tue Feb 8 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.18-5
* Tue Feb 8 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.18-5
- Add patch for CVE-2022-23613
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.18-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jan 14 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.18-3
* Fri Jan 14 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.18-3
- Add patch for imlib2 on RHEL7/8
* Wed Jan 12 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.18-2
* Wed Jan 12 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.18-2
- Bump release up for rebuild
* Tue Jan 11 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.18-1
* Tue Jan 11 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.18-1
- Bump up to 0.9.18
* Sat Jan 8 2022 Bojan Smojver <bojan@rexurive.com> - 1:0.9.17-6
* Sat Jan 8 2022 Bojan Smojver <bojan@rexursive.com> - 1:0.9.17-6
- Adjust hardlink condition for EPEL 9
* Thu Dec 9 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.17-5
* Thu Dec 9 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.17-5
- Enable (experimental) IPv6 support (bug #2028630)
* Thu Nov 11 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.17-4
* Thu Nov 11 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.17-4
- Add -Wno-error=deprecated-declarations to CFLAGS to avoid build errors
* Tue Sep 14 2021 Sahana Prasad <sahana@redhat.com> - 1:0.9.17-3
- Rebuilt with OpenSSL 3.0.0
* Mon Sep 6 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.17-2
* Mon Sep 6 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.17-2
- Trivially implement missing rfb_get_eds_status_msg() function
* Wed Sep 1 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.17-1
* Wed Sep 1 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.17-1
- Bump up to 0.9.17
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.16-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Wed Jul 14 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.16-2
* Wed Jul 14 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.16-2
- Bring logrotate file in line with defaults (BZ #1977175).
* Sat May 1 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.16-1
* Sat May 1 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.16-1
- Bump up to 0.9.16
* Thu Jan 28 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.15-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Sat Jan 2 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.15-3
* Sat Jan 2 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.15-3
- Remove setpriv patch and adjust SELinux policy to match
* Fri Jan 1 2021 Bojan Smojver <bojan@rexurive.com> - 1:0.9.15-2
* Fri Jan 1 2021 Bojan Smojver <bojan@rexursive.com> - 1:0.9.15-2
- Use /usr/libexec/Xorg or Xorg session of Fedora and RHEL8+
* Tue Dec 29 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.15-1
* Tue Dec 29 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.15-1
- Bump up to 0.9.15
* Tue Sep 1 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.14-3
* Tue Sep 1 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.14-3
- Add a patch for uninitialised variables, courtesy of Dan Horák
* Mon Aug 31 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.14-2
* Mon Aug 31 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.14-2
- Bump up to 0.9.14
- Add a set of patches to deal with new GCC warnings/errors
- Do not emit warning on failed architecture detection
@ -378,14 +602,14 @@ fi
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.13.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Jun 30 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.13.1-1
* Tue Jun 30 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.13.1-1
- Bump up to 0.9.13.1
- CVE-2022-4044
* Thu May 14 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.13-2
* Thu May 14 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.13-2
- Move sockets to /run/xrdp, bug #1834178
* Wed Mar 11 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.13-1
* Wed Mar 11 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.13-1
- Bump up to 0.9.13
* Sat Feb 22 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.12-6
@ -395,98 +619,98 @@ fi
* Thu Feb 20 2020 Tom Callaway <spot@fedoraproject.org> - 1:0.9.12-5
- fix license tag (bz1804932)
* Thu Jan 30 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.12-4
* Thu Jan 30 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.12-4
- README.Fedora: VSOCK support
- README.Fedora: possibly incorrect SELinux context of the sessions
- Add polkit-1 rules for colord access and repo refresh
* Mon Jan 13 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.12-3
* Mon Jan 13 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.12-3
- Add vsock items to SELinux policy (thanks to mm19827 of gmail.com)
* Sun Jan 12 2020 Bojan Smojver <bojan@rexurive.com> - 1:0.9.12-2
* Sun Jan 12 2020 Bojan Smojver <bojan@rexursive.com> - 1:0.9.12-2
- Enable vsock (bug #1787953)
* Sun Dec 29 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.12-1
* Sun Dec 29 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.12-1
- Bump up to 0.9.12
* Mon Sep 23 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.11-5
* Mon Sep 23 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.11-5
- Make xrdp-selinux a weak dependency on versions that support them.
- Drop xrdp-selinux dependency completely.
* Sun Sep 15 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.11-3
* Sun Sep 15 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.11-3
- Decouple xrdp from xorgxrdp, causing repeated installation issues in RHEL.
* Tue Aug 27 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.11-2
* Tue Aug 27 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.11-2
- Increment release for rebuild in F31.
* Thu Aug 22 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.11-1
* Thu Aug 22 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.11-1
- Bump up to 0.9.11
* Sat Aug 10 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.10-3
* Sat Aug 10 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.10-3
- Make sure rsakeys.ini exists (bug #1739176).
* Sat Jul 27 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.10-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri May 3 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.10-1
* Fri May 3 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.10-1
- Bump up to 0.9.10
* Sun Feb 03 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.9-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jan 11 2019 Bojan Smojver <bojan@rexurive.com> - 1:0.9.9-1
* Fri Jan 11 2019 Bojan Smojver <bojan@rexursive.com> - 1:0.9.9-1
- Bump up to 0.9.9
- Fix sesman.ini patch
- Fix xrdp.ini patch
* Wed Nov 14 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.8-2
* Wed Nov 14 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.8-2
- Make main and selinux packages codependent
* Wed Sep 26 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.8-1
* Wed Sep 26 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.8-1
- Bump up to 0.9.8
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Wed Jul 4 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.7-1
* Wed Jul 4 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.7-1
- Bump up to 0.9.7
* Mon Apr 23 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.6-4
* Mon Apr 23 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.6-4
- mark files in /etc/xrdp/pulse as configs
- add null command on postun, so that it is never empty
* Mon Apr 23 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.6-3
* Mon Apr 23 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.6-3
- mark files in /etc/xrdp as configs
- run ldconfig
- remove chmod of certs/keys
- fix script interpreter
* Sun Apr 22 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.6-2
* Sun Apr 22 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.6-2
- Allow oddjob-mkhomedir in SELinux policy (stolen from grishin-a)
- Allow no new privileges transition in SELinux policy
* Tue Mar 27 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.6-1
* Tue Mar 27 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.6-1
- Bump up to 0.9.6
* Fri Mar 9 2018 Bojan Smojver <bojan@rexurive.com> - 1:0.9.5-2
* Fri Mar 9 2018 Bojan Smojver <bojan@rexursive.com> - 1:0.9.5-2
- add gcc build requirement
* Fri Feb 09 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> - 1:0.9.5-2
- Escape macros in %%changelog
* Sat Dec 30 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.5-1
* Sat Dec 30 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.5-1
- Bump up to 0.9.5
* Fri Nov 24 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.4-2
* Fri Nov 24 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.4-2
- Patch CVE-2017-16927
* Fri Oct 6 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.4-1
* Fri Oct 6 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.4-1
- Bump up to 0.9.4
* Tue Sep 19 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.3-2
* Tue Sep 19 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.3-2
- Add patch to clean up sockets
* Thu Aug 10 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.3-1
* Thu Aug 10 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.3-1
- Bump up to 0.9.3
* Thu Aug 03 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.2-14
@ -495,46 +719,46 @@ fi
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.2-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Thu May 18 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-12
* Thu May 18 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-12
- Document problems/workaround with clipboard support in TigerVNC 1.8.0
* Thu May 18 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-11
* Thu May 18 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-11
- Add a patch that allows equal signs in ini file values
* Thu Apr 13 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-10
* Thu Apr 13 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-10
- Use epoch in version dependency
- Provide selinux sub-package scriptlets
* Thu Apr 13 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-9
* Thu Apr 13 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-9
- Adjust Fedora README file for SELinux changes
* Wed Apr 12 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-8
* Wed Apr 12 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-8
- Add SELinux policy sub-package
* Tue Apr 11 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-7
* Tue Apr 11 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-7
- Own /usr/libexec/xrdp directory
* Tue Apr 11 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-6
* Tue Apr 11 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-6
- Move scripts to /usr/libexec/xrdp, so that they get labelled as bin_t
* Sat Apr 8 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-5
* Sat Apr 8 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-5
- Rework call to Xorg to use setpriv instead, properly
* Fri Apr 7 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-4
* Fri Apr 7 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-4
- Do not call prctl() from xrdp, use setpriv instead
* Tue Apr 4 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-3
* Tue Apr 4 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-3
- Do not attempt xrdp restarts, may cause dnf transaction problems
- Stop depending on Xorg server, xorgxrdp already does
- Add README.Fedora
* Mon Apr 3 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-2
* Mon Apr 3 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-2
- Stop using /usr/libexec/Xorg, not present on EL7
* Fri Mar 31 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.2-1
* Fri Mar 31 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.2-1
- Bump up to 0.9.2
* Tue Mar 14 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.1-8
* Tue Mar 14 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.1-8
- Require tigervnc-server-minimal again, make it default
- Comment out references to X11rdp
@ -548,14 +772,14 @@ fi
- Make Xorg backend default
- Call /usr/libexec/Xorg directly to avoid permission checks
* Tue Feb 21 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.1-5
* Tue Feb 21 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.1-5
- Require openssl in posttrans phase
- Move conditional restart to posttrans phase
* Mon Feb 20 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.1-4
* Mon Feb 20 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.1-4
- Move key/cert generation to posttrans stage
* Thu Feb 16 2017 Bojan Smojver <bojan@rexurive.com> - 1:0.9.1-3
* Thu Feb 16 2017 Bojan Smojver <bojan@rexursive.com> - 1:0.9.1-3
- Fix log file rotation
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.1-2

2
xrdp.sysusers Normal file
View file

@ -0,0 +1,2 @@
#Type Name ID GECOS Home directory Shell
u xrdp - "Unprivileged xrdp user" /run/xrdp /sbin/nologin