Compare commits

...
Sign in to create a new pull request.

63 commits

Author SHA1 Message Date
Bojan Smojver
ded6843d0a Bump release for rebuild 2026-07-18 08:09:58 +10:00
Bojan Smojver
950bca1572 Replace m-dashes with hyphens 2026-07-18 08:06:58 +10:00
Bojan Smojver
da773d7b96 Fix epoch/release bump 2026-07-17 18:13:33 +10:00
Bojan Smojver
840ef696de Fix changelog 2026-07-17 18:06:43 +10:00
Bojan Smojver
7691357362 Fix bug #2499948
Update to 0.10.6.1
CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
CVE-2026-55639, CVE-2026-55645
2026-07-17 18:03:54 +10:00
Bojan Smojver
94b6f4aba2 Upload new source tarball 2026-07-07 19:49:14 +10:00
Bojan Smojver
f339e61176 Update to 0.10.6.1
CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
CVE-2026-55639, CVE-2026-55645
2026-07-07 19:33:24 +10:00
Bojan Smojver
8206f1cde6 Revert "Close TCP port in default Xvnc config, Unix domain socket only"
This reverts commit abcf261e6c.
2026-07-07 19:18:11 +10:00
Bojan Smojver
5c0c4355e8 Revert "close TCP port in default Xvnc config, Unix domain socket only"
This reverts commit 9da935c087.
2026-07-07 19:02:39 +10:00
Yaakov Selkowitz
15b67bfea5 Rebuilt for openssl 4.0 2026-06-12 20:08:57 -04:00
Bojan Smojver
9da935c087 close TCP port in default Xvnc config, Unix domain socket only 2026-05-22 05:15:19 +10:00
Bojan Smojver
abcf261e6c Close TCP port in default Xvnc config, Unix domain socket only 2026-05-22 05:11:45 +10:00
Bojan Smojver
13a9c73444 Update to 0.10.6 2026-04-18 08:23:21 +10:00
Bojan Smojver
500f161a30 Update to 0.10.5 2026-01-28 18:41:05 +11:00
Fedora Release Engineering
e70d849749 Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild 2026-01-17 20:52:58 +00:00
Tom spot Callaway
31a153d643 rebuild for new fuse3 2025-11-04 16:52:43 -05:00
Fedora Release Engineering
8473a1b002 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 21:03:48 +00:00
Bojan Smojver
bfa74ff263 Add vmconnect patch 2025-07-07 20:41:58 +10:00
Bojan Smojver
a468304b66 Patch upstream issue #3558, fix by matt335672 2025-07-07 20:33:56 +10:00
Bojan Smojver
fc1c271a1f Update to 0.10.4 2025-07-04 07:16:35 +10:00
Bojan Smojver
58d96b27c6 Enable Xvnc over Unix domain socket 2025-04-01 21:15:51 +11:00
Bojan Smojver
8631180d0b Update to 0.10.3 2025-04-01 21:00:15 +11:00
Bojan Smojver
253e64e7ca Rebuild for noopenh264 2.6.0, once more 2025-03-26 06:29:12 +11:00
Fabio Valentini
be9a73e597
Rebuild for noopenh264 2.6.0 2025-03-13 18:49:20 +01:00
Bojan Smojver
48c3c0c869 Add fuse3 dependency 2025-03-06 15:20:41 +11:00
63cd7fae8e Drop call to %sysusers_create_compat
After https://fedoraproject.org/wiki/Changes/RPMSuportForSystemdSysusers,
rpm will handle account creation automatically.
2025-02-11 18:03:12 +01:00
Bojan Smojver
bb831b9e36 Add utmp support contributed upstream by Magnus Lewis-Smith 2025-02-06 11:46:11 +11:00
mlewissmith
560f7a2003 Add utmp support
Addresses RHBZ#2339004

- Backport https://github.com/neutrinolabs/xrdp/pull/3400
- Build with necessary build flag '--enable-utmp'
- Update xrdp-sesman.pamd accordingly
2025-02-06 11:43:15 +11:00
Bojan Smojver
0a6bb02d7a Document KDE Plasma specific info 2025-01-25 16:27:06 +11:00
Fedora Release Engineering
301178bcb7 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 16:16:31 +00:00
Bojan Smojver
0fb0287ee9 Comment out generic RDP proxy in xrdp.ini 2025-01-05 21:21:58 +11:00
Bojan Smojver
9bea902969 Remove noopenh264 dep, adjust permissions of SSL related files 2025-01-05 14:13:43 +11:00
Bojan Smojver
a6aced6f40 Correct README.md source 2024-12-27 07:39:27 +11:00
Bojan Smojver
7ee2e171cd Adjust ownership/permissions of certs/keys for unprivileged user 2024-12-27 07:26:15 +11:00
Bojan Smojver
00ae909eea If openh264 is not present, require noopenh264 instead 2024-12-26 16:55:06 +11:00
Bojan Smojver
7f62e9d274 Add unprivileged user section to README file 2024-12-26 15:56:21 +11:00
Bojan Smojver
52c9861931 Add sysusers file, do not build with H264 on EPEL8 2024-12-25 22:58:17 +11:00
Bojan Smojver
2d02bc5324 Add xrdp sysusers 2024-12-25 22:43:39 +11:00
Bojan Smojver
bbe715feef Run as unprivileged user 2024-12-25 22:41:32 +11:00
Koichiro Iwao
c80b7cb47c Enable OpenH264 2024-12-25 06:15:04 +00:00
Bojan Smojver
b51e0d04c7 Do not expand macro in comment 2024-12-25 07:39:32 +11:00
Bojan Smojver
a26ce0ad01 Update to 0.10.2 2024-12-25 07:37:18 +11:00
Bojan Smojver
a9de146d17 Update to 0.10.2-rc.1 2024-12-24 08:13:31 +11:00
Miroslav Suchý
ee4d59ab85 convert license to SPDX
This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4
2024-09-04 22:57:36 +02:00
Bojan Smojver
6548d8b7d3 Update to 0.10.1 2024-08-01 00:09:28 +10:00
Fedora Release Engineering
25fb61557c Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-20 10:26:46 +00:00
Bojan Smojver
e33983fa06 Fix release number 2024-06-01 20:23:12 +10:00
Bojan Smojver
0ab794b1a6 Explain downgrades from 0.10.x to 0.9.x in README.Fedora 2024-06-01 20:21:07 +10:00
Bojan Smojver
5004123f25 Do not fail if systemd-tmpfiles fails 2024-05-14 23:18:28 +10:00
Bojan Smojver
3bbe3491d8 Bump release for rebuild 2024-05-14 22:58:03 +10:00
Bojan Smojver
61320c3a12 Only require systemd-tmpfiles on Fedora 2024-05-14 22:56:21 +10:00
Bojan Smojver
bdb793303a Fix changelog order 2024-05-14 19:41:17 +10:00
Bojan Smojver
60542e6e4c Explicitly run systemd-tmpfiles --remove on package removal 2024-05-14 18:37:45 +10:00
Bojan Smojver
6b29715e1a Revert "Add upstream PR 2994"
This reverts commit d09880d4ca.
2024-05-14 15:58:57 +10:00
Bojan Smojver
dd8024580d Merge branch '0.10.0' into rawhide 2024-05-14 15:33:34 +10:00
Bojan Smojver
33857e65c9 Update to 0.10.0 final, add tmpfiles.conf 2024-05-14 15:23:45 +10:00
Bojan Smojver
9e82f0d656 Update to 0.10.0-beta.2 2024-04-03 11:14:41 +11:00
Bojan Smojver
d09880d4ca Add upstream PR 2994 2024-03-13 13:17:49 +11:00
Bojan Smojver
d2f8963baa Update to 0.9.25 2024-03-12 09:59:41 +11:00
Bojan Smojver
05b4d9a5b9 Initial work on build of 0.10.0 2024-03-12 09:29:28 +11:00
Fedora Release Engineering
4252753eb9 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-27 10:08:54 +00:00
Bojan Smojver
add9bfa264 Remove already applied patch affecting compilation on EL7 2023-12-31 11:49:46 +11:00
Bojan Smojver
14612e89c8 Update to 0.9.24 2023-12-31 09:51:24 +11:00
19 changed files with 550 additions and 304 deletions

11
.gitignore vendored
View file

@ -29,3 +29,14 @@ xrdp-cvs-03-17-2010.tar.gz
/xrdp-0.9.22.1.tar.gz
/xrdp-0.9.23.tar.gz
/xrdp-0.9.23.1.tar.gz
/xrdp-0.9.24.tar.gz
/xrdp-0.9.25.tar.gz
/xrdp-0.10.0.tar.gz
/xrdp-0.10.1.tar.gz
/xrdp-0.10.2-rc.1.tar.gz
/xrdp-0.10.2.tar.gz
/xrdp-0.10.3.tar.gz
/xrdp-0.10.4.tar.gz
/xrdp-0.10.5.tar.gz
/xrdp-0.10.6.tar.gz
/xrdp-0.10.6.1.tar.gz

View file

@ -1,72 +0,0 @@
Restarts
========
Service restarts after RPM package upgrades have been disabled on purpose.
This is to avoid a situation where an update is performed from within a
session running on xrdp, which can then cause dnf to only perform part of the
transaction and leave the system in a state that requires further manual
intervention, including removal of duplicate packages etc.
So, it will be up to the user/admin to restart xrdp service after any RPM
package upgrade. This is in line with what other GUI systems like Xorg and
Wayland do.
xorgxrdp
========
Note that xorgxrdp is not installed and configured by default. Each build
depends on specific binary version of Xorg, which tends to create very strict
installation dependencies that can be an inconvenience in EPEL.
SELinux
=======
Please note that you may need to install xrdp-selinux package in order to get
the required SELinux policy that will allow xrdp and associated processes to
run successfully if SELinux is enabled. On versions of Fedora and RHEL that
support weak dependencies, xrdp-selinux will be a recommended package.
WARNING: The policy module contains a rule that permits unconfined_service_t
processes to transition into unconfined_t. If xrdp is not the only service
that runs as unconfined_service_t on your system, this policy will allow any
other such service to transition as well.
Default configuration in /etc/pam.d/xrdp-sesman uses password-auth for auth,
account, password and session. This may result in an incorrect context for
the processes in the session. Please adjust this file to match your desktop
environment. An example for Gnome desktop is given in the file.
TigerVNC >= 1.8.0
=================
TigerVNC 1.8.0 enables clipboard support by default (i.e. no need to run
vncconfig), which may cause disconnections in xrdp. To avoid the issue, these
can be added to [Xvnc] stanza in /etc/xrdp/sesman.ini:
param=-AcceptCutText=0
param=-SendCutText=0
param=-SendPrimary=0
param=-SetPrimary=0
Of course, cut and paste support will not work with these set.
Runlevel
========
If the system is configured to boot into graphical target, you may experience
problems with xrdp Gnome sessions. In order to avoid this, put the system into
multi user target. Like this:
systemctl set-default multi-user.target
Then reboot.
VSOCK
========
An example of a how to set up xrdp with VSOCK can be found here:
https://bugzilla.redhat.com/show_bug.cgi?id=1787953#c22
Please note that polkit rules for active sessions, allowing access to colord
and repository updates are already shipped, but in a current, JavaScript
format.

114
README.md Normal file
View file

@ -0,0 +1,114 @@
Downgrade from 0.10.x to 0.9.x
==
Version 0.10.x requires different permissions of `/run/xrdp` directory than
version 0.9.x. When 0.10.x is fully uninstalled, this directory is removed
and subsequent installation of 0.9.x should work fine.
However, if 0.10.x is downgraded to 0.9.x, the directory is preserved,
because we could have xrdp and its sessions still running, so subsequent start
or restart will fail, unless the permissions of `/run/xrdp` directory are
changed to 1777 beforehand.
Unprivileged xrdp user in 0.10.2 and up
==
Recent builds of xrdp (0.10.2 and above) create local unprivileged xrdp user,
which is used to run xrdp daemon. Script `/usr/share/xrdp/xrdp-chkpriv` checks
whether `/etc/xrdp/key.pem`, `/etc/xrdp/cert.pem` and `/etc/xrdp/rsakeys.ini`
files have correct ownership and permissions. It also makes sure
`/etc/xrdp/xrdp.ini` and `/etc/xrdp/sesman.ini` agree on which group is used
for unprivileged user.
If you are upgrading from previous version of xrdp and you already have all
these files, you may need to adjust them by hand after running this script.
For clean installs, these files should be created with correct ownership and
permissions.
Restarts
==
Service restarts after RPM package upgrades have been disabled on purpose.
This is to avoid a situation where an update is performed from within a
session running on xrdp, which can then cause dnf to only perform part of the
transaction and leave the system in a state that requires further manual
intervention, including removal of duplicate packages etc.
So, it will be up to the user/admin to restart xrdp service after any RPM
package upgrade. This is in line with what other GUI systems like Xorg and
Wayland do.
xorgxrdp
==
Note that xorgxrdp is not installed and configured by default. Each build
depends on specific binary version of Xorg. If you wish to use it, install
it by hand or its glamor build.
SELinux
==
You may need to install xrdp-selinux package in order to get the required
SELinux policy that will allow xrdp and associated processes to run
successfully if SELinux is enabled. On versions of Fedora and RHEL that support
weak dependencies, xrdp-selinux will be a recommended package.
**WARNING**: The policy module contains a rule that permits
unconfined_service_t processes to transition into unconfined_t. If xrdp is not
the only service that runs as unconfined_service_t on your system, this policy
will allow any other such service to transition as well. This transition is
exercised on every xrdp session (see below), not just latent in the policy.
The default `/etc/pam.d/xrdp-sesman` configuration invokes `pam_selinux.so`,
`pam_loginuid.so`, `pam_namespace.so` and `pam_keyinit.so` around the shared
`password-auth` stack, so session processes get the correct `unconfined_t`
context instead of remaining `unconfined_service_t` (rhbz#2499948).
If you are running a GNOME session over xrdp, comment out the generic block
in `/etc/pam.d/xrdp-sesman` and uncomment the Gnome-specific block instead.
This routes auth/session handling through `gdm-password`, which already
carries the correct SELinux/session ordering and additionally unlocks GNOME
Keyring automatically at login, so you won't be prompted to unlock it a
second time inside the session.
TigerVNC >= 1.8.0
==
TigerVNC 1.8.0 enables clipboard support by default (i.e. no need to run
vncconfig), which may cause disconnections in xrdp. To avoid the issue, these
can be added to [Xvnc] stanza in `/etc/xrdp/sesman.ini`:
```
param=-AcceptCutText=0
param=-SendCutText=0
param=-SendPrimary=0
param=-SetPrimary=0
```
Of course, cut and paste support will not work with these set.
Runlevel
==
If the system is configured to boot into graphical target, you may experience
problems with xrdp Gnome sessions. In order to avoid this, put the system into
multi user target. Like this:
```
systemctl set-default multi-user.target
```
Then reboot.
GNOME on X11 is no longer part of Fedora, so GNOME is no longer a supported
desktop for xrdp sessions on Fedora. If you need RDP access to a GNOME
desktop, use GNOME's built-in headless GNOME Remote Desktop instead of xrdp -
it speaks RDP natively, is Wayland-based, and doesn't need any of the
X11/PAM workarounds this document describes. xrdp remains the right choice
for XFCE, KDE Plasma, and other X11-based desktops on Fedora.
VSOCK
==
An example of a how to set up xrdp with VSOCK can be found here:
https://bugzilla.redhat.com/show_bug.cgi?id=1787953#c22
Polkit rules for active sessions, allowing access to colord and repository
updates are already shipped, but in a current, JavaScript format.
KDE Plasma
==
If you are using plasma-workspace package with xrdp, be sure to install
plasma-workspace-x11 to get full functionality. See this for more details:
https://github.com/neutrinolabs/xrdp/issues/3395

View file

@ -1 +1 @@
SHA512 (xrdp-0.9.23.1.tar.gz) = 92b732b85afe49c49c103c37404c66aa24fddf1583a91ec4a691044a8f02ec1abd7c834a6e0f06469e3a3bfe9fae69d90759a7ea6904ccf468271309b1fe5577
SHA512 (xrdp-0.10.6.1.tar.gz) = 14fc2bdc7d450b0194d48244450fee2dc40d248bf0d7d64538959827919d517bda90cda5985014e6b5adf101cbb584e83cf72e5181adcff78b3131653937e108

View file

@ -0,0 +1,38 @@
--- xrdp-0.10.0-beta.1/sesman/libsesman/sesman_config.c.o 2024-03-11 14:21:33.295277249 +1100
+++ xrdp-0.10.0-beta.1/sesman/libsesman/sesman_config.c 2024-03-11 14:24:16.114048106 +1100
@@ -249,14 +249,14 @@ config_read_globals(int file, struct con
cf->default_wm = g_strdup("startwm.sh");
}
/* if default_wm doesn't begin with '/', it's a relative path to
- * XRDP_CFG_PATH */
+ * /usr/libexec/xrdp */
if (cf->default_wm[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- int length = (sizeof(XRDP_CFG_PATH) +
+ int length = (sizeof("/usr/libexec/xrdp") +
g_strlen(cf->default_wm) + 1); /* '/' */
char *buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->default_wm);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->default_wm);
g_free(cf->default_wm);
cf->default_wm = buf;
}
@@ -267,14 +267,14 @@ config_read_globals(int file, struct con
cf->reconnect_sh = g_strdup("reconnectwm.sh");
}
/* if reconnect_sh doesn't begin with '/', it's a relative path to
- * XRDP_CFG_PATH */
+ * /usr/libexec/xrdp */
if (cf->reconnect_sh[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- int length = (sizeof(XRDP_CFG_PATH) +
+ int length = (sizeof("/usr/libexec/xrdp") +
g_strlen(cf->reconnect_sh) + 1); /* '/' */
char *buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->reconnect_sh);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->reconnect_sh);
g_free(cf->reconnect_sh);
cf->reconnect_sh = buf;
}

13
xrdp-0.10.1-service.patch Normal file
View file

@ -0,0 +1,13 @@
diff -ruNp xrdp-0.10.1-v/instfiles/xrdp-sesman.service.in xrdp-0.10.1/instfiles/xrdp-sesman.service.in
--- xrdp-0.10.1-v/instfiles/xrdp-sesman.service.in 2024-07-31 22:55:03.000000000 +1000
+++ xrdp-0.10.1/instfiles/xrdp-sesman.service.in 2024-07-31 23:58:48.247323165 +1000
@@ -1,7 +1,8 @@
[Unit]
Description=xrdp session manager
Documentation=man:xrdp-sesman(8) man:sesman.ini(5)
-After=network.target
+Wants=network-online.target nss-lookup.target nss-user-lookup.target
+After=network-online.target nss-lookup.target nss-user-lookup.target
StopWhenUnneeded=true
BindsTo=xrdp.service

11
xrdp-0.10.2-sesman.patch Normal file
View file

@ -0,0 +1,11 @@
--- xrdp-0.10.2-rc.1/sesman/sesman.ini.in.org 2024-12-24 00:36:22.000000000 +1100
+++ xrdp-0.10.2-rc.1/sesman/sesman.ini.in 2024-12-24 07:06:20.309329448 +1100
@@ -7,7 +7,7 @@ EnableUserWindowManager=true
; Give in relative path to user's home directory
UserWindowManager=startwm.sh
; Give in full path or relative path to @sesmansysconfdir@
-DefaultWindowManager=startwm.sh
+DefaultWindowManager=startwm-bash.sh
; Give in full path or relative path to @sesmansysconfdir@
ReconnectScript=reconnectwm.sh

102
xrdp-0.10.3-xrdp-ini.patch Normal file
View file

@ -0,0 +1,102 @@
--- xrdp-0.10.3/xrdp/xrdp.ini.in.org 2025-04-01 21:11:30.997621951 +1100
+++ xrdp-0.10.3/xrdp/xrdp.ini.in 2025-04-01 21:13:18.881162132 +1100
@@ -30,8 +30,8 @@ use_vsock=false
; Unprivileged User name and group to run the xrdp daemon.
; It is HIGHLY RECOMMENDED you set these values. See the xrdp.ini(5)
; manpage for more information on setting and checking these.
-#runtime_user=xrdp
-#runtime_group=xrdp
+runtime_user=xrdp
+runtime_group=xrdp
; regulate if the listening socket use socket option tcp_nodelay
; no buffering will be performed in the TCP stack
@@ -241,24 +241,24 @@ xrdpvr=true
; Some session types such as Xorg and Xvnc start a display server.
; Startup command-line parameters for the display server are configured
; in sesman.ini. See and configure also sesman.ini.
-[Xorg]
-name=Xorg
-lib=libxup.@lib_extension@
-username=ask
-password=ask
-port=-1
-code=20
+#[Xorg]
+#name=Xorg
+#lib=libxup.@lib_extension@
+#username=ask
+#password=ask
+#port=-1
+#code=20
; Frame capture interval (milliseconds)
-h264_frame_interval=16
-rfx_frame_interval=32
-normal_frame_interval=40
+#h264_frame_interval=16
+#rfx_frame_interval=32
+#normal_frame_interval=40
[Xvnc]
name=Xvnc
lib=libvnc.@lib_extension@
username=ask
password=ask
-ip=127.0.0.1
+#ip=127.0.0.1
; port is -1 (sesman controlled), numeric (TCP connection) or an
; absolute path (UDS connection).
port=-1
@@ -277,7 +277,7 @@ port=-1
; VNC password files is no longer considered secure by FIPS
;
; The default value is 0 on non-FIPS systems, and 1 on FIPS-based systems.
-#code=0
+code=1
#xserverbpp=24
#delay_ms=2000
; Disable requested encodings to support buggy VNC servers
@@ -287,13 +287,13 @@ port=-1
; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name.
-[vnc-any]
-name=vnc-any
-lib=libvnc.@lib_extension@
-ip=ask
-port=ask5900
-username=na
-password=ask
+#[vnc-any]
+#name=vnc-any
+#lib=libvnc.@lib_extension@
+#ip=ask
+#port=ask5900
+#username=na
+#password=ask
#pamusername=asksame
#pampassword=asksame
#delay_ms=2000
@@ -310,15 +310,15 @@ password=ask
; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting
; a suitable name.
-[neutrinordp-any]
-name=neutrinordp-any
+#[neutrinordp-any]
+#name=neutrinordp-any
; To use this section, you should build xrdp with configure option
; --enable-neutrinordp.
-lib=libxrdpneutrinordp.@lib_extension@
-ip=ask
-port=ask3389
-username=ask
-password=ask
+#lib=libxrdpneutrinordp.@lib_extension@
+#ip=ask
+#port=ask3389
+#username=ask
+#password=ask
; Uncomment the following lines to enable PAM authentication for proxy
; connections.
#pamusername=ask

View file

@ -0,0 +1,20 @@
--- xrdp-0.10.2-rc.1/sesman/sesman.ini.in.org 2024-12-24 07:11:02.643702480 +1100
+++ xrdp-0.10.2-rc.1/sesman/sesman.ini.in 2024-12-24 07:12:42.372540720 +1100
@@ -48,7 +48,7 @@ RestrictInboundClipboard=none
; local sockets for the session are created.
; This MUST be the same as runtime_group in xrdp.ini, or xrdp will not
; be able to connect to your sessions.
-#SessionSockdirGroup=xrdp
+SessionSockdirGroup=xrdp
[Sessions]
@@ -143,7 +143,7 @@ EnableSyslog=true
; Arch Linux : param=/usr/lib/Xorg
; FreeBSD (from 2022Q4) : param=/usr/local/libexec/Xorg
;
-param=Xorg
+param=/usr/libexec/Xorg
; Leave the rest parameters as-is unless you understand what will happen.
param=-config
param=xrdp/xorg.conf

View file

@ -1,37 +0,0 @@
diff -ruN xrdp-0.9.10-v/sesman/config.c xrdp-0.9.10/sesman/config.c
--- xrdp-0.9.10-v/sesman/config.c 2019-04-18 15:38:26.000000000 +1000
+++ xrdp-0.9.10/sesman/config.c 2019-05-03 07:59:36.784643398 +1000
@@ -179,13 +179,13 @@
g_free(cf->default_wm);
cf->default_wm = g_strdup("startwm.sh");
}
- /* if default_wm doesn't begin with '/', it's a relative path to XRDP_CFG_PATH */
+ /* if default_wm doesn't begin with '/', it's a relative path to /usr/libexec/xrdp */
if (cf->default_wm[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- length = sizeof(XRDP_CFG_PATH) + g_strlen(cf->default_wm) + 1; /* '/' */
+ length = sizeof("/usr/libexec/xrdp") + g_strlen(cf->default_wm) + 1; /* '/' */
buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->default_wm);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->default_wm);
g_free(cf->default_wm);
cf->default_wm = g_strdup(buf);
g_free(buf);
@@ -200,13 +200,13 @@
g_free(cf->reconnect_sh);
cf->reconnect_sh = g_strdup("reconnectwm.sh");
}
- /* if reconnect_sh doesn't begin with '/', it's a relative path to XRDP_CFG_PATH */
+ /* if reconnect_sh doesn't begin with '/', it's a relative path to /usr/libexec/xrdp */
if (cf->reconnect_sh[0] != '/')
{
/* sizeof operator returns string length including null terminator */
- length = sizeof(XRDP_CFG_PATH) + g_strlen(cf->reconnect_sh) + 1; /* '/' */
+ length = sizeof("/usr/libexec/xrdp") + g_strlen(cf->reconnect_sh) + 1; /* '/' */
buf = (char *)g_malloc(length, 0);
- g_sprintf(buf, "%s/%s", XRDP_CFG_PATH, cf->reconnect_sh);
+ g_sprintf(buf, "%s/%s", "/usr/libexec/xrdp", cf->reconnect_sh);
g_free(cf->reconnect_sh);
cf->reconnect_sh = g_strdup(buf);
g_free(buf);

View file

@ -1,70 +0,0 @@
diff -ruN xrdp-0.9.17-v/xrdp/xrdp.ini xrdp-0.9.17/xrdp/xrdp.ini
--- xrdp-0.9.17-v/xrdp/xrdp.ini 2021-09-01 11:32:12.000000000 +1000
+++ xrdp-0.9.17/xrdp/xrdp.ini 2021-09-01 13:06:55.525816406 +1000
@@ -203,14 +203,14 @@
; Some session types such as Xorg, X11rdp and Xvnc start a display server.
; Startup command-line parameters for the display server are configured
; in sesman.ini. See and configure also sesman.ini.
-[Xorg]
-name=Xorg
-lib=libxup.so
-username=ask
-password=ask
-ip=127.0.0.1
-port=-1
-code=20
+#[Xorg]
+#name=Xorg
+#lib=libxup.so
+#username=ask
+#password=ask
+#ip=127.0.0.1
+#port=-1
+#code=20
[Xvnc]
name=Xvnc
@@ -232,13 +232,13 @@
; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name.
-[vnc-any]
-name=vnc-any
-lib=libvnc.so
-ip=ask
-port=ask5900
-username=na
-password=ask
+#[vnc-any]
+#name=vnc-any
+#lib=libvnc.so
+#ip=ask
+#port=ask5900
+#username=na
+#password=ask
#pamusername=asksame
#pampassword=asksame
#pamsessionmng=127.0.0.1
@@ -247,15 +247,15 @@
; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting
; a suitable name.
-[neutrinordp-any]
-name=neutrinordp-any
+#[neutrinordp-any]
+#name=neutrinordp-any
; To use this section, you should build xrdp with configure option
; --enable-neutrinordp.
-lib=libxrdpneutrinordp.so
-ip=ask
-port=ask3389
-username=ask
-password=ask
+#lib=libxrdpneutrinordp.so
+#ip=ask
+#port=ask3389
+#username=ask
+#password=ask
; Uncomment the following lines to enable PAM authentication for proxy
; connections.
#pamusername=ask

View file

@ -1,12 +0,0 @@
diff -ruN xrdp-0.9.20-v/sesman/sesman.ini xrdp-0.9.20/sesman/sesman.ini
--- xrdp-0.9.20-v/sesman/sesman.ini 2022-09-15 15:59:55.000000000 +1000
+++ xrdp-0.9.20/sesman/sesman.ini 2022-09-15 17:40:10.032704634 +1000
@@ -111,7 +111,7 @@
; CentOS 8 : param=/usr/libexec/Xorg
; FreeBSD (from 2022Q4) : param=/usr/local/libexec/Xorg
;
-param=Xorg
+param=/usr/libexec/Xorg
; Leave the rest parameters as-is unless you understand what will happen.
param=-config
param=xrdp/xorg.conf

View file

@ -1,16 +0,0 @@
diff -rup xrdp-0.9.22.1-v/sesman/chansrv/sound.c xrdp-0.9.22.1/sesman/chansrv/sound.c
--- xrdp-0.9.22.1-v/sesman/chansrv/sound.c 2023-05-23 10:18:50.000000000 +1000
+++ xrdp-0.9.22.1/sesman/chansrv/sound.c 2023-05-23 12:35:50.273215167 +1000
@@ -1116,9 +1116,11 @@ process_pcm_message(int id, int size, st
char *buf = (char *) g_malloc(g_bbuf_size, 0);
if (buf != NULL)
{
+ int i;
+
silence_start_time = g_time3();
sending_silence = 1;
- for (int i = 0; i < send_silence_times; i++)
+ for (i = 0; i < send_silence_times; i++)
{
g_memset(buf, 0, g_bbuf_size);
sound_send_wave_data_chunk(buf, g_bbuf_size);

View file

@ -1,47 +0,0 @@
diff -ruN xrdp-0.9.4-v/instfiles/xrdp.service.in xrdp-0.9.4/instfiles/xrdp.service.in
--- xrdp-0.9.4-v/instfiles/xrdp.service.in 2017-07-19 14:23:49.000000000 +1000
+++ xrdp-0.9.4/instfiles/xrdp.service.in 2017-10-06 14:29:13.910973750 +1100
@@ -2,15 +2,11 @@
Description=xrdp daemon
Documentation=man:xrdp(8) man:xrdp.ini(5)
Requires=xrdp-sesman.service
-After=network.target xrdp-sesman.service
+After=xrdp-sesman.service
[Service]
-Type=forking
-PIDFile=@localstatedir@/run/xrdp.pid
-EnvironmentFile=-@sysconfdir@/sysconfig/xrdp
-EnvironmentFile=-@sysconfdir@/default/xrdp
-ExecStart=@sbindir@/xrdp $XRDP_OPTIONS
-ExecStop=@sbindir@/xrdp $XRDP_OPTIONS --kill
+EnvironmentFile=@sysconfdir@/sysconfig/xrdp
+ExecStart=@sbindir@/xrdp $XRDP_OPTIONS --nodaemon
[Install]
WantedBy=multi-user.target
diff -ruN xrdp-0.9.4-v/instfiles/xrdp-sesman.service.in xrdp-0.9.4/instfiles/xrdp-sesman.service.in
--- xrdp-0.9.4-v/instfiles/xrdp-sesman.service.in 2017-07-19 14:23:49.000000000 +1000
+++ xrdp-0.9.4/instfiles/xrdp-sesman.service.in 2017-10-06 14:29:13.910973750 +1100
@@ -1,17 +1,14 @@
[Unit]
Description=xrdp session manager
Documentation=man:xrdp-sesman(8) man:sesman.ini(5)
-After=network.target
+Wants=network-online.target nss-lookup.target nss-user-lookup.target
+After=network-online.target nss-lookup.target nss-user-lookup.target
StopWhenUnneeded=true
BindsTo=xrdp.service
[Service]
-Type=forking
-PIDFile=@localstatedir@/run/xrdp-sesman.pid
-EnvironmentFile=-@sysconfdir@/sysconfig/xrdp
-EnvironmentFile=-@sysconfdir@/default/xrdp
-ExecStart=@sbindir@/xrdp-sesman $SESMAN_OPTIONS
-ExecStop=@sbindir@/xrdp-sesman $SESMAN_OPTIONS --kill
+EnvironmentFile=@sysconfdir@/sysconfig/xrdp
+ExecStart=@sbindir@/xrdp-sesman $SESMAN_OPTIONS --nodaemon
[Install]
WantedBy=multi-user.target

View file

@ -1,12 +0,0 @@
diff -ruN xrdp-0.9.9-v/sesman/sesman.ini xrdp-0.9.9/sesman/sesman.ini
--- xrdp-0.9.9-v/sesman/sesman.ini 2018-12-25 15:49:32.000000000 +1100
+++ xrdp-0.9.9/sesman/sesman.ini 2019-01-11 19:19:42.253947862 +1100
@@ -7,7 +7,7 @@
; Give in relative path to user's home directory
UserWindowManager=startwm.sh
; Give in full path or relative path to /etc/xrdp
-DefaultWindowManager=startwm.sh
+DefaultWindowManager=startwm-bash.sh
; Give in full path or relative path to /etc/xrdp
ReconnectScript=reconnectwm.sh

View file

@ -1,11 +1,30 @@
#%PAM-1.0
# Generic Fedora config
# Generic Fedora/RHEL config - use this unless you are running xrdp
# sessions into a GNOME desktop, in which case use the Gnome-specific
# config below instead, which also unlocks GNOME Keyring automatically.
auth include password-auth
account include password-auth
password include password-auth
session include password-auth
# Gnome specific Fedora config
# pam_selinux.so close must be the first session rule so any
# prior context is torn down before we set up the new one.
session required pam_selinux.so close
session required pam_loginuid.so
# pam_selinux.so open must run before any module below that
# should execute in the user's context. Without this pair,
# session processes are left running as unconfined_service_t
# instead of unconfined_t. See rhbz#2499948.
session required pam_selinux.so open
session required pam_namespace.so
session optional pam_keyinit.so force revoke
session include password-auth
session optional pam_lastlog.so silent
# Gnome specific config. Uncomment this block and comment out the
# generic block above if you are running xrdp sessions into a GNOME
# desktop. This uses GDM's own PAM stack, which already includes the
# correct pam_selinux.so/pam_namespace.so ordering and additionally
# unlocks GNOME Keyring automatically at login.
#auth include gdm-password
#account include gdm-password
#password include gdm-password

2
xrdp-tmpfiles.conf Normal file
View file

@ -0,0 +1,2 @@
d /run/xrdp 0755 root root -
R /run/xrdp 0755 root root -

250
xrdp.spec
View file

@ -1,3 +1,5 @@
#%%global prerelease -rc.1
%global _hardened_build 1
%global selinux_types %(%{__awk} '/^#[[:space:]]*SELINUXTYPE=/,/^[^#]/ { if ($3 == "-") printf "%s ", $2 }' /etc/selinux/config 2>/dev/null)
@ -13,33 +15,36 @@
%global _missing_braces -Wno-error=missing-braces
%endif
%ifarch %{ix86}
%global _file_offset_bits -D_FILE_OFFSET_BITS=64
%endif
Summary: Open source remote desktop protocol (RDP) server
Name: xrdp
Epoch: 1
Version: 0.9.23.1
Release: 1%{?dist}
License: ASL 2.0 and GPLv2+ and MIT
Version: 0.10.6.1
Release: 3%{?dist}
# Automatically converted from old format: ASL 2.0 and GPLv2+ and MIT - review is highly recommended.
License: Apache-2.0 AND GPL-2.0-or-later AND LicenseRef-Callaway-MIT
URL: http://www.xrdp.org/
Source0: https://github.com/neutrinolabs/xrdp/releases/download/v%{version}/xrdp-%{version}.tar.gz
Source0: https://github.com/neutrinolabs/xrdp/releases/download/v%{version}%{?prerelease}/xrdp-%{version}%{?prerelease}.tar.gz
Source1: xrdp-sesman.pamd
Source2: xrdp.sysconfig
Source3: xrdp.logrotate
Source4: openssl.conf
Source5: README.Fedora
Source5: README.md
Source6: xrdp.te
Source7: xrdp-polkit-1.rules
Patch0: xrdp-0.9.9-sesman.patch
Patch1: xrdp-0.9.17-xrdp-ini.patch
Patch2: xrdp-0.9.4-service.patch
Patch3: xrdp-0.9.10-scripts-libexec.patch
Source8: %{name}-tmpfiles.conf
Source9: %{name}.sysusers
Patch0: xrdp-0.10.2-sesman.patch
Patch2: xrdp-0.10.1-service.patch
Patch3: xrdp-0.10.0-scripts-libexec.patch
Patch4: xrdp-0.9.6-script-interpreter.patch
Patch5: xrdp-0.9.16-arch.patch
Patch6: xrdp-0.9.18-vnc-uninit.patch
%if 0%{?fedora} >= 32 || 0%{?rhel} >= 8
Patch7: xrdp-0.9.20-sesman-ini.patch
%endif
%if ! 0%{?fedora} && 0%{?rhel} <= 7
Patch8: xrdp-0.9.22.1-no-c99.patch
Patch8: xrdp-0.10.5-sesman-ini.patch
%endif
BuildRequires: make
@ -51,20 +56,29 @@ BuildRequires: libXrandr-devel
BuildRequires: imlib2-devel
BuildRequires: openssl
BuildRequires: pam-devel
BuildRequires: pkgconfig(fuse)
BuildRequires: pkgconfig(fuse3)
BuildRequires: pkgconfig(openssl)
BuildRequires: pkgconfig(pixman-1)
BuildRequires: pkgconfig(systemd)
BuildRequires: nasm
%if 0%{?fedora} || 0%{?rhel} > 8
BuildRequires: noopenh264-devel
%endif
BuildRequires: checkpolicy, selinux-policy-devel
BuildRequires: %{_hardlink}
BuildRequires: systemd-rpm-macros
%if 0%{?fedora} < 42 || 0%{?rhel}
%{?sysusers_requires_compat}
%endif
# tigervnc-server-minimal provides Xvnc (default for now)
# xorgxrdp is another back end, depends on specific Xorg binary, omit
Requires: tigervnc-server-minimal
Requires: xorg-x11-xinit
Requires: util-linux
Requires: fuse3
%if 0%{?fedora} || 0%{?rhel} >= 8
Recommends: %{name}-selinux = %{epoch}:%{version}-%{release}
@ -75,6 +89,9 @@ Requires(post): systemd-sysv
Requires(post): /sbin/ldconfig
Requires(posttrans): openssl
Requires(preun): systemd
%if 0%{?fedora}
Requires(preun): systemd-tmpfiles
%endif
Requires(posttrans): systemd
@ -95,7 +112,9 @@ talk to xrdp.
Summary: SELinux policy module required tu run xrdp
Requires: %{name} = %{epoch}:%{version}-%{release}
%if "%{_selinux_policy_version}" != ""
Requires: selinux-policy >= %{_selinux_policy_version}
%endif
Requires(post): /usr/sbin/semodule
Requires(postun): /usr/sbin/semodule
@ -103,7 +122,7 @@ Requires(postun): /usr/sbin/semodule
This package contains SELinux policy module necessary to run xrdp.
%prep
%autosetup -p1
%autosetup -p1 -n %{name}-%{version}%{?prerelease}
%{__cp} %{SOURCE5} .
# SELinux policy module
@ -116,9 +135,19 @@ echo '#!/bin/bash -l
%build
autoreconf -vif
CFLAGS="$RPM_OPT_FLAGS %{?_missing_braces}" \
%configure --enable-fuse --enable-pixman --enable-painter --enable-vsock \
--enable-ipv6 --with-socketdir=%{_rundir}/%{name} --with-imlib2
CFLAGS="$RPM_OPT_FLAGS %{?_missing_braces} %{?_file_offset_bits}" \
%configure --enable-fuse \
--enable-pixman \
--enable-painter \
--enable-vsock \
--enable-ipv6 \
%if 0%{?fedora} || 0%{?rhel} > 8
--enable-openh264 \
%endif
--enable-utmp \
--with-socketdir=%{_rundir}/%{name} \
--with-imlib2
%make_build
# SELinux policy module
@ -156,6 +185,10 @@ cd -
#install xrdp.rules /usr/share/polkit-1/rules.d
%{__install} -Dp -m 644 %{SOURCE7} %{buildroot}%{_datadir}/polkit-1/rules.d/xrdp.rules
# Temporary files for socket
%{__mkdir_p} %{buildroot}%{_tmpfilesdir}
%{__install} -m 0644 %{SOURCE8} %{buildroot}%{_tmpfilesdir}/%{name}.conf
# SELinux policy module
for selinuxvariant in %{selinux_variants}
do
@ -165,6 +198,13 @@ do
done
%{_hardlink} -cv %{buildroot}%{_datadir}/selinux
%{__install} -p -D -m 0644 %{SOURCE9} %{buildroot}%{_sysusersdir}/xrdp.conf
%if 0%{?fedora} < 42 || 0%{?rhel}
%pre
%sysusers_create_compat %{SOURCE9}
%endif
%post
%{?ldconfig}
%systemd_post xrdp.service
@ -173,36 +213,42 @@ done
%systemd_preun xrdp.service
if [ $1 -eq 0 ]; then
# Stop services on package removal (see bug 1349083)
systemctl stop xrdp.service > /dev/null 2>&1 || :
systemctl stop xrdp.service &>/dev/null || :
systemd-tmpfiles --remove %{name}.conf &>/dev/null || :
fi
%triggerun -- xrdp < 0.6.0-1
systemd-sysv-convert --save xrdp >/dev/null 2>&1 ||:
systemd-sysv-convert --save xrdp &>/dev/null || :
# If the package is allowed to autostart:
systemctl preset xrdp.service >/dev/null 2>&1 ||:
systemctl preset xrdp.service &>/dev/null || :
# Run these because the SysV package being removed won't do them
/sbin/chkconfig --del xrdp >/dev/null 2>&1 || :
/sbin/chkconfig --del xrdp &>/dev/null || :
if [ "`systemctl is-active xrdp.service`" = 'active' ]; then
systemctl stop xrdp.service >/dev/null 2>&1 || :
systemctl start xrdp.service >/dev/null 2>&1 || :
systemctl stop xrdp.service &>/dev/null || :
systemctl start xrdp.service &>/dev/null || :
fi
%ldconfig_postun
%posttrans
if [ ! -s %{_sysconfdir}/xrdp/rsakeys.ini ]; then
(umask 377; touch %{_sysconfdir}/xrdp/rsakeys.ini; %{_bindir}/xrdp-keygen xrdp %{_sysconfdir}/xrdp/rsakeys.ini &>/dev/null)
(umask 0137
%{_bindir}/xrdp-keygen xrdp %{_sysconfdir}/xrdp/rsakeys.ini &>/dev/null)
fi
if [ ! -s %{_sysconfdir}/xrdp/cert.pem ]; then
(umask 377; openssl req -x509 -newkey rsa:2048 -sha256 -nodes -days 3652 \
-keyout %{_sysconfdir}/xrdp/key.pem \
-out %{_sysconfdir}/xrdp/cert.pem \
-config %{_sysconfdir}/xrdp/openssl.conf >/dev/null 2>&1)
(umask 0337
openssl req -x509 -newkey rsa:2048 -nodes -days 3652 \
-keyout %{_sysconfdir}/xrdp/key.pem \
-out %{_sysconfdir}/xrdp/cert.pem \
-config %{_sysconfdir}/xrdp/openssl.conf &>/dev/null)
fi
chgrp xrdp %{_sysconfdir}/xrdp/{rsakeys.ini,{key,cert}.pem}
chmod 0640 %{_sysconfdir}/xrdp/{rsakeys.ini,{key,cert}.pem}
%post selinux
for selinuxvariant in %{selinux_variants}
do
@ -220,12 +266,14 @@ fi
%files
%doc COPYING README.Fedora
%doc COPYING README.md
%dir %{_libdir}/xrdp
%dir %{_sysconfdir}/xrdp
%dir %{_sysconfdir}/xrdp/pulse
%dir %{_datadir}/xrdp
%dir %{_libexecdir}/xrdp
%{_tmpfilesdir}/%{name}.conf
%{_sysusersdir}/xrdp.conf
%config(noreplace) %{_sysconfdir}/xrdp/xrdp.ini
%config(noreplace) %{_sysconfdir}/pam.d/xrdp-sesman
%config(noreplace) %{_sysconfdir}/logrotate.d/xrdp
@ -234,16 +282,21 @@ fi
%config(noreplace) %{_sysconfdir}/xrdp/km*.ini
%config(noreplace) %{_sysconfdir}/xrdp/openssl.conf
%config(noreplace) %{_sysconfdir}/xrdp/xrdp_keyboard.ini
%config(noreplace) %{_sysconfdir}/xrdp/gfx.toml
%config(noreplace) %{_sysconfdir}/xrdp/pulse/default.pa
%exclude %ghost %{_sysconfdir}/xrdp/*.pem
%exclude %ghost %{_sysconfdir}/xrdp/rsakeys.ini
%{_libexecdir}/xrdp/startwm*.sh
%{_libexecdir}/xrdp/reconnectwm.sh
%{_libexecdir}/xrdp/waitforx
%{_libexecdir}/xrdp/xrdp-sesexec
%{_libexecdir}/xrdp/xrdp-droppriv
%{_bindir}/xrdp-genkeymap
%{_bindir}/xrdp-sesadmin
%{_bindir}/xrdp-keygen
%{_bindir}/xrdp-sesrun
%{_bindir}/xrdp-dis
%{_bindir}/xrdp-dumpfv1
%{_sbindir}/xrdp-chansrv
%{_sbindir}/xrdp
%{_sbindir}/xrdp-sesman
@ -252,18 +305,19 @@ fi
%{_datadir}/xrdp/cursor1.cur
%{_datadir}/xrdp/xrdp256.bmp
%{_datadir}/xrdp/sans-10.fv1
%{_datadir}/xrdp/sans-18.fv1
%{_datadir}/xrdp/ad24b.bmp
%{_datadir}/xrdp/xrdp24b.bmp
%{_datadir}/xrdp/xrdp_logo.bmp
%{_datadir}/xrdp/xrdp_logo.png
%{_datadir}/xrdp/xrdp-chkpriv
%{_datadir}/xrdp/README.logo
%{_datadir}/polkit-1/rules.d/xrdp.rules
%{_mandir}/man5/*
%{_mandir}/man8/*
%{_mandir}/man1/*
%{_libdir}/librfxencode.so*
%{_libdir}/xrdp/lib*.so*
%exclude %{_libdir}/librfxencode.so
%exclude %{_libdir}/xrdp/libcommon.so
%exclude %{_libdir}/xrdp/libscp.so
%exclude %{_libdir}/xrdp/libxrdp.so
%exclude %{_libdir}/xrdp/libxrdpapi.so
%{_unitdir}/xrdp-sesman.service
@ -285,9 +339,7 @@ fi
%{_includedir}/ms-*
%{_includedir}/xrdp*
%{_includedir}/rfxcodec_*.h
%{_libdir}/librfxencode.so
%{_libdir}/xrdp/libcommon.so
%{_libdir}/xrdp/libscp.so
%{_libdir}/xrdp/libxrdp.so
%{_libdir}/xrdp/libxrdpapi.so
%{_libdir}/pkgconfig/rfxcodec.pc
@ -298,6 +350,134 @@ fi
%{_datadir}/selinux/*/%{name}.pp
%changelog
* Sat Jul 18 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6.1-3
- Fix bug #2499948
* Tue Jul 07 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6.1-1
- Update to 0.10.6.1
- CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218
- CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626
- CVE-2026-55639, CVE-2026-55645
* Sat Jun 13 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1:0.10.6-3
- Rebuilt for openssl 4.0
* Fri May 22 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6-2
- close TCP port in default Xvnc config, Unix domain socket only
* Sat Apr 18 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.6-1
- Update to 0.10.6
- CVE-2026-32105, CVE-2026-32107, CVE-2026-32623, CVE-2026-32624
- CVE-2026-33145, CVE-2026-33516, CVE-2026-33689, CVE-2026-35512
* Wed Jan 28 2026 Bojan Smojver <bojan@rexursive.com> - 1:0.10.5-1
- Update to 0.10.5
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.4-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Tue Nov 4 2025 Tom Callaway <spot@fedoraproject.org> - 1:0.10.4-4
- rebuild for new fuse3
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 7 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.4-2
- Patch upstream issue #3558, fix by matt335672
* Thu Jul 3 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.4-1
- Update to 0.10.4
* Tue Apr 1 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.3-1
- Update to 0.10.3
- Enable Xvnc over Unix domain socket
* Wed Mar 26 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-13
- Rebuild for noopenh264 2.6.0, once more
* Thu Mar 13 2025 Fabio Valentini <decathorpe@gmail.com> - 1:0.10.2-12
- Rebuild for noopenh264 2.6.0
* Thu Mar 6 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-11
- Drop call to %sysusers_create_compat only in Fedora 42 and above
- Add fuse3 dependency BZ#2350108
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 1:0.10.2-10
- Drop call to %sysusers_create_compat
* Thu Feb 6 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-9
- Add utmp support contributed upstream by Magnus Lewis-Smith
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.2-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Sun Jan 5 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-7
- Comment out generic RDP proxy in xrdp.ini
* Sun Jan 5 2025 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-6
- Set permissions of cert, key and rsakeys.ini to 0640
- Revert optional dependency on noopenh264, library dependency exists
* Fri Dec 27 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-5
- Move README.Fedora to README.md
- Adjust ownership/permissions of certs/keys for unprivileged user
* Thu Dec 26 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-4
- If openh264 is not present, require noopenh264 instead
* Wed Dec 25 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-3
- Run as unprivileged user
* Wed Dec 25 2024 Koichiro Iwao <meta@almalinux.org> - 1:0.10.2-2
- Enable OpenH264
* Wed Dec 25 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2-1
- Update to 0.10.2
* Tue Dec 24 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.2~0.rc1.1
- Update to 0.10.2-rc.1
* Wed Sep 4 2024 Miroslav Suchý <msuchy@redhat.com> - 1:0.10.1-2
- convert license to SPDX
* Wed Jul 31 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.1-1
- Update to 0.10.1
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.10.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sat Jun 1 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-4
- Explain downgrades from 0.10.x to 0.9.x in README.Fedora
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-3
- Only require systemd-tmpfiles on Fedora
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-2
- Explicitly run systemd-tmpfiles --remove on package removal BZ#2279775
* Tue May 14 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-1
- Update to 0.10.0
- Revert PR 2994
* Wed Apr 03 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-0.beta.2
- Update to 0.10.0-beta.2
* Wed Mar 13 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.9.25-2
- Add upstream PR 2994
* Tue Mar 12 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.9.25-1
- Update to 0.9.25
* Mon Mar 11 2024 Bojan Smojver <bojan@rexursive.com> - 1:0.10.0-0.beta.1
- Update to 0.10.0-beta.1
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:0.9.24-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Dec 31 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.24-1
- Update to 0.9.24
- Remove already applied patch affecting compilation on EL7
* Thu Sep 28 2023 Bojan Smojver <bojan@rexursive.com> - 1:0.9.23.1-1
- Update to 0.9.23.1
- CVE-2023-42822

2
xrdp.sysusers Normal file
View file

@ -0,0 +1,2 @@
#Type Name ID GECOS Home directory Shell
u xrdp - "Unprivileged xrdp user" /run/xrdp /sbin/nologin