2 * FreeRDP: A Remote Desktop Protocol Client
5 * Copyright 2011 Marc-Andre Moreau <marcandre.moreau@gmail.com>
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
24 #include "redirection.h"
26 static const char* const DATA_PDU_TYPE_STRINGS[] =
28 "", "", /* 0x00 - 0x01 */
30 "", "", "", "", "", "", "", "", /* 0x03 - 0x0A */
31 "", "", "", "", "", "", "", "", "", /* 0x0B - 0x13 */
33 "", "", "", "", "", "", /* 0x15 - 0x1A */
36 "", "", /* 0x1D - 0x1E */
37 "Synchronize", /* 0x1F */
39 "Refresh Rect", /* 0x21 */
40 "Play Sound", /* 0x22 */
41 "Suppress Output", /* 0x23 */
42 "Shutdown Request", /* 0x24 */
43 "Shutdown Denied", /* 0x25 */
44 "Save Session Info", /* 0x26 */
45 "Font List", /* 0x27 */
46 "Font Map", /* 0x28 */
47 "Set Keyboard Indicators", /* 0x29 */
49 "Bitmap Cache Persistent List", /* 0x2B */
50 "Bitmap Cache Error", /* 0x2C */
51 "Set Keyboard IME Status", /* 0x2D */
52 "Offscreen Cache Error", /* 0x2E */
53 "Set Error Info", /* 0x2F */
54 "Draw Nine Grid Error", /* 0x30 */
55 "Draw GDI+ Error", /* 0x31 */
56 "ARC Status", /* 0x32 */
57 "", "", "", /* 0x33 - 0x35 */
58 "Status Info", /* 0x36 */
59 "Monitor Layout" /* 0x37 */
60 "", "", "", /* 0x38 - 0x40 */
61 "", "", "", "", "", "" /* 0x41 - 0x46 */
65 * Read RDP Security Header.\n
68 * @param flags security flags
71 void rdp_read_security_header(STREAM* s, uint16* flags)
73 /* Basic Security Header */
74 stream_read_uint16(s, *flags); /* flags */
75 stream_seek(s, 2); /* flagsHi (unused) */
79 * Write RDP Security Header.\n
82 * @param flags security flags
85 void rdp_write_security_header(STREAM* s, uint16 flags)
87 /* Basic Security Header */
88 stream_write_uint16(s, flags); /* flags */
89 stream_write_uint16(s, 0); /* flagsHi (unused) */
92 boolean rdp_read_share_control_header(STREAM* s, uint16* length, uint16* type, uint16* channel_id)
94 /* Share Control Header */
95 stream_read_uint16(s, *length); /* totalLength */
96 stream_read_uint16(s, *type); /* pduType */
97 stream_read_uint16(s, *channel_id); /* pduSource */
98 *type &= 0x0F; /* type is in the 4 least significant bits */
100 if (*length - 6 > stream_get_left(s))
106 void rdp_write_share_control_header(STREAM* s, uint16 length, uint16 type, uint16 channel_id)
108 length -= (s->p - s->data);
110 /* Share Control Header */
111 stream_write_uint16(s, length); /* totalLength */
112 stream_write_uint16(s, type | 0x10); /* pduType */
113 stream_write_uint16(s, channel_id); /* pduSource */
116 boolean rdp_read_share_data_header(STREAM* s, uint16* length, uint8* type, uint32* share_id,
117 uint8 *compressed_type, uint16 *compressed_len)
119 if (stream_get_left(s) < 12)
122 /* Share Data Header */
123 stream_read_uint32(s, *share_id); /* shareId (4 bytes) */
124 stream_seek_uint8(s); /* pad1 (1 byte) */
125 stream_seek_uint8(s); /* streamId (1 byte) */
126 stream_read_uint16(s, *length); /* uncompressedLength (2 bytes) */
127 stream_read_uint8(s, *type); /* pduType2, Data PDU Type (1 byte) */
130 stream_read_uint8(s, *compressed_type); /* compressedType (1 byte) */
131 stream_read_uint16(s, *compressed_len); /* compressedLength (2 bytes) */
136 *compressed_type = 0;
143 void rdp_write_share_data_header(STREAM* s, uint16 length, uint8 type, uint32 share_id)
145 length -= RDP_PACKET_HEADER_LENGTH;
146 length -= RDP_SHARE_CONTROL_HEADER_LENGTH;
147 length -= RDP_SHARE_DATA_HEADER_LENGTH;
149 /* Share Data Header */
150 stream_write_uint32(s, share_id); /* shareId (4 bytes) */
151 stream_write_uint8(s, 0); /* pad1 (1 byte) */
152 stream_write_uint8(s, STREAM_LOW); /* streamId (1 byte) */
153 stream_write_uint16(s, length); /* uncompressedLength (2 bytes) */
154 stream_write_uint8(s, type); /* pduType2, Data PDU Type (1 byte) */
155 stream_write_uint8(s, 0); /* compressedType (1 byte) */
156 stream_write_uint16(s, 0); /* compressedLength (2 bytes) */
159 static int rdp_security_stream_init(rdpRdp* rdp, STREAM* s)
164 if (rdp->settings->encryption_method == ENCRYPTION_METHOD_FIPS)
166 rdp->sec_flags |= SEC_ENCRYPT;
168 else if (rdp->sec_flags != 0)
176 * Initialize an RDP packet stream.\n
177 * @param rdp rdp module
181 STREAM* rdp_send_stream_init(rdpRdp* rdp)
185 s = transport_send_stream_init(rdp->transport, 2048);
186 stream_seek(s, RDP_PACKET_HEADER_LENGTH);
187 rdp_security_stream_init(rdp, s);
192 STREAM* rdp_pdu_init(rdpRdp* rdp)
195 s = transport_send_stream_init(rdp->transport, 2048);
196 stream_seek(s, RDP_PACKET_HEADER_LENGTH);
197 rdp_security_stream_init(rdp, s);
198 stream_seek(s, RDP_SHARE_CONTROL_HEADER_LENGTH);
202 STREAM* rdp_data_pdu_init(rdpRdp* rdp)
205 s = transport_send_stream_init(rdp->transport, 2048);
206 stream_seek(s, RDP_PACKET_HEADER_LENGTH);
207 rdp_security_stream_init(rdp, s);
208 stream_seek(s, RDP_SHARE_CONTROL_HEADER_LENGTH);
209 stream_seek(s, RDP_SHARE_DATA_HEADER_LENGTH);
214 * Read an RDP packet header.\n
215 * @param rdp rdp module
217 * @param length RDP packet length
218 * @param channel_id channel id
221 boolean rdp_read_header(rdpRdp* rdp, STREAM* s, uint16* length, uint16* channel_id)
224 enum DomainMCSPDU MCSPDU;
226 MCSPDU = (rdp->settings->server_mode) ? DomainMCSPDU_SendDataRequest : DomainMCSPDU_SendDataIndication;
227 mcs_read_domain_mcspdu_header(s, &MCSPDU, length);
229 per_read_integer16(s, &initiator, MCS_BASE_CHANNEL_ID); /* initiator (UserId) */
230 per_read_integer16(s, channel_id, 0); /* channelId */
231 stream_seek(s, 1); /* dataPriority + Segmentation (0x70) */
232 per_read_length(s, length); /* userData (OCTET_STRING) */
234 if (*length > stream_get_left(s))
241 * Write an RDP packet header.\n
242 * @param rdp rdp module
244 * @param length RDP packet length
245 * @param channel_id channel id
248 void rdp_write_header(rdpRdp* rdp, STREAM* s, uint16 length, uint16 channel_id)
251 enum DomainMCSPDU MCSPDU;
253 MCSPDU = (rdp->settings->server_mode) ? DomainMCSPDU_SendDataIndication : DomainMCSPDU_SendDataRequest;
255 if ((rdp->sec_flags & SEC_ENCRYPT) && (rdp->settings->encryption_method == ENCRYPTION_METHOD_FIPS))
259 body_length = length - RDP_PACKET_HEADER_LENGTH - 16;
260 pad = 8 - (body_length % 8);
265 mcs_write_domain_mcspdu_header(s, MCSPDU, length, 0);
266 per_write_integer16(s, rdp->mcs->user_id, MCS_BASE_CHANNEL_ID); /* initiator */
267 per_write_integer16(s, channel_id, 0); /* channelId */
268 stream_write_uint8(s, 0x70); /* dataPriority + segmentation */
270 length = (length - RDP_PACKET_HEADER_LENGTH) | 0x8000;
271 stream_write_uint16_be(s, length); /* userData (OCTET_STRING) */
274 static uint32 rdp_security_stream_out(rdpRdp* rdp, STREAM* s, int length)
282 sec_flags = rdp->sec_flags;
286 rdp_write_security_header(s, sec_flags);
288 if (sec_flags & SEC_ENCRYPT)
290 if (rdp->settings->encryption_method == ENCRYPTION_METHOD_FIPS)
294 length = length - (data - s->data);
295 stream_write_uint16(s, 0x10); /* length */
296 stream_write_uint8(s, 0x1); /* TSFIPS_VERSION 1*/
299 pad = 8 - (length % 8);
304 memset(data+length, 0, pad);
306 stream_write_uint8(s, pad);
308 security_hmac_signature(data, length, s->p, rdp);
310 security_fips_encrypt(data, length + pad, rdp);
315 length = length - (data - s->data);
318 ml = rdp->rc4_key_len;
319 security_mac_signature(mk, ml, data, length, s->p);
321 security_encrypt(s->p, length, rdp);
331 static uint32 rdp_get_sec_bytes(rdpRdp* rdp)
335 if (rdp->sec_flags & SEC_ENCRYPT)
339 if (rdp->settings->encryption_method == ENCRYPTION_METHOD_FIPS)
342 else if (rdp->sec_flags != 0)
355 * Send an RDP packet.\n
356 * @param rdp RDP module
358 * @param channel_id channel id
361 boolean rdp_send(rdpRdp* rdp, STREAM* s, uint16 channel_id)
367 length = stream_get_length(s);
368 stream_set_pos(s, 0);
370 rdp_write_header(rdp, s, length, channel_id);
372 sec_bytes = rdp_get_sec_bytes(rdp);
374 stream_seek(s, sec_bytes);
377 length += rdp_security_stream_out(rdp, s, length);
379 stream_set_pos(s, length);
380 if (transport_write(rdp->transport, s) < 0)
386 boolean rdp_send_pdu(rdpRdp* rdp, STREAM* s, uint16 type, uint16 channel_id)
392 length = stream_get_length(s);
393 stream_set_pos(s, 0);
395 rdp_write_header(rdp, s, length, MCS_GLOBAL_CHANNEL_ID);
397 sec_bytes = rdp_get_sec_bytes(rdp);
399 stream_seek(s, sec_bytes);
401 rdp_write_share_control_header(s, length, type, channel_id);
404 length += rdp_security_stream_out(rdp, s, length);
406 stream_set_pos(s, length);
407 if (transport_write(rdp->transport, s) < 0)
413 boolean rdp_send_data_pdu(rdpRdp* rdp, STREAM* s, uint8 type, uint16 channel_id)
419 length = stream_get_length(s);
420 stream_set_pos(s, 0);
422 rdp_write_header(rdp, s, length, MCS_GLOBAL_CHANNEL_ID);
424 sec_bytes = rdp_get_sec_bytes(rdp);
426 stream_seek(s, sec_bytes);
428 rdp_write_share_control_header(s, length, PDU_TYPE_DATA, channel_id);
429 rdp_write_share_data_header(s, length, type, rdp->settings->share_id);
432 length += rdp_security_stream_out(rdp, s, length);
434 stream_set_pos(s, length);
435 if (transport_write(rdp->transport, s) < 0)
441 void rdp_recv_set_error_info_data_pdu(rdpRdp* rdp, STREAM* s)
443 stream_read_uint32(s, rdp->errorInfo); /* errorInfo (4 bytes) */
445 if (rdp->errorInfo != ERRINFO_SUCCESS)
446 rdp_print_errinfo(rdp->errorInfo);
449 void rdp_recv_data_pdu(rdpRdp* rdp, STREAM* s)
454 uint8 compressed_type;
455 uint16 compressed_len;
457 rdp_read_share_data_header(s, &length, &type, &share_id, &compressed_type, &compressed_len);
459 #ifdef WITH_DEBUG_RDP
460 if (type != DATA_PDU_TYPE_UPDATE)
461 printf("recv %s Data PDU (0x%02X), length:%d\n", DATA_PDU_TYPE_STRINGS[type], type, length);
466 case DATA_PDU_TYPE_UPDATE:
467 update_recv(rdp->update, s);
470 case DATA_PDU_TYPE_CONTROL:
471 rdp_recv_server_control_pdu(rdp, s);
474 case DATA_PDU_TYPE_POINTER:
475 update_recv_pointer(rdp->update, s);
478 case DATA_PDU_TYPE_INPUT:
481 case DATA_PDU_TYPE_SYNCHRONIZE:
482 rdp_recv_synchronize_pdu(rdp, s);
485 case DATA_PDU_TYPE_REFRESH_RECT:
488 case DATA_PDU_TYPE_PLAY_SOUND:
489 update_recv_play_sound(rdp->update, s);
492 case DATA_PDU_TYPE_SUPPRESS_OUTPUT:
495 case DATA_PDU_TYPE_SHUTDOWN_REQUEST:
498 case DATA_PDU_TYPE_SHUTDOWN_DENIED:
501 case DATA_PDU_TYPE_SAVE_SESSION_INFO:
502 rdp_recv_save_session_info(rdp, s);
505 case DATA_PDU_TYPE_FONT_LIST:
508 case DATA_PDU_TYPE_FONT_MAP:
509 rdp_recv_font_map_pdu(rdp, s);
512 case DATA_PDU_TYPE_SET_KEYBOARD_INDICATORS:
515 case DATA_PDU_TYPE_BITMAP_CACHE_PERSISTENT_LIST:
518 case DATA_PDU_TYPE_BITMAP_CACHE_ERROR:
521 case DATA_PDU_TYPE_SET_KEYBOARD_IME_STATUS:
524 case DATA_PDU_TYPE_OFFSCREEN_CACHE_ERROR:
527 case DATA_PDU_TYPE_SET_ERROR_INFO:
528 rdp_recv_set_error_info_data_pdu(rdp, s);
531 case DATA_PDU_TYPE_DRAW_NINEGRID_ERROR:
534 case DATA_PDU_TYPE_DRAW_GDIPLUS_ERROR:
537 case DATA_PDU_TYPE_ARC_STATUS:
540 case DATA_PDU_TYPE_STATUS_INFO:
543 case DATA_PDU_TYPE_MONITOR_LAYOUT:
551 boolean rdp_recv_out_of_sequence_pdu(rdpRdp* rdp, STREAM* s)
557 rdp_read_share_control_header(s, &length, &type, &channelId);
559 if (type == PDU_TYPE_DATA)
561 rdp_recv_data_pdu(rdp, s);
564 else if (type == PDU_TYPE_SERVER_REDIRECTION)
566 rdp_recv_enhanced_security_redirection_packet(rdp, s);
576 * Decrypt an RDP packet.\n
577 * @param rdp RDP module
582 boolean rdp_decrypt(rdpRdp* rdp, STREAM* s, int length)
584 uint8 cmac[8], wmac[8];
588 if (rdp->settings->encryption_method == ENCRYPTION_METHOD_FIPS)
594 stream_read_uint16(s, len); /* 0x10 */
595 stream_read_uint8(s, version); /* 0x1 */
596 stream_read_uint8(s, pad);
599 stream_seek(s, 8); /* signature */
603 if (!security_fips_decrypt(s->p, length, rdp))
605 printf("FATAL: cannot decrypt\n");
606 return false; /* TODO */
609 if (!security_fips_check_signature(s->p, length - pad, sig, rdp))
611 printf("FATAL: invalid packet signature\n");
612 return false; /* TODO */
615 /* is this what needs adjusting? */
620 stream_read(s, wmac, sizeof(wmac));
621 length -= sizeof(wmac);
622 security_decrypt(s->p, length, rdp);
624 ml = rdp->rc4_key_len;
625 security_mac_signature(mk, ml, s->p, length, cmac);
626 if (memcmp(wmac, cmac, sizeof(wmac)) != 0) {
627 printf("FATAL: invalid packet signature\n");
634 * Process an RDP packet.\n
635 * @param rdp RDP module
639 static boolean rdp_recv_tpkt_pdu(rdpRdp* rdp, STREAM* s)
646 uint32 securityHeader;
648 if (!rdp_read_header(rdp, s, &length, &channelId))
650 printf("Incorrect RDP header.\n");
654 if (rdp->settings->encryption)
656 stream_read_uint32(s, securityHeader);
657 if (securityHeader & SEC_SECURE_CHECKSUM)
659 printf("Error: TODO\n");
662 if (securityHeader & (SEC_ENCRYPT|SEC_REDIRECTION_PKT))
664 if (!rdp_decrypt(rdp, s, length - 4))
666 printf("rdp_decrypt failed\n");
670 if (securityHeader & SEC_REDIRECTION_PKT)
673 * [MS-RDPBCGR] 2.2.13.2.1
674 * - no share control header, nor the 2 byte pad
677 rdp_recv_enhanced_security_redirection_packet(rdp, s);
682 if (channelId != MCS_GLOBAL_CHANNEL_ID)
684 freerdp_channel_process(rdp->instance, s, channelId);
688 rdp_read_share_control_header(s, &pduLength, &pduType, &pduSource);
690 rdp->settings->pdu_source = pduSource;
695 rdp_recv_data_pdu(rdp, s);
698 case PDU_TYPE_DEACTIVATE_ALL:
699 if (!rdp_recv_deactivate_all(rdp, s))
703 case PDU_TYPE_SERVER_REDIRECTION:
704 rdp_recv_enhanced_security_redirection_packet(rdp, s);
708 printf("incorrect PDU type: 0x%04X\n", pduType);
716 static boolean rdp_recv_fastpath_pdu(rdpRdp* rdp, STREAM* s)
719 rdpFastPath* fastpath;
721 fastpath = rdp->fastpath;
722 length = fastpath_read_header_rdp(fastpath, s);
724 if (length == 0 || length > stream_get_left(s))
726 printf("incorrect FastPath PDU header length %d\n", length);
730 if (fastpath->encryptionFlags & FASTPATH_OUTPUT_ENCRYPTED)
732 rdp_decrypt(rdp, s, length);
735 return fastpath_recv_updates(rdp->fastpath, s);
738 static boolean rdp_recv_pdu(rdpRdp* rdp, STREAM* s)
740 if (tpkt_verify_header(s))
741 return rdp_recv_tpkt_pdu(rdp, s);
743 return rdp_recv_fastpath_pdu(rdp, s);
747 * Receive an RDP packet.\n
748 * @param rdp RDP module
751 void rdp_recv(rdpRdp* rdp)
755 s = transport_recv_stream_init(rdp->transport, 4096);
756 transport_read(rdp->transport, s);
758 rdp_recv_pdu(rdp, s);
761 static boolean rdp_recv_callback(rdpTransport* transport, STREAM* s, void* extra)
763 rdpRdp* rdp = (rdpRdp*) extra;
767 case CONNECTION_STATE_NEGO:
768 if (!rdp_client_connect_mcs_connect_response(rdp, s))
772 case CONNECTION_STATE_MCS_ATTACH_USER:
773 if (!rdp_client_connect_mcs_attach_user_confirm(rdp, s))
777 case CONNECTION_STATE_MCS_CHANNEL_JOIN:
778 if (!rdp_client_connect_mcs_channel_join_confirm(rdp, s))
782 case CONNECTION_STATE_LICENSE:
783 if (!rdp_client_connect_license(rdp, s))
787 case CONNECTION_STATE_CAPABILITY:
788 if (!rdp_client_connect_demand_active(rdp, s))
790 printf("rdp_client_connect_demand_active failed\n");
795 case CONNECTION_STATE_FINALIZATION:
796 if (!rdp_recv_pdu(rdp, s))
798 if (rdp->finalize_sc_pdus == FINALIZE_SC_COMPLETE)
799 rdp->state = CONNECTION_STATE_ACTIVE;
802 case CONNECTION_STATE_ACTIVE:
803 if (!rdp_recv_pdu(rdp, s))
808 printf("Invalid state %d\n", rdp->state);
815 int rdp_send_channel_data(rdpRdp* rdp, int channel_id, uint8* data, int size)
817 return freerdp_channel_send(rdp, channel_id, data, size);
821 * Set non-blocking mode information.
822 * @param rdp RDP module
823 * @param blocking blocking mode
825 void rdp_set_blocking_mode(rdpRdp* rdp, boolean blocking)
827 rdp->transport->recv_callback = rdp_recv_callback;
828 rdp->transport->recv_extra = rdp;
829 transport_set_blocking_mode(rdp->transport, blocking);
832 int rdp_check_fds(rdpRdp* rdp)
834 return transport_check_fds(rdp->transport);
838 * Instantiate new RDP module.
839 * @return new RDP module
842 rdpRdp* rdp_new(freerdp* instance)
846 rdp = (rdpRdp*) xzalloc(sizeof(rdpRdp));
850 rdp->instance = instance;
851 rdp->settings = settings_new((void*) instance);
852 if (instance != NULL)
853 instance->settings = rdp->settings;
854 rdp->extension = extension_new(instance);
855 rdp->transport = transport_new(rdp->settings);
856 rdp->license = license_new(rdp);
857 rdp->input = input_new(rdp);
858 rdp->update = update_new(rdp);
859 rdp->fastpath = fastpath_new(rdp);
860 rdp->nego = nego_new(rdp->transport);
861 rdp->mcs = mcs_new(rdp->transport);
862 rdp->redirection = redirection_new();
863 rdp->mppc = mppc_new(rdp);
871 * @param rdp RDP module to be freed
874 void rdp_free(rdpRdp* rdp)
878 extension_free(rdp->extension);
879 settings_free(rdp->settings);
880 transport_free(rdp->transport);
881 license_free(rdp->license);
882 input_free(rdp->input);
883 update_free(rdp->update);
884 fastpath_free(rdp->fastpath);
885 nego_free(rdp->nego);
887 redirection_free(rdp->redirection);