Commit graph

310 commits

Author SHA1 Message Date
ElCruncharino
35d877e128 refactor: make SecureSocket write-retry state per connection
doWrite()'s retry/buffer state was held in function-local static
variables, shared across every SecureSocket instance in the process
rather than per connection. Move it to instance members, and simplify
secureRead()/secureWrite()'s retry counters (also static, but not
load-bearing across calls) to plain locals.
2026-07-28 09:06:06 -04:00
ElCruncharino
59d41b906e fix(win): stop TLS sockets busy-spinning the socket poll loop
pollSocket() caches a socket's writability and skips waiting once it's
known writable, relying on writeSocket() to clear the cache on
WSAEWOULDBLOCK. SecureSocket writes via SSL_write(), bypassing
writeSocket() entirely, so the cache never clears and the multiplexer
spins at a zero timeout instead of blocking whenever TLS hits
backpressure.

Add IArchNetwork::resetPollWriteOnSocket() and call it from
checkResult()'s SSL_ERROR_WANT_WRITE case, mirroring writeSocket()'s
existing WSAEWOULDBLOCK handling.
2026-07-28 09:06:06 -04:00
sithlord48
f3fb31914d refactor: replace use of insert for std::maps with try_emplace 2026-06-22 10:27:35 -04:00
Nick Bolton
4e121dac30 chore: update 'Synergy App Ltd' copyright (company renamed) 2026-06-09 00:06:11 -04:00
Kentaro Hayashi
faf83d7824 fix: drop misleading SSL_set1_host for OpenSSL 4.0.0
It will fix the following warning:

  In member function 'int SecureSocket::secureConnect(int)':
  /build/deskflow.work/src/lib/net/SecureSocket.cpp:479:16: warning: 'int SSL_set1_host(SSL*, const char*)' is deprecated: Since OpenSSL 4.0 [
  -Wdeprecated-declarations]
    479 |   SSL_set1_host(m_ssl->m_ssl, name.c_str());
        |   ~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~
  In file included from /build/deskflow.work/src/lib/net/SslLogger.h:8,
                   from /build/deskflow.work/src/lib/net/SecureSocket.cpp:20:
  /usr/include/openssl/ssl.h:1922:34: note: declared here
   1922 | OSSL_DEPRECATEDIN_4_0 __owur int SSL_set1_host(SSL *s, const char *host);
        |                                  ^~~~~~~~~~~~~

NOTE: It seems that SSL_set1_host setup params for hostname verification, but
it will not be used correctly afterward (See
SSL_CTX_set_cert_verify_callback
in SecureSocket::initContext). This implicit behavior cause misleading
and harmful.

Signed-off-by: Kentaro Hayashi <kenhys@xdump.org>
2026-06-05 10:59:58 +01:00
Kentaro Hayashi
fdb100649b fix: invalid type conversion for OpenSSL 4.0.0
Since OpenSSL 4.0.0, X509_get_subject_name returns const X509_NAME
pointer, thus X509_NAME_add_entry_by_txt does not accept it anymore.

See /usr/include/openssl/x509.h.

Instead, explicitly operates it via mutable X509_NAME object.

It is safe operation without using X509_get_subject_name() because
subject name was not modified after cert = X509_new() assignment.

It will fix the following error.

  error: invalid conversion from 'const X509_name_st*' to 'X509_NAME*' {aka 'X509_name
  _st*'} [-fpermissive]
     87 |   X509_NAME_add_entry_by_txt(name, "CN", MBSTRING_ASC, reinterpret_cast<const unsigned char *>("Deskflow"), -1, -1, 0);
        |                              ^~~~
        |                              |
        |                              const X509_name_st*

Signed-off-by: Kentaro Hayashi <kenhys@xdump.org>
2026-06-05 10:59:58 +01:00
sithlord48
80cc64c238 fix: use Qt localized path for open cert
fixes: #9764
2026-06-01 13:21:20 +01:00
Nick Bolton
bf65080b8b fix: change QString to QByteArray for exception message handling 2026-05-26 12:25:56 -04:00
SASANO Takayoshi
53903016b1 fix: remove unneeded EVP_PKEY_new() (causes memory leak) 2026-05-19 11:56:14 -04:00
SASANO Takayoshi
67f1f41819 chore: remove old OpenSSL support 2026-05-19 11:06:45 +01:00
sithlord48
acf865fa11 refactor(log): Convert LogLevel into a class using LogLevel::Level as its enum, store values as the Option string display as localized string' 2026-05-15 11:47:10 +01:00
sithlord48
8e469379e8 refactor(log): Squash all Debug1 And Debug2 logs into Verbose
fixes: #9725
BREAKING_CHANGE: log level values have changed settings for log level may need to be reset
2026-05-15 11:47:10 +01:00
sithlord48
050397f5b3 refactor: use QStrings for exceptions whats 2026-05-05 13:11:00 +01:00
Nick Bolton
329783490b fix(tls): prevent DoS by removing blocking sleep 2026-04-28 12:36:08 +01:00
Daniel Albers
f9fd0e86b0 fix: Improve SecureSocket handshake and event handling
This fix addresses a busy-loop and stalled connection issue during the TLS
handshake. Previously, SecureSocket incorrectly managed its readiness flags
during negotiation, often polling for 'writability' when OpenSSL was actually
waiting for more 'read' data (or vice versa).

- Explicitly maps SSL_ERROR_WANT_READ and SSL_ERROR_WANT_WRITE to
  socket multiplexer events.
- Resets readiness flags before each handshake attempt to ensure the
  multiplexer receives the most accurate requirements from OpenSSL.
- Restores readability/writability flags upon a successful handshake
  to allow subsequent application-layer protocol exchange.
- Removes inefficient busy-wait sleeps that were masking the loop
  and slowing down handshakes.
2026-04-22 07:12:02 -04:00
Daniel Albers
7d78e55fcc fix: Enable TCP keepalive by default
Deskflow previously lacked support for TCP keepalive, which meant that
dead connections (such as those resulting from a terminated SSH tunnel
or an ungraceful network interruption) could remain in the system's
connection table indefinitely.

This commit adds the setKeepAliveOnSocket method to the IArchNetwork
abstraction and implements it for both BSD/Unix and Winsock/Windows
backends. Keepalive is now enabled by default in TCPSocket::init,
allowing the operating system to eventually detect and clean up
stale connections.
2026-04-22 07:12:02 -04:00
Nick Bolton
66c9b6607c feat(ipc): Messaging for connection states via IPC (async client) 2026-04-07 13:09:29 +01:00
sithlord48
15bae79bf4 refactor: correctly use [[maybe_unused]] 2026-03-30 10:36:15 +01:00
sithlord48
ca6220ad30 refactor: remove redundant c_str when setting logError 2026-03-30 10:36:15 +01:00
sithlord48
f2a54f4af0 buid: replace NIH SYSAPI_WIN32 with Q_OS_WIN 2026-03-06 08:57:31 -05:00
sithlord48
fce1a37e97 build: remove SYSAPI_UNIX define 2026-03-06 08:57:31 -05:00
Luiz Sardinha
220bf3178c fix: correctly deletes sockets that failed to become clients 2026-02-26 12:02:28 +00:00
sithlord48
be4e861604 feat: use Computer in settings to replace name
provide Settings::upgradeSettings to upgrade the screenName -> computerName
Make a note to remove "ScreenName" for 2.0
2026-02-03 18:55:17 +00:00
sithlord48
aca274e9ee refactor: add (C) to copyright header where missing 2026-01-18 15:38:59 +00:00
gayanMatch
35ee17f959 fix: macOS server crash when client disconnects abruptly 2026-01-12 10:49:02 +00:00
sithlord48
7f3d661e31 refactor: net, lookup hostname using any valid Ip4 or Ip6 address
fixes: #9110
2025-12-22 14:24:02 +00:00
sithlord48
27579e4fae refactor: Move file open logic to SecureUtil where its used 2025-12-08 11:24:36 +00:00
sithlord48
cb4621cad7 chore: SecureUtils::generatePemSelfSignedCert take QString for path 2025-12-08 11:24:36 +00:00
sithlord48
a6daff59f6 refactor: SecureSocket::doWrite remove unnessessary reset of bufferSize 2025-12-02 08:37:30 -05:00
sithlord48
dc76366a48 fix: SecureSocket::secureConnect, uset SSL host name before connect 2025-12-02 08:37:30 -05:00
sithlord48
7d07222832 refactor: SecureSocket::loadCertificates(const std::string) & => SecureSocket::loadCertificate(const QString &) 2025-12-02 08:37:30 -05:00
sithlord48
a37d30c6ab refactor: SecureUtils::GenerateFingerprintArt, auto type for char pool 2025-12-01 13:20:47 +00:00
sithlord48
b6bc9202db chore: remove unused SecureUtils::pemFileCertFingerprint 2025-11-27 08:05:04 -05:00
sithlord48
ff02285a6a refactor: move SecureUtils::getCertLength -> TlsUtility, and use Qt to get the length of the key file 2025-11-27 08:05:04 -05:00
sithlord48
1a6f81a34b refactor: SecureUtils use QStringLiterals where possible 2025-11-27 08:05:04 -05:00
sithlord48
2dfba73cfb refactor: use QCryptographicHash::Algorithm in place of Fingerprint::Type 2025-11-27 08:05:04 -05:00
Nick Bolton
39382bfd8c fix: Prevent out-of-bounds access for Qt string when building TLS fingerprint
Only happens when using debug build of Qt lib because release Qt is optimized and doesn't check for bounds for the sake of efficiency.
2025-11-10 21:18:56 +00:00
Nick Bolton
477c7b07e5 chore: Fix typos for var names in formatSSLFingerprintColumns 2025-11-10 21:18:56 +00:00
sithlord48
f8b299ff67 chore: IStream remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
f294daa077 chore: TCPSocketFactoryy remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
e389b2ed56 chore: TCPSocket remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
9b145c2739 chore: SocketMultiplexer remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
bc8dcf76ad chore: SecureUtils remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
93f42df4db chore: SecureListenSocket remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
00f10bdb14 chore: NetworkAddress remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
2ca2500954 chore: ISocket remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
b20201007e chore: IListenSocket remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
959e6b2d0d chore: IDataSocket remove unused includes 2025-11-07 15:54:19 -05:00
sithlord48
5966b8f1b8 chore: SecureSocket remove unused includes 2025-11-06 09:12:18 -05:00
sithlord48
8fadbecf00 chore: make TMethodJob const void* 2025-11-05 22:07:16 +00:00