vnc.c 79.0 KB
Newer Older
B
bellard 已提交
1 2
/*
 * QEMU VNC display driver
3
 *
B
bellard 已提交
4 5
 * Copyright (C) 2006 Anthony Liguori <anthony@codemonkey.ws>
 * Copyright (C) 2006 Fabrice Bellard
6
 * Copyright (C) 2009 Red Hat, Inc
7
 *
B
bellard 已提交
8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */

27
#include "vnc.h"
C
Corentin Chary 已提交
28
#include "vnc-jobs.h"
P
pbrook 已提交
29
#include "sysemu.h"
B
bellard 已提交
30
#include "qemu_socket.h"
P
pbrook 已提交
31
#include "qemu-timer.h"
32
#include "acl.h"
33
#include "qemu-objects.h"
B
bellard 已提交
34

S
Stefano Stabellini 已提交
35 36 37
#define VNC_REFRESH_INTERVAL_BASE 30
#define VNC_REFRESH_INTERVAL_INC  50
#define VNC_REFRESH_INTERVAL_MAX  2000
B
bellard 已提交
38 39

#include "vnc_keysym.h"
40 41
#include "d3des.h"

42 43 44 45 46 47
#define count_bits(c, v) { \
    for (c = 0; v; v >>= 1) \
    { \
        c += v & 1; \
    } \
}
48

49
static VncDisplay *vnc_display; /* needed for info vnc */
50
static DisplayChangeListener *dcl;
B
bellard 已提交
51

G
Gerd Hoffmann 已提交
52 53
static int vnc_cursor_define(VncState *vs);

54 55 56 57 58 59 60
static char *addr_to_string(const char *format,
                            struct sockaddr_storage *sa,
                            socklen_t salen) {
    char *addr;
    char host[NI_MAXHOST];
    char serv[NI_MAXSERV];
    int err;
61
    size_t addrlen;
62 63 64 65 66 67 68 69 70 71

    if ((err = getnameinfo((struct sockaddr *)sa, salen,
                           host, sizeof(host),
                           serv, sizeof(serv),
                           NI_NUMERICHOST | NI_NUMERICSERV)) != 0) {
        VNC_DEBUG("Cannot resolve address %d: %s\n",
                  err, gai_strerror(err));
        return NULL;
    }

72
    /* Enough for the existing format + the 2 vars we're
S
Stefan Weil 已提交
73
     * substituting in. */
74 75 76 77
    addrlen = strlen(format) + strlen(host) + strlen(serv);
    addr = qemu_malloc(addrlen + 1);
    snprintf(addr, addrlen, format, host, serv);
    addr[addrlen] = '\0';
78 79 80 81

    return addr;
}

82 83

char *vnc_socket_local_addr(const char *format, int fd) {
84 85 86 87 88 89 90 91 92 93
    struct sockaddr_storage sa;
    socklen_t salen;

    salen = sizeof(sa);
    if (getsockname(fd, (struct sockaddr*)&sa, &salen) < 0)
        return NULL;

    return addr_to_string(format, &sa, salen);
}

94
char *vnc_socket_remote_addr(const char *format, int fd) {
95 96 97 98 99 100 101 102 103 104
    struct sockaddr_storage sa;
    socklen_t salen;

    salen = sizeof(sa);
    if (getpeername(fd, (struct sockaddr*)&sa, &salen) < 0)
        return NULL;

    return addr_to_string(format, &sa, salen);
}

105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122
static int put_addr_qdict(QDict *qdict, struct sockaddr_storage *sa,
                          socklen_t salen)
{
    char host[NI_MAXHOST];
    char serv[NI_MAXSERV];
    int err;

    if ((err = getnameinfo((struct sockaddr *)sa, salen,
                           host, sizeof(host),
                           serv, sizeof(serv),
                           NI_NUMERICHOST | NI_NUMERICSERV)) != 0) {
        VNC_DEBUG("Cannot resolve address %d: %s\n",
                  err, gai_strerror(err));
        return -1;
    }

    qdict_put(qdict, "host", qstring_from_str(host));
    qdict_put(qdict, "service", qstring_from_str(serv));
L
Luiz Capitulino 已提交
123
    qdict_put(qdict, "family",qstring_from_str(inet_strfamily(sa->ss_family)));
124 125 126 127

    return 0;
}

L
Luiz Capitulino 已提交
128
static int vnc_server_addr_put(QDict *qdict, int fd)
129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
{
    struct sockaddr_storage sa;
    socklen_t salen;

    salen = sizeof(sa);
    if (getsockname(fd, (struct sockaddr*)&sa, &salen) < 0) {
        return -1;
    }

    return put_addr_qdict(qdict, &sa, salen);
}

static int vnc_qdict_remote_addr(QDict *qdict, int fd)
{
    struct sockaddr_storage sa;
    socklen_t salen;

    salen = sizeof(sa);
    if (getpeername(fd, (struct sockaddr*)&sa, &salen) < 0) {
        return -1;
    }

    return put_addr_qdict(qdict, &sa, salen);
}

154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188
static const char *vnc_auth_name(VncDisplay *vd) {
    switch (vd->auth) {
    case VNC_AUTH_INVALID:
        return "invalid";
    case VNC_AUTH_NONE:
        return "none";
    case VNC_AUTH_VNC:
        return "vnc";
    case VNC_AUTH_RA2:
        return "ra2";
    case VNC_AUTH_RA2NE:
        return "ra2ne";
    case VNC_AUTH_TIGHT:
        return "tight";
    case VNC_AUTH_ULTRA:
        return "ultra";
    case VNC_AUTH_TLS:
        return "tls";
    case VNC_AUTH_VENCRYPT:
#ifdef CONFIG_VNC_TLS
        switch (vd->subauth) {
        case VNC_AUTH_VENCRYPT_PLAIN:
            return "vencrypt+plain";
        case VNC_AUTH_VENCRYPT_TLSNONE:
            return "vencrypt+tls+none";
        case VNC_AUTH_VENCRYPT_TLSVNC:
            return "vencrypt+tls+vnc";
        case VNC_AUTH_VENCRYPT_TLSPLAIN:
            return "vencrypt+tls+plain";
        case VNC_AUTH_VENCRYPT_X509NONE:
            return "vencrypt+x509+none";
        case VNC_AUTH_VENCRYPT_X509VNC:
            return "vencrypt+x509+vnc";
        case VNC_AUTH_VENCRYPT_X509PLAIN:
            return "vencrypt+x509+plain";
189 190 191 192
        case VNC_AUTH_VENCRYPT_TLSSASL:
            return "vencrypt+tls+sasl";
        case VNC_AUTH_VENCRYPT_X509SASL:
            return "vencrypt+x509+sasl";
193 194 195 196 197 198
        default:
            return "vencrypt";
        }
#else
        return "vencrypt";
#endif
199
    case VNC_AUTH_SASL:
200
        return "sasl";
201 202 203 204
    }
    return "unknown";
}

L
Luiz Capitulino 已提交
205 206 207 208 209 210 211 212 213 214
static int vnc_server_info_put(QDict *qdict)
{
    if (vnc_server_addr_put(qdict, vnc_display->lsock) < 0) {
        return -1;
    }

    qdict_put(qdict, "auth", qstring_from_str(vnc_auth_name(vnc_display)));
    return 0;
}

215
static void vnc_client_cache_auth(VncState *client)
216
{
B
Blue Swirl 已提交
217
#if defined(CONFIG_VNC_TLS) || defined(CONFIG_VNC_SASL)
218
    QDict *qdict;
B
Blue Swirl 已提交
219
#endif
220

221 222
    if (!client->info) {
        return;
223
    }
224

B
Blue Swirl 已提交
225
#if defined(CONFIG_VNC_TLS) || defined(CONFIG_VNC_SASL)
226
    qdict = qobject_to_qdict(client->info);
B
Blue Swirl 已提交
227
#endif
228

229 230
#ifdef CONFIG_VNC_TLS
    if (client->tls.session &&
231 232 233
        client->tls.dname) {
        qdict_put(qdict, "x509_dname", qstring_from_str(client->tls.dname));
    }
234 235 236
#endif
#ifdef CONFIG_VNC_SASL
    if (client->sasl.conn &&
237
        client->sasl.username) {
238 239
        qdict_put(qdict, "sasl_username",
                  qstring_from_str(client->sasl.username));
240
    }
241
#endif
242
}
243

244 245 246 247 248 249 250 251 252 253 254 255
static void vnc_client_cache_addr(VncState *client)
{
    QDict *qdict;

    qdict = qdict_new();
    if (vnc_qdict_remote_addr(qdict, client->csock) < 0) {
        QDECREF(qdict);
        /* XXX: how to report the error? */
        return;
    }

    client->info = QOBJECT(qdict);
256 257
}

258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281
static void vnc_qmp_event(VncState *vs, MonitorEvent event)
{
    QDict *server;
    QObject *data;

    if (!vs->info) {
        return;
    }

    server = qdict_new();
    if (vnc_server_info_put(server) < 0) {
        QDECREF(server);
        return;
    }

    data = qobject_from_jsonf("{ 'client': %p, 'server': %p }",
                              vs->info, QOBJECT(server));

    monitor_protocol_event(event, data);

    qobject_incref(vs->info);
    qobject_decref(data);
}

282
static void info_vnc_iter(QObject *obj, void *opaque)
B
bellard 已提交
283
{
284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299
    QDict *client;
    Monitor *mon = opaque;

    client = qobject_to_qdict(obj);
    monitor_printf(mon, "Client:\n");
    monitor_printf(mon, "     address: %s:%s\n",
                   qdict_get_str(client, "host"),
                   qdict_get_str(client, "service"));

#ifdef CONFIG_VNC_TLS
    monitor_printf(mon, "  x509_dname: %s\n",
        qdict_haskey(client, "x509_dname") ?
        qdict_get_str(client, "x509_dname") : "none");
#endif
#ifdef CONFIG_VNC_SASL
    monitor_printf(mon, "    username: %s\n",
300 301
        qdict_haskey(client, "sasl_username") ?
        qdict_get_str(client, "sasl_username") : "none");
302 303 304 305 306 307 308 309 310
#endif
}

void do_info_vnc_print(Monitor *mon, const QObject *data)
{
    QDict *server;
    QList *clients;

    server = qobject_to_qdict(data);
311
    if (qdict_get_bool(server, "enabled") == 0) {
312
        monitor_printf(mon, "Server: disabled\n");
313 314
        return;
    }
315

316 317 318 319
    monitor_printf(mon, "Server:\n");
    monitor_printf(mon, "     address: %s:%s\n",
                   qdict_get_str(server, "host"),
                   qdict_get_str(server, "service"));
L
Luiz Capitulino 已提交
320
    monitor_printf(mon, "        auth: %s\n", qdict_get_str(server, "auth"));
321 322 323 324 325 326 327 328

    clients = qdict_get_qlist(server, "clients");
    if (qlist_empty(clients)) {
        monitor_printf(mon, "Client: none\n");
    } else {
        qlist_iter(clients, info_vnc_iter, mon);
    }
}
329

330 331 332
void do_info_vnc(Monitor *mon, QObject **ret_data)
{
    if (vnc_display == NULL || vnc_display->display == NULL) {
333
        *ret_data = qobject_from_jsonf("{ 'enabled': false }");
334 335
    } else {
        QList *clist;
336
        VncState *client;
337

338
        clist = qlist_new();
339 340 341 342 343
        QTAILQ_FOREACH(client, &vnc_display->clients, next) {
            if (client->info) {
                /* incref so that it's not freed by upper layers */
                qobject_incref(client->info);
                qlist_append_obj(clist, client->info);
344
            }
345 346
        }

347
        *ret_data = qobject_from_jsonf("{ 'enabled': true, 'clients': %p }",
348 349 350
                                       QOBJECT(clist));
        assert(*ret_data != NULL);

L
Luiz Capitulino 已提交
351
        if (vnc_server_info_put(qobject_to_qdict(*ret_data)) < 0) {
352 353
            qobject_decref(*ret_data);
            *ret_data = NULL;
354
        }
B
bellard 已提交
355 356 357
    }
}

B
bellard 已提交
358 359 360 361 362 363 364
/* TODO
   1) Get the queue working for IO.
   2) there is some weirdness when using the -S option (the screen is grey
      and not totally invalidated
   3) resolutions > 1024
*/

S
Stefano Stabellini 已提交
365
static int vnc_update_client(VncState *vs, int has_dirty);
C
Corentin Chary 已提交
366
static int vnc_update_client_sync(VncState *vs, int has_dirty);
367 368
static void vnc_disconnect_start(VncState *vs);
static void vnc_disconnect_finish(VncState *vs);
369 370
static void vnc_init_timer(VncDisplay *vd);
static void vnc_remove_timer(VncDisplay *vd);
B
bellard 已提交
371

372
static void vnc_colordepth(VncState *vs);
S
Stefano Stabellini 已提交
373 374 375 376 377
static void framebuffer_update_request(VncState *vs, int incremental,
                                       int x_position, int y_position,
                                       int w, int h);
static void vnc_refresh(void *opaque);
static int vnc_refresh_server_surface(VncDisplay *vd);
378

B
bellard 已提交
379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397
static inline void vnc_set_bit(uint32_t *d, int k)
{
    d[k >> 5] |= 1 << (k & 0x1f);
}

static inline void vnc_clear_bit(uint32_t *d, int k)
{
    d[k >> 5] &= ~(1 << (k & 0x1f));
}

static inline void vnc_set_bits(uint32_t *d, int n, int nb_words)
{
    int j;

    j = 0;
    while (n >= 32) {
        d[j++] = -1;
        n -= 32;
    }
398
    if (n > 0)
B
bellard 已提交
399 400 401 402 403 404 405 406 407 408
        d[j++] = (1 << n) - 1;
    while (j < nb_words)
        d[j++] = 0;
}

static inline int vnc_get_bit(const uint32_t *d, int k)
{
    return (d[k >> 5] >> (k & 0x1f)) & 1;
}

409
static inline int vnc_and_bits(const uint32_t *d1, const uint32_t *d2,
B
bellard 已提交
410 411 412 413 414 415 416 417 418 419
                               int nb_words)
{
    int i;
    for(i = 0; i < nb_words; i++) {
        if ((d1[i] & d2[i]) != 0)
            return 1;
    }
    return 0;
}

S
Stefano Stabellini 已提交
420
static void vnc_dpy_update(DisplayState *ds, int x, int y, int w, int h)
B
bellard 已提交
421 422
{
    int i;
S
Stefano Stabellini 已提交
423 424
    VncDisplay *vd = ds->opaque;
    struct VncSurface *s = &vd->guest;
B
bellard 已提交
425 426 427

    h += y;

428 429 430 431 432 433 434
    /* round x down to ensure the loop only spans one 16-pixel block per,
       iteration.  otherwise, if (x % 16) != 0, the last iteration may span
       two 16-pixel blocks but we only mark the first as dirty
    */
    w += (x % 16);
    x -= (x % 16);

435 436 437 438
    x = MIN(x, s->ds->width);
    y = MIN(y, s->ds->height);
    w = MIN(x + w, s->ds->width) - x;
    h = MIN(h, s->ds->height);
439

B
bellard 已提交
440
    for (; y < h; y++)
441
        for (i = 0; i < w; i += 16)
442
            vnc_set_bit(s->dirty[y], (x + i) / 16);
B
bellard 已提交
443 444
}

445 446
void vnc_framebuffer_update(VncState *vs, int x, int y, int w, int h,
                            int32_t encoding)
B
bellard 已提交
447 448 449 450 451 452 453 454 455
{
    vnc_write_u16(vs, x);
    vnc_write_u16(vs, y);
    vnc_write_u16(vs, w);
    vnc_write_u16(vs, h);

    vnc_write_s32(vs, encoding);
}

456
void buffer_reserve(Buffer *buffer, size_t len)
457 458
{
    if ((buffer->capacity - buffer->offset) < len) {
459 460 461 462 463 464
        buffer->capacity += (len + 1024);
        buffer->buffer = qemu_realloc(buffer->buffer, buffer->capacity);
        if (buffer->buffer == NULL) {
            fprintf(stderr, "vnc: out of memory\n");
            exit(1);
        }
465 466 467
    }
}

468
int buffer_empty(Buffer *buffer)
469 470 471 472
{
    return buffer->offset == 0;
}

473
uint8_t *buffer_end(Buffer *buffer)
474 475 476 477
{
    return buffer->buffer + buffer->offset;
}

478
void buffer_reset(Buffer *buffer)
479
{
480
        buffer->offset = 0;
481 482
}

C
Corentin Chary 已提交
483 484 485 486 487 488 489 490
void buffer_free(Buffer *buffer)
{
    qemu_free(buffer->buffer);
    buffer->offset = 0;
    buffer->capacity = 0;
    buffer->buffer = NULL;
}

491
void buffer_append(Buffer *buffer, const void *data, size_t len)
492 493 494 495 496
{
    memcpy(buffer->buffer + buffer->offset, data, len);
    buffer->offset += len;
}

497 498 499 500 501 502 503
static void vnc_desktop_resize(VncState *vs)
{
    DisplayState *ds = vs->ds;

    if (vs->csock == -1 || !vnc_has_feature(vs, VNC_FEATURE_RESIZE)) {
        return;
    }
504 505 506 507
    if (vs->client_width == ds_get_width(ds) &&
        vs->client_height == ds_get_height(ds)) {
        return;
    }
508 509
    vs->client_width = ds_get_width(ds);
    vs->client_height = ds_get_height(ds);
C
Corentin Chary 已提交
510
    vnc_lock_output(vs);
511 512 513
    vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
    vnc_write_u8(vs, 0);
    vnc_write_u16(vs, 1); /* number of rects */
514
    vnc_framebuffer_update(vs, 0, 0, vs->client_width, vs->client_height,
515
                           VNC_ENCODING_DESKTOPRESIZE);
C
Corentin Chary 已提交
516
    vnc_unlock_output(vs);
517 518 519
    vnc_flush(vs);
}

C
Corentin Chary 已提交
520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544
#ifdef CONFIG_VNC_THREAD
static void vnc_abort_display_jobs(VncDisplay *vd)
{
    VncState *vs;

    QTAILQ_FOREACH(vs, &vd->clients, next) {
        vnc_lock_output(vs);
        vs->abort = true;
        vnc_unlock_output(vs);
    }
    QTAILQ_FOREACH(vs, &vd->clients, next) {
        vnc_jobs_join(vs);
    }
    QTAILQ_FOREACH(vs, &vd->clients, next) {
        vnc_lock_output(vs);
        vs->abort = false;
        vnc_unlock_output(vs);
    }
}
#else
static void vnc_abort_display_jobs(VncDisplay *vd)
{
}
#endif

S
Stefano Stabellini 已提交
545
static void vnc_dpy_resize(DisplayState *ds)
B
bellard 已提交
546
{
S
Stefano Stabellini 已提交
547
    VncDisplay *vd = ds->opaque;
548
    VncState *vs;
S
Stefano Stabellini 已提交
549

C
Corentin Chary 已提交
550 551
    vnc_abort_display_jobs(vd);

S
Stefano Stabellini 已提交
552 553 554 555 556 557 558 559
    /* server surface */
    if (!vd->server)
        vd->server = qemu_mallocz(sizeof(*vd->server));
    if (vd->server->data)
        qemu_free(vd->server->data);
    *(vd->server) = *(ds->surface);
    vd->server->data = qemu_mallocz(vd->server->linesize *
                                    vd->server->height);
B
bellard 已提交
560

561
    /* guest surface */
S
Stefano Stabellini 已提交
562 563 564
    if (!vd->guest.ds)
        vd->guest.ds = qemu_mallocz(sizeof(*vd->guest.ds));
    if (ds_get_bytes_per_pixel(ds) != vd->guest.ds->pf.bytes_per_pixel)
565
        console_color_init(ds);
S
Stefano Stabellini 已提交
566 567
    *(vd->guest.ds) = *(ds->surface);
    memset(vd->guest.dirty, 0xFF, sizeof(vd->guest.dirty));
B
bellard 已提交
568

569
    QTAILQ_FOREACH(vs, &vd->clients, next) {
S
Stefano Stabellini 已提交
570
        vnc_colordepth(vs);
571
        vnc_desktop_resize(vs);
G
Gerd Hoffmann 已提交
572 573 574
        if (vs->vd->cursor) {
            vnc_cursor_define(vs);
        }
S
Stefano Stabellini 已提交
575
        memset(vs->dirty, 0xFF, sizeof(vs->dirty));
576 577 578
    }
}

B
bellard 已提交
579
/* fastest code */
G
Gerd Hoffmann 已提交
580 581
static void vnc_write_pixels_copy(VncState *vs, struct PixelFormat *pf,
                                  void *pixels, int size)
B
bellard 已提交
582 583 584 585 586
{
    vnc_write(vs, pixels, size);
}

/* slowest but generic code. */
587
void vnc_convert_pixel(VncState *vs, uint8_t *buf, uint32_t v)
B
bellard 已提交
588
{
589
    uint8_t r, g, b;
S
Stefano Stabellini 已提交
590 591 592 593 594 595 596 597
    VncDisplay *vd = vs->vd;

    r = ((((v & vd->server->pf.rmask) >> vd->server->pf.rshift) << vs->clientds.pf.rbits) >>
        vd->server->pf.rbits);
    g = ((((v & vd->server->pf.gmask) >> vd->server->pf.gshift) << vs->clientds.pf.gbits) >>
        vd->server->pf.gbits);
    b = ((((v & vd->server->pf.bmask) >> vd->server->pf.bshift) << vs->clientds.pf.bbits) >>
        vd->server->pf.bbits);
598 599 600 601
    v = (r << vs->clientds.pf.rshift) |
        (g << vs->clientds.pf.gshift) |
        (b << vs->clientds.pf.bshift);
    switch(vs->clientds.pf.bytes_per_pixel) {
B
bellard 已提交
602 603 604 605
    case 1:
        buf[0] = v;
        break;
    case 2:
606
        if (vs->clientds.flags & QEMU_BIG_ENDIAN_FLAG) {
B
bellard 已提交
607 608 609 610 611 612 613 614 615
            buf[0] = v >> 8;
            buf[1] = v;
        } else {
            buf[1] = v >> 8;
            buf[0] = v;
        }
        break;
    default:
    case 4:
616
        if (vs->clientds.flags & QEMU_BIG_ENDIAN_FLAG) {
B
bellard 已提交
617 618 619 620 621 622 623 624 625 626 627 628 629 630
            buf[0] = v >> 24;
            buf[1] = v >> 16;
            buf[2] = v >> 8;
            buf[3] = v;
        } else {
            buf[3] = v >> 24;
            buf[2] = v >> 16;
            buf[1] = v >> 8;
            buf[0] = v;
        }
        break;
    }
}

G
Gerd Hoffmann 已提交
631 632
static void vnc_write_pixels_generic(VncState *vs, struct PixelFormat *pf,
                                     void *pixels1, int size)
B
bellard 已提交
633 634 635
{
    uint8_t buf[4];

G
Gerd Hoffmann 已提交
636
    if (pf->bytes_per_pixel == 4) {
637 638 639 640 641
        uint32_t *pixels = pixels1;
        int n, i;
        n = size >> 2;
        for(i = 0; i < n; i++) {
            vnc_convert_pixel(vs, buf, pixels[i]);
642
            vnc_write(vs, buf, vs->clientds.pf.bytes_per_pixel);
643
        }
G
Gerd Hoffmann 已提交
644
    } else if (pf->bytes_per_pixel == 2) {
645 646 647 648 649
        uint16_t *pixels = pixels1;
        int n, i;
        n = size >> 1;
        for(i = 0; i < n; i++) {
            vnc_convert_pixel(vs, buf, pixels[i]);
650
            vnc_write(vs, buf, vs->clientds.pf.bytes_per_pixel);
651
        }
G
Gerd Hoffmann 已提交
652
    } else if (pf->bytes_per_pixel == 1) {
653 654 655 656 657
        uint8_t *pixels = pixels1;
        int n, i;
        n = size;
        for(i = 0; i < n; i++) {
            vnc_convert_pixel(vs, buf, pixels[i]);
658
            vnc_write(vs, buf, vs->clientds.pf.bytes_per_pixel);
659 660 661
        }
    } else {
        fprintf(stderr, "vnc_write_pixels_generic: VncState color depth not supported\n");
B
bellard 已提交
662 663 664
    }
}

665
int vnc_raw_send_framebuffer_update(VncState *vs, int x, int y, int w, int h)
B
bellard 已提交
666 667
{
    int i;
T
ths 已提交
668
    uint8_t *row;
S
Stefano Stabellini 已提交
669
    VncDisplay *vd = vs->vd;
B
bellard 已提交
670

S
Stefano Stabellini 已提交
671
    row = vd->server->data + y * ds_get_linesize(vs->ds) + x * ds_get_bytes_per_pixel(vs->ds);
B
bellard 已提交
672
    for (i = 0; i < h; i++) {
G
Gerd Hoffmann 已提交
673
        vs->write_pixels(vs, &vd->server->pf, row, w * ds_get_bytes_per_pixel(vs->ds));
674
        row += ds_get_linesize(vs->ds);
B
bellard 已提交
675
    }
676
    return 1;
B
bellard 已提交
677 678
}

C
Corentin Chary 已提交
679
int vnc_send_framebuffer_update(VncState *vs, int x, int y, int w, int h)
B
bellard 已提交
680
{
681 682
    int n = 0;

683
    switch(vs->vnc_encoding) {
684
        case VNC_ENCODING_ZLIB:
685
            n = vnc_zlib_send_framebuffer_update(vs, x, y, w, h);
686 687 688
            break;
        case VNC_ENCODING_HEXTILE:
            vnc_framebuffer_update(vs, x, y, w, h, VNC_ENCODING_HEXTILE);
689
            n = vnc_hextile_send_framebuffer_update(vs, x, y, w, h);
690
            break;
C
Corentin Chary 已提交
691 692 693
        case VNC_ENCODING_TIGHT:
            n = vnc_tight_send_framebuffer_update(vs, x, y, w, h);
            break;
C
Corentin Chary 已提交
694 695 696
        case VNC_ENCODING_TIGHT_PNG:
            n = vnc_tight_png_send_framebuffer_update(vs, x, y, w, h);
            break;
697 698
        default:
            vnc_framebuffer_update(vs, x, y, w, h, VNC_ENCODING_RAW);
699
            n = vnc_raw_send_framebuffer_update(vs, x, y, w, h);
700
            break;
701
    }
702
    return n;
B
bellard 已提交
703 704
}

705
static void vnc_copy(VncState *vs, int src_x, int src_y, int dst_x, int dst_y, int w, int h)
B
bellard 已提交
706
{
707
    /* send bitblit op to the vnc client */
C
Corentin Chary 已提交
708
    vnc_lock_output(vs);
709
    vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
B
bellard 已提交
710 711
    vnc_write_u8(vs, 0);
    vnc_write_u16(vs, 1); /* number of rects */
712
    vnc_framebuffer_update(vs, dst_x, dst_y, w, h, VNC_ENCODING_COPYRECT);
B
bellard 已提交
713 714
    vnc_write_u16(vs, src_x);
    vnc_write_u16(vs, src_y);
C
Corentin Chary 已提交
715
    vnc_unlock_output(vs);
B
bellard 已提交
716 717 718
    vnc_flush(vs);
}

719 720 721
static void vnc_dpy_copy(DisplayState *ds, int src_x, int src_y, int dst_x, int dst_y, int w, int h)
{
    VncDisplay *vd = ds->opaque;
722
    VncState *vs, *vn;
S
Stefano Stabellini 已提交
723 724 725 726
    uint8_t *src_row;
    uint8_t *dst_row;
    int i,x,y,pitch,depth,inc,w_lim,s;
    int cmp_bytes;
727

S
Stefano Stabellini 已提交
728
    vnc_refresh_server_surface(vd);
729
    QTAILQ_FOREACH_SAFE(vs, &vd->clients, next, vn) {
730 731
        if (vnc_has_feature(vs, VNC_FEATURE_COPYRECT)) {
            vs->force_update = 1;
C
Corentin Chary 已提交
732
            vnc_update_client_sync(vs, 1);
733 734 735 736
            /* vs might be free()ed here */
        }
    }

S
Stefano Stabellini 已提交
737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772
    /* do bitblit op on the local surface too */
    pitch = ds_get_linesize(vd->ds);
    depth = ds_get_bytes_per_pixel(vd->ds);
    src_row = vd->server->data + pitch * src_y + depth * src_x;
    dst_row = vd->server->data + pitch * dst_y + depth * dst_x;
    y = dst_y;
    inc = 1;
    if (dst_y > src_y) {
        /* copy backwards */
        src_row += pitch * (h-1);
        dst_row += pitch * (h-1);
        pitch = -pitch;
        y = dst_y + h - 1;
        inc = -1;
    }
    w_lim = w - (16 - (dst_x % 16));
    if (w_lim < 0)
        w_lim = w;
    else
        w_lim = w - (w_lim % 16);
    for (i = 0; i < h; i++) {
        for (x = 0; x <= w_lim;
                x += s, src_row += cmp_bytes, dst_row += cmp_bytes) {
            if (x == w_lim) {
                if ((s = w - w_lim) == 0)
                    break;
            } else if (!x) {
                s = (16 - (dst_x % 16));
                s = MIN(s, w_lim);
            } else {
                s = 16;
            }
            cmp_bytes = s * depth;
            if (memcmp(src_row, dst_row, cmp_bytes) == 0)
                continue;
            memmove(dst_row, src_row, cmp_bytes);
773 774
            QTAILQ_FOREACH(vs, &vd->clients, next) {
                if (!vnc_has_feature(vs, VNC_FEATURE_COPYRECT)) {
S
Stefano Stabellini 已提交
775
                    vnc_set_bit(vs->dirty[y], ((x + dst_x) / 16));
776
                }
S
Stefano Stabellini 已提交
777 778 779 780 781 782 783
            }
        }
        src_row += pitch - w * depth;
        dst_row += pitch - w * depth;
        y += inc;
    }

784 785
    QTAILQ_FOREACH(vs, &vd->clients, next) {
        if (vnc_has_feature(vs, VNC_FEATURE_COPYRECT)) {
786
            vnc_copy(vs, src_x, src_y, dst_x, dst_y, w, h);
787
        }
788 789 790
    }
}

G
Gerd Hoffmann 已提交
791 792 793 794 795 796 797 798 799 800 801 802
static void vnc_mouse_set(int x, int y, int visible)
{
    /* can we ask the client(s) to move the pointer ??? */
}

static int vnc_cursor_define(VncState *vs)
{
    QEMUCursor *c = vs->vd->cursor;
    PixelFormat pf = qemu_default_pixelformat(32);
    int isize;

    if (vnc_has_feature(vs, VNC_FEATURE_RICH_CURSOR)) {
803
        vnc_lock_output(vs);
G
Gerd Hoffmann 已提交
804 805 806 807 808 809 810 811
        vnc_write_u8(vs,  VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
        vnc_write_u8(vs,  0);  /*  padding     */
        vnc_write_u16(vs, 1);  /*  # of rects  */
        vnc_framebuffer_update(vs, c->hot_x, c->hot_y, c->width, c->height,
                               VNC_ENCODING_RICH_CURSOR);
        isize = c->width * c->height * vs->clientds.pf.bytes_per_pixel;
        vnc_write_pixels_generic(vs, &pf, c->data, isize);
        vnc_write(vs, vs->vd->cursor_mask, vs->vd->cursor_msize);
812
        vnc_unlock_output(vs);
G
Gerd Hoffmann 已提交
813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836
        return 0;
    }
    return -1;
}

static void vnc_dpy_cursor_define(QEMUCursor *c)
{
    VncDisplay *vd = vnc_display;
    VncState *vs;

    cursor_put(vd->cursor);
    qemu_free(vd->cursor_mask);

    vd->cursor = c;
    cursor_get(vd->cursor);
    vd->cursor_msize = cursor_get_mono_bpl(c) * c->height;
    vd->cursor_mask = qemu_mallocz(vd->cursor_msize);
    cursor_get_mono_mask(c, 0, vd->cursor_mask);

    QTAILQ_FOREACH(vs, &vd->clients, next) {
        vnc_cursor_define(vs);
    }
}

S
Stefano Stabellini 已提交
837
static int find_and_clear_dirty_height(struct VncState *vs,
838
                                       int y, int last_x, int x)
B
bellard 已提交
839 840
{
    int h;
S
Stefano Stabellini 已提交
841
    VncDisplay *vd = vs->vd;
B
bellard 已提交
842

S
Stefano Stabellini 已提交
843
    for (h = 1; h < (vd->server->height - y); h++) {
844
        int tmp_x;
S
Stefano Stabellini 已提交
845
        if (!vnc_get_bit(vs->dirty[y + h], last_x))
846 847
            break;
        for (tmp_x = last_x; tmp_x < x; tmp_x++)
S
Stefano Stabellini 已提交
848
            vnc_clear_bit(vs->dirty[y + h], tmp_x);
B
bellard 已提交
849 850 851 852 853
    }

    return h;
}

C
Corentin Chary 已提交
854 855 856 857 858 859 860 861 862 863 864 865 866 867
#ifdef CONFIG_VNC_THREAD
static int vnc_update_client_sync(VncState *vs, int has_dirty)
{
    int ret = vnc_update_client(vs, has_dirty);
    vnc_jobs_join(vs);
    return ret;
}
#else
static int vnc_update_client_sync(VncState *vs, int has_dirty)
{
    return vnc_update_client(vs, has_dirty);
}
#endif

S
Stefano Stabellini 已提交
868
static int vnc_update_client(VncState *vs, int has_dirty)
B
bellard 已提交
869 870
{
    if (vs->need_update && vs->csock != -1) {
S
Stefano Stabellini 已提交
871
        VncDisplay *vd = vs->vd;
C
Corentin Chary 已提交
872
        VncJob *job;
873
        int y;
874
        int width, height;
C
Corentin Chary 已提交
875 876
        int n = 0;

B
bellard 已提交
877

878
        if (vs->output.offset && !vs->audio_cap && !vs->force_update)
879
            /* kernel send buffers are full -> drop frames to throttle */
S
Stefano Stabellini 已提交
880
            return 0;
881

882
        if (!has_dirty && !vs->audio_cap && !vs->force_update)
S
Stefano Stabellini 已提交
883
            return 0;
884

885 886 887 888 889 890
        /*
         * Send screen updates to the vnc client using the server
         * surface and server dirty map.  guest surface updates
         * happening in parallel don't disturb us, the next pass will
         * send them to the client.
         */
C
Corentin Chary 已提交
891
        job = vnc_job_new(vs);
892

893 894 895 896
        width = MIN(vd->server->width, vs->client_width);
        height = MIN(vd->server->height, vs->client_height);

        for (y = 0; y < height; y++) {
897 898
            int x;
            int last_x = -1;
899
            for (x = 0; x < width / 16; x++) {
S
Stefano Stabellini 已提交
900
                if (vnc_get_bit(vs->dirty[y], x)) {
901 902 903
                    if (last_x == -1) {
                        last_x = x;
                    }
S
Stefano Stabellini 已提交
904
                    vnc_clear_bit(vs->dirty[y], x);
905 906
                } else {
                    if (last_x != -1) {
S
Stefano Stabellini 已提交
907
                        int h = find_and_clear_dirty_height(vs, y, last_x, x);
C
Corentin Chary 已提交
908 909 910

                        n += vnc_job_add_rect(job, last_x * 16, y,
                                              (x - last_x) * 16, h);
911 912 913 914 915
                    }
                    last_x = -1;
                }
            }
            if (last_x != -1) {
S
Stefano Stabellini 已提交
916
                int h = find_and_clear_dirty_height(vs, y, last_x, x);
C
Corentin Chary 已提交
917 918
                n += vnc_job_add_rect(job, last_x * 16, y,
                                      (x - last_x) * 16, h);
919 920
            }
        }
C
Corentin Chary 已提交
921 922

        vnc_job_push(job);
923
        vs->force_update = 0;
C
Corentin Chary 已提交
924
        return n;
B
bellard 已提交
925 926
    }

927
    if (vs->csock == -1)
928
        vnc_disconnect_finish(vs);
S
Stefano Stabellini 已提交
929 930

    return 0;
B
bellard 已提交
931 932
}

M
malc 已提交
933 934 935 936 937 938 939
/* audio */
static void audio_capture_notify(void *opaque, audcnotification_e cmd)
{
    VncState *vs = opaque;

    switch (cmd) {
    case AUD_CNOTIFY_DISABLE:
C
Corentin Chary 已提交
940
        vnc_lock_output(vs);
941 942 943
        vnc_write_u8(vs, VNC_MSG_SERVER_QEMU);
        vnc_write_u8(vs, VNC_MSG_SERVER_QEMU_AUDIO);
        vnc_write_u16(vs, VNC_MSG_SERVER_QEMU_AUDIO_END);
C
Corentin Chary 已提交
944
        vnc_unlock_output(vs);
M
malc 已提交
945 946 947 948
        vnc_flush(vs);
        break;

    case AUD_CNOTIFY_ENABLE:
C
Corentin Chary 已提交
949
        vnc_lock_output(vs);
950 951 952
        vnc_write_u8(vs, VNC_MSG_SERVER_QEMU);
        vnc_write_u8(vs, VNC_MSG_SERVER_QEMU_AUDIO);
        vnc_write_u16(vs, VNC_MSG_SERVER_QEMU_AUDIO_BEGIN);
C
Corentin Chary 已提交
953
        vnc_unlock_output(vs);
M
malc 已提交
954 955 956 957 958 959 960 961 962 963 964 965 966
        vnc_flush(vs);
        break;
    }
}

static void audio_capture_destroy(void *opaque)
{
}

static void audio_capture(void *opaque, void *buf, int size)
{
    VncState *vs = opaque;

C
Corentin Chary 已提交
967
    vnc_lock_output(vs);
968 969 970
    vnc_write_u8(vs, VNC_MSG_SERVER_QEMU);
    vnc_write_u8(vs, VNC_MSG_SERVER_QEMU_AUDIO);
    vnc_write_u16(vs, VNC_MSG_SERVER_QEMU_AUDIO_DATA);
M
malc 已提交
971 972
    vnc_write_u32(vs, size);
    vnc_write(vs, buf, size);
C
Corentin Chary 已提交
973
    vnc_unlock_output(vs);
M
malc 已提交
974 975 976 977 978 979 980 981
    vnc_flush(vs);
}

static void audio_add(VncState *vs)
{
    struct audio_capture_ops ops;

    if (vs->audio_cap) {
982
        monitor_printf(default_mon, "audio already running\n");
M
malc 已提交
983 984 985 986 987 988 989
        return;
    }

    ops.notify = audio_capture_notify;
    ops.destroy = audio_capture_destroy;
    ops.capture = audio_capture;

990
    vs->audio_cap = AUD_add_capture(&vs->as, &ops, vs);
M
malc 已提交
991
    if (!vs->audio_cap) {
992
        monitor_printf(default_mon, "Failed to add audio capture\n");
M
malc 已提交
993 994 995 996 997 998 999 1000 1001 1002 1003
    }
}

static void audio_del(VncState *vs)
{
    if (vs->audio_cap) {
        AUD_del_capture(vs->audio_cap, vs);
        vs->audio_cap = NULL;
    }
}

1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014
static void vnc_disconnect_start(VncState *vs)
{
    if (vs->csock == -1)
        return;
    qemu_set_fd_handler2(vs->csock, NULL, NULL, NULL, NULL);
    closesocket(vs->csock);
    vs->csock = -1;
}

static void vnc_disconnect_finish(VncState *vs)
{
C
Corentin Chary 已提交
1015 1016 1017
    vnc_jobs_join(vs); /* Wait encoding jobs */

    vnc_lock_output(vs);
1018 1019
    vnc_qmp_event(vs, QEVENT_VNC_DISCONNECTED);

C
Corentin Chary 已提交
1020 1021
    buffer_free(&vs->input);
    buffer_free(&vs->output);
1022 1023 1024

    qobject_decref(vs->info);

1025
    vnc_zlib_clear(vs);
C
Corentin Chary 已提交
1026
    vnc_tight_clear(vs);
1027

1028 1029 1030 1031 1032 1033 1034 1035
#ifdef CONFIG_VNC_TLS
    vnc_tls_client_cleanup(vs);
#endif /* CONFIG_VNC_TLS */
#ifdef CONFIG_VNC_SASL
    vnc_sasl_client_cleanup(vs);
#endif /* CONFIG_VNC_SASL */
    audio_del(vs);

1036 1037 1038
    QTAILQ_REMOVE(&vs->vd->clients, vs, next);

    if (QTAILQ_EMPTY(&vs->vd->clients)) {
1039
        dcl->idle = 1;
1040
    }
1041

1042
    qemu_remove_mouse_mode_change_notifier(&vs->mouse_mode_notifier);
1043
    vnc_remove_timer(vs->vd);
G
Gerd Hoffmann 已提交
1044 1045
    if (vs->vd->lock_key_sync)
        qemu_remove_led_event_handler(vs->led);
C
Corentin Chary 已提交
1046 1047 1048 1049 1050
    vnc_unlock_output(vs);

#ifdef CONFIG_VNC_THREAD
    qemu_mutex_destroy(&vs->output_mutex);
#endif
G
Glauber Costa 已提交
1051
    qemu_free(vs);
1052
}
1053 1054

int vnc_client_io_error(VncState *vs, int ret, int last_errno)
B
bellard 已提交
1055 1056
{
    if (ret == 0 || ret == -1) {
1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068
        if (ret == -1) {
            switch (last_errno) {
                case EINTR:
                case EAGAIN:
#ifdef _WIN32
                case WSAEWOULDBLOCK:
#endif
                    return 0;
                default:
                    break;
            }
        }
B
bellard 已提交
1069

1070 1071 1072
        VNC_DEBUG("Closing down client sock: ret %d, errno %d\n",
                  ret, ret < 0 ? last_errno : 0);
        vnc_disconnect_start(vs);
1073

1074
        return 0;
B
bellard 已提交
1075 1076 1077 1078
    }
    return ret;
}

1079 1080

void vnc_client_error(VncState *vs)
B
bellard 已提交
1081
{
1082 1083
    VNC_DEBUG("Closing down client sock: protocol error\n");
    vnc_disconnect_start(vs);
B
bellard 已提交
1084 1085
}

1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102

/*
 * Called to write a chunk of data to the client socket. The data may
 * be the raw data, or may have already been encoded by SASL.
 * The data will be written either straight onto the socket, or
 * written via the GNUTLS wrappers, if TLS/SSL encryption is enabled
 *
 * NB, it is theoretically possible to have 2 layers of encryption,
 * both SASL, and this TLS layer. It is highly unlikely in practice
 * though, since SASL encryption will typically be a no-op if TLS
 * is active
 *
 * Returns the number of bytes written, which may be less than
 * the requested 'datalen' if the socket would block. Returns
 * -1 on error, and disconnects the client socket.
 */
long vnc_client_write_buf(VncState *vs, const uint8_t *data, size_t datalen)
B
bellard 已提交
1103
{
1104
    long ret;
1105
#ifdef CONFIG_VNC_TLS
1106
    if (vs->tls.session) {
1107 1108 1109 1110 1111 1112 1113 1114
        ret = gnutls_write(vs->tls.session, data, datalen);
        if (ret < 0) {
            if (ret == GNUTLS_E_AGAIN)
                errno = EAGAIN;
            else
                errno = EIO;
            ret = -1;
        }
1115 1116
    } else
#endif /* CONFIG_VNC_TLS */
1117
        ret = send(vs->csock, (const void *)data, datalen, 0);
1118
    VNC_DEBUG("Wrote wire %p %zd -> %ld\n", data, datalen, ret);
1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137
    return vnc_client_io_error(vs, ret, socket_error());
}


/*
 * Called to write buffered data to the client socket, when not
 * using any SASL SSF encryption layers. Will write as much data
 * as possible without blocking. If all buffered data is written,
 * will switch the FD poll() handler back to read monitoring.
 *
 * Returns the number of bytes written, which may be less than
 * the buffered output data if the socket would block. Returns
 * -1 on error, and disconnects the client socket.
 */
static long vnc_client_write_plain(VncState *vs)
{
    long ret;

#ifdef CONFIG_VNC_SASL
1138
    VNC_DEBUG("Write Plain: Pending output %p size %zd offset %zd. Wait SSF %d\n",
1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150
              vs->output.buffer, vs->output.capacity, vs->output.offset,
              vs->sasl.waitWriteSSF);

    if (vs->sasl.conn &&
        vs->sasl.runSSF &&
        vs->sasl.waitWriteSSF) {
        ret = vnc_client_write_buf(vs, vs->output.buffer, vs->sasl.waitWriteSSF);
        if (ret)
            vs->sasl.waitWriteSSF -= ret;
    } else
#endif /* CONFIG_VNC_SASL */
        ret = vnc_client_write_buf(vs, vs->output.buffer, vs->output.offset);
B
bellard 已提交
1151
    if (!ret)
1152
        return 0;
B
bellard 已提交
1153 1154 1155 1156 1157

    memmove(vs->output.buffer, vs->output.buffer + ret, (vs->output.offset - ret));
    vs->output.offset -= ret;

    if (vs->output.offset == 0) {
1158
        qemu_set_fd_handler2(vs->csock, NULL, vnc_client_read, NULL, vs);
B
bellard 已提交
1159
    }
1160 1161 1162 1163 1164 1165 1166 1167 1168 1169

    return ret;
}


/*
 * First function called whenever there is data to be written to
 * the client socket. Will delegate actual work according to whether
 * SASL SSF layers are enabled (thus requiring encryption calls)
 */
C
Corentin Chary 已提交
1170
static void vnc_client_write_locked(void *opaque)
1171 1172 1173 1174 1175 1176
{
    VncState *vs = opaque;

#ifdef CONFIG_VNC_SASL
    if (vs->sasl.conn &&
        vs->sasl.runSSF &&
1177 1178 1179
        !vs->sasl.waitWriteSSF) {
        vnc_client_write_sasl(vs);
    } else
1180
#endif /* CONFIG_VNC_SASL */
1181
        vnc_client_write_plain(vs);
B
bellard 已提交
1182 1183
}

C
Corentin Chary 已提交
1184 1185 1186 1187 1188 1189 1190
void vnc_client_write(void *opaque)
{
    VncState *vs = opaque;

    vnc_lock_output(vs);
    if (vs->output.offset) {
        vnc_client_write_locked(opaque);
1191
    } else if (vs->csock != -1) {
C
Corentin Chary 已提交
1192 1193 1194 1195 1196
        qemu_set_fd_handler2(vs->csock, NULL, vnc_client_read, NULL, vs);
    }
    vnc_unlock_output(vs);
}

1197
void vnc_read_when(VncState *vs, VncReadEvent *func, size_t expecting)
B
bellard 已提交
1198 1199 1200 1201 1202
{
    vs->read_handler = func;
    vs->read_handler_expect = expecting;
}

1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219

/*
 * Called to read a chunk of data from the client socket. The data may
 * be the raw data, or may need to be further decoded by SASL.
 * The data will be read either straight from to the socket, or
 * read via the GNUTLS wrappers, if TLS/SSL encryption is enabled
 *
 * NB, it is theoretically possible to have 2 layers of encryption,
 * both SASL, and this TLS layer. It is highly unlikely in practice
 * though, since SASL encryption will typically be a no-op if TLS
 * is active
 *
 * Returns the number of bytes read, which may be less than
 * the requested 'datalen' if the socket would block. Returns
 * -1 on error, and disconnects the client socket.
 */
long vnc_client_read_buf(VncState *vs, uint8_t *data, size_t datalen)
B
bellard 已提交
1220
{
1221
    long ret;
1222
#ifdef CONFIG_VNC_TLS
1223
    if (vs->tls.session) {
1224 1225 1226 1227 1228 1229 1230 1231
        ret = gnutls_read(vs->tls.session, data, datalen);
        if (ret < 0) {
            if (ret == GNUTLS_E_AGAIN)
                errno = EAGAIN;
            else
                errno = EIO;
            ret = -1;
        }
1232 1233
    } else
#endif /* CONFIG_VNC_TLS */
B
Blue Swirl 已提交
1234
        ret = recv(vs->csock, (void *)data, datalen, 0);
1235
    VNC_DEBUG("Read wire %p %zd -> %ld\n", data, datalen, ret);
1236 1237
    return vnc_client_io_error(vs, ret, socket_error());
}
B
bellard 已提交
1238

1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250

/*
 * Called to read data from the client socket to the input buffer,
 * when not using any SASL SSF encryption layers. Will read as much
 * data as possible without blocking.
 *
 * Returns the number of bytes read. Returns -1 on error, and
 * disconnects the client socket.
 */
static long vnc_client_read_plain(VncState *vs)
{
    int ret;
1251
    VNC_DEBUG("Read plain %p size %zd offset %zd\n",
1252 1253 1254 1255 1256
              vs->input.buffer, vs->input.capacity, vs->input.offset);
    buffer_reserve(&vs->input, 4096);
    ret = vnc_client_read_buf(vs, buffer_end(&vs->input), 4096);
    if (!ret)
        return 0;
B
bellard 已提交
1257
    vs->input.offset += ret;
1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277
    return ret;
}


/*
 * First function called whenever there is more data to be read from
 * the client socket. Will delegate actual work according to whether
 * SASL SSF layers are enabled (thus requiring decryption calls)
 */
void vnc_client_read(void *opaque)
{
    VncState *vs = opaque;
    long ret;

#ifdef CONFIG_VNC_SASL
    if (vs->sasl.conn && vs->sasl.runSSF)
        ret = vnc_client_read_sasl(vs);
    else
#endif /* CONFIG_VNC_SASL */
        ret = vnc_client_read_plain(vs);
1278 1279 1280
    if (!ret) {
        if (vs->csock == -1)
            vnc_disconnect_finish(vs);
1281
        return;
1282
    }
B
bellard 已提交
1283 1284

    while (vs->read_handler && vs->input.offset >= vs->read_handler_expect) {
1285 1286 1287 1288
        size_t len = vs->read_handler_expect;
        int ret;

        ret = vs->read_handler(vs, vs->input.buffer, len);
1289 1290
        if (vs->csock == -1) {
            vnc_disconnect_finish(vs);
1291
            return;
1292
        }
1293 1294 1295 1296 1297 1298 1299

        if (!ret) {
            memmove(vs->input.buffer, vs->input.buffer + len, (vs->input.offset - len));
            vs->input.offset -= len;
        } else {
            vs->read_handler_expect = ret;
        }
B
bellard 已提交
1300 1301 1302
    }
}

1303
void vnc_write(VncState *vs, const void *data, size_t len)
B
bellard 已提交
1304 1305 1306
{
    buffer_reserve(&vs->output, len);

1307
    if (vs->csock != -1 && buffer_empty(&vs->output)) {
1308
        qemu_set_fd_handler2(vs->csock, NULL, vnc_client_read, vnc_client_write, vs);
B
bellard 已提交
1309 1310 1311 1312 1313
    }

    buffer_append(&vs->output, data, len);
}

1314
void vnc_write_s32(VncState *vs, int32_t value)
B
bellard 已提交
1315 1316 1317 1318
{
    vnc_write_u32(vs, *(uint32_t *)&value);
}

1319
void vnc_write_u32(VncState *vs, uint32_t value)
B
bellard 已提交
1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330
{
    uint8_t buf[4];

    buf[0] = (value >> 24) & 0xFF;
    buf[1] = (value >> 16) & 0xFF;
    buf[2] = (value >>  8) & 0xFF;
    buf[3] = value & 0xFF;

    vnc_write(vs, buf, 4);
}

1331
void vnc_write_u16(VncState *vs, uint16_t value)
B
bellard 已提交
1332
{
1333
    uint8_t buf[2];
B
bellard 已提交
1334 1335 1336 1337 1338 1339 1340

    buf[0] = (value >> 8) & 0xFF;
    buf[1] = value & 0xFF;

    vnc_write(vs, buf, 2);
}

1341
void vnc_write_u8(VncState *vs, uint8_t value)
B
bellard 已提交
1342 1343 1344 1345
{
    vnc_write(vs, (char *)&value, 1);
}

1346
void vnc_flush(VncState *vs)
B
bellard 已提交
1347
{
C
Corentin Chary 已提交
1348 1349 1350 1351 1352
    vnc_lock_output(vs);
    if (vs->csock != -1 && vs->output.offset) {
        vnc_client_write_locked(vs);
    }
    vnc_unlock_output(vs);
B
bellard 已提交
1353 1354
}

1355
uint8_t read_u8(uint8_t *data, size_t offset)
B
bellard 已提交
1356 1357 1358 1359
{
    return data[offset];
}

1360
uint16_t read_u16(uint8_t *data, size_t offset)
B
bellard 已提交
1361 1362 1363 1364
{
    return ((data[offset] & 0xFF) << 8) | (data[offset + 1] & 0xFF);
}

1365
int32_t read_s32(uint8_t *data, size_t offset)
B
bellard 已提交
1366 1367
{
    return (int32_t)((data[offset] << 24) | (data[offset + 1] << 16) |
1368
                     (data[offset + 2] << 8) | data[offset + 3]);
B
bellard 已提交
1369 1370
}

1371
uint32_t read_u32(uint8_t *data, size_t offset)
B
bellard 已提交
1372 1373
{
    return ((data[offset] << 24) | (data[offset + 1] << 16) |
1374
            (data[offset + 2] << 8) | data[offset + 3]);
B
bellard 已提交
1375 1376
}

T
ths 已提交
1377
static void client_cut_text(VncState *vs, size_t len, uint8_t *text)
B
bellard 已提交
1378 1379 1380
{
}

1381
static void check_pointer_type_change(Notifier *notifier)
1382
{
1383 1384 1385
    VncState *vs = container_of(notifier, VncState, mouse_mode_notifier);
    int absolute = kbd_mouse_is_absolute();

1386
    if (vnc_has_feature(vs, VNC_FEATURE_POINTER_TYPE_CHANGE) && vs->absolute != absolute) {
C
Corentin Chary 已提交
1387
        vnc_lock_output(vs);
1388
        vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
1389 1390 1391 1392
        vnc_write_u8(vs, 0);
        vnc_write_u16(vs, 1);
        vnc_framebuffer_update(vs, absolute, 0,
                               ds_get_width(vs->ds), ds_get_height(vs->ds),
1393
                               VNC_ENCODING_POINTER_TYPE_CHANGE);
C
Corentin Chary 已提交
1394
        vnc_unlock_output(vs);
1395
        vnc_flush(vs);
1396 1397 1398 1399
    }
    vs->absolute = absolute;
}

B
bellard 已提交
1400 1401 1402 1403 1404 1405
static void pointer_event(VncState *vs, int button_mask, int x, int y)
{
    int buttons = 0;
    int dz = 0;

    if (button_mask & 0x01)
1406
        buttons |= MOUSE_EVENT_LBUTTON;
B
bellard 已提交
1407
    if (button_mask & 0x02)
1408
        buttons |= MOUSE_EVENT_MBUTTON;
B
bellard 已提交
1409
    if (button_mask & 0x04)
1410
        buttons |= MOUSE_EVENT_RBUTTON;
B
bellard 已提交
1411
    if (button_mask & 0x08)
1412
        dz = -1;
B
bellard 已提交
1413
    if (button_mask & 0x10)
1414
        dz = 1;
1415 1416

    if (vs->absolute) {
1417 1418 1419 1420
        kbd_mouse_event(ds_get_width(vs->ds) > 1 ?
                          x * 0x7FFF / (ds_get_width(vs->ds) - 1) : 0x4000,
                        ds_get_height(vs->ds) > 1 ?
                          y * 0x7FFF / (ds_get_height(vs->ds) - 1) : 0x4000,
1421
                        dz, buttons);
1422
    } else if (vnc_has_feature(vs, VNC_FEATURE_POINTER_TYPE_CHANGE)) {
1423 1424
        x -= 0x7FFF;
        y -= 0x7FFF;
B
bellard 已提交
1425

1426
        kbd_mouse_event(x, y, dz, buttons);
1427
    } else {
1428 1429 1430 1431 1432 1433
        if (vs->last_x != -1)
            kbd_mouse_event(x - vs->last_x,
                            y - vs->last_y,
                            dz, buttons);
        vs->last_x = x;
        vs->last_y = y;
B
bellard 已提交
1434 1435 1436
    }
}

1437 1438 1439 1440 1441
static void reset_keys(VncState *vs)
{
    int i;
    for(i = 0; i < 256; i++) {
        if (vs->modifiers_state[i]) {
1442 1443 1444
            if (i & SCANCODE_GREY)
                kbd_put_keycode(SCANCODE_EMUL0);
            kbd_put_keycode(i | SCANCODE_UP);
1445 1446 1447 1448 1449
            vs->modifiers_state[i] = 0;
        }
    }
}

1450 1451
static void press_key(VncState *vs, int keysym)
{
1452 1453 1454 1455 1456 1457 1458
    int keycode = keysym2scancode(vs->vd->kbd_layout, keysym) & SCANCODE_KEYMASK;
    if (keycode & SCANCODE_GREY)
        kbd_put_keycode(SCANCODE_EMUL0);
    kbd_put_keycode(keycode & SCANCODE_KEYCODEMASK);
    if (keycode & SCANCODE_GREY)
        kbd_put_keycode(SCANCODE_EMUL0);
    kbd_put_keycode(keycode | SCANCODE_UP);
1459 1460
}

G
Gerd Hoffmann 已提交
1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476
static void kbd_leds(void *opaque, int ledstate)
{
    VncState *vs = opaque;
    int caps, num;

    caps = ledstate & QEMU_CAPS_LOCK_LED ? 1 : 0;
    num  = ledstate & QEMU_NUM_LOCK_LED  ? 1 : 0;

    if (vs->modifiers_state[0x3a] != caps) {
        vs->modifiers_state[0x3a] = caps;
    }
    if (vs->modifiers_state[0x45] != num) {
        vs->modifiers_state[0x45] = num;
    }
}

1477
static void do_key_event(VncState *vs, int down, int keycode, int sym)
B
bellard 已提交
1478
{
1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491
    /* QEMU console switch */
    switch(keycode) {
    case 0x2a:                          /* Left Shift */
    case 0x36:                          /* Right Shift */
    case 0x1d:                          /* Left CTRL */
    case 0x9d:                          /* Right CTRL */
    case 0x38:                          /* Left ALT */
    case 0xb8:                          /* Right ALT */
        if (down)
            vs->modifiers_state[keycode] = 1;
        else
            vs->modifiers_state[keycode] = 0;
        break;
1492
    case 0x02 ... 0x0a: /* '1' to '9' keys */
1493 1494 1495 1496 1497 1498 1499
        if (down && vs->modifiers_state[0x1d] && vs->modifiers_state[0x38]) {
            /* Reset the modifiers sent to the current console */
            reset_keys(vs);
            console_select(keycode - 0x02);
            return;
        }
        break;
1500 1501
    case 0x3a:                        /* CapsLock */
    case 0x45:                        /* NumLock */
G
Gerd Hoffmann 已提交
1502
        if (down)
1503 1504 1505 1506
            vs->modifiers_state[keycode] ^= 1;
        break;
    }

G
Gerd Hoffmann 已提交
1507 1508
    if (vs->vd->lock_key_sync &&
        keycode_is_keypad(vs->vd->kbd_layout, keycode)) {
1509 1510 1511 1512
        /* If the numlock state needs to change then simulate an additional
           keypress before sending this one.  This will happen if the user
           toggles numlock away from the VNC window.
        */
1513
        if (keysym_is_numlock(vs->vd->kbd_layout, sym & 0xFFFF)) {
1514 1515 1516 1517 1518 1519 1520 1521 1522 1523
            if (!vs->modifiers_state[0x45]) {
                vs->modifiers_state[0x45] = 1;
                press_key(vs, 0xff7f);
            }
        } else {
            if (vs->modifiers_state[0x45]) {
                vs->modifiers_state[0x45] = 0;
                press_key(vs, 0xff7f);
            }
        }
1524
    }
B
bellard 已提交
1525

G
Gerd Hoffmann 已提交
1526 1527
    if (vs->vd->lock_key_sync &&
        ((sym >= 'A' && sym <= 'Z') || (sym >= 'a' && sym <= 'z'))) {
G
Gerd Hoffmann 已提交
1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547
        /* If the capslock state needs to change then simulate an additional
           keypress before sending this one.  This will happen if the user
           toggles capslock away from the VNC window.
        */
        int uppercase = !!(sym >= 'A' && sym <= 'Z');
        int shift = !!(vs->modifiers_state[0x2a] | vs->modifiers_state[0x36]);
        int capslock = !!(vs->modifiers_state[0x3a]);
        if (capslock) {
            if (uppercase == shift) {
                vs->modifiers_state[0x3a] = 0;
                press_key(vs, 0xffe5);
            }
        } else {
            if (uppercase != shift) {
                vs->modifiers_state[0x3a] = 1;
                press_key(vs, 0xffe5);
            }
        }
    }

1548
    if (is_graphic_console()) {
1549 1550
        if (keycode & SCANCODE_GREY)
            kbd_put_keycode(SCANCODE_EMUL0);
1551
        if (down)
1552
            kbd_put_keycode(keycode & SCANCODE_KEYCODEMASK);
1553
        else
1554
            kbd_put_keycode(keycode | SCANCODE_UP);
1555 1556 1557
    } else {
        /* QEMU console emulation */
        if (down) {
1558
            int numlock = vs->modifiers_state[0x45];
1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593
            switch (keycode) {
            case 0x2a:                          /* Left Shift */
            case 0x36:                          /* Right Shift */
            case 0x1d:                          /* Left CTRL */
            case 0x9d:                          /* Right CTRL */
            case 0x38:                          /* Left ALT */
            case 0xb8:                          /* Right ALT */
                break;
            case 0xc8:
                kbd_put_keysym(QEMU_KEY_UP);
                break;
            case 0xd0:
                kbd_put_keysym(QEMU_KEY_DOWN);
                break;
            case 0xcb:
                kbd_put_keysym(QEMU_KEY_LEFT);
                break;
            case 0xcd:
                kbd_put_keysym(QEMU_KEY_RIGHT);
                break;
            case 0xd3:
                kbd_put_keysym(QEMU_KEY_DELETE);
                break;
            case 0xc7:
                kbd_put_keysym(QEMU_KEY_HOME);
                break;
            case 0xcf:
                kbd_put_keysym(QEMU_KEY_END);
                break;
            case 0xc9:
                kbd_put_keysym(QEMU_KEY_PAGEUP);
                break;
            case 0xd1:
                kbd_put_keysym(QEMU_KEY_PAGEDOWN);
                break;
1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644

            case 0x47:
                kbd_put_keysym(numlock ? '7' : QEMU_KEY_HOME);
                break;
            case 0x48:
                kbd_put_keysym(numlock ? '8' : QEMU_KEY_UP);
                break;
            case 0x49:
                kbd_put_keysym(numlock ? '9' : QEMU_KEY_PAGEUP);
                break;
            case 0x4b:
                kbd_put_keysym(numlock ? '4' : QEMU_KEY_LEFT);
                break;
            case 0x4c:
                kbd_put_keysym('5');
                break;
            case 0x4d:
                kbd_put_keysym(numlock ? '6' : QEMU_KEY_RIGHT);
                break;
            case 0x4f:
                kbd_put_keysym(numlock ? '1' : QEMU_KEY_END);
                break;
            case 0x50:
                kbd_put_keysym(numlock ? '2' : QEMU_KEY_DOWN);
                break;
            case 0x51:
                kbd_put_keysym(numlock ? '3' : QEMU_KEY_PAGEDOWN);
                break;
            case 0x52:
                kbd_put_keysym('0');
                break;
            case 0x53:
                kbd_put_keysym(numlock ? '.' : QEMU_KEY_DELETE);
                break;

            case 0xb5:
                kbd_put_keysym('/');
                break;
            case 0x37:
                kbd_put_keysym('*');
                break;
            case 0x4a:
                kbd_put_keysym('-');
                break;
            case 0x4e:
                kbd_put_keysym('+');
                break;
            case 0x9c:
                kbd_put_keysym('\n');
                break;

1645 1646 1647 1648 1649 1650
            default:
                kbd_put_keysym(sym);
                break;
            }
        }
    }
B
bellard 已提交
1651 1652
}

B
bellard 已提交
1653 1654
static void key_event(VncState *vs, int down, uint32_t sym)
{
1655
    int keycode;
G
Gerd Hoffmann 已提交
1656
    int lsym = sym;
1657

G
Gerd Hoffmann 已提交
1658 1659 1660
    if (lsym >= 'A' && lsym <= 'Z' && is_graphic_console()) {
        lsym = lsym - 'A' + 'a';
    }
1661

1662
    keycode = keysym2scancode(vs->vd->kbd_layout, lsym & 0xFFFF) & SCANCODE_KEYMASK;
1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673
    do_key_event(vs, down, keycode, sym);
}

static void ext_key_event(VncState *vs, int down,
                          uint32_t sym, uint16_t keycode)
{
    /* if the user specifies a keyboard layout, always use it */
    if (keyboard_layout)
        key_event(vs, down, sym);
    else
        do_key_event(vs, down, keycode, sym);
B
bellard 已提交
1674 1675
}

B
bellard 已提交
1676
static void framebuffer_update_request(VncState *vs, int incremental,
1677 1678
                                       int x_position, int y_position,
                                       int w, int h)
B
bellard 已提交
1679
{
1680 1681 1682 1683
    if (y_position > ds_get_height(vs->ds))
        y_position = ds_get_height(vs->ds);
    if (y_position + h >= ds_get_height(vs->ds))
        h = ds_get_height(vs->ds) - y_position;
1684

B
bellard 已提交
1685 1686 1687
    int i;
    vs->need_update = 1;
    if (!incremental) {
1688
        vs->force_update = 1;
1689
        for (i = 0; i < h; i++) {
S
Stefano Stabellini 已提交
1690
            vnc_set_bits(vs->dirty[y_position + i],
1691
                         (ds_get_width(vs->ds) / 16), VNC_DIRTY_WORDS);
1692
        }
B
bellard 已提交
1693 1694 1695
    }
}

1696 1697
static void send_ext_key_event_ack(VncState *vs)
{
C
Corentin Chary 已提交
1698
    vnc_lock_output(vs);
1699
    vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
1700 1701
    vnc_write_u8(vs, 0);
    vnc_write_u16(vs, 1);
1702 1703
    vnc_framebuffer_update(vs, 0, 0, ds_get_width(vs->ds), ds_get_height(vs->ds),
                           VNC_ENCODING_EXT_KEY_EVENT);
C
Corentin Chary 已提交
1704
    vnc_unlock_output(vs);
1705 1706 1707
    vnc_flush(vs);
}

M
malc 已提交
1708 1709
static void send_ext_audio_ack(VncState *vs)
{
C
Corentin Chary 已提交
1710
    vnc_lock_output(vs);
1711
    vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
M
malc 已提交
1712 1713
    vnc_write_u8(vs, 0);
    vnc_write_u16(vs, 1);
1714 1715
    vnc_framebuffer_update(vs, 0, 0, ds_get_width(vs->ds), ds_get_height(vs->ds),
                           VNC_ENCODING_AUDIO);
C
Corentin Chary 已提交
1716
    vnc_unlock_output(vs);
M
malc 已提交
1717 1718 1719
    vnc_flush(vs);
}

B
bellard 已提交
1720 1721 1722
static void set_encodings(VncState *vs, int32_t *encodings, size_t n_encodings)
{
    int i;
1723
    unsigned int enc = 0;
B
bellard 已提交
1724

1725
    vs->features = 0;
1726
    vs->vnc_encoding = 0;
1727 1728
    vs->tight.compression = 9;
    vs->tight.quality = -1; /* Lossless by default */
1729
    vs->absolute = -1;
B
bellard 已提交
1730

1731 1732 1733 1734 1735
    /*
     * Start from the end because the encodings are sent in order of preference.
     * This way the prefered encoding (first encoding defined in the array)
     * will be set at the end of the loop.
     */
B
bellard 已提交
1736
    for (i = n_encodings - 1; i >= 0; i--) {
1737 1738 1739
        enc = encodings[i];
        switch (enc) {
        case VNC_ENCODING_RAW:
1740
            vs->vnc_encoding = enc;
1741 1742
            break;
        case VNC_ENCODING_COPYRECT:
1743
            vs->features |= VNC_FEATURE_COPYRECT_MASK;
1744 1745 1746
            break;
        case VNC_ENCODING_HEXTILE:
            vs->features |= VNC_FEATURE_HEXTILE_MASK;
1747
            vs->vnc_encoding = enc;
1748
            break;
C
Corentin Chary 已提交
1749 1750 1751 1752
        case VNC_ENCODING_TIGHT:
            vs->features |= VNC_FEATURE_TIGHT_MASK;
            vs->vnc_encoding = enc;
            break;
C
Corentin Chary 已提交
1753 1754 1755 1756
        case VNC_ENCODING_TIGHT_PNG:
            vs->features |= VNC_FEATURE_TIGHT_PNG_MASK;
            vs->vnc_encoding = enc;
            break;
1757 1758
        case VNC_ENCODING_ZLIB:
            vs->features |= VNC_FEATURE_ZLIB_MASK;
1759
            vs->vnc_encoding = enc;
1760
            break;
1761 1762 1763 1764 1765 1766
        case VNC_ENCODING_DESKTOPRESIZE:
            vs->features |= VNC_FEATURE_RESIZE_MASK;
            break;
        case VNC_ENCODING_POINTER_TYPE_CHANGE:
            vs->features |= VNC_FEATURE_POINTER_TYPE_CHANGE_MASK;
            break;
G
Gerd Hoffmann 已提交
1767 1768 1769
        case VNC_ENCODING_RICH_CURSOR:
            vs->features |= VNC_FEATURE_RICH_CURSOR_MASK;
            break;
1770
        case VNC_ENCODING_EXT_KEY_EVENT:
1771 1772
            send_ext_key_event_ack(vs);
            break;
1773
        case VNC_ENCODING_AUDIO:
M
malc 已提交
1774 1775
            send_ext_audio_ack(vs);
            break;
1776 1777
        case VNC_ENCODING_WMVi:
            vs->features |= VNC_FEATURE_WMVI_MASK;
1778
            break;
1779
        case VNC_ENCODING_COMPRESSLEVEL0 ... VNC_ENCODING_COMPRESSLEVEL0 + 9:
1780
            vs->tight.compression = (enc & 0x0F);
1781 1782
            break;
        case VNC_ENCODING_QUALITYLEVEL0 ... VNC_ENCODING_QUALITYLEVEL0 + 9:
1783
            vs->tight.quality = (enc & 0x0F);
1784
            break;
1785 1786 1787 1788
        default:
            VNC_DEBUG("Unknown encoding: %d (0x%.8x): %d\n", i, enc, enc);
            break;
        }
B
bellard 已提交
1789
    }
1790
    vnc_desktop_resize(vs);
1791
    check_pointer_type_change(&vs->mouse_mode_notifier);
B
bellard 已提交
1792 1793
}

1794 1795 1796 1797 1798 1799
static void set_pixel_conversion(VncState *vs)
{
    if ((vs->clientds.flags & QEMU_BIG_ENDIAN_FLAG) ==
        (vs->ds->surface->flags & QEMU_BIG_ENDIAN_FLAG) && 
        !memcmp(&(vs->clientds.pf), &(vs->ds->surface->pf), sizeof(PixelFormat))) {
        vs->write_pixels = vnc_write_pixels_copy;
1800
        vnc_hextile_set_pixel_conversion(vs, 0);
1801 1802
    } else {
        vs->write_pixels = vnc_write_pixels_generic;
1803
        vnc_hextile_set_pixel_conversion(vs, 1);
1804 1805 1806
    }
}

B
bellard 已提交
1807
static void set_pixel_format(VncState *vs,
1808 1809 1810 1811
                             int bits_per_pixel, int depth,
                             int big_endian_flag, int true_color_flag,
                             int red_max, int green_max, int blue_max,
                             int red_shift, int green_shift, int blue_shift)
B
bellard 已提交
1812
{
B
bellard 已提交
1813
    if (!true_color_flag) {
1814
        vnc_client_error(vs);
B
bellard 已提交
1815 1816
        return;
    }
B
bellard 已提交
1817

S
Stefano Stabellini 已提交
1818
    vs->clientds = *(vs->vd->guest.ds);
1819
    vs->clientds.pf.rmax = red_max;
1820
    count_bits(vs->clientds.pf.rbits, red_max);
1821 1822 1823
    vs->clientds.pf.rshift = red_shift;
    vs->clientds.pf.rmask = red_max << red_shift;
    vs->clientds.pf.gmax = green_max;
1824
    count_bits(vs->clientds.pf.gbits, green_max);
1825 1826 1827
    vs->clientds.pf.gshift = green_shift;
    vs->clientds.pf.gmask = green_max << green_shift;
    vs->clientds.pf.bmax = blue_max;
1828
    count_bits(vs->clientds.pf.bbits, blue_max);
1829 1830 1831 1832 1833 1834 1835 1836
    vs->clientds.pf.bshift = blue_shift;
    vs->clientds.pf.bmask = blue_max << blue_shift;
    vs->clientds.pf.bits_per_pixel = bits_per_pixel;
    vs->clientds.pf.bytes_per_pixel = bits_per_pixel / 8;
    vs->clientds.pf.depth = bits_per_pixel == 32 ? 24 : bits_per_pixel;
    vs->clientds.flags = big_endian_flag ? QEMU_BIG_ENDIAN_FLAG : 0x00;

    set_pixel_conversion(vs);
B
bellard 已提交
1837 1838 1839 1840 1841

    vga_hw_invalidate();
    vga_hw_update();
}

1842 1843 1844
static void pixel_format_message (VncState *vs) {
    char pad[3] = { 0, 0, 0 };

1845 1846
    vnc_write_u8(vs, vs->ds->surface->pf.bits_per_pixel); /* bits-per-pixel */
    vnc_write_u8(vs, vs->ds->surface->pf.depth); /* depth */
1847

1848
#ifdef HOST_WORDS_BIGENDIAN
1849 1850 1851 1852 1853
    vnc_write_u8(vs, 1);             /* big-endian-flag */
#else
    vnc_write_u8(vs, 0);             /* big-endian-flag */
#endif
    vnc_write_u8(vs, 1);             /* true-color-flag */
1854 1855 1856 1857 1858 1859
    vnc_write_u16(vs, vs->ds->surface->pf.rmax);     /* red-max */
    vnc_write_u16(vs, vs->ds->surface->pf.gmax);     /* green-max */
    vnc_write_u16(vs, vs->ds->surface->pf.bmax);     /* blue-max */
    vnc_write_u8(vs, vs->ds->surface->pf.rshift);    /* red-shift */
    vnc_write_u8(vs, vs->ds->surface->pf.gshift);    /* green-shift */
    vnc_write_u8(vs, vs->ds->surface->pf.bshift);    /* blue-shift */
1860 1861 1862

    vnc_hextile_set_pixel_conversion(vs, 0);

1863
    vs->clientds = *(vs->ds->surface);
1864
    vs->clientds.flags &= ~QEMU_ALLOCATED_FLAG;
1865 1866 1867 1868 1869
    vs->write_pixels = vnc_write_pixels_copy;

    vnc_write(vs, pad, 3);           /* padding */
}

1870 1871 1872 1873 1874
static void vnc_dpy_setdata(DisplayState *ds)
{
    /* We don't have to do anything */
}

1875
static void vnc_colordepth(VncState *vs)
1876
{
1877
    if (vnc_has_feature(vs, VNC_FEATURE_WMVI)) {
1878
        /* Sending a WMVi message to notify the client*/
C
Corentin Chary 已提交
1879
        vnc_lock_output(vs);
1880
        vnc_write_u8(vs, VNC_MSG_SERVER_FRAMEBUFFER_UPDATE);
1881 1882
        vnc_write_u8(vs, 0);
        vnc_write_u16(vs, 1); /* number of rects */
1883 1884
        vnc_framebuffer_update(vs, 0, 0, ds_get_width(vs->ds), 
                               ds_get_height(vs->ds), VNC_ENCODING_WMVi);
1885
        pixel_format_message(vs);
C
Corentin Chary 已提交
1886
        vnc_unlock_output(vs);
1887
        vnc_flush(vs);
1888
    } else {
1889
        set_pixel_conversion(vs);
1890 1891 1892
    }
}

T
ths 已提交
1893
static int protocol_client_msg(VncState *vs, uint8_t *data, size_t len)
B
bellard 已提交
1894 1895 1896
{
    int i;
    uint16_t limit;
S
Stefano Stabellini 已提交
1897 1898 1899 1900 1901 1902 1903
    VncDisplay *vd = vs->vd;

    if (data[0] > 3) {
        vd->timer_interval = VNC_REFRESH_INTERVAL_BASE;
        if (!qemu_timer_expired(vd->timer, qemu_get_clock(rt_clock) + vd->timer_interval))
            qemu_mod_timer(vd->timer, qemu_get_clock(rt_clock) + vd->timer_interval);
    }
B
bellard 已提交
1904 1905

    switch (data[0]) {
1906
    case VNC_MSG_CLIENT_SET_PIXEL_FORMAT:
1907 1908 1909 1910 1911 1912 1913 1914 1915
        if (len == 1)
            return 20;

        set_pixel_format(vs, read_u8(data, 4), read_u8(data, 5),
                         read_u8(data, 6), read_u8(data, 7),
                         read_u16(data, 8), read_u16(data, 10),
                         read_u16(data, 12), read_u8(data, 14),
                         read_u8(data, 15), read_u8(data, 16));
        break;
1916
    case VNC_MSG_CLIENT_SET_ENCODINGS:
1917 1918
        if (len == 1)
            return 4;
B
bellard 已提交
1919

1920
        if (len == 4) {
1921 1922 1923 1924 1925
            limit = read_u16(data, 2);
            if (limit > 0)
                return 4 + (limit * 4);
        } else
            limit = read_u16(data, 2);
B
bellard 已提交
1926

1927 1928 1929 1930
        for (i = 0; i < limit; i++) {
            int32_t val = read_s32(data, 4 + (i * 4));
            memcpy(data + 4 + (i * 4), &val, sizeof(val));
        }
B
bellard 已提交
1931

1932 1933
        set_encodings(vs, (int32_t *)(data + 4), limit);
        break;
1934
    case VNC_MSG_CLIENT_FRAMEBUFFER_UPDATE_REQUEST:
1935 1936
        if (len == 1)
            return 10;
B
bellard 已提交
1937

1938 1939 1940 1941
        framebuffer_update_request(vs,
                                   read_u8(data, 1), read_u16(data, 2), read_u16(data, 4),
                                   read_u16(data, 6), read_u16(data, 8));
        break;
1942
    case VNC_MSG_CLIENT_KEY_EVENT:
1943 1944
        if (len == 1)
            return 8;
B
bellard 已提交
1945

1946 1947
        key_event(vs, read_u8(data, 1), read_u32(data, 4));
        break;
1948
    case VNC_MSG_CLIENT_POINTER_EVENT:
1949 1950
        if (len == 1)
            return 6;
B
bellard 已提交
1951

1952 1953
        pointer_event(vs, read_u8(data, 1), read_u16(data, 2), read_u16(data, 4));
        break;
1954
    case VNC_MSG_CLIENT_CUT_TEXT:
1955 1956
        if (len == 1)
            return 8;
B
bellard 已提交
1957

1958
        if (len == 8) {
1959 1960 1961 1962
            uint32_t dlen = read_u32(data, 4);
            if (dlen > 0)
                return 8 + dlen;
        }
B
bellard 已提交
1963

1964 1965
        client_cut_text(vs, read_u32(data, 4), data + 8);
        break;
1966
    case VNC_MSG_CLIENT_QEMU:
1967 1968 1969 1970
        if (len == 1)
            return 2;

        switch (read_u8(data, 1)) {
1971
        case VNC_MSG_CLIENT_QEMU_EXT_KEY_EVENT:
1972 1973 1974 1975 1976 1977
            if (len == 2)
                return 12;

            ext_key_event(vs, read_u16(data, 2),
                          read_u32(data, 4), read_u32(data, 8));
            break;
1978
        case VNC_MSG_CLIENT_QEMU_AUDIO:
M
malc 已提交
1979 1980 1981 1982
            if (len == 2)
                return 4;

            switch (read_u16 (data, 2)) {
1983
            case VNC_MSG_CLIENT_QEMU_AUDIO_ENABLE:
M
malc 已提交
1984 1985
                audio_add(vs);
                break;
1986
            case VNC_MSG_CLIENT_QEMU_AUDIO_DISABLE:
M
malc 已提交
1987 1988
                audio_del(vs);
                break;
1989
            case VNC_MSG_CLIENT_QEMU_AUDIO_SET_FORMAT:
M
malc 已提交
1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019
                if (len == 4)
                    return 10;
                switch (read_u8(data, 4)) {
                case 0: vs->as.fmt = AUD_FMT_U8; break;
                case 1: vs->as.fmt = AUD_FMT_S8; break;
                case 2: vs->as.fmt = AUD_FMT_U16; break;
                case 3: vs->as.fmt = AUD_FMT_S16; break;
                case 4: vs->as.fmt = AUD_FMT_U32; break;
                case 5: vs->as.fmt = AUD_FMT_S32; break;
                default:
                    printf("Invalid audio format %d\n", read_u8(data, 4));
                    vnc_client_error(vs);
                    break;
                }
                vs->as.nchannels = read_u8(data, 5);
                if (vs->as.nchannels != 1 && vs->as.nchannels != 2) {
                    printf("Invalid audio channel coount %d\n",
                           read_u8(data, 5));
                    vnc_client_error(vs);
                    break;
                }
                vs->as.freq = read_u32(data, 6);
                break;
            default:
                printf ("Invalid audio message %d\n", read_u8(data, 4));
                vnc_client_error(vs);
                break;
            }
            break;

2020 2021 2022 2023 2024 2025
        default:
            printf("Msg: %d\n", read_u16(data, 0));
            vnc_client_error(vs);
            break;
        }
        break;
B
bellard 已提交
2026
    default:
2027 2028 2029
        printf("Msg: %d\n", data[0]);
        vnc_client_error(vs);
        break;
B
bellard 已提交
2030
    }
2031

B
bellard 已提交
2032 2033 2034 2035
    vnc_read_when(vs, protocol_client_msg, 1);
    return 0;
}

T
ths 已提交
2036
static int protocol_client_init(VncState *vs, uint8_t *data, size_t len)
B
bellard 已提交
2037
{
T
ths 已提交
2038 2039
    char buf[1024];
    int size;
B
bellard 已提交
2040

2041 2042 2043 2044
    vs->client_width = ds_get_width(vs->ds);
    vs->client_height = ds_get_height(vs->ds);
    vnc_write_u16(vs, vs->client_width);
    vnc_write_u16(vs, vs->client_height);
B
bellard 已提交
2045

2046
    pixel_format_message(vs);
B
bellard 已提交
2047

T
ths 已提交
2048 2049 2050 2051 2052 2053 2054
    if (qemu_name)
        size = snprintf(buf, sizeof(buf), "QEMU (%s)", qemu_name);
    else
        size = snprintf(buf, sizeof(buf), "QEMU");

    vnc_write_u32(vs, size);
    vnc_write(vs, buf, size);
B
bellard 已提交
2055 2056
    vnc_flush(vs);

2057
    vnc_client_cache_auth(vs);
2058
    vnc_qmp_event(vs, QEVENT_VNC_INITIALIZED);
2059

B
bellard 已提交
2060 2061 2062 2063 2064
    vnc_read_when(vs, protocol_client_msg, 1);

    return 0;
}

2065 2066 2067 2068 2069
void start_client_init(VncState *vs)
{
    vnc_read_when(vs, protocol_client_init, 1);
}

2070 2071 2072 2073 2074 2075 2076 2077 2078 2079
static void make_challenge(VncState *vs)
{
    int i;

    srand(time(NULL)+getpid()+getpid()*987654+rand());

    for (i = 0 ; i < sizeof(vs->challenge) ; i++)
        vs->challenge[i] = (int) (256.0*rand()/(RAND_MAX+1.0));
}

T
ths 已提交
2080
static int protocol_client_auth_vnc(VncState *vs, uint8_t *data, size_t len)
2081
{
T
ths 已提交
2082
    unsigned char response[VNC_AUTH_CHALLENGE_SIZE];
2083
    int i, j, pwlen;
T
ths 已提交
2084
    unsigned char key[8];
G
Gerd Hoffmann 已提交
2085
    time_t now = time(NULL);
2086

2087
    if (!vs->vd->password) {
2088
        VNC_DEBUG("No password configured on server");
G
Gerd Hoffmann 已提交
2089
        goto reject;
2090
    }
G
Gerd Hoffmann 已提交
2091 2092 2093 2094
    if (vs->vd->expires < now) {
        VNC_DEBUG("Password is expired");
        goto reject;
    }
2095 2096 2097 2098

    memcpy(response, vs->challenge, VNC_AUTH_CHALLENGE_SIZE);

    /* Calculate the expected challenge response */
2099
    pwlen = strlen(vs->vd->password);
2100
    for (i=0; i<sizeof(key); i++)
2101
        key[i] = i<pwlen ? vs->vd->password[i] : 0;
2102 2103 2104 2105 2106 2107
    deskey(key, EN0);
    for (j = 0; j < VNC_AUTH_CHALLENGE_SIZE; j += 8)
        des(response+j, response+j);

    /* Compare expected vs actual challenge response */
    if (memcmp(response, data, VNC_AUTH_CHALLENGE_SIZE) != 0) {
2108
        VNC_DEBUG("Client challenge reponse did not match\n");
G
Gerd Hoffmann 已提交
2109
        goto reject;
2110
    } else {
2111 2112 2113
        VNC_DEBUG("Accepting VNC challenge response\n");
        vnc_write_u32(vs, 0); /* Accept auth */
        vnc_flush(vs);
2114

2115
        start_client_init(vs);
2116 2117
    }
    return 0;
G
Gerd Hoffmann 已提交
2118 2119 2120 2121 2122 2123 2124 2125 2126 2127 2128

reject:
    vnc_write_u32(vs, 1); /* Reject auth */
    if (vs->minor >= 8) {
        static const char err[] = "Authentication failed";
        vnc_write_u32(vs, sizeof(err));
        vnc_write(vs, err, sizeof(err));
    }
    vnc_flush(vs);
    vnc_client_error(vs);
    return 0;
2129 2130
}

2131
void start_auth_vnc(VncState *vs)
2132 2133 2134 2135 2136 2137 2138
{
    make_challenge(vs);
    /* Send client a 'random' challenge */
    vnc_write(vs, vs->challenge, sizeof(vs->challenge));
    vnc_flush(vs);

    vnc_read_when(vs, protocol_client_auth_vnc, sizeof(vs->challenge));
2139 2140 2141
}


T
ths 已提交
2142
static int protocol_client_auth(VncState *vs, uint8_t *data, size_t len)
2143 2144 2145
{
    /* We only advertise 1 auth scheme at a time, so client
     * must pick the one we sent. Verify this */
2146
    if (data[0] != vs->vd->auth) { /* Reject auth */
2147
       VNC_DEBUG("Reject auth %d because it didn't match advertized\n", (int)data[0]);
2148 2149 2150 2151 2152 2153 2154 2155 2156
       vnc_write_u32(vs, 1);
       if (vs->minor >= 8) {
           static const char err[] = "Authentication failed";
           vnc_write_u32(vs, sizeof(err));
           vnc_write(vs, err, sizeof(err));
       }
       vnc_client_error(vs);
    } else { /* Accept requested auth */
       VNC_DEBUG("Client requested auth %d\n", (int)data[0]);
2157
       switch (vs->vd->auth) {
2158 2159
       case VNC_AUTH_NONE:
           VNC_DEBUG("Accept auth none\n");
2160 2161 2162 2163
           if (vs->minor >= 8) {
               vnc_write_u32(vs, 0); /* Accept auth completion */
               vnc_flush(vs);
           }
2164
           start_client_init(vs);
2165 2166 2167 2168
           break;

       case VNC_AUTH_VNC:
           VNC_DEBUG("Start VNC auth\n");
2169 2170
           start_auth_vnc(vs);
           break;
2171

2172
#ifdef CONFIG_VNC_TLS
2173 2174
       case VNC_AUTH_VENCRYPT:
           VNC_DEBUG("Accept VeNCrypt auth\n");;
2175 2176
           start_auth_vencrypt(vs);
           break;
2177 2178
#endif /* CONFIG_VNC_TLS */

2179 2180 2181 2182 2183 2184 2185
#ifdef CONFIG_VNC_SASL
       case VNC_AUTH_SASL:
           VNC_DEBUG("Accept SASL auth\n");
           start_auth_sasl(vs);
           break;
#endif /* CONFIG_VNC_SASL */

2186
       default: /* Should not be possible, but just in case */
2187
           VNC_DEBUG("Reject auth %d server code bug\n", vs->vd->auth);
2188 2189 2190 2191 2192 2193 2194 2195 2196 2197 2198 2199
           vnc_write_u8(vs, 1);
           if (vs->minor >= 8) {
               static const char err[] = "Authentication failed";
               vnc_write_u32(vs, sizeof(err));
               vnc_write(vs, err, sizeof(err));
           }
           vnc_client_error(vs);
       }
    }
    return 0;
}

T
ths 已提交
2200
static int protocol_version(VncState *vs, uint8_t *version, size_t len)
B
bellard 已提交
2201 2202 2203 2204 2205 2206
{
    char local[13];

    memcpy(local, version, 12);
    local[12] = 0;

2207
    if (sscanf(local, "RFB %03d.%03d\n", &vs->major, &vs->minor) != 2) {
2208 2209 2210
        VNC_DEBUG("Malformed protocol version %s\n", local);
        vnc_client_error(vs);
        return 0;
B
bellard 已提交
2211
    }
2212 2213
    VNC_DEBUG("Client request protocol version %d.%d\n", vs->major, vs->minor);
    if (vs->major != 3 ||
2214 2215 2216 2217 2218 2219 2220 2221 2222 2223
        (vs->minor != 3 &&
         vs->minor != 4 &&
         vs->minor != 5 &&
         vs->minor != 7 &&
         vs->minor != 8)) {
        VNC_DEBUG("Unsupported client version\n");
        vnc_write_u32(vs, VNC_AUTH_INVALID);
        vnc_flush(vs);
        vnc_client_error(vs);
        return 0;
2224
    }
2225
    /* Some broken clients report v3.4 or v3.5, which spec requires to be treated
2226 2227
     * as equivalent to v3.3 by servers
     */
2228
    if (vs->minor == 4 || vs->minor == 5)
2229
        vs->minor = 3;
2230 2231

    if (vs->minor == 3) {
2232
        if (vs->vd->auth == VNC_AUTH_NONE) {
2233
            VNC_DEBUG("Tell client auth none\n");
2234
            vnc_write_u32(vs, vs->vd->auth);
2235
            vnc_flush(vs);
2236
            start_client_init(vs);
2237
       } else if (vs->vd->auth == VNC_AUTH_VNC) {
2238
            VNC_DEBUG("Tell client VNC auth\n");
2239
            vnc_write_u32(vs, vs->vd->auth);
2240 2241 2242
            vnc_flush(vs);
            start_auth_vnc(vs);
       } else {
2243
            VNC_DEBUG("Unsupported auth %d for protocol 3.3\n", vs->vd->auth);
2244 2245 2246 2247 2248
            vnc_write_u32(vs, VNC_AUTH_INVALID);
            vnc_flush(vs);
            vnc_client_error(vs);
       }
    } else {
2249 2250 2251 2252 2253
        VNC_DEBUG("Telling client we support auth %d\n", vs->vd->auth);
        vnc_write_u8(vs, 1); /* num auth */
        vnc_write_u8(vs, vs->vd->auth);
        vnc_read_when(vs, protocol_client_auth, 1);
        vnc_flush(vs);
2254
    }
B
bellard 已提交
2255 2256 2257 2258

    return 0;
}

S
Stefano Stabellini 已提交
2259 2260 2261 2262 2263 2264 2265
static int vnc_refresh_server_surface(VncDisplay *vd)
{
    int y;
    uint8_t *guest_row;
    uint8_t *server_row;
    int cmp_bytes;
    uint32_t width_mask[VNC_DIRTY_WORDS];
2266
    VncState *vs;
S
Stefano Stabellini 已提交
2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294
    int has_dirty = 0;

    /*
     * Walk through the guest dirty map.
     * Check and copy modified bits from guest to server surface.
     * Update server dirty map.
     */
    vnc_set_bits(width_mask, (ds_get_width(vd->ds) / 16), VNC_DIRTY_WORDS);
    cmp_bytes = 16 * ds_get_bytes_per_pixel(vd->ds);
    guest_row  = vd->guest.ds->data;
    server_row = vd->server->data;
    for (y = 0; y < vd->guest.ds->height; y++) {
        if (vnc_and_bits(vd->guest.dirty[y], width_mask, VNC_DIRTY_WORDS)) {
            int x;
            uint8_t *guest_ptr;
            uint8_t *server_ptr;

            guest_ptr  = guest_row;
            server_ptr = server_row;

            for (x = 0; x < vd->guest.ds->width;
                    x += 16, guest_ptr += cmp_bytes, server_ptr += cmp_bytes) {
                if (!vnc_get_bit(vd->guest.dirty[y], (x / 16)))
                    continue;
                vnc_clear_bit(vd->guest.dirty[y], (x / 16));
                if (memcmp(server_ptr, guest_ptr, cmp_bytes) == 0)
                    continue;
                memcpy(server_ptr, guest_ptr, cmp_bytes);
2295
                QTAILQ_FOREACH(vs, &vd->clients, next) {
S
Stefano Stabellini 已提交
2296 2297 2298 2299 2300 2301 2302 2303 2304 2305 2306
                    vnc_set_bit(vs->dirty[y], (x / 16));
                }
                has_dirty++;
            }
        }
        guest_row  += ds_get_linesize(vd->ds);
        server_row += ds_get_linesize(vd->ds);
    }
    return has_dirty;
}

2307 2308 2309
static void vnc_refresh(void *opaque)
{
    VncDisplay *vd = opaque;
2310 2311
    VncState *vs, *vn;
    int has_dirty, rects = 0;
2312 2313 2314

    vga_hw_update();

C
Corentin Chary 已提交
2315 2316 2317 2318 2319 2320 2321
    if (vnc_trylock_display(vd)) {
        vd->timer_interval = VNC_REFRESH_INTERVAL_BASE;
        qemu_mod_timer(vd->timer, qemu_get_clock(rt_clock) +
                       vd->timer_interval);
        return;
    }

S
Stefano Stabellini 已提交
2322
    has_dirty = vnc_refresh_server_surface(vd);
C
Corentin Chary 已提交
2323
    vnc_unlock_display(vd);
S
Stefano Stabellini 已提交
2324

2325
    QTAILQ_FOREACH_SAFE(vs, &vd->clients, next, vn) {
S
Stefano Stabellini 已提交
2326
        rects += vnc_update_client(vs, has_dirty);
2327
        /* vs might be free()ed here */
2328
    }
C
Corentin Chary 已提交
2329

2330 2331 2332 2333
    /* vd->timer could be NULL now if the last client disconnected,
     * in this case don't update the timer */
    if (vd->timer == NULL)
        return;
2334

S
Stefano Stabellini 已提交
2335 2336 2337 2338 2339 2340 2341 2342 2343 2344
    if (has_dirty && rects) {
        vd->timer_interval /= 2;
        if (vd->timer_interval < VNC_REFRESH_INTERVAL_BASE)
            vd->timer_interval = VNC_REFRESH_INTERVAL_BASE;
    } else {
        vd->timer_interval += VNC_REFRESH_INTERVAL_INC;
        if (vd->timer_interval > VNC_REFRESH_INTERVAL_MAX)
            vd->timer_interval = VNC_REFRESH_INTERVAL_MAX;
    }
    qemu_mod_timer(vd->timer, qemu_get_clock(rt_clock) + vd->timer_interval);
2345 2346 2347 2348
}

static void vnc_init_timer(VncDisplay *vd)
{
S
Stefano Stabellini 已提交
2349
    vd->timer_interval = VNC_REFRESH_INTERVAL_BASE;
2350
    if (vd->timer == NULL && !QTAILQ_EMPTY(&vd->clients)) {
2351
        vd->timer = qemu_new_timer(rt_clock, vnc_refresh, vd);
S
Stefano Stabellini 已提交
2352
        vnc_refresh(vd);
2353 2354 2355 2356 2357
    }
}

static void vnc_remove_timer(VncDisplay *vd)
{
2358
    if (vd->timer != NULL && QTAILQ_EMPTY(&vd->clients)) {
2359 2360 2361 2362 2363 2364
        qemu_del_timer(vd->timer);
        qemu_free_timer(vd->timer);
        vd->timer = NULL;
    }
}

2365
static void vnc_connect(VncDisplay *vd, int csock)
2366
{
2367 2368 2369 2370
    VncState *vs = qemu_mallocz(sizeof(VncState));
    vs->csock = csock;

    VNC_DEBUG("New client on socket %d\n", csock);
2371
    dcl->idle = 0;
2372 2373
    socket_set_nonblock(vs->csock);
    qemu_set_fd_handler2(vs->csock, NULL, vnc_client_read, NULL, vs);
2374

2375
    vnc_client_cache_addr(vs);
2376
    vnc_qmp_event(vs, QEVENT_VNC_CONNECTED);
2377

2378 2379 2380 2381 2382 2383 2384 2385 2386 2387
    vs->vd = vd;
    vs->ds = vd->ds;
    vs->last_x = -1;
    vs->last_y = -1;

    vs->as.freq = 44100;
    vs->as.nchannels = 2;
    vs->as.fmt = AUD_FMT_S16;
    vs->as.endianness = 0;

C
Corentin Chary 已提交
2388 2389 2390 2391
#ifdef CONFIG_VNC_THREAD
    qemu_mutex_init(&vs->output_mutex);
#endif

2392
    QTAILQ_INSERT_HEAD(&vd->clients, vs, next);
S
Stefano Stabellini 已提交
2393 2394 2395

    vga_hw_update();

2396 2397 2398
    vnc_write(vs, "RFB 003.008\n", 12);
    vnc_flush(vs);
    vnc_read_when(vs, protocol_version, 12);
M
malc 已提交
2399
    reset_keys(vs);
G
Gerd Hoffmann 已提交
2400 2401
    if (vs->vd->lock_key_sync)
        vs->led = qemu_add_led_event_handler(kbd_leds, vs);
2402

2403 2404 2405
    vs->mouse_mode_notifier.notify = check_pointer_type_change;
    qemu_add_mouse_mode_change_notifier(&vs->mouse_mode_notifier);

2406
    vnc_init_timer(vd);
S
Stefano Stabellini 已提交
2407

2408
    /* vs might be free()ed here */
2409 2410
}

B
bellard 已提交
2411 2412
static void vnc_listen_read(void *opaque)
{
2413
    VncDisplay *vs = opaque;
B
bellard 已提交
2414 2415 2416
    struct sockaddr_in addr;
    socklen_t addrlen = sizeof(addr);

2417 2418 2419
    /* Catch-up */
    vga_hw_update();

K
Kevin Wolf 已提交
2420
    int csock = qemu_accept(vs->lsock, (struct sockaddr *)&addr, &addrlen);
2421 2422
    if (csock != -1) {
        vnc_connect(vs, csock);
B
bellard 已提交
2423 2424 2425
    }
}

2426
void vnc_display_init(DisplayState *ds)
B
bellard 已提交
2427
{
2428
    VncDisplay *vs = qemu_mallocz(sizeof(*vs));
B
bellard 已提交
2429

2430
    dcl = qemu_mallocz(sizeof(DisplayChangeListener));
B
bellard 已提交
2431 2432

    ds->opaque = vs;
2433
    dcl->idle = 1;
2434
    vnc_display = vs;
B
bellard 已提交
2435 2436 2437 2438

    vs->lsock = -1;

    vs->ds = ds;
2439
    QTAILQ_INIT(&vs->clients);
G
Gerd Hoffmann 已提交
2440
    vs->expires = TIME_MAX;
B
bellard 已提交
2441

2442
    if (keyboard_layout)
2443
        vs->kbd_layout = init_keyboard_layout(name2keysym, keyboard_layout);
2444
    else
2445
        vs->kbd_layout = init_keyboard_layout(name2keysym, "en-us");
B
bellard 已提交
2446 2447

    if (!vs->kbd_layout)
2448
        exit(1);
B
bellard 已提交
2449

C
Corentin Chary 已提交
2450 2451 2452 2453 2454
#ifdef CONFIG_VNC_THREAD
    qemu_mutex_init(&vs->mutex);
    vnc_start_worker_thread();
#endif

2455
    dcl->dpy_copy = vnc_dpy_copy;
2456 2457 2458 2459
    dcl->dpy_update = vnc_dpy_update;
    dcl->dpy_resize = vnc_dpy_resize;
    dcl->dpy_setdata = vnc_dpy_setdata;
    register_displaychangelistener(ds, dcl);
G
Gerd Hoffmann 已提交
2460 2461
    ds->mouse_set = vnc_mouse_set;
    ds->cursor_define = vnc_dpy_cursor_define;
2462 2463
}

2464

2465 2466
void vnc_display_close(DisplayState *ds)
{
2467
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;
2468

2469 2470
    if (!vs)
        return;
2471
    if (vs->display) {
2472 2473
        qemu_free(vs->display);
        vs->display = NULL;
2474 2475
    }
    if (vs->lsock != -1) {
2476 2477 2478
        qemu_set_fd_handler2(vs->lsock, NULL, NULL, NULL, NULL);
        close(vs->lsock);
        vs->lsock = -1;
2479
    }
2480
    vs->auth = VNC_AUTH_INVALID;
2481
#ifdef CONFIG_VNC_TLS
2482
    vs->subauth = VNC_AUTH_INVALID;
2483
    vs->tls.x509verify = 0;
2484
#endif
2485 2486
}

2487 2488 2489 2490 2491 2492 2493 2494 2495 2496 2497 2498 2499 2500 2501 2502 2503 2504
int vnc_display_disable_login(DisplayState *ds)
{
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;

    if (!vs) {
        return -1;
    }

    if (vs->password) {
        qemu_free(vs->password);
    }

    vs->password = NULL;
    vs->auth = VNC_AUTH_VNC;

    return 0;
}

2505 2506
int vnc_display_password(DisplayState *ds, const char *password)
{
2507
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;
2508

2509 2510 2511 2512
    if (!vs) {
        return -1;
    }

2513 2514 2515 2516 2517 2518
    if (!password) {
        /* This is not the intention of this interface but err on the side
           of being safe */
        return vnc_display_disable_login(ds);
    }

2519
    if (vs->password) {
2520 2521
        qemu_free(vs->password);
        vs->password = NULL;
2522
    }
2523 2524
    vs->password = qemu_strdup(password);
    vs->auth = VNC_AUTH_VNC;
2525 2526

    return 0;
2527 2528
}

G
Gerd Hoffmann 已提交
2529 2530 2531 2532 2533 2534 2535 2536
int vnc_display_pw_expire(DisplayState *ds, time_t expires)
{
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;

    vs->expires = expires;
    return 0;
}

2537 2538 2539 2540 2541 2542 2543
char *vnc_display_local_addr(DisplayState *ds)
{
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;
    
    return vnc_socket_local_addr("%s:%s", vs->lsock);
}

2544
int vnc_display_open(DisplayState *ds, const char *display)
2545
{
2546
    VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;
2547 2548
    const char *options;
    int password = 0;
2549
    int reverse = 0;
2550
#ifdef CONFIG_VNC_TLS
2551
    int tls = 0, x509 = 0;
2552
#endif
2553 2554 2555 2556
#ifdef CONFIG_VNC_SASL
    int sasl = 0;
    int saslErr;
#endif
B
Blue Swirl 已提交
2557
#if defined(CONFIG_VNC_TLS) || defined(CONFIG_VNC_SASL)
2558
    int acl = 0;
B
Blue Swirl 已提交
2559
#endif
G
Gerd Hoffmann 已提交
2560
    int lock_key_sync = 1;
2561

2562
    if (!vnc_display)
2563
        return -1;
2564
    vnc_display_close(ds);
2565
    if (strcmp(display, "none") == 0)
2566
        return 0;
B
bellard 已提交
2567

2568
    if (!(vs->display = strdup(display)))
2569
        return -1;
2570 2571 2572

    options = display;
    while ((options = strchr(options, ','))) {
2573 2574 2575 2576 2577
        options++;
        if (strncmp(options, "password", 8) == 0) {
            password = 1; /* Require password auth */
        } else if (strncmp(options, "reverse", 7) == 0) {
            reverse = 1;
G
Gerd Hoffmann 已提交
2578 2579
        } else if (strncmp(options, "no-lock-key-sync", 9) == 0) {
            lock_key_sync = 0;
2580
#ifdef CONFIG_VNC_SASL
2581 2582
        } else if (strncmp(options, "sasl", 4) == 0) {
            sasl = 1; /* Require SASL auth */
2583
#endif
2584
#ifdef CONFIG_VNC_TLS
2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605 2606 2607 2608 2609 2610 2611 2612 2613 2614 2615
        } else if (strncmp(options, "tls", 3) == 0) {
            tls = 1; /* Require TLS */
        } else if (strncmp(options, "x509", 4) == 0) {
            char *start, *end;
            x509 = 1; /* Require x509 certificates */
            if (strncmp(options, "x509verify", 10) == 0)
                vs->tls.x509verify = 1; /* ...and verify client certs */

            /* Now check for 'x509=/some/path' postfix
             * and use that to setup x509 certificate/key paths */
            start = strchr(options, '=');
            end = strchr(options, ',');
            if (start && (!end || (start < end))) {
                int len = end ? end-(start+1) : strlen(start+1);
                char *path = qemu_strndup(start + 1, len);

                VNC_DEBUG("Trying certificate path '%s'\n", path);
                if (vnc_tls_set_x509_creds_dir(vs, path) < 0) {
                    fprintf(stderr, "Failed to find x509 certificates/keys in %s\n", path);
                    qemu_free(path);
                    qemu_free(vs->display);
                    vs->display = NULL;
                    return -1;
                }
                qemu_free(path);
            } else {
                fprintf(stderr, "No certificate path provided\n");
                qemu_free(vs->display);
                vs->display = NULL;
                return -1;
            }
2616
#endif
B
Blue Swirl 已提交
2617
#if defined(CONFIG_VNC_TLS) || defined(CONFIG_VNC_SASL)
2618 2619
        } else if (strncmp(options, "acl", 3) == 0) {
            acl = 1;
B
Blue Swirl 已提交
2620
#endif
C
Corentin Chary 已提交
2621 2622
        } else if (strncmp(options, "lossy", 5) == 0) {
            vs->lossy = true;
2623
        }
2624 2625
    }

2626 2627
#ifdef CONFIG_VNC_TLS
    if (acl && x509 && vs->tls.x509verify) {
2628 2629 2630 2631
        if (!(vs->tls.acl = qemu_acl_init("vnc.x509dname"))) {
            fprintf(stderr, "Failed to create x509 dname ACL\n");
            exit(1);
        }
2632 2633 2634 2635
    }
#endif
#ifdef CONFIG_VNC_SASL
    if (acl && sasl) {
2636 2637 2638 2639
        if (!(vs->sasl.acl = qemu_acl_init("vnc.username"))) {
            fprintf(stderr, "Failed to create username ACL\n");
            exit(1);
        }
2640 2641 2642
    }
#endif

2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654 2655 2656 2657 2658
    /*
     * Combinations we support here:
     *
     *  - no-auth                (clear text, no auth)
     *  - password               (clear text, weak auth)
     *  - sasl                   (encrypt, good auth *IF* using Kerberos via GSSAPI)
     *  - tls                    (encrypt, weak anonymous creds, no auth)
     *  - tls + password         (encrypt, weak anonymous creds, weak auth)
     *  - tls + sasl             (encrypt, weak anonymous creds, good auth)
     *  - tls + x509             (encrypt, good x509 creds, no auth)
     *  - tls + x509 + password  (encrypt, good x509 creds, weak auth)
     *  - tls + x509 + sasl      (encrypt, good x509 creds, good auth)
     *
     * NB1. TLS is a stackable auth scheme.
     * NB2. the x509 schemes have option to validate a client cert dname
     */
2659
    if (password) {
2660
#ifdef CONFIG_VNC_TLS
2661 2662 2663 2664 2665 2666 2667 2668 2669 2670
        if (tls) {
            vs->auth = VNC_AUTH_VENCRYPT;
            if (x509) {
                VNC_DEBUG("Initializing VNC server with x509 password auth\n");
                vs->subauth = VNC_AUTH_VENCRYPT_X509VNC;
            } else {
                VNC_DEBUG("Initializing VNC server with TLS password auth\n");
                vs->subauth = VNC_AUTH_VENCRYPT_TLSVNC;
            }
        } else {
2671
#endif /* CONFIG_VNC_TLS */
2672 2673
            VNC_DEBUG("Initializing VNC server with password auth\n");
            vs->auth = VNC_AUTH_VNC;
2674
#ifdef CONFIG_VNC_TLS
2675 2676
            vs->subauth = VNC_AUTH_INVALID;
        }
2677 2678 2679 2680 2681 2682 2683
#endif /* CONFIG_VNC_TLS */
#ifdef CONFIG_VNC_SASL
    } else if (sasl) {
#ifdef CONFIG_VNC_TLS
        if (tls) {
            vs->auth = VNC_AUTH_VENCRYPT;
            if (x509) {
2684
                VNC_DEBUG("Initializing VNC server with x509 SASL auth\n");
2685 2686
                vs->subauth = VNC_AUTH_VENCRYPT_X509SASL;
            } else {
2687
                VNC_DEBUG("Initializing VNC server with TLS SASL auth\n");
2688 2689 2690 2691
                vs->subauth = VNC_AUTH_VENCRYPT_TLSSASL;
            }
        } else {
#endif /* CONFIG_VNC_TLS */
2692
            VNC_DEBUG("Initializing VNC server with SASL auth\n");
2693 2694 2695 2696 2697 2698
            vs->auth = VNC_AUTH_SASL;
#ifdef CONFIG_VNC_TLS
            vs->subauth = VNC_AUTH_INVALID;
        }
#endif /* CONFIG_VNC_TLS */
#endif /* CONFIG_VNC_SASL */
2699
    } else {
2700
#ifdef CONFIG_VNC_TLS
2701 2702 2703 2704 2705 2706 2707 2708 2709 2710
        if (tls) {
            vs->auth = VNC_AUTH_VENCRYPT;
            if (x509) {
                VNC_DEBUG("Initializing VNC server with x509 no auth\n");
                vs->subauth = VNC_AUTH_VENCRYPT_X509NONE;
            } else {
                VNC_DEBUG("Initializing VNC server with TLS no auth\n");
                vs->subauth = VNC_AUTH_VENCRYPT_TLSNONE;
            }
        } else {
2711
#endif
2712 2713
            VNC_DEBUG("Initializing VNC server with no auth\n");
            vs->auth = VNC_AUTH_NONE;
2714
#ifdef CONFIG_VNC_TLS
2715 2716
            vs->subauth = VNC_AUTH_INVALID;
        }
2717
#endif
2718
    }
B
bellard 已提交
2719

2720 2721 2722 2723 2724 2725 2726 2727 2728
#ifdef CONFIG_VNC_SASL
    if ((saslErr = sasl_server_init(NULL, "qemu")) != SASL_OK) {
        fprintf(stderr, "Failed to initialize SASL auth %s",
                sasl_errstring(saslErr, NULL, NULL));
        free(vs->display);
        vs->display = NULL;
        return -1;
    }
#endif
G
Gerd Hoffmann 已提交
2729
    vs->lock_key_sync = lock_key_sync;
2730

2731
    if (reverse) {
2732 2733 2734 2735 2736 2737
        /* connect to viewer */
        if (strncmp(display, "unix:", 5) == 0)
            vs->lsock = unix_connect(display+5);
        else
            vs->lsock = inet_connect(display, SOCK_STREAM);
        if (-1 == vs->lsock) {
2738 2739 2740 2741
            free(vs->display);
            vs->display = NULL;
            return -1;
        } else {
2742
            int csock = vs->lsock;
2743
            vs->lsock = -1;
2744
            vnc_connect(vs, csock);
2745
        }
2746
        return 0;
B
bellard 已提交
2747

2748 2749 2750 2751 2752
    } else {
        /* listen for connects */
        char *dpy;
        dpy = qemu_malloc(256);
        if (strncmp(display, "unix:", 5) == 0) {
B
blueswir1 已提交
2753
            pstrcpy(dpy, 256, "unix:");
2754
            vs->lsock = unix_listen(display+5, dpy+5, 256-5);
2755 2756 2757 2758 2759
        } else {
            vs->lsock = inet_listen(display, dpy, 256, SOCK_STREAM, 5900);
        }
        if (-1 == vs->lsock) {
            free(dpy);
2760
            return -1;
2761 2762 2763 2764
        } else {
            free(vs->display);
            vs->display = dpy;
        }
B
bellard 已提交
2765
    }
2766
    return qemu_set_fd_handler2(vs->lsock, NULL, vnc_listen_read, NULL, vs);
B
bellard 已提交
2767
}