Coverage Report

Created: 2026-05-11 07:01

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/FreeRDP/libfreerdp/core/surface.c
Line
Count
Source
1
/**
2
 * FreeRDP: A Remote Desktop Protocol Implementation
3
 * Surface Commands
4
 *
5
 * Copyright 2011 Vic Lee
6
 *
7
 * Licensed under the Apache License, Version 2.0 (the "License");
8
 * you may not use this file except in compliance with the License.
9
 * You may obtain a copy of the License at
10
 *
11
 *     http://www.apache.org/licenses/LICENSE-2.0
12
 *
13
 * Unless required by applicable law or agreed to in writing, software
14
 * distributed under the License is distributed on an "AS IS" BASIS,
15
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16
 * See the License for the specific language governing permissions and
17
 * limitations under the License.
18
 */
19
20
#include <freerdp/config.h>
21
22
#include "settings.h"
23
24
#include <winpr/assert.h>
25
#include <winpr/cast.h>
26
27
#include <freerdp/utils/pcap.h>
28
#include <freerdp/log.h>
29
30
#include "../cache/cache.h"
31
#include "surface.h"
32
33
#define TAG FREERDP_TAG("core.surface")
34
35
static BOOL update_recv_surfcmd_bitmap_header_ex(wStream* s, TS_COMPRESSED_BITMAP_HEADER_EX* header)
36
2.15k
{
37
2.15k
  if (!s || !header)
38
0
    return FALSE;
39
40
2.15k
  if (!Stream_CheckAndLogRequiredLength(TAG, s, 24))
41
88
    return FALSE;
42
43
2.06k
  Stream_Read_UINT32(s, header->highUniqueId);
44
2.06k
  Stream_Read_UINT32(s, header->lowUniqueId);
45
2.06k
  Stream_Read_UINT64(s, header->tmMilliseconds);
46
2.06k
  Stream_Read_UINT64(s, header->tmSeconds);
47
2.06k
  return TRUE;
48
2.15k
}
49
50
static BOOL update_recv_surfcmd_bitmap_ex(wStream* s, TS_BITMAP_DATA_EX* bmp)
51
3.68k
{
52
3.68k
  if (!s || !bmp)
53
0
    return FALSE;
54
55
3.68k
  if (!Stream_CheckAndLogRequiredLength(TAG, s, 12))
56
259
    return FALSE;
57
58
3.42k
  Stream_Read_UINT8(s, bmp->bpp);
59
3.42k
  Stream_Read_UINT8(s, bmp->flags);
60
3.42k
  Stream_Seek(s, 1); /* reserved */
61
3.42k
  Stream_Read_UINT8(s, bmp->codecID);
62
3.42k
  Stream_Read_UINT16(s, bmp->width);
63
3.42k
  Stream_Read_UINT16(s, bmp->height);
64
3.42k
  Stream_Read_UINT32(s, bmp->bitmapDataLength);
65
66
3.42k
  if ((bmp->width == 0) || (bmp->height == 0))
67
160
  {
68
160
    WLog_ERR(TAG, "invalid size value width=%" PRIu16 ", height=%" PRIu16, bmp->width,
69
160
             bmp->height);
70
160
    return FALSE;
71
160
  }
72
73
3.26k
  if ((bmp->bpp < 1) || (bmp->bpp > 32))
74
461
  {
75
461
    WLog_ERR(TAG, "invalid bpp value %" PRIu32 "", bmp->bpp);
76
461
    return FALSE;
77
461
  }
78
79
2.80k
  if (bmp->flags & EX_COMPRESSED_BITMAP_HEADER_PRESENT)
80
2.15k
  {
81
2.15k
    if (!update_recv_surfcmd_bitmap_header_ex(s, &bmp->exBitmapDataHeader))
82
88
      return FALSE;
83
2.15k
  }
84
85
2.72k
  bmp->bitmapData = Stream_Pointer(s);
86
2.72k
  if (!Stream_SafeSeek(s, bmp->bitmapDataLength))
87
2.00k
  {
88
2.00k
    WLog_ERR(TAG, "expected bitmapDataLength %" PRIu32 ", not enough data",
89
2.00k
             bmp->bitmapDataLength);
90
2.00k
    return FALSE;
91
2.00k
  }
92
719
  return TRUE;
93
2.72k
}
94
95
static BOOL update_recv_surfcmd_is_rect_valid(const rdpContext* context,
96
                                              const SURFACE_BITS_COMMAND* cmd)
97
5.96k
{
98
5.96k
  WINPR_ASSERT(context);
99
5.96k
  WINPR_ASSERT(context->settings);
100
5.96k
  WINPR_ASSERT(cmd);
101
102
  /* We need a rectangle with left/top being smaller than right/bottom.
103
   * Also do not allow empty rectangles. */
104
5.96k
  if ((cmd->destTop >= cmd->destBottom) || (cmd->destLeft >= cmd->destRight))
105
1.32k
  {
106
1.32k
    WLog_WARN(TAG,
107
1.32k
              "Empty surface bits command rectangle: %" PRIu16 "x%" PRIu16 "-%" PRIu16
108
1.32k
              "x%" PRIu16,
109
1.32k
              cmd->destLeft, cmd->destTop, cmd->destRight, cmd->destBottom);
110
1.32k
    return FALSE;
111
1.32k
  }
112
113
  /* The rectangle needs to fit into our session size */
114
4.63k
  const DWORD DesktopWidth = freerdp_settings_get_uint32(context->settings, FreeRDP_DesktopWidth);
115
4.63k
  const DWORD DesktopHeight =
116
4.63k
      freerdp_settings_get_uint32(context->settings, FreeRDP_DesktopHeight);
117
4.63k
  if ((cmd->destRight > DesktopWidth) || (cmd->destBottom > DesktopHeight))
118
949
  {
119
949
    WLog_WARN(TAG,
120
949
              "Invalid surface bits command rectangle: %" PRIu16 "x%" PRIu16 "-%" PRIu16
121
949
              "x%" PRIu16 " does not fit %" PRIu32 "x%" PRIu32,
122
949
              cmd->destLeft, cmd->destTop, cmd->destRight, cmd->destBottom, DesktopWidth,
123
949
              DesktopHeight);
124
949
    return FALSE;
125
949
  }
126
127
3.68k
  return TRUE;
128
4.63k
}
129
130
static BOOL update_recv_surfcmd_surface_bits(rdpUpdate* update, wStream* s, UINT16 cmdType)
131
6.47k
{
132
6.47k
  BOOL rc = FALSE;
133
6.47k
  SURFACE_BITS_COMMAND cmd = WINPR_C_ARRAY_INIT;
134
135
6.47k
  if (!Stream_CheckAndLogRequiredLength(TAG, s, 8))
136
516
    goto fail;
137
138
5.96k
  cmd.cmdType = cmdType;
139
5.96k
  Stream_Read_UINT16(s, cmd.destLeft);
140
5.96k
  Stream_Read_UINT16(s, cmd.destTop);
141
5.96k
  Stream_Read_UINT16(s, cmd.destRight);
142
5.96k
  Stream_Read_UINT16(s, cmd.destBottom);
143
144
5.96k
  if (!update_recv_surfcmd_is_rect_valid(update->context, &cmd))
145
2.27k
    goto fail;
146
147
3.68k
  if (!update_recv_surfcmd_bitmap_ex(s, &cmd.bmp))
148
2.96k
    goto fail;
149
150
719
  if (!IFCALLRESULT(TRUE, update->SurfaceBits, update->context, &cmd))
151
140
  {
152
140
    WLog_DBG(TAG, "update->SurfaceBits implementation failed");
153
140
    goto fail;
154
140
  }
155
156
579
  rc = TRUE;
157
6.47k
fail:
158
6.47k
  return rc;
159
579
}
160
161
static BOOL update_recv_surfcmd_frame_marker(rdpUpdate* update, wStream* s)
162
1.37k
{
163
1.37k
  SURFACE_FRAME_MARKER marker = WINPR_C_ARRAY_INIT;
164
1.37k
  rdp_update_internal* up = update_cast(update);
165
166
1.37k
  WINPR_ASSERT(s);
167
168
1.37k
  if (!Stream_CheckAndLogRequiredLength(TAG, s, 2))
169
303
    return FALSE;
170
171
1.06k
  Stream_Read_UINT16(s, marker.frameAction);
172
1.06k
  if (!Stream_CheckAndLogRequiredLength(TAG, s, 4))
173
665
    WLog_WARN(TAG,
174
1.06k
              "[SERVER-BUG]: got %" PRIuz ", expected %u"
175
1.06k
              " bytes. [MS-RDPBCGR] 2.2.9.2.3 Frame Marker Command (TS_FRAME_MARKER) is "
176
1.06k
              "missing frameId, ignoring",
177
1.06k
              Stream_GetRemainingLength(s), 4u);
178
404
  else
179
404
    Stream_Read_UINT32(s, marker.frameId);
180
1.06k
  WLog_Print(up->log, WLOG_DEBUG, "SurfaceFrameMarker: action: %s (%" PRIu32 ") id: %" PRIu32 "",
181
1.06k
             (!marker.frameAction) ? "Begin" : "End", marker.frameAction, marker.frameId);
182
183
1.06k
  if (!update->SurfaceFrameMarker)
184
195
  {
185
195
    WINPR_ASSERT(update->context);
186
195
    if (freerdp_settings_get_bool(update->context->settings, FreeRDP_DeactivateClientDecoding))
187
0
      return TRUE;
188
195
    WLog_ERR(TAG, "Missing callback update->SurfaceFrameMarker");
189
195
    return FALSE;
190
195
  }
191
192
874
  if (!update->SurfaceFrameMarker(update->context, &marker))
193
874
  {
194
874
    WLog_DBG(TAG, "update->SurfaceFrameMarker implementation failed");
195
874
    return FALSE;
196
874
  }
197
198
0
  return TRUE;
199
874
}
200
201
BOOL update_recv_surfcmds(rdpUpdate* update, wStream* s)
202
31.9k
{
203
31.9k
  UINT16 cmdType = 0;
204
31.9k
  rdp_update_internal* up = update_cast(update);
205
206
31.9k
  WINPR_ASSERT(s);
207
208
32.4k
  while (Stream_GetRemainingLength(s) >= 2)
209
18.7k
  {
210
18.7k
    const size_t start = Stream_GetPosition(s);
211
18.7k
    const BYTE* mark = Stream_ConstPointer(s);
212
213
18.7k
    Stream_Read_UINT16(s, cmdType);
214
215
18.7k
    switch (cmdType)
216
18.7k
    {
217
5.37k
      case CMDTYPE_SET_SURFACE_BITS:
218
6.47k
      case CMDTYPE_STREAM_SURFACE_BITS:
219
6.47k
        if (!update_recv_surfcmd_surface_bits(update, s, cmdType))
220
5.89k
          return FALSE;
221
222
579
        break;
223
224
1.37k
      case CMDTYPE_FRAME_MARKER:
225
1.37k
        if (!update_recv_surfcmd_frame_marker(update, s))
226
1.37k
          return FALSE;
227
228
0
        break;
229
230
10.9k
      default:
231
10.9k
        WLog_ERR(TAG, "unknown cmdType 0x%04" PRIX16 "", cmdType);
232
10.9k
        return FALSE;
233
18.7k
    }
234
235
579
    if (up->dump_rfx)
236
0
    {
237
0
      const size_t size = Stream_GetPosition(s) - start;
238
      /* TODO: treat return values */
239
0
      if (!pcap_add_record(up->pcap_rfx, mark, size))
240
0
        return FALSE;
241
0
      pcap_flush(up->pcap_rfx);
242
0
    }
243
579
  }
244
245
13.7k
  return TRUE;
246
31.9k
}
247
248
static BOOL update_write_surfcmd_bitmap_header_ex(wStream* s,
249
                                                  const TS_COMPRESSED_BITMAP_HEADER_EX* header)
250
67
{
251
67
  if (!s || !header)
252
0
    return FALSE;
253
254
67
  if (!Stream_EnsureRemainingCapacity(s, 24))
255
0
    return FALSE;
256
257
67
  Stream_Write_UINT32(s, header->highUniqueId);
258
67
  Stream_Write_UINT32(s, header->lowUniqueId);
259
67
  Stream_Write_UINT64(s, header->tmMilliseconds);
260
67
  Stream_Write_UINT64(s, header->tmSeconds);
261
67
  return TRUE;
262
67
}
263
264
static BOOL update_write_surfcmd_bitmap_ex(wStream* s, const TS_BITMAP_DATA_EX* bmp)
265
139
{
266
139
  if (!s || !bmp)
267
0
    return FALSE;
268
269
139
  if (!Stream_EnsureRemainingCapacity(s, 12))
270
0
    return FALSE;
271
272
139
  if (bmp->codecID > UINT8_MAX)
273
0
  {
274
0
    WLog_ERR(TAG, "Invalid TS_BITMAP_DATA_EX::codecID=0x%04" PRIx16 "", bmp->codecID);
275
0
    return FALSE;
276
0
  }
277
139
  Stream_Write_UINT8(s, bmp->bpp);
278
139
  Stream_Write_UINT8(s, bmp->flags);
279
139
  Stream_Write_UINT8(s, 0); /* reserved1, reserved2 */
280
139
  Stream_Write_UINT8(s, (UINT8)bmp->codecID);
281
139
  Stream_Write_UINT16(s, bmp->width);
282
139
  Stream_Write_UINT16(s, bmp->height);
283
139
  Stream_Write_UINT32(s, bmp->bitmapDataLength);
284
285
139
  if (bmp->flags & EX_COMPRESSED_BITMAP_HEADER_PRESENT)
286
67
  {
287
67
    if (!update_write_surfcmd_bitmap_header_ex(s, &bmp->exBitmapDataHeader))
288
0
      return FALSE;
289
67
  }
290
291
139
  if (!Stream_EnsureRemainingCapacity(s, bmp->bitmapDataLength))
292
0
    return FALSE;
293
294
139
  Stream_Write(s, bmp->bitmapData, bmp->bitmapDataLength);
295
139
  return TRUE;
296
139
}
297
298
BOOL update_write_surfcmd_surface_bits(wStream* s, const SURFACE_BITS_COMMAND* cmd)
299
139
{
300
139
  if (!Stream_EnsureRemainingCapacity(s, SURFCMD_SURFACE_BITS_HEADER_LENGTH))
301
0
    return FALSE;
302
303
139
  WINPR_ASSERT(cmd->cmdType <= UINT16_MAX);
304
139
  UINT16 cmdType = (UINT16)cmd->cmdType;
305
139
  switch (cmdType)
306
139
  {
307
94
    case CMDTYPE_SET_SURFACE_BITS:
308
139
    case CMDTYPE_STREAM_SURFACE_BITS:
309
139
      break;
310
0
    default:
311
0
    {
312
0
      const UINT16 defaultCmdType = CMDTYPE_STREAM_SURFACE_BITS;
313
0
      WLog_WARN(TAG,
314
0
                "SURFACE_BITS_COMMAND->cmdType 0x%04" PRIx16
315
0
                " not allowed, correcting to 0x%04" PRIx16,
316
0
                cmdType, defaultCmdType);
317
0
      cmdType = defaultCmdType;
318
0
    }
319
0
    break;
320
139
  }
321
322
139
  Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, cmdType));
323
139
  Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, cmd->destLeft));
324
139
  Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, cmd->destTop));
325
139
  Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, cmd->destRight));
326
139
  Stream_Write_UINT16(s, WINPR_ASSERTING_INT_CAST(uint16_t, cmd->destBottom));
327
139
  return update_write_surfcmd_bitmap_ex(s, &cmd->bmp);
328
139
}
329
330
BOOL update_write_surfcmd_frame_marker(wStream* s, UINT16 frameAction, UINT32 frameId)
331
869
{
332
869
  if (!Stream_EnsureRemainingCapacity(s, SURFCMD_FRAME_MARKER_LENGTH))
333
0
    return FALSE;
334
335
869
  Stream_Write_UINT16(s, CMDTYPE_FRAME_MARKER);
336
869
  Stream_Write_UINT16(s, frameAction);
337
869
  Stream_Write_UINT32(s, frameId);
338
869
  return TRUE;
339
869
}