diff options
| author | Gerd Hoffmann <kraxel@redhat.com> | 2014-10-02 12:09:34 +0200 |
|---|---|---|
| committer | Gerd Hoffmann <kraxel@redhat.com> | 2015-01-22 11:18:47 +0100 |
| commit | e5f34cdd2da54f28d90889a3afd15fad2d6105ff (patch) | |
| tree | b4bb4eafa06d5c95b7d8413f49e1d18bd4ab4185 /ui/vnc.h | |
| parent | 86fdcf23f4a9d8473844734907555b3a93ed686c (diff) | |
| download | focaccia-qemu-e5f34cdd2da54f28d90889a3afd15fad2d6105ff.tar.gz focaccia-qemu-e5f34cdd2da54f28d90889a3afd15fad2d6105ff.zip | |
vnc: track & limit connections
Also track the number of connections in "connecting" and "shared" state (in addition to the "exclusive" state). Apply a configurable limit to these connections. The logic to apply the limit to connections in "shared" state is pretty simple: When the limit is reached no new connections are allowed. The logic to apply the limit to connections in "connecting" state (this is the state you are in *before* successful authentication) is slightly different: A new connect kicks out the oldest client which is still in "connecting" state. This avoids a easy DoS by unauthenticated users by simply opening connections until the limit is reached. Cc: Dr. David Alan Gilbert <dgilbert@redhat.com> Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Diffstat (limited to 'ui/vnc.h')
| -rw-r--r-- | ui/vnc.h | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/ui/vnc.h b/ui/vnc.h index 6fe8278126..5e2b1a561e 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -150,7 +150,10 @@ typedef enum VncSharePolicy { struct VncDisplay { QTAILQ_HEAD(, VncState) clients; + int num_connecting; + int num_shared; int num_exclusive; + int connections_limit; VncSharePolicy share_policy; int lsock; #ifdef CONFIG_VNC_WS |