Implements RFB (RFC 6143) directly against QTcpSocket. No permissively licensed VNC client library exists to vendor the way FreeRDP was for RDP: LibVNCClient is GPLv2, gtk-vnc is LGPL but GTK-tied, and vendoring either would force a licensing decision on the whole (MIT) project. This is from-scratch protocol code instead, threaded like SshSessionBackend (a QObject on its own QThread driven by Qt's own async socket signals) rather than RdpSessionBackend's manual worker-thread/blocking-loop pattern, since QTcpSocket is already async. Scope, matching SessionTab's existing SSH/RDP dispatch pattern (session_backend_factory.cpp, session_tab.cpp's widget construction and signal wiring) and VncDisplayWidget mirroring RdpDisplayWidget's scale-to-fit rendering: - Protocol handshake: RFB 3.3/3.7/3.8 negotiated explicitly (the SecurityResult message only exists in 3.8; pre-3.8 servers signal auth failure by closing the socket, which the disconnect handler accounts for) - VNC Authentication (DES challenge-response, via OpenSSL's classic DES API) and no-auth security types - Raw + CopyRect framebuffer decoding into a persistent QImage, requesting a fixed 32bpp format whose byte layout matches QImage::Format_RGB32 directly (same zero-conversion trick RdpSessionBackend uses for FreeRDP's GDI buffer) - Keyboard (Qt key -> X11 keysym, including the Unicode-beyond-Latin-1 keysym convention) and mouse/wheel input forwarding Explicit non-goals for this pass (see docs/PROGRESS.md for the full list): Apple's Screen Sharing auth (so this can't yet reach macOS's built-in VNC server), compression encodings beyond Raw/CopyRect, dynamic resize, remote cursor shape sync, clipboard sync. 19 unit tests (tests/test_vnc_session_backend.cpp): pure-function coverage (DES key prep verified against an independently documented test vector for password "COW", X11 keysym mapping, socket-error mapping) plus state-machine coverage against a scripted in-process fake RFB server covering all three protocol-version handshake shapes, auth success/ failure, unsupported security types, and pixel-accurate Raw decoding. That harness caught a real re-entrancy bug: QAbstractSocket::abort() synchronously re-emits disconnected() before returning, so failConnection() calling it was silently letting a second, generic disconnected-socket handler overwrite an already-correct, specific error message. Also verified live against a real, independently implemented VNC server (TightVNC on Windows): connect with VNC Authentication, correct framebuffer dimensions and pixel data, clean disconnect, reconnect. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
OrbitHub
OrbitHub is a cross-platform native desktop app for managing and launching remote sessions from one place.
It is implemented in C++17 with Qt6 Widgets and built with CMake.
Supported target platforms:
- Windows
- Linux
- macOS
Current Status
OrbitHub is in active development.
- Milestones completed: M0-M9
- Current milestone: Milestone 10 (v1.0 Stabilization)
- Latest checkpoint tag:
v2026.9.15 - VNC (M6) covers standard VNC Authentication and no-auth servers; see docs/PROGRESS.md for known gaps (Apple Screen Sharing auth, compression encodings, resize, cursor sync, clipboard)
Progress and milestone details:
Latest release (installers for Windows, Linux, and macOS):
User Guide:
- docs/USER_GUIDE.md (also available as a PDF attached to each release, and in-app via
Help -> User Guide)
Screenshots
Profiles organized into folders, with protocol, host, and tags shown at a glance. (Sample data shown; not real hosts.)
An interactive SSH terminal session in a tab, with the event log below.
An embedded RDP session in a tab.
Implemented Features
Profile Management
- SQLite-backed profile storage
- Create, edit, delete profiles
- Protocol-aware profile validation (SSH/RDP/VNC)
- Profile search and sorting
- Tags support
- Folder/subfolder support
ListandFoldersprofile views- Right-click profile tree actions:
- New Folder
- New Connection
- Drag-and-drop profile moves between folders with persistence
Session Experience
- Multi-tab session window
- Auto-connect on tab open
- Disconnect on tab close
- Session state indicators on tabs
- Timestamped event log with filtering and export
SSH
- Embedded interactive terminal (in-app typing)
- Theme support (
Dark,Light,Solarized Dark) - Password and private-key auth flows
- Known-hosts policy support
RDP
- Embedded in-window RDP rendering surface (no external launcher)
- Keyboard/mouse input forwarding
- Resize handling and resolution renegotiation
- Domain-aware authentication support
- RDP security/performance profile options
App UX
- App icon and themed About dialog
Filemenu:- New Profile
- New Folder
- Quit
Helpmenu:- About OrbitHub
Build and Run
Detailed platform instructions:
Quick start (Linux/macOS with Ninja):
cmake -S . -B build -G Ninja
cmake --build build
./build/orbithub
Packaging
Detailed packaging instructions for all platforms:
Linux (.deb):
./packaging/linux/build-deb.sh
Linux (Flatpak):
./packaging/flatpak/build-flatpak.sh
Windows (Inno Setup installer):
.\packaging\windows\build-installer.ps1
macOS (.dmg):
./packaging/macos/build-dmg.sh
Dependencies
Core dependencies:
- Qt 6 (Widgets, SQL)
- CMake 3.21+
- C++17 toolchain
Protocol/runtime dependencies:
- SSH client (
ssh) available onPATHfor SSH sessions
Bundled/vendored third-party components:
- KodoTerm
- libvterm
- FreeRDP/WinPR
Licensing
Project license:
- MIT (see LICENSE)
License links:
- MIT License: https://opensource.org/licenses/MIT
- GNU LGPLv3: https://www.gnu.org/licenses/lgpl-3.0.html
- Apache License 2.0: https://www.apache.org/licenses/LICENSE-2.0
Important third-party license notes:
- Qt6 is dynamically linked in this project build setup.
- Qt6 is used under LGPLv3 terms in this project build setup.
- KodoTerm and libvterm are MIT-licensed.
- FreeRDP/WinPR is Apache-2.0 licensed.
Repository license files:
- Project: LICENSE
- KodoTerm: third_party/KodoTerm/LICENSE
- FreeRDP: third_party/FreeRDP/LICENSE
See in-app Help -> About OrbitHub for license links and third-party inventory.
Repository Structure
src/- application source codedocs/- build guide, spec, and progress trackingthird_party/- vendored third-party dependenciesbuild/- local build output (generated)
Notes
- Passwords are requested at connect time and are not stored in the profile database.
- VNC support covers standard VNC Authentication and no-auth servers (e.g. TigerVNC, x11vnc, TightVNC); it doesn't yet reach macOS's built-in Screen Sharing server, which uses a different authentication scheme (see docs/PROGRESS.md, Milestone 6).


