Files
orbithub/tests/CMakeLists.txt
T
ksmithandClaude Sonnet 5 1f026dde70 Add Apple Screen Sharing authentication for VNC (security type 30)
Apple's macOS Screen Sharing server doesn't speak standard VNC
Authentication -- it uses a Diffie-Hellman key exchange followed by
AES-128-ECB-encrypted credentials, security type 30. Apple never
published this scheme (it's not part of RFC 6143); this implements
the well-established reverse-engineered wire format: the server sends
a generator, prime, and its own DH public key; the client generates
an ephemeral keypair, derives the shared secret, MD5-hashes it into
an AES key, and sends back its public key plus a 128-byte encrypted
username+password buffer.

The DH/AES math lives in new src/vnc_apple_dh_auth.h/.cpp as a pure,
socket-free helper (mirroring vncAuthResponse()'s shape for standard
VNC Auth), built entirely on modern EVP_PKEY-based OpenSSL 3.0 APIs --
no deprecated low-level DH_* calls, unlike VNC Authentication's
necessary use of classic DES. Reuses Profile::username (already a
shared field) since Apple's scheme needs an actual macOS account name,
unlike password-only VNC Authentication.

Security-type preference when multiple are offered is now None >
AppleDH > VNCAuth, since DH+AES is strictly stronger than static-
challenge DES. Adds a DH round-trip test (generates a real 512-bit
group at test time, computes the response, then independently
re-derives the shared secret as the server would and decrypts the
credentials back out -- proving self-consistency without needing a
hand-computed expected value), a fake-server integration test for the
full RFB 3.8 handshake sequencing, and a preference-order test.

Not yet live-verified against a real macOS Screen Sharing server --
that's next.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 21:27:17 -06:00

64 lines
2.8 KiB
CMake

add_executable(test_profile_repository
test_profile_repository.cpp
${CMAKE_SOURCE_DIR}/src/profile_repository.cpp
)
target_include_directories(test_profile_repository PRIVATE ${CMAKE_SOURCE_DIR}/src)
target_link_libraries(test_profile_repository PRIVATE Qt6::Core Qt6::Sql Qt6::Test)
add_test(NAME test_profile_repository COMMAND test_profile_repository)
add_executable(test_mremoteng_importer
test_mremoteng_importer.cpp
${CMAKE_SOURCE_DIR}/src/mremoteng_importer.cpp
)
target_include_directories(test_mremoteng_importer PRIVATE ${CMAKE_SOURCE_DIR}/src)
target_link_libraries(test_mremoteng_importer PRIVATE Qt6::Core Qt6::Test)
add_test(NAME test_mremoteng_importer COMMAND test_mremoteng_importer)
add_executable(test_ssh_session_backend
test_ssh_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/ssh_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/session_backend.h
)
target_include_directories(test_ssh_session_backend PRIVATE ${CMAKE_SOURCE_DIR}/src)
target_link_libraries(test_ssh_session_backend PRIVATE Qt6::Core Qt6::Gui Qt6::Test)
target_compile_definitions(test_ssh_session_backend PRIVATE
ORBITHUB_TEST_FIXTURES_DIR="${CMAKE_CURRENT_SOURCE_DIR}/fixtures"
)
add_test(NAME test_ssh_session_backend COMMAND test_ssh_session_backend)
add_executable(test_vnc_session_backend
test_vnc_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/vnc_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/vnc_pixel_codecs.cpp
${CMAKE_SOURCE_DIR}/src/vnc_apple_dh_auth.cpp
${CMAKE_SOURCE_DIR}/src/session_backend.h
)
target_include_directories(test_vnc_session_backend PRIVATE ${CMAKE_SOURCE_DIR}/src)
target_link_libraries(test_vnc_session_backend PRIVATE
Qt6::Core Qt6::Gui Qt6::Network Qt6::Test OpenSSL::Crypto ZLIB::ZLIB JPEG::JPEG
)
add_test(NAME test_vnc_session_backend COMMAND test_vnc_session_backend)
if(TARGET freerdp AND TARGET winpr)
add_executable(test_rdp_session_backend
test_rdp_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/rdp_session_backend.cpp
${CMAKE_SOURCE_DIR}/src/session_backend.h
)
target_include_directories(test_rdp_session_backend PRIVATE
${CMAKE_SOURCE_DIR}/src
${CMAKE_SOURCE_DIR}/third_party/FreeRDP/include
${CMAKE_SOURCE_DIR}/third_party/FreeRDP/winpr/include
${CMAKE_BINARY_DIR}/third_party/FreeRDP/include
${CMAKE_BINARY_DIR}/third_party/FreeRDP/winpr/include
)
target_compile_definitions(test_rdp_session_backend PRIVATE ORBITHUB_HAS_FREERDP)
target_link_libraries(test_rdp_session_backend PRIVATE Qt6::Core Qt6::Gui Qt6::Test freerdp winpr)
if(TARGET freerdp-client)
target_link_libraries(test_rdp_session_backend PRIVATE freerdp-client)
endif()
add_test(NAME test_rdp_session_backend COMMAND test_rdp_session_backend)
else()
message(STATUS "FreeRDP targets not available -- skipping test_rdp_session_backend")
endif()