10 #define SET_PIXEL_FORMAT        0
 
  11 #define SET_ENCODINGS           2
 
  12 #define FB_UPDATE_REQUEST       3
 
  14 #define POINTER_EVENT           5
 
  15 #define CLIENT_CUT_TEXT         6
 
  17 #define RFB_BUF_SIZE    64
 
  33 struct server_init_message {
 
  36         struct pixel_format fmt;
 
  41 struct fb_update_req {
 
  57 struct key_event_pkt {
 
  64 struct pointer_event_pkt {
 
  71 struct text_event_pkt {
 
  78 struct update_header {
 
  98         char data[RFB_BUF_SIZE];
 
 102         char next_update_incremental;
 
 103         char update_requested;
 
 105         struct fb_update_req client_interest_area;
 
 114         uint32_t frame_bytes;
 
 117 static struct server_init_message server_info;
 
 119 static void init_server_info() {
 
 120         server_info.name_length = htonl(8);
 
 121         memcpy(server_info.name_string, "NetWatch", 8);
 
 124 static void update_server_info() {
 
 126                 outputf("RFB: setting fmt %d", fb->curmode.format);
 
 127                 server_info.fb_width = htons(fb->curmode.xres);
 
 128                 server_info.fb_height = htons(fb->curmode.yres);
 
 129                 switch (fb->curmode.format) {
 
 131                         server_info.fmt.bpp = 32;
 
 132                         server_info.fmt.depth = 24;
 
 133                         server_info.fmt.big_endian = 0;
 
 134                         server_info.fmt.true_color = 1;
 
 135                         server_info.fmt.red_max = htons(255);
 
 136                         server_info.fmt.green_max = htons(255);
 
 137                         server_info.fmt.blue_max = htons(255);
 
 138                         server_info.fmt.red_shift = 0;
 
 139                         server_info.fmt.green_shift = 8;
 
 140                         server_info.fmt.blue_shift = 16;
 
 143                         outputf("RFB: unknown fb fmt %d", fb->curmode.format);
 
 147                 outputf("RFB: fb null");
 
 151 static void send_fsm(struct tcp_pcb *pcb, struct rfb_state *state) {
 
 152         struct update_header hdr;
 
 156         switch (state->send_state) {
 
 159                 if (state->update_requested) {
 
 160                         outputf("RFB send: update requested");
 
 161                         state->update_requested = 0;
 
 162                         state->send_state = SST_NEEDS_UPDATE;
 
 167                 /* potential FALL THROUGH */
 
 169         case SST_NEEDS_UPDATE:
 
 170                 outputf("RFB send: sending header");
 
 172                 state->frame_bytes = fb->curmode.xres * fb->curmode.yres * fb->curmode.bytestride;
 
 174                 hdr.nrects = htons(1);
 
 177                 hdr.width = htons(fb->curmode.xres);
 
 178                 hdr.height = htons(fb->curmode.yres);
 
 179                 hdr.enctype = htonl(0);
 
 180                 tcp_write(pcb, &hdr, sizeof(hdr), TCP_WRITE_FLAG_COPY);
 
 182                 state->update_pos = 0;
 
 183                 state->send_state = SST_SENDING;
 
 190                         unsigned char mbuf[8192 /* XXX magic */];
 
 192                         left = state->frame_bytes - state->update_pos;
 
 195                                 state->send_state = SST_IDLE;
 
 202                         if (left > tcp_mss(pcb)) {
 
 203                                 sndlength = tcp_mss(pcb);
 
 208                         memcpy(mbuf, fb->fbaddr + state->update_pos, sndlength);        /* It's OK if it becomes smaller later. */
 
 211                                 err = tcp_write(pcb, mbuf, sndlength, TCP_WRITE_FLAG_COPY /* This is my memory on the stack, thank you very much. */);
 
 212                                 if (err == ERR_MEM) {
 
 213                                         outputf("RFB: ERR_MEM sending %d", sndlength);
 
 216                         } while (err == ERR_MEM && sndlength > 1);
 
 219                                 outputf("RFB: attempting send %d", sndlength);
 
 221                                 outputf("RFB: send error %d", err);
 
 225                         state->update_pos += sndlength;
 
 227                         if (tcp_sndbuf(pcb) == 0) {
 
 235         if (tcp_output(pcb) != ERR_OK)
 
 237                 outputf("RFB: tcp_output bailed in send_fsm?");
 
 241 static err_t rfb_sent(void *arg, struct tcp_pcb *pcb, uint16_t len) {
 
 242         struct rfb_state *state = arg;
 
 243         send_fsm(pcb, state);
 
 247 static void close_conn(struct tcp_pcb *pcb, struct rfb_state *state) {
 
 261 static enum fsm_result recv_fsm(struct tcp_pcb *pcb, struct rfb_state *state) {
 
 265         outputf("RFB FSM: st %d rp %d wp %d", state->state, state->readpos,
 
 268         switch(state->state) {
 
 270                 if (state->writepos < 12) return NEEDMORE;
 
 272                 if (!strncmp(state->data, "RFB 003.003\n", 12)) {
 
 274                 } else if (!strncmp(state->data, "RFB 003.005\n", 12)) {
 
 275                         /* Spec states that "RFB 003.005", an incorrect value,
 
 276                          * should be treated by the server as 3.3. */
 
 278                 } else if (!strncmp(state->data, "RFB 003.007\n", 12)) {
 
 280                 } else if (!strncmp(state->data, "RFB 003.008\n", 12)) {
 
 283                         outputf("RFB: Negotiation fail");
 
 287                 outputf("RFB: Negotiated v3.%d", state->version);
 
 289                 state->readpos += 12;
 
 290                 state->state = ST_CLIENTINIT;
 
 292                 /* We support one security type, currently "none".
 
 293                  * Send that and SecurityResult. */
 
 294                 if (state->version >= 7) {
 
 295                         tcp_write(pcb, "\x01\x01\x00\x00\x00\x00", 6, 0);
 
 297                         tcp_write(pcb, "\x01\x00\x00\x00\x00", 5, 0);
 
 305                 if (state->version >= 7) {
 
 306                         /* Ignore the security type and ClientInit */
 
 307                         if (state->writepos < 2) return NEEDMORE;
 
 310                         /* Just ClientInit */
 
 311                         if (state->writepos < 1) return NEEDMORE;
 
 315                 state->state = ST_MAIN;
 
 317                 outputf("RFB: Sending server info", state->version);
 
 318                 tcp_write(pcb, &server_info, sizeof(server_info), TCP_WRITE_FLAG_COPY);
 
 324                 if (state->writepos < 1) return NEEDMORE;
 
 326                 outputf("RFB: cmd %d", state->data[0]);
 
 327                 switch (state->data[0]) {
 
 329                 case SET_PIXEL_FORMAT:
 
 331                         if (state->writepos < (sizeof(struct pixel_format) + 4))
 
 333                         outputf("RFB: SetPixelFormat");
 
 335                         struct pixel_format * new_fmt =
 
 336                                 (struct pixel_format *)(&state->data[4]);
 
 340                         state->readpos += sizeof(struct pixel_format) + 4;
 
 344                         if (state->writepos < 4) return NEEDMORE;
 
 346                         struct set_encs_req * req = (struct set_encs_req *)state->data;
 
 348                         pktsize = sizeof(struct set_encs_req) + (4 * ntohs(req->num));
 
 350                         outputf("RFB: SetEncodings [%d]", ntohs(req->num));
 
 351                         if (state->writepos < pktsize) return NEEDMORE;
 
 353                         for (i = 0; i < ntohs(req->num); i++) {
 
 354                                 outputf("RFB: Encoding: %d", ntohl(req->encodings[i]));
 
 359                         state->readpos += pktsize;
 
 362                 case FB_UPDATE_REQUEST:
 
 363                         if (state->writepos < sizeof(struct fb_update_req))
 
 365                         outputf("RFB: UpdateRequest");
 
 367                         state->update_requested = 1;
 
 368                         memcpy(&state->client_interest_area, state->data,
 
 369                                sizeof(struct fb_update_req)); 
 
 371                         state->readpos += sizeof(struct fb_update_req);
 
 375                         if (state->writepos < sizeof(struct key_event_pkt))
 
 381                         state->readpos += sizeof(struct key_event_pkt);
 
 385                         if (state->writepos < sizeof(struct pointer_event_pkt))
 
 387                         outputf("RFB: Pointer");
 
 391                         state->readpos += sizeof(struct pointer_event_pkt);
 
 394                 case CLIENT_CUT_TEXT:
 
 395                         if (state->writepos < sizeof(struct text_event_pkt))
 
 397                         outputf("RFB: Cut Text");
 
 399                         struct text_event_pkt * pkt =
 
 400                                 (struct text_event_pkt *)state->data;
 
 402                         if (state->writepos < sizeof(struct text_event_pkt)
 
 408                         state->readpos += sizeof(struct text_event_pkt)
 
 413                         outputf("RFB: Bad command: %d", state->data[0]);
 
 416                 outputf("RFB: Bad state");
 
 421 static err_t rfb_recv(void *arg, struct tcp_pcb *pcb,
 
 422                       struct pbuf *p, err_t err) {
 
 423         struct rfb_state *state = arg;
 
 428                 outputf("RFB: recv err %d", err);
 
 429                 /* FIXME do something better here? */
 
 434                 outputf("RFB: Connection closed");
 
 435                 close_conn(pcb, state);
 
 439         if (p->tot_len > (RFB_BUF_SIZE - state->writepos)) {
 
 441                 outputf("RFB: Overflow!");
 
 442                 close_conn(pcb, state);
 
 446         outputf("RFB: Processing %d", p->tot_len);
 
 447         pbuf_copy_partial(p, state->data + state->writepos, p->tot_len, 0);
 
 448         state->writepos += p->tot_len;
 
 450         tcp_recved(pcb, p->tot_len);
 
 454                 switch (recv_fsm(pcb, state)) {
 
 456                         outputf("RFB FSM: blocking");
 
 461                         outputf("RFB FSM: ok");
 
 463                         /* Might as well send now... */
 
 464                         if (state->send_state == SST_IDLE
 
 465                             && state->update_requested) {
 
 466                                 send_fsm(pcb, state);
 
 469                         if (state->readpos == state->writepos) {
 
 475                                         state->data + state->readpos,
 
 476                                         state->writepos - state->readpos);
 
 481                         outputf("RFB: Protocol error");
 
 482                         close_conn(pcb, state);
 
 488 static err_t rfb_accept(void *arg, struct tcp_pcb *pcb, err_t err) {
 
 489         struct rfb_state *state;
 
 491         LWIP_UNUSED_ARG(arg);
 
 492         LWIP_UNUSED_ARG(err);
 
 494         state = (struct rfb_state *)mem_malloc(sizeof(struct rfb_state));
 
 496         state->state = ST_BEGIN;
 
 499         state->update_requested = 0;
 
 500         state->send_state = SST_IDLE;
 
 502         /* XXX: update_server_info() should be called from the 64ms timer, and deal
 
 503          * with screen resizes appropriately. */
 
 504         update_server_info();
 
 508                 outputf("rfb_accept: out of memory\n");
 
 513         tcp_recv(pcb, rfb_recv);
 
 514         tcp_sent(pcb, rfb_sent);
 
 516         tcp_err(pcb, rfb_err);
 
 517         tcp_poll(pcb, rfb_poll, 2);
 
 519         tcp_write(pcb, "RFB 003.008\n", 12, 0);
 
 531         tcp_bind(pcb, IP_ADDR_ANY, RFB_PORT);
 
 532         pcb = tcp_listen(pcb);
 
 533         tcp_accept(pcb, rfb_accept);