Merge pull request #7902 from dicemans/rdp-password-not-in-argv

[Security] Keep the Windows VM password out of the RDP client's argument list
This commit is contained in:
Erik Melton authored and GitHub committed 2026-09-15 18:08:10 +02:00
commit 6ea3215542
1 file changed
+25 -2
+25 -2
View File
@@ -1457,8 +1457,31 @@ To stop: omarchy-windows-vm stop"
fi
# If scale is less than 130%, don't set any scale (use default 100)
# Connect with RDP in fullscreen (auto-detects resolution)
xfreerdp3 /u:"$WIN_USER" /p:"$WIN_PASS" /v:127.0.0.1:3389 -grab-keyboard /sound /microphone /clipboard /cert:ignore /title:"Windows VM - Omarchy" /dynamic-resolution /gfx:AVC444 /floatbar:sticky:off,default:visible,show:fullscreen $RDP_SCALE
RDP_ARGS=(
"/u:$WIN_USER"
"/p:$WIN_PASS"
/v:127.0.0.1:3389
-grab-keyboard
/sound
/microphone
/clipboard
/cert:ignore
"/title:Windows VM - Omarchy"
/dynamic-resolution
/gfx:AVC444
/floatbar:sticky:off,default:visible,show:fullscreen
)
if [[ -n $RDP_SCALE ]]; then
RDP_ARGS+=("$RDP_SCALE")
fi
# Connect with RDP in fullscreen (auto-detects resolution). The arguments go
# in over stdin rather than on the command line: /proc/<pid>/cmdline is
# world-readable, so passing the VM password as /p:"$WIN_PASS" would show it
# to every other user on the machine for as long as the session is open.
# /args-from must stay the only argument here — FreeRDP rejects it outright
# when it is combined with any other, so new flags belong in RDP_ARGS above.
printf '%s\n' "${RDP_ARGS[@]}" | xfreerdp3 /args-from:stdin
# After RDP closes, stop the container unless --keep-alive was specified
if [[ $KEEP_ALIVE = "false" ]]; then