JetKVM - Control any computer remotely
kvm
Go to file
Alex P 821675cd21 security: fix critical race conditions and add validation to session management
This commit addresses multiple CRITICAL and HIGH severity security issues
identified during the multi-session implementation review.

CRITICAL Fixes:
- Fix race condition in session approval handlers (jsonrpc.go)
  Previously approveNewSession and denyNewSession directly mutated
  session.Mode without holding the SessionManager.mu lock, potentially
  causing data corruption during concurrent access.

- Add validation to ApprovePrimaryRequest (session_manager.go:795-810)
  Now verifies that requester session exists and is in Queued mode
  before approving transfer, preventing invalid state transitions.

- Close dual-primary window during reconnection (session_manager.go:208)
  Added explicit primaryExists check to prevent brief window where two
  sessions could both be primary during reconnection.

HIGH Priority Fixes:
- Add nickname uniqueness validation (session_manager.go:152-159)
  Prevents multiple sessions from having the same nickname, both in
  AddSession and updateSessionNickname RPC handler.

Code Quality:
- Remove debug scaffolding from cloud.go (lines 515-520, 530)
  Cleaned up temporary debug logs that are no longer needed.

Thread Safety:
- Add centralized ApproveSession() method (session_manager.go:870-890)
- Add centralized DenySession() method (session_manager.go:894-912)
  Both methods properly acquire locks and validate session state.

- Update RPC handlers to use thread-safe methods
  approveNewSession and denyNewSession now call sessionManager methods
  instead of direct session mutation.

All changes have been verified with linters (golangci-lint: 0 issues).
2025-10-10 20:04:44 +03:00
.devcontainer Remove the temporary directory after extracting buildkit (#874) 2025-10-07 11:57:26 +02:00
.github build(deps): bump actions/setup-go from 5 to 6 (#848) 2025-10-01 21:35:35 +02:00
.vscode feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
bin Release 202412292127 2024-12-29 21:27:42 +01:00
cmd feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
internal Merge branch 'dev' into feat/multisession-support 2025-10-10 00:23:50 +03:00
resource feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
scripts feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
ui Merge branch 'dev' into feat/multisession-support 2025-10-10 00:23:50 +03:00
.gitignore feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
.golangci.yml feat: add command to show version (#604) 2025-07-11 11:32:46 +02:00
CODE_OF_CONDUCT.md Release 202412292127 2024-12-29 21:27:42 +01:00
DEVELOPMENT.md docs: debugging UI builds because of ui symlink (#873) 2025-10-04 12:05:14 +02:00
Dockerfile.build feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
LICENSE Release 202412292127 2024-12-29 21:27:42 +01:00
Makefile feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
README.md docs: add comprehensive DEVELOPMENT.md for JetKVM (#692) 2025-07-16 00:04:41 +02:00
block_device.go chore/Deprecate browser mount (#752) 2025-08-28 23:46:55 +02:00
block_device_linux.go network enhanecment / refactor (#361) 2025-04-16 01:39:23 +02:00
block_device_notlinux.go network enhanecment / refactor (#361) 2025-04-16 01:39:23 +02:00
cloud.go security: fix critical race conditions and add validation to session management 2025-10-10 20:04:44 +03:00
config.go Merge branch 'dev' into feat/multisession-support 2025-10-10 00:23:50 +03:00
datachannel_helpers.go fix: resolve all Go and TypeScript linting issues 2025-10-08 20:15:45 +03:00
dc_metrics.go feat(metrics): adding prometheus metrics for dc power extension (#556) 2025-07-11 17:04:41 +02:00
dev_deploy.sh feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
display.go feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
errors.go fix: resolve all Go and TypeScript linting issues 2025-10-08 20:15:45 +03:00
go.mod chore: downgrade gin to v1.10.1 (#869) 2025-10-03 08:48:51 +02:00
go.sum chore: downgrade gin to v1.10.1 (#869) 2025-10-03 08:48:51 +02:00
hidrpc.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
hw.go network enhanecment / refactor (#361) 2025-04-16 01:39:23 +02:00
jiggler.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
jsonrpc.go security: fix critical race conditions and add validation to session management 2025-10-10 20:04:44 +03:00
log.go feat: hid rpc channel (#755) 2025-09-04 22:27:56 +02:00
main.go [WIP] Bugfixes: session promotion 2025-10-10 10:16:21 +03:00
mdns.go feat: Adds IPv6 disabling feature (#803) 2025-09-16 12:44:56 +02:00
native.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
network.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
ota.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
prometheus.go chore: Enable more linters 2025-03-26 18:41:09 +01:00
publish_source.sh fix: Shell linting (#328) 2025-04-11 00:43:45 +02:00
serial.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
session_manager.go security: fix critical race conditions and add validation to session management 2025-10-10 20:04:44 +03:00
session_permissions.go fix: resolve all Go and TypeScript linting issues 2025-10-08 20:15:45 +03:00
terminal.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
timesync.go network enhanecment / refactor (#361) 2025-04-16 01:39:23 +02:00
usb.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
usb_mass_storage.go chore/Deprecate browser mount (#752) 2025-08-28 23:46:55 +02:00
version.go feat: jetkvm native in cGo 2025-09-29 14:09:30 +02:00
video.go Merge branch 'dev' into feat/multisession-support 2025-10-10 00:23:50 +03:00
web.go fix: handle intentional logout to trigger immediate observer promotion 2025-10-09 12:56:57 +03:00
web_tls.go feat: multi-session support with role-based permissions 2025-10-08 18:52:45 +03:00
webrtc.go fix: correct grace period protection during primary reconnection 2025-10-10 19:33:49 +03:00
wol.go Add ability to track modifier state on the device (#725) 2025-08-26 17:09:35 +02:00

README.md

JetKVM is a high-performance, open-source KVM over IP (Keyboard, Video, Mouse) solution designed for efficient remote management of computers, servers, and workstations. Whether you're dealing with boot failures, installing a new operating system, adjusting BIOS settings, or simply taking control of a machine from afar, JetKVM provides the tools to get it done effectively.

Features

  • Ultra-low Latency - 1080p@60FPS video with 30-60ms latency using H.264 encoding. Smooth mouse and keyboard interaction for responsive remote control.
  • Free & Optional Remote Access - Remote management via JetKVM Cloud using WebRTC.
  • Open-source software - Written in Golang on Linux. Easily customizable through SSH access to the JetKVM device.

Contributing

We welcome contributions from the community! Whether it's improving the firmware, adding new features, or enhancing documentation, your input is valuable. We also have some rules and taboos here, so please read this page and our Code of Conduct carefully.

I need help

The best place to search for answers is our Documentation. If you can't find the answer there, check our Discord Server.

I want to report an issue

If you've found an issue and want to report it, please check our Issues page. Make sure the description contains information about the firmware version you're using, your platform, and a clear explanation of the steps to reproduce the issue.

Development

JetKVM is written in Go & TypeScript. with some bits and pieces written in C. An intermediate level of Go & TypeScript knowledge is recommended for comfortable programming.

The project contains two main parts, the backend software that runs on the KVM device and the frontend software that is served by the KVM device, and also the cloud.

For comprehensive development information, including setup, testing, debugging, and contribution guidelines, see DEVELOPMENT.md.

For quick device development, use the ./dev_deploy.sh script. It will build the frontend and backend and deploy them to the local KVM device. Run ./dev_deploy.sh --help for more information.

Backend

The backend is written in Go and is responsible for the KVM device management, the cloud API and the cloud web.

Frontend

The frontend is written in React and TypeScript and is served by the KVM device. It has three build targets: device, development and production. Development is used for development of the cloud version on your local machine, device is used for building the frontend for the KVM device and production is used for building the frontend for the cloud.