[
https://issues.apache.org/jira/browse/GUACAMOLE-2301?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18097225#comment-18097225
]
Ciro Iriarte commented on GUACAMOLE-2301:
-----------------------------------------
Future enhancement — seeking input before implementation: in-band file transfer
over the serial console (XMODEM/YMODEM/ZMODEM).
Unlike SSH, a serial line is a single in-band stream with no side channel, so
file transfer has to ride the console using the classic protocols (sz/rz on
Linux; ZMODEM/XMODEM in many bootloaders and network-OS recovery modes). This
is a common need for firmware/image upload and config/log movement to boxes
reachable only by console.
Proposed first cut: ZMODEM as primary (YMODEM/XMODEM as fallbacks), invoking
lrzsz (sz/rz) as a subprocess (no license linkage) gated/degrading like the
RFC2217 libtelnet support; reuse the terminal's existing upload/download stream
plumbing (as SSH SFTP does); upload via the browser's drag-drop while the
device runs rz, and auto-detected ZMODEM download when the device runs sz;
disabled by default with a staging directory, size limits, filename
sanitization, and read-only enforcement.
Key questions for maintainers:
1. lrzsz-subprocess vs an embedded ZMODEM library — any preference or licensing
concern?
2. Is auto-detected ZMODEM download acceptable, or should downloads require an
explicit per-transfer opt-in?
3. Should this be serial-specific, or a shared terminal file-transfer facility
that telnet (also lacking SFTP) could reuse?
4. Is there appetite for this in-tree, or is it better left as an out-of-scope
add-on?
A full worked design (architecture, fd-multiplexing control flow, security,
phasing, lab test plan) is written up here:
https://github.com/ciroiriarte/guacamole-server/issues/37
This is independent of the serial protocol PRs already open for this ticket;
raising it here only to gather direction.
> Add serial console protocol support
> -----------------------------------
>
> Key: GUACAMOLE-2301
> URL: https://issues.apache.org/jira/browse/GUACAMOLE-2301
> Project: Guacamole
> Issue Type: New Feature
> Components: guacamole-client, guacamole-manual, guacd
> Reporter: Ciro Iriarte
> Priority: Major
> Attachments: qa-serial-client-send-break-dtr-rts-menu.png,
> qa-serial-color-scheme-white-black.png,
> qa-serial-connection-form-reverse-fields.png, qa-serial-connection-form.png,
> qa-serial-local-mode-juniper-console.png, qa-serial-report.md,
> qa-serial-reverse-and-telnet-evidence.md,
> qa-serial-reverse-mode-web-client.png,
> qa-serial-reverse-reconnect-typescript.txt,
> qa-serial-reverse-telnet-web-client.png, qa-serial-ser2net-raw.png,
> qa-serial-ser2net-rfc2217.png, qa-serial-telnet-transport-web-client.png
>
>
> Guacamole offers terminal protocols (SSH, Telnet) and, recently, IPMI
> Serial-over-LAN (GUACAMOLE-2300), but has no way to reach a plain *serial
> console* — the RS-232 console port of network switches, routers, firewalls,
> PDUs, and headless servers — which remains the primary out-of-band
> administration and disaster-recovery interface for that equipment.
> This proposes a new "serial" protocol module for guacd, with a matching
> connection form in guacamole-client and a chapter in guacamole-manual,
> mirroring the existing terminal protocols and reusing the shared terminal
> emulator (color schemes, fonts, scrollback, session recording, typescript,
> copy/paste).
> h3. Scope
> Two connection modes, selected by an explicit parameter:
> * *Local* — a serial device attached to the guacd host (e.g. /dev/ttyUSB0,
> /dev/serial/by-id/...), configured via termios: baud rate, data bits, parity,
> stop bits, and hardware/software flow control, with an optional server-side
> device allowlist.
> * *Network* — a serial port exposed over IP by ser2net
> (https://github.com/cminyard/ser2net), either as raw TCP or via RFC2217
> (Telnet COM-PORT-OPTION), the latter enabling negotiation of serial line
> settings and break signalling over the wire.
> h3. Notable features
> * Configurable *send-break* (break-duration) for password-recovery / ROMMON /
> U-Boot workflows, triggerable from the browser and via a client-agnostic
> control pipe.
> * *Paste pacing* (paste-delay) to avoid FIFO overrun when pasting
> configuration blocks at low baud without flow control.
> * Session recording / typescript for audit, read-only mode, and clipboard
> controls, inherited from the shared terminal.
> h3. Implementation status
> A working implementation exists across guacamole-server, guacamole-client,
> and guacamole-manual, building cleanly against apache/main; coordinated PRs
> to follow. USB/IP was evaluated and deliberately not integrated, as ser2net
> is the appropriate mechanism for remote serial access.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)