Apache-2.0 C11 RFB/VNC + RDP client that draws the remote desktop in a Kitty graphics terminal.
This is not Apple High Performance Screen Sharing (AHPSS). Classic VNC
Authentication proves password knowledge only — it is not session
encryption. See SECURITY.md.
nix run github:zw3rk/farsee -- --version
nix run github:zw3rk/farsee -- vnc://host.example:5900
nix run github:zw3rk/farsee -- rdp://user@host.examplePassword is never taken from argv or a URL. Use the TTY prompt (echo off) or
--password-fd N. Production rejects URL userinfo passwords.
Live graphics use the
Kitty graphics protocol
(KGP). Use --presenter null when the client must receive frames without
displaying them.
Terminals that implement KGP (per the protocol docs; feature depth varies):
| Terminal | Notes |
|---|---|
| Kitty | Reference implementation |
| Ghostty | |
| WezTerm | |
| Konsole | |
| Warp | |
| iTerm2 | |
| wayst | |
| st | With the KGP patch |
| xterm.js | Embeddable / web |
Farsee is developed and manually accepted primarily against Kitty. Other entries may work for basic placement; SHM transfer, APC drain timing, and cursor overlay can differ. Nested multiplexers (tmux, screen) often need passthrough configuration.
nix develop
make help
make test
make ciHermetic toolchain via the flake (flake.nix); all work goes through the
Makefile (make help).
| Target | What it does |
|---|---|
make help |
Full target catalogue |
make / make build |
Dev build (Clang, strict warnings) |
make test |
Build and run the unit suite |
make ci |
Full release-candidate gate |
make asan-ubsan |
Address + UBSan build and tests |
make release |
Optimized release binary |
make no-rdp-release-check |
Optimized release gates without FreeRDP |
make check-reproducible |
Reproduce and compare complete artifacts |
make coverage / make coverage-report |
Coverage build + report |
make fuzz-smoke |
Brief corpus run per fuzz target |
make check-license |
SPDX + third-party notices |
make clean |
Remove build outputs |
The build and test matrix supports macOS and Linux. Published release
artifacts are currently limited to aarch64-darwin and x86_64-darwin by
release/dependencies.json. Linux release packaging fails closed because its
runtime libraries are not approved by the locked release-license policy.
- Classic VNC (RFB 3.3/3.7/3.8): VNC Auth, Raw / CopyRect / ZRLE, Cursor, DesktopSize, input, clipboard, Bell
- Apple Screen Sharing: security types 33 and 36 are live. The default
policy prefers 33;
--apple-security=36requires 36. These features are present in the retained implementation but are not approved for release; see ADR-0013. - Apple encodings:
0x03f3supported type-0 image planes paint;0x0450decodes to a separate RGBA8 alpha cursor and composites into the copied presentation frame. - RDP via FreeRDP
- Live graphics need a KGP-capable terminal
No VNC TLS/VeNCrypt. The default Apple post-auth mode is the cleartext
compatibility path; protected records and the private Apple encoding list are
explicit options. Apple 0x0450 supports the profile-1000 cursor;
other profiles fail closed. Details:
docs/known-limitations.md.
| Doc | Role |
|---|---|
USAGE.md |
CLI, flags, runtime paths |
plan.md |
Controlling requirements |
docs/implementation-status.md |
Gate status |
SECURITY.md |
Secure-use guide |
THIRD_PARTY_NOTICES.md |
Dependencies & licenses |
Apache-2.0 — see LICENSE. Source and dependency rules are in
ADR-0001. ADR-0013 and docs/provenance.md record the
separate Apple feature release block.