LoopbackUtil.cs 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Linq;
  4. using System.Runtime.InteropServices;
  5. using System.Text;
  6. using System.Threading.Tasks;
  7. namespace MediaBrowser.ServerApplication.Native
  8. {
  9. /// <summary>
  10. /// http://blogs.msdn.com/b/fiddler/archive/2011/12/10/fiddler-windows-8-apps-enable-LoopUtil-network-isolation-exemption.aspx
  11. /// </summary>
  12. public class LoopUtil
  13. {
  14. //http://msdn.microsoft.com/en-us/library/windows/desktop/aa379595(v=vs.85).aspx
  15. [StructLayout(LayoutKind.Sequential)]
  16. internal struct SID_AND_ATTRIBUTES
  17. {
  18. public IntPtr Sid;
  19. public uint Attributes;
  20. }
  21. [StructLayoutAttribute(LayoutKind.Sequential)]
  22. internal struct INET_FIREWALL_AC_CAPABILITIES
  23. {
  24. public uint count;
  25. public IntPtr capabilities; //SID_AND_ATTRIBUTES
  26. }
  27. [StructLayoutAttribute(LayoutKind.Sequential)]
  28. internal struct INET_FIREWALL_AC_BINARIES
  29. {
  30. public uint count;
  31. public IntPtr binaries;
  32. }
  33. [StructLayoutAttribute(LayoutKind.Sequential)]
  34. internal struct INET_FIREWALL_APP_CONTAINER
  35. {
  36. internal IntPtr appContainerSid;
  37. internal IntPtr userSid;
  38. [MarshalAs(UnmanagedType.LPWStr)]
  39. public string appContainerName;
  40. [MarshalAs(UnmanagedType.LPWStr)]
  41. public string displayName;
  42. [MarshalAs(UnmanagedType.LPWStr)]
  43. public string description;
  44. internal INET_FIREWALL_AC_CAPABILITIES capabilities;
  45. internal INET_FIREWALL_AC_BINARIES binaries;
  46. [MarshalAs(UnmanagedType.LPWStr)]
  47. public string workingDirectory;
  48. [MarshalAs(UnmanagedType.LPWStr)]
  49. public string packageFullName;
  50. }
  51. // Call this API to free the memory returned by the Enumeration API
  52. [DllImport("FirewallAPI.dll")]
  53. internal static extern void NetworkIsolationFreeAppContainers(IntPtr pACs);
  54. // Call this API to load the current list of LoopUtil-enabled AppContainers
  55. [DllImport("FirewallAPI.dll")]
  56. internal static extern uint NetworkIsolationGetAppContainerConfig(out uint pdwCntACs, out IntPtr appContainerSids);
  57. // Call this API to set the LoopUtil-exemption list
  58. [DllImport("FirewallAPI.dll")]
  59. private static extern uint NetworkIsolationSetAppContainerConfig(uint pdwCntACs, SID_AND_ATTRIBUTES[] appContainerSids);
  60. // Use this API to convert a string SID into an actual SID
  61. [DllImport("advapi32.dll", SetLastError = true)]
  62. internal static extern bool ConvertStringSidToSid(string strSid, out IntPtr pSid);
  63. [DllImport("advapi32", CharSet = CharSet.Auto, SetLastError = true)]
  64. static extern bool ConvertSidToStringSid(
  65. [MarshalAs(UnmanagedType.LPArray)] byte[] pSID,
  66. out IntPtr ptrSid);
  67. [DllImport("advapi32", CharSet = CharSet.Auto, SetLastError = true)]
  68. static extern bool ConvertSidToStringSid(IntPtr pSid, out string strSid);
  69. // Use this API to convert a string reference (e.g. "@{blah.pri?ms-resource://whatever}") into a plain string
  70. [DllImport("shlwapi.dll", CharSet = CharSet.Unicode, ExactSpelling = true)]
  71. internal static extern int SHLoadIndirectString(string pszSource, StringBuilder pszOutBuf);
  72. // Call this API to enumerate all of the AppContainers on the system
  73. [DllImport("FirewallAPI.dll")]
  74. internal static extern uint NetworkIsolationEnumAppContainers(uint Flags, out uint pdwCntPublicACs, out IntPtr ppACs);
  75. // DWORD NetworkIsolationEnumAppContainers(
  76. // _In_ DWORD Flags,
  77. // _Out_ DWORD *pdwNumPublicAppCs,
  78. // _Out_ PINET_FIREWALL_APP_CONTAINER *ppPublicAppCs
  79. //);
  80. //http://msdn.microsoft.com/en-gb/library/windows/desktop/hh968116.aspx
  81. enum NETISO_FLAG
  82. {
  83. NETISO_FLAG_FORCE_COMPUTE_BINARIES = 0x1,
  84. NETISO_FLAG_MAX = 0x2
  85. }
  86. public class AppContainer
  87. {
  88. public String appContainerName { get; set; }
  89. public String displayName { get; set; }
  90. public String workingDirectory { get; set; }
  91. public String StringSid { get; set; }
  92. public List<uint> capabilities { get; set; }
  93. public bool LoopUtil { get; set; }
  94. public AppContainer(String _appContainerName, String _displayName, String _workingDirectory, IntPtr _sid)
  95. {
  96. this.appContainerName = _appContainerName;
  97. this.displayName = _displayName;
  98. this.workingDirectory = _workingDirectory;
  99. String tempSid;
  100. ConvertSidToStringSid(_sid, out tempSid);
  101. this.StringSid = tempSid;
  102. }
  103. }
  104. internal List<LoopUtil.INET_FIREWALL_APP_CONTAINER> _AppList;
  105. internal List<LoopUtil.SID_AND_ATTRIBUTES> _AppListConfig;
  106. public List<AppContainer> Apps = new List<AppContainer>();
  107. internal IntPtr _pACs;
  108. public LoopUtil()
  109. {
  110. LoadApps();
  111. }
  112. public void LoadApps()
  113. {
  114. Apps.Clear();
  115. _pACs = IntPtr.Zero;
  116. //Full List of Apps
  117. _AppList = PI_NetworkIsolationEnumAppContainers();
  118. //List of Apps that have LoopUtil enabled.
  119. _AppListConfig = PI_NetworkIsolationGetAppContainerConfig();
  120. foreach (var PI_app in _AppList)
  121. {
  122. AppContainer app = new AppContainer(PI_app.appContainerName, PI_app.displayName, PI_app.workingDirectory, PI_app.appContainerSid);
  123. var app_capabilities = LoopUtil.getCapabilites(PI_app.capabilities);
  124. if (app_capabilities.Count > 0)
  125. {
  126. //var sid = new SecurityIdentifier(app_capabilities[0], 0);
  127. IntPtr arrayValue = IntPtr.Zero;
  128. //var b = LoopUtil.ConvertStringSidToSid(app_capabilities[0].Sid, out arrayValue);
  129. //string mysid;
  130. //var b = LoopUtil.ConvertSidToStringSid(app_capabilities[0].Sid, out mysid);
  131. }
  132. app.LoopUtil = CheckLoopback(PI_app.appContainerSid);
  133. Apps.Add(app);
  134. }
  135. }
  136. private bool CheckLoopback(IntPtr intPtr)
  137. {
  138. foreach (SID_AND_ATTRIBUTES item in _AppListConfig)
  139. {
  140. string left, right;
  141. ConvertSidToStringSid(item.Sid, out left);
  142. ConvertSidToStringSid(intPtr, out right);
  143. if (left == right)
  144. {
  145. return true;
  146. }
  147. }
  148. return false;
  149. }
  150. private bool CreateExcemptions(string appName)
  151. {
  152. var hasChanges = false;
  153. foreach (var app in Apps)
  154. {
  155. if ((app.appContainerName ?? string.Empty).IndexOf(appName, StringComparison.OrdinalIgnoreCase) != -1 ||
  156. (app.displayName ?? string.Empty).IndexOf(appName, StringComparison.OrdinalIgnoreCase) != -1)
  157. {
  158. if (!app.LoopUtil)
  159. {
  160. app.LoopUtil = true;
  161. hasChanges = true;
  162. }
  163. }
  164. }
  165. return hasChanges;
  166. }
  167. public static void Run(string appName)
  168. {
  169. var util = new LoopUtil();
  170. util.LoadApps();
  171. var hasChanges = util.CreateExcemptions(appName);
  172. if (hasChanges)
  173. {
  174. util.SaveLoopbackState();
  175. }
  176. util.SaveLoopbackState();
  177. }
  178. private static List<SID_AND_ATTRIBUTES> getCapabilites(INET_FIREWALL_AC_CAPABILITIES cap)
  179. {
  180. List<SID_AND_ATTRIBUTES> mycap = new List<SID_AND_ATTRIBUTES>();
  181. IntPtr arrayValue = cap.capabilities;
  182. var structSize = Marshal.SizeOf(typeof(SID_AND_ATTRIBUTES));
  183. for (var i = 0; i < cap.count; i++)
  184. {
  185. var cur = (SID_AND_ATTRIBUTES)Marshal.PtrToStructure(arrayValue, typeof(SID_AND_ATTRIBUTES));
  186. mycap.Add(cur);
  187. arrayValue = new IntPtr((long)(arrayValue) + (long)(structSize));
  188. }
  189. return mycap;
  190. }
  191. private static List<SID_AND_ATTRIBUTES> getContainerSID(INET_FIREWALL_AC_CAPABILITIES cap)
  192. {
  193. List<SID_AND_ATTRIBUTES> mycap = new List<SID_AND_ATTRIBUTES>();
  194. IntPtr arrayValue = cap.capabilities;
  195. var structSize = Marshal.SizeOf(typeof(SID_AND_ATTRIBUTES));
  196. for (var i = 0; i < cap.count; i++)
  197. {
  198. var cur = (SID_AND_ATTRIBUTES)Marshal.PtrToStructure(arrayValue, typeof(SID_AND_ATTRIBUTES));
  199. mycap.Add(cur);
  200. arrayValue = new IntPtr((long)(arrayValue) + (long)(structSize));
  201. }
  202. return mycap;
  203. }
  204. private static List<SID_AND_ATTRIBUTES> PI_NetworkIsolationGetAppContainerConfig()
  205. {
  206. IntPtr arrayValue = IntPtr.Zero;
  207. uint size = 0;
  208. var list = new List<SID_AND_ATTRIBUTES>();
  209. // Pin down variables
  210. GCHandle handle_pdwCntPublicACs = GCHandle.Alloc(size, GCHandleType.Pinned);
  211. GCHandle handle_ppACs = GCHandle.Alloc(arrayValue, GCHandleType.Pinned);
  212. uint retval = NetworkIsolationGetAppContainerConfig(out size, out arrayValue);
  213. var structSize = Marshal.SizeOf(typeof(SID_AND_ATTRIBUTES));
  214. for (var i = 0; i < size; i++)
  215. {
  216. var cur = (SID_AND_ATTRIBUTES)Marshal.PtrToStructure(arrayValue, typeof(SID_AND_ATTRIBUTES));
  217. list.Add(cur);
  218. arrayValue = new IntPtr((long)(arrayValue) + (long)(structSize));
  219. }
  220. //release pinned variables.
  221. handle_pdwCntPublicACs.Free();
  222. handle_ppACs.Free();
  223. return list;
  224. }
  225. private List<INET_FIREWALL_APP_CONTAINER> PI_NetworkIsolationEnumAppContainers()
  226. {
  227. IntPtr arrayValue = IntPtr.Zero;
  228. uint size = 0;
  229. var list = new List<INET_FIREWALL_APP_CONTAINER>();
  230. // Pin down variables
  231. GCHandle handle_pdwCntPublicACs = GCHandle.Alloc(size, GCHandleType.Pinned);
  232. GCHandle handle_ppACs = GCHandle.Alloc(arrayValue, GCHandleType.Pinned);
  233. //uint retval2 = NetworkIsolationGetAppContainerConfig( out size, out arrayValue);
  234. uint retval = NetworkIsolationEnumAppContainers((Int32)NETISO_FLAG.NETISO_FLAG_MAX, out size, out arrayValue);
  235. _pACs = arrayValue; //store the pointer so it can be freed when we close the form
  236. var structSize = Marshal.SizeOf(typeof(INET_FIREWALL_APP_CONTAINER));
  237. for (var i = 0; i < size; i++)
  238. {
  239. var cur = (INET_FIREWALL_APP_CONTAINER)Marshal.PtrToStructure(arrayValue, typeof(INET_FIREWALL_APP_CONTAINER));
  240. list.Add(cur);
  241. arrayValue = new IntPtr((long)(arrayValue) + (long)(structSize));
  242. }
  243. //release pinned variables.
  244. handle_pdwCntPublicACs.Free();
  245. handle_ppACs.Free();
  246. return list;
  247. }
  248. public bool SaveLoopbackState()
  249. {
  250. var countEnabled = CountEnabledLoopUtil();
  251. SID_AND_ATTRIBUTES[] arr = new SID_AND_ATTRIBUTES[countEnabled];
  252. int count = 0;
  253. for (int i = 0; i < Apps.Count; i++)
  254. {
  255. if (Apps[i].LoopUtil)
  256. {
  257. arr[count].Attributes = 0;
  258. //TO DO:
  259. IntPtr ptr;
  260. ConvertStringSidToSid(Apps[i].StringSid, out ptr);
  261. arr[count].Sid = ptr;
  262. count++;
  263. }
  264. }
  265. if (NetworkIsolationSetAppContainerConfig((uint)countEnabled, arr) == 0)
  266. {
  267. return true;
  268. }
  269. else
  270. { return false; }
  271. }
  272. private int CountEnabledLoopUtil()
  273. {
  274. var count = 0;
  275. for (int i = 0; i < Apps.Count; i++)
  276. {
  277. if (Apps[i].LoopUtil)
  278. {
  279. count++;
  280. }
  281. }
  282. return count;
  283. }
  284. public void FreeResources()
  285. {
  286. NetworkIsolationFreeAppContainers(_pACs);
  287. }
  288. }
  289. }