diff --git a/src/Common/src/CoreLib/Interop/Windows/Kernel32/Interop.Mutex.cs b/src/Common/src/CoreLib/Interop/Windows/Kernel32/Interop.Mutex.cs index 46ddd12f9b43..6adaf9873704 100644 --- a/src/Common/src/CoreLib/Interop/Windows/Kernel32/Interop.Mutex.cs +++ b/src/Common/src/CoreLib/Interop/Windows/Kernel32/Interop.Mutex.cs @@ -2,6 +2,7 @@ // The .NET Foundation licenses this file to you under the MIT license. // See the LICENSE file in the project root for more information. +#nullable enable using Microsoft.Win32.SafeHandles; using System; using System.Runtime.InteropServices; @@ -12,13 +13,13 @@ internal static partial class Kernel32 { internal const uint CREATE_MUTEX_INITIAL_OWNER = 0x1; - [DllImport(Interop.Libraries.Kernel32, EntryPoint = "OpenMutexW", SetLastError = true, CharSet = CharSet.Unicode)] + [DllImport(Libraries.Kernel32, EntryPoint = "OpenMutexW", SetLastError = true, CharSet = CharSet.Unicode)] internal static extern SafeWaitHandle OpenMutex(uint desiredAccess, bool inheritHandle, string name); - [DllImport(Interop.Libraries.Kernel32, EntryPoint = "CreateMutexExW", SetLastError = true, CharSet = CharSet.Unicode)] + [DllImport(Libraries.Kernel32, EntryPoint = "CreateMutexExW", SetLastError = true, CharSet = CharSet.Unicode)] internal static extern SafeWaitHandle CreateMutexEx(IntPtr lpMutexAttributes, string? name, uint flags, uint desiredAccess); - [DllImport(Interop.Libraries.Kernel32, SetLastError = true)] + [DllImport(Libraries.Kernel32, SetLastError = true)] internal static extern bool ReleaseMutex(SafeWaitHandle handle); } } diff --git a/src/System.Threading.AccessControl/System.Threading.AccessControl.sln b/src/System.Threading.AccessControl/System.Threading.AccessControl.sln index a1994361f8b8..bb4c50ca7495 100644 --- a/src/System.Threading.AccessControl/System.Threading.AccessControl.sln +++ b/src/System.Threading.AccessControl/System.Threading.AccessControl.sln @@ -1,6 +1,6 @@ Microsoft Visual Studio Solution File, Format Version 12.00 -# Visual Studio 15 -VisualStudioVersion = 15.0.27213.1 +# Visual Studio Version 16 +VisualStudioVersion = 16.0.29411.138 MinimumVisualStudioVersion = 10.0.40219.1 Project("{9A19103F-16F7-4668-BE54-9A1E7A4F7556}") = "System.Threading.AccessControl.Tests", "tests\System.Threading.AccessControl.Tests.csproj", "{458E445C-DF3C-4E4D-8E1D-F2FAC365BB40}" ProjectSection(ProjectDependencies) = postProject diff --git a/src/System.Threading.AccessControl/ref/System.Threading.AccessControl.cs b/src/System.Threading.AccessControl/ref/System.Threading.AccessControl.cs index 8d7efcd0bf12..e843a297264d 100644 --- a/src/System.Threading.AccessControl/ref/System.Threading.AccessControl.cs +++ b/src/System.Threading.AccessControl/ref/System.Threading.AccessControl.cs @@ -147,4 +147,9 @@ public static void SetAccessControl(this System.Threading.EventWaitHandle handle public static void SetAccessControl(this System.Threading.Mutex mutex, System.Security.AccessControl.MutexSecurity mutexSecurity) { } public static void SetAccessControl(this System.Threading.Semaphore semaphore, System.Security.AccessControl.SemaphoreSecurity semaphoreSecurity) { } } + + public static class MutexAcl + { + public static System.Threading.Mutex Create(bool initiallyOwned, string name, out bool createdNew, System.Security.AccessControl.MutexSecurity mutexSecurity) { throw null; } + } } diff --git a/src/System.Threading.AccessControl/src/Resources/Strings.resx b/src/System.Threading.AccessControl/src/Resources/Strings.resx index 265db70986ef..2e0669e8eca8 100644 --- a/src/System.Threading.AccessControl/src/Resources/Strings.resx +++ b/src/System.Threading.AccessControl/src/Resources/Strings.resx @@ -1,4 +1,64 @@ - + + + @@ -63,4 +123,52 @@ Access Control List (ACL) APIs are part of resource management on Windows and are not supported on this platform. + + The length of the name exceeds the maximum limit. + + + Enum value was out of legal range. + + + Cannot create '{0}' because a file or directory with the same name already exists. + + + The file '{0}' already exists. + + + Unable to find the specified file. + + + Could not find file '{0}'. + + + Could not find a part of the path. + + + Could not find a part of the path '{0}'. + + + The specified file name or path is too long, or a component of the specified path is too long. + + + The path '{0}' is too long, or a component of the specified path is too long. + + + The process cannot access the file '{0}' because it is being used by another process. + + + The process cannot access the file because it is being used by another process. + + + Access to the path is denied. + + + Access to the path '{0}' is denied. + + + Argument cannot be null or empty. + + + A WaitHandle with system-wide name '{0}' cannot be created. A WaitHandle of a different type might have the same name. + \ No newline at end of file diff --git a/src/System.Threading.AccessControl/src/System.Threading.AccessControl.csproj b/src/System.Threading.AccessControl/src/System.Threading.AccessControl.csproj index 1485cdf4b117..f4792d905474 100644 --- a/src/System.Threading.AccessControl/src/System.Threading.AccessControl.csproj +++ b/src/System.Threading.AccessControl/src/System.Threading.AccessControl.csproj @@ -1,25 +1,37 @@ - + Windows_NT SR.PlatformNotSupported_AccessControl true net461-Windows_NT-Debug;net461-Windows_NT-Release;netfx-Windows_NT-Debug;netfx-Windows_NT-Release;netstandard2.0-Debug;netstandard2.0-Release;netstandard2.0-Windows_NT-Debug;netstandard2.0-Windows_NT-Release + true + + + - - Common\Interop\Windows\Interop.Errors.cs - + + + + + + + + + + + diff --git a/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.cs b/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.cs new file mode 100644 index 000000000000..0d94b09b48de --- /dev/null +++ b/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.cs @@ -0,0 +1,82 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. +// See the LICENSE file in the project root for more information. + +using System.IO; +using System.Runtime.InteropServices; +using System.Security.AccessControl; +using Microsoft.Win32.SafeHandles; + +namespace System.Threading +{ + public static class MutexAcl + { + /// Gets or creates instance, allowing a to be optionally specified to set it during the mutex creation. + /// to give the calling thread initial ownership of the named system mutex if the named system mutex is created as a result of this call; otherwise, . + /// The optional name of the system mutex. If this argument is set to or , a local mutex is created. + /// When this method returns, this argument is always set to if a local mutex is created; that is, when is or . If has a valid non-empty value, this argument is set to when the system mutex is created, or it is set to if an existing system mutex is found with that name. This parameter is passed uninitialized. + /// The optional mutex access control security to apply. + /// An object that represents a system mutex, if named, or a local mutex, if nameless. + /// .NET Framework only: The length of the name exceeds the maximum limit. + /// A mutex handle with system-wide cannot be created. A mutex handle of a different type might have the same name. + public static unsafe Mutex Create(bool initiallyOwned, string name, out bool createdNew, MutexSecurity mutexSecurity) + { + if (mutexSecurity == null) + { + return new Mutex(initiallyOwned, name, out createdNew); + } + + uint mutexFlags = initiallyOwned ? Interop.Kernel32.CREATE_MUTEX_INITIAL_OWNER : 0; + + fixed (byte* pSecurityDescriptor = mutexSecurity.GetSecurityDescriptorBinaryForm()) + { + var secAttrs = new Interop.Kernel32.SECURITY_ATTRIBUTES + { + nLength = (uint)sizeof(Interop.Kernel32.SECURITY_ATTRIBUTES), + lpSecurityDescriptor = (IntPtr)pSecurityDescriptor + }; + + SafeWaitHandle handle = Interop.Kernel32.CreateMutexEx( + (IntPtr)(&secAttrs), + name, + mutexFlags, + (uint)MutexRights.FullControl // Equivalent to MUTEX_ALL_ACCESS + ); + + ValidateMutexHandle(handle, name, out createdNew); + + Mutex mutex = new Mutex(initiallyOwned); + SafeWaitHandle old = mutex.SafeWaitHandle; + mutex.SafeWaitHandle = handle; + old.Dispose(); + + return mutex; + } + } + + private static void ValidateMutexHandle(SafeWaitHandle mutexHandle, string name, out bool createdNew) + { + int errorCode = Marshal.GetLastWin32Error(); + + if (mutexHandle.IsInvalid) + { + mutexHandle.SetHandleAsInvalid(); + + if (errorCode == Interop.Errors.ERROR_FILENAME_EXCED_RANGE) + { + // On Unix, length validation is done by CoreCLR's PAL after converting to utf-8 + throw new ArgumentException(SR.Argument_WaitHandleNameTooLong, nameof(name)); + } + + if (errorCode == Interop.Errors.ERROR_INVALID_HANDLE) + { + throw new WaitHandleCannotBeOpenedException(SR.Format(SR.Threading_WaitHandleCannotBeOpenedException_InvalidHandle, name)); + } + + throw Win32Marshal.GetExceptionForWin32Error(errorCode, name); + } + + createdNew = (errorCode != Interop.Errors.ERROR_ALREADY_EXISTS); + } + } +} diff --git a/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.net46.cs b/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.net46.cs new file mode 100644 index 000000000000..2c1a5caf8279 --- /dev/null +++ b/src/System.Threading.AccessControl/src/System/Threading/MutexAcl.net46.cs @@ -0,0 +1,16 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. +// See the LICENSE file in the project root for more information. + +using System.Security.AccessControl; + +namespace System.Threading +{ + public static class MutexAcl + { + public static Mutex Create(bool initiallyOwned, string name, out bool createdNew, MutexSecurity mutexSecurity) + { + return new Mutex(initiallyOwned, name, out createdNew, mutexSecurity); + } + } +} diff --git a/src/System.Threading.AccessControl/tests/AclTests.cs b/src/System.Threading.AccessControl/tests/AclTests.cs new file mode 100644 index 000000000000..496d8e76a746 --- /dev/null +++ b/src/System.Threading.AccessControl/tests/AclTests.cs @@ -0,0 +1,14 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. +// See the LICENSE file in the project root for more information. + +namespace System.Threading.Tests +{ + public class AclTests + { + protected string GetRandomName() + { + return Guid.NewGuid().ToString("N"); + } + } +} diff --git a/src/System.Threading.AccessControl/tests/MutexAclTests.cs b/src/System.Threading.AccessControl/tests/MutexAclTests.cs new file mode 100644 index 000000000000..f51f09e04e6a --- /dev/null +++ b/src/System.Threading.AccessControl/tests/MutexAclTests.cs @@ -0,0 +1,147 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. +// See the LICENSE file in the project root for more information. + +using System.Collections.Generic; +using System.Linq; +using System.Security.AccessControl; +using System.Security.Principal; +using Xunit; + +namespace System.Threading.Tests +{ + public class MutexAclTests : AclTests + { + [Fact] + public void Mutex_Create_NullSecurity() + { + CreateAndVerifyMutex(initiallyOwned: true, GetRandomName(), expectedSecurity: null, expectedCreatedNew: true).Dispose(); + } + + [Theory] + [InlineData(null)] + [InlineData("")] + public void Mutex_Create_NameMultipleNew(string name) + { + var security = GetBasicMutexSecurity(); + + using Mutex mutex1 = CreateAndVerifyMutex(initiallyOwned: true, name, security, expectedCreatedNew: true); + using Mutex mutex2 = CreateAndVerifyMutex(initiallyOwned: true, name, security, expectedCreatedNew: true); + } + + [Fact] + public void Mutex_Create_CreateNewExisting() + { + string name = GetRandomName(); + var security = GetBasicMutexSecurity(); + + using Mutex mutexNew = CreateAndVerifyMutex(initiallyOwned: true, name, security, expectedCreatedNew: true); + using Mutex mutexExisting = CreateAndVerifyMutex(initiallyOwned: true, name, security, expectedCreatedNew: false); + } + + [Fact] + public void Mutex_Create_BeyondMaxPathLength() + { + string name = new string('x', Interop.Kernel32.MAX_PATH + 100); + + if (PlatformDetection.IsFullFramework) + { + Assert.Throws(() => + { + CreateAndVerifyMutex(initiallyOwned: true, name, GetBasicMutexSecurity(), expectedCreatedNew: true).Dispose(); + }); + } + else + { + using Mutex created = CreateAndVerifyMutex(initiallyOwned: true, name, GetBasicMutexSecurity(), expectedCreatedNew: true); + using Mutex openedByName = Mutex.OpenExisting(name); + Assert.NotNull(openedByName); + } + } + + [Theory] + [InlineData(true, MutexRights.FullControl, AccessControlType.Allow)] + [InlineData(true, MutexRights.FullControl, AccessControlType.Deny)] + [InlineData(true, MutexRights.Synchronize, AccessControlType.Allow)] + [InlineData(true, MutexRights.Synchronize, AccessControlType.Deny)] + [InlineData(true, MutexRights.Modify, AccessControlType.Allow)] + [InlineData(true, MutexRights.Modify, AccessControlType.Deny)] + [InlineData(true, MutexRights.Modify | MutexRights.Synchronize, AccessControlType.Allow)] + [InlineData(true, MutexRights.Modify | MutexRights.Synchronize, AccessControlType.Deny)] + [InlineData(false, MutexRights.FullControl, AccessControlType.Allow)] + [InlineData(false, MutexRights.FullControl, AccessControlType.Deny)] + [InlineData(false, MutexRights.Synchronize, AccessControlType.Allow)] + [InlineData(false, MutexRights.Synchronize, AccessControlType.Deny)] + [InlineData(false, MutexRights.Modify, AccessControlType.Allow)] + [InlineData(false, MutexRights.Modify, AccessControlType.Deny)] + public void Mutex_Create_SpecificParameters(bool initiallyOwned, MutexRights rights, AccessControlType accessControl) + { + var security = GetMutexSecurity(WellKnownSidType.BuiltinUsersSid, rights, accessControl); + CreateAndVerifyMutex(initiallyOwned, GetRandomName(), security, expectedCreatedNew: true).Dispose(); + + } + + private MutexSecurity GetBasicMutexSecurity() + { + return GetMutexSecurity( + WellKnownSidType.BuiltinUsersSid, + MutexRights.FullControl, + AccessControlType.Allow); + } + + private MutexSecurity GetMutexSecurity(WellKnownSidType sid, MutexRights rights, AccessControlType accessControl) + { + var security = new MutexSecurity(); + SecurityIdentifier identity = new SecurityIdentifier(sid, null); + var accessRule = new MutexAccessRule(identity, rights, accessControl); + security.AddAccessRule(accessRule); + return security; + } + + private Mutex CreateAndVerifyMutex(bool initiallyOwned, string name, MutexSecurity expectedSecurity, bool expectedCreatedNew) + { + Mutex mutex = MutexAcl.Create(initiallyOwned, name, out bool createdNew, expectedSecurity); + Assert.NotNull(mutex); + Assert.Equal(createdNew, expectedCreatedNew); + + if (expectedSecurity != null) + { + MutexSecurity actualSecurity = mutex.GetAccessControl(); + VerifyMutexSecurity(expectedSecurity, actualSecurity); + } + + return mutex; + } + + private void VerifyMutexSecurity(MutexSecurity expectedSecurity, MutexSecurity actualSecurity) + { + Assert.Equal(typeof(MutexRights), expectedSecurity.AccessRightType); + Assert.Equal(typeof(MutexRights), actualSecurity.AccessRightType); + + List expectedAccessRules = expectedSecurity.GetAccessRules(includeExplicit: true, includeInherited: false, typeof(SecurityIdentifier)) + .Cast().ToList(); + + List actualAccessRules = actualSecurity.GetAccessRules(includeExplicit: true, includeInherited: false, typeof(SecurityIdentifier)) + .Cast().ToList(); + + Assert.Equal(expectedAccessRules.Count, actualAccessRules.Count); + if (expectedAccessRules.Count > 0) + { + Assert.All(expectedAccessRules, actualAccessRule => + { + int count = expectedAccessRules.Count(expectedAccessRule => AreAccessRulesEqual(expectedAccessRule, actualAccessRule)); + Assert.True(count > 0); + }); + } + } + + private bool AreAccessRulesEqual(MutexAccessRule expectedRule, MutexAccessRule actualRule) + { + return + expectedRule.AccessControlType == actualRule.AccessControlType && + expectedRule.MutexRights == actualRule.MutexRights && + expectedRule.InheritanceFlags == actualRule.InheritanceFlags && + expectedRule.PropagationFlags == actualRule.PropagationFlags; + } + } +} diff --git a/src/System.Threading.AccessControl/tests/System.Threading.AccessControl.Tests.csproj b/src/System.Threading.AccessControl/tests/System.Threading.AccessControl.Tests.csproj index 62b99a1f8291..8e31f48f3125 100644 --- a/src/System.Threading.AccessControl/tests/System.Threading.AccessControl.Tests.csproj +++ b/src/System.Threading.AccessControl/tests/System.Threading.AccessControl.Tests.csproj @@ -3,6 +3,10 @@ netcoreapp-Windows_NT-Debug;netcoreapp-Windows_NT-Release;netfx-Windows_NT-Debug;netfx-Windows_NT-Release + + + +