7 ms·
Named Pipes in .NET 6 with Tray Icon and Service
- ape4 5y agoNamed pipes have been in Windows for many years https://docs.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea https://docs.microsoft.com/en-us/windows/win32/api/winbase/n...
- hobs 5y agoFirst thing I do with SQL Server setups - turn off named pipes :)
- giancarlostoro 5y agoIs there a reason you do this? Curious, I havent had to setup SQL Server myself in a while so I don't know what a reasonable reason would be.
- tyingq 5y agoNamed pipes are fast when the database is on the same box, but slower than a normal tcp connection when the database is remote. Something to do with PeekNamedPipe calls having to prepend reads.
- hobs 5y agoYeah one of my favorite SE posters talks a little more about it, generally the benefits are only there if you have app/db/sql server all on the same box. https://dba.stackexchange.com/a/24176/15642 https://dba.stackexchange.com/a/24176/15642
- deleted 5y ago[deleted]
- zwieback 5y agoBeen using them since 1992 but at this point I would naturally turn to sockets, even on the same machine. I can't even really say why though. Named pipes are nice because they are really more like a file but at this point sockets feel more natural because they exist and are supported everywhere.
- ziml77 5y agoYou can apply permissions to named pipes and, well, they're named which is useful since you can use a unique and deterministic enough name that you don't need an extra band of communication for the client to know what port the server ended up starting on.
- zwieback 5y agoYeah, good point, as opposed to anonymous pipes, which also still exist.
- ww520 5y agoTCP server cannot assume the security context of the client, thus privilege elevation attack can easily happen.
- monocasa 5y agoMore importantly in a lot of cases, you can ask the kernel for the client's SID as the server, and make decisions knowing that the client couldn't forge it.
- krisrm 5y agoJust to clarify something at the start of the article... If you are using full Visual Studio to develop with .NET 6, you will need 2022. If not, (eg. VS Code), will work with the command line sdk.
- philliphaydon 5y agoPretty sure there isn't anything you can't do in Jetbrains Rider EAP. Edit: would like to know why I'm being downvoted.
- krisrm 5y agoApologies - my comment was poorly worded and I think it caused confusion. The article sort of implied that Visual Studio was "The Way to Develop in .NET", while both you and I obviously know that's not true. I've seen a lot of documentation (third party and Microsoft) that just start in on a "Visual Studio"-based solution while ignoring everything else, which kind of rubs me the wrong way.
- philliphaydon 5y agoMy reply wasn’t trying to be negative to yours. Just also wanting to include Rider :) sometimes the features lag behind in rider. Hence I had to be specific and say EAP. Yeah I know the feeling. I like to remind people there is a good development experience on linux also when using Rider. Sometimes feel like people are still stuck on “.net is windows only!”
- achandlerwhite 5y agoHot reload in Rider only works in debug mode on Windows (to be clear it also works in nondebug sessions on Windows). On Mac trying to use Hot Reload with Rider on a nondebug session errors out, so it’s not 100% yet.
- philliphaydon 5y agoBut the article doesn't require hot reload to achieve the goal right?
- thefz 5y agoAmazing read and insanely helpful. Thanks a ton both to the author and to who posted it, if different people.
- entrep 5y agoWe’re the same person. Thanks.
- k8sToGo 5y agoI don't know why I expected something more technical for the tray icon part. I mean using a third party library is not really anything .NET 6 specific.
- entrep 5y agoI’ll guess that will be a separate post.
- comeonseriously 5y agoSeems to me, the focus of the article was more on named pipes than the tray icon, so maybe that's why?
- thrower123 5y agoI think this is the first NamedPipes tutorial in C# that I've ever seen that doesn't do things completely wrong by using a StreamWriter or StreamReader. Of course, that's because it uses another library that wraps all the tricky bits of NamedPipes that everybody always does wrong -> https://github.com/HavenDV/H.Pipes https://github.com/HavenDV/H.Pipes NamedPipes are sweet for doing same-machine IPC on Windows, that is for sure, but the built-in API is full of footguns.
- jborean93 5y agoCan you elaborate what’s wrong with using StreamReader or StreamWriter with a np? I’ve used them before so wondering what I’m potentially doing wrong here and what’s the alternative.
- thrower123 5y agoIt becomes an issue if the data you're reading or writing is larger than 1024 bytes and you are in PipeTransmissionMode.Message, because of some implementation details with buffers and how StreamReader/Writer handle Read/Write calls on the underlying NamedPipe(Client/Server)Stream See https://stackoverflow.com/questions/31936100/namedpipeserverstream-receive-max-1024-bytes-why https://stackoverflow.com/questions/31936100/namedpipeserver...
- jborean93 5y agoThanks for the info, I personally avoid the message mode and just operate on bytes so that could be why I haven't had problems with it.
- sebazzz 5y agoAn alternative that comes with built-in dependency injection is using the .NET hosted process model. Much easier to test too.
- bloblaw 5y agoGood article, but I wish the author would've addressed securing these named pipes. Consider that if a user-mode application can send messages to a privileged process (like a Windows service). What prevents any user-mode application from doing that? And if your Windows service is running as "NT_AUTHORITY/SYSTEM" and even executes privileged commands, well you might find you've got a simple privilege escalation vuln. Remember, secure your named pipes...especially when the named pipe server runs as SYSTEM. - https://stackoverflow.com/a/59983266 https://stackoverflow.com/a/59983266 - https://versprite.com/blog/security-research/vulnerable-named-pipe-application/ https://versprite.com/blog/security-research/vulnerable-name...
- merb 5y agoI think the package he used, also has some kind of pipe authorization access control.
- entrep 5y agoThat is correct.
- entrep 5y agoThanks! That’s very valid feedback. Could be my next write up.
- bloblaw 5y agoYou're welcome. An alternative I've used to named pipes among processes of different privilege levels is to build the service to listen for custom commands sent to it. These are just integers, and the service maps those to pre-defined commands. Then the only thing the user-mode application can send are just flags (integers) that the service has already pre-determined what it will do in response. Here's an article: https://www.codeproject.com/Articles/24434/How-to-Write-Windows-Service-and-Control-It-By-App https://www.codeproject.com/Articles/24434/How-to-Write-Wind... And here's a succinct example: https://stackoverflow.com/a/5805700 https://stackoverflow.com/a/5805700
- resoluteteeth 5y agoThis uses the package H.Pipes which seems to use System.Runtime.Serialization.BinaryFormatter by default; isn't this insecure?
- tonyedgecombe 5y agoWhy is BinaryFormatter insecure? Edit: Never mind, see https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide https://docs.microsoft.com/en-us/dotnet/standard/serializati...
- entrep 5y agoIt's possible to use different formatters for H.Pipes. I will probably update the post to not mislead.
- HappySweeney 5y agoI've recently done something close to this, and found Ceras[0] to be an excellent choice for the serialization layer. [0] https://github.com/rikimaru0345/Ceras https://github.com/rikimaru0345/Ceras
- havendv 5y agoI added a package for Ceras: https://www.nuget.org/packages/H.Formatters.Ceras/ https://www.nuget.org/packages/H.Formatters.Ceras/ I ran into some issues in testing where the data hash after serialization/deserialization does not match for Ceras. I added the package anyway, but this needs to be used with caution.
- nsonha 5y agoWow the dotnet people are still doing this thing when they have screenshots of what to click in VS? So easy to reproduce!
- p2t2p 5y agoHonest question - how relevant the skill like that nowadays with all the stuff going Web and Electron? Are there any apps (except for creating stuff) that are being developed in a way that “server” part is running locally? It seems to me that everything goes web now and if you have a desktop it’s “just” a client for something remote?
- vicpara 5y agoI didn't use named pipes since 2010 but last time I checked named pipes are great for Inter Process Communication on the same machine. Great in terms of performance and access to a standard interface. WCF can be configured to use named pipes on local machines. Last time I checked named pipes were also available on the network and visible by other machines with some overhead. Security can be achieved not at channel level but at message level: If cannot decrypt the message then it's not for you. At the expense of overhead you open the door for flexibility. Ultimately it's a tool. What it matters is how you use it. Definitely better than using shared memory for IPC. Files are by default not secured either. Anyone can write into it.