feat: add --firewall (#57)

This commit is contained in:
Arsenii es3n1n
2026-08-15 16:37:25 +02:00
committed by GitHub
parent 0c9be5724f
commit 2acdf7724a
7 changed files with 61 additions and 18 deletions

View File

@@ -8,27 +8,41 @@
namespace defendnot {
namespace {
void activate(const auto& step, IWscASStatus* inst) {
step("update", inst->UpdateStatus(WSCSecurityProductState::ON, TRUE));
}
void activate(const auto& step, IWscAVStatus4* inst) {
step("update", inst->UpdateStatus(WSCSecurityProductState::ON, TRUE));
step("scan_update", inst->UpdateScanSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
step("settings_update", inst->UpdateSettingsSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
step("prot_update", inst->UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
}
void activate(const auto& step, IWscFWStatus2* inst) {
step("update", inst->UpdateStatus(WSCSecurityProductState::ON));
step("domain_update", inst->UpdateDomainProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
step("private_update", inst->UpdatePrivateProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
step("public_update", inst->UpdatePublicProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
}
template <com::ComObject Ty>
void apply(const std::string_view log_prefix, const BSTR name) {
void apply(const std::string_view log_prefix, const BSTR name, const bool should_register) {
/// Get the WSC interface
auto inst = com::query<Ty>();
/// This can fail if we dont have any products registered so no com_checked
/// This can fail if we dont have any products registered so no com::checked
logln("{}_unregister: {:#x}", log_prefix, com::retry_while_pending([&inst]() -> HRESULT { return inst->Unregister(); }) & 0xFFFFFFFF);
if (shared::ctx.state == shared::State::OFF) {
if (!should_register) {
return;
}
/// Register and activate
logln("{}_register: {:#x}", log_prefix, com::checked(inst->Register(name, name, 0, 0)));
logln("{}_update: {:#x}", log_prefix, com::checked(inst->UpdateStatus(WSCSecurityProductState::ON, static_cast<BOOL>(true))));
/// Update the substatuses, if the interface supports this
if constexpr (std::is_same_v<Ty, IWscAVStatus4>) {
logln("{}_scan_update: {:#x}", log_prefix, com::checked(inst->UpdateScanSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
logln("{}_settings_update: {:#x}", log_prefix, com::checked(inst->UpdateSettingsSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
logln("{}_prot_update: {:#x}", log_prefix, com::checked(inst->UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
}
const auto step = [&](const std::string_view what, const HRESULT hr) -> void {
logln("{}_{}: {:#x}", log_prefix, what, com::checked(hr));
};
step("register", inst->Register(name, name, 0, 0));
activate(step, inst.get());
}
} // namespace
@@ -45,12 +59,14 @@ namespace defendnot {
/// Convert to BSTR
auto name = SysAllocString(name_w.c_str());
defer->void {
defer {
SysFreeString(name);
};
/// Register our stuff in the WSC interfaces
apply<IWscASStatus>("IWscASStatus", name);
apply<IWscAVStatus4>("IWscAVStatus4", name);
const bool enabled = shared::ctx.state != shared::State::OFF;
apply<IWscASStatus>("IWscASStatus", name, enabled);
apply<IWscAVStatus4>("IWscAVStatus4", name, enabled);
apply<IWscFWStatus2>("IWscFWStatus2", name, enabled && shared::ctx.register_firewall);
}
} // namespace defendnot

View File

@@ -69,4 +69,14 @@ namespace defendnot {
virtual HRESULT COM_CALLCONV Unregister() = 0;
virtual HRESULT COM_CALLCONV UpdateStatus(WSCSecurityProductState state, BOOL unk) = 0;
};
class IWscFWStatus2 : public com::IBaseObject<detail::CLSID_WscIsv, detail::IID_IWscFWStatus2> {
public:
virtual HRESULT COM_CALLCONV Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
virtual HRESULT COM_CALLCONV Unregister() = 0;
virtual HRESULT COM_CALLCONV UpdateStatus(WSCSecurityProductState state) = 0;
virtual HRESULT COM_CALLCONV UpdateDomainProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
virtual HRESULT COM_CALLCONV UpdatePrivateProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
virtual HRESULT COM_CALLCONV UpdatePublicProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
};
} // namespace defendnot