ホーム › Security.AppLocker › SaferComputeTokenFromLevel
SaferComputeTokenFromLevel
関数SAFER信頼レベルに基づき制限付きアクセストークンを生成する。
シグネチャ
// ADVAPI32.dll
#include <windows.h>
BOOL SaferComputeTokenFromLevel(
SAFER_LEVEL_HANDLE LevelHandle,
HANDLE InAccessToken, // optional
HANDLE* OutAccessToken,
SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags,
void* lpReserved // optional
);パラメーター
| 名前 | 型 | 方向 | 説明 |
|---|---|---|---|
| LevelHandle | SAFER_LEVEL_HANDLE | in | 適用する信頼レベルのSAFERレベルハンドル。 |
| InAccessToken | HANDLE | inoptional | 元となるアクセストークンハンドル。NULLで現在のスレッド/プロセストークン。 |
| OutAccessToken | HANDLE* | out | レベルに基づき制限されたアクセストークンを受け取る出力先。 |
| dwFlags | SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS | in | トークン生成動作を制御するフラグ。 |
| lpReserved | void* | inoutoptional | 予約パラメータ。NULLを指定する。 |
戻り値の型: BOOL
各言語での呼び出し定義
// ADVAPI32.dll
#include <windows.h>
BOOL SaferComputeTokenFromLevel(
SAFER_LEVEL_HANDLE LevelHandle,
HANDLE InAccessToken, // optional
HANDLE* OutAccessToken,
SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags,
void* lpReserved // optional
);[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", SetLastError = true, ExactSpelling = true)]
static extern bool SaferComputeTokenFromLevel(
IntPtr LevelHandle, // SAFER_LEVEL_HANDLE
IntPtr InAccessToken, // HANDLE optional
IntPtr OutAccessToken, // HANDLE* out
uint dwFlags, // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
IntPtr lpReserved // void* optional, in/out
);<DllImport("ADVAPI32.dll", SetLastError:=True, ExactSpelling:=True)>
Public Shared Function SaferComputeTokenFromLevel(
LevelHandle As IntPtr, ' SAFER_LEVEL_HANDLE
InAccessToken As IntPtr, ' HANDLE optional
OutAccessToken As IntPtr, ' HANDLE* out
dwFlags As UInteger, ' SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
lpReserved As IntPtr ' void* optional, in/out
) As Boolean
End Function' LevelHandle : SAFER_LEVEL_HANDLE
' InAccessToken : HANDLE optional
' OutAccessToken : HANDLE* out
' dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
' lpReserved : void* optional, in/out
Declare PtrSafe Function SaferComputeTokenFromLevel Lib "advapi32" ( _
ByVal LevelHandle As LongPtr, _
ByVal InAccessToken As LongPtr, _
ByVal OutAccessToken As LongPtr, _
ByVal dwFlags As Long, _
ByVal lpReserved As LongPtr) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。import ctypes
from ctypes import wintypes
SaferComputeTokenFromLevel = ctypes.windll.advapi32.SaferComputeTokenFromLevel
SaferComputeTokenFromLevel.restype = wintypes.BOOL
SaferComputeTokenFromLevel.argtypes = [
wintypes.HANDLE, # LevelHandle : SAFER_LEVEL_HANDLE
wintypes.HANDLE, # InAccessToken : HANDLE optional
ctypes.c_void_p, # OutAccessToken : HANDLE* out
wintypes.DWORD, # dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
ctypes.POINTER(None), # lpReserved : void* optional, in/out
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))require 'fiddle'
require 'fiddle/import'
lib = Fiddle.dlopen('ADVAPI32.dll')
SaferComputeTokenFromLevel = Fiddle::Function.new(
lib['SaferComputeTokenFromLevel'],
[
Fiddle::TYPE_VOIDP, # LevelHandle : SAFER_LEVEL_HANDLE
Fiddle::TYPE_VOIDP, # InAccessToken : HANDLE optional
Fiddle::TYPE_VOIDP, # OutAccessToken : HANDLE* out
-Fiddle::TYPE_INT, # dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
Fiddle::TYPE_VOIDP, # lpReserved : void* optional, in/out
],
Fiddle::TYPE_INT)#[link(name = "advapi32")]
extern "system" {
fn SaferComputeTokenFromLevel(
LevelHandle: *mut core::ffi::c_void, // SAFER_LEVEL_HANDLE
InAccessToken: *mut core::ffi::c_void, // HANDLE optional
OutAccessToken: *mut *mut core::ffi::c_void, // HANDLE* out
dwFlags: u32, // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
lpReserved: *mut () // void* optional, in/out
) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.$sig = @"
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", SetLastError = true)]
public static extern bool SaferComputeTokenFromLevel(IntPtr LevelHandle, IntPtr InAccessToken, IntPtr OutAccessToken, uint dwFlags, IntPtr lpReserved);
"@
$api = Add-Type -MemberDefinition $sig -Name 'ADVAPI32_SaferComputeTokenFromLevel' -Namespace Win32 -PassThru
# $api::SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)#uselib "ADVAPI32.dll"
#func global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" sptr, sptr, sptr, sptr, sptr
; SaferComputeTokenFromLevel LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved ; 戻り値は stat
; LevelHandle : SAFER_LEVEL_HANDLE -> "sptr"
; InAccessToken : HANDLE optional -> "sptr"
; OutAccessToken : HANDLE* out -> "sptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "sptr"
; lpReserved : void* optional, in/out -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。#uselib "ADVAPI32.dll"
#cfunc global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" sptr, sptr, sptr, int, sptr
; res = SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
; LevelHandle : SAFER_LEVEL_HANDLE -> "sptr"
; InAccessToken : HANDLE optional -> "sptr"
; OutAccessToken : HANDLE* out -> "sptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "int"
; lpReserved : void* optional, in/out -> "sptr"; BOOL SaferComputeTokenFromLevel(SAFER_LEVEL_HANDLE LevelHandle, HANDLE InAccessToken, HANDLE* OutAccessToken, SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags, void* lpReserved)
#uselib "ADVAPI32.dll"
#cfunc global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" intptr, intptr, intptr, int, intptr
; res = SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
; LevelHandle : SAFER_LEVEL_HANDLE -> "intptr"
; InAccessToken : HANDLE optional -> "intptr"
; OutAccessToken : HANDLE* out -> "intptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "int"
; lpReserved : void* optional, in/out -> "intptr"import (
"golang.org/x/sys/windows"
"unsafe"
)
var (
advapi32 = windows.NewLazySystemDLL("ADVAPI32.dll")
procSaferComputeTokenFromLevel = advapi32.NewProc("SaferComputeTokenFromLevel")
)
// LevelHandle (SAFER_LEVEL_HANDLE), InAccessToken (HANDLE optional), OutAccessToken (HANDLE* out), dwFlags (SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS), lpReserved (void* optional, in/out)
r1, _, err := procSaferComputeTokenFromLevel.Call(
uintptr(LevelHandle),
uintptr(InAccessToken),
uintptr(OutAccessToken),
uintptr(dwFlags),
uintptr(lpReserved),
)
_ = err // syscall.Errno (valid when the call sets last-error)
_ = r1 // BOOLfunction SaferComputeTokenFromLevel(
LevelHandle: THandle; // SAFER_LEVEL_HANDLE
InAccessToken: THandle; // HANDLE optional
OutAccessToken: Pointer; // HANDLE* out
dwFlags: DWORD; // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
lpReserved: Pointer // void* optional, in/out
): BOOL; stdcall;
external 'ADVAPI32.dll' name 'SaferComputeTokenFromLevel';result := DllCall("ADVAPI32\SaferComputeTokenFromLevel"
, "Ptr", LevelHandle ; SAFER_LEVEL_HANDLE
, "Ptr", InAccessToken ; HANDLE optional
, "Ptr", OutAccessToken ; HANDLE* out
, "UInt", dwFlags ; SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
, "Ptr", lpReserved ; void* optional, in/out
, "Int") ; return: BOOL●SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved) = DLL("ADVAPI32.dll", "bool SaferComputeTokenFromLevel(void*, void*, void*, dword, void*)")
# 呼び出し: SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
# LevelHandle : SAFER_LEVEL_HANDLE -> "void*"
# InAccessToken : HANDLE optional -> "void*"
# OutAccessToken : HANDLE* out -> "void*"
# dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "dword"
# lpReserved : void* optional, in/out -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。