Win32 API 日本語リファレンス
ホームSecurity.AppLocker › SaferComputeTokenFromLevel

SaferComputeTokenFromLevel

関数
SAFER信頼レベルに基づき制限付きアクセストークンを生成する。
DLLADVAPI32.dll呼出規約winapiSetLastErrorあり対応OSWindows XP 以降

シグネチャ

// ADVAPI32.dll
#include <windows.h>

BOOL SaferComputeTokenFromLevel(
    SAFER_LEVEL_HANDLE LevelHandle,
    HANDLE InAccessToken,   // optional
    HANDLE* OutAccessToken,
    SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags,
    void* lpReserved   // optional
);

パラメーター

名前方向説明
LevelHandleSAFER_LEVEL_HANDLEin適用する信頼レベルのSAFERレベルハンドル。
InAccessTokenHANDLEinoptional元となるアクセストークンハンドル。NULLで現在のスレッド/プロセストークン。
OutAccessTokenHANDLE*outレベルに基づき制限されたアクセストークンを受け取る出力先。
dwFlagsSAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGSinトークン生成動作を制御するフラグ。
lpReservedvoid*inoutoptional予約パラメータ。NULLを指定する。

戻り値の型: BOOL

各言語での呼び出し定義

// ADVAPI32.dll
#include <windows.h>

BOOL SaferComputeTokenFromLevel(
    SAFER_LEVEL_HANDLE LevelHandle,
    HANDLE InAccessToken,   // optional
    HANDLE* OutAccessToken,
    SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags,
    void* lpReserved   // optional
);
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", SetLastError = true, ExactSpelling = true)]
static extern bool SaferComputeTokenFromLevel(
    IntPtr LevelHandle,   // SAFER_LEVEL_HANDLE
    IntPtr InAccessToken,   // HANDLE optional
    IntPtr OutAccessToken,   // HANDLE* out
    uint dwFlags,   // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
    IntPtr lpReserved   // void* optional, in/out
);
<DllImport("ADVAPI32.dll", SetLastError:=True, ExactSpelling:=True)>
Public Shared Function SaferComputeTokenFromLevel(
    LevelHandle As IntPtr,   ' SAFER_LEVEL_HANDLE
    InAccessToken As IntPtr,   ' HANDLE optional
    OutAccessToken As IntPtr,   ' HANDLE* out
    dwFlags As UInteger,   ' SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
    lpReserved As IntPtr   ' void* optional, in/out
) As Boolean
End Function
' LevelHandle : SAFER_LEVEL_HANDLE
' InAccessToken : HANDLE optional
' OutAccessToken : HANDLE* out
' dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
' lpReserved : void* optional, in/out
Declare PtrSafe Function SaferComputeTokenFromLevel Lib "advapi32" ( _
    ByVal LevelHandle As LongPtr, _
    ByVal InAccessToken As LongPtr, _
    ByVal OutAccessToken As LongPtr, _
    ByVal dwFlags As Long, _
    ByVal lpReserved As LongPtr) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

SaferComputeTokenFromLevel = ctypes.windll.advapi32.SaferComputeTokenFromLevel
SaferComputeTokenFromLevel.restype = wintypes.BOOL
SaferComputeTokenFromLevel.argtypes = [
    wintypes.HANDLE,  # LevelHandle : SAFER_LEVEL_HANDLE
    wintypes.HANDLE,  # InAccessToken : HANDLE optional
    ctypes.c_void_p,  # OutAccessToken : HANDLE* out
    wintypes.DWORD,  # dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
    ctypes.POINTER(None),  # lpReserved : void* optional, in/out
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('ADVAPI32.dll')
SaferComputeTokenFromLevel = Fiddle::Function.new(
  lib['SaferComputeTokenFromLevel'],
  [
    Fiddle::TYPE_VOIDP,  # LevelHandle : SAFER_LEVEL_HANDLE
    Fiddle::TYPE_VOIDP,  # InAccessToken : HANDLE optional
    Fiddle::TYPE_VOIDP,  # OutAccessToken : HANDLE* out
    -Fiddle::TYPE_INT,  # dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
    Fiddle::TYPE_VOIDP,  # lpReserved : void* optional, in/out
  ],
  Fiddle::TYPE_INT)
#[link(name = "advapi32")]
extern "system" {
    fn SaferComputeTokenFromLevel(
        LevelHandle: *mut core::ffi::c_void,  // SAFER_LEVEL_HANDLE
        InAccessToken: *mut core::ffi::c_void,  // HANDLE optional
        OutAccessToken: *mut *mut core::ffi::c_void,  // HANDLE* out
        dwFlags: u32,  // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
        lpReserved: *mut ()  // void* optional, in/out
    ) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", SetLastError = true)]
public static extern bool SaferComputeTokenFromLevel(IntPtr LevelHandle, IntPtr InAccessToken, IntPtr OutAccessToken, uint dwFlags, IntPtr lpReserved);
"@
$api = Add-Type -MemberDefinition $sig -Name 'ADVAPI32_SaferComputeTokenFromLevel' -Namespace Win32 -PassThru
# $api::SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
#uselib "ADVAPI32.dll"
#func global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" sptr, sptr, sptr, sptr, sptr
; SaferComputeTokenFromLevel LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved   ; 戻り値は stat
; LevelHandle : SAFER_LEVEL_HANDLE -> "sptr"
; InAccessToken : HANDLE optional -> "sptr"
; OutAccessToken : HANDLE* out -> "sptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "sptr"
; lpReserved : void* optional, in/out -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
#uselib "ADVAPI32.dll"
#cfunc global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" sptr, sptr, sptr, int, sptr
; res = SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
; LevelHandle : SAFER_LEVEL_HANDLE -> "sptr"
; InAccessToken : HANDLE optional -> "sptr"
; OutAccessToken : HANDLE* out -> "sptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "int"
; lpReserved : void* optional, in/out -> "sptr"
; BOOL SaferComputeTokenFromLevel(SAFER_LEVEL_HANDLE LevelHandle, HANDLE InAccessToken, HANDLE* OutAccessToken, SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS dwFlags, void* lpReserved)
#uselib "ADVAPI32.dll"
#cfunc global SaferComputeTokenFromLevel "SaferComputeTokenFromLevel" intptr, intptr, intptr, int, intptr
; res = SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
; LevelHandle : SAFER_LEVEL_HANDLE -> "intptr"
; InAccessToken : HANDLE optional -> "intptr"
; OutAccessToken : HANDLE* out -> "intptr"
; dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "int"
; lpReserved : void* optional, in/out -> "intptr"
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	advapi32 = windows.NewLazySystemDLL("ADVAPI32.dll")
	procSaferComputeTokenFromLevel = advapi32.NewProc("SaferComputeTokenFromLevel")
)

// LevelHandle (SAFER_LEVEL_HANDLE), InAccessToken (HANDLE optional), OutAccessToken (HANDLE* out), dwFlags (SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS), lpReserved (void* optional, in/out)
r1, _, err := procSaferComputeTokenFromLevel.Call(
	uintptr(LevelHandle),
	uintptr(InAccessToken),
	uintptr(OutAccessToken),
	uintptr(dwFlags),
	uintptr(lpReserved),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // BOOL
function SaferComputeTokenFromLevel(
  LevelHandle: THandle;   // SAFER_LEVEL_HANDLE
  InAccessToken: THandle;   // HANDLE optional
  OutAccessToken: Pointer;   // HANDLE* out
  dwFlags: DWORD;   // SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
  lpReserved: Pointer   // void* optional, in/out
): BOOL; stdcall;
  external 'ADVAPI32.dll' name 'SaferComputeTokenFromLevel';
result := DllCall("ADVAPI32\SaferComputeTokenFromLevel"
    , "Ptr", LevelHandle   ; SAFER_LEVEL_HANDLE
    , "Ptr", InAccessToken   ; HANDLE optional
    , "Ptr", OutAccessToken   ; HANDLE* out
    , "UInt", dwFlags   ; SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS
    , "Ptr", lpReserved   ; void* optional, in/out
    , "Int")   ; return: BOOL
●SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved) = DLL("ADVAPI32.dll", "bool SaferComputeTokenFromLevel(void*, void*, void*, dword, void*)")
# 呼び出し: SaferComputeTokenFromLevel(LevelHandle, InAccessToken, OutAccessToken, dwFlags, lpReserved)
# LevelHandle : SAFER_LEVEL_HANDLE -> "void*"
# InAccessToken : HANDLE optional -> "void*"
# OutAccessToken : HANDLE* out -> "void*"
# dwFlags : SAFER_COMPUTE_TOKEN_FROM_LEVEL_FLAGS -> "dword"
# lpReserved : void* optional, in/out -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。