Win32 API 日本語リファレンス
ホームSecurity › ObjectPrivilegeAuditAlarmA

ObjectPrivilegeAuditAlarmA

関数
オブジェクトに対する特権使用の監査アラームを生成する(ANSI版)。
DLLADVAPI32.dll文字セットANSI (-A)呼出規約winapiSetLastErrorあり対応OSWindows XP 以降

シグネチャ

// ADVAPI32.dll  (ANSI / -A)
#include <windows.h>

BOOL ObjectPrivilegeAuditAlarmA(
    LPCSTR SubsystemName,
    void* HandleId,
    HANDLE ClientToken,
    DWORD DesiredAccess,
    PRIVILEGE_SET* Privileges,
    BOOL AccessGranted
);

パラメーター

名前方向
SubsystemNameLPCSTRin
HandleIdvoid*in
ClientTokenHANDLEin
DesiredAccessDWORDin
PrivilegesPRIVILEGE_SET*in
AccessGrantedBOOLin

戻り値の型: BOOL

各言語での呼び出し定義

// ADVAPI32.dll  (ANSI / -A)
#include <windows.h>

BOOL ObjectPrivilegeAuditAlarmA(
    LPCSTR SubsystemName,
    void* HandleId,
    HANDLE ClientToken,
    DWORD DesiredAccess,
    PRIVILEGE_SET* Privileges,
    BOOL AccessGranted
);
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", CharSet = CharSet.Ansi, SetLastError = true, ExactSpelling = true)]
static extern bool ObjectPrivilegeAuditAlarmA(
    [MarshalAs(UnmanagedType.LPStr)] string SubsystemName,   // LPCSTR
    IntPtr HandleId,   // void*
    IntPtr ClientToken,   // HANDLE
    uint DesiredAccess,   // DWORD
    IntPtr Privileges,   // PRIVILEGE_SET*
    bool AccessGranted   // BOOL
);
<DllImport("ADVAPI32.dll", CharSet:=CharSet.Ansi, SetLastError:=True, ExactSpelling:=True)>
Public Shared Function ObjectPrivilegeAuditAlarmA(
    <MarshalAs(UnmanagedType.LPStr)> SubsystemName As String,   ' LPCSTR
    HandleId As IntPtr,   ' void*
    ClientToken As IntPtr,   ' HANDLE
    DesiredAccess As UInteger,   ' DWORD
    Privileges As IntPtr,   ' PRIVILEGE_SET*
    AccessGranted As Boolean   ' BOOL
) As Boolean
End Function
' SubsystemName : LPCSTR
' HandleId : void*
' ClientToken : HANDLE
' DesiredAccess : DWORD
' Privileges : PRIVILEGE_SET*
' AccessGranted : BOOL
Declare PtrSafe Function ObjectPrivilegeAuditAlarmA Lib "advapi32" ( _
    ByVal SubsystemName As String, _
    ByVal HandleId As LongPtr, _
    ByVal ClientToken As LongPtr, _
    ByVal DesiredAccess As Long, _
    ByVal Privileges As LongPtr, _
    ByVal AccessGranted As Long) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

ObjectPrivilegeAuditAlarmA = ctypes.windll.advapi32.ObjectPrivilegeAuditAlarmA
ObjectPrivilegeAuditAlarmA.restype = wintypes.BOOL
ObjectPrivilegeAuditAlarmA.argtypes = [
    wintypes.LPCSTR,  # SubsystemName : LPCSTR
    ctypes.POINTER(None),  # HandleId : void*
    wintypes.HANDLE,  # ClientToken : HANDLE
    wintypes.DWORD,  # DesiredAccess : DWORD
    ctypes.c_void_p,  # Privileges : PRIVILEGE_SET*
    wintypes.BOOL,  # AccessGranted : BOOL
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('ADVAPI32.dll')
ObjectPrivilegeAuditAlarmA = Fiddle::Function.new(
  lib['ObjectPrivilegeAuditAlarmA'],
  [
    Fiddle::TYPE_VOIDP,  # SubsystemName : LPCSTR
    Fiddle::TYPE_VOIDP,  # HandleId : void*
    Fiddle::TYPE_VOIDP,  # ClientToken : HANDLE
    -Fiddle::TYPE_INT,  # DesiredAccess : DWORD
    Fiddle::TYPE_VOIDP,  # Privileges : PRIVILEGE_SET*
    Fiddle::TYPE_INT,  # AccessGranted : BOOL
  ],
  Fiddle::TYPE_INT)
#[link(name = "advapi32")]
extern "system" {
    fn ObjectPrivilegeAuditAlarmA(
        SubsystemName: *const u8,  // LPCSTR
        HandleId: *mut (),  // void*
        ClientToken: *mut core::ffi::c_void,  // HANDLE
        DesiredAccess: u32,  // DWORD
        Privileges: *mut PRIVILEGE_SET,  // PRIVILEGE_SET*
        AccessGranted: i32  // BOOL
    ) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", CharSet = CharSet.Ansi, SetLastError = true)]
public static extern bool ObjectPrivilegeAuditAlarmA([MarshalAs(UnmanagedType.LPStr)] string SubsystemName, IntPtr HandleId, IntPtr ClientToken, uint DesiredAccess, IntPtr Privileges, bool AccessGranted);
"@
$api = Add-Type -MemberDefinition $sig -Name 'ADVAPI32_ObjectPrivilegeAuditAlarmA' -Namespace Win32 -PassThru
# $api::ObjectPrivilegeAuditAlarmA(SubsystemName, HandleId, ClientToken, DesiredAccess, Privileges, AccessGranted)
#uselib "ADVAPI32.dll"
#func global ObjectPrivilegeAuditAlarmA "ObjectPrivilegeAuditAlarmA" sptr, sptr, sptr, sptr, sptr, sptr
; ObjectPrivilegeAuditAlarmA SubsystemName, HandleId, ClientToken, DesiredAccess, varptr(Privileges), AccessGranted   ; 戻り値は stat
; SubsystemName : LPCSTR -> "sptr"
; HandleId : void* -> "sptr"
; ClientToken : HANDLE -> "sptr"
; DesiredAccess : DWORD -> "sptr"
; Privileges : PRIVILEGE_SET* -> "sptr"
; AccessGranted : BOOL -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "ADVAPI32.dll"
#cfunc global ObjectPrivilegeAuditAlarmA "ObjectPrivilegeAuditAlarmA" str, sptr, sptr, int, var, int
; res = ObjectPrivilegeAuditAlarmA(SubsystemName, HandleId, ClientToken, DesiredAccess, Privileges, AccessGranted)
; SubsystemName : LPCSTR -> "str"
; HandleId : void* -> "sptr"
; ClientToken : HANDLE -> "sptr"
; DesiredAccess : DWORD -> "int"
; Privileges : PRIVILEGE_SET* -> "var"
; AccessGranted : BOOL -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; BOOL ObjectPrivilegeAuditAlarmA(LPCSTR SubsystemName, void* HandleId, HANDLE ClientToken, DWORD DesiredAccess, PRIVILEGE_SET* Privileges, BOOL AccessGranted)
#uselib "ADVAPI32.dll"
#cfunc global ObjectPrivilegeAuditAlarmA "ObjectPrivilegeAuditAlarmA" str, intptr, intptr, int, var, int
; res = ObjectPrivilegeAuditAlarmA(SubsystemName, HandleId, ClientToken, DesiredAccess, Privileges, AccessGranted)
; SubsystemName : LPCSTR -> "str"
; HandleId : void* -> "intptr"
; ClientToken : HANDLE -> "intptr"
; DesiredAccess : DWORD -> "int"
; Privileges : PRIVILEGE_SET* -> "var"
; AccessGranted : BOOL -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	advapi32 = windows.NewLazySystemDLL("ADVAPI32.dll")
	procObjectPrivilegeAuditAlarmA = advapi32.NewProc("ObjectPrivilegeAuditAlarmA")
)

// SubsystemName (LPCSTR), HandleId (void*), ClientToken (HANDLE), DesiredAccess (DWORD), Privileges (PRIVILEGE_SET*), AccessGranted (BOOL)
r1, _, err := procObjectPrivilegeAuditAlarmA.Call(
	uintptr(unsafe.Pointer(windows.BytePtrFromString(SubsystemName))),
	uintptr(HandleId),
	uintptr(ClientToken),
	uintptr(DesiredAccess),
	uintptr(Privileges),
	uintptr(AccessGranted),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // BOOL
function ObjectPrivilegeAuditAlarmA(
  SubsystemName: PAnsiChar;   // LPCSTR
  HandleId: Pointer;   // void*
  ClientToken: THandle;   // HANDLE
  DesiredAccess: DWORD;   // DWORD
  Privileges: Pointer;   // PRIVILEGE_SET*
  AccessGranted: BOOL   // BOOL
): BOOL; stdcall;
  external 'ADVAPI32.dll' name 'ObjectPrivilegeAuditAlarmA';
result := DllCall("ADVAPI32\ObjectPrivilegeAuditAlarmA"
    , "AStr", SubsystemName   ; LPCSTR
    , "Ptr", HandleId   ; void*
    , "Ptr", ClientToken   ; HANDLE
    , "UInt", DesiredAccess   ; DWORD
    , "Ptr", Privileges   ; PRIVILEGE_SET*
    , "Int", AccessGranted   ; BOOL
    , "Int")   ; return: BOOL
●ObjectPrivilegeAuditAlarmA(SubsystemName, HandleId, ClientToken, DesiredAccess, Privileges, AccessGranted) = DLL("ADVAPI32.dll", "bool ObjectPrivilegeAuditAlarmA(char*, void*, void*, dword, void*, bool)")
# 呼び出し: ObjectPrivilegeAuditAlarmA(SubsystemName, HandleId, ClientToken, DesiredAccess, Privileges, AccessGranted)
# SubsystemName : LPCSTR -> "char*"
# HandleId : void* -> "void*"
# ClientToken : HANDLE -> "void*"
# DesiredAccess : DWORD -> "dword"
# Privileges : PRIVILEGE_SET* -> "void*"
# AccessGranted : BOOL -> "bool"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。