Difference between revisions of "Truxton child file get modified"
Jump to navigation
Jump to search
(→Sample) |
(→Sample) |
||
| (4 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
This retrieves the modified (last write) date of the file. | This retrieves the modified (last write) date of the file. | ||
| + | This corresponds to the <code>[LastWrite]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table. | ||
=Syntax= | =Syntax= | ||
| − | < | + | <source lang="C"> |
uint64_t truxton_child_file_get_modified( uint64_t child_handle ); | uint64_t truxton_child_file_get_modified( uint64_t child_handle ); | ||
| − | </ | + | </source> |
=Parameters= | =Parameters= | ||
==<code>child_handle</code>== | ==<code>child_handle</code>== | ||
| − | |||
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call. | The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call. | ||
| Line 15: | Line 15: | ||
=Sample= | =Sample= | ||
| − | + | <source lang="C" highlight="28"> | |
| − | < | + | void add_folder( uint64_t truxton, uint64_t parent_file ) |
| − | void add_folder(uint64_t truxton, uint64_t parent_file) | ||
{ | { | ||
| − | truxton_start_adding_files(truxton); | + | truxton_start_adding_files( truxton ); |
| − | uint64_t child = truxton_child_file_create(truxton); | + | uint64_t child = truxton_child_file_create( truxton ); |
char id[40]; | char id[40]; | ||
| − | truxton_file_get_id(parent_file, id, sizeof(id)); | + | truxton_file_get_id( parent_file, id, sizeof(id) ); |
| − | truxton_child_file_set_parent_id(child, id); | + | truxton_child_file_set_parent_id( child, id ); |
| − | truxton_child_file_set_type(child, Type_Directory); | + | truxton_child_file_set_type( child, Type_Directory ); |
| − | truxton_child_file_set_name(child, "Custom Exploits Folder") | + | truxton_child_file_set_name( child, "Custom Exploits Folder" ); |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | + | uint64_t now = truxton_time_now(); | |
| − | |||
| − | truxton_child_file_set_created(child, | + | truxton_child_file_set_created( child, now ); |
| − | truxton_child_file_set_accessed(child, | + | truxton_child_file_set_accessed( child, now ); |
| − | truxton_child_file_set_modified(child, | + | truxton_child_file_set_modified( child, now ); |
| − | truxton_child_file_set_origin(child, ORIGIN_GENERATED); | + | truxton_child_file_set_origin( child, ORIGIN_GENERATED ); |
| − | if ( truxton_child_file_save(child) == 0 ) | + | if ( truxton_child_file_save( child ) == 0 ) |
{ | { | ||
printf( "Failed to add child to Truxton\n" ); | printf( "Failed to add child to Truxton\n" ); | ||
| Line 51: | Line 43: | ||
else | else | ||
{ | { | ||
| − | ticks.QuadPart = truxton_child_file_get_modified(child_file); | + | ticks.QuadPart = truxton_child_file_get_modified( child_file ); |
printf( "Tick count is %" PRIu64 "\n", ticks.QuadPart ); | printf( "Tick count is %" PRIu64 "\n", ticks.QuadPart ); | ||
} | } | ||
| − | truxton_child_file_destroy(child); | + | truxton_child_file_destroy( child ); |
} | } | ||
| − | </ | + | </source> |
Note, the <code>PRIu64</code> in the sample code above is the new standard way of [https://en.wikipedia.org/wiki/C_data_types#Printf_and_scanf_format_specifiers formatting] a 64-bit integer in C. | Note, the <code>PRIu64</code> in the sample code above is the new standard way of [https://en.wikipedia.org/wiki/C_data_types#Printf_and_scanf_format_specifiers formatting] a 64-bit integer in C. | ||
Over the years, different compilers on different operating systems used different format specifiers for things, these <code>PRI</code> macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic. | Over the years, different compilers on different operating systems used different format specifiers for things, these <code>PRI</code> macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic. | ||
Latest revision as of 03:01, 14 April 2024
This retrieves the modified (last write) date of the file.
This corresponds to the [LastWrite] column of the [File] table.
Syntax
uint64_t truxton_child_file_get_modified( uint64_t child_handle );
Parameters
child_handle
The handle created by the truxton_child_file_create or truxton_file_create_child call.
Return value
The modified date of the file in FILETIME ticks.
Sample
void add_folder( uint64_t truxton, uint64_t parent_file )
{
truxton_start_adding_files( truxton );
uint64_t child = truxton_child_file_create( truxton );
char id[40];
truxton_file_get_id( parent_file, id, sizeof(id) );
truxton_child_file_set_parent_id( child, id );
truxton_child_file_set_type( child, Type_Directory );
truxton_child_file_set_name( child, "Custom Exploits Folder" );
uint64_t now = truxton_time_now();
truxton_child_file_set_created( child, now );
truxton_child_file_set_accessed( child, now );
truxton_child_file_set_modified( child, now );
truxton_child_file_set_origin( child, ORIGIN_GENERATED );
if ( truxton_child_file_save( child ) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
else
{
ticks.QuadPart = truxton_child_file_get_modified( child_file );
printf( "Tick count is %" PRIu64 "\n", ticks.QuadPart );
}
truxton_child_file_destroy( child );
}
Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.