SeQuerySigningPolicyWorker
NTSTATUS __stdcall SeQuerySigningPolicyWorker(
VOID *ProcessToken,
_UNICODE_STRING *ImagePath,
UINT64 Flags,
PS_PROTECTION RequestedProtection,
UINT8 *ExeSigningLevel,
UINT8 *DllSigningLevel,
PS_PROTECTION *Protection){
char v8;
UINT8 *v11;
int v12;
UINT8 v13;
FEATURE_LOGGED_TRAITS *traits;
UINT64 v16;
wil_details_FeatureReportingCache *v17;
unsigned __int8 Level;
unsigned __int8 v19;
UINT8 v20;
NTSTATUS v21;
INT64 enabled;
VOID *TokenInformation;
__int64 v24;
__int64 v25[3];
unsigned __int8 *v26;
v8 = Flags;
v24 = 0i64;
HIDWORD(TokenInformation) = 0;
v25[0] = 0i64;
v25[1] = 0i64;
LODWORD(v11) = AppModelPolicy_GetPolicy_Internal(
(_DWORD)ProcessToken,
(_DWORD)ImagePath,
(unsigned int)&TokenInformation + 4,
(unsigned int)&v24,
(__int64)v25);
if( (int)v11 >= 0 )
{
v12 = HIDWORD(TokenInformation);
if( (unsigned int)(HIDWORD(TokenInformation) - 3014657) <= 1 )
{
LODWORD(enabled) = 1;
if( CmIsStateSeparationEnabled() )
{
traits = (FEATURE_LOGGED_TRAITS *)&Feature_LogErrorRecords_logged_traits;
v16 = 17895887i64;
v17 = (wil_details_FeatureReportingCache *)((char *)&stru_140CF2E80 + 6592);
}
else
{
traits = (FEATURE_LOGGED_TRAITS *)&Feature_SchedulerAssistHRTimer_logged_traits;
v16 = 15816256i64;
v17 = (wil_details_FeatureReportingCache *)((char *)&WheapErrorSourceTable + 984);
}
wil_details_FeatureReporting_ReportUsageToService(v17, v16, 0i64, 0i64, traits, enabled);
if( v12 != 3014658 || (unsigned int)BYTE4(v24) - 4 <= 1 )
{
if( (v8 & 1) == 0 )
{
if( BYTE4(v24) <= 1u )
{
v13 = (unsigned __int8)ExeSigningLevel;
}
else
{
if( BYTE4(v24) == 2 )
{
*DllSigningLevel = 8;
Protection->Level = (unsigned __int8)ExeSigningLevel;
goto LABEL_8;
}
if( BYTE4(v24) == 3 )
{
v13 = 6;
}
else
{
if( BYTE4(v24) <= 3u )
goto LABEL_9;
if( BYTE4(v24) <= 5u )
{
v20 = (_BYTE)ExeSigningLevel != 0 ? 3 : 0;
*DllSigningLevel = v20;
Protection->Level = v20;
goto LABEL_8;
}
if( BYTE4(v24) != 6 )
goto LABEL_9;
v13 = (_BYTE)ExeSigningLevel != 2 ? 0 : 2;
}
}
*DllSigningLevel = v13;
goto LABEL_7;
}
if( !RequestedProtection.Level )
{
*DllSigningLevel = 4;
Protection->Level = 4;
*v26 = 18;
goto LABEL_9;
}
}
}
if( ImagePath && SepIsNgenImage(ImagePath) )
{
LODWORD(TokenInformation) = 0;
v21 = SeQueryInformationToken(ProcessToken, TokenIsAppContainer, &TokenInformation);
v11 = (UINT8 *)(unsigned int)v21;
if( v21 < 0 )
return(int)v11;
*DllSigningLevel = 11;
if( (v8 & 1) == 0 )
{
LOBYTE(v11) = (_BYTE)ExeSigningLevel;
if( !(_DWORD)TokenInformation )
{
Protection->Level = (unsigned __int8)ExeSigningLevel;
*v26 = (unsigned __int8)ExeSigningLevel >= 2u ? 0x21 : 0;
goto LABEL_9;
}
LODWORD(v11) = SepIsLockedDown(v11);
if( (int)v11 < 0 )
return(int)v11;
v13 = (_BYTE)ExeSigningLevel != 2 ? 0 : 2;
goto LABEL_7;
}
if( !RequestedProtection.Level )
{
Protection->Level = (_DWORD)TokenInformation != 0 ? 6 : 8;
*v26 = 33;
goto LABEL_9;
}
}
if( (v8 & 1) != 0 )
{
Level = RequestedProtection.Level;
if( !RequestedProtection.Level )
Level = 18;
*v26 = Level;
*DllSigningLevel = *((_BYTE *)&SeProtectedMapping + 2 * ((unsigned __int64)Level >> 4));
v19 = *((_BYTE *)&SeProtectedMapping + 2 * ((unsigned __int64)*v26 >> 4) + 1);
Protection->Level = v19;
if( (unsigned __int8)ExeSigningLevel > *DllSigningLevel )
{
*DllSigningLevel = (unsigned __int8)ExeSigningLevel;
v19 = Protection->Level;
}
if( (unsigned __int8)ExeSigningLevel > v19 )
Protection->Level = (unsigned __int8)ExeSigningLevel;
goto LABEL_9;
}
v13 = (unsigned __int8)ExeSigningLevel;
*DllSigningLevel = (unsigned __int8)ExeSigningLevel;
LABEL_7:
Protection->Level = v13;
LABEL_8:
*v26 = 0;
LABEL_9:
LODWORD(v11) = 0;
}
return(int)v11;
}Referenced by:
SeQuerySigningPolicy