SeAccessCheckWithHintWithAdminlessChecks

BOOL __stdcall SeAccessCheckWithHintWithAdminlessChecks(
        UINT64 *SecurityDescriptor,
        CHAR dl0,
        INT64 a3,
        CHAR a4,
        UINT64 a5,
        INT64 a6,
        PRIVILEGE_SET **a7,
        INT64 *a8,
        CHAR PreviousMode,
        UINT64 *a10,
        INT64 *a11,
        CHAR a12){
  INT64 *v12; 
  unsigned int *v13; 
  int v14; 
  int v17; 
  __int16 v18; 
  unsigned int v19; 
  char *v20; 
  char *v21; 
  unsigned int v22; 
  int v23; 
  _TOKEN *v24; 
  NTSTATUS v25; 
  INT64 *v26; 
  UINT8 v27; 
  char v28; 
  CHAR v29; 
  NTSTATUS v30; 
  INT64 *v31; 
  char v32; 
  unsigned __int8 *v33; 
  _SID_AND_ATTRIBUTES_HASH *p_SidHash; 
  int v35; 
  __int64 v36; 
  unsigned int v37; 
  unsigned __int64 v38; 
  __int64 v39; 
  int v40; 
  unsigned __int64 v41; 
  int v42; 
  __int64 SidAttr; 
  _SID_AND_ATTRIBUTES *v44; 
  UINT8 TokenIsOwner; 
  __int16 v46; 
  char *v47; 
  _WORD *SeOwnerRightsSid; 
  int v49; 
  int v50; 
  int v51; 
  unsigned int SidCount; 
  _SECURITY_SUBJECT_CONTEXT *v53; 
  _TOKEN *ClientToken; 
  _TOKEN *PrimaryToken; 
  char v56; 
  _RTL_DYNAMIC_HASH_TABLE_ENTRY *v57; 
  char v58; 
  INT64 *v59; 
  UINT64 *v60; 
  char v61; 
  char v62; 
  void *v63; 
  BOOL result; 
  __int64 v65; 
  INT64 *v66; 
  __int64 v67; 
  __int64 v68; 
  unsigned __int8 *v69; 
  unsigned int v70; 
  int v71; 
  unsigned int v72; 
  __int64 v73; 
  unsigned __int8 *v74; 
  unsigned __int64 v75; 
  int v76; 
  int v77; 
  VOID *v78; 
  int v79; 
  VOID *v80; 
  VOID *v81; 
  NTSTATUS v82; 
  bool v83; 
  VOID *v84; 
  VOID *TokenTrustLevel; 
  _SEP_LOGON_SESSION_REFERENCES *LogonSession; 
  __int16 v87; 
  __int64 v88; 
  _ACL *v89; 
  VOID *ScopedPolicySid; 
  NTSTATUS Cap; 
  _RTL_DYNAMIC_HASH_TABLE_ENTRY *v92; 
  __int64 v93; 
  unsigned int v94; 
  int v95; 
  unsigned int v96; 
  int v97; 
  _RTL_DYNAMIC_HASH_TABLE_ENTRY *v98; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v99; 
  NTSTATUS v100; 
  int v101; 
  _AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *pClaimAttributes; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedDeviceSecurityAttributes; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pDeviceSecurityAttributes; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedUserSecurityAttributes; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pUserSecurityAttributes; 
  NTSTATUS v107; 
  int v108; 
  NTSTATUS v109; 
  _AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *v110; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v111; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v112; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v113; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v114; 
  NTSTATUS v115; 
  int v116; 
  int v117; 
  int v118; 
  _SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *Blink; 
  UINT8 v120; 
  _SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *v121; 
  int v122; 
  int v123; 
  int v124; 
  _SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *v125; 
  INT64 v126; 
  INT64 v127; 
  _SEP_MANDATORY_INFORMATION *MandatoryInformation; 
  __int128 *ObjectTypeListLength; 
  UINT64 ObjectTypeListLengtha; 
  UINT64 PreviouslyGrantedAccess; 
  UINT64 PreviouslyGrantedAccessa; 
  UINT8 ReturnSomeAccessGranted; 
  CHAR v134; 
  char v135; 
  UINT8 pbDominate; 
  UINT8 v137; 
  char v138; 
  int v139; 
  int v140; 
  char v141; 
  int v142; 
  INT64 *AccessStatus; 
  _RTL_DYNAMIC_HASH_TABLE_ENTRY *v144; 
  UINT64 *GrantedAccess; 
  unsigned int v146; 
  INT64 ResourceInfo; 
  INT64 Result; 
  _RTL_DYNAMIC_HASH_TABLE_ENTRY *a2; 
  UINT64 v150; 
  _SECURITY_SUBJECT_CONTEXT *SubjectContext; 
  INT64 v152; 
  VOID *SecurityDescriptora; 
  _ACL *pSacl; 
  _WORD *v155; 
  __int128 v156; 
  _GENERIC_MAPPING *GenericMapping; 
  INT64 v158; 
  __int64 v159; 
  _PRIVILEGE_SET **Privileges; 
  __int128 CapeSecurityDescriptor[2]; 
  __int64 v162; 
  _BYTE PackageCapabilityInfo[28]; 

  v12 = a11;
  v13 = (unsigned int *)SecurityDescriptor;
  v14 = a5;
  SecurityDescriptora = SecurityDescriptor;
  *(_QWORD *)&PackageCapabilityInfo[16] = 0i64;
  *(_DWORD *)&PackageCapabilityInfo[24] = 0;
  v162 = 0i64;
  v135 = 0;
  v17 = -1;
  LODWORD(v158) = -1;
  SubjectContext = (_SECURITY_SUBJECT_CONTEXT *)a3;
  v134 = a4;
  v139 = a6;
  AccessStatus = a11;
  *(_DWORD *)a10 = 0;
  GrantedAccess = a10;
  Privileges = a7;
  GenericMapping = (_GENERIC_MAPPING *)a8;
  ReturnSomeAccessGranted = 0;
  pSacl = 0i64;
  a2 = 0i64;
  v140 = 0;
  ResourceInfo = 0i64;
  LODWORD(Result) = 0;
  *(_DWORD *)a11 = -1073741790;
  LODWORD(v150) = 0;
  LODWORD(v152) = -1073741790;
  HIDWORD(v150) = dl0 & 8;
  v156 = 0i64;
  *(_OWORD *)PackageCapabilityInfo = 0i64;
  memset(CapeSecurityDescriptor, 0, sizeof(CapeSecurityDescriptor));
  if( a7 )
    *a7 = 0i64;
  if( !PreviousMode )
  {
    if( (a5 & 0x2000000) != 0 )
      v76 = a6 | a5 & 0xFDFFFFFF | *((_DWORD *)a8 + 3);
    else
      v76 = a6 | a5;
    *(_DWORD *)a10 = v76;
    result = 1;
    *(_DWORD *)a11 = 0;
    return result;
  }
  if( !SecurityDescriptor )
    goto LABEL_310;
  if( *(_QWORD *)a3 && *(int *)(a3 + 8) < 2 )
  {
    *(_DWORD *)a11 = -1073741659;
    return 0;
  }
  if( !(_DWORD)a5 )
  {
    if( (_DWORD)a6 )
    {
      *(_DWORD *)a10 = a6;
      *(_DWORD *)a11 = 0;
      if( a7 )
        *a7 = 0i64;
      return 1;
    }
LABEL_310:
    *(_DWORD *)a11 = -1073741790;
    return 0;
  }
  if( !a4 )
    SeLockSubjectContext((PSECURITY_SUBJECT_CONTEXT)a3);
  v18 = *((_WORD *)v13 + 1);
  v19 = 0;
  pbDominate = 0;
  v137 = 0;
  while( 1 )
  {
    if( (v18 & 0x10) != 0 )
    {
      if( v18 >= 0 )
      {
        v20 = (char *)*((_QWORD *)v13 + 3);
        goto LABEL_13;
      }
      v67 = v13[3];
      if( (_DWORD)v67 )
        break;
    }
LABEL_18:
    v21 = 0i64;
LABEL_19:
    ++v19;
    if( !v21 )
      goto LABEL_20;
  }
  v20 = (char *)v13 + v67;
LABEL_13:
  if( !v20 )
    goto LABEL_18;
  v21 = v20 + 8;
  v22 = 0;
  if( !*((_WORD *)v20 + 2) )
    goto LABEL_18;
  while( v22 < v19 || *v21 != 20 )
  {
    ++v22;
    v21 += *((unsigned __int16 *)v21 + 1);
    if( v22 >= *((unsigned __int16 *)v20 + 2) )
      goto LABEL_18;
  }
  v19 = v22;
  if( (v21[1] & 8) != 0 )
    goto LABEL_19;
  if( v21 )
  {
    v79 = *((_DWORD *)v21 + 1);
    v80 = v21 + 8;
    if( v21 == (char *)-8i64 )
    {
      v12 = AccessStatus;
    }
    else
    {
      if( !*(_QWORD *)a3 )
        goto LABEL_179;
      v81 = *(VOID **)(*(_QWORD *)a3 + 1104i64);
      v82 = RtlSidDominatesForTrust(*(VOID **)(*(_QWORD *)(a3 + 16) + 1104i64), v81, &v137);
      if( v82 >= 0 )
      {
        if( !v137 )
LABEL_179:
          v81 = *(VOID **)(*(_QWORD *)(a3 + 16) + 1104i64);
        v82 = RtlSidDominatesForTrust(v81, v80, &pbDominate);
        if( v82 >= 0 )
        {
          v17 = v79 | 0x1000000;
          if( pbDominate )
            v17 = -1;
        }
      }
      v12 = AccessStatus;
      *(_DWORD *)AccessStatus = v82;
      if( v82 < 0 )
      {
LABEL_184:
        if( v134 )
          return 0;
        goto LABEL_155;
      }
    }
  }
LABEL_20:
  v23 = a5 & 0xFDFFFFFF;
  if( (v17 & a5 & 0xFDFFFFFF) != (a5 & 0xFDFFFFFF) )
  {
    v83 = HIDWORD(v150) == 0;
    *(_DWORD *)v12 = -1073741790;
    if( v83 )
    {
      v84 = *(VOID **)a3;
      if( !*(_QWORD *)a3 )
        v84 = *(VOID **)(a3 + 16);
      TokenTrustLevel = SepLocateTokenTrustLevel((_SECURITY_SUBJECT_CONTEXT *)a3);
      SeLogAccessFailure(v84, 0i64, 0i64, (UINT64)TokenTrustLevel, (UINT8)v13);
    }
    if( v134 )
      return 0;
    goto LABEL_155;
  }
  *(_DWORD *)v12 = 0;
  v24 = *(_TOKEN **)a3;
  if( !*(_QWORD *)a3 )
    v24 = *(_TOKEN **)(a3 + 16);
  if( (dl0 & 4) == 0 )
  {
    v25 = SepFilterCheck((INT64)v13, &ResourceInfo, v24, 0, (INT64)&v158);
    v26 = AccessStatus;
    *(_DWORD *)AccessStatus = v25;
    if( v25 < 0 )
      goto LABEL_184;
    if( ((unsigned int)v158 & v23) == v23 )
    {
      *(_DWORD *)v26 = 0;
      goto LABEL_27;
    }
    v83 = HIDWORD(v150) == 0;
    *(_DWORD *)v26 = -1073741790;
    if( v83 )
      SeLogAccessFailure(v24, 0i64, 0i64, 0i64, (UINT8)v13);
    if( v134 )
      return 0;
LABEL_155:
    SeUnlockSubjectContext((PSECURITY_SUBJECT_CONTEXT)a3);
    return 0;
  }
  v26 = AccessStatus;
LABEL_27:
  if( (dl0 & 2) == 0 )
  {
    v27 = 0;
    goto LABEL_29;
  }
  v27 = 1;
  if( (v24->TokenFlags & 0x2000) != 0 )
    v28 = 1;
  else
LABEL_29:
    v28 = 0;
  v141 = v28;
  v138 = 0;
  if( !SepAllowAccessUponLogoff && (v24->TokenFlags & 0x20) == 0 )
  {
    LogonSession = v24->LogonSession;
    if( LogonSession )
    {
      if( (LogonSession->Flags & 0x20) != 0 )
      {
        v83 = v134 == 0;
        *(_DWORD *)GrantedAccess = 0;
        *(_DWORD *)v26 = -1073741790;
        if( !v83 )
          return 0;
        goto LABEL_155;
      }
    }
  }
  v29 = a12;
  if( !v28 )
  {
    ObjectTypeListLength = &v156;
    LOBYTE(MandatoryInformation) = a12;
    v30 = SepMandatoryIntegrityCheck(GenericMapping, (_SECURITY_DESCRIPTOR *)v13, v27, v24, 0, MandatoryInformation);
    v31 = AccessStatus;
    *(_DWORD *)AccessStatus = v30;
    if( v30 < 0 )
      goto LABEL_184;
    if( DWORD2(v156) && (v23 & (unsigned int)v156) != v23 )
    {
      *(_DWORD *)v31 = -1073741790;
      if( (v24->TokenFlags & 0x4000) == 0 || HIDWORD(v156) > 0x2000 )
      {
        if( v134 )
          return 0;
        goto LABEL_155;
      }
    }
    else
    {
      *(_DWORD *)v31 = 0;
      if( (a5 & 0x2000000) == 0 || (v24->TokenFlags & 0x4000) == 0 || HIDWORD(v156) > 0x2000 )
      {
LABEL_36:
        v29 = a12;
        goto LABEL_37;
      }
    }
    v138 = 1;
    goto LABEL_36;
  }
LABEL_37:
  if( !SepRmEnforceCap )
  {
LABEL_38:
    v32 = 0;
    goto LABEL_39;
  }
  v87 = *((_WORD *)v13 + 1);
  if( (v87 & 0x10) == 0 || KeGetCurrentIrql() >= 2u )
  {
LABEL_217:
    v29 = a12;
    goto LABEL_38;
  }
  if( v87 >= 0 )
  {
    v89 = (_ACL *)*((_QWORD *)v13 + 3);
  }
  else
  {
    v88 = v13[3];
    if( !(_DWORD)v88 )
    {
      pSacl = 0i64;
      goto LABEL_217;
    }
    v89 = (_ACL *)((char *)v13 + v88);
  }
  pSacl = v89;
  if( !v89 )
    goto LABEL_217;
  ScopedPolicySid = SepGetScopedPolicySid(v89);
  if( !ScopedPolicySid )
    goto LABEL_217;
  Cap = SepRmReferenceFindCap(ScopedPolicySid, (_SEP_CENTRALIZED_ACCESS_POLICY **)&a2);
  v92 = a2;
  v29 = a12;
  v32 = 1;
  if( Cap < 0 )
    v92 = (_RTL_DYNAMIC_HASH_TABLE_ENTRY *)SepRmDefaultCap;
  a2 = v92;
  v135 = 1;
LABEL_39:
  if( (dl0 & 1) != 0 )
  {
    v137 = 1;
    if( (a5 & 0x2060000) == 0 && !v32 )
    {
      TokenIsOwner = 0;
      goto LABEL_70;
    }
  }
  else
  {
    v137 = 0;
  }
  if( *((__int16 *)v13 + 1) < 0 )
  {
    v65 = v13[1];
    if( (_DWORD)v65 )
      v33 = (unsigned __int8 *)v13 + v65;
    else
      v33 = 0i64;
  }
  else
  {
    v33 = (unsigned __int8 *)*((_QWORD *)v13 + 1);
  }
  p_SidHash = &v24->SidHash;
  if( v29 && v33 && RtlEqualSid(SeAliasAdminsSid, v33) )
  {
    TokenIsOwner = 0;
    goto LABEL_56;
  }
  if( v24 == (_TOKEN *)-232i64 || !v33 )
    goto LABEL_68;
  v35 = v33[1];
  v36 = *(unsigned __int16 *)v33;
  v159 = v36;
  v37 = 4 * v35 + 8;
  v146 = v37;
  v38 = (unsigned __int64)v33[4 * ((unsigned __int64)(unsigned int)v36 >> 8) + 4] >> 4;
  v39 = v33[4 * ((unsigned __int64)(unsigned int)v36 >> 8) + 4] & 0xF;
  LOBYTE(v40) = 0;
  pbDominate = 0;
  v41 = p_SidHash->Hash[v39] & p_SidHash->Hash[v38 + 16];
  if( !v41 )
    goto LABEL_66;
  while( 2 )
  {
    LOBYTE(v42) = v41;
    v142 = (unsigned __int8)v41;
    if( !(_BYTE)v41 )
      goto LABEL_135;
    SidAttr = (__int64)v24->SidHash.SidAttr;
    v40 = (unsigned __int8)v40;
    v155 = (_WORD *)SidAttr;
    HIDWORD(Result) = (unsigned __int8)v40;
    while( 2 )
    {
      LODWORD(v144) = *((unsigned __int8 *)SidHashByteToIndexLookupTable + (unsigned __int8)v42);
      v44 = (_SID_AND_ATTRIBUTES *)(SidAttr + 16i64 * (unsigned int)(v40 + (_DWORD)v144));
      if( *(_WORD *)v44->Sid == (_WORD)v36 )
      {
        if( !memcmp(v33, v44->Sid, v37) )
        {
LABEL_51:
          if( v44 == v24->SidHash.SidAttr && (v44->Attributes & 0x10) == 0 || (v44->Attributes & 4) != 0 )
          {
            if( v24->RestrictedSidCount )
              TokenIsOwner = SepSidInTokenSidHash(&v24->RestrictedSidHash, 0i64, v33, 0, 1u, 0);
            else
              TokenIsOwner = 1;
          }
          else
          {
            TokenIsOwner = 0;
          }
          v13 = (unsigned int *)SecurityDescriptora;
LABEL_56:
          if( !TokenIsOwner || (a5 & 0x2060000) == 0 )
            goto LABEL_69;
          if( v137 )
            goto LABEL_62;
          v46 = *((_WORD *)v13 + 1);
          if( (v46 & 4) != 0 )
          {
            if( v46 >= 0 )
            {
              v47 = (char *)*((_QWORD *)v13 + 4);
            }
            else
            {
              v68 = v13[4];
              v47 = (_DWORD)v68 ? (char *)v13 + v68 : 0i64;
            }
          }
          else
          {
            v47 = 0i64;
          }
          SeOwnerRightsSid = SeExports->SeOwnerRightsSid;
          v155 = SeOwnerRightsSid;
          if( !v47
            || (v69 = (unsigned __int8 *)(v47 + 8),
                LODWORD(v144) = *((unsigned __int16 *)v47 + 2),
                v70 = 0,
                !(_DWORD)v144) )
          {
LABEL_62:
            v32 = v135;
            v49 = 393216;
            if( (a5 & 0x2000000) == 0 )
              v49 = a5 & 0x60000;
            v14 = a5 & 0xFFF9FFFF;
            v50 = v139 | v49;
            v139 = v50;
            v51 = v50;
            if( !v135 )
            {
              TokenIsOwner = 0;
              v139 = v50;
            }
            goto LABEL_71;
          }
          v71 = 104928;
          while( 2 )
          {
            if( (v69[1] & 8) != 0 )
              goto LABEL_117;
            v72 = *v69;
            if( (unsigned __int8)v72 <= 0x10u && _bittest(&v71, v72) )
            {
              v73 = 16i64 * (*((_DWORD *)v69 + 2) & 1) + ((8i64 * (*((_DWORD *)v69 + 2) & 2)) | 0xC);
            }
            else
            {
              if( (_BYTE)v72 != 4 )
              {
                if( (unsigned __int8)v72 < 0xBu || (unsigned __int8)(v72 - 13) <= 1u )
                {
                  v73 = 8i64;
                  break;
                }
LABEL_117:
                ++v70;
                v69 += *((unsigned __int16 *)v69 + 1);
                if( v70 >= (unsigned int)v144 )
                  goto LABEL_62;
                continue;
              }
              v73 = 12i64;
            }
            break;
          }
          v74 = &v69[v73];
          if( v74 )
          {
            v75 = *(unsigned __int16 *)v74;
            if( (_WORD)v75 == *SeOwnerRightsSid )
            {
              if( !memcmp(v74, SeOwnerRightsSid, 4 * (v75 >> 8) + 8) )
                goto LABEL_69;
              SeOwnerRightsSid = v155;
              v71 = 104928;
            }
          }
          goto LABEL_117;
        }
        LOWORD(v36) = v159;
        v37 = v146;
        v40 = HIDWORD(Result);
      }
      v42 = (unsigned __int8)v142 ^ (1 << (char)v144);
      SidAttr = (__int64)v155;
      v142 = v42;
      if( (_BYTE)v42 )
        continue;
      break;
    }
    LOBYTE(v40) = pbDominate;
LABEL_135:
    LOBYTE(v40) = v40 + 8;
    v41 >>= 8;
    pbDominate = v40;
    if( v41 )
      continue;
    break;
  }
LABEL_66:
  SidCount = p_SidHash->SidCount;
  if( p_SidHash->SidCount > 0x40 )
  {
    v93 = (__int64)v24->SidHash.SidAttr;
    v94 = 64;
    v142 = 64;
    v155 = (_WORD *)v93;
    do
    {
      v44 = (_SID_AND_ATTRIBUTES *)(v93 + 16i64 * v94);
      if( *(_WORD *)v44->Sid == (_WORD)v36 )
      {
        if( !memcmp(v33, v44->Sid, v37) )
          goto LABEL_51;
        LOWORD(v36) = v159;
        v37 = v146;
        v94 = v142;
        v93 = (__int64)v155;
      }
      v142 = ++v94;
    }
    while( v94 < SidCount );
  }
  v13 = (unsigned int *)SecurityDescriptora;
LABEL_68:
  TokenIsOwner = 0;
LABEL_69:
  v32 = v135;
LABEL_70:
  v49 = v140;
  v51 = v139;
LABEL_71:
  if( !v14 && !v32 && ((v24->TokenFlags & 0x2000) != 0 || !v49) )
  {
    if( !v134 )
      SeUnlockSubjectContext(SubjectContext);
    v66 = AccessStatus;
    *(_DWORD *)GrantedAccess = v51;
    *(_DWORD *)v66 = 0;
    return 1;
  }
  v53 = SubjectContext;
  ClientToken = (_TOKEN *)SubjectContext->ClientToken;
  PrimaryToken = (_TOKEN *)SubjectContext->PrimaryToken;
  LODWORD(PreviouslyGrantedAccess) = v51;
  LODWORD(ObjectTypeListLength) = 0;
  *(_DWORD *)PackageCapabilityInfo = v49;
  memset(&PackageCapabilityInfo[4], 0, 24);
  LODWORD(v126) = v14;
  v56 = SepAccessCheck(
          v13,
          0i64,
          PrimaryToken,
          ClientToken,
          v126,
          0i64,
          (UINT64)ObjectTypeListLength,
          GenericMapping,
          PreviouslyGrantedAccess,
          PreviousMode,
          GrantedAccess,
          Privileges,
          AccessStatus,
          0,
          TokenIsOwner,
          (_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
          (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
          &ReturnSomeAccessGranted,
          0i64);
  v57 = a2;
  v58 = v56;
  v144 = a2;
  if( !SepRmEnforceCap || (v95 = *(_DWORD *)AccessStatus, v146 = v95, v95 < 0) || !v135 )
  {
    v59 = AccessStatus;
    v60 = GrantedAccess;
    goto LABEL_74;
  }
  v96 = 0;
  pbDominate = 0;
  LOBYTE(v142) = 0;
  HIDWORD(Result) = 0;
  v97 = *(_DWORD *)GrantedAccess;
  v140 = *(_DWORD *)GrantedAccess;
  if( !HIDWORD(a2[2].Linkage.Blink) )
    goto LABEL_290;
  while( 2 )
  {
    v98 = (_RTL_DYNAMIC_HASH_TABLE_ENTRY *)*(&v57[2].Signature + v96);
    a2 = v98;
    if( v98[1].Linkage.Flink )
    {
      v99 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
      if( !ResourceInfo )
      {
        v100 = AuthzBasepInitializeResourceClaimsFromSacl(
                 pSacl,
                 (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo);
        v99 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
        v101 = (unsigned __int8)v142;
        if( v100 < 0 )
          v101 = 1;
        v142 = v101;
      }
      pClaimAttributes = v24->pClaimAttributes;
      if( pClaimAttributes )
      {
        pRestrictedDeviceSecurityAttributes = pClaimAttributes->pRestrictedDeviceSecurityAttributes;
        pDeviceSecurityAttributes = pClaimAttributes->pDeviceSecurityAttributes;
        pRestrictedUserSecurityAttributes = pClaimAttributes->pRestrictedUserSecurityAttributes;
        pUserSecurityAttributes = pClaimAttributes->pUserSecurityAttributes;
      }
      else
      {
        pRestrictedDeviceSecurityAttributes = 0i64;
        pDeviceSecurityAttributes = 0i64;
        pRestrictedUserSecurityAttributes = 0i64;
        pUserSecurityAttributes = 0i64;
      }
      LODWORD(PreviouslyGrantedAccessa) = v98->Signature;
      v107 = AuthzBasepEvaluateAceCondition(
               v24,
               v24->pSecurityAttributes,
               v99,
               pUserSecurityAttributes,
               pRestrictedUserSecurityAttributes,
               pDeviceSecurityAttributes,
               pRestrictedDeviceSecurityAttributes,
               (UINT8 *)v98[1].Linkage.Flink,
               PreviouslyGrantedAccessa,
               1u,
               0,
               &Result);
      v108 = Result;
      v109 = v107;
      if( (_DWORD)Result != 1 )
      {
        if( v107 < 0 )
        {
          if( !v134 )
            SeUnlockSubjectContext(SubjectContext);
          Blink = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
          if( Blink )
            goto LABEL_279;
          goto LABEL_280;
        }
        if( (v24->TokenFlags & 0x10) != 0 )
        {
          v110 = v24->pClaimAttributes;
          if( v110 )
          {
            v111 = v110->pRestrictedDeviceSecurityAttributes;
            v112 = v110->pDeviceSecurityAttributes;
            v113 = v110->pRestrictedUserSecurityAttributes;
            v114 = v110->pUserSecurityAttributes;
          }
          else
          {
            v111 = 0i64;
            v112 = 0i64;
            v113 = 0i64;
            v114 = 0i64;
          }
          LODWORD(PreviouslyGrantedAccessa) = a2->Signature;
          v109 = AuthzBasepEvaluateAceCondition(
                   v24,
                   v24->pSecurityAttributes,
                   (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo,
                   v114,
                   v113,
                   v112,
                   v111,
                   (UINT8 *)a2[1].Linkage.Flink,
                   PreviouslyGrantedAccessa,
                   1u,
                   1u,
                   &Result);
          if( v109 >= 0 )
          {
            v108 = Result;
            goto LABEL_259;
          }
          if( !v134 )
            SeUnlockSubjectContext(SubjectContext);
          Blink = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
          if( Blink )
LABEL_279:
            SepRmDereferenceCapTable(Blink);
LABEL_280:
          *(_DWORD *)GrantedAccess = 0;
          *(_DWORD *)AccessStatus = v109;
LABEL_282:
          SepFreeResourceInfo((VOID *)ResourceInfo);
          return 0;
        }
LABEL_259:
        if( !(_BYTE)v142 && v108 != 1 )
        {
          v95 = v146;
          v53 = SubjectContext;
          goto LABEL_274;
        }
      }
      v98 = a2;
    }
    v115 = SepBuildCapeSecurityDescriptor(CapeSecurityDescriptor, v98[1].Linkage.Blink, pSacl);
    if( v115 < 0 )
    {
      if( !v134 )
        SeUnlockSubjectContext(SubjectContext);
      v121 = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
      if( v121 )
        SepRmDereferenceCapTable(v121);
      *(_DWORD *)GrantedAccess = 0;
      *(_DWORD *)AccessStatus = v115;
      goto LABEL_282;
    }
    v116 = v14;
    if( ((__int64)v98[2].Linkage.Flink & 1) != 0 )
    {
      v117 = 0;
      if( (v14 & 0x2000000) == 0 )
        v116 = v139 | v14;
    }
    else
    {
      v117 = v139;
    }
    v53 = SubjectContext;
    LODWORD(PreviouslyGrantedAccessa) = v117;
    LODWORD(ObjectTypeListLengtha) = 0;
    LODWORD(v127) = v116;
    v58 = SepAccessCheck(
            CapeSecurityDescriptor,
            0i64,
            (_TOKEN *)SubjectContext->PrimaryToken,
            (_TOKEN *)SubjectContext->ClientToken,
            v127,
            0i64,
            ObjectTypeListLengtha,
            GenericMapping,
            PreviouslyGrantedAccessa,
            PreviousMode,
            &v150,
            0i64,
            &v152,
            0,
            TokenIsOwner,
            (_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
            (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
            &ReturnSomeAccessGranted,
            0i64);
    if( pbDominate )
      v118 = v150 & v140;
    else
      v118 = v150;
    v140 = v118;
    if( v118 )
    {
      v95 = v152;
      v146 = v152;
      pbDominate = 1;
      if( (int)v152 < 0 )
        goto LABEL_288;
LABEL_274:
      v57 = v144;
      v96 = HIDWORD(Result) + 1;
      HIDWORD(Result) = v96;
      if( v96 >= HIDWORD(v144[2].Linkage.Blink) )
        goto LABEL_289;
      continue;
    }
    break;
  }
  v95 = -1073741790;
LABEL_288:
  v57 = v144;
LABEL_289:
  v97 = v140;
LABEL_290:
  v59 = AccessStatus;
  v60 = GrantedAccess;
  *(_DWORD *)AccessStatus = v95;
  v120 = ReturnSomeAccessGranted;
  *(_DWORD *)v60 &= v97;
  if( *(int *)v59 < 0 )
    v120 = 0;
  ReturnSomeAccessGranted = v120;
LABEL_74:
  if( !v141 && (v14 & 0x2000000) != 0 )
  {
    if( (!v138 || !PackageCapabilityInfo[21] && !PackageCapabilityInfo[22])
      && DWORD2(v156)
      && (!BYTE4(v156) || !BYTE5(v156) || !BYTE6(v156)) )
    {
      v77 = *(_DWORD *)v60 & v156;
      if( v77 != *(_DWORD *)v60 )
      {
        *(_DWORD *)v60 = v77;
        if( v77 )
        {
          *(_DWORD *)v59 = 0;
          ReturnSomeAccessGranted = 1;
        }
        else
        {
          *(_DWORD *)v59 = -1073741790;
LABEL_167:
          ReturnSomeAccessGranted = 0;
        }
      }
    }
  }
  else if( v138 && !PackageCapabilityInfo[21] && !PackageCapabilityInfo[22] )
  {
    *(_DWORD *)v59 = -1073741790;
    *(_DWORD *)v60 = 0;
    goto LABEL_167;
  }
  v61 = 0;
  if( (v14 & 0x2000000) != 0 )
  {
    if( v17 != -1 )
    {
      v122 = v17 & *(_DWORD *)v60;
      if( v122 != *(_DWORD *)v60 )
      {
        *(_DWORD *)v60 = v122;
        v61 = 1;
        if( v122 )
        {
          *(_DWORD *)v59 = 0;
          ReturnSomeAccessGranted = 1;
        }
        else
        {
          *(_DWORD *)v59 = -1073741790;
          ReturnSomeAccessGranted = 0;
        }
      }
    }
    v62 = 0;
    if( (_DWORD)v158 != -1 )
    {
      v123 = *(_DWORD *)v60;
      v124 = v158 & *(_DWORD *)v60;
      if( v124 != v123 )
      {
        v62 = 1;
        *(_DWORD *)GrantedAccess = v124;
        if( v124 )
        {
          *(_DWORD *)v59 = 0;
          ReturnSomeAccessGranted = 1;
        }
        else
        {
          *(_DWORD *)v59 = -1073741790;
          ReturnSomeAccessGranted = 0;
        }
      }
    }
  }
  else
  {
    v62 = 0;
  }
  if( v24 )
  {
    if( (v61
       || v62
       || !*(_DWORD *)&PackageCapabilityInfo[12]
       && (v24->TokenFlags & 0x4000) != 0
       && (*(int *)v59 < 0 || PackageCapabilityInfo[23]))
      && !HIDWORD(v150) )
    {
      v78 = SepLocateTokenTrustLevel(v53);
      SeLogAccessFailure(v24, 0i64, 0i64, (UINT64)v78, (UINT8)v13);
      v57 = v144;
      v59 = AccessStatus;
    }
    if( *(int *)v59 < 0
      && !*(_DWORD *)&PackageCapabilityInfo[12]
      && (v24->TokenFlags & 0x4000) != 0
      && PackageCapabilityInfo[24]
      && (v14 & ~(*(_DWORD *)&PackageCapabilityInfo[4] | *(_DWORD *)&PackageCapabilityInfo[8] | 0x2000000) & *(_DWORD *)&PackageCapabilityInfo[16]) == (v14 & ~(*(_DWORD *)&PackageCapabilityInfo[4] | *(_DWORD *)&PackageCapabilityInfo[8] | 0x2000000)) )
    {
      SepLogLpacAccessFailure();
      v57 = v144;
    }
  }
  if( v135 )
  {
    v125 = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v57[1].Linkage.Blink;
    if( v125 )
      SepRmDereferenceCapTable(v125);
  }
  if( !v134 )
    SeUnlockSubjectContext(v53);
  v63 = (void *)ResourceInfo;
  if( ResourceInfo )
  {
    AuthzBasepFreeSecurityAttributesList((_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo);
    ExFreePoolWithTag(v63, 0);
  }
  return v58 && ReturnSomeAccessGranted;
}

Referenced by:

SeAccessCheck
SeAccessCheckWithHint