SeAccessCheckWithHintWithAdminlessChecks
BOOL __stdcall SeAccessCheckWithHintWithAdminlessChecks(
UINT64 *SecurityDescriptor,
CHAR dl0,
INT64 a3,
CHAR a4,
UINT64 a5,
INT64 a6,
PRIVILEGE_SET **a7,
INT64 *a8,
CHAR PreviousMode,
UINT64 *a10,
INT64 *a11,
CHAR a12){
INT64 *v12;
unsigned int *v13;
int v14;
int v17;
__int16 v18;
unsigned int v19;
char *v20;
char *v21;
unsigned int v22;
int v23;
_TOKEN *v24;
NTSTATUS v25;
INT64 *v26;
UINT8 v27;
char v28;
CHAR v29;
NTSTATUS v30;
INT64 *v31;
char v32;
unsigned __int8 *v33;
_SID_AND_ATTRIBUTES_HASH *p_SidHash;
int v35;
__int64 v36;
unsigned int v37;
unsigned __int64 v38;
__int64 v39;
int v40;
unsigned __int64 v41;
int v42;
__int64 SidAttr;
_SID_AND_ATTRIBUTES *v44;
UINT8 TokenIsOwner;
__int16 v46;
char *v47;
_WORD *SeOwnerRightsSid;
int v49;
int v50;
int v51;
unsigned int SidCount;
_SECURITY_SUBJECT_CONTEXT *v53;
_TOKEN *ClientToken;
_TOKEN *PrimaryToken;
char v56;
_RTL_DYNAMIC_HASH_TABLE_ENTRY *v57;
char v58;
INT64 *v59;
UINT64 *v60;
char v61;
char v62;
void *v63;
BOOL result;
__int64 v65;
INT64 *v66;
__int64 v67;
__int64 v68;
unsigned __int8 *v69;
unsigned int v70;
int v71;
unsigned int v72;
__int64 v73;
unsigned __int8 *v74;
unsigned __int64 v75;
int v76;
int v77;
VOID *v78;
int v79;
VOID *v80;
VOID *v81;
NTSTATUS v82;
bool v83;
VOID *v84;
VOID *TokenTrustLevel;
_SEP_LOGON_SESSION_REFERENCES *LogonSession;
__int16 v87;
__int64 v88;
_ACL *v89;
VOID *ScopedPolicySid;
NTSTATUS Cap;
_RTL_DYNAMIC_HASH_TABLE_ENTRY *v92;
__int64 v93;
unsigned int v94;
int v95;
unsigned int v96;
int v97;
_RTL_DYNAMIC_HASH_TABLE_ENTRY *v98;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v99;
NTSTATUS v100;
int v101;
_AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *pClaimAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedDeviceSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pDeviceSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedUserSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pUserSecurityAttributes;
NTSTATUS v107;
int v108;
NTSTATUS v109;
_AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *v110;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v111;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v112;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v113;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v114;
NTSTATUS v115;
int v116;
int v117;
int v118;
_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *Blink;
UINT8 v120;
_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *v121;
int v122;
int v123;
int v124;
_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *v125;
INT64 v126;
INT64 v127;
_SEP_MANDATORY_INFORMATION *MandatoryInformation;
__int128 *ObjectTypeListLength;
UINT64 ObjectTypeListLengtha;
UINT64 PreviouslyGrantedAccess;
UINT64 PreviouslyGrantedAccessa;
UINT8 ReturnSomeAccessGranted;
CHAR v134;
char v135;
UINT8 pbDominate;
UINT8 v137;
char v138;
int v139;
int v140;
char v141;
int v142;
INT64 *AccessStatus;
_RTL_DYNAMIC_HASH_TABLE_ENTRY *v144;
UINT64 *GrantedAccess;
unsigned int v146;
INT64 ResourceInfo;
INT64 Result;
_RTL_DYNAMIC_HASH_TABLE_ENTRY *a2;
UINT64 v150;
_SECURITY_SUBJECT_CONTEXT *SubjectContext;
INT64 v152;
VOID *SecurityDescriptora;
_ACL *pSacl;
_WORD *v155;
__int128 v156;
_GENERIC_MAPPING *GenericMapping;
INT64 v158;
__int64 v159;
_PRIVILEGE_SET **Privileges;
__int128 CapeSecurityDescriptor[2];
__int64 v162;
_BYTE PackageCapabilityInfo[28];
v12 = a11;
v13 = (unsigned int *)SecurityDescriptor;
v14 = a5;
SecurityDescriptora = SecurityDescriptor;
*(_QWORD *)&PackageCapabilityInfo[16] = 0i64;
*(_DWORD *)&PackageCapabilityInfo[24] = 0;
v162 = 0i64;
v135 = 0;
v17 = -1;
LODWORD(v158) = -1;
SubjectContext = (_SECURITY_SUBJECT_CONTEXT *)a3;
v134 = a4;
v139 = a6;
AccessStatus = a11;
*(_DWORD *)a10 = 0;
GrantedAccess = a10;
Privileges = a7;
GenericMapping = (_GENERIC_MAPPING *)a8;
ReturnSomeAccessGranted = 0;
pSacl = 0i64;
a2 = 0i64;
v140 = 0;
ResourceInfo = 0i64;
LODWORD(Result) = 0;
*(_DWORD *)a11 = -1073741790;
LODWORD(v150) = 0;
LODWORD(v152) = -1073741790;
HIDWORD(v150) = dl0 & 8;
v156 = 0i64;
*(_OWORD *)PackageCapabilityInfo = 0i64;
memset(CapeSecurityDescriptor, 0, sizeof(CapeSecurityDescriptor));
if( a7 )
*a7 = 0i64;
if( !PreviousMode )
{
if( (a5 & 0x2000000) != 0 )
v76 = a6 | a5 & 0xFDFFFFFF | *((_DWORD *)a8 + 3);
else
v76 = a6 | a5;
*(_DWORD *)a10 = v76;
result = 1;
*(_DWORD *)a11 = 0;
return result;
}
if( !SecurityDescriptor )
goto LABEL_310;
if( *(_QWORD *)a3 && *(int *)(a3 + 8) < 2 )
{
*(_DWORD *)a11 = -1073741659;
return 0;
}
if( !(_DWORD)a5 )
{
if( (_DWORD)a6 )
{
*(_DWORD *)a10 = a6;
*(_DWORD *)a11 = 0;
if( a7 )
*a7 = 0i64;
return 1;
}
LABEL_310:
*(_DWORD *)a11 = -1073741790;
return 0;
}
if( !a4 )
SeLockSubjectContext((PSECURITY_SUBJECT_CONTEXT)a3);
v18 = *((_WORD *)v13 + 1);
v19 = 0;
pbDominate = 0;
v137 = 0;
while( 1 )
{
if( (v18 & 0x10) != 0 )
{
if( v18 >= 0 )
{
v20 = (char *)*((_QWORD *)v13 + 3);
goto LABEL_13;
}
v67 = v13[3];
if( (_DWORD)v67 )
break;
}
LABEL_18:
v21 = 0i64;
LABEL_19:
++v19;
if( !v21 )
goto LABEL_20;
}
v20 = (char *)v13 + v67;
LABEL_13:
if( !v20 )
goto LABEL_18;
v21 = v20 + 8;
v22 = 0;
if( !*((_WORD *)v20 + 2) )
goto LABEL_18;
while( v22 < v19 || *v21 != 20 )
{
++v22;
v21 += *((unsigned __int16 *)v21 + 1);
if( v22 >= *((unsigned __int16 *)v20 + 2) )
goto LABEL_18;
}
v19 = v22;
if( (v21[1] & 8) != 0 )
goto LABEL_19;
if( v21 )
{
v79 = *((_DWORD *)v21 + 1);
v80 = v21 + 8;
if( v21 == (char *)-8i64 )
{
v12 = AccessStatus;
}
else
{
if( !*(_QWORD *)a3 )
goto LABEL_179;
v81 = *(VOID **)(*(_QWORD *)a3 + 1104i64);
v82 = RtlSidDominatesForTrust(*(VOID **)(*(_QWORD *)(a3 + 16) + 1104i64), v81, &v137);
if( v82 >= 0 )
{
if( !v137 )
LABEL_179:
v81 = *(VOID **)(*(_QWORD *)(a3 + 16) + 1104i64);
v82 = RtlSidDominatesForTrust(v81, v80, &pbDominate);
if( v82 >= 0 )
{
v17 = v79 | 0x1000000;
if( pbDominate )
v17 = -1;
}
}
v12 = AccessStatus;
*(_DWORD *)AccessStatus = v82;
if( v82 < 0 )
{
LABEL_184:
if( v134 )
return 0;
goto LABEL_155;
}
}
}
LABEL_20:
v23 = a5 & 0xFDFFFFFF;
if( (v17 & a5 & 0xFDFFFFFF) != (a5 & 0xFDFFFFFF) )
{
v83 = HIDWORD(v150) == 0;
*(_DWORD *)v12 = -1073741790;
if( v83 )
{
v84 = *(VOID **)a3;
if( !*(_QWORD *)a3 )
v84 = *(VOID **)(a3 + 16);
TokenTrustLevel = SepLocateTokenTrustLevel((_SECURITY_SUBJECT_CONTEXT *)a3);
SeLogAccessFailure(v84, 0i64, 0i64, (UINT64)TokenTrustLevel, (UINT8)v13);
}
if( v134 )
return 0;
goto LABEL_155;
}
*(_DWORD *)v12 = 0;
v24 = *(_TOKEN **)a3;
if( !*(_QWORD *)a3 )
v24 = *(_TOKEN **)(a3 + 16);
if( (dl0 & 4) == 0 )
{
v25 = SepFilterCheck((INT64)v13, &ResourceInfo, v24, 0, (INT64)&v158);
v26 = AccessStatus;
*(_DWORD *)AccessStatus = v25;
if( v25 < 0 )
goto LABEL_184;
if( ((unsigned int)v158 & v23) == v23 )
{
*(_DWORD *)v26 = 0;
goto LABEL_27;
}
v83 = HIDWORD(v150) == 0;
*(_DWORD *)v26 = -1073741790;
if( v83 )
SeLogAccessFailure(v24, 0i64, 0i64, 0i64, (UINT8)v13);
if( v134 )
return 0;
LABEL_155:
SeUnlockSubjectContext((PSECURITY_SUBJECT_CONTEXT)a3);
return 0;
}
v26 = AccessStatus;
LABEL_27:
if( (dl0 & 2) == 0 )
{
v27 = 0;
goto LABEL_29;
}
v27 = 1;
if( (v24->TokenFlags & 0x2000) != 0 )
v28 = 1;
else
LABEL_29:
v28 = 0;
v141 = v28;
v138 = 0;
if( !SepAllowAccessUponLogoff && (v24->TokenFlags & 0x20) == 0 )
{
LogonSession = v24->LogonSession;
if( LogonSession )
{
if( (LogonSession->Flags & 0x20) != 0 )
{
v83 = v134 == 0;
*(_DWORD *)GrantedAccess = 0;
*(_DWORD *)v26 = -1073741790;
if( !v83 )
return 0;
goto LABEL_155;
}
}
}
v29 = a12;
if( !v28 )
{
ObjectTypeListLength = &v156;
LOBYTE(MandatoryInformation) = a12;
v30 = SepMandatoryIntegrityCheck(GenericMapping, (_SECURITY_DESCRIPTOR *)v13, v27, v24, 0, MandatoryInformation);
v31 = AccessStatus;
*(_DWORD *)AccessStatus = v30;
if( v30 < 0 )
goto LABEL_184;
if( DWORD2(v156) && (v23 & (unsigned int)v156) != v23 )
{
*(_DWORD *)v31 = -1073741790;
if( (v24->TokenFlags & 0x4000) == 0 || HIDWORD(v156) > 0x2000 )
{
if( v134 )
return 0;
goto LABEL_155;
}
}
else
{
*(_DWORD *)v31 = 0;
if( (a5 & 0x2000000) == 0 || (v24->TokenFlags & 0x4000) == 0 || HIDWORD(v156) > 0x2000 )
{
LABEL_36:
v29 = a12;
goto LABEL_37;
}
}
v138 = 1;
goto LABEL_36;
}
LABEL_37:
if( !SepRmEnforceCap )
{
LABEL_38:
v32 = 0;
goto LABEL_39;
}
v87 = *((_WORD *)v13 + 1);
if( (v87 & 0x10) == 0 || KeGetCurrentIrql() >= 2u )
{
LABEL_217:
v29 = a12;
goto LABEL_38;
}
if( v87 >= 0 )
{
v89 = (_ACL *)*((_QWORD *)v13 + 3);
}
else
{
v88 = v13[3];
if( !(_DWORD)v88 )
{
pSacl = 0i64;
goto LABEL_217;
}
v89 = (_ACL *)((char *)v13 + v88);
}
pSacl = v89;
if( !v89 )
goto LABEL_217;
ScopedPolicySid = SepGetScopedPolicySid(v89);
if( !ScopedPolicySid )
goto LABEL_217;
Cap = SepRmReferenceFindCap(ScopedPolicySid, (_SEP_CENTRALIZED_ACCESS_POLICY **)&a2);
v92 = a2;
v29 = a12;
v32 = 1;
if( Cap < 0 )
v92 = (_RTL_DYNAMIC_HASH_TABLE_ENTRY *)SepRmDefaultCap;
a2 = v92;
v135 = 1;
LABEL_39:
if( (dl0 & 1) != 0 )
{
v137 = 1;
if( (a5 & 0x2060000) == 0 && !v32 )
{
TokenIsOwner = 0;
goto LABEL_70;
}
}
else
{
v137 = 0;
}
if( *((__int16 *)v13 + 1) < 0 )
{
v65 = v13[1];
if( (_DWORD)v65 )
v33 = (unsigned __int8 *)v13 + v65;
else
v33 = 0i64;
}
else
{
v33 = (unsigned __int8 *)*((_QWORD *)v13 + 1);
}
p_SidHash = &v24->SidHash;
if( v29 && v33 && RtlEqualSid(SeAliasAdminsSid, v33) )
{
TokenIsOwner = 0;
goto LABEL_56;
}
if( v24 == (_TOKEN *)-232i64 || !v33 )
goto LABEL_68;
v35 = v33[1];
v36 = *(unsigned __int16 *)v33;
v159 = v36;
v37 = 4 * v35 + 8;
v146 = v37;
v38 = (unsigned __int64)v33[4 * ((unsigned __int64)(unsigned int)v36 >> 8) + 4] >> 4;
v39 = v33[4 * ((unsigned __int64)(unsigned int)v36 >> 8) + 4] & 0xF;
LOBYTE(v40) = 0;
pbDominate = 0;
v41 = p_SidHash->Hash[v39] & p_SidHash->Hash[v38 + 16];
if( !v41 )
goto LABEL_66;
while( 2 )
{
LOBYTE(v42) = v41;
v142 = (unsigned __int8)v41;
if( !(_BYTE)v41 )
goto LABEL_135;
SidAttr = (__int64)v24->SidHash.SidAttr;
v40 = (unsigned __int8)v40;
v155 = (_WORD *)SidAttr;
HIDWORD(Result) = (unsigned __int8)v40;
while( 2 )
{
LODWORD(v144) = *((unsigned __int8 *)SidHashByteToIndexLookupTable + (unsigned __int8)v42);
v44 = (_SID_AND_ATTRIBUTES *)(SidAttr + 16i64 * (unsigned int)(v40 + (_DWORD)v144));
if( *(_WORD *)v44->Sid == (_WORD)v36 )
{
if( !memcmp(v33, v44->Sid, v37) )
{
LABEL_51:
if( v44 == v24->SidHash.SidAttr && (v44->Attributes & 0x10) == 0 || (v44->Attributes & 4) != 0 )
{
if( v24->RestrictedSidCount )
TokenIsOwner = SepSidInTokenSidHash(&v24->RestrictedSidHash, 0i64, v33, 0, 1u, 0);
else
TokenIsOwner = 1;
}
else
{
TokenIsOwner = 0;
}
v13 = (unsigned int *)SecurityDescriptora;
LABEL_56:
if( !TokenIsOwner || (a5 & 0x2060000) == 0 )
goto LABEL_69;
if( v137 )
goto LABEL_62;
v46 = *((_WORD *)v13 + 1);
if( (v46 & 4) != 0 )
{
if( v46 >= 0 )
{
v47 = (char *)*((_QWORD *)v13 + 4);
}
else
{
v68 = v13[4];
v47 = (_DWORD)v68 ? (char *)v13 + v68 : 0i64;
}
}
else
{
v47 = 0i64;
}
SeOwnerRightsSid = SeExports->SeOwnerRightsSid;
v155 = SeOwnerRightsSid;
if( !v47
|| (v69 = (unsigned __int8 *)(v47 + 8),
LODWORD(v144) = *((unsigned __int16 *)v47 + 2),
v70 = 0,
!(_DWORD)v144) )
{
LABEL_62:
v32 = v135;
v49 = 393216;
if( (a5 & 0x2000000) == 0 )
v49 = a5 & 0x60000;
v14 = a5 & 0xFFF9FFFF;
v50 = v139 | v49;
v139 = v50;
v51 = v50;
if( !v135 )
{
TokenIsOwner = 0;
v139 = v50;
}
goto LABEL_71;
}
v71 = 104928;
while( 2 )
{
if( (v69[1] & 8) != 0 )
goto LABEL_117;
v72 = *v69;
if( (unsigned __int8)v72 <= 0x10u && _bittest(&v71, v72) )
{
v73 = 16i64 * (*((_DWORD *)v69 + 2) & 1) + ((8i64 * (*((_DWORD *)v69 + 2) & 2)) | 0xC);
}
else
{
if( (_BYTE)v72 != 4 )
{
if( (unsigned __int8)v72 < 0xBu || (unsigned __int8)(v72 - 13) <= 1u )
{
v73 = 8i64;
break;
}
LABEL_117:
++v70;
v69 += *((unsigned __int16 *)v69 + 1);
if( v70 >= (unsigned int)v144 )
goto LABEL_62;
continue;
}
v73 = 12i64;
}
break;
}
v74 = &v69[v73];
if( v74 )
{
v75 = *(unsigned __int16 *)v74;
if( (_WORD)v75 == *SeOwnerRightsSid )
{
if( !memcmp(v74, SeOwnerRightsSid, 4 * (v75 >> 8) + 8) )
goto LABEL_69;
SeOwnerRightsSid = v155;
v71 = 104928;
}
}
goto LABEL_117;
}
LOWORD(v36) = v159;
v37 = v146;
v40 = HIDWORD(Result);
}
v42 = (unsigned __int8)v142 ^ (1 << (char)v144);
SidAttr = (__int64)v155;
v142 = v42;
if( (_BYTE)v42 )
continue;
break;
}
LOBYTE(v40) = pbDominate;
LABEL_135:
LOBYTE(v40) = v40 + 8;
v41 >>= 8;
pbDominate = v40;
if( v41 )
continue;
break;
}
LABEL_66:
SidCount = p_SidHash->SidCount;
if( p_SidHash->SidCount > 0x40 )
{
v93 = (__int64)v24->SidHash.SidAttr;
v94 = 64;
v142 = 64;
v155 = (_WORD *)v93;
do
{
v44 = (_SID_AND_ATTRIBUTES *)(v93 + 16i64 * v94);
if( *(_WORD *)v44->Sid == (_WORD)v36 )
{
if( !memcmp(v33, v44->Sid, v37) )
goto LABEL_51;
LOWORD(v36) = v159;
v37 = v146;
v94 = v142;
v93 = (__int64)v155;
}
v142 = ++v94;
}
while( v94 < SidCount );
}
v13 = (unsigned int *)SecurityDescriptora;
LABEL_68:
TokenIsOwner = 0;
LABEL_69:
v32 = v135;
LABEL_70:
v49 = v140;
v51 = v139;
LABEL_71:
if( !v14 && !v32 && ((v24->TokenFlags & 0x2000) != 0 || !v49) )
{
if( !v134 )
SeUnlockSubjectContext(SubjectContext);
v66 = AccessStatus;
*(_DWORD *)GrantedAccess = v51;
*(_DWORD *)v66 = 0;
return 1;
}
v53 = SubjectContext;
ClientToken = (_TOKEN *)SubjectContext->ClientToken;
PrimaryToken = (_TOKEN *)SubjectContext->PrimaryToken;
LODWORD(PreviouslyGrantedAccess) = v51;
LODWORD(ObjectTypeListLength) = 0;
*(_DWORD *)PackageCapabilityInfo = v49;
memset(&PackageCapabilityInfo[4], 0, 24);
LODWORD(v126) = v14;
v56 = SepAccessCheck(
v13,
0i64,
PrimaryToken,
ClientToken,
v126,
0i64,
(UINT64)ObjectTypeListLength,
GenericMapping,
PreviouslyGrantedAccess,
PreviousMode,
GrantedAccess,
Privileges,
AccessStatus,
0,
TokenIsOwner,
(_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
&ReturnSomeAccessGranted,
0i64);
v57 = a2;
v58 = v56;
v144 = a2;
if( !SepRmEnforceCap || (v95 = *(_DWORD *)AccessStatus, v146 = v95, v95 < 0) || !v135 )
{
v59 = AccessStatus;
v60 = GrantedAccess;
goto LABEL_74;
}
v96 = 0;
pbDominate = 0;
LOBYTE(v142) = 0;
HIDWORD(Result) = 0;
v97 = *(_DWORD *)GrantedAccess;
v140 = *(_DWORD *)GrantedAccess;
if( !HIDWORD(a2[2].Linkage.Blink) )
goto LABEL_290;
while( 2 )
{
v98 = (_RTL_DYNAMIC_HASH_TABLE_ENTRY *)*(&v57[2].Signature + v96);
a2 = v98;
if( v98[1].Linkage.Flink )
{
v99 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
if( !ResourceInfo )
{
v100 = AuthzBasepInitializeResourceClaimsFromSacl(
pSacl,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo);
v99 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
v101 = (unsigned __int8)v142;
if( v100 < 0 )
v101 = 1;
v142 = v101;
}
pClaimAttributes = v24->pClaimAttributes;
if( pClaimAttributes )
{
pRestrictedDeviceSecurityAttributes = pClaimAttributes->pRestrictedDeviceSecurityAttributes;
pDeviceSecurityAttributes = pClaimAttributes->pDeviceSecurityAttributes;
pRestrictedUserSecurityAttributes = pClaimAttributes->pRestrictedUserSecurityAttributes;
pUserSecurityAttributes = pClaimAttributes->pUserSecurityAttributes;
}
else
{
pRestrictedDeviceSecurityAttributes = 0i64;
pDeviceSecurityAttributes = 0i64;
pRestrictedUserSecurityAttributes = 0i64;
pUserSecurityAttributes = 0i64;
}
LODWORD(PreviouslyGrantedAccessa) = v98->Signature;
v107 = AuthzBasepEvaluateAceCondition(
v24,
v24->pSecurityAttributes,
v99,
pUserSecurityAttributes,
pRestrictedUserSecurityAttributes,
pDeviceSecurityAttributes,
pRestrictedDeviceSecurityAttributes,
(UINT8 *)v98[1].Linkage.Flink,
PreviouslyGrantedAccessa,
1u,
0,
&Result);
v108 = Result;
v109 = v107;
if( (_DWORD)Result != 1 )
{
if( v107 < 0 )
{
if( !v134 )
SeUnlockSubjectContext(SubjectContext);
Blink = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
if( Blink )
goto LABEL_279;
goto LABEL_280;
}
if( (v24->TokenFlags & 0x10) != 0 )
{
v110 = v24->pClaimAttributes;
if( v110 )
{
v111 = v110->pRestrictedDeviceSecurityAttributes;
v112 = v110->pDeviceSecurityAttributes;
v113 = v110->pRestrictedUserSecurityAttributes;
v114 = v110->pUserSecurityAttributes;
}
else
{
v111 = 0i64;
v112 = 0i64;
v113 = 0i64;
v114 = 0i64;
}
LODWORD(PreviouslyGrantedAccessa) = a2->Signature;
v109 = AuthzBasepEvaluateAceCondition(
v24,
v24->pSecurityAttributes,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo,
v114,
v113,
v112,
v111,
(UINT8 *)a2[1].Linkage.Flink,
PreviouslyGrantedAccessa,
1u,
1u,
&Result);
if( v109 >= 0 )
{
v108 = Result;
goto LABEL_259;
}
if( !v134 )
SeUnlockSubjectContext(SubjectContext);
Blink = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
if( Blink )
LABEL_279:
SepRmDereferenceCapTable(Blink);
LABEL_280:
*(_DWORD *)GrantedAccess = 0;
*(_DWORD *)AccessStatus = v109;
LABEL_282:
SepFreeResourceInfo((VOID *)ResourceInfo);
return 0;
}
LABEL_259:
if( !(_BYTE)v142 && v108 != 1 )
{
v95 = v146;
v53 = SubjectContext;
goto LABEL_274;
}
}
v98 = a2;
}
v115 = SepBuildCapeSecurityDescriptor(CapeSecurityDescriptor, v98[1].Linkage.Blink, pSacl);
if( v115 < 0 )
{
if( !v134 )
SeUnlockSubjectContext(SubjectContext);
v121 = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v144[1].Linkage.Blink;
if( v121 )
SepRmDereferenceCapTable(v121);
*(_DWORD *)GrantedAccess = 0;
*(_DWORD *)AccessStatus = v115;
goto LABEL_282;
}
v116 = v14;
if( ((__int64)v98[2].Linkage.Flink & 1) != 0 )
{
v117 = 0;
if( (v14 & 0x2000000) == 0 )
v116 = v139 | v14;
}
else
{
v117 = v139;
}
v53 = SubjectContext;
LODWORD(PreviouslyGrantedAccessa) = v117;
LODWORD(ObjectTypeListLengtha) = 0;
LODWORD(v127) = v116;
v58 = SepAccessCheck(
CapeSecurityDescriptor,
0i64,
(_TOKEN *)SubjectContext->PrimaryToken,
(_TOKEN *)SubjectContext->ClientToken,
v127,
0i64,
ObjectTypeListLengtha,
GenericMapping,
PreviouslyGrantedAccessa,
PreviousMode,
&v150,
0i64,
&v152,
0,
TokenIsOwner,
(_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
&ReturnSomeAccessGranted,
0i64);
if( pbDominate )
v118 = v150 & v140;
else
v118 = v150;
v140 = v118;
if( v118 )
{
v95 = v152;
v146 = v152;
pbDominate = 1;
if( (int)v152 < 0 )
goto LABEL_288;
LABEL_274:
v57 = v144;
v96 = HIDWORD(Result) + 1;
HIDWORD(Result) = v96;
if( v96 >= HIDWORD(v144[2].Linkage.Blink) )
goto LABEL_289;
continue;
}
break;
}
v95 = -1073741790;
LABEL_288:
v57 = v144;
LABEL_289:
v97 = v140;
LABEL_290:
v59 = AccessStatus;
v60 = GrantedAccess;
*(_DWORD *)AccessStatus = v95;
v120 = ReturnSomeAccessGranted;
*(_DWORD *)v60 &= v97;
if( *(int *)v59 < 0 )
v120 = 0;
ReturnSomeAccessGranted = v120;
LABEL_74:
if( !v141 && (v14 & 0x2000000) != 0 )
{
if( (!v138 || !PackageCapabilityInfo[21] && !PackageCapabilityInfo[22])
&& DWORD2(v156)
&& (!BYTE4(v156) || !BYTE5(v156) || !BYTE6(v156)) )
{
v77 = *(_DWORD *)v60 & v156;
if( v77 != *(_DWORD *)v60 )
{
*(_DWORD *)v60 = v77;
if( v77 )
{
*(_DWORD *)v59 = 0;
ReturnSomeAccessGranted = 1;
}
else
{
*(_DWORD *)v59 = -1073741790;
LABEL_167:
ReturnSomeAccessGranted = 0;
}
}
}
}
else if( v138 && !PackageCapabilityInfo[21] && !PackageCapabilityInfo[22] )
{
*(_DWORD *)v59 = -1073741790;
*(_DWORD *)v60 = 0;
goto LABEL_167;
}
v61 = 0;
if( (v14 & 0x2000000) != 0 )
{
if( v17 != -1 )
{
v122 = v17 & *(_DWORD *)v60;
if( v122 != *(_DWORD *)v60 )
{
*(_DWORD *)v60 = v122;
v61 = 1;
if( v122 )
{
*(_DWORD *)v59 = 0;
ReturnSomeAccessGranted = 1;
}
else
{
*(_DWORD *)v59 = -1073741790;
ReturnSomeAccessGranted = 0;
}
}
}
v62 = 0;
if( (_DWORD)v158 != -1 )
{
v123 = *(_DWORD *)v60;
v124 = v158 & *(_DWORD *)v60;
if( v124 != v123 )
{
v62 = 1;
*(_DWORD *)GrantedAccess = v124;
if( v124 )
{
*(_DWORD *)v59 = 0;
ReturnSomeAccessGranted = 1;
}
else
{
*(_DWORD *)v59 = -1073741790;
ReturnSomeAccessGranted = 0;
}
}
}
}
else
{
v62 = 0;
}
if( v24 )
{
if( (v61
|| v62
|| !*(_DWORD *)&PackageCapabilityInfo[12]
&& (v24->TokenFlags & 0x4000) != 0
&& (*(int *)v59 < 0 || PackageCapabilityInfo[23]))
&& !HIDWORD(v150) )
{
v78 = SepLocateTokenTrustLevel(v53);
SeLogAccessFailure(v24, 0i64, 0i64, (UINT64)v78, (UINT8)v13);
v57 = v144;
v59 = AccessStatus;
}
if( *(int *)v59 < 0
&& !*(_DWORD *)&PackageCapabilityInfo[12]
&& (v24->TokenFlags & 0x4000) != 0
&& PackageCapabilityInfo[24]
&& (v14 & ~(*(_DWORD *)&PackageCapabilityInfo[4] | *(_DWORD *)&PackageCapabilityInfo[8] | 0x2000000) & *(_DWORD *)&PackageCapabilityInfo[16]) == (v14 & ~(*(_DWORD *)&PackageCapabilityInfo[4] | *(_DWORD *)&PackageCapabilityInfo[8] | 0x2000000)) )
{
SepLogLpacAccessFailure();
v57 = v144;
}
}
if( v135 )
{
v125 = (_SEP_CENTRALIZED_ACCESS_POLICIES_TABLE *)v57[1].Linkage.Blink;
if( v125 )
SepRmDereferenceCapTable(v125);
}
if( !v134 )
SeUnlockSubjectContext(v53);
v63 = (void *)ResourceInfo;
if( ResourceInfo )
{
AuthzBasepFreeSecurityAttributesList((_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo);
ExFreePoolWithTag(v63, 0);
}
return v58 && ReturnSomeAccessGranted;
}Referenced by:
SeAccessCheck
SeAccessCheckWithHint