RtlpNewSecurityObject
NTSTATUS __stdcall RtlpNewSecurityObject(
VOID *ParentDescriptor,
VOID *CreatorDescriptor,
VOID **NewDescriptor,
_GUID **pObjectType,
UINT64 GuidCount,
UINT8 IsDirectoryObject,
UINT64 AutoInheritFlags,
VOID *Token,
_GENERIC_MAPPING *GenericMapping,
_SECURITY_OBJECT_AI_PARAMS *AutoInheritParams){
int v10;
__int128 *v11;
_DWORD *v12;
unsigned int *v13;
char *v14;
char *v15;
_ACL *v16;
char v17;
char *v18;
__int16 v19;
bool v20;
_ETHREAD *CurrentThread;
__int64 v22;
__int64 v23;
unsigned __int8 *v24;
unsigned __int16 *v25;
unsigned __int8 *v26;
__int64 v27;
__int64 v28;
unsigned __int8 *v29;
unsigned __int8 *v30;
unsigned __int8 **v31;
unsigned __int8 *v32;
unsigned __int8 *v33;
unsigned __int8 *v34;
__int64 v35;
__int64 v36;
__int64 v37;
__int64 v38;
VOID **PoolWithTag;
size_t v40;
char *v41;
__int64 v42;
_ACL *v43;
int v44;
__int16 v45;
char *v46;
char *v47;
char *v48;
char *v49;
bool v50;
int v51;
UINT8 v52;
int v53;
int v54;
int v55;
_ACL *v56;
_ACL *v57;
unsigned int v58;
__int16 v59;
int v60;
bool v61;
__int16 v62;
int v63;
int v64;
_ACL *v65;
_ACL *v66;
unsigned int v67;
_ACL *v68;
__int16 v69;
VOID *v70;
__int16 v71;
_ACL *v72;
char *AceByType;
UINT8 v74;
char *v75;
unsigned int v76;
unsigned int v77;
__int64 v78;
VOID *v79;
__int16 v80;
_ACL *v81;
_DWORD *v82;
UINT8 v83;
_DWORD *v84;
int v85;
int v86;
int v87;
__int64 v88;
unsigned __int8 v89;
UINT64 v90;
_ACL *v91;
_ACL *v92;
unsigned int v93;
int v94;
VOID **AclBuffer;
_ACL *v96;
__int16 v97;
_ACL *v98;
_ACL *v99;
NTSTATUS v100;
int v101;
int v102;
int v103;
_ACL *v104;
int v105;
int v106;
int v107;
char *v108;
VOID *v109;
UINT8 v110;
__int64 v111;
int v112;
__int16 v113;
__int16 v114;
_ACL *v115;
_ACL *v116;
unsigned int v117;
__int16 v118;
int v119;
int v120;
char v121;
_SECURITY_SUBJECT_CONTEXT *v122;
char v123;
_ACL *v124;
bool v125;
int v126;
size_t v127;
size_t v128;
int v129;
unsigned int v130;
int v131;
unsigned int v132;
VOID **v133;
VOID **v134;
__int16 v135;
_ACL *v136;
bool v137;
_ACL *v138;
_GENERIC_MAPPING *v139;
__int64 AclSize;
_ACL *v141;
_GENERIC_MAPPING *v142;
char v143;
__int64 v144;
char *v145;
unsigned int v147;
int v148;
VOID **v149;
__int16 v150;
_ACL *v151;
char *v152;
__int16 v153;
int v154;
int v155;
int v156;
_DWORD *v157;
__int16 v158;
unsigned int v159;
_ACL *v160;
__int64 v161;
__int64 v162;
__int64 v163;
int v164;
__int16 v165;
unsigned int v166;
__int16 v167;
__int64 v168;
__int16 v169;
__int64 v170;
__int16 v171;
__int64 v172;
unsigned int v173;
VOID **v174;
UINT8 v175;
unsigned int v176;
unsigned int v177;
VOID **v178;
_ETHREAD *v179;
__int64 v180;
__int64 v181;
__int64 v182;
__int64 v183;
__int64 v184;
int v185;
int v186;
__int64 v187;
_ACL *v188;
__int64 v189;
char *v190;
__int64 v191;
__int64 v192;
_ACL *v193;
__int64 v194;
__int16 v195;
_ACL *v196;
__int64 v197;
char *v198;
UINT64 v199;
VOID *v200;
unsigned int ConstraintMask;
unsigned int v202;
int v203;
_DWORD *v204;
INT8 v205;
INT8 v206;
void *AceType;
UINT64 AceTypea;
void *AccessMask;
VOID *OwnerSid;
_KPROCESSOR_MODE GroupSid;
UINT64 v212;
char v213;
char PreviousMode;
bool v215;
_ACL *Src;
char pbDominate[8];
_ACL *pAuditAcl;
char v219;
char v220[12];
UINT8 v221;
char v222;
UINT8 v223;
bool v224;
char v225;
char v226;
bool v227;
UINT8 ServerAclAllocated;
char v229;
char v230;
char v231;
char NewGenericControl[12];
UINT8 v233;
char NewAclExplicitlyAssigned[3];
UINT64 pIndex;
__int128 *v236;
VOID *Owner;
int v238;
VOID *ClientGroupSid;
PGENERIC_MAPPING v240;
VOID *ServerSid;
_SECURITY_SUBJECT_CONTEXT *SubjectContext;
UINT64 v243;
UINT64 AclBufferSize;
VOID *ParentDescriptora;
VOID *NewDescriptora;
VOID *Sid;
VOID *ServerGroupSid;
INT64 ReturnStatus;
VOID *Sid1;
_GUID **pObjectTypea;
PVOID P;
_ACL *p_Acl;
_ACL *v254;
_ACL *ServerAcl;
_ACL *pTrustAcl;
unsigned int GrantedAccess;
int AccessStatus;
UINT64 v259;
VOID *TokenTrustLevel;
_SECURITY_OBJECT_AI_PARAMS *v261;
UINT64 pSaclSecurityInformation;
__int64 v263;
VOID **v264;
__int128 v265[2];
__int64 v266;
int v267;
unsigned __int16 v268;
PRIVILEGE_SET RequiredPrivileges;
_ACL Acl;
char v271[120];
_ACL ModificationAcl;
v10 = 0;
v240 = GenericMapping;
v11 = (__int128 *)CreatorDescriptor;
v12 = 0i64;
v261 = AutoInheritParams;
v13 = (unsigned int *)ParentDescriptor;
v264 = NewDescriptor;
v266 = 0i64;
v219 = 0;
v14 = 0i64;
v230 = 0;
v15 = 0i64;
v229 = 0;
v16 = 0i64;
v213 = 0;
v222 = 0;
v221 = 0;
v233 = 0;
NewAclExplicitlyAssigned[0] = 0;
v223 = 0;
v226 = 0;
ServerAclAllocated = 0;
v236 = (__int128 *)CreatorDescriptor;
v17 = AutoInheritFlags;
pObjectTypea = pObjectType;
v18 = 0i64;
p_Acl = &Acl;
ParentDescriptora = ParentDescriptor;
SubjectContext = (_SECURITY_SUBJECT_CONTEXT *)Token;
v238 = 0;
Src = 0i64;
ServerAcl = 0i64;
P = 0i64;
Sid1 = 0i64;
TokenTrustLevel = 0i64;
ServerSid = 0i64;
ServerGroupSid = 0i64;
v254 = 0i64;
*(_QWORD *)&v220[4] = 0i64;
PreviousMode = 1;
memset(NewGenericControl, 0, sizeof(NewGenericControl));
LODWORD(v259) = 0;
v263 = 0i64;
Sid = 0i64;
pSaclSecurityInformation = 0i64;
NewDescriptora = 0i64;
pbDominate[0] = 1;
pTrustAcl = 0i64;
v231 = 0;
memset(v265, 0, sizeof(v265));
memset(&RequiredPrivileges, 0, sizeof(RequiredPrivileges));
if( (AutoInheritFlags & 0x2000) == 0 )
PreviousMode = KeGetCurrentThread()->PreviousMode;
if( v11 )
{
v225 = 1;
}
else
{
v11 = v265;
v225 = 0;
v236 = v265;
LOBYTE(v265[0]) = 1;
}
v19 = *((_WORD *)v11 + 1);
v20 = (v19 & 0x80u) != 0;
v215 = (v19 & 0x80u) != 0;
v227 = (v19 & 0x40) != 0;
if( Token || (v19 & 0x80u) != 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquireResourceSharedLite(*(_QWORD *)(*((_QWORD *)Token + 2) + 48i64), 1);
if( *(_QWORD *)Token
&& (v179 = (_ETHREAD *)KeGetCurrentThread(),
--v179->Tcb.KernelApcDisable,
ExAcquireResourceSharedLite(*(_QWORD *)(*(_QWORD *)Token + 48i64), 1),
(v22 = *(_QWORD *)Token) != 0) )
{
if( *((_DWORD *)Token + 2) == 1 )
v215 = 1;
v23 = *((_QWORD *)Token + 2);
}
else
{
v22 = *((_QWORD *)Token + 2);
v23 = v22;
}
v24 = *(unsigned __int8 **)(v22 + 168);
v25 = *(unsigned __int16 **)(v22 + 184);
v26 = *(unsigned __int8 **)(*(_QWORD *)(v22 + 152) + 16i64 * *(unsigned int *)(v22 + 144));
v27 = *(_QWORD *)(v23 + 152);
v28 = *(unsigned int *)(v23 + 144);
v29 = *(unsigned __int8 **)(v23 + 168);
v30 = *(unsigned __int8 **)(v27 + 16 * v28);
SepLocateTokenIntegrity();
if( v31 )
v32 = *v31;
else
v32 = (unsigned __int8 *)SepDefaultMandatorySid;
v33 = (unsigned __int8 *)SepLocateTokenTrustLevel(SubjectContext);
v34 = v33;
if( v33 )
v35 = 4i64 * v33[1] + 8;
else
v35 = 0i64;
if( v24 )
v36 = 4i64 * v24[1] + 8;
else
v36 = 0i64;
if( v29 )
v37 = 4i64 * v29[1] + 32;
else
v37 = 24i64;
if( v25 )
v38 = v25[1];
else
v38 = 0i64;
PoolWithTag = ExAllocatePoolWithTag(
1ui64,
v37 + v38 + v36 + v35 + 4 * (v32[1] + v26[1] + (unsigned __int64)v30[1]),
1683187027i64);
P = PoolWithTag;
if( !PoolWithTag )
{
SeUnlockSubjectContext(SubjectContext);
return -1073741670;
}
memmove(PoolWithTag, v26, 4 * v26[1] + 8);
v40 = 4 * v32[1] + 8;
v41 = (char *)P + 4 * v26[1] + 8;
Sid1 = v41;
memmove(v41, v32, v40);
v42 = v32[1];
v15 = &v41[4 * v42 + 8];
ServerSid = v15;
if( v34 )
{
v164 = v34[1];
TokenTrustLevel = &v41[4 * v42 + 8];
memmove(TokenTrustLevel, v34, 4 * v164 + 8);
v15 += 4 * v34[1] + 8;
ServerSid = v15;
}
else
{
TokenTrustLevel = 0i64;
}
if( v24 )
{
v14 = v15;
memmove(v15, v24, 4 * v24[1] + 8);
v15 += 4 * v24[1] + 8;
ServerSid = v15;
}
else
{
v14 = 0i64;
}
memmove(v15, v30, 4 * v30[1] + 8);
v43 = (_ACL *)&v15[4 * v30[1] + 8];
v254 = v43;
if( v29 )
{
v44 = v29[1];
ServerGroupSid = v43;
v16 = v43;
memmove(v43, v29, 4 * v44 + 8);
v43 = (_ACL *)((char *)v43 + 4 * v29[1] + 8);
v254 = v43;
}
else
{
v16 = 0i64;
ServerGroupSid = 0i64;
}
if( v25 )
memmove(v43, v25, v25[1]);
else
v254 = 0i64;
ExReleaseResourceLite(*((PERESOURCE *)SubjectContext->PrimaryToken + 6));
KeLeaveCriticalRegion();
if( SubjectContext->ClientToken )
{
ExReleaseResourceLite(*((PERESOURCE *)SubjectContext->ClientToken + 6));
KeLeaveCriticalRegion();
}
v20 = v215;
v10 = 0;
v13 = (unsigned int *)ParentDescriptora;
v18 = (char *)P;
v17 = AutoInheritFlags;
v11 = v236;
v12 = *(_DWORD **)&v220[4];
}
v45 = *((_WORD *)v11 + 1);
if( v45 < 0 )
{
v161 = *((unsigned int *)v11 + 1);
if( !(_DWORD)v161 )
goto LABEL_33;
v46 = (char *)v11 + v161;
}
else
{
v46 = (char *)*((_QWORD *)v11 + 1);
}
Owner = v46;
if( v46 )
{
v222 = 1;
goto LABEL_37;
}
LABEL_33:
if( (v17 & 0x20) != 0 )
{
if( !v13 )
{
v141 = 0i64;
v85 = -1073741734;
v138 = 0i64;
goto LABEL_501;
}
if( *((__int16 *)v13 + 1) >= 0 )
{
v190 = (char *)*((_QWORD *)v13 + 1);
}
else
{
v189 = v13[1];
if( !(_DWORD)v189 )
goto LABEL_377;
v190 = (char *)v13 + v189;
}
Owner = v190;
v222 = 1;
if( v190 )
goto LABEL_37;
LABEL_377:
v141 = 0i64;
v85 = -1073741734;
v138 = 0i64;
goto LABEL_501;
}
v47 = v15;
if( !v20 )
v47 = v18;
Owner = v47;
if( !v47 )
{
v141 = 0i64;
v85 = -1073741700;
v138 = 0i64;
goto LABEL_501;
}
LABEL_37:
if( v45 < 0 )
{
v162 = *((unsigned int *)v11 + 2);
if( !(_DWORD)v162 )
goto LABEL_40;
v48 = (char *)v11 + v162;
}
else
{
v48 = (char *)*((_QWORD *)v11 + 2);
}
ClientGroupSid = v48;
if( v48 )
goto LABEL_44;
LABEL_40:
if( (v17 & 0x40) != 0 )
{
if( !v13 )
{
v141 = 0i64;
v85 = -1073741733;
v138 = 0i64;
goto LABEL_501;
}
if( *((__int16 *)v13 + 1) >= 0 )
{
v49 = (char *)*((_QWORD *)v13 + 2);
}
else
{
v191 = v13[2];
if( !(_DWORD)v191 )
goto LABEL_385;
v49 = (char *)v13 + v191;
}
}
else
{
v49 = v14;
if( v20 )
v49 = (char *)v16;
}
ClientGroupSid = v49;
if( !v49 )
{
LABEL_385:
v141 = 0i64;
v85 = -1073741733;
v138 = 0i64;
goto LABEL_501;
}
LABEL_44:
HIDWORD(pIndex) = v17 & 4;
v50 = (v17 & 4) != 0;
v51 = v17 & 2;
v52 = v51 != 0;
v224 = v51 != 0;
if( (v45 & 0x20) != 0 )
v10 = 8;
v53 = 0;
if( (v45 & 0x800) != 0 )
v54 = 1024;
else
v54 = 0;
if( (v45 & 0x2000) != 0 )
v55 = 4096;
else
v55 = 0;
if( (v45 & 0x10) != 0 )
{
if( v45 >= 0 )
{
v56 = (_ACL *)*((_QWORD *)v11 + 3);
}
else
{
v181 = *((unsigned int *)v11 + 3);
if( (_DWORD)v181 )
v56 = (_ACL *)((char *)v11 + v181);
else
v56 = 0i64;
}
}
else
{
v56 = 0i64;
}
if( !v13 )
goto LABEL_53;
v165 = *((_WORD *)v13 + 1);
if( (v165 & 0x10) == 0 )
goto LABEL_53;
if( v165 < 0 )
{
v166 = v13[3];
if( v166 )
{
v57 = (_ACL *)((char *)ParentDescriptora + v166);
goto LABEL_54;
}
LABEL_53:
v57 = 0i64;
goto LABEL_54;
}
v57 = (_ACL *)*((_QWORD *)v13 + 3);
LABEL_54:
v58 = v10 | v54 | v55 | ((v45 & 0x10) != 0 ? 4 : 0);
if( !v58 && !v57 )
{
*(_DWORD *)NewGenericControl = v51 != 0 ? 0x400 : 0;
pAuditAcl = 0i64;
goto LABEL_57;
}
v173 = 200;
*(_DWORD *)v220 = 200;
while( 1 )
{
v174 = ExAllocatePoolWithTag(1ui64, v173, 1665230163i64);
pAuditAcl = (_ACL *)v174;
if( !v174 )
{
v138 = 0i64;
goto LABEL_498;
}
LODWORD(v212) = GuidCount;
v85 = RtlpInheritAcl2(
v57,
v56,
v58,
IsDirectoryObject,
v52,
v50,
Owner,
ClientGroupSid,
ServerSid,
ServerGroupSid,
v240,
SepAclTypeSacl,
pObjectTypea,
v212,
(UINT64 *)v220,
(UINT8 *)v174,
&v221,
(UINT64 *)NewGenericControl);
if( v85 >= 0 )
break;
ExFreePoolWithTag(pAuditAcl, 0);
pAuditAcl = 0i64;
if( v85 != -1073741789 )
goto LABEL_279;
if( (unsigned int)++v53 >= 2 )
goto LABEL_279;
v173 = *(_DWORD *)v220;
v52 = v224;
}
if( !*(_DWORD *)v220 )
{
ExFreePoolWithTag(pAuditAcl, 0);
pAuditAcl = 0i64;
}
LABEL_279:
if( v85 >= 0 )
{
v219 = 1;
v185 = 32784;
if( (NewGenericControl[0] & 8) != 0 )
v185 = 32816;
if( (*(_WORD *)NewGenericControl & 0x1000) != 0 )
v186 = 0x2000;
else
v186 = 0;
v11 = v236;
*(_DWORD *)v220 = v185 | v186 | (2 * (*(_WORD *)NewGenericControl & 0x400));
goto LABEL_60;
}
if( v85 != -2147483637 )
goto LABEL_423;
v11 = v236;
LABEL_57:
v59 = *((_WORD *)v11 + 1);
v60 = 34816;
if( !v51 )
v60 = 0x8000;
*(_DWORD *)v220 = v60;
if( (v59 & 0x30) == 48 )
{
if( (v59 & 0x10) == 0 )
{
pAuditAcl = 0i64;
LABEL_403:
v221 = 1;
*(_DWORD *)v220 = v60 | v59 & 0x2000 | 0x10;
goto LABEL_60;
}
if( v59 >= 0 )
{
v193 = (_ACL *)*((_QWORD *)v11 + 3);
}
else
{
v192 = *((unsigned int *)v11 + 3);
if( !(_DWORD)v192 )
{
pAuditAcl = 0i64;
goto LABEL_403;
}
v193 = (_ACL *)((char *)v11 + v192);
}
pAuditAcl = v193;
goto LABEL_403;
}
LABEL_60:
v61 = HIDWORD(pIndex) != 0;
v62 = *((_WORD *)v11 + 1);
if( (v62 & 0x20) != 0 )
v63 = 8;
else
v63 = 0;
if( (v62 & 0x800) != 0 )
v64 = 1024;
else
v64 = 0;
if( (v62 & 0x10) != 0 )
{
if( v62 >= 0 )
{
v65 = (_ACL *)*((_QWORD *)v11 + 3);
}
else
{
v182 = *((unsigned int *)v11 + 3);
if( (_DWORD)v182 )
v65 = (_ACL *)((char *)v11 + v182);
else
v65 = 0i64;
}
}
else
{
v65 = 0i64;
}
if( !ParentDescriptora )
goto LABEL_67;
v167 = *((_WORD *)ParentDescriptora + 1);
if( (v167 & 0x10) == 0 )
goto LABEL_67;
if( v167 >= 0 )
{
v66 = (_ACL *)*((_QWORD *)ParentDescriptora + 3);
goto LABEL_68;
}
v168 = *((unsigned int *)ParentDescriptora + 3);
if( (_DWORD)v168 )
v66 = (_ACL *)((char *)ParentDescriptora + v168);
else
LABEL_67:
v66 = 0i64;
LABEL_68:
v67 = v63 | v64 | ((*((_WORD *)v11 + 1) & 0x10) != 0 ? 4 : 0);
if( !v67 && !v66 )
{
v68 = 0i64;
*(_QWORD *)&NewGenericControl[4] = 0i64;
HIDWORD(ReturnStatus) = -2147483637;
goto LABEL_71;
}
v175 = v224;
v176 = 200;
LODWORD(v243) = 200;
v177 = 0;
while( 1 )
{
v178 = ExAllocatePoolWithTag(1ui64, v176, 1665230163i64);
*(_QWORD *)&NewGenericControl[4] = v178;
if( !v178 )
goto LABEL_496;
LODWORD(v212) = GuidCount;
v85 = RtlpInheritAcl2(
v66,
v65,
v67,
IsDirectoryObject,
v175,
v61,
Owner,
ClientGroupSid,
ServerSid,
ServerGroupSid,
v240,
SepAclTypeSacl,
pObjectTypea,
v212,
&v243,
(UINT8 *)v178,
&v233,
&v259);
if( v85 >= 0 )
break;
ExFreePoolWithTag(*(PVOID *)&NewGenericControl[4], 0);
*(_QWORD *)&NewGenericControl[4] = 0i64;
if( v85 != -1073741789 || (++v177, v177 >= 2) )
{
v68 = 0i64;
goto LABEL_287;
}
v176 = v243;
}
if( (_DWORD)v243 )
{
v68 = *(_ACL **)&NewGenericControl[4];
}
else
{
ExFreePoolWithTag(*(PVOID *)&NewGenericControl[4], 0);
v68 = 0i64;
*(_QWORD *)&NewGenericControl[4] = 0i64;
}
LABEL_287:
HIDWORD(ReturnStatus) = v85;
if( v85 >= 0 )
{
v11 = v236;
v230 = 1;
goto LABEL_72;
}
if( v85 != -2147483637 )
goto LABEL_423;
v11 = v236;
LABEL_71:
v69 = *((_WORD *)v11 + 1);
if( (v69 & 0x30) == 48 )
{
if( (v69 & 0x10) == 0 )
{
v68 = 0i64;
*(_QWORD *)&NewGenericControl[4] = 0i64;
goto LABEL_72;
}
if( v69 >= 0 )
{
v68 = (_ACL *)*((_QWORD *)v11 + 3);
}
else
{
v194 = *((unsigned int *)v11 + 3);
if( !(_DWORD)v194 )
{
v68 = 0i64;
*(_QWORD *)&NewGenericControl[4] = 0i64;
goto LABEL_72;
}
v68 = (_ACL *)((char *)v11 + v194);
}
*(_QWORD *)&NewGenericControl[4] = v68;
}
LABEL_72:
v70 = TokenTrustLevel;
LODWORD(pIndex) = 0;
while( 2 )
{
v71 = *((_WORD *)v11 + 1);
if( (v71 & 0x10) != 0 )
{
if( v71 >= 0 )
{
v72 = (_ACL *)*((_QWORD *)v11 + 3);
}
else
{
v180 = *((unsigned int *)v11 + 3);
if( (_DWORD)v180 )
v72 = (_ACL *)((char *)v11 + v180);
else
v72 = 0i64;
}
}
else
{
v72 = 0i64;
}
AceByType = (char *)RtlFindAceByType(v72, 0x14ui64, &pIndex);
v75 = AceByType;
if( AceByType
&& AceByType != (char *)-8i64
&& !(unsigned __int8)RtlpValidTrustSubjectContext(v70, AceByType + 8, v74, (INT64 *)((char *)&ReturnStatus + 4)) )
{
LABEL_422:
v85 = -1073741790;
goto LABEL_423;
}
LODWORD(pIndex) = pIndex + 1;
if( v75 )
{
v11 = v236;
continue;
}
break;
}
v76 = AutoInheritFlags;
v77 = 4;
v78 = (__int64)v236;
if( (AutoInheritFlags & 0x800) == 0 )
{
LABEL_78:
v79 = ClientGroupSid;
pTrustAcl = v68;
goto LABEL_79;
}
LODWORD(pIndex) = 0;
do
{
v195 = *(_WORD *)(v78 + 2);
if( (v195 & 0x10) != 0 )
{
if( v195 >= 0 )
{
v196 = *(_ACL **)(v78 + 24);
}
else
{
v197 = *(unsigned int *)(v78 + 12);
if( (_DWORD)v197 )
v196 = (_ACL *)(v78 + v197);
else
v196 = 0i64;
}
}
else
{
v196 = 0i64;
}
v198 = (char *)RtlFindAceByType(v196, 0x14ui64, &pIndex);
LODWORD(pIndex) = pIndex + 1;
if( !v198 )
{
if( v70 )
{
if( !v261 )
{
v138 = pAuditAcl;
v85 = -1073741811;
goto LABEL_499;
}
ConstraintMask = v261->ConstraintMask;
v200 = v70;
v202 = 0;
goto LABEL_442;
}
goto LABEL_78;
}
}
while( (v198[1] & 8) != 0 );
v200 = v198 + 8;
ConstraintMask = *((_DWORD *)v198 + 1);
v202 = (unsigned __int8)v198[1];
if( !v261 || (ConstraintMask & v261->ConstraintMask) != ConstraintMask || v198 == (char *)-8i64 )
{
LABEL_437:
v138 = pAuditAcl;
v85 = -1073741811;
goto LABEL_499;
}
LABEL_442:
v85 = RtlCreateAcl(&ModificationAcl, (_ACL)88i64, 2ui64, v199);
if( v85 < 0
|| (LODWORD(AccessMask) = ConstraintMask,
v85 = RtlAddProcessTrustLabelAce(&ModificationAcl, 2ui64, v202, v200, 0x14u, (UINT64)AccessMask),
v85 < 0)
|| (v78 = (__int64)v236,
v79 = ClientGroupSid,
v85 = RtlpComputeMergedAcl(
*(_BYTE **)&NewGenericControl[4],
(*((_WORD *)v236 + 1) & 0x800 | (*((unsigned __int16 *)v236 + 1) >> 1) & 0x18u) >> 1,
&ModificationAcl,
4ui64,
Owner,
ClientGroupSid,
v240,
SepAclTypeSacl,
&pTrustAcl,
(UINT64 *)NewGenericControl),
v85 < 0) )
{
LABEL_423:
v138 = pAuditAcl;
LABEL_499:
v141 = Src;
LABEL_500:
v12 = *(_DWORD **)&v220[4];
LABEL_501:
v143 = 0;
goto LABEL_186;
}
v76 = AutoInheritFlags;
v231 = 1;
LABEL_79:
v80 = *(_WORD *)(v78 + 2);
if( (v80 & 0x10) != 0 )
{
if( v80 >= 0 )
{
v81 = *(_ACL **)(v78 + 24);
}
else
{
v183 = *(unsigned int *)(v78 + 12);
if( (_DWORD)v183 )
v81 = (_ACL *)(v78 + v183);
else
v81 = 0i64;
}
}
else
{
v81 = 0i64;
}
LODWORD(ReturnStatus) = 0;
v267 = 0;
v268 = 256;
HIDWORD(v243) = 0;
while( 2 )
{
v82 = RtlFindAceByType(v81, 0x15ui64, (UINT64 *)((char *)&v243 + 4));
v84 = v82;
if( !v82 )
goto LABEL_83;
if( (v82[1] & 0xFF000000) != 0 )
goto LABEL_437;
if( (*((_BYTE *)v82 + 1) & 0x40) != 0 )
{
if( !(unsigned __int8)RtlpValidTrustSubjectContext(v70, v82 + 2, v83, &ReturnStatus) )
goto LABEL_422;
goto LABEL_83;
}
v203 = *(_DWORD *)((char *)v82 + 10) - v267;
if( !v203 )
v203 = *((unsigned __int16 *)v82 + 7) - v268;
if( v203 )
goto LABEL_437;
if( *((_BYTE *)v82 + 9) == 1 && !v82[4] )
{
LABEL_83:
++HIDWORD(v243);
if( !v84 )
{
v85 = ReturnStatus;
goto LABEL_85;
}
continue;
}
break;
}
v85 = -1073741811;
LABEL_85:
if( v85 < 0 )
goto LABEL_482;
v86 = (v76 >> 8) & 1 | 2;
if( (v76 & 0x200) == 0 )
v86 = (v76 >> 8) & 1;
v87 = v86 | 4;
if( (v76 & 0x400) == 0 )
v87 = v86;
if( v87 )
{
v88 = v263;
goto LABEL_92;
}
v150 = *(_WORD *)(v78 + 2);
if( (v150 & 0x10) != 0 )
{
if( v150 >= 0 )
{
v151 = *(_ACL **)(v78 + 24);
}
else
{
v184 = *(unsigned int *)(v78 + 12);
if( (_DWORD)v184 )
v151 = (_ACL *)(v78 + v184);
else
v151 = 0i64;
}
}
else
{
v151 = 0i64;
}
v152 = (char *)RtlFindAceByType(v151, 0x11ui64, 0i64);
v88 = (__int64)v152;
if( v152 )
{
v89 = v152[1];
v87 = *((_DWORD *)v152 + 1);
Sid = v152 + 8;
if( v89 == 8 || (v89 & 0x10) != 0 )
{
v88 = 0i64;
Sid = 0i64;
v87 = 0;
goto LABEL_92;
}
}
else
{
LABEL_92:
v89 = 0;
}
if( (v89 & 8) != 0 )
{
LODWORD(v204) = RtlSubAuthoritySid((INT64)Sid1, 0i64);
if( *v204 < 0x2000u )
{
v138 = pAuditAcl;
v85 = -1073740730;
goto LABEL_499;
}
}
if( v87 )
{
LABEL_95:
if( !v88 )
{
if( !SubjectContext )
{
v138 = pAuditAcl;
v85 = -1073741700;
goto LABEL_499;
}
Sid = Sid1;
v89 = 0;
}
}
else if( Sid1 )
{
LODWORD(v157) = RtlSubAuthoritySid((INT64)Sid1, 0i64);
if( *v157 < 0x2000u )
{
v87 = 1;
goto LABEL_95;
}
}
if( !Sid )
{
v91 = 0i64;
p_Acl = 0i64;
LABEL_101:
if( (v76 & 0x700) == 0 )
{
if( !v88 && v91 )
{
v77 = 0;
}
else
{
v153 = *(_WORD *)(v78 + 2);
if( (v153 & 0x20) != 0 )
v154 = 8;
else
v154 = 0;
if( (v153 & 0x800) != 0 )
v155 = 1024;
else
v155 = 0;
if( (v153 & 0x2000) != 0 )
v156 = 4096;
else
v156 = 0;
v77 = v154 | (*(unsigned __int16 *)(v78 + 2) >> 2) & 4 | v155 | v156;
}
}
if( ParentDescriptora )
{
v169 = *((_WORD *)ParentDescriptora + 1);
if( (v169 & 0x10) != 0 )
{
if( v169 >= 0 )
{
v92 = (_ACL *)*((_QWORD *)ParentDescriptora + 3);
LABEL_104:
if( !v77 && !v92 )
{
LABEL_206:
v98 = p_Acl;
v96 = p_Acl;
*(_DWORD *)NewGenericControl = 0;
v97 = 0;
LABEL_113:
v99 = pAuditAcl;
v100 = RtlpCombineAcls(
pAuditAcl,
v96,
*(_ACL **)&NewGenericControl[4],
*(_ACL **)&NewGenericControl[4],
pTrustAcl,
*(_ACL ***)&NewGenericControl[4],
&pSaclSecurityInformation);
v101 = *(_DWORD *)v220;
v85 = v100;
if( (*(_WORD *)v220 & 0x2000) != 0 )
v102 = 0x40000000;
else
v102 = 0;
v103 = v102 | v238;
if( v96 && v96 != v98 )
ExFreePoolWithTag(v96, 0);
if( v85 < 0 )
goto LABEL_423;
v104 = (_ACL *)pSaclSecurityInformation;
if( pSaclSecurityInformation )
{
if( v219 && pAuditAcl )
ExFreePoolWithTag(pAuditAcl, 0);
pAuditAcl = v104;
v99 = v104;
v229 = 1;
if( (v97 & 8) != 0 )
v105 = 48;
else
v105 = 16;
if( (v97 & 0x1000) != 0 )
v106 = 0x2000;
else
v106 = 0;
v101 |= v105 | (2 * (v97 & 0x400)) | v106;
*(_DWORD *)v220 = v101;
}
v107 = AutoInheritFlags;
v238 = AutoInheritFlags & 8;
if( (AutoInheritFlags & 8) == 0 )
{
v108 = (char *)RtlFindAceByType(v99, 0x11ui64, 0i64);
if( v108 )
v109 = v108 + 8;
else
v109 = Sid;
if( v109 )
{
if( !SubjectContext )
{
v138 = pAuditAcl;
v85 = -1073741700;
goto LABEL_499;
}
v85 = RtlSidDominates(Sid1, v109, (UINT8 *)pbDominate);
if( v85 < 0 )
goto LABEL_482;
v107 = AutoInheritFlags;
if( !pbDominate[0] )
v226 = 1;
}
else
{
v107 = AutoInheritFlags;
}
}
v110 = HIDWORD(pIndex) != 0;
v111 = (__int64)v236;
v112 = v107 & 1;
pbDominate[0] = HIDWORD(pIndex) != 0;
v113 = *((_WORD *)v236 + 1);
v114 = v113;
if( (v113 & 4) != 0 )
{
if( v113 >= 0 )
{
v115 = (_ACL *)*((_QWORD *)v236 + 4);
}
else
{
v163 = *((unsigned int *)v236 + 4);
if( (_DWORD)v163 )
v115 = (_ACL *)((char *)v236 + v163);
else
v115 = 0i64;
}
}
else
{
v115 = 0i64;
}
if( !ParentDescriptora )
goto LABEL_137;
v171 = *((_WORD *)ParentDescriptora + 1);
if( (v171 & 4) == 0 )
goto LABEL_137;
if( v171 >= 0 )
{
v116 = (_ACL *)*((_QWORD *)ParentDescriptora + 4);
goto LABEL_138;
}
v172 = *((unsigned int *)ParentDescriptora + 4);
if( (_DWORD)v172 )
v116 = (_ACL *)((char *)ParentDescriptora + v172);
else
LABEL_137:
v116 = 0i64;
LABEL_138:
v117 = v114 & 0x140C;
if( v117 || v116 )
{
v147 = 200;
v148 = 0;
HIDWORD(pIndex) = 200;
while( 1 )
{
v149 = ExAllocatePoolWithTag(1ui64, v147, 1665230163i64);
Src = (_ACL *)v149;
if( !v149 )
{
v138 = pAuditAcl;
v85 = -1073741801;
v141 = 0i64;
goto LABEL_500;
}
LODWORD(v212) = GuidCount;
v85 = RtlpInheritAcl2(
v116,
v115,
v117,
IsDirectoryObject,
v112,
v110,
Owner,
ClientGroupSid,
ServerSid,
ServerGroupSid,
v240,
SepAclTypeDacl,
pObjectTypea,
v212,
(UINT64 *)((char *)&pIndex + 4),
(UINT8 *)v149,
&v223,
(UINT64 *)NewGenericControl);
if( v85 >= 0 )
break;
ExFreePoolWithTag(Src, 0);
Src = 0i64;
if( v85 != -1073741789 )
goto LABEL_203;
if( (unsigned int)++v148 >= 2 )
goto LABEL_203;
v147 = HIDWORD(pIndex);
v110 = pbDominate[0];
}
if( !HIDWORD(pIndex) )
{
ExFreePoolWithTag(Src, 0);
Src = 0i64;
}
LABEL_203:
if( v85 >= 0 )
{
v121 = 1;
v107 = AutoInheritFlags;
v213 = 1;
v120 = *(_WORD *)NewGenericControl & 0x1408 | 4 | *(_DWORD *)v220;
*(_DWORD *)v220 = v120;
goto LABEL_148;
}
if( v85 == -2147483637 )
{
v101 = *(_DWORD *)v220;
v111 = (__int64)v236;
v107 = AutoInheritFlags;
goto LABEL_141;
}
goto LABEL_423;
}
Src = 0i64;
LABEL_141:
v118 = *(_WORD *)(v111 + 2);
v119 = v101 | 0x400;
if( !v112 )
v119 = v101;
if( (*(_WORD *)(v111 + 2) & 0xC) != 12 )
{
v120 = v119;
*(_DWORD *)v220 = v119;
if( !v254 )
{
LABEL_147:
v121 = 0;
LABEL_148:
v122 = SubjectContext;
if( (v107 & 0x1000) == 0 && v225 && SubjectContext && ParentDescriptora )
{
LODWORD(OwnerSid) = v107 | 1;
GrantedAccess = 0;
AccessStatus = 0;
LODWORD(AceTypea) = GuidCount;
v85 = RtlpNewSecurityObject(
ParentDescriptora,
0i64,
&NewDescriptora,
pObjectTypea,
AceTypea,
IsDirectoryObject,
(UINT64)OwnerSid,
SubjectContext,
v240,
v261);
if( v85 < 0 )
goto LABEL_482;
v158 = *((_WORD *)NewDescriptora + 1);
if( (v158 & 4) != 0 )
{
if( v158 >= 0 )
{
v160 = (_ACL *)*((_QWORD *)NewDescriptora + 4);
}
else
{
v159 = *((_DWORD *)NewDescriptora + 4);
if( v159 )
v160 = (_ACL *)((char *)NewDescriptora + v159);
else
v160 = 0i64;
}
}
else
{
v160 = 0i64;
}
v123 = PreviousMode;
if( RtlpOwnerAcesPresent(0x10u, v160) )
{
LOBYTE(GroupSid) = PreviousMode;
if( !(unsigned __int8)SeAccessCheck(
NewDescriptora,
v122,
0,
0x40000,
0,
0i64,
v240,
GroupSid,
&GrantedAccess,
&AccessStatus) )
{
v85 = -1073741790;
goto LABEL_482;
}
}
LOBYTE(v107) = AutoInheritFlags;
}
else
{
v123 = PreviousMode;
}
v124 = Src;
if( v112 && !Src )
{
v120 |= 0x1000u;
*(_DWORD *)v220 = v120;
}
v125 = !v103 || (v103 & 0x1B0) != v103;
if( v123 == 1 )
{
v126 = v238;
if( v221 && !v238 && v125 )
{
if( !v122 )
{
v85 = -1073741700;
goto LABEL_482;
}
RequiredPrivileges.Privilege[0].Luid = SeSecurityPrivilege;
RequiredPrivileges.Privilege[0].Attributes = 0;
RequiredPrivileges.PrivilegeCount = 1;
RequiredPrivileges.Control = 1;
v205 = SePrivilegeCheck((UINT64 *)&RequiredPrivileges.PrivilegeCount, (INT64)v122, 1);
SePrivilegedServiceAuditAlarm(0i64, v122, &RequiredPrivileges, v205);
if( !v205 )
{
v85 = -1073741727;
goto LABEL_482;
}
v124 = Src;
LOBYTE(v107) = AutoInheritFlags;
}
if( v226 && !v126 )
{
if( !v122 )
{
v85 = -1073741700;
goto LABEL_482;
}
RequiredPrivileges.Privilege[0].Luid = (_LUID)SeRelabelPrivilege;
RequiredPrivileges.PrivilegeCount = 1;
RequiredPrivileges.Control = 1;
RequiredPrivileges.Privilege[0].Attributes = 0;
v206 = SePrivilegeCheck((UINT64 *)&RequiredPrivileges.PrivilegeCount, (INT64)v122, 1);
SePrivilegedServiceAuditAlarm(0i64, v122, &RequiredPrivileges, v206);
if( !v206 )
{
v85 = -1073741727;
goto LABEL_482;
}
v124 = Src;
LOBYTE(v107) = AutoInheritFlags;
}
if( v222 && (v107 & 0x10) == 0 && !SepValidOwnerSubjectContext(v122, Owner, v215) )
{
v85 = -1073741734;
goto LABEL_482;
}
if( v223 && v215 )
{
v85 = RtlpCreateServerAcl(v124, v227, ServerSid, &ServerAcl, &ServerAclAllocated);
if( v85 < 0 )
goto LABEL_482;
if( v121 && Src )
ExFreePoolWithTag(Src, 0);
v124 = ServerAcl;
Src = ServerAcl;
ServerAcl = 0i64;
}
}
v127 = 4 * *((unsigned __int8 *)Owner + 1) + 8;
if( ClientGroupSid )
v128 = 4 * *((unsigned __int8 *)ClientGroupSid + 1) + 8;
else
v128 = 0;
v129 = v120 & 0x10;
if( (v120 & 0x10) != 0 && pAuditAcl )
v130 = (pAuditAcl->AclSize + 3) & 0xFFFFFFFC;
else
v130 = 0;
v131 = v120 & 4;
if( v131 && v124 )
v132 = (v124->AclSize + 3) & 0xFFFFFFFC;
else
v132 = 0;
v133 = ExAllocatePoolWithTag(
1ui64,
v128 + v132 + v130 + 4 * *((unsigned __int8 *)Owner + 1) + 28,
1683187027i64);
*(_QWORD *)&v220[4] = v133;
v134 = v133;
if( !v133 )
{
v85 = -1073741670;
goto LABEL_482;
}
v135 = *(_WORD *)v220;
v136 = (_ACL *)((char *)v133 + 20);
*(_OWORD *)v133 = 0i64;
*((_DWORD *)v133 + 4) = 0;
*((_WORD *)v133 + 1) |= v135;
v137 = v129 == 0;
*(_BYTE *)v133 = 1;
v138 = pAuditAcl;
if( !v137 && pAuditAcl )
{
memmove(v136, pAuditAcl, pAuditAcl->AclSize);
if( !v219 )
RtlpApplyAclToObject(v136, v240, v139);
v134 = *(VOID ***)&v220[4];
*(_DWORD *)(*(_QWORD *)&v220[4] + 12i64) = (_DWORD)v136 - *(_DWORD *)&v220[4];
AclSize = v138->AclSize;
if( v130 > (unsigned int)AclSize )
{
memset((char *)v136 + AclSize, 0i64, v130 - AclSize);
v134 = *(VOID ***)&v220[4];
}
v136 = (_ACL *)((char *)v136 + v130);
}
v137 = v131 == 0;
v141 = Src;
if( !v137 )
{
if( Src )
{
memmove(v136, Src, Src->AclSize);
v143 = v213;
if( !v213 )
RtlpApplyAclToObject(v136, v240, v142);
*(_DWORD *)(*(_QWORD *)&v220[4] + 16i64) = (_DWORD)v136 - *(_DWORD *)&v220[4];
v144 = Src->AclSize;
if( v132 > (unsigned int)v144 )
memset((char *)v136 + v144, 0i64, v132 - v144);
v136 = (_ACL *)((char *)v136 + v132);
goto LABEL_183;
}
*((_DWORD *)v134 + 4) = 0;
}
v143 = v213;
LABEL_183:
memmove(v136, Owner, v127);
v12 = *(_DWORD **)&v220[4];
*(_DWORD *)(*(_QWORD *)&v220[4] + 4i64) = (_DWORD)v136 - *(_DWORD *)&v220[4];
v145 = (char *)v136 + v127;
if( ClientGroupSid )
{
memmove(v145, ClientGroupSid, v128);
v12[2] = (_DWORD)v145 - (_DWORD)v12;
}
v85 = 0;
goto LABEL_186;
}
Src = v254;
LABEL_146:
v120 |= 4u;
*(_DWORD *)v220 = v120;
goto LABEL_147;
}
if( (v118 & 4) != 0 )
{
if( v118 >= 0 )
{
v188 = *(_ACL **)(v111 + 32);
}
else
{
v187 = *(unsigned int *)(v111 + 16);
if( !(_DWORD)v187 )
{
Src = 0i64;
goto LABEL_354;
}
v188 = (_ACL *)(v111 + v187);
}
Src = v188;
}
else
{
Src = 0i64;
}
LABEL_354:
v223 = 1;
v120 = v119 | v118 & 0x1000;
goto LABEL_146;
}
v93 = 200;
v94 = 0;
LODWORD(AclBufferSize) = 200;
while( 1 )
{
AclBuffer = ExAllocatePoolWithTag(1ui64, v93, 1665230163i64);
v96 = (_ACL *)AclBuffer;
if( !AclBuffer )
break;
LODWORD(v212) = GuidCount;
v85 = RtlpInheritAcl2(
v92,
v91,
v77,
IsDirectoryObject,
1u,
0,
Owner,
v79,
ServerSid,
ServerGroupSid,
v240,
SepAclTypeMacl,
pObjectTypea,
v212,
&AclBufferSize,
(UINT8 *)AclBuffer,
(UINT8 *)NewAclExplicitlyAssigned,
(UINT64 *)NewGenericControl);
if( v85 >= 0 )
{
if( !(_DWORD)AclBufferSize )
{
ExFreePoolWithTag(v96, 0);
v96 = 0i64;
}
LABEL_110:
if( v85 == -2147483637 )
goto LABEL_206;
if( v85 >= 0 )
{
v97 = *(_WORD *)NewGenericControl;
v98 = p_Acl;
goto LABEL_113;
}
goto LABEL_482;
}
ExFreePoolWithTag(v96, 0);
v96 = 0i64;
if( v85 != -1073741789 )
goto LABEL_110;
if( (unsigned int)++v94 >= 2 )
goto LABEL_110;
v93 = AclBufferSize;
v91 = p_Acl;
}
LABEL_496:
v138 = pAuditAcl;
LABEL_498:
v85 = -1073741801;
goto LABEL_499;
}
v170 = *((unsigned int *)ParentDescriptora + 3);
if( (_DWORD)v170 )
{
v92 = (_ACL *)((char *)ParentDescriptora + v170);
goto LABEL_104;
}
}
}
v92 = 0i64;
goto LABEL_104;
}
memset(v271, 0i64, sizeof(v271));
Acl = (_ACL)8388610i64;
LODWORD(AccessMask) = v87;
v85 = RtlAddMandatoryAce(&Acl, v90, (VOID *)v89, (UINT64)Sid, AceType, AccessMask);
if( v85 >= 0 )
{
v91 = &Acl;
goto LABEL_101;
}
LABEL_482:
v12 = *(_DWORD **)&v220[4];
v141 = Src;
v138 = pAuditAcl;
v143 = v213;
LABEL_186:
if( NewDescriptora )
ExFreePoolWithTag(NewDescriptora, 0);
if( ServerAclAllocated && ServerAcl )
ExFreePoolWithTag(ServerAcl, 0);
if( P )
ExFreePoolWithTag(P, 0);
if( (v229 || v219) && v138 )
ExFreePoolWithTag(v138, 0);
if( v230 && *(_QWORD *)&NewGenericControl[4] )
ExFreePoolWithTag(*(PVOID *)&NewGenericControl[4], 0);
if( pTrustAcl && v231 )
ExFreePoolWithTag(pTrustAcl, 0);
if( v143 )
{
if( v141 )
ExFreePoolWithTag(v141, 0);
}
*v264 = v12;
return v85;
}Referenced by:
RtlpNewSecurityObject
SeAssignSecurity
SeAssignSecurityEx2