RtlNormalizeSecurityDescriptor
BOOL __stdcall RtlNormalizeSecurityDescriptor(
PSECURITY_DESCRIPTOR *SecurityDescriptor,
UINT32 SecurityDescriptorLength,
PSECURITY_DESCRIPTOR *NewSecurityDescriptor,
PULONG NewSecurityDescriptorLength,
BOOL CheckOnly){
BYTE *v5;
UINT64 v6;
UINT8 *v8;
char v9;
SIZE_T PoolWithTag;
unsigned int v11;
unsigned int v12;
unsigned int v13;
unsigned int v14;
__int64 v15;
unsigned int v16;
unsigned __int16 v17;
__int64 v18;
unsigned int v19;
unsigned int v20;
_WORD *v21;
_WORD *v22;
unsigned __int16 v23;
int v24;
unsigned int v25;
unsigned int v26;
UINT8 *v27;
_WORD *v28;
unsigned __int16 v29;
SIZE_T v30;
UINT8 *v31;
unsigned int v32;
unsigned int v33;
UINT8 *v34;
int v35;
PSECURITY_DESCRIPTOR *v36;
unsigned int v38;
unsigned int v39;
unsigned __int16 j;
unsigned int v41;
unsigned int v42;
unsigned __int16 i;
unsigned int v44;
int v45;
UINT8 *v46;
char v48;
v5 = (BYTE *)*SecurityDescriptor;
v6 = SecurityDescriptorLength;
v46 = 0i64;
v48 = 0;
v8 = 0i64;
v9 = 0;
LOBYTE(PoolWithTag) = SeValidSecurityDescriptor(SecurityDescriptorLength, *SecurityDescriptor);
v11 = 0;
if( !(_BYTE)PoolWithTag )
goto LABEL_92;
if( !CheckOnly )
{
if( NewSecurityDescriptor )
{
v8 = (UINT8 *)*NewSecurityDescriptor;
if( *NewSecurityDescriptor )
goto LABEL_7;
}
PoolWithTag = (SIZE_T)ExAllocatePoolWithTag(PagedPool, v6, 0x64536553ui64);
v8 = (UINT8 *)PoolWithTag;
if( PoolWithTag )
{
v48 = 1;
LABEL_7:
*(_OWORD *)v8 = *(_OWORD *)v5;
*((_DWORD *)v8 + 4) = *((_DWORD *)v5 + 4);
v11 = 0;
goto LABEL_8;
}
LABEL_92:
LOBYTE(PoolWithTag) = 0;
return PoolWithTag;
}
LABEL_8:
v12 = 20;
v13 = 1;
v45 = 1;
do
{
if( v13 == 1 )
v14 = *((_DWORD *)v5 + 3);
else
v14 = *((_DWORD *)v5 + 4);
v44 = v14;
if( v14 )
{
v15 = v14;
if( v13 != 1 || (v16 = 0, *(_WORD *)&v5[v14 + 4]) )
v16 = v12;
if( v16 != v14 )
{
v9 = 1;
if( CheckOnly )
goto LABEL_89;
if( v13 == 1 )
*((_DWORD *)v8 + 3) = v16;
else
*((_DWORD *)v8 + 4) = v16;
}
if( v16 )
{
if( !CheckOnly )
{
v46 = &v8[v16];
*(_QWORD *)v46 = *(_QWORD *)&v5[v14];
v11 = 0;
}
v17 = *(_WORD *)&v5[v14 + 4];
v18 = (__int64)&v5[v14 + 8];
v38 = 0;
v12 += 8;
v39 = 0;
v19 = 0;
v20 = 0;
v21 = (_WORD *)v18;
if( v17 )
{
while( 1 )
{
if( *(_BYTE *)v21 )
goto LABEL_37;
if( CheckOnly )
break;
v28 = v46 + 8;
v41 = 0;
if( !v19 )
goto LABEL_38;
v29 = v21[1];
for( i = v29; ; v29 = i )
{
if( v28[1] == v29 )
{
i = v21[1];
v30 = RtlCompareMemory(v21, v28, v29);
v19 = v38;
v11 = v41;
if( v30 == i )
break;
}
++v11;
v28 = (_WORD *)((char *)v28 + (unsigned __int16)v28[1]);
v41 = v11;
if( v11 >= v19 )
goto LABEL_37;
}
v9 = 1;
if( v41 >= v38 )
goto LABEL_37;
LOWORD(v24) = v21[1];
LABEL_40:
v14 = v44;
v15 = v44;
v20 = v39 + 1;
v21 = (_WORD *)((char *)v21 + (unsigned __int16)v24);
v39 = v20;
v17 = *(_WORD *)&v5[v44 + 4];
v18 = (__int64)&v5[v44 + 8];
if( v20 >= v17 )
{
v13 = v45;
goto LABEL_42;
}
v11 = 0;
}
v22 = (_WORD *)v18;
v42 = 0;
if( v20 )
{
v23 = v21[1];
for( j = v23; ; v23 = j )
{
if( v22[1] == v23 )
{
j = v21[1];
PoolWithTag = RtlCompareMemory(v21, v22, v23);
v20 = v39;
v11 = v42;
if( PoolWithTag == j )
break;
}
++v11;
v22 = (_WORD *)((char *)v22 + (unsigned __int16)v22[1]);
v42 = v11;
if( v11 >= v20 )
goto LABEL_36;
}
v9 = 1;
if( v42 < v39 )
goto LABEL_80;
LABEL_36:
v19 = v38;
}
LABEL_37:
if( !CheckOnly )
{
LABEL_38:
memmove(&v8[v12], (UINT8 *)v21, (unsigned __int16)v21[1]);
v19 = v38;
}
v24 = (unsigned __int16)v21[1];
v12 += v24;
v38 = ++v19;
goto LABEL_40;
}
LABEL_42:
LODWORD(PoolWithTag) = *(unsigned __int16 *)&v5[v15 + 2];
v25 = (v12 + 3) & 0xFFFFFFFC;
v26 = v25 - v16;
if( v25 - v16 == (_DWORD)PoolWithTag )
{
v27 = v46;
}
else
{
v9 = 1;
if( CheckOnly )
goto LABEL_89;
v27 = v46;
*((_WORD *)v46 + 1) = v26;
v17 = *(_WORD *)&v5[v15 + 4];
}
LODWORD(PoolWithTag) = v17;
if( v19 != v17 )
*((_WORD *)v27 + 2) = v19;
if( v12 == v25 )
{
v11 = 0;
}
else
{
if( v16 == v14 && (LODWORD(PoolWithTag) = *(unsigned __int16 *)&v5[v15 + 2], v26 == (_DWORD)PoolWithTag) )
{
LOBYTE(PoolWithTag) = RtlIsZeroMemory(&v5[v12], v25 - v12);
v11 = 0;
if( !(_BYTE)PoolWithTag )
{
v9 = 1;
if( CheckOnly )
goto LABEL_89;
}
}
else
{
v11 = 0;
}
if( !CheckOnly )
{
LODWORD(PoolWithTag) = memset((INT64)&v8[v12], 0i64);
v11 = 0;
}
v12 = (v12 + 3) & 0xFFFFFFFC;
}
}
}
v45 = ++v13;
}
while( v13 <= 2 );
LODWORD(PoolWithTag) = *((_DWORD *)v5 + 1);
if( v12 != (_DWORD)PoolWithTag )
{
v9 = 1;
if( CheckOnly )
goto LABEL_89;
*((_DWORD *)v8 + 1) = v12;
LODWORD(PoolWithTag) = *((_DWORD *)v5 + 1);
}
v31 = &v5[(unsigned int)PoolWithTag];
v32 = RtlLengthRequiredSid(v31[1]);
v33 = v32;
if( !CheckOnly )
memmove(&v8[*((unsigned int *)v8 + 1)], v31, v32);
LODWORD(PoolWithTag) = *((_DWORD *)v5 + 2);
v12 += v33;
if( (_DWORD)PoolWithTag )
{
if( v12 != (_DWORD)PoolWithTag )
{
v9 = 1;
if( CheckOnly )
goto LABEL_89;
*((_DWORD *)v8 + 2) = v12;
LODWORD(PoolWithTag) = *((_DWORD *)v5 + 2);
}
v34 = &v5[(unsigned int)PoolWithTag];
LODWORD(PoolWithTag) = RtlLengthRequiredSid(v34[1]);
v35 = PoolWithTag;
if( !CheckOnly )
memmove(&v8[*((unsigned int *)v8 + 2)], v34, (unsigned int)PoolWithTag);
v12 += v35;
}
LABEL_80:
if( !v9 || CheckOnly )
{
LABEL_89:
if( v48 )
ExFreePoolWithTag(v8, 0);
goto LABEL_91;
}
v36 = NewSecurityDescriptor;
if( NewSecurityDescriptor )
{
if( !v48 )
goto LABEL_87;
}
else
{
ExFreePoolWithTag(v5, 0);
v36 = SecurityDescriptor;
}
*v36 = v8;
LABEL_87:
LODWORD(PoolWithTag) = (_DWORD)NewSecurityDescriptorLength;
if( NewSecurityDescriptorLength )
*NewSecurityDescriptorLength = v12;
LABEL_91:
LOBYTE(PoolWithTag) = v9;
return PoolWithTag;
}Referenced by:
No references.