AuthzBasepCopyoutSecurityAttributes

int __fastcall AuthzBasepCopyoutSecurityAttributes(_DWORD *a1, __int64 a2, unsigned int a3, _DWORD *a4, size_t Size){
  size_t v5; 
  unsigned int v6; 
  _DWORD *v10; 
  UINT8 *v11; 
  unsigned int v12; 
  int result; 
  __int64 v14; 
  int v15; 
  ULONGLONG v16; 
  _DWORD *v17; 
  UNICODE_STRING *SecurityAttribute; 
  UINT8 *v19; 
  int Buffer_high; 
  ULONGLONG Length; 
  UINT64 v22; 
  INT64 *v23; 
  INT64 v24; 
  _DWORD *v25; 
  UINT8 *v26; 
  ULONGLONG v27; 
  UINT64 v28; 
  ULONGLONG pullResult; 
  v5 = Size;
  v6 = 0;
  v10 = a1;
  if( !a4 || !Size )
  {
    result = -1073741811;
    goto LABEL_16;
  }
  v11 = (UINT8 *)a4 + Size;
  if( (_DWORD *)((char *)a4 + Size) < a4 )
  {
    result = -1073741811;
  }
  else
  {
    memset((INT64)a4, 0i64);
    pullResult = 16i64;
    if( a4 + 4 > (_DWORD *)v11 )
    {
      result = -1073741789;
    }
    else
    {
      v12 = a3;
      if( !a2 )
        v12 = *v10;
      result = RtlULongLongMult(0x28ui64, v12, &pullResult);
      if( result >= 0 )
      {
        v16 = v14 + pullResult;
        if( v14 + pullResult <= (unsigned __int64)v11 )
        {
          *a4 = 1;
          a4[1] = v15;
          *((_QWORD *)a4 + 1) = v14;
          if( a2 )
          {
            if( a3 )
            {
              v17 = (_DWORD *)(v14 + 24);
              while( 1 )
              {
                SecurityAttribute = AuthzBasepFindSecurityAttribute(
                                      (__int64)v10,
                                      (const UNICODE_STRING *)(a2 + 16i64 * v6));
                if( !SecurityAttribute )
                  break;
                *((_WORD *)v17 - 4) = SecurityAttribute[3].Length;
                v19 = (UINT8 *)((v16 + 1) & 0xFFFFFFFFFFFFFFFEui64);
                Buffer_high = HIDWORD(SecurityAttribute[3].Buffer);
                *((_WORD *)v17 - 3) = 0;
                *v17 = Buffer_high;
                *(v17 - 1) = *(_DWORD *)(&SecurityAttribute[3].MaximumLength + 1);
                Length = SecurityAttribute[2].Length;
                pullResult = Length;
                if( &v19[Length] > v11 )
                  goto LABEL_28;
                *((_WORD *)v17 - 12) = Length;
                *((_WORD *)v17 - 11) = Length;
                *((_QWORD *)v17 - 2) = v19;
                memmove(v19, (UINT8 *)SecurityAttribute[2].Buffer, (unsigned int)Length);
                v22 = (UINT64)&v19[pullResult];
                result = AuthzBasepCopyoutSecurityAttributeValues(
                           (INT64)SecurityAttribute,
                           (INT64)(v17 - 6),
                           v22,
                           (INT64)&v11[-v22],
                           (INT64)&pullResult);
                if( result < 0 )
                  goto LABEL_25;
                v16 = pullResult + v22;
                ++v6;
                v10 = a1;
                v17 += 10;
                if( v6 >= a3 )
                  goto LABEL_16;
              }
              result = -1073741275;
              goto LABEL_25;
            }
LABEL_16:
            if( result >= 0 )
              return result;
            goto LABEL_25;
          }
          v23 = (INT64 *)(v10 + 2);
          v24 = *v23;
          if( (INT64 *)*v23 == v23 )
            goto LABEL_16;
          v25 = (_DWORD *)(v14 + 24);
          while( 1 )
          {
            *((_WORD *)v25 - 4) = *(_WORD *)(v24 + 48);
            *v25 = *(_DWORD *)(v24 + 60);
            *((_WORD *)v25 - 3) = 0;
            v26 = (UINT8 *)((v16 + 1) & 0xFFFFFFFFFFFFFFFEui64);
            *(v25 - 1) = *(_DWORD *)(v24 + 52);
            v27 = *(unsigned __int16 *)(v24 + 32);
            pullResult = v27;
            if( &v26[v27] > v11 )
              break;
            *((_WORD *)v25 - 12) = v27;
            *((_WORD *)v25 - 11) = v27;
            *((_QWORD *)v25 - 2) = v26;
            memmove(v26, *(UINT8 **)(v24 + 40), (unsigned int)v27);
            v28 = (UINT64)&v26[pullResult];
            result = AuthzBasepCopyoutSecurityAttributeValues(
                       v24,
                       (INT64)(v25 - 6),
                       v28,
                       (INT64)&v11[-v28],
                       (INT64)&pullResult);
            if( result < 0 )
              goto LABEL_25;
            v16 = pullResult + v28;
            v25 += 10;
            v24 = *(_QWORD *)v24;
            if( (INT64 *)v24 == v23 )
              goto LABEL_16;
          }
        }
LABEL_28:
        result = -2147483643;
      }
    }
  }
LABEL_25:
  if( v5 >= 0x10 )
    *(_OWORD *)a4 = 0i64;
  return result;
}

Referenced by:

AuthzBasepQuerySecurityAttributesToken