RtlEnumerateBoundaryDescriptorEntries
__int64 __fastcall RtlEnumerateBoundaryDescriptorEntries(
_DWORD *a1,
unsigned int (__fastcall *a2)(_DWORD *, __int64),
__int64 a3){
__int64 v3;
__int64 v4;
char *v7;
_DWORD *v8;
int v9;
char *v10;
int v11;
int v12;
__int64 v13;
char *v14;
v3 = (unsigned int)a1[2];
v4 = a3;
if( (unsigned int)v3 >= 0x10 && *a1 == 1 )
{
v7 = (char *)a1 + v3;
if( (_DWORD *)((char *)a1 + v3) >= a1 )
{
v8 = a1 + 4;
v9 = 0;
v10 = (char *)(a1 + 6);
v11 = 0;
v12 = 0;
if( v10 >= v7 )
{
LABEL_18:
if( a1[1] == v12 )
return 0i64;
}
else
{
while( 1 )
{
v13 = (unsigned int)v8[1];
++v12;
if( (unsigned int)v13 < 8 )
break;
v14 = (char *)v8 + v13;
if( (_DWORD *)((char *)v8 + v13) < v8 || v14 > v7 )
break;
if( *v8 == 1 )
{
if( (unsigned int)++v11 > 1 )
return 3221225661i64;
}
else
{
if( *v8 != 2 )
{
if( *v8 != 3 )
return 3221225485i64;
if( (unsigned int)++v9 > 1 )
return 3221226026i64;
}
if( !RtlpValidateSidBuffer(v10, (unsigned int)(v13 - 8)) )
return 3221225485i64;
v4 = a3;
}
if( a2 && !a2(v8, v4) )
goto LABEL_18;
v8 = (_DWORD *)((unsigned __int64)(v14 + 7) & 0xFFFFFFFFFFFFFFF8ui64);
v10 = (char *)(v8 + 2);
if( v8 + 2 >= (_DWORD *)v7 )
goto LABEL_18;
v4 = a3;
}
}
}
}
return 3221225485i64;
}Referenced by:
ObpCaptureBoundaryDescriptor
ObpCheckDuplicateEntries
ObpCompareEntryLevel1
ObpLookupNamespaceEntry
ObpVerifyCreatorAccessCheck