AuthzBasepInitializeResourceClaimsFromSacl

__int64 __fastcall AuthzBasepInitializeResourceClaimsFromSacl(__int64 a1, __int64 a2){
  int v3; 
  int *v4; 
  _DWORD *v5; 
  _DWORD *v6; 
  __int64 v7; 
  _QWORD *v8; 
  unsigned int v9; 
  int v11; 
  UINT64 v12; 
  int SecurityAttributesToken; 
  size_t v14; 
  SIZE_T NumberOfBytes; 
  int v16; 
  __int128 v17; 
  _QWORD *v18; 
  int P[64]; 
  v18 = (_QWORD *)a2;
  v16 = 2;
  NumberOfBytes = 256i64;
  v3 = 0;
  v17 = 0i64;
  v4 = P;
  v5 = AuthzBasepMemAlloc(0x30ui64, a2);
  v6 = v5;
  if( !v5 )
    return(unsigned int)-1073741801;
  *v5 = 0;
  v7 = a1 + 8;
  v8 = v5 + 2;
  v6[6] = 0;
  v9 = 0;
  v8[1] = v8;
  *v8 = v8;
  *((_QWORD *)v6 + 5) = v6 + 8;
  *((_QWORD *)v6 + 4) = v6 + 8;
  if( !*(_WORD *)(a1 + 4) )
    goto LABEL_12;
  while( 1 )
  {
    if( v4 && v4 != P )
      ExFreePoolWithTag(v4, 0);
    LODWORD(NumberOfBytes) = 256;
    v4 = P;
    if( *(_BYTE *)v7 != 18 || (*(_BYTE *)(v7 + 1) & 8) != 0 )
      goto LABEL_7;
    v11 = *(unsigned __int16 *)(v7 + 2) - 4 * *(unsigned __int8 *)(v7 + 9);
    v3 = AuthzBasepConvertRelativeToAbsoluteTokenAttribute(
           (UINT64 *)(v7 + 8 + 4 * (unsigned int)*(unsigned __int8 *)(v7 + 9) + 8),
           (unsigned int)(v11 - 16),
           (INT64)P,
           &NumberOfBytes);
    if( v3 == -1073741789 )
      break;
LABEL_19:
    if( v3 < 0 )
      goto LABEL_8;
    *((_QWORD *)&v17 + 1) = v4;
    LOWORD(v17) = 1;
    DWORD1(v17) = 1;
    LODWORD(v14) = 0;
    SecurityAttributesToken = AuthzBasepQuerySecurityAttributesToken(
                                v6,
                                (__int64)v4,
                                1u,
                                0i64,
                                v14,
                                (_DWORD *)&NumberOfBytes + 1);
    v3 = SecurityAttributesToken;
    if( SecurityAttributesToken == -1073741789 || SecurityAttributesToken == -1073741275 )
      v3 = 0;
    if( v3 < 0 )
      goto LABEL_8;
    if( HIDWORD(NumberOfBytes) <= 0x10 )
      v3 = AuthzBasepSetSecurityAttributesToken(v6, &v16, (__int64)&v17);
    if( v3 < 0 )
      goto LABEL_8;
LABEL_7:
    ++v9;
    v7 += *(unsigned __int16 *)(v7 + 2);
    if( v9 >= *(unsigned __int16 *)(a1 + 4) )
      goto LABEL_8;
  }
  v4 = (int *)AuthzBasepMemAlloc((unsigned int)NumberOfBytes, v12);
  if( v4 )
  {
    v3 = AuthzBasepConvertRelativeToAbsoluteTokenAttribute(
           (UINT64 *)(v7 + 4 * (*(unsigned __int8 *)(v7 + 9) + 4i64)),
           (unsigned int)(v11 - 16),
           (INT64)v4,
           &NumberOfBytes);
    goto LABEL_19;
  }
  v3 = -1073741801;
LABEL_8:
  if( v4 && v4 != P )
    ExFreePoolWithTag(v4, 0);
  if( v3 < 0 )
  {
    AuthzBasepFreeSecurityAttributesList(v6);
    ExFreePoolWithTag(v6, 0);
  }
  else
  {
LABEL_12:
    *v18 = v6;
  }
  return(unsigned int)v3;
}

Referenced by:

SeAccessCheckByTypeWithAdminlessChecks
SeAccessCheckWithHintWithAdminlessChecks
SeExamineSacl
SepAccessCheckAndAuditAlarmWithAdminlessChecks
SepCommonAccessCheckExWithAdminlessChecks
SepExamineSaclEx
SepFilterCheck
SepMaximumAccessCheck
SepMaximumAccessCheckEx
SepNormalAccessCheck
SepNormalAccessCheckEx