AuthzBasepEvaluateAceCondition

__int64 __fastcall AuthzBasepEvaluateAceCondition(
        __int64 a1,
        __int64 a2,
        __int64 a3,
        __int64 a4,
        __int64 a5,
        __int64 a6,
        __int64 a7,
        char *a8,
        unsigned int a9,
        char a10,
        char a11,
        int *a12){
  unsigned int v12; 
  char *v13; 
  int SecurityAttributeAndValues; 
  __int64 v16; 
  __int64 v17; 
  int v18; 
  __int64 v19; 
  unsigned int v20; 
  int v21; 
  __int64 v22; 
  INT64 v23; 
  UINT8 v24; 
  PVOID *v25; 
  _QWORD *v26; 
  PVOID v27; 
  _DWORD *v28; 
  __int64 v29; 
  INT64 v30; 
  UINT8 v31; 
  PVOID *v32; 
  __int64 v33; 
  __int64 v34; 
  int v35; 
  int v36; 
  int *v37; 
  BYTE *v38; 
  PVOID *v39; 
  int v41; 
  INT64 v42; 
  bool v43; 
  INT64 v44; 
  int v45; 
  int v46; 
  INT64 v47; 
  INT64 v48; 
  INT64 v49; 
  int v50; 
  bool v51; 
  char v52; 
  int v53; 
  bool v54; 
  char v55; 
  __int64 v56; 
  __int64 v57; 
  int v58; 
  PVOID v59; 
  char v60[4]; 
  BYTE v61[2]; 
  INT64 v62; 
  int *v63; 
  char v64; 
  UINT64 StackPos; 
  unsigned int v66; 
  INT64 Result; 
  PVOID Token; 
  PVOID *v69; 
  INT64 result[2]; 
  INT64 v71[2]; 
  __int64 v72; 
  __int128 v73; 
  INT64 v74[2]; 
  __int64 v75; 
  INT64 v76; 
  void *v77; 
  __int64 v78; 
  PVOID v79; 
  INT64 v80; 
  char *v81; 
  void *v82; 
  void *v83; 
  void *v84; 
  void *v85; 
  void *v86; 
  PCUNICODE_STRING String2; 
  __int128 v88; 
  __int128 v89; 
  char *v90; 
  __int128 v91; 
  PVOID P[2]; 
  __int128 v93; 
  __int128 v94; 
  __int64 v95; 
  INT64 v96[2]; 
  __int128 v97; 
  __int128 v98; 
  __int128 v99; 
  __int64 v100; 
  INT64 ResultStack[128]; 
  v12 = 0;
  v13 = a8;
  SecurityAttributeAndValues = 0;
  v82 = (void *)a5;
  v85 = (void *)a6;
  v86 = (void *)a3;
  v77 = (void *)a2;
  Token = (PVOID)a1;
  v84 = (void *)a7;
  v83 = (void *)a4;
  v81 = a8;
  v63 = a12;
  LODWORD(StackPos) = 0;
  LODWORD(v91) = 0;
  *((_QWORD *)&v91 + 1) = 0i64;
  memset((INT64)P, 0i64);
  LOWORD(result[0]) = 0;
  BYTE4(result[0]) = 0;
  memset((INT64)result + 5, 0i64);
  LODWORD(v62) = -1;
  v90 = 0i64;
  v80 = -1i64;
  Result = 0i64;
  v16 = 2i64;
  LODWORD(v76) = 0;
  *(_WORD *)v61 = 0;
  WORD2(v62) = 0;
  v60[0] = 0;
  BYTE4(StackPos) = 0;
  v64 = 0;
  v79 = 0i64;
  *a12 = -1;
  P[1] = 0i64;
  *((_QWORD *)&v97 + 1) = 0i64;
  v88 = 0i64;
  HIDWORD(v88) = 1;
  v89 = 0i64;
  if( !a1 || !a8 )
  {
    SecurityAttributeAndValues = -1073741811;
    v37 = a12;
    goto LABEL_40;
  }
  BYTE5(StackPos) = KeGetCurrentIrql() >= 2u;
  if( a9 < 4 )
  {
    *a12 = 1;
    SecurityAttributeAndValues = -2147483601;
    v37 = a12;
    goto LABEL_40;
  }
  if( *(_DWORD *)a8 != 2020897377 )
  {
    *a12 = 1;
    SecurityAttributeAndValues = -2147483601;
    v37 = a12;
    goto LABEL_40;
  }
  AuthzBasepResetOperands((INT64)result, v61);
  LODWORD(v17) = 4;
  v66 = 0;
  if( a9 <= 4 )
    goto LABEL_61;
  do
  {
    v18 = (unsigned __int8)v13[(unsigned int)v17];
    if( v18 == 248 )
    {
LABEL_14:
      v19 = (unsigned int)(v17 + 1);
      if( v12 == 2 )
      {
        if( HIDWORD(result[1]) == 1 )
          goto LABEL_59;
        LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
        SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, (unsigned int)v62);
        if( SecurityAttributeAndValues < 0 )
          goto LABEL_60;
        if( v61[0] )
          ExFreePoolWithTag(*(PVOID *)(v57 + 24), 0);
        v91 = *(_OWORD *)v96;
        *(_OWORD *)P = v97;
        v93 = v98;
        v95 = v100;
        v94 = v99;
        v71[1] = v74[1];
        v71[0] = (INT64)&v91;
        v61[0] = v61[1];
        *(_OWORD *)result = v73;
        v72 = v75;
        v61[1] = 0;
        v73 = 0i64;
        v75 = 0i64;
        *(_OWORD *)v74 = 0i64;
        memset((INT64)v96, 0i64);
        v12 = 1;
        v66 = 1;
      }
      if( a9 - (unsigned int)v19 < 4 )
        goto LABEL_59;
      v20 = *(_DWORD *)&v13[v19];
      v21 = v19 + 4;
      if( a9 - v21 < v20 )
        goto LABEL_59;
      if( v20 > 0xFFFE )
      {
        SecurityAttributeAndValues = -1073741562;
        goto LABEL_60;
      }
      v90 = &v81[v21];
      DWORD2(v89) = v20;
      v22 = 9i64 * v12;
      v78 = v22 * 8;
      String2 = (PCUNICODE_STRING)&P[v22];
      SecurityAttributeAndValues = AuthzBasepUnicodeStringFromOperandValue(
                                     (__int64)&v88,
                                     0,
                                     (unsigned __int16 *)&P[v22],
                                     &v61[v12]);
      if( SecurityAttributeAndValues < 0 )
        goto LABEL_60;
      v25 = &P[v22 - 2];
      v26 = (PVOID *)((char *)&P[-1] + v78);
      v69 = (PVOID *)((char *)&P[-1] + v78);
      switch( (_BYTE)v18 )
      {
        case 0xF9:
          v27 = v82;
          if( !a11 )
            v27 = v83;
          *(_DWORD *)v25 = 3;
          break;
        case 0xFB:
          v27 = v84;
          if( !a11 )
            v27 = v85;
          *(_DWORD *)v25 = 5;
          break;
        case 0xFA:
          v27 = v86;
          *(_DWORD *)v25 = 4;
          break;
        case 0xFC:
          v28 = Token;
          v27 = Token;
          *(_DWORD *)v25 = 6;
LABEL_25:
          *v26 = v27;
          v29 = 9i64 * v12;
          *((_QWORD *)&v94 + v29 + 1) = 0i64;
          v96[v29 - 1] = 0i64;
          SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v23, v24);
          if( SecurityAttributeAndValues != -1073741275 )
            goto LABEL_32;
          if( *(_DWORD *)v25 == 2 )
          {
            v30 = *((unsigned int *)SepSingletonGlobal + 4);
            if( (v30 & 1) != 0
              && (v28[50] & 0x20000) == 0
              && SepPotentialGlobalTableAttribute((UNICODE_STRING *)String2)
              && !BYTE4(StackPos) )
            {
              if( v64 )
              {
LABEL_180:
                v32 = v69;
                *v69 = v79;
                SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v30, v31);
                if( SecurityAttributeAndValues != -1073741275 )
                  goto LABEL_32;
                *v32 = v77;
                goto LABEL_29;
              }
              v58 = SepValidateAndCopyGlobalEntry((__int64)v77, &v79);
              SecurityAttributeAndValues = v58;
              if( v58 >= 0 )
              {
                v64 = 1;
                goto LABEL_180;
              }
              BYTE4(StackPos) = 1;
              if( v58 != -1073741275 )
                goto LABEL_32;
            }
          }
          v32 = v69;
LABEL_29:
          if( BYTE5(StackPos) || *(_DWORD *)v25 != 2 )
            goto LABEL_67;
          *(_DWORD *)v25 = 7;
          *v32 = 0i64;
          SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v30, v31);
LABEL_32:
          if( SecurityAttributeAndValues >= 0 )
          {
            v33 = v78;
            v34 = 5i64 * v12;
            v71[v34] = (INT64)v25;
            LOWORD(result[v34]) = *(_WORD *)((char *)&v93 + v33);
            HIDWORD(result[v34]) = *(_DWORD *)((char *)&v93 + v33 + 8);
LABEL_34:
            v35 = *(_DWORD *)v25;
            LODWORD(v71[v34 + 1]) = 0;
            *(__int64 *)((char *)&v72 + v34 * 8) = 0i64;
            LODWORD(result[v34 + 1]) = 0;
            v12 = v66 + 1;
            HIDWORD(result[v34 + 1]) = v35;
            LODWORD(v17) = v20 + v21;
            v13 = v81;
LABEL_35:
            v66 = v12;
            continue;
          }
          if( SecurityAttributeAndValues != -1073741275 )
            goto LABEL_60;
LABEL_67:
          v34 = 5i64 * v12;
          SecurityAttributeAndValues = 0;
          LOWORD(result[v34]) = 0;
          HIDWORD(result[v34]) = 0;
          v71[v34] = 0i64;
          if( v61[v12] )
          {
            ExFreePoolWithTag(*(PVOID *)((char *)&P[1] + v78), 0);
            if( v12 >= 2ui64 )
              _report_rangecheckfailure();
            v61[v12] = 0;
          }
          goto LABEL_34;
        default:
          v27 = v77;
          *(_DWORD *)v25 = 2;
          break;
      }
      v28 = Token;
      goto LABEL_25;
    }
    if( v18 == 162 )
    {
      LODWORD(v17) = v17 + 1;
      if( !AuthzBasepIsValidExpression(0xA2ui64, (__int64)result, v12, v60) )
        goto LABEL_59;
      if( v12 == 1 )
      {
        LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
        v41 = v62;
        AuthzBasepResetOperands((INT64)result, v61);
      }
      else
      {
        SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, &v62);
        if( SecurityAttributeAndValues < 0 )
          goto LABEL_60;
        v41 = v62;
      }
      if( v41 == -1 )
        v42 = 0xFFFFFFFFi64;
      else
        v42 = v41 == 0;
      goto LABEL_53;
    }
    if( (_BYTE)v18 )
    {
      if( v18 != 134 )
      {
        if( v18 == 16 )
        {
LABEL_11:
          if( v12 == 2 )
          {
            if( HIDWORD(result[1]) == 1 )
              goto LABEL_59;
            LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
            SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, (unsigned int)v62);
            if( SecurityAttributeAndValues < 0 )
              goto LABEL_60;
            if( v61[0] )
              ExFreePoolWithTag(*(PVOID *)(v56 + 24), 0);
            v91 = *(_OWORD *)v96;
            *(_OWORD *)P = v97;
            v93 = v98;
            v95 = v100;
            v94 = v99;
            v71[1] = v74[1];
            v71[0] = (INT64)&v91;
            v61[0] = v61[1];
            *(_OWORD *)result = v73;
            v72 = v75;
            v61[1] = 0;
            v73 = 0i64;
            v75 = 0i64;
            *(_OWORD *)v74 = 0i64;
            memset((INT64)v96, 0i64);
            v12 = 1;
          }
          SecurityAttributeAndValues = AuthzBasepGetConstantOperand(
                                         &v13[(unsigned int)v17],
                                         a9 - (unsigned int)v17,
                                         (INT64)&result[5 * v12],
                                         &v76);
          if( SecurityAttributeAndValues < 0 )
            goto LABEL_60;
          ++v12;
          LODWORD(v17) = v76 + v17;
          goto LABEL_35;
        }
        switch( v13[(unsigned int)v17] )
        {
          case 1:
          case 2:
          case 3:
          case 4:
          case 24:
          case 80:
          case 81:
            goto LABEL_11;
          case -128:
          case -127:
          case -126:
          case -125:
          case -124:
          case -123:
          case -120:
          case -114:
          case -113:
            goto LABEL_62;
          case -121:
          case -115:
            LODWORD(v17) = v17 + 1;
            if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
              goto LABEL_59;
            v44 = v71[0] != 0;
            LODWORD(v62) = v71[0] != 0;
            if( (_BYTE)v18 == 0x8D )
            {
              v44 = v71[0] == 0;
              LODWORD(v62) = v71[0] == 0;
            }
            goto LABEL_74;
          case -119:
          case -117:
          case -112:
          case -110:
            LODWORD(v17) = v17 + 1;
            if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
            {
              SecurityAttributeAndValues = -1073741406;
              if( !v60[0] )
                goto LABEL_60;
LABEL_115:
              v49 = 0xFFFFFFFFi64;
              LODWORD(v62) = -1;
              v50 = -1;
              goto LABEL_127;
            }
            if( v60[0] )
            {
              v52 = BYTE5(v62);
            }
            else
            {
              v51 = (_BYTE)v18 == 0x89 || (_BYTE)v18 == 0x90;
              SecurityAttributeAndValues = AuthzBasepMemberOf(
                                             (INT64)result,
                                             Token,
                                             (unsigned __int8)a10,
                                             a11,
                                             v51,
                                             (INT64)&v62 + 4);
              v52 = BYTE4(v62);
              BYTE5(v62) = BYTE4(v62);
            }
            if( SecurityAttributeAndValues < 0 )
              goto LABEL_115;
            if( v52 )
            {
              v49 = 1i64;
              LODWORD(v62) = 1;
              v50 = 1;
            }
            else
            {
              v49 = 0i64;
              LODWORD(v62) = 0;
              v50 = 0;
            }
LABEL_127:
            if( (((_BYTE)v18 + 112) & 0xFD) == 0 && v50 != -1 )
            {
              v49 = v50 == 0;
              LODWORD(v62) = v50 == 0;
            }
            SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v49);
            if( SecurityAttributeAndValues >= 0 )
              goto LABEL_54;
            goto LABEL_60;
          case -118:
          case -116:
          case -111:
          case -109:
            LODWORD(v17) = v17 + 1;
            if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
            {
              SecurityAttributeAndValues = -1073741406;
              if( !v60[0] )
                goto LABEL_60;
LABEL_134:
              v44 = 0xFFFFFFFFi64;
              LODWORD(v62) = -1;
              v53 = -1;
              goto LABEL_146;
            }
            if( v60[0] )
            {
              v55 = BYTE5(v62);
            }
            else
            {
              v54 = (_BYTE)v18 == 0x8A || (_BYTE)v18 == 0x91;
              SecurityAttributeAndValues = AuthzBasepDeviceMemberOf(
                                             (__int64)result,
                                             (__int64)Token,
                                             (unsigned __int8)a10,
                                             a11,
                                             v54,
                                             (_BYTE *)&v62 + 4);
              v55 = BYTE4(v62);
              BYTE5(v62) = BYTE4(v62);
            }
            if( SecurityAttributeAndValues < 0 )
              goto LABEL_134;
            if( v55 )
            {
              v44 = 1i64;
              LODWORD(v62) = 1;
              v53 = 1;
            }
            else
            {
              v44 = 0i64;
              LODWORD(v62) = 0;
              v53 = 0;
            }
LABEL_146:
            if( (((_BYTE)v18 + 111) & 0xFD) == 0 && v53 != -1 )
            {
              v44 = v53 == 0;
              LODWORD(v62) = v53 == 0;
            }
LABEL_74:
            SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v44);
            if( SecurityAttributeAndValues >= 0 )
              goto LABEL_54;
            goto LABEL_60;
          case -96:
          case -95:
            LODWORD(v17) = v17 + 1;
            if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
              goto LABEL_59;
            if( v12 == 2 )
            {
              LODWORD(Result) = AuthzBasepEvaluateAttribute(v71[0]);
              v45 = AuthzBasepEvaluateAttribute(v74[0]);
              HIDWORD(Result) = v45;
            }
            else
            {
              if( v12 == 1 )
              {
                LODWORD(Result) = AuthzBasepEvaluateAttribute(v71[0]);
              }
              else
              {
                SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, &Result);
                if( SecurityAttributeAndValues < 0 )
                  goto LABEL_60;
              }
              SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, (INT64 *)((char *)&Result + 4));
              if( SecurityAttributeAndValues < 0 )
                goto LABEL_60;
              v45 = HIDWORD(Result);
            }
            if( (_BYTE)v18 == 0xA0 )
            {
              if( !v46 || !v45 )
                goto LABEL_100;
              if( v46 == -1 || v45 == -1 )
                goto LABEL_95;
            }
            else if( v46 != 1 && v45 != 1 )
            {
              if( v46 != -1 && v45 != -1 )
              {
LABEL_100:
                v47 = 0i64;
                LODWORD(v62) = 0;
                goto LABEL_103;
              }
LABEL_95:
              v47 = 0xFFFFFFFFi64;
              goto LABEL_102;
            }
            v47 = 1i64;
LABEL_102:
            LODWORD(v62) = v47;
LABEL_103:
            SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v47);
            if( SecurityAttributeAndValues < 0 )
              goto LABEL_60;
            break;
          case -93:
            LODWORD(v17) = v17 + 1;
            if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
            {
              SecurityAttributeAndValues = -1073741406;
              if( !v60[0] )
                goto LABEL_60;
LABEL_107:
              v48 = 0xFFFFFFFFi64;
              goto LABEL_108;
            }
            if( v60[0] )
              goto LABEL_107;
            AuthzBasepComputeExpression(v18, (INT64)result, &v80);
            if( v80 == -1 )
              goto LABEL_107;
            v48 = v80 != 0;
LABEL_108:
            LODWORD(v62) = v48;
            SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v48);
            if( SecurityAttributeAndValues < 0 )
              goto LABEL_60;
            AuthzBasepResetOperands((INT64)result, v61);
            continue;
          case -7:
          case -6:
          case -5:
          case -4:
            goto LABEL_14;
          default:
            goto LABEL_59;
        }
        goto LABEL_54;
      }
LABEL_62:
      LODWORD(v17) = v17 + 1;
      if( AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
      {
        if( !v60[0] )
        {
          AuthzBasepEvaluateExpression(v18, (INT64)result, (BOOL *)&v62);
          v42 = (unsigned int)v62;
          if( ((_BYTE)v18 == 0x8E || (_BYTE)v18 == 0x8F) && (_DWORD)v62 != -1 )
          {
            v42 = (_DWORD)v62 == 0;
            LODWORD(v62) = v62 == 0;
          }
LABEL_53:
          SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v42);
          if( SecurityAttributeAndValues < 0 )
            goto LABEL_60;
LABEL_54:
          AuthzBasepResetOperands((INT64)result, v61);
          v12 = 0;
          v66 = 0;
          continue;
        }
      }
      else
      {
        SecurityAttributeAndValues = -1073741406;
        if( !v60[0] )
          goto LABEL_60;
      }
      v42 = 0xFFFFFFFFi64;
      LODWORD(v62) = -1;
      goto LABEL_53;
    }
    while( 1 )
    {
      v17 = (unsigned int)(v17 + 1);
      v43 = (_DWORD)v17 == a9;
      if( (unsigned int)v17 >= a9 )
        break;
      if( v13[v17] )
      {
        v43 = (_DWORD)v17 == a9;
        break;
      }
    }
    if( !v43 )
    {
LABEL_59:
      SecurityAttributeAndValues = -1073741406;
      goto LABEL_60;
    }
  }
  while( (unsigned int)v17 < a9 );
  if( (_DWORD)StackPos == 1 )
  {
    v36 = ResultStack[0];
LABEL_39:
    v37 = v63;
    v16 = 2i64;
    *v63 = v36;
    goto LABEL_40;
  }
  if( !(_DWORD)StackPos && v12 == 1 )
  {
    v36 = AuthzBasepEvaluateAttribute(v71[0]);
    goto LABEL_39;
  }
LABEL_60:
  v16 = 2i64;
LABEL_61:
  v37 = v63;
LABEL_40:
  v38 = v61;
  v39 = &P[1];
  do
  {
    if( *v38 )
      ExFreePoolWithTag(*v39, 0);
    ++v38;
    v39 += 9;
    --v16;
  }
  while( v16 );
  if( v64 )
  {
    v59 = v79;
    if( v79 )
    {
      AuthzBasepFreeSecurityAttributesList(v79);
      ExFreePoolWithTag(v59, 0x74416553u);
    }
  }
  if( SecurityAttributeAndValues < 0 )
    *v37 = -1;
  return(unsigned int)SecurityAttributeAndValues;
}

Referenced by:

SeAccessCheckByTypeWithAdminlessChecks
SeAccessCheckWithHintWithAdminlessChecks
SeExamineSacl
SepAccessCheckAndAuditAlarmWithAdminlessChecks
SepCommonAccessCheckExWithAdminlessChecks
SepExamineSaclEx
SepFilterCheck
SepMaximumAccessCheck
SepMaximumAccessCheckEx
SepNormalAccessCheck
SepNormalAccessCheckEx
SepVerifyDesktopAppxPackageName