SeQuerySecurityDescriptorInfo

NTSTATUS __stdcall SeQuerySecurityDescriptorInfo(
        UINT64 *SecurityInformation,
        VOID *SecurityDescriptor,
        UINT64 *Length,
        VOID **ObjectsSecurityDescriptor){
  UINT64 *v4; 
  _DWORD *v5; 
  size_t v7; 
  unsigned int v8; 
  unsigned int v9; 
  unsigned int *v10; 
  __int16 v11; 
  __int64 v12; 
  unsigned __int8 *v13; 
  __int64 v14; 
  unsigned __int8 *v15; 
  __int64 v16; 
  unsigned __int16 *v17; 
  _ACL *v18; 
  unsigned __int64 v19; 
  unsigned int v20; 
  int v21; 
  int v22; 
  int v23; 
  int v24; 
  UINT64 v25; 
  __int16 v26; 
  _ACL *v27; 
  int v28; 
  UINT64 *v29; 
  int v30; 
  char v31; 
  __int64 v32; 
  UINT64 Lengtha; 
  _ACL *pSourceSacl; 
  unsigned __int64 v36; 
  _ACL *v37; 
  unsigned int v38; 
  __int128 v39; 
  unsigned __int8 *v40; 
  _ACL *v41; 
  unsigned __int16 *v42; 

  v4 = Length;
  v5 = SecurityDescriptor;
  v7 = 0;
  v8 = 0;
  Lengtha = 0i64;
  v9 = *(_DWORD *)v4;
  v38 = *(_DWORD *)v4;
  v10 = (unsigned int *)*ObjectsSecurityDescriptor;
  if( *ObjectsSecurityDescriptor )
  {
    v39 = *(_OWORD *)v10;
    LODWORD(v40) = v10[4];
    v11 = *((_WORD *)v10 + 1);
    if( v11 >= 0 )
    {
      v13 = (unsigned __int8 *)*((_QWORD *)v10 + 1);
    }
    else
    {
      v12 = v10[1];
      if( (_DWORD)v12 )
        v13 = (unsigned __int8 *)v10 + v12;
      else
        v13 = 0i64;
    }
    *((_QWORD *)&v39 + 1) = v13;
    if( v11 >= 0 )
    {
      v15 = (unsigned __int8 *)*((_QWORD *)v10 + 2);
    }
    else
    {
      v14 = v10[2];
      if( (_DWORD)v14 )
        v15 = (unsigned __int8 *)v10 + v14;
      else
        v15 = 0i64;
    }
    v40 = v15;
    if( (v11 & 4) != 0 )
    {
      if( v11 >= 0 )
      {
        v17 = (unsigned __int16 *)*((_QWORD *)v10 + 4);
      }
      else
      {
        v16 = v10[4];
        if( (_DWORD)v16 )
          v17 = (unsigned __int16 *)((char *)v10 + v16);
        else
          v17 = 0i64;
      }
    }
    else
    {
      v17 = 0i64;
    }
    v42 = v17;
    if( (v11 & 0x10) != 0 )
    {
      if( v11 >= 0 )
      {
        v18 = (_ACL *)*((_QWORD *)v10 + 3);
      }
      else
      {
        v32 = v10[3];
        if( (_DWORD)v32 )
          v18 = (_ACL *)((char *)v10 + v32);
        else
          v18 = 0i64;
      }
    }
    else
    {
      v18 = 0i64;
    }
    pSourceSacl = v18;
    v41 = v18;
    v19 = (unsigned __int64)v39 >> 16;
    LOWORD(v19) = WORD1(v39) & 0x7FFF;
    v36 = v19;
    WORD1(v39) &= ~0x8000u;
    v20 = 20;
    v21 = *(_DWORD *)SecurityInformation;
    v22 = *(_DWORD *)SecurityInformation & 0x80;
    v23 = *(_DWORD *)SecurityInformation & 0x100;
    if( (*(_DWORD *)SecurityInformation & 0x10000) != 0 )
    {
      v21 |= 0x1FFu;
      *(_DWORD *)SecurityInformation = v21;
      if( !v22 )
      {
        v21 &= ~0x80u;
        *(_DWORD *)SecurityInformation = v21;
      }
      if( !v23 )
      {
        v21 &= ~0x100u;
        *(_DWORD *)SecurityInformation = v21;
      }
    }
    if( (v21 & 1) != 0 && v13 )
    {
      v24 = v13[1];
      v7 = 4 * v24 + 8;
      v20 = ((4 * v24 + 11) & 0xFFFFFFFC) + 20;
    }
    if( (v21 & 2) != 0 && v15 )
    {
      HIDWORD(Lengtha) = 4 * v15[1] + 8;
      v20 += (HIDWORD(Lengtha) + 3) & 0xFFFFFFFC;
    }
    if( (v21 & 4) != 0 && (BYTE2(v39) & 4) != 0 && v17 )
    {
      v8 = (v17[1] + 3) & 0xFFFFFFFC;
      v20 += v8;
    }
    v25 = v21 & 0x1F8;
    if( (_DWORD)v25 && (BYTE2(v39) & 0x10) != 0 && pSourceSacl )
    {
      RtlpFilterSacl(pSourceSacl, 0i64, &Lengtha, v25);
      v20 += Lengtha;
      LOWORD(v19) = v36;
      v5 = SecurityDescriptor;
      v4 = Length;
    }
    *(_DWORD *)v4 = v20;
    if( v20 > v38 )
    {
      return -1073741789;
    }
    else
    {
      *(_OWORD *)v5 = 0i64;
      v5[4] = 0;
      *(_BYTE *)v5 = 1;
      v26 = *((_WORD *)v5 + 1) | 0x8000;
      *((_WORD *)v5 + 1) = v26;
      v27 = (_ACL *)(((unsigned __int64)v5 + 23) & 0xFFFFFFFFFFFFFFFCui64);
      v37 = v27;
      v28 = *(_DWORD *)SecurityInformation;
      if( (*(_DWORD *)SecurityInformation & 1) != 0 && v13 )
      {
        memmove(v27, v13, v7);
        v5 = SecurityDescriptor;
        *((_DWORD *)SecurityDescriptor + 1) = (_DWORD)v27 - (_DWORD)SecurityDescriptor;
        LOWORD(v19) = v36;
        *((_WORD *)SecurityDescriptor + 1) |= v36 & 1;
        v26 = *((_WORD *)SecurityDescriptor + 1);
        v27 = (_ACL *)((char *)v27 + ((v7 + 3) & 0xFFFFFFFC));
        v37 = v27;
        v29 = SecurityInformation;
        v28 = *(_DWORD *)SecurityInformation;
      }
      else
      {
        v29 = SecurityInformation;
      }
      if( (v28 & 2) != 0 && v15 )
      {
        v30 = HIDWORD(Lengtha);
        memmove(v27, v15, HIDWORD(Lengtha));
        v5 = SecurityDescriptor;
        *((_DWORD *)SecurityDescriptor + 2) = (_DWORD)v27 - (_DWORD)SecurityDescriptor;
        LOWORD(v19) = v36;
        *((_WORD *)SecurityDescriptor + 1) |= v36 & 2;
        v26 = *((_WORD *)SecurityDescriptor + 1);
        v27 = (_ACL *)((char *)v27 + ((v30 + 3) & 0xFFFFFFFC));
        v37 = v27;
        v28 = *(_DWORD *)v29;
      }
      if( (v28 & 4) != 0 )
      {
        *((_WORD *)v5 + 1) = v26 | v19 & 0x140C;
        v31 = BYTE2(v39);
        if( (BYTE2(v39) & 4) != 0 && v17 )
        {
          memmove(v27, v17, v17[1]);
          v5 = SecurityDescriptor;
          *((_DWORD *)SecurityDescriptor + 4) = (_DWORD)v27 - (_DWORD)SecurityDescriptor;
          v27 = (_ACL *)((char *)v27 + v8);
          v37 = v27;
        }
      }
      else
      {
        v31 = BYTE2(v39);
      }
      if( (*(_DWORD *)v29 & 0x1F8) != 0 )
      {
        *((_WORD *)v5 + 1) |= v36 & 0x2830;
        if( (v31 & 0x10) != 0 )
        {
          if( pSourceSacl )
          {
            RtlpFilterSacl(pSourceSacl, v27, &Lengtha, *(_DWORD *)v29 & 0x1F8);
            *((_DWORD *)SecurityDescriptor + 3) = (_DWORD)v27 - (_DWORD)SecurityDescriptor;
            v37 = (_ACL *)((char *)v27 + (unsigned int)Lengtha);
          }
        }
      }
      return 0;
    }
  }
  else
  {
    *(_DWORD *)v4 = 20;
    if( v9 < 0x14 )
    {
      return -1073741789;
    }
    else
    {
      *(_OWORD *)SecurityDescriptor = 0i64;
      *((_DWORD *)SecurityDescriptor + 4) = 0;
      *(_BYTE *)SecurityDescriptor = 1;
      *((_WORD *)SecurityDescriptor + 1) |= 0x8000u;
      return 0;
    }
  }
}

Referenced by:

CmpQueryKeySecurity
EtwQueryPerformanceTraceInformation
IopGetSetSecurityObject
ObQuerySecurityDescriptorInfo
ObpAllocateAndQuerySecurityDescriptorInfo