SeAccessCheckByTypeWithAdminlessChecks
NTSTATUS __stdcall SeAccessCheckByTypeWithAdminlessChecks(
INT64 a1,
INT64 a2,
INT64 a3,
INT64 a4,
INT64 ObjectTypeList,
INT64 a6,
INT64 a7,
VOID *Address,
_SIZE_T Length,
INT64 a10,
INT64 a11,
VOID *a12,
INT8 ReturnResultList,
INT8 a14){
int v15;
char v16;
__int64 v17;
INT64 v18;
INT64 v19;
NTSTATUS result;
unsigned int v21;
int v22;
_TOKEN *v23;
__int16 v24;
__int64 v25;
char *v26;
__int64 v27;
char *v28;
VOID *v29;
INT64 v30;
NTSTATUS v31;
CHAR v32;
NTSTATUS v33;
unsigned __int8 v34;
_PRIVILEGE_SET *v35;
_ETHREAD *CurrentThread;
PERESOURCE *v37;
UINT8 v38;
UINT8 TokenIsOwner;
__int16 *v40;
int v41;
int v42;
UINT64 *GrantedAccess;
INT64 *AccessStatus;
__int64 v45;
UINT64 *Group;
INT8 v47;
_DWORD *v48;
_DWORD *v49;
INT64 *v50;
_DWORD *v51;
__int64 v52;
unsigned int v53;
__int64 v54;
CHAR v55;
int v56;
unsigned int v57;
_ACL *v58;
int v59;
int v60;
int v61;
int v62;
int v63;
_ETHREAD *v64;
INT64 v65;
_DWORD *v66;
unsigned int v67;
UINT64 v68;
_DWORD *v69;
unsigned int v70;
INT64 v71;
_DWORD *v72;
_DWORD *v73;
unsigned int v74;
UINT64 v75;
int v76;
unsigned int PrivilegeCount;
unsigned int v78;
unsigned int v79;
int v80;
size_t v81;
_SEP_LOGON_SESSION_REFERENCES *LogonSession;
_DWORD *v83;
unsigned int v84;
UINT64 v85;
__int64 v86;
_ACL *v87;
VOID *ScopedPolicySid;
NTSTATUS Cap;
_ACL *Sacl;
__int64 v91;
VOID **PoolWithTag;
int v93;
VOID **v94;
unsigned int v95;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v96;
_AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *pClaimAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v98;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v99;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v100;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *v101;
NTSTATUS v102;
int v103;
_AUTHZBASEP_CLAIM_ATTRIBUTES_COLLECTION *v104;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedDeviceSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pDeviceSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pRestrictedUserSecurityAttributes;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *pUserSecurityAttributes;
int v109;
int v110;
unsigned int v111;
unsigned int v112;
PVOID UseNewTrust;
PVOID UseNewTrusta;
VOID **TrustLevelSid;
VOID **TrustLevelSida;
VOID **TrustLevelSidb;
VOID **TrustLevelSidc;
VOID **TrustLevelSidd;
INT64 v120;
void *p_MandatoryInformation;
UINT64 v122;
UINT64 ConditionSize;
UINT64 ConditionSizea;
INT8 PreviousMode;
int v126;
char v127;
char v128;
UINT64 DesiredAccess;
char v130;
char v131;
char v132;
char v133[5];
UINT64 ObjectTypeListLength;
NTSTATUS v135;
int v136;
VOID *Token;
unsigned int v138;
VOID *OutputSecurityDescriptor;
UINT64 PreviouslyGrantedAccess;
char v141;
UINT64 v142;
_DWORD *v143;
INT64 Result;
INT64 *v145;
PVOID P;
int v147;
PRIVILEGE_SET *PrivilegeSet;
INT64 ResourceInfo;
INT64 v150;
_SECURITY_DESCRIPTOR SecurityDescriptor;
VOID *PrincipalSelfSid;
VOID *InputSecurityDescriptor;
INT64 v154;
_IOBJECT_TYPE_LIST *NewObjectTypeList;
UINT64 v156;
int v157;
int v158;
INT64 v159;
_SECURITY_SUBJECT_CONTEXT SubjectContext;
VOID *Src;
_SEP_MANDATORY_INFORMATION MandatoryInformation;
INT64 v163;
INT64 v164;
INT64 v165;
INT64 v166;
VOID *v167;
INT64 v168;
_DWORD *v169;
__int128 CapeSecurityDescriptor[2];
__int64 v171;
INT64 PackageCapabilityInfo[3];
int v173;
_GENERIC_MAPPING GenericMapping;
v15 = a2;
Src = (VOID *)a2;
InputSecurityDescriptor = (VOID *)a1;
v163 = a1;
v164 = a2;
v165 = a3;
LODWORD(DesiredAccess) = a4;
v166 = ObjectTypeList;
LODWORD(ObjectTypeListLength) = a6;
v167 = Address;
v150 = a10;
v142 = a11;
v168 = a11;
v143 = a12;
v169 = a12;
v156 = 0i64;
v157 = 0;
P = 0i64;
v158 = 0;
v145 = 0i64;
Token = 0i64;
OutputSecurityDescriptor = 0i64;
PrincipalSelfSid = 0i64;
LODWORD(PreviouslyGrantedAccess) = 0;
v136 = 0;
GenericMapping = 0i64;
PrivilegeSet = 0i64;
memset(&SubjectContext, 0, sizeof(SubjectContext));
MandatoryInformation = 0i64;
LOBYTE(v15) = 0;
v127 = 0;
ResourceInfo = 0i64;
memset(PackageCapabilityInfo, 0, sizeof(PackageCapabilityInfo));
v173 = 0;
memset(&SecurityDescriptor.Owner, 0, 32);
memset(CapeSecurityDescriptor, 0, sizeof(CapeSecurityDescriptor));
v171 = 0i64;
v130 = 0;
v128 = 0;
LODWORD(Result) = 0;
HIDWORD(PreviouslyGrantedAccess) = v15;
v141 = 0;
NewObjectTypeList = 0i64;
v133[0] = 0;
v131 = 0;
v132 = 0;
v159 = 0i64;
v135 = -1073741790;
*(_DWORD *)&SecurityDescriptor.Revision = -1;
v154 = 0xFFFFFFFFi64;
v16 = KeGetCurrentThread()->PreviousMode;
PreviousMode = v16;
if( !v16 )
{
*(_DWORD *)a12 = 0;
*(_DWORD *)a11 = DesiredAccess;
return 0;
}
if( ReturnResultList )
{
if( !(_DWORD)a6 )
{
result = -1073741811;
goto LABEL_19;
}
ProbeForWrite((UINT64)a12, 4i64 * (unsigned int)a6, 4i64);
ProbeForWrite(v142, 4i64 * (unsigned int)a6, 4i64);
}
else
{
v17 = (__int64)a12;
if( (unsigned __int64)a12 >= 0x7FFFFFFF0000i64 )
v17 = 0x7FFFFFFF0000i64;
*(_DWORD *)v17 = *(_DWORD *)v17;
v18 = a11;
if( (unsigned __int64)a11 >= 0x7FFFFFFF0000i64 )
v18 = 0x7FFFFFFF0000i64;
*(_DWORD *)v18 = *(_DWORD *)v18;
}
v19 = a10;
if( (unsigned __int64)a10 >= 0x7FFFFFFF0000i64 )
v19 = 0x7FFFFFFF0000i64;
*(_DWORD *)v19 = *(_DWORD *)v19;
ProbeForWrite((UINT64)Address, (unsigned int)Length, 4i64);
if( Address && (unsigned int)Length >= 0x14 )
*(_DWORD *)Address = 0;
if( (a7 & 3) != 0 )
ExRaiseDatatypeMisalignment();
GenericMapping = *(_GENERIC_MAPPING *)a7;
result = 0;
v16 = PreviousMode;
LABEL_19:
if( result < 0 )
return result;
v21 = DesiredAccess;
if( (DesiredAccess & 0xF0000000) != 0 )
{
v22 = -1073741594;
v126 = -1073741594;
v23 = (_TOKEN *)Token;
goto LABEL_176;
}
v22 = SepReferenceTokenByHandle((VOID *)a3, 8ui64, v16, (_TOKEN **)&Token, (UINT8 *)v133, (VOID **)&v159);
v126 = v22;
if( v22 < 0 )
{
v23 = 0i64;
Token = 0i64;
v55 = PreviousMode;
v47 = ReturnResultList;
goto LABEL_80;
}
v23 = (_TOKEN *)Token;
if( (unsigned __int64)(a3 + 6) > 2 )
{
if( *((_DWORD *)Token + 48) != 2 )
{
v22 = -1073741732;
v126 = -1073741732;
v55 = PreviousMode;
goto LABEL_172;
}
if( *((int *)Token + 49) < 1 )
{
v22 = -1073741659;
v126 = -1073741659;
v55 = PreviousMode;
goto LABEL_172;
}
}
v22 = SeCaptureObjectTypeList(
(_OBJECT_TYPE_LIST *)ObjectTypeList,
(unsigned int)ObjectTypeListLength,
PreviousMode,
(_IOBJECT_TYPE_LIST **)&SecurityDescriptor.Dacl);
v126 = v22;
if( v22 < 0
|| (v22 = SeCaptureSecurityDescriptor(
InputSecurityDescriptor,
PreviousMode,
PagedPool,
0,
&OutputSecurityDescriptor,
(INT64)TrustLevelSid,
v120),
v126 = v22,
v22 < 0) )
{
LABEL_174:
v55 = PreviousMode;
goto LABEL_172;
}
if( !OutputSecurityDescriptor )
goto LABEL_173;
InputSecurityDescriptor = (char *)OutputSecurityDescriptor + 2;
v24 = *((_WORD *)OutputSecurityDescriptor + 1);
if( v24 >= 0 )
{
v26 = (char *)*((_QWORD *)OutputSecurityDescriptor + 1);
}
else
{
v25 = *((unsigned int *)OutputSecurityDescriptor + 1);
if( !(_DWORD)v25 )
goto LABEL_173;
v26 = (char *)OutputSecurityDescriptor + v25;
}
if( !v26 )
goto LABEL_173;
if( v24 < 0 )
{
v27 = *((unsigned int *)OutputSecurityDescriptor + 2);
if( (_DWORD)v27 )
{
v28 = (char *)OutputSecurityDescriptor + v27;
goto LABEL_35;
}
LABEL_173:
v22 = -1073741703;
v126 = -1073741703;
goto LABEL_174;
}
v28 = (char *)*((_QWORD *)OutputSecurityDescriptor + 2);
LABEL_35:
if( !v28 )
goto LABEL_173;
if( v133[0] )
v29 = (VOID *)v159;
else
v29 = v23->TrustLevelSid;
LOBYTE(TrustLevelSida) = 1;
v22 = SepTrustLevelCheck(
&SecurityDescriptor,
OutputSecurityDescriptor,
0i64,
v23,
v29,
(_SEP_TRUST_CHECK_INFORMATION *)TrustLevelSida,
(_SEP_TRUST_CHECK_INFORMATION *)&SecurityDescriptor);
v126 = v22;
if( v22 < 0 )
goto LABEL_176;
if( (*(_DWORD *)&SecurityDescriptor.Revision & DesiredAccess & 0xFDFFFFFF) != (DesiredAccess & 0xFDFFFFFF) )
{
v131 = 1;
LABEL_184:
v33 = -1073741790;
v34 = PreviousMode;
goto LABEL_47;
}
v22 = SepFilterCheck((INT64)OutputSecurityDescriptor, &ResourceInfo, v23, 1, (INT64)&v154);
v126 = v22;
if( v22 < 0 )
{
LABEL_176:
v55 = PreviousMode;
goto LABEL_172;
}
if( ((unsigned int)v154 & DesiredAccess & 0xFDFFFFFF) != (DesiredAccess & 0xFDFFFFFF) )
{
v132 = 1;
goto LABEL_184;
}
p_MandatoryInformation = &MandatoryInformation;
LOBYTE(TrustLevelSidb) = a14;
v22 = SepMandatoryIntegrityCheck(
&GenericMapping,
(_SECURITY_DESCRIPTOR *)OutputSecurityDescriptor,
0,
v23,
1u,
(_SEP_MANDATORY_INFORMATION *)TrustLevelSidb);
v126 = v22;
if( v22 < 0 )
goto LABEL_176;
v127 = 0;
v31 = SepMandatoryToDiscretionary(&MandatoryInformation, (unsigned int)DesiredAccess);
v33 = v31;
if( (v31 < 0 || (DesiredAccess & 0x2000000) != 0)
&& (v23->TokenFlags & 0x4000) != 0
&& MandatoryInformation.ObjectLabel <= 0x2000 )
{
v32 = 1;
v127 = 1;
}
if( v31 < 0 && !v32 )
{
v34 = PreviousMode;
goto LABEL_48;
}
v34 = PreviousMode;
v33 = SePrivilegePolicyCheck(&DesiredAccess, &PreviouslyGrantedAccess, 0i64, v23, &PrivilegeSet, PreviousMode);
v21 = DesiredAccess;
if( !(_DWORD)DesiredAccess )
{
v76 = BYTE4(PreviouslyGrantedAccess);
if( (_DWORD)PreviouslyGrantedAccess )
v76 = 1;
HIDWORD(PreviouslyGrantedAccess) = v76;
}
LABEL_47:
v32 = v127;
LABEL_48:
if( v33 < 0 && !v32 )
{
v47 = ReturnResultList;
v73 = v143;
if( ReturnResultList )
{
v74 = 0;
v138 = 0;
v75 = v142;
while( v74 < (unsigned int)ObjectTypeListLength )
{
v73[v74] = v33;
*(_DWORD *)(v75 + 4i64 * v74++) = 0;
v138 = v74;
}
}
else
{
*v143 = v33;
*(_DWORD *)v142 = 0;
}
v135 = v33;
v22 = 0;
v126 = 0;
v55 = PreviousMode;
goto LABEL_80;
}
v35 = PrivilegeSet;
if( PrivilegeSet )
{
PrivilegeCount = PrivilegeSet->PrivilegeCount;
v78 = 12 * PrivilegeSet->PrivilegeCount;
v79 = v78 + 8;
if( !PrivilegeSet->PrivilegeCount )
v79 = 8;
if( v79 > Length )
{
v80 = v78 + 8;
if( !PrivilegeCount )
v80 = 8;
*(_DWORD *)v150 = v80;
v22 = -1073741789;
v126 = -1073741789;
v55 = PreviousMode;
CmSiFreeMemory(v35);
goto LABEL_172;
}
v81 = v78 + 8;
if( !PrivilegeCount )
v81 = 8;
memmove(Address, PrivilegeSet, v81);
CmSiFreeMemory(v35);
}
else
{
if( (unsigned int)Length < 0x14 )
{
*(_DWORD *)v150 = 20;
v22 = -1073741789;
v126 = -1073741789;
v47 = ReturnResultList;
v55 = PreviousMode;
goto LABEL_80;
}
*(_QWORD *)Address = PrivilegeSet;
}
if( Src )
{
p_MandatoryInformation = &PrincipalSelfSid;
v22 = SeCaptureSid(Src, v34, v32, v30);
v126 = v22;
if( v22 < 0 )
{
PrincipalSelfSid = 0i64;
v55 = PreviousMode;
LABEL_172:
v47 = ReturnResultList;
goto LABEL_80;
}
}
SeCaptureSubjectContext((INT64)&SubjectContext);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
v23 = (_TOKEN *)Token;
v37 = (PERESOURCE *)((char *)Token + 48);
ExAcquireResourceSharedLite(*((_QWORD *)Token + 6), 1);
TokenIsOwner = SepTokenIsOwner(v23, OutputSecurityDescriptor, v38);
if( !SepAllowAccessUponLogoff && (v23->TokenFlags & 0x20) == 0 )
{
LogonSession = v23->LogonSession;
if( LogonSession )
{
if( (LogonSession->Flags & 0x20) != 0 )
{
v47 = ReturnResultList;
v83 = v143;
if( ReturnResultList )
{
v84 = 0;
v138 = 0;
v85 = v142;
while( v84 < (unsigned int)ObjectTypeListLength )
{
v83[v84] = -1073741790;
*(_DWORD *)(v85 + 4i64 * v84++) = 0;
v138 = v84;
}
}
else
{
*v143 = -1073741790;
*(_DWORD *)v142 = 0;
}
v135 = -1073741790;
v22 = 0;
v126 = 0;
v55 = PreviousMode;
ExReleaseResourceLite(v23->TokenLock);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v21 = DesiredAccess;
goto LABEL_80;
}
}
}
v40 = (__int16 *)InputSecurityDescriptor;
if( SepRmEnforceCap && (*(_WORD *)InputSecurityDescriptor & 0x10) != 0 && KeGetCurrentIrql() < 2u )
{
if( *(__int16 *)InputSecurityDescriptor >= 0 )
{
v87 = (_ACL *)*((_QWORD *)OutputSecurityDescriptor + 3);
}
else
{
v86 = *((unsigned int *)OutputSecurityDescriptor + 3);
if( !(_DWORD)v86 )
{
SecurityDescriptor.Owner = 0i64;
goto LABEL_55;
}
v87 = (_ACL *)((char *)OutputSecurityDescriptor + v86);
}
SecurityDescriptor.Owner = v87;
if( v87 )
{
ScopedPolicySid = SepGetScopedPolicySid(v87);
if( ScopedPolicySid )
{
Cap = SepRmReferenceFindCap(ScopedPolicySid, (_SEP_CENTRALIZED_ACCESS_POLICY **)&SecurityDescriptor.Sacl);
Sacl = SecurityDescriptor.Sacl;
if( Cap < 0 )
Sacl = (_ACL *)SepRmDefaultCap;
SecurityDescriptor.Sacl = Sacl;
v130 = 1;
}
}
}
LABEL_55:
v21 = DesiredAccess;
if( (DesiredAccess & 0x2060000) != 0
&& TokenIsOwner
&& ((*v40 & 4) == 0 ? (v58 = 0i64) : *v40 >= 0 ? (v58 = (_ACL *)*((_QWORD *)OutputSecurityDescriptor + 4)) : (v57 = *((_DWORD *)OutputSecurityDescriptor + 4)) == 0 ? (v58 = 0i64) : (v58 = (_ACL *)((char *)OutputSecurityDescriptor + v57)),
!RtlpOwnerAcesPresent(0, v58)) )
{
if( (v21 & 0x2000000) != 0 )
{
v59 = 393216;
v41 = PreviouslyGrantedAccess | 0x60000;
}
else
{
v59 = v21 & 0x60000;
v41 = PreviouslyGrantedAccess | v21 & 0x60000;
}
v136 = v59;
LODWORD(PreviouslyGrantedAccess) = v41;
v21 &= 0xFFF9FFFF;
LODWORD(DesiredAccess) = v21;
}
else
{
v41 = PreviouslyGrantedAccess;
}
if( v21 || v130 && !BYTE4(PreviouslyGrantedAccess) )
{
v23 = (_TOKEN *)Token;
v42 = v136;
}
else
{
v23 = (_TOKEN *)Token;
if( (*((_DWORD *)Token + 50) & 0x2000) != 0 || (v42 = v136) == 0 )
{
v47 = ReturnResultList;
if( ReturnResultList )
{
v70 = 0;
v138 = 0;
v71 = v168;
v72 = v169;
while( v70 < (unsigned int)ObjectTypeListLength )
{
if( v41 )
{
v72[v70] = 0;
v135 = 0;
*(_DWORD *)(v71 + 4i64 * v70) = v41;
}
else
{
v72[v70] = -1073741790;
v135 = -1073741790;
*(_DWORD *)(v71 + 4i64 * v70) = 0;
}
v138 = ++v70;
}
}
else
{
v69 = (_DWORD *)v142;
if( v41 )
{
*v143 = 0;
v135 = 0;
*v69 = v41;
}
else
{
*v143 = -1073741790;
v135 = -1073741790;
*v69 = 0;
}
}
v22 = 0;
v126 = 0;
v55 = PreviousMode;
ExReleaseResourceLite(v23->TokenLock);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
goto LABEL_80;
}
}
if( ReturnResultList )
{
v91 = (unsigned int)ObjectTypeListLength;
PoolWithTag = ExAllocatePoolWithTag(1ui64, 8i64 * (unsigned int)ObjectTypeListLength, 1632068947i64);
GrantedAccess = (UINT64 *)PoolWithTag;
SecurityDescriptor.Group = PoolWithTag;
if( !PoolWithTag )
{
ExReleaseResourceLite(*v37);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v22 = -1073741670;
v126 = -1073741670;
v55 = PreviousMode;
goto LABEL_172;
}
AccessStatus = (INT64 *)((char *)PoolWithTag + 4 * v91);
v42 = v136;
}
else
{
GrantedAccess = &v156;
SecurityDescriptor.Group = &v156;
AccessStatus = (INT64 *)((char *)&v156 + 4);
}
LODWORD(PackageCapabilityInfo[0]) = v42;
LODWORD(ConditionSize) = v41;
v45 = (unsigned int)ObjectTypeListLength;
LODWORD(p_MandatoryInformation) = ObjectTypeListLength;
LODWORD(UseNewTrust) = v21;
SepAccessCheck(
OutputSecurityDescriptor,
PrincipalSelfSid,
(_TOKEN *)SubjectContext.PrimaryToken,
v23,
(UINT64)UseNewTrust,
(_IOBJECT_TYPE_LIST *)SecurityDescriptor.Dacl,
(UINT64)p_MandatoryInformation,
&GenericMapping,
ConditionSize,
PreviousMode,
GrantedAccess,
0i64,
AccessStatus,
ReturnResultList,
TokenIsOwner,
(_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
0i64,
0i64);
if( SepRmEnforceCap && (v93 = *(_DWORD *)AccessStatus, v136 = v93, v93 >= 0) && v130 )
{
if( ReturnResultList )
{
v94 = ExAllocatePoolWithTag(1ui64, 8 * v45, 1632068947i64);
P = v94;
if( !v94 )
{
ExReleaseResourceLite(*v37);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v22 = -1073741670;
v126 = -1073741670;
v23 = (_TOKEN *)Token;
v21 = DesiredAccess;
v55 = PreviousMode;
goto LABEL_172;
}
v145 = (INT64 *)((char *)v94 + 4 * v45);
v93 = *(_DWORD *)AccessStatus;
v136 = *(_DWORD *)AccessStatus;
}
else
{
P = &v157;
v145 = (INT64 *)&v158;
}
LODWORD(PrivilegeSet) = *(_DWORD *)SecurityDescriptor.Group;
LOBYTE(v45) = 0;
HIDWORD(PreviouslyGrantedAccess) = v45;
if( (_DWORD)ObjectTypeListLength )
{
v22 = SepCopyObjectTypeList(
(_IOBJECT_TYPE_LIST *)SecurityDescriptor.Dacl,
(unsigned int)ObjectTypeListLength,
&NewObjectTypeList);
v126 = v22;
if( v22 < 0 )
{
v23 = (_TOKEN *)Token;
v21 = DesiredAccess;
v55 = PreviousMode;
goto LABEL_172;
}
v93 = v136;
LOBYTE(v45) = BYTE4(PreviouslyGrantedAccess);
}
v95 = 0;
v147 = 0;
v23 = (_TOKEN *)Token;
v21 = DesiredAccess;
while( v95 < *(_DWORD *)&SecurityDescriptor.Sacl[7].AceCount )
{
v150 = (INT64)SecurityDescriptor.Sacl[v95 + 8];
if( !*(_QWORD *)(v150 + 24) )
goto LABEL_278;
v96 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
if( !ResourceInfo )
{
LODWORD(v45) = (unsigned __int8)v45;
if( AuthzBasepInitializeResourceClaimsFromSacl(
(_ACL *)SecurityDescriptor.Owner,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo) < 0 )
LODWORD(v45) = 1;
HIDWORD(PreviouslyGrantedAccess) = v45;
v96 = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo;
}
pClaimAttributes = v23->pClaimAttributes;
v98 = pClaimAttributes ? pClaimAttributes->pRestrictedDeviceSecurityAttributes : 0i64;
v99 = pClaimAttributes ? pClaimAttributes->pDeviceSecurityAttributes : 0i64;
v100 = pClaimAttributes ? pClaimAttributes->pRestrictedUserSecurityAttributes : 0i64;
v101 = pClaimAttributes ? pClaimAttributes->pUserSecurityAttributes : 0i64;
LODWORD(ConditionSizea) = *(_DWORD *)(v150 + 16);
v102 = AuthzBasepEvaluateAceCondition(
v23,
v23->pSecurityAttributes,
v96,
v101,
v100,
v99,
v98,
*(UINT8 **)(v150 + 24),
ConditionSizea,
1u,
0,
&Result);
v22 = v102;
v126 = v102;
v103 = Result;
if( (_DWORD)Result == 1 )
goto LABEL_278;
if( v102 < 0 )
goto LABEL_294;
if( (v23->TokenFlags & 0x10) != 0 )
{
v104 = v23->pClaimAttributes;
if( v104 )
pRestrictedDeviceSecurityAttributes = v104->pRestrictedDeviceSecurityAttributes;
else
pRestrictedDeviceSecurityAttributes = 0i64;
if( v104 )
pDeviceSecurityAttributes = v104->pDeviceSecurityAttributes;
else
pDeviceSecurityAttributes = 0i64;
if( v104 )
pRestrictedUserSecurityAttributes = v104->pRestrictedUserSecurityAttributes;
else
pRestrictedUserSecurityAttributes = 0i64;
if( v104 )
pUserSecurityAttributes = v104->pUserSecurityAttributes;
else
pUserSecurityAttributes = 0i64;
LODWORD(ConditionSizea) = *(_DWORD *)(v150 + 16);
v22 = AuthzBasepEvaluateAceCondition(
v23,
v23->pSecurityAttributes,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)ResourceInfo,
pUserSecurityAttributes,
pRestrictedUserSecurityAttributes,
pDeviceSecurityAttributes,
pRestrictedDeviceSecurityAttributes,
*(UINT8 **)(v150 + 24),
ConditionSizea,
1u,
1u,
&Result);
v126 = v22;
if( v22 < 0 )
{
LABEL_294:
ExReleaseResourceLite(*v37);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v55 = PreviousMode;
goto LABEL_172;
}
v103 = Result;
}
LOBYTE(v45) = BYTE4(PreviouslyGrantedAccess);
if( BYTE4(PreviouslyGrantedAccess) || v103 == 1 )
{
LABEL_278:
v22 = SepBuildCapeSecurityDescriptor(
CapeSecurityDescriptor,
*(PVOID *)(v150 + 32),
(_ACL *)SecurityDescriptor.Owner);
v126 = v22;
if( v22 < 0 )
goto LABEL_294;
v109 = v21;
if( (*(_DWORD *)(v150 + 48) & 1) != 0 )
{
if( (v21 & 0x2000000) == 0 )
v109 = PreviouslyGrantedAccess | v21;
v110 = 0;
}
else
{
v110 = PreviouslyGrantedAccess;
}
LODWORD(ConditionSizea) = v110;
v111 = ObjectTypeListLength;
LODWORD(v122) = ObjectTypeListLength;
LODWORD(UseNewTrusta) = v109;
SepAccessCheck(
CapeSecurityDescriptor,
PrincipalSelfSid,
(_TOKEN *)SubjectContext.PrimaryToken,
v23,
(UINT64)UseNewTrusta,
NewObjectTypeList,
v122,
&GenericMapping,
ConditionSizea,
PreviousMode,
(UINT64 *)P,
0i64,
v145,
ReturnResultList,
TokenIsOwner,
(_SE_PACKAGE_CAPABILITY_INFO *)PackageCapabilityInfo,
(_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION **)&ResourceInfo,
0i64,
0i64);
v112 = *(_DWORD *)P;
if( v128 )
v112 = (unsigned int)PrivilegeSet & *(_DWORD *)P;
LODWORD(PrivilegeSet) = v112;
if( v112 )
v93 = *(_DWORD *)v145;
else
v93 = -1073741790;
v136 = v93;
v128 = 1;
if( NewObjectTypeList )
SepMergeObjectTypeListAccesses((_IOBJECT_TYPE_LIST *)SecurityDescriptor.Dacl, NewObjectTypeList, v111);
if( v93 < 0 )
break;
LOBYTE(v45) = BYTE4(PreviouslyGrantedAccess);
}
else
{
v93 = v136;
}
v95 = ++v147;
}
*(_DWORD *)AccessStatus = v93;
Group = (UINT64 *)SecurityDescriptor.Group;
*(_DWORD *)SecurityDescriptor.Group &= (unsigned int)PrivilegeSet;
}
else
{
v23 = (_TOKEN *)Token;
v21 = DesiredAccess;
Group = (UINT64 *)SecurityDescriptor.Group;
}
ExReleaseResourceLite(*v37);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
if( (v21 & 0x2000000) != 0 )
{
if( !v127 || !*(_WORD *)((char *)&PackageCapabilityInfo[2] + 5) )
{
v47 = ReturnResultList;
if( ReturnResultList )
v60 = ObjectTypeListLength;
else
v60 = 0;
LODWORD(TrustLevelSidc) = v60;
SepConstrainByMandatory(&MandatoryInformation, v21, Group, AccessStatus, 0i64, (UINT64)TrustLevelSidc);
goto LABEL_66;
}
}
else if( v127 && !*(_WORD *)((char *)&PackageCapabilityInfo[2] + 5) )
{
v47 = ReturnResultList;
v66 = v143;
if( ReturnResultList )
{
v67 = 0;
v138 = 0;
v68 = v142;
while( v67 < (unsigned int)ObjectTypeListLength )
{
v66[v67] = -1073741790;
*(_DWORD *)(v68 + 4i64 * v67++) = 0;
v138 = v67;
}
}
else
{
*v143 = -1073741790;
*(_DWORD *)v142 = 0;
}
v135 = -1073741790;
v22 = 0;
v126 = 0;
v55 = PreviousMode;
goto LABEL_80;
}
v47 = ReturnResultList;
LABEL_66:
if( (v21 & 0x2000000) != 0 )
{
v61 = ObjectTypeListLength;
if( v47 )
v62 = ObjectTypeListLength;
else
v62 = 0;
LODWORD(TrustLevelSidc) = v62;
SepConstrainByConstraintMask(
*(unsigned int *)&SecurityDescriptor.Revision,
v21,
(CHAR *)Group,
(CHAR *)AccessStatus,
0i64,
(UINT64)TrustLevelSidc,
&v131);
if( v47 )
v63 = v61;
else
v63 = 0;
LODWORD(TrustLevelSidd) = v63;
SepConstrainByConstraintMask(
(unsigned int)v154,
v21,
(CHAR *)Group,
(CHAR *)AccessStatus,
0i64,
(UINT64)TrustLevelSidd,
&v132);
}
v48 = v143;
*v143 = *(_DWORD *)AccessStatus;
v49 = (_DWORD *)v142;
*(_DWORD *)v142 = *(_DWORD *)Group;
v135 = *(_DWORD *)AccessStatus;
v50 = v145;
v51 = P;
if( SepRmEnforceCap && v128 && *(int *)AccessStatus >= 0 )
{
*v48 = *(_DWORD *)v145;
*v49 &= *v51;
v135 = *(_DWORD *)v50;
}
if( v47 )
{
v52 = 1i64;
v53 = ObjectTypeListLength;
while( 1 )
{
v138 = v52;
if( (unsigned int)v52 >= v53 )
break;
v54 = v52;
v48[v54] = *((_DWORD *)AccessStatus + v52);
v49[v54] = *((_DWORD *)Group + v52);
if( SepRmEnforceCap && v128 && *(int *)((char *)AccessStatus + v54 * 4) >= 0 )
{
v48[v52] = *((_DWORD *)v50 + v52);
v49[v52] &= v51[v52];
}
v52 = v138 + 1;
}
}
v22 = 0;
v126 = 0;
v23 = (_TOKEN *)Token;
v21 = DesiredAccess;
v55 = PreviousMode;
LABEL_80:
if( OutputSecurityDescriptor && v23 )
{
if( v131 || v132 )
{
LABEL_129:
v64 = (_ETHREAD *)KeGetCurrentThread();
--v64->Tcb.KernelApcDisable;
v23 = (_TOKEN *)Token;
ExAcquireResourceSharedLite(*((_QWORD *)Token + 6), 1);
if( v133[0] )
v65 = v159;
else
v65 = (INT64)v23->TrustLevelSid;
v21 = DesiredAccess;
SeLogAccessFailure(v23, 0i64, 0i64, v65, (UINT8)OutputSecurityDescriptor);
ExReleaseResourceLite(v23->TokenLock);
KeLeaveCriticalRegion();
v22 = v126;
v56 = HIDWORD(PackageCapabilityInfo[1]);
LABEL_86:
if( v22 >= 0
&& v135 < 0
&& !v56
&& (v23->TokenFlags & 0x4000) != 0
&& SepLpacCausedAccessFailure((INT64)PackageCapabilityInfo, v21) )
{
SepLogLpacAccessFailure();
}
goto LABEL_88;
}
v56 = HIDWORD(PackageCapabilityInfo[1]);
if( HIDWORD(PackageCapabilityInfo[1]) || (v23->TokenFlags & 0x4000) == 0 )
goto LABEL_86;
if( v22 >= 0 )
{
if( v135 >= 0 && !HIBYTE(PackageCapabilityInfo[2]) )
goto LABEL_86;
goto LABEL_129;
}
}
LABEL_88:
if( v47 )
{
if( SecurityDescriptor.Group )
ExFreePoolWithTag(SecurityDescriptor.Group, 0);
if( P )
ExFreePoolWithTag(P, 0);
}
if( v23 )
HalPutDmaAdapter((PADAPTER_OBJECT)v23);
if( SecurityDescriptor.Dacl )
SeFreeCapturedObjectTypeList(SecurityDescriptor.Dacl);
if( PrincipalSelfSid )
SeReleaseSid(PrincipalSelfSid, v55, 1u);
if( OutputSecurityDescriptor )
SeReleaseSecurityDescriptor(OutputSecurityDescriptor, v55, 0);
if( v130 )
SepRmDereferenceCap((_SEP_CENTRALIZED_ACCESS_POLICY *)SecurityDescriptor.Sacl);
if( NewObjectTypeList )
ExFreePoolWithTag(NewObjectTypeList, 0);
SepFreeResourceInfo((VOID *)ResourceInfo);
return v22;
}Referenced by:
SeAccessCheckByType