CmpCheckOpenAccessOnKeyBody

INT64 __fastcall CmpCheckOpenAccessOnKeyBody(
        PVOID Object,
        INT64 a2,
        _DWORD *a3,
        struct _ACCESS_STATE *a4,
        CHAR a5,
        CHAR a6,
        _CM_TRANS *ObjectCreated,
        INT64 a8,
        INT64 a9){
  __int16 v9; 
  LIST_ENTRY *v11; 
  INT64 i; 
  __int64 v14; 
  __int16 v15; 
  _LIST_ENTRY *Blink; 
  CHAR v17; 
  unsigned __int8 v18; 
  INT64 v19; 
  int v20; 
  __int64 v21; 
  _PRIVILEGE_SET *v22; 
  int started; 
  int v24; 
  _DWORD *v25; 
  int v26; 
  __int64 v27; 
  _PRIVILEGE_SET *v28; 
  int v29; 
  __int16 v30; 
  PPRIVILEGE_SET j; 
  PPRIVILEGE_SET v32; 
  __int16 Control_high; 
  _ETHREAD *CurrentThread; 
  _LUID Luid; 
  UINT8 v36; 
  unsigned int v37; 
  __int16 v38; 
  __int64 v39; 
  unsigned __int8 v40; 
  char v41; 
  _ETHREAD *v43; 
  _EPROCESS *CurrentThreadProcess; 
  INT64 v45; 
  NTSTATUS ServerSiloServiceSessionId; 
  INT64 v47; 
  INT64 v48; 
  LIST_ENTRY *v49; 
  __int64 v50; 
  _CM_TRANS *v51; 
  __int64 v52; 
  INT64 v53; 
  __int64 v54; 
  __int64 v55; 
  __int64 v56; 
  __int16 v57; 
  INT16 v58; 
  INT64 KcbAtLayerHeight; 
  INT64 v60; 
  _PRIVILEGE_SET *TransientPoolWithTag; 
  PPRIVILEGE_SET *Privileges; 
  _KPROCESSOR_MODE AccessMode; 
  int AccessStatus; 
  unsigned int GrantedAccess; 
  PPRIVILEGE_SET v66; 
  LIST_ENTRY *ListIterator; 
  __int128 v68; 
  PPRIVILEGE_SET v69[2]; 
  INT64 v70[2]; 
  PPRIVILEGE_SET v71[2]; 

  v9 = *(_WORD *)(a2 + 2);
  v11 = 0i64;
  for( i = a2; v9 >= 0; --v9 )
  {
    if( v9 >= 2 )
      v14 = *(_QWORD *)(*(_QWORD *)(i + 24) + 8i64 * v9 - 16);
    else
      v14 = *(_QWORD *)(i + 8i64 * v9 + 8);
    v15 = *(_WORD *)(v14 + 66);
    if( v15 && *(_BYTE *)(v14 + 65) == 1 )
      break;
    if( *(_DWORD *)(v14 + 40) != -1 )
    {
      v11 = (LIST_ENTRY *)v14;
      if( v15 )
      {
        if( *(_BYTE *)(v14 + 65) )
          break;
      }
    }
  }
  Blink = v11[5].Blink;
  if( ObjectCreated )
  {
    v49 = v11 + 13;
    ListIterator = 0i64;
    LODWORD(v50) = CmListGetPrevElement(v11 + 13, &ListIterator, (INT64)a3);
    v52 = v50;
    if( v50 )
    {
      while( !CmEqualTrans(*(_QWORD *)(v52 + 56), (__int64)v51) || *(_DWORD *)(v52 + 68) != 9 )
      {
        LODWORD(v54) = CmListGetPrevElement(v49, &ListIterator, v53);
        v52 = v54;
        if( !v54 )
          goto LABEL_9;
        v51 = ObjectCreated;
      }
      Blink = *(_LIST_ENTRY **)(v52 + 88);
    }
  }
LABEL_9:
  v17 = a6;
  v18 = a5;
  if( a6 && (int)CmpSetAccessStateForBackupRestore((INT64)a4, a5, &Blink[2], 1) < 0 )
    goto LABEL_74;
  v19 = *((_QWORD *)Object + 1);
  v20 = *((_DWORD *)a4 + 6);
  *(_OWORD *)v70 = 0i64;
  WORD1(v70[0]) = -1;
  v21 = *(_QWORD *)(v19 + 32);
  *(_OWORD *)v71 = 0i64;
  if( (*(_DWORD *)(v21 + 160) & 0x100000) == 0 )
  {
    v22 = 0i64;
    started = 0;
    goto LABEL_12;
  }
  if( (v20 & 0xD0026) == 0 )
  {
    v22 = 0i64;
    started = 0;
    goto LABEL_12;
  }
  if( (v20 & 0xD0002) != 0 )
  {
    started = -1073741790;
LABEL_98:
    v22 = 0i64;
    goto LABEL_12;
  }
  if( (*(_DWORD *)(v21 + 4152) & 0x2000) == 0 )
  {
    started = -1073741790;
    goto LABEL_98;
  }
  if( *(_BYTE *)(v19 + 65) )
  {
    started = -1073741790;
    goto LABEL_98;
  }
  started = CmpStartKcbStackForTopLayerKcb((INT64)v70, v19);
  if( started < 0 )
    goto LABEL_98;
  v58 = *(_WORD *)(v19 + 66) - 1;
  if( v58 < 0 )
  {
LABEL_97:
    v17 = a6;
    goto LABEL_98;
  }
  while( 1 )
  {
    KcbAtLayerHeight = CmpGetKcbAtLayerHeight((INT64)v70, v58);
    WORD1(v70[0]) = v58;
    v60 = KcbAtLayerHeight;
    if( CmpIsKeyStackDeleted((INT64)v70, 0i64) )
    {
LABEL_95:
      started = -1073741790;
LABEL_96:
      v18 = a5;
      goto LABEL_97;
    }
    if( (*(_DWORD *)(*(_QWORD *)(v60 + 32) + 160i64) & 0x100000) == 0 )
      break;
    if( (*(_DWORD *)(*(_QWORD *)(v19 + 32) + 4152i64) & 0x2000) == 0 || *(_BYTE *)(v19 + 65) )
      goto LABEL_95;
    if( --v58 < 0 )
      goto LABEL_96;
  }
  v17 = a6;
  v22 = 0i64;
  v18 = a5;
  started = 0;
LABEL_12:
  if( v71[1] )
  {
    CmSiFreeMemory(v71[1]);
    v22 = 0i64;
  }
  if( started < 0 || (v24 = *((_DWORD *)a4 + 6), v25 = a3, (v24 & a3[24]) != v24) )
  {
LABEL_74:
    v40 = 0;
    *(_DWORD *)a9 = -1073741790;
    v41 = 0;
    goto LABEL_44;
  }
  if( v17 && !*((_DWORD *)a4 + 4) || !v24 && (*a3 & 0x1000) != 0 )
    goto LABEL_43;
  v26 = *((_DWORD *)Object + 12);
  GrantedAccess = 0;
  v66 = 0i64;
  v68 = 0i64;
  WORD1(v68) = -1;
  *(_OWORD *)v69 = 0i64;
  if( (v26 & 9) == 0 )
  {
    v27 = *((_QWORD *)Object + 1);
    v28 = 0i64;
    v29 = *(__int16 *)(v27 + 66);
    v30 = *(_WORD *)(v27 + 66);
    if( v29 >= 2 )
    {
      TransientPoolWithTag = (_PRIVILEGE_SET *)CmpAllocateTransientPoolWithTag(1ui64, 8i64 * (unsigned int)(v29 - 1));
      v28 = TransientPoolWithTag;
      if( !TransientPoolWithTag )
      {
        AccessStatus = -1073741670;
        v36 = 0;
LABEL_39:
        v25 = a3;
        i = a2;
        v17 = a6;
        goto LABEL_40;
      }
      memset(TransientPoolWithTag, 0i64, 8 * (v29 - 1));
      v30 = *(_WORD *)(v27 + 66);
      v22 = 0i64;
    }
    LOWORD(v68) = v29;
    v69[1] = v28;
    WORD1(v68) = v30;
    if( v30 )
    {
      v55 = *(_QWORD *)(v27 + 192);
      if( v55 )
      {
        do
        {
          CmpSetKcbAtLayerHeight((__int64)&v68, v30, *(_QWORD *)(v55 + 16));
          v55 = *(_QWORD *)(v56 + 24);
          v30 = v57 - 1;
        }
        while( v55 );
        v28 = v69[1];
        v30 = WORD1(v68);
      }
    }
    else
    {
      *((_QWORD *)&v68 + 1) = v27;
    }
    AccessStatus = (int)v22;
    for( j = v22; v30 >= 0; --v30 )
    {
      if( v30 >= 2 )
        v32 = (PPRIVILEGE_SET)*((_QWORD *)v28 + v30 - 2);
      else
        v32 = v69[v30 - 1];
      Control_high = HIWORD(v32[3].Control);
      if( Control_high && BYTE1(v32[3].Control) == 1 )
        break;
      if( v32[2].PrivilegeCount != -1 )
      {
        j = v32;
        if( Control_high )
        {
          if( BYTE1(v32[3].Control) )
            break;
        }
      }
    }
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    Luid = j[4].Privilege[0].Luid;
    --CurrentThread->Tcb.KernelApcDisable;
    ExAcquireResourceSharedLite(*(_QWORD *)(*((_QWORD *)a4 + 6) + 48i64), 1);
    if( *((_QWORD *)a4 + 4) )
    {
      v43 = (_ETHREAD *)KeGetCurrentThread();
      --v43->Tcb.KernelApcDisable;
      ExAcquireResourceSharedLite(*(_QWORD *)(*((_QWORD *)a4 + 4) + 48i64), 1);
    }
    LOBYTE(AccessMode) = v18;
    v36 = (unsigned __int8)SeAccessCheck(
                             (PSECURITY_DESCRIPTOR)(*(_QWORD *)&Luid + 32i64),
                             (PSECURITY_SUBJECT_CONTEXT)a4 + 1,
                             1u,
                             *((_DWORD *)a4 + 4),
                             *((_DWORD *)a4 + 5),
                             &v66,
                             (PGENERIC_MAPPING)((char *)CmKeyObjectType + 76),
                             AccessMode,
                             &GrantedAccess,
                             &AccessStatus);
    if( v66 )
    {
      SeAppendPrivileges(a4, v66);
      CmSiFreeMemory(v66);
    }
    if( v36 )
    {
      v37 = GrantedAccess;
      *((_DWORD *)a4 + 5) |= GrantedAccess;
      *((_DWORD *)a4 + 4) &= ~(v37 | 0x2000000);
    }
    *((_WORD *)Object + 24) |= 2u;
    v38 = *((_WORD *)Object + 24);
    if( v18 )
    {
      SeOpenObjectAuditAlarmWithTransaction(
        (_UNICODE_STRING *)CmKeyObjectType + 1,
        Object,
        0i64,
        (VOID *)(*(_QWORD *)&Luid + 32i64),
        a4,
        0,
        v36,
        v18,
        0i64,
        (UINT8 *)a4 + 10);
      v38 = *((_WORD *)Object + 24);
    }
    *((_WORD *)Object + 24) = v38 & 0xFFFD;
    ExReleaseResourceLite(*(PERESOURCE *)(*((_QWORD *)a4 + 6) + 48i64));
    KeLeaveCriticalRegion();
    v39 = *((_QWORD *)a4 + 4);
    if( v39 )
    {
      ExReleaseResourceLite(*(PERESOURCE *)(v39 + 48));
      KeLeaveCriticalRegion();
    }
    goto LABEL_39;
  }
  AccessStatus = -1073741444;
  v36 = 0;
LABEL_40:
  if( v69[1] )
  {
    CmSiFreeMemory(v69[1]);
    v25 = a3;
  }
  if( v36 )
  {
LABEL_43:
    v40 = 1;
    *(_DWORD *)a9 = 0;
    v41 = 0;
    goto LABEL_44;
  }
  if( v17 )
    goto LABEL_49;
  LODWORD(Privileges) = AccessStatus;
  if( (int)CmpVEPerformOpenAccessCheck(
              (INT64)Object,
              (INT64)ObjectCreated,
              (INT64)a4,
              v18,
              (INT64)v25,
              (UINT64)Privileges) >= 0 )
  {
    v40 = 1;
    *(_DWORD *)a9 = 0;
    v41 = 0;
    goto LABEL_44;
  }
  if( KeGetCurrentThread()->PreviousMode == 1
    && (CurrentThreadProcess = (_EPROCESS *)PsGetCurrentThreadProcess(),
        LODWORD(v45) = PsGetProcessServerSilo((INT64)CurrentThreadProcess),
        ServerSiloServiceSessionId = PsGetServerSiloServiceSessionId(v45),
        MmGetSessionIdEx(CurrentThreadProcess) != ServerSiloServiceSessionId)
    && (*((_DWORD *)a4 + 4) & 0xD0026) != 0
    && CmpCheckKeyOwnerForPca(i, v47, v48) )
  {
    v41 = 1;
    v40 = 0;
    *(_DWORD *)a9 = -1073741790;
  }
  else
  {
LABEL_49:
    v41 = 0;
    v40 = 0;
    *(_DWORD *)a9 = -1073741790;
  }
LABEL_44:
  *(_BYTE *)a8 = v41;
  return v40;
}

Referenced by:

CmpDoParseKey