SeComputeAutoInheritByObjectTypeEx

NTSTATUS __stdcall SeComputeAutoInheritByObjectTypeEx(
        VOID *ObjectType,
        VOID *SecurityDescriptor,
        VOID *ParentSecurityDescriptor,
        UINT64 *AutoInheritFlags,
        _SECURITY_OBJECT_AI_PARAMS *AutoInheritParams){
  _SECURITY_OBJECT_AI_PARAMS *v5; 
  char v6; 
  int v11; 
  int v12; 
  _ETHREAD *CurrentThread; 
  unsigned int v14; 
  VOID **v15; 
  unsigned int v16; 
  __int64 v17; 
  int v18; 
  __int16 v20; 
  _ACL *v21; 
  _DWORD *AceByType; 
  __int64 v23; 
  __int16 v24; 
  _ACL *v25; 
  __int64 v26; 
  _BYTE *v27; 

  v5 = AutoInheritParams;
  v6 = 0;
  v11 = 0;
  v12 = 0;
  if( AutoInheritParams )
  {
    if( AutoInheritParams->Size != 8 )
      return -1073741811;
    AutoInheritParams->ConstraintMask = -1;
  }
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  ExAcquirePushLockSharedEx(&SepMandatoryObjectTypePolicyLock, 0i64);
  v14 = 0;
  if( SepMandatoryObjectTypePolicyCount )
  {
    v15 = (VOID **)SepMandatoryObjectTypePolicy;
    while( ObjectType != *v15 )
    {
      ++v14;
      v15 += 3;
      if( v14 >= SepMandatoryObjectTypePolicyCount )
      {
        v16 = 0;
        goto LABEL_13;
      }
    }
    v17 = 3i64 * v14;
    v18 = SepMandatoryObjectTypePolicy[2 * v17 + 2];
    if( (v18 & 1) != 0 )
    {
      v11 = SepMandatoryObjectTypePolicy[2 * v17 + 4];
      v12 = SepMandatoryObjectTypePolicy[2 * v17 + 3];
    }
    if( (v18 & 2) != 0 )
    {
      v16 = SepMandatoryObjectTypePolicy[2 * v17 + 5];
      v6 = 1;
    }
    else
    {
      v16 = 0;
    }
  }
  else
  {
    v16 = 0;
  }
LABEL_13:
  if( _InterlockedCompareExchange64(&SepMandatoryObjectTypePolicyLock._bf_0, 0i64, 17i64) != 17 )
    ExfReleasePushLockShared(&SepMandatoryObjectTypePolicyLock);
  KeAbPostRelease(&SepMandatoryObjectTypePolicyLock);
  KeLeaveCriticalRegion();
  if( v12 && SecurityDescriptor )
  {
    v20 = *((_WORD *)SecurityDescriptor + 1);
    if( (v20 & 0x10) != 0 )
    {
      if( v20 >= 0 )
      {
        v21 = (_ACL *)*((_QWORD *)SecurityDescriptor + 3);
      }
      else
      {
        v23 = *((unsigned int *)SecurityDescriptor + 3);
        v21 = (_DWORD)v23 ? (_ACL *)((char *)SecurityDescriptor + v23) : 0i64;
      }
    }
    else
    {
      v21 = 0i64;
    }
    AceByType = RtlFindAceByType(v21, 0x11ui64, 0i64);
    if( AceByType )
    {
      AceByType[1] |= v12;
      v11 = 0;
    }
  }
  if( v6 )
  {
    if( SecurityDescriptor )
    {
      LODWORD(AutoInheritParams) = 0;
      while( 1 )
      {
        v24 = *((_WORD *)SecurityDescriptor + 1);
        if( (v24 & 0x10) != 0 )
        {
          if( v24 >= 0 )
          {
            v25 = (_ACL *)*((_QWORD *)SecurityDescriptor + 3);
          }
          else
          {
            v26 = *((unsigned int *)SecurityDescriptor + 3);
            v25 = (_DWORD)v26 ? (_ACL *)((char *)SecurityDescriptor + v26) : 0i64;
          }
        }
        else
        {
          v25 = 0i64;
        }
        v27 = RtlFindAceByType(v25, 0x11ui64, (UINT64 *)&AutoInheritParams);
        if( v27 )
        {
          if( (v27[1] & 8) == 0 )
            break;
        }
        LODWORD(AutoInheritParams) = (_DWORD)AutoInheritParams + 1;
        if( !v27 )
          goto LABEL_55;
      }
      *((_DWORD *)v27 + 1) &= v16;
    }
    else
    {
LABEL_55:
      if( v5 )
      {
        v5->ConstraintMask = v16;
        v11 |= 0x800u;
      }
    }
  }
  if( ParentSecurityDescriptor )
  {
    if( (!SecurityDescriptor || (*((_BYTE *)SecurityDescriptor + 2) & 4) == 0)
      && (*((_WORD *)ParentSecurityDescriptor + 1) & 0x400) != 0 )
    {
      v11 |= 1u;
    }
    if( (!SecurityDescriptor || (*((_BYTE *)SecurityDescriptor + 2) & 0x10) == 0)
      && (*((_WORD *)ParentSecurityDescriptor + 1) & 0x800) != 0 )
    {
      v11 |= 2u;
    }
  }
  *(_DWORD *)AutoInheritFlags = v11;
  return 0;
}

Referenced by:

ObInsertObjectEx
ObpAssignSecurity
SeComputeAutoInheritByObjectType