RtlpAddKnownAce
NTSTATUS __stdcall RtlpAddKnownAce(
_ACL *Acl,
UINT64 AceRevision,
UINT64 AceFlags,
UINT64 AccessMask,
VOID *Sid,
UINT8 NewType){
int v6;
unsigned __int8 v7;
unsigned __int8 AclRevision;
unsigned __int8 v10;
int v11;
char v12;
_ACL *v13;
unsigned int v14;
_ACL *v15;
unsigned __int16 v16;
NTSTATUS result;
v6 = AccessMask;
v7 = AceFlags;
if( (unsigned __int64)Sid <= 0x7FFFFFFF0000i64 || (*(_BYTE *)Sid & 0xF) != 1 || *((_BYTE *)Sid + 1) > 0xFu )
return -1073741704;
AclRevision = Acl->AclRevision;
if( AclRevision > 4u || (unsigned int)AceRevision > 4 )
return -1073741735;
v10 = AclRevision;
if( AclRevision <= (unsigned __int8)AceRevision )
v10 = AceRevision;
v11 = AceFlags & 0xFFFFFFE0;
if( (AceFlags & 0xFFFFFFE0) != 0 )
{
if( NewType == 2 )
{
v11 = AceFlags & 0xFFFFFF20;
}
else if( !NewType )
{
v11 = AceFlags & 0xFFFFFFC0;
}
if( v11 )
return -1073741811;
}
RtlValidAcl(Acl, (VOID *)AceRevision, (VOID *)AceFlags);
if( !v12 )
return -1073741705;
v13 = Acl + 1;
v14 = 0;
if( Acl->AceCount )
{
while( v13 < (_ACL *)((char *)Acl + Acl->AclSize) )
{
++v14;
v13 = (_ACL *)((char *)v13 + v13->AclSize);
if( v14 >= Acl->AceCount )
goto LABEL_13;
}
return -1073741705;
}
LABEL_13:
v15 = (_ACL *)((char *)Acl + Acl->AclSize);
if( v13 > v15 )
v13 = 0i64;
v16 = 4 * (*((unsigned __int8 *)Sid + 1) + 4);
if( !v13 || (_ACL *)((char *)v13 + v16) > v15 )
return -1073741671;
v13->AclSize = v16;
v13->Sbz1 = v7;
v13->AclRevision = NewType;
*(_DWORD *)&v13->AceCount = v6;
memmove(&v13[1], Sid, 4 * *((unsigned __int8 *)Sid + 1) + 8);
++Acl->AceCount;
result = 0;
Acl->AclRevision = v10;
return result;
}Referenced by:
BiCreateKeySecurityDescriptor
CMFCreateSecurityDescriptor
CmGetRegKeySecurityDescriptor
CmpAdminSystemSecurityDescriptor
CmpGenerateAppHiveSecurityDescriptor
CmpHiveRootSecurityDescriptor
DbgkpCreateNotificationEvent
DrvDbGetSecurityDescriptor
IopCreateDefaultDeviceSecurityDescriptor
LocalGetAclForString
MiCreateMemoryEventSD
MiSessionObjectCreate
NtSetUuidSeed
ObCreateKernelObjectsSD
ObpCreateDefaultObjectTypeSD
ObpGetDosDevicesProtection
ObpGetSilosRootDirectory
ObpVerifyAccessToBoundaryEntry
PfpCreateEvent
PiAuCheckTokenMembership
PiAuGetServiceStateSecurityObject
PiAuGetStateDirectorySecurityObject
PiDevCfgGetKeySecurityDescriptor
PiUEventInitClientRegistrationContext
PnpGetEnumSecurityDescriptor
PnpGetPropertiesSecurityDescriptor
PopCreateHiberFileSecurityDescriptor
PopCreateNotificationName
PspAllocateAndQueryNotificationChannel
PspAllocateAndQueryProcessNotificationChannel
RtlAddAccessAllowedAce
RtlAddAccessAllowedAceEx
RtlAddAccessAllowedObjectAce
RtlAddAccessDeniedAceEx
RtlAddAccessDeniedObjectAce
RtlAddAuditAccessAce
RtlAddAuditAccessAceEx
RtlAddAuditAccessObjectAce
RtlpSysVolCreateSecurityDescriptor
SepAppendAceToTokenObjectAcl
SepCreateImpersonationTokenDacl
SmKmStoreFileMakeSecurityDescriptor
sub_1405F50F8