SepCheckAndCopySelfRelativeSD

NTSTATUS __stdcall SepCheckAndCopySelfRelativeSD(
        _SECURITY_DESCRIPTOR *SecurityDescriptorIn,
        _SECURITY_DESCRIPTOR **SecurityDescriptorOut,
        UINT64 *SDLength,
        UINT8 *NeedToFree){
  int v7; 
  VOID **PoolWithTag; 
  _SECURITY_DESCRIPTOR *v9; 
  PSECURITY_DESCRIPTOR AbsoluteSecurityDescriptor; 

  AbsoluteSecurityDescriptor = SecurityDescriptorIn;
  *SecurityDescriptorOut = 0i64;
  *(_DWORD *)SDLength = 0;
  *NeedToFree = 0;
  v7 = 0;
  if( SecurityDescriptorIn )
  {
    if( (SecurityDescriptorIn->Control & 0x8000u) != 0 )
    {
      *(_DWORD *)SDLength = SepSecurityDescriptorStrictLength(SecurityDescriptorIn);
      *SecurityDescriptorOut = v9;
    }
    else
    {
      v7 = RtlAbsoluteToSelfRelativeSD(&AbsoluteSecurityDescriptor, 0i64, SDLength);
      if( v7 == -1073741789 )
      {
        PoolWithTag = ExAllocatePoolWithTag(1ui64, *(unsigned int *)SDLength, 1883333971i64);
        *SecurityDescriptorOut = (_SECURITY_DESCRIPTOR *)PoolWithTag;
        if( PoolWithTag )
        {
          v7 = RtlAbsoluteToSelfRelativeSD(AbsoluteSecurityDescriptor, PoolWithTag, SDLength);
          if( v7 >= 0 )
          {
            *NeedToFree = 1;
          }
          else
          {
            ExFreePoolWithTag(*SecurityDescriptorOut, 0);
            *SecurityDescriptorOut = 0i64;
          }
        }
        else
        {
          return -1073741670;
        }
      }
    }
  }
  return v7;
}

Referenced by:

SeOperationAuditAlarm
SepAdtOpenObjectAuditAlarm
SepAdtStagingEvent