RtlpSysVolCheckOwnerAndSecurity

INT64 __fastcall RtlpSysVolCheckOwnerAndSecurity(VOID *Handle, _ACL *StandardAcl){
  unsigned int v2; 
  VOID *PoolWithTag; 
  NTSTATUS DaclSecurityDescriptor; 
  void *v7; 
  unsigned int i; 
  NTSTATUS v9; 
  _BYTE *v10; 
  char v11; 
  UINT8 *v12; 
  int SelfRelativeSD; 
  unsigned int v15; 
  int v16; 
  UINT8 *v17; 
  UINT8 *v18; 
  int v19; 
  UINT8 *v20; 
  UINT64 Length; 
  PACL Dacl; 
  PVOID Ace; 
  PSID Owner; 
  __int16 Sid2; 
  int v26; 
  __int16 v27; 
  int v28; 
  int v29; 
  __int16 v30; 
  int v31; 
  __int16 v32; 
  int v33; 
  v2 = 0;
  LODWORD(Length) = 0;
  Owner = 0i64;
  BYTE4(Length) = 0;
  Ace = 0i64;
  Dacl = 0i64;
  if( NtQuerySecurityObject(Handle, 5ui64, 0i64, 0i64, &Length) != -1073741789 )
    return 0i64;
  PoolWithTag = ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
  if( !PoolWithTag )
    return 3221225626i64;
  DaclSecurityDescriptor = NtQuerySecurityObject(Handle, 5ui64, PoolWithTag, (unsigned int)Length, &Length);
  v7 = PoolWithTag;
  if( DaclSecurityDescriptor < 0 )
    goto LABEL_24;
  DaclSecurityDescriptor = RtlGetDaclSecurityDescriptor(PoolWithTag, (UINT8 *)&Length + 4, &Dacl, (UINT8 *)&Length + 5);
  v7 = PoolWithTag;
  if( DaclSecurityDescriptor < 0 )
    goto LABEL_24;
  DaclSecurityDescriptor = RtlGetOwnerSecurityDescriptor(PoolWithTag, &Owner, (UINT8 *)&Length + 5);
  if( DaclSecurityDescriptor < 0 )
  {
    v7 = PoolWithTag;
LABEL_24:
    ExFreePoolWithTag(v7, 0);
    return(unsigned int)DaclSecurityDescriptor;
  }
  v31 = 0;
  v26 = 0;
  v30 = 257;
  v32 = 1280;
  v33 = 18;
  Sid2 = 513;
  v27 = 1280;
  v28 = 32;
  v29 = 544;
  if( Owner && RtlEqualSid(Owner, &Sid2) && BYTE4(Length) && Dacl )
  {
    for( i = 0; ; ++i )
    {
      v9 = RtlGetAce(Dacl, i, &Ace);
      v10 = Ace;
      if( v9 < 0 )
        v10 = 0i64;
      Ace = v10;
      if( !v10 )
        break;
      if( !*v10 && RtlEqualSid(v10 + 8, &v30) )
      {
        v11 = v10[1];
        if( (v11 & 1) == 0 || (v11 & 2) == 0 )
        {
          v10[1] = v11 | 3;
          SelfRelativeSD = NtSetSecurityObject(Handle, 4ui64, PoolWithTag);
          goto LABEL_26;
        }
        goto LABEL_18;
      }
    }
  }
  v15 = Length;
  if( (unsigned int)RtlSelfRelativeToAbsoluteSD2(PoolWithTag, &Length) != -1073741789 )
    goto LABEL_30;
  v16 = Length;
  v17 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
  v18 = v17;
  if( !v17 )
    goto LABEL_37;
  memmove(v17, (UINT8 *)PoolWithTag, v15);
  ExFreePoolWithTag(PoolWithTag, 0);
  LODWORD(Length) = v16;
  PoolWithTag = v18;
  v19 = RtlSelfRelativeToAbsoluteSD2(v18, &Length);
  if( v19 >= 0 )
  {
LABEL_30:
    SelfRelativeSD = RtlSetOwnerSecurityDescriptor(PoolWithTag, &Sid2, 0);
    if( SelfRelativeSD < 0
      || (SelfRelativeSD = RtlSetDaclSecurityDescriptor(PoolWithTag, 1u, StandardAcl, 0), SelfRelativeSD < 0)
      || (LODWORD(Length) = 0,
          SelfRelativeSD = RtlMakeSelfRelativeSD(PoolWithTag, 0i64, &Length),
          SelfRelativeSD != -1073741789) )
    {
LABEL_26:
      v2 = SelfRelativeSD;
LABEL_18:
      v12 = (UINT8 *)PoolWithTag;
LABEL_19:
      ExFreePoolWithTag(v12, 0);
      return v2;
    }
    v20 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
    v18 = v20;
    if( v20 )
    {
      v19 = RtlMakeSelfRelativeSD(PoolWithTag, v20, &Length);
      ExFreePoolWithTag(PoolWithTag, 0);
      if( v19 >= 0 )
      {
        v2 = NtSetSecurityObject(Handle, 5ui64, v18);
        v12 = v18;
        goto LABEL_19;
      }
      goto LABEL_36;
    }
LABEL_37:
    v2 = -1073741670;
    goto LABEL_18;
  }
LABEL_36:
  ExFreePoolWithTag(v18, 0);
  return(unsigned int)v19;
}

Referenced by:

RtlCreateSystemVolumeInformationFolder