SeAccessCheckByTypeWithAdminlessChecks

VOID __fastcall SeAccessCheckByTypeWithAdminlessChecks(
        INT16 *a1,
        VOID *a2,
        VOID *a3,
        INT64 a4,
        UINT64 a5,
        UINT64 a6,
        _GENERIC_MAPPING *a7,
        _DWORD *Address,
        UINT64 Length,
        UINT64 a10,
        _DWORD *a11,
        NTSTATUS *a12,
        UINT8 a13,
        CHAR a14){
  int v15; 
  __int64 v16; 
  __int64 v17; 
  UINT64 v18; 
  int v19; 
  unsigned int v20; 
  int v21; 
  PADAPTER_OBJECT v22; 
  __int64 v23; 
  char *v24; 
  __int64 v25; 
  char *v26; 
  VOID *Sid1; 
  PVOID *v28; 
  int v29; 
  UINT8 v30; 
  NTSTATUS v31; 
  INT8 v32; 
  struct _PRIVILEGE_SET *v33; 
  _ETHREAD *CurrentThread; 
  PERESOURCE *v35; 
  BOOL v36; 
  UINT8 v37; 
  char IsOwner; 
  __int16 *v39; 
  unsigned int v40; 
  int v41; 
  unsigned int *v42; 
  int *v43; 
  __int64 v44; 
  CHAR *v45; 
  UINT8 v46; 
  _DWORD *v47; 
  int *v48; 
  _DWORD *v49; 
  __int64 v50; 
  unsigned int v51; 
  __int64 v52; 
  INT8 v53; 
  int v54; 
  unsigned int v55; 
  ACL *v56; 
  int v57; 
  int v58; 
  int v59; 
  int v60; 
  int v61; 
  _ETHREAD *v62; 
  VOID *v63; 
  NTSTATUS *v64; 
  unsigned int v65; 
  _DWORD *v66; 
  _DWORD *v67; 
  unsigned int v68; 
  _DWORD *v69; 
  NTSTATUS *v70; 
  NTSTATUS *v71; 
  _DWORD *v72; 
  unsigned int PrivilegeCount; 
  unsigned int v74; 
  unsigned int v75; 
  int v76; 
  unsigned int v77; 
  _DMA_OPERATIONS *DmaOperations; 
  NTSTATUS *v79; 
  unsigned int v80; 
  _DWORD *v81; 
  __int64 v82; 
  ACL *v83; 
  void *v84; 
  NTSTATUS Cap; 
  __int64 v86; 
  __int64 v87; 
  unsigned int *PoolWithTag; 
  int v89; 
  char *v90; 
  unsigned int v91; 
  PVOID v92; 
  _DMA_OPERATIONS *v93; 
  __int64 v94; 
  __int64 v95; 
  __int64 v96; 
  __int64 v97; 
  int v98; 
  int v99; 
  _DMA_OPERATIONS *v100; 
  __int64 GetCommonBufferFromVectorByIndex; 
  __int64 AllocateCommonBufferWithBounds; 
  __int64 AllocateCommonBufferVector; 
  __int64 GetDmaDomain; 
  unsigned int v105; 
  unsigned int v106; 
  unsigned int v107; 
  unsigned int v108; 
  VOID **TrustLevelSid; 
  VOID **TrustLevelSida; 
  unsigned int v111; 
  unsigned __int8 v112; 
  int v113; 
  char v114; 
  char v115; 
  UINT64 RemainingDesiredAccess; 
  char v117; 
  BYTE v118; 
  BYTE v119; 
  char UseNewTrust[5]; 
  UINT64 v121; 
  NTSTATUS v122; 
  int v123; 
  PADAPTER_OBJECT DmaAdapter; 
  unsigned int v125; 
  PVOID OutputSecurityDescriptor; 
  UINT64 PreviouslyGrantedAccess; 
  char v128; 
  VOID *v129; 
  NTSTATUS *v130; 
  int v131; 
  int *v132; 
  PVOID v133; 
  int v134; 
  PPRIVILEGE_SET Privileges; 
  PVOID ResourceInfo; 
  UINT64 v137; 
  INT64 v138; 
  ACL *Sacl; 
  PVOID P; 
  INT64 v141; 
  INT64 v142; 
  PVOID CapturedSid; 
  PVOID InputSecurityDescriptor; 
  INT64 v145; 
  PVOID v146; 
  int v147; 
  CHAR v148[4]; 
  int v149; 
  int v150; 
  VOID *v151; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectContext; 
  void *Src; 
  INT64 v154[2]; 
  INT16 *v155; 
  VOID *v156; 
  VOID *v157; 
  UINT64 v158; 
  _DWORD *v159; 
  _DWORD *v160; 
  NTSTATUS *v161; 
  __int128 SecurityDescriptor[2]; 
  __int64 v163; 
  INT64 v164[2]; 
  __int64 v165; 
  int v166; 
  _GENERIC_MAPPING v167; 
  v15 = (int)a2;
  Src = a2;
  InputSecurityDescriptor = a1;
  v155 = a1;
  v156 = a2;
  v157 = a3;
  LODWORD(RemainingDesiredAccess) = a4;
  v158 = a5;
  LODWORD(v121) = a6;
  v159 = Address;
  v137 = a10;
  v129 = a11;
  v160 = a11;
  v130 = a12;
  v161 = a12;
  v147 = 0;
  P = 0i64;
  *(_DWORD *)v148 = 0;
  v149 = 0;
  v133 = 0i64;
  v150 = 0;
  v132 = 0i64;
  DmaAdapter = 0i64;
  OutputSecurityDescriptor = 0i64;
  CapturedSid = 0i64;
  LODWORD(PreviouslyGrantedAccess) = 0;
  v123 = 0;
  v167 = 0i64;
  v142 = 0i64;
  Privileges = 0i64;
  memset(&SubjectContext, 0, sizeof(SubjectContext));
  *(_OWORD *)v154 = 0i64;
  LOBYTE(v15) = 0;
  v114 = 0;
  ResourceInfo = 0i64;
  *(_OWORD *)v164 = 0i64;
  v165 = 0i64;
  v166 = 0;
  Sacl = 0i64;
  memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
  v163 = 0i64;
  v141 = 0i64;
  v117 = 0;
  v115 = 0;
  v131 = 0;
  HIDWORD(PreviouslyGrantedAccess) = v15;
  v128 = 0;
  v146 = 0i64;
  UseNewTrust[0] = 0;
  v118 = 0;
  v119 = 0;
  v151 = 0i64;
  v122 = -1073741790;
  LODWORD(v138) = -1;
  v145 = 0xFFFFFFFFi64;
  LODWORD(a2) = *((unsigned __int8 *)KeGetCurrentThread() + 562);
  v112 = (unsigned __int8)a2;
  if( !(_BYTE)a2 )
  {
    *a12 = 0;
    *a11 = RemainingDesiredAccess;
    return;
  }
  if( a13 )
  {
    if( !(_DWORD)a6 )
    {
      v19 = -1073741811;
      goto LABEL_19;
    }
    ProbeForWrite(a12, 4i64 * (unsigned int)a6, 4ui64);
    ProbeForWrite(v129, 4i64 * (unsigned int)a6, 4ui64);
  }
  else
  {
    v16 = (__int64)a12;
    if( (unsigned __int64)a12 >= 0x7FFFFFFF0000i64 )
      v16 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v16 = *(_DWORD *)v16;
    v17 = (__int64)a11;
    if( (unsigned __int64)a11 >= 0x7FFFFFFF0000i64 )
      v17 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v17 = *(_DWORD *)v17;
  }
  v18 = a10;
  if( a10 >= 0x7FFFFFFF0000i64 )
    v18 = 0x7FFFFFFF0000i64;
  *(_DWORD *)v18 = *(_DWORD *)v18;
  ProbeForWrite(Address, (unsigned int)Length, 4ui64);
  if( Address && (unsigned int)Length >= 0x14 )
    *Address = 0;
  if( ((unsigned __int8)a7 & 3) != 0 )
    ExRaiseDatatypeMisalignment();
  v167 = *a7;
  v19 = 0;
  LODWORD(a2) = v112;
LABEL_19:
  if( v19 < 0 )
    return;
  v20 = RemainingDesiredAccess;
  if( (RemainingDesiredAccess & 0xF0000000) != 0 )
  {
    v21 = -1073741594;
    v113 = -1073741594;
    v22 = DmaAdapter;
    goto LABEL_176;
  }
  v21 = SepReferenceTokenByHandle(a3, 8ui64, (CHAR)a2, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &v151);
  v113 = v21;
  if( v21 < 0 )
  {
    v22 = 0i64;
    DmaAdapter = 0i64;
    v53 = v112;
    v46 = a13;
    goto LABEL_80;
  }
  v22 = DmaAdapter;
  if( (unsigned __int64)a3 + 6 > 2 )
  {
    if( *(_DWORD *)&DmaAdapter[12].Version != 2 )
    {
      v21 = -1073741732;
      v113 = -1073741732;
      v53 = v112;
      goto LABEL_172;
    }
    if( *(int *)(&DmaAdapter[12].Size + 1) < 1 )
    {
      v21 = -1073741659;
      v113 = -1073741659;
      v53 = v112;
      goto LABEL_172;
    }
  }
  v21 = SeCaptureObjectTypeList(a5, (unsigned int)v121, v112, (CHAR **)&v142);
  v113 = v21;
  if( v21 < 0
    || (v21 = SeCaptureSecurityDescriptor(InputSecurityDescriptor, v112, PagedPool, 0, &OutputSecurityDescriptor),
        v113 = v21,
        v21 < 0) )
  {
LABEL_174:
    v53 = v112;
    goto LABEL_172;
  }
  if( !OutputSecurityDescriptor )
    goto LABEL_173;
  InputSecurityDescriptor = (char *)OutputSecurityDescriptor + 2;
  LODWORD(a2) = *((unsigned __int16 *)OutputSecurityDescriptor + 1);
  if( (__int16)a2 >= 0 )
  {
    v24 = (char *)*((_QWORD *)OutputSecurityDescriptor + 1);
  }
  else
  {
    v23 = *((unsigned int *)OutputSecurityDescriptor + 1);
    if( !(_DWORD)v23 )
      goto LABEL_173;
    v24 = (char *)OutputSecurityDescriptor + v23;
  }
  if( !v24 )
    goto LABEL_173;
  if( (__int16)a2 < 0 )
  {
    v25 = *((unsigned int *)OutputSecurityDescriptor + 2);
    if( (_DWORD)v25 )
    {
      v26 = (char *)OutputSecurityDescriptor + v25;
      goto LABEL_35;
    }
LABEL_173:
    v21 = -1073741703;
    v113 = -1073741703;
    goto LABEL_174;
  }
  v26 = (char *)*((_QWORD *)OutputSecurityDescriptor + 2);
LABEL_35:
  if( !v26 )
    goto LABEL_173;
  if( UseNewTrust[0] )
    Sid1 = v151;
  else
    Sid1 = *(VOID **)&v22[69].Version;
  v21 = SepTrustLevelCheck((INT64)&v138, OutputSecurityDescriptor, 0i64, (INT64)v22, Sid1, 1, &v138);
  v113 = v21;
  if( v21 < 0 )
    goto LABEL_176;
  if( ((unsigned int)v138 & RemainingDesiredAccess & 0xFDFFFFFF) != (RemainingDesiredAccess & 0xFDFFFFFF) )
  {
    v118 = 1;
LABEL_184:
    v31 = -1073741790;
    v32 = v112;
    goto LABEL_47;
  }
  v21 = SepFilterCheck((__int64)OutputSecurityDescriptor, (__int64 *)&ResourceInfo, (__int64)v22, 1, (char *)&v145);
  v113 = v21;
  if( v21 < 0 )
  {
LABEL_176:
    v53 = v112;
    goto LABEL_172;
  }
  if( ((unsigned int)v145 & RemainingDesiredAccess & 0xFDFFFFFF) != (RemainingDesiredAccess & 0xFDFFFFFF) )
  {
    v119 = 1;
    goto LABEL_184;
  }
  v21 = SepMandatoryIntegrityCheck(
          (int *)&v167,
          (__int64)OutputSecurityDescriptor,
          0,
          (__int64)v22,
          1,
          a14,
          (__int64)v154);
  v113 = v21;
  if( v21 < 0 )
    goto LABEL_176;
  v114 = 0;
  v29 = SepMandatoryToDiscretionary(v154, RemainingDesiredAccess);
  v31 = v29;
  if( (v29 < 0 || (RemainingDesiredAccess & 0x2000000) != 0)
    && ((__int64)v22[12].DmaOperations & 0x4000) != 0
    && HIDWORD(v154[1]) <= 0x2000 )
  {
    v30 = 1;
    v114 = 1;
  }
  if( v29 < 0 && !v30 )
  {
    v32 = v112;
    goto LABEL_48;
  }
  v32 = v112;
  v31 = SePrivilegePolicyCheck(&RemainingDesiredAccess, &PreviouslyGrantedAccess, 0i64, v22, &Privileges, v112);
  v20 = RemainingDesiredAccess;
  if( !(_DWORD)RemainingDesiredAccess )
  {
    LODWORD(a2) = BYTE4(PreviouslyGrantedAccess);
    if( (_DWORD)PreviouslyGrantedAccess )
      LODWORD(a2) = 1;
    HIDWORD(PreviouslyGrantedAccess) = (_DWORD)a2;
  }
LABEL_47:
  v30 = v114;
LABEL_48:
  if( v31 < 0 && !v30 )
  {
    v46 = a13;
    v71 = v130;
    if( a13 )
    {
      LODWORD(a2) = 0;
      v125 = 0;
      v72 = v129;
      while( (unsigned int)a2 < (unsigned int)v121 )
      {
        v71[(unsigned int)a2] = v31;
        v72[(unsigned int)a2] = 0;
        LODWORD(a2) = (_DWORD)a2 + 1;
        v125 = (unsigned int)a2;
      }
    }
    else
    {
      *v130 = v31;
      *(_DWORD *)v129 = 0;
    }
    v122 = v31;
    v21 = 0;
    v113 = 0;
    v53 = v112;
    goto LABEL_80;
  }
  v33 = Privileges;
  if( Privileges )
  {
    PrivilegeCount = Privileges->PrivilegeCount;
    v74 = 12 * Privileges->PrivilegeCount;
    v75 = v74 + 8;
    if( !Privileges->PrivilegeCount )
      v75 = 8;
    if( v75 > (unsigned int)Length )
    {
      v76 = v74 + 8;
      if( !PrivilegeCount )
        v76 = 8;
      *(_DWORD *)v137 = v76;
      v21 = -1073741789;
      v113 = -1073741789;
      v53 = v112;
      CmSiFreeMemory(v33);
      goto LABEL_172;
    }
    v77 = v74 + 8;
    if( !PrivilegeCount )
      v77 = 8;
    memmove((UINT8 *)Address, (UINT8 *)Privileges, v77);
    CmSiFreeMemory(v33);
  }
  else
  {
    if( (unsigned int)Length < 0x14 )
    {
      *(_DWORD *)v137 = 20;
      v21 = -1073741789;
      v113 = -1073741789;
      v46 = a13;
      v53 = v112;
      goto LABEL_80;
    }
    *(_QWORD *)Address = Privileges;
  }
  if( Src )
  {
    v21 = SeCaptureSid(Src, v32, v30, v28);
    v113 = v21;
    if( v21 < 0 )
    {
      CapturedSid = 0i64;
      v53 = v112;
LABEL_172:
      v46 = a13;
      goto LABEL_80;
    }
  }
  SeCaptureSubjectContext(&SubjectContext);
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  v22 = DmaAdapter;
  v35 = (PERESOURCE *)&DmaAdapter[3];
  LOBYTE(v36) = 1;
  ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v36);
  IsOwner = SepTokenIsOwner(v22, OutputSecurityDescriptor, v37);
  if( !SepAllowAccessUponLogoff && ((__int64)v22[12].DmaOperations & 0x20) == 0 )
  {
    DmaOperations = v22[13].DmaOperations;
    if( DmaOperations )
    {
      if( ((__int64)DmaOperations->AllocateAdapterChannel & 0x20) != 0 )
      {
        v46 = a13;
        v79 = v130;
        if( a13 )
        {
          v80 = 0;
          v125 = 0;
          v81 = v129;
          while( v80 < (unsigned int)v121 )
          {
            v79[v80] = -1073741790;
            v81[v80++] = 0;
            v125 = v80;
          }
        }
        else
        {
          *v130 = -1073741790;
          *(_DWORD *)v129 = 0;
        }
        v122 = -1073741790;
        v21 = 0;
        v113 = 0;
        v53 = v112;
        ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
        KeLeaveCriticalRegion();
        SeReleaseSubjectContext(&SubjectContext);
        v20 = RemainingDesiredAccess;
        goto LABEL_80;
      }
    }
  }
  v39 = (__int16 *)InputSecurityDescriptor;
  if( SepRmEnforceCap && (*(_WORD *)InputSecurityDescriptor & 0x10) != 0 && KeGetCurrentIrql() < 2u )
  {
    if( *(__int16 *)InputSecurityDescriptor >= 0 )
    {
      v83 = (ACL *)*((_QWORD *)OutputSecurityDescriptor + 3);
    }
    else
    {
      v82 = *((unsigned int *)OutputSecurityDescriptor + 3);
      if( !(_DWORD)v82 )
      {
        Sacl = 0i64;
        goto LABEL_55;
      }
      v83 = (ACL *)((char *)OutputSecurityDescriptor + v82);
    }
    Sacl = v83;
    if( v83 )
    {
      LODWORD(v84) = SepGetScopedPolicySid(v83);
      if( v84 )
      {
        Cap = SepRmReferenceFindCap(v84, (RTL_DYNAMIC_HASH_TABLE_ENTRY **)&v141);
        v86 = v141;
        if( Cap < 0 )
          v86 = SepRmDefaultCap;
        v141 = v86;
        v117 = 1;
      }
    }
  }
LABEL_55:
  v20 = RemainingDesiredAccess;
  if( (RemainingDesiredAccess & 0x2060000) != 0
    && IsOwner
    && ((*v39 & 4) == 0 ? (v56 = 0i64) : *v39 >= 0 ? (v56 = (ACL *)*((_QWORD *)OutputSecurityDescriptor + 4)) : (v55 = *((_DWORD *)OutputSecurityDescriptor + 4)) == 0 ? (v56 = 0i64) : (v56 = (ACL *)((char *)OutputSecurityDescriptor + v55)),
        !RtlpOwnerAcesPresent(0, v56)) )
  {
    if( (v20 & 0x2000000) != 0 )
    {
      v57 = 393216;
      v40 = PreviouslyGrantedAccess | 0x60000;
    }
    else
    {
      v57 = v20 & 0x60000;
      v40 = PreviouslyGrantedAccess | v20 & 0x60000;
    }
    v123 = v57;
    LODWORD(PreviouslyGrantedAccess) = v40;
    v20 &= 0xFFF9FFFF;
    LODWORD(RemainingDesiredAccess) = v20;
  }
  else
  {
    v40 = PreviouslyGrantedAccess;
  }
  if( v20 || v117 && !BYTE4(PreviouslyGrantedAccess) )
  {
    v22 = DmaAdapter;
    v41 = v123;
  }
  else
  {
    v22 = DmaAdapter;
    if( ((__int64)DmaAdapter[12].DmaOperations & 0x2000) != 0 || (v41 = v123) == 0 )
    {
      v46 = a13;
      if( a13 )
      {
        v68 = 0;
        v125 = 0;
        v69 = v160;
        v70 = v161;
        while( v68 < (unsigned int)v121 )
        {
          if( v40 )
          {
            v70[v68] = 0;
            v122 = 0;
            v69[v68] = v40;
          }
          else
          {
            v70[v68] = -1073741790;
            v122 = -1073741790;
            v69[v68] = 0;
          }
          v125 = ++v68;
        }
      }
      else
      {
        v67 = v129;
        if( v40 )
        {
          *v130 = 0;
          v122 = 0;
          *v67 = v40;
        }
        else
        {
          *v130 = -1073741790;
          v122 = -1073741790;
          *v67 = 0;
        }
      }
      v21 = 0;
      v113 = 0;
      v53 = v112;
      ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
      KeLeaveCriticalRegion();
      SeReleaseSubjectContext(&SubjectContext);
      goto LABEL_80;
    }
  }
  if( a13 )
  {
    v87 = (unsigned int)v121;
    PoolWithTag = (unsigned int *)ExAllocatePoolWithTag(PagedPool, 8i64 * (unsigned int)v121, 0x61476553ui64);
    v42 = PoolWithTag;
    P = PoolWithTag;
    if( !PoolWithTag )
    {
      ExReleaseResourceLite(*v35);
      KeLeaveCriticalRegion();
      SeReleaseSubjectContext(&SubjectContext);
      v21 = -1073741670;
      v113 = -1073741670;
      v53 = v112;
      goto LABEL_172;
    }
    v43 = (int *)&PoolWithTag[v87];
    v41 = v123;
  }
  else
  {
    v42 = (unsigned int *)&v147;
    P = &v147;
    v43 = (int *)v148;
  }
  LODWORD(v164[0]) = v41;
  v111 = v40;
  v44 = (unsigned int)v121;
  SepAccessCheck(
    (__int64)OutputSecurityDescriptor,
    CapturedSid,
    (__int64)SubjectContext.PrimaryToken,
    (__int64)v22,
    v20,
    (__int128 *)v142,
    v121,
    &v167,
    v111,
    v112,
    v42,
    0i64,
    v43,
    a13,
    IsOwner,
    (int *)v164,
    (__int64 *)&ResourceInfo,
    0i64,
    0i64,
    a14);
  if( SepRmEnforceCap && (v89 = *v43, v123 = v89, v89 >= 0) && v117 )
  {
    if( a13 )
    {
      v90 = (char *)ExAllocatePoolWithTag(PagedPool, 8 * v44, 0x61476553ui64);
      v133 = v90;
      if( !v90 )
      {
        ExReleaseResourceLite(*v35);
        KeLeaveCriticalRegion();
        SeReleaseSubjectContext(&SubjectContext);
        v21 = -1073741670;
        v113 = -1073741670;
        v22 = DmaAdapter;
        v20 = RemainingDesiredAccess;
        v53 = v112;
        goto LABEL_172;
      }
      v132 = (int *)&v90[4 * v44];
      v89 = *v43;
      v123 = *v43;
    }
    else
    {
      v133 = &v149;
      v132 = &v150;
    }
    LODWORD(Privileges) = *(_DWORD *)P;
    LOBYTE(v44) = 0;
    HIDWORD(PreviouslyGrantedAccess) = v44;
    if( (_DWORD)v121 )
    {
      v21 = SepCopyObjectTypeList(v142, (unsigned int)v121, (CHAR **)&v146);
      v113 = v21;
      if( v21 < 0 )
      {
        v22 = DmaAdapter;
        v20 = RemainingDesiredAccess;
        v53 = v112;
        goto LABEL_172;
      }
      v89 = v123;
      LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
    }
    v91 = 0;
    v134 = 0;
    v22 = DmaAdapter;
    v20 = RemainingDesiredAccess;
    while( v91 < *(_DWORD *)(v141 + 60) )
    {
      v137 = *(_QWORD *)(v141 + 8i64 * v91 + 64);
      if( !*(_QWORD *)(v137 + 24) )
        goto LABEL_278;
      v92 = ResourceInfo;
      if( !ResourceInfo )
      {
        LODWORD(v44) = (unsigned __int8)v44;
        if( (int)AuthzBasepInitializeResourceClaimsFromSacl((__int64)Sacl, (__int64)&ResourceInfo) < 0 )
          LODWORD(v44) = 1;
        HIDWORD(PreviouslyGrantedAccess) = v44;
        v92 = ResourceInfo;
      }
      v93 = v22[68].DmaOperations;
      v94 = v93 ? (__int64)v93[1].GetCommonBufferFromVectorByIndex : 0i64;
      v95 = v93 ? (__int64)v93[1].AllocateCommonBufferWithBounds : 0i64;
      v96 = v93 ? (__int64)v93[1].AllocateCommonBufferVector : 0i64;
      v97 = v93 ? (__int64)v93[1].GetDmaDomain : 0i64;
      v98 = AuthzBasepEvaluateAceCondition(
              (__int64)v22,
              (__int64)v22[48].DmaOperations,
              (__int64)v92,
              v97,
              v96,
              v95,
              v94,
              *(char **)(v137 + 24),
              *(_DWORD *)(v137 + 16),
              1,
              0,
              &v131);
      v21 = v98;
      v113 = v98;
      v99 = v131;
      if( v131 == 1 )
        goto LABEL_278;
      if( v98 < 0 )
        goto LABEL_294;
      if( ((__int64)v22[12].DmaOperations & 0x10) != 0 )
      {
        v100 = v22[68].DmaOperations;
        if( v100 )
          GetCommonBufferFromVectorByIndex = (__int64)v100[1].GetCommonBufferFromVectorByIndex;
        else
          GetCommonBufferFromVectorByIndex = 0i64;
        if( v100 )
          AllocateCommonBufferWithBounds = (__int64)v100[1].AllocateCommonBufferWithBounds;
        else
          AllocateCommonBufferWithBounds = 0i64;
        if( v100 )
          AllocateCommonBufferVector = (__int64)v100[1].AllocateCommonBufferVector;
        else
          AllocateCommonBufferVector = 0i64;
        if( v100 )
          GetDmaDomain = (__int64)v100[1].GetDmaDomain;
        else
          GetDmaDomain = 0i64;
        v21 = AuthzBasepEvaluateAceCondition(
                (__int64)v22,
                (__int64)v22[48].DmaOperations,
                (__int64)ResourceInfo,
                GetDmaDomain,
                AllocateCommonBufferVector,
                AllocateCommonBufferWithBounds,
                GetCommonBufferFromVectorByIndex,
                *(char **)(v137 + 24),
                *(_DWORD *)(v137 + 16),
                1,
                1,
                &v131);
        v113 = v21;
        if( v21 < 0 )
        {
LABEL_294:
          ExReleaseResourceLite(*v35);
          KeLeaveCriticalRegion();
          SeReleaseSubjectContext(&SubjectContext);
          v53 = v112;
          goto LABEL_172;
        }
        v99 = v131;
      }
      LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
      if( BYTE4(PreviouslyGrantedAccess) || v99 == 1 )
      {
LABEL_278:
        v21 = SepBuildCapeSecurityDescriptor(SecurityDescriptor, *(PVOID *)(v137 + 32), Sacl);
        v113 = v21;
        if( v21 < 0 )
          goto LABEL_294;
        v105 = v20;
        if( (*(_DWORD *)(v137 + 48) & 1) != 0 )
        {
          if( (v20 & 0x2000000) == 0 )
            v105 = PreviouslyGrantedAccess | v20;
          v106 = 0;
        }
        else
        {
          v106 = PreviouslyGrantedAccess;
        }
        v107 = v121;
        SepAccessCheck(
          (__int64)SecurityDescriptor,
          CapturedSid,
          (__int64)SubjectContext.PrimaryToken,
          (__int64)v22,
          v105,
          (__int128 *)v146,
          v121,
          &v167,
          v106,
          v112,
          (unsigned int *)v133,
          0i64,
          v132,
          a13,
          IsOwner,
          (int *)v164,
          (__int64 *)&ResourceInfo,
          0i64,
          0i64,
          a14);
        v108 = *(_DWORD *)v133;
        if( v115 )
          v108 = (unsigned int)Privileges & *(_DWORD *)v133;
        LODWORD(Privileges) = v108;
        if( v108 )
          v89 = *v132;
        else
          v89 = -1073741790;
        v123 = v89;
        v115 = 1;
        if( v146 )
          SepMergeObjectTypeListAccesses(v142, (INT64)v146, v107);
        if( v89 < 0 )
          break;
        LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
      }
      else
      {
        v89 = v123;
      }
      v91 = ++v134;
    }
    *v43 = v89;
    v45 = (CHAR *)P;
    *(_DWORD *)P &= (unsigned int)Privileges;
  }
  else
  {
    v22 = DmaAdapter;
    v20 = RemainingDesiredAccess;
    v45 = (CHAR *)P;
  }
  ExReleaseResourceLite(*v35);
  KeLeaveCriticalRegion();
  SeReleaseSubjectContext(&SubjectContext);
  if( (v20 & 0x2000000) != 0 )
  {
    if( !v114 || !*(_WORD *)((char *)&v165 + 5) )
    {
      v46 = a13;
      if( a13 )
        v58 = v121;
      else
        v58 = 0;
      LODWORD(TrustLevelSid) = v58;
      SepConstrainByMandatory((INT64)v154, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSid);
      goto LABEL_66;
    }
  }
  else if( v114 && !*(_WORD *)((char *)&v165 + 5) )
  {
    v46 = a13;
    v64 = v130;
    if( a13 )
    {
      v65 = 0;
      v125 = 0;
      v66 = v129;
      while( v65 < (unsigned int)v121 )
      {
        v64[v65] = -1073741790;
        v66[v65++] = 0;
        v125 = v65;
      }
    }
    else
    {
      *v130 = -1073741790;
      *(_DWORD *)v129 = 0;
    }
    v122 = -1073741790;
    v21 = 0;
    v113 = 0;
    v53 = v112;
    goto LABEL_80;
  }
  v46 = a13;
LABEL_66:
  if( (v20 & 0x2000000) != 0 )
  {
    v59 = v121;
    if( v46 )
      v60 = v121;
    else
      v60 = 0;
    LODWORD(TrustLevelSid) = v60;
    SepConstrainByConstraintMask((unsigned int)v138, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSid, &v118);
    if( v46 )
      v61 = v59;
    else
      v61 = 0;
    LODWORD(TrustLevelSida) = v61;
    SepConstrainByConstraintMask((unsigned int)v145, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSida, &v119);
  }
  a2 = v130;
  *v130 = *v43;
  v47 = v129;
  *(_DWORD *)v129 = *(_DWORD *)v45;
  v122 = *v43;
  v48 = v132;
  v49 = v133;
  if( SepRmEnforceCap && v115 && *v43 >= 0 )
  {
    *(_DWORD *)a2 = *v132;
    *v47 &= *v49;
    v122 = *v48;
  }
  if( v46 )
  {
    v50 = 1i64;
    v51 = v121;
    while( 1 )
    {
      v125 = v50;
      if( (unsigned int)v50 >= v51 )
        break;
      v52 = v50;
      *(_DWORD *)((char *)a2 + v52 * 4) = v43[v50];
      v47[v52] = *(_DWORD *)&v45[4 * v50];
      if( SepRmEnforceCap && v115 && v43[v52] >= 0 )
      {
        *((_DWORD *)a2 + v50) = v48[v50];
        v47[v50] &= v49[v50];
      }
      v50 = v125 + 1;
    }
  }
  v21 = 0;
  v113 = 0;
  v22 = DmaAdapter;
  v20 = RemainingDesiredAccess;
  v53 = v112;
LABEL_80:
  if( OutputSecurityDescriptor && v22 )
  {
    if( v118 || v119 )
    {
LABEL_129:
      v62 = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)v62 + 242);
      v22 = DmaAdapter;
      LOBYTE(a2) = 1;
      ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, (BOOL)a2);
      if( UseNewTrust[0] )
        v63 = v151;
      else
        v63 = *(VOID **)&v22[69].Version;
      v20 = RemainingDesiredAccess;
      SeLogAccessFailure(v22, 0i64, 0i64, (UINT64)v63, (UINT8)OutputSecurityDescriptor);
      ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
      KeLeaveCriticalRegion();
      v21 = v113;
      v54 = HIDWORD(v164[1]);
LABEL_86:
      if( v21 >= 0
        && v122 < 0
        && !v54
        && ((__int64)v22[12].DmaOperations & 0x4000) != 0
        && SepLpacCausedAccessFailure((INT64)v164, v20) )
      {
        SepLogLpacAccessFailure();
      }
      goto LABEL_88;
    }
    v54 = HIDWORD(v164[1]);
    if( HIDWORD(v164[1]) || ((__int64)v22[12].DmaOperations & 0x4000) == 0 )
      goto LABEL_86;
    if( v21 >= 0 )
    {
      if( v122 >= 0 && !HIBYTE(v165) )
        goto LABEL_86;
      goto LABEL_129;
    }
  }
LABEL_88:
  if( v46 )
  {
    if( P )
      ExFreePoolWithTag(P, 0);
    if( v133 )
      ExFreePoolWithTag(v133, 0);
  }
  if( v22 )
    HalPutDmaAdapter(v22);
  if( v142 )
    SeFreeCapturedObjectTypeList((PVOID)v142);
  if( CapturedSid )
    SeReleaseSid(CapturedSid, v53, 1u);
  if( OutputSecurityDescriptor )
    SeReleaseSecurityDescriptor(OutputSecurityDescriptor, v53, 0);
  if( v117 )
    SepRmDereferenceCap(v141);
  if( v146 )
    ExFreePoolWithTag(v146, 0);
  SepFreeResourceInfo(ResourceInfo);
}

Referenced by:

SeAccessCheckByType