SeAccessCheckByTypeWithAdminlessChecks
VOID __fastcall SeAccessCheckByTypeWithAdminlessChecks(
INT16 *a1,
VOID *a2,
VOID *a3,
INT64 a4,
UINT64 a5,
UINT64 a6,
_GENERIC_MAPPING *a7,
_DWORD *Address,
UINT64 Length,
UINT64 a10,
_DWORD *a11,
NTSTATUS *a12,
UINT8 a13,
CHAR a14){
int v15;
__int64 v16;
__int64 v17;
UINT64 v18;
int v19;
unsigned int v20;
int v21;
PADAPTER_OBJECT v22;
__int64 v23;
char *v24;
__int64 v25;
char *v26;
VOID *Sid1;
PVOID *v28;
int v29;
UINT8 v30;
NTSTATUS v31;
INT8 v32;
struct _PRIVILEGE_SET *v33;
_ETHREAD *CurrentThread;
PERESOURCE *v35;
BOOL v36;
UINT8 v37;
char IsOwner;
__int16 *v39;
unsigned int v40;
int v41;
unsigned int *v42;
int *v43;
__int64 v44;
CHAR *v45;
UINT8 v46;
_DWORD *v47;
int *v48;
_DWORD *v49;
__int64 v50;
unsigned int v51;
__int64 v52;
INT8 v53;
int v54;
unsigned int v55;
ACL *v56;
int v57;
int v58;
int v59;
int v60;
int v61;
_ETHREAD *v62;
VOID *v63;
NTSTATUS *v64;
unsigned int v65;
_DWORD *v66;
_DWORD *v67;
unsigned int v68;
_DWORD *v69;
NTSTATUS *v70;
NTSTATUS *v71;
_DWORD *v72;
unsigned int PrivilegeCount;
unsigned int v74;
unsigned int v75;
int v76;
unsigned int v77;
_DMA_OPERATIONS *DmaOperations;
NTSTATUS *v79;
unsigned int v80;
_DWORD *v81;
__int64 v82;
ACL *v83;
void *v84;
NTSTATUS Cap;
__int64 v86;
__int64 v87;
unsigned int *PoolWithTag;
int v89;
char *v90;
unsigned int v91;
PVOID v92;
_DMA_OPERATIONS *v93;
__int64 v94;
__int64 v95;
__int64 v96;
__int64 v97;
int v98;
int v99;
_DMA_OPERATIONS *v100;
__int64 GetCommonBufferFromVectorByIndex;
__int64 AllocateCommonBufferWithBounds;
__int64 AllocateCommonBufferVector;
__int64 GetDmaDomain;
unsigned int v105;
unsigned int v106;
unsigned int v107;
unsigned int v108;
VOID **TrustLevelSid;
VOID **TrustLevelSida;
unsigned int v111;
unsigned __int8 v112;
int v113;
char v114;
char v115;
UINT64 RemainingDesiredAccess;
char v117;
BYTE v118;
BYTE v119;
char UseNewTrust[5];
UINT64 v121;
NTSTATUS v122;
int v123;
PADAPTER_OBJECT DmaAdapter;
unsigned int v125;
PVOID OutputSecurityDescriptor;
UINT64 PreviouslyGrantedAccess;
char v128;
VOID *v129;
NTSTATUS *v130;
int v131;
int *v132;
PVOID v133;
int v134;
PPRIVILEGE_SET Privileges;
PVOID ResourceInfo;
UINT64 v137;
INT64 v138;
ACL *Sacl;
PVOID P;
INT64 v141;
INT64 v142;
PVOID CapturedSid;
PVOID InputSecurityDescriptor;
INT64 v145;
PVOID v146;
int v147;
CHAR v148[4];
int v149;
int v150;
VOID *v151;
struct _SECURITY_SUBJECT_CONTEXT SubjectContext;
void *Src;
INT64 v154[2];
INT16 *v155;
VOID *v156;
VOID *v157;
UINT64 v158;
_DWORD *v159;
_DWORD *v160;
NTSTATUS *v161;
__int128 SecurityDescriptor[2];
__int64 v163;
INT64 v164[2];
__int64 v165;
int v166;
_GENERIC_MAPPING v167;
v15 = (int)a2;
Src = a2;
InputSecurityDescriptor = a1;
v155 = a1;
v156 = a2;
v157 = a3;
LODWORD(RemainingDesiredAccess) = a4;
v158 = a5;
LODWORD(v121) = a6;
v159 = Address;
v137 = a10;
v129 = a11;
v160 = a11;
v130 = a12;
v161 = a12;
v147 = 0;
P = 0i64;
*(_DWORD *)v148 = 0;
v149 = 0;
v133 = 0i64;
v150 = 0;
v132 = 0i64;
DmaAdapter = 0i64;
OutputSecurityDescriptor = 0i64;
CapturedSid = 0i64;
LODWORD(PreviouslyGrantedAccess) = 0;
v123 = 0;
v167 = 0i64;
v142 = 0i64;
Privileges = 0i64;
memset(&SubjectContext, 0, sizeof(SubjectContext));
*(_OWORD *)v154 = 0i64;
LOBYTE(v15) = 0;
v114 = 0;
ResourceInfo = 0i64;
*(_OWORD *)v164 = 0i64;
v165 = 0i64;
v166 = 0;
Sacl = 0i64;
memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
v163 = 0i64;
v141 = 0i64;
v117 = 0;
v115 = 0;
v131 = 0;
HIDWORD(PreviouslyGrantedAccess) = v15;
v128 = 0;
v146 = 0i64;
UseNewTrust[0] = 0;
v118 = 0;
v119 = 0;
v151 = 0i64;
v122 = -1073741790;
LODWORD(v138) = -1;
v145 = 0xFFFFFFFFi64;
LODWORD(a2) = *((unsigned __int8 *)KeGetCurrentThread() + 562);
v112 = (unsigned __int8)a2;
if( !(_BYTE)a2 )
{
*a12 = 0;
*a11 = RemainingDesiredAccess;
return;
}
if( a13 )
{
if( !(_DWORD)a6 )
{
v19 = -1073741811;
goto LABEL_19;
}
ProbeForWrite(a12, 4i64 * (unsigned int)a6, 4ui64);
ProbeForWrite(v129, 4i64 * (unsigned int)a6, 4ui64);
}
else
{
v16 = (__int64)a12;
if( (unsigned __int64)a12 >= 0x7FFFFFFF0000i64 )
v16 = 0x7FFFFFFF0000i64;
*(_DWORD *)v16 = *(_DWORD *)v16;
v17 = (__int64)a11;
if( (unsigned __int64)a11 >= 0x7FFFFFFF0000i64 )
v17 = 0x7FFFFFFF0000i64;
*(_DWORD *)v17 = *(_DWORD *)v17;
}
v18 = a10;
if( a10 >= 0x7FFFFFFF0000i64 )
v18 = 0x7FFFFFFF0000i64;
*(_DWORD *)v18 = *(_DWORD *)v18;
ProbeForWrite(Address, (unsigned int)Length, 4ui64);
if( Address && (unsigned int)Length >= 0x14 )
*Address = 0;
if( ((unsigned __int8)a7 & 3) != 0 )
ExRaiseDatatypeMisalignment();
v167 = *a7;
v19 = 0;
LODWORD(a2) = v112;
LABEL_19:
if( v19 < 0 )
return;
v20 = RemainingDesiredAccess;
if( (RemainingDesiredAccess & 0xF0000000) != 0 )
{
v21 = -1073741594;
v113 = -1073741594;
v22 = DmaAdapter;
goto LABEL_176;
}
v21 = SepReferenceTokenByHandle(a3, 8ui64, (CHAR)a2, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &v151);
v113 = v21;
if( v21 < 0 )
{
v22 = 0i64;
DmaAdapter = 0i64;
v53 = v112;
v46 = a13;
goto LABEL_80;
}
v22 = DmaAdapter;
if( (unsigned __int64)a3 + 6 > 2 )
{
if( *(_DWORD *)&DmaAdapter[12].Version != 2 )
{
v21 = -1073741732;
v113 = -1073741732;
v53 = v112;
goto LABEL_172;
}
if( *(int *)(&DmaAdapter[12].Size + 1) < 1 )
{
v21 = -1073741659;
v113 = -1073741659;
v53 = v112;
goto LABEL_172;
}
}
v21 = SeCaptureObjectTypeList(a5, (unsigned int)v121, v112, (CHAR **)&v142);
v113 = v21;
if( v21 < 0
|| (v21 = SeCaptureSecurityDescriptor(InputSecurityDescriptor, v112, PagedPool, 0, &OutputSecurityDescriptor),
v113 = v21,
v21 < 0) )
{
LABEL_174:
v53 = v112;
goto LABEL_172;
}
if( !OutputSecurityDescriptor )
goto LABEL_173;
InputSecurityDescriptor = (char *)OutputSecurityDescriptor + 2;
LODWORD(a2) = *((unsigned __int16 *)OutputSecurityDescriptor + 1);
if( (__int16)a2 >= 0 )
{
v24 = (char *)*((_QWORD *)OutputSecurityDescriptor + 1);
}
else
{
v23 = *((unsigned int *)OutputSecurityDescriptor + 1);
if( !(_DWORD)v23 )
goto LABEL_173;
v24 = (char *)OutputSecurityDescriptor + v23;
}
if( !v24 )
goto LABEL_173;
if( (__int16)a2 < 0 )
{
v25 = *((unsigned int *)OutputSecurityDescriptor + 2);
if( (_DWORD)v25 )
{
v26 = (char *)OutputSecurityDescriptor + v25;
goto LABEL_35;
}
LABEL_173:
v21 = -1073741703;
v113 = -1073741703;
goto LABEL_174;
}
v26 = (char *)*((_QWORD *)OutputSecurityDescriptor + 2);
LABEL_35:
if( !v26 )
goto LABEL_173;
if( UseNewTrust[0] )
Sid1 = v151;
else
Sid1 = *(VOID **)&v22[69].Version;
v21 = SepTrustLevelCheck((INT64)&v138, OutputSecurityDescriptor, 0i64, (INT64)v22, Sid1, 1, &v138);
v113 = v21;
if( v21 < 0 )
goto LABEL_176;
if( ((unsigned int)v138 & RemainingDesiredAccess & 0xFDFFFFFF) != (RemainingDesiredAccess & 0xFDFFFFFF) )
{
v118 = 1;
LABEL_184:
v31 = -1073741790;
v32 = v112;
goto LABEL_47;
}
v21 = SepFilterCheck((__int64)OutputSecurityDescriptor, (__int64 *)&ResourceInfo, (__int64)v22, 1, (char *)&v145);
v113 = v21;
if( v21 < 0 )
{
LABEL_176:
v53 = v112;
goto LABEL_172;
}
if( ((unsigned int)v145 & RemainingDesiredAccess & 0xFDFFFFFF) != (RemainingDesiredAccess & 0xFDFFFFFF) )
{
v119 = 1;
goto LABEL_184;
}
v21 = SepMandatoryIntegrityCheck(
(int *)&v167,
(__int64)OutputSecurityDescriptor,
0,
(__int64)v22,
1,
a14,
(__int64)v154);
v113 = v21;
if( v21 < 0 )
goto LABEL_176;
v114 = 0;
v29 = SepMandatoryToDiscretionary(v154, RemainingDesiredAccess);
v31 = v29;
if( (v29 < 0 || (RemainingDesiredAccess & 0x2000000) != 0)
&& ((__int64)v22[12].DmaOperations & 0x4000) != 0
&& HIDWORD(v154[1]) <= 0x2000 )
{
v30 = 1;
v114 = 1;
}
if( v29 < 0 && !v30 )
{
v32 = v112;
goto LABEL_48;
}
v32 = v112;
v31 = SePrivilegePolicyCheck(&RemainingDesiredAccess, &PreviouslyGrantedAccess, 0i64, v22, &Privileges, v112);
v20 = RemainingDesiredAccess;
if( !(_DWORD)RemainingDesiredAccess )
{
LODWORD(a2) = BYTE4(PreviouslyGrantedAccess);
if( (_DWORD)PreviouslyGrantedAccess )
LODWORD(a2) = 1;
HIDWORD(PreviouslyGrantedAccess) = (_DWORD)a2;
}
LABEL_47:
v30 = v114;
LABEL_48:
if( v31 < 0 && !v30 )
{
v46 = a13;
v71 = v130;
if( a13 )
{
LODWORD(a2) = 0;
v125 = 0;
v72 = v129;
while( (unsigned int)a2 < (unsigned int)v121 )
{
v71[(unsigned int)a2] = v31;
v72[(unsigned int)a2] = 0;
LODWORD(a2) = (_DWORD)a2 + 1;
v125 = (unsigned int)a2;
}
}
else
{
*v130 = v31;
*(_DWORD *)v129 = 0;
}
v122 = v31;
v21 = 0;
v113 = 0;
v53 = v112;
goto LABEL_80;
}
v33 = Privileges;
if( Privileges )
{
PrivilegeCount = Privileges->PrivilegeCount;
v74 = 12 * Privileges->PrivilegeCount;
v75 = v74 + 8;
if( !Privileges->PrivilegeCount )
v75 = 8;
if( v75 > (unsigned int)Length )
{
v76 = v74 + 8;
if( !PrivilegeCount )
v76 = 8;
*(_DWORD *)v137 = v76;
v21 = -1073741789;
v113 = -1073741789;
v53 = v112;
CmSiFreeMemory(v33);
goto LABEL_172;
}
v77 = v74 + 8;
if( !PrivilegeCount )
v77 = 8;
memmove((UINT8 *)Address, (UINT8 *)Privileges, v77);
CmSiFreeMemory(v33);
}
else
{
if( (unsigned int)Length < 0x14 )
{
*(_DWORD *)v137 = 20;
v21 = -1073741789;
v113 = -1073741789;
v46 = a13;
v53 = v112;
goto LABEL_80;
}
*(_QWORD *)Address = Privileges;
}
if( Src )
{
v21 = SeCaptureSid(Src, v32, v30, v28);
v113 = v21;
if( v21 < 0 )
{
CapturedSid = 0i64;
v53 = v112;
LABEL_172:
v46 = a13;
goto LABEL_80;
}
}
SeCaptureSubjectContext(&SubjectContext);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v22 = DmaAdapter;
v35 = (PERESOURCE *)&DmaAdapter[3];
LOBYTE(v36) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v36);
IsOwner = SepTokenIsOwner(v22, OutputSecurityDescriptor, v37);
if( !SepAllowAccessUponLogoff && ((__int64)v22[12].DmaOperations & 0x20) == 0 )
{
DmaOperations = v22[13].DmaOperations;
if( DmaOperations )
{
if( ((__int64)DmaOperations->AllocateAdapterChannel & 0x20) != 0 )
{
v46 = a13;
v79 = v130;
if( a13 )
{
v80 = 0;
v125 = 0;
v81 = v129;
while( v80 < (unsigned int)v121 )
{
v79[v80] = -1073741790;
v81[v80++] = 0;
v125 = v80;
}
}
else
{
*v130 = -1073741790;
*(_DWORD *)v129 = 0;
}
v122 = -1073741790;
v21 = 0;
v113 = 0;
v53 = v112;
ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v20 = RemainingDesiredAccess;
goto LABEL_80;
}
}
}
v39 = (__int16 *)InputSecurityDescriptor;
if( SepRmEnforceCap && (*(_WORD *)InputSecurityDescriptor & 0x10) != 0 && KeGetCurrentIrql() < 2u )
{
if( *(__int16 *)InputSecurityDescriptor >= 0 )
{
v83 = (ACL *)*((_QWORD *)OutputSecurityDescriptor + 3);
}
else
{
v82 = *((unsigned int *)OutputSecurityDescriptor + 3);
if( !(_DWORD)v82 )
{
Sacl = 0i64;
goto LABEL_55;
}
v83 = (ACL *)((char *)OutputSecurityDescriptor + v82);
}
Sacl = v83;
if( v83 )
{
LODWORD(v84) = SepGetScopedPolicySid(v83);
if( v84 )
{
Cap = SepRmReferenceFindCap(v84, (RTL_DYNAMIC_HASH_TABLE_ENTRY **)&v141);
v86 = v141;
if( Cap < 0 )
v86 = SepRmDefaultCap;
v141 = v86;
v117 = 1;
}
}
}
LABEL_55:
v20 = RemainingDesiredAccess;
if( (RemainingDesiredAccess & 0x2060000) != 0
&& IsOwner
&& ((*v39 & 4) == 0 ? (v56 = 0i64) : *v39 >= 0 ? (v56 = (ACL *)*((_QWORD *)OutputSecurityDescriptor + 4)) : (v55 = *((_DWORD *)OutputSecurityDescriptor + 4)) == 0 ? (v56 = 0i64) : (v56 = (ACL *)((char *)OutputSecurityDescriptor + v55)),
!RtlpOwnerAcesPresent(0, v56)) )
{
if( (v20 & 0x2000000) != 0 )
{
v57 = 393216;
v40 = PreviouslyGrantedAccess | 0x60000;
}
else
{
v57 = v20 & 0x60000;
v40 = PreviouslyGrantedAccess | v20 & 0x60000;
}
v123 = v57;
LODWORD(PreviouslyGrantedAccess) = v40;
v20 &= 0xFFF9FFFF;
LODWORD(RemainingDesiredAccess) = v20;
}
else
{
v40 = PreviouslyGrantedAccess;
}
if( v20 || v117 && !BYTE4(PreviouslyGrantedAccess) )
{
v22 = DmaAdapter;
v41 = v123;
}
else
{
v22 = DmaAdapter;
if( ((__int64)DmaAdapter[12].DmaOperations & 0x2000) != 0 || (v41 = v123) == 0 )
{
v46 = a13;
if( a13 )
{
v68 = 0;
v125 = 0;
v69 = v160;
v70 = v161;
while( v68 < (unsigned int)v121 )
{
if( v40 )
{
v70[v68] = 0;
v122 = 0;
v69[v68] = v40;
}
else
{
v70[v68] = -1073741790;
v122 = -1073741790;
v69[v68] = 0;
}
v125 = ++v68;
}
}
else
{
v67 = v129;
if( v40 )
{
*v130 = 0;
v122 = 0;
*v67 = v40;
}
else
{
*v130 = -1073741790;
v122 = -1073741790;
*v67 = 0;
}
}
v21 = 0;
v113 = 0;
v53 = v112;
ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
goto LABEL_80;
}
}
if( a13 )
{
v87 = (unsigned int)v121;
PoolWithTag = (unsigned int *)ExAllocatePoolWithTag(PagedPool, 8i64 * (unsigned int)v121, 0x61476553ui64);
v42 = PoolWithTag;
P = PoolWithTag;
if( !PoolWithTag )
{
ExReleaseResourceLite(*v35);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v21 = -1073741670;
v113 = -1073741670;
v53 = v112;
goto LABEL_172;
}
v43 = (int *)&PoolWithTag[v87];
v41 = v123;
}
else
{
v42 = (unsigned int *)&v147;
P = &v147;
v43 = (int *)v148;
}
LODWORD(v164[0]) = v41;
v111 = v40;
v44 = (unsigned int)v121;
SepAccessCheck(
(__int64)OutputSecurityDescriptor,
CapturedSid,
(__int64)SubjectContext.PrimaryToken,
(__int64)v22,
v20,
(__int128 *)v142,
v121,
&v167,
v111,
v112,
v42,
0i64,
v43,
a13,
IsOwner,
(int *)v164,
(__int64 *)&ResourceInfo,
0i64,
0i64,
a14);
if( SepRmEnforceCap && (v89 = *v43, v123 = v89, v89 >= 0) && v117 )
{
if( a13 )
{
v90 = (char *)ExAllocatePoolWithTag(PagedPool, 8 * v44, 0x61476553ui64);
v133 = v90;
if( !v90 )
{
ExReleaseResourceLite(*v35);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v21 = -1073741670;
v113 = -1073741670;
v22 = DmaAdapter;
v20 = RemainingDesiredAccess;
v53 = v112;
goto LABEL_172;
}
v132 = (int *)&v90[4 * v44];
v89 = *v43;
v123 = *v43;
}
else
{
v133 = &v149;
v132 = &v150;
}
LODWORD(Privileges) = *(_DWORD *)P;
LOBYTE(v44) = 0;
HIDWORD(PreviouslyGrantedAccess) = v44;
if( (_DWORD)v121 )
{
v21 = SepCopyObjectTypeList(v142, (unsigned int)v121, (CHAR **)&v146);
v113 = v21;
if( v21 < 0 )
{
v22 = DmaAdapter;
v20 = RemainingDesiredAccess;
v53 = v112;
goto LABEL_172;
}
v89 = v123;
LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
}
v91 = 0;
v134 = 0;
v22 = DmaAdapter;
v20 = RemainingDesiredAccess;
while( v91 < *(_DWORD *)(v141 + 60) )
{
v137 = *(_QWORD *)(v141 + 8i64 * v91 + 64);
if( !*(_QWORD *)(v137 + 24) )
goto LABEL_278;
v92 = ResourceInfo;
if( !ResourceInfo )
{
LODWORD(v44) = (unsigned __int8)v44;
if( (int)AuthzBasepInitializeResourceClaimsFromSacl((__int64)Sacl, (__int64)&ResourceInfo) < 0 )
LODWORD(v44) = 1;
HIDWORD(PreviouslyGrantedAccess) = v44;
v92 = ResourceInfo;
}
v93 = v22[68].DmaOperations;
v94 = v93 ? (__int64)v93[1].GetCommonBufferFromVectorByIndex : 0i64;
v95 = v93 ? (__int64)v93[1].AllocateCommonBufferWithBounds : 0i64;
v96 = v93 ? (__int64)v93[1].AllocateCommonBufferVector : 0i64;
v97 = v93 ? (__int64)v93[1].GetDmaDomain : 0i64;
v98 = AuthzBasepEvaluateAceCondition(
(__int64)v22,
(__int64)v22[48].DmaOperations,
(__int64)v92,
v97,
v96,
v95,
v94,
*(char **)(v137 + 24),
*(_DWORD *)(v137 + 16),
1,
0,
&v131);
v21 = v98;
v113 = v98;
v99 = v131;
if( v131 == 1 )
goto LABEL_278;
if( v98 < 0 )
goto LABEL_294;
if( ((__int64)v22[12].DmaOperations & 0x10) != 0 )
{
v100 = v22[68].DmaOperations;
if( v100 )
GetCommonBufferFromVectorByIndex = (__int64)v100[1].GetCommonBufferFromVectorByIndex;
else
GetCommonBufferFromVectorByIndex = 0i64;
if( v100 )
AllocateCommonBufferWithBounds = (__int64)v100[1].AllocateCommonBufferWithBounds;
else
AllocateCommonBufferWithBounds = 0i64;
if( v100 )
AllocateCommonBufferVector = (__int64)v100[1].AllocateCommonBufferVector;
else
AllocateCommonBufferVector = 0i64;
if( v100 )
GetDmaDomain = (__int64)v100[1].GetDmaDomain;
else
GetDmaDomain = 0i64;
v21 = AuthzBasepEvaluateAceCondition(
(__int64)v22,
(__int64)v22[48].DmaOperations,
(__int64)ResourceInfo,
GetDmaDomain,
AllocateCommonBufferVector,
AllocateCommonBufferWithBounds,
GetCommonBufferFromVectorByIndex,
*(char **)(v137 + 24),
*(_DWORD *)(v137 + 16),
1,
1,
&v131);
v113 = v21;
if( v21 < 0 )
{
LABEL_294:
ExReleaseResourceLite(*v35);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
v53 = v112;
goto LABEL_172;
}
v99 = v131;
}
LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
if( BYTE4(PreviouslyGrantedAccess) || v99 == 1 )
{
LABEL_278:
v21 = SepBuildCapeSecurityDescriptor(SecurityDescriptor, *(PVOID *)(v137 + 32), Sacl);
v113 = v21;
if( v21 < 0 )
goto LABEL_294;
v105 = v20;
if( (*(_DWORD *)(v137 + 48) & 1) != 0 )
{
if( (v20 & 0x2000000) == 0 )
v105 = PreviouslyGrantedAccess | v20;
v106 = 0;
}
else
{
v106 = PreviouslyGrantedAccess;
}
v107 = v121;
SepAccessCheck(
(__int64)SecurityDescriptor,
CapturedSid,
(__int64)SubjectContext.PrimaryToken,
(__int64)v22,
v105,
(__int128 *)v146,
v121,
&v167,
v106,
v112,
(unsigned int *)v133,
0i64,
v132,
a13,
IsOwner,
(int *)v164,
(__int64 *)&ResourceInfo,
0i64,
0i64,
a14);
v108 = *(_DWORD *)v133;
if( v115 )
v108 = (unsigned int)Privileges & *(_DWORD *)v133;
LODWORD(Privileges) = v108;
if( v108 )
v89 = *v132;
else
v89 = -1073741790;
v123 = v89;
v115 = 1;
if( v146 )
SepMergeObjectTypeListAccesses(v142, (INT64)v146, v107);
if( v89 < 0 )
break;
LOBYTE(v44) = BYTE4(PreviouslyGrantedAccess);
}
else
{
v89 = v123;
}
v91 = ++v134;
}
*v43 = v89;
v45 = (CHAR *)P;
*(_DWORD *)P &= (unsigned int)Privileges;
}
else
{
v22 = DmaAdapter;
v20 = RemainingDesiredAccess;
v45 = (CHAR *)P;
}
ExReleaseResourceLite(*v35);
KeLeaveCriticalRegion();
SeReleaseSubjectContext(&SubjectContext);
if( (v20 & 0x2000000) != 0 )
{
if( !v114 || !*(_WORD *)((char *)&v165 + 5) )
{
v46 = a13;
if( a13 )
v58 = v121;
else
v58 = 0;
LODWORD(TrustLevelSid) = v58;
SepConstrainByMandatory((INT64)v154, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSid);
goto LABEL_66;
}
}
else if( v114 && !*(_WORD *)((char *)&v165 + 5) )
{
v46 = a13;
v64 = v130;
if( a13 )
{
v65 = 0;
v125 = 0;
v66 = v129;
while( v65 < (unsigned int)v121 )
{
v64[v65] = -1073741790;
v66[v65++] = 0;
v125 = v65;
}
}
else
{
*v130 = -1073741790;
*(_DWORD *)v129 = 0;
}
v122 = -1073741790;
v21 = 0;
v113 = 0;
v53 = v112;
goto LABEL_80;
}
v46 = a13;
LABEL_66:
if( (v20 & 0x2000000) != 0 )
{
v59 = v121;
if( v46 )
v60 = v121;
else
v60 = 0;
LODWORD(TrustLevelSid) = v60;
SepConstrainByConstraintMask((unsigned int)v138, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSid, &v118);
if( v46 )
v61 = v59;
else
v61 = 0;
LODWORD(TrustLevelSida) = v61;
SepConstrainByConstraintMask((unsigned int)v145, v20, v45, (CHAR *)v43, 0i64, (UINT64)TrustLevelSida, &v119);
}
a2 = v130;
*v130 = *v43;
v47 = v129;
*(_DWORD *)v129 = *(_DWORD *)v45;
v122 = *v43;
v48 = v132;
v49 = v133;
if( SepRmEnforceCap && v115 && *v43 >= 0 )
{
*(_DWORD *)a2 = *v132;
*v47 &= *v49;
v122 = *v48;
}
if( v46 )
{
v50 = 1i64;
v51 = v121;
while( 1 )
{
v125 = v50;
if( (unsigned int)v50 >= v51 )
break;
v52 = v50;
*(_DWORD *)((char *)a2 + v52 * 4) = v43[v50];
v47[v52] = *(_DWORD *)&v45[4 * v50];
if( SepRmEnforceCap && v115 && v43[v52] >= 0 )
{
*((_DWORD *)a2 + v50) = v48[v50];
v47[v50] &= v49[v50];
}
v50 = v125 + 1;
}
}
v21 = 0;
v113 = 0;
v22 = DmaAdapter;
v20 = RemainingDesiredAccess;
v53 = v112;
LABEL_80:
if( OutputSecurityDescriptor && v22 )
{
if( v118 || v119 )
{
LABEL_129:
v62 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v62 + 242);
v22 = DmaAdapter;
LOBYTE(a2) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, (BOOL)a2);
if( UseNewTrust[0] )
v63 = v151;
else
v63 = *(VOID **)&v22[69].Version;
v20 = RemainingDesiredAccess;
SeLogAccessFailure(v22, 0i64, 0i64, (UINT64)v63, (UINT8)OutputSecurityDescriptor);
ExReleaseResourceLite(*(PERESOURCE *)&v22[3].Version);
KeLeaveCriticalRegion();
v21 = v113;
v54 = HIDWORD(v164[1]);
LABEL_86:
if( v21 >= 0
&& v122 < 0
&& !v54
&& ((__int64)v22[12].DmaOperations & 0x4000) != 0
&& SepLpacCausedAccessFailure((INT64)v164, v20) )
{
SepLogLpacAccessFailure();
}
goto LABEL_88;
}
v54 = HIDWORD(v164[1]);
if( HIDWORD(v164[1]) || ((__int64)v22[12].DmaOperations & 0x4000) == 0 )
goto LABEL_86;
if( v21 >= 0 )
{
if( v122 >= 0 && !HIBYTE(v165) )
goto LABEL_86;
goto LABEL_129;
}
}
LABEL_88:
if( v46 )
{
if( P )
ExFreePoolWithTag(P, 0);
if( v133 )
ExFreePoolWithTag(v133, 0);
}
if( v22 )
HalPutDmaAdapter(v22);
if( v142 )
SeFreeCapturedObjectTypeList((PVOID)v142);
if( CapturedSid )
SeReleaseSid(CapturedSid, v53, 1u);
if( OutputSecurityDescriptor )
SeReleaseSecurityDescriptor(OutputSecurityDescriptor, v53, 0);
if( v117 )
SepRmDereferenceCap(v141);
if( v146 )
ExFreePoolWithTag(v146, 0);
SepFreeResourceInfo(ResourceInfo);
}Referenced by:
SeAccessCheckByType