CmpSetSecurityDescriptorInfo
INT64 __fastcall CmpSetSecurityDescriptorInfo(
_CM_KEY_CONTROL_BLOCK *Key,
UINT *SecurityInformation,
void *ModificationDescriptor,
void **ObjectsSecurityDescriptor,
_POOL_TYPE PoolType,
_GENERIC_MAPPING *GenericMapping,
_CM_TRANS *CmTrans,
_CM_KCB_UOW *UoW){
_HHIVE *KeyHive;
unsigned int v11;
unsigned int KeyCell;
_CELL_DATA *v13;
_CELL_DATA *(__fastcall *GetCellRoutine)(_HHIVE *, unsigned int, _HV_GET_CELL_CONTEXT *);
INT64 v15;
_CM_TRANS *v16;
INT64 v17;
LIST_ENTRY *KCBCacheSecurity;
__int64 v19;
_CHILD_LIST *v20;
__int64 v21;
struct _PRIVILEGE_SET *v22;
UINT v23;
PSECURITY_SUBJECT_CONTEXT Token;
int v25;
int v26;
_CM_KCB_UOW *v27;
_LARGE_INTEGER v28;
unsigned int v29;
__int64 v30;
int v32;
ULONG_PTR v33;
__int64 v34;
int v35;
ULONG v36;
__int64 v37;
unsigned int v38;
_CM_KEY_SECURITY_CACHE *v39;
unsigned int *v40;
int v41;
_UNICODE_STRING *v42;
WCHAR v43;
int *v44;
ULONG_PTR BugCheckParameter4;
UINT64 v47;
__int64 v48;
unsigned int Flink;
VOID *CellAddress;
ULONG_PTR v51;
PVOID P;
UINT64 v53;
PPRIVILEGE_SET Privileges;
int v55[2];
__int64 v56;
_HV_GET_CELL_CONTEXT CellAddressContext;
size_t Size;
int *v59;
int v60[2];
int v61[2];
struct _UNICODE_STRING DestinationString;
PSECURITY_DESCRIPTOR NewDescriptor;
void **AceRemoved;
PSECURITY_SUBJECT_CONTEXT SubjectSecurityContext;
AceRemoved = ObjectsSecurityDescriptor;
NewDescriptor = ModificationDescriptor;
P = 0i64;
v55[1] = 0;
*(_DWORD *)&CellAddressContext.BinContext = 0;
v55[0] = -1;
CellAddressContext.Cell = -1;
KeyHive = Key->KeyHash.KeyHive;
v11 = 0;
KeyCell = Key->KeyHash.KeyCell;
v13 = 0i64;
v60[0] = -1;
v61[0] = -1;
v60[1] = 0;
v61[1] = 0;
DestinationString = 0i64;
GetCellRoutine = KeyHive->GetCellRoutine;
LODWORD(v51) = 0;
v59 = 0i64;
LOBYTE(AceRemoved) = 0;
v48 = 0i64;
CellAddress = 0i64;
Privileges = 0i64;
LODWORD(v53) = KeyCell;
v15 = (__int64)GetCellRoutine(KeyHive, KeyCell, (_HV_GET_CELL_CONTEXT *)v61);
v56 = v15;
if( !v15 )
return 3221225626i64;
CmpUpdateKeyNodeAccessBits((UINT64)KeyHive, v15, KeyCell);
v16 = CmTrans;
KCBCacheSecurity = CmGetKCBCacheSecurity((LIST_ENTRY *)Key, (INT64)CmTrans, v17);
Flink = (unsigned int)KCBCacheSecurity->Flink;
v19 = (__int64)KeyHive->GetCellRoutine(KeyHive, (unsigned int)KCBCacheSecurity->Flink, (_HV_GET_CELL_CONTEXT *)v55);
v21 = v19;
if( !v19
|| (CmpAllocateTransientPoolWithTag((_HHIVE *)1, *(unsigned int *)(v19 + 16), 0x36384D43ui64, v20),
(Privileges = v22) == 0i64) )
{
v25 = -1073741670;
goto LABEL_19;
}
memmove((UINT8 *)v22, (UINT8 *)(v21 + 20), *(unsigned int *)(v21 + 16));
v23 = *SecurityInformation;
Token = SubjectSecurityContext;
if( (v23 & 4) != 0 )
{
SeCheckForCriticalAceRemoval(Privileges, NewDescriptor, SubjectSecurityContext, (PBOOLEAN)&AceRemoved);
if( (_BYTE)AceRemoved )
{
v42 = CmpConstructName(Key);
if( v42 )
{
v25 = -1073741822;
CmpFreeTransientPoolWithTag(v42, 0x624E4D43ui64);
}
else
{
RtlInitUnicodeString(&DestinationString, L"", v43);
v25 = -1073741822;
}
goto LABEL_19;
}
}
P = Privileges;
LODWORD(v47) = PoolType;
LODWORD(BugCheckParameter4) = 0;
v25 = RtlpSetSecurityObject(
0i64,
*SecurityInformation,
NewDescriptor,
&P,
BugCheckParameter4,
v47,
GenericMapping,
Token);
if( v25 >= 0 )
{
v25 = CmpTraceSecurityChanging((INT64)Key, Privileges, *SecurityInformation, NewDescriptor, P);
if( v25 < 0 )
{
LABEL_19:
v30 = 0i64;
goto LABEL_20;
}
LODWORD(Size) = RtlLengthSecurityDescriptorStrict(P);
if( v16 )
v26 = 1;
else
v26 = (unsigned int)v53 >> 31;
v27 = UoW;
v28 = *(_LARGE_INTEGER *)&KUSER_SHARED_DATA.SystemTime.LowPart;
if( v16 )
{
if( !HvMarkCellDirty((UINT64)KeyHive, Flink, 0) )
{
LABEL_76:
v25 = -1073741443;
LABEL_17:
v13 = (_CELL_DATA *)CellAddress;
LABEL_18:
v11 = 0;
goto LABEL_19;
}
v27->TxSecurityCell = -1;
v27->LastWriteTime.QuadPart = 0i64;
v27->ActionType = UoWSetSecurityDescriptor;
}
else if( !HvMarkCellDirty((UINT64)KeyHive, (unsigned int)v53, 0) || !HvMarkCellDirty((UINT64)KeyHive, Flink, 0) )
{
goto LABEL_76;
}
if( CmpFindMatchingDescriptorCell((__int64)KeyHive, P, v26, &v51, &v59) )
{
v29 = v51;
if( (_DWORD)v51 == Flink )
{
if( v16 )
{
++*(_DWORD *)(v21 + 12);
v27->LastWriteTime.QuadPart = (LONGLONG)v59;
v27->TxSecurityCell = v29;
}
else
{
*(_LARGE_INTEGER *)(v56 + 4) = v28;
Key->KcbLastWriteTime = v28;
}
goto LABEL_17;
}
if( !HvMarkCellDirty((UINT64)KeyHive, (unsigned int)v51, 0) )
goto LABEL_76;
if( v16 )
{
v44 = v59;
v27->TxSecurityCell = *v59;
v27->LastWriteTime.QuadPart = (LONGLONG)v44;
}
else if( *(_DWORD *)(v21 + 12) == 1
&& (!HvMarkCellDirty((UINT64)KeyHive, *(unsigned int *)(v21 + 4), 0)
|| !HvMarkCellDirty((UINT64)KeyHive, *(unsigned int *)(v21 + 8), 0)) )
{
goto LABEL_76;
}
v13 = KeyHive->GetCellRoutine(KeyHive, v29, &CellAddressContext);
if( !v13 )
{
if( !v16 )
KeBugCheckEx(0x51u, 4ui64, 5ui64, (ULONG_PTR)KeyHive, (unsigned int)v51);
v25 = -1073741670;
goto LABEL_18;
}
if( !v16 )
{
v32 = *(_DWORD *)(v21 + 12);
if( v32 == 1 )
{
KeyHive->ReleaseCellRoutine(KeyHive, (_HV_GET_CELL_CONTEXT *)v55);
v21 = 0i64;
CmpRemoveSecurityCellList(KeyHive, Flink);
HvFreeCell((UINT64)KeyHive, Flink);
}
else
{
*(_DWORD *)(v21 + 12) = v32 - 1;
}
*(_DWORD *)(v56 + 44) = v51;
}
++v13->u.KeyValue.Type;
LODWORD(v33) = Flink;
}
else
{
v35 = RtlLengthSecurityDescriptorStrict(P);
v36 = HvAllocateCell(KeyHive, (unsigned int)(v35 + 20), (HSTORAGE_TYPE)v26, &CellAddress, &CellAddressContext);
v33 = v36;
if( v36 == -1 )
{
v25 = -1073741670;
goto LABEL_17;
}
if( CmTrans )
{
v13 = (_CELL_DATA *)CellAddress;
*((_DWORD *)CellAddress + 2) = v36;
v13->u.KeyNode.LastWriteTime.LowPart = v36;
}
else
{
if( !HvMarkCellDirty((UINT64)KeyHive, *(unsigned int *)(v21 + 4), 0)
|| *(_DWORD *)(v21 + 12) == 1 && !HvMarkCellDirty((UINT64)KeyHive, *(unsigned int *)(v21 + 8), 0) )
{
v13 = (_CELL_DATA *)CellAddress;
v25 = -1073741443;
v11 = v33;
goto LABEL_45;
}
v37 = (__int64)KeyHive->GetCellRoutine(KeyHive, *(_DWORD *)(v21 + 4), (_HV_GET_CELL_CONTEXT *)v60);
v13 = (_CELL_DATA *)CellAddress;
v48 = v37;
if( !v37 )
{
v25 = -1073741670;
v11 = v33;
v30 = 0i64;
LABEL_20:
if( P )
ExFreePoolWithTag(P, 0);
goto LABEL_22;
}
*((_DWORD *)CellAddress + 1) = *(_DWORD *)(v21 + 4);
v13->u.KeyNode.LastWriteTime.HighPart = Flink;
*(_DWORD *)(v21 + 4) = v33;
*(_DWORD *)(v37 + 8) = v33;
--*(_DWORD *)(v21 + 12);
}
v13->u.KeyNode.Signature = 27507;
v38 = Size;
v13->u.KeyValue.Type = 1;
v13->u.KeyNode.Parent = v38;
memmove(&v13->u.KeySecurity.Descriptor.Revision, (UINT8 *)P, v38);
if( CmpAddSecurityCellToCache((_CMHIVE *)KeyHive, (unsigned int)v33, 0, v39) < 0 )
{
v30 = v48;
if( !CmTrans )
{
++*(_DWORD *)(v21 + 12);
*(_DWORD *)(v21 + 4) = v13->u.KeyNode.LastWriteTime.LowPart;
*(_DWORD *)(v48 + 8) = v13->u.KeyNode.LastWriteTime.HighPart;
}
v25 = -1073741670;
v11 = v33;
goto LABEL_20;
}
if( !CmTrans )
{
v34 = v56;
*(_DWORD *)(v56 + 44) = v33;
if( !*(_DWORD *)(v21 + 12) )
{
KeyHive->ReleaseCellRoutine(KeyHive, (_HV_GET_CELL_CONTEXT *)v55);
v21 = 0i64;
CmpRemoveSecurityCellList(KeyHive, Flink);
HvFreeCell((UINT64)KeyHive, Flink);
}
LABEL_44:
*(_LARGE_INTEGER *)(v34 + 4) = v28;
++Key->SequenceNumber;
Key->KcbLastWriteTime = v28;
CmpAssignSecurityToKcb((UINT64)Key, *(unsigned int *)(v34 + 44), 0i64, 1, 0);
v11 = 0;
LABEL_45:
v30 = v48;
goto LABEL_20;
}
LODWORD(NewDescriptor) = 0;
if( !CmpFindSecurityCellCacheIndex((__int64)KeyHive, v33, &NewDescriptor) )
KeBugCheckEx(0x51u, 4ui64, 3ui64, (ULONG_PTR)Key, v33);
v40 = *(unsigned int **)&KeyHive[1].Storage[0].FreeDisplay[1].Display.Buffer[4 * (unsigned int)NewDescriptor + 2];
v27->LastWriteTime.QuadPart = (LONGLONG)v40;
v27->TxSecurityCell = *v40;
}
if( CmTrans )
{
v41 = CmAddLogForAction((__int64)v27, 1u);
v11 = 0;
v25 = v41;
if( v41 < 0 && v13->u.KeyValue.Type-- == 1 )
{
CmpRemoveSecurityCellList(KeyHive, (unsigned int)v33);
HvFreeCell((UINT64)KeyHive, (unsigned int)v33);
}
goto LABEL_45;
}
v34 = v56;
goto LABEL_44;
}
P = 0i64;
v30 = 0i64;
LABEL_22:
if( Privileges )
CmSiFreeMemory(Privileges);
if( v11 )
HvFreeCell((UINT64)KeyHive, v11);
if( v30 )
KeyHive->ReleaseCellRoutine(KeyHive, (_HV_GET_CELL_CONTEXT *)v60);
if( v13 )
KeyHive->ReleaseCellRoutine(KeyHive, &CellAddressContext);
if( v21 )
KeyHive->ReleaseCellRoutine(KeyHive, (_HV_GET_CELL_CONTEXT *)v55);
KeyHive->ReleaseCellRoutine(KeyHive, (_HV_GET_CELL_CONTEXT *)v61);
return(unsigned int)v25;
}Referenced by:
CmpSetKeySecurity