RtlAddAce
INT64 __fastcall RtlAddAce(_ACL *Acl, UINT64 AceRevision, UINT64 StartingAceIndex, VOID *AceList, UINT64 AceListLength){
unsigned int v6;
unsigned int v7;
char *v9;
unsigned __int8 AclRevision;
__int64 v11;
char *v12;
__int16 v13;
unsigned __int8 v14;
unsigned int v15;
_ACL *i;
int v17;
__int64 v18;
char *v19;
INT64 result;
__int64 v21;
bool v22;
PACE Ace;
Ace = 0i64;
v6 = StartingAceIndex;
v7 = AceRevision;
if( !RtlValidAcl(Acl) || !RtlFirstFreeAce(Acl, (VOID **)&Ace) )
return 3221225485i64;
v9 = (char *)AceList;
AclRevision = v7;
v11 = (unsigned int)AceListLength;
if( (unsigned __int8)v7 <= Acl->AclRevision )
AclRevision = Acl->AclRevision;
v12 = (char *)AceList + (unsigned int)AceListLength;
v13 = 0;
if( AceList < v12 )
{
do
{
v14 = *v9;
if( (unsigned __int8)*v9 > 3u )
{
if( v14 > 4u )
{
if( v14 > 8u )
goto LABEL_7;
v22 = v7 < 4;
}
else
{
v22 = v7 < 3;
}
if( v22 )
return 3221225485i64;
}
LABEL_7:
++v13;
v9 += *((unsigned __int16 *)v9 + 1);
}
while( v9 < v12 );
}
if( v9 > v12 )
return 3221225485i64;
if( !Ace || (char *)Ace + (unsigned int)AceListLength > (char *)Acl + Acl->AclSize )
return 3221225507i64;
v15 = 0;
for( i = Acl + 1; v15 < v6; i = (_ACL *)((char *)i + i->AclSize) )
{
if( v15 >= Acl->AceCount )
break;
++v15;
}
v17 = (_DWORD)Ace - (_DWORD)i - 1;
v18 = v17;
if( v17 >= 0 )
{
v21 = (unsigned int)(v17 + AceListLength);
do
{
*(&i->AclRevision + v21) = *(&i->AclRevision + v18);
v21 = (unsigned int)(v21 - 1);
--v18;
}
while( v18 >= 0 );
}
if( (_DWORD)AceListLength )
{
v19 = (char *)((_BYTE *)AceList - (_BYTE *)i);
do
{
i->AclRevision = *(&i->AclRevision + (_QWORD)v19);
i = (_ACL *)((char *)i + 1);
--v11;
}
while( v11 );
}
Acl->AceCount += v13;
result = 0i64;
Acl->AclRevision = AclRevision;
return result;
}Referenced by:
AdtpBuildAccessReasonAuditStringInternal
LocalGetAclForString
PiDevCfgGetKeySecurityDescriptor
SepAppendAceToTokenDefaultDacl
SepAppendAceToTokenObjectAcl