NtQueryInformationToken

NTSTATUS __stdcall NtQueryInformationToken(
        PVOID TokenHandle,
        _TOKEN_INFORMATION_CLASS TokenInformationClass,
        PVOID TokenInformation,
        UINT64 TokenInformationLength,
        UINT64 *ReturnLength){
  unsigned int v5; 
  VOID *v8; 
  __int64 v9; 
  CHAR v10; 
  UINT64 *v11; 
  __int64 v12; 
  NTSTATUS result; 
  _TOKEN *v14; 
  BOOL v15; 
  _ETHREAD *v16; 
  UINT64 v17; 
  PADAPTER_OBJECT v18; 
  unsigned int v19; 
  BOOL v20; 
  _ETHREAD *v21; 
  unsigned __int8 *Package; 
  char *v23; 
  BOOL v24; 
  _ETHREAD *v25; 
  PADAPTER_OBJECT v26; 
  int v27; 
  _DMA_OPERATIONS *v28; 
  BOOL v29; 
  _ETHREAD *v30; 
  unsigned int v31; 
  BOOL v32; 
  _ETHREAD *v33; 
  PADAPTER_OBJECT v34; 
  _DMA_OPERATIONS *DmaOperations; 
  unsigned int v36; 
  UINT8 *v37; 
  BOOL v38; 
  _ETHREAD *v39; 
  unsigned __int8 *Sid; 
  unsigned int v41; 
  unsigned int v42; 
  BOOL v43; 
  _ETHREAD *v44; 
  char v45; 
  PSID v46; 
  unsigned __int8 *TrustLevelSid; 
  char *v48; 
  BOOL v49; 
  _ETHREAD *v50; 
  UINT64 v51; 
  BOOL v52; 
  _ETHREAD *v53; 
  unsigned int v54; 
  int AllocateAdapterChannel; 
  BOOL v56; 
  _ETHREAD *v57; 
  PADAPTER_OBJECT v58; 
  _DMA_OPERATIONS *v59; 
  unsigned int v60; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *GetDmaDomain; 
  BOOL v62; 
  _ETHREAD *v63; 
  unsigned __int8 IsElevatedRid; 
  unsigned int v65; 
  BOOL v66; 
  _ETHREAD *v67; 
  unsigned int *p_Size; 
  unsigned int v69; 
  NTSTATUS v70; 
  BOOL v71; 
  _ETHREAD *v72; 
  unsigned int v73; 
  unsigned int v74; 
  BOOL v75; 
  _ETHREAD *v76; 
  _DMA_OPERATIONS *v77; 
  unsigned int Size; 
  UINT64 v79; 
  BOOL v80; 
  _ETHREAD *v81; 
  int v82; 
  unsigned int DmaOperations_high; 
  unsigned int v84; 
  unsigned int v85; 
  _DMA_OPERATIONS *v86; 
  __int64 v87; 
  unsigned int v88; 
  unsigned int v89; 
  unsigned int v90; 
  unsigned int v91; 
  SID_AND_ATTRIBUTES *v92; 
  SID_AND_ATTRIBUTES *v93; 
  _LUID_AND_ATTRIBUTES *v94; 
  BOOL v95; 
  _ETHREAD *v96; 
  unsigned int v97; 
  __int64 v98; 
  BOOL v99; 
  _ETHREAD *CurrentThread; 
  unsigned int UserAndGroupCount; 
  UINT64 v102; 
  __int64 v103; 
  __int64 v104; 
  BOOL v105; 
  _ETHREAD *v106; 
  UINT8 *v107; 
  CHAR v108; 
  unsigned int TokenAccessInformationBufferSize; 
  BOOL v110; 
  _ETHREAD *v111; 
  unsigned int CapabilityCount; 
  UINT64 v113; 
  _SID_AND_ATTRIBUTES *Capabilities; 
  __int64 v115; 
  int v116; 
  NTSTATUS v117; 
  _TOKEN_TYPE v118; 
  _SEP_LOGON_SESSION_REFERENCES *v119; 
  int inserted; 
  BOOL v121; 
  _ETHREAD *v122; 
  unsigned int v123; 
  unsigned int v124; 
  _DMA_OPERATIONS *v125; 
  __int64 v126; 
  unsigned int v127; 
  __int64 v128; 
  __int64 v129; 
  _SID_AND_ATTRIBUTES *RestrictedSids; 
  __int64 RestrictedSidCount; 
  struct _DMA_ADAPTER *v132; 
  BOOL v133; 
  _ETHREAD *v134; 
  int v135; 
  BOOL v136; 
  _ETHREAD *v137; 
  _DMA_OPERATIONS *v138; 
  void(__fastcall *PutDmaAdapter)(_DMA_ADAPTER *); 
  __int64 v140; 
  BOOL v141; 
  _ETHREAD *v142; 
  PADAPTER_OBJECT v143; 
  UNICODE_STRING *v144; 
  NTSTATUS SecurityAttributesToken; 
  PSID SidArea; 
  PSID SidAreaa; 
  VOID *SidAreab; 
  PSID *RemainingSidArea; 
  PSID *RemainingSidAreaa; 
  UINT64 *RemainingSidAreaSize; 
  PULONG RemainingSidAreaSizea; 
  UINT64 *pRestrictedSidsSALength; 
  UINT64 *pPackageSidLength; 
  UINT64 *pCapabilitySidsLength; 
  UINT64 *pCapabilitySidsSALength; 
  UINT64 *pTrustSidLength; 
  UINT64 *pSecurityAttributesLength; 
  char UseNewTrust[8]; 
  PADAPTER_OBJECT DmaAdapter; 
  PSID SourceSid; 
  PSID NextTargetSid; 
  UINT64 pReturnLength; 
  int v164; 
  int v165; 
  ULONG SessionId; 
  UINT64 v167; 
  UINT64 v168; 
  UINT64 v169; 
  UINT64 v170; 
  UINT64 v171; 
  void *Handle; 
  _SEP_LOGON_SESSION_REFERENCES *ReturnSession; 
  PVOID Object; 
  _AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION pInfo; 
  PSID_AND_ATTRIBUTES Dest; 
  struct _SID_AND_ATTRIBUTES Src; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int128 v179; 
  v5 = TokenInformationLength;
  v8 = TokenHandle;
  v9 = 0i64;
  DmaAdapter = 0i64;
  LODWORD(pReturnLength) = 0;
  v171 = 0i64;
  LODWORD(v170) = 0;
  Dest = 0i64;
  Src = 0i64;
  NextTargetSid = 0i64;
  SessionId = 0;
  v179 = 0i64;
  memset(&pInfo, 0, sizeof(pInfo));
  UseNewTrust[0] = 0;
  SourceSid = 0i64;
  v10 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v10 )
  {
    ProbeForWrite(TokenInformation, (unsigned int)TokenInformationLength, 4ui64);
    v11 = ReturnLength;
    v12 = (__int64)ReturnLength;
    if( (unsigned __int64)ReturnLength >= 0x7FFFFFFF0000i64 )
      v12 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v12 = *(_DWORD *)v12;
    v8 = TokenHandle;
  }
  else
  {
    v11 = ReturnLength;
  }
  if( TokenInformationClass != TokenUser )
  {
    if( TokenInformationClass == TokenType )
    {
      result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
      if( result < 0 )
        return result;
      *(_DWORD *)v11 = 4;
      if( v5 < 4 )
      {
LABEL_156:
        HalPutDmaAdapter(DmaAdapter);
        return -1073741789;
      }
      v18 = DmaAdapter;
      *(_DWORD *)TokenInformation = *(_DWORD *)&DmaAdapter[12].Version;
    }
    else
    {
      switch( TokenInformationClass )
      {
        case TokenGroups:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          CurrentThread = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)CurrentThread + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v99) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v99);
          UserAndGroupCount = v14->UserAndGroupCount;
          v102 = 16 * UserAndGroupCount - 8;
          if( UserAndGroupCount > 1 )
          {
            v103 = (__int64)&v14->UserAndGroups[1];
            v104 = UserAndGroupCount - 1;
            do
            {
              v102 = (unsigned int)v102 + 4 * *(unsigned __int8 *)(*(_QWORD *)v103 + 1i64) + 8;
              v103 += 16i64;
              --v104;
            }
            while( v104 );
          }
          *(_DWORD *)v11 = v102;
          if( v5 < (unsigned int)v102 )
            goto LABEL_41;
          *(_DWORD *)TokenInformation = v14->UserAndGroupCount - 1;
          RtlCopySidAndAttributesArray(
            v14->UserAndGroupCount - 1,
            v14->UserAndGroups + 1,
            v102,
            (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
            (char *)TokenInformation + 16 * v14->UserAndGroupCount - 32 + 24,
            &NextTargetSid,
            (UINT64 *)&NextTargetSid);
          goto LABEL_14;
        case TokenPrivileges:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v72 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v72 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v71) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v71);
          v73 = SepTokenPrivilegeCount((INT64)v14);
          if( v73 <= 1 )
            v74 = 16;
          else
            v74 = 12 * v73 + 4;
          *(_DWORD *)v11 = v74;
          if( v5 < v74 )
            goto LABEL_41;
          SepConvertTokenPrivileges(v14, (_TOKEN_PRIVILEGES *)TokenInformation);
          goto LABEL_14;
        case TokenOwner:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v53 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v53 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v52) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v52);
          v54 = 4 * *((unsigned __int8 *)v14->UserAndGroups[v14->DefaultOwnerIndex].Sid + 1) + 16;
          *(_DWORD *)v11 = v54;
          if( v5 < v54 )
            goto LABEL_41;
          *(_QWORD *)TokenInformation = (char *)TokenInformation + 8;
          RtlCopySid(v54 - 8, (char *)TokenInformation + 8, v14->UserAndGroups[v14->DefaultOwnerIndex].Sid);
          goto LABEL_14;
        case TokenPrimaryGroup:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v30 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v30 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v29) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v29);
          v31 = 4 * *((unsigned __int8 *)v14->PrimaryGroup + 1) + 16;
          *(_DWORD *)v11 = v31;
          if( v5 < v31 )
            goto LABEL_41;
          *(_QWORD *)TokenInformation = (char *)TokenInformation + 8;
          RtlCopySid(v31 - 8, (char *)TokenInformation + 8, v14->PrimaryGroup);
          goto LABEL_14;
        case TokenDefaultDacl:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          LODWORD(pReturnLength) = 8;
          v33 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v33 + 242);
          v34 = DmaAdapter;
          LOBYTE(v32) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v32);
          DmaOperations = v34[11].DmaOperations;
          if( DmaOperations )
            v36 = HIWORD(DmaOperations->Size) + 8;
          else
            v36 = pReturnLength;
          *(_DWORD *)v11 = v36;
          if( v5 < v36 )
            goto LABEL_101;
          v37 = (UINT8 *)TokenInformation + 8;
          if( v34[11].DmaOperations )
          {
            *(_QWORD *)TokenInformation = v37;
            memmove(v37, (UINT8 *)v34[11].DmaOperations, HIWORD(v34[11].DmaOperations->Size));
          }
          else
          {
            *(_QWORD *)TokenInformation = 0i64;
          }
          goto LABEL_54;
        case TokenSource:
          result = SepReferenceTokenByHandle(
                     v8,
                     0x10ui64,
                     v10,
                     (_TOKEN **)&DmaAdapter,
                     (UINT8 *)UseNewTrust,
                     &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 16;
          if( v5 < 0x10 )
            goto LABEL_156;
          v18 = DmaAdapter;
          *(struct _DMA_ADAPTER *)TokenInformation = *DmaAdapter;
          goto LABEL_16;
        case TokenImpersonationLevel:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v18 = DmaAdapter;
          if( *(_DWORD *)&DmaAdapter[12].Version != 2 )
          {
            HalPutDmaAdapter(DmaAdapter);
            return -1073741821;
          }
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_42;
          *(_DWORD *)TokenInformation = *(_DWORD *)(&v18[12].Size + 1);
          goto LABEL_16;
        case TokenStatistics:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 56;
          if( v5 < 0x38 )
            goto LABEL_156;
          v25 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v25 + 242);
          v26 = DmaAdapter;
          LOBYTE(v24) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v24);
          v165 = 0;
          *(struct _DMA_ADAPTER *)TokenInformation = v26[1];
          *((_QWORD *)TokenInformation + 2) = v26[2].DmaOperations;
          *((_DWORD *)TokenInformation + 6) = *(_DWORD *)&v26[12].Version;
          *((_DWORD *)TokenInformation + 7) = *(_DWORD *)(&v26[12].Size + 1);
          *((_DWORD *)TokenInformation + 8) = v26[8].DmaOperations;
          v27 = LODWORD(v26[8].DmaOperations) - 4 * BYTE1(v26[10].DmaOperations->Size) - 8;
          v165 = v27;
          v28 = v26[11].DmaOperations;
          if( v28 )
          {
            v27 -= HIWORD(v28->Size);
            v165 = v27;
          }
          *((_DWORD *)TokenInformation + 9) = v27;
          *((_DWORD *)TokenInformation + 10) = HIDWORD(v26[7].DmaOperations) - 1;
          *((_DWORD *)TokenInformation + 11) = SepTokenPrivilegeCount((INT64)v26);
          *((_QWORD *)TokenInformation + 6) = v26[3].DmaOperations;
          goto LABEL_39;
        case TokenRestrictedSids:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v50 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v50 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v49) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v49);
          v51 = 16 * v14->RestrictedSidCount + 8;
          if( v14->RestrictedSidCount )
          {
            RestrictedSids = v14->RestrictedSids;
            RestrictedSidCount = v14->RestrictedSidCount;
            do
            {
              v51 = (unsigned int)v51 + 4 * *((unsigned __int8 *)RestrictedSids->Sid + 1) + 8;
              ++RestrictedSids;
              --RestrictedSidCount;
            }
            while( RestrictedSidCount );
          }
          *(_DWORD *)v11 = v51;
          if( v5 < (unsigned int)v51 )
            goto LABEL_41;
          *(_DWORD *)TokenInformation = v14->RestrictedSidCount;
          RtlCopySidAndAttributesArray(
            v14->RestrictedSidCount,
            v14->RestrictedSids,
            v51,
            (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
            (char *)TokenInformation + 16 * v14->RestrictedSidCount + 8,
            &NextTargetSid,
            (UINT64 *)&NextTargetSid);
          goto LABEL_14;
        case TokenSessionId:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_156;
          v14 = (_TOKEN *)DmaAdapter;
          SeQuerySessionIdToken(DmaAdapter, (UINT64 *)&SessionId);
          *(_DWORD *)TokenInformation = SessionId;
          *(_DWORD *)v11 = 4;
          goto LABEL_15;
        case TokenGroupsAndPrivileges:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v81 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v81 + 242);
          v34 = DmaAdapter;
          LOBYTE(v80) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v80);
          HIDWORD(pReturnLength) = SepTokenPrivilegeCount((INT64)v34);
          v82 = 12 * HIDWORD(pReturnLength);
          DmaOperations_high = HIDWORD(v34[7].DmaOperations);
          v84 = DmaOperations_high;
          v85 = 16 * DmaOperations_high;
          if( DmaOperations_high )
          {
            v86 = v34[9].DmaOperations;
            v87 = DmaOperations_high;
            do
            {
              v85 += (4 * *(unsigned __int8 *)(*(_QWORD *)&v86->Size + 1i64) + 15) & 0xFFFFFFF8;
              v86 = (_DMA_OPERATIONS *)((char *)v86 + 16);
              --v87;
            }
            while( v87 );
          }
          v88 = 16 * *(_DWORD *)&v34[8].Version;
          v89 = v88;
          v90 = v88;
          if( *(_DWORD *)&v34[8].Version )
          {
            v128 = *(_QWORD *)&v34[10].Version;
            v129 = *(unsigned int *)&v34[8].Version;
            do
            {
              v89 += (4 * *(unsigned __int8 *)(*(_QWORD *)v128 + 1i64) + 15) & 0xFFFFFFF8;
              v90 = v89;
              v128 += 16i64;
              --v129;
            }
            while( v129 );
          }
          v91 = v90 + v82 + v85 + 56;
          *(_DWORD *)v11 = v91;
          if( v5 < v91 )
            goto LABEL_101;
          *((_QWORD *)TokenInformation + 6) = v34[1].DmaOperations;
          *((_DWORD *)TokenInformation + 1) = v85;
          *(_DWORD *)TokenInformation = HIDWORD(v34[7].DmaOperations);
          v92 = (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 56);
          *((_QWORD *)TokenInformation + 1) = (char *)TokenInformation + 56;
          *((_DWORD *)TokenInformation + 5) = v89;
          *((_DWORD *)TokenInformation + 4) = *(_DWORD *)&v34[8].Version;
          if( *(_DWORD *)&v34[8].Version )
          {
            v93 = (SID_AND_ATTRIBUTES *)((char *)v92 + ((v85 + 7i64) & 0xFFFFFFFFFFFFFFF8ui64));
            *((_QWORD *)TokenInformation + 3) = v93;
          }
          else
          {
            *((_QWORD *)TokenInformation + 3) = 0i64;
            v93 = Dest;
          }
          *((_DWORD *)TokenInformation + 9) = v82;
          *((_DWORD *)TokenInformation + 8) = HIDWORD(pReturnLength);
          v94 = (_LUID_AND_ATTRIBUTES *)((char *)v92 + v89 + v85);
          *((_QWORD *)TokenInformation + 5) = v94;
          RtlCopySidAndAttributesArray(
            HIDWORD(v34[7].DmaOperations),
            (SID_AND_ATTRIBUTES *)v34[9].DmaOperations,
            v85 - v84 * 16,
            v92,
            &v92[v84],
            &NextTargetSid,
            (UINT64 *)&NextTargetSid);
          if( v93 )
            RtlCopySidAndAttributesArray(
              *(unsigned int *)&v34[8].Version,
              *(SID_AND_ATTRIBUTES **)&v34[10].Version,
              v89 - v88,
              v93,
              &v93[v88 / 0x10],
              &NextTargetSid,
              (UINT64 *)&NextTargetSid);
          SepConvertTokenPrivilegesToLuidAndAttributes((_TOKEN *)v34, v94);
          goto LABEL_54;
        case TokenSandBoxInert:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            return -1073741789;
          v18 = DmaAdapter;
          *(_DWORD *)TokenInformation = ((__int64)DmaAdapter[12].DmaOperations & 0x40) != 0;
          goto LABEL_16;
        case TokenAuditPolicy:
          if( !SeSinglePrivilegeCheck(*(INT64 *)SeSecurityPrivilege, v10) )
            return -1073741727;
          result = SepReferenceTokenByHandle(
                     TokenHandle,
                     8ui64,
                     v10,
                     (_TOKEN **)&DmaAdapter,
                     (UINT8 *)UseNewTrust,
                     &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 30;
          if( v5 < 0x1E )
            goto LABEL_156;
          v134 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v134 + 242);
          v26 = DmaAdapter;
          LOBYTE(v133) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v133);
          *(struct _DMA_ADAPTER *)TokenInformation = *(PADAPTER_OBJECT)((char *)v26 + 88);
          *((_QWORD *)TokenInformation + 2) = v26[6].DmaOperations;
          *((_DWORD *)TokenInformation + 6) = *(_DWORD *)&v26[7].Version;
          *((_WORD *)TokenInformation + 14) = *(&v26[7].Size + 1);
LABEL_39:
          ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
          KeLeaveCriticalRegion();
LABEL_40:
          HalPutDmaAdapter(v26);
          return 0;
        case TokenOrigin:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 8;
          if( v5 < 8 )
            goto LABEL_156;
          v18 = DmaAdapter;
          *(_QWORD *)TokenInformation = *(_QWORD *)&DmaAdapter[14].Version;
          goto LABEL_16;
        case TokenElevationType:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_156;
          v26 = DmaAdapter;
          AllocateAdapterChannel = (int)DmaAdapter[13].DmaOperations->AllocateAdapterChannel;
          if( (AllocateAdapterChannel & 4) != 0 )
          {
            if( SeIsSModeAdminlessEnabled() )
              *(_DWORD *)TokenInformation = 1;
            else
              *(_DWORD *)TokenInformation = 3;
          }
          else
          {
            LOBYTE(v9) = (AllocateAdapterChannel & 2) != 0;
            *(_DWORD *)TokenInformation = v9 + 1;
          }
          goto LABEL_40;
        case TokenLinkedToken:
          ReturnSession = 0i64;
          Handle = 0i64;
          Object = 0i64;
          *(&ObjectAttributes.Length + 1) = 0;
          *(&ObjectAttributes.Attributes + 1) = 0;
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 8;
          if( v5 == 8 )
          {
            v116 = -(SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v10) != 0);
            if( SeIsSModeAdminlessEnabled() )
            {
              HIDWORD(pReturnLength) = 0;
              SepGetStackTraceHash((_DWORD *)&pReturnLength + 1);
              EtwTraceAdminlessAccessFailure(HIDWORD(pReturnLength), 1i64, 0i64, 1);
              HalPutDmaAdapter(DmaAdapter);
              return -1073741729;
            }
            else
            {
              v34 = DmaAdapter;
              v117 = SepReferenceLogonSessionSilo(
                       (_LUID *)&DmaAdapter[13].DmaOperations->AllocateCommonBuffer,
                       (_EJOB *)DmaAdapter[13].DmaOperations->AllocateAdapterChannelEx,
                       &ReturnSession);
              if( v117 < 0 )
                goto LABEL_174;
              ObjectAttributes.Length = 48;
              ObjectAttributes.RootDirectory = 0i64;
              ObjectAttributes.Attributes = v10 ? 0 : 512;
              ObjectAttributes.ObjectName = 0i64;
              *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
              v118 = v116 + 2;
              v119 = ReturnSession;
              v117 = SepDuplicateToken(
                       (_TOKEN *)ReturnSession->Token,
                       &ObjectAttributes,
                       0,
                       v118,
                       SecurityIdentification,
                       0,
                       0,
                       (_TOKEN **)&Object);
              SepDeReferenceLogonSessionDirect(v119);
              if( v117 < 0 )
              {
LABEL_174:
                HalPutDmaAdapter(v34);
                return v117;
              }
              inserted = ObInsertObject(Object, 0i64, 0xF01FFui64, 0i64, 0i64, &Handle);
              if( inserted >= 0 )
              {
                *(_QWORD *)TokenInformation = Handle;
                goto LABEL_55;
              }
              v132 = v34;
LABEL_205:
              HalPutDmaAdapter(v132);
              return inserted;
            }
          }
          else
          {
            HalPutDmaAdapter(DmaAdapter);
            return -1073741820;
          }
        case TokenElevation:
          *(_DWORD *)v11 = 4;
          if( v5 != 4 )
            return -1073741820;
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v63 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v63 + 242);
          v26 = DmaAdapter;
          LOBYTE(v62) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v62);
          IsElevatedRid = (*(_QWORD *)&v26[4].Version & 0x1120160684i64) != 0;
          v65 = HIDWORD(v26[7].DmaOperations);
          if( v65 )
          {
            do
            {
              if( IsElevatedRid )
                break;
              IsElevatedRid = RtlIsElevatedRid((INT64)v26[9].DmaOperations + 16 * (unsigned int)v9);
              LODWORD(v9) = v9 + 1;
            }
            while( (unsigned int)v9 < v65 );
          }
          ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
          KeLeaveCriticalRegion();
          *(_DWORD *)TokenInformation = IsElevatedRid;
          goto LABEL_40;
        case TokenHasRestrictions:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 1;
          if( !v5 )
            goto LABEL_156;
          v18 = DmaAdapter;
          *(_BYTE *)TokenInformation = ((__int64)DmaAdapter[12].DmaOperations & 0x810) != 0;
          goto LABEL_16;
        case TokenAccessInformation:
          HIDWORD(v170) = 0;
          v169 = 0i64;
          v168 = 0i64;
          v167 = 0i64;
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v106 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v106 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v105) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v105);
          v107 = (UINT8 *)SourceSid;
          v108 = UseNewTrust[0];
          TokenAccessInformationBufferSize = SepGetTokenAccessInformationBufferSize(
                                               v14,
                                               UseNewTrust[0],
                                               SourceSid,
                                               (UINT64 *)((char *)&v171 + 4),
                                               &v171,
                                               (UINT64 *)((char *)&v170 + 4),
                                               &v170,
                                               (UINT64 *)((char *)&v169 + 4),
                                               &v169,
                                               (UINT64 *)((char *)&v168 + 4),
                                               &v168,
                                               (UINT64 *)((char *)&v167 + 4),
                                               &v167);
          *(_DWORD *)v11 = TokenAccessInformationBufferSize;
          if( v5 < TokenAccessInformationBufferSize )
            goto LABEL_41;
          LODWORD(pTrustSidLength) = HIDWORD(v167);
          LODWORD(pSecurityAttributesLength) = v167;
          LODWORD(pCapabilitySidsLength) = HIDWORD(v168);
          LODWORD(pCapabilitySidsSALength) = v168;
          LODWORD(pRestrictedSidsSALength) = HIDWORD(v169);
          LODWORD(pPackageSidLength) = v169;
          LODWORD(RemainingSidAreaa) = HIDWORD(v170);
          LODWORD(RemainingSidAreaSizea) = v170;
          LODWORD(SidAreaa) = v171;
          SepCopyTokenAccessInformation(
            (INT64)v14,
            (INT64)TokenInformation,
            v5,
            HIDWORD(v171),
            (UINT64)SidAreaa,
            (UINT64)RemainingSidAreaa,
            (UINT64)RemainingSidAreaSizea,
            (UINT64)pRestrictedSidsSALength,
            (INT64)pPackageSidLength,
            (UINT64)pCapabilitySidsLength,
            (UINT64)pCapabilitySidsSALength,
            (INT64)pTrustSidLength,
            (UINT64)pSecurityAttributesLength,
            v108,
            v107);
          goto LABEL_14;
        case TokenVirtualizationAllowed:
        case TokenVirtualizationEnabled:
        case TokenUIAccess:
        case TokenIsRestricted:
        case TokenIsRestricted|TokenGroups:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_156;
          v18 = DmaAdapter;
          switch( TokenInformationClass )
          {
            case TokenVirtualizationAllowed:
              LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 9) & 1;
              goto LABEL_129;
            case TokenVirtualizationEnabled:
              LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 10) & 1;
              goto LABEL_129;
            case TokenUIAccess:
              LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 12) & 1;
              goto LABEL_129;
          }
          if( TokenInformationClass != TokenIsRestricted )
          {
            if( ((__int64)DmaAdapter[12].DmaOperations & 0x10000) == 0 )
              goto LABEL_129;
            goto LABEL_230;
          }
          v135 = (int)DmaAdapter[12].DmaOperations;
          if( (v135 & 0x10) != 0 || (v135 & 8) != 0 )
LABEL_230:
            LODWORD(v9) = 1;
LABEL_129:
          *(_DWORD *)TokenInformation = v9;
          break;
        case TokenIntegrityLevel:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v39 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v39 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v38) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v38);
          SepCopyTokenIntegrity((INT64)v14);
          Sid = (unsigned __int8 *)Src.Sid;
          v41 = 4 * *((unsigned __int8 *)Src.Sid + 1) + 24;
          *(_DWORD *)v11 = v41;
          if( v5 < v41 )
            goto LABEL_41;
          RtlCopySidAndAttributesArray(
            1ui64,
            &Src,
            4 * (unsigned int)Sid[1] + 8,
            (SID_AND_ATTRIBUTES *)TokenInformation,
            (char *)TokenInformation + 16,
            &NextTargetSid,
            (UINT64 *)&NextTargetSid);
          goto LABEL_14;
        case TokenMandatoryPolicy:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_156;
          inserted = SeQueryMandatoryPolicyToken(DmaAdapter, (_TOKEN_MANDATORY_POLICY *)TokenInformation);
          v164 = inserted;
          goto LABEL_205;
        case TokenLogonSid:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v122 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v122 + 242);
          v34 = DmaAdapter;
          LOBYTE(v121) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v121);
          v123 = 0;
          v124 = HIDWORD(v34[7].DmaOperations);
          if( !v124 )
            goto LABEL_188;
          v125 = v34[9].DmaOperations;
          while( (*(_DWORD *)(&v125->PutDmaAdapter + 2 * v123) & 0xC0000000) != -1073741824 )
          {
            if( ++v123 >= v124 )
              goto LABEL_188;
          }
          v9 = *((_QWORD *)&v125->Size + 2 * v123);
LABEL_188:
          if( v9 )
          {
            v126 = 16i64 * v123;
            v127 = 4 * *(unsigned __int8 *)(*(_QWORD *)((char *)&v34[9].DmaOperations->Size + v126) + 1i64) + 32;
            *(_DWORD *)v11 = v127;
            if( v5 < v127 )
            {
LABEL_101:
              ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
              KeLeaveCriticalRegion();
              HalPutDmaAdapter(v34);
              return -1073741789;
            }
            else
            {
              *(_DWORD *)TokenInformation = 1;
              RtlCopySidAndAttributesArray(
                1ui64,
                (SID_AND_ATTRIBUTES *)((char *)v34[9].DmaOperations + v126),
                4 * (unsigned int)*(unsigned __int8 *)(*(_QWORD *)((char *)&v34[9].DmaOperations->Size + v126) + 1i64)
              + 8,
                (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
                (char *)TokenInformation + 24,
                &NextTargetSid,
                (UINT64 *)&NextTargetSid);
LABEL_54:
              ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
              KeLeaveCriticalRegion();
LABEL_55:
              HalPutDmaAdapter(v34);
              return 0;
            }
          }
          else
          {
            ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
            KeLeaveCriticalRegion();
            HalPutDmaAdapter(v34);
            return -1073741275;
          }
        case TokenIsAppContainer:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          v18 = DmaAdapter;
          if( v5 < 4 )
            goto LABEL_42;
          LOBYTE(v9) = ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0;
          *(_DWORD *)TokenInformation = v9;
          goto LABEL_16;
        case TokenCapabilities:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v111 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v111 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v110) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v110);
          CapabilityCount = v14->CapabilityCount;
          v113 = 16 * CapabilityCount + 8;
          if( CapabilityCount )
          {
            Capabilities = v14->Capabilities;
            v115 = CapabilityCount;
            do
            {
              v113 = (unsigned int)v113 + 4 * *((unsigned __int8 *)Capabilities->Sid + 1) + 8;
              ++Capabilities;
              --v115;
            }
            while( v115 );
          }
          *(_DWORD *)v11 = v113;
          if( v5 < (unsigned int)v113 )
            goto LABEL_41;
          *(_DWORD *)TokenInformation = v14->CapabilityCount;
          RtlCopySidAndAttributesArray(
            v14->CapabilityCount,
            v14->Capabilities,
            v113,
            (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
            (char *)TokenInformation + 16 * v14->CapabilityCount + 8,
            &NextTargetSid,
            (UINT64 *)&NextTargetSid);
          goto LABEL_14;
        case TokenAppContainerSid:
          v19 = 8;
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v21 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v21 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v20) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v20);
          Package = (unsigned __int8 *)v14->Package;
          if( Package )
            v19 = 4 * Package[1] + 16;
          *(_DWORD *)v11 = v19;
          if( v5 < v19 )
            goto LABEL_41;
          v23 = (char *)TokenInformation + 8;
          if( !Package )
            v23 = 0i64;
          *(_QWORD *)TokenInformation = v23;
          if( v23 )
            RtlCopySid(v19 - 8, v23, v14->Package);
          goto LABEL_14;
        case TokenAppContainerNumber:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            goto LABEL_156;
          v137 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v137 + 242);
          v26 = DmaAdapter;
          LOBYTE(v136) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v136);
          v138 = v26[67].DmaOperations;
          if( v138 )
            LODWORD(v9) = v138->FlushAdapterBuffers;
          ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
          KeLeaveCriticalRegion();
          *(_DWORD *)TokenInformation = v9;
          goto LABEL_40;
        case TokenUserClaimAttributes:
        case TokenDeviceClaimAttributes:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v57 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v57 + 242);
          v58 = DmaAdapter;
          LOBYTE(v56) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v56);
          v59 = v58[68].DmaOperations;
          if( v59
            && (v59[1].GetDmaDomain || TokenInformationClass != TokenUserClaimAttributes)
            && ((GetDmaDomain = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)v59[1].AllocateCommonBufferWithBounds) != 0i64
             || TokenInformationClass != TokenDeviceClaimAttributes) )
          {
            if( TokenInformationClass == TokenUserClaimAttributes )
              GetDmaDomain = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)v59[1].GetDmaDomain;
            AuthzBasepQueryClaimAttributesToken(GetDmaDomain, 0i64, 0i64, &pReturnLength);
            v60 = pReturnLength;
          }
          else
          {
            v60 = 16;
            pInfo.SecurityAttributesList.Blink = &pInfo.SecurityAttributesList;
            pInfo.SecurityAttributesList.Flink = &pInfo.SecurityAttributesList;
            pInfo.WorkingSecurityAttributeCount = 0;
            pInfo.WorkingSecurityAttributesList.Blink = &pInfo.WorkingSecurityAttributesList;
            pInfo.WorkingSecurityAttributesList.Flink = &pInfo.WorkingSecurityAttributesList;
            GetDmaDomain = &pInfo;
          }
          *(_DWORD *)v11 = v60;
          if( v5 < v60 )
            goto LABEL_94;
          v70 = AuthzBasepQueryClaimAttributesToken(GetDmaDomain, TokenInformation, v5, &pReturnLength);
          v164 = v70;
          goto LABEL_108;
        case TokenDeviceGroups:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v76 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v76 + 242);
          v34 = DmaAdapter;
          LOBYTE(v75) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v75);
          v77 = v34[68].DmaOperations;
          if( v77 && (Size = v77->Size) != 0 )
          {
            v79 = 16 * Size + 8;
          }
          else
          {
            Size = 0;
            v79 = 24i64;
          }
          if( Size )
          {
            PutDmaAdapter = v77->PutDmaAdapter;
            v140 = Size;
            do
            {
              v79 = (unsigned int)v79 + 4 * *(unsigned __int8 *)(*(_QWORD *)PutDmaAdapter + 1i64) + 8;
              PutDmaAdapter = (void(__fastcall *)(_DMA_ADAPTER *))((char *)PutDmaAdapter + 16);
              --v140;
            }
            while( v140 );
          }
          *(_DWORD *)v11 = v79;
          if( v5 < (unsigned int)v79 )
            goto LABEL_101;
          *(_OWORD *)TokenInformation = 0i64;
          *((_QWORD *)TokenInformation + 2) = 0i64;
          *(_DWORD *)TokenInformation = Size;
          if( Size )
            RtlCopySidAndAttributesArray(
              Size,
              (SID_AND_ATTRIBUTES *)v34[68].DmaOperations->PutDmaAdapter,
              v79,
              (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
              (char *)TokenInformation + 16 * Size + 8,
              &NextTargetSid,
              (UINT64 *)&NextTargetSid);
          goto LABEL_54;
        case TokenSecurityAttributes:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v67 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v67 + 242);
          v58 = DmaAdapter;
          LOBYTE(v66) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v66);
          p_Size = &v58[48].DmaOperations->Size;
          if( p_Size )
          {
            LODWORD(SidArea) = 0;
            AuthzBasepQuerySecurityAttributesToken(p_Size, 0i64, 0, 0i64, (size_t)SidArea, &pReturnLength);
            v69 = pReturnLength;
          }
          else
          {
            v69 = 16;
          }
          *(_DWORD *)v11 = v69;
          if( v5 < v69 )
            goto LABEL_94;
          LODWORD(SidArea) = v5;
          v70 = AuthzBasepQuerySecurityAttributesToken(
                  &v58[48].DmaOperations->Size,
                  0i64,
                  0,
                  TokenInformation,
                  (size_t)SidArea,
                  &pReturnLength);
          v164 = v70;
LABEL_108:
          ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
          KeLeaveCriticalRegion();
          HalPutDmaAdapter(v58);
          return v70;
        case MaxTokenInfoClass:
          v42 = 8;
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v44 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v44 + 242);
          v14 = (_TOKEN *)DmaAdapter;
          LOBYTE(v43) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v43);
          v45 = UseNewTrust[0];
          v46 = SourceSid;
          if( UseNewTrust[0] )
            TrustLevelSid = (unsigned __int8 *)SourceSid;
          else
            TrustLevelSid = (unsigned __int8 *)v14->TrustLevelSid;
          if( TrustLevelSid )
            v42 = 4 * TrustLevelSid[1] + 16;
          *(_DWORD *)v11 = v42;
          if( v5 < v42 )
            goto LABEL_41;
          v48 = (char *)TokenInformation + 8;
          if( !TrustLevelSid )
            v48 = 0i64;
          *(_QWORD *)TokenInformation = v48;
          if( v48 )
          {
            if( !v45 )
              v46 = v14->TrustLevelSid;
            RtlCopySid(v42 - 8, v48, v46);
          }
          goto LABEL_14;
        case MaxTokenInfoClass|TokenGroups:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result >= 0 )
          {
            v142 = (_ETHREAD *)KeGetCurrentThread();
            --*((_WORD *)v142 + 242);
            v143 = DmaAdapter;
            LOBYTE(v141) = 1;
            ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v141);
            LODWORD(RemainingSidAreaSize) = v5;
            LOBYTE(SidAreab) = 1;
            SecurityAttributesToken = SepInternalQuerySecurityAttributesTokenEx(
                                        v143,
                                        v144,
                                        0i64,
                                        0,
                                        SidAreab,
                                        (UINT64)TokenInformation,
                                        RemainingSidAreaSize);
            v164 = SecurityAttributesToken;
            ExReleaseResourceLite(*(PERESOURCE *)&v143[3].Version);
            KeLeaveCriticalRegion();
            HalPutDmaAdapter(v143);
            return SecurityAttributesToken;
          }
          return result;
        case TokenIsRestricted|TokenOwner:
          result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
          if( result < 0 )
            return result;
          v96 = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)v96 + 242);
          v58 = DmaAdapter;
          LOBYTE(v95) = 1;
          ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v95);
          v97 = 16;
          v98 = *(_QWORD *)&v58[72].Version;
          if( v98 )
            v97 = *(unsigned __int16 *)(v98 + 42) + 16;
          *(_DWORD *)v11 = v97;
          if( v5 < v97 )
          {
LABEL_94:
            ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
            KeLeaveCriticalRegion();
            HalPutDmaAdapter(v58);
            return -1073741789;
          }
          else
          {
            if( *(_QWORD *)&v58[72].Version )
            {
              *((_BYTE *)TokenInformation + 8) = 1;
              *(_QWORD *)TokenInformation = (char *)TokenInformation + 16;
              memmove(
                (UINT8 *)TokenInformation + 16,
                *(UINT8 **)(*(_QWORD *)&v58[72].Version + 48i64),
                *(unsigned __int16 *)(*(_QWORD *)&v58[72].Version + 42i64));
            }
            else
            {
              *((_BYTE *)TokenInformation + 8) = 0;
              *(_QWORD *)TokenInformation = 0i64;
            }
            ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
            KeLeaveCriticalRegion();
            HalPutDmaAdapter(v58);
            return 0;
          }
        case MaxTokenInfoClass|TokenDefaultDacl:
          *(_DWORD *)v11 = 4;
          if( v5 < 4 )
            return -1073741789;
          *(_DWORD *)TokenInformation = RtlIsSandboxedTokenHandle(v8, v10);
          return 0;
        case TokenAppContainerNumber|TokenAuditPolicy:
          LODWORD(RemainingSidArea) = 0;
          wil_details_FeatureReporting_ReportUsageToService(
            &Feature_PPLEnforcement__private_reporting,
            0x126C519ui64,
            0i64,
            0i64,
            (FEATURE_LOGGED_TRAITS *)&Feature_PPLEnforcement_logged_traits,
            (INT64)RemainingSidArea);
          return -1073741821;
        default:
          return -1073741821;
      }
    }
    goto LABEL_16;
  }
  result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
  if( result < 0 )
    return result;
  v16 = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)v16 + 242);
  v14 = (_TOKEN *)DmaAdapter;
  LOBYTE(v15) = 1;
  ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v15);
  v17 = 4 * (unsigned int)*((unsigned __int8 *)v14->UserAndGroups->Sid + 1) + 24;
  *(_DWORD *)v11 = v17;
  if( v5 >= (unsigned int)v17 )
  {
    RtlCopySidAndAttributesArray(
      1ui64,
      v14->UserAndGroups,
      v17,
      (SID_AND_ATTRIBUTES *)TokenInformation,
      (char *)TokenInformation + 16,
      &NextTargetSid,
      (UINT64 *)&NextTargetSid);
LABEL_14:
    ExReleaseResourceLite(v14->TokenLock);
    KeLeaveCriticalRegion();
LABEL_15:
    v18 = (PADAPTER_OBJECT)v14;
LABEL_16:
    HalPutDmaAdapter(v18);
    return 0;
  }
LABEL_41:
  ExReleaseResourceLite(v14->TokenLock);
  KeLeaveCriticalRegion();
  v18 = (PADAPTER_OBJECT)v14;
LABEL_42:
  HalPutDmaAdapter(v18);
  return -1073741789;
}

Referenced by:

RtlGetAppContainerNamedObjectPath
RtlpGetTokenNamedObjectPath