NtQueryInformationToken
NTSTATUS __stdcall NtQueryInformationToken(
PVOID TokenHandle,
_TOKEN_INFORMATION_CLASS TokenInformationClass,
PVOID TokenInformation,
UINT64 TokenInformationLength,
UINT64 *ReturnLength){
unsigned int v5;
VOID *v8;
__int64 v9;
CHAR v10;
UINT64 *v11;
__int64 v12;
NTSTATUS result;
_TOKEN *v14;
BOOL v15;
_ETHREAD *v16;
UINT64 v17;
PADAPTER_OBJECT v18;
unsigned int v19;
BOOL v20;
_ETHREAD *v21;
unsigned __int8 *Package;
char *v23;
BOOL v24;
_ETHREAD *v25;
PADAPTER_OBJECT v26;
int v27;
_DMA_OPERATIONS *v28;
BOOL v29;
_ETHREAD *v30;
unsigned int v31;
BOOL v32;
_ETHREAD *v33;
PADAPTER_OBJECT v34;
_DMA_OPERATIONS *DmaOperations;
unsigned int v36;
UINT8 *v37;
BOOL v38;
_ETHREAD *v39;
unsigned __int8 *Sid;
unsigned int v41;
unsigned int v42;
BOOL v43;
_ETHREAD *v44;
char v45;
PSID v46;
unsigned __int8 *TrustLevelSid;
char *v48;
BOOL v49;
_ETHREAD *v50;
UINT64 v51;
BOOL v52;
_ETHREAD *v53;
unsigned int v54;
int AllocateAdapterChannel;
BOOL v56;
_ETHREAD *v57;
PADAPTER_OBJECT v58;
_DMA_OPERATIONS *v59;
unsigned int v60;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *GetDmaDomain;
BOOL v62;
_ETHREAD *v63;
unsigned __int8 IsElevatedRid;
unsigned int v65;
BOOL v66;
_ETHREAD *v67;
unsigned int *p_Size;
unsigned int v69;
NTSTATUS v70;
BOOL v71;
_ETHREAD *v72;
unsigned int v73;
unsigned int v74;
BOOL v75;
_ETHREAD *v76;
_DMA_OPERATIONS *v77;
unsigned int Size;
UINT64 v79;
BOOL v80;
_ETHREAD *v81;
int v82;
unsigned int DmaOperations_high;
unsigned int v84;
unsigned int v85;
_DMA_OPERATIONS *v86;
__int64 v87;
unsigned int v88;
unsigned int v89;
unsigned int v90;
unsigned int v91;
SID_AND_ATTRIBUTES *v92;
SID_AND_ATTRIBUTES *v93;
_LUID_AND_ATTRIBUTES *v94;
BOOL v95;
_ETHREAD *v96;
unsigned int v97;
__int64 v98;
BOOL v99;
_ETHREAD *CurrentThread;
unsigned int UserAndGroupCount;
UINT64 v102;
__int64 v103;
__int64 v104;
BOOL v105;
_ETHREAD *v106;
UINT8 *v107;
CHAR v108;
unsigned int TokenAccessInformationBufferSize;
BOOL v110;
_ETHREAD *v111;
unsigned int CapabilityCount;
UINT64 v113;
_SID_AND_ATTRIBUTES *Capabilities;
__int64 v115;
int v116;
NTSTATUS v117;
_TOKEN_TYPE v118;
_SEP_LOGON_SESSION_REFERENCES *v119;
int inserted;
BOOL v121;
_ETHREAD *v122;
unsigned int v123;
unsigned int v124;
_DMA_OPERATIONS *v125;
__int64 v126;
unsigned int v127;
__int64 v128;
__int64 v129;
_SID_AND_ATTRIBUTES *RestrictedSids;
__int64 RestrictedSidCount;
struct _DMA_ADAPTER *v132;
BOOL v133;
_ETHREAD *v134;
int v135;
BOOL v136;
_ETHREAD *v137;
_DMA_OPERATIONS *v138;
void(__fastcall *PutDmaAdapter)(_DMA_ADAPTER *);
__int64 v140;
BOOL v141;
_ETHREAD *v142;
PADAPTER_OBJECT v143;
UNICODE_STRING *v144;
NTSTATUS SecurityAttributesToken;
PSID SidArea;
PSID SidAreaa;
VOID *SidAreab;
PSID *RemainingSidArea;
PSID *RemainingSidAreaa;
UINT64 *RemainingSidAreaSize;
PULONG RemainingSidAreaSizea;
UINT64 *pRestrictedSidsSALength;
UINT64 *pPackageSidLength;
UINT64 *pCapabilitySidsLength;
UINT64 *pCapabilitySidsSALength;
UINT64 *pTrustSidLength;
UINT64 *pSecurityAttributesLength;
char UseNewTrust[8];
PADAPTER_OBJECT DmaAdapter;
PSID SourceSid;
PSID NextTargetSid;
UINT64 pReturnLength;
int v164;
int v165;
ULONG SessionId;
UINT64 v167;
UINT64 v168;
UINT64 v169;
UINT64 v170;
UINT64 v171;
void *Handle;
_SEP_LOGON_SESSION_REFERENCES *ReturnSession;
PVOID Object;
_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION pInfo;
PSID_AND_ATTRIBUTES Dest;
struct _SID_AND_ATTRIBUTES Src;
_OBJECT_ATTRIBUTES ObjectAttributes;
__int128 v179;
v5 = TokenInformationLength;
v8 = TokenHandle;
v9 = 0i64;
DmaAdapter = 0i64;
LODWORD(pReturnLength) = 0;
v171 = 0i64;
LODWORD(v170) = 0;
Dest = 0i64;
Src = 0i64;
NextTargetSid = 0i64;
SessionId = 0;
v179 = 0i64;
memset(&pInfo, 0, sizeof(pInfo));
UseNewTrust[0] = 0;
SourceSid = 0i64;
v10 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v10 )
{
ProbeForWrite(TokenInformation, (unsigned int)TokenInformationLength, 4ui64);
v11 = ReturnLength;
v12 = (__int64)ReturnLength;
if( (unsigned __int64)ReturnLength >= 0x7FFFFFFF0000i64 )
v12 = 0x7FFFFFFF0000i64;
*(_DWORD *)v12 = *(_DWORD *)v12;
v8 = TokenHandle;
}
else
{
v11 = ReturnLength;
}
if( TokenInformationClass != TokenUser )
{
if( TokenInformationClass == TokenType )
{
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
{
LABEL_156:
HalPutDmaAdapter(DmaAdapter);
return -1073741789;
}
v18 = DmaAdapter;
*(_DWORD *)TokenInformation = *(_DWORD *)&DmaAdapter[12].Version;
}
else
{
switch( TokenInformationClass )
{
case TokenGroups:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v99) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v99);
UserAndGroupCount = v14->UserAndGroupCount;
v102 = 16 * UserAndGroupCount - 8;
if( UserAndGroupCount > 1 )
{
v103 = (__int64)&v14->UserAndGroups[1];
v104 = UserAndGroupCount - 1;
do
{
v102 = (unsigned int)v102 + 4 * *(unsigned __int8 *)(*(_QWORD *)v103 + 1i64) + 8;
v103 += 16i64;
--v104;
}
while( v104 );
}
*(_DWORD *)v11 = v102;
if( v5 < (unsigned int)v102 )
goto LABEL_41;
*(_DWORD *)TokenInformation = v14->UserAndGroupCount - 1;
RtlCopySidAndAttributesArray(
v14->UserAndGroupCount - 1,
v14->UserAndGroups + 1,
v102,
(SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
(char *)TokenInformation + 16 * v14->UserAndGroupCount - 32 + 24,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
goto LABEL_14;
case TokenPrivileges:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v72 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v72 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v71) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v71);
v73 = SepTokenPrivilegeCount((INT64)v14);
if( v73 <= 1 )
v74 = 16;
else
v74 = 12 * v73 + 4;
*(_DWORD *)v11 = v74;
if( v5 < v74 )
goto LABEL_41;
SepConvertTokenPrivileges(v14, (_TOKEN_PRIVILEGES *)TokenInformation);
goto LABEL_14;
case TokenOwner:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v53 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v53 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v52) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v52);
v54 = 4 * *((unsigned __int8 *)v14->UserAndGroups[v14->DefaultOwnerIndex].Sid + 1) + 16;
*(_DWORD *)v11 = v54;
if( v5 < v54 )
goto LABEL_41;
*(_QWORD *)TokenInformation = (char *)TokenInformation + 8;
RtlCopySid(v54 - 8, (char *)TokenInformation + 8, v14->UserAndGroups[v14->DefaultOwnerIndex].Sid);
goto LABEL_14;
case TokenPrimaryGroup:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v30 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v30 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v29) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v29);
v31 = 4 * *((unsigned __int8 *)v14->PrimaryGroup + 1) + 16;
*(_DWORD *)v11 = v31;
if( v5 < v31 )
goto LABEL_41;
*(_QWORD *)TokenInformation = (char *)TokenInformation + 8;
RtlCopySid(v31 - 8, (char *)TokenInformation + 8, v14->PrimaryGroup);
goto LABEL_14;
case TokenDefaultDacl:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
LODWORD(pReturnLength) = 8;
v33 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v33 + 242);
v34 = DmaAdapter;
LOBYTE(v32) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v32);
DmaOperations = v34[11].DmaOperations;
if( DmaOperations )
v36 = HIWORD(DmaOperations->Size) + 8;
else
v36 = pReturnLength;
*(_DWORD *)v11 = v36;
if( v5 < v36 )
goto LABEL_101;
v37 = (UINT8 *)TokenInformation + 8;
if( v34[11].DmaOperations )
{
*(_QWORD *)TokenInformation = v37;
memmove(v37, (UINT8 *)v34[11].DmaOperations, HIWORD(v34[11].DmaOperations->Size));
}
else
{
*(_QWORD *)TokenInformation = 0i64;
}
goto LABEL_54;
case TokenSource:
result = SepReferenceTokenByHandle(
v8,
0x10ui64,
v10,
(_TOKEN **)&DmaAdapter,
(UINT8 *)UseNewTrust,
&SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 16;
if( v5 < 0x10 )
goto LABEL_156;
v18 = DmaAdapter;
*(struct _DMA_ADAPTER *)TokenInformation = *DmaAdapter;
goto LABEL_16;
case TokenImpersonationLevel:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v18 = DmaAdapter;
if( *(_DWORD *)&DmaAdapter[12].Version != 2 )
{
HalPutDmaAdapter(DmaAdapter);
return -1073741821;
}
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_42;
*(_DWORD *)TokenInformation = *(_DWORD *)(&v18[12].Size + 1);
goto LABEL_16;
case TokenStatistics:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 56;
if( v5 < 0x38 )
goto LABEL_156;
v25 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v25 + 242);
v26 = DmaAdapter;
LOBYTE(v24) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v24);
v165 = 0;
*(struct _DMA_ADAPTER *)TokenInformation = v26[1];
*((_QWORD *)TokenInformation + 2) = v26[2].DmaOperations;
*((_DWORD *)TokenInformation + 6) = *(_DWORD *)&v26[12].Version;
*((_DWORD *)TokenInformation + 7) = *(_DWORD *)(&v26[12].Size + 1);
*((_DWORD *)TokenInformation + 8) = v26[8].DmaOperations;
v27 = LODWORD(v26[8].DmaOperations) - 4 * BYTE1(v26[10].DmaOperations->Size) - 8;
v165 = v27;
v28 = v26[11].DmaOperations;
if( v28 )
{
v27 -= HIWORD(v28->Size);
v165 = v27;
}
*((_DWORD *)TokenInformation + 9) = v27;
*((_DWORD *)TokenInformation + 10) = HIDWORD(v26[7].DmaOperations) - 1;
*((_DWORD *)TokenInformation + 11) = SepTokenPrivilegeCount((INT64)v26);
*((_QWORD *)TokenInformation + 6) = v26[3].DmaOperations;
goto LABEL_39;
case TokenRestrictedSids:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v50 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v50 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v49) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v49);
v51 = 16 * v14->RestrictedSidCount + 8;
if( v14->RestrictedSidCount )
{
RestrictedSids = v14->RestrictedSids;
RestrictedSidCount = v14->RestrictedSidCount;
do
{
v51 = (unsigned int)v51 + 4 * *((unsigned __int8 *)RestrictedSids->Sid + 1) + 8;
++RestrictedSids;
--RestrictedSidCount;
}
while( RestrictedSidCount );
}
*(_DWORD *)v11 = v51;
if( v5 < (unsigned int)v51 )
goto LABEL_41;
*(_DWORD *)TokenInformation = v14->RestrictedSidCount;
RtlCopySidAndAttributesArray(
v14->RestrictedSidCount,
v14->RestrictedSids,
v51,
(SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
(char *)TokenInformation + 16 * v14->RestrictedSidCount + 8,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
goto LABEL_14;
case TokenSessionId:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_156;
v14 = (_TOKEN *)DmaAdapter;
SeQuerySessionIdToken(DmaAdapter, (UINT64 *)&SessionId);
*(_DWORD *)TokenInformation = SessionId;
*(_DWORD *)v11 = 4;
goto LABEL_15;
case TokenGroupsAndPrivileges:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v81 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v81 + 242);
v34 = DmaAdapter;
LOBYTE(v80) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v80);
HIDWORD(pReturnLength) = SepTokenPrivilegeCount((INT64)v34);
v82 = 12 * HIDWORD(pReturnLength);
DmaOperations_high = HIDWORD(v34[7].DmaOperations);
v84 = DmaOperations_high;
v85 = 16 * DmaOperations_high;
if( DmaOperations_high )
{
v86 = v34[9].DmaOperations;
v87 = DmaOperations_high;
do
{
v85 += (4 * *(unsigned __int8 *)(*(_QWORD *)&v86->Size + 1i64) + 15) & 0xFFFFFFF8;
v86 = (_DMA_OPERATIONS *)((char *)v86 + 16);
--v87;
}
while( v87 );
}
v88 = 16 * *(_DWORD *)&v34[8].Version;
v89 = v88;
v90 = v88;
if( *(_DWORD *)&v34[8].Version )
{
v128 = *(_QWORD *)&v34[10].Version;
v129 = *(unsigned int *)&v34[8].Version;
do
{
v89 += (4 * *(unsigned __int8 *)(*(_QWORD *)v128 + 1i64) + 15) & 0xFFFFFFF8;
v90 = v89;
v128 += 16i64;
--v129;
}
while( v129 );
}
v91 = v90 + v82 + v85 + 56;
*(_DWORD *)v11 = v91;
if( v5 < v91 )
goto LABEL_101;
*((_QWORD *)TokenInformation + 6) = v34[1].DmaOperations;
*((_DWORD *)TokenInformation + 1) = v85;
*(_DWORD *)TokenInformation = HIDWORD(v34[7].DmaOperations);
v92 = (SID_AND_ATTRIBUTES *)((char *)TokenInformation + 56);
*((_QWORD *)TokenInformation + 1) = (char *)TokenInformation + 56;
*((_DWORD *)TokenInformation + 5) = v89;
*((_DWORD *)TokenInformation + 4) = *(_DWORD *)&v34[8].Version;
if( *(_DWORD *)&v34[8].Version )
{
v93 = (SID_AND_ATTRIBUTES *)((char *)v92 + ((v85 + 7i64) & 0xFFFFFFFFFFFFFFF8ui64));
*((_QWORD *)TokenInformation + 3) = v93;
}
else
{
*((_QWORD *)TokenInformation + 3) = 0i64;
v93 = Dest;
}
*((_DWORD *)TokenInformation + 9) = v82;
*((_DWORD *)TokenInformation + 8) = HIDWORD(pReturnLength);
v94 = (_LUID_AND_ATTRIBUTES *)((char *)v92 + v89 + v85);
*((_QWORD *)TokenInformation + 5) = v94;
RtlCopySidAndAttributesArray(
HIDWORD(v34[7].DmaOperations),
(SID_AND_ATTRIBUTES *)v34[9].DmaOperations,
v85 - v84 * 16,
v92,
&v92[v84],
&NextTargetSid,
(UINT64 *)&NextTargetSid);
if( v93 )
RtlCopySidAndAttributesArray(
*(unsigned int *)&v34[8].Version,
*(SID_AND_ATTRIBUTES **)&v34[10].Version,
v89 - v88,
v93,
&v93[v88 / 0x10],
&NextTargetSid,
(UINT64 *)&NextTargetSid);
SepConvertTokenPrivilegesToLuidAndAttributes((_TOKEN *)v34, v94);
goto LABEL_54;
case TokenSandBoxInert:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
return -1073741789;
v18 = DmaAdapter;
*(_DWORD *)TokenInformation = ((__int64)DmaAdapter[12].DmaOperations & 0x40) != 0;
goto LABEL_16;
case TokenAuditPolicy:
if( !SeSinglePrivilegeCheck(*(INT64 *)SeSecurityPrivilege, v10) )
return -1073741727;
result = SepReferenceTokenByHandle(
TokenHandle,
8ui64,
v10,
(_TOKEN **)&DmaAdapter,
(UINT8 *)UseNewTrust,
&SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 30;
if( v5 < 0x1E )
goto LABEL_156;
v134 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v134 + 242);
v26 = DmaAdapter;
LOBYTE(v133) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v133);
*(struct _DMA_ADAPTER *)TokenInformation = *(PADAPTER_OBJECT)((char *)v26 + 88);
*((_QWORD *)TokenInformation + 2) = v26[6].DmaOperations;
*((_DWORD *)TokenInformation + 6) = *(_DWORD *)&v26[7].Version;
*((_WORD *)TokenInformation + 14) = *(&v26[7].Size + 1);
LABEL_39:
ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
KeLeaveCriticalRegion();
LABEL_40:
HalPutDmaAdapter(v26);
return 0;
case TokenOrigin:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 8;
if( v5 < 8 )
goto LABEL_156;
v18 = DmaAdapter;
*(_QWORD *)TokenInformation = *(_QWORD *)&DmaAdapter[14].Version;
goto LABEL_16;
case TokenElevationType:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_156;
v26 = DmaAdapter;
AllocateAdapterChannel = (int)DmaAdapter[13].DmaOperations->AllocateAdapterChannel;
if( (AllocateAdapterChannel & 4) != 0 )
{
if( SeIsSModeAdminlessEnabled() )
*(_DWORD *)TokenInformation = 1;
else
*(_DWORD *)TokenInformation = 3;
}
else
{
LOBYTE(v9) = (AllocateAdapterChannel & 2) != 0;
*(_DWORD *)TokenInformation = v9 + 1;
}
goto LABEL_40;
case TokenLinkedToken:
ReturnSession = 0i64;
Handle = 0i64;
Object = 0i64;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 8;
if( v5 == 8 )
{
v116 = -(SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v10) != 0);
if( SeIsSModeAdminlessEnabled() )
{
HIDWORD(pReturnLength) = 0;
SepGetStackTraceHash((_DWORD *)&pReturnLength + 1);
EtwTraceAdminlessAccessFailure(HIDWORD(pReturnLength), 1i64, 0i64, 1);
HalPutDmaAdapter(DmaAdapter);
return -1073741729;
}
else
{
v34 = DmaAdapter;
v117 = SepReferenceLogonSessionSilo(
(_LUID *)&DmaAdapter[13].DmaOperations->AllocateCommonBuffer,
(_EJOB *)DmaAdapter[13].DmaOperations->AllocateAdapterChannelEx,
&ReturnSession);
if( v117 < 0 )
goto LABEL_174;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = v10 ? 0 : 512;
ObjectAttributes.ObjectName = 0i64;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v118 = v116 + 2;
v119 = ReturnSession;
v117 = SepDuplicateToken(
(_TOKEN *)ReturnSession->Token,
&ObjectAttributes,
0,
v118,
SecurityIdentification,
0,
0,
(_TOKEN **)&Object);
SepDeReferenceLogonSessionDirect(v119);
if( v117 < 0 )
{
LABEL_174:
HalPutDmaAdapter(v34);
return v117;
}
inserted = ObInsertObject(Object, 0i64, 0xF01FFui64, 0i64, 0i64, &Handle);
if( inserted >= 0 )
{
*(_QWORD *)TokenInformation = Handle;
goto LABEL_55;
}
v132 = v34;
LABEL_205:
HalPutDmaAdapter(v132);
return inserted;
}
}
else
{
HalPutDmaAdapter(DmaAdapter);
return -1073741820;
}
case TokenElevation:
*(_DWORD *)v11 = 4;
if( v5 != 4 )
return -1073741820;
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v63 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v63 + 242);
v26 = DmaAdapter;
LOBYTE(v62) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v62);
IsElevatedRid = (*(_QWORD *)&v26[4].Version & 0x1120160684i64) != 0;
v65 = HIDWORD(v26[7].DmaOperations);
if( v65 )
{
do
{
if( IsElevatedRid )
break;
IsElevatedRid = RtlIsElevatedRid((INT64)v26[9].DmaOperations + 16 * (unsigned int)v9);
LODWORD(v9) = v9 + 1;
}
while( (unsigned int)v9 < v65 );
}
ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
KeLeaveCriticalRegion();
*(_DWORD *)TokenInformation = IsElevatedRid;
goto LABEL_40;
case TokenHasRestrictions:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 1;
if( !v5 )
goto LABEL_156;
v18 = DmaAdapter;
*(_BYTE *)TokenInformation = ((__int64)DmaAdapter[12].DmaOperations & 0x810) != 0;
goto LABEL_16;
case TokenAccessInformation:
HIDWORD(v170) = 0;
v169 = 0i64;
v168 = 0i64;
v167 = 0i64;
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v106 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v106 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v105) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v105);
v107 = (UINT8 *)SourceSid;
v108 = UseNewTrust[0];
TokenAccessInformationBufferSize = SepGetTokenAccessInformationBufferSize(
v14,
UseNewTrust[0],
SourceSid,
(UINT64 *)((char *)&v171 + 4),
&v171,
(UINT64 *)((char *)&v170 + 4),
&v170,
(UINT64 *)((char *)&v169 + 4),
&v169,
(UINT64 *)((char *)&v168 + 4),
&v168,
(UINT64 *)((char *)&v167 + 4),
&v167);
*(_DWORD *)v11 = TokenAccessInformationBufferSize;
if( v5 < TokenAccessInformationBufferSize )
goto LABEL_41;
LODWORD(pTrustSidLength) = HIDWORD(v167);
LODWORD(pSecurityAttributesLength) = v167;
LODWORD(pCapabilitySidsLength) = HIDWORD(v168);
LODWORD(pCapabilitySidsSALength) = v168;
LODWORD(pRestrictedSidsSALength) = HIDWORD(v169);
LODWORD(pPackageSidLength) = v169;
LODWORD(RemainingSidAreaa) = HIDWORD(v170);
LODWORD(RemainingSidAreaSizea) = v170;
LODWORD(SidAreaa) = v171;
SepCopyTokenAccessInformation(
(INT64)v14,
(INT64)TokenInformation,
v5,
HIDWORD(v171),
(UINT64)SidAreaa,
(UINT64)RemainingSidAreaa,
(UINT64)RemainingSidAreaSizea,
(UINT64)pRestrictedSidsSALength,
(INT64)pPackageSidLength,
(UINT64)pCapabilitySidsLength,
(UINT64)pCapabilitySidsSALength,
(INT64)pTrustSidLength,
(UINT64)pSecurityAttributesLength,
v108,
v107);
goto LABEL_14;
case TokenVirtualizationAllowed:
case TokenVirtualizationEnabled:
case TokenUIAccess:
case TokenIsRestricted:
case TokenIsRestricted|TokenGroups:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_156;
v18 = DmaAdapter;
switch( TokenInformationClass )
{
case TokenVirtualizationAllowed:
LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 9) & 1;
goto LABEL_129;
case TokenVirtualizationEnabled:
LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 10) & 1;
goto LABEL_129;
case TokenUIAccess:
LODWORD(v9) = (LODWORD(DmaAdapter[12].DmaOperations) >> 12) & 1;
goto LABEL_129;
}
if( TokenInformationClass != TokenIsRestricted )
{
if( ((__int64)DmaAdapter[12].DmaOperations & 0x10000) == 0 )
goto LABEL_129;
goto LABEL_230;
}
v135 = (int)DmaAdapter[12].DmaOperations;
if( (v135 & 0x10) != 0 || (v135 & 8) != 0 )
LABEL_230:
LODWORD(v9) = 1;
LABEL_129:
*(_DWORD *)TokenInformation = v9;
break;
case TokenIntegrityLevel:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v39 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v39 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v38) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v38);
SepCopyTokenIntegrity((INT64)v14);
Sid = (unsigned __int8 *)Src.Sid;
v41 = 4 * *((unsigned __int8 *)Src.Sid + 1) + 24;
*(_DWORD *)v11 = v41;
if( v5 < v41 )
goto LABEL_41;
RtlCopySidAndAttributesArray(
1ui64,
&Src,
4 * (unsigned int)Sid[1] + 8,
(SID_AND_ATTRIBUTES *)TokenInformation,
(char *)TokenInformation + 16,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
goto LABEL_14;
case TokenMandatoryPolicy:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_156;
inserted = SeQueryMandatoryPolicyToken(DmaAdapter, (_TOKEN_MANDATORY_POLICY *)TokenInformation);
v164 = inserted;
goto LABEL_205;
case TokenLogonSid:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v122 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v122 + 242);
v34 = DmaAdapter;
LOBYTE(v121) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v121);
v123 = 0;
v124 = HIDWORD(v34[7].DmaOperations);
if( !v124 )
goto LABEL_188;
v125 = v34[9].DmaOperations;
while( (*(_DWORD *)(&v125->PutDmaAdapter + 2 * v123) & 0xC0000000) != -1073741824 )
{
if( ++v123 >= v124 )
goto LABEL_188;
}
v9 = *((_QWORD *)&v125->Size + 2 * v123);
LABEL_188:
if( v9 )
{
v126 = 16i64 * v123;
v127 = 4 * *(unsigned __int8 *)(*(_QWORD *)((char *)&v34[9].DmaOperations->Size + v126) + 1i64) + 32;
*(_DWORD *)v11 = v127;
if( v5 < v127 )
{
LABEL_101:
ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v34);
return -1073741789;
}
else
{
*(_DWORD *)TokenInformation = 1;
RtlCopySidAndAttributesArray(
1ui64,
(SID_AND_ATTRIBUTES *)((char *)v34[9].DmaOperations + v126),
4 * (unsigned int)*(unsigned __int8 *)(*(_QWORD *)((char *)&v34[9].DmaOperations->Size + v126) + 1i64)
+ 8,
(SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
(char *)TokenInformation + 24,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
LABEL_54:
ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
KeLeaveCriticalRegion();
LABEL_55:
HalPutDmaAdapter(v34);
return 0;
}
}
else
{
ExReleaseResourceLite(*(PERESOURCE *)&v34[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v34);
return -1073741275;
}
case TokenIsAppContainer:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
v18 = DmaAdapter;
if( v5 < 4 )
goto LABEL_42;
LOBYTE(v9) = ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0;
*(_DWORD *)TokenInformation = v9;
goto LABEL_16;
case TokenCapabilities:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v111 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v111 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v110) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v110);
CapabilityCount = v14->CapabilityCount;
v113 = 16 * CapabilityCount + 8;
if( CapabilityCount )
{
Capabilities = v14->Capabilities;
v115 = CapabilityCount;
do
{
v113 = (unsigned int)v113 + 4 * *((unsigned __int8 *)Capabilities->Sid + 1) + 8;
++Capabilities;
--v115;
}
while( v115 );
}
*(_DWORD *)v11 = v113;
if( v5 < (unsigned int)v113 )
goto LABEL_41;
*(_DWORD *)TokenInformation = v14->CapabilityCount;
RtlCopySidAndAttributesArray(
v14->CapabilityCount,
v14->Capabilities,
v113,
(SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
(char *)TokenInformation + 16 * v14->CapabilityCount + 8,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
goto LABEL_14;
case TokenAppContainerSid:
v19 = 8;
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v21 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v21 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v20) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v20);
Package = (unsigned __int8 *)v14->Package;
if( Package )
v19 = 4 * Package[1] + 16;
*(_DWORD *)v11 = v19;
if( v5 < v19 )
goto LABEL_41;
v23 = (char *)TokenInformation + 8;
if( !Package )
v23 = 0i64;
*(_QWORD *)TokenInformation = v23;
if( v23 )
RtlCopySid(v19 - 8, v23, v14->Package);
goto LABEL_14;
case TokenAppContainerNumber:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
*(_DWORD *)v11 = 4;
if( v5 < 4 )
goto LABEL_156;
v137 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v137 + 242);
v26 = DmaAdapter;
LOBYTE(v136) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v136);
v138 = v26[67].DmaOperations;
if( v138 )
LODWORD(v9) = v138->FlushAdapterBuffers;
ExReleaseResourceLite(*(PERESOURCE *)&v26[3].Version);
KeLeaveCriticalRegion();
*(_DWORD *)TokenInformation = v9;
goto LABEL_40;
case TokenUserClaimAttributes:
case TokenDeviceClaimAttributes:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v57 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v57 + 242);
v58 = DmaAdapter;
LOBYTE(v56) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v56);
v59 = v58[68].DmaOperations;
if( v59
&& (v59[1].GetDmaDomain || TokenInformationClass != TokenUserClaimAttributes)
&& ((GetDmaDomain = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)v59[1].AllocateCommonBufferWithBounds) != 0i64
|| TokenInformationClass != TokenDeviceClaimAttributes) )
{
if( TokenInformationClass == TokenUserClaimAttributes )
GetDmaDomain = (_AUTHZBASEP_SECURITY_ATTRIBUTES_INFORMATION *)v59[1].GetDmaDomain;
AuthzBasepQueryClaimAttributesToken(GetDmaDomain, 0i64, 0i64, &pReturnLength);
v60 = pReturnLength;
}
else
{
v60 = 16;
pInfo.SecurityAttributesList.Blink = &pInfo.SecurityAttributesList;
pInfo.SecurityAttributesList.Flink = &pInfo.SecurityAttributesList;
pInfo.WorkingSecurityAttributeCount = 0;
pInfo.WorkingSecurityAttributesList.Blink = &pInfo.WorkingSecurityAttributesList;
pInfo.WorkingSecurityAttributesList.Flink = &pInfo.WorkingSecurityAttributesList;
GetDmaDomain = &pInfo;
}
*(_DWORD *)v11 = v60;
if( v5 < v60 )
goto LABEL_94;
v70 = AuthzBasepQueryClaimAttributesToken(GetDmaDomain, TokenInformation, v5, &pReturnLength);
v164 = v70;
goto LABEL_108;
case TokenDeviceGroups:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v76 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v76 + 242);
v34 = DmaAdapter;
LOBYTE(v75) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v75);
v77 = v34[68].DmaOperations;
if( v77 && (Size = v77->Size) != 0 )
{
v79 = 16 * Size + 8;
}
else
{
Size = 0;
v79 = 24i64;
}
if( Size )
{
PutDmaAdapter = v77->PutDmaAdapter;
v140 = Size;
do
{
v79 = (unsigned int)v79 + 4 * *(unsigned __int8 *)(*(_QWORD *)PutDmaAdapter + 1i64) + 8;
PutDmaAdapter = (void(__fastcall *)(_DMA_ADAPTER *))((char *)PutDmaAdapter + 16);
--v140;
}
while( v140 );
}
*(_DWORD *)v11 = v79;
if( v5 < (unsigned int)v79 )
goto LABEL_101;
*(_OWORD *)TokenInformation = 0i64;
*((_QWORD *)TokenInformation + 2) = 0i64;
*(_DWORD *)TokenInformation = Size;
if( Size )
RtlCopySidAndAttributesArray(
Size,
(SID_AND_ATTRIBUTES *)v34[68].DmaOperations->PutDmaAdapter,
v79,
(SID_AND_ATTRIBUTES *)((char *)TokenInformation + 8),
(char *)TokenInformation + 16 * Size + 8,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
goto LABEL_54;
case TokenSecurityAttributes:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v67 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v67 + 242);
v58 = DmaAdapter;
LOBYTE(v66) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v66);
p_Size = &v58[48].DmaOperations->Size;
if( p_Size )
{
LODWORD(SidArea) = 0;
AuthzBasepQuerySecurityAttributesToken(p_Size, 0i64, 0, 0i64, (size_t)SidArea, &pReturnLength);
v69 = pReturnLength;
}
else
{
v69 = 16;
}
*(_DWORD *)v11 = v69;
if( v5 < v69 )
goto LABEL_94;
LODWORD(SidArea) = v5;
v70 = AuthzBasepQuerySecurityAttributesToken(
&v58[48].DmaOperations->Size,
0i64,
0,
TokenInformation,
(size_t)SidArea,
&pReturnLength);
v164 = v70;
LABEL_108:
ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v58);
return v70;
case MaxTokenInfoClass:
v42 = 8;
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v44 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v44 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v43) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v43);
v45 = UseNewTrust[0];
v46 = SourceSid;
if( UseNewTrust[0] )
TrustLevelSid = (unsigned __int8 *)SourceSid;
else
TrustLevelSid = (unsigned __int8 *)v14->TrustLevelSid;
if( TrustLevelSid )
v42 = 4 * TrustLevelSid[1] + 16;
*(_DWORD *)v11 = v42;
if( v5 < v42 )
goto LABEL_41;
v48 = (char *)TokenInformation + 8;
if( !TrustLevelSid )
v48 = 0i64;
*(_QWORD *)TokenInformation = v48;
if( v48 )
{
if( !v45 )
v46 = v14->TrustLevelSid;
RtlCopySid(v42 - 8, v48, v46);
}
goto LABEL_14;
case MaxTokenInfoClass|TokenGroups:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result >= 0 )
{
v142 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v142 + 242);
v143 = DmaAdapter;
LOBYTE(v141) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v141);
LODWORD(RemainingSidAreaSize) = v5;
LOBYTE(SidAreab) = 1;
SecurityAttributesToken = SepInternalQuerySecurityAttributesTokenEx(
v143,
v144,
0i64,
0,
SidAreab,
(UINT64)TokenInformation,
RemainingSidAreaSize);
v164 = SecurityAttributesToken;
ExReleaseResourceLite(*(PERESOURCE *)&v143[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v143);
return SecurityAttributesToken;
}
return result;
case TokenIsRestricted|TokenOwner:
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v96 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v96 + 242);
v58 = DmaAdapter;
LOBYTE(v95) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v95);
v97 = 16;
v98 = *(_QWORD *)&v58[72].Version;
if( v98 )
v97 = *(unsigned __int16 *)(v98 + 42) + 16;
*(_DWORD *)v11 = v97;
if( v5 < v97 )
{
LABEL_94:
ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v58);
return -1073741789;
}
else
{
if( *(_QWORD *)&v58[72].Version )
{
*((_BYTE *)TokenInformation + 8) = 1;
*(_QWORD *)TokenInformation = (char *)TokenInformation + 16;
memmove(
(UINT8 *)TokenInformation + 16,
*(UINT8 **)(*(_QWORD *)&v58[72].Version + 48i64),
*(unsigned __int16 *)(*(_QWORD *)&v58[72].Version + 42i64));
}
else
{
*((_BYTE *)TokenInformation + 8) = 0;
*(_QWORD *)TokenInformation = 0i64;
}
ExReleaseResourceLite(*(PERESOURCE *)&v58[3].Version);
KeLeaveCriticalRegion();
HalPutDmaAdapter(v58);
return 0;
}
case MaxTokenInfoClass|TokenDefaultDacl:
*(_DWORD *)v11 = 4;
if( v5 < 4 )
return -1073741789;
*(_DWORD *)TokenInformation = RtlIsSandboxedTokenHandle(v8, v10);
return 0;
case TokenAppContainerNumber|TokenAuditPolicy:
LODWORD(RemainingSidArea) = 0;
wil_details_FeatureReporting_ReportUsageToService(
&Feature_PPLEnforcement__private_reporting,
0x126C519ui64,
0i64,
0i64,
(FEATURE_LOGGED_TRAITS *)&Feature_PPLEnforcement_logged_traits,
(INT64)RemainingSidArea);
return -1073741821;
default:
return -1073741821;
}
}
goto LABEL_16;
}
result = SepReferenceTokenByHandle(v8, 8ui64, v10, (_TOKEN **)&DmaAdapter, (UINT8 *)UseNewTrust, &SourceSid);
if( result < 0 )
return result;
v16 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v16 + 242);
v14 = (_TOKEN *)DmaAdapter;
LOBYTE(v15) = 1;
ExAcquireResourceSharedLite(*(PERESOURCE *)&DmaAdapter[3].Version, v15);
v17 = 4 * (unsigned int)*((unsigned __int8 *)v14->UserAndGroups->Sid + 1) + 24;
*(_DWORD *)v11 = v17;
if( v5 >= (unsigned int)v17 )
{
RtlCopySidAndAttributesArray(
1ui64,
v14->UserAndGroups,
v17,
(SID_AND_ATTRIBUTES *)TokenInformation,
(char *)TokenInformation + 16,
&NextTargetSid,
(UINT64 *)&NextTargetSid);
LABEL_14:
ExReleaseResourceLite(v14->TokenLock);
KeLeaveCriticalRegion();
LABEL_15:
v18 = (PADAPTER_OBJECT)v14;
LABEL_16:
HalPutDmaAdapter(v18);
return 0;
}
LABEL_41:
ExReleaseResourceLite(v14->TokenLock);
KeLeaveCriticalRegion();
v18 = (PADAPTER_OBJECT)v14;
LABEL_42:
HalPutDmaAdapter(v18);
return -1073741789;
}Referenced by:
RtlGetAppContainerNamedObjectPath
RtlpGetTokenNamedObjectPath