SepVerifyDesktopAppxPackageName

INT64 __fastcall SepVerifyDesktopAppxPackageName(_TOKEN *Token, VOID *SecurityDescriptor, UINT8 *PackageNameVerified){
  int v5; 
  UNICODE_STRING *v7; 
  __int128 *PoolWithTag; 
  INT64 v9; 
  _DWORD *v10; 
  _DWORD *v11; 
  __int16 v12; 
  __int64 v13; 
  ACL *v14; 
  __int64 v15; 
  __int64 v16; 
  int v18; 
  UINT64 BufferLength; 
  UINT64 BufferLengtha; 
  SIZE_T NumberOfBytes; 
  int v22; 
  int v23; 
  struct _UNICODE_STRING DestinationString; 
  __int128 P[32]; 
  v23 = 2;
  v22 = 0;
  NumberOfBytes = 0i64;
  *PackageNameVerified = 0;
  v5 = 0;
  DestinationString = 0i64;
  RtlInitUnicodeString(&DestinationString, L"WIN:
  if( !SeSecurityAttributePresent(Token, &DestinationString, v7) )
    return(unsigned int)v5;
  LODWORD(BufferLength) = 512;
  PoolWithTag = P;
  v5 = SeQuerySecurityAttributesToken(Token, &DestinationString, 1ui64, P, BufferLength, &NumberOfBytes);
  if( v5 == -1073741789 )
  {
    v18 = NumberOfBytes;
    PoolWithTag = (__int128 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)NumberOfBytes, 0x20206553ui64);
    if( !PoolWithTag )
      return(unsigned int)-1073741801;
    LODWORD(BufferLengtha) = v18;
    v5 = SeQuerySecurityAttributesToken(Token, &DestinationString, 1ui64, PoolWithTag, BufferLengtha, &NumberOfBytes);
  }
  if( v5 < 0 )
    goto LABEL_16;
  if( !PoolWithTag )
    return(unsigned int)-1073739509;
  AuthzBasepAllocateSecurityAttributesList(v9);
  v11 = v10;
  if( !v10 )
  {
    v5 = -1073741670;
    goto LABEL_16;
  }
  v5 = AuthzBasepSetSecurityAttributesToken(v10, &v23, (__int64)PoolWithTag);
  if( v5 < 0 )
    goto LABEL_15;
  do
  {
    v12 = *((_WORD *)SecurityDescriptor + 1);
    if( (v12 & 4) == 0 )
      goto LABEL_27;
    if( v12 >= 0 )
    {
      v14 = (ACL *)*((_QWORD *)SecurityDescriptor + 4);
      goto LABEL_11;
    }
    v13 = *((unsigned int *)SecurityDescriptor + 4);
    if( (_DWORD)v13 )
      v14 = (ACL *)((char *)SecurityDescriptor + v13);
    else
LABEL_27:
      v14 = 0i64;
LABEL_11:
    LODWORD(v15) = RtlFindAceByType(v14, 9ui64, (SIZE_T *)((char *)&NumberOfBytes + 4));
    v16 = v15;
    if( v15 )
    {
      v5 = AuthzBasepEvaluateAceCondition(
             (__int64)Token,
             (__int64)v11,
             0i64,
             0i64,
             0i64,
             0i64,
             0i64,
             (char *)(v15 + 4 * (unsigned int)*(unsigned __int8 *)(v15 + 9) + 8 + 8i64),
             *(unsigned __int16 *)(v15 + 2) - (4 * (unsigned int)*(unsigned __int8 *)(v15 + 9) + 8) - 8,
             0,
             0,
             &v22);
      if( v5 < 0 )
        break;
      if( v22 == 1 )
        goto LABEL_14;
    }
    ++HIDWORD(NumberOfBytes);
  }
  while( v16 );
  if( v22 == 1 )
LABEL_14:
    *PackageNameVerified = 1;
LABEL_15:
  AuthzBasepFreeSecurityAttributesList(v11);
LABEL_16:
  if( PoolWithTag && PoolWithTag != P )
    ExFreePoolWithTag(PoolWithTag, 0);
  return(unsigned int)v5;
}

Referenced by:

SepVerifyDesktopAppxImage