PiSwPdoPnPDispatch
NTSTATUS __stdcall PiSwPdoPnPDispatch(_DEVICE_OBJECT *DeviceObject, _IRP *Irp){
INT64 v2;
_DWORD *DeviceExtension;
signed int Status;
_IO_STACK_LOCATION *CurrentStackLocation;
unsigned int MinorFunction;
_ETHREAD *v9;
_IO_SECURITY_CONTEXT *v10;
__m128i si128;
int v12;
int v13;
int v14;
int v15;
unsigned int v16;
unsigned int v17;
unsigned int v18;
unsigned int v19;
unsigned int v20;
WCHAR *v21;
UINT64 v22;
signed int MultiSZ;
_ETHREAD *v25;
__int64 v26;
_QWORD *v27;
int SecurityContext;
int v29;
int v30;
int v31;
VOID **v32;
UINT64 v33;
_ETHREAD *v34;
PI_SWD_OBJECT *v35;
int v36;
_ETHREAD *v37;
VOID **PoolWithTag;
_ETHREAD *CurrentThread;
unsigned __int64 Information;
__int64 v41;
unsigned __int64 v42;
VOID *v43;
_ETHREAD *v44;
int v45;
_ETHREAD *v46;
int v47;
VOID **v48;
unsigned __int64 v49;
DeviceExtension = DeviceObject->DeviceExtension;
Status = Irp->IoStatus.Status;
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
if( (DeviceExtension[2] & 0x10) != 0 )
{
Status = -1073741810;
goto LABEL_26;
}
MinorFunction = CurrentStackLocation->MinorFunction;
if( MinorFunction > 0xC )
{
v16 = MinorFunction - 19;
if( v16 )
{
v17 = v16 - 1;
if( !v17 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
if( *(_QWORD *)DeviceExtension )
{
Information = Irp->IoStatus.Information;
v41 = Information | 2;
v42 = Information & 0xFFFFFFFFFFFFFFFDui64;
if( (*(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64) & 4) == 0 )
v41 = v42;
Irp->IoStatus.Information = v41;
goto LABEL_12;
}
LABEL_69:
Status = -1073741810;
goto LABEL_25;
}
v18 = v17 - 1;
if( v18 )
{
v19 = v18 - 1;
if( !v19 )
{
Status = LOBYTE(CurrentStackLocation->Parameters.SecurityContext) != 0 ? 0xC00000BB : 0;
goto LABEL_26;
}
v20 = v19 - 1;
if( !v20 )
{
v44 = (_ETHREAD *)KeGetCurrentThread();
--v44->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
v45 = DeviceExtension[2] | 4;
DeviceExtension[2] = v45;
PiSwProcessRemove(DeviceObject, (v45 & 8) != 0);
LABEL_59:
ExReleaseResourceLite(&PiSwLockObj);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
goto LABEL_20;
}
if( v20 != 2 )
goto LABEL_26;
PiSwCompleteCreate(DeviceObject);
}
else
{
PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1466986064i64);
if( !PoolWithTag )
goto LABEL_67;
*((_DWORD *)PoolWithTag + 5) = 0;
*((_DWORD *)PoolWithTag + 4) = 15;
*(GUID *)PoolWithTag = GUID_BUS_TYPE_SW_DEVICE;
Irp->IoStatus.Information = (unsigned __int64)PoolWithTag;
}
LABEL_20:
Status = 0;
goto LABEL_26;
}
v25 = (_ETHREAD *)KeGetCurrentThread();
--v25->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
v27 = *(_QWORD **)DeviceExtension;
if( !*(_QWORD *)DeviceExtension )
goto LABEL_69;
SecurityContext = (int)CurrentStackLocation->Parameters.SecurityContext;
if( SecurityContext )
{
v29 = SecurityContext - 1;
if( !v29 )
{
v43 = (VOID *)v27[3];
if( !v43 )
goto LABEL_25;
MultiSZ = PnpAllocateMultiSZ(v43, 0x7FFFFFFFi64, v26, &Irp->IoStatus.Information);
goto LABEL_24;
}
v30 = v29 - 1;
if( !v30 )
{
MultiSZ = PiSwDeviceMakeCompatibleIds(*(PI_SWD_OBJECT **)DeviceExtension, (WCHAR **)&Irp->IoStatus.Information);
goto LABEL_24;
}
v31 = v30 - 1;
if( v31 )
{
if( v31 != 2 || !v27[5] )
goto LABEL_25;
v32 = ExAllocatePoolWithTag(1ui64, 0x4Eui64, 1466986064i64);
Irp->IoStatus.Information = (unsigned __int64)v32;
if( !v32 )
{
Status = -1073741670;
goto LABEL_25;
}
MultiSZ = PnpStringFromGuid(*(const _GUID **)(*(_QWORD *)DeviceExtension + 40i64), (WCHAR *)v32, v33);
goto LABEL_24;
}
v21 = (WCHAR *)v27[2];
}
else
{
v21 = (WCHAR *)v27[1];
}
v22 = 200i64;
LABEL_23:
MultiSZ = PnpAllocatePWSTR(v21, v22, 0x57706E50u, (PVOID *)&Irp->IoStatus.Information);
LABEL_24:
Status = MultiSZ;
goto LABEL_25;
}
if( MinorFunction == 12 )
{
v34 = (_ETHREAD *)KeGetCurrentThread();
--v34->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
v35 = *(PI_SWD_OBJECT **)DeviceExtension;
if( !*(_QWORD *)DeviceExtension )
goto LABEL_69;
v36 = (int)CurrentStackLocation->Parameters.SecurityContext;
if( v36 )
{
if( v36 != 1 )
goto LABEL_25;
v21 = (WCHAR *)*((_QWORD *)v35 + 7);
}
else
{
v21 = (WCHAR *)*((_QWORD *)v35 + 6);
}
if( !v21 )
goto LABEL_25;
v22 = 0x7FFFFFFFi64;
goto LABEL_23;
}
if( !CurrentStackLocation->MinorFunction )
{
v37 = (_ETHREAD *)KeGetCurrentThread();
--v37->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
if( (DeviceExtension[2] & 1) == 0 )
{
Status = PiSwDeviceInterfacesUpdateState(*(PI_SWD_OBJECT **)DeviceExtension, 1u);
if( Status < 0 )
PiSwDeviceInterfacesUpdateState(*(PI_SWD_OBJECT **)DeviceExtension, 0);
else
DeviceExtension[2] |= 1u;
goto LABEL_25;
}
goto LABEL_12;
}
if( MinorFunction == 1 )
goto LABEL_20;
if( MinorFunction == 2 )
{
v46 = (_ETHREAD *)KeGetCurrentThread();
--v46->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
v47 = DeviceExtension[2] | 2;
DeviceExtension[2] = v47;
PiSwProcessRemove(DeviceObject, (v47 & 8) != 0);
if( (DeviceExtension[2] & 8) == 0 )
PiSwDestroyDeviceObject(DeviceObject);
goto LABEL_59;
}
if( MinorFunction <= 6 )
goto LABEL_20;
if( MinorFunction == 7 )
{
if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) != 4 )
goto LABEL_26;
v48 = ExAllocatePoolWithTag(1ui64, 0x10ui64, 1466986064i64);
v49 = (unsigned __int64)v48;
if( v48 )
{
*(_DWORD *)v48 = 1;
v48[1] = DeviceObject;
ObfReferenceObject(DeviceObject);
Irp->IoStatus.Information = v49;
goto LABEL_20;
}
LABEL_67:
Status = -1073741670;
goto LABEL_26;
}
if( MinorFunction == 9 )
{
v9 = (_ETHREAD *)KeGetCurrentThread();
--v9->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
if( *(_QWORD *)DeviceExtension )
{
v10 = CurrentStackLocation->Parameters.SecurityContext;
si128 = _mm_load_si128((const __m128i *)&_xmm);
v10->DesiredAccess = 0;
v10->FullCreateOptions = 1;
*(__m128i *)&v10[1].SecurityQos = si128;
v10[1].DesiredAccess = _mm_cvtsi128_si32(si128);
v10[1].FullCreateOptions = 0;
LODWORD(v10[2].SecurityQos) = 0;
v12 = HIDWORD(v10->SecurityQos) | 0x240;
HIDWORD(v10->SecurityQos) = v12;
v13 = v12 ^ ((unsigned __int8)v12 ^ (unsigned __int8)(16 * *(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64))) & 0x10;
HIDWORD(v10->SecurityQos) = v13;
v14 = v13 ^ ((unsigned __int8)v13 ^ (unsigned __int8)((unsigned __int8)*(_DWORD *)(*(_QWORD *)DeviceExtension
+ 64i64) << 6)) & 0x80;
HIDWORD(v10->SecurityQos) = v14;
v15 = v14 ^ (v14 ^ (*(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64) << 15)) & 0x20000;
HIDWORD(v10->SecurityQos) = v15;
HIDWORD(v10->SecurityQos) = v15 ^ ((unsigned __int16)v15 ^ (unsigned __int16)~(32
* *(_DWORD *)(*(_QWORD *)DeviceExtension
+ 64i64))) & 0x100;
LABEL_12:
Status = 0;
LABEL_25:
ExReleaseResourceLite(&PiSwLockObj);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
goto LABEL_26;
}
goto LABEL_69;
}
LABEL_26:
Irp->IoStatus.Status = Status;
IofCompleteRequest(Irp, 0);
return Status;
}Referenced by:
No references.