PiSwPdoPnPDispatch

NTSTATUS __stdcall PiSwPdoPnPDispatch(_DEVICE_OBJECT *DeviceObject, _IRP *Irp){
  INT64 v2; 
  _DWORD *DeviceExtension; 
  signed int Status; 
  _IO_STACK_LOCATION *CurrentStackLocation; 
  unsigned int MinorFunction; 
  _ETHREAD *v9; 
  _IO_SECURITY_CONTEXT *v10; 
  __m128i si128; 
  int v12; 
  int v13; 
  int v14; 
  int v15; 
  unsigned int v16; 
  unsigned int v17; 
  unsigned int v18; 
  unsigned int v19; 
  unsigned int v20; 
  WCHAR *v21; 
  UINT64 v22; 
  signed int MultiSZ; 
  _ETHREAD *v25; 
  __int64 v26; 
  _QWORD *v27; 
  int SecurityContext; 
  int v29; 
  int v30; 
  int v31; 
  VOID **v32; 
  UINT64 v33; 
  _ETHREAD *v34; 
  PI_SWD_OBJECT *v35; 
  int v36; 
  _ETHREAD *v37; 
  VOID **PoolWithTag; 
  _ETHREAD *CurrentThread; 
  unsigned __int64 Information; 
  __int64 v41; 
  unsigned __int64 v42; 
  VOID *v43; 
  _ETHREAD *v44; 
  int v45; 
  _ETHREAD *v46; 
  int v47; 
  VOID **v48; 
  unsigned __int64 v49; 

  DeviceExtension = DeviceObject->DeviceExtension;
  Status = Irp->IoStatus.Status;
  CurrentStackLocation = Irp->Tail.CurrentStackLocation;
  if( (DeviceExtension[2] & 0x10) != 0 )
  {
    Status = -1073741810;
    goto LABEL_26;
  }
  MinorFunction = CurrentStackLocation->MinorFunction;
  if( MinorFunction > 0xC )
  {
    v16 = MinorFunction - 19;
    if( v16 )
    {
      v17 = v16 - 1;
      if( !v17 )
      {
        CurrentThread = (_ETHREAD *)KeGetCurrentThread();
        --CurrentThread->Tcb.KernelApcDisable;
        ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
        if( *(_QWORD *)DeviceExtension )
        {
          Information = Irp->IoStatus.Information;
          v41 = Information | 2;
          v42 = Information & 0xFFFFFFFFFFFFFFFDui64;
          if( (*(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64) & 4) == 0 )
            v41 = v42;
          Irp->IoStatus.Information = v41;
          goto LABEL_12;
        }
LABEL_69:
        Status = -1073741810;
        goto LABEL_25;
      }
      v18 = v17 - 1;
      if( v18 )
      {
        v19 = v18 - 1;
        if( !v19 )
        {
          Status = LOBYTE(CurrentStackLocation->Parameters.SecurityContext) != 0 ? 0xC00000BB : 0;
          goto LABEL_26;
        }
        v20 = v19 - 1;
        if( !v20 )
        {
          v44 = (_ETHREAD *)KeGetCurrentThread();
          --v44->Tcb.KernelApcDisable;
          ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
          v45 = DeviceExtension[2] | 4;
          DeviceExtension[2] = v45;
          PiSwProcessRemove(DeviceObject, (v45 & 8) != 0);
LABEL_59:
          ExReleaseResourceLite(&PiSwLockObj);
          KeLeaveCriticalRegionThread(KeGetCurrentThread());
          goto LABEL_20;
        }
        if( v20 != 2 )
          goto LABEL_26;
        PiSwCompleteCreate(DeviceObject);
      }
      else
      {
        PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1466986064i64);
        if( !PoolWithTag )
          goto LABEL_67;
        *((_DWORD *)PoolWithTag + 5) = 0;
        *((_DWORD *)PoolWithTag + 4) = 15;
        *(GUID *)PoolWithTag = GUID_BUS_TYPE_SW_DEVICE;
        Irp->IoStatus.Information = (unsigned __int64)PoolWithTag;
      }
LABEL_20:
      Status = 0;
      goto LABEL_26;
    }
    v25 = (_ETHREAD *)KeGetCurrentThread();
    --v25->Tcb.KernelApcDisable;
    ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
    v27 = *(_QWORD **)DeviceExtension;
    if( !*(_QWORD *)DeviceExtension )
      goto LABEL_69;
    SecurityContext = (int)CurrentStackLocation->Parameters.SecurityContext;
    if( SecurityContext )
    {
      v29 = SecurityContext - 1;
      if( !v29 )
      {
        v43 = (VOID *)v27[3];
        if( !v43 )
          goto LABEL_25;
        MultiSZ = PnpAllocateMultiSZ(v43, 0x7FFFFFFFi64, v26, &Irp->IoStatus.Information);
        goto LABEL_24;
      }
      v30 = v29 - 1;
      if( !v30 )
      {
        MultiSZ = PiSwDeviceMakeCompatibleIds(*(PI_SWD_OBJECT **)DeviceExtension, (WCHAR **)&Irp->IoStatus.Information);
        goto LABEL_24;
      }
      v31 = v30 - 1;
      if( v31 )
      {
        if( v31 != 2 || !v27[5] )
          goto LABEL_25;
        v32 = ExAllocatePoolWithTag(1ui64, 0x4Eui64, 1466986064i64);
        Irp->IoStatus.Information = (unsigned __int64)v32;
        if( !v32 )
        {
          Status = -1073741670;
          goto LABEL_25;
        }
        MultiSZ = PnpStringFromGuid(*(const _GUID **)(*(_QWORD *)DeviceExtension + 40i64), (WCHAR *)v32, v33);
        goto LABEL_24;
      }
      v21 = (WCHAR *)v27[2];
    }
    else
    {
      v21 = (WCHAR *)v27[1];
    }
    v22 = 200i64;
LABEL_23:
    MultiSZ = PnpAllocatePWSTR(v21, v22, 0x57706E50u, (PVOID *)&Irp->IoStatus.Information);
LABEL_24:
    Status = MultiSZ;
    goto LABEL_25;
  }
  if( MinorFunction == 12 )
  {
    v34 = (_ETHREAD *)KeGetCurrentThread();
    --v34->Tcb.KernelApcDisable;
    ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
    v35 = *(PI_SWD_OBJECT **)DeviceExtension;
    if( !*(_QWORD *)DeviceExtension )
      goto LABEL_69;
    v36 = (int)CurrentStackLocation->Parameters.SecurityContext;
    if( v36 )
    {
      if( v36 != 1 )
        goto LABEL_25;
      v21 = (WCHAR *)*((_QWORD *)v35 + 7);
    }
    else
    {
      v21 = (WCHAR *)*((_QWORD *)v35 + 6);
    }
    if( !v21 )
      goto LABEL_25;
    v22 = 0x7FFFFFFFi64;
    goto LABEL_23;
  }
  if( !CurrentStackLocation->MinorFunction )
  {
    v37 = (_ETHREAD *)KeGetCurrentThread();
    --v37->Tcb.KernelApcDisable;
    ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
    if( (DeviceExtension[2] & 1) == 0 )
    {
      Status = PiSwDeviceInterfacesUpdateState(*(PI_SWD_OBJECT **)DeviceExtension, 1u);
      if( Status < 0 )
        PiSwDeviceInterfacesUpdateState(*(PI_SWD_OBJECT **)DeviceExtension, 0);
      else
        DeviceExtension[2] |= 1u;
      goto LABEL_25;
    }
    goto LABEL_12;
  }
  if( MinorFunction == 1 )
    goto LABEL_20;
  if( MinorFunction == 2 )
  {
    v46 = (_ETHREAD *)KeGetCurrentThread();
    --v46->Tcb.KernelApcDisable;
    ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
    v47 = DeviceExtension[2] | 2;
    DeviceExtension[2] = v47;
    PiSwProcessRemove(DeviceObject, (v47 & 8) != 0);
    if( (DeviceExtension[2] & 8) == 0 )
      PiSwDestroyDeviceObject(DeviceObject);
    goto LABEL_59;
  }
  if( MinorFunction <= 6 )
    goto LABEL_20;
  if( MinorFunction == 7 )
  {
    if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) != 4 )
      goto LABEL_26;
    v48 = ExAllocatePoolWithTag(1ui64, 0x10ui64, 1466986064i64);
    v49 = (unsigned __int64)v48;
    if( v48 )
    {
      *(_DWORD *)v48 = 1;
      v48[1] = DeviceObject;
      ObfReferenceObject(DeviceObject);
      Irp->IoStatus.Information = v49;
      goto LABEL_20;
    }
LABEL_67:
    Status = -1073741670;
    goto LABEL_26;
  }
  if( MinorFunction == 9 )
  {
    v9 = (_ETHREAD *)KeGetCurrentThread();
    --v9->Tcb.KernelApcDisable;
    ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v2);
    if( *(_QWORD *)DeviceExtension )
    {
      v10 = CurrentStackLocation->Parameters.SecurityContext;
      si128 = _mm_load_si128((const __m128i *)&_xmm);
      v10->DesiredAccess = 0;
      v10->FullCreateOptions = 1;
      *(__m128i *)&v10[1].SecurityQos = si128;
      v10[1].DesiredAccess = _mm_cvtsi128_si32(si128);
      v10[1].FullCreateOptions = 0;
      LODWORD(v10[2].SecurityQos) = 0;
      v12 = HIDWORD(v10->SecurityQos) | 0x240;
      HIDWORD(v10->SecurityQos) = v12;
      v13 = v12 ^ ((unsigned __int8)v12 ^ (unsigned __int8)(16 * *(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64))) & 0x10;
      HIDWORD(v10->SecurityQos) = v13;
      v14 = v13 ^ ((unsigned __int8)v13 ^ (unsigned __int8)((unsigned __int8)*(_DWORD *)(*(_QWORD *)DeviceExtension
                                                                                       + 64i64) << 6)) & 0x80;
      HIDWORD(v10->SecurityQos) = v14;
      v15 = v14 ^ (v14 ^ (*(_DWORD *)(*(_QWORD *)DeviceExtension + 64i64) << 15)) & 0x20000;
      HIDWORD(v10->SecurityQos) = v15;
      HIDWORD(v10->SecurityQos) = v15 ^ ((unsigned __int16)v15 ^ (unsigned __int16)~(32
                                                                                   * *(_DWORD *)(*(_QWORD *)DeviceExtension
                                                                                               + 64i64))) & 0x100;
LABEL_12:
      Status = 0;
LABEL_25:
      ExReleaseResourceLite(&PiSwLockObj);
      KeLeaveCriticalRegionThread(KeGetCurrentThread());
      goto LABEL_26;
    }
    goto LABEL_69;
  }
LABEL_26:
  Irp->IoStatus.Status = Status;
  IofCompleteRequest(Irp, 0);
  return Status;
}

Referenced by:

No references.