IopPnPDispatch
NTSTATUS __stdcall IopPnPDispatch(
PDEVICE_OBJECT DeviceObject,
_IRP *Irp,
INT64 a3,
INT64 a4,
INT64 a5,
INT64 a6,
INT64 a7,
INT64 a8){
_IO_STACK_LOCATION *CurrentStackLocation;
unsigned __int16 *v9;
UINT64 *p_Count;
unsigned int MinorFunction;
unsigned int v14;
const WCHAR **v15;
_IO_SECURITY_CONTEXT *v16;
__m128i si128;
int RootDevices;
unsigned int v20;
unsigned int v21;
unsigned int v22;
unsigned int v23;
void *v24;
GUID *SecurityContext;
GUID *v26;
__int64 v27;
int v28;
UINT64 v29;
VOID **v30;
_WORD *v31;
int v32;
_WORD *v33;
__int16 v34;
VOID **PoolWithTag;
VOID **v36;
__int64 v37;
char *v38;
_DWORD *DeviceNode;
VOID **v40;
VOID **v41;
int v42;
_WORD *v43;
__int16 v44;
char *v45;
__int16 v46;
signed __int64 v47;
WCHAR **v48;
UINT64 v49;
int v50;
char v51;
UINT64 Flags;
_DEVICE_RELATIONS *DeviceRelations[2];
UINT64 BufferSize;
UINT64 CmRegPropType;
int PropertyBuffer;
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
v9 = 0i64;
LODWORD(BufferSize) = 0;
LODWORD(CmRegPropType) = 0;
PropertyBuffer = 0;
p_Count = 0i64;
MinorFunction = CurrentStackLocation->MinorFunction;
DeviceRelations[0] = 0i64;
if( MinorFunction <= 8 )
{
if( MinorFunction != 8 )
{
switch( MinorFunction )
{
case 0u:
case 1u:
goto LABEL_9;
case 2u:
if( DeviceObject )
DeviceNode = DeviceObject->DeviceObjectExtension->DeviceNode;
else
DeviceNode = 0i64;
if( !DeviceNode || (DeviceNode[99] & 0x10000) != 0 )
IoDeleteDevice(DeviceObject);
IoInvalidateDeviceRelations(*(PDEVICE_OBJECT *)(*(&PnpReplaceEvent + 831) + 32i64), SingleBusRelations);
goto LABEL_9;
case 3u:
goto LABEL_9;
}
if( MinorFunction <= 5 )
goto LABEL_78;
if( MinorFunction == 6 )
{
LABEL_9:
RootDevices = 0;
goto LABEL_20;
}
if( DeviceObject == *(PDEVICE_OBJECT *)(*(&PnpReplaceEvent + 831) + 32i64)
&& !LODWORD(CurrentStackLocation->Parameters.SecurityContext) )
{
RootDevices = IopGetRootDevices(DeviceRelations);
goto LABEL_63;
}
if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) != 4 )
goto LABEL_19;
PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x10ui64, 1684303952i64);
v36 = PoolWithTag;
if( !PoolWithTag )
goto LABEL_77;
*(_DWORD *)PoolWithTag = 1;
PoolWithTag[1] = DeviceObject;
ObfReferenceObject(DeviceObject);
p_Count = (UINT64 *)v36;
LABEL_60:
RootDevices = 0;
goto LABEL_20;
}
RootDevices = Irp->IoStatus.Status;
if( DeviceObject )
v24 = DeviceObject->DeviceObjectExtension->DeviceNode;
else
v24 = 0i64;
if( v24 != (void *)*(&PnpReplaceEvent + 831) )
goto LABEL_20;
SecurityContext = (GUID *)CurrentStackLocation->Parameters.SecurityContext;
if( SecurityContext != &GUID_ARBITER_INTERFACE_STANDARD
&& RtlCompareMemory(SecurityContext, &GUID_ARBITER_INTERFACE_STANDARD, 16) != (_SIZE_T *)16 )
{
v26 = (GUID *)CurrentStackLocation->Parameters.SecurityContext;
if( v26 != &GUID_TRANSLATOR_INTERFACE_STANDARD
&& RtlCompareMemory(v26, &GUID_TRANSLATOR_INTERFACE_STANDARD, 16) != (_SIZE_T *)16 )
{
goto LABEL_20;
}
v27 = *(_QWORD *)&CurrentStackLocation->Parameters.FileAttributes;
*(_QWORD *)(v27 + 32) = IopTranslatorHandlerCm;
*(_QWORD *)(v27 + 40) = IopTranslatorHandlerIo;
goto LABEL_60;
}
v37 = *(_QWORD *)&CurrentStackLocation->Parameters.FileAttributes;
RootDevices = 0;
*(_QWORD *)(v37 + 32) = ArbArbiterHandler;
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) == 1 )
{
v38 = (char *)&PnpReplaceEvent + 4768;
goto LABEL_69;
}
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) == 2 )
{
v38 = (char *)&PnpReplaceEvent + 4064;
goto LABEL_69;
}
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) != 3 )
{
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) == 4 )
{
v38 = (char *)&PnpReplaceEvent + 4416;
LABEL_69:
*(_QWORD *)(v37 + 8) = v38;
goto LABEL_20;
}
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) == 6 )
{
v38 = (char *)&PnpReplaceEvent + 3712;
goto LABEL_69;
}
if( LOBYTE(CurrentStackLocation->Parameters.EaLength) != 7 )
{
RootDevices = -1073741811;
goto LABEL_20;
}
}
v38 = (char *)&PnpReplaceEvent + 5120;
goto LABEL_69;
}
v14 = MinorFunction - 9;
if( !v14 )
{
if( DeviceObject )
v15 = (const WCHAR **)DeviceObject->DeviceObjectExtension->DeviceNode;
else
v15 = 0i64;
v16 = CurrentStackLocation->Parameters.SecurityContext;
LODWORD(v16->SecurityQos) = 65600;
if( DeviceObject == *(PDEVICE_OBJECT *)(*(&PnpReplaceEvent + 831) + 32i64) )
{
HIDWORD(v16->SecurityQos) |= 0x1C0u;
HIDWORD(v16->AccessState) = 0;
}
si128 = _mm_load_si128((const __m128i *)&_xmm);
v16->DesiredAccess = 0;
v16->FullCreateOptions = 1;
*(__m128i *)&v16[1].SecurityQos = si128;
v16[1].DesiredAccess = _mm_cvtsi128_si32(si128);
if( HIDWORD(v16->AccessState) == -1 )
{
LODWORD(Flags) = 0;
LODWORD(BufferSize) = 4;
if( CmGetDeviceRegProp(
*(&stru_140CF2E80 + 607),
v15[6],
0i64,
17i64,
&CmRegPropType,
(UINT8 *)&PropertyBuffer,
&BufferSize,
Flags) >= 0
&& (_DWORD)CmRegPropType == 4
&& (_DWORD)BufferSize == 4 )
{
HIDWORD(v16->AccessState) = PropertyBuffer;
}
}
goto LABEL_9;
}
v20 = v14 - 1;
if( !v20 )
{
v50 = 0;
v51 = 4;
LABEL_127:
RootDevices = PnpGetDeviceResourcesFromRegistry(
(__int64)DeviceObject,
v50,
v51,
(VOID **)DeviceRelations,
(ULONG *)&BufferSize);
if( RootDevices == -1073741772 )
goto LABEL_9;
LABEL_63:
p_Count = (UINT64 *)&DeviceRelations[0]->Count;
goto LABEL_20;
}
v21 = v20 - 1;
if( !v21 )
{
v50 = 1;
v51 = 2;
goto LABEL_127;
}
v22 = v21 - 1;
if( !v22 )
{
if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) != 1 || Irp->IoStatus.Information )
goto LABEL_19;
if( DeviceObject )
v48 = (WCHAR **)DeviceObject->DeviceObjectExtension->DeviceNode;
else
v48 = 0i64;
PiGetDeviceRegProperty(v48[6], (UINT64)Irp, CM_REG_PROP_DEVICEDESC, (VOID *)0xE, 0i64);
if( (_DWORD)BufferSize )
{
p_Count = (UINT64 *)ExAllocatePoolWithTag(1ui64, (unsigned int)BufferSize, 1684303952i64);
if( p_Count )
{
RootDevices = PiGetDeviceRegProperty(v48[6], v49, CM_REG_PROP_DEVICEDESC, (VOID *)0xE, p_Count);
if( RootDevices < 0 )
{
if( RootDevices == -1073741275 )
RootDevices = -1073741772;
ExFreePoolWithTag(p_Count, 0);
p_Count = 0i64;
}
goto LABEL_20;
}
goto LABEL_77;
}
LABEL_78:
RootDevices = -1073741823;
goto LABEL_20;
}
v23 = v22 - 7;
if( v23 )
{
if( v23 == 3 )
goto LABEL_9;
LABEL_19:
p_Count = (UINT64 *)Irp->IoStatus.Information;
RootDevices = Irp->IoStatus.Status;
goto LABEL_20;
}
if( DeviceObject == *(PDEVICE_OBJECT *)(*(&PnpReplaceEvent + 831) + 32i64) )
goto LABEL_19;
RootDevices = Irp->IoStatus.Status;
if( RootDevices >= 0 )
{
if( Irp->IoStatus.Information )
goto LABEL_19;
}
if( DeviceObject )
v9 = (unsigned __int16 *)DeviceObject->DeviceObjectExtension->DeviceNode;
v28 = (int)CurrentStackLocation->Parameters.SecurityContext;
DeviceRelations[0] = (_DEVICE_RELATIONS *)v9;
if( v28 )
{
if( v28 <= 0 )
goto LABEL_96;
if( v28 <= 2 )
{
if( RootDevices == -1073741637 )
{
RootDevices = PiGetDeviceRegProperty(
*((WCHAR **)v9 + 6),
(UINT64)Irp,
CM_REG_PROP_UNUSED2,
(VOID *)((unsigned int)(v28 != 1) + 2),
0i64);
if( RootDevices == -1073741789 )
{
v30 = ExAllocatePoolWithTag(1ui64, (unsigned int)BufferSize, 1684303952i64);
if( v30 )
{
RootDevices = PiGetDeviceRegProperty(
*((WCHAR **)v9 + 6),
v29,
CM_REG_PROP_UNUSED2,
(VOID *)((unsigned int)(LODWORD(CurrentStackLocation->Parameters.SecurityContext) != 1) + 2),
(UINT64 *)v30);
v31 = v30;
if( RootDevices < 0 )
{
ExFreePoolWithTag(v30, 0);
}
else
{
v32 = BufferSize;
v33 = 0i64;
if( v30 < (VOID **)((char *)v30 + ((unsigned int)BufferSize & 0xFFFFFFFE)) )
{
do
{
v34 = *v31;
if( *v31 )
{
if( (unsigned __int16)(v34 - 32) > 0x5Fu || v34 == 44 )
{
*v31 = 63;
v32 = BufferSize;
}
}
else
{
if( v33 && v31 == v33 + 1 )
break;
v33 = v31;
}
++v31;
}
while( v31 < (_WORD *)((char *)v30 + (v32 & 0xFFFFFFFE)) );
}
p_Count = (UINT64 *)v30;
}
}
else
{
RootDevices = -1073741670;
}
}
if( RootDevices == -1073741275 )
{
p_Count = (UINT64 *)Irp->IoStatus.Information;
RootDevices = Irp->IoStatus.Status;
}
}
goto LABEL_20;
}
if( v28 != 3 )
{
if( v28 == 5 )
{
v40 = ExAllocatePoolWithTag(1ui64, 0x4Eui64, 1684303952i64);
if( v40 )
{
p_Count = (UINT64 *)v40;
wcscpy((wchar_t *)v40, L"{00000000-0000-0000-FFFF-FFFFFFFFFFFF}");
RootDevices = 0;
goto LABEL_20;
}
goto LABEL_77;
}
LABEL_96:
p_Count = (UINT64 *)Irp->IoStatus.Information;
goto LABEL_20;
}
}
v41 = ExAllocatePoolWithTag(1ui64, v9[20], 1684303952i64);
if( !v41 )
{
LABEL_77:
RootDevices = -1073741670;
goto LABEL_20;
}
v42 = 0;
memset(v41, 0i64, LOWORD(DeviceRelations[0][2].Objects[0]));
p_Count = (UINT64 *)v41;
RootDevices = 0;
v43 = *(_WORD **)&DeviceRelations[0][3].Count;
v44 = *v43;
if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) )
{
while( v44 )
{
if( v44 == 92 && ++v42 == 2 )
{
v45 = (char *)(v43 + 1);
v46 = *(_WORD *)v45;
if( *(_WORD *)v45 )
{
v47 = v45 - (char *)v41;
do
{
*(_WORD *)v41 = v46;
v41 = (VOID **)((char *)v41 + 2);
v46 = *(_WORD *)((char *)v41 + v47);
}
while( v46 );
}
break;
}
v44 = *++v43;
}
}
else
{
while( v44 )
{
if( v44 == 92 && ++v42 == 2 )
break;
*(_WORD *)v41 = v44;
v41 = (VOID **)((char *)v41 + 2);
v44 = *++v43;
}
}
LABEL_20:
IopPnPCompleteRequest(Irp, (unsigned int)RootDevices, (UINT64)p_Count);
return RootDevices;
}Referenced by:
No references.