NtQueryBootOptions

INT64 __fastcall NtQueryBootOptions(_BOOT_OPTIONS *BootOptions, UINT64 *BootOptionsLength){
  __int64 v5; 
  unsigned int v6; 
  unsigned int v7; 
  _ETHREAD *v8; 
  unsigned int EnvironmentVariable; 
  int v10; 
  unsigned int v11; 
  unsigned int v12; 
  UINT64 ValueLength; 
  ULONG Value; 
  ULONG v15; 
  unsigned int v16; 
  _ETHREAD *CurrentThread; 
  INT8 PreviousMode; 
  HIDWORD(ValueLength) = 0;
  Value = 0;
  v15 = 0;
  if( dword_140C19650 != 2 )
    return 3221225474i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  PreviousMode = *((_BYTE *)CurrentThread + 562);
  if( PreviousMode )
  {
    v5 = 0x7FFFFFFF0000i64;
    if( (unsigned __int64)BootOptionsLength < 0x7FFFFFFF0000i64 )
      v5 = (__int64)BootOptionsLength;
    *(_DWORD *)v5 = *(_DWORD *)v5;
    v6 = BootOptions != 0i64 ? *(_DWORD *)BootOptionsLength : 0;
    v16 = v6;
    if( v6 )
      ProbeForWrite(BootOptions, v6, 4ui64);
    if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemEnvironmentPrivilege, PreviousMode) )
      return 3221225569i64;
  }
  else
  {
    v6 = BootOptions != 0i64 ? *(_DWORD *)BootOptionsLength : 0;
    v16 = v6;
  }
  if( v6 >= 0x16 )
  {
    v8 = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)v8 + 242);
    ExAcquireFastMutexUnsafe(&ExpEnvironmentLock);
    LODWORD(ValueLength) = 4;
    EnvironmentVariable = IoGetEnvironmentVariableEx(
                            (WCHAR *)L"Timeout",
                            (GUID *)&EfiBootVariablesGuid,
                            (char *)&ValueLength + 4,
                            &ValueLength,
                            0i64);
    v7 = EnvironmentVariable;
    if( EnvironmentVariable == -1073741789 )
    {
      HIDWORD(ValueLength) = -2;
LABEL_24:
      LODWORD(ValueLength) = 4;
      v11 = IoGetEnvironmentVariableEx(
              (WCHAR *)L"BootCurrent",
              (GUID *)&EfiBootVariablesGuid,
              &Value,
              &ValueLength,
              0i64);
      v7 = v11;
      if( v11 == -1073741789 || v11 == -1073741568 )
      {
        Value = -2;
LABEL_30:
        LODWORD(ValueLength) = 2;
        v12 = IoGetEnvironmentVariableEx((WCHAR *)L"BootNext", (GUID *)&EfiBootVariablesGuid, &v15, &ValueLength, 0i64);
        v7 = v12;
        if( v12 == -1073741789 || v12 == -1073741568 )
        {
          v15 = -2;
          v7 = 0;
        }
        else if( !v12 && (unsigned int)ValueLength > 2 )
        {
          v15 = (unsigned __int16)v15;
        }
        goto LABEL_36;
      }
      if( !v11 )
      {
        if( (unsigned int)ValueLength > 2 )
          Value = (unsigned __int16)Value;
        goto LABEL_30;
      }
LABEL_36:
      ExReleaseFastMutexUnsafe(&ExpEnvironmentLock);
      KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
      goto LABEL_37;
    }
    if( EnvironmentVariable != -1073741568 )
    {
      if( EnvironmentVariable )
        goto LABEL_36;
      if( (unsigned int)ValueLength <= 2 )
      {
LABEL_21:
        if( HIDWORD(ValueLength) != 0xFFFF )
          goto LABEL_24;
        goto LABEL_22;
      }
      v10 = HIDWORD(ValueLength);
      if( HIDWORD(ValueLength) != -1 )
      {
        if( HIDWORD(ValueLength) > 0xFFFE )
          v10 = 65534;
        HIDWORD(ValueLength) = v10;
        goto LABEL_21;
      }
    }
LABEL_22:
    HIDWORD(ValueLength) = -1;
    goto LABEL_24;
  }
  v7 = -1073741789;
LABEL_37:
  if( !v7 )
  {
    if( BootOptions )
    {
      BootOptions->Version = 1;
      BootOptions->Length = 22;
      BootOptions->Timeout = HIDWORD(ValueLength);
      BootOptions->CurrentBootEntryId = Value;
      BootOptions->NextBootEntryId = v15;
      BootOptions->HeadlessRedirection[0] = 0;
    }
  }
  *(_DWORD *)BootOptionsLength = 22;
  return v7;
}

Referenced by:

No references.