PiCMOpenObjectKey

NTSTATUS __stdcall PiCMOpenObjectKey(
        PVOID IoctlInputBuffer,
        UINT64 IoctlInputBufferSize,
        PVOID IoctlOutputBuffer,
        UINT64 IoctlOutputBufferSize,
        UINT64 *BytesUsed){
  unsigned int v5; 
  INT8 v7; 
  int v8; 
  unsigned int v9; 
  int v10; 
  UINT64 v11; 
  int v12; 
  __int64 v14; 
  HANDLE *IoctlOutputBufferSizea; 
  __int64 v16; 
  __int64 v17; 
  HANDLE Handle; 
  HANDLE v19; 
  INT64 a4[2]; 
  UINT64 *DesiredAccess[2]; 
  unsigned int ExpectedOutputSize[4]; 
  unsigned int *v23; 
  v19 = 0i64;
  Handle = 0i64;
  v5 = IoctlOutputBufferSize;
  *(_OWORD *)a4 = 0i64;
  *v23 = 0;
  *(_OWORD *)DesiredAccess = 0i64;
  *(_OWORD *)ExpectedOutputSize = 0i64;
  v7 = *((_BYTE *)KeGetCurrentThread() + 562);
  v8 = PiCMCaptureRegistryInputData(IoctlInputBuffer, IoctlInputBufferSize, (unsigned int)BytesUsed, (INT64)a4);
  if( v8 < 0 )
    goto LABEL_21;
  if( !DesiredAccess[0] || HIDWORD(a4[0]) || ExpectedOutputSize[1] || !IoctlOutputBuffer || v5 < 0x10 )
    goto LABEL_48;
  v9 = 0;
  if( SLODWORD(a4[1]) <= 6 )
  {
    switch( LODWORD(a4[1]) )
    {
      case 6:
        v9 = 6;
        goto LABEL_45;
      case 1:
        v9 = 1;
LABEL_46:
        v8 = -1073741637;
        goto LABEL_14;
      case 2:
        v9 = 2;
        goto LABEL_14;
      case 3:
        v9 = 4;
        goto LABEL_14;
      case 4:
        v9 = 3;
        goto LABEL_45;
      case 5:
        v9 = 5;
        goto LABEL_45;
    }
  }
  else
  {
    switch( LODWORD(a4[1]) )
    {
      case 0x10001:
        v10 = 7;
        goto LABEL_11;
      case 0x10002:
        v10 = 8;
LABEL_11:
        v9 = PiDrvDbCtx != 0 ? v10 : 0;
        break;
      case 0x10003:
        v10 = 9;
        goto LABEL_11;
      case 0x10004:
        v10 = 10;
        goto LABEL_11;
      case 0x10005:
        v10 = 11;
        goto LABEL_11;
    }
  }
  if( !v9 )
  {
LABEL_48:
    v8 = -1073741811;
    goto LABEL_18;
  }
  if( v9 > 6 || v9 <= 4 )
    goto LABEL_14;
LABEL_45:
  if( ExpectedOutputSize[0] == 1 )
    goto LABEL_46;
LABEL_14:
  if( v8 >= 0 )
  {
    v8 = PnpOpenObjectRegKey(
           PiPnpRtlCtx,
           (__int64)DesiredAccess[0],
           v9,
           SHIDWORD(DesiredAccess[1]),
           0,
           (__int64)&Handle);
    if( v8 != -1073741772 )
      goto LABEL_16;
    if( ExpectedOutputSize[0] == 1 )
    {
      if( PiAuDoesClientHaveAccess(2ui64) )
      {
        v8 = PnpCreateObject(v14, (__int64)DesiredAccess[0], v9, SHIDWORD(DesiredAccess[1]), &Handle);
LABEL_16:
        if( v8 >= 0 )
        {
          IoctlOutputBufferSizea = &v19;
          PiCMDuplicateRegistryHandle(Handle, v11, (UINT64 *)HIDWORD(DesiredAccess[1]), v7);
          v8 = v12;
        }
        goto LABEL_18;
      }
      v8 = -1073741790;
    }
  }
LABEL_18:
  LODWORD(IoctlOutputBufferSizea) = v5;
  v8 = PiCMReturnHandleResultData(
         v8,
         v19,
         ExpectedOutputSize[2],
         IoctlOutputBuffer,
         (__int64)IoctlOutputBufferSizea,
         v23,
         v16,
         v17);
  if( Handle )
    ZwClose(Handle);
  if( v8 < 0 && v19 )
    ObCloseHandle(v19, v7);
LABEL_21:
  PiCMReleaseRegistryInputData((INT64)a4);
  return v8;
}

Referenced by:

No references.