IoRegisterPlugPlayNotification
NTSTATUS __stdcall IoRegisterPlugPlayNotification(
IO_NOTIFICATION_EVENT_CATEGORY EventCategory,
ULONG EventCategoryFlags,
PVOID EventCategoryData,
PDRIVER_OBJECT DriverObject,
PDRIVER_NOTIFICATION_CALLBACK_ROUTINE CallbackRoutine,
PVOID Context,
PVOID *NotificationEntry){
NTSTATUS result;
__int32 v11;
__int32 v12;
__int32 v13;
NTSTATUS restarted;
_GUID *PoolWithTag;
PCWSTR v16;
PCWSTR *v17;
_FAST_MUTEX *v18;
_GUID *v19;
__int64 *v20;
__int64 **v21;
__int128 v22;
WCHAR v23;
int v24;
WCHAR *v25;
const WCHAR *i;
_EJOB *CurrentServerSilo;
int SessionIdFromSymbolicName;
_GUID **v29;
struct _DMA_ADAPTER *v30;
ULONG v31;
PCWSTR SourceString;
struct _UNICODE_STRING DestinationString;
int v34;
GUID v35;
__int128 v36;
int v37;
UNICODE_STRING *SymbolicLinkName;
LODWORD(SourceString) = EventCategoryFlags;
*NotificationEntry = 0i64;
result = ObReferenceObjectByPointerWithTag(DriverObject, 0, IoDriverObjectType, 0, 0x4E706E50u);
if( result >= 0 )
{
v11 = EventCategory - 1;
if( v11 )
{
v12 = v11 - 1;
if( v12 )
{
v13 = v12 - 1;
if( v13 )
{
if( v13 != 1 )
{
restarted = -1073741585;
goto LABEL_33;
}
restarted = PiRegisterKernelSoftRestartNotification(
(INT64)DriverObject,
CallbackRoutine,
(INT64)Context,
(CHAR **)NotificationEntry);
goto LABEL_13;
}
SourceString = 0i64;
restarted = PnpGetRelatedTargetDevice((PFILE_OBJECT)EventCategoryData, &SourceString);
if( restarted < 0 )
goto LABEL_33;
PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x70ui64, 0x43706E50ui64);
if( PoolWithTag )
{
restarted = PnpInitializeNotifyEntry(
(__int64)PoolWithTag,
3,
(unsigned __int64)CallbackRoutine,
(__int64)Context,
(__int64)DriverObject,
(__int64)&PnpTargetDeviceNotifyLock);
if( restarted < 0 )
{
ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
v30 = (struct _DMA_ADAPTER *)*((_QWORD *)SourceString + 4);
}
else
{
v16 = SourceString;
*(_QWORD *)&PoolWithTag[5].Data1 = EventCategoryData;
*(_QWORD *)PoolWithTag[5].Data4 = *((_QWORD *)v16 + 4);
restarted = PnpDeferNotification((__int64)PoolWithTag);
if( restarted >= 0 )
{
KeAcquireGuardedMutex(&PnpTargetDeviceNotifyLock);
v17 = (PCWSTR *)*((_QWORD *)v16 + 60);
if( *v17 == v16 + 236 )
{
*(_QWORD *)&PoolWithTag->Data1 = v16 + 236;
v18 = &PnpTargetDeviceNotifyLock;
*(_QWORD *)PoolWithTag->Data4 = v17;
*v17 = (PCWSTR)PoolWithTag;
*((_QWORD *)v16 + 60) = PoolWithTag;
LABEL_11:
KeReleaseGuardedMutex(v18);
LABEL_12:
*NotificationEntry = PoolWithTag;
goto LABEL_13;
}
goto LABEL_47;
}
ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
v30 = (struct _DMA_ADAPTER *)*((_QWORD *)v16 + 4);
}
HalPutDmaAdapter(v30);
LABEL_13:
if( restarted >= 0 )
return restarted;
LABEL_33:
ObfDereferenceObjectWithTag(DriverObject, 0x4E706E50ui64);
return restarted;
}
HalPutDmaAdapter(*((PADAPTER_OBJECT *)SourceString + 4));
LABEL_38:
restarted = -1073741670;
goto LABEL_33;
}
PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x60ui64, 0x44706E50ui64);
if( !PoolWithTag )
goto LABEL_38;
restarted = PnpInitializeNotifyEntry(
(__int64)PoolWithTag,
2,
(unsigned __int64)CallbackRoutine,
(__int64)Context,
(__int64)DriverObject,
(__int64)&PnpDeviceClassNotifyLock);
if( restarted < 0 )
goto LABEL_33;
v19 = PoolWithTag + 5;
PoolWithTag[5] = *(_GUID *)EventCategoryData;
restarted = PnpDeferNotification((__int64)PoolWithTag);
if( restarted >= 0 )
{
KeAcquireGuardedMutex(&PnpDeviceClassNotifyLock);
v20 = &PnpDeviceClassNotifyList[2
* ((v19->Data1
+ *(_DWORD *)&PoolWithTag[5].Data2
+ *(_DWORD *)PoolWithTag[5].Data4
+ *(_DWORD *)&PoolWithTag[5].Data4[4])
% 0xD)];
v21 = (__int64 **)v20[1];
if( *v21 == v20 )
{
*(_QWORD *)&PoolWithTag->Data1 = v20;
*(_QWORD *)PoolWithTag->Data4 = v21;
*v21 = (__int64 *)PoolWithTag;
v20[1] = (__int64)PoolWithTag;
KeReleaseGuardedMutex(&PnpDeviceClassNotifyLock);
if( ((unsigned __int8)SourceString & 1) != 0 )
{
v22 = (__int128)*v19;
SourceString = 0i64;
DestinationString = 0i64;
v37 = 0;
v34 = 3145729;
v35 = GUID_DEVICE_INTERFACE_ARRIVAL;
v36 = v22;
IopGetDeviceInterfaces(PoolWithTag + 5, 0i64, 0i64, 0, (WCHAR **)&SourceString, 0i64);
restarted = v24;
if( v24 < 0 )
goto LABEL_33;
v25 = (WCHAR *)SourceString;
for( i = SourceString; *i; i += ((unsigned __int64)DestinationString.Length >> 1) + 1 )
{
LODWORD(SourceString) = 0;
RtlInitUnicodeString(&DestinationString, i, v23);
SymbolicLinkName = &DestinationString;
CurrentServerSilo = PsGetCurrentServerSilo();
if( *(_DWORD *)&PoolWithTag[1].Data2 != (unsigned int)PsGetServerSiloServiceSessionId(CurrentServerSilo) )
{
SessionIdFromSymbolicName = IopGetSessionIdFromSymbolicName(SymbolicLinkName);
if( SessionIdFromSymbolicName != -1 && *(_DWORD *)&PoolWithTag[1].Data2 != SessionIdFromSymbolicName )
continue;
}
PnpNotifyDriverCallback((__int64)PoolWithTag, (__int64)&v34, &SourceString);
}
ExFreePoolWithTag(v25, 0);
}
goto LABEL_12;
}
goto LABEL_47;
}
v31 = 1148218960;
}
else
{
PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x50ui64, 0x39706E50ui64);
if( !PoolWithTag )
goto LABEL_38;
restarted = PnpInitializeNotifyEntry(
(__int64)PoolWithTag,
1,
(unsigned __int64)CallbackRoutine,
(__int64)Context,
(__int64)DriverObject,
(__int64)&PnpHwProfileNotifyLock);
if( restarted < 0 )
goto LABEL_33;
restarted = PnpDeferNotification((__int64)PoolWithTag);
if( restarted >= 0 )
{
KeAcquireGuardedMutex(&PnpHwProfileNotifyLock);
v29 = (_GUID **)qword_140D2DB58;
if( *(PVOID **)qword_140D2DB58 == &PnpProfileNotifyList )
{
*(_QWORD *)&PoolWithTag->Data1 = &PnpProfileNotifyList;
v18 = &PnpHwProfileNotifyLock;
*(_QWORD *)PoolWithTag->Data4 = v29;
*v29 = PoolWithTag;
qword_140D2DB58 = (__int64)PoolWithTag;
goto LABEL_11;
}
LABEL_47:
__fastfail(3u);
}
v31 = 963669584;
}
ExFreePoolWithTag(PoolWithTag, v31);
goto LABEL_13;
}
return result;
}Referenced by:
HalpPostPnpInitialize
PoInitDriverServices
PopRegisterCoolingExtensionProtection
SbpWaitForVmbus
SmKmStoreFileCreate