PiDrvDbSetupNodeHive
INT64 __fastcall PiDrvDbSetupNodeHive(INT64 a1, WCHAR *a2, WCHAR a3){
char v4;
WCHAR v6;
WCHAR v7;
NTSTATUS v8;
WCHAR v9;
int appended;
unsigned __int16 i;
WCHAR v12;
WCHAR v13;
__int64 Length;
unsigned __int64 v15;
wchar_t *Buffer;
NTSTATUS v17;
struct _UNICODE_STRING Destination;
struct _UNICODE_STRING UnicodeString;
struct _UNICODE_STRING DestinationString;
UNICODE_STRING String1;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
void *KeyHandle;
KeyHandle = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
v4 = 0;
DestinationString = 0i64;
UnicodeString = 0i64;
Destination = 0i64;
String1 = 0i64;
RtlInitUnicodeString(&DestinationString, a2, a3);
RtlInitUnicodeString(&UnicodeString, 0i64, v6);
RtlInitUnicodeString(&Destination, 0i64, v7);
if( !wcsicmp(a2, L"SYSTEM") )
{
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)(a1 + 32);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v8 = ZwOpenKey(&KeyHandle, 0xF003Fu, &ObjectAttributes);
appended = v8;
LABEL_9:
if( v8 < 0 )
goto LABEL_38;
LABEL_34:
appended = PiDrvDbResolveNodeFilePaths(a1, (INT64)KeyHandle, v9);
if( appended >= 0 && (*(_DWORD *)(a1 + 64) & 8) != 0 )
appended = PiDrvDbOverlayNodeHive(a1, a2, KeyHandle);
goto LABEL_38;
}
if( (*(_DWORD *)(a1 + 64) & 8) == 0 )
{
Destination.Length = 0;
Destination.MaximumLength = DestinationString.Length + 38;
Destination.Buffer = (wchar_t *)ExpAllocateStringRoutine((unsigned __int16)(DestinationString.Length + 38));
if( !Destination.Buffer )
{
LABEL_5:
appended = -1073741670;
goto LABEL_38;
}
appended = RtlAppendUnicodeToString(&Destination, (PWCHAR)L"\\REGISTRY\\MACHINE\\");
if( appended < 0 )
goto LABEL_38;
appended = RtlAppendUnicodeStringToString(&Destination, &DestinationString);
if( appended < 0 )
goto LABEL_38;
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &Destination;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v8 = ZwOpenKey(&KeyHandle, 0xF003Fu, &ObjectAttributes);
appended = v8;
if( v8 != -1073741772 )
goto LABEL_9;
LABEL_37:
appended = 0;
goto LABEL_38;
}
if( !CmIsStateSeparationEnabled() )
goto LABEL_37;
UnicodeString.MaximumLength = DestinationString.Length + *(_WORD *)(a1 + 50);
UnicodeString.Length = 0;
UnicodeString.Buffer = (wchar_t *)ExpAllocateStringRoutine(UnicodeString.MaximumLength);
if( !UnicodeString.Buffer )
goto LABEL_5;
appended = RtlAppendUnicodeStringToString(&UnicodeString, (UNICODE_STRING *)(a1 + 48));
if( appended >= 0 )
{
for( i = UnicodeString.Length; i > 2u; UnicodeString.Length = i )
{
if( UnicodeString.Buffer[((unsigned __int64)i >> 1) - 1] == 92 )
break;
i -= 2;
}
appended = RtlAppendUnicodeStringToString(&UnicodeString, &DestinationString);
if( appended >= 0 )
{
Destination.MaximumLength = DestinationString.Length + *(_WORD *)(a1 + 34);
Destination.Length = 0;
Destination.Buffer = (wchar_t *)ExpAllocateStringRoutine(Destination.MaximumLength);
if( !Destination.Buffer )
goto LABEL_5;
appended = RtlAppendUnicodeStringToString(&Destination, (UNICODE_STRING *)(a1 + 32));
if( appended >= 0 )
{
RtlInitUnicodeString(&String1, L"DRIVERS", v12);
Length = String1.Length;
v15 = Destination.Length;
Buffer = Destination.Buffer;
if( Destination.Length > (unsigned __int64)String1.Length + 2
&& RtlSuffixUnicodeString(&String1, &Destination, 1u)
&& Buffer[(((unsigned __int64)(unsigned int)v15 - Length) >> 1) - 1] != 92
|| (RtlInitUnicodeString(&String1, L"SYSTEM", v13),
Length = String1.Length,
v15 > (unsigned __int64)String1.Length + 2)
&& RtlSuffixUnicodeString(&String1, &Destination, 1u)
&& Buffer[((v15 - Length) >> 1) - 1] != 92 )
{
Destination.Length = v15 - Length;
}
appended = RtlAppendUnicodeStringToString(&Destination, &DestinationString);
if( appended >= 0 )
{
v17 = PiDrvDbLoadHive(&Destination, &UnicodeString, (PVOID *)0x2000);
appended = v17;
if( v17 != -1073741772 )
{
if( v17 < 0 )
goto LABEL_38;
if( (*(_DWORD *)(a1 + 492) & 2) == 0 || wcsicmp(a2, L"SOFTWARE") )
v4 = 1;
else
PnpSetObjectProperty(
PiPnpRtlCtx,
*(_QWORD *)(a1 + 24),
7u,
*(_QWORD *)(a1 + 72),
0i64,
(__int64)DEVPKEY_DriverDatabase_SoftwareRegistryPath,
18,
(__int64)Destination.Buffer,
Destination.Length + 2,
0);
goto LABEL_34;
}
goto LABEL_37;
}
}
}
}
LABEL_38:
if( KeyHandle )
ZwClose(KeyHandle);
if( v4 )
PiDrvDbUnloadHive(&Destination, 0i64);
RtlFreeAnsiString(&UnicodeString);
RtlFreeAnsiString(&Destination);
return(unsigned int)appended;
}Referenced by:
PiDrvDbLoadNodeWorkerCallback
PiDrvDbSetupNodes