IoRegisterFsRegistrationChangeMountAware
NTSTATUS __stdcall IoRegisterFsRegistrationChangeMountAware(
PDRIVER_OBJECT DriverObject,
PDRIVER_FS_NOTIFICATION DriverNotificationRoutine,
BOOLEAN SynchronizeWithMounts){
NTSTATUS result;
_ETHREAD *CurrentThread;
NTSTATUS v8;
_QWORD *PoolWithTag;
_QWORD *v10;
BOOL v11;
BOOL v12;
BOOL v13;
EVENT_DESCRIPTOR *v14;
UINT64 v15;
int Length;
GUID *ActivityIdThread;
UINT64 v18;
UINT8 v19;
UINT8 v20;
IRP *UserData;
__int16 v22;
EVENT_DATA_DESCRIPTOR v23;
wchar_t *Buffer;
int v25;
int v26;
if( IopBlockLegacyFsFilters && !IopIsKnownGoodLegacyFsFilter(&DriverObject->DriverName) )
{
v15 = IoMgrTraceHandle;
if( EtwEventEnabled(IoMgrTraceHandle, (EVENT_DESCRIPTOR *)&IoMgr_LegacyFsFilterBlockedByPolicy, v14) )
{
Length = DriverObject->DriverName.Length;
v23.Reserved = 0;
v26 = 0;
v22 = (unsigned __int16)Length >> 1;
v23.Ptr = (unsigned __int64)&v22;
Buffer = DriverObject->DriverName.Buffer;
v23.Size = 2;
v25 = Length;
ActivityIdThread = (GUID *)IoGetActivityIdThread();
EtwWrite(v15, (EVENT_DESCRIPTOR *)&IoMgr_LegacyFsFilterBlockedByPolicy, ActivityIdThread, 2ui64, &v23);
}
return -1073741637;
}
result = FsRtlSetDriverBacking();
if( result < 0 )
return result;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
if( !SynchronizeWithMounts )
{
LABEL_22:
ExAcquireResourceExclusiveLite(&IopDatabaseResource, 1u);
goto LABEL_5;
}
if( !ExAcquireResourceExclusiveLite(&IopDatabaseResource, 0) )
{
if( IopGetFsRegistrationInProgress() )
{
v8 = -1073741267;
goto LABEL_9;
}
goto LABEL_22;
}
LABEL_5:
if( *(PRESOURCELIST(__stdcall **)(UINT32, INTERRUPTSYNCMODE))IopFsNotifyChangeQueueHead != IopFsNotifyChangeQueueHead
&& *(PDRIVER_OBJECT *)(qword_140C45968 + 16) == DriverObject
&& *(PDRIVER_FS_NOTIFICATION *)(qword_140C45968 + 24) == DriverNotificationRoutine )
{
ExReleaseResourceLite(&IopDatabaseResource);
v8 = -1073741768;
LABEL_9:
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return v8;
}
PoolWithTag = ExAllocatePoolWithTag(PagedPool, 0x20ui64, 0x73466F49ui64);
if( !PoolWithTag )
{
ExReleaseResourceLite(&IopDatabaseResource);
v8 = -1073741670;
goto LABEL_9;
}
PoolWithTag[2] = DriverObject;
PoolWithTag[3] = DriverNotificationRoutine;
v10 = (_QWORD *)qword_140C45968;
if( *(PRESOURCELIST(__stdcall **)(UINT32, INTERRUPTSYNCMODE))qword_140C45968 != IopFsNotifyChangeQueueHead )
__fastfail(3u);
*PoolWithTag = IopFsNotifyChangeQueueHead;
PoolWithTag[1] = v10;
*v10 = PoolWithTag;
qword_140C45968 = (__int64)PoolWithTag;
if( SynchronizeWithMounts == 1 )
{
while( IopMountsInProgress )
{
++IopMountCompletionWaiters;
ExReleaseResourceLite(&IopDatabaseResource);
KeWaitForSingleObject(&IopMountCompletionEvent, Executive, 0, 0, 0i64);
ExAcquireResourceExclusiveLite(&IopDatabaseResource, 1u);
if( --IopMountCompletionWaiters )
{
if( !IopMountsInProgress )
break;
}
KeResetEvent(&IopMountCompletionEvent, v18, v19, v20, UserData);
}
}
IopNotifyAlreadyRegisteredFileSystems(&IopNetworkFileSystemQueueHead, DriverNotificationRoutine, 0);
LOBYTE(v11) = 1;
IopNotifyAlreadyRegisteredFileSystems((PLIST_ENTRY)IopCdRomFileSystemQueueHead, DriverNotificationRoutine, v11);
LOBYTE(v12) = 1;
IopNotifyAlreadyRegisteredFileSystems(&IopDiskFileSystemQueueHead, DriverNotificationRoutine, v12);
LOBYTE(v13) = 1;
IopNotifyAlreadyRegisteredFileSystems(&IopTapeFileSystemQueueHead, DriverNotificationRoutine, v13);
ExReleaseResourceLite(&IopDatabaseResource);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
ObfReferenceObject(DriverObject);
return 0;
}Referenced by:
IoRegisterFsRegistrationChange