PiCreateDriverSwDeviceCallback
INT64 __fastcall PiCreateDriverSwDeviceCallback(INT64 a1, VOID *a2, WCHAR *a3, INT64 a4){
INT64 v4;
int v5;
wchar_t *v6;
KEY_VALUE_FULL_INFORMATION *v7;
unsigned int v8;
__int64 PoolWithTag;
__int64 v10;
int DeviceRegProp;
int v12;
WCHAR v13;
wchar_t *Buffer;
__int64 v15;
__int64 v16;
WCHAR v17;
WCHAR v18;
int v19;
int v20;
wchar_t *v21;
WCHAR **v22;
unsigned int v23;
int *v24;
int v25;
const wchar_t *v26;
__int64 v27;
NTSTATUS RegistryValue;
PCWSTR v30;
__int64 v31;
PVOID v32;
int v33;
__int64 v34;
signed int i;
unsigned int v36;
char *v37;
char *v38;
char *v39;
unsigned int v40;
__int64 v41;
__int64 v42;
int v43;
int v44;
void *v45;
VOID *v46;
void *v47;
PVOID *v48;
__int64 v49;
WCHAR *DeviceDescription;
DEVPROPERTY *Properties;
SIZE_T NumberOfBytes;
INT64 v53;
int v54;
KEY_VALUE_FULL_INFORMATION *Information;
wchar_t *Str1;
ULONG HashValue;
UINT64 DeviceIdsHash;
HANDLE Handle;
int v60;
int v61;
unsigned int v62;
_DWORD PropertyCount[3];
struct _UNICODE_STRING UnicodeString;
struct _UNICODE_STRING ContainerId;
UNICODE_STRING GuidString;
PVOID P;
UNICODE_STRING String2;
struct _UNICODE_STRING DestinationString;
UNICODE_STRING v70;
struct _UNICODE_STRING DeviceLocation;
struct _UNICODE_STRING SecurityDescriptor;
int v73[4];
PCWSTR SourceString;
__int64 v75;
UINT64 SecurityDescriptorSize;
__int64 v77[2];
GUID Guid;
INT64 result;
int v80;
const wchar_t *v81;
struct _UNICODE_STRING *p_UnicodeString;
int v83;
int v84;
const wchar_t *v85;
struct _UNICODE_STRING *p_ContainerId;
int v87;
int v88;
const wchar_t *v89;
UNICODE_STRING *p_GuidString;
int v91;
int v92;
const wchar_t *v93;
__int64 v94;
int v95;
int v96;
const WCHAR *v97;
struct _UNICODE_STRING *p_DeviceLocation;
int v99;
int v100;
const wchar_t *v101;
struct _UNICODE_STRING *p_SecurityDescriptor;
int v103;
v53 = a4;
v75 = a1;
v60 = 1;
SourceString = a3;
Handle = 0i64;
v4 = a4;
v5 = 0;
v61 = 0;
v6 = 0i64;
DeviceIdsHash = 0i64;
v7 = 0i64;
HashValue = 0;
v8 = 0;
Str1 = 0i64;
PoolWithTag = 0i64;
v54 = 0;
Information = 0i64;
SecurityDescriptorSize = 0i64;
memset(PropertyCount, 0, sizeof(PropertyCount));
P = 0i64;
v62 = 0;
LODWORD(NumberOfBytes) = 0;
UnicodeString = 0i64;
ContainerId = 0i64;
GuidString = 0i64;
Guid = 0i64;
DeviceLocation = 0i64;
SecurityDescriptor = 0i64;
String2 = 0i64;
DestinationString = 0i64;
v70 = 0i64;
if( a1 )
v10 = *(_QWORD *)(a1 + 224);
else
v10 = 0i64;
DeviceRegProp = SysCtxRegOpenKey(v10, (char *)a2, a3, 0, 0x20019u, &Handle);
if( DeviceRegProp >= 0 )
{
memset((INT64)&result, 0i64);
v95 = 0x4000000;
v80 = 304;
v83 = 117440512;
v81 = L"HardwareIds";
v84 = 304;
p_UnicodeString = &UnicodeString;
v87 = 117440512;
v85 = L"CompatibleIds";
v88 = 288;
p_ContainerId = &ContainerId;
v91 = 0x1000000;
v89 = L"ContainerId";
p_GuidString = &GuidString;
v93 = L"Capabilities";
v94 = (__int64)&DeviceIdsHash + 4;
v97 = L"Description";
p_DeviceLocation = &DeviceLocation;
v101 = L"LocationInfo";
v92 = 288;
v96 = 288;
v99 = 0x1000000;
v100 = 288;
v103 = 0x1000000;
p_SecurityDescriptor = &SecurityDescriptor;
LOBYTE(v12) = RtlpQueryRegistryValues((_KTRAP_FRAME *)0xC0000000i64, (_KEXCEPTION_FRAME *)Handle);
DeviceRegProp = v12;
if( v12 >= 0 )
{
if( UnicodeString.Buffer && UnicodeString.Length <= 2u )
RtlFreeAnsiString(&UnicodeString);
if( ContainerId.Buffer && ContainerId.Length <= 2u )
RtlFreeAnsiString(&ContainerId);
Buffer = GuidString.Buffer;
if( !GuidString.Buffer )
goto LABEL_17;
if( GuidString.Length < 2u )
{
RtlFreeAnsiString(&GuidString);
Buffer = GuidString.Buffer;
}
if( !Buffer || RtlGUIDFromString(&GuidString, &Guid) < 0 )
LABEL_17:
Guid = 0i64;
if( DeviceLocation.Buffer && DeviceLocation.Length < 2u )
RtlFreeAnsiString(&DeviceLocation);
if( SecurityDescriptor.Buffer && SecurityDescriptor.Length < 2u )
RtlFreeAnsiString(&SecurityDescriptor);
if( !UnicodeString.Buffer && !ContainerId.Buffer )
{
DeviceRegProp = -1073741637;
goto LABEL_77;
}
v15 = *(_QWORD *)v4;
v16 = -1i64;
v77[0] = (__int64)UnicodeString.Buffer;
v77[1] = (__int64)ContainerId.Buffer;
v73[0] = 2;
v73[1] = 3;
if( (PVOID)v15 != IopRootDeviceNode )
{
while( 1 )
{
if( *(PDRIVER_OBJECT *)(*(_QWORD *)(v15 + 32) + 8i64) == PiSwDeviceDriverObject )
{
RtlInitUnicodeString(&DestinationString, L"SWD\\", v13);
if( (unsigned __int8)RtlPrefixUnicodeString(&DestinationString, (INT64 *)(v15 + 40)) )
{
RtlInitUnicodeString(
&String2,
(PCWSTR)(*(_QWORD *)(v15 + 48) + 2 * ((unsigned __int64)DestinationString.Length >> 1)),
v13);
RtlInitUnicodeString(&DestinationString, L"DRIVERENUM", v17);
if( (unsigned __int8)RtlPrefixUnicodeString(&DestinationString, (INT64 *)&String2) )
{
if( String2.Buffer[(unsigned __int64)DestinationString.Length >> 1] == 92 )
{
if( !v5 )
{
DeviceRegProp = PnpGenerateDeviceIdsHash(UnicodeString.Buffer, ContainerId.Buffer, &DeviceIdsHash);
if( DeviceRegProp < 0 )
goto LABEL_142;
if( (DeviceIdsHash & 0x800000000i64) != 0 )
{
v19 = DeviceIdsHash;
}
else
{
RtlInitUnicodeString(&String2, L"SWD\\GenericRaw", v18);
DeviceRegProp = RtlHashUnicodeString(&String2, 1u, 0i64, (UINT64 *)&HashValue);
if( DeviceRegProp < 0 )
{
LABEL_142:
v7 = Information;
goto LABEL_76;
}
v19 = HashValue + DeviceIdsHash;
}
RtlInitUnicodeString(&String2, L"SWD\\Generic", v18);
DeviceRegProp = RtlHashUnicodeString(&String2, 1u, 0i64, (UINT64 *)&HashValue);
if( DeviceRegProp < 0 )
goto LABEL_44;
v5 = HashValue + v19;
v61 = v5;
LODWORD(DeviceIdsHash) = v5;
}
if( *(_DWORD *)(v15 + 684) == v5 )
{
if( v6 )
{
v20 = v54;
}
else
{
v20 = 2048;
v54 = 2048;
Str1 = (wchar_t *)ExAllocatePoolWithTag(PagedPool, 0x800ui64, 0x20207050ui64);
v6 = Str1;
if( !Str1 )
{
DeviceRegProp = -1073741670;
goto LABEL_44;
}
}
v21 = Str1;
v22 = (WCHAR **)v77;
v23 = 0;
v24 = v73;
do
{
v25 = *v24;
LODWORD(NumberOfBytes) = v20;
DeviceRegProp = CmGetDeviceRegProp(
PiPnpRtlCtx,
*(const wchar_t **)(v15 + 48),
0i64,
v25,
(__int64)&v60,
(__int64)v21,
(__int64)&NumberOfBytes,
0);
if( DeviceRegProp < 0 || v60 != 7 || (unsigned int)NumberOfBytes < 2 )
{
*v21 = 0;
DeviceRegProp = 0;
}
if( v23 == 1 )
{
v26 = v21;
if( *v21 )
{
while( wcsicmp(v26, L"SWD\\GenericRaw") && wcsicmp(v26, L"SWD\\Generic") )
{
v27 = -1i64;
do
++v27;
while( v26[v27] );
v26 += v27 + 1;
if( !*v26 )
goto LABEL_60;
}
*v26 = 0;
}
LABEL_60:
v20 = v54;
}
if( *v22 )
{
if( !PnpCompareMultiSz(*v22, v21) )
break;
}
else if( *v21 )
{
break;
}
++v23;
++v24;
++v22;
}
while( v23 < 2 );
v5 = v61;
if( v23 >= 2 )
{
DeviceRegProp = -1073740028;
LABEL_71:
v8 = v62;
v16 = -1i64;
PoolWithTag = v62;
break;
}
v6 = Str1;
}
}
}
}
}
v15 = *(_QWORD *)(v15 + 16);
if( (PVOID)v15 == IopRootDeviceNode )
goto LABEL_71;
}
}
if( DeviceRegProp >= 0 )
{
RegistryValue = IopGetRegistryValue(Handle, (PWCHAR)L"Security", 0i64, &Information);
v7 = Information;
DeviceRegProp = RegistryValue;
if( RegistryValue >= 0 )
{
if( Information->Type != 3 || (PropertyCount[0] = Information->DataLength, PropertyCount[0] < 0x28u) )
{
DeviceRegProp = -1073741823;
goto LABEL_130;
}
SecurityDescriptorSize = (UINT64)Information + Information->DataOffset;
}
else if( RegistryValue != -1073741772 )
{
LABEL_75:
v6 = Str1;
goto LABEL_76;
}
if( *(PVOID *)v53 == IopRootDeviceNode )
{
if( !RtlCreateUnicodeString(&v70, (PWCHAR)SourceString) )
goto LABEL_98;
}
else
{
DeviceRegProp = PipMakeGloballyUniqueId();
if( DeviceRegProp < 0 )
goto LABEL_75;
v30 = SourceString;
v31 = -1i64;
do
++v31;
while( SourceString[v31] );
v32 = P;
do
++v16;
while( *((_WORD *)P + v16) );
v70.MaximumLength = 2 * (v16 + v31 + 2);
v70.Buffer = (wchar_t *)ExpAllocateStringRoutine((unsigned __int16)(2 * (v16 + v31) + 4));
if( !v70.Buffer )
{
LABEL_98:
DeviceRegProp = -1073741670;
goto LABEL_75;
}
RtlUnicodeStringPrintf(&v70, L"%ws&%ws", v30, v32);
DeviceRegProp = v33;
if( v33 < 0 )
goto LABEL_75;
}
v34 = v75;
for( i = PnpGetGenericStorePropertyKeys(v75, (char *)Handle, 0i64, 0, 0i64, 0, (unsigned int *)&NumberOfBytes);
;
i = PnpGetGenericStorePropertyKeys(
v34,
(char *)Handle,
0i64,
0,
PoolWithTag,
v8,
(unsigned int *)&NumberOfBytes) )
{
DeviceRegProp = i;
if( i != -1073741789 )
{
v8 = NumberOfBytes;
goto LABEL_110;
}
v36 = NumberOfBytes;
if( (unsigned int)NumberOfBytes <= v8 )
{
DeviceRegProp = -1073741595;
goto LABEL_138;
}
if( PoolWithTag )
{
ExFreePoolWithTag((PVOID)PoolWithTag, 0);
v36 = NumberOfBytes;
}
v8 = v36;
PoolWithTag = (__int64)ExAllocatePoolWithTag(PagedPool, 20i64 * v36, 0x20207050ui64);
if( !PoolWithTag )
break;
}
DeviceRegProp = -1073741670;
LABEL_110:
if( DeviceRegProp < 0 )
goto LABEL_138;
if( v8 )
{
v37 = (char *)ExAllocatePoolWithTag(PagedPool, 48i64 * v8, 0x20207050ui64);
*(_QWORD *)&PropertyCount[1] = v37;
v38 = v37;
if( !v37 )
{
DeviceRegProp = -1073741670;
goto LABEL_138;
}
memset((INT64)v37, 0i64);
v39 = v38 + 36;
v40 = 0;
v41 = PoolWithTag;
do
{
v42 = *(_QWORD *)(v39 + 4);
*(_OWORD *)(v39 - 36) = *(_OWORD *)v41;
v43 = *(_DWORD *)(v41 + 16);
*((_DWORD *)v39 - 4) = 0;
*((_DWORD *)v39 - 5) = v43;
while( 1 )
{
DeviceRegProp = PnpGetGenericStoreProperty(
v75,
(char *)Handle,
0i64,
PoolWithTag + 20i64 * v40,
(_DWORD *)v39 - 1,
v42,
*(_DWORD *)v39,
&NumberOfBytes);
v44 = NumberOfBytes;
if( DeviceRegProp != -1073741789 )
break;
if( (unsigned int)NumberOfBytes <= *(_DWORD *)v39 )
{
DeviceRegProp = -1073741595;
goto LABEL_130;
}
v45 = *(void **)(v39 + 4);
if( v45 )
{
ExFreePoolWithTag(v45, 0);
v44 = NumberOfBytes;
}
*(_DWORD *)v39 = v44;
v46 = ExAllocatePoolWithTag(PagedPool, (unsigned int)NumberOfBytes, 0x20207050ui64);
*(_QWORD *)(v39 + 4) = v46;
v42 = (__int64)v46;
if( !v46 )
{
DeviceRegProp = -1073741670;
goto LABEL_125;
}
}
*(_DWORD *)v39 = NumberOfBytes;
LABEL_125:
if( DeviceRegProp < 0 )
goto LABEL_130;
++v40;
v39 += 48;
v41 += 20i64;
}
while( v40 < v8 );
}
LODWORD(Properties) = PropertyCount[0];
LODWORD(DeviceDescription) = HIDWORD(DeviceIdsHash);
DeviceRegProp = PiSwStartCreate(
(WCHAR *)((unsigned __int64)&Guid & -(__int64)(GuidString.Buffer != 0i64)),
*(WCHAR **)(*(_QWORD *)v53 + 48i64),
v70.Buffer,
UnicodeString.Buffer,
(GUID *)ContainerId.Buffer,
(unsigned __int64)&Guid & -(__int64)(GuidString.Buffer != 0i64),
DeviceDescription,
DeviceLocation.Buffer,
SecurityDescriptor.Buffer,
SecurityDescriptorSize,
Properties,
*(UINT64 *)&PropertyCount[1]);
LABEL_130:
v47 = *(void **)&PropertyCount[1];
if( *(_QWORD *)&PropertyCount[1] )
{
if( v8 )
{
v48 = (PVOID *)(*(_QWORD *)&PropertyCount[1] + 40i64);
v49 = v8;
do
{
if( *v48 )
ExFreePoolWithTag(*v48, 0);
v48 += 6;
--v49;
}
while( v49 );
v47 = *(void **)&PropertyCount[1];
}
ExFreePoolWithTag(v47, 0);
}
LABEL_138:
if( PoolWithTag )
ExFreePoolWithTag((PVOID)PoolWithTag, 0);
v7 = Information;
goto LABEL_75;
}
v6 = Str1;
LABEL_44:
v7 = Information;
LABEL_76:
v4 = v53;
}
}
LABEL_77:
RtlFreeAnsiString(&v70);
if( P )
ExFreePoolWithTag(P, 0);
RtlFreeAnsiString(&UnicodeString);
RtlFreeAnsiString(&ContainerId);
RtlFreeAnsiString(&GuidString);
RtlFreeAnsiString(&DeviceLocation);
RtlFreeAnsiString(&SecurityDescriptor);
if( v7 )
ExFreePoolWithTag(v7, 0);
if( v6 )
ExFreePoolWithTag(v6, 0);
if( Handle )
ZwClose(Handle);
if( *(int *)(v4 + 8) >= 0 )
*(_DWORD *)(v4 + 8) = DeviceRegProp;
return 0i64;
}Referenced by:
No references.