AlpcpQueryHandleInformationMessage

INT64 __fastcall AlpcpQueryHandleInformationMessage(
        _ALPC_PORT *OwnerPort,
        _KALPC_MESSAGE *Message,
        VOID *MessageInformation,
        UINT64 Length,
        UINT64 *ReturnLength){
  unsigned int v7; 
  __int64 v8; 
  char v9; 
  INT64 v10; 
  _EPROCESS *v11; 
  _OB_DUPLICATE_OBJECT_STATE *v12; 
  int v13; 
  void *TargetHandle[3]; 
  __int128 v16; 
  int GrantedAccess[6]; 
  TargetHandle[0] = 0i64;
  *(_QWORD *)&v16 = 0i64;
  GrantedAccess[0] = 0;
  if( (_DWORD)Length != 20 )
    return 3221225476i64;
  v7 = *(_DWORD *)MessageInformation;
  LODWORD(v16) = *(_DWORD *)MessageInformation;
  v8 = *((_QWORD *)Message + 19);
  if( !v8 || v7 >= *(_DWORD *)(v8 + 4) )
    return 3221225480i64;
  v9 = *((_BYTE *)KeGetCurrentThread() + 562);
  v10 = 48i64 * (unsigned int)v16;
  if( (*(_DWORD *)(v10 + v8) & *((_DWORD *)OwnerPort + 80)) == 0 )
    return 3221225508i64;
  v11 = 0i64;
  if( (*((_QWORD *)OwnerPort + 3) & 1) == 0 )
    v11 = (_EPROCESS *)*((_QWORD *)OwnerPort + 3);
  if( !v11 )
    return 3221225506i64;
  HIDWORD(v16) = *(_DWORD *)(v10 + v8);
  v12 = (_OB_DUPLICATE_OBJECT_STATE *)(v10 + v8 + 8);
  LOBYTE(v10) = v9;
  v13 = ObCompleteObjectDuplication(v12, v11, v10, TargetHandle, (UINT *)GrantedAccess);
  DWORD2(v16) = TargetHandle[0];
  if( v13 >= 0 )
  {
    *(_OWORD *)MessageInformation = v16;
    *((_DWORD *)MessageInformation + 4) = GrantedAccess[0];
    if( ReturnLength )
      *(_DWORD *)ReturnLength = 20;
  }
  return(unsigned int)v13;
}

Referenced by:

NtAlpcQueryInformationMessage