CmpParseKey

NTSTATUS __stdcall CmpParseKey(
        PVOID ParseObject,
        PVOID ObjectType,
        ACCESS_STATE *AccessState,
        INT8 AccessMode,
        UINT64 Attributes,
        UNICODE_STRING *CompleteName,
        UNICODE_STRING *RemainingName,
        PVOID Context,
        SECURITY_QUALITY_OF_SERVICE *SecurityQos,
        PVOID *Object){
  __int64 v10; 
  SLIST_ENTRY *v11; 
  char *v12; 
  ACCESS_STATE *v13; 
  UNICODE_STRING v14; 
  PPRIVILEGE_SET v15; 
  PVOID *v16; 
  unsigned __int16 Length; 
  wchar_t *Buffer; 
  unsigned __int16 MaximumLength; 
  int v20; 
  _ETHREAD *CurrentThread; 
  UNICODE_STRING *v22; 
  __int64 v23; 
  int v24; 
  NTSTATUS v25; 
  unsigned int i; 
  NTSTATUS v27; 
  UINT8 *v28; 
  ACCESS_STATE *v29; 
  SLIST_ENTRY *v30; 
  int v31; 
  SLIST_ENTRY *v33; 
  bool v34; 
  struct _PRIVILEGE_SET *v35; 
  __int64 v36; 
  int v37; 
  UNICODE_STRING v38; 
  PADAPTER_OBJECT v39; 
  INT64 a5[2]; 
  char *v41; 
  INT64 v42[2]; 
  PPRIVILEGE_SET Privileges; 
  __int16 v44[2]; 
  int v45; 
  __int64 v46; 
  SLIST_ENTRY *Argument[2]; 
  __int128 v48; 
  __int128 v49; 
  __int128 v50; 
  __int128 v51; 
  __int128 v52; 
  __int128 v53; 
  __int128 v54; 
  __int64 v55; 
  __int128 a6; 
  char v57; 
  UINT64 RetryCount; 
  ACCESS_STATE *v59; 
  unsigned __int8 v60; 
  _QWORD *v61; 
  v60 = AccessMode;
  v59 = AccessState;
  v10 = (__int64)v61;
  v11 = (SLIST_ENTRY *)ParseObject;
  v12 = (char *)Context;
  a6 = 0i64;
  v13 = AccessState;
  v57 = 0;
  v14 = *RemainingName;
  *v61 = 0i64;
  v15 = 0i64;
  v55 = 0i64;
  v41 = 0i64;
  v42[1] = (INT64)v42;
  v38 = v14;
  v42[0] = (INT64)v42;
  v39 = 0i64;
  Privileges = 0i64;
  *(_OWORD *)Argument = 0i64;
  LODWORD(RemainingName) = 0;
  v48 = 0i64;
  LODWORD(RetryCount) = 0;
  v49 = 0i64;
  v50 = 0i64;
  v51 = 0i64;
  v52 = 0i64;
  v53 = 0i64;
  v54 = 0i64;
  *(_OWORD *)a5 = 0i64;
  if( ObjectType != CmKeyObjectType )
    return -1073741788;
  v16 = Object;
  if( ParseObject == CmpRegistryRootObject )
  {
    LODWORD(v33) = CmpGetRegistryNamespaceRootForSilo((_EJOB *)Object[1]);
    v11 = v33;
  }
  Length = v38.Length;
  if( v38.Length )
  {
    Buffer = v38.Buffer;
    while( v38.Buffer[((unsigned __int64)Length >> 1) - 1] == 92 )
    {
      v34 = Length == 2;
      Length -= 2;
      v38.Length = Length;
      if( v34 )
        goto LABEL_10;
    }
    if( Length )
    {
      MaximumLength = v38.MaximumLength;
      do
      {
        if( *Buffer != 92 )
          break;
        ++Buffer;
        Length -= 2;
        MaximumLength -= 2;
        v38.Buffer = Buffer;
        v38.Length = Length;
        v38.MaximumLength = MaximumLength;
      }
      while( Length );
    }
  }
LABEL_10:
  if( !v12 )
  {
    CmpAllocateTransientPoolWithTag((_HHIVE *)1, 0x128ui64, 0x34364D43ui64, (_CHILD_LIST *)AccessMode);
    Privileges = v35;
    v15 = v35;
    if( !v35 )
      return -1073741670;
    memset((INT64)v35, 0i64);
    v15[4].Privilege[0].Attributes = -1;
    *(_QWORD *)&v15[7].Privilege[0].Luid.HighPart = (char *)v15 + 144;
    *(_QWORD *)&v15[7].Control = (char *)v15 + 144;
    memset((INT64)&v15[10].Privilege[0].Attributes, 0i64);
    v12 = (char *)v15;
  }
  v20 = *((_DWORD *)v16 + 1) & (__int64)v11[6].Next;
  *((_DWORD *)v12 + 24) = v20;
  if( CmpDoesParseEnterRegistryA((__int64)v11, (__int64)&v38) && (*(_DWORD *)v12 & 0x40) == 0 )
  {
    v25 = -1073741790;
    goto LABEL_38;
  }
  if( (*(_DWORD *)v12 & 0x800) != 0 && !CmpDoesParseEnterRegistryA((__int64)v11, (__int64)&v38) )
  {
    v25 = -1073741790;
    goto LABEL_38;
  }
  if( ((__int64)v11[3].Next & 0x10) != 0 )
    *((_DWORD *)v12 + 6) |= 0x10u;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  v22 = CompleteName;
  if( !CmpCallBackCount || ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
    goto LABEL_23;
  *((_QWORD *)&v53 + 1) = 1i64;
  DWORD2(v54) = *((_DWORD *)v12 + 7);
  HIDWORD(v54) = Attributes;
  *(_QWORD *)&v54 = &v38;
  LOBYTE(v55) = v60;
  DWORD2(v48) = *((_DWORD *)v12 + 6);
  *(_QWORD *)&v48 = CmKeyObjectType;
  DWORD2(v50) = *((_DWORD *)v13 + 4);
  Argument[0] = (SLIST_ENTRY *)v22;
  Argument[1] = v11;
  *((_QWORD *)&v51 + 1) = v10;
  v23 = *((_QWORD *)v12 + 9);
  if( (v23 & 1) != 0 )
    v23 = 0i64;
  *(_QWORD *)&v53 = v23;
  a5[0] = (INT64)Argument;
  LODWORD(a5[1]) = *((_DWORD *)v12 + 24);
  v41 = v12 + 144;
  if( (*(_DWORD *)v12 & 1) != 0 )
  {
    v44[0] = *((_WORD *)v12 + 2);
    v44[1] = v44[0];
    v46 = *((_QWORD *)v12 + 1);
    *(_QWORD *)&v51 = v12 + 32;
    *(_QWORD *)&v49 = v44;
    *((_QWORD *)&v49 + 1) = *((_QWORD *)v13 + 8);
    *(_QWORD *)&v50 = SecurityQos;
    v45 = 0;
    v24 = CmpCallCallBacksEx(RegNtPreCreateKeyEx, Argument, (INT64)a5, 1, RegNtPostCreateKeyEx, (INT64)v11, (INT64)v42);
  }
  else
  {
    v24 = CmpCallCallBacksEx(RegNtPreOpenKeyEx, Argument, (INT64)a5, 1, RegNtPostOpenKeyEx, (INT64)v11, (INT64)v42);
  }
  v25 = v24;
  if( v24 >= 0 )
  {
    v11 = Argument[1];
    v13 = v59;
    *((_DWORD *)v12 + 24) = a5[1];
    v57 = 1;
LABEL_23:
    for( i = (unsigned int)RemainingName; ; ++i )
    {
      while( 1 )
      {
        a6 = (__int128)v38;
        v27 = CmpDoParseKey(
                (__int64)v11,
                (struct _SECURITY_SUBJECT_CONTEXT *)v13,
                v60,
                Attributes,
                v22,
                (__int64 *)&a6,
                (__int64)v12,
                (int)SecurityQos,
                &v39);
        v25 = v27;
        if( v27 != 259 )
          break;
        KeWaitForSingleObject(&qword_140C00F70[25 * *((unsigned int *)v12 + 34)], Executive, 0, 0, 0i64);
        *(_DWORD *)v12 &= ~0x100u;
        v13 = v59;
      }
      if( v27 != -1073741267 )
        break;
      if( i >= 0x40 )
      {
        v25 = -1073741772;
        break;
      }
      if( (*((_DWORD *)v12 + 25) & 4) != 0 )
      {
        CmpRollbackTransactionArray(*((unsigned int *)v12 + 30), *((VOID ***)v12 + 16), v28, &RetryCount);
        *((_DWORD *)v12 + 25) &= ~4u;
        *((_DWORD *)v12 + 30) = 0;
        *((_QWORD *)v12 + 16) = 0i64;
      }
      v13 = v59;
    }
    v20 = *((_DWORD *)v16 + 1) & (__int64)v11[6].Next;
    if( v25 >= 0 )
    {
      *(_QWORD *)v10 = v39;
      v39 = 0i64;
    }
    if( v57 )
    {
      v29 = v59;
      v30 = *(SLIST_ENTRY **)v10;
      HIDWORD(v50) = *((_DWORD *)v59 + 5);
      v25 = CmPostCallbackNotificationEx(
              (REG_NOTIFY_CLASS)(2 * ((*(_DWORD *)v12 & 1) == 0) + 27),
              v30,
              (unsigned int)v25,
              (INT64)Argument,
              (INT64)a5,
              (INT64)v42);
      if( v25 >= 0 )
      {
        v31 = HIDWORD(v50);
        if( HIDWORD(v50) != *((_DWORD *)v29 + 5) )
        {
          *((_DWORD *)v29 + 5) = HIDWORD(v50);
          *((_DWORD *)v29 + 4) = *((_DWORD *)v29 + 6) & ~(v31 | 0x2000000);
        }
      }
      if( *(_QWORD *)v10 )
        *(_DWORD *)(*(_QWORD *)v10 + 96i64) = a5[1];
    }
LABEL_34:
    if( v25 != 872 )
    {
      if( v25 == 260 )
      {
        *((_DWORD *)v12 + 24) = v20;
        v16[1] = PsGetCurrentSilo();
      }
      goto LABEL_37;
    }
    goto LABEL_50;
  }
  if( v24 != -1073740541 )
    goto LABEL_34;
  v25 = HIDWORD(a5[1]);
  if( HIDWORD(a5[1]) == 260 )
    goto LABEL_34;
  if( HIDWORD(a5[1]) != 872 )
  {
    v36 = (__int64)v59;
    v37 = HIDWORD(v50);
    *((_DWORD *)v59 + 5) |= HIDWORD(v50);
    *(_DWORD *)(v36 + 16) &= ~(v37 | 0x2000000);
    v25 = 0;
    goto LABEL_37;
  }
LABEL_50:
  *((_QWORD *)v12 + 8) = 0i64;
  v16[1] = 0i64;
LABEL_37:
  KeLeaveCriticalRegion();
  v15 = Privileges;
LABEL_38:
  if( v15 )
  {
    CmpCleanupParseContext((__int64)v15, 0);
    CmSiFreeMemory(v15);
  }
  return v25;
}

Referenced by:

No references.