CmpSaveBootControlSet
NTSTATUS __stdcall CmpSaveBootControlSet(UINT16 ControlSetNum){
unsigned int v1;
char v2;
struct _DMA_ADAPTER *v3;
char v4;
__int64 v5;
struct _PRIVILEGE_SET *v6;
int v7;
_CHILD_LIST *v8;
struct _PRIVILEGE_SET *v9;
char v10;
INT8 v11;
INT8 v12;
int v13;
INT64 v14;
INT64 v15;
int v16;
int v17;
int v18;
INT64 v19;
_DMA_OPERATIONS *DmaOperations;
UINT64 AllocateAdapterChannel;
INT64 FlushAdapterBuffers_low;
__int64 v23;
unsigned int v24;
UINT64 v25;
INT64 v26;
__int64 v27;
CHAR v28;
unsigned __int8 *v29;
UINT64 CreateOptions;
bool v32;
int a1;
ULONG Length[2];
OBJECT_HANDLE_INFORMATION v35;
ULONG Disposition[2];
void *KeyHandle;
OBJECT_HANDLE_INFORMATION HandleInformation[3];
HANDLE Handle;
INT64 a4[2];
struct _OBJECT_ATTRIBUTES ObjectAttributes;
struct _UNICODE_STRING DestinationString;
KAPC_STATE ApcState;
struct _EVENT_DATA_DESCRIPTOR v44;
int *p_a1;
__int64 v46;
OBJECT_HANDLE_INFORMATION *v47;
__int64 v48;
char v49;
v1 = ControlSetNum;
Disposition[0] = 0;
KeyHandle = 0i64;
memset(HandleInformation, 0, sizeof(HandleInformation));
DestinationString = 0i64;
v2 = 0;
v3 = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
Disposition[1] = 0;
v4 = 0;
Handle = 0i64;
v5 = 0i64;
v35 = 0i64;
v6 = 0i64;
*(_OWORD *)a4 = 0i64;
Length[0] = 0;
memset(&ApcState, 0, sizeof(ApcState));
a1 = 0;
CmpInitializeDelayDerefContext(a4);
v32 = CmpAcquireShutdownRundown();
if( !v32 )
{
v7 = -1073741431;
goto LABEL_36;
}
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &CmRegistryMachineSystemCurrentControlSet;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v7 = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( v7 >= 0 )
{
if( ZwQuerySecurityObject(KeyHandle, 4ui64, 0i64, 0i64, (UINT64 *)Length) == -1073741789 )
{
CmpAllocateTransientPoolWithTag((_HHIVE *)1, Length[0], 0x20204D43ui64, v8);
v6 = v9;
if( v9 )
{
if( ZwQuerySecurityObject(KeyHandle, 4ui64, v9, Length[0], (UINT64 *)Length) < 0 )
{
CmSiFreeMemory(v6);
v6 = 0i64;
}
}
}
DestinationString.MaximumLength = 256;
DestinationString.Buffer = (wchar_t *)&v49;
RtlUnicodeStringPrintf(&DestinationString, L"\\Registry\\Machine\\System\\ControlSet%03d", v1);
v10 = 0;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Attributes = 576;
LODWORD(CreateOptions) = 0;
ObjectAttributes.SecurityDescriptor = v6;
ObjectAttributes.SecurityQualityOfService = 0i64;
v7 = ZwCreateKey(&Handle, 0x2001Fui64, &ObjectAttributes, 0i64, 0i64, CreateOptions, (UINT64 *)Disposition);
if( v6 )
CmSiFreeMemory(v6);
if( v7 >= 0 )
{
v7 = CmObReferenceObjectByHandle(KeyHandle, 0x20019ui64, v11, 0i64, HandleInformation);
if( v7 >= 0 )
{
v7 = CmObReferenceObjectByHandle(Handle, 0x20006ui64, v12, 0i64, &v35);
if( v7 >= 0 )
{
CmpLockRegistryExclusive();
v3 = (struct _DMA_ADAPTER *)HandleInformation[0];
v13 = CmpPerformKeyBodyDeletionCheck(*(_QWORD *)HandleInformation, 0i64);
v5 = (__int64)v35;
while( 1 )
{
v7 = v13;
if( v13 < 0 || (v7 = CmpPerformKeyBodyDeletionCheck(v5, 0i64), v7 < 0) )
{
LABEL_27:
v4 = 1;
goto LABEL_36;
}
v15 = *(_QWORD *)(v5 + 8);
v16 = CmpTryAcquireKcbIXLocks(v15, 1, v14, (UINT64 *)&HandleInformation[1]);
v7 = v16;
if( v16 == -1073741267 )
{
v10 = 1;
}
else if( v16 < 0 )
{
goto LABEL_27;
}
v17 = CmpPrepareToInvalidateAllHigherLayerKcbs(v15, 0, (INT64)&HandleInformation[1]);
v7 = v17;
if( v17 == -1073741267 )
{
v10 = 1;
}
else if( v17 < 0 )
{
goto LABEL_27;
}
v18 = CmpPrepareForSubtreeInvalidation(v15, (INT64)&HandleInformation[1]);
v7 = v18;
if( v18 != -1073741267 )
{
if( v18 < 0 )
goto LABEL_27;
if( !v10 )
break;
}
CmpLogTransactionAbortedForRollbackPacket(v15, 12i64, (UINT64 *)&HandleInformation[1], v19);
CmpUnlockRegistry();
v10 = 0;
v7 = CmpAbortRollbackPacket((INT64)&HandleInformation[1]);
if( v7 < 0 )
goto LABEL_36;
CmpRetryBackOff(&a1);
CmpCleanupRollbackPacket((INT64)&HandleInformation[1]);
*(_OWORD *)&HandleInformation[1].HandleAttributes = 0i64;
CmpLockRegistryExclusive();
v13 = CmpPerformKeyBodyDeletionCheck((__int64)v3, 0i64);
}
CmpInvalidateAllHigherLayerKcbs(v15, 0, 8i64, (INT64)a4);
CmpInvalidateSubtree(v15, 8i64, (INT64)a4, &Disposition[1]);
CmpAttachToRegistryProcess(&ApcState);
v2 = 1;
DmaOperations = v3->DmaOperations;
AllocateAdapterChannel = (UINT64)DmaOperations->AllocateAdapterChannel;
FlushAdapterBuffers_low = LODWORD(DmaOperations->FlushAdapterBuffers);
if( Disposition[0] == 1 )
{
v23 = *(_QWORD *)(v5 + 8);
v24 = 0;
v25 = *(_QWORD *)(v23 + 32);
v26 = *(unsigned int *)(v23 + 40);
}
else
{
v27 = *(_QWORD *)(v5 + 8);
v24 = 1;
v25 = *(_QWORD *)(v27 + 32);
v26 = *(unsigned int *)(v27 + 40);
}
v28 = CmpCopySyncTree(AllocateAdapterChannel, FlushAdapterBuffers_low, v25, v26, 2, v24);
CmpRebuildKcbCache(*(_CM_KEY_CONTROL_BLOCK **)(v5 + 8));
v4 = 1;
if( v28 )
v7 = 0;
else
v7 = -1073741492;
goto LABEL_36;
}
v5 = (__int64)v35;
}
v3 = (struct _DMA_ADAPTER *)HandleInformation[0];
}
}
LABEL_36:
CmpDrainDelayDerefContext((UINT64 **)a4);
if( v4 )
CmpUnlockRegistry();
if( v2 )
CmpDetachFromRegistryProcess(&ApcState);
CmpCleanupRollbackPacket((INT64)&HandleInformation[1]);
if( v3 )
HalPutDmaAdapter(v3);
if( v5 )
HalPutDmaAdapter((PADAPTER_OBJECT)v5);
if( KeyHandle )
ZwClose(KeyHandle);
if( Handle )
ZwClose(Handle);
if( v32 )
CmpReleaseShutdownRundown();
if( v7 < 0 )
{
if( (unsigned int)dword_140C02130 > 5 && tlgKeywordOn((__int64)&dword_140C02130, 0x400000000000i64) )
{
a1 = v7;
v29 = (unsigned __int8 *)word_1400219AA;
goto LABEL_57;
}
}
else if( (unsigned int)dword_140C02130 > 5 && tlgKeywordOn((__int64)&dword_140C02130, 0x400000000000i64) )
{
v29 = (unsigned __int8 *)&byte_1400219EF;
a1 = Disposition[1];
LABEL_57:
v35 = (OBJECT_HANDLE_INFORMATION)0x1000000i64;
v46 = 4i64;
p_a1 = &a1;
v48 = 8i64;
v47 = &v35;
tlgWriteTransfer_EtwWriteTransfer((__int64)&dword_140C02130, v29, 0i64, 0i64, 4u, &v44);
}
return v7;
}Referenced by:
CmpAcceptBoot