AlpcpCreateConnectionPort

INT64 __fastcall AlpcpCreateConnectionPort(
        VOID **PortHandle,
        _OBJECT_ATTRIBUTES *ObjectAttributes,
        _ALPC_PORT_ATTRIBUTES *PortAttributes,
        UINT64 MaxMessageLength,
        VOID *Waitable,
        INT64 LegacyPort){
  int v6; 
  INT8 v10; 
  __int64 v11; 
  __int64 v12; 
  INT64 Port; 
  __int64 v14; 
  char v15; 
  PADAPTER_OBJECT v16; 
  int v17; 
  _ALPC_PORT_ATTRIBUTES *v18; 
  int v19; 
  CHAR *Blob; 
  _QWORD *v21; 
  int v22; 
  NTSTATUS inserted; 
  UINT64 MaxMessageLengtha; 
  UINT64 MaxMessageLengthb; 
  INT64 v26; 
  INT64 v27; 
  HANDLE Handle; 
  PADAPTER_OBJECT DmaAdapter; 
  INT64 result[2]; 
  __int128 v31; 
  __int128 v32; 
  __int128 v33; 
  __int64 v34; 
  v6 = MaxMessageLength;
  memset((INT64)result, 0i64);
  DmaAdapter = 0i64;
  Handle = 0i64;
  v10 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v10 )
  {
    v11 = (__int64)PortHandle;
    if( (unsigned __int64)PortHandle >= 0x7FFFFFFF0000i64 )
      v11 = 0x7FFFFFFF0000i64;
    *(_QWORD *)v11 = *(_QWORD *)v11;
    if( PortAttributes )
    {
      v12 = (__int64)PortAttributes;
      if( (unsigned __int64)PortAttributes >= 0x7FFFFFFF0000i64 )
        v12 = 0x7FFFFFFF0000i64;
      *(_OWORD *)result = *(_OWORD *)v12;
      v31 = *(_OWORD *)(v12 + 16);
      v32 = *(_OWORD *)(v12 + 32);
      v33 = *(_OWORD *)(v12 + 48);
      v34 = *(_QWORD *)(v12 + 64);
    }
  }
  else if( PortAttributes )
  {
    *(_OWORD *)result = *(_OWORD *)&PortAttributes->Flags;
    v31 = *(_OWORD *)&PortAttributes->MaxMessageLength;
    v32 = *(_OWORD *)&PortAttributes->MaxPoolUsage;
    v33 = *(_OWORD *)&PortAttributes->MaxViewSize;
    v34 = *(_QWORD *)&PortAttributes->DupObjectTypes;
  }
  Port = AlpcpCreatePort(v10, (INT64)ObjectAttributes, (VOID **)&DmaAdapter);
  if( (int)Port >= 0 )
  {
    if( PortAttributes )
    {
      v15 = (char)Waitable;
      if( (result[0] & 0x40000) != 0 )
        v15 = 1;
      LOBYTE(Waitable) = v15;
    }
    LOBYTE(v14) = (_BYTE)Waitable;
    v16 = DmaAdapter;
    v17 = AlpcpInitializePort(DmaAdapter, 1i64, v14);
    if( v17 < 0 )
    {
      HalPutDmaAdapter(v16);
      return(unsigned int)v17;
    }
    v18 = (_ALPC_PORT_ATTRIBUTES *)((unsigned __int64)result & -(__int64)(PortAttributes != 0i64));
    LOBYTE(v27) = LegacyPort;
    LOBYTE(v26) = (_BYTE)Waitable;
    LODWORD(MaxMessageLengtha) = v6;
    v19 = AlpcpValidateAndSetPortAttributes(
            (_ALPC_PORT *)v16,
            v18,
            (_ALPC_PORT *)v16,
            0i64,
            MaxMessageLengtha,
            v26,
            v27);
    if( v19 >= 0 )
    {
      if( (_BYTE)LegacyPort )
        *(_DWORD *)&v16[26].Version |= 0x3000u;
      AlpcpSetOwnerProcessPort((_ALPC_PORT *)v16, v18);
      Blob = AlpcpAllocateBlob(&AlpcConnectionType, 0x50ui64, 1ui64);
      *(_QWORD *)&v16[1].Version = Blob;
      if( Blob )
      {
        *((_QWORD *)Blob + 2) = 0i64;
        **(_QWORD **)&v16[1].Version = v16;
        *(_QWORD *)(*(_QWORD *)&v16[1].Version + 8i64) = 0i64;
        *(_QWORD *)(*(_QWORD *)&v16[1].Version + 72i64) = 0i64;
        v21 = (_QWORD *)(*(_QWORD *)&v16[1].Version + 24i64);
        v21[1] = v21;
        *v21 = v21;
        v22 = AlpcInitializeHandleTable(*(_QWORD *)&v16[1].Version + 40i64);
        if( v22 >= 0 )
        {
          LODWORD(MaxMessageLengthb) = 0;
          inserted = ObInsertObjectEx(v16, 0i64, 0x1F0001ui64, 0i64, MaxMessageLengthb, 0i64, &Handle);
          if( inserted >= 0 )
            *PortHandle = Handle;
          return(unsigned int)inserted;
        }
        v19 = v22;
      }
      else
      {
        v19 = -1073741801;
      }
    }
    HalPutDmaAdapter(v16);
    return(unsigned int)v19;
  }
  return Port;
}

Referenced by:

NtAlpcCreatePort
NtCreatePort
NtCreateWaitablePort