RawMountVolume
INT64 __fastcall RawMountVolume(_IO_STACK_LOCATION *IrpSp){
__int64 v2;
INT64 result;
PDEVICE_OBJECT v4;
unsigned int v5;
int v6;
FILE_OBJECT *StreamFileObjectLite;
_QWORD *v8;
__int64 v9;
FSRTL_ADVANCED_FCB_HEADER *v10;
UINT64 DeviceCharacteristics;
PDEVICE_OBJECT DeviceObject;
FILE_OBJECT *v13;
char Event[44];
int v15;
int v16;
int v17;
wchar_t v18;
int v19;
DeviceObject = 0i64;
RawScanDeletedList();
v2 = *((_QWORD *)IrpSp + 2);
if( *(_WORD *)(v2 + 304) > 0x1000u )
return 3221225807i64;
LODWORD(DeviceCharacteristics) = 0;
LODWORD(result) = IoCreateDevice(
*(DRIVER_OBJECT **)(*((_QWORD *)IrpSp + 5) + 8i64),
0x150ui64,
0i64,
8ui64,
DeviceCharacteristics,
0,
&DeviceObject);
if( (int)result >= 0 )
{
v4 = DeviceObject;
v5 = *(_DWORD *)(v2 + 152);
if( v5 > *((_DWORD *)DeviceObject + 38) )
*((_DWORD *)DeviceObject + 38) = v5;
*((_WORD *)v4 + 152) = *(_WORD *)(v2 + 304);
*((_DWORD *)v4 + 12) |= 0x10u;
v6 = RawInitializeVcb((_DWORD *)v4 + 84, *((_QWORD *)IrpSp + 2), *((_QWORD *)IrpSp + 1));
if( v6 < 0 )
{
v10 = (FSRTL_ADVANCED_FCB_HEADER *)((char *)v4 + 336);
}
else
{
*(_QWORD *)(*((_QWORD *)v4 + 65) + 8i64) = v4;
*(_DWORD *)(*((_QWORD *)v4 + 65) + 24i64) = -1;
*(_WORD *)(*((_QWORD *)v4 + 65) + 6i64) = 0;
*((_DWORD *)v4 + 12) &= ~0x80u;
*((_BYTE *)v4 + 76) = *(_BYTE *)(v2 + 76) + 1;
v13 = 0i64;
memset(&Event[4], 0, 20);
v19 = 0;
StreamFileObjectLite = IoCreateStreamFileObjectLite(0i64, v4);
v13 = StreamFileObjectLite;
if( v6 >= 0 )
{
*((_DWORD *)v4 + 111) += 2;
*((_DWORD *)v4 + 112) += 2;
*(_DWORD *)Event = 4063233;
*(_QWORD *)&Event[24] = 0i64;
*(_DWORD *)&Event[32] = -1;
*(_QWORD *)&Event[36] = 1i64;
v15 = 6;
v16 = 16;
v17 = *(_DWORD *)L"RAW";
v18 = aRaw[2];
FsRtlNotifyVolumeEventEx(StreamFileObjectLite, 6ui64, (TARGET_DEVICE_CUSTOM_NOTIFICATION *)Event);
HalPutDmaAdapter((PADAPTER_OBJECT)StreamFileObjectLite);
*((_DWORD *)v4 + 111) -= 2;
*((_DWORD *)v4 + 112) -= 2;
ExAcquireFastMutex(&RawGlobalLock);
v8 = (_QWORD *)((char *)v4 + 496);
v9 = RawMountedQueue;
if( *(__int64 **)(RawMountedQueue + 8) != &RawMountedQueue )
__fastfail(3u);
*v8 = RawMountedQueue;
v8[1] = &RawMountedQueue;
*(_QWORD *)(v9 + 8) = v8;
RawMountedQueue = (__int64)v8;
KeReleaseGuardedMutex(&RawGlobalLock);
return(unsigned int)v6;
}
v10 = (FSRTL_ADVANCED_FCB_HEADER *)((char *)v4 + 336);
}
RawCleanupVcb(v10);
IoDeleteDevice(v4);
return(unsigned int)v6;
}
return result;
}Referenced by:
RawFileSystemControl