PnpDeviceActionWorker
VOID __stdcall PnpDeviceActionWorker(PVOID Context){
CHAR v1;
char v2;
char v3;
UINT64 v4;
int v5;
INT64 v6;
UINT8 v7;
UINT8 v8;
__int64 v9;
__int64 v10;
_ETHREAD *CurrentThread;
char v12;
_QWORD *v13;
__int64 v14;
__int64 v15;
int v16;
int started;
int PowerRelations;
int v19;
volatile INT32 *v20;
__int64 v21;
int *v22;
struct _KEVENT *v23;
__int64 v24;
_DEVICE_NODE *v25;
int v26;
int v27;
int v28;
int v29;
int v30;
int v31;
int v32;
INT64 v33;
char v34;
char v35;
char v36;
INT64 v37;
__int128 NotificationStructure[2];
__int64 v39;
__int128 v40;
v37 = 0i64;
memset(NotificationStructure, 0, sizeof(NotificationStructure));
v39 = 0i64;
v1 = 0;
v34 = 0;
v40 = 0i64;
v2 = 0;
_InterlockedExchange64((volatile __int64 *)PnpDeviceActionThread, (__int64)KeGetCurrentThread());
v3 = 0;
PpDevNodeLockTree(1);
while( 1 )
{
v36 = 0;
v5 = 0;
v35 = 1;
KeAcquireSpinLockRaiseToDpc(&PnpSpinLock, v4);
v6 = PnpEnumerationRequestList;
v8 = v7;
if( (INT64 *)PnpEnumerationRequestList != &PnpEnumerationRequestList )
{
if( *(INT64 **)(PnpEnumerationRequestList + 8) != &PnpEnumerationRequestList
|| (v9 = *(_QWORD *)PnpEnumerationRequestList,
*(_QWORD *)(*(_QWORD *)PnpEnumerationRequestList + 8i64) != PnpEnumerationRequestList) )
{
LABEL_99:
__fastfail(3u);
}
PnpEnumerationRequestList = *(_QWORD *)PnpEnumerationRequestList;
*(_QWORD *)(v9 + 8) = &PnpEnumerationRequestList;
*(_BYTE *)(v6 + 76) = 1;
goto LABEL_6;
}
if( !v1 && !v2 && !v3 )
break;
v6 = 0i64;
LABEL_6:
KeReleaseSpinLock(&PnpSpinLock, v8);
if( v6 )
{
v10 = *(_QWORD *)&NullGuid.Data1 - *(_QWORD *)(v6 + 56);
if( *(_QWORD *)&NullGuid.Data1 == *(_QWORD *)(v6 + 56) )
v10 = *(_QWORD *)NullGuid.Data4 - *(_QWORD *)(v6 + 64);
if( v10 )
{
v36 = 1;
v40 = *(_OWORD *)(v6 + 56);
*((_QWORD *)KeGetCurrentThread() + 180) = &v40;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquirePushLockExclusiveEx(v6 + 80, 0i64);
v12 = *(_BYTE *)(v6 + 88);
ExReleasePushLockEx(v6 + 80, 0i64);
KeLeaveCriticalRegion();
PoNotifyPnpActionQueueEvent(2i64, *(unsigned int *)(v6 + 24));
*(_QWORD *)(v6 + 8) = v6;
*(_QWORD *)v6 = v6;
if( PnpShutdownEvent.Header.SignalState )
{
v5 = -1073741431;
}
else if( v12 )
{
v5 = -1073741536;
}
else
{
v13 = *(_QWORD **)(v6 + 16);
if( v13 )
v14 = *(_QWORD *)(v13[39] + 40i64);
else
v14 = 0i64;
if( *(_DWORD *)(v14 + 300) != 788 )
{
if( v13 )
v15 = *(_QWORD *)(v13[39] + 40i64);
else
v15 = 0i64;
if( v15 )
{
ObfReferenceObjectWithTag(v13, 0x65706E50u);
PnpLogActionQueueEvent(v15);
}
v16 = *(_DWORD *)(v6 + 24);
if( v16 <= 12 )
{
if( v16 != 12 )
{
if( v16 > 5 )
{
if( v16 == 6 )
{
PowerRelations = PnpProcessRebalance((LIST_ENTRY *)v6);
goto LABEL_33;
}
if( v16 == 7 )
{
v2 = 1;
}
else
{
if( v16 <= 10 )
goto LABEL_26;
PowerRelations = PiProcessRequeryDeviceState((_PNP_DEVICE_ACTION_ENTRY *)v6);
LABEL_33:
v5 = PowerRelations;
}
LABEL_34:
if( v15 )
{
PnpLogActionQueueEvent(v15);
ObfDereferenceObjectWithTag(*(PVOID *)(v6 + 16), 0x65706E50ui64);
}
goto LABEL_36;
}
if( v16 == 5 )
{
v24 = *(_QWORD *)(v6 + 16);
if( v24 )
v25 = *(_DEVICE_NODE **)(*(_QWORD *)(v24 + 312) + 40i64);
else
v25 = 0i64;
PowerRelations = PiQueryPowerRelations(v25, 0);
goto LABEL_33;
}
if( !v16 )
{
v1 = 1;
goto LABEL_34;
}
v26 = v16 - 1;
if( v26 )
{
v27 = v26 - 1;
if( !v27 )
{
PowerRelations = PpProcessClearProblem(v6);
goto LABEL_33;
}
v32 = v27 - 1;
if( v32 )
{
if( v32 == 1 )
{
PowerRelations = PiProcessHaltDevice((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_33;
}
goto LABEL_80;
}
}
LABEL_70:
PiProcessClearDeviceProblem((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_33;
}
LABEL_69:
PowerRelations = PiRestartDevice((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_33;
}
if( v16 <= 18 )
{
if( v16 == 18 )
{
v34 = 1;
goto LABEL_34;
}
v28 = v16 - 13;
if( !v28 )
{
v5 = PiProcessResourceRequirementsChanged((_PNP_DEVICE_ACTION_ENTRY *)v6);
if( v5 < 0 )
{
v1 = 1;
v5 = 0;
}
goto LABEL_34;
}
v29 = v28 - 1;
if( !v29 )
{
LABEL_26:
started = PiProcessReenumeration(v6);
LABEL_27:
v5 = started;
v35 = 0;
goto LABEL_34;
}
v30 = v29 - 1;
if( !v30 )
{
PowerRelations = PiProcessSetDeviceProblem((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_33;
}
v31 = v30 - 1;
if( !v31 )
goto LABEL_69;
if( v31 == 1 )
{
started = PiProcessStartSystemDevices((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_27;
}
LABEL_80:
v5 = -1073741823;
goto LABEL_34;
}
if( v16 == 19 )
{
DWORD1(NotificationStructure[1]) = 0;
*(GUID *)((char *)NotificationStructure + 4) = GUID_TARGET_DEVICE_TRANSPORT_RELATIONS_CHANGED;
LODWORD(NotificationStructure[0]) = 2359297;
*((_QWORD *)&NotificationStructure[1] + 1) = 0i64;
v39 = 0xFFFFFFFFi64;
IoReportTargetDeviceChangeAsynchronous(*(PDEVICE_OBJECT *)(v6 + 16), NotificationStructure, 0i64, 0i64);
v33 = 21i64;
}
else
{
if( v16 != 20 )
{
if( v16 <= 24 )
{
PiConfigureDevice((_PNP_DEVICE_ACTION_ENTRY *)v6);
goto LABEL_33;
}
if( v16 == 25 )
goto LABEL_70;
goto LABEL_80;
}
v33 = 17i64;
}
PiPnpRtlPdoRaiseNtPlugPlayPropertyChangeEvent(*(_QWORD *)(v6 + 16), v33);
goto LABEL_34;
}
v5 = -1073741823;
}
LABEL_36:
PoNotifyPnpActionQueueEvent(3i64, *(unsigned int *)(v6 + 24));
v19 = 1;
do
{
v20 = *(volatile INT32 **)v6;
if( *(_QWORD *)(*(_QWORD *)v6 + 8i64) != v6 )
goto LABEL_99;
v21 = *(_QWORD *)v20;
if( *(volatile INT32 **)(*(_QWORD *)v20 + 8i64) != v20 )
goto LABEL_99;
*(_QWORD *)v6 = v21;
*(_QWORD *)(v21 + 8) = v6;
PoNotifyPnpActionQueueEvent(1i64, *((unsigned int *)v20 + 6));
v22 = (int *)*((_QWORD *)v20 + 6);
if( v22 )
*v22 = v5;
v23 = (struct _KEVENT *)*((_QWORD *)v20 + 5);
if( v23 )
KeSetEvent(v23, 0);
if( v20 == (volatile INT32 *)v6 )
{
v19 = 0;
if( v35 )
HalPutDmaAdapter(*((PADAPTER_OBJECT *)v20 + 2));
}
PnpDeleteDeviceActionRequest(v20);
}
while( v19 );
v3 = v34;
if( v36 )
*((_QWORD *)KeGetCurrentThread() + 180) = 0i64;
}
else if( v1 || v2 )
{
LODWORD(v37) = 3;
BYTE4(v37) = PnPBootDriversInitialized;
ObfReferenceObject(*((PVOID *)IopRootDeviceNode + 4));
PipProcessDevNodeTree((INT64)IopRootDeviceNode, 0i64, (INT64)&v37, v2 == 0 ? 3 : 0, v1, 0, 0);
v1 = 0;
v2 = 0;
}
else
{
PnpCompleteSystemStartProcess();
v3 = 0;
v34 = 0;
}
}
PnpEnumerationInProgress = 0;
KeSetEvent(&PnpEnumerationLock, 0);
KeReleaseSpinLock(&PnpSpinLock, v8);
_InterlockedExchange64((volatile __int64 *)PnpDeviceActionThread, 0i64);
PpDevNodeUnlockTree(1);
}Referenced by:
PnpRequestDeviceAction