WmipForwardWmiIrp
INT64 __fastcall WmipForwardWmiIrp(
_IRP *Irp,
UINT8 MinorFunction,
UINT64 ProviderId,
VOID *DataPath,
UINT64 BufferLength,
VOID *Buffer){
unsigned int v6;
LIST_ENTRY *RegEntryByProviderId;
INT64 v10;
int Flink;
DEVICE_OBJECT *v12;
__int64 v13;
__int64 v14;
DEVICE_OBJECT *AttachedDeviceReference;
INT8 v16;
__int64 v17;
__int64 v18;
__int64 v19;
NTSTATUS v20;
INT64 result;
unsigned int v22;
unsigned int v23;
struct _KEVENT Event;
v6 = MinorFunction;
memset(&Event, 0, sizeof(Event));
RegEntryByProviderId = WmipFindRegEntryByProviderId((unsigned int)ProviderId);
v10 = (INT64)RegEntryByProviderId;
if( RegEntryByProviderId )
{
Flink = (int)RegEntryByProviderId[3].Flink;
if( (Flink & 0x20000000) == 0 )
{
v12 = *(DEVICE_OBJECT **)(v10 + 16);
if( (Flink & 0x10000000) != 0 )
{
v23 = 0;
v22 = (*(__int64(__fastcall **)(_QWORD, VOID *, _QWORD, VOID *, DEVICE_OBJECT *, unsigned int *))v12)(
v6,
DataPath,
(unsigned int)BufferLength,
Buffer,
v12,
&v23);
*((_QWORD *)Irp + 7) = v23;
*((_DWORD *)Irp + 12) = v22;
WmipUnreferenceRegEntry(v10);
return v22;
}
else
{
if( (_BYTE)v6 != 11 && (_BYTE)v6 != 8 )
{
v13 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnpidGuid;
if( !v13 )
v13 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnpidGuid + 1);
if( !v13 )
goto LABEL_36;
v14 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnPIdInstanceNamesGuid;
if( !v14 )
v14 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnPIdInstanceNamesGuid + 1);
if( !v14 )
{
LABEL_36:
if( *(_QWORD *)(v10 + 24) )
v12 = WmipServiceDeviceObject;
}
}
AttachedDeviceReference = IoGetAttachedDeviceReference(v12);
v16 = *((_BYTE *)AttachedDeviceReference + 76) + 1;
if( v16 <= *((char *)WmipServiceDeviceObject + 76) || AttachedDeviceReference == WmipServiceDeviceObject )
{
KeInitializeEvent(&Event, SynchronizationEvent, 0);
v17 = *((_QWORD *)Irp + 23);
*(_QWORD *)(v17 - 16) = SmKmGenericCompletion;
*(_QWORD *)(v17 - 8) = &Event;
*(_BYTE *)(v17 - 69) = -32;
v18 = *((_QWORD *)Irp + 23);
*(_QWORD *)(v18 - 40) = Buffer;
*(_BYTE *)(v18 - 72) = 23;
*(_BYTE *)(v18 - 71) = v6;
*(_QWORD *)(v18 - 64) = v12;
*(_QWORD *)(v18 - 56) = DataPath;
*(_DWORD *)(v18 - 48) = BufferLength;
v19 = *((_QWORD *)Irp + 23);
*((_DWORD *)Irp + 12) = -1073741637;
*(_BYTE *)(v19 + 3) |= 1u;
v20 = IofCallDriver(AttachedDeviceReference, Irp);
if( v20 == 259 )
{
KeWaitForSingleObject(&Event, Executive, 0, 0, 0i64);
v20 = *((_DWORD *)Irp + 12);
}
if( v20 == -1073741637 )
{
v20 = -1073741163;
*((_DWORD *)Irp + 12) = -1073741163;
}
if( ((_BYTE)v6 == 11 || (_BYTE)v6 == 8) && v20 >= 0 && *((_QWORD *)Irp + 7) > 0x18ui64 )
WmipTranslatePDOInstanceNames((__int64)Irp, v6, BufferLength, v10);
WmipUnreferenceRegEntry(v10);
}
else
{
WmipUnreferenceRegEntry(v10);
WmipUpdateDeviceStackSize(v16);
v20 = -1073741160;
}
HalPutDmaAdapter((PADAPTER_OBJECT)AttachedDeviceReference);
return(unsigned int)v20;
}
}
WmipUnreferenceRegEntry(v10);
}
result = 3221226134i64;
if( (unsigned __int8)(v6 - 1) > 1u )
return 3221225473i64;
return result;
}Referenced by:
WmipQueryAllData
WmipQuerySetExecuteSI
WmipSendWmiIrp
WmipSendWmiIrpToTraceDeviceList
WmipSetTraceNotify