NtAlpcOpenSenderThread
INT64 __fastcall NtAlpcOpenSenderThread(
VOID **ThreadHandle,
VOID *PortHandle,
_PORT_MESSAGE *PortMessage,
UINT64 Flags,
UINT64 DesiredAccess,
_OBJECT_ATTRIBUTES *ObjectAttributes){
unsigned int v6;
_ETHREAD *CurrentThread;
KPROCESSOR_MODE v10;
int v11;
_OBJECT_ATTRIBUTES *v12;
__int64 v13;
struct _DMA_ADAPTER *v14;
ULONG_PTR v15;
struct _DMA_ADAPTER *v16;
PVOID *Object;
INT64 PreviousMode;
PADAPTER_OBJECT DmaAdapter;
ULONG_PTR BugCheckParameter2;
VOID *ThreadHandlea;
__int128 Source2;
INT64 v24[2];
INT64 v25;
OBJECT_ATTRIBUTES v26;
v6 = Flags;
Source2 = 0i64;
*(_OWORD *)v24 = 0i64;
v25 = 0i64;
ThreadHandlea = 0i64;
BugCheckParameter2 = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v10 = *((_BYTE *)KeGetCurrentThread() + 562);
DmaAdapter = 0i64;
v11 = ObReferenceObjectByHandle(PortHandle, 0x20000u, AlpcPortObjectType, v10, (PVOID *)&DmaAdapter, 0i64);
if( v11 >= 0 )
{
if( v10 )
{
v13 = 0x7FFFFFFF0000i64;
if( (unsigned __int64)ThreadHandle < 0x7FFFFFFF0000i64 )
v13 = (__int64)ThreadHandle;
*(_QWORD *)v13 = *(_QWORD *)v13;
AlpcpProbeAndCaptureMessageHeader(PortMessage, (_PORT_MESSAGE *)&Source2, v6);
if( ObjectAttributes < v12 )
v12 = ObjectAttributes;
v26 = *v12;
}
else
{
Source2 = *(_OWORD *)PortMessage;
*(_OWORD *)v24 = *((_OWORD *)PortMessage + 1);
v25 = *((_QWORD *)PortMessage + 4);
v26 = *ObjectAttributes;
}
v14 = DmaAdapter;
v11 = AlpcpLookupMessage((INT64)DmaAdapter, LODWORD(v24[1]), (unsigned int)v25, (INT64)v12, &BugCheckParameter2);
if( v11 < 0 )
{
HalPutDmaAdapter(v14);
}
else
{
v15 = BugCheckParameter2;
if( (*(_DWORD *)(BugCheckParameter2 + 40) & 0x80u) != 0 )
{
AlpcpUnlockMessage(BugCheckParameter2);
HalPutDmaAdapter(v14);
v11 = -1073740029;
}
else
{
v16 = *(struct _DMA_ADAPTER **)(BugCheckParameter2 + 32);
if( v16 && RtlCompareMemory(&v16[71].DmaOperations, (char *)&Source2 + 8, 0x10ui64) == 16 )
{
ObfReferenceObject(v16);
AlpcpUnlockMessage(v15);
LOBYTE(PreviousMode) = v10;
LOBYTE(Object) = 0;
v11 = PsOpenThread(
&ThreadHandlea,
(unsigned int)DesiredAccess,
&v26,
(CLIENT_ID *)((char *)&Source2 + 8),
(INT64)Object,
PreviousMode,
(INT64)DmaAdapter,
BugCheckParameter2);
HalPutDmaAdapter(v16);
HalPutDmaAdapter(v14);
if( v11 >= 0 )
*ThreadHandle = ThreadHandlea;
}
else
{
AlpcpUnlockMessage(v15);
HalPutDmaAdapter(v14);
v11 = -1073741790;
}
}
}
}
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return(unsigned int)v11;
}Referenced by:
No references.