NtAlpcOpenSenderThread

INT64 __fastcall NtAlpcOpenSenderThread(
        VOID **ThreadHandle,
        VOID *PortHandle,
        _PORT_MESSAGE *PortMessage,
        UINT64 Flags,
        UINT64 DesiredAccess,
        _OBJECT_ATTRIBUTES *ObjectAttributes){
  unsigned int v6; 
  _ETHREAD *CurrentThread; 
  KPROCESSOR_MODE v10; 
  int v11; 
  _OBJECT_ATTRIBUTES *v12; 
  __int64 v13; 
  struct _DMA_ADAPTER *v14; 
  ULONG_PTR v15; 
  struct _DMA_ADAPTER *v16; 
  PVOID *Object; 
  INT64 PreviousMode; 
  PADAPTER_OBJECT DmaAdapter; 
  ULONG_PTR BugCheckParameter2; 
  VOID *ThreadHandlea; 
  __int128 Source2; 
  INT64 v24[2]; 
  INT64 v25; 
  OBJECT_ATTRIBUTES v26; 
  v6 = Flags;
  Source2 = 0i64;
  *(_OWORD *)v24 = 0i64;
  v25 = 0i64;
  ThreadHandlea = 0i64;
  BugCheckParameter2 = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  v10 = *((_BYTE *)KeGetCurrentThread() + 562);
  DmaAdapter = 0i64;
  v11 = ObReferenceObjectByHandle(PortHandle, 0x20000u, AlpcPortObjectType, v10, (PVOID *)&DmaAdapter, 0i64);
  if( v11 >= 0 )
  {
    if( v10 )
    {
      v13 = 0x7FFFFFFF0000i64;
      if( (unsigned __int64)ThreadHandle < 0x7FFFFFFF0000i64 )
        v13 = (__int64)ThreadHandle;
      *(_QWORD *)v13 = *(_QWORD *)v13;
      AlpcpProbeAndCaptureMessageHeader(PortMessage, (_PORT_MESSAGE *)&Source2, v6);
      if( ObjectAttributes < v12 )
        v12 = ObjectAttributes;
      v26 = *v12;
    }
    else
    {
      Source2 = *(_OWORD *)PortMessage;
      *(_OWORD *)v24 = *((_OWORD *)PortMessage + 1);
      v25 = *((_QWORD *)PortMessage + 4);
      v26 = *ObjectAttributes;
    }
    v14 = DmaAdapter;
    v11 = AlpcpLookupMessage((INT64)DmaAdapter, LODWORD(v24[1]), (unsigned int)v25, (INT64)v12, &BugCheckParameter2);
    if( v11 < 0 )
    {
      HalPutDmaAdapter(v14);
    }
    else
    {
      v15 = BugCheckParameter2;
      if( (*(_DWORD *)(BugCheckParameter2 + 40) & 0x80u) != 0 )
      {
        AlpcpUnlockMessage(BugCheckParameter2);
        HalPutDmaAdapter(v14);
        v11 = -1073740029;
      }
      else
      {
        v16 = *(struct _DMA_ADAPTER **)(BugCheckParameter2 + 32);
        if( v16 && RtlCompareMemory(&v16[71].DmaOperations, (char *)&Source2 + 8, 0x10ui64) == 16 )
        {
          ObfReferenceObject(v16);
          AlpcpUnlockMessage(v15);
          LOBYTE(PreviousMode) = v10;
          LOBYTE(Object) = 0;
          v11 = PsOpenThread(
                  &ThreadHandlea,
                  (unsigned int)DesiredAccess,
                  &v26,
                  (CLIENT_ID *)((char *)&Source2 + 8),
                  (INT64)Object,
                  PreviousMode,
                  (INT64)DmaAdapter,
                  BugCheckParameter2);
          HalPutDmaAdapter(v16);
          HalPutDmaAdapter(v14);
          if( v11 >= 0 )
            *ThreadHandle = ThreadHandlea;
        }
        else
        {
          AlpcpUnlockMessage(v15);
          HalPutDmaAdapter(v14);
          v11 = -1073741790;
        }
      }
    }
  }
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  return(unsigned int)v11;
}

Referenced by:

No references.