SLQueryLicenseValueInternal
NTSTATUS __stdcall SLQueryLicenseValueInternal(
INT64 a1,
const _UNICODE_STRING *a2,
INT64 a3,
VOID *a4,
UINT64 a5,
UINT64 *a6){
__int64 v7;
wchar_t *v8;
NTSTATUS v9;
int v10;
__int64 v11;
unsigned __int16 v12;
__int64(**v13)[9];
UINT64 v14;
__int64(*v15)[9];
_DWORD *v16;
UINT64 *v17;
char v18;
__int64(*v19)[9];
int v20;
unsigned int v21;
__int64 v22;
unsigned __int16 v23;
__int64(**v24)[9];
UINT64 v25;
unsigned int v27;
char *v28;
__int64 v29;
__int64 v30;
unsigned int v31;
char *v32;
__int64 v33;
__int64 v34;
NTSTATUS v35;
_ETHREAD *CurrentThread;
size_t v37;
VOID **PoolWithTag;
unsigned int v39;
const wchar_t **v40;
char v41;
NTSTATUS v42;
_ETHREAD *v43;
NTSTATUS v44;
char v45;
char v46;
NTSTATUS v47;
unsigned __int16 v48;
unsigned int v49;
wchar_t *Str1;
UINT64 *v51;
INT64 v52;
int v53;
INT64 v54;
VOID *v55;
__int64(**v56)[9];
NTSTATUS v57;
int v58;
PVOID P;
__int128 v60;
__int64(*v61)[9];
VOID *v62;
INT64 v63;
const _UNICODE_STRING *v64;
INT64 v65;
__int64 v66[7];
char buf1[112];
char v68[112];
v55 = a4;
v52 = a3;
v7 = a1;
v54 = a1;
v63 = a1;
v64 = a2;
v65 = a3;
v62 = a4;
v51 = a6;
v47 = 0;
v60 = 0i64;
v45 = 0;
v8 = 0i64;
Str1 = 0i64;
P = 0i64;
v58 = 0;
if( !a2 || !a6 || (v9 = 0, v47 = 0, !a2->Buffer) || a2->Length < 2u )
{
v9 = -1073741811;
goto LABEL_85;
}
LOBYTE(v60) = 1;
*((_QWORD *)&v60 + 1) = a2;
v57 = ExpLoadAndSortLicensingCacheDescriptors();
v61 = 0i64;
v46 = 0;
v10 = 1;
v53 = 1;
v49 = 0;
v11 = *((_QWORD *)&v60 + 1);
v12 = **((_WORD **)&v60 + 1);
v48 = **((_WORD **)&v60 + 1);
v56 = &off_140983380;
v13 = &off_140983380;
while( 1 )
{
v14 = *((unsigned __int16 *)v13 + 4);
if( v12 != (_WORD)v14 )
{
v10 += v14;
v53 = v10;
goto LABEL_8;
}
v27 = v12 >> 1;
if( v27 )
{
v28 = buf1;
v29 = *(_QWORD *)(v11 + 8) - (_QWORD)buf1;
v30 = v27;
do
{
*(_WORD *)v28 = *(_WORD *)&v28[v29] ^ ((v10 + 1) | ((_WORD)v10 << 8) | 0x5555);
v10 += 2;
v28 += 2;
--v30;
}
while( v30 );
v53 = v10;
v7 = v54;
}
if( !memcmp(buf1, *v13, v14) )
break;
v10 = v53;
v11 = *((_QWORD *)&v60 + 1);
LABEL_8:
++v49;
v13 += 5;
if( v49 >= 0xE )
{
v15 = 0i64;
goto LABEL_11;
}
v12 = v48;
}
v15 = v13[2];
v61 = v15;
LOBYTE(v8) = *((_BYTE *)v13 + 32);
v46 = (char)v8;
LABEL_11:
if( v15 )
{
if( (_BYTE)v8 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)(v7 + 46840), 0i64);
v35 = ((__int64(__fastcall *)(__int64, INT64, VOID *, _QWORD, UINT64 *, char *))v61)(
v7,
v52,
v55,
(unsigned int)a5,
v51,
&v45);
}
else
{
v35 = ((__int64(__fastcall *)(__int64, INT64, VOID *, _QWORD, UINT64 *, char *))v15)(
v7,
v52,
v55,
(unsigned int)a5,
v51,
&v45);
}
v9 = v35;
v47 = v35;
if( (_BYTE)v8 )
{
if( _InterlockedCompareExchange64((volatile signed __int64 *)(v7 + 46840), 0i64, 17i64) != 17 )
ExfReleasePushLockShared((_EX_PUSH_LOCK *)(v7 + 46840));
KeAbPostRelease((VOID *)(v7 + 46840));
KeLeaveCriticalRegionThread(KeGetCurrentThread());
v9 = v47;
}
}
if( v45 )
{
if( v9 >= 0 )
{
if( *(_DWORD *)v51 > (unsigned int)a5 )
v9 = -1073741789;
v47 = v9;
}
v8 = Str1;
goto LABEL_27;
}
v9 = v57;
if( v57 < 0 )
{
v47 = v57;
goto LABEL_26;
}
v47 = 0;
v49 = 0;
v9 = sub_1403B8E0C(v7, &qword_140983CC0, 0i64, &v49, 4u, &v58);
v47 = v9;
if( !qword_140D2C408 || !v49 || (unsigned __int8)RtlEqualUnicodeString(a2, &stru_140983CA0, 0) )
{
LABEL_15:
v16 = (_DWORD *)v52;
v17 = v51;
goto LABEL_16;
}
v37 = a2->Length + 2;
PoolWithTag = ExAllocatePoolWithTag(1ui64, v37, 542329939i64);
v8 = (wchar_t *)PoolWithTag;
Str1 = (wchar_t *)PoolWithTag;
if( !PoolWithTag )
{
v9 = -1073741801;
LABEL_85:
v47 = v9;
goto LABEL_27;
}
memset(PoolWithTag, 0i64, v37);
memmove(v8, a2->Buffer, a2->Length);
v66[0] = (__int64)L"Security-SPP-GenuineLocalStatus";
v66[1] = (__int64)L"Security-SPP-Action-StateData";
v66[2] = (__int64)L"Security-SPP-LastWindowsActivationHResult";
v66[3] = (__int64)L"Security-SPP-LastWindowsActivationTime";
v66[4] = (__int64)L"Kernel-ExpirationDate";
v66[5] = (__int64)L"SMR-HostManaged-Enabled";
v66[6] = (__int64)L"TerminalServices-RemoteConnectionManager-AllowAppServerMode";
v39 = 0;
v40 = (const wchar_t **)v66;
while( wcsicmp(Str1, *v40) )
{
++v39;
++v40;
if( v39 >= 7 )
{
v41 = 0;
goto LABEL_68;
}
}
v41 = 1;
LABEL_68:
if( v41 )
{
v7 = v54;
goto LABEL_15;
}
SLGetSubscriptionPfn(v54, &P);
v16 = (_DWORD *)v52;
v17 = v51;
v42 = qword_140D2C408(P, 0i64, 0i64, 0i64, Str1, v37, v55, a5, v51, v52, 0i64);
if( (int)(v42 + 0x80000000) < 0 || v42 == -1073741789 )
{
v9 = v42;
if( !(_DWORD)a5 )
v9 = -1073741789;
v47 = v9;
v18 = 0;
v7 = v54;
}
else
{
v7 = v54;
LABEL_16:
v18 = 1;
}
if( v18 )
{
v9 = sub_1403B8E0C(v7, &v60, v16, v55, a5, v17);
v47 = v9;
if( v9 == -1073741762 )
{
v43 = (_ETHREAD *)KeGetCurrentThread();
--v43->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx((_EX_PUSH_LOCK *)(v7 + 46840), 0i64);
*(_BYTE *)(v7 + 46992) = 1;
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)(v7 + 46840), 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((_EX_PUSH_LOCK *)(v7 + 46840));
KeAbPostRelease((VOID *)(v7 + 46840));
KeLeaveCriticalRegionThread(KeGetCurrentThread());
v9 = v47;
}
}
v19 = 0i64;
v20 = 1;
v21 = 0;
v22 = *((_QWORD *)&v60 + 1);
v23 = **((_WORD **)&v60 + 1);
v48 = **((_WORD **)&v60 + 1);
v24 = &off_140983380;
while( 2 )
{
v25 = *((unsigned __int16 *)v24 + 4);
if( v23 != (_WORD)v25 )
{
v20 += v25;
LABEL_22:
++v21;
v24 += 5;
v56 = v24;
if( v21 >= 0xE )
goto LABEL_25;
v23 = v48;
continue;
}
break;
}
v31 = v23 >> 1;
if( v31 )
{
v32 = v68;
v33 = *(_QWORD *)(v22 + 8) - (_QWORD)v68;
v34 = v31;
do
{
*(_WORD *)v32 = *(_WORD *)&v32[v33] ^ ((v20 + 1) | ((_WORD)v20 << 8) | 0x5555);
v20 += 2;
v32 += 2;
--v34;
}
while( v34 );
v7 = v54;
}
if( memcmp(v68, *v24, v25) )
{
v22 = *((_QWORD *)&v60 + 1);
v24 = v56;
goto LABEL_22;
}
v19 = v56[3];
LABEL_25:
if( v19 && (v9 >= 0 || v9 == -1073741772 || v9 == -1073741275) )
{
v44 = ((__int64(__fastcall *)(__int64, INT64, VOID *, _QWORD, UINT64 *, char *))v19)(
v7,
v52,
v55,
(unsigned int)a5,
v51,
&v45);
if( v45 )
{
v9 = v44;
v47 = v44;
}
}
LABEL_26:
v8 = Str1;
LABEL_27:
if( P )
ExFreePoolWithTag(P, 0);
if( v8 )
ExFreePoolWithTag(v8, 0);
return v9;
}Referenced by:
NtQueryLicenseValue
ntoskrnl_27