PiAuditDeviceOperation

NTSTATUS __stdcall PiAuditDeviceOperation(
        _UNICODE_STRING *DeviceInstance,
        PNP_AUDIT_OPERATION_TYPE AuditOperationType,
        UINT8 AuditSuccess){
  VOID **v4; 
  __int32 v5; 
  __int32 v6; 
  __int32 v7; 
  __int32 v8; 
  int v9; 
  NTSTATUS v10; 
  _SE_PLUGPLAY_AUDIT_OPERATION_TYPE v11; 
  UINT64 i; 
  VOID **PoolWithTag; 
  VOID **v14; 
  NTSTATUS ObjectProperty; 
  unsigned __int16 v16; 
  UINT64 v17; 
  VOID **v18; 
  VOID **v19; 
  NTSTATUS v20; 
  unsigned __int16 v21; 
  UINT64 v22; 
  VOID **v23; 
  NTSTATUS v24; 
  unsigned __int16 v25; 
  wchar_t *Buffer; 
  UINT64 j; 
  VOID **v28; 
  VOID **v29; 
  NTSTATUS v30; 
  VOID **v31; 
  VOID **v32; 
  NTSTATUS k; 
  VOID **v34; 
  int AlternateStringData; 
  const wchar_t *v36; 
  INT64 v38; 
  UINT64 v39; 
  UINT8 v40; 
  unsigned int NumberOfBytes; 
  unsigned int NumberOfBytes_4; 
  int v43; 
  const wchar_t *v44; 
  _UNICODE_STRING *DeviceInstanceId; 
  _UNICODE_STRING LocationInformation; 
  _UNICODE_STRING CompatibleIds; 
  _UNICODE_STRING HardwareIds; 
  int v49; 
  _UNICODE_STRING DestinationString; 
  _UNICODE_STRING DeviceDesc; 
  INT64 v52[2]; 

  v40 = AuditSuccess;
  DeviceInstanceId = DeviceInstance;
  v44 = 0i64;
  NumberOfBytes_4 = 0;
  v4 = 0i64;
  v39 = 0i64;
  v43 = 0;
  v38 = 0i64;
  DeviceDesc = 0i64;
  *(_OWORD *)v52 = 0i64;
  DestinationString = 0i64;
  CompatibleIds = 0i64;
  HardwareIds = 0i64;
  LocationInformation = 0i64;
  if( AuditOperationType )
  {
    v5 = AuditOperationType - 1;
    if( v5 )
    {
      v6 = v5 - 1;
      if( v6 )
      {
        v7 = v6 - 1;
        if( v7 )
        {
          v8 = v7 - 1;
          if( v8 )
          {
            v9 = v8 - 1;
            if( v9 )
            {
              if( v9 != 1 )
                return -1073741823;
              v11 = SE_PLUGPLAY_AUDIT_INSTALL_UNBLOCKED;
            }
            else
            {
              v11 = SE_PLUGPLAY_AUDIT_INSTALL_BLOCKED;
            }
          }
          else
          {
            v11 = SE_PLUGPLAY_AUDIT_ENABLE_ACTION;
          }
        }
        else
        {
          v11 = SE_PLUGPLAY_AUDIT_ENABLE_REQUEST;
        }
      }
      else
      {
        v11 = SE_PLUGPLAY_AUDIT_DISABLE_ACTION;
      }
    }
    else
    {
      v11 = SE_PLUGPLAY_AUDIT_DISABLE_REQUEST;
    }
  }
  else
  {
    v11 = SE_PLUGPLAY_AUDIT_REMOVABLE_START;
  }
  NumberOfBytes = 512;
  for( i = 512i64; ; i = NumberOfBytes )
  {
    PoolWithTag = ExAllocatePoolWithTag(1ui64, i, 538996816i64);
    v14 = PoolWithTag;
    if( !PoolWithTag )
      return -1073741670;
    ObjectProperty = PnpGetObjectProperty(
                       *(&stru_140CF2E80 + 1214),
                       (INT64)DeviceInstance->Buffer,
                       1i64,
                       0i64,
                       0i64,
                       (INT64)&DEVPKEY_Device_HardwareIds,
                       (INT64)&v38,
                       (INT64)PoolWithTag);
    if( ObjectProperty != -1073741789 )
      break;
    ExFreePoolWithTag(v14, 0);
  }
  if( ObjectProperty >= 0 && (_DWORD)v38 == 8210 )
  {
    v16 = NumberOfBytes;
  }
  else
  {
    ExFreePoolWithTag(v14, 0);
    v16 = 0;
    v14 = 0i64;
    NumberOfBytes = 0;
  }
  HardwareIds.Length = v16;
  v17 = 512i64;
  HardwareIds.MaximumLength = v16;
  HardwareIds.Buffer = (wchar_t *)v14;
  HIDWORD(v38) = 512;
  while( 1 )
  {
    v18 = ExAllocatePoolWithTag(1ui64, v17, 538996816i64);
    v19 = v18;
    if( !v18 )
    {
      v10 = -1073741670;
      goto LABEL_74;
    }
    v20 = PnpGetObjectProperty(
            *(&stru_140CF2E80 + 1214),
            (INT64)DeviceInstance->Buffer,
            1i64,
            0i64,
            0i64,
            (INT64)&DEVPKEY_Device_CompatibleIds,
            (INT64)&v38,
            (INT64)v18);
    if( v20 != -1073741789 )
      break;
    ExFreePoolWithTag(v19, 0);
    v17 = HIDWORD(v38);
  }
  if( v20 >= 0 && (_DWORD)v38 == 8210 )
  {
    v21 = WORD2(v38);
  }
  else
  {
    ExFreePoolWithTag(v19, 0);
    v21 = 0;
    v19 = 0i64;
    HIDWORD(v38) = 0;
  }
  v22 = 64i64;
  CompatibleIds.Length = v21;
  LODWORD(v39) = 64;
  CompatibleIds.MaximumLength = v21;
  CompatibleIds.Buffer = (wchar_t *)v19;
  while( 1 )
  {
    v23 = ExAllocatePoolWithTag(1ui64, v22, 538996816i64);
    v4 = v23;
    if( !v23 )
      break;
    v24 = PnpGetObjectProperty(
            *(&stru_140CF2E80 + 1214),
            (INT64)DeviceInstance->Buffer,
            1i64,
            0i64,
            0i64,
            (INT64)&DEVPKEY_Device_LocationInfo,
            (INT64)&v38,
            (INT64)v23);
    if( v24 != -1073741789 )
    {
      if( v24 >= 0 && (_DWORD)v38 == 18 )
      {
        v25 = v39;
      }
      else
      {
        ExFreePoolWithTag(v4, 0);
        v25 = 0;
        v4 = 0i64;
        LODWORD(v39) = 0;
      }
      Buffer = DeviceInstance->Buffer;
      LocationInformation.Length = v25;
      LocationInformation.MaximumLength = v25;
      v43 = 16;
      LocationInformation.Buffer = (wchar_t *)v4;
      if( PnpGetObjectProperty(
             *(&stru_140CF2E80 + 1214),
             (INT64)Buffer,
             1i64,
             0i64,
             0i64,
             (INT64)&DEVPKEY_Device_ClassGuid,
             (INT64)&v38,
             (INT64)v52) < 0
        || (_DWORD)v38 != 13
        || v43 != 16 )
      {
        *(_OWORD *)v52 = 0i64;
      }
      NumberOfBytes_4 = 32;
      for( j = 32i64; ; j = NumberOfBytes_4 )
      {
        v28 = ExAllocatePoolWithTag(1ui64, j, 538996816i64);
        v29 = v28;
        if( !v28 )
          goto LABEL_35;
        v30 = PnpGetObjectProperty(
                *(&stru_140CF2E80 + 1214),
                (INT64)DeviceInstance->Buffer,
                1i64,
                0i64,
                0i64,
                (INT64)&DEVPKEY_Device_Class,
                (INT64)&v38,
                (INT64)v28);
        if( v30 != -1073741789 )
          break;
        ExFreePoolWithTag(v29, 0);
      }
      if( v30 < 0 || (_DWORD)v38 != 18 )
      {
        ExFreePoolWithTag(v29, 0);
        v29 = 0i64;
        NumberOfBytes_4 = 0;
      }
      RtlInitUnicodeString(&DestinationString, (PCWSTR)v29);
      HIDWORD(v39) = 32;
      v31 = ExAllocatePoolWithTag(1ui64, 0x20ui64, 538996816i64);
      v32 = v31;
      if( !v31 )
      {
LABEL_54:
        v10 = -1073741670;
LABEL_70:
        if( v29 )
          ExFreePoolWithTag(v29, 0);
        goto LABEL_72;
      }
      for( k = PnpGetObjectProperty(
                  *(&stru_140CF2E80 + 1214),
                  (INT64)DeviceInstance->Buffer,
                  1i64,
                  0i64,
                  0i64,
                  (INT64)&DEVPKEY_NAME,
                  (INT64)&v38,
                  (INT64)v31);
            ;
            k = PnpGetObjectProperty(
                  *(&stru_140CF2E80 + 1214),
                  (INT64)DeviceInstanceId->Buffer,
                  1i64,
                  0i64,
                  0i64,
                  (INT64)&DEVPKEY_NAME,
                  (INT64)&v38,
                  (INT64)v34) )
      {
        v10 = k;
        if( k != -1073741789 )
          break;
        ExFreePoolWithTag(v32, 0);
        v34 = ExAllocatePoolWithTag(1ui64, HIDWORD(v39), 538996816i64);
        v32 = v34;
        if( !v34 )
          goto LABEL_54;
      }
      if( k < 0 )
        goto LABEL_67;
      if( (_DWORD)v38 == 25 )
      {
        AlternateStringData = PnpFindAlternateStringData(v32, HIDWORD(v39), &v44, &v49);
        LODWORD(v38) = 18;
        v36 = (const wchar_t *)v32;
        if( AlternateStringData )
          v36 = v44;
        goto LABEL_68;
      }
      if( (_DWORD)v38 == 18 )
      {
        v36 = (const wchar_t *)v32;
      }
      else
      {
LABEL_67:
        v10 = 0;
        ExFreePoolWithTag(v32, 0);
        HIDWORD(v39) = 0;
        v32 = 0i64;
        v36 = 0i64;
      }
LABEL_68:
      RtlInitUnicodeString(&DeviceDesc, v36);
      SeAuditPlugAndPlay(
        DeviceInstanceId,
        &DeviceDesc,
        &HardwareIds,
        &CompatibleIds,
        &LocationInformation,
        (_GUID *)v52,
        &DestinationString,
        v11,
        v40);
      if( v32 )
        ExFreePoolWithTag(v32, 0);
      goto LABEL_70;
    }
    ExFreePoolWithTag(v4, 0);
    v22 = (unsigned int)v39;
  }
LABEL_35:
  v10 = -1073741670;
LABEL_72:
  if( v19 )
    ExFreePoolWithTag(v19, 0);
LABEL_74:
  if( v14 )
    ExFreePoolWithTag(v14, 0);
  if( v4 )
    ExFreePoolWithTag(v4, 0);
  return v10;
}

Referenced by:

PiAuditDeviceEnableDisableAction
PiAuditDeviceEnableDisableRequest
PiAuditDeviceStart
PiPnpRtlSetObjectProperty