CmpInitHiveFromFile

INT64 __fastcall CmpInitHiveFromFile(
        _UNICODE_STRING *FileName,
        UINT64 HiveFlags,
        _CMHIVE **CmHive,
        UINT8 *Allocate,
        UINT64 CheckFlags,
        _GUID *HiveRmUuid,
        _GUID *HiveTmUuid,
        UINT8 *NeedRmLogStart,
        _HIVE_LOAD_FAILURE *HiveLoadFailure){
  _CMHIVE **v9; 
  int v10; 
  __int64 a6; 
  VOID *v13; 
  unsigned int v14; 
  UINT64 v15; 
  PVOID v16; 
  int v17; 
  NTSTATUS v18; 
  int v19; 
  VOID *v20; 
  int v22; 
  _ETHREAD *CurrentThread; 
  _HIVE_LOAD_FAILURE *a12; 
  char v25; 
  VOID **PoolWithTag; 
  _UNICODE_STRING *v27; 
  _HHIVE *v28; 
  NTSTATUS v29; 
  INT64 v30; 
  UINT64 Point; 
  UINT64 Pointa; 
  UINT64 Flags; 
  char v34; 
  char v35; 
  UINT8 v36; 
  int v37; 
  UINT64 a4; 
  _HHIVE *Hive; 
  VOID *Handle; 
  _HIVE_LOAD_FAILURE *HiveLoadFailurea; 
  UINT64 v42; 
  __int64 v43; 
  VOID *FileHandle; 
  PVOID SecurityDescriptor; 
  int v46; 
  int v47; 
  _CMHIVE **v48; 
  int v49; 
  int v50; 
  UINT64 a3; 
  __int64 a7; 
  UINT8 *v53; 
  INT64 a11; 
  INT64 v55[2]; 
  __int128 v56; 
  _IO_STATUS_BLOCK IoStatusBlock; 
  __int128 FileInformation; 
  __int128 v59; 
  __int64 v60; 
  _KAPC_STATE ApcState; 
  _EVENT_DATA_DESCRIPTOR v62; 
  int *v63; 
  __int64 v64; 
  wchar_t *Buffer; 
  int v66[2]; 
  _EVENT_DATA_DESCRIPTOR v67; 
  int *v68; 
  int v69; 
  int v70; 
  _HIVE_LOAD_FAILURE *v71; 

  a11 = (INT64)HiveLoadFailure;
  v9 = CmHive;
  HiveLoadFailurea = v71;
  v48 = CmHive;
  v10 = HiveFlags;
  a6 = (__int64)HiveRmUuid;
  v53 = Allocate;
  LODWORD(a3) = HiveFlags;
  v43 = (__int64)HiveRmUuid;
  *(_OWORD *)v55 = 0i64;
  v47 = 0;
  v56 = 0i64;
  v50 = 0;
  Hive = 0i64;
  v46 = 0;
  FileInformation = 0i64;
  v60 = 0i64;
  v59 = 0i64;
  IoStatusBlock = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  if( *(&stru_140C00F40 + 1148) > 4u )
  {
    if( tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
    {
      v64 = 2i64;
      v63 = v66;
      Buffer = FileName->Buffer;
      v66[0] = FileName->Length;
      v66[1] = 0;
      tlgWriteTransfer_EtwWriteTransfer(
        (__int64)&stru_140C00F40 + 4592,
        (unsigned __int8 *)byte_140021A6D,
        0i64,
        0i64,
        4u,
        &v62);
      Allocate = v53;
      v9 = v48;
    }
    a6 = v43;
  }
  v35 = 0;
  v13 = 0i64;
  v14 = ((unsigned int)CheckFlags >> 19) & 0x40;
  v36 = 0;
  FileHandle = 0i64;
  v49 = v10 & 0x8000;
  v15 = 0i64;
  Handle = 0i64;
  v16 = 0i64;
  v42 = 0i64;
  v34 = 1;
  SecurityDescriptor = 0i64;
  if( (v10 & 0x8000) != 0 )
  {
    v34 = 0;
    v17 = v14 | ((v10 & 0x40000 | 0x10000u) >> 11);
  }
  else
  {
    v17 = v14 | 2;
    if( (CheckFlags & 0x40000000) == 0 )
      v17 = ((unsigned int)CheckFlags >> 19) & 0x40;
    if( *Allocate )
      v17 |= 1u;
  }
  while( 1 )
  {
    *v9 = 0i64;
    a7 = 0i64;
    v18 = CmpOpenHiveFile(FileName, 0, &FileHandle, &v46, v17, a6, (__int64)&a7, 0i64, 0i64);
    v19 = v18;
    if( v18 < 0 )
    {
      LODWORD(Point) = 16;
      SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, (unsigned int)v18, Point);
      v20 = FileHandle;
      goto LABEL_9;
    }
    v37 = v17;
    if( v46 == 2 )
    {
      v35 = 1;
      v37 = v17 | 0x10;
    }
    v20 = FileHandle;
    if( !v49 )
    {
      v19 = CmpQueryFileSecurityDescriptor(FileHandle, &SecurityDescriptor);
      if( v19 < 0 )
      {
        LODWORD(Point) = 32;
        SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, (unsigned int)v19, Point);
        v16 = SecurityDescriptor;
        goto LABEL_9;
      }
      v16 = SecurityDescriptor;
    }
    if( (CheckFlags & 0x10000000) != 0 )
    {
      LODWORD(a4) = 1;
      v22 = CmpOpenHiveFile(FileName, 1u, &Handle, &v47, v37, v43, 0i64, (__int64)v16, 0i64);
      v19 = v22;
      if( v22 < 0 )
      {
        v13 = 0i64;
        Handle = 0i64;
        if( v34 )
        {
          LODWORD(Pointa) = 48;
          goto LABEL_78;
        }
      }
      else
      {
        v13 = Handle;
      }
    }
    else
    {
      LODWORD(a4) = 2;
      v19 = CmpOpenHiveFile(FileName, 4u, &Handle, &v47, v37, v43, 0i64, (__int64)v16, 0i64);
      if( v19 < 0 )
      {
        v13 = 0i64;
        Handle = 0i64;
        if( v34 )
        {
          LODWORD(Pointa) = 64;
          v30 = (unsigned int)v19;
LABEL_79:
          SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, v30, Pointa);
          goto LABEL_9;
        }
      }
      else
      {
        v13 = Handle;
      }
      v22 = CmpOpenHiveFile(FileName, 5u, (VOID **)&v42, &v50, v37, v43, 0i64, (__int64)v16, 0i64);
      v19 = v22;
      if( v22 >= 0 )
      {
        v15 = v42;
        goto LABEL_31;
      }
      v15 = 0i64;
      v42 = 0i64;
      if( v34 )
      {
        LODWORD(Pointa) = 80;
LABEL_78:
        v30 = (unsigned int)v22;
        goto LABEL_79;
      }
    }
LABEL_31:
    if( !v34 )
    {
      if( (_DWORD)a4 != 2 )
      {
        LODWORD(a4) = v13 != 0i64;
        goto LABEL_35;
      }
      if( v13 )
      {
        if( v15 )
          goto LABEL_35;
        ZwClose((_HANDLE)v13);
        v13 = 0i64;
        Handle = 0i64;
      }
      if( v15 )
      {
        ZwClose(v15);
        v15 = 0i64;
        v42 = 0i64;
      }
      LODWORD(a4) = 0;
    }
LABEL_35:
    if( !v36 )
    {
      CurrentThread = (_ETHREAD *)KeGetCurrentThread();
      --CurrentThread->Tcb.KernelApcDisable;
      v36 = ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
      if( !v36 )
        KeLeaveCriticalRegionThread(KeGetCurrentThread());
      v13 = Handle;
      v15 = v42;
      v20 = FileHandle;
      v16 = SecurityDescriptor;
      if( !v36 )
      {
        v19 = -1073741431;
        goto LABEL_9;
      }
    }
    a12 = HiveLoadFailurea;
    v55[0] = (INT64)v20;
    v55[1] = (INT64)v13;
    v56 = v15;
    memset(HiveLoadFailurea, 0i64, 0x1B0u);
    LODWORD(Flags) = CheckFlags;
    v22 = CmpCreateHive(
            (INT64)&Hive,
            v35 == 0 ? 5 : 0,
            (unsigned int)a3,
            (unsigned int)a4,
            0i64,
            (INT64)v55,
            (INT64)FileName,
            Flags,
            0i64,
            0i64,
            a11,
            (INT64)a12);
    v19 = v22;
    if( v22 != -1073741267 )
      break;
    ZwClose((_HANDLE)v20);
    FileHandle = 0i64;
    if( v13 )
    {
      ZwClose((_HANDLE)v13);
      v13 = 0i64;
      Handle = 0i64;
    }
    a6 = v43;
    v9 = v48;
    if( v15 )
    {
      ZwClose(v15);
      a6 = v43;
      v15 = 0i64;
      v9 = v48;
      v42 = 0i64;
    }
  }
  if( v22 < 0 )
  {
    LODWORD(Pointa) = 96;
    goto LABEL_78;
  }
  v25 = v35;
  if( !v35 && (Hive[2].Storage[1].FreeDisplay[6].RealVectorSize & 0x800) != 0 )
  {
    CmpAttachToRegistryProcess(&ApcState);
    v29 = CmpFlushHive((CMHIVE *)Hive, 0xCui64);
    KiUnstackDetachProcess(&ApcState, 0i64);
    if( v29 < 0 )
    {
      LODWORD(Pointa) = 230;
      SetFailureLocation(HiveLoadFailurea, 1ui64, _CmpCreateHive, (unsigned int)v29, Pointa);
    }
    v25 = 0;
  }
  PoolWithTag = ExAllocatePoolWithTag(1ui64, FileName->Length, 1649298755i64);
  *(_QWORD *)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize = PoolWithTag;
  v28 = Hive;
  if( *(_QWORD *)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize )
  {
    LOWORD(Hive[1].Storage[0].Guard) = FileName->Length;
    HIWORD(Hive[1].Storage[0].Guard) = FileName->Length;
    memmove(*(VOID **)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize, FileName->Buffer, FileName->Length);
    v28 = Hive;
  }
  if( (v28->BaseBlock->BootType & 4) != 0 )
    CmpLogEvent((_EVENT_DESCRIPTOR *)®_EVENT_SELFHEAL, 2147483690i64, FileName, v27);
  if( ZwQueryInformationFile(v20, &IoStatusBlock, &FileInformation, 0x28ui64, FileBasicInformation) >= 0 )
    *(_QWORD *)&Hive[2].Storage[1].FreeDisplay[9].RealVectorSize = v59;
  Hive->LogFileSizeCap = HIDWORD(a7);
  *v48 = (_CMHIVE *)Hive;
  *v53 = v25;
  v19 = 0;
LABEL_9:
  if( v36 )
  {
    ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
    v13 = Handle;
    v15 = v42;
    v20 = FileHandle;
    v16 = SecurityDescriptor;
  }
  if( v20 )
    ZwClose((_HANDLE)v20);
  if( v13 )
    ZwClose((_HANDLE)v13);
  if( v15 )
    ZwClose(v15);
  if( v16 )
    ExFreePoolWithTag(v16, 0);
  if( *(&stru_140C00F40 + 1148) > 4u && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
  {
    v70 = 0;
    v68 = &v37;
    v37 = v19;
    v69 = 4;
    tlgWriteTransfer_EtwWriteTransfer(
      (__int64)&stru_140C00F40 + 4592,
      (unsigned __int8 *)byte_140021A43,
      0i64,
      0i64,
      3u,
      &v67);
  }
  return(unsigned int)v19;
}

Referenced by:

CmpCmdHiveOpen
CmpLoadHiveThread