IoRegisterPlugPlayNotification

NTSTATUS __fastcall IoRegisterPlugPlayNotification(
        INT64 a1,
        INT8 a2,
        OWORD *a3,
        UINT64 a4,
        INT64 CallbackRoutine,
        INT64 Context,
        INT64 *NotificationEntry){
  int v9; 
  NTSTATUS result; 
  INT64 v11; 
  int v12; 
  int v13; 
  int v14; 
  NTSTATUS restarted; 
  VOID **PoolWithTag; 
  WCHAR *v17; 
  VOID ***v18; 
  _FAST_MUTEX *v19; 
  _DWORD *v20; 
  char *v21; 
  VOID ***v22; 
  __int128 v23; 
  int v24; 
  WCHAR *v25; 
  WCHAR *i; 
  _EJOB *CurrentServerSilo; 
  int SessionIdFromSymbolicName; 
  VOID ***v29; 
  _ADAPTER_OBJECT *v30; 
  UINT32 v31; 
  UINT64 Tag; 
  WCHAR *SymbolicLinkList; 
  _UNICODE_STRING DestinationString; 
  int v35; 
  GUID v36; 
  __int128 v37; 
  int v38; 
  _UNICODE_STRING *SymbolicLinkName; 

  LODWORD(SymbolicLinkList) = a2;
  v9 = a1;
  LODWORD(Tag) = 1315991120;
  *NotificationEntry = 0i64;
  result = ObReferenceObjectByPointerWithTag((VOID *)a4, 0i64, IoDriverObjectType, 0, Tag);
  if( result >= 0 )
  {
    v12 = v9 - 1;
    if( v12 )
    {
      v13 = v12 - 1;
      if( v13 )
      {
        v14 = v13 - 1;
        if( v14 )
        {
          if( v14 != 1 )
          {
            restarted = -1073741585;
            goto LABEL_33;
          }
          restarted = PiRegisterKernelSoftRestartNotification(
                        a4,
                        (VOID *)CallbackRoutine,
                        Context,
                        (CHAR **)NotificationEntry);
          goto LABEL_13;
        }
        SymbolicLinkList = 0i64;
        restarted = PnpGetRelatedTargetDevice((_FILE_OBJECT *)a3, &SymbolicLinkList, v11);
        if( restarted < 0 )
          goto LABEL_33;
        PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x70ui64, 1131441744i64);
        if( PoolWithTag )
        {
          restarted = PnpInitializeNotifyEntry(
                        (__int64)PoolWithTag,
                        3,
                        (VOID *)CallbackRoutine,
                        Context,
                        a4,
                        (__int64)&stru_140C452E0 + 256);
          if( restarted < 0 )
          {
            ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
            v30 = (_ADAPTER_OBJECT *)*((_QWORD *)SymbolicLinkList + 4);
          }
          else
          {
            v17 = SymbolicLinkList;
            PoolWithTag[10] = a3;
            PoolWithTag[11] = (VOID *)*((_QWORD *)v17 + 4);
            restarted = PnpDeferNotification((__int64)PoolWithTag);
            if( restarted >= 0 )
            {
              KeAcquireGuardedMutex((PKGUARDED_MUTEX)((char *)&stru_140C452E0 + 256));
              v18 = (VOID ***)*((_QWORD *)v17 + 60);
              if( *v18 == (VOID **)(v17 + 236) )
              {
                *PoolWithTag = v17 + 236;
                v19 = (_FAST_MUTEX *)((char *)&stru_140C452E0 + 256);
                PoolWithTag[1] = v18;
                *v18 = PoolWithTag;
                *((_QWORD *)v17 + 60) = PoolWithTag;
LABEL_11:
                KeReleaseGuardedMutex(v19);
LABEL_12:
                *NotificationEntry = (INT64)PoolWithTag;
                goto LABEL_13;
              }
              goto LABEL_47;
            }
            ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
            v30 = (_ADAPTER_OBJECT *)*((_QWORD *)v17 + 4);
          }
          HalPutDmaAdapter(v30);
LABEL_13:
          if( restarted >= 0 )
            return restarted;
LABEL_33:
          ObfDereferenceObjectWithTag((VOID *)a4, 0x4E706E50ui64);
          return restarted;
        }
        HalPutDmaAdapter(*((PADAPTER_OBJECT *)SymbolicLinkList + 4));
LABEL_38:
        restarted = -1073741670;
        goto LABEL_33;
      }
      PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x60ui64, 1148218960i64);
      if( !PoolWithTag )
        goto LABEL_38;
      restarted = PnpInitializeNotifyEntry(
                    (__int64)PoolWithTag,
                    2,
                    (VOID *)CallbackRoutine,
                    Context,
                    a4,
                    (__int64)&stru_140C452E0 + 192);
      if( restarted < 0 )
        goto LABEL_33;
      v20 = PoolWithTag + 10;
      *((_OWORD *)PoolWithTag + 5) = *a3;
      restarted = PnpDeferNotification((__int64)PoolWithTag);
      if( restarted >= 0 )
      {
        KeAcquireGuardedMutex((PKGUARDED_MUTEX)((char *)&stru_140C452E0 + 192));
        v21 = (char *)&PnpDeviceClassNotifyList
            + 16
            * ((*v20 + *((_DWORD *)PoolWithTag + 21) + *((_DWORD *)PoolWithTag + 22) + *((_DWORD *)PoolWithTag + 23))
             % 0xDu);
        v22 = (VOID ***)*((_QWORD *)v21 + 1);
        if( *v22 == (VOID **)v21 )
        {
          *PoolWithTag = v21;
          PoolWithTag[1] = v22;
          *v22 = PoolWithTag;
          *((_QWORD *)v21 + 1) = PoolWithTag;
          KeReleaseGuardedMutex((PKGUARDED_MUTEX)((char *)&stru_140C452E0 + 192));
          if( ((unsigned __int8)SymbolicLinkList & 1) != 0 )
          {
            v23 = *(_OWORD *)v20;
            SymbolicLinkList = 0i64;
            DestinationString = 0i64;
            v38 = 0;
            v35 = 3145729;
            v36 = GUID_DEVICE_INTERFACE_ARRIVAL;
            v37 = v23;
            IopGetDeviceInterfaces((const _GUID *)PoolWithTag + 5, 0i64, 0i64, 0, &SymbolicLinkList, 0i64);
            restarted = v24;
            if( v24 < 0 )
              goto LABEL_33;
            v25 = SymbolicLinkList;
            for( i = SymbolicLinkList; *i; i += ((unsigned __int64)DestinationString.Length >> 1) + 1 )
            {
              LODWORD(SymbolicLinkList) = 0;
              RtlInitUnicodeString(&DestinationString, i);
              SymbolicLinkName = &DestinationString;
              CurrentServerSilo = PsGetCurrentServerSilo();
              if( *((_DWORD *)PoolWithTag + 5) != PsGetServerSiloServiceSessionId((INT64)CurrentServerSilo) )
              {
                SessionIdFromSymbolicName = IopGetSessionIdFromSymbolicName(SymbolicLinkName);
                if( SessionIdFromSymbolicName != -1 && *((_DWORD *)PoolWithTag + 5) != SessionIdFromSymbolicName )
                  continue;
              }
              PnpNotifyDriverCallback((__int64)PoolWithTag, (__int64)&v35, &SymbolicLinkList);
            }
            ExFreePoolWithTag(v25, 0);
          }
          goto LABEL_12;
        }
        goto LABEL_47;
      }
      v31 = 1148218960;
    }
    else
    {
      PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x50ui64, 963669584i64);
      if( !PoolWithTag )
        goto LABEL_38;
      restarted = PnpInitializeNotifyEntry(
                    (__int64)PoolWithTag,
                    1,
                    (VOID *)CallbackRoutine,
                    Context,
                    a4,
                    (__int64)&stru_140C452E0 + 64);
      if( restarted < 0 )
        goto LABEL_33;
      restarted = PnpDeferNotification((__int64)PoolWithTag);
      if( restarted >= 0 )
      {
        KeAcquireGuardedMutex((PKGUARDED_MUTEX)((char *)&stru_140C452E0 + 64));
        v29 = (VOID ***)qword_140D2DB58;
        if( *(PVOID **)qword_140D2DB58 == &PnpProfileNotifyList )
        {
          *PoolWithTag = &PnpProfileNotifyList;
          v19 = (_FAST_MUTEX *)((char *)&stru_140C452E0 + 64);
          PoolWithTag[1] = v29;
          *v29 = PoolWithTag;
          qword_140D2DB58 = (__int64)PoolWithTag;
          goto LABEL_11;
        }
LABEL_47:
        __fastfail(3u);
      }
      v31 = 963669584;
    }
    ExFreePoolWithTag(PoolWithTag, v31);
    goto LABEL_13;
  }
  return result;
}

Referenced by:

HalpPostPnpInitialize
PoInitDriverServices
PopRegisterCoolingExtensionProtection
SbpWaitForVmbus
SmKmStoreFileCreate