CmLoadKey

NTSTATUS __stdcall CmLoadKey(
        OBJECT_ATTRIBUTES *TargetKey,
        UNICODE_STRING *SourceFile,
        UINT64 Flags,
        CM_KEY_BODY *TrustClassKeyBody,
        CM_KEY_BODY *LowerLayerKeyBody,
        KEVENT *UserEvent,
        UNICODE_STRING **PathToRoot,
        PVOID *LoadKeyContext){
  unsigned int v9; 
  _UNICODE_STRING *ObjectName; 
  unsigned int Length; 
  __int64 v13; 
  _UNICODE_STRING *v14; 
  VOID **PoolWithTag; 
  WCHAR v16; 
  VOID **v17; 
  _UNICODE_STRING *v18; 
  _ETHREAD *CurrentThread; 
  int v20; 
  _HIVE_LOAD_FAILURE *TransientPoolWithTag; 
  _HIVE_LOAD_FAILURE *v22; 
  int v23; 
  int v24; 
  NTSTATUS v25; 
  CMHIVE *v26; 
  char v27; 
  int KeyCommon; 
  __int64 v29; 
  _UNICODE_STRING *p_Destination; 
  NTSTATUS v32; 
  int Conflict; 
  VOID *v34; 
  NTSTATUS v35; 
  unsigned int v36; 
  int RecoverableIndex; 
  int Index; 
  __int64 p_Locations; 
  int FailureCount; 
  int v41; 
  int v42; 
  int v43; 
  UINT64 Point; 
  UINT64 Pointa; 
  UINT64 Pointb; 
  UINT64 Pointc; 
  UINT64 Pointd; 
  UINT64 Pointe; 
  POBJECT_HANDLE_INFORMATION HandleInformation; 
  VOID **NeedRmLogStart; 
  char Allocate[3]; 
  __int16 v53; 
  __int16 v54; 
  __int16 v55; 
  __int16 v56; 
  __int16 v57; 
  __int16 v58; 
  PVOID P; 
  int v60; 
  NTSTATUS v61; 
  NTSTATUS v62; 
  NTSTATUS v63; 
  _HANDLE Handle[2]; 
  PVOID Object; 
  PVOID v66; 
  UINT8 v67[8]; 
  KEVENT *v68; 
  CM_KEY_BODY *TrustClassKeyBodya; 
  UINT8 *v70; 
  __int64 v71; 
  CM_KEY_BODY *v72; 
  _UNICODE_STRING Destination; 
  __int64 v74; 
  __int64 v75; 
  __int64 v76; 
  __int64 v77; 
  _KAPC_STATE ApcState; 
  _EVENT_DATA_DESCRIPTOR v79; 
  __int64 *v80; 
  __int64 v81; 
  int *v82; 
  __int64 v83; 
  __int16 *v84; 
  __int64 v85; 
  __int16 *v86; 
  __int64 v87; 
  __int16 *v88; 
  __int64 v89; 
  unsigned __int16 *p_Index; 
  __int64 v91; 
  struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *v92; 
  int v93; 
  int v94; 
  unsigned __int16 *p_RecoverableIndex; 
  __int64 v96; 
  struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *p_RecoverableLocations; 
  int v98; 
  int v99; 
  unsigned __int8 *p_FailureCount; 
  __int64 v101; 
  struct {int Status;unsigned int Point;} *p_FailurePoints; 
  int v103; 
  int v104; 
  __int64 *v105; 
  __int64 v106; 
  _EVENT_DATA_DESCRIPTOR v107; 
  int *v108; 
  __int64 v109; 
  __int16 *v110; 
  __int64 v111; 
  __int16 *v112; 
  __int64 v113; 
  __int16 *v114; 
  __int64 v115; 
  unsigned __int16 *v116; 
  __int64 v117; 
  __int64 v118; 
  int v119; 
  int v120; 
  unsigned __int16 *v121; 
  __int64 v122; 
  struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *v123; 
  int v124; 
  int v125; 
  unsigned __int8 *v126; 
  __int64 v127; 
  struct {int Status;unsigned int Point;} *v128; 
  int v129; 
  int v130; 
  _EVENT_DATA_DESCRIPTOR v131; 
  __int64 *v132; 
  __int64 v133; 
  int *v134; 
  __int64 v135; 
  __int64 *v136; 
  __int64 v137; 
  char v138; 
  __int64 v139; 
  __int64 v140; 

  v72 = LowerLayerKeyBody;
  v68 = (KEVENT *)PathToRoot;
  v9 = Flags;
  v70 = (UINT8 *)LoadKeyContext;
  v71 = v139;
  *(_QWORD *)v67 = v140;
  ObjectName = TargetKey->ObjectName;
  memset(&ApcState, 0, sizeof(ApcState));
  TrustClassKeyBodya = TrustClassKeyBody;
  P = 0i64;
  Length = ObjectName->Length;
  *(_QWORD *)Handle = 0i64;
  v60 = 0;
  if( (unsigned __int16)Length >= 2u )
  {
    LODWORD(v13) = Length >> 1;
    if( Length >> 1 )
    {
      do
      {
        v14 = TargetKey->ObjectName;
        v13 = (unsigned int)(v13 - 1);
        if( v14->Buffer[v13] != 92 )
          break;
        v14->Length -= 2;
      }
      while( (_DWORD)v13 );
    }
  }
  if( TargetKey->ObjectName->Length < 2u )
    return -1073741811;
  PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x104ui64, 1649626435i64);
  v17 = PoolWithTag;
  if( !PoolWithTag )
    return -1073741670;
  v18 = TargetKey->ObjectName;
  *(_QWORD *)&Destination.Length = 17039360i64;
  Destination.Buffer = (wchar_t *)PoolWithTag;
  if( CmpQueryHiveRedirectionFileList(v18, &Destination, v16) )
  {
    p_Destination = &Destination;
    if( Destination.Length == 2 )
      p_Destination = SourceFile;
    SourceFile = p_Destination;
  }
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  if( !ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132) )
  {
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
    ExFreePoolWithTag(v17, 0);
    return -1073741431;
  }
  v20 = ((v9 & 0x2000) != 0 ? 3 : 0) | 8;
  if( (v9 & 0x4000) == 0 )
    v20 = (v9 & 0x2000) != 0 ? 3 : 0;
  TransientPoolWithTag = (_HIVE_LOAD_FAILURE *)CmpAllocateTransientPoolWithTag(1ui64, 0x1B0ui64);
  v22 = TransientPoolWithTag;
  if( !TransientPoolWithTag )
  {
    v25 = -1073741670;
    goto LABEL_22;
  }
  memset(TransientPoolWithTag, 0i64, 0x1B0u);
  Allocate[0] = 1;
  v23 = v20 | 4;
  if( !v72 )
    v23 = v20;
  LODWORD(HandleInformation) = v23;
  LODWORD(Point) = ((v9 & 0xFFFFF223 | (2 * (v9 & 0x480 | (2 * (v9 & 0x20 | ((v9 & 4) << 6)))))) << 19) | 0x1190001;
  v24 = CmpCmdHiveOpen(SourceFile, 1u, (UINT8 *)Allocate, (CMHIVE **)&P, Point, (UINT64)HandleInformation, v70);
  v25 = v24;
  if( v24 < 0 )
  {
    if( v24 != -1073741757 )
    {
      LODWORD(Pointa) = 16;
      SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v24, Pointa);
      v26 = (CMHIVE *)P;
      goto LABEL_20;
    }
    if( CmpOpenHiveFile(SourceFile, 0, (VOID **)Handle, &v60, 8, (__int64)v70, 0i64, 0i64, 0i64) >= 0 )
    {
      Object = 0i64;
      v32 = ObReferenceObjectByHandle(
              *(VOID **)Handle,
              0i64,
              (_OBJECT_TYPE *)**(&CmpDummyThreadEvent + 344),
              0,
              &Object,
              0i64);
      ZwClose(Handle[0]);
      if( v32 < 0 )
      {
        LODWORD(Pointc) = 48;
      }
      else
      {
        Conflict = CmpResolveHiveLoadConflict(
                     TargetKey,
                     (__int64)Object,
                     v9,
                     (__int64)TrustClassKeyBodya,
                     (__int64)v68,
                     v22,
                     v138,
                     v71,
                     *(__int64 *)v67);
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
        if( Conflict >= 0 )
        {
          v26 = (CMHIVE *)P;
          goto LABEL_19;
        }
        LODWORD(Pointc) = 64;
      }
    }
    else
    {
      LODWORD(Pointc) = 32;
    }
    v25 = -1073741757;
    SetFailureLocation(v22, 0i64, _CmLoadKey, 3221225539i64, Pointc);
    v26 = (CMHIVE *)P;
    goto LABEL_20;
  }
  v26 = (CMHIVE *)P;
  if( (v9 & 0x2000) != 0 )
  {
    v34 = (VOID *)*((_QWORD *)P + 192);
    v66 = 0i64;
    v35 = ObReferenceObjectByHandle(v34, 0i64, (_OBJECT_TYPE *)**(&CmpDummyThreadEvent + 344), 0, &v66, 0i64);
    v25 = v35;
    if( v35 < 0 )
    {
      LODWORD(Pointd) = 80;
      SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v35, Pointd);
      goto LABEL_20;
    }
    v27 = v138;
    v25 = CmpResolveHiveLoadConflict(
            TargetKey,
            (__int64)v66,
            v9,
            (__int64)TrustClassKeyBodya,
            (__int64)v68,
            v22,
            v138,
            v71,
            *(__int64 *)v67);
    HalPutDmaAdapter((PADAPTER_OBJECT)v66);
    if( v25 < 0 )
    {
      if( v25 == -1073741275 )
        goto LABEL_16;
      LODWORD(Pointe) = 96;
      SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v25, Pointe);
LABEL_20:
      if( v26 )
      {
        CmpAttachToRegistryProcess(&ApcState);
        CmpDestroyHive(v26);
        KiUnstackDetachProcess(&ApcState, 0i64);
      }
      goto LABEL_22;
    }
LABEL_19:
    v25 = 0;
    goto LABEL_20;
  }
  v27 = v138;
LABEL_16:
  if( (_BYTE)UserEvent )
    v26->Flags |= 0x2000u;
  LOBYTE(NeedRmLogStart) = v27;
  KeyCommon = CmpLoadKeyCommon(v26, TargetKey, v9, TrustClassKeyBodya, v72, v68, NeedRmLogStart, v67[0], Allocate[0]);
  v25 = KeyCommon;
  v26 = 0i64;
  if( KeyCommon >= 0 )
    goto LABEL_19;
  LODWORD(Pointb) = 112;
  SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)KeyCommon, Pointb);
LABEL_22:
  ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
  KeLeaveCriticalRegionThread(KeGetCurrentThread());
  ExFreePoolWithTag(v17, 0);
  if( v25 < 0 )
  {
    if( *(&stru_140C00F40 + 1148) > 5u )
    {
      if( tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 0x400000000008i64) )
      {
        v74 = 1i64;
        v80 = &v74;
        v84 = &v53;
        v82 = &v61;
        RecoverableIndex = v22->RecoverableIndex;
        Index = v22->Index;
        p_Index = &v22->Index;
        v86 = &v54;
        p_Locations = (__int64)&v22->Locations;
        v53 = Index;
        FailureCount = v22->LinkDebug.FailureCount;
        v93 = 12 * Index;
        p_RecoverableLocations = &v22->RecoverableLocations;
        v98 = 12 * RecoverableIndex;
        p_FailurePoints = &v22->LinkDebug.FailurePoints;
        v105 = &v75;
        v55 = FailureCount;
        v54 = RecoverableIndex;
        p_RecoverableIndex = &v22->RecoverableIndex;
        v81 = 8i64;
        v61 = v25;
        v83 = 4i64;
        v85 = 2i64;
        v87 = 2i64;
        v88 = &v55;
        v89 = 2i64;
        v91 = 2i64;
        v92 = &v22->Locations;
        v94 = 0;
        v96 = 2i64;
        v99 = 0;
        p_FailureCount = &v22->LinkDebug.FailureCount;
        v101 = 2i64;
        v103 = 8 * FailureCount;
        v104 = 0;
        v75 = 0x1000000i64;
        v106 = 8i64;
        tlgWriteAgg(
          (__int64)&stru_140C00F40 + 4592,
          (unsigned __int8 *)&byte_140021CEB,
          (__int64)&v22->LinkDebug.FailureCount,
          0xEu,
          &v79);
        v36 = *(&stru_140C00F40 + 1148);
      }
      else
      {
        p_Locations = (__int64)&v22->Locations;
      }
      if( v36 > 5 && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
      {
        v62 = v25;
        v108 = &v62;
        v110 = &v56;
        v41 = v22->Index;
        v42 = v22->RecoverableIndex;
        v116 = &v22->Index;
        v112 = &v57;
        v43 = v22->LinkDebug.FailureCount;
        v119 = 12 * v41;
        v123 = &v22->RecoverableLocations;
        v124 = 12 * v42;
        v128 = &v22->LinkDebug.FailurePoints;
        v58 = v43;
        v56 = v41;
        v57 = v42;
        v121 = &v22->RecoverableIndex;
        v126 = &v22->LinkDebug.FailureCount;
        v109 = 4i64;
        v111 = 2i64;
        v113 = 2i64;
        v114 = &v58;
        v115 = 2i64;
        v117 = 2i64;
        v118 = p_Locations;
        v120 = 0;
        v122 = 2i64;
        v125 = 0;
        v127 = 2i64;
        v129 = 8 * v43;
        v130 = 0;
        tlgWriteTransfer_EtwWriteTransfer(
          (__int64)&stru_140C00F40 + 4592,
          (unsigned __int8 *)byte_140021E4B,
          0i64,
          0i64,
          0xCu,
          &v107);
      }
    }
  }
  else if( *(&stru_140C00F40 + 1148) > 5u && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 0x400000000008i64) )
  {
    v76 = 1i64;
    v132 = &v76;
    v133 = 8i64;
    v134 = &v63;
    v63 = v25;
    v136 = &v77;
    v135 = 4i64;
    v77 = 0x1000000i64;
    v137 = 8i64;
    tlgWriteAgg((__int64)&stru_140C00F40 + 4592, (unsigned __int8 *)&unk_140021C98, v29, 5u, &v131);
  }
  if( v22 )
    CmSiFreeMemory((PPRIVILEGE_SET)v22);
  return v25;
}

Referenced by:

CmLoadDifferencingKey