CmLoadKey
NTSTATUS __stdcall CmLoadKey(
OBJECT_ATTRIBUTES *TargetKey,
UNICODE_STRING *SourceFile,
UINT64 Flags,
CM_KEY_BODY *TrustClassKeyBody,
CM_KEY_BODY *LowerLayerKeyBody,
KEVENT *UserEvent,
UNICODE_STRING **PathToRoot,
PVOID *LoadKeyContext){
unsigned int v9;
_UNICODE_STRING *ObjectName;
unsigned int Length;
__int64 v13;
_UNICODE_STRING *v14;
VOID **PoolWithTag;
WCHAR v16;
VOID **v17;
_UNICODE_STRING *v18;
_ETHREAD *CurrentThread;
int v20;
_HIVE_LOAD_FAILURE *TransientPoolWithTag;
_HIVE_LOAD_FAILURE *v22;
int v23;
int v24;
NTSTATUS v25;
CMHIVE *v26;
char v27;
int KeyCommon;
__int64 v29;
_UNICODE_STRING *p_Destination;
NTSTATUS v32;
int Conflict;
VOID *v34;
NTSTATUS v35;
unsigned int v36;
int RecoverableIndex;
int Index;
__int64 p_Locations;
int FailureCount;
int v41;
int v42;
int v43;
UINT64 Point;
UINT64 Pointa;
UINT64 Pointb;
UINT64 Pointc;
UINT64 Pointd;
UINT64 Pointe;
POBJECT_HANDLE_INFORMATION HandleInformation;
VOID **NeedRmLogStart;
char Allocate[3];
__int16 v53;
__int16 v54;
__int16 v55;
__int16 v56;
__int16 v57;
__int16 v58;
PVOID P;
int v60;
NTSTATUS v61;
NTSTATUS v62;
NTSTATUS v63;
_HANDLE Handle[2];
PVOID Object;
PVOID v66;
UINT8 v67[8];
KEVENT *v68;
CM_KEY_BODY *TrustClassKeyBodya;
UINT8 *v70;
__int64 v71;
CM_KEY_BODY *v72;
_UNICODE_STRING Destination;
__int64 v74;
__int64 v75;
__int64 v76;
__int64 v77;
_KAPC_STATE ApcState;
_EVENT_DATA_DESCRIPTOR v79;
__int64 *v80;
__int64 v81;
int *v82;
__int64 v83;
__int16 *v84;
__int64 v85;
__int16 *v86;
__int64 v87;
__int16 *v88;
__int64 v89;
unsigned __int16 *p_Index;
__int64 v91;
struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *v92;
int v93;
int v94;
unsigned __int16 *p_RecoverableIndex;
__int64 v96;
struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *p_RecoverableLocations;
int v98;
int v99;
unsigned __int8 *p_FailureCount;
__int64 v101;
struct {int Status;unsigned int Point;} *p_FailurePoints;
int v103;
int v104;
__int64 *v105;
__int64 v106;
_EVENT_DATA_DESCRIPTOR v107;
int *v108;
__int64 v109;
__int16 *v110;
__int64 v111;
__int16 *v112;
__int64 v113;
__int16 *v114;
__int64 v115;
unsigned __int16 *v116;
__int64 v117;
__int64 v118;
int v119;
int v120;
unsigned __int16 *v121;
__int64 v122;
struct {_CM_LOAD_FAILURE_TYPE Failure;int Status;unsigned int Point;} *v123;
int v124;
int v125;
unsigned __int8 *v126;
__int64 v127;
struct {int Status;unsigned int Point;} *v128;
int v129;
int v130;
_EVENT_DATA_DESCRIPTOR v131;
__int64 *v132;
__int64 v133;
int *v134;
__int64 v135;
__int64 *v136;
__int64 v137;
char v138;
__int64 v139;
__int64 v140;
v72 = LowerLayerKeyBody;
v68 = (KEVENT *)PathToRoot;
v9 = Flags;
v70 = (UINT8 *)LoadKeyContext;
v71 = v139;
*(_QWORD *)v67 = v140;
ObjectName = TargetKey->ObjectName;
memset(&ApcState, 0, sizeof(ApcState));
TrustClassKeyBodya = TrustClassKeyBody;
P = 0i64;
Length = ObjectName->Length;
*(_QWORD *)Handle = 0i64;
v60 = 0;
if( (unsigned __int16)Length >= 2u )
{
LODWORD(v13) = Length >> 1;
if( Length >> 1 )
{
do
{
v14 = TargetKey->ObjectName;
v13 = (unsigned int)(v13 - 1);
if( v14->Buffer[v13] != 92 )
break;
v14->Length -= 2;
}
while( (_DWORD)v13 );
}
}
if( TargetKey->ObjectName->Length < 2u )
return -1073741811;
PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x104ui64, 1649626435i64);
v17 = PoolWithTag;
if( !PoolWithTag )
return -1073741670;
v18 = TargetKey->ObjectName;
*(_QWORD *)&Destination.Length = 17039360i64;
Destination.Buffer = (wchar_t *)PoolWithTag;
if( CmpQueryHiveRedirectionFileList(v18, &Destination, v16) )
{
p_Destination = &Destination;
if( Destination.Length == 2 )
p_Destination = SourceFile;
SourceFile = p_Destination;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
if( !ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132) )
{
KeLeaveCriticalRegionThread(KeGetCurrentThread());
ExFreePoolWithTag(v17, 0);
return -1073741431;
}
v20 = ((v9 & 0x2000) != 0 ? 3 : 0) | 8;
if( (v9 & 0x4000) == 0 )
v20 = (v9 & 0x2000) != 0 ? 3 : 0;
TransientPoolWithTag = (_HIVE_LOAD_FAILURE *)CmpAllocateTransientPoolWithTag(1ui64, 0x1B0ui64);
v22 = TransientPoolWithTag;
if( !TransientPoolWithTag )
{
v25 = -1073741670;
goto LABEL_22;
}
memset(TransientPoolWithTag, 0i64, 0x1B0u);
Allocate[0] = 1;
v23 = v20 | 4;
if( !v72 )
v23 = v20;
LODWORD(HandleInformation) = v23;
LODWORD(Point) = ((v9 & 0xFFFFF223 | (2 * (v9 & 0x480 | (2 * (v9 & 0x20 | ((v9 & 4) << 6)))))) << 19) | 0x1190001;
v24 = CmpCmdHiveOpen(SourceFile, 1u, (UINT8 *)Allocate, (CMHIVE **)&P, Point, (UINT64)HandleInformation, v70);
v25 = v24;
if( v24 < 0 )
{
if( v24 != -1073741757 )
{
LODWORD(Pointa) = 16;
SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v24, Pointa);
v26 = (CMHIVE *)P;
goto LABEL_20;
}
if( CmpOpenHiveFile(SourceFile, 0, (VOID **)Handle, &v60, 8, (__int64)v70, 0i64, 0i64, 0i64) >= 0 )
{
Object = 0i64;
v32 = ObReferenceObjectByHandle(
*(VOID **)Handle,
0i64,
(_OBJECT_TYPE *)**(&CmpDummyThreadEvent + 344),
0,
&Object,
0i64);
ZwClose(Handle[0]);
if( v32 < 0 )
{
LODWORD(Pointc) = 48;
}
else
{
Conflict = CmpResolveHiveLoadConflict(
TargetKey,
(__int64)Object,
v9,
(__int64)TrustClassKeyBodya,
(__int64)v68,
v22,
v138,
v71,
*(__int64 *)v67);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
if( Conflict >= 0 )
{
v26 = (CMHIVE *)P;
goto LABEL_19;
}
LODWORD(Pointc) = 64;
}
}
else
{
LODWORD(Pointc) = 32;
}
v25 = -1073741757;
SetFailureLocation(v22, 0i64, _CmLoadKey, 3221225539i64, Pointc);
v26 = (CMHIVE *)P;
goto LABEL_20;
}
v26 = (CMHIVE *)P;
if( (v9 & 0x2000) != 0 )
{
v34 = (VOID *)*((_QWORD *)P + 192);
v66 = 0i64;
v35 = ObReferenceObjectByHandle(v34, 0i64, (_OBJECT_TYPE *)**(&CmpDummyThreadEvent + 344), 0, &v66, 0i64);
v25 = v35;
if( v35 < 0 )
{
LODWORD(Pointd) = 80;
SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v35, Pointd);
goto LABEL_20;
}
v27 = v138;
v25 = CmpResolveHiveLoadConflict(
TargetKey,
(__int64)v66,
v9,
(__int64)TrustClassKeyBodya,
(__int64)v68,
v22,
v138,
v71,
*(__int64 *)v67);
HalPutDmaAdapter((PADAPTER_OBJECT)v66);
if( v25 < 0 )
{
if( v25 == -1073741275 )
goto LABEL_16;
LODWORD(Pointe) = 96;
SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)v25, Pointe);
LABEL_20:
if( v26 )
{
CmpAttachToRegistryProcess(&ApcState);
CmpDestroyHive(v26);
KiUnstackDetachProcess(&ApcState, 0i64);
}
goto LABEL_22;
}
LABEL_19:
v25 = 0;
goto LABEL_20;
}
v27 = v138;
LABEL_16:
if( (_BYTE)UserEvent )
v26->Flags |= 0x2000u;
LOBYTE(NeedRmLogStart) = v27;
KeyCommon = CmpLoadKeyCommon(v26, TargetKey, v9, TrustClassKeyBodya, v72, v68, NeedRmLogStart, v67[0], Allocate[0]);
v25 = KeyCommon;
v26 = 0i64;
if( KeyCommon >= 0 )
goto LABEL_19;
LODWORD(Pointb) = 112;
SetFailureLocation(v22, 0i64, _CmLoadKey, (unsigned int)KeyCommon, Pointb);
LABEL_22:
ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
ExFreePoolWithTag(v17, 0);
if( v25 < 0 )
{
if( *(&stru_140C00F40 + 1148) > 5u )
{
if( tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 0x400000000008i64) )
{
v74 = 1i64;
v80 = &v74;
v84 = &v53;
v82 = &v61;
RecoverableIndex = v22->RecoverableIndex;
Index = v22->Index;
p_Index = &v22->Index;
v86 = &v54;
p_Locations = (__int64)&v22->Locations;
v53 = Index;
FailureCount = v22->LinkDebug.FailureCount;
v93 = 12 * Index;
p_RecoverableLocations = &v22->RecoverableLocations;
v98 = 12 * RecoverableIndex;
p_FailurePoints = &v22->LinkDebug.FailurePoints;
v105 = &v75;
v55 = FailureCount;
v54 = RecoverableIndex;
p_RecoverableIndex = &v22->RecoverableIndex;
v81 = 8i64;
v61 = v25;
v83 = 4i64;
v85 = 2i64;
v87 = 2i64;
v88 = &v55;
v89 = 2i64;
v91 = 2i64;
v92 = &v22->Locations;
v94 = 0;
v96 = 2i64;
v99 = 0;
p_FailureCount = &v22->LinkDebug.FailureCount;
v101 = 2i64;
v103 = 8 * FailureCount;
v104 = 0;
v75 = 0x1000000i64;
v106 = 8i64;
tlgWriteAgg(
(__int64)&stru_140C00F40 + 4592,
(unsigned __int8 *)&byte_140021CEB,
(__int64)&v22->LinkDebug.FailureCount,
0xEu,
&v79);
v36 = *(&stru_140C00F40 + 1148);
}
else
{
p_Locations = (__int64)&v22->Locations;
}
if( v36 > 5 && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
{
v62 = v25;
v108 = &v62;
v110 = &v56;
v41 = v22->Index;
v42 = v22->RecoverableIndex;
v116 = &v22->Index;
v112 = &v57;
v43 = v22->LinkDebug.FailureCount;
v119 = 12 * v41;
v123 = &v22->RecoverableLocations;
v124 = 12 * v42;
v128 = &v22->LinkDebug.FailurePoints;
v58 = v43;
v56 = v41;
v57 = v42;
v121 = &v22->RecoverableIndex;
v126 = &v22->LinkDebug.FailureCount;
v109 = 4i64;
v111 = 2i64;
v113 = 2i64;
v114 = &v58;
v115 = 2i64;
v117 = 2i64;
v118 = p_Locations;
v120 = 0;
v122 = 2i64;
v125 = 0;
v127 = 2i64;
v129 = 8 * v43;
v130 = 0;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&stru_140C00F40 + 4592,
(unsigned __int8 *)byte_140021E4B,
0i64,
0i64,
0xCu,
&v107);
}
}
}
else if( *(&stru_140C00F40 + 1148) > 5u && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 0x400000000008i64) )
{
v76 = 1i64;
v132 = &v76;
v133 = 8i64;
v134 = &v63;
v63 = v25;
v136 = &v77;
v135 = 4i64;
v77 = 0x1000000i64;
v137 = 8i64;
tlgWriteAgg((__int64)&stru_140C00F40 + 4592, (unsigned __int8 *)&unk_140021C98, v29, 5u, &v131);
}
if( v22 )
CmSiFreeMemory((PPRIVILEGE_SET)v22);
return v25;
}Referenced by:
CmLoadDifferencingKey