ExpGetSystemFirmwareTableInformation

NTSTATUS __stdcall ExpGetSystemFirmwareTableInformation(
        PVOID SystemInformation,
        INT8 PreviousMode,
        UINT64 SystemInformationLength,
        UINT64 *ReturnedLength){
  NTSTATUS v7; 
  _DWORD *v8; 
  _DWORD *v9; 
  int v10; 
  _ETHREAD *CurrentThread; 
  __int64(__fastcall *v12)(_DWORD *); 
  __int64 v13; 
  char *v14; 
  int v15; 
  size_t v17; 
  _DWORD *PoolWithQuotaTag; 
  int v19; 
  VOID *v20; 
  _EVENT_DATA_DESCRIPTOR v21; 
  int *v22; 
  int v23; 
  int v24; 

  v7 = 0;
  v8 = 0i64;
  v20 = 0i64;
  if( (unsigned int)SystemInformationLength < 0x10 )
  {
    *(_DWORD *)ReturnedLength = 16;
    v7 = -1073741820;
    goto LABEL_14;
  }
  v9 = SystemInformation;
  v10 = SystemInformationLength - 16;
  if( !PreviousMode )
    goto LABEL_3;
  v17 = SystemInformationLength;
  PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, (unsigned int)SystemInformationLength, 0x54465241ui64);
  v8 = PoolWithQuotaTag;
  v20 = PoolWithQuotaTag;
  if( !PoolWithQuotaTag )
  {
    v7 = -1073741670;
    goto LABEL_14;
  }
  memmove(PoolWithQuotaTag, SystemInformation, v17);
  v9 = v8;
  if( !PsIsProcessAppContainer(KeGetCurrentThread()->ApcState.Process)
    || *v8 == 1381190978 && ExpFirmwareAccessAppContainerCheck(0i64) )
  {
LABEL_3:
    v9[3] = v10;
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --CurrentThread->Tcb.KernelApcDisable;
    ExAcquireResourceSharedLite((UINT64)&ExBootDevicesRemovedEvent + 928, 1);
    v12 = 0i64;
    v13 = *(&ExBootDevicesRemovedEvent + 130) - 24i64;
    if( (_UNKNOWN *)((char *)&ExBootDevicesRemovedEvent + 1040) != (_UNKNOWN *)*(&ExBootDevicesRemovedEvent + 130) )
    {
      while( *(_DWORD *)v13 != *v9 )
      {
        v14 = *(char **)(v13 + 24);
        v13 = (__int64)(v14 - 24);
        if( (char *)&ExBootDevicesRemovedEvent + 1040 == v14 )
          goto LABEL_8;
      }
      v12 = *(__int64(__fastcall **)(_DWORD *))(v13 + 8);
    }
LABEL_8:
    if( v12 )
      v7 = v12(v9);
    ExReleaseResourceLite((PERESOURCE)((char *)&ExBootDevicesRemovedEvent + 928));
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
    if( v12 )
    {
      if( PreviousMode )
      {
        if( v7 >= 0 )
          memmove((char *)SystemInformation + 16, v8 + 4, v8[3]);
        if( (int)(v7 + 0x80000000) < 0 || v7 == -1073741789 )
          *((_DWORD *)SystemInformation + 3) = v8[3];
        v15 = v8[3];
      }
      else
      {
        v15 = v9[3];
      }
      *(_DWORD *)ReturnedLength = v15 + 16;
    }
    else
    {
      v7 = -1073741822;
    }
  }
  else
  {
    v7 = -1073741790;
    if( (unsigned int)dword_140C044D0 > 5 && tlgKeywordOn((__int64)&dword_140C044D0, 0x200000000000i64) )
    {
      v19 = *v8;
      v22 = &v19;
      v23 = 4;
      v24 = 0;
      tlgWriteTransfer_EtwWriteTransfer(
        (__int64)&dword_140C044D0,
        (unsigned __int8 *)byte_14002CA6D,
        0i64,
        0i64,
        3u,
        &v21);
    }
  }
LABEL_14:
  if( v8 )
    ExFreePoolWithTag(v8, 0x54465241u);
  return v7;
}

Referenced by:

ExEnumerateSystemFirmwareTables
ExGetSystemFirmwareTable
ExpGetSystemFlushInformation
ExpGetSystemPlatformBinary
ExpQuerySystemInformation