RawReadWriteDeviceControl
NTSTATUS __stdcall RawReadWriteDeviceControl(_VCB *Vcb, PIRP Irp, _IO_STACK_LOCATION *IrpSp){
_CCHAR v6;
unsigned __int8 MajorFunction;
int v8;
char v9;
_IO_STACK_LOCATION *CurrentStackLocation;
_IO_STACK_LOCATION *v11;
RawBeginOperation((INT64)Vcb, (INT64)IrpSp->FileObject);
MajorFunction = IrpSp->MajorFunction;
v8 = 0;
if( v9 )
{
if( (unsigned __int8)(MajorFunction - 3) > 1u || LODWORD(IrpSp->Parameters.SecurityContext) )
{
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
*(_OWORD *)&CurrentStackLocation[-1].MajorFunction = *(_OWORD *)&IrpSp->MajorFunction;
*(_OWORD *)&CurrentStackLocation[-1].Parameters.Options = *(_OWORD *)&IrpSp->Parameters.Options;
*(_OWORD *)&CurrentStackLocation[-1].Parameters.EaLength = *(_OWORD *)&IrpSp->Parameters.EaLength;
*(_OWORD *)&CurrentStackLocation[-1].FileObject = *(_OWORD *)&IrpSp->FileObject;
CurrentStackLocation[-1].Context = IrpSp->Context;
CurrentStackLocation[-1].Flags |= 2u;
v11 = Irp->Tail.CurrentStackLocation;
v11[-1].CompletionRoutine = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *, void *))RawCompletionRoutine;
v11[-1].Context = Vcb;
v11[-1].Control = -32;
return IofCallDriver(*((_QWORD *)Vcb + 22), (UINT64)Irp);
}
RawEndOperation(Vcb, IrpSp->FileObject);
}
else
{
if( MajorFunction == 27 )
{
ExAcquireFastMutex((PFAST_MUTEX)Vcb + 4);
--Vcb[28];
if( Vcb[27] || !RawInitiateDeleteVolume(Vcb, 0i64, 0i64) )
KeReleaseGuardedMutex((PKGUARDED_MUTEX)Vcb + 4);
}
v8 = -1073741202;
}
LOBYTE(v6) = 1;
Irp->IoStatus.Status = v8;
IofCompleteRequest(Irp, v6);
return v8;
}Referenced by:
RawDispatch