CmFcpInitializeChangeSubscription

NTSTATUS __fastcall CmFcpInitializeChangeSubscription(__int64 a1, VOID *a2, unsigned __int64 a3){
  __int64 v6; 
  NTSTATUS result; 
  _EPROCESS *CurrentProcess; 

  memset((VOID *)a1, 0i64, 0x60u);
  CmFcpWorkItemInitialize((unsigned __int64 *)(a1 + 16), v6, (unsigned __int64)CmFcpChangeSubscriptionWrapper, a3);
  result = MmIsSessionAddress(a2);
  if( result )
  {
    *(_DWORD *)(a1 + 88) |= 1u;
    CurrentProcess = (_EPROCESS *)PsGetCurrentProcess();
    result = MmGetSessionIdEx(CurrentProcess);
    *(_DWORD *)(a1 + 92) = result;
  }
  *(_QWORD *)(a1 + 80) = a2;
  return result;
}

Referenced by:

CmFcpManagerAllocateChangeSubscription