CmFcpInitializeChangeSubscription
NTSTATUS __fastcall CmFcpInitializeChangeSubscription(__int64 a1, VOID *a2, unsigned __int64 a3){
__int64 v6;
NTSTATUS result;
_EPROCESS *CurrentProcess;
memset((VOID *)a1, 0i64, 0x60u);
CmFcpWorkItemInitialize((unsigned __int64 *)(a1 + 16), v6, (unsigned __int64)CmFcpChangeSubscriptionWrapper, a3);
result = MmIsSessionAddress(a2);
if( result )
{
*(_DWORD *)(a1 + 88) |= 1u;
CurrentProcess = (_EPROCESS *)PsGetCurrentProcess();
result = MmGetSessionIdEx(CurrentProcess);
*(_DWORD *)(a1 + 92) = result;
}
*(_QWORD *)(a1 + 80) = a2;
return result;
}Referenced by:
CmFcpManagerAllocateChangeSubscription