SmKmSendUsageNotification
NTSTATUS __stdcall SmKmSendUsageNotification(PIRP Irp, PFILE_OBJECT FileObject, UINT64 Remove){
int v3;
_IO_STACK_LOCATION *CurrentStackLocation;
UINT64 v7;
_IO_STACK_LOCATION *v8;
NTSTATUS result;
char Object[40];
v3 = Remove;
KeInitializeEvent((INT64)Object, 0, 0);
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
LODWORD(v7) = IoGetRelatedDeviceObject((INT64)FileObject);
*(_WORD *)&CurrentStackLocation[-1].MajorFunction = 5659;
CurrentStackLocation[-1].Parameters.Options = 1;
CurrentStackLocation[-1].FileObject = FileObject;
LOBYTE(CurrentStackLocation[-1].Parameters.SecurityContext) = v3 == 0;
v8 = Irp->Tail.CurrentStackLocation;
Irp->IoStatus.Status = -1073741637;
v8[-1].CompletionRoutine = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *, void *))SmKmGenericCompletion;
v8[-1].Context = Object;
v8[-1].Control = -32;
result = IofCallDriver(v7, (UINT64)Irp);
if( result == 259 )
{
KeWaitForSingleObject((UINT64)Object, 0, 0, 0, 0i64);
return Irp->IoStatus.Status;
}
return result;
}Referenced by:
SmKmFileInfoCleanup
SmKmIsVolumeIoPossible