FsFilterAllocateCompletionStack
NTSTATUS __stdcall FsFilterAllocateCompletionStack(
_FS_FILTER_CTRL *FsFilterCtrl,
UINT8 CanFail,
UINT64 *AllocationSize){
_QWORD *v5;
UINT64 v6;
__int16 *v7;
VOID **PoolWithTag;
v5 = 0i64;
v6 = 32 * (unsigned int)*((unsigned __int16 *)FsFilterCtrl + 36);
*(_DWORD *)AllocationSize = v6;
v7 = 0i64;
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, v6, 1735217990i64);
if( PoolWithTag )
goto LABEL_13;
if( CanFail )
return -1073741670;
switch( *((unsigned __int8 *)FsFilterCtrl + 4) )
{
case 0xFAu:
goto LABEL_11;
case 0xFBu:
goto LABEL_10;
case 0xFCu:
LABEL_11:
v5 = (_QWORD *)qword_140C474F8;
v7 = &word_140C47500;
break;
case 0xFDu:
LABEL_10:
v5 = qword_140C474C0;
v7 = &word_140C474E0;
break;
case 0xFEu:
goto LABEL_11;
case 0xFFu:
goto LABEL_10;
}
KeWaitForSingleObject((UINT64)v7, 0, 0, 0, 0i64);
*v5 = KeGetCurrentThread();
PoolWithTag = (VOID **)(v5 + 1);
FsFilterCtrl[16] |= 2u;
LABEL_13:
FsFilterCtrl[16] |= 1u;
*((_QWORD *)FsFilterCtrl + 10) = PoolWithTag;
return 0;
}Referenced by:
FsFilterCtrlInit