FsFilterAllocateCompletionStack

NTSTATUS __stdcall FsFilterAllocateCompletionStack(
        _FS_FILTER_CTRL *FsFilterCtrl,
        UINT8 CanFail,
        UINT64 *AllocationSize){
  _QWORD *v5; 
  UINT64 v6; 
  __int16 *v7; 
  VOID **PoolWithTag; 

  v5 = 0i64;
  v6 = 32 * (unsigned int)*((unsigned __int16 *)FsFilterCtrl + 36);
  *(_DWORD *)AllocationSize = v6;
  v7 = 0i64;
  PoolWithTag = ExAllocatePoolWithTag(0x200ui64, v6, 1735217990i64);
  if( PoolWithTag )
    goto LABEL_13;
  if( CanFail )
    return -1073741670;
  switch( *((unsigned __int8 *)FsFilterCtrl + 4) )
  {
    case 0xFAu:
      goto LABEL_11;
    case 0xFBu:
      goto LABEL_10;
    case 0xFCu:
LABEL_11:
      v5 = (_QWORD *)qword_140C474F8;
      v7 = &word_140C47500;
      break;
    case 0xFDu:
LABEL_10:
      v5 = qword_140C474C0;
      v7 = &word_140C474E0;
      break;
    case 0xFEu:
      goto LABEL_11;
    case 0xFFu:
      goto LABEL_10;
  }
  KeWaitForSingleObject((UINT64)v7, 0, 0, 0, 0i64);
  *v5 = KeGetCurrentThread();
  PoolWithTag = (VOID **)(v5 + 1);
  FsFilterCtrl[16] |= 2u;
LABEL_13:
  FsFilterCtrl[16] |= 1u;
  *((_QWORD *)FsFilterCtrl + 10) = PoolWithTag;
  return 0;
}

Referenced by:

FsFilterCtrlInit