NtSetVolumeInformationFile
NTSTATUS __stdcall NtSetVolumeInformationFile(
VOID *FileHandle,
_IO_STATUS_BLOCK *IoStatusBlock,
VOID *FsInformation,
UINT64 Length,
_FSINFOCLASS FsInformationClass){
UINT64 v5;
_KEVENT *v8;
_ETHREAD *CurrentThread;
INT8 PreviousMode;
unsigned int v11;
__int64 v12;
_EWOW64PROCESS *WoW64Process;
unsigned __int16 Machine;
NTSTATUS result;
_FILE_OBJECT *v16;
NTSTATUS RelatedTargetDevice;
_DEVICE_OBJECT *v18;
bool v19;
_ETHREAD *v20;
_FILE_OBJECT *v21;
_BYTE *v22;
int v23;
_DEVICE_OBJECT *v24;
_IRP *v25;
_IRP *v26;
_IO_STATUS_BLOCK *p_LocalIoStatus;
__int64 v28;
__int64 v29;
VOID *PoolWithQuota;
INT8 v31;
int v32;
size_t v33;
__int64 v34;
UINT8 v35;
_DEVICE_OBJECT *v36;
_KEVENT *Pool;
UINT8 SynchronousIo;
INT8 RequestorMode;
size_t Size;
_FILE_OBJECT *pFileObject;
_DEVICE_OBJECT *DeviceObject;
_ETHREAD *v43;
unsigned int *p_Flags;
_IO_STATUS_BLOCK *IoStatusBlocka;
PVOID KernelEvent;
PDEVICE_OBJECT v47;
PIRP Irp;
_IO_STATUS_BLOCK LocalIoStatus;
int NotificationStructure;
GUID v51;
int v52;
__int64 v53;
int v54;
int v55;
VOID *retaddr;
v5 = (unsigned int)Length;
Size = Length;
IoStatusBlocka = IoStatusBlock;
pFileObject = 0i64;
v8 = 0i64;
KernelEvent = 0i64;
DeviceObject = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v43 = CurrentThread;
PreviousMode = CurrentThread->Tcb.PreviousMode;
RequestorMode = PreviousMode;
if( PreviousMode )
{
if( (unsigned int)FsInformationClass >= FileFsMaximumInformation )
return -1073741821;
v11 = *((unsigned __int8 *)IopSetFsOperationLength + (int)FsInformationClass);
if( !(_BYTE)v11 )
return -1073741821;
if( (unsigned int)v5 < v11 )
return -1073741820;
v12 = (__int64)IoStatusBlock;
if( (unsigned __int64)IoStatusBlock >= 0x7FFFFFFF0000i64 )
v12 = 0x7FFFFFFF0000i64;
*(_DWORD *)v12 = *(_DWORD *)v12;
WoW64Process = CurrentThread->Tcb.ApcState.Process->WoW64Process;
if( WoW64Process && ((Machine = WoW64Process->Machine, Machine == 332) || Machine == 452) )
{
if( (_DWORD)v5 )
{
if( ((unsigned __int8)FsInformation & 3) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)FsInformation + v5 > 0x7FFFFFFF0000i64 || (char *)FsInformation + v5 < FsInformation )
MEMORY[0x7FFFFFFF0000] = 0;
}
}
else if( (_DWORD)v5 )
{
if( ((*((unsigned __int8 *)IopQuerySetFsAlignmentRequirement + (int)FsInformationClass) - 1i64) & (unsigned __int64)FsInformation) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)FsInformation + v5 > 0x7FFFFFFF0000i64 || (char *)FsInformation + v5 < FsInformation )
MEMORY[0x7FFFFFFF0000] = 0;
}
}
result = IopReferenceFileObject(
FileHandle,
(unsigned int)IopSetFsOperationAccess[FsInformationClass],
PreviousMode,
&pFileObject,
0i64);
if( result < 0 )
return result;
v16 = pFileObject;
RelatedTargetDevice = IoGetRelatedTargetDevice(pFileObject, &DeviceObject);
v18 = DeviceObject;
if( RelatedTargetDevice < 0 )
v18 = 0i64;
DeviceObject = v18;
p_Flags = &v16->Flags;
if( (v16->Flags & 2) != 0 )
{
v19 = (v16->Flags & 4) != 0;
v20 = (_ETHREAD *)KeGetCurrentThread();
--v20->Tcb.KernelApcDisable;
v21 = pFileObject;
v22 = KeAbPreAcquire(pFileObject->gap80, 0i64, 0i64);
SynchronousIo = 0;
if( _InterlockedExchange((volatile __int32 *)&v21->Busy, 1) )
{
v16 = pFileObject;
v23 = IopWaitAndAcquireFileObjectLock(pFileObject, RequestorMode, v19, v22, (INT64)&SynchronousIo);
}
else
{
if( v22 )
v22[26] |= 1u;
v16 = pFileObject;
ObfReferenceObject(pFileObject);
v23 = 0;
}
if( SynchronousIo )
{
HalPutDmaAdapter((PADAPTER_OBJECT)v16);
v36 = DeviceObject;
if( !DeviceObject )
return v23;
goto LABEL_48;
}
SynchronousIo = 1;
v18 = DeviceObject;
v5 = Size;
}
else
{
Pool = (_KEVENT *)IopVerifierExAllocatePool();
v8 = Pool;
KernelEvent = Pool;
if( !Pool )
{
HalPutDmaAdapter((PADAPTER_OBJECT)v16);
LABEL_64:
if( v18 )
HalPutDmaAdapter((PADAPTER_OBJECT)v18);
return -1073741670;
}
KeInitializeEvent((INT64)Pool, 1, 0);
SynchronousIo = 0;
}
if( (*p_Flags & 0x4000000) == 0 )
KeResetEvent((_KEVENT *)&v16->gap80[24]);
LODWORD(v24) = IoGetRelatedDeviceObject((INT64)v16);
v47 = v24;
v25 = IopAllocateIrpExReturn(v24, v24->StackSize, 0, retaddr);
v26 = v25;
Irp = v25;
if( !v25 )
{
if( (*p_Flags & 2) == 0 )
ExFreePoolWithTag(v8, 0);
IopAllocateIrpCleanup(v16, 0i64);
goto LABEL_64;
}
v25->Tail.OriginalFileObject = v16;
v25->Tail.Thread = v43;
v25->RequestorMode = RequestorMode;
LocalIoStatus = 0i64;
if( SynchronousIo )
{
p_LocalIoStatus = IoStatusBlocka;
v28 = 0i64;
}
else
{
v25->Flags = 4;
p_LocalIoStatus = &LocalIoStatus;
v28 = (__int64)v8;
}
v26->UserEvent = (_KEVENT *)v28;
v26->UserIosb = p_LocalIoStatus;
v26->Overlay.UserApcRoutine = 0i64;
v29 = (__int64)&v26->Tail.CurrentStackLocation[-1];
v43 = (_ETHREAD *)v29;
*(_BYTE *)v29 = 11;
*(_QWORD *)(v29 + 48) = v16;
v26->AssociatedIrp.MasterIrp = 0i64;
v26->MdlAddress = 0i64;
PoolWithQuota = IopVerifierExAllocatePoolWithQuota(v28, v5);
v26->AssociatedIrp.MasterIrp = (_IRP *)PoolWithQuota;
memmove(PoolWithQuota, FsInformation, v5);
v31 = RequestorMode;
if( !RequestorMode || FsInformationClass != FileFsLabelInformation )
{
v33 = Size;
LABEL_42:
v26->Flags |= 0x30u;
v34 = (__int64)v43;
*(_DWORD *)&v43->Tcb.gap0[8] = v33;
*(_DWORD *)(v34 + 16) = FsInformationClass;
v35 = SynchronousIo;
v23 = IopSynchronousServiceTail(v47, v26, v16, 0, v31, SynchronousIo, OtherTransfer);
if( !v35 )
v23 = IopSynchronousApiServiceTail((unsigned int)v23, v8, v26, RequestorMode, &LocalIoStatus, IoStatusBlocka);
if( !v18 )
return v23;
if( v23 >= 0 )
{
v52 = 0;
v55 = 0;
NotificationStructure = 2359297;
v53 = 0i64;
v54 = -1;
v51 = GUID_IO_VOLUME_CHANGE;
IoReportTargetDeviceChange(v18, &NotificationStructure);
}
v36 = v18;
LABEL_48:
HalPutDmaAdapter((PADAPTER_OBJECT)v36);
return v23;
}
v32 = *(_DWORD *)v26->AssociatedIrp.MasterIrp;
if( v32 >= 0 )
{
v33 = Size;
if( v32 + 4 <= Size )
goto LABEL_42;
}
IopExceptionCleanup(v16, v26, 0i64, v8);
if( v18 )
HalPutDmaAdapter((PADAPTER_OBJECT)v18);
return -1073741811;
}Referenced by:
No references.