NtQueryKey
NTSTATUS __stdcall NtQueryKey(
VOID *KeyHandle,
_KEY_INFORMATION_CLASS KeyInformationClass,
VOID *KeyInformation,
UINT64 Length,
UINT64 *ResultLength){
__int64 v5;
_ETHREAD *CurrentThread;
INT64 v10;
INT64 v11;
char v12;
unsigned __int64 v13;
unsigned __int64 v14;
unsigned __int64 v15;
__int64 v16;
NTSTATUS v17;
_QWORD *v18;
_ETHREAD *v19;
NTSTATUS IsResourceAcquiredSharedLite;
unsigned __int16 *v21;
int v22;
_ETHREAD *v23;
bool v24;
VOID *v25;
size_t v27;
unsigned int v28;
char PreviousMode;
NTSTATUS v30;
char v31;
char v32;
char v33;
UINT8 v34;
unsigned int Size;
unsigned int v36;
PVOID Object;
PADAPTER_OBJECT DmaAdapter;
PADAPTER_OBJECT v39;
__int64 v40;
INT64 v41[2];
PVOID v42;
_OBJECT_HANDLE_INFORMATION HandleInformation;
_SLIST_ENTRY *v44;
NTSTATUS v45;
int v46;
_SLIST_ENTRY **v47;
NTSTATUS v48;
__int128 v49;
__int64 v50;
int v51;
_SLIST_ENTRY *Argument[8];
VOID *Src[2];
char v54;
char v55[71];
_LARGE_INTEGER TimeStamp[2];
__int128 v57;
v5 = (unsigned int)Length;
Size = Length;
HandleInformation = 0i64;
v36 = 0;
memset(v55, 0i64, sizeof(v55));
*(_OWORD *)&TimeStamp[0].anonymous_0.LowPart = 0i64;
v57 = 0i64;
v40 = 0i64;
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
EtwGetKernelTraceTimestamp(TimeStamp, 0x20000ui64);
v32 = 0;
v33 = 0;
DmaAdapter = 0i64;
memset(Argument, 0i64, sizeof(Argument));
*(_OWORD *)Src = 0i64;
v54 = 0;
v41[1] = (INT64)v41;
v41[0] = (INT64)v41;
v39 = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
v34 = ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
if( !v34 )
KeLeaveCriticalRegionThread(KeGetCurrentThread());
if( !v34 )
{
v17 = -1073741431;
goto LABEL_35;
}
if( (unsigned int)KeyInformationClass > KeyTrustInformation )
{
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
if( KeyHandle )
{
PreviousMode = KeGetCurrentThread()->PreviousMode;
v42 = 0i64;
if( ObReferenceObjectByHandle(KeyHandle, 0i64, (_OBJECT_TYPE *)CmKeyObjectType, PreviousMode, &v42, 0i64) >= 0 )
{
v40 = *((_QWORD *)v42 + 1);
HalPutDmaAdapter((PADAPTER_OBJECT)v42);
}
}
}
v17 = -1073741811;
goto LABEL_35;
}
v12 = KeGetCurrentThread()->PreviousMode;
v31 = v12;
if( v12 == 1 )
{
if( (_DWORD)v5 )
{
v13 = (unsigned __int64)KeyInformation;
if( ((unsigned __int8)KeyInformation & 3) != 0 )
ExRaiseDatatypeMisalignment();
v14 = (unsigned __int64)KeyInformation + v5 - 1;
if( (unsigned __int64)KeyInformation > v14 || v14 >= 0x7FFFFFFF0000i64 )
ExRaiseAccessViolation();
v15 = (v14 & 0xFFFFFFFFFFFFF000ui64) + 4096;
do
{
*(_BYTE *)v13 = *(_BYTE *)v13;
v13 = (v13 & 0xFFFFFFFFFFFFF000ui64) + 4096;
}
while( v13 != v15 );
}
v16 = (__int64)ResultLength;
if( (unsigned __int64)ResultLength >= 0x7FFFFFFF0000i64 )
v16 = 0x7FFFFFFF0000i64;
*(_DWORD *)v16 = *(_DWORD *)v16;
v12 = 1;
}
Object = 0i64;
v17 = ObReferenceObjectByHandle(
KeyHandle,
((KeyInformationClass - 3) & 0xFFFFFFFB) != 0,
(_OBJECT_TYPE *)CmKeyObjectType,
v12,
&Object,
&HandleInformation);
v18 = Object;
DmaAdapter = (PADAPTER_OBJECT)Object;
v30 = v17;
if( v17 < 0 )
goto LABEL_36;
if( *(_DWORD *)Object != 1803104306 )
{
if( KeyInformationClass != KeyCachedInformation )
{
v17 = -1073741816;
goto LABEL_35;
}
*(_DWORD *)ResultLength = 40;
if( (unsigned int)v5 < 0x28 )
{
v17 = -1073741789;
v30 = -1073741789;
goto LABEL_36;
}
*(_OWORD *)KeyInformation = 0i64;
*((_OWORD *)KeyInformation + 1) = 0i64;
*((_QWORD *)KeyInformation + 4) = 0i64;
*((_DWORD *)KeyInformation + 5) = *(_DWORD *)(v18[1] + 96i64);
goto LABEL_34;
}
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
v40 = *((_QWORD *)Object + 1);
if( ((KeyInformationClass - 3) & 0xFFFFFFFB) == 0 && !HandleInformation.GrantedAccess )
{
v17 = -1073741790;
goto LABEL_35;
}
v19 = (_ETHREAD *)KeGetCurrentThread();
--v19->Tcb.KernelApcDisable;
v33 = 1;
if( !dword_140C5083C )
{
v21 = (unsigned __int16 *)Object;
goto LABEL_30;
}
IsResourceAcquiredSharedLite = ExIsResourceAcquiredSharedLite((UINT64)&CmpRegistryLock, v10, v11);
v21 = (unsigned __int16 *)Object;
if( !IsResourceAcquiredSharedLite )
{
Argument[0] = (_SLIST_ENTRY *)Object;
LODWORD(Argument[1]) = KeyInformationClass;
Argument[2] = (_SLIST_ENTRY *)KeyInformation;
LODWORD(Argument[3]) = Size;
Argument[4] = (_SLIST_ENTRY *)ResultLength;
v22 = CmpCallCallBacksEx(RegNtQueryKey, Argument, 0i64, 1, RegNtPostQueryKey, (INT64)Object, (INT64)v41);
v17 = v22;
v30 = v22;
if( v22 >= 0 )
{
v32 = 1;
goto LABEL_30;
}
if( v22 != -1073740541 )
goto LABEL_36;
LABEL_34:
v17 = 0;
LABEL_35:
v30 = v17;
goto LABEL_36;
}
LABEL_30:
if( KeyInformationClass == KeyHandleTagsInformation )
{
*(_DWORD *)ResultLength = 4;
if( Size < 4 )
{
v17 = -1073741789;
v30 = -1073741789;
goto LABEL_36;
}
*(_DWORD *)KeyInformation = v21[25];
goto LABEL_34;
}
v17 = CmKeyBodyRemapToVirtualForEnum((CM_KEY_BODY **)&DmaAdapter, (CM_KEY_BODY **)(unsigned __int8)v31);
v30 = v17;
if( v17 >= 0 )
{
v27 = Size;
v17 = CmpBounceContextStart((INT64)Src, (struct SLIST_ENTRY *)KeyInformation, Size, (unsigned int)v31, 2);
v30 = v17;
if( v17 >= 0 )
{
v17 = CmQueryKey((__int64)DmaAdapter, (__int64)v39, KeyInformationClass, (unsigned int *)Src[1], Size, &v36);
v30 = v17;
if( v17 >= 0 || v17 == -2147483643 || v17 == -1073741789 )
{
v28 = v36;
*(_DWORD *)ResultLength = v36;
if( v17 != -1073741789 )
{
if( Size >= v28 )
v27 = v28;
if( Src[0] != Src[1] )
memmove(Src[0], Src[1], v27);
}
}
}
}
LABEL_36:
if( v39 )
HalPutDmaAdapter(v39);
if( v32 )
{
if( dword_140C5083C
&& !ExIsResourceAcquiredSharedLite((UINT64)&CmpRegistryLock, v10, v11)
&& (INT64 *)v41[0] != v41 )
{
v46 = 0;
v49 = 0i64;
v50 = 0i64;
v51 = 0;
v44 = (_SLIST_ENTRY *)DmaAdapter;
v45 = v17;
v48 = v17;
v47 = Argument;
CmpCallCallBacksEx(RegNtPostQueryKey, &v44, 0i64, 0, RegNtPostQueryKey, (INT64)DmaAdapter, (INT64)v41);
v17 = v48;
}
v30 = v17;
}
if( v33 )
{
v23 = (_ETHREAD *)KeGetCurrentThread();
v24 = v23->Tcb.KernelApcDisable++ == -1;
if( v24
&& ($F25F8C4BA33AF922A5F1AF68CD89DDDF *)v23->Tcb.ApcState.ApcListHead[0].Flink != &v23->Tcb.152
&& !v23->Tcb.SpecialApcDisable )
{
KiCheckForKernelApcDelivery();
}
v17 = v30;
}
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
v25 = Src[1];
if( Src[1] && Src[1] != Src[0] && Src[1] != v55 )
{
if( (v54 & 1) != 0 )
{
++*(&WheapErrorSourceTable + 401);
if( *(&WheapErrorSourceTable + 788) >= *(&WheapErrorSourceTable + 796) )
{
++*(&WheapErrorSourceTable + 402);
(*(&WheapErrorSourceTable + 204))(Src[1], (char *)&WheapErrorSourceTable + 1576);
}
else
{
RtlpInterlockedPushEntrySList((PSLIST_HEADER)((char *)&WheapErrorSourceTable + 1576), (PSLIST_ENTRY)Src[1]);
}
}
else
{
CmSiFreeMemory((PPRIVILEGE_SET)Src[1]);
}
}
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
LOBYTE(v25) = 13;
(*(void(__fastcall **)(VOID *, _LARGE_INTEGER *, _QWORD, _QWORD, __int64, _QWORD))((char *)&NlsMbCodePageTag + 7))(
v25,
TimeStamp,
(unsigned int)v17,
(unsigned int)KeyInformationClass,
v40,
0i64);
}
if( v34 )
{
ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
return v30;
}
return v17;
}Referenced by:
ExpWatchLicenseInfoWork
ExpWatchProductTypeInitialization
IopLoadDriver
PiDevCfgConfigureDeviceLocation
PiDevCfgFindDeviceMigrationNode
PiDevCfgQueryPolicyStringList