PspCreateProcess

NTSTATUS __stdcall PspCreateProcess(
        VOID **ProcessHandle,
        UINT64 DesiredAccess,
        _OBJECT_ATTRIBUTES *ObjectAttributes,
        VOID *ParentProcess,
        UINT64 CreateFlags,
        VOID *SectionHandle,
        VOID *DebugPort,
        VOID *TokenHandle){
  _KPROCESSOR_MODE v10; 
  _ADAPTER_OBJECT *v11; 
  _EPROCESS *v12; 
  int ProcessProtectionRequirementsFromImage; 
  UINT64 v14; 
  PS_PROTECTION v15; 
  NTSTATUS Process; 
  int v17; 
  int v18; 
  NTSTATUS result; 
  _UNICODE_STRING *ObjectName; 
  unsigned int Attributes; 
  int v22; 
  _UNICODE_STRING *v23; 
  PVOID *Object; 
  POBJECT_HANDLE_INFORMATION HandleInformation; 
  UINT64 v26; 
  PSP_CREATE_PROCESS_CONTEXT *CreateContext; 
  PSP_ALLOCATE_PROCESS_STATE *AllocateProcessState; 
  _PS_PROTECTION Protection; 
  UINT8 ExeSigningLevel; 
  UINT8 DllSigningLevel; 
  UINT8 SignatureLevel; 
  char v33; 
  int v34; 
  VOID *NewObject; 
  VOID *NewToken; 
  UINT64 DesiredAccessa; 
  _EPROCESS *ParentProcessa; 
  PVOID v39; 
  VOID *v40; 
  __int64 v41; 
  VOID **v42; 
  PVOID v43; 
  _HANDLE Handle[2]; 
  _PSP_OBJECT_CREATION_STATE ObjectAccessState[100]; 
  VOID *v46; 

  LODWORD(DesiredAccessa) = DesiredAccess;
  v42 = ProcessHandle;
  *(_QWORD *)Handle = TokenHandle;
  v40 = v46;
  v41 = 0i64;
  v33 = 0;
  ParentProcessa = 0i64;
  NewObject = 0i64;
  ExeSigningLevel = 0;
  DllSigningLevel = 0;
  NewToken = 0i64;
  if( ((unsigned int)SectionHandle & 0xFFF94040) != 0
    || (KeGetCurrentThread()->ApcState.Process->Protection.Level & 7) != 0 && (_BYTE)CreateFlags )
  {
    return -1073741811;
  }
  if( ((unsigned __int16)SectionHandle & 0x4000) != 0 && ((unsigned __int16)SectionHandle & 0x2000) == 0 )
    return -1073741811;
  v34 = (unsigned __int16)SectionHandle & 0x800;
  if( ((unsigned __int16)SectionHandle & 0x2000) != 0 && ((unsigned __int16)SectionHandle & 0x800) == 0 )
    return -1073741811;
  if( ((unsigned __int16)SectionHandle & 0x800) != 0 )
  {
    if( (_BYTE)CreateFlags )
      return -1073741811;
    if( ObjectAttributes )
    {
      if( ObjectAttributes->RootDirectory )
        return -1073741811;
      ObjectName = ObjectAttributes->ObjectName;
      if( !ObjectName
        || !ObjectName->Buffer
        || !ObjectName->Length
        || ObjectAttributes->Attributes != 512
        || ObjectAttributes->SecurityDescriptor
        || ObjectAttributes->SecurityQualityOfService )
      {
        return -1073741811;
      }
    }
    if( DebugPort || TokenHandle || !ParentProcess )
      return -1073741811;
  }
  if( ((unsigned int)SectionHandle & 0x20000) != 0
    && ((_BYTE)CreateFlags || ((unsigned __int16)SectionHandle & 0x800) == 0) )
  {
    return -1073741811;
  }
  memset(ObjectAccessState, 0i64, sizeof(ObjectAccessState));
  LOBYTE(ObjectAccessState[97]) = CreateFlags;
  if( ObjectAttributes )
  {
    if( (_BYTE)CreateFlags )
    {
      if( ((unsigned __int8)ObjectAttributes & 3) != 0 )
        ExRaiseDatatypeMisalignment();
      Attributes = ObjectAttributes->Attributes;
      ObjectAccessState[96] = Attributes;
    }
    else
    {
      Attributes = ObjectAttributes->Attributes;
    }
    if( (_BYTE)CreateFlags )
      v22 = Attributes & 0x1DF2;
    else
      v22 = Attributes & 0x11FF2;
    ObjectAccessState[96] = v22;
  }
  if( DebugPort )
  {
    v39 = 0i64;
    result = ObReferenceObjectByHandle(DebugPort, 8ui64, MmSectionObjectType, CreateFlags, &v39, 0i64);
    v11 = (_ADAPTER_OBJECT *)v39;
    v43 = v39;
    if( result < 0 )
      return result;
  }
  else
  {
    v11 = 0i64;
    v43 = 0i64;
  }
  if( !ParentProcess
    || (LODWORD(Object) = 1917023056,
        ProcessProtectionRequirementsFromImage = ObReferenceObjectByHandleWithTag(
                                                   ParentProcess,
                                                   0x80ui64,
                                                   (_OBJECT_TYPE *)PsProcessType,
                                                   CreateFlags,
                                                   (UINT64)Object,
                                                   (VOID **)&ParentProcessa,
                                                   0i64),
        ProcessProtectionRequirementsFromImage >= 0) )
  {
    LOBYTE(v10) = CreateFlags;
    v12 = ParentProcessa;
    ProcessProtectionRequirementsFromImage = PspReferenceTokenForNewProcess(&ParentProcessa->Pcb, v46, v10, &NewToken);
    if( ProcessProtectionRequirementsFromImage < 0 )
      goto LABEL_28;
    if( v12 )
    {
      if( v11 )
      {
        Protection.Level = 0;
        ProcessProtectionRequirementsFromImage = SeQuerySigningPolicy(
                                                   NewToken,
                                                   0i64,
                                                   0i64,
                                                   0,
                                                   &ExeSigningLevel,
                                                   &DllSigningLevel,
                                                   &Protection);
        if( ProcessProtectionRequirementsFromImage < 0 )
          goto LABEL_27;
        SignatureLevel = ExeSigningLevel;
        if( ExeSigningLevel > 1u || (v15.Level = Protection.Level) != 0 )
        {
LABEL_72:
          ProcessProtectionRequirementsFromImage = -1073741637;
          goto LABEL_27;
        }
LABEL_15:
        if( !v11 )
          goto LABEL_16;
        ProcessProtectionRequirementsFromImage = PspGetProcessProtectionRequirementsFromImage((INT64)v11);
        if( ProcessProtectionRequirementsFromImage >= 0 )
        {
          if( v15.Level == v33 )
          {
LABEL_16:
            if( v34 )
            {
              if( ObjectAttributes )
                v23 = ObjectAttributes->ObjectName;
              else
                LOBYTE(v23) = 0;
              LOBYTE(v14) = v15;
              ProcessProtectionRequirementsFromImage = PsCreateMinimalProcess(
                                                         v12,
                                                         (PS_PROTECTION)v23,
                                                         0i64,
                                                         v14,
                                                         (VOID **)((unsigned __int64)NewToken & -(__int64)(v40 != 0i64)));
            }
            else
            {
              LODWORD(AllocateProcessState) = v40 != 0i64;
              LODWORD(CreateContext) = 0;
              LODWORD(v26) = (_DWORD)SectionHandle;
              Process = PspAllocateProcess(
                          v12,
                          CreateFlags,
                          ObjectAttributes,
                          v15,
                          SignatureLevel,
                          DllSigningLevel,
                          v11,
                          NewToken,
                          v26,
                          CreateContext,
                          0i64,
                          AllocateProcessState,
                          0i64);
              ProcessProtectionRequirementsFromImage = Process;
              if( Process >= 0 )
              {
                v17 = Process;
                v34 = Process;
                v18 = 1;
                if( (_DWORD)v41 )
                  v18 = 3;
                LODWORD(HandleInformation) = v18;
                ProcessProtectionRequirementsFromImage = PspInsertProcess(
                                                           (_EPROCESS *)NewObject,
                                                           v12,
                                                           (unsigned int)DesiredAccessa,
                                                           (unsigned int)SectionHandle,
                                                           *(VOID **)Handle,
                                                           (UINT64)HandleInformation,
                                                           0i64,
                                                           ObjectAccessState);
                if( ProcessProtectionRequirementsFromImage >= 0 )
                {
                  ProcessProtectionRequirementsFromImage = PspCreateObjectHandle(
                                                             NewObject,
                                                             ObjectAccessState,
                                                             (_OBJECT_TYPE *)PsProcessType);
                  if( ProcessProtectionRequirementsFromImage >= 0 )
                  {
                    *v42 = *(VOID **)&ObjectAccessState[98];
                    ProcessProtectionRequirementsFromImage = v17;
                  }
                  PspDeleteObjectAccessState((_ACCESS_STATE *)ObjectAccessState);
                }
                if( ProcessProtectionRequirementsFromImage < 0 )
                  PspRundownSingleProcess((_EPROCESS *)NewObject, 0);
                ObfDereferenceObjectWithTag(NewObject, 0x72437350ui64);
              }
            }
            goto LABEL_27;
          }
          goto LABEL_72;
        }
LABEL_27:
        HalPutDmaAdapter((PADAPTER_OBJECT)NewToken);
LABEL_28:
        if( v12 )
          ObfDereferenceObjectWithTag(v12, 0x72437350ui64);
        goto LABEL_30;
      }
      v15.Level = v12->Protection.Level;
      DllSigningLevel = v12->SectionSignatureLevel;
      SignatureLevel = v12->SignatureLevel;
      ExeSigningLevel = SignatureLevel;
    }
    else
    {
      v15.Level = 114;
      SignatureLevel = 30;
      ExeSigningLevel = 30;
      DllSigningLevel = 28;
    }
    Protection.Level = v15.Level;
    goto LABEL_15;
  }
LABEL_30:
  if( v11 )
    HalPutDmaAdapter(v11);
  return ProcessProtectionRequirementsFromImage;
}

Referenced by:

NtCreateProcessEx
PspInitPhase0