PspAllocateAndQueryNotificationChannel

NTSTATUS __stdcall PspAllocateAndQueryNotificationChannel(
        _ETHREAD *CurrentThread,
        _EJOB *Job,
        _JOBOBJECT_WAKE_INFORMATION *WakeInfo){
  bool v3; 
  char v7; 
  _JOBOBJECT_WAKE_FILTER *p_ReportFilter; 
  char v9; 
  _EJOB *v10; 
  INT64 v11; 
  int ObjectSecurity; 
  VOID *v14; 
  _ADAPTER_OBJECT *v15; 
  VOID **PoolWithTag; 
  UINT64 v17; 
  _ACL *v18; 
  __int64 v19; 
  _EJOB *v20; 
  _PS_PROTECTION *ProcessProtection; 
  _EJOB *NewTypea; 
  _EJOB *NewType; 
  VOID *v24; 
  INT64 *v25; 
  _EPROCESS *MemoryAllocated; 
  _EJOB *RootJob; 
  VOID *TokenType; 
  VOID *TokenInformation; 
  UINT64 AclLength; 
  PVOID Owner; 
  PVOID SecurityDescriptor; 
  _JOBOBJECT_WAKE_FILTER ReportFilter; 
  _SECURITY_IMPERSONATION_LEVEL ImpersonationLevel; 
  _JOBOBJECT_WAKE_FILTER *v35; 
  INT64 v36[2]; 
  __int128 v37; 
  __int64 v38; 
  _WNF_STATE_NAME StateName; 

  v3 = (*((_DWORD *)Job + 330) & 0x800) == 0;
  LOWORD(MemoryAllocated) = 0;
  ReportFilter = 0i64;
  Owner = 0i64;
  v7 = 0;
  SecurityDescriptor = 0i64;
  p_ReportFilter = 0i64;
  RootJob = 0i64;
  *(_OWORD *)v36 = 0i64;
  v38 = 0i64;
  v37 = 0i64;
  LODWORD(TokenType) = 0;
  TokenInformation = 0i64;
  v35 = 0i64;
  StateName = 0i64;
  if( !v3 )
  {
    v9 = 1;
    PspLockRootJobExclusive(Job, CurrentThread, &RootJob);
    v10 = RootJob;
    if( Job != RootJob )
    {
      ExConvertExclusiveToSharedLite((_ERESOURCE *)((char *)RootJob + 56));
      ExAcquireResourceExclusiveLite((UINT64)Job + 56, 1, v11);
    }
    goto LABEL_4;
  }
  ObjectSecurity = ObpGetObjectSecurity(Job, &SecurityDescriptor, (UINT8 *)&MemoryAllocated, 0);
  if( ObjectSecurity < 0 )
    return ObjectSecurity;
  v14 = SecurityDescriptor;
  if( !SecurityDescriptor )
  {
    ObjectSecurity = -1073741790;
LABEL_25:
    ObReleaseObjectSecurity(v14, (UINT8)MemoryAllocated);
    return ObjectSecurity;
  }
  ObjectSecurity = RtlGetOwnerSecurityDescriptor(SecurityDescriptor, &Owner, (UINT8 *)&MemoryAllocated + 2);
  if( ObjectSecurity < 0 )
    goto LABEL_25;
  v15 = (_ADAPTER_OBJECT *)PsReferenceEffectiveToken(
                             CurrentThread,
                             (_TOKEN_TYPE *)&TokenType,
                             (UINT8 *)&MemoryAllocated + 1,
                             &ImpersonationLevel,
                             0i64);
  ObjectSecurity = SeQueryInformationToken(v15, TokenUser, &TokenInformation);
  if( (_DWORD)TokenType == 1 )
  {
    ObFastDereferenceObject(&CurrentThread->Tcb.ApcState.Process->Token, v15);
  }
  else if( v15 )
  {
    HalPutDmaAdapter(v15);
  }
  if( ObjectSecurity < 0 )
    goto LABEL_25;
  LODWORD(AclLength) = 4 * (*((unsigned __int8 *)Owner + 1) + *(unsigned __int8 *)(*(_QWORD *)TokenInformation + 1i64))
                     + 48;
  PoolWithTag = ExAllocatePoolWithTag(0x200ui64, (unsigned int)AclLength, 1717007184i64);
  v18 = (_ACL *)PoolWithTag;
  if( !PoolWithTag )
    goto LABEL_24;
  RtlCreateAcl((PACL)PoolWithTag, (_ACL)(unsigned int)AclLength, 2ui64, v17);
  RtlpAddKnownAce(v18, 2ui64, 0i64, 0x80000000ui64, Owner, 0);
  RtlpAddKnownAce(v18, 2ui64, 0i64, 0x80000000ui64, *(VOID **)TokenInformation, 0);
  RtlCreateSecurityDescriptor(v36, 1ui64);
  RtlSetDaclSecurityDescriptor(v36, 1u, v18, 0);
  LODWORD(NewTypea) = 0;
  ObjectSecurity = ZwCreateWnfStateName(
                     &StateName,
                     WnfTemporaryStateName,
                     WnfDataScopeMachine,
                     0,
                     0i64,
                     (UINT64)NewTypea,
                     v36);
  ExFreePoolWithTag(v18, 0x66577350u);
  if( ObjectSecurity < 0 )
  {
LABEL_24:
    ExFreePoolWithTag(TokenInformation, 0);
    goto LABEL_25;
  }
  v9 = 0;
  PspLockRootJobExclusive(Job, CurrentThread, &RootJob);
  if( (*((_DWORD *)Job + 330) & 0x800) != 0 )
  {
    v10 = RootJob;
    v7 = 1;
    p_ReportFilter = v35;
  }
  else
  {
    *((_WNF_STATE_NAME *)Job + 110) = StateName;
    p_ReportFilter = &ReportFilter;
    PspComputeReportWakeFilter(Job, &ReportFilter, (_JOBOBJECT_WAKE_FILTER *)Job + 119, 0);
    LODWORD(NewType) = 2;
    PspEnumJobsAndProcessesInJobHierarchy(
      v20,
      0i64,
      (_EJOB *)PspEnableWakeCounters,
      PspEnableProcessWakeCounters,
      (INT64 *)(v19 & (unsigned __int64)ProcessProtection),
      NewType,
      v24,
      v25,
      MemoryAllocated,
      RootJob,
      TokenType,
      (UINT64)TokenInformation);
    _interlockedbittestandset((volatile signed __int32 *)Job + 330, 0xBu);
    _InterlockedIncrement64(&PspJobTimeLimitsRequest);
    v10 = RootJob;
  }
LABEL_4:
  *(_OWORD *)&WakeInfo->NotificationChannel = *((_OWORD *)Job + 55);
  *(_OWORD *)&WakeInfo->WakeCounters[1] = *((_OWORD *)Job + 56);
  *(_OWORD *)&WakeInfo->WakeCounters[3] = *((_OWORD *)Job + 57);
  *(_OWORD *)&WakeInfo[1].NotificationChannel = *((_OWORD *)Job + 58);
  if( v9 )
    PspUnlockJobConditionally(Job, &RootJob);
  PspUnlockJob(v10, CurrentThread);
  if( v7 )
  {
    ZwDeleteWnfStateName(&StateName);
  }
  else if( !v9 )
  {
    PspDispatchWakeNotification(Job, p_ReportFilter, WakeInfo);
  }
  return 0;
}

Referenced by:

NtQueryInformationJobObject