PspAllocateAndQueryNotificationChannel
NTSTATUS __stdcall PspAllocateAndQueryNotificationChannel(
_ETHREAD *CurrentThread,
_EJOB *Job,
_JOBOBJECT_WAKE_INFORMATION *WakeInfo){
bool v3;
char v7;
_JOBOBJECT_WAKE_FILTER *p_ReportFilter;
char v9;
_EJOB *v10;
INT64 v11;
int ObjectSecurity;
VOID *v14;
_ADAPTER_OBJECT *v15;
VOID **PoolWithTag;
UINT64 v17;
_ACL *v18;
__int64 v19;
_EJOB *v20;
_PS_PROTECTION *ProcessProtection;
_EJOB *NewTypea;
_EJOB *NewType;
VOID *v24;
INT64 *v25;
_EPROCESS *MemoryAllocated;
_EJOB *RootJob;
VOID *TokenType;
VOID *TokenInformation;
UINT64 AclLength;
PVOID Owner;
PVOID SecurityDescriptor;
_JOBOBJECT_WAKE_FILTER ReportFilter;
_SECURITY_IMPERSONATION_LEVEL ImpersonationLevel;
_JOBOBJECT_WAKE_FILTER *v35;
INT64 v36[2];
__int128 v37;
__int64 v38;
_WNF_STATE_NAME StateName;
v3 = (*((_DWORD *)Job + 330) & 0x800) == 0;
LOWORD(MemoryAllocated) = 0;
ReportFilter = 0i64;
Owner = 0i64;
v7 = 0;
SecurityDescriptor = 0i64;
p_ReportFilter = 0i64;
RootJob = 0i64;
*(_OWORD *)v36 = 0i64;
v38 = 0i64;
v37 = 0i64;
LODWORD(TokenType) = 0;
TokenInformation = 0i64;
v35 = 0i64;
StateName = 0i64;
if( !v3 )
{
v9 = 1;
PspLockRootJobExclusive(Job, CurrentThread, &RootJob);
v10 = RootJob;
if( Job != RootJob )
{
ExConvertExclusiveToSharedLite((_ERESOURCE *)((char *)RootJob + 56));
ExAcquireResourceExclusiveLite((UINT64)Job + 56, 1, v11);
}
goto LABEL_4;
}
ObjectSecurity = ObpGetObjectSecurity(Job, &SecurityDescriptor, (UINT8 *)&MemoryAllocated, 0);
if( ObjectSecurity < 0 )
return ObjectSecurity;
v14 = SecurityDescriptor;
if( !SecurityDescriptor )
{
ObjectSecurity = -1073741790;
LABEL_25:
ObReleaseObjectSecurity(v14, (UINT8)MemoryAllocated);
return ObjectSecurity;
}
ObjectSecurity = RtlGetOwnerSecurityDescriptor(SecurityDescriptor, &Owner, (UINT8 *)&MemoryAllocated + 2);
if( ObjectSecurity < 0 )
goto LABEL_25;
v15 = (_ADAPTER_OBJECT *)PsReferenceEffectiveToken(
CurrentThread,
(_TOKEN_TYPE *)&TokenType,
(UINT8 *)&MemoryAllocated + 1,
&ImpersonationLevel,
0i64);
ObjectSecurity = SeQueryInformationToken(v15, TokenUser, &TokenInformation);
if( (_DWORD)TokenType == 1 )
{
ObFastDereferenceObject(&CurrentThread->Tcb.ApcState.Process->Token, v15);
}
else if( v15 )
{
HalPutDmaAdapter(v15);
}
if( ObjectSecurity < 0 )
goto LABEL_25;
LODWORD(AclLength) = 4 * (*((unsigned __int8 *)Owner + 1) + *(unsigned __int8 *)(*(_QWORD *)TokenInformation + 1i64))
+ 48;
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, (unsigned int)AclLength, 1717007184i64);
v18 = (_ACL *)PoolWithTag;
if( !PoolWithTag )
goto LABEL_24;
RtlCreateAcl((PACL)PoolWithTag, (_ACL)(unsigned int)AclLength, 2ui64, v17);
RtlpAddKnownAce(v18, 2ui64, 0i64, 0x80000000ui64, Owner, 0);
RtlpAddKnownAce(v18, 2ui64, 0i64, 0x80000000ui64, *(VOID **)TokenInformation, 0);
RtlCreateSecurityDescriptor(v36, 1ui64);
RtlSetDaclSecurityDescriptor(v36, 1u, v18, 0);
LODWORD(NewTypea) = 0;
ObjectSecurity = ZwCreateWnfStateName(
&StateName,
WnfTemporaryStateName,
WnfDataScopeMachine,
0,
0i64,
(UINT64)NewTypea,
v36);
ExFreePoolWithTag(v18, 0x66577350u);
if( ObjectSecurity < 0 )
{
LABEL_24:
ExFreePoolWithTag(TokenInformation, 0);
goto LABEL_25;
}
v9 = 0;
PspLockRootJobExclusive(Job, CurrentThread, &RootJob);
if( (*((_DWORD *)Job + 330) & 0x800) != 0 )
{
v10 = RootJob;
v7 = 1;
p_ReportFilter = v35;
}
else
{
*((_WNF_STATE_NAME *)Job + 110) = StateName;
p_ReportFilter = &ReportFilter;
PspComputeReportWakeFilter(Job, &ReportFilter, (_JOBOBJECT_WAKE_FILTER *)Job + 119, 0);
LODWORD(NewType) = 2;
PspEnumJobsAndProcessesInJobHierarchy(
v20,
0i64,
(_EJOB *)PspEnableWakeCounters,
PspEnableProcessWakeCounters,
(INT64 *)(v19 & (unsigned __int64)ProcessProtection),
NewType,
v24,
v25,
MemoryAllocated,
RootJob,
TokenType,
(UINT64)TokenInformation);
_interlockedbittestandset((volatile signed __int32 *)Job + 330, 0xBu);
_InterlockedIncrement64(&PspJobTimeLimitsRequest);
v10 = RootJob;
}
LABEL_4:
*(_OWORD *)&WakeInfo->NotificationChannel = *((_OWORD *)Job + 55);
*(_OWORD *)&WakeInfo->WakeCounters[1] = *((_OWORD *)Job + 56);
*(_OWORD *)&WakeInfo->WakeCounters[3] = *((_OWORD *)Job + 57);
*(_OWORD *)&WakeInfo[1].NotificationChannel = *((_OWORD *)Job + 58);
if( v9 )
PspUnlockJobConditionally(Job, &RootJob);
PspUnlockJob(v10, CurrentThread);
if( v7 )
{
ZwDeleteWnfStateName(&StateName);
}
else if( !v9 )
{
PspDispatchWakeNotification(Job, p_ReportFilter, WakeInfo);
}
return 0;
}Referenced by:
NtQueryInformationJobObject