ObpCreateSymbolicLinkName

VOID __stdcall ObpCreateSymbolicLinkName(_OBJECT_SYMBOLIC_LINK *SymbolicLink){
  unsigned int *p_AccessMask; 
  char v2; 
  char *v4; 
  UINT16 *v5; 
  UINT16 v6; 
  _OBJECT_DIRECTORY **v7; 
  __int16 v8; 
  unsigned __int8 DirectoryLocked; 
  unsigned __int8 LockedExclusive; 
  _EJOB *CurrentSilo; 
  _OBJECT_DIRECTORY *v12; 
  _UNICODE_STRING v13; 
  _KSPIN_LOCK *v14; 
  _ESERVERSILO_GLOBALS *CurrentServerSiloGlobals; 
  _OBJECT_DIRECTORY *DosDevicesDirectory; 
  unsigned __int16 Length; 
  wchar_t *v18; 
  wchar_t *Buffer; 
  char *v20; 
  char *v21; 
  _OBJECT_TYPE *v22; 
  char v23; 
  _DEVICE_MAP *v24; 
  unsigned int v25; 
  _ETHREAD *CurrentThread; 
  __int64 v27; 
  int v28; 
  bool v29; 
  _UNICODE_STRING v30; 
  _UNICODE_STRING Name; 
  _OBP_LOOKUP_CONTEXT LookupContext; 
  int v34; 
  _OBJECT_DIRECTORY *v35; 
  PADAPTER_OBJECT DmaAdapter; 

  p_AccessMask = &SymbolicLink[-2].AccessMask;
  LookupContext.EntryLink = 0i64;
  v2 = BYTE2(SymbolicLink[-1].CallbackContext);
  LookupContext.HashValue = 0;
  LookupContext.HashIndex = 0;
  v34 = 64;
  *(&LookupContext.LockStateSignature + 1) = 0;
  if( (v2 & 2) != 0 )
    v4 = (char *)p_AccessMask - *((unsigned __int8 *)&dword_140C25D60 + (v2 & 3));
  else
    v4 = 0i64;
  if( !v4 )
    return;
  if( !*(_QWORD *)(*(_QWORD *)v4 + 304i64) )
    return;
  if( *((_WORD *)v4 + 4) != 4 )
    return;
  v5 = (UINT16 *)*((_QWORD *)v4 + 2);
  if( v5[1] != 58 )
    return;
  v6 = NLS_UPCASE(*v5);
  if( (unsigned __int16)(v6 - 65) > 0x19u )
    return;
  *(_WORD *)&LookupContext.DirectoryLocked = v8;
  SymbolicLink->DosDeviceDriveIndex = v6 - 64;
  DirectoryLocked = v8;
  LockedExclusive = v8;
  v35 = *v7;
  *(_OWORD *)&LookupContext.Directory = 0i64;
  LookupContext.LockStateSignature = -60876;
  CurrentSilo = PsGetCurrentSilo();
  DmaAdapter = (PADAPTER_OBJECT)OBP_GET_SILO_ROOT_DIRECTORY_FROM_SILO(CurrentSilo);
  v12 = (_OBJECT_DIRECTORY *)DmaAdapter;
  ObfReferenceObject(DmaAdapter);
  v13 = (_UNICODE_STRING)SymbolicLink->8;
  v30 = v13;
  CurrentServerSiloGlobals = PsGetCurrentServerSiloGlobals(v14);
  while( 1 )
  {
    DosDevicesDirectory = v12;
    if( (_mm_cvtsi128_si32(_mm_srli_si128((__m128i)v13, 8)) & 7) != 0
      || !CurrentServerSiloGlobals->ObSiloState.SystemDeviceMap->DosDevicesDirectory )
    {
      Length = v30.Length;
LABEL_48:
      Buffer = v30.Buffer;
      goto LABEL_15;
    }
    Length = _mm_cvtsi128_si32((__m128i)v13);
    v30.Length = Length;
    if( Length < 8u )
      goto LABEL_48;
    v18 = (wchar_t *)_mm_srli_si128((__m128i)v13, 8).m128i_u64[0];
    Buffer = v18;
    if( *(_QWORD *)v18 == ObpDosDevicesShortNamePrefix )
    {
      Buffer = v18 + 4;
      Length -= 8;
      v30.Buffer = v18 + 4;
      v30.Length = Length;
      DosDevicesDirectory = CurrentServerSiloGlobals->ObSiloState.SystemDeviceMap->DosDevicesDirectory;
      v13 = v30;
    }
    while( 1 )
    {
LABEL_15:
      if( *Buffer == 92 )
      {
        ++Buffer;
        Length -= 2;
        v30.Buffer = Buffer;
        v30.Length = Length;
        v13 = v30;
      }
      Name = v13;
      if( Length )
      {
        do
        {
          if( *Buffer == 92 )
            break;
          ++Buffer;
          v29 = Length == 2;
          Length -= 2;
          v30.Length = Length;
        }
        while( !v29 );
        v30.Buffer = Buffer;
        v13 = v30;
      }
      Name.Length -= Length;
      if( !Name.Length )
        goto LABEL_42;
      if( DosDevicesDirectory == v35 )
      {
        *(_WORD *)&LookupContext.DirectoryLocked = 257;
      }
      else
      {
        DirectoryLocked = 0;
        LockedExclusive = 0;
      }
      v20 = (char *)ObpLookupDirectoryEntryEx(DosDevicesDirectory, &Name, 0i64, 0, 0, &LookupContext);
      v21 = v20;
      if( DosDevicesDirectory == v35 )
      {
        LookupContext.DirectoryLocked = DirectoryLocked;
        LookupContext.LockedExclusive = LockedExclusive;
      }
      else
      {
        LockedExclusive = LookupContext.LockedExclusive;
        DirectoryLocked = LookupContext.DirectoryLocked;
      }
      if( !v20 )
        goto LABEL_30;
      v22 = (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ (unsigned __int8)*(v20 - 24) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v20 - 48) >> 8)];
      if( v22 != ::DmaAdapter )
        break;
      DosDevicesDirectory = (_OBJECT_DIRECTORY *)v21;
    }
    if( v22 != ObjectType || *((_DWORD *)v21 + 6) )
      break;
    if( !v34 )
    {
      v21 = 0i64;
      break;
    }
    v13 = *(_UNICODE_STRING *)(v21 + 8);
    v12 = (_OBJECT_DIRECTORY *)DmaAdapter;
    --v34;
    v30 = v13;
  }
LABEL_30:
  v23 = 1;
  v24 = *(_DEVICE_MAP **)(*(_QWORD *)((char *)p_AccessMask
                                    - *((unsigned __int8 *)&dword_140C25D60 + (*((_BYTE *)p_AccessMask + 26) & 3)))
                        + 304i64);
  if( v21
    && (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ (unsigned __int8)*(v21 - 24) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v21 - 48) >> 8)] == IoDeviceObjectType )
  {
    v25 = *((_DWORD *)v21 + 18);
    if( v25 <= 0x13 )
    {
      if( v25 < 0x12 )
      {
        if( v25 < 2 )
          goto LABEL_44;
        if( v25 <= 3 )
        {
          v23 = 5;
          goto LABEL_39;
        }
        if( v25 <= 6 )
          goto LABEL_44;
        if( v25 <= 9 )
        {
          v23 = ((*((_DWORD *)v21 + 13) & 1) == 0) + 2;
          goto LABEL_39;
        }
        v29 = v25 == 16;
LABEL_59:
        if( v29 )
          goto LABEL_60;
LABEL_44:
        v23 = 0;
        goto LABEL_39;
      }
LABEL_60:
      v23 = 4;
      goto LABEL_39;
    }
    if( v25 == 20 )
      goto LABEL_60;
    if( v25 != 36 )
    {
      v29 = v25 == 40;
      goto LABEL_59;
    }
    v23 = 6;
  }
LABEL_39:
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.SpecialApcDisable;
  ExAcquirePushLockExclusiveEx(&CurrentServerSiloGlobals->ObSiloState.DeviceMapLock, 0i64);
  v27 = SymbolicLink->DosDeviceDriveIndex - 1;
  v28 = 1 << (LOBYTE(SymbolicLink->DosDeviceDriveIndex) - 1);
  v24->DriveType[v27] = v23;
  v24->DriveMap |= v28;
  if( v24 == CurrentServerSiloGlobals->ObSiloState.SystemDeviceMap )
    CurrentServerSiloGlobals->ObSiloState.SystemDosDeviceState.GlobalDeviceMap |= v28;
  else
    ++CurrentServerSiloGlobals->ObSiloState.SystemDosDeviceState.LocalDeviceCount[v27];
  ExReleasePushLockEx((_DWORD)CurrentServerSiloGlobals + 120, 0);
  KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
LABEL_42:
  ObpReleaseLookupContext(&LookupContext);
  HalPutDmaAdapter(DmaAdapter);
}

Referenced by:

ObpCreateHandle