PiSwIrpGetLifetime
NTSTATUS __stdcall PiSwIrpGetLifetime(_IRP *Irp){
INT64 v1;
_IO_STACK_LOCATION *CurrentStackLocation;
int v3;
_IRP *MasterIrp;
INT64 FsContext2;
_ETHREAD *CurrentThread;
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
v3 = 0;
MasterIrp = Irp->AssociatedIrp.MasterIrp;
FsContext2 = (INT64)CurrentStackLocation->FileObject->FsContext2;
if( LODWORD(CurrentStackLocation->Parameters.SecurityContext) >= 4 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&PiSwLockObj, 1, v1);
if( PiSwDeviceOperationsAllowed(FsContext2) )
{
*(_DWORD *)&MasterIrp->Type = *(_DWORD *)(FsContext2 + 180);
Irp->IoStatus.Information = 4i64;
}
else
{
v3 = -1073741637;
}
ExReleaseResourceLite(&PiSwLockObj);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
}
else
{
v3 = -1073741811;
}
Irp->IoStatus.Status = v3;
IofCompleteRequest(Irp, 0);
return v3;
}Referenced by:
PiSwDispatch