WmipForwardWmiIrp

NTSTATUS __stdcall WmipForwardWmiIrp(
        PIRP Irp,
        UINT8 MinorFunction,
        UINT64 ProviderId,
        VOID *DataPath,
        UINT64 BufferLength,
        VOID *Buffer){
  unsigned int v6; 
  _LIST_ENTRY *RegEntryByProviderId; 
  INT64 v10; 
  INT64 v11; 
  _LIST_ENTRY *v12; 
  int Flink; 
  _IO_SECURITY_CONTEXT *v14; 
  __int64 v15; 
  __int64 v16; 
  __int64 v17; 
  _ADAPTER_OBJECT *v18; 
  INT8 v19; 
  _IO_STACK_LOCATION *CurrentStackLocation; 
  _IO_STACK_LOCATION *v21; 
  _IO_STACK_LOCATION *v22; 
  int Status; 
  NTSTATUS result; 
  int v25; 
  unsigned int v26; 
  __int128 Object; 
  __int64 v28; 

  v6 = MinorFunction;
  Object = 0i64;
  v28 = 0i64;
  RegEntryByProviderId = WmipFindRegEntryByProviderId((unsigned int)ProviderId);
  v12 = RegEntryByProviderId;
  if( RegEntryByProviderId )
  {
    Flink = (int)RegEntryByProviderId[3].Flink;
    if( (Flink & 0x20000000) == 0 )
    {
      v14 = (_IO_SECURITY_CONTEXT *)v12[1].Flink;
      if( (Flink & 0x10000000) != 0 )
      {
        v26 = 0;
        v25 = ((__int64(__fastcall *)(_QWORD, VOID *, _QWORD, VOID *, _IO_SECURITY_CONTEXT *, unsigned int *))v14->SecurityQos)(
                v6,
                DataPath,
                (unsigned int)BufferLength,
                Buffer,
                v14,
                &v26);
        Irp->IoStatus.Information = v26;
        Irp->IoStatus.Status = v25;
        WmipUnreferenceRegEntry((_REGENTRY *)v12);
        return v25;
      }
      else
      {
        if( (_BYTE)v6 != 11 && (_BYTE)v6 != 8 )
        {
          v15 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnpidGuid;
          if( !v15 )
            v15 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnpidGuid + 1);
          if( !v15 )
            goto LABEL_36;
          v16 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnPIdInstanceNamesGuid;
          if( !v16 )
            v16 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnPIdInstanceNamesGuid + 1);
          if( !v16 )
          {
LABEL_36:
            if( v12[1].Blink )
              v14 = (_IO_SECURITY_CONTEXT *)*(&ExBootDevicesRemovedEvent + 391);
          }
        }
        LODWORD(v17) = IoGetAttachedDeviceReference((INT64)v14, v10, v11);
        v18 = (_ADAPTER_OBJECT *)v17;
        v19 = *(_BYTE *)(v17 + 76) + 1;
        if( v19 <= *(char *)(*(&ExBootDevicesRemovedEvent + 391) + 76i64) || v17 == *(&ExBootDevicesRemovedEvent + 391) )
        {
          KeInitializeEvent((INT64)&Object, 1, 0);
          CurrentStackLocation = Irp->Tail.CurrentStackLocation;
          CurrentStackLocation[-1].CompletionRoutine = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *, void *))SmKmGenericCompletion;
          CurrentStackLocation[-1].Context = &Object;
          CurrentStackLocation[-1].Control = -32;
          v21 = Irp->Tail.CurrentStackLocation;
          *(_QWORD *)&v21[-1].Parameters.EaLength = Buffer;
          v21[-1].MajorFunction = 23;
          v21[-1].MinorFunction = v6;
          v21[-1].Parameters.SecurityContext = v14;
          *(_QWORD *)&v21[-1].Parameters.Options = DataPath;
          *(_DWORD *)&v21[-1].Parameters.FileAttributes = BufferLength;
          v22 = Irp->Tail.CurrentStackLocation;
          Irp->IoStatus.Status = -1073741637;
          v22->Control |= 1u;
          Status = IofCallDriver((UINT64)v18, (UINT64)Irp);
          if( Status == 259 )
          {
            KeWaitForSingleObject((UINT64)&Object, 0, 0, 0, 0i64);
            Status = Irp->IoStatus.Status;
          }
          if( Status == -1073741637 )
          {
            Status = -1073741163;
            Irp->IoStatus.Status = -1073741163;
          }
          if( ((_BYTE)v6 == 11 || (_BYTE)v6 == 8) && Status >= 0 && Irp->IoStatus.Information > 0x18 )
            WmipTranslatePDOInstanceNames(Irp, v6, (unsigned int)BufferLength, (_REGENTRY *)v12);
          WmipUnreferenceRegEntry((_REGENTRY *)v12);
        }
        else
        {
          WmipUnreferenceRegEntry((_REGENTRY *)v12);
          WmipUpdateDeviceStackSize(v19);
          Status = -1073741160;
        }
        HalPutDmaAdapter(v18);
        return Status;
      }
    }
    WmipUnreferenceRegEntry((_REGENTRY *)v12);
  }
  result = -1073741162;
  if( (unsigned __int8)(v6 - 1) > 1u )
    return -1073741823;
  return result;
}

Referenced by:

WmipQueryAllData
WmipQuerySetExecuteSI
WmipSendWmiIrp
WmipSendWmiIrpToTraceDeviceList
WmipSetTraceNotify