WmipForwardWmiIrp
NTSTATUS __stdcall WmipForwardWmiIrp(
PIRP Irp,
UINT8 MinorFunction,
UINT64 ProviderId,
VOID *DataPath,
UINT64 BufferLength,
VOID *Buffer){
unsigned int v6;
_LIST_ENTRY *RegEntryByProviderId;
INT64 v10;
INT64 v11;
_LIST_ENTRY *v12;
int Flink;
_IO_SECURITY_CONTEXT *v14;
__int64 v15;
__int64 v16;
__int64 v17;
_ADAPTER_OBJECT *v18;
INT8 v19;
_IO_STACK_LOCATION *CurrentStackLocation;
_IO_STACK_LOCATION *v21;
_IO_STACK_LOCATION *v22;
int Status;
NTSTATUS result;
int v25;
unsigned int v26;
__int128 Object;
__int64 v28;
v6 = MinorFunction;
Object = 0i64;
v28 = 0i64;
RegEntryByProviderId = WmipFindRegEntryByProviderId((unsigned int)ProviderId);
v12 = RegEntryByProviderId;
if( RegEntryByProviderId )
{
Flink = (int)RegEntryByProviderId[3].Flink;
if( (Flink & 0x20000000) == 0 )
{
v14 = (_IO_SECURITY_CONTEXT *)v12[1].Flink;
if( (Flink & 0x10000000) != 0 )
{
v26 = 0;
v25 = ((__int64(__fastcall *)(_QWORD, VOID *, _QWORD, VOID *, _IO_SECURITY_CONTEXT *, unsigned int *))v14->SecurityQos)(
v6,
DataPath,
(unsigned int)BufferLength,
Buffer,
v14,
&v26);
Irp->IoStatus.Information = v26;
Irp->IoStatus.Status = v25;
WmipUnreferenceRegEntry((_REGENTRY *)v12);
return v25;
}
else
{
if( (_BYTE)v6 != 11 && (_BYTE)v6 != 8 )
{
v15 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnpidGuid;
if( !v15 )
v15 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnpidGuid + 1);
if( !v15 )
goto LABEL_36;
v16 = *((_QWORD *)Buffer + 3) - WmipDataProviderPnPIdInstanceNamesGuid;
if( !v16 )
v16 = *((_QWORD *)Buffer + 4) - *((_QWORD *)&WmipDataProviderPnPIdInstanceNamesGuid + 1);
if( !v16 )
{
LABEL_36:
if( v12[1].Blink )
v14 = (_IO_SECURITY_CONTEXT *)*(&ExBootDevicesRemovedEvent + 391);
}
}
LODWORD(v17) = IoGetAttachedDeviceReference((INT64)v14, v10, v11);
v18 = (_ADAPTER_OBJECT *)v17;
v19 = *(_BYTE *)(v17 + 76) + 1;
if( v19 <= *(char *)(*(&ExBootDevicesRemovedEvent + 391) + 76i64) || v17 == *(&ExBootDevicesRemovedEvent + 391) )
{
KeInitializeEvent((INT64)&Object, 1, 0);
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
CurrentStackLocation[-1].CompletionRoutine = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *, void *))SmKmGenericCompletion;
CurrentStackLocation[-1].Context = &Object;
CurrentStackLocation[-1].Control = -32;
v21 = Irp->Tail.CurrentStackLocation;
*(_QWORD *)&v21[-1].Parameters.EaLength = Buffer;
v21[-1].MajorFunction = 23;
v21[-1].MinorFunction = v6;
v21[-1].Parameters.SecurityContext = v14;
*(_QWORD *)&v21[-1].Parameters.Options = DataPath;
*(_DWORD *)&v21[-1].Parameters.FileAttributes = BufferLength;
v22 = Irp->Tail.CurrentStackLocation;
Irp->IoStatus.Status = -1073741637;
v22->Control |= 1u;
Status = IofCallDriver((UINT64)v18, (UINT64)Irp);
if( Status == 259 )
{
KeWaitForSingleObject((UINT64)&Object, 0, 0, 0, 0i64);
Status = Irp->IoStatus.Status;
}
if( Status == -1073741637 )
{
Status = -1073741163;
Irp->IoStatus.Status = -1073741163;
}
if( ((_BYTE)v6 == 11 || (_BYTE)v6 == 8) && Status >= 0 && Irp->IoStatus.Information > 0x18 )
WmipTranslatePDOInstanceNames(Irp, v6, (unsigned int)BufferLength, (_REGENTRY *)v12);
WmipUnreferenceRegEntry((_REGENTRY *)v12);
}
else
{
WmipUnreferenceRegEntry((_REGENTRY *)v12);
WmipUpdateDeviceStackSize(v19);
Status = -1073741160;
}
HalPutDmaAdapter(v18);
return Status;
}
}
WmipUnreferenceRegEntry((_REGENTRY *)v12);
}
result = -1073741162;
if( (unsigned __int8)(v6 - 1) > 1u )
return -1073741823;
return result;
}Referenced by:
WmipQueryAllData
WmipQuerySetExecuteSI
WmipSendWmiIrp
WmipSendWmiIrpToTraceDeviceList
WmipSetTraceNotify