NtQuerySymbolicLinkObject

NTSTATUS __stdcall NtQuerySymbolicLinkObject(PVOID LinkHandle, _UNICODE_STRING *LinkTarget, UINT64 *ReturnedLength){
  KPROCESSOR_MODE v6; 
  __int64 v7; 
  __int64 p_MaximumLength; 
  __int64 v9; 
  _ETHREAD *CurrentThread; 
  char *v11; 
  WCHAR v12; 
  int v13; 
  unsigned int v14; 
  PVOID Object; 
  ULONG_PTR BugCheckParameter2; 
  void *Src[2]; 
  UINT8 *dst[2]; 
  int v20; 
  *(_OWORD *)dst = 0i64;
  *(_OWORD *)Src = 0i64;
  v6 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v6 )
  {
    if( ((unsigned __int8)LinkTarget & 1) != 0 )
      ExRaiseDatatypeMisalignment();
    v7 = (__int64)LinkTarget;
    if( (unsigned __int64)LinkTarget >= 0x7FFFFFFF0000i64 )
      v7 = 0x7FFFFFFF0000i64;
    *(_WORD *)v7 = *(_WORD *)v7;
    p_MaximumLength = (__int64)&LinkTarget->MaximumLength;
    if( (unsigned __int64)&LinkTarget->MaximumLength >= 0x7FFFFFFF0000i64 )
      p_MaximumLength = 0x7FFFFFFF0000i64;
    *(_WORD *)p_MaximumLength = *(_WORD *)p_MaximumLength;
    *(_UNICODE_STRING *)dst = *LinkTarget;
    ProbeForWrite((VOID *)_mm_srli_si128(*(__m128i *)dst, 8).m128i_i64[0], WORD1(dst[0]), 1ui64);
    if( ReturnedLength )
    {
      v9 = (__int64)ReturnedLength;
      if( (unsigned __int64)ReturnedLength >= 0x7FFFFFFF0000i64 )
        v9 = 0x7FFFFFFF0000i64;
      *(_DWORD *)v9 = *(_DWORD *)v9;
    }
  }
  else
  {
    *(_UNICODE_STRING *)dst = *LinkTarget;
  }
  Object = 0i64;
  v20 = ObReferenceObjectByHandle(LinkHandle, 1u, ObpSymbolicLinkObjectType, v6, &Object, 0i64);
  if( v20 >= 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 242);
    v11 = (char *)Object;
    BugCheckParameter2 = (ULONG_PTR)Object - 32;
    ExAcquirePushLockExclusiveEx((UINT64)Object - 32, 0i64);
    if( (*((_DWORD *)v11 + 7) & 0x10) != 0 )
      RtlInitUnicodeString((PUNICODE_STRING)Src, &word_1407CF120, v12);
    else
      *(_OWORD *)Src = *(_OWORD *)(v11 + 8);
    v13 = (int)Src[0];
    if( ReturnedLength )
    {
      if( WORD1(Src[0]) <= WORD1(dst[0]) )
      {
        v14 = WORD1(Src[0]);
LABEL_18:
        memmove(dst[1], (UINT8 *)Src[1], v14);
        LinkTarget->Length = v13;
        if( ReturnedLength )
          *(_DWORD *)ReturnedLength = HIWORD(v13);
LABEL_20:
        ExReleasePushLockEx(BugCheckParameter2, 0i64);
        KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
        return v20;
      }
    }
    else if( LOWORD(Src[0]) <= WORD1(dst[0]) )
    {
      v14 = LOWORD(Src[0]);
      goto LABEL_18;
    }
    v20 = -1073741789;
    if( ReturnedLength )
      *(_DWORD *)ReturnedLength = WORD1(Src[0]);
    goto LABEL_20;
  }
  return v20;
}

Referenced by:

AdtpInitializeDriveLetters
IopReassignSystemRoot
IopStoreSystemPartitionInformation