NtQuerySymbolicLinkObject
NTSTATUS __stdcall NtQuerySymbolicLinkObject(PVOID LinkHandle, _UNICODE_STRING *LinkTarget, UINT64 *ReturnedLength){
KPROCESSOR_MODE v6;
__int64 v7;
__int64 p_MaximumLength;
__int64 v9;
_ETHREAD *CurrentThread;
char *v11;
WCHAR v12;
int v13;
unsigned int v14;
PVOID Object;
ULONG_PTR BugCheckParameter2;
void *Src[2];
UINT8 *dst[2];
int v20;
*(_OWORD *)dst = 0i64;
*(_OWORD *)Src = 0i64;
v6 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v6 )
{
if( ((unsigned __int8)LinkTarget & 1) != 0 )
ExRaiseDatatypeMisalignment();
v7 = (__int64)LinkTarget;
if( (unsigned __int64)LinkTarget >= 0x7FFFFFFF0000i64 )
v7 = 0x7FFFFFFF0000i64;
*(_WORD *)v7 = *(_WORD *)v7;
p_MaximumLength = (__int64)&LinkTarget->MaximumLength;
if( (unsigned __int64)&LinkTarget->MaximumLength >= 0x7FFFFFFF0000i64 )
p_MaximumLength = 0x7FFFFFFF0000i64;
*(_WORD *)p_MaximumLength = *(_WORD *)p_MaximumLength;
*(_UNICODE_STRING *)dst = *LinkTarget;
ProbeForWrite((VOID *)_mm_srli_si128(*(__m128i *)dst, 8).m128i_i64[0], WORD1(dst[0]), 1ui64);
if( ReturnedLength )
{
v9 = (__int64)ReturnedLength;
if( (unsigned __int64)ReturnedLength >= 0x7FFFFFFF0000i64 )
v9 = 0x7FFFFFFF0000i64;
*(_DWORD *)v9 = *(_DWORD *)v9;
}
}
else
{
*(_UNICODE_STRING *)dst = *LinkTarget;
}
Object = 0i64;
v20 = ObReferenceObjectByHandle(LinkHandle, 1u, ObpSymbolicLinkObjectType, v6, &Object, 0i64);
if( v20 >= 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v11 = (char *)Object;
BugCheckParameter2 = (ULONG_PTR)Object - 32;
ExAcquirePushLockExclusiveEx((UINT64)Object - 32, 0i64);
if( (*((_DWORD *)v11 + 7) & 0x10) != 0 )
RtlInitUnicodeString((PUNICODE_STRING)Src, &word_1407CF120, v12);
else
*(_OWORD *)Src = *(_OWORD *)(v11 + 8);
v13 = (int)Src[0];
if( ReturnedLength )
{
if( WORD1(Src[0]) <= WORD1(dst[0]) )
{
v14 = WORD1(Src[0]);
LABEL_18:
memmove(dst[1], (UINT8 *)Src[1], v14);
LinkTarget->Length = v13;
if( ReturnedLength )
*(_DWORD *)ReturnedLength = HIWORD(v13);
LABEL_20:
ExReleasePushLockEx(BugCheckParameter2, 0i64);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
return v20;
}
}
else if( LOWORD(Src[0]) <= WORD1(dst[0]) )
{
v14 = LOWORD(Src[0]);
goto LABEL_18;
}
v20 = -1073741789;
if( ReturnedLength )
*(_DWORD *)ReturnedLength = WORD1(Src[0]);
goto LABEL_20;
}
return v20;
}Referenced by:
AdtpInitializeDriveLetters
IopReassignSystemRoot
IopStoreSystemPartitionInformation