ObInitSystem
INT64 __fastcall ObInitSystem(){
INT64 inited;
__int16 v1;
__int16 v2;
struct _KPRCB *CurrentPrcb;
__int64 v4;
__int64 *v5;
WCHAR v6;
WCHAR v7;
WCHAR v8;
UCHAR v9;
KBUGCHECK_CALLBACK_REASON v10;
UCHAR *v11;
unsigned int v12;
unsigned int v13;
struct _NPAGED_LOOKASIDE_LIST *v14;
__int64 v15;
__int128 *v16;
void *v17;
PADAPTER_OBJECT v18;
__int64 *i;
__int64 v20;
INT64 v21;
UINT32 v22;
UINT64 v23;
void *v24;
_BYTE *v25;
UINT8 Size;
UINT8 Tag;
PVOID Object;
PVOID Ace;
void *DirectoryHandle;
__int16 result;
char result_2;
char result_3;
int v34;
__int128 v35;
int v36;
int v37;
int v38;
NTSTATUS(__fastcall *v39)(__int64, __int64, __int64, __int64);
VOID(__stdcall *v40)(PVOID);
NTSTATUS(__stdcall *v41)(PVOID, PVOID, ACCESS_STATE *, INT8, UINT64, UNICODE_STRING *, UNICODE_STRING *, PVOID, SECURITY_QUALITY_OF_SERVICE *, _OB_EXTENDED_PARSE_PARAMETERS *, PVOID *);
struct _OBJECT_ATTRIBUTES ObjectAttributes;
_OBP_LOOKUP_CONTEXT LookupContext;
struct _UNICODE_STRING DestinationString;
struct _UNICODE_STRING v45;
struct _UNICODE_STRING v46;
__int128 SecurityDescriptor[2];
__int64 v48;
struct _ACL Acl;
v48 = 0i64;
Ace = 0i64;
memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
v45 = 0i64;
memset(&LookupContext, 0, sizeof(LookupContext));
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
inited = memset((INT64)&result, 0i64);
DirectoryHandle = 0i64;
v46 = 0i64;
DestinationString = 0i64;
if( (_BYTE)dword_140CFA19C )
{
v1 = 64;
v2 = 32;
}
else
{
v1 = 32;
v2 = 16;
}
if( !*(_DWORD *)InitializationPhase )
{
ObHeaderCookie = ExGenRandom(0i64);
ExInitializeSystemLookasideList(
(unsigned int)ObpCreateInfoLookasideList,
512,
64,
1766023759,
v1,
(__int64)&ExSystemLookasideListHead);
ExInitializeSystemLookasideList(
(unsigned int)ObpNameBufferLookasideList,
1,
248,
1833853519,
v2,
(__int64)&ExSystemLookasideListHead);
CurrentPrcb = KeGetCurrentPrcb();
ObpPendingObjectDirectoryList = 0i64;
*((_QWORD *)CurrentPrcb + 267) = ObpNameBufferLookasideList;
*((_QWORD *)CurrentPrcb + 266) = ObpNameBufferLookasideList;
*((_QWORD *)CurrentPrcb + 265) = ObpCreateInfoLookasideList;
v4 = 256i64;
*((_QWORD *)CurrentPrcb + 264) = ObpCreateInfoLookasideList;
v5 = qword_140D24A08;
ObpRemoveObjectList = 0i64;
ObpRemoveObjectWait.0 = 0i64;
ObpPendingObjectDirectoryListLock = 0i64;
do
{
*(v5 - 1) = 0i64;
*v5 = 0i64;
v5 += 2;
--v4;
}
while( v4 );
ObpDefaultObject = 0;
qword_140C258B0 = (__int64)&qword_140C258A8;
qword_140C258A8 = (__int64)&qword_140C258A8;
byte_140C258A2 = 6;
dword_140C258A4 = 1;
ObpKernelHandleTable = ExCreateHandleTable(0i64, 1i64);
inited = ObpKernelHandleTable;
*(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1392i64) = ObpKernelHandleTable;
if( !ObpKernelHandleTable )
goto LABEL_40;
ObpRemoveObjectWorkItem.Parameter = 0i64;
ObpRemoveObjectWorkItem.WorkerRoutine = (void(__fastcall *)(void *))ObpProcessRemoveObjectQueue;
qword_140C258D8 = (__int64)ObpProcessRemoveObjectDpcWorker;
ObpRemoveObjectWorkItem.List.Flink = 0i64;
LODWORD(ObpRemoveObjectDpc) = 275;
qword_140C258E0 = 0i64;
qword_140C258F8 = 0i64;
qword_140C258D0 = 0i64;
ObpInitInfoBlockOffsets();
qword_140CFBE88 = (__int64)MmBadPointer;
v34 = 256;
result = 120;
v37 = 512;
RtlInitUnicodeString(&DestinationString, L"Type", v6);
result_2 |= 0x24u;
v36 = 983041;
v38 = 216;
v35 = ObpTypeMapping;
inited = ObCreateObjectType(&DestinationString, (__int64)&result, 0i64, (__int64)&ObpTypeObjectType);
if( (int)inited < 0 )
goto LABEL_40;
v37 = 1;
RtlInitUnicodeString(&v45, L"Directory", v7);
v38 = 344;
v36 = 983055;
result_2 = result_2 & 0xD2 | 0xD;
v39 = ObpCloseDirectoryObject;
v40 = ObpDeleteDirectoryObject;
v35 = ObpDirectoryMapping;
inited = ObCreateObjectType(&v45, (__int64)&result, 0i64, (__int64)&ObpDirectoryObjectType);
if( (int)inited < 0 )
goto LABEL_40;
v39 = 0i64;
ObpDirectoryObjectType->TypeInfo.ValidAccessMask &= ~0x100000u;
RtlInitUnicodeString(&v46, L"SymbolicLink", v8);
result_3 |= 1u;
v40 = ObpDeleteSymbolicLink;
v38 = 40;
v41 = ObpParseSymbolicLinkEx;
v37 = 1;
v36 = 0xFFFFF;
result_2 = result_2 & 0xF6 | 1;
v35 = ObpSymbolicLinkMapping;
inited = ObCreateObjectType(&v46, (__int64)&result, 0i64, (__int64)&ObpSymbolicLinkObjectType);
if( (int)inited < 0 )
goto LABEL_40;
ObpSymbolicLinkObjectType->TypeInfo.ValidAccessMask &= ~0x100000u;
ObpInitStackTrace();
}
if( *(_DWORD *)InitializationPhase != 1 )
{
LABEL_38:
LOBYTE(inited) = 1;
return inited;
}
inited = ObInitServerSilo(0i64);
if( (int)inited >= 0 )
{
v12 = 0;
if( (_DWORD)KeNumberProcessors_0 )
{
do
{
ObInitializeProcessor((INT64)*(&KiProcessorBlock + v12), v9, v10, v11);
if( (int)inited < 0 )
goto LABEL_40;
}
while( ++v12 < (unsigned int)KeNumberProcessors_0 );
}
v13 = 0;
v14 = (struct _NPAGED_LOOKASIDE_LIST *)ObpWaitBlockLookaside;
do
{
v15 = 14 * v13 + 24;
if( (unsigned int)v15 >= 0x40 )
v15 = 64i64;
ExInitializeNPagedLookasideList(v14, 0i64, 0i64, 0x200u, 48 * v15, 0x6D57624Fu, 0);
++v13;
v14 = (struct _NPAGED_LOOKASIDE_LIST *)((char *)v14 + 128);
}
while( v13 < 4 );
v16 = (__int128 *)SePublicDefaultUnrestrictedSd;
if( !ObpAuditBaseDirectories && !ObpAuditBaseObjects )
goto LABEL_56;
inited = (INT64)SeWorldSid;
v22 = 4 * *((unsigned __int8 *)SeWorldSid + 1) + 28;
if( v22 < 0xFA )
{
LODWORD(inited) = RtlCreateAcl(&Acl, v22, 2u);
if( (int)inited >= 0 )
{
inited = RtlAddAuditAccessAce(&Acl, v23, 0x60000000ui64, v24, Size, Tag);
if( (int)inited >= 0 )
{
LODWORD(inited) = RtlGetAce(&Acl, 0i64, &Ace);
if( (int)inited >= 0 )
{
v25 = Ace;
if( ObpAuditBaseDirectories )
*((_BYTE *)Ace + 1) |= 0xAu;
if( ObpAuditBaseObjects )
v25[1] |= 9u;
v16 = SecurityDescriptor;
LODWORD(inited) = RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64);
if( (int)inited >= 0 )
{
LODWORD(inited) = RtlSetDaclSecurityDescriptor(
SecurityDescriptor,
1u,
(ACL *)SePublicDefaultUnrestrictedDacl,
0);
if( (int)inited >= 0 )
{
inited = RtlSetSaclSecurityDescriptor(SecurityDescriptor, 1u, &Acl, 0);
if( (int)inited >= 0 )
{
LABEL_56:
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&ObpRootDirectoryName;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 80;
ObjectAttributes.SecurityDescriptor = v16;
ObjectAttributes.SecurityQualityOfService = 0i64;
LODWORD(inited) = NtCreateDirectoryObject(&DirectoryHandle, 0xF000Fui64, &ObjectAttributes);
if( (int)inited >= 0 )
{
v17 = DirectoryHandle;
Object = 0i64;
LODWORD(inited) = ObReferenceObjectByHandle(
DirectoryHandle,
0,
ObpDirectoryObjectType,
0,
&Object,
0i64);
ObpRootDirectoryObject = Object;
if( (int)inited >= 0 )
{
LODWORD(inited) = ObpInitializeRootNamespace(0i64, v17, 0i64);
if( (int)inited >= 0 )
{
LODWORD(inited) = NtClose(v17);
if( (int)inited >= 0 )
{
LookupContext.LockStateSignature = -60876;
ObpLockDirectoryExclusive(&LookupContext, (_OBJECT_DIRECTORY *)ObpTypeDirectoryObject);
v18 = ObpTypeObjectType;
for( i = *(__int64 **)&ObpTypeObjectType->Version; i != (__int64 *)v18; i = (__int64 *)*i )
{
if( (*((_BYTE *)i + 58) & 2) != 0 )
v20 = (__int64)i
- *((unsigned __int8 *)ObpInfoMaskToOffset + (*((_BYTE *)i + 58) & 3))
+ 32;
else
v20 = 0i64;
if( v20
&& !*(_QWORD *)v20
&& !ObpLookupDirectoryEntry(
(CHAR *)ObpTypeDirectoryObject,
(const UNICODE_STRING *)(v20 + 8),
64,
(INT64)&LookupContext) )
{
if( !i[9] )
{
inited = ObpInitObjectTypeSD(i + 10, 0i64, v21);
if( (int)inited < 0 )
goto LABEL_40;
}
if( !ObpInsertDirectoryEntry(
(CHAR *)ObpTypeDirectoryObject,
(CHAR *)i + 80,
(INT64)&LookupContext) )
goto LABEL_40;
}
}
ObpReleaseLookupContext((INT64)&LookupContext);
inited = (INT64)&ObpLUIDDeviceMapsEnabled;
Object = &ObpLUIDDeviceMapsEnabled;
goto LABEL_38;
}
}
}
}
}
}
}
}
}
}
}
}
LABEL_40:
LOBYTE(inited) = 0;
return inited;
}Referenced by:
InitBootProcessor
Phase1InitializationDiscard