ObInitSystem

INT64 __fastcall ObInitSystem(){
  INT64 inited; 
  __int16 v1; 
  __int16 v2; 
  struct _KPRCB *CurrentPrcb; 
  __int64 v4; 
  __int64 *v5; 
  WCHAR v6; 
  WCHAR v7; 
  WCHAR v8; 
  UCHAR v9; 
  KBUGCHECK_CALLBACK_REASON v10; 
  UCHAR *v11; 
  unsigned int v12; 
  unsigned int v13; 
  struct _NPAGED_LOOKASIDE_LIST *v14; 
  __int64 v15; 
  __int128 *v16; 
  void *v17; 
  PADAPTER_OBJECT v18; 
  __int64 *i; 
  __int64 v20; 
  INT64 v21; 
  UINT32 v22; 
  UINT64 v23; 
  void *v24; 
  _BYTE *v25; 
  UINT8 Size; 
  UINT8 Tag; 
  PVOID Object; 
  PVOID Ace; 
  void *DirectoryHandle; 
  __int16 result; 
  char result_2; 
  char result_3; 
  int v34; 
  __int128 v35; 
  int v36; 
  int v37; 
  int v38; 
  NTSTATUS(__fastcall *v39)(__int64, __int64, __int64, __int64); 
  VOID(__stdcall *v40)(PVOID); 
  NTSTATUS(__stdcall *v41)(PVOID, PVOID, ACCESS_STATE *, INT8, UINT64, UNICODE_STRING *, UNICODE_STRING *, PVOID, SECURITY_QUALITY_OF_SERVICE *, _OB_EXTENDED_PARSE_PARAMETERS *, PVOID *); 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  _OBP_LOOKUP_CONTEXT LookupContext; 
  struct _UNICODE_STRING DestinationString; 
  struct _UNICODE_STRING v45; 
  struct _UNICODE_STRING v46; 
  __int128 SecurityDescriptor[2]; 
  __int64 v48; 
  struct _ACL Acl; 
  v48 = 0i64;
  Ace = 0i64;
  memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
  v45 = 0i64;
  memset(&LookupContext, 0, sizeof(LookupContext));
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  inited = memset((INT64)&result, 0i64);
  DirectoryHandle = 0i64;
  v46 = 0i64;
  DestinationString = 0i64;
  if( (_BYTE)dword_140CFA19C )
  {
    v1 = 64;
    v2 = 32;
  }
  else
  {
    v1 = 32;
    v2 = 16;
  }
  if( !*(_DWORD *)InitializationPhase )
  {
    ObHeaderCookie = ExGenRandom(0i64);
    ExInitializeSystemLookasideList(
      (unsigned int)ObpCreateInfoLookasideList,
      512,
      64,
      1766023759,
      v1,
      (__int64)&ExSystemLookasideListHead);
    ExInitializeSystemLookasideList(
      (unsigned int)ObpNameBufferLookasideList,
      1,
      248,
      1833853519,
      v2,
      (__int64)&ExSystemLookasideListHead);
    CurrentPrcb = KeGetCurrentPrcb();
    ObpPendingObjectDirectoryList = 0i64;
    *((_QWORD *)CurrentPrcb + 267) = ObpNameBufferLookasideList;
    *((_QWORD *)CurrentPrcb + 266) = ObpNameBufferLookasideList;
    *((_QWORD *)CurrentPrcb + 265) = ObpCreateInfoLookasideList;
    v4 = 256i64;
    *((_QWORD *)CurrentPrcb + 264) = ObpCreateInfoLookasideList;
    v5 = qword_140D24A08;
    ObpRemoveObjectList = 0i64;
    ObpRemoveObjectWait.0 = 0i64;
    ObpPendingObjectDirectoryListLock = 0i64;
    do
    {
      *(v5 - 1) = 0i64;
      *v5 = 0i64;
      v5 += 2;
      --v4;
    }
    while( v4 );
    ObpDefaultObject = 0;
    qword_140C258B0 = (__int64)&qword_140C258A8;
    qword_140C258A8 = (__int64)&qword_140C258A8;
    byte_140C258A2 = 6;
    dword_140C258A4 = 1;
    ObpKernelHandleTable = ExCreateHandleTable(0i64, 1i64);
    inited = ObpKernelHandleTable;
    *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1392i64) = ObpKernelHandleTable;
    if( !ObpKernelHandleTable )
      goto LABEL_40;
    ObpRemoveObjectWorkItem.Parameter = 0i64;
    ObpRemoveObjectWorkItem.WorkerRoutine = (void(__fastcall *)(void *))ObpProcessRemoveObjectQueue;
    qword_140C258D8 = (__int64)ObpProcessRemoveObjectDpcWorker;
    ObpRemoveObjectWorkItem.List.Flink = 0i64;
    LODWORD(ObpRemoveObjectDpc) = 275;
    qword_140C258E0 = 0i64;
    qword_140C258F8 = 0i64;
    qword_140C258D0 = 0i64;
    ObpInitInfoBlockOffsets();
    qword_140CFBE88 = (__int64)MmBadPointer;
    v34 = 256;
    result = 120;
    v37 = 512;
    RtlInitUnicodeString(&DestinationString, L"Type", v6);
    result_2 |= 0x24u;
    v36 = 983041;
    v38 = 216;
    v35 = ObpTypeMapping;
    inited = ObCreateObjectType(&DestinationString, (__int64)&result, 0i64, (__int64)&ObpTypeObjectType);
    if( (int)inited < 0 )
      goto LABEL_40;
    v37 = 1;
    RtlInitUnicodeString(&v45, L"Directory", v7);
    v38 = 344;
    v36 = 983055;
    result_2 = result_2 & 0xD2 | 0xD;
    v39 = ObpCloseDirectoryObject;
    v40 = ObpDeleteDirectoryObject;
    v35 = ObpDirectoryMapping;
    inited = ObCreateObjectType(&v45, (__int64)&result, 0i64, (__int64)&ObpDirectoryObjectType);
    if( (int)inited < 0 )
      goto LABEL_40;
    v39 = 0i64;
    ObpDirectoryObjectType->TypeInfo.ValidAccessMask &= ~0x100000u;
    RtlInitUnicodeString(&v46, L"SymbolicLink", v8);
    result_3 |= 1u;
    v40 = ObpDeleteSymbolicLink;
    v38 = 40;
    v41 = ObpParseSymbolicLinkEx;
    v37 = 1;
    v36 = 0xFFFFF;
    result_2 = result_2 & 0xF6 | 1;
    v35 = ObpSymbolicLinkMapping;
    inited = ObCreateObjectType(&v46, (__int64)&result, 0i64, (__int64)&ObpSymbolicLinkObjectType);
    if( (int)inited < 0 )
      goto LABEL_40;
    ObpSymbolicLinkObjectType->TypeInfo.ValidAccessMask &= ~0x100000u;
    ObpInitStackTrace();
  }
  if( *(_DWORD *)InitializationPhase != 1 )
  {
LABEL_38:
    LOBYTE(inited) = 1;
    return inited;
  }
  inited = ObInitServerSilo(0i64);
  if( (int)inited >= 0 )
  {
    v12 = 0;
    if( (_DWORD)KeNumberProcessors_0 )
    {
      do
      {
        ObInitializeProcessor((INT64)*(&KiProcessorBlock + v12), v9, v10, v11);
        if( (int)inited < 0 )
          goto LABEL_40;
      }
      while( ++v12 < (unsigned int)KeNumberProcessors_0 );
    }
    v13 = 0;
    v14 = (struct _NPAGED_LOOKASIDE_LIST *)ObpWaitBlockLookaside;
    do
    {
      v15 = 14 * v13 + 24;
      if( (unsigned int)v15 >= 0x40 )
        v15 = 64i64;
      ExInitializeNPagedLookasideList(v14, 0i64, 0i64, 0x200u, 48 * v15, 0x6D57624Fu, 0);
      ++v13;
      v14 = (struct _NPAGED_LOOKASIDE_LIST *)((char *)v14 + 128);
    }
    while( v13 < 4 );
    v16 = (__int128 *)SePublicDefaultUnrestrictedSd;
    if( !ObpAuditBaseDirectories && !ObpAuditBaseObjects )
      goto LABEL_56;
    inited = (INT64)SeWorldSid;
    v22 = 4 * *((unsigned __int8 *)SeWorldSid + 1) + 28;
    if( v22 < 0xFA )
    {
      LODWORD(inited) = RtlCreateAcl(&Acl, v22, 2u);
      if( (int)inited >= 0 )
      {
        inited = RtlAddAuditAccessAce(&Acl, v23, 0x60000000ui64, v24, Size, Tag);
        if( (int)inited >= 0 )
        {
          LODWORD(inited) = RtlGetAce(&Acl, 0i64, &Ace);
          if( (int)inited >= 0 )
          {
            v25 = Ace;
            if( ObpAuditBaseDirectories )
              *((_BYTE *)Ace + 1) |= 0xAu;
            if( ObpAuditBaseObjects )
              v25[1] |= 9u;
            v16 = SecurityDescriptor;
            LODWORD(inited) = RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64);
            if( (int)inited >= 0 )
            {
              LODWORD(inited) = RtlSetDaclSecurityDescriptor(
                                  SecurityDescriptor,
                                  1u,
                                  (ACL *)SePublicDefaultUnrestrictedDacl,
                                  0);
              if( (int)inited >= 0 )
              {
                inited = RtlSetSaclSecurityDescriptor(SecurityDescriptor, 1u, &Acl, 0);
                if( (int)inited >= 0 )
                {
LABEL_56:
                  ObjectAttributes.Length = 48;
                  ObjectAttributes.ObjectName = (_UNICODE_STRING *)&ObpRootDirectoryName;
                  ObjectAttributes.RootDirectory = 0i64;
                  ObjectAttributes.Attributes = 80;
                  ObjectAttributes.SecurityDescriptor = v16;
                  ObjectAttributes.SecurityQualityOfService = 0i64;
                  LODWORD(inited) = NtCreateDirectoryObject(&DirectoryHandle, 0xF000Fui64, &ObjectAttributes);
                  if( (int)inited >= 0 )
                  {
                    v17 = DirectoryHandle;
                    Object = 0i64;
                    LODWORD(inited) = ObReferenceObjectByHandle(
                                        DirectoryHandle,
                                        0,
                                        ObpDirectoryObjectType,
                                        0,
                                        &Object,
                                        0i64);
                    ObpRootDirectoryObject = Object;
                    if( (int)inited >= 0 )
                    {
                      LODWORD(inited) = ObpInitializeRootNamespace(0i64, v17, 0i64);
                      if( (int)inited >= 0 )
                      {
                        LODWORD(inited) = NtClose(v17);
                        if( (int)inited >= 0 )
                        {
                          LookupContext.LockStateSignature = -60876;
                          ObpLockDirectoryExclusive(&LookupContext, (_OBJECT_DIRECTORY *)ObpTypeDirectoryObject);
                          v18 = ObpTypeObjectType;
                          for( i = *(__int64 **)&ObpTypeObjectType->Version; i != (__int64 *)v18; i = (__int64 *)*i )
                          {
                            if( (*((_BYTE *)i + 58) & 2) != 0 )
                              v20 = (__int64)i
                                  - *((unsigned __int8 *)ObpInfoMaskToOffset + (*((_BYTE *)i + 58) & 3))
                                  + 32;
                            else
                              v20 = 0i64;
                            if( v20
                              && !*(_QWORD *)v20
                              && !ObpLookupDirectoryEntry(
                                    (CHAR *)ObpTypeDirectoryObject,
                                    (const UNICODE_STRING *)(v20 + 8),
                                    64,
                                    (INT64)&LookupContext) )
                            {
                              if( !i[9] )
                              {
                                inited = ObpInitObjectTypeSD(i + 10, 0i64, v21);
                                if( (int)inited < 0 )
                                  goto LABEL_40;
                              }
                              if( !ObpInsertDirectoryEntry(
                                      (CHAR *)ObpTypeDirectoryObject,
                                      (CHAR *)i + 80,
                                      (INT64)&LookupContext) )
                                goto LABEL_40;
                            }
                          }
                          ObpReleaseLookupContext((INT64)&LookupContext);
                          inited = (INT64)&ObpLUIDDeviceMapsEnabled;
                          Object = &ObpLUIDDeviceMapsEnabled;
                          goto LABEL_38;
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
LABEL_40:
  LOBYTE(inited) = 0;
  return inited;
}

Referenced by:

InitBootProcessor
Phase1InitializationDiscard