AlpcpDispatchNewMessage
INT64 __fastcall AlpcpDispatchNewMessage(INT64 a1){
__int64 v1;
int v2;
ULONG_PTR v4;
INT64 *v5;
_ETHREAD *CurrentThread;
int v7;
int v8;
INT64 v9;
INT64 v10;
__int64 v11;
_EJOB *ProcessJob;
__int16 v14;
int v15;
__int16 v16;
unsigned int v17;
int v18;
v1 = *(_QWORD *)a1;
v2 = *(_DWORD *)(a1 + 48);
v4 = *(_QWORD *)(a1 + 8);
*(_QWORD *)(a1 + 32) = 0i64;
*(_QWORD *)(a1 + 24) = 0i64;
*(_QWORD *)(a1 + 40) = 0i64;
v5 = *(INT64 **)(v1 + 16);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v18 = v2;
v7 = (*(_DWORD *)(v1 + 416) >> 1) & 3;
ExAcquirePushLockSharedEx((UINT64)(v5 - 2), 0i64);
v8 = v7 - 1;
if( !v8 )
{
v9 = *v5;
goto LABEL_6;
}
if( v8 != 1 )
{
v9 = v5[2];
LABEL_6:
v10 = v9;
goto LABEL_7;
}
v9 = *v5;
v10 = v5[1];
LABEL_7:
if( v9 && !ObReferenceObjectSafe((PVOID)v9) )
v9 = 0i64;
if( v10 && !ObReferenceObjectSafe((PVOID)v10) )
v10 = 0i64;
if( !v9 || !v10 )
{
if( _InterlockedCompareExchange64(v5 - 2, 0i64, 17i64) != 17 )
ExfReleasePushLockShared(v5 - 2);
KeAbPostRelease(v5 - 2);
if( v9 )
HalPutDmaAdapter((PADAPTER_OBJECT)v9);
if( v10 )
HalPutDmaAdapter((PADAPTER_OBJECT)v10);
goto LABEL_49;
}
ExAcquirePushLockSharedEx(v9 + 352, 0i64);
if( v10 != v9 )
ExAcquirePushLockSharedEx(v10 + 352, 0i64);
if( (*(_DWORD *)(v9 + 416) & 0x20) != 0
|| (*(_DWORD *)(v10 + 416) & 0x20) != 0
|| (*(_DWORD *)(v1 + 416) & 0x20) != 0 && (*(_DWORD *)(v1 + 256) & 0x1000) == 0 )
{
AlpcpUnlockAndDereferenceTargetPortsAndCommunicationInfo((INT64)v5, v9, v10);
LABEL_49:
AlpcpUnlockMessage(v4);
return 3221225527i64;
}
if( (*(_DWORD *)(*(_QWORD *)a1 + 256i64) & 0x800000) != 0
&& (*(_DWORD *)(*(_QWORD *)(a1 + 8) + 40i64) & 0x200) == 0
&& (v11 = *(_QWORD *)(v9 + 24), (v11 & 1) == 0)
&& v11
&& (ProcessJob = (_EJOB *)PsGetProcessJob(v11)) != 0i64
&& (unsigned int)PsGetJobEffectiveFreezeCount(ProcessJob) )
{
AlpcpUnlockAndDereferenceTargetPortsAndCommunicationInfo((INT64)v5, v9, v10);
AlpcpUnlockMessage(v4);
return 3221225526i64;
}
else if( (*(_DWORD *)(v9 + 256) & 0x20000) != 0 )
{
if( (unsigned __int64)*(unsigned __int16 *)(a1 + 52) <= *(_QWORD *)(v9 + 272) )
{
*(_QWORD *)(v4 + 200) = 0i64;
*(_WORD *)(v4 + 242) = *(_WORD *)(a1 + 52);
*(_WORD *)(v4 + 240) = *(_WORD *)(a1 + 52) - 40;
v14 = *(_WORD *)(a1 + 54);
*(_WORD *)(v4 + 244) = v14;
*(_WORD *)(v4 + 246) = *(_WORD *)(a1 + 56);
v15 = *(_DWORD *)(v4 + 40);
*(_OWORD *)(v4 + 248) = *(_OWORD *)((char *)CurrentThread + 1144);
if( (v18 & 0x10000) != 0 )
{
v16 = v14 & 0xDFFF;
v17 = v15 | 0x200;
}
else
{
v16 = v14 | 0x2000;
v17 = v15 & 0xFFFFFDFF;
}
*(_DWORD *)(v4 + 40) = v17;
*(_WORD *)(v4 + 244) = v16;
AlpcpSetOwnerPortMessage(v4, (VOID *)v1);
*(_DWORD *)(v4 + 44) = _InterlockedIncrement((volatile signed __int32 *)(v10 + 400));
*(_QWORD *)(v4 + 120) = *(_QWORD *)(v10 + 56);
*(_QWORD *)(v4 + 184) = v5;
*(_QWORD *)(v4 + 192) = *v5;
if( v10 != v9 )
{
if( _InterlockedCompareExchange64((volatile signed __int64 *)(v10 + 352), 0i64, 17i64) != 17 )
ExfReleasePushLockShared((INT64 *)(v10 + 352));
KeAbPostRelease((PVOID)(v10 + 352));
}
if( (v18 & 0x20000) != 0 )
{
*(_DWORD *)(v4 + 40) &= ~0x100u;
*(_WORD *)(v4 - 30) += 2;
*(_QWORD *)(v4 + 32) = CurrentThread;
_InterlockedExchange64((volatile __int64 *)CurrentThread + 165, v4);
}
*(_QWORD *)(a1 + 32) = v9;
*(_QWORD *)(a1 + 16) = v5;
AlpcpCompleteDispatchMessage(a1);
HalPutDmaAdapter((PADAPTER_OBJECT)v10);
return 0i64;
}
else
{
AlpcpUnlockAndDereferenceTargetPortsAndCommunicationInfo((INT64)v5, v9, v10);
AlpcpUnlockMessage(v4);
return 3221225507i64;
}
}
else
{
AlpcpUnlockAndDereferenceTargetPortsAndCommunicationInfo((INT64)v5, v9, v10);
AlpcpUnlockMessage(v4);
return 3221227271i64;
}
}Referenced by:
AlpcpDispatchMessage
AlpcpSendMessage