PiCMOpenDeviceInterfaceKey
INT64 __stdcall PiCMOpenDeviceInterfaceKey(
PVOID IoctlInputBuffer,
UINT64 IoctlInputBufferSize,
PVOID IoctlOutputBuffer,
UINT64 IoctlOutputBufferSize,
UINT64 *BytesUsed){
unsigned int *v5;
unsigned int v6;
INT8 v8;
int v9;
__int64 v10;
const WCHAR *v11;
unsigned int v12;
UINT64 v13;
int v14;
__int64 v15;
int v16;
HANDLE *IoctlOutputBufferSizea;
__int64 v19;
__int64 v20;
HANDLE v21;
INT64 a4[2];
UINT64 *DesiredAccess[2];
unsigned int ExpectedOutputSize[4];
HANDLE Handle;
v5 = (unsigned int *)Handle;
v6 = IoctlOutputBufferSize;
v21 = 0i64;
Handle = 0i64;
*v5 = 0;
*(_OWORD *)a4 = 0i64;
*(_OWORD *)DesiredAccess = 0i64;
v8 = *((_BYTE *)KeGetCurrentThread() + 562);
*(_OWORD *)ExpectedOutputSize = 0i64;
v9 = PiCMCaptureRegistryInputData(IoctlInputBuffer, IoctlInputBufferSize, (unsigned int)BytesUsed, (INT64)a4);
if( v9 < 0 )
goto LABEL_21;
v11 = (const WCHAR *)DesiredAccess[0];
if( !DesiredAccess[0]
|| *(INT64 *)((char *)a4 + 4) != 0x400000000i64
|| ExpectedOutputSize[1]
|| !IoctlOutputBuffer
|| v6 < 0x10 )
{
v14 = -1073741811;
goto LABEL_15;
}
v12 = HIDWORD(DesiredAccess[1]);
v14 = CmOpenDeviceInterfaceRegKey(
PiPnpRtlCtx,
(const WCHAR *)DesiredAccess[0],
0x32u,
v10,
SHIDWORD(DesiredAccess[1]),
0,
(__int64)&Handle,
0i64);
if( v14 != -1073741772 )
goto LABEL_12;
if( ExpectedOutputSize[0] == 1 )
{
if( !PiAuDoesClientHaveAccess(2ui64) )
{
v14 = -1073741790;
goto LABEL_15;
}
v14 = CmOpenDeviceInterfaceRegKey(PiPnpRtlCtx, v11, 0x32u, v15, v12, 1, (__int64)&Handle, 0i64);
LABEL_12:
if( v14 >= 0 )
{
IoctlOutputBufferSizea = &v21;
PiCMDuplicateRegistryHandle(Handle, v13, (UINT64 *)v12, v8);
v14 = v16;
}
}
LABEL_15:
LODWORD(IoctlOutputBufferSizea) = v6;
v9 = PiCMReturnHandleResultData(
v14,
v21,
ExpectedOutputSize[2],
IoctlOutputBuffer,
(__int64)IoctlOutputBufferSizea,
v5,
v19,
v20);
if( Handle )
ZwClose(Handle);
if( v9 < 0 || v14 < 0 )
{
if( v21 )
ObCloseHandle(v21, v8);
}
LABEL_21:
PiCMReleaseRegistryInputData((INT64)a4);
return(unsigned int)v9;
}Referenced by:
No references.