IopGetDriverPathInformation

NTSTATUS __stdcall IopGetDriverPathInformation(
        _FILE_OBJECT *FileObject,
        _FILE_FS_DRIVER_PATH_INFORMATION *FsDpInfo,
        UINT64 a3){
  NTSTATUS result; 
  _VPB *Vpb; 
  DEVICE_OBJECT *DeviceObject; 
  KIRQL v8; 
  __int16 v9[2]; 
  int v10; 
  WCHAR *DriverName; 
  PVOID Object; 
  v10 = 0;
  Object = 0i64;
  if( (unsigned int)(a3 - 8) < FsDpInfo->DriverNameLength )
    return -1073741811;
  DriverName = FsDpInfo->DriverName;
  v9[0] = FsDpInfo->DriverNameLength;
  v9[1] = v9[0];
  result = ObReferenceObjectByName(
             (unsigned __int64)v9,
             64,
             0i64,
             0,
             (__int64)IoDriverObjectType,
             0,
             0i64,
             (PADAPTER_OBJECT *)&Object);
  if( result >= 0 )
  {
    KeAcquireQueuedSpinLock(0xAui64);
    Vpb = FileObject->Vpb;
    if( Vpb
      && (DeviceObject = Vpb->DeviceObject) != 0i64
      && IopVerifyDriverObjectOnStack(DeviceObject, (DRIVER_OBJECT *)Object) )
    {
      FsDpInfo->DriverInPath = 1;
    }
    else
    {
      FsDpInfo->DriverInPath = IopVerifyDriverObjectOnStack(FileObject->DeviceObject, (DRIVER_OBJECT *)Object);
    }
    KeReleaseQueuedSpinLock(0xAui64, v8);
    ObfDereferenceObjectWithTag(Object, 0x746C6644ui64);
    return 0;
  }
  return result;
}

Referenced by:

NtQueryVolumeInformationFile