IopRaiseHardError

VOID __stdcall IopRaiseHardError(PVOID NormalContext, PVOID SystemArgument1, PVOID SystemArgument2){
  char v6; 
  CHAR *Pool_1; 
  CHAR *v8; 
  int v9; 
  WCHAR v10; 
  _KPROCESS *v11; 
  int v12; 
  unsigned int v13; 
  UINT64 v14; 
  __int64 v15; 
  int v16; 
  _BYTE *v17; 
  UINT64 Mode; 
  UINT64 ReturnLength; 
  struct _UNICODE_STRING DestinationString; 
  _KAPC_STATE ApcState; 
  UINT64 Parameters; 
  CHAR *v23; 
  __int64 v24; 
  ReturnLength = 0i64;
  v6 = 0;
  memset(&ApcState, 0, sizeof(ApcState));
  DestinationString = 0i64;
  ObQueryNameStringMode(SystemArgument2, 0i64, 0i64, (UINT64 *)((char *)&ReturnLength + 4), 0);
  Pool_1 = IopVerifierExAllocatePool_1(PagedPool, HIDWORD(ReturnLength));
  v8 = Pool_1;
  if( !Pool_1 )
  {
    v9 = -1073741670;
LABEL_35:
    *((_DWORD *)NormalContext + 12) = v9;
LABEL_36:
    *((_QWORD *)NormalContext + 7) = 0i64;
    goto LABEL_37;
  }
  v9 = ObQueryNameStringMode(
         SystemArgument2,
         (OBJECT_NAME_INFORMATION *)Pool_1,
         HIDWORD(ReturnLength),
         &ReturnLength,
         0);
  if( v9 < 0 )
  {
    ExFreePoolWithTag(v8, 0);
    goto LABEL_35;
  }
  if( SystemArgument1 && (*((_BYTE *)SystemArgument1 + 4) & 1) != 0 )
  {
    DestinationString.MaximumLength = 64;
    DestinationString.Buffer = (wchar_t *)((char *)SystemArgument1 + 32);
    DestinationString.Length = *((_WORD *)SystemArgument1 + 3);
  }
  else
  {
    RtlInitUnicodeString(&DestinationString, 0i64, v10);
  }
  v11 = *(_EPROCESS **)(*((_QWORD *)NormalContext + 19) + 544i64);
  if( v11 != *((_EPROCESS **)KeGetCurrentThread() + 23) )
  {
    KiStackAttachProcess((_KPROCESS *)v11, 0i64, &ApcState);
    v6 = 1;
  }
  v12 = *((_DWORD *)NormalContext + 12);
  if( v12 != -1073741806 )
  {
    if( v12 <= -1073741806 )
    {
LABEL_17:
      v13 = 0;
      v14 = 0i64;
      goto LABEL_19;
    }
    if( v12 <= -1073741804 )
    {
LABEL_16:
      Parameters = (UINT64)v8;
      v13 = 2;
      v14 = 1i64;
      v15 = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
      v24 = 0i64;
      v23 = (CHAR *)v15;
      goto LABEL_19;
    }
    if( v12 != -1073741662 )
    {
      if( v12 == -1073741661 || v12 == -1073741643 )
        goto LABEL_16;
      goto LABEL_17;
    }
  }
  v23 = v8;
  Parameters = (UINT64)&DestinationString;
  v13 = 3;
  v14 = 3i64;
  v24 = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
LABEL_19:
  if( ExReadyForErrors )
  {
    LODWORD(Mode) = 8;
    v16 = ExRaiseHardError((unsigned int)v12, v13, v14, &Parameters, Mode, &ReturnLength);
  }
  else
  {
    LODWORD(ReturnLength) = 0;
    v16 = -1073741823;
  }
  if( v6 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  ExFreePoolWithTag(v8, 0);
  if( v16 >= 0 && (_DWORD)ReturnLength == 9 )
  {
    (*(void(__fastcall **)(_QWORD, PVOID))(*(_QWORD *)(*(_QWORD *)(*((_QWORD *)NormalContext + 23) + 40i64) + 8i64)
                                          + 8i64 * **((unsigned __int8 **)NormalContext + 23)
                                          + 112))(
      *(_QWORD *)(*((_QWORD *)NormalContext + 23) + 40i64),
      NormalContext);
    return;
  }
  if( (_DWORD)ReturnLength == 3 )
  {
    v17 = (_BYTE *)*((_QWORD *)NormalContext + 23);
    if( *v17 == 13 && v17[1] == 1 )
      *((_QWORD *)NormalContext + 7) = 1i64;
    else
      *((_DWORD *)NormalContext + 12) = -1073741248;
  }
  if( (*((_DWORD *)NormalContext + 4) & 0x40) != 0 )
    goto LABEL_36;
LABEL_37:
  IofCompleteRequest((_IRP *)NormalContext, 1);
}

Referenced by:

IopApcHardError