ExpWnfSubscribeWnfStateChange
__int64 __fastcall ExpWnfSubscribeWnfStateChange(
signed __int64 *a1,
struct _EX_RUNDOWN_REF **a2,
__int64 *a3,
int a4,
__int64 a5,
__int64 a6,
int a7,
char a8){
unsigned int v8;
int v9;
char v10;
_WNF_STATE_NAME_STRUCT v11;
unsigned __int64 v12;
int v13;
_EPROCESS *v14;
int v15;
_EPROCESS *v16;
_WNF_NAME_INSTANCE *v17;
int v18;
int v19;
UINT64 v20;
_WNF_NAME_INSTANCE *NameInstance;
int v23;
PVOID P;
_EPROCESS *Process;
_WNF_SCOPE_INSTANCE *ScopeInstance;
int v27;
_WNF_STATE_NAME_STRUCT StateName;
INT64 v29;
StateName = 0i64;
v23 = 0;
P = 0i64;
ScopeInstance = 0i64;
NameInstance = 0i64;
v29 = 0i64;
v8 = 0;
v9 = ExpCaptureWnfStateName((const _WNF_STATE_NAME *)a3, &StateName, a8);
v27 = v9;
if( v9 >= 0 )
{
if( (a7 & 0xFFFFFFE0) != 0 )
{
v9 = -1073741811;
goto LABEL_23;
}
v11 = StateName;
v12 = (*(unsigned __int64 *)&StateName >> 4) & 3;
if( v10 )
{
v13 = 0;
v8 = (a7 & 0x11) != 0;
if( (a7 & 0xFFFFFFEE) != 0 )
v8 |= 2u;
}
else
{
v13 = 1;
}
if( v10 )
{
v14 = (_EPROCESS *)*((_QWORD *)KeGetCurrentThread() + 23);
v11 = StateName;
}
else
{
v14 = (_EPROCESS *)PsInitialSystemProcess;
}
Process = v14;
v9 = ExpWnfResolveScopeInstance(
(struct _EX_RUNDOWN_REF **)&ScopeInstance,
(__int64)v14,
0i64,
(*(unsigned __int64 *)&StateName >> 6) & 0xF,
0i64);
if( v9 >= 0 )
{
v15 = ExpWnfLookupNameInstance(ScopeInstance, v11, &NameInstance);
v9 = v15;
if( v15 != -1073741772 || (_DWORD)v12 == 3 )
{
if( v15 < 0 )
goto LABEL_23;
if( !v13 )
{
v9 = ExpWnfCheckCallerAccess(NameInstance->StateNameInfo.SecurityDescriptor, v8);
if( v9 < 0 )
goto LABEL_23;
}
v16 = Process;
}
else
{
v9 = ExpWnfLookupPermanentName(v11, (_WNF_STATE_NAME_REGISTRATION **)&P);
if( v9 < 0 )
goto LABEL_23;
if( !v13 )
{
v9 = ExpWnfCheckCallerAccess(*((PVOID *)P + 2), v8);
if( v9 < 0 )
goto LABEL_23;
}
v16 = Process;
v9 = ExpWnfCreateNameInstance(ScopeInstance, v11, (_WNF_STATE_NAME_REGISTRATION *)P, Process, &NameInstance);
ExFreePoolWithTag(P, 0x20666E57u);
P = 0i64;
if( v9 < 0 )
goto LABEL_23;
}
v17 = NameInstance;
v9 = ExpWnfSubscribeNameInstance(
(__int64)NameInstance,
(unsigned __int64)v16,
a5,
a6,
a4,
a7,
a8,
a1,
a2,
(struct _EX_RUNDOWN_REF **)&v29,
&v23);
if( v9 >= 0 )
{
v18 = 0;
if( a4 != v17->CurrentChangeStamp && v17->StateData )
v18 = 1;
v19 = v18 | 8;
if( NameInstance->CurrentDeliveryCount )
v19 = v18;
if( !v23 )
{
if( NameInstance->DataSubscribersCount )
v19 |= 2u;
else
v19 |= 4u;
}
v20 = a7 & (unsigned int)v19;
if( (_DWORD)v20 )
ExpWnfNotifySubscription((INT64)NameInstance, v29, v20, a8 != 0);
}
}
}
LABEL_23:
if( v29 )
ExReleaseRundownProtection((PEX_RUNDOWN_REF)(v29 + 8));
if( NameInstance )
ExReleaseRundownProtection(&NameInstance->RunRef);
if( ScopeInstance )
ExReleaseRundownProtection(&ScopeInstance->RunRef);
if( P )
ExFreePoolWithTag(P, 0x20666E57u);
return(unsigned int)v9;
}Referenced by:
ExSubscribeWnfStateChange
NtSubscribeWnfStateChange