IopCreateArcNamesCd
HANDLE __stdcall IopCreateArcNamesCd(PVOID Address, SIZE_T Size, ULONG ProbeMode){
WCHAR **v3;
int v4;
ULONG CdRomCount;
int ConfigurationInformation;
WCHAR *v8;
char v9;
const WCHAR *v10;
WCHAR *v11;
__int64 v12;
unsigned __int8 *v13;
__int64 v14;
WCHAR *v15;
int v16;
int v17;
CHAR *Pool_1;
WCHAR v20;
ULONG v21;
int v22;
bool v23;
int v24;
__int64 v25;
NTSTATUS DeviceObjectPointer;
_DEVICE_OBJECT *v27;
_IRP *v28;
INT8 v29;
INT8 v30;
IRP *v31;
NTSTATUS Status;
unsigned __int64 v33;
__m128i v34;
__m128i v35;
__m128i v36;
__m128i v37;
int v38;
INT8 v39;
PKEVENT Event;
UINT64 Object;
_KEVENT Object_8;
WCHAR *P[3];
PDEVICE_OBJECT DeviceObject;
PFILE_OBJECT FileObject;
struct _STRING DestinationString;
struct _IO_STATUS_BLOCK IoStatusBlock;
union _LARGE_INTEGER StartingOffset[2];
PVOID v49;
struct _UNICODE_STRING SymbolicLinkName;
STRING v51;
union _LARGE_INTEGER OutputBuffer;
int v53;
char pszDest[128];
char SourceString[128];
PVOID ReturnAddress;
v3 = (WCHAR **)*((_QWORD *)Address + 29);
v49 = Address;
v4 = 0;
DestinationString = 0i64;
DeviceObject = 0i64;
FileObject = 0i64;
v51 = 0i64;
SymbolicLinkName = 0i64;
LODWORD(Object) = 0;
IoStatusBlock = 0i64;
memset(&Object_8, 0, sizeof(Object_8));
memset(P, 0, sizeof(P));
CdRomCount = IoGetConfigurationInformation()->CdRomCount;
OutputBuffer.QuadPart = 0i64;
v53 = 0;
*(GUID *)&StartingOffset[0].LowPart = GUID_DEVINTERFACE_CDROM;
ConfigurationInformation = IopFetchConfigurationInformation(P, (GUID *)StartingOffset, CdRomCount, &Object);
v8 = P[0];
v9 = 0;
v10 = P[0];
if( ConfigurationInformation < 0 )
v9 = 1;
v11 = *v3;
if( *v3 == (WCHAR *)v3 )
goto LABEL_11;
v12 = *((_QWORD *)Address + 23);
do
{
v13 = (unsigned __int8 *)*((_QWORD *)v11 + 3);
v14 = v12 - (_QWORD)v13;
P[0] = v11;
v15 = v11;
do
{
v16 = v13[v14];
v17 = *v13 - v16;
if( v17 )
break;
++v13;
}
while( v16 );
if( !v17 )
break;
v11 = *(WCHAR **)v11;
v15 = 0i64;
P[0] = 0i64;
}
while( v11 != (WCHAR *)v3 );
if( !v15 )
goto LABEL_11;
Pool_1 = IopVerifierExAllocatePool_1(NonPagedPoolNxCacheAligned, 0x800ui64);
if( !Pool_1 )
goto LABEL_11;
v21 = Object;
v22 = 0;
v23 = (unsigned int)Object <= CdRomCount;
LODWORD(Object) = 0;
if( !v23 )
CdRomCount = v21;
if( v9 && !v21 )
CdRomCount += 5;
v24 = 0;
if( !CdRomCount )
goto LABEL_54;
while( 1 )
{
if( v10 && *v10 )
{
RtlInitUnicodeString((PUNICODE_STRING)&P[1], v10, v20);
v25 = -1i64;
do
++v25;
while( v10[v25] );
v10 += v25 + 1;
DeviceObjectPointer = IoGetDeviceObjectPointer((UNICODE_STRING *)&P[1], 0x80ui64, &FileObject, &DeviceObject);
if( DeviceObjectPointer < 0 )
goto LABEL_45;
v27 = DeviceObject;
LODWORD(Event) = 12;
v28 = IopBuildDeviceIoControlRequest(
0x2D1080ui64,
DeviceObject,
0i64,
0i64,
&OutputBuffer,
(UINT64)Event,
0,
&Object_8,
&IoStatusBlock,
ReturnAddress);
if( !v28 )
goto LABEL_57;
LOWORD(Object_8.Header.Lock) = 0;
Object_8.Header.WaitListHead.Blink = &Object_8.Header.WaitListHead;
Object_8.Header.Size = 6;
Object_8.Header.WaitListHead.Flink = &Object_8.Header.WaitListHead;
Object_8.Header.SignalState = 0;
DeviceObjectPointer = IofCallDriver(v27, v28);
if( DeviceObjectPointer == 259 )
{
KeWaitForSingleObject(&Object_8, Executive, 0, 0, 0i64);
DeviceObjectPointer = IoStatusBlock.Status;
}
if( DeviceObjectPointer < 0
|| (RtlStringCchPrintfA(pszDest, 0x80ui64, (INT8 *)"\\Device\\CdRom%d"),
RtlInitAnsiString(&DestinationString, pszDest, v29),
DeviceObjectPointer = RtlAnsiStringToUnicodeString((UNICODE_STRING *)&P[1], &DestinationString, 1u),
DeviceObjectPointer < 0) )
{
LABEL_45:
if( v8 )
ExFreePoolWithTag(v8, 0);
goto LABEL_48;
}
v24 = 0;
}
else
{
RtlStringCchPrintfA(pszDest, 0x80ui64, (INT8 *)"\\Device\\CdRom%d");
LODWORD(Object) = v22 + 1;
RtlInitAnsiString(&DestinationString, pszDest, v30);
if( RtlAnsiStringToUnicodeString((UNICODE_STRING *)&P[1], &DestinationString, 1u) < 0 )
{
LABEL_57:
if( v8 )
ExFreePoolWithTag(v8, 0);
DeviceObjectPointer = -1073741670;
LABEL_48:
ExFreePoolWithTag(Pool_1, 0);
return(HANDLE)(unsigned int)DeviceObjectPointer;
}
if( IoGetDeviceObjectPointer((UNICODE_STRING *)&P[1], 0x80ui64, &FileObject, &DeviceObject) < 0 )
goto LABEL_53;
v27 = DeviceObject;
}
StartingOffset[0].QuadPart = 0x8000i64;
v31 = IoBuildSynchronousFsdRequest(3u, v27, Pool_1, 0x800u, StartingOffset, &Object_8, &IoStatusBlock);
if( v31 )
{
LOWORD(Object_8.Header.Lock) = 0;
Object_8.Header.SignalState = 0;
Object_8.Header.WaitListHead.Blink = &Object_8.Header.WaitListHead;
Object_8.Header.WaitListHead.Flink = &Object_8.Header.WaitListHead;
Object_8.Header.Size = 6;
Status = IofCallDriver(v27, v31);
if( Status == 259 )
{
KeWaitForSingleObject(&Object_8, Executive, 0, 0, 0i64);
Status = IoStatusBlock.Status;
}
if( Status >= 0 )
{
v33 = 0i64;
v34 = 0i64;
do
{
v35 = _mm_loadu_si128((const __m128i *)&Pool_1[4 * v33]);
v33 += 4i64;
v36 = _mm_add_epi32(v35, v34);
v34 = v36;
}
while( v33 < 0x200 );
v37 = _mm_add_epi32(v36, _mm_srli_si128(v36, 8));
v24 = _mm_cvtsi128_si32(_mm_add_epi32(v37, _mm_srli_si128(v37, 4)));
}
}
ObfDereferenceObjectWithTag(FileObject, 0x746C6644ui64);
v38 = v24 + *((_DWORD *)P[0] + 8);
v24 = 0;
if( !v38 )
break;
RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
if( ++v4 >= CdRomCount )
goto LABEL_54;
v22 = Object;
}
RtlStringCchPrintfA(SourceString, 0x80ui64, (INT8 *)"\\ArcName\\%s");
RtlInitAnsiString(&v51, SourceString, v39);
DeviceObjectPointer = RtlAnsiStringToUnicodeString(&SymbolicLinkName, &v51, 1u);
if( DeviceObjectPointer < 0 )
{
ExFreePoolWithTag(Pool_1, 0);
if( v8 )
ExFreePoolWithTag(v8, 0);
RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
return(HANDLE)(unsigned int)DeviceObjectPointer;
}
IoCreateSymbolicLink(&SymbolicLinkName, (_UNICODE_STRING *)&P[1]);
RtlFreeAnsiString(&SymbolicLinkName);
LABEL_53:
RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
LABEL_54:
ExFreePoolWithTag(Pool_1, 0);
LABEL_11:
if( v8 )
ExFreePoolWithTag(v8, 0);
return 0i64;
}Referenced by:
IopCreateArcNames