FsRtlGetFileSize
NTSTATUS __stdcall FsRtlGetFileSize(PFILE_OBJECT FileObject, PLARGE_INTEGER FileSize){
__int64 v4;
_DEVICE_OBJECT *RelatedDeviceObject;
__int64 v6;
unsigned __int8(__fastcall *v7)(PFILE_OBJECT, __int64, __int128 *, __int128 *, _DEVICE_OBJECT *);
NTSTATUS result;
_IRP *Irp;
UINT8 v10;
__int64 v11;
UINT8 v12;
NTSTATUS v13;
NTSTATUS v14;
__int128 v15;
struct _KEVENT Event;
__int128 v17;
__int64 v18;
v15 = 0i64;
v18 = 0i64;
v17 = 0i64;
RelatedDeviceObject = IoGetRelatedDeviceObject(FileObject);
v6 = *(_QWORD *)(*((_QWORD *)RelatedDeviceObject + 1) + 80i64);
if( !v6
|| (v7 = *(unsigned __int8(__fastcall **)(PFILE_OBJECT, __int64, __int128 *, __int128 *, _DEVICE_OBJECT *))(v6 + 40)) == 0i64
|| (LOBYTE(v4) = 1, !v7(FileObject, v4, &v17, &v15, RelatedDeviceObject)) )
{
memset(&Event, 0, sizeof(Event));
KeInitializeEvent(&Event, NotificationEvent, 0);
Irp = IoAllocateIrpEx(RelatedDeviceObject, *((_BYTE *)RelatedDeviceObject + 76), 0);
if( !Irp )
return -1073741670;
v10 = IoSetThreadHardErrorMode(0);
v11 = *((_QWORD *)Irp + 23);
v12 = v10;
*((_DWORD *)Irp + 4) = 66;
*((_QWORD *)Irp + 9) = &v15;
*((_QWORD *)Irp + 10) = &Event;
*((_BYTE *)Irp + 64) = 0;
*((_QWORD *)Irp + 24) = FileObject;
*((_QWORD *)Irp + 19) = KeGetCurrentThread();
*((_QWORD *)Irp + 3) = &v17;
*(_BYTE *)(v11 - 72) = 5;
*(_QWORD *)(v11 - 24) = FileObject;
*(_QWORD *)(v11 - 32) = RelatedDeviceObject;
*(_DWORD *)(v11 - 64) = 24;
*(_DWORD *)(v11 - 56) = 5;
v13 = IofCallDriver(RelatedDeviceObject, Irp);
if( v13 == 259 )
KeWaitForSingleObject(&Event, Executive, 0, 0, 0i64);
v14 = v15;
if( v13 < 0 )
v14 = v13;
LODWORD(v15) = v14;
IoSetThreadHardErrorMode(v12);
}
result = v15;
if( (int)v15 >= 0 )
{
if( BYTE5(v18) )
return -1073741638;
else
*FileSize = *(union _LARGE_INTEGER *)((char *)&v17 + 8);
}
return result;
}Referenced by:
ExpQueryCodeIntegrityCertificateInfo
ExpQueryElamCertInfo
FsRtlCreateSectionForDataScan
MiCreateDataFileMap
MiCreateImageFileMap
MmExtendSection