IopOpenLinkOrRenameTarget
NTSTATUS __stdcall IopOpenLinkOrRenameTarget(
PVOID *TargetHandle,
_IRP *Irp,
PVOID RenameBuffer,
_FILE_OBJECT *FileObject){
bool v4;
ACCESS_MASK v8;
HANDLE v10;
NTSTATUS result;
void *v12;
__int64 v13;
char v14;
char v15;
void **FileObjectExtension;
_FILE_OBJECT *v17;
VOID **v18;
UINT64 v19;
int v20;
_FILE_OBJECT *v21;
_DEVICE_OBJECT *RelatedDeviceObject;
UINT64 FileAttributes;
UINT64 ShareAccess;
UINT64 Disposition;
UINT64 CreateOptions;
UINT64 EaLength;
UINT64 Options;
void *FileHandle;
HANDLE Handle;
PVOID Object;
__int16 v32[2];
int v33;
__int64 v34;
IO_DRIVER_CREATE_CONTEXT DriverContext;
struct _OBJECT_HANDLE_INFORMATION HandleInformation;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
struct _IO_STATUS_BLOCK IoStatusBlock;
FILE_BASIC_INFORMATION BasicInformationBuffer;
FileHandle = 0i64;
v4 = (FileObject->Flags & 0x800) == 0;
Handle = 0i64;
*(&ObjectAttributes.Length + 1) = 0;
v8 = 2;
*(&ObjectAttributes.Attributes + 1) = 0;
v33 = 0;
IoStatusBlock = 0i64;
v10 = 0i64;
HandleInformation = 0i64;
memset(&BasicInformationBuffer, 0, sizeof(BasicInformationBuffer));
memset(&DriverContext.Size + 1, 0, 22);
if( v4 )
{
result = IopGetBasicInformationFile(FileObject, &BasicInformationBuffer);
if( result < 0 )
return result;
if( (BasicInformationBuffer.FileAttributes & 0x10) != 0 )
v8 = 4;
}
v12 = (void *)*((_QWORD *)RenameBuffer + 1);
if( v12 )
{
if( *((_BYTE *)KeGetCurrentThread() + 562) == 1 )
{
result = IoConvertFileHandleToKernelHandle(v12, 1, 0i64, 0, &Handle);
if( result < 0 )
return result;
v10 = Handle;
}
else
{
v10 = (HANDLE)*((_QWORD *)RenameBuffer + 1);
Handle = v10;
}
}
v13 = *((_QWORD *)Irp + 23);
v32[0] = *((_WORD *)RenameBuffer + 8);
v32[1] = v32[0];
v34 = (__int64)RenameBuffer + 20;
v14 = ~(unsigned __int8)(FileObject->Flags >> 11);
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = v10;
v15 = ~*(_BYTE *)(v13 - 70);
DriverContext.SiloContext = (_EJOB *)1;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)v32;
ObjectAttributes.Attributes = v14 & 0x40 | ((v15 & 1) << 10) | 0x200;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
DriverContext.Size = 40;
memset(&DriverContext.Size + 1, 0, 22);
FileObjectExtension = (void **)IopGetFileObjectExtension(FileObject, FoExtTypeInternal, 0i64);
if( FileObjectExtension )
DriverContext.DeviceObjectHint = *FileObjectExtension;
DriverContext.TxnParameters = (_TXN_PARAMETER_BLOCK *)IopGetFileObjectExtension(v17, FoExtTypeTransactionParams, v18);
v19 = v8;
LODWORD(v19) = v8 | 0x100000;
LODWORD(Options) = ((*(_BYTE *)(v13 - 70) & 1) == 0) | 0x104;
LODWORD(EaLength) = 0;
LODWORD(CreateOptions) = 0x4000;
LODWORD(Disposition) = 1;
LODWORD(ShareAccess) = 3;
LODWORD(FileAttributes) = 0;
v20 = IoCreateFileEx(
&FileHandle,
v19,
&ObjectAttributes,
&IoStatusBlock,
0i64,
FileAttributes,
ShareAccess,
Disposition,
CreateOptions,
0i64,
EaLength,
CreateFileTypeNone,
0i64,
Options,
&DriverContext);
if( v20 >= 0 )
{
Object = 0i64;
v20 = ObReferenceObjectByHandle(FileHandle, v8, (POBJECT_TYPE)IoFileObjectType, 0, &Object, &HandleInformation);
if( v20 < 0 )
{
ObCloseHandle(FileHandle, 0);
}
else
{
v21 = (_FILE_OBJECT *)Object;
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
RelatedDeviceObject = IoGetRelatedDeviceObject(FileObject);
if( IoGetRelatedDeviceObject(v21) == RelatedDeviceObject )
{
*(_QWORD *)(v13 - 48) = v21;
v20 = 0;
*TargetHandle = FileHandle;
}
else
{
ObCloseHandle(FileHandle, 0);
v20 = -1073741612;
}
}
}
if( v10 )
{
if( *((_BYTE *)KeGetCurrentThread() + 562) == 1 )
ObCloseHandle(Handle, 0);
}
return v20;
}Referenced by:
IoSetInformation
NtSetInformationFile