AlpcpReplyLegacySynchronousRequest

INT64 __fastcall AlpcpReplyLegacySynchronousRequest(
        _ALPC_DISPATCH_CONTEXT *DispatchContext,
        _PORT_MESSAGE *ReplyMessage,
        INT64 ProbeMode){
  _ALPC_PORT *PortObject; 
  int v5; 
  UINT64 *v6; 
  INT64 v7; 
  ULONG_PTR v8; 
  int v9; 
  _ALPC_PORT *v10; 
  __int64 v11; 
  _ALPC_PORT **v12; 
  INT64 *v13; 
  bool v14; 
  _ALPC_PORT **v15; 
  unsigned __int64 v16; 
  UINT64 v17; 
  ULONG_PTR v18; 
  __int64 v19; 
  ULONG_PTR v20; 
  unsigned int v21; 
  __int64 v22; 
  __int64 v23; 
  __int64 v24; 
  UINT64 v25; 
  int v27[8]; 
  UINT64 *v28; 
  int v29; 
  _ALPC_PORT *v30; 
  UINT16 v31[8]; 
  INT64 v32[2]; 
  INT64 v33; 
  ULONG_PTR BugCheckParameter2; 
  PortObject = DispatchContext->PortObject;
  *(_OWORD *)v31 = 0i64;
  *(_OWORD *)v32 = 0i64;
  v33 = 0i64;
  BugCheckParameter2 = 0i64;
  v30 = PortObject;
  if( (_BYTE)ProbeMode )
  {
    AlpcpProbeAndCaptureMessageHeader(ReplyMessage, (_PORT_MESSAGE *)v31, 0i64);
    v5 = AlpcpValidateMessage(v31, 1);
    v29 = v5;
    if( v5 < 0 )
      return(unsigned int)v5;
    if( v31[3] )
    {
      v5 = AlpcpValidateDataInformation(ReplyMessage, (OBJECT_NAME_INFORMATION **)v31, v6);
      v29 = v5;
      if( v5 < 0 )
        return(unsigned int)v5;
    }
  }
  else
  {
    *(_OWORD *)v31 = *(_OWORD *)ReplyMessage;
    *(_OWORD *)v32 = *((_OWORD *)ReplyMessage + 1);
    HIDWORD(v33) = HIDWORD(*((_QWORD *)ReplyMessage + 4));
    LODWORD(v33) = 0;
    v5 = AlpcpValidateMessage(v31, 1);
    if( v5 < 0 )
      return(unsigned int)v5;
  }
  v5 = AlpcpLookupMessage((INT64)PortObject, LODWORD(v32[1]), (unsigned int)v33, v7, &BugCheckParameter2);
  v29 = v5;
  if( v5 < 0 )
    return(unsigned int)v5;
  v8 = BugCheckParameter2;
  v9 = *(_DWORD *)(BugCheckParameter2 + 40);
  if( (v9 & 0x80u) != 0 )
  {
    AlpcpCancelMessage(PortObject, (_KALPC_MESSAGE *)BugCheckParameter2, 0x10000ui64);
    return(unsigned int)-1073741769;
  }
  if( (v9 & 0x200) != 0 || !*(_QWORD *)(BugCheckParameter2 + 32) )
    goto LABEL_49;
  v10 = *(_ALPC_PORT **)(BugCheckParameter2 + 16);
  if( v10 != PortObject )
  {
    if( (v9 & 7) == 0 )
    {
      v11 = *(_QWORD *)(BugCheckParameter2 + 24);
      if( v11 )
      {
        v12 = *(_ALPC_PORT ***)(v11 + 16);
        v13 = (INT64 *)(v12 - 2);
        ExAcquirePushLockSharedEx((UINT64)(v12 - 2), 0i64);
        if( ((*(_DWORD *)(v11 + 416) >> 1) & 3) == 1 || ((*(_DWORD *)(v11 + 416) >> 1) & 3) != 2 )
          v14 = v12[2] == PortObject;
        else
          v14 = *v12 == PortObject || v12[1] == PortObject;
        if( _InterlockedCompareExchange64(v13, 0i64, 17i64) != 17 )
          ExfReleasePushLockShared(v13);
        KeAbPostRelease(v13);
        v8 = BugCheckParameter2;
        goto LABEL_31;
      }
LABEL_49:
      AlpcpUnlockMessage(v8);
      return(unsigned int)-1073741790;
    }
    if( (*((_BYTE *)PortObject + 416) & 6) != 6 )
      goto LABEL_49;
    v15 = (_ALPC_PORT **)*((_QWORD *)PortObject + 2);
    if( !v15 || *v15 != v10 )
      goto LABEL_49;
  }
  if( (*(_DWORD *)(BugCheckParameter2 + 40) & 7) != 3 || (v9 & 0x2000) != 0 )
    goto LABEL_49;
  v14 = 1;
LABEL_31:
  if( !v14 )
    goto LABEL_49;
  v16 = AlpcpAvailableBufferSize(v8);
  if( v17 > v16 )
  {
    v5 = AlpcpCaptureMessageData(v8, v17, (CHAR *)ReplyMessage + 40);
    v29 = v5;
  }
  else
  {
    memmove((UINT8 *)(v8 + 280), (UINT8 *)ReplyMessage + 40, v17);
    v5 = 0;
    v29 = 0;
  }
  if( v5 >= 0 )
  {
    *(_DWORD *)(v8 + 40) |= 0x8000u;
    _InterlockedOr(v27, 0);
    v18 = BugCheckParameter2;
    v19 = *(_QWORD *)(BugCheckParameter2 + 24);
    AlpcpClearOwnerPortMessage(BugCheckParameter2);
    AlpcpRemoveMessageFromPendingQueue((_KALPC_MESSAGE *)v18);
    *(_DWORD *)(v18 + 240) = *(_DWORD *)v31;
    *(_WORD *)(v18 + 244) = 2;
    v20 = BugCheckParameter2;
    *(_OWORD *)(BugCheckParameter2 + 248) = *(_OWORD *)((char *)KeGetCurrentThread() + 1144);
    *(_DWORD *)(v8 + 40) |= 0x200u;
    v21 = *(_DWORD *)(v8 + 40) & 0xFFFFFF87 | (4 * (*(_DWORD *)(v19 + 416) & 6));
    *(_DWORD *)(v8 + 40) = v21;
    if( ((v21 >> 3) & 0xF) == 1 )
    {
      v22 = *(_QWORD *)(v19 + 16);
      ExAcquirePushLockSharedEx(v22 - 16, 0i64);
      v23 = *(_QWORD *)(v22 + 8);
      if( v23 )
        *(_QWORD *)(v20 + 120) = *(_QWORD *)(v23 + 56);
      else
        *(_QWORD *)(v20 + 120) = 0i64;
      if( _InterlockedCompareExchange64((volatile signed __int64 *)(v22 - 16), 0i64, 17i64) != 17 )
        ExfReleasePushLockShared((INT64 *)(v22 - 16));
      KeAbPostRelease((PVOID)(v22 - 16));
      v20 = BugCheckParameter2;
    }
    else
    {
      *(_QWORD *)(v20 + 120) = *(_QWORD *)(v19 + 56);
    }
    v24 = *(_QWORD *)(v20 + 32);
    *(_QWORD *)(v20 + 32) = 0i64;
    --*(_WORD *)(v20 - 30);
    *(_DWORD *)(v8 + 40) = *(_DWORD *)(v8 + 40) & 0xFFFF7EF8 | 0x105;
    AlpcpSetOwnerPortMessage(v20, PortObject);
    AlpcpUnlockMessage(v20);
    if( (DispatchContext->Flags & 4) != 0 )
    {
      DispatchContext->TargetThread = (_ETHREAD *)v24;
    }
    else
    {
      LODWORD(v28) = 2;
      KeReleaseSemaphoreEx((KSEMAPHORE *)(v24 + 1160), 1i64, 1i64, v25);
    }
    return(unsigned int)v29;
  }
  else
  {
    AlpcpUnlockMessage(v8);
  }
  return(unsigned int)v5;
}

Referenced by:

NtReplyPort
NtReplyWaitReceivePortEx