AlpcpReplyLegacySynchronousRequest
INT64 __fastcall AlpcpReplyLegacySynchronousRequest(
_ALPC_DISPATCH_CONTEXT *DispatchContext,
_PORT_MESSAGE *ReplyMessage,
INT64 ProbeMode){
_ALPC_PORT *PortObject;
int v5;
UINT64 *v6;
INT64 v7;
ULONG_PTR v8;
int v9;
_ALPC_PORT *v10;
__int64 v11;
_ALPC_PORT **v12;
INT64 *v13;
bool v14;
_ALPC_PORT **v15;
unsigned __int64 v16;
UINT64 v17;
ULONG_PTR v18;
__int64 v19;
ULONG_PTR v20;
unsigned int v21;
__int64 v22;
__int64 v23;
__int64 v24;
UINT64 v25;
int v27[8];
UINT64 *v28;
int v29;
_ALPC_PORT *v30;
UINT16 v31[8];
INT64 v32[2];
INT64 v33;
ULONG_PTR BugCheckParameter2;
PortObject = DispatchContext->PortObject;
*(_OWORD *)v31 = 0i64;
*(_OWORD *)v32 = 0i64;
v33 = 0i64;
BugCheckParameter2 = 0i64;
v30 = PortObject;
if( (_BYTE)ProbeMode )
{
AlpcpProbeAndCaptureMessageHeader(ReplyMessage, (_PORT_MESSAGE *)v31, 0i64);
v5 = AlpcpValidateMessage(v31, 1);
v29 = v5;
if( v5 < 0 )
return(unsigned int)v5;
if( v31[3] )
{
v5 = AlpcpValidateDataInformation(ReplyMessage, (OBJECT_NAME_INFORMATION **)v31, v6);
v29 = v5;
if( v5 < 0 )
return(unsigned int)v5;
}
}
else
{
*(_OWORD *)v31 = *(_OWORD *)ReplyMessage;
*(_OWORD *)v32 = *((_OWORD *)ReplyMessage + 1);
HIDWORD(v33) = HIDWORD(*((_QWORD *)ReplyMessage + 4));
LODWORD(v33) = 0;
v5 = AlpcpValidateMessage(v31, 1);
if( v5 < 0 )
return(unsigned int)v5;
}
v5 = AlpcpLookupMessage((INT64)PortObject, LODWORD(v32[1]), (unsigned int)v33, v7, &BugCheckParameter2);
v29 = v5;
if( v5 < 0 )
return(unsigned int)v5;
v8 = BugCheckParameter2;
v9 = *(_DWORD *)(BugCheckParameter2 + 40);
if( (v9 & 0x80u) != 0 )
{
AlpcpCancelMessage(PortObject, (_KALPC_MESSAGE *)BugCheckParameter2, 0x10000ui64);
return(unsigned int)-1073741769;
}
if( (v9 & 0x200) != 0 || !*(_QWORD *)(BugCheckParameter2 + 32) )
goto LABEL_49;
v10 = *(_ALPC_PORT **)(BugCheckParameter2 + 16);
if( v10 != PortObject )
{
if( (v9 & 7) == 0 )
{
v11 = *(_QWORD *)(BugCheckParameter2 + 24);
if( v11 )
{
v12 = *(_ALPC_PORT ***)(v11 + 16);
v13 = (INT64 *)(v12 - 2);
ExAcquirePushLockSharedEx((UINT64)(v12 - 2), 0i64);
if( ((*(_DWORD *)(v11 + 416) >> 1) & 3) == 1 || ((*(_DWORD *)(v11 + 416) >> 1) & 3) != 2 )
v14 = v12[2] == PortObject;
else
v14 = *v12 == PortObject || v12[1] == PortObject;
if( _InterlockedCompareExchange64(v13, 0i64, 17i64) != 17 )
ExfReleasePushLockShared(v13);
KeAbPostRelease(v13);
v8 = BugCheckParameter2;
goto LABEL_31;
}
LABEL_49:
AlpcpUnlockMessage(v8);
return(unsigned int)-1073741790;
}
if( (*((_BYTE *)PortObject + 416) & 6) != 6 )
goto LABEL_49;
v15 = (_ALPC_PORT **)*((_QWORD *)PortObject + 2);
if( !v15 || *v15 != v10 )
goto LABEL_49;
}
if( (*(_DWORD *)(BugCheckParameter2 + 40) & 7) != 3 || (v9 & 0x2000) != 0 )
goto LABEL_49;
v14 = 1;
LABEL_31:
if( !v14 )
goto LABEL_49;
v16 = AlpcpAvailableBufferSize(v8);
if( v17 > v16 )
{
v5 = AlpcpCaptureMessageData(v8, v17, (CHAR *)ReplyMessage + 40);
v29 = v5;
}
else
{
memmove((UINT8 *)(v8 + 280), (UINT8 *)ReplyMessage + 40, v17);
v5 = 0;
v29 = 0;
}
if( v5 >= 0 )
{
*(_DWORD *)(v8 + 40) |= 0x8000u;
_InterlockedOr(v27, 0);
v18 = BugCheckParameter2;
v19 = *(_QWORD *)(BugCheckParameter2 + 24);
AlpcpClearOwnerPortMessage(BugCheckParameter2);
AlpcpRemoveMessageFromPendingQueue((_KALPC_MESSAGE *)v18);
*(_DWORD *)(v18 + 240) = *(_DWORD *)v31;
*(_WORD *)(v18 + 244) = 2;
v20 = BugCheckParameter2;
*(_OWORD *)(BugCheckParameter2 + 248) = *(_OWORD *)((char *)KeGetCurrentThread() + 1144);
*(_DWORD *)(v8 + 40) |= 0x200u;
v21 = *(_DWORD *)(v8 + 40) & 0xFFFFFF87 | (4 * (*(_DWORD *)(v19 + 416) & 6));
*(_DWORD *)(v8 + 40) = v21;
if( ((v21 >> 3) & 0xF) == 1 )
{
v22 = *(_QWORD *)(v19 + 16);
ExAcquirePushLockSharedEx(v22 - 16, 0i64);
v23 = *(_QWORD *)(v22 + 8);
if( v23 )
*(_QWORD *)(v20 + 120) = *(_QWORD *)(v23 + 56);
else
*(_QWORD *)(v20 + 120) = 0i64;
if( _InterlockedCompareExchange64((volatile signed __int64 *)(v22 - 16), 0i64, 17i64) != 17 )
ExfReleasePushLockShared((INT64 *)(v22 - 16));
KeAbPostRelease((PVOID)(v22 - 16));
v20 = BugCheckParameter2;
}
else
{
*(_QWORD *)(v20 + 120) = *(_QWORD *)(v19 + 56);
}
v24 = *(_QWORD *)(v20 + 32);
*(_QWORD *)(v20 + 32) = 0i64;
--*(_WORD *)(v20 - 30);
*(_DWORD *)(v8 + 40) = *(_DWORD *)(v8 + 40) & 0xFFFF7EF8 | 0x105;
AlpcpSetOwnerPortMessage(v20, PortObject);
AlpcpUnlockMessage(v20);
if( (DispatchContext->Flags & 4) != 0 )
{
DispatchContext->TargetThread = (_ETHREAD *)v24;
}
else
{
LODWORD(v28) = 2;
KeReleaseSemaphoreEx((KSEMAPHORE *)(v24 + 1160), 1i64, 1i64, v25);
}
return(unsigned int)v29;
}
else
{
AlpcpUnlockMessage(v8);
}
return(unsigned int)v5;
}Referenced by:
NtReplyPort
NtReplyWaitReceivePortEx