NtCreatePrivateNamespace
NTSTATUS __stdcall NtCreatePrivateNamespace(
PVOID *NamespaceHandle,
UINT64 DesiredAccess,
OBJECT_ATTRIBUTES *ObjectAttributes,
PVOID BoundaryDescriptor){
unsigned int v5;
char v7;
__int64 v8;
NTSTATUS result;
PVOID v10;
NTSTATUS v11;
int v12;
_QWORD *v13;
unsigned __int64 v14;
UINT64 v15;
__int64 v16;
int inserted;
__int64 *CurrentServerSiloGlobals;
_ETHREAD *CurrentThread;
_QWORD *v20;
__int64 v21;
_QWORD *v22;
__int64 v23;
_QWORD *v24;
__int64 Flags;
UINT64 Flagsa;
PVOID Object;
PVOID P;
PVOID Handle;
v5 = DesiredAccess;
Object = 0i64;
Handle = 0i64;
P = 0i64;
v7 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v7 )
{
v8 = 0x7FFFFFFF0000i64;
if( (unsigned __int64)NamespaceHandle < 0x7FFFFFFF0000i64 )
v8 = (__int64)NamespaceHandle;
*(_QWORD *)v8 = *(_QWORD *)v8;
}
result = ObpCaptureBoundaryDescriptor((__m128i *)BoundaryDescriptor, (CHAR **)&P);
if( result >= 0 )
{
v10 = P;
v11 = ObpVerifyCreatorAccessCheck((_DWORD *)P + 12);
if( v11 >= 0 )
{
if( (unsigned __int64)(unsigned int)(*((_DWORD *)v10 + 6) + 392) < *((_QWORD *)v10 + 3) )
{
v11 = -1073741811;
}
else
{
v12 = ObCreateObjectEx(
v7,
ObpDirectoryObjectType,
(__int64)ObjectAttributes,
v7,
Flags,
*((_DWORD *)v10 + 6) + 392,
0,
0,
&Object,
0i64);
if( v12 >= 0 )
{
v13 = Object;
memset((INT64)Object, 0i64);
v14 = ((unsigned __int64)v13 + 351) & 0xFFFFFFFFFFFFFFF8ui64;
*(_QWORD *)(v14 + 8) = v14;
*(_QWORD *)v14 = v14;
v15 = *((_QWORD *)v10 + 3);
*(_QWORD *)(v14 + 24) = v15;
*(_QWORD *)(v14 + 16) = 0i64;
*(_BYTE *)(v14 + 40) = *((_BYTE *)v10 + 40);
memmove((UINT8 *)(v14 + 48), (UINT8 *)v10 + 48, v15);
ExFreePoolWithTag(v10, 0x534E624Fu);
v13[37] = 0i64;
*((_DWORD *)v13 + 85) = -1;
*((_DWORD *)v13 + 84) = 1;
if( (*((_BYTE *)v13 - 22) & 2) != 0 )
v16 = (__int64)v13 - *((unsigned __int8 *)ObpInfoMaskToOffset + (*((_BYTE *)v13 - 22) & 3)) - 48;
else
v16 = 0i64;
if( v16 )
{
inserted = -1073741773;
}
else
{
inserted = ObpRegisterPrivateNamespace(((unsigned __int64)v13 + 351) & 0xFFFFFFFFFFFFFFF8ui64);
if( inserted >= 0 )
{
ObfReferenceObject(v13);
LODWORD(Flagsa) = 0;
inserted = ObInsertObjectEx(v13, 0i64, v5, 0i64, Flagsa, 0i64, &Handle);
CurrentServerSiloGlobals = PsGetCurrentServerSiloGlobals();
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquirePushLockExclusiveEx((UINT64)(CurrentServerSiloGlobals + 90), 0i64);
if( inserted < 0 )
{
v21 = *(_QWORD *)v14;
v22 = *(_QWORD **)(v14 + 8);
if( *(_QWORD *)(*(_QWORD *)v14 + 8i64) == v14 && *v22 == v14 )
{
*v22 = v21;
*(_QWORD *)(v21 + 8) = v22;
LABEL_32:
--*((_DWORD *)CurrentServerSiloGlobals + 182);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
LABEL_16:
ExReleasePushLockEx((UINT64)(CurrentServerSiloGlobals + 90), 0i64);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( inserted >= 0 )
*NamespaceHandle = Handle;
return inserted;
}
}
else
{
if( (v13[42] & 2) == 0 )
{
v20 = Object;
*(_QWORD *)(v14 + 16) = Object;
v20[40] = v14;
goto LABEL_16;
}
v23 = *(_QWORD *)v14;
v24 = *(_QWORD **)(v14 + 8);
if( *(_QWORD *)(*(_QWORD *)v14 + 8i64) == v14 && *v24 == v14 )
{
*v24 = v23;
*(_QWORD *)(v23 + 8) = v24;
goto LABEL_32;
}
}
__fastfail(3u);
}
}
HalPutDmaAdapter((PADAPTER_OBJECT)v13);
return inserted;
}
v11 = v12;
}
}
ExFreePoolWithTag(v10, 0x534E624Fu);
return v11;
}
return result;
}Referenced by:
No references.