LpcpCopyRequestData

NTSTATUS __fastcall LpcpCopyRequestData(
        CHAR a1,
        VOID *a2,
        UINT64 a3,
        UINT64 a4,
        CHAR *Address,
        UINT64 Length,
        UINT64 *a7){
  unsigned __int64 v7; 
  struct _OBJECT_HANDLE_INFORMATION *HandleInformation; 
  KPROCESSOR_MODE v12; 
  UINT64 v13; 
  UINT64 *v14; 
  UINT64 *v15; 
  NTSTATUS result; 
  INT64 v17; 
  NTSTATUS v18; 
  __int64 v19; 
  unsigned __int64 v20; 
  __int64 v21; 
  __int64 v22; 
  unsigned __int64 v23; 
  unsigned __int64 v24; 
  _ETHREAD *CurrentThread; 
  _HHIVE *v26; 
  _LIST_ENTRY *v27; 
  CHAR *v28; 
  ULONG_PTR BugCheckParameter2; 
  PVOID PrimaryToken; 
  __int64 v31; 
  INT64 ControlSet[2]; 
  __int128 v33; 
  INT64 v34[2]; 
  INT64 v35; 
  v7 = (unsigned int)a4;
  HandleInformation = 0i64;
  BugCheckParameter2 = 0i64;
  v33 = 0i64;
  *(_OWORD *)v34 = 0i64;
  v35 = 0i64;
  *(_OWORD *)ControlSet = 0i64;
  v31 = 0i64;
  v12 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v12 )
  {
    v13 = Length;
    if( a1 )
    {
      if( Length && ((unsigned __int64)&Address[Length] > 0x7FFFFFFF0000i64 || &Address[Length] < Address) )
        MEMORY[0x7FFFFFFF0000] = 0;
    }
    else
    {
      ProbeForWrite(Address, Length, 1ui64);
    }
    AlpcpProbeAndCaptureMessageHeader((_PORT_MESSAGE *)a3, (_PORT_MESSAGE *)&v33, 0i64);
    v15 = a7;
    if( a7 )
    {
      if( a7 < v14 )
        v14 = a7;
      *v14 = *v14;
    }
  }
  else
  {
    v33 = *(_OWORD *)a3;
    *(_OWORD *)v34 = *(_OWORD *)(a3 + 16);
    v35 = *(_QWORD *)(a3 + 32);
    v15 = a7;
    v13 = Length;
  }
  if( !WORD3(v33) )
    return -1073741811;
  PrimaryToken = HandleInformation;
  result = ObReferenceObjectByHandle(a2, 1u, AlpcPortObjectType, v12, &PrimaryToken, HandleInformation);
  if( result >= 0 )
  {
    v18 = AlpcpLookupMessage((INT64)PrimaryToken, LODWORD(v34[1]), (unsigned int)v35, v17, &BugCheckParameter2);
    if( v18 < 0 )
    {
LABEL_35:
      PsDereferencePrimaryToken(PrimaryToken);
      return v18;
    }
    v19 = *(_QWORD *)(BugCheckParameter2 + 32);
    if( v19 )
    {
      v18 = -1073741811;
      if( *(_WORD *)(BugCheckParameter2 + 246) )
      {
        v20 = AlpcpAvailableBufferSize(BugCheckParameter2);
        v24 = *(unsigned __int16 *)(v21 + 242);
        if( v20 <= v24 )
          v24 = v20;
        if( v23 >= v24 || v7 >= (v24 - v23) >> 4 )
          goto LABEL_34;
        if( *(_DWORD *)(v21 + v22 + 240) > (unsigned int)v7 )
        {
          *(_OWORD *)ControlSet = *(_OWORD *)(v21 + v22 + 16 * v7 + 248);
          v18 = (unsigned int)_mm_cvtsi128_si32(_mm_srli_si128(*(__m128i *)ControlSet, 8)) < v13 ? 0xC000000D : 0;
        }
      }
      if( v18 >= 0 )
      {
        CurrentThread = (_ETHREAD *)KeGetCurrentThread();
        if( a1 )
        {
          v26 = (_HHIVE *)*((_QWORD *)CurrentThread + 23);
          v27 = *(_LIST_ENTRY **)(v19 + 544);
          v28 = Address;
        }
        else
        {
          v27 = (_LIST_ENTRY *)*((_QWORD *)CurrentThread + 23);
          v28 = (CHAR *)ControlSet[0];
          v26 = *(_HHIVE **)(v19 + 544);
        }
        v18 = MmCopyVirtualMemory(v26, (INT64)v28, v27);
        if( v18 >= 0 )
        {
          if( v15 )
            *v15 = v31;
        }
      }
    }
    else
    {
      v18 = -1073741790;
    }
LABEL_34:
    AlpcpUnlockMessage(BugCheckParameter2);
    goto LABEL_35;
  }
  return result;
}

Referenced by:

NtReadRequestData
NtWriteRequestData