MiGetNextSession
NTSTATUS __stdcall MiGetNextSession(PVOID OpaqueSession, UINT64 Next){
INT64 ThreadServerSilo;
NTSTATUS v4;
__int64 v5;
__int64 *i;
_EPROCESS *v8;
struct _KLOCK_QUEUE_HANDLE LockHandle;
memset(&LockHandle, 0, sizeof(LockHandle));
if( KeIsExecutingInArbitraryThreadContext() )
ThreadServerSilo = 0i64;
else
ThreadServerSilo = PsGetThreadServerSilo((INT64)KeGetCurrentThread());
v4 = 0;
if( OpaqueSession )
v5 = *((_QWORD *)OpaqueSession + 171);
else
v5 = 0i64;
KeAcquireInStackQueuedSpinLock(&WorkerRoutine, &LockHandle);
if( v5 )
{
LABEL_17:
for( i = *(__int64 **)(v5 + 128); i != &qword_140C4EC40; i = (__int64 *)*i )
{
v8 = MiSelectSessionAttachProcess((_MM_SESSION_SPACE *)(i - 16));
v4 = (int)v8;
if( v8 )
{
if( !ThreadServerSilo || i[115] == ThreadServerSilo )
break;
HalPutDmaAdapter((PADAPTER_OBJECT)v8);
v4 = 0;
}
}
KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
__writecr8(LockHandle.OldIrql);
if( OpaqueSession )
HalPutDmaAdapter((PADAPTER_OBJECT)OpaqueSession);
return v4;
}
else
{
i = (__int64 *)qword_140C4EC40;
if( qword_140C4EC40 )
goto LABEL_17;
KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
__writecr8(LockHandle.OldIrql);
return 0;
}
}Referenced by:
ExpHpCompactSessionPools
MiEmptyAccessLogs
MmGetNextSession
PsQueryCpuQuotaInformation