ObpFreeObject

VOID __fastcall ObpFreeObject(_OBJECT_HEADER *ObjectHeader){
  __int64 InfoMask; 
  unsigned __int8 *p_TypeIndex; 
  PVOID *v4; 
  char *v5; 
  unsigned int *v6; 
  char v7; 
  __int64 v8; 
  _OBJECT_CREATE_INFORMATION *ObjectCreateInfo; 
  volatile INT32 *v10; 
  unsigned int v11; 
  unsigned int v12; 
  _OBJECT_CREATE_INFORMATION *v13; 
  ULONG v14; 
  struct _KPRCB *CurrentPrcb; 
  __int64 v16; 
  void *v17; 
  _ETHREAD *CurrentThread; 
  __int64 v19; 
  unsigned __int8 **v20; 
  int v21; 
  char *v22; 
  _OBJECT_CREATE_INFORMATION *v23; 
  __int64 v24; 
  INT64 v25; 
  __int64 v26; 
  PVOID *v27; 
  char *v28; 
  PVOID *v29; 
  InfoMask = ObjectHeader->InfoMask;
  if( (InfoMask & 1) != 0 )
    p_TypeIndex = &ObjectHeader[-1].TypeIndex;
  else
    p_TypeIndex = 0i64;
  if( (InfoMask & 2) != 0 )
    v28 = (char *)ObjectHeader - *((unsigned __int8 *)ObpInfoMaskToOffset + (InfoMask & 3));
  else
    v28 = 0i64;
  if( (InfoMask & 4) != 0 )
    v4 = (PVOID *)((char *)ObjectHeader - *((unsigned __int8 *)ObpInfoMaskToOffset + (InfoMask & 7)));
  else
    v4 = 0i64;
  v27 = v4;
  if( (InfoMask & 8) != 0 )
    v5 = (char *)ObjectHeader - *((unsigned __int8 *)ObpInfoMaskToOffset + (InfoMask & 0xF));
  else
    v5 = 0i64;
  if( (InfoMask & 0x20) != 0 )
    v29 = (PVOID *)((char *)ObjectHeader - *((unsigned __int8 *)ObpInfoMaskToOffset + (InfoMask & 0x3F)));
  else
    v29 = 0i64;
  v6 = (unsigned int *)((char *)ObjectHeader - *((unsigned __int8 *)ObpInfoMaskToOffset + InfoMask));
  if( (InfoMask & 0x80u) != 0i64 )
    v6 = (unsigned int *)((char *)v6 + 4i64 - *v6);
  v7 = BYTE1(ObjectHeader);
  v8 = ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ BYTE1(ObjectHeader) ^ (unsigned __int64)ObjectHeader->TypeIndex];
  if( p_TypeIndex && *(unsigned __int8 **)p_TypeIndex != p_TypeIndex )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 243);
    ExAcquirePushLockExclusiveEx(v8 + 184, 0i64);
    v19 = *(_QWORD *)p_TypeIndex;
    v20 = (unsigned __int8 **)*((_QWORD *)p_TypeIndex + 1);
    if( *(unsigned __int8 **)(*(_QWORD *)p_TypeIndex + 8i64) != p_TypeIndex || *v20 != p_TypeIndex )
      __fastfail(3u);
    *v20 = (unsigned __int8 *)v19;
    *(_QWORD *)(v19 + 8) = v20;
    ExReleasePushLockEx(v8 + 184, 0i64);
    KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
  }
  _InterlockedDecrement((volatile signed __int32 *)(v8 + 44));
  ObjectCreateInfo = ObjectHeader->ObjectCreateInfo;
  if( (ObjectHeader->Flags & 1) != 0 )
  {
    if( !ObjectCreateInfo )
      goto LABEL_26;
    if( ObjectCreateInfo->SecurityDescriptor )
    {
      SeReleaseSecurityDescriptor(ObjectCreateInfo->SecurityDescriptor, ObjectCreateInfo->ProbeMode, 1u);
      ObjectHeader->ObjectCreateInfo->SecurityDescriptor = 0i64;
      ObjectCreateInfo = ObjectHeader->ObjectCreateInfo;
    }
    CurrentPrcb = KeGetCurrentPrcb();
    v16 = *((_QWORD *)CurrentPrcb + 264);
    ++*(_DWORD *)(v16 + 28);
    if( *(_WORD *)v16 < *(_WORD *)(v16 + 16)
      || (++*(_DWORD *)(v16 + 32),
          v16 = *((_QWORD *)CurrentPrcb + 265),
          ++*(_DWORD *)(v16 + 28),
          *(_WORD *)v16 < *(_WORD *)(v16 + 16)) )
    {
      RtlpInterlockedPushEntrySList((PSLIST_HEADER)v16, (PSLIST_ENTRY)ObjectCreateInfo);
    }
    else
    {
      ++*(_DWORD *)(v16 + 32);
      (*(void(**)(void))(v16 + 56))();
    }
    goto LABEL_25;
  }
  if( ObjectCreateInfo )
  {
    if( v5 )
    {
      v10 = (volatile INT32 *)*((_QWORD *)v5 + 2);
      v11 = *(_DWORD *)v5;
      v12 = *((_DWORD *)v5 + 1);
      if( v10 && v10 != (volatile INT32 *)1 )
      {
        if( *((_DWORD *)v5 + 2) )
          PspReturnQuota(*((CHAR **)v5 + 2), 0i64, 1ui64, *((unsigned int *)v5 + 2));
        PspDereferenceQuotaBlock(v10);
      }
    }
    else
    {
      v11 = *(_DWORD *)(v8 + 104);
      v12 = *(_DWORD *)(v8 + 108);
    }
    v13 = ObjectHeader->ObjectCreateInfo;
    if( v13 == (_OBJECT_CREATE_INFORMATION *)1 )
      goto LABEL_24;
    if( v11 )
      PspReturnQuota((CHAR *)ObjectHeader->ObjectCreateInfo, 0i64, 1ui64, v11);
    if( v12 )
      PspReturnQuota((CHAR *)v13, 0i64, 0i64, v12);
    if( _InterlockedExchangeAdd((volatile signed __int32 *)&v13[8], 0xFFFFFFFF) != 1 )
    {
LABEL_24:
      v4 = v27;
LABEL_25:
      ObjectHeader->ObjectCreateInfo = 0i64;
      goto LABEL_26;
    }
    v21 = 0;
    v22 = PspResourceFlags;
    v23 = v13 + 1;
    while( 1 )
    {
      if( (*v22 & 3) == 1 )
      {
        v24 = *(_QWORD *)&v23->ProbeMode;
        v25 = *(_QWORD *)&v23->Attributes;
        if( (char *)v23->RootDirectory + *(_QWORD *)&v23->Attributes )
        {
          if( v24 )
          {
            v26 = _InterlockedExchange64((volatile __int64 *)&v23->RootDirectory, 0i64);
            v25 = _InterlockedExchange64((volatile __int64 *)v23, 0i64) + v26;
          }
          if( v25 )
          {
LABEL_67:
            PspReturnResourceQuota((unsigned int)v21, (INT64)&v23[-1], v25, v24 != 0);
            goto LABEL_68;
          }
        }
        else
        {
          v25 = 0i64;
        }
        if( v24 )
          goto LABEL_67;
      }
LABEL_68:
      ++v21;
      v23 += 2;
      v22 += 8;
      if( v21 >= 4 )
      {
        PspRemoveQuotaBlock((__int64)v13);
        ExFreePoolWithTag(v13, 0);
        goto LABEL_24;
      }
    }
  }
LABEL_26:
  if( v4 && (ObjectHeader->Flags & 0x40) == 0 )
  {
    ExFreePoolWithTag(*v4, 0);
    *v4 = 0i64;
  }
  if( v28 )
  {
    v17 = (void *)*((_QWORD *)v28 + 2);
    if( v17 )
    {
      ExFreePoolWithTag(v17, 0);
      *((_QWORD *)v28 + 2) = 0i64;
    }
  }
  if( v29 && *v29 )
  {
    ExFreePoolWithTag(*v29, 0);
    *v29 = 0i64;
  }
  ObjectHeader->TypeIndex = ObHeaderCookie ^ v7 ^ 1;
  if( v8 )
    v14 = *(_DWORD *)(v8 + 192);
  else
    v14 = 1416258127;
  ExFreePoolWithTag(v6, v14);
}

Referenced by:

ObpRemoveObjectRoutine