KeDeleteMutant
NTSTATUS __stdcall KeDeleteMutant(PVOID BugCheckParameter2){
int v1;
_ETHREAD *CurrentThread;
int v3;
volatile signed __int32 *v4;
char v5;
__int64 OldIrql;
_KPRCB *CurrentPrcb;
int v9;
NTSTATUS result;
int v11;
int v12;
PVOID *v13;
PVOID *v14;
__int64 *v15;
__int64 v16;
_KWAIT_BLOCK *v17;
_KWAIT_BLOCK **Blink;
unsigned __int8 WaitType;
bool v20;
_KQUEUE *NotificationQueue;
_LIST_ENTRY *p_WaitListHead;
struct _KPRCB *v23;
__int64 v24;
int SignalState;
_LIST_ENTRY *v26;
_KPRCB *v27;
_KTHREAD *WakeThread;
__int64 *v29;
_ETHREAD *v30;
__int128 v31;
__int64 v32;
UINT64 SpinCount;
int v34;
int v35;
__int64 v36;
v34 = v1;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v3 = 0;
LOBYTE(v34) = 0;
v4 = 0i64;
v30 = CurrentThread;
v5 = 0;
WakeThread = 0i64;
OldIrql = KeGetCurrentIrql();
v36 = OldIrql;
__writecr8(2ui64);
CurrentPrcb = KeGetCurrentPrcb();
v27 = CurrentPrcb;
KiAcquireKobjectLockSafe(BugCheckParameter2);
v9 = *((_DWORD *)BugCheckParameter2 + 1);
*((_BYTE *)BugCheckParameter2 + 48) |= 1u;
*((_DWORD *)BugCheckParameter2 + 1) = 1;
if( v9 <= 0 )
{
v32 = 0i64;
v11 = *(_DWORD *)BugCheckParameter2;
v31 = 0i64;
LODWORD(v31) = v11;
BYTE2(v31) = 0;
*(_DWORD *)BugCheckParameter2 = v31;
v12 = *((unsigned __int8 *)BugCheckParameter2 + 49);
v4 = (volatile signed __int32 *)*((_QWORD *)BugCheckParameter2 + 5);
v35 = v12;
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64(v4 + 16, 0i64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( *((_QWORD *)v4 + 8) );
}
v13 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 3);
v14 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 4);
if( v13[1] != (char *)BugCheckParameter2 + 24 || *v14 != (char *)BugCheckParameter2 + 24 )
LABEL_15:
__fastfail(3u);
*v14 = v13;
v13[1] = v14;
if( (*((_BYTE *)BugCheckParameter2 + 48) & 2) != 0 )
{
LOBYTE(v34) = 1;
if( v4 != (volatile signed __int32 *)CurrentThread )
ObfReferenceObjectWithTag((PVOID)v4, 0x746C6644u);
}
KiReleaseThreadLockSafe((INT64)v4);
*((_QWORD *)BugCheckParameter2 + 5) = 0i64;
v15 = (__int64 *)*((_QWORD *)BugCheckParameter2 + 1);
if( v15 != (__int64 *)((char *)BugCheckParameter2 + 8) )
{
while( 1 )
{
v16 = *v15;
v17 = (_KWAIT_BLOCK *)v15;
v15 = (__int64 *)v16;
v29 = (__int64 *)v16;
Blink = (_KWAIT_BLOCK **)v17->WaitListEntry.Blink;
if( *(_KWAIT_BLOCK **)(v16 + 8) != v17 || *Blink != v17 )
goto LABEL_15;
*Blink = (_KWAIT_BLOCK *)v16;
*(_QWORD *)(v16 + 8) = Blink;
WaitType = v17->WaitType;
if( WaitType == 1 )
{
if( KiTryUnwaitThread(CurrentPrcb, v17, v17->WaitKey, (_KTHREAD **)&WakeThread) )
{
v20 = (*((_DWORD *)BugCheckParameter2 + 1))-- == 1;
if( v20 )
goto LABEL_40;
}
}
else if( WaitType == 2 )
{
v17->BlockState = 5;
NotificationQueue = v17->NotificationQueue;
v17->WaitListEntry.Flink = 0i64;
p_WaitListHead = &NotificationQueue->Header.WaitListHead;
KeGetCurrentIrql();
__writecr8(2ui64);
v23 = KeGetCurrentPrcb();
v24 = *((_QWORD *)v23 + 1);
KiAcquireKobjectLockSafe(NotificationQueue);
if( p_WaitListHead->Flink == p_WaitListHead
|| NotificationQueue->CurrentCount >= NotificationQueue->MaximumCount
|| *(_KQUEUE **)(v24 + 232) == NotificationQueue && *(_BYTE *)(v24 + 643) == 15
|| !KiWakeQueueWaiter(v23, NotificationQueue, (INT64)v17) )
{
SignalState = NotificationQueue->Header.SignalState;
NotificationQueue->Header.SignalState = SignalState + 1;
v26 = NotificationQueue->EntryListHead.Blink;
if( v26->Flink != &NotificationQueue->EntryListHead )
goto LABEL_15;
v17->WaitListEntry.Flink = &NotificationQueue->EntryListHead;
v17->WaitListEntry.Blink = v26;
v26->Flink = &v17->WaitListEntry;
NotificationQueue->EntryListHead.Blink = &v17->WaitListEntry;
if( !SignalState && p_WaitListHead->Flink != p_WaitListHead )
KiWakeOtherQueueWaiters(v23, NotificationQueue);
}
_InterlockedAnd(&NotificationQueue->Header.Lock, 0xFFFFFF7F);
v20 = (*((_DWORD *)BugCheckParameter2 + 1))-- == 1;
if( v20 )
{
LABEL_40:
LOBYTE(OldIrql) = v36;
break;
}
v15 = v29;
CurrentPrcb = v27;
}
else
{
KiTryUnwaitThread(CurrentPrcb, v17, 256i64, 0i64);
}
if( v15 == (__int64 *)((char *)BugCheckParameter2 + 8) )
goto LABEL_40;
}
}
_InterlockedAnd((volatile signed __int32 *)BugCheckParameter2, 0xFFFFFF7F);
KiAcquireReleaseObjectRundownLockExclusive(BugCheckParameter2);
CurrentThread = v30;
CurrentPrcb = v27;
v5 = v34;
v3 = v35;
}
else
{
_InterlockedAnd((volatile signed __int32 *)BugCheckParameter2, 0xFFFFFF7F);
}
KiExitDispatcher(CurrentPrcb, 0i64, AdjustUnwait, 1i64, OldIrql);
if( v5 )
{
if( v4 == (volatile signed __int32 *)CurrentThread )
{
KeAbPostRelease(BugCheckParameter2);
}
else
{
KeAbCrossThreadDelete((unsigned __int64)BugCheckParameter2, (ULONG_PTR)v4);
result = ObfDereferenceObjectWithTag((PVOID)v4, 0x746C6644ui64);
}
}
if( v4 == (volatile signed __int32 *)CurrentThread )
{
if( v3 )
return(unsigned int)KeLeaveCriticalRegionThread((__int64)CurrentThread);
}
return result;
}Referenced by:
ExpDeleteMutant