EtwpCovSampCaptureCleanupLookasides
INT64 __fastcall EtwpCovSampCaptureCleanupLookasides(INT64 a1){
UINT64 v1;
UINT64 *v2;
int v4;
unsigned __int8 v5;
unsigned __int64 v6;
_QWORD *i;
__int64 *v8;
bool v9;
INT64 result;
v2 = (UINT64 *)(a1 + 264);
v4 = 1;
KeAcquireSpinLockRaiseToDpc((UINT64 *)(a1 + 264), v1);
v6 = v5;
if( !*(_DWORD *)(a1 + 912) && !*(_DWORD *)(a1 + 920) )
{
for( i = *(_QWORD **)(a1 + 576); i != (_QWORD *)(a1 + 576); i = (_QWORD *)*i )
EtwpCovSampLookasideFlushFreeListToCleanupList((union SLIST_HEADER *)(i - 2));
v8 = *(__int64 **)(a1 + 592);
if( v8 == (__int64 *)(a1 + 592) )
goto LABEL_11;
do
{
v9 = *((_DWORD *)v8 + 15) < *((_DWORD *)v8 + 14);
v8 = (__int64 *)*v8;
if( v9 )
v4 = 0;
}
while( v8 != (__int64 *)(a1 + 592) );
if( v4 )
{
LABEL_11:
*(_DWORD *)(a1 + 920) = 1;
KeSetEvent((PRKEVENT)(a1 + 888), 0);
}
}
KxReleaseSpinLock(v2);
result = (unsigned int)KiIrqlFlags;
__writecr8(v6);
return result;
}Referenced by:
EtwpCovSampCaptureCleanupDpc
EtwpCovSampCaptureContextStop