FsRtlpOplockSendModernAppTermination
VOID __stdcall FsRtlpOplockSendModernAppTermination(_NONOPAQUE_OPLOCK *Oplock, _RH_OP_CONTEXT *RHOpContext){
char v2;
unsigned int v4;
int *PoolWithTag;
int *v6;
_LIST_ENTRY *p_RHBreakQueue;
unsigned int v8;
_LIST_ENTRY *i;
__int64 v10;
_EPROCESS *ExclusiveOplockOwner;
int v12;
int v13;
v2 = 0;
if( RHOpContext || (ExclusiveOplockOwner = Oplock->ExclusiveOplockOwner) == 0i64 )
{
v4 = 4096;
PoolWithTag = (int *)ExAllocatePoolWithTag(PagedPool, 0x1000ui64, 0x74725346ui64);
v6 = PoolWithTag;
if( PoolWithTag )
{
memset((INT64)PoolWithTag, 0i64);
p_RHBreakQueue = &Oplock->RHBreakQueue;
v2 = 1;
v8 = 1;
for( i = p_RHBreakQueue->Flink; ; i = i->Flink )
{
if( i == p_RHBreakQueue )
{
*v6 = v8 - 1;
goto LABEL_8;
}
if( v8 >= 0x400 )
break;
v10 = v8++;
v6[v10] = (int)i[2].Flink[68].Flink;
}
memset((INT64)(v6 + 1), 0i64);
*v6 = -1;
}
else
{
v12 = -1;
v6 = &v12;
v13 = 0;
}
v4 = 4;
}
else
{
v12 = 1;
v6 = &v12;
v4 = 8;
v13 = *((_DWORD *)ExclusiveOplockOwner + 272);
}
LABEL_8:
FsRtlSendModernAppTermination((__int64)v6, v4, 1);
if( v2 )
ExFreePoolWithTag(v6, 0);
}Referenced by:
FsRtlpOplockBreakByCacheFlags
FsRtlpOplockBreakNotify
FsRtlpOplockBreakToII
FsRtlpOplockBreakToNone
FsRtlpRemoveAndBreakRHIrp
FsRtlpRemoveAndCompleteRHIrp