NtRollbackRegistryTransaction
NTSTATUS __stdcall NtRollbackRegistryTransaction(PVOID TransactionHandle, UINT64 Flags){
int v2;
_ETHREAD *CurrentThread;
NTSTATUS v5;
struct _DMA_ADAPTER *v6;
NTSTATUS v7;
PVOID Object;
KAPC_STATE ApcState;
v2 = Flags;
memset(&ApcState, 0, sizeof(ApcState));
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown) )
{
if( v2 )
{
v7 = -1073741811;
}
else
{
Object = 0i64;
v5 = ObReferenceObjectByHandle(
TransactionHandle,
0x10u,
CmRegistryTransactionType,
*((_BYTE *)KeGetCurrentThread() + 562),
&Object,
0i64);
v6 = (struct _DMA_ADAPTER *)Object;
v7 = v5;
if( v5 >= 0 )
{
CmpAttachToRegistryProcess(&ApcState);
v7 = CmpRollbackLightWeightTransaction((INT64)v6);
KiUnstackDetachProcess(&ApcState, 0i64);
if( v7 >= 0 )
v7 = 0;
}
if( v6 )
HalPutDmaAdapter(v6);
}
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}
else
{
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return -1073741431;
}
return v7;
}Referenced by:
No references.