FsRtlLookupPerFileObjectContext

PFSRTL_PER_FILEOBJECT_CONTEXT __stdcall FsRtlLookupPerFileObjectContext(
        PFILE_OBJECT FileObject,
        PVOID OwnerId,
        PVOID InstanceId){
  _QWORD *FileObjectExtension; 
  UINT64 v7; 
  _ETHREAD *CurrentThread; 
  struct _FSRTL_PER_FILEOBJECT_CONTEXT *v9; 
  struct _FSRTL_PER_FILEOBJECT_CONTEXT **v10; 
  struct _FSRTL_PER_FILEOBJECT_CONTEXT *Flink; 
  if( !FileObject )
    return 0i64;
  FileObjectExtension = FileObject->FileObjectExtension;
  if( !FileObjectExtension )
    return 0i64;
  if( FileObjectExtension == (_QWORD *)IopRevocationExtension )
    return 0i64;
  v7 = FileObjectExtension[4];
  if( !v7 )
    return 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v9 = 0i64;
  --*((_WORD *)CurrentThread + 242);
  ExAcquirePushLockSharedEx(v7, 0i64);
  v10 = (struct _FSRTL_PER_FILEOBJECT_CONTEXT **)(v7 + 8);
  if( InstanceId )
  {
    Flink = *v10;
    if( *v10 == (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)v10 )
      goto LABEL_11;
    while( Flink->OwnerId != OwnerId || Flink->InstanceId != InstanceId )
    {
      Flink = (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)Flink->Links.Flink;
      if( Flink == (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)v10 )
        goto LABEL_11;
    }
    goto LABEL_10;
  }
  if( !OwnerId )
  {
    if( *v10 != (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)v10 )
      v9 = *v10;
    goto LABEL_11;
  }
  Flink = *v10;
  if( *v10 != (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)v10 )
  {
    while( Flink->OwnerId != OwnerId )
    {
      Flink = (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)Flink->Links.Flink;
      if( Flink == (struct _FSRTL_PER_FILEOBJECT_CONTEXT *)v10 )
        goto LABEL_11;
    }
LABEL_10:
    v9 = Flink;
  }
LABEL_11:
  ExReleasePushLockEx(v7, 0i64);
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  return v9;
}

Referenced by:

No references.