FsRtlInsertPerFileContext

VOID __stdcall FsRtlInsertPerFileContext(PVOID *PerFileContextPointer, _FSRTL_PER_FILE_CONTEXT *Ptr){
  _QWORD *v4; 
  _QWORD *PoolWithTag; 
  _QWORD *v6; 
  signed __int64 v7; 
  _ETHREAD *CurrentThread; 
  _LIST_ENTRY *v9; 
  _LIST_ENTRY *v10; 
  if( PerFileContextPointer )
  {
    v4 = (_QWORD *)_InterlockedCompareExchange64((volatile signed __int64 *)PerFileContextPointer, 0i64, 0i64);
    if( !v4 )
    {
      PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, 0x20ui64, 0x63665346ui64);
      v4 = PoolWithTag;
      if( !PoolWithTag )
        return;
      *PoolWithTag = 0i64;
      v6 = PoolWithTag + 1;
      v4[3] = 0i64;
      v6[1] = v6;
      *v6 = v6;
      v7 = _InterlockedCompareExchange64((volatile signed __int64 *)PerFileContextPointer, (signed __int64)v4, 0i64);
      if( v7 )
      {
        ExFreePoolWithTag(v4, 0x63665346u);
        v4 = (_QWORD *)v7;
      }
    }
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 242);
    ExAcquirePushLockExclusiveEx((UINT64)v4, 0i64);
    v9 = (_LIST_ENTRY *)(v4 + 1);
    v10 = (_LIST_ENTRY *)v4[1];
    if( v10->Blink != (_LIST_ENTRY *)(v4 + 1) )
      __fastfail(3u);
    Ptr->Links.Flink = v10;
    Ptr->Links.Blink = v9;
    v10->Blink = &Ptr->Links;
    v9->Flink = &Ptr->Links;
    ExReleasePushLockEx((UINT64)v4, 0i64);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  }
}

Referenced by:

No references.