MiDeleteHotPatchRecord
INT64 __fastcall MiDeleteHotPatchRecord(RTL_BALANCED_NODE **a1, UINT64 a2, INT64 a3, INT64 a4){
__int64 *v4;
int v5;
_ETHREAD *CurrentThread;
__int64 *v8;
int v9;
int v10;
INT64 v12[2];
__int64 v13;
int v14;
int v15;
__int128 v16;
v4 = 0i64;
v13 = 0i64;
v14 = a3;
v15 = a4;
v5 = a2;
*(_OWORD *)v12 = 0i64;
v16 = 0i64;
if( (_DWORD)a2 )
{
CurrentThread = 0i64;
}
else
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 243);
ExAcquirePushLockExclusiveEx((UINT64)&MiHotPatchListLock, a2);
}
v8 = (__int64 *)*a1;
if( *a1 )
{
do
{
v9 = MiCompareHotPatchNodes((INT64)v12, (INT64)v8);
if( v9 >= 0 )
{
if( v9 <= 0 )
break;
v8 = (__int64 *)v8[1];
}
else
{
v8 = (__int64 *)*v8;
}
}
while( v8 );
if( v8 )
{
v4 = v8;
RtlAvlRemoveNode((unsigned __int64 *)a1, v8);
v10 = 1;
if( MiHotPatchGeneration != -1 )
v10 = MiHotPatchGeneration + 1;
MiHotPatchGeneration = v10;
}
}
if( !v5 )
{
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&MiHotPatchListLock, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((volatile INT64 *)&MiHotPatchListLock);
KeAbPostRelease(&MiHotPatchListLock);
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
}
if( !v4 )
return 0i64;
ExFreePoolWithTag(v4, 0);
return 1i64;
}Referenced by:
MiUnloadHotPatch
MiUnloadHotPatchForUserSid