IopQueryProcessIdsUsingFile

INT64 __stdcall IopQueryProcessIdsUsingFile(
        FILE_OBJECT *FileObject,
        _FILE_PROCESS_IDS_USING_FILE_INFORMATION *PidBuffer,
        UINT64 PidBufferLength,
        UINT64 *OutputSize){
  ULONG_PTR *ProcessIdList; 
  unsigned int v7; 
  unsigned int v8; 
  struct _EX_RUNDOWN_REF *i; 
  struct _EX_RUNDOWN_REF *NextProcess; 
  struct _EX_RUNDOWN_REF *v11; 
  unsigned int *v12; 
  char v13; 
  FILE_OBJECT *v15; 
  __int64 v16; 
  ProcessIdList = PidBuffer->ProcessIdList;
  v7 = (unsigned int)(PidBufferLength - 8) >> 3;
  v8 = 0;
  v16 = 0i64;
  PidBuffer->NumberOfProcessIdsInList = 0;
  v15 = FileObject;
  for( i = 0i64; ; i = v11 )
  {
    NextProcess = (struct _EX_RUNDOWN_REF *)PsGetNextProcess(i);
    v11 = NextProcess;
    if( !NextProcess )
      break;
    v12 = (unsigned int *)ObReferenceProcessHandleTable(NextProcess);
    if( v12 )
    {
      LOBYTE(v16) = v11 == *((struct _EX_RUNDOWN_REF **)KeGetCurrentThread() + 23);
      v13 = ExEnumHandleTable(
              v12,
              (__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))IopIsFileOpenOrSection,
              (__int64)&v15,
              0i64);
      ExReleaseRundownProtection(v11 + 139);
    }
    else
    {
      v13 = 0;
    }
    if( v13 || (unsigned int)MmIsFileMapped((ULONG_PTR)v11, (__int64)FileObject) )
    {
      if( v8 < v7 )
      {
        *ProcessIdList = v11[136].Count;
        ++PidBuffer->NumberOfProcessIdsInList;
        ++ProcessIdList;
      }
      ++v8;
    }
  }
  *(_DWORD *)OutputSize = 8 * v8 + 8;
  return v7 < v8 ? 0xC0000004 : 0;
}

Referenced by:

NtQueryInformationFile