IopQueryProcessIdsUsingFile
INT64 __stdcall IopQueryProcessIdsUsingFile(
FILE_OBJECT *FileObject,
_FILE_PROCESS_IDS_USING_FILE_INFORMATION *PidBuffer,
UINT64 PidBufferLength,
UINT64 *OutputSize){
ULONG_PTR *ProcessIdList;
unsigned int v7;
unsigned int v8;
struct _EX_RUNDOWN_REF *i;
struct _EX_RUNDOWN_REF *NextProcess;
struct _EX_RUNDOWN_REF *v11;
unsigned int *v12;
char v13;
FILE_OBJECT *v15;
__int64 v16;
ProcessIdList = PidBuffer->ProcessIdList;
v7 = (unsigned int)(PidBufferLength - 8) >> 3;
v8 = 0;
v16 = 0i64;
PidBuffer->NumberOfProcessIdsInList = 0;
v15 = FileObject;
for( i = 0i64; ; i = v11 )
{
NextProcess = (struct _EX_RUNDOWN_REF *)PsGetNextProcess(i);
v11 = NextProcess;
if( !NextProcess )
break;
v12 = (unsigned int *)ObReferenceProcessHandleTable(NextProcess);
if( v12 )
{
LOBYTE(v16) = v11 == *((struct _EX_RUNDOWN_REF **)KeGetCurrentThread() + 23);
v13 = ExEnumHandleTable(
v12,
(__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))IopIsFileOpenOrSection,
(__int64)&v15,
0i64);
ExReleaseRundownProtection(v11 + 139);
}
else
{
v13 = 0;
}
if( v13 || (unsigned int)MmIsFileMapped((ULONG_PTR)v11, (__int64)FileObject) )
{
if( v8 < v7 )
{
*ProcessIdList = v11[136].Count;
++PidBuffer->NumberOfProcessIdsInList;
++ProcessIdList;
}
++v8;
}
}
*(_DWORD *)OutputSize = 8 * v8 + 8;
return v7 < v8 ? 0xC0000004 : 0;
}Referenced by:
NtQueryInformationFile