KeQueryOwnerMutant
VOID __stdcall KeQueryOwnerMutant(_KMUTANT *Mutant, _CLIENT_ID *ClientId){
unsigned __int8 CurrentIrql;
_ETHREAD *OwnerThread;
ClientId->UniqueProcess = 0i64;
ClientId->UniqueThread = 0i64;
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
KiAcquireKobjectLockSafe(Mutant);
OwnerThread = Mutant->OwnerThread;
if( OwnerThread )
*ClientId = *(_CLIENT_ID *)((char *)OwnerThread + 1144);
_InterlockedAnd(&Mutant->Header.Lock, 0xFFFFFF7F);
__writecr8(CurrentIrql);
}Referenced by:
NtQueryMutant