PiSwProcessParentRemoveIrp
VOID __stdcall PiSwProcessParentRemoveIrp(DEVICE_OBJECT *ParentDeviceObject){
DEVICE_OBJECT *v1;
UNICODE_STRING *v2;
_ETHREAD *CurrentThread;
__int64 *v4;
__int64 *v5;
WCHAR *Buffer;
INT64 SwDevice;
__int64 v8;
v1 = ParentDeviceObject;
if( ParentDeviceObject )
ParentDeviceObject = *(DEVICE_OBJECT **)(*((_QWORD *)ParentDeviceObject + 39) + 40i64);
v2 = (UNICODE_STRING *)(((unsigned __int64)ParentDeviceObject + 40) & -(__int64)(ParentDeviceObject != 0i64));
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquireResourceExclusiveLite((ERESOURCE *)PiSwLockObj, 1u);
v4 = (__int64 *)PiSwGlobalPdoAssociationList;
while( v4 != &PiSwGlobalPdoAssociationList )
{
v5 = v4;
v4 = (__int64 *)*v4;
if( (DEVICE_OBJECT *)v5[2] == v1 )
{
v8 = v5[3];
if( (*(_DWORD *)(*(_QWORD *)(v8 + 64) + 8i64) & 0x20) == 0 )
PiSwProcessRemove((DEVICE_OBJECT *)v8, 0);
PiSwDestroyDeviceObject((DEVICE_OBJECT *)v8);
}
}
if( v2 )
{
Buffer = v2->Buffer;
if( Buffer )
{
SwDevice = PiSwFindSwDevice(Buffer);
if( !SwDevice || (*(_DWORD *)(SwDevice + 4) & 1) == 0 && !*(_DWORD *)(SwDevice + 180) )
PiSwCloseDescendants(v2);
}
}
ExReleaseResourceLite((PERESOURCE)PiSwLockObj);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}Referenced by:
IopRemoveDevice