ExpUpdateDebugInfo

VOID __fastcall ExpUpdateDebugInfo(_HANDLE_TABLE *HandleTable, _ETHREAD *CurrentThread, VOID *Handle, UINT64 Type){
  unsigned int v4; 
  _HANDLE_TRACE_DEBUG_INFO *v8; 
  _HANDLE_TRACE_DEBUG_INFO *v9; 
  char v10; 
  unsigned int BitMaskFlags; 
  unsigned int CurrentStackIndex; 
  unsigned int TableSize; 
  unsigned int v14; 
  unsigned int v15; 
  __int64 v16; 
  __int64 v17; 
  __int64 v18; 
  int *v19; 
  _OWORD *v20; 
  unsigned int v21; 
  int v22; 
  _HANDLE_TRACE_DB_ENTRY *v23; 
  unsigned int v24; 
  unsigned int v25; 
  int v26; 
  v4 = Type;
  v8 = ExReferenceHandleDebugInfo(HandleTable);
  v9 = v8;
  if( v8 )
  {
    v10 = 0;
    BitMaskFlags = v8->BitMaskFlags;
    if( (BitMaskFlags & 3) != 0 )
    {
      ExAcquireFastMutex(&v9->CloseCompactionLock);
      v10 = 1;
      BitMaskFlags = v9->BitMaskFlags;
    }
    if( (BitMaskFlags & 1) != 0 )
    {
      v9->BitMaskFlags = BitMaskFlags & 0x3FFFFFFE | 0x80000000;
      v9->CurrentStackIndex = 0;
      memset((INT64)v9->TraceDb, 0i64);
      BitMaskFlags = v9->BitMaskFlags;
    }
    if( (BitMaskFlags & 2) != 0 && v4 == 2 )
    {
      CurrentStackIndex = v9->CurrentStackIndex;
      TableSize = CurrentStackIndex;
      if( (BitMaskFlags & 0x40000000) != 0 )
        TableSize = v9->TableSize;
      v14 = 1;
      if( TableSize )
      {
        v15 = v9->TableSize;
        while( 1 )
        {
          v16 = v14 % v15;
          if( v9->TraceDb[(unsigned int)v16].Type == 1 && v9->TraceDb[v16].Handle == Handle )
            break;
          if( ++v14 > TableSize )
            goto LABEL_25;
        }
        v9->CurrentStackIndex = CurrentStackIndex - 1;
        v17 = (CurrentStackIndex - 1) % v15;
        if( (_DWORD)v17 )
        {
          v18 = 160 * v17;
          v19 = &v9->RefCount + 40 * (v14 % v15);
          v20 = (_OWORD *)((char *)&v9->RefCount + v18);
          *((_OWORD *)v19 + 5) = v20[5];
          *((_OWORD *)v19 + 6) = v20[6];
          *((_OWORD *)v19 + 7) = v20[7];
          *((_OWORD *)v19 + 8) = v20[8];
          *((_OWORD *)v19 + 9) = v20[9];
          *((_OWORD *)v19 + 10) = v20[10];
          *((_OWORD *)v19 + 11) = v20[11];
          *((_OWORD *)v19 + 12) = v20[12];
          *((_OWORD *)v19 + 13) = v20[13];
          *((_OWORD *)v19 + 14) = v20[14];
        }
      }
    }
    else
    {
      v21 = _InterlockedIncrement((volatile signed __int32 *)&v9->CurrentStackIndex) % v9->TableSize;
      if( !v21 )
      {
        v22 = v9->BitMaskFlags | 0x40000000;
        v9->BitMaskFlags = v22;
        if( (v22 & 4) != 0 )
          __debugbreak();
      }
      v23 = &v9->TraceDb[v21];
      v23->ClientId = *(_CLIENT_ID *)((char *)CurrentThread + 1144);
      v23->Handle = Handle;
      v23->Type = v4;
      v24 = RtlWalkFrameChain(v23->StackTrace, 0x10ui64, 0x300ui64);
      if( v24 <= 3 )
        v25 = 0;
      else
        v25 = v24 - 3;
      v26 = RtlWalkFrameChain(&v23->StackTrace[v25], 16 - v25, 1ui64);
      memset((INT64)(&v23->StackTrace[v26] + v25), 0i64);
    }
LABEL_25:
    if( v10 )
      KeReleaseGuardedMutex(&v9->CloseCompactionLock);
    ExDereferenceHandleDebugInfo(HandleTable, v9);
  }
}

Referenced by:

ExCreateHandleEx
ExDestroyHandle
ExDupHandleTable
ExHandleLogBadReference
ObCloseHandleTableEntry
ObpCreateHandle