ExpUpdateDebugInfo
VOID __fastcall ExpUpdateDebugInfo(_HANDLE_TABLE *HandleTable, _ETHREAD *CurrentThread, VOID *Handle, UINT64 Type){
unsigned int v4;
_HANDLE_TRACE_DEBUG_INFO *v8;
_HANDLE_TRACE_DEBUG_INFO *v9;
char v10;
unsigned int BitMaskFlags;
unsigned int CurrentStackIndex;
unsigned int TableSize;
unsigned int v14;
unsigned int v15;
__int64 v16;
__int64 v17;
__int64 v18;
int *v19;
_OWORD *v20;
unsigned int v21;
int v22;
_HANDLE_TRACE_DB_ENTRY *v23;
unsigned int v24;
unsigned int v25;
int v26;
v4 = Type;
v8 = ExReferenceHandleDebugInfo(HandleTable);
v9 = v8;
if( v8 )
{
v10 = 0;
BitMaskFlags = v8->BitMaskFlags;
if( (BitMaskFlags & 3) != 0 )
{
ExAcquireFastMutex(&v9->CloseCompactionLock);
v10 = 1;
BitMaskFlags = v9->BitMaskFlags;
}
if( (BitMaskFlags & 1) != 0 )
{
v9->BitMaskFlags = BitMaskFlags & 0x3FFFFFFE | 0x80000000;
v9->CurrentStackIndex = 0;
memset((INT64)v9->TraceDb, 0i64);
BitMaskFlags = v9->BitMaskFlags;
}
if( (BitMaskFlags & 2) != 0 && v4 == 2 )
{
CurrentStackIndex = v9->CurrentStackIndex;
TableSize = CurrentStackIndex;
if( (BitMaskFlags & 0x40000000) != 0 )
TableSize = v9->TableSize;
v14 = 1;
if( TableSize )
{
v15 = v9->TableSize;
while( 1 )
{
v16 = v14 % v15;
if( v9->TraceDb[(unsigned int)v16].Type == 1 && v9->TraceDb[v16].Handle == Handle )
break;
if( ++v14 > TableSize )
goto LABEL_25;
}
v9->CurrentStackIndex = CurrentStackIndex - 1;
v17 = (CurrentStackIndex - 1) % v15;
if( (_DWORD)v17 )
{
v18 = 160 * v17;
v19 = &v9->RefCount + 40 * (v14 % v15);
v20 = (_OWORD *)((char *)&v9->RefCount + v18);
*((_OWORD *)v19 + 5) = v20[5];
*((_OWORD *)v19 + 6) = v20[6];
*((_OWORD *)v19 + 7) = v20[7];
*((_OWORD *)v19 + 8) = v20[8];
*((_OWORD *)v19 + 9) = v20[9];
*((_OWORD *)v19 + 10) = v20[10];
*((_OWORD *)v19 + 11) = v20[11];
*((_OWORD *)v19 + 12) = v20[12];
*((_OWORD *)v19 + 13) = v20[13];
*((_OWORD *)v19 + 14) = v20[14];
}
}
}
else
{
v21 = _InterlockedIncrement((volatile signed __int32 *)&v9->CurrentStackIndex) % v9->TableSize;
if( !v21 )
{
v22 = v9->BitMaskFlags | 0x40000000;
v9->BitMaskFlags = v22;
if( (v22 & 4) != 0 )
__debugbreak();
}
v23 = &v9->TraceDb[v21];
v23->ClientId = *(_CLIENT_ID *)((char *)CurrentThread + 1144);
v23->Handle = Handle;
v23->Type = v4;
v24 = RtlWalkFrameChain(v23->StackTrace, 0x10ui64, 0x300ui64);
if( v24 <= 3 )
v25 = 0;
else
v25 = v24 - 3;
v26 = RtlWalkFrameChain(&v23->StackTrace[v25], 16 - v25, 1ui64);
memset((INT64)(&v23->StackTrace[v26] + v25), 0i64);
}
LABEL_25:
if( v10 )
KeReleaseGuardedMutex(&v9->CloseCompactionLock);
ExDereferenceHandleDebugInfo(HandleTable, v9);
}
}Referenced by:
ExCreateHandleEx
ExDestroyHandle
ExDupHandleTable
ExHandleLogBadReference
ObCloseHandleTableEntry
ObpCreateHandle