PopScanIdleList
NTSTATUS __stdcall PopScanIdleList(){
__int64 v0;
int v1;
int v2;
unsigned __int64 v3;
int v4;
int v5;
unsigned __int8 v6;
unsigned __int64 v7;
_DEVICE_OBJECT *v8;
volatile __int32 *v9;
unsigned int v10;
volatile __int32 *v11;
__int32 v12;
unsigned __int32 v13;
unsigned int v14;
int v15;
unsigned int v16;
unsigned int v17;
unsigned int v18;
unsigned int v19;
unsigned int v20;
int v21;
int v22;
_DEVICE_OBJECT *DeviceAttachmentBaseRefWithTag;
_WORD *DeviceNode;
char v25;
char v26;
int v27;
unsigned int v28;
int v29;
unsigned __int64 v30;
_DEVICE_OBJECT *a5;
char v33;
char v34;
int ReturnedLength;
unsigned __int8 v36;
__int16 v37;
int v38;
int v39;
UINT64 ReturnedLengtha;
int v41;
unsigned int IdleDiskTimeout;
unsigned int IdleDiskTimeout_4;
unsigned int v44;
unsigned __int32 v45;
int v46;
int v47;
_DEVICE_OBJECT *v48;
__int64 v49;
_EVENT_DATA_DESCRIPTOR UserData;
__int64 *v51;
__int64 v52;
__int16 *v53;
__int64 v54;
__int64 v55;
int v56;
int v57;
char *v58;
__int64 v59;
char *v60;
__int64 v61;
int *v62;
__int64 v63;
int *v64;
__int64 v65;
char *v66;
__int64 v67;
char *v68;
__int64 v69;
char *v70;
__int64 v71;
v41 = *(&stru_140C23628 + 448);
v3 = v0;
v49 = v0;
v4 = v1;
LOBYTE(v2) = 0;
v5 = 0;
v47 = v1;
ReturnedLength = 0;
LODWORD(ReturnedLengtha) = 0;
IdleDiskTimeout = *(_DWORD *)(*(&stru_140C23628 + 232) + 212i64);
IdleDiskTimeout_4 = PopCurrentCoalescingSpindownTimeout;
v38 = v2;
v39 = 0;
v44 = *(&stru_140C23628 + 447);
v6 = KeAcquireSpinLockRaiseToDpc((UINT64 *)&stru_140C23628 + 142);
v7 = v6;
v36 = v6;
if( byte_140C502F4 )
{
KxReleaseSpinLock((UINT64 *)&stru_140C23628 + 142);
__writecr8(v7);
}
else
{
PopDiagTraceEventNoPayload(&POP_ETW_EVENT_DEVICE_IDLE_START);
v9 = (volatile __int32 *)*(&stru_140C23628 + 145);
if( (_UNKNOWN *)*(&stru_140C23628 + 145) != (_UNKNOWN *)((char *)&stru_140C23628 + 1160) )
{
v10 = 0;
do
{
v11 = v9 - 8;
v12 = _InterlockedExchange(v9 - 7, 0);
*((_DWORD *)v9 - 5) += v12;
if( v12 || *((_DWORD *)v11 + 2) )
*v11 = 0;
v13 = _InterlockedExchangeAdd(v11, PopIdleScanInterval);
if( !v13 )
*((_DWORD *)v11 + 14) = 1;
if( v41 == 1 )
v14 = *((_DWORD *)v11 + 4);
else
v14 = *((_DWORD *)v11 + 5);
v15 = *((_DWORD *)v11 + 12);
if( v15 == 1 )
{
if( v14 == -1 )
v14 = IdleDiskTimeout;
v17 = PopCoalescingCheck(IdleDiskTimeout_4, v14, v13, v8);
v14 = v17;
if( v17 )
++v39;
v10 = v44;
if( v44 > v17 )
v10 = v17;
v18 = *((_DWORD *)v11 + 23);
v16 = PopIdleScanInterval + *((_DWORD *)v11 + 22);
v8 = (_DEVICE_OBJECT *)v16;
if( v13 )
{
if( v18 <= PopIdleScanInterval )
v20 = 0;
else
v20 = v18 - PopIdleScanInterval;
}
else
{
v19 = PopIdleScanInterval + v18;
v16 = v10;
v20 = v10;
if( v19 <= v10 )
v16 = (unsigned int)v8;
if( v19 <= v10 )
v20 = v19;
}
v15 = *((_DWORD *)v11 + 12);
*((_DWORD *)v11 + 22) = v16;
*((_DWORD *)v11 + 23) = v20;
}
else
{
v16 = v13;
}
if( v14 && v16 >= v14 && *((_DWORD *)v11 + 14) == 1 && (v13 || (*(&stru_140C23628 + 582) & 0x2000000) != 0) )
{
if( *((_DWORD *)v11 + 12) == 1 )
PopDiagTraceIoCoalescingDiskIdle(*((_DEVICE_OBJECT **)v11 + 3));
if( PopRequestPowerIrp(
*((_DEVICE_OBJECT **)v11 + 3),
2,
*((unsigned int *)v11 + 13),
(INT64)PopDeviceIdleCompletion,
0i64,
0,
0i64) >= 0 )
{
v21 = *((_DWORD *)v11 + 13);
++dword_140C502F0;
*((_DWORD *)v11 + 14) = v21;
*((_DWORD *)v11 + 3) = 0;
}
}
else if( v15 == 1 )
{
v22 = (unsigned __int8)v38;
if( !v13 )
v22 = 1;
v38 = v22;
}
v46 = v12;
v45 = v13;
v34 = 0;
v33 = 0;
v37 = 0;
v48 = 0i64;
if( PopDiagHandleRegistered )
{
if( EtwEventEnabled(PopDiagHandle, &POP_ETW_EVENT_DEVICE_IDLE_CHECK) )
{
DeviceAttachmentBaseRefWithTag = IoGetDeviceAttachmentBaseRefWithTag(
*((_DEVICE_OBJECT **)v11 + 3),
0x67446F50ui64);
v48 = DeviceAttachmentBaseRefWithTag;
if( DeviceAttachmentBaseRefWithTag )
{
DeviceNode = DeviceAttachmentBaseRefWithTag->DeviceObjectExtension->DeviceNode;
if( DeviceNode )
{
v37 = DeviceNode[20] >> 1;
v25 = *((_BYTE *)v11 + 52) - 1;
UserData.Ptr = (unsigned __int64)(v11 + 6);
v33 = v25;
v26 = *((_BYTE *)v11 + 56) - 1;
*(_QWORD *)&UserData.Size = 8i64;
v34 = v26;
v51 = (__int64 *)&v48;
v53 = &v37;
v52 = 8i64;
v54 = 2i64;
v27 = (unsigned __int16)DeviceNode[20];
v55 = *((_QWORD *)DeviceNode + 6);
v58 = (char *)(v11 + 4);
v60 = (char *)(v11 + 5);
v62 = (int *)&v45;
v64 = &v46;
v66 = (char *)(v11 + 3);
v68 = &v33;
v70 = &v34;
v56 = v27;
v57 = 0;
v59 = 4i64;
v61 = 4i64;
v63 = 4i64;
v65 = 4i64;
v67 = 4i64;
v69 = 1i64;
v71 = 1i64;
EtwWrite(PopDiagHandle, &POP_ETW_EVENT_DEVICE_IDLE_CHECK, 0, 0xBu, &UserData);
DeviceAttachmentBaseRefWithTag = v48;
}
if( DeviceAttachmentBaseRefWithTag )
ObfDereferenceObjectWithTag(DeviceAttachmentBaseRefWithTag, 0x67446F50ui64);
}
}
}
if( *((_DWORD *)v11 + 12) == 1 )
PopDiagTraceDiskIdleCheck((__int64)(v9 - 8), v14, v10);
v9 = *(volatile __int32 **)v9;
}
while( v9 != (volatile __int32 *)((char *)&stru_140C23628 + 1160) );
LOBYTE(v7) = v36;
LOBYTE(v2) = v38;
v5 = v39;
v3 = v49;
v4 = v47;
}
PopDiagTraceEventNoPayload(&POP_ETW_EVENT_DEVICE_IDLE_END);
KxReleaseSpinLock((UINT64 *)&stru_140C23628 + 142);
__writecr8((unsigned __int8)v7);
v29 = *(&stru_140C23628 + 1191);
if( *(&stru_140C23628 + 1191) )
v29 = --*(&stru_140C23628 + 1191);
if( *(&stru_140C23628 + 1190) )
--*(&stru_140C23628 + 1190);
if( !v4
|| (v28 = (PopIdleScanInterval + 179) % (unsigned int)PopIdleScanInterval,
v30 = (PopIdleScanInterval + 179) / (unsigned int)PopIdleScanInterval,
v3 == v30) )
{
PopBackgroundTaskAllowed = 1;
}
else if( v3 < v30 )
{
PopBackgroundTaskAllowed = 0;
}
if( !v5 || (_BYTE)v2 )
{
if( !v29 && !*(&stru_140C23628 + 441) )
{
PopGetPowerSettingValue(
&GUID_IDLE_BACKGROUND_TASK,
v28,
(VOID *)3,
&ReturnedLength,
(UINT64)a5,
&ReturnedLengtha);
++ReturnedLength;
PopSetPowerSettingValueAcDc((_LPCGUID)&GUID_IDLE_BACKGROUND_TASK, 4ui64, &ReturnedLength);
v28 = (PopIdleScanInterval + 59) % (unsigned int)PopIdleScanInterval;
*(&stru_140C23628 + 1191) = (PopIdleScanInterval + 59) / (unsigned int)PopIdleScanInterval;
}
if( !*(&stru_140C23628 + 1190) && !*(&stru_140C23628 + 441) && PopSIdle >= 50 && PopBackgroundTaskAllowed )
{
PopGetPowerSettingValue(
&GUID_BACKGROUND_TASK_NOTIFICATION,
v28,
0i64,
&ReturnedLength,
(UINT64)a5,
&ReturnedLengtha);
++ReturnedLength;
PopSetPowerSettingValue((_LPCGUID)&GUID_BACKGROUND_TASK_NOTIFICATION, (VOID *)0xFFFFFFFFi64);
PopBackgroundTaskAllowed = 0;
*(&stru_140C23628 + 1190) = (PopIdleScanInterval + 179) / (unsigned int)PopIdleScanInterval;
}
}
}
return 0;
}Referenced by:
PopIdleDetection
PopPolicySystemIdle