ExAcquireFastMutex
VOID *__stdcall ExAcquireFastMutex(PFAST_MUTEX FastMutex){
__int64 v1;
_ETHREAD *CurrentThread;
unsigned __int8 AbEntrySummary;
__int64 v5;
NTSTATUS SessionId;
bool v7;
unsigned __int8 CurrentIrql;
VOID *result;
unsigned __int8 AbOrphanedEntrySummary;
UINT64 a3;
v1 = 0i64;
LODWORD(a3) = 0;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.SpecialApcDisable;
if( ++CurrentThread->Tcb.AbAllocationRegionCount != 1 )
KeBugCheckEx(0x192u, CurrentThread, FastMutex, (PVOID)KeGetCurrentIrql(), 0i64);
AbEntrySummary = CurrentThread->Tcb.AbEntrySummary;
if( !AbEntrySummary )
{
if( !CurrentThread->Tcb.AbOrphanedEntrySummary )
goto LABEL_18;
AbOrphanedEntrySummary = CurrentThread->Tcb.AbOrphanedEntrySummary;
CurrentThread->Tcb.AbOrphanedEntrySummary = 0;
AbEntrySummary = AbOrphanedEntrySummary | CurrentThread->Tcb.AbEntrySummary;
}
_BitScanForward((unsigned int *)&v5, AbEntrySummary);
CurrentThread->Tcb.AbEntrySummary = AbEntrySummary & ~(1 << v5);
v1 = (__int64)&CurrentThread->Tcb.LockEntries[v5];
if( !v1 )
{
LABEL_18:
_interlockedbittestandset((volatile signed __int32 *)&CurrentThread->Tcb.116 + 1, 0x10u);
goto LABEL_8;
}
if( (unsigned __int64)FastMutex >= 0xFFFF800000000000ui64
&& *((_BYTE *)&stru_140C4DB30 + (((unsigned __int64)FastMutex >> 39) & 0x1FF) + 6872) == 1 )
{
SessionId = MmGetSessionIdEx(CurrentThread->Tcb.ApcState.Process);
}
else
{
SessionId = -1;
}
*(_DWORD *)(v1 + 40) = SessionId;
*(_QWORD *)(v1 + 32) = (unsigned __int64)FastMutex & 0x7FFFFFFFFFFFFFFCi64;
LABEL_8:
--CurrentThread->Tcb.AbAllocationRegionCount;
KiAbThreadRemoveBoosts(&CurrentThread->Tcb, FastMutex, &a3);
v7 = CurrentThread->Tcb.SpecialApcDisable++ == -1;
if( v7
&& ($F25F8C4BA33AF922A5F1AF68CD89DDDF *)CurrentThread->Tcb.ApcState.ApcListHead[0].Flink != &CurrentThread->Tcb.152 )
{
KiCheckForKernelApcDelivery();
}
CurrentIrql = KeGetCurrentIrql();
__writecr8(1ui64);
if( !_interlockedbittestandreset(&FastMutex->Count, 0) )
ExpAcquireFastMutexContended(FastMutex, (VOID *)v1);
if( v1 )
*(_BYTE *)(v1 + 26) |= 1u;
FastMutex->Owner = KeGetCurrentThread();
result = (VOID *)CurrentIrql;
FastMutex->OldIrql = CurrentIrql;
return result;
}Referenced by:
CcAcquireBcbLockAndVacbLock
CcAcquireByteRangeForWrite
CcDeleteMbcb
CcGetDirtyPagesHelper
CcGetFlushedValidData
CcGetLsnForFileObject
CcPinFileData
CcPrepareMdlWrite
CcRepinBcb
CcSetDirtyInMask
CcUnmapInactiveViewsInternal
CcUnmapVacbArray
CcWriteBehindInternal
CcZeroEndOfLastPage
CmWorkerEngineDequeueWorkItem
CmpAddStringToMapping
CmpDelayCloseWorker
CmpGetMappingHiveForString
CmpRemoveFromDelayedClose
CmpVERemoveHiveFromSIDMappingTable
CmpWaitForLateUnloadWorker
CmpWorkerEngineWorker
DbgkClearProcessDebugObject
DbgkCopyProcessDebugPort
DbgkOpenProcessDebugPort
DbgkpCloseObject
DbgkpMarkProcessPeb
DbgkpQueueMessage
DbgkpSetProcessDebugObject
EtwpReleaseProviderTraitsReference
EtwpSetProviderTraitsCommon
ExSwapinWorkerThreads
ExpUpdateDebugInfo
FsRtlAcquireToCreateMappedSection
FsRtlAddLargeMcbEntry
FsRtlAddToTunnelCacheEx
FsRtlDeleteKeyFromTunnelCache
FsRtlFindInTunnelCacheEx
FsRtlGetNextLargeMcbEntry
FsRtlInsertPerStreamContext
FsRtlLookupLargeMcbEntry
FsRtlLookupLastLargeMcbEntry
FsRtlLookupLastLargeMcbEntryAndIndex
FsRtlLookupPerStreamContextInternal
FsRtlNumberOfRunsInLargeMcb
FsRtlPrivateInitializeFileLock
FsRtlRemoveLargeMcbEntry
FsRtlRemovePerStreamContext
FsRtlResetLargeMcb
FsRtlSplitLargeMcb
FsRtlTeardownPerStreamContexts
FsRtlTruncateLargeMcb
FsRtlpCancelExclusiveIrp
FsRtlpCancelOplockRHIrp
FsRtlpCancelReadOnlyOplockIrp
FsRtlpCancelWaitingIrp
FsRtlpWaitOnIrp
HalpAcpiGetAllTables
HalpAcpiGetFacsMapping
HalpAcpiGetTable
HalpIrtAllocateDeviceAperture
HalpIrtAllocateIndex
HalpIrtExtendApertureRange
HalpIrtExtendRemappingRange
HalpIrtFreeIndex
HalpIrtReleaseDeviceAperture
IoGetDeviceProperty
IopCleanupFileObjectIosbRange
IopDestroyDeviceNode
IopLegacyResourceAllocation
IopReleaseResources
IopSetFileObjectIosbRange
KeRegisterProcessorChangeCallback
KeSynchronizeWithDynamicProcessors
KiOpPatchCode
NtDebugContinue
NtSetInformationDebugObject
NtWaitForDebugEvent
PfGetCompletedTrace
PfSnEndTrace
PfSnGetCompletedTrace
PfSnTracingStateExWorkerRoutine
PfTCleanup
PfTInitialize
PfTStart
PfTTraceListAdd
PiDqObjectManagerMakeInconsistent
PiDqObjectManagerServiceActionQueue
PiDqObjectManagerUnregisterQuery
PiQueryResourceRequirements
PiRegisterKernelSoftRestartNotification
PiUEventBroadcastEventWorker
PiUEventDereferenceEventEntry
PiUEventFreeClientRegistrationContext
PiUEventHandleGetEvent
PiUEventHandleRegistration
PiUEventHandleUnregisterClient
PiUEventNotifyClient
PiUEventNotifyClientPendingEvent
PiUEventNotifyDeviceInstanceChange
PiUEventNotifyDeviceInstancePropertyChange
PiUEventNotifyDeviceInterfaceChange
PiUEventNotifyTargetDeviceChange
PiUEventNotifyUserMode
PiUEventQueueBroadcastEventEntry
PiUEventReferenceEventEntry
PiUpdateDeviceResourceLists
PipKsrNotifyDrivers
PipProcessRebuildPowerRelationsQueue
PnpBuildCmResourceLists
PnpBusTypeGuidGet
PnpBusTypeGuidGetIndex
PnpCleanupDeviceRegistryValues
PnpDeferNotification
PnpDeviceObjectFromDeviceInstanceWithTag
PnpDisableUserModeNotifications
PnpFreeDeviceInstancePath
PnpGetResourceRequirementsForAssignTable
PnpInsertEventInQueue
PnpMapDeviceObjectToDeviceInstance
PnpNotifyDeviceClassChange
PnpNotifyHwProfileChange
PnpOrphanNotification
PnpProcessDeferredRegistrations
PnpProfileUpdateHardwareProfile
PnpRemoveEventFromQueue
PnpRestartDeviceNode
PnpUnregisterPlugPlayNotification
PoDisableSleepStates
PoQueueShutdownWorkItem
PoReenableSleepStates
PoRegisterPowerSettingCallback
PoRunDownDeviceObject
PoUnregisterPowerSettingCallback
PopAcquireIrpWorkerLock
PopCallPowerSettingCallback
PopCreateDynamicIrpWorker
PopDiagTraceControlCallback
PopDispatchNotificationsToList
PopDispatchPowerSettingCallbacks
PopFlushVolumeWorker
PopFlushVolumes
PopFreeSessionState
PopGetPowerSettingValue
PopGetSettingNotificationName
PopGetSettingValue
PopInitilizeAcDcSettings
PopIrpWorkerControl
PopLogDisabledSleepReason
PopQueryPowerSettingUlong
PopRunMaximumIrpWorkers
PopRunNormalIrpWorkers
PopSetPowerSettingValue
PpProfileCancelHardwareProfileTransition
PpProfileCancelTransitioningDock
PpProfileCommitTransitioningDock
PpProfileIncludeInHardwareProfileTransition
PpProfileMarkAllTransitioningDocksEjected
PpProfileQueryHardwareProfileChange
RawCleanup
RawClose
RawCompletionRoutine
RawCreate
RawDispatch
RawInitiateDeleteVolume
RawMountVolume
RawReadWriteDeviceControl
RawScanDeletedList
RawUserFsCtrl
RawVerifyVolume
RtlpTraceDatabaseAcquireLock
WheaCrashDumpInitializationComplete
WheapCreateLiveDumpFromPreviousSession
WheapReportDeferredLiveDumps
WheapSaveRecordForLiveDump