ExpSetResourceOwnerPointerEx
NTSTATUS __stdcall ExpSetResourceOwnerPointerEx(PVOID BugCheckParameter1, PVOID BugCheckParameter4){
char v2;
char v3;
_ETHREAD *CurrentThread;
unsigned __int8 CurrentIrql;
PVOID v8;
char *v9;
__int64 v10;
char *v11;
unsigned __int64 v12;
unsigned __int64 v13;
char *v14;
char *v15;
char *v16;
unsigned int SpareByte0;
unsigned __int64 v18;
char *v19;
__int64 v20;
int v21;
unsigned __int64 v22;
volatile signed __int64 *v23;
__int64 v24;
unsigned int v25;
_KSPIN_LOCK_QUEUE *v26;
NTSTATUS result;
int v28;
int v29;
__int64 v30;
unsigned __int64 v31;
char *v32;
char *v33;
int v34;
int v35;
int v36;
int v37;
INT64 v38[2];
__int64 v39;
v3 = v2;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v38[1] = (INT64)BugCheckParameter1 + 96;
v38[0] = 0i64;
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
v39 = CurrentIrql;
if( _InterlockedExchange64((volatile __int64 *)BugCheckParameter1 + 12, (__int64)v38) )
KxWaitForLockOwnerShip((INT64)v38);
if( *((char *)BugCheckParameter1 + 26) >= 0 )
{
v8 = (PVOID)*((_QWORD *)BugCheckParameter1 + 6);
v9 = (char *)BugCheckParameter1 + 48;
if( v8 == BugCheckParameter4 )
{
v14 = (char *)BugCheckParameter1 + 48;
}
else
{
v10 = *((_QWORD *)BugCheckParameter1 + 2);
v11 = (char *)BugCheckParameter1 + 48;
v12 = *((_QWORD *)BugCheckParameter1 + 6) != 0i64;
if( v8 )
v11 = 0i64;
v13 = *((unsigned int *)BugCheckParameter1 + 16) + (unsigned __int64)*((unsigned int *)BugCheckParameter1 + 18);
if( v10 && (v14 = (char *)(*((_QWORD *)BugCheckParameter1 + 2) + 16i64), v12 < v13) )
{
while( 1 )
{
v15 = v11;
v16 = v11;
if( *(PVOID *)v14 == BugCheckParameter4 )
break;
if( *(_QWORD *)v14 )
{
if( ++v12 == v13 )
goto LABEL_13;
}
else
{
v11 = v14;
if( v16 )
v11 = v15;
}
v14 += 16;
if( v14 == (char *)(v10 + 16i64 * *(unsigned int *)(v10 + 8)) )
goto LABEL_13;
}
KeGetCurrentThread()->SchedulerApc.SpareByte0 = (__int64)&v14[-v10] >> 4;
}
else
{
LABEL_13:
v14 = 0i64;
}
}
if( ((unsigned __int8)CurrentThread & 3) != 0 )
SpareByte0 = 0;
else
SpareByte0 = CurrentThread->Tcb.SchedulerApc.SpareByte0;
if( *(_ETHREAD **)v9 != CurrentThread )
{
v18 = *(_QWORD *)v9 != 0i64;
if( *(_QWORD *)v9 )
v9 = 0i64;
v19 = v9;
if( !SpareByte0
|| (v20 = *((_QWORD *)BugCheckParameter1 + 2)) == 0
|| SpareByte0 >= *(_DWORD *)(v20 + 8)
|| (v9 = (char *)(v20 + 16i64 * SpareByte0), *(_ETHREAD **)v9 != CurrentThread) )
{
v30 = *((_QWORD *)BugCheckParameter1 + 2);
v31 = *((unsigned int *)BugCheckParameter1 + 16) + (unsigned __int64)*((unsigned int *)BugCheckParameter1 + 18);
if( !v30 || (v9 = (char *)(v30 + 16), v18 >= v31) )
LABEL_78:
KeBugCheckEx(0xE3u, BugCheckParameter1, CurrentThread, *((PVOID *)BugCheckParameter1 + 2), (PVOID)4);
while( 1 )
{
v32 = v19;
v33 = v19;
if( *(_ETHREAD **)v9 == CurrentThread )
break;
if( *(_QWORD *)v9 )
{
if( ++v18 == v31 )
goto LABEL_78;
}
else
{
v19 = v9;
if( v33 )
v19 = v32;
}
v9 += 16;
if( v9 == (char *)(v30 + 16i64 * *(unsigned int *)(v30 + 8)) )
goto LABEL_78;
}
KeGetCurrentThread()->SchedulerApc.SpareByte0 = (__int64)&v9[-v30] >> 4;
}
}
v21 = v3 & 1;
if( !v14 )
{
if( v21 )
{
v22 = (unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64;
if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
KeBugCheckEx(
0x132u,
BugCheckParameter1,
*((PVOID *)BugCheckParameter1 + 2),
CurrentThread,
BugCheckParameter4);
v23 = (volatile signed __int64 *)(v22 - 48);
if( ObpTraceFlags )
ObpPushStackInfo((_OBJECT_HEADER *)(v22 - 48), 1u, 1ui64, 0x746C6644ui64);
v24 = _InterlockedIncrement64(v23);
if( v24 <= 1 )
KeBugCheckEx(0x18u, 0i64, (PVOID)(v23 + 6), (PVOID)0x10, (PVOID)v24);
*((_DWORD *)v9 + 2) |= 2u;
}
else
{
v34 = *((_DWORD *)v9 + 2);
if( (v34 & 1) != 0 )
{
PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
*((_DWORD *)v9 + 2) &= ~1u;
v34 = *((_DWORD *)v9 + 2);
}
if( (v34 & 4) != 0 )
{
PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
*((_DWORD *)v9 + 2) &= ~4u;
}
}
*(_QWORD *)v9 = BugCheckParameter4;
v25 = 34520;
goto LABEL_31;
}
if( v21 )
{
if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
KeBugCheckEx(0x132u, BugCheckParameter1, *((PVOID *)BugCheckParameter1 + 2), CurrentThread, BugCheckParameter4);
v28 = *((_DWORD *)v9 + 2);
if( (v28 & 1) != 0 )
{
v36 = *((_DWORD *)v14 + 2);
if( (v36 & 1) != 0 )
PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
else
*((_DWORD *)v14 + 2) = v36 | 1;
*((_DWORD *)v9 + 2) &= ~1u;
v28 = *((_DWORD *)v9 + 2);
}
if( (v28 & 4) != 0 )
{
v37 = *((_DWORD *)v14 + 2);
if( (v37 & 4) != 0 )
PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
else
*((_DWORD *)v14 + 2) = v37 | 4;
*((_DWORD *)v9 + 2) &= ~4u;
}
if( (*((_DWORD *)v14 + 2) & 2) == 0 )
{
ObfReferenceObjectWithTag(*(VOID **)v9, 0x746C6644ui64);
*((_DWORD *)v14 + 2) |= 2u;
}
}
else
{
v29 = *((_DWORD *)v9 + 2);
if( (v29 & 1) != 0 )
{
PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
*((_DWORD *)v9 + 2) &= ~1u;
v29 = *((_DWORD *)v9 + 2);
}
if( (v29 & 4) == 0 )
goto LABEL_42;
PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
*((_DWORD *)v9 + 2) &= ~4u;
}
v29 = *((_DWORD *)v9 + 2);
LABEL_42:
v25 = 34524;
*((_DWORD *)v14 + 2) = (v29 + (*((_DWORD *)v14 + 2) & 0xFFFFFFF8)) ^ ((unsigned __int8)v29 ^ (unsigned __int8)*((_DWORD *)v14 + 2)) & 7;
*((_DWORD *)v9 + 2) &= 7u;
*(_QWORD *)v9 = 0i64;
--*((_DWORD *)BugCheckParameter1 + 16);
LABEL_31:
__incgsdword(v25);
goto LABEL_32;
}
if( ExpResourceEnforcesOwnershipTransfer((INT64)BugCheckParameter1)
&& *((_ETHREAD **)BugCheckParameter1 + 6) != CurrentThread )
{
KeBugCheckEx(0xE3u, BugCheckParameter1, CurrentThread, *((PVOID *)BugCheckParameter1 + 2), (PVOID)5);
}
if( (v3 & 1) != 0 )
{
if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
KeBugCheckEx(0x132u, BugCheckParameter1, *((PVOID *)BugCheckParameter1 + 2), CurrentThread, BugCheckParameter4);
ObfReferenceObjectWithTag((VOID *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64), 0x746C6644ui64);
*((_DWORD *)BugCheckParameter1 + 14) |= 2u;
}
else
{
v35 = *((_DWORD *)BugCheckParameter1 + 14);
if( (v35 & 1) != 0 )
{
PsBoostThreadIoEx(*((_ETHREAD **)BugCheckParameter1 + 6), 1u, 0, 0i64);
*((_DWORD *)BugCheckParameter1 + 14) &= ~1u;
v35 = *((_DWORD *)BugCheckParameter1 + 14);
}
if( (v35 & 4) != 0 )
{
PsBoostThreadIoQoS(*((_ETHREAD **)BugCheckParameter1 + 6), 1ui64);
*((_DWORD *)BugCheckParameter1 + 14) &= ~4u;
}
}
*((_QWORD *)BugCheckParameter1 + 6) = BugCheckParameter4;
__incgsdword(0x86D4u);
LABEL_32:
_m_prefetchw(v38);
v26 = (_KSPIN_LOCK_QUEUE *)v38[0];
if( v38[0] )
{
LABEL_57:
v38[0] = 0i64;
_InterlockedXor64((volatile signed __int64 *)&v26->Lock, 1ui64);
goto LABEL_34;
}
if( (INT64 *)_InterlockedCompareExchange64((volatile signed __int64 *)v38[1], 0i64, (signed __int64)v38) != v38 )
{
v26 = KxWaitForLockChainValid((_KSPIN_LOCK_QUEUE *)v38);
goto LABEL_57;
}
LABEL_34:
result = KiIrqlFlags;
__writecr8((unsigned __int8)v39);
return result;
}Referenced by:
ExSetResourceOwnerPointer
ExSetResourceOwnerPointerEx