ExpSetResourceOwnerPointerEx

NTSTATUS __stdcall ExpSetResourceOwnerPointerEx(PVOID BugCheckParameter1, PVOID BugCheckParameter4){
  char v2; 
  char v3; 
  _ETHREAD *CurrentThread; 
  unsigned __int8 CurrentIrql; 
  PVOID v8; 
  char *v9; 
  __int64 v10; 
  char *v11; 
  unsigned __int64 v12; 
  unsigned __int64 v13; 
  char *v14; 
  char *v15; 
  char *v16; 
  unsigned int SpareByte0; 
  unsigned __int64 v18; 
  char *v19; 
  __int64 v20; 
  int v21; 
  unsigned __int64 v22; 
  volatile signed __int64 *v23; 
  __int64 v24; 
  unsigned int v25; 
  _KSPIN_LOCK_QUEUE *v26; 
  NTSTATUS result; 
  int v28; 
  int v29; 
  __int64 v30; 
  unsigned __int64 v31; 
  char *v32; 
  char *v33; 
  int v34; 
  int v35; 
  int v36; 
  int v37; 
  INT64 v38[2]; 
  __int64 v39; 

  v3 = v2;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v38[1] = (INT64)BugCheckParameter1 + 96;
  v38[0] = 0i64;
  CurrentIrql = KeGetCurrentIrql();
  __writecr8(2ui64);
  v39 = CurrentIrql;
  if( _InterlockedExchange64((volatile __int64 *)BugCheckParameter1 + 12, (__int64)v38) )
    KxWaitForLockOwnerShip((INT64)v38);
  if( *((char *)BugCheckParameter1 + 26) >= 0 )
  {
    v8 = (PVOID)*((_QWORD *)BugCheckParameter1 + 6);
    v9 = (char *)BugCheckParameter1 + 48;
    if( v8 == BugCheckParameter4 )
    {
      v14 = (char *)BugCheckParameter1 + 48;
    }
    else
    {
      v10 = *((_QWORD *)BugCheckParameter1 + 2);
      v11 = (char *)BugCheckParameter1 + 48;
      v12 = *((_QWORD *)BugCheckParameter1 + 6) != 0i64;
      if( v8 )
        v11 = 0i64;
      v13 = *((unsigned int *)BugCheckParameter1 + 16) + (unsigned __int64)*((unsigned int *)BugCheckParameter1 + 18);
      if( v10 && (v14 = (char *)(*((_QWORD *)BugCheckParameter1 + 2) + 16i64), v12 < v13) )
      {
        while( 1 )
        {
          v15 = v11;
          v16 = v11;
          if( *(PVOID *)v14 == BugCheckParameter4 )
            break;
          if( *(_QWORD *)v14 )
          {
            if( ++v12 == v13 )
              goto LABEL_13;
          }
          else
          {
            v11 = v14;
            if( v16 )
              v11 = v15;
          }
          v14 += 16;
          if( v14 == (char *)(v10 + 16i64 * *(unsigned int *)(v10 + 8)) )
            goto LABEL_13;
        }
        KeGetCurrentThread()->SchedulerApc.SpareByte0 = (__int64)&v14[-v10] >> 4;
      }
      else
      {
LABEL_13:
        v14 = 0i64;
      }
    }
    if( ((unsigned __int8)CurrentThread & 3) != 0 )
      SpareByte0 = 0;
    else
      SpareByte0 = CurrentThread->Tcb.SchedulerApc.SpareByte0;
    if( *(_ETHREAD **)v9 != CurrentThread )
    {
      v18 = *(_QWORD *)v9 != 0i64;
      if( *(_QWORD *)v9 )
        v9 = 0i64;
      v19 = v9;
      if( !SpareByte0
        || (v20 = *((_QWORD *)BugCheckParameter1 + 2)) == 0
        || SpareByte0 >= *(_DWORD *)(v20 + 8)
        || (v9 = (char *)(v20 + 16i64 * SpareByte0), *(_ETHREAD **)v9 != CurrentThread) )
      {
        v30 = *((_QWORD *)BugCheckParameter1 + 2);
        v31 = *((unsigned int *)BugCheckParameter1 + 16) + (unsigned __int64)*((unsigned int *)BugCheckParameter1 + 18);
        if( !v30 || (v9 = (char *)(v30 + 16), v18 >= v31) )
LABEL_78:
          KeBugCheckEx(0xE3u, BugCheckParameter1, CurrentThread, *((PVOID *)BugCheckParameter1 + 2), (PVOID)4);
        while( 1 )
        {
          v32 = v19;
          v33 = v19;
          if( *(_ETHREAD **)v9 == CurrentThread )
            break;
          if( *(_QWORD *)v9 )
          {
            if( ++v18 == v31 )
              goto LABEL_78;
          }
          else
          {
            v19 = v9;
            if( v33 )
              v19 = v32;
          }
          v9 += 16;
          if( v9 == (char *)(v30 + 16i64 * *(unsigned int *)(v30 + 8)) )
            goto LABEL_78;
        }
        KeGetCurrentThread()->SchedulerApc.SpareByte0 = (__int64)&v9[-v30] >> 4;
      }
    }
    v21 = v3 & 1;
    if( !v14 )
    {
      if( v21 )
      {
        v22 = (unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64;
        if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
          KeBugCheckEx(
            0x132u,
            BugCheckParameter1,
            *((PVOID *)BugCheckParameter1 + 2),
            CurrentThread,
            BugCheckParameter4);
        v23 = (volatile signed __int64 *)(v22 - 48);
        if( ObpTraceFlags )
          ObpPushStackInfo((_OBJECT_HEADER *)(v22 - 48), 1u, 1ui64, 0x746C6644ui64);
        v24 = _InterlockedIncrement64(v23);
        if( v24 <= 1 )
          KeBugCheckEx(0x18u, 0i64, (PVOID)(v23 + 6), (PVOID)0x10, (PVOID)v24);
        *((_DWORD *)v9 + 2) |= 2u;
      }
      else
      {
        v34 = *((_DWORD *)v9 + 2);
        if( (v34 & 1) != 0 )
        {
          PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
          *((_DWORD *)v9 + 2) &= ~1u;
          v34 = *((_DWORD *)v9 + 2);
        }
        if( (v34 & 4) != 0 )
        {
          PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
          *((_DWORD *)v9 + 2) &= ~4u;
        }
      }
      *(_QWORD *)v9 = BugCheckParameter4;
      v25 = 34520;
      goto LABEL_31;
    }
    if( v21 )
    {
      if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
        KeBugCheckEx(0x132u, BugCheckParameter1, *((PVOID *)BugCheckParameter1 + 2), CurrentThread, BugCheckParameter4);
      v28 = *((_DWORD *)v9 + 2);
      if( (v28 & 1) != 0 )
      {
        v36 = *((_DWORD *)v14 + 2);
        if( (v36 & 1) != 0 )
          PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
        else
          *((_DWORD *)v14 + 2) = v36 | 1;
        *((_DWORD *)v9 + 2) &= ~1u;
        v28 = *((_DWORD *)v9 + 2);
      }
      if( (v28 & 4) != 0 )
      {
        v37 = *((_DWORD *)v14 + 2);
        if( (v37 & 4) != 0 )
          PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
        else
          *((_DWORD *)v14 + 2) = v37 | 4;
        *((_DWORD *)v9 + 2) &= ~4u;
      }
      if( (*((_DWORD *)v14 + 2) & 2) == 0 )
      {
        ObfReferenceObjectWithTag(*(VOID **)v9, 0x746C6644ui64);
        *((_DWORD *)v14 + 2) |= 2u;
      }
    }
    else
    {
      v29 = *((_DWORD *)v9 + 2);
      if( (v29 & 1) != 0 )
      {
        PsBoostThreadIoEx(*(_ETHREAD **)v9, 1u, 0, 0i64);
        *((_DWORD *)v9 + 2) &= ~1u;
        v29 = *((_DWORD *)v9 + 2);
      }
      if( (v29 & 4) == 0 )
        goto LABEL_42;
      PsBoostThreadIoQoS(*(_ETHREAD **)v9, 1ui64);
      *((_DWORD *)v9 + 2) &= ~4u;
    }
    v29 = *((_DWORD *)v9 + 2);
LABEL_42:
    v25 = 34524;
    *((_DWORD *)v14 + 2) = (v29 + (*((_DWORD *)v14 + 2) & 0xFFFFFFF8)) ^ ((unsigned __int8)v29 ^ (unsigned __int8)*((_DWORD *)v14 + 2)) & 7;
    *((_DWORD *)v9 + 2) &= 7u;
    *(_QWORD *)v9 = 0i64;
    --*((_DWORD *)BugCheckParameter1 + 16);
LABEL_31:
    __incgsdword(v25);
    goto LABEL_32;
  }
  if( ExpResourceEnforcesOwnershipTransfer((INT64)BugCheckParameter1)
    && *((_ETHREAD **)BugCheckParameter1 + 6) != CurrentThread )
  {
    KeBugCheckEx(0xE3u, BugCheckParameter1, CurrentThread, *((PVOID *)BugCheckParameter1 + 2), (PVOID)5);
  }
  if( (v3 & 1) != 0 )
  {
    if( (_ETHREAD *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64) != CurrentThread )
      KeBugCheckEx(0x132u, BugCheckParameter1, *((PVOID *)BugCheckParameter1 + 2), CurrentThread, BugCheckParameter4);
    ObfReferenceObjectWithTag((VOID *)((unsigned __int64)BugCheckParameter4 & 0xFFFFFFFFFFFFFFFCui64), 0x746C6644ui64);
    *((_DWORD *)BugCheckParameter1 + 14) |= 2u;
  }
  else
  {
    v35 = *((_DWORD *)BugCheckParameter1 + 14);
    if( (v35 & 1) != 0 )
    {
      PsBoostThreadIoEx(*((_ETHREAD **)BugCheckParameter1 + 6), 1u, 0, 0i64);
      *((_DWORD *)BugCheckParameter1 + 14) &= ~1u;
      v35 = *((_DWORD *)BugCheckParameter1 + 14);
    }
    if( (v35 & 4) != 0 )
    {
      PsBoostThreadIoQoS(*((_ETHREAD **)BugCheckParameter1 + 6), 1ui64);
      *((_DWORD *)BugCheckParameter1 + 14) &= ~4u;
    }
  }
  *((_QWORD *)BugCheckParameter1 + 6) = BugCheckParameter4;
  __incgsdword(0x86D4u);
LABEL_32:
  _m_prefetchw(v38);
  v26 = (_KSPIN_LOCK_QUEUE *)v38[0];
  if( v38[0] )
  {
LABEL_57:
    v38[0] = 0i64;
    _InterlockedXor64((volatile signed __int64 *)&v26->Lock, 1ui64);
    goto LABEL_34;
  }
  if( (INT64 *)_InterlockedCompareExchange64((volatile signed __int64 *)v38[1], 0i64, (signed __int64)v38) != v38 )
  {
    v26 = KxWaitForLockChainValid((_KSPIN_LOCK_QUEUE *)v38);
    goto LABEL_57;
  }
LABEL_34:
  result = KiIrqlFlags;
  __writecr8((unsigned __int8)v39);
  return result;
}

Referenced by:

ExSetResourceOwnerPointer
ExSetResourceOwnerPointerEx