ExReleasePushLockEx

VOID __fastcall ExReleasePushLockEx(UINT64 P2, UINT64 P1){
  char v2; 
  signed __int64 v4; 
  signed __int64 v5; 
  _ETHREAD *CurrentThread; 
  int v7; 
  unsigned int SessionId; 
  char v9; 
  int v10; 
  bool v11; 
  __int64 v12; 
  unsigned __int64 v13; 
  unsigned int v14; 
  __int64 v15; 
  char v16; 
  v2 = P1;
  if( (P1 & 0xFFFFFFFC) != 0 )
    KeBugCheckEx(0x152u, (unsigned int)P1, P2, 0i64, 0i64);
  _m_prefetchw((const void *)P2);
  v4 = *(_QWORD *)P2;
  v5 = *(_QWORD *)P2 - 16i64;
  if( (*(_QWORD *)P2 & 0xFFFFFFFFFFFFFFF0ui64) <= 0x10 )
    v5 = 0i64;
  if( (v4 & 2) != 0 || v4 != _InterlockedCompareExchange64((volatile signed __int64 *)P2, v5, v4) )
    ExfReleasePushLock((_EX_PUSH_LOCK *__ptr32)P2);
  if( (v2 & 2) == 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    v7 = 0;
    v16 = 0;
    if( P2 >= 0xFFFF800000000000ui64 && *((_BYTE *)&antNameB + ((P2 >> 39) & 0x1FF) - 256) == 1 )
      SessionId = MmGetSessionIdEx(*((_QWORD *)CurrentThread + 23));
    else
      SessionId = -1;
    --*((_WORD *)CurrentThread + 243);
    v9 = ++*((_BYTE *)CurrentThread + 794);
    v10 = (*((char *)CurrentThread + 792) | *((char *)CurrentThread + 870)) ^ 0x3F;
    v11 = !_BitScanReverse((unsigned int *)&v12, v10);
    if( v11 )
      goto LABEL_27;
    while( 1 )
    {
      v13 = *((_QWORD *)CurrentThread + 100) + 96 * v12;
      v10 &= ~(1 << v12);
      if( (*(_BYTE *)(v13 + 26) & 1) != 0
        && (*(_DWORD *)(v13 + 32) & 1) == 0
        && (*(_QWORD *)(v13 + 32) & 0x7FFFFFFFFFFFFFFCi64) == (P2 & 0x7FFFFFFFFFFFFFFCi64)
        && *(_DWORD *)(v13 + 40) == SessionId )
      {
        *(_BYTE *)(v13 + 26) &= ~1u;
        if( *(_QWORD *)(v13 + 32) )
          break;
      }
      v11 = !_BitScanReverse((unsigned int *)&v12, v10);
      if( v11 )
        goto LABEL_27;
    }
    if( !v13 )
    {
LABEL_27:
      if( (*((_DWORD *)CurrentThread + 30) & 0x10000) == 0 )
        KeBugCheckEx(0x162u, (ULONG_PTR)CurrentThread, P2, SessionId, 0i64);
    }
    else
    {
      *(_BYTE *)(v13 + 32) |= 2u;
      if( *(__int64 *)(v13 + 32) < 0 )
        KiAbEntryRemoveFromTree(v13);
      v7 = *(_DWORD *)(v13 + 88) & 0x1FFFF;
      v14 = *(_DWORD *)(v13 + 88) & 0xFFFE0000;
      *(_BYTE *)(v13 + 25) &= ~1u;
      v16 = BYTE2(v7);
      *(_DWORD *)(v13 + 88) = v14;
      *(_QWORD *)(v13 + 32) = 0i64;
      v15 = (__int64)(v13 - *((_QWORD *)CurrentThread + 100)) / 96;
      if( v9 == 1 )
        *((_BYTE *)CurrentThread + 792) |= 1 << v15;
      else
        _InterlockedOr8((volatile signed __int8 *)CurrentThread + 870, 1 << v15);
    }
    --*((_BYTE *)CurrentThread + 794);
    if( (v7 & 0x1FFFF) != 0 )
    {
      if( (v7 & 0x8000u) != 0 )
        KiAbThreadUnboostIoPriority((__int64)CurrentThread, 0);
      if( (v16 & 1) != 0 )
      {
        _InterlockedDecrement((volatile signed __int32 *)CurrentThread + 216);
        PsBoostThreadIoQoS((__int64)CurrentThread, 1);
      }
      if( (v7 & 0x7FFF) != 0 )
        KiAbThreadUnboostCpuPriority((ULONG_PTR)CurrentThread, v7 & 0x7FFF);
    }
    v11 = (*((_WORD *)CurrentThread + 243))++ == 0xFFFF;
    if( v11 && *((_ETHREAD **)CurrentThread + 19) != (_ETHREAD *)((char *)CurrentThread + 152) )
      KiCheckForKernelApcDelivery();
  }
}

Referenced by:

CcAsyncReadWorker
CcAsyncReadWorkerThread
CcCompleteAsyncReadWorker
CcGetNumberOfMappedPages
CcGetVirtualAddress
CcGetVirtualAddressIfMapped
CcPostWorkQueueAsyncRead
CcReleaseBcbLockAndVacbLock
CcShouldSpinAsyncReadWorkerThread
CcUnmapVacbArray
CcUnpinFileDataEx
CmDumpKey
CmEnumerateValueKey
CmLoadAppKey
CmLockKeyForWrite
CmRegisterMachineHiveLoadedNotification
CmSetCallbackObjectContext
CmThawRegistry
CmUnRegisterCallback
CmUnlockHiveSecurity
CmUnregisterMachineHiveLoadedNotification
CmpAssignSecurityToKcb
CmpCallCallBacksEx
CmpCallbackFillObjectContext
CmpCopyMergeOfLayeredKeyNode
CmpCreateKeyControlBlock
CmpDereferenceKeyControlBlock
CmpDereferenceNameControlBlockWithLock
CmpEnumerateCallback
CmpFinishSystemHivesLoad
CmpFreeCallbackObjectContexts
CmpFreeKeyByCell
CmpGetCallbackObjectContext
CmpGetLastHive
CmpGetNextActiveHive
CmpGetNextHive
CmpGlobalLockKeyForWrite
CmpGlobalUnlockKeyForWrite
CmpInsertCallbackInListByAltitude
CmpLazyCommitWorker
CmpLockRegistryFreezeAware
CmpMachineHiveLoadedWorkItem
CmpOKToFollowLink
CmpPerformSingleKcbCacheLookup
CmpStartSiloKeyLockTracker
CmpStopSiloKeyLockTracker
CmpSyncNextBackupHive
CmpUnlockDeletedHashEntryByKcb
CmpUnlockHashEntry
CmpUnlockHashEntryByIndex
CmpUnlockHashEntryByKcb
CmpUnlockHiveList
CmpUnlockKcb
CmpUnlockKcbStack
CmpUnlockNameHashEntry
CmpUnlockTwoKcbs
CmpUnlockTwoSecurityCaches
CmpWalkOneLevel
DelistKeyBodyFromKCB
EtwInitializeSiloState
EtwUnregister
EtwpAddGuidEntry
EtwpAddRegEntryToGroup
EtwpClearSessionAndUnreferenceEntry
EtwpDeleteRegistrationObject
EtwpDeleteSessionDemuxObject
EtwpDemuxPrivateTraceHandle
EtwpDisallowedGuidAddition
EtwpDisallowedGuidRemoval
EtwpEnableGuid
EtwpFreeGuidEntry
EtwpFreeLoggerContext
EtwpGetPrivateSessionTraceHandle
EtwpGetTraceGroupInfo
EtwpGetTraceGuidInfo
EtwpNotifyGuid
EtwpQueueNotification
EtwpRealtimeConnect
EtwpRealtimeDisconnectConsumer
EtwpReceiveNotification
EtwpRegisterPrivateSession
EtwpRegisterProvider
EtwpRegisterUMGuid
EtwpRundownNotifications
EtwpStopLoggerInstance
EtwpTracingProvEnableCallback
EtwpTrackGuidEntryRegistrations
EtwpTrackProviderBinary
EtwpUnlockBufferList
ExReleaseAutoExpandPushLockExclusive
ExShutdownSystem
ExpGetNextCallback
ExpUnlockCallbackListExclusive
ExpWatchProductTypeWork
FsRtlInsertPerFileContext
FsRtlInsertPerFileObjectContext
FsRtlInsertPerStreamContext
FsRtlLookupPerFileContext
FsRtlLookupPerFileObjectContext
FsRtlLookupPerStreamContextInternal
FsRtlRemovePerFileContext
FsRtlRemovePerFileObjectContext
FsRtlRemovePerStreamContext
FsRtlTeardownPerFileContexts
FsRtlTeardownPerStreamContexts
IoRegisterContainerNotification
IoUnregisterContainerNotification
IopCleanupNotifications
IopRegisterDeviceInterface
NtCreatePrivateNamespace
NtMakePermanentObject
NtOpenPrivateNamespace
NtQuerySymbolicLinkObject
NtTraceEvent
ObCheckActiveHandles
ObCloseHandleTableEntry
ObCreateObjectTypeEx
ObDereferenceDeviceMap
ObDestroyHandleRevocationBlock
ObHandleRevocationBlockAddObject
ObInsertObjectEx
ObIsDosDeviceLocallyMapped
ObMakeTemporaryObject
ObOpenObjectByNameEx
ObQueryDeviceMapInformation
ObRegisterCallbacks
ObRevokeHandles
ObSetCurrentProcessDeviceMap
ObSetSecurityDescriptorInfo
ObShutdownSystem
ObUnRegisterCallbacks
ObfDereferenceDeviceMap
ObpCallPreOperationCallbacks
ObpCreateSymbolicLinkName
ObpCreateTypeArray
ObpDecrementHandleCount
ObpDeleteNameCheck
ObpDeleteSymbolicLinkName
ObpFreeObject
ObpGetShadowDirectory
ObpHandleRevocationBlockRemoveInsertedObject
ObpIncrementHandleCountEx
ObpInsertCallbackByAltitude
ObpLookupObjectName
ObpMarkDirectoryObjectsTemporary
ObpMarkDirectoryTreeTemporary
ObpReferenceDeviceMap
ObpRemoveNamespaceFromTable
ObpSetDeviceMap
ObpSetObjectAuditInfo
ObpUnlockDirectory
PiControlGetDeviceInterfaceEnabled
PiDmListAddList
PiDmListAddObject
PiDmListEnumObjectsWithCallback
PiDmListRemoveList
PiDmListRemoveObject
PiDmObjectGetAggregatedBooleanPropertyData
PiDmObjectGetCachedObjectPropertyData
PiDmObjectGetCachedObjectReference
PiDmObjectIsEnumerable
PiDmObjectProcessPropertyChange
PiDmObjectReleaseLock
PiDmObjectUpdateCachedObjectProperty
PiDqDispatch
PiDqIrpQueryCreate
PiDqIrpQueryGetResult
PiDqObjectManagerServiceActionQueue
PiDqQueryApplyObjectEvent
PiDqQuerySerializeActionQueue
PiDqQueryUnlock
PiPnpRtlEnsureObjectCached
PiPnpRtlObjectEventWorker
PnpCancelDeviceActionRequest
PnpDeviceActionWorker
PopFxDestroyDirectedDripsCandidateDeviceList
PopFxDestroyDripsBlockingDeviceList
PopReleaseAwaymodeLock
PopReleaseRwLock
PopReleaseUmpoPushLock
PopUmpoProcessMessage
PsNotifyCoreDriversInitialized
PsRegisterAltSystemCallHandler
SendCaptureStateNotificationsWorker
UNLOCK_HIVE_LOAD
UnlockShutdown
VrpDereferenceDiffHiveEntry
VrpFindOrCreateDiffHiveEntryForMountPoint
VrpUnloadDifferencingHive
WdipSemActivateInstance
WdipSemDeleteTransitionalInstance
WdipSemDisableContextProvider
WdipSemDisableScenario
WdipSemEnableContextProvider
WdipSemEnableScenario
WdipSemInitialize
WdipSemMarkInstanceForDeletion
WdipSemMarkNextTimedOutInstanceForDeletion
WdipSemReserveInstanceTableEntry
WdipSemSqmLogInflightLimitExceededDataPoints
WdipSemUpdate
WdipSemUpdateFrequentScenarioTable
WdipTimeoutCheckRoutine