KeDeleteMutant
NTSTATUS __stdcall KeDeleteMutant(PVOID BugCheckParameter2){
int v1;
_ETHREAD *CurrentThread;
int v3;
INT64 v4;
char v5;
__int64 OldIrql;
_KPRCB *CurrentPrcb;
int v9;
NTSTATUS result;
int v11;
int v12;
PVOID *v13;
PVOID *v14;
__int64 *v15;
__int64 v16;
_KWAIT_BLOCK *v17;
_KWAIT_BLOCK **Blink;
unsigned __int8 WaitType;
bool v20;
_ETHREAD *Thread;
_QWORD *v22;
struct _KPRCB *v23;
_ETHREAD *v24;
char v25;
int v26;
_KWAIT_BLOCK **QuantumTarget;
_KPRCB *v28;
_KTHREAD *WakeThread;
__int64 *v30;
_ETHREAD *v31;
__int128 v32;
__int64 v33;
UINT64 SpinCount;
int v35;
int v36;
__int64 v37;
v35 = v1;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v3 = 0;
LOBYTE(v35) = 0;
v4 = 0i64;
v31 = CurrentThread;
v5 = 0;
WakeThread = 0i64;
OldIrql = KeGetCurrentIrql();
v37 = OldIrql;
__writecr8(2ui64);
CurrentPrcb = KeGetCurrentPrcb();
v28 = CurrentPrcb;
KiAcquireKobjectLockSafe(BugCheckParameter2);
v9 = *((_DWORD *)BugCheckParameter2 + 1);
*((_BYTE *)BugCheckParameter2 + 48) |= 1u;
*((_DWORD *)BugCheckParameter2 + 1) = 1;
if( v9 <= 0 )
{
v33 = 0i64;
v11 = *(_DWORD *)BugCheckParameter2;
v32 = 0i64;
LODWORD(v32) = v11;
BYTE2(v32) = 0;
*(_DWORD *)BugCheckParameter2 = v32;
v12 = *((unsigned __int8 *)BugCheckParameter2 + 49);
v4 = *((_QWORD *)BugCheckParameter2 + 5);
v36 = v12;
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)(v4 + 64), 0i64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( *(_QWORD *)(v4 + 64) );
}
v13 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 3);
v14 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 4);
if( v13[1] != (char *)BugCheckParameter2 + 24 || *v14 != (char *)BugCheckParameter2 + 24 )
LABEL_15:
__fastfail(3u);
*v14 = v13;
v13[1] = v14;
if( (*((_BYTE *)BugCheckParameter2 + 48) & 2) != 0 )
{
LOBYTE(v35) = 1;
if( (_ETHREAD *)v4 != CurrentThread )
ObfReferenceObjectWithTag((VOID *)v4, 0x746C6644ui64);
}
KiReleaseThreadLockSafe(v4);
*((_QWORD *)BugCheckParameter2 + 5) = 0i64;
v15 = (__int64 *)*((_QWORD *)BugCheckParameter2 + 1);
if( v15 != (__int64 *)((char *)BugCheckParameter2 + 8) )
{
while( 1 )
{
v16 = *v15;
v17 = (_KWAIT_BLOCK *)v15;
v15 = (__int64 *)v16;
v30 = (__int64 *)v16;
Blink = (_KWAIT_BLOCK **)v17->WaitListEntry.Blink;
if( *(_KWAIT_BLOCK **)(v16 + 8) != v17 || *Blink != v17 )
goto LABEL_15;
*Blink = (_KWAIT_BLOCK *)v16;
*(_QWORD *)(v16 + 8) = Blink;
WaitType = v17->WaitType;
if( WaitType == 1 )
{
if( KiTryUnwaitThread(CurrentPrcb, v17, v17->WaitKey, (_KTHREAD **)&WakeThread) )
{
v20 = (*((_DWORD *)BugCheckParameter2 + 1))-- == 1;
if( v20 )
goto LABEL_40;
}
}
else if( WaitType == 2 )
{
v17->BlockState = 5;
Thread = v17->Thread;
v17->WaitListEntry.Flink = 0i64;
v22 = &Thread->Tcb.gap0[8];
KeGetCurrentIrql();
__writecr8(2ui64);
v23 = KeGetCurrentPrcb();
v24 = v23->CurrentThread;
KiAcquireKobjectLockSafe(Thread);
if( (_QWORD *)*v22 == v22
|| LODWORD(Thread->Tcb.InitialStack) >= HIDWORD(Thread->Tcb.InitialStack)
|| (_ETHREAD *)v24->Tcb.Queue == Thread && v24->Tcb.WaitReason == 15
|| (KiWakeQueueWaiter(v23, (_KQUEUE *)Thread, (INT64)v17), !v25) )
{
v26 = *(_DWORD *)&Thread->Tcb.gap0[4];
*(_DWORD *)&Thread->Tcb.gap0[4] = v26 + 1;
QuantumTarget = (_KWAIT_BLOCK **)Thread->Tcb.QuantumTarget;
if( *QuantumTarget != (_KWAIT_BLOCK *)&Thread->Tcb.SListFaultAddress )
goto LABEL_15;
v17->WaitListEntry.Flink = (_LIST_ENTRY *)&Thread->Tcb.SListFaultAddress;
v17->WaitListEntry.Blink = (_LIST_ENTRY *)QuantumTarget;
*QuantumTarget = v17;
Thread->Tcb.QuantumTarget = (unsigned __int64)v17;
if( !v26 && (_QWORD *)*v22 != v22 )
KiWakeOtherQueueWaiters(v23, (_KQUEUE *)Thread);
}
_InterlockedAnd((volatile signed __int32 *)Thread, 0xFFFFFF7F);
v20 = (*((_DWORD *)BugCheckParameter2 + 1))-- == 1;
if( v20 )
{
LABEL_40:
LOBYTE(OldIrql) = v37;
break;
}
v15 = v30;
CurrentPrcb = v28;
}
else
{
KiTryUnwaitThread(CurrentPrcb, v17, 256i64, 0i64);
}
if( v15 == (__int64 *)((char *)BugCheckParameter2 + 8) )
goto LABEL_40;
}
}
_InterlockedAnd((volatile signed __int32 *)BugCheckParameter2, 0xFFFFFF7F);
KiAcquireReleaseObjectRundownLockExclusive(BugCheckParameter2);
CurrentThread = v31;
CurrentPrcb = v28;
v5 = v35;
v3 = v36;
}
else
{
_InterlockedAnd((volatile signed __int32 *)BugCheckParameter2, 0xFFFFFF7F);
}
KiExitDispatcher(CurrentPrcb, 0i64, AdjustUnwait, 1i64, OldIrql);
if( v5 )
{
if( (_ETHREAD *)v4 == CurrentThread )
{
KeAbPostRelease(BugCheckParameter2);
}
else
{
KeAbCrossThreadDelete(BugCheckParameter2, (_KTHREAD *)v4);
result = ObfDereferenceObjectWithTag((VOID *)v4, 0x746C6644ui64);
}
}
if( (_ETHREAD *)v4 == CurrentThread )
{
if( v3 )
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
}
return result;
}Referenced by:
ExpDeleteMutant