PspRundownSingleProcess

UINT8 __stdcall PspRundownSingleProcess(_EPROCESS *Process, UINT8 ForceKill){
  UINT8 v2; 
  _ETHREAD *CurrentThread; 
  _EX_PUSH_LOCK *p_ProcessLock; 
  _HANDLE_TABLE *v6; 
  UINT64 v7; 
  _RTL_BALANCED_NODE *Root; 
  _RTL_BALANCED_NODE *v9; 
  _RTL_BALANCED_NODE *v10; 
  unsigned __int64 ParentValue; 
  unsigned __int64 v12; 
  _RTL_BALANCED_NODE *v13; 
  _RTL_BALANCED_NODE *v14; 
  _RTL_BALANCED_NODE *v15; 
  unsigned __int64 v16; 
  unsigned __int64 v17; 
  _ADAPTER_OBJECT *SectionObject; 
  _FILE_OBJECT *ImageFilePointer; 
  void *UniqueProcessId; 
  _KAPC_STATE ApcState; 

  v2 = ForceKill;
  memset(&ApcState, 0, sizeof(ApcState));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  if( ForceKill )
    goto LABEL_10;
  --CurrentThread->Tcb.KernelApcDisable;
  p_ProcessLock = &Process->ProcessLock;
  ExAcquirePushLockExclusiveEx(&Process->ProcessLock, 0i64);
  if( !Process->ActiveThreads )
  {
    _m_prefetchw(&Process->1124);
    if( (_InterlockedOr((volatile signed __int32 *)&Process->1124, 0x2000008u) & 0x2000000) == 0 )
      v2 = 1;
  }
  if( (_InterlockedExchangeAdd64(&p_ProcessLock->_bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock(p_ProcessLock);
  KeAbPostRelease(p_ProcessLock);
  KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
  if( v2 )
  {
LABEL_10:
    ExWaitForRundownProtectionRelease(&Process->RundownProtect);
    ExRundownCompleted((INT64 *)&Process->RundownProtect);
    if( Process->Job && (Process->Flags2 & 1) == 0 )
    {
      RtlInterlockedSetClearBits((UINT64 *)&Process->Flags2, 8ui64, 0x20ui64);
      PspSendProcessNotificationToJobChain(Process, v7, Process->UniqueProcessId);
    }
    if( Process->Pcb.SecureState )
      KeRundownSecureProcess((INT64)Process);
    if( (Process->Flags & 0x40000) != 0 )
    {
      KiStackAttachProcess(Process, 0i64, &ApcState);
      if( Process->ObjectTable )
        ObKillProcess(Process);
      MmCleanProcessAddressSpace(Process);
      KiUnstackDetachProcess(&ApcState, 0i64);
    }
    if( Process->EnclaveTable )
    {
      --CurrentThread->Tcb.KernelApcDisable;
      ExAcquirePushLockExclusiveEx(&Process->EnclaveLock, 0i64);
      ExFreePoolWithTag(*((PVOID *)Process->EnclaveTable + 1), 0);
      ExFreePoolWithTag(Process->EnclaveTable, 0);
      Process->EnclaveTable = 0i64;
      if( (_InterlockedExchangeAdd64(&Process->EnclaveLock._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
        ExfTryToWakePushLock(&Process->EnclaveLock);
      KeAbPostRelease(&Process->EnclaveLock);
      KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
    }
    Root = Process->DynamicEHContinuationTargetsTree.Root;
    if( Root )
    {
      while( 1 )
      {
        while( 1 )
        {
          while( Root->Children[0] )
          {
            v9 = Root;
            Root = Root->Children[0];
            v9->Children[0] = 0i64;
          }
          if( !Root->Children[1] )
            break;
          v10 = Root;
          Root = Root->Children[1];
          v10->Children[1] = 0i64;
        }
        ParentValue = Root->ParentValue;
        SC_ENV::Free(Root);
        v12 = ParentValue & 0xFFFFFFFFFFFFFFFCui64;
        if( !v12 )
          break;
        Root = (_RTL_BALANCED_NODE *)v12;
      }
    }
    Process->DynamicEHContinuationTargetsTree.Root = 0i64;
    v13 = Process->DynamicEnforcedCetCompatibleRanges.Tree.Root;
    if( v13 )
    {
      while( 1 )
      {
        while( 1 )
        {
          while( v13->Children[0] )
          {
            v14 = v13;
            v13 = v13->Children[0];
            v14->Children[0] = 0i64;
          }
          if( !v13->Children[1] )
            break;
          v15 = v13;
          v13 = v13->Children[1];
          v15->Children[1] = 0i64;
        }
        v16 = v13->ParentValue;
        SC_ENV::Free(v13);
        v17 = v16 & 0xFFFFFFFFFFFFFFFCui64;
        if( !v17 )
          break;
        v13 = (_RTL_BALANCED_NODE *)v17;
      }
    }
    Process->DynamicEnforcedCetCompatibleRanges.Tree.Root = 0i64;
    if( Process->PathRedirectionHashes )
    {
      ExFreePoolWithTag(Process->PathRedirectionHashes, 0);
      Process->PathRedirectionHashes = 0i64;
    }
    SectionObject = (_ADAPTER_OBJECT *)Process->SectionObject;
    if( SectionObject )
    {
      Process->SectionObject = 0i64;
      HalPutDmaAdapter(SectionObject);
    }
    ImageFilePointer = Process->ImageFilePointer;
    if( ImageFilePointer )
    {
      ObfDereferenceObjectWithTag(ImageFilePointer, 0x72437350ui64);
      Process->ImageFilePointer = 0i64;
    }
    if( (Process->Flags & 0x40000) != 0 )
      KeSetProcess();
    if( Process->Job )
    {
      PspRemoveProcessFromJobChain(Process, 0i64, 4, 0i64);
      PspNotifyEmptyJobsInJobChain(Process);
    }
    UniqueProcessId = Process->UniqueProcessId;
    if( UniqueProcessId )
      PspClearProcessThreadCidRefs(CurrentThread, UniqueProcessId, Process);
  }
  else
  {
    v6 = ObReferenceProcessHandleTable(Process);
    if( v6 )
    {
      ExSweepHandleTable(Process, v6, 1u);
      ExReleaseRundownProtection(&Process->RundownProtect);
    }
  }
  return v2;
}

Referenced by:

NtCreateUserProcess
PsCreateMinimalProcess
PsTerminateMinimalProcess
PspAllocateProcess
PspCreateProcess
PspExitThread
PspProcessRundownWorker
PspProcessRundownWorkerSingle
PspTerminateAllThreads
PspTerminateProcess