PspRundownSingleProcess
UINT8 __stdcall PspRundownSingleProcess(_EPROCESS *Process, UINT8 ForceKill){
UINT8 v2;
_ETHREAD *CurrentThread;
_EX_PUSH_LOCK *p_ProcessLock;
_HANDLE_TABLE *v6;
UINT64 v7;
_RTL_BALANCED_NODE *Root;
_RTL_BALANCED_NODE *v9;
_RTL_BALANCED_NODE *v10;
unsigned __int64 ParentValue;
unsigned __int64 v12;
_RTL_BALANCED_NODE *v13;
_RTL_BALANCED_NODE *v14;
_RTL_BALANCED_NODE *v15;
unsigned __int64 v16;
unsigned __int64 v17;
_ADAPTER_OBJECT *SectionObject;
_FILE_OBJECT *ImageFilePointer;
void *UniqueProcessId;
_KAPC_STATE ApcState;
v2 = ForceKill;
memset(&ApcState, 0, sizeof(ApcState));
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( ForceKill )
goto LABEL_10;
--CurrentThread->Tcb.KernelApcDisable;
p_ProcessLock = &Process->ProcessLock;
ExAcquirePushLockExclusiveEx(&Process->ProcessLock, 0i64);
if( !Process->ActiveThreads )
{
_m_prefetchw(&Process->1124);
if( (_InterlockedOr((volatile signed __int32 *)&Process->1124, 0x2000008u) & 0x2000000) == 0 )
v2 = 1;
}
if( (_InterlockedExchangeAdd64(&p_ProcessLock->_bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(p_ProcessLock);
KeAbPostRelease(p_ProcessLock);
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
if( v2 )
{
LABEL_10:
ExWaitForRundownProtectionRelease(&Process->RundownProtect);
ExRundownCompleted((INT64 *)&Process->RundownProtect);
if( Process->Job && (Process->Flags2 & 1) == 0 )
{
RtlInterlockedSetClearBits((UINT64 *)&Process->Flags2, 8ui64, 0x20ui64);
PspSendProcessNotificationToJobChain(Process, v7, Process->UniqueProcessId);
}
if( Process->Pcb.SecureState )
KeRundownSecureProcess((INT64)Process);
if( (Process->Flags & 0x40000) != 0 )
{
KiStackAttachProcess(Process, 0i64, &ApcState);
if( Process->ObjectTable )
ObKillProcess(Process);
MmCleanProcessAddressSpace(Process);
KiUnstackDetachProcess(&ApcState, 0i64);
}
if( Process->EnclaveTable )
{
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx(&Process->EnclaveLock, 0i64);
ExFreePoolWithTag(*((PVOID *)Process->EnclaveTable + 1), 0);
ExFreePoolWithTag(Process->EnclaveTable, 0);
Process->EnclaveTable = 0i64;
if( (_InterlockedExchangeAdd64(&Process->EnclaveLock._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(&Process->EnclaveLock);
KeAbPostRelease(&Process->EnclaveLock);
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
}
Root = Process->DynamicEHContinuationTargetsTree.Root;
if( Root )
{
while( 1 )
{
while( 1 )
{
while( Root->Children[0] )
{
v9 = Root;
Root = Root->Children[0];
v9->Children[0] = 0i64;
}
if( !Root->Children[1] )
break;
v10 = Root;
Root = Root->Children[1];
v10->Children[1] = 0i64;
}
ParentValue = Root->ParentValue;
SC_ENV::Free(Root);
v12 = ParentValue & 0xFFFFFFFFFFFFFFFCui64;
if( !v12 )
break;
Root = (_RTL_BALANCED_NODE *)v12;
}
}
Process->DynamicEHContinuationTargetsTree.Root = 0i64;
v13 = Process->DynamicEnforcedCetCompatibleRanges.Tree.Root;
if( v13 )
{
while( 1 )
{
while( 1 )
{
while( v13->Children[0] )
{
v14 = v13;
v13 = v13->Children[0];
v14->Children[0] = 0i64;
}
if( !v13->Children[1] )
break;
v15 = v13;
v13 = v13->Children[1];
v15->Children[1] = 0i64;
}
v16 = v13->ParentValue;
SC_ENV::Free(v13);
v17 = v16 & 0xFFFFFFFFFFFFFFFCui64;
if( !v17 )
break;
v13 = (_RTL_BALANCED_NODE *)v17;
}
}
Process->DynamicEnforcedCetCompatibleRanges.Tree.Root = 0i64;
if( Process->PathRedirectionHashes )
{
ExFreePoolWithTag(Process->PathRedirectionHashes, 0);
Process->PathRedirectionHashes = 0i64;
}
SectionObject = (_ADAPTER_OBJECT *)Process->SectionObject;
if( SectionObject )
{
Process->SectionObject = 0i64;
HalPutDmaAdapter(SectionObject);
}
ImageFilePointer = Process->ImageFilePointer;
if( ImageFilePointer )
{
ObfDereferenceObjectWithTag(ImageFilePointer, 0x72437350ui64);
Process->ImageFilePointer = 0i64;
}
if( (Process->Flags & 0x40000) != 0 )
KeSetProcess();
if( Process->Job )
{
PspRemoveProcessFromJobChain(Process, 0i64, 4, 0i64);
PspNotifyEmptyJobsInJobChain(Process);
}
UniqueProcessId = Process->UniqueProcessId;
if( UniqueProcessId )
PspClearProcessThreadCidRefs(CurrentThread, UniqueProcessId, Process);
}
else
{
v6 = ObReferenceProcessHandleTable(Process);
if( v6 )
{
ExSweepHandleTable(Process, v6, 1u);
ExReleaseRundownProtection(&Process->RundownProtect);
}
}
return v2;
}Referenced by:
NtCreateUserProcess
PsCreateMinimalProcess
PsTerminateMinimalProcess
PspAllocateProcess
PspCreateProcess
PspExitThread
PspProcessRundownWorker
PspProcessRundownWorkerSingle
PspTerminateAllThreads
PspTerminateProcess