FsRtlInsertPerFileContext
NTSTATUS __stdcall FsRtlInsertPerFileContext(VOID **PerFileContextPointer, _FSRTL_PER_FILE_CONTEXT *Ptr){
_EX_PUSH_LOCK *v4;
VOID **PoolWithTag;
_QWORD *v6;
signed __int64 v7;
_ETHREAD *CurrentThread;
_LIST_ENTRY *v9;
_LIST_ENTRY *bf_0;
if( !PerFileContextPointer )
return -1073741808;
v4 = (_EX_PUSH_LOCK *)_InterlockedCompareExchange64((volatile signed __int64 *)PerFileContextPointer, 0i64, 0i64);
if( !v4 )
{
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, 0x20ui64, 1667650374i64);
v4 = (_EX_PUSH_LOCK *)PoolWithTag;
if( !PoolWithTag )
return -1073741670;
*PoolWithTag = 0i64;
v6 = PoolWithTag + 1;
v4[3]._bf_0 = 0i64;
v6[1] = v6;
*v6 = v6;
v7 = _InterlockedCompareExchange64((volatile signed __int64 *)PerFileContextPointer, (signed __int64)v4, 0i64);
if( v7 )
{
ExFreePoolWithTag(v4, 0x63665346u);
v4 = (_EX_PUSH_LOCK *)v7;
}
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx(v4, 0i64);
v9 = (_LIST_ENTRY *)&v4[1];
bf_0 = (_LIST_ENTRY *)v4[1]._bf_0;
if( (_EX_PUSH_LOCK *)bf_0->Blink != &v4[1] )
__fastfail(3u);
Ptr->Links.Flink = bf_0;
Ptr->Links.Blink = v9;
bf_0->Blink = &Ptr->Links;
v9->Flink = &Ptr->Links;
ExReleasePushLockEx((ULONG_PTR)v4, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
return 0;
}Referenced by:
No references.