MiDeleteHotPatchRecord
NTSTATUS __stdcall MiDeleteHotPatchRecord(_RTL_BALANCED_NODE **Tree, ULONG_PTR a2, INT64 a3, INT64 a4){
INT64 *v4;
_ETHREAD *CurrentThread;
INT64 *v8;
NTSTATUS v9;
int v10;
INT64 v12[3];
int v13;
int v14;
__int128 v15;
v4 = 0i64;
v13 = a3;
v14 = a4;
memset(v12, 0, sizeof(v12));
v15 = 0i64;
if( a2 )
{
CurrentThread = 0i64;
}
else
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.SpecialApcDisable;
ExAcquirePushLockExclusiveEx(&MiHotPatchListLock, *(UINT64 *)&a2);
}
v8 = (INT64 *)*Tree;
if( *Tree )
{
do
{
v9 = MiCompareHotPatchNodes((INT64)v12, (INT64)v8);
if( v9 >= 0 )
{
if( v9 <= 0 )
break;
v8 = (INT64 *)v8[1];
}
else
{
v8 = (INT64 *)*v8;
}
}
while( v8 );
if( v8 )
{
v4 = v8;
RtlAvlRemoveNode((UINT64 *)Tree, v8);
v10 = 1;
if( MiHotPatchGeneration != -1 )
v10 = MiHotPatchGeneration + 1;
MiHotPatchGeneration = v10;
}
}
if( !a2 )
{
if( (_InterlockedExchangeAdd64(&MiHotPatchListLock._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(&MiHotPatchListLock);
KeAbPostRelease(&MiHotPatchListLock);
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
}
if( !v4 )
return 0;
ExFreePoolWithTag(v4, 0);
return 1;
}Referenced by:
MiUnloadHotPatch
MiUnloadHotPatchForUserSid