ExGetNextWakeTime
BOOL __fastcall ExGetNextWakeTime(UINT64 a1, UINT64 a2, CHAR a3, UINT64 *a4, UINT64 **WakeTimerInfo){
UINT64 v5;
INT64 v6;
UINT64 *v7;
__int64 v8;
__int64 *v9;
__int64 *v11;
UINT64 v12;
INT64 v13;
unsigned __int8 v14;
UINT64 TimerDueTime;
bool v16;
UINT64 *PoolWithTag;
BOOL result;
SIZE_T NumberOfBytes;
__int64 v20;
PKSPIN_LOCK SpinLock;
unsigned __int8 v22;
NumberOfBytes = 0i64;
v5 = a2;
v6 = 0i64;
v7 = 0i64;
v8 = *(_QWORD *)&KUSER_SHARED_DATA.SystemTime.LowPart;
v9 = (__int64 *)ExpWakeTimerList;
v20 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
if( (__int64 *)ExpWakeTimerList == &ExpWakeTimerList )
goto LABEL_21;
do
{
v11 = v9 - 33;
v9 = (__int64 *)*v9;
v12 = 0i64;
SpinLock = (PKSPIN_LOCK)(v11 + 8);
KeAcquireSpinLockRaiseToDpc((UINT64 *)v11 + 8, a2);
v13 = v11[32];
v22 = v14;
if( a3 && (v11[38] & 4) == 0 )
goto LABEL_12;
if( (v11[38] & 2) != 0 )
{
TimerDueTime = v11[39];
if( *((_BYTE *)v11 + 248) == 1 )
{
if( TimerDueTime )
v12 = TimerDueTime - v8 + v20;
goto LABEL_10;
}
}
else
{
TimerDueTime = KeQueryTimerDueTime((KTIMER *)v11);
}
v12 = TimerDueTime;
LABEL_10:
if( v12 < a1 )
v12 = 0i64;
LABEL_12:
KxReleaseSpinLock(SpinLock);
__writecr8(v22);
v16 = v12 - 1 < v5 - 1;
if( v12 - 1 >= v5 - 1 )
v12 = v5;
if( !v16 )
v13 = v6;
v6 = v13;
v5 = v12;
}
while( v9 != &ExpWakeTimerList );
v7 = 0i64;
if( v13 )
{
PoStoreDiagnosticContext(v13, 0i64, &NumberOfBytes);
PoolWithTag = (UINT64 *)ExAllocatePoolWithTag(PagedPool, NumberOfBytes, 0x53577254ui64);
v7 = PoolWithTag;
if( PoolWithTag )
{
if( (int)PoStoreDiagnosticContext(v13, PoolWithTag, &NumberOfBytes) < 0 )
{
ExFreePoolWithTag(v7, 0x53577254u);
v7 = 0i64;
}
}
}
LABEL_21:
*a4 = v5;
result = (int)WakeTimerInfo;
*WakeTimerInfo = v7;
LOBYTE(result) = v6 != 0;
return result;
}Referenced by:
PopIsWakeTimerImmanent
PopTransitionSystemPowerStateEx