NtRollbackRegistryTransaction

NTSTATUS __stdcall NtRollbackRegistryTransaction(PVOID TransactionHandle, UINT64 Flags){
  int v2; 
  _ETHREAD *CurrentThread; 
  NTSTATUS v5; 
  struct _DMA_ADAPTER *v6; 
  NTSTATUS v7; 
  PVOID Object; 
  KAPC_STATE ApcState; 
  v2 = Flags;
  memset(&ApcState, 0, sizeof(ApcState));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown) )
  {
    if( v2 )
    {
      v7 = -1073741811;
    }
    else
    {
      Object = 0i64;
      v5 = ObReferenceObjectByHandle(
             TransactionHandle,
             0x10u,
             CmRegistryTransactionType,
             *((_BYTE *)KeGetCurrentThread() + 562),
             &Object,
             0i64);
      v6 = (struct _DMA_ADAPTER *)Object;
      v7 = v5;
      if( v5 >= 0 )
      {
        CmpAttachToRegistryProcess(&ApcState);
        v7 = CmpRollbackLightWeightTransaction((INT64)v6);
        KiUnstackDetachProcess(&ApcState, 0i64);
        if( v7 >= 0 )
          v7 = 0;
      }
      if( v6 )
        HalPutDmaAdapter(v6);
    }
    ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  }
  else
  {
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    return -1073741431;
  }
  return v7;
}

Referenced by:

No references.