KiAbEntryRemoveFromTree
__int64 __fastcall KiAbEntryRemoveFromTree(unsigned __int64 a1){
__int64 v2;
INT64 *v3;
unsigned __int64 *v4;
unsigned __int8 CurrentIrql;
int i;
WORK_QUEUE_TYPE v7;
void *v8;
unsigned __int64 v9;
unsigned __int64 v10;
int v11;
unsigned __int64 v12;
unsigned int v13;
unsigned __int64 v14;
unsigned __int64 *v15;
char v16;
unsigned __int64 v17;
__int64 result;
unsigned __int64 v19;
WORK_QUEUE_TYPE v20;
PVOID v21;
__int64 v22;
unsigned __int64 v23;
unsigned int v24;
struct _IO_WORKITEM LockHandle;
v24 = *(_DWORD *)(a1 + 40);
v23 = *(_QWORD *)(a1 + 32) & 0x7FFFFFFFFFFFFFFCi64;
v2 = ((v23 >> 4) & 0x3FF) << 6;
memset(&LockHandle, 0, 48);
v3 = (__int64 *)((char *)&KiAbTreeArray[2] + v2);
v4 = (unsigned __int64 *)((char *)KiAbTreeArray + v2);
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
for( i = *(_BYTE *)(a1 + 27) & 1; ; i = 1 )
{
if( i )
ExAcquireSpinLockExclusiveAtDpcLevel(v3);
else
ExAcquireSpinLockSharedAtDpcLevel((PEX_SPIN_LOCK)v3);
v9 = v4[1];
v10 = *v4;
if( (v9 & 1) != 0 && v10 )
v10 ^= (unsigned __int64)v4;
v11 = v9 & 1;
while( v10 )
{
v12 = *(_QWORD *)(v10 + 32) & 0x7FFFFFFFFFFFFFFCi64;
if( v12 < v23 )
goto LABEL_27;
if( v12 > v23 )
goto LABEL_12;
v13 = *(_DWORD *)(v10 + 40);
if( v13 == v24 )
break;
if( v13 < v24 )
{
LABEL_27:
v14 = *(_QWORD *)(v10 + 8);
if( v11 && v14 )
{
LABEL_31:
v10 ^= v14;
continue;
}
}
else
{
LABEL_12:
v14 = *(_QWORD *)v10;
if( v11 && v14 )
goto LABEL_31;
}
v10 = v14;
}
LockHandle.WorkItem.List.Flink = 0i64;
LockHandle.WorkItem.List.Blink = (_LIST_ENTRY *)(v10 + 80);
KxAcquireQueuedSpinLock(&LockHandle, (PIO_WORKITEM_ROUTINE)(v10 + 80), v7, v8);
if( v10 != a1 )
break;
if( i )
{
if( *(_QWORD *)(v10 + 64) )
{
v15 = (unsigned __int64 *)(v10 + 64);
}
else
{
v15 = (unsigned __int64 *)(v10 + 48);
if( !*(_QWORD *)(v10 + 48) )
goto LABEL_19;
}
if( v15 )
{
v19 = *v15;
RtlRbRemoveNode(v15, *v15);
RtlRbReplaceNode(v4, v10, v19);
LockHandle.WorkItem.Parameter = 0i64;
LockHandle.Routine = (void(__fastcall *)(void *, void *, _IO_WORKITEM *))(v19 + 80);
KxAcquireQueuedSpinLock(
(PIO_WORKITEM)&LockHandle.WorkItem.Parameter,
(PIO_WORKITEM_ROUTINE)(v19 + 80),
v20,
v21);
ExReleaseSpinLockExclusiveFromDpcLevel(v3);
*(_OWORD *)(v19 + 48) = *(_OWORD *)(v10 + 48);
*(_OWORD *)(v19 + 64) = *(_OWORD *)(v10 + 64);
*(_WORD *)(v19 + 90) ^= (*(_WORD *)(v19 + 90) ^ *(_WORD *)(v10 + 90)) & 0x1FE;
*(_WORD *)(v19 + 90) = *(_WORD *)(v10 + 90) ^ (*(_WORD *)(v19 + 90) ^ *(_WORD *)(v10 + 90)) & 0x1FF;
KiAbTryDecrementIoWaiterCounts((_KLOCK_ENTRY *)v10, (_KLOCK_ENTRY *)v19);
*(_BYTE *)(v19 + 27) |= 1u;
KeReleaseInStackQueuedSpinLockFromDpcLevel((_KLOCK_QUEUE_HANDLE *)&LockHandle.WorkItem.Parameter);
}
else
{
LABEL_19:
RtlRbRemoveNode(v4, v10);
ExReleaseSpinLockExclusiveFromDpcLevel(v3);
v16 = *(_BYTE *)(v10 + 27);
if( (v16 & 2) != 0 )
{
*(_WORD *)(v10 + 90) ^= (*(_WORD *)(v10 + 90) ^ (2 * ((*(_WORD *)(v10 + 90) >> 1) - 1))) & 0x1FE;
*(_BYTE *)(v10 + 27) &= ~2u;
v16 = *(_BYTE *)(v10 + 27);
}
if( (v16 & 4) != 0 )
{
*(_WORD *)(v10 + 90) = *(_WORD *)(v10 + 90) & 0x1FF | (((*(_WORD *)(v10 + 90) >> 9) - 1) << 9);
*(_BYTE *)(v10 + 27) &= ~4u;
}
}
*(_BYTE *)(v10 + 39) &= ~0x80u;
*(_BYTE *)(v10 + 27) &= ~1u;
goto LABEL_24;
}
ExReleaseSpinLockSharedFromDpcLevel((PEX_SPIN_LOCK)v3);
KeReleaseInStackQueuedSpinLockFromDpcLevel((_KLOCK_QUEUE_HANDLE *)&LockHandle);
}
if( i )
ExReleaseSpinLockExclusiveFromDpcLevel(v3);
else
ExReleaseSpinLockSharedFromDpcLevel((PEX_SPIN_LOCK)v3);
*(_BYTE *)(a1 + 39) &= ~0x80u;
if( (*(_BYTE *)(a1 + 25) & 1) != 0 )
{
KiAbTryDecrementIoWaiterCounts((_KLOCK_ENTRY *)a1, (_KLOCK_ENTRY *)v10);
v22 = 64i64;
}
else
{
v22 = 48i64;
}
RtlRbRemoveNode((unsigned __int64 *)(v10 + v22), a1);
LABEL_24:
KeReleaseInStackQueuedSpinLockFromDpcLevel((_KLOCK_QUEUE_HANDLE *)&LockHandle);
v17 = a1 - 16i64 * *(unsigned __int8 *)(a1 + 24);
if( (*(_BYTE *)(a1 + 25) & 1) != 0 )
--*(_BYTE *)(v17 + 793);
else
_InterlockedExchangeAdd8((volatile signed __int8 *)(v17 + 871), 0xFFu);
result = CurrentIrql;
__writecr8(CurrentIrql);
return result;
}Referenced by:
CcAmILowPriorityWriter
CcApplyLowIoPriorityToThread
CcBoostLowPriorityWorkerThread
CcChangeBackingFileObject
EmpParseInfDatabase
EmpQueueRuleUpdateState
EmpRuleUpdateWorkerThread
EtwpBufferingModeCompressionFlush
EtwpCompressPendingBuffers
EtwpCompressionProc
EtwpDisableCompression
EtwpFreeCompression
EtwpSetCompressionSettings
ExDisableHandleTracing
ExGetWakeTimerList
ExQueryHandleExceptionsPermanency
ExReleaseCacheAwarePushLockSharedEx
ExReleasePushLockEx
ExReleasePushLockExclusiveEx
ExShareAddressSpaceWithDevice
ExSvmBeginDeviceReset
ExSvmFinalizeDeviceReset
ExpDeleteTimer
ExpSaAllocatorAllocate
ExpSaAllocatorFree
ExpSaPageGroupAllocateMemory
ExpSaPageGroupDescriptorAllocate
ExpSaPageGroupDescriptorFree
ExpSaPageGroupFreeMemory
ExpSetTimerObject
ExpSvmDereferenceDevice
FlushLookUpTableBucket
HalpIommuBlockDevice
HalpIommuUnblockDevice
HalpLeaveDmaDomain
IommuBeginDeviceReset
IommuFinalizeDeviceReset
IopReleaseFileObjectLock
KeAbEntryFree
KeAbPostRelease
KeAbPreAcquire
KeAbPreWait
KiAbCrossThreadRelease
KsepShimDbChanged
MI_UNLOCK_RELOCATIONS_EXCLUSIVE
MiAddViewsForSection
MiClearPartitionPageBitMap
MiCommitPageTableRangesForVad
MiContractWsSwapPageFileWorker
MiCreatePrototypePtes
MiDecommitHardwareEnclavePages
MiDeletePartialVad
MiDeletePartitionResources
MiDereferenceExtendInfo
MiExpandPtes
MiFinishVadDeletion
MiFreeUnusedPfnPages
MiIncrementAweMapCount
MiInitializeMirroring
MiInitializePagedPoolEvents
MiInsertInSystemSpace
MiMarkSystemVaAllocated
MiObtainSessionVa
MiObtainSystemCacheView
MiReleaseSessionVa
MiRemoveFromSystemSpace
MiRemovePlaceholderVad
MiTrimUnusedPageFileRegionsWorker
MiUnlockAndDereferenceVad
MiUnlockDriverMappings
MiUnlockDynamicMemoryExclusive
MiUnlockDynamicMemoryNestedParentExclusive
MiUnlockLoaderEntry
MiUnlockPartitionSystemThreads
MiUnlockVad
MiUpControlAreaRefs
MmOutSwapVirtualAddresses
MmOutSwapWorkingSet
NormalizationList__Unlock
NtCancelTimer
PfFileInfoNotify
PfLockExclusiveRelease
PfTSetTraceWorkerPriority
PopDirectedDripsDiagTraceNotifyDevices
PopDirectedDripsNotifyResiliencyCompletionWorker
PopFxBuildDirectedDripsCandidateDeviceList
PopFxBuildDripsBlockingDeviceList
PopFxClearDirectedDripsCandidateDeviceList
PopFxInsertAcpiDevice
PopFxPrepareDevicesForShutdown
PopFxRegisterPluginEx
PopFxRemoveAcpiDevice
PopFxRemoveDevice
PopPepPlatformStateRegistered
PopPepRemoveDevice
PsAdjustBasicEnclaveThreadList
PsGetProcessEnclaveModuleInfo
PsLoadVsmEnclaveData
PspStorageEmptyArrayNonReadonly
PspUnlockAffinityUpdateExclusive
PspUnlockProcessExclusive
PspUnlockProcessExclusiveUnsafe
PspUnlockProcessListExclusive
PspUnlockQuotaExpansion
PspUnlockQuotaListExclusive
PspUnlockThreadSecurityExclusive
PspUnlockWorkingSetChangeExclusiveUnsafe
RtlInsertDynamicFunctionTable
RtlRemoveDynamicFunctionTable
RtlpCSparseBitmapUnlock
RtlpHpAcquireReleaseLockExclusive
RtlpHpFixedVsAllocate
RtlpHpFixedVsFree
RtlpHpHeapExtendContext
RtlpHpLargeAlloc
RtlpHpLargeFree
RtlpHpLfhBucketAddSubsegment
RtlpHpLfhBucketGetSubsegment
RtlpHpLfhBucketUpdateAffinityMapping
RtlpHpLfhSlotAllocate
RtlpHpLfhSubsegmentDecommitPages
RtlpHpLfhSubsegmentFreeBlock
RtlpHpLfhSubsegmentIncBlockCounts
RtlpHpReleaseQueuedLockExclusive
RtlpHpSegContextCompact
RtlpHpSegMgrCommitComplete
RtlpHpSegMgrCommitInitiate
RtlpHpSegMgrVaCtxAlloc
RtlpHpSegMgrVaCtxFree
RtlpHpSegMgrVaCtxInsert
RtlpHpSegPageRangeAllocate
RtlpHpSegPageRangeCoalesce
RtlpHpSegPageRangeShrink
RtlpHpVaMgrAlloc
RtlpHpVaMgrCtxFree
RtlpHpVsChunkSplit
RtlpHpVsSubsegmentCommitPages
SMKM_STORE::SmStCleanup
SMKM_STORE::SmStHelperSendCommand
SMKM_STORE::SmStWorker
SMKM_STORE_MGR::SmFeAddInitiate
SMKM_STORE_MGR::SmFeEmpty
SMKM_STORE_MGR::SmFeEvictComplete
SMKM_STORE_MGR::SmFeEvictInitiate
SMKM_STORE_MGR::SmFeSetEvictFailed
SMKM_STORE_MGR::SmFeStoreDelete
SMKM_STORE_MGR::SmFeStoreEvictKeys
SSHSupportReleasePushLockExclusive
ST_STORE::StDmPageRemove
ST_STORE::StDmpSinglePageAdd
SeRegisterObjectTypeMandatoryPolicy
SepDeleteSessionLowboxEntries
SmFirstTimeInit
SmKmVirtualLockContextIncreaseWsMin
SmKmVirtualLockCtxMemoryUnlocked
SmpKeyedStoreEntryGet
SmpKeyedStoreSetVaRanges
SshpSetCollectionActive
UNLOCK_ADDRESS_SPACE
UNLOCK_ADDRESS_SPACE_UNORDERED
UNLOCK_PAGE_TABLE_COMMITMENT
WheaInitialize