MiDeleteImageHotPatchState

VOID __fastcall MiDeleteImageHotPatchState(UINT64 a1){
  _ETHREAD *CurrentThread; 
  _QWORD *ProcessHotPatchContext; 
  unsigned __int64 v4; 
  void *v5; 
  volatile INT64 *v6; 
  unsigned __int64 v7; 
  int v8; 
  int v9; 
  unsigned __int64 v10; 
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  ProcessHotPatchContext = MiGetProcessHotPatchContext(*((_QWORD *)CurrentThread + 23), 0i64);
  v4 = (unsigned __int64)ProcessHotPatchContext;
  if( ProcessHotPatchContext )
  {
    v5 = 0i64;
    --*((_WORD *)CurrentThread + 243);
    v6 = ProcessHotPatchContext + 2;
    ExAcquirePushLockExclusiveEx((UINT64)(ProcessHotPatchContext + 2), 0i64);
    v7 = *(_QWORD *)v4;
    if( (*(_BYTE *)(v4 + 8) & 1) != 0 )
    {
      if( v7 )
        v7 ^= v4;
      else
        v7 = 0i64;
    }
    v8 = *(_BYTE *)(v4 + 8) & 1;
    if( v7 )
    {
      do
      {
        v9 = MiHotPatchImageTreeCompare(a1, v7);
        if( v9 >= 0 )
        {
          if( v9 <= 0 )
            break;
          v10 = *(_QWORD *)(v7 + 8);
        }
        else
        {
          v10 = *(_QWORD *)v7;
        }
        if( v8 && v10 )
          v7 ^= v10;
        else
          v7 = v10;
      }
      while( v7 );
      v6 = (volatile INT64 *)(v4 + 16);
      if( v7 )
      {
        RtlRbRemoveNode((unsigned __int64 *)v4, v7);
        *(_DWORD *)(v7 + 92) |= 2u;
        v5 = (void *)v7;
        if( (*(_DWORD *)(v7 + 92) & 1) != 0 )
          v5 = 0i64;
      }
    }
    if( (_InterlockedExchangeAdd64(v6, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
      ExfTryToWakePushLock(v6);
    KeAbPostRelease((PVOID)v6);
    KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
    if( v5 )
      MiDeleteHotPatchEntry(v5);
  }
}

Referenced by:

MiFinishVadDeletion
MiHotPatchImage