FsRtlAcquireFileForCcFlushEx
NTSTATUS __stdcall FsRtlAcquireFileForCcFlushEx(FILE_OBJECT *FileObject){
int v2;
INT64 *v3;
char v4;
BOOL v5;
__int64 v6;
_DEVICE_OBJECT *BaseFileSystemDeviceObject;
int v8;
__int64 v9;
__int64 v10;
__int64 v11;
NTSTATUS v12;
_ETHREAD *CurrentThread;
char v14;
__int64(__fastcall *v15)(FILE_OBJECT *, _DEVICE_OBJECT *);
_ETHREAD *v16;
__int64 v17;
void *FsContext;
struct _ERESOURCE *v19;
ULONG IsResourceAcquiredSharedLite;
ERESOURCE *v21;
BOOL v22;
struct _ERESOURCE *v23;
_DWORD a4[2];
_DEVICE_OBJECT *RelatedDeviceObject;
INT64 result[8];
char v27;
memset((INT64)result, 0i64);
v2 = 0;
v3 = result;
a4[1] = 0;
v4 = 0;
RelatedDeviceObject = IoGetRelatedDeviceObject(FileObject);
BaseFileSystemDeviceObject = IoGetBaseFileSystemDeviceObject(FileObject);
v8 = 0;
v9 = *((_QWORD *)BaseFileSystemDeviceObject + 1);
v10 = *(_QWORD *)(v9 + 80);
v11 = *(_QWORD *)(*(_QWORD *)(v9 + 48) + 48i64);
if( v11 && (*(_DWORD *)v11 >= 0x30u && *(_QWORD *)(v11 + 40) || *(_DWORD *)v11 >= 0x38u && *(_QWORD *)(v11 + 48)) )
v4 = 1;
if( RelatedDeviceObject != BaseFileSystemDeviceObject || v4 )
{
v12 = FsFilterCtrlInit((__int64)result, 251, (__int64)RelatedDeviceObject, v6, (__int64)FileObject, 1);
if( v12 < 0 )
return v12;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v2 = FsFilterPerformCallbacks((INT64)result, 1, 1, &a4[1]);
v8 = 0;
}
else
{
v16 = (_ETHREAD *)KeGetCurrentThread();
v3 = 0i64;
--*((_WORD *)v16 + 242);
}
if( v2 >= 0 )
{
if( v2 )
{
if( v2 != 294 )
v8 = v2;
v2 = v8;
}
else
{
if( v3 && (FileObject = (FILE_OBJECT *)result[2], (v27 & 4) != 0) )
{
BaseFileSystemDeviceObject = IoGetDeviceAttachmentBaseRef((_DEVICE_OBJECT *)result[1]);
v14 = 1;
v17 = *((_QWORD *)BaseFileSystemDeviceObject + 1);
v10 = *(_QWORD *)(v17 + 80);
v11 = *(_QWORD *)(*(_QWORD *)(v17 + 48) + 48i64);
}
else
{
v14 = 0;
}
if( !v11
|| (*(_DWORD *)v11 < 0x30u || !*(_QWORD *)(v11 + 40)) && (*(_DWORD *)v11 < 0x38u || !*(_QWORD *)(v11 + 48)) )
{
if( v10
&& *(_DWORD *)v10 >= 0xD8u
&& (v15 = *(__int64(__fastcall **)(FILE_OBJECT *, _DEVICE_OBJECT *))(v10 + 208)) != 0i64 )
{
v2 = v15(FileObject, BaseFileSystemDeviceObject);
}
else
{
v2 = -1073741808;
}
a4[1] |= 1u;
}
if( v14 )
HalPutDmaAdapter((PADAPTER_OBJECT)BaseFileSystemDeviceObject);
}
}
if( v2 == -1073741808 && (a4[1] & 1) != 0 )
{
FsContext = FileObject->FsContext;
v19 = (struct _ERESOURCE *)*((_QWORD *)FsContext + 1);
if( v19 )
{
IsResourceAcquiredSharedLite = ExIsResourceAcquiredSharedLite(v19);
v21 = (ERESOURCE *)*((_QWORD *)FsContext + 1);
LOBYTE(v22) = 1;
if( IsResourceAcquiredSharedLite )
ExAcquireResourceSharedLite(v21, v22);
else
ExAcquireResourceExclusiveLite(v21, 1u);
}
v23 = (struct _ERESOURCE *)*((_QWORD *)FsContext + 2);
if( v23 )
{
LOBYTE(v5) = 1;
ExAcquireResourceSharedLite(v23, v5);
}
v2 = 0;
}
if( v3 )
{
if( *((_WORD *)v3 + 37) )
FsFilterPerformCompletionCallbacks((__int64)result, v2);
FsFilterCtrlFree((__int64)result);
}
if( v2 < 0 )
KeLeaveCriticalRegion();
return v2;
}Referenced by:
MiDeleteCachedSubsection
MiFlushControlArea
MmFlushSection
MmFlushVirtualMemory