PspEstablishDfssHierarchy

INT64 __fastcall PspEstablishDfssHierarchy(INT64 a1, INT64 a2, INT64 a3){
  INT64 result; 
  _KSCHEDULING_GROUP *SessionSchedulingGroupByProcess; 
  _EPROCESS *v6; 
  int v7; 
  void *v8; 
  void *v9; 
  result = (unsigned int)(a3 - 1);
  if( (result & 0xFFFFFFFD) == 0 )
  {
    SessionSchedulingGroupByProcess = (_KSCHEDULING_GROUP *)MmGetSessionSchedulingGroupByProcess(a2);
    LODWORD(result) = MmGetSessionObjectByProcess(v6);
    v8 = (void *)result;
    if( *(_QWORD *)(*(_QWORD *)(a1 + 1080) + 1008i64)
      || *(_KSCHEDULING_GROUP **)(a1 + 1016) == SessionSchedulingGroupByProcess )
    {
      if( v7 == 1 )
      {
        result = *(_QWORD *)(a1 + 1080);
        if( result == a1 && *(_QWORD *)(a1 + 1008) && !*(_DWORD *)(a1 + 216) && *(void **)(a1 + 1112) != v8 )
        {
          KeRemoveSchedulingGroup(*(UINT16 **)(a1 + 1016));
          KeInsertSchedulingGroup(
            (_KSCHEDULING_GROUP *)(*(_QWORD *)(a1 + 1008) + 128i64),
            *(_KSCHEDULING_GROUP_POLICY *)(*(_QWORD *)(a1 + 1008) + 128i64),
            SessionSchedulingGroupByProcess);
          v9 = *(void **)(a1 + 1112);
          if( v9 )
            ObfDereferenceObjectWithTag(v9, 0x624A7350ui64);
          *(_QWORD *)(a1 + 1112) = v8;
          return ObfReferenceObjectWithTag(v8, 0x624A7350u);
        }
      }
    }
    else
    {
      if( *(_KSCHEDULING_GROUP **)(*(_QWORD *)(a1 + 1080) + 1016i64) != SessionSchedulingGroupByProcess )
      {
        *(_QWORD *)(*(_QWORD *)(a1 + 1080) + 1016i64) = SessionSchedulingGroupByProcess;
        result = *(_QWORD *)(a1 + 1080);
        *(_QWORD *)(result + 1112) = v8;
      }
      *(_QWORD *)(a1 + 1016) = SessionSchedulingGroupByProcess;
    }
  }
  return result;
}

Referenced by:

PspEstablishJobHierarchy