FsRtlpAllocateOplock
CHAR *__stdcall FsRtlpAllocateOplock(){
_KEVENT *v0;
_QWORD *PoolWithTag;
PoolWithTag = ExAllocatePoolWithTag((_POOL_TYPE)17, 0xA0ui64, 0x6F725346ui64);
memset((INT64)PoolWithTag, 0i64);
v0 = (_KEVENT *)ExAllocatePoolWithTag((_POOL_TYPE)528, 0x38ui64, 0x6F725346ui64);
PoolWithTag[19] = v0;
v0->Header.LockNV = 1;
v0->Header.WaitListHead.Flink = 0i64;
LODWORD(v0->Header.WaitListHead.Blink) = 0;
KeInitializeEvent(v0 + 1, SynchronizationEvent, 0);
PoolWithTag[6] = PoolWithTag + 5;
PoolWithTag[5] = PoolWithTag + 5;
PoolWithTag[8] = PoolWithTag + 7;
PoolWithTag[7] = PoolWithTag + 7;
PoolWithTag[10] = PoolWithTag + 9;
PoolWithTag[9] = PoolWithTag + 9;
PoolWithTag[12] = PoolWithTag + 11;
PoolWithTag[11] = PoolWithTag + 11;
PoolWithTag[14] = PoolWithTag + 13;
PoolWithTag[13] = PoolWithTag + 13;
PoolWithTag[16] = PoolWithTag + 15;
PoolWithTag[15] = PoolWithTag + 15;
*((_DWORD *)PoolWithTag + 36) = 1;
return(CHAR *)PoolWithTag;
}Referenced by:
FsRtlpOplockFsctrlInternal
FsRtlpOplockStoreKeyForDeleteOperation
FsRtlpRequestExclusiveOplock
FsRtlpRequestShareableOplock