PerfLogSpinLockRelease
VOID __stdcall PerfLogSpinLockRelease(PVOID SpinLockAddress, PVOID CallerAddress, UINT64 ReleaseTime){
struct _KPRCB *CurrentPrcb;
__int64 v7;
char v8;
unsigned __int8 v9;
struct _KPRCB *v10;
__int64 v11;
unsigned int v12;
char v13;
unsigned __int8 CurrentIrql;
char v15;
char v16;
unsigned __int8 v17;
__int64 v18;
__int128 v19;
UINT64 Flag;
__int128 v21;
__int128 v22;
__int128 v23;
__int64 v24;
EVENT_DATA_DESCRIPTOR EventData;
v21 = 0i64;
v24 = 0i64;
v22 = 0i64;
v23 = 0i64;
CurrentPrcb = KeGetCurrentPrcb();
v7 = *((_QWORD *)CurrentPrcb + 4197) + 16i64;
v8 = *(_BYTE *)(*((_QWORD *)CurrentPrcb + 4197) + 272i64);
if( v8 )
{
v9 = *(_BYTE *)(*((_QWORD *)CurrentPrcb + 4197) + 272i64);
while( *(PVOID *)(32i64 * --v9 + v7 + 8) != SpinLockAddress )
{
if( !v9 )
{
++*(_DWORD *)(*((_QWORD *)CurrentPrcb + 4197) + 280i64);
return;
}
}
v10 = KeGetCurrentPrcb();
v11 = 32i64 * v9 + v7;
if( *(_BYTE *)(*((_QWORD *)CurrentPrcb + 4197) + 273i64) )
goto LABEL_20;
if( !*(_DWORD *)EtwpSpinLockHoldThreshold
|| (unsigned int)(ReleaseTime - *(_DWORD *)v11) <= *(_DWORD *)EtwpSpinLockHoldThreshold )
{
v12 = *(_DWORD *)(v11 + 20);
if( (v12 < EtwpSpinLockSpinThreshold || *((_DWORD *)v10 + 8497) % (unsigned int)EtwpSpinLockContentionSampleRate)
&& (v12 || (*((_DWORD *)v10 + 8496) - *((_DWORD *)v10 + 8497)) % (unsigned int)EtwpSpinLockAcquireSampleRate) )
{
goto LABEL_20;
}
}
v13 = *((_BYTE *)v10 + 32);
*(_BYTE *)(*((_QWORD *)CurrentPrcb + 4197) + 273i64) = 1;
*(_QWORD *)&v21 = SpinLockAddress;
*((_QWORD *)&v21 + 1) = CallerAddress;
*((_QWORD *)&v22 + 1) = ReleaseTime;
DWORD2(v23) = *((_DWORD *)KeGetCurrentThread() + 288);
BYTE1(v24) = v8;
CurrentIrql = KeGetCurrentIrql();
LOBYTE(v24) = CurrentIrql;
*(_QWORD *)&v22 = *(_QWORD *)v11;
*(_QWORD *)&v23 = *(_QWORD *)(v11 + 16);
HIDWORD(v23) = *((_DWORD *)v10 + 8096) - *(_DWORD *)(v11 + 24);
v15 = *(_BYTE *)(v11 + 28);
BYTE2(v24) = v15;
if( v13 == 1 )
{
if( (*((_DWORD *)KeGetPcr() + 3243) & 0x10001) != 0 )
{
v16 = v15 | 0x40;
LABEL_18:
BYTE2(v24) = v16;
goto LABEL_19;
}
}
else if( !v13 )
{
LABEL_19:
EventData.Reserved = 0;
EventData.Ptr = (unsigned __int64)&v21;
EventData.Size = 56;
LODWORD(Flag) = 1538;
EtwTraceKernelEvent(&EventData, 1ui64, 0x20010000ui64, 0x529u, Flag);
*(_BYTE *)(v7 + 257) = 0;
LABEL_20:
v17 = v8 - 1;
while( v9 < v17 )
{
v18 = 32 * ++v9;
v19 = *(_OWORD *)(v18 + v7 + 16);
*(_OWORD *)v11 = *(_OWORD *)(v18 + v7);
*(_OWORD *)(v11 + 16) = v19;
v11 += 32i64;
}
--*(_BYTE *)(v7 + 256);
return;
}
v16 = v15 | 0x80;
goto LABEL_18;
}
}Referenced by:
ExpReleaseSpinLockExclusiveFromDpcLevelInstrumented
ExpReleaseSpinLockSharedFromDpcLevelInstrumented
KiReleaseQueuedSpinLockInstrumented
KiReleaseSpinLockInstrumented