CmpFreeCallbackObjectContexts

VOID **__fastcall CmpFreeCallbackObjectContexts(INT64 a1){
  char v1; 
  _ETHREAD *CurrentThread; 
  PVOID ***v4; 
  PVOID **v5; 
  PVOID v6; 
  VOID **result; 
  __int64 v8; 
  PVOID **v9; 
  PVOID *v10; 
  PVOID ***v11; 
  PVOID *v12; 
  int v13[8]; 
  PVOID P; 
  PVOID *p_P; 
  v1 = 0;
  p_P = &P;
  P = &P;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquirePushLockExclusiveEx((UINT64)&CmpContextListLock, 0i64);
  v4 = (PVOID ***)(a1 + 72);
  while( 1 )
  {
    v5 = *v4;
    if( *v4 == (PVOID **)v4 )
      break;
    if( v5[1] != (PVOID *)v4 )
      goto LABEL_17;
    v9 = (PVOID **)*v5;
    if( (*v5)[1] != v5 )
      goto LABEL_17;
    *v4 = v9;
    v9[1] = (PVOID *)v4;
    v10 = v5[2];
    if( v10[1] != v5 + 2 )
      goto LABEL_17;
    v11 = (PVOID ***)v5[3];
    if( *v11 != v5 + 2 )
      goto LABEL_17;
    *v11 = (PVOID **)v10;
    v10[1] = v11;
    if( v11 == (PVOID ***)v10 )
      v1 = 1;
    v12 = p_P;
    if( *p_P != &P )
LABEL_17:
      __fastfail(3u);
    v5[1] = p_P;
    *v5 = &P;
    *v12 = v5;
    p_P = (PVOID *)v5;
  }
  ExReleasePushLockEx((UINT64)&CmpContextListLock, 0i64);
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  if( v1 )
  {
    _InterlockedOr(v13, 0);
    if( CallbackListDeleteEvent.0 )
      ExfUnblockPushLock(&CallbackListDeleteEvent, 0i64);
  }
  while( 1 )
  {
    v6 = P;
    result = &P;
    if( P == &P )
      return result;
    if( *((PVOID **)P + 1) != &P )
      goto LABEL_17;
    v8 = *(_QWORD *)P;
    if( *(PVOID *)(*(_QWORD *)P + 8i64) != P )
      goto LABEL_17;
    P = *(PVOID *)P;
    *(_QWORD *)(v8 + 8) = &P;
    ExFreePoolWithTag(v6, 0x63634D43u);
  }
}

Referenced by:

CmpDeleteKeyObject