ObpReferenceObjectByHandleWithTag
__int64 __fastcall ObpReferenceObjectByHandleWithTag(
ULONG_PTR BugCheckParameter1,
int a2,
__int64 a3,
char a4,
ULONG Tag,
__int64 a6,
__int64 a7,
__int64 a8){
_ETHREAD *CurrentThread;
unsigned int v11;
__int64 v13;
_HANDLE_TABLE *v14;
_HANDLE_TABLE_ENTRY *v15;
_HANDLE_TABLE_ENTRY *v16;
INT64 LowValue;
signed __int64 HighValue;
INT64 v19;
unsigned __int128 v20;
unsigned __int8 v21;
__int64 v22;
unsigned __int64 v23;
unsigned __int8 v24;
int v25;
int v26;
__int64 v27;
char v28;
INT64 v29;
unsigned __int64 v31;
PVOID v32;
unsigned int v33;
int v34;
INT64 v35;
unsigned __int64 v36;
_EX_PUSH_LOCK *v37;
__int64 v38;
signed __int64 v39;
ULONG_PTR v40;
signed __int64 v41;
int v42;
_HANDLE_TABLE_ENTRY_INFO *HandleExtraInfo;
int v44[8];
ULONG_PTR BugCheckParameter4;
_HANDLE_TABLE_ENTRY CurrentValue;
struct _EX_RUNDOWN_REF *v47;
char v51;
_HANDLE_TABLE *HandleTable;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v11 = 0;
v51 = 0;
v13 = *((_QWORD *)CurrentThread + 23);
v47 = (struct _EX_RUNDOWN_REF *)v13;
*(_QWORD *)a6 = 0i64;
if( a8 )
*(_QWORD *)a8 = 0i64;
if( (BugCheckParameter1 & 0xFFFFFFFF80000000ui64) == 0xFFFFFFFF80000000ui64 )
{
if( BugCheckParameter1 == -1i64 )
{
if( (POBJECT_TYPE *)a3 != PsProcessType && a3 )
return 3221225508i64;
v40 = *((_QWORD *)CurrentThread + 23);
if( (a2 & 0xFFE00000) != 0 && a4 )
{
return(unsigned int)-1073741790;
}
else
{
if( a7 )
{
*(_DWORD *)(a7 + 4) = 0x1FFFFF;
*(_DWORD *)a7 = 0;
}
if( ObpTraceFlags )
{
ObpPushStackInfo(v40 - 48, 1, 1i64, Tag);
v11 = 0;
}
v41 = _InterlockedIncrement64((volatile signed __int64 *)(v40 - 48));
if( v41 <= 1 )
KeBugCheckEx(0x18u, 0i64, v40, 0x10ui64, v41);
*(_QWORD *)a6 = v40;
}
return v11;
}
if( BugCheckParameter1 == -2i64 )
{
if( (POBJECT_TYPE *)a3 != PsThreadType && a3 )
return 3221225508i64;
if( (a2 & 0xFFE00000) != 0 && a4 )
{
return(unsigned int)-1073741790;
}
else
{
if( a7 )
{
*(_DWORD *)(a7 + 4) = 0x1FFFFF;
*(_DWORD *)a7 = 0;
}
if( ObpTraceFlags )
{
ObpPushStackInfo((INT64)CurrentThread - 48, 1, 1i64, Tag);
v11 = 0;
}
v39 = _InterlockedIncrement64((volatile signed __int64 *)CurrentThread - 6);
if( v39 <= 1 )
KeBugCheckEx(0x18u, 0i64, (ULONG_PTR)CurrentThread, 0x10ui64, v39);
*(_QWORD *)a6 = CurrentThread;
}
return v11;
}
if( a4 )
return 3221225480i64;
v14 = (_HANDLE_TABLE *)ObpKernelHandleTable;
BugCheckParameter1 ^= 0xFFFFFFFF80000000ui64;
--*((_WORD *)CurrentThread + 242);
HandleTable = v14;
goto LABEL_10;
}
if( (MmVerifierData & 0x100) != 0 && !a4 )
VfCheckUserHandle((VOID *)BugCheckParameter1);
--*((_WORD *)CurrentThread + 242);
if( v13 == *((_QWORD *)CurrentThread + 68) )
{
if( (*(_DWORD *)(v13 + 1124) & 0x4000000) == 0 )
{
LABEL_110:
v33 = -1073741816;
goto LABEL_81;
}
v14 = *(_HANDLE_TABLE **)(v13 + 1392);
}
else
{
v14 = (_HANDLE_TABLE *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)v13);
v51 = 1;
}
HandleTable = v14;
if( !v14 )
goto LABEL_110;
if( v14 == (_HANDLE_TABLE *)ObpKernelHandleTable )
{
LABEL_85:
v33 = -1073741816;
goto LABEL_79;
}
LABEL_10:
if( (BugCheckParameter1 & 0x3FC) == 0
|| (v15 = ExpLookupHandleTableEntry(v14, (_EXHANDLE)BugCheckParameter1), (v16 = v15) == 0i64) )
{
LABEL_83:
if( BugCheckParameter1 )
ExHandleLogBadReference((ULONG_PTR)v14, BugCheckParameter1, *((_BYTE *)KeGetCurrentThread() + 562));
goto LABEL_85;
}
_m_prefetchw(v15);
LowValue = v15->LowValue;
HighValue = v15->HighValue;
CurrentValue.HighValue = HighValue;
CurrentValue.LowValue = LowValue;
v19 = LowValue;
if( (LowValue & 0x1FFFE) == 0 )
goto LABEL_46;
while( 1 )
{
if( (v19 & 1) == 0 )
{
ExpBlockOnLockedHandleEntry(v14, v16, v19);
_m_prefetchw(v16);
HighValue = v16->HighValue;
v14 = HandleTable;
CurrentValue.LowValue = v16->LowValue;
v19 = CurrentValue.LowValue;
CurrentValue.HighValue = HighValue;
goto LABEL_75;
}
*(_QWORD *)&v20 = v19;
*((_QWORD *)&v20 + 1) = HighValue;
v21 = _InterlockedCompareExchange128(&v16->VolatileLowValue, HighValue, v19 - 2, (signed __int64 *)&v20);
HighValue = v20 >> 64;
v22 = v20;
v19 = v20;
CurrentValue = (_HANDLE_TABLE_ENTRY)v20;
if( v21 )
break;
LABEL_75:
if( (v19 & 0x1FFFE) == 0 )
{
do
{
LABEL_46:
while( 1 )
{
_m_prefetchw(v16);
v35 = v16->LowValue;
if( (v16->LowValue & 1) != 0 )
break;
if( !v35 )
goto LABEL_83;
ExpBlockOnLockedHandleEntry(v14, v16, v35);
v14 = HandleTable;
}
}
while( v35 != _InterlockedCompareExchange64(&v16->VolatileLowValue, v35 - 1, v35) );
v23 = (v16->LowValue >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
CurrentValue = *v16;
v36 = (int)(ExSlowReplenishHandleTableEntry((unsigned __int64 *)v16) + 1);
v38 = _InterlockedExchangeAdd64((volatile signed __int64 *)v23, v36);
if( v38 <= 0 )
KeBugCheckEx(0x18u, 0i64, v23 + 48, 0x10ui64, v36 + v38);
_InterlockedExchangeAdd64(&v16->VolatileLowValue, 1ui64);
_InterlockedOr(v44, 0);
if( v37[6].Value )
ExfUnblockPushLock(v37 + 6, 0i64);
goto LABEL_51;
}
}
if( (unsigned __int16)((unsigned __int64)v22 >> 1) != 16 )
{
v23 = (v22 >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
goto LABEL_17;
}
CurrentValue.LowValue = v22 ^ ((unsigned int)v22 ^ (2 * (unsigned int)((unsigned __int64)v22 >> 1) - 2)) & 0x1FFFE;
v23 = (CurrentValue.LowValue >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
ObpIncrPointerCountEx((volatile INT64 *)v23, 32752i64);
v42 = ExFastReplenishHandleTableEntry(&v16->VolatileLowValue, (unsigned __int64 *)&CurrentValue, 32752);
if( v42 )
_InterlockedExchangeAdd64((volatile signed __int64 *)v23, -v42);
LABEL_51:
LODWORD(HighValue) = CurrentValue.LeafHandleValue.0;
v19 = CurrentValue.LowValue;
LABEL_17:
if( ObpTraceFlags )
ObpPushStackInfo(v23, 1, 1i64, Tag);
v24 = ObHeaderCookie ^ *(_BYTE *)(v23 + 24) ^ BYTE1(v23);
if( !a3 || *(_BYTE *)(a3 + 40) != v24 )
{
v32 = (PVOID)ObTypeIndexTable[v24];
if( !v32 || v32 == MmBadPointer )
KeBugCheckEx(0x189u, v23, (ULONG_PTR)v32, 0i64, 0i64);
if( a3 )
{
v33 = -1073741788;
goto LABEL_78;
}
}
v25 = a2;
v26 = HighValue & 0x1FFFFFF;
if( !a4 )
{
LABEL_24:
v27 = v19 >> 17;
if( a7 )
{
v34 = v27 & 7;
*(_DWORD *)(a7 + 4) = v26;
*(_DWORD *)a7 = v34;
if( (v34 & 4) == 0 )
goto LABEL_26;
}
else if( (v27 & 4) == 0 )
{
LABEL_26:
v28 = 0;
goto LABEL_27;
}
v28 = 1;
LABEL_27:
v29 = (INT64)HandleTable;
if( a8 )
{
if( HandleTable->ExtraInfoPages )
{
HandleExtraInfo = ExpGetHandleExtraInfo(HandleTable, (VOID *)BugCheckParameter1);
v25 = a2;
if( HandleExtraInfo )
*(_HANDLE_TABLE_ENTRY_INFO *)a8 = *HandleExtraInfo;
}
}
if( v28 )
{
if( v25 )
{
LODWORD(BugCheckParameter4) = v25;
if( !ObpAuditObjectAccess(
v29,
(VOID *)BugCheckParameter1,
&v16->VolatileLowValue,
(UINT8 *)v23,
BugCheckParameter4) )
{
v33 = -1073741816;
goto LABEL_78;
}
}
}
*(_QWORD *)a6 = v23 + 48;
if( v51 )
ExReleaseRundownProtection(v47 + 139);
KeLeaveCriticalRegionThread((__int64)CurrentThread);
return 0i64;
}
if( (~v26 & a2) != 0 )
{
v33 = -1073741790;
goto LABEL_78;
}
if( (*(_BYTE *)(v23 + 26) & 0x40) == 0 )
goto LABEL_24;
v31 = v23 - *((unsigned __int8 *)ObpInfoMaskToOffset + (*(_BYTE *)(v23 + 26) & 0x7F));
if( !*(_BYTE *)(*(_QWORD *)v31 + 24i64) )
{
LABEL_35:
v25 = a2;
goto LABEL_24;
}
if( *(_QWORD *)(*(_QWORD *)v31 + 16i64) != 1i64 )
{
v19 = CurrentValue.LowValue;
goto LABEL_35;
}
v33 = -1073700858;
LABEL_78:
ObfDereferenceObjectWithTag((PVOID)(v23 + 48), Tag);
LABEL_79:
if( v51 )
ExReleaseRundownProtection(v47 + 139);
LABEL_81:
KeLeaveCriticalRegionThread((__int64)CurrentThread);
return v33;
}Referenced by:
DbgkpCreateNotificationEvent
DbgkpWerInitializeDeferredLiveDump
ExpWnfCaptureScopeInstanceId
HalpAcquirePccInterface
MiAllocateVirtualMemoryPrepare
MmFreeVirtualMemory
MmPrefetchVirtualMemory
MmProcessWorkingSetControl
NtAlertThread
NtCreateEnclave
NtCreateThreadEx
NtCreateUserProcess
NtOpenProcessTokenEx
NtQueryInformationJobObject
NtRemoveProcessDebug
ObReferenceObjectByHandle
ObReferenceObjectByHandleWithTag
ObpLookupObjectName
PfpSourceGetPrefetchSupport
PopSetSpecialRequest
PsCreateSystemThreadEx
PsReferencePartitionByHandle
PspBuildCreateProcessContext
PspConvertSiloToServerSilo
PspCreateThread
VrpHandleIoctlGetVirtualRootKey