ObpReferenceObjectByHandleWithTag

__int64 __fastcall ObpReferenceObjectByHandleWithTag(
        ULONG_PTR BugCheckParameter1,
        int a2,
        __int64 a3,
        char a4,
        ULONG Tag,
        __int64 a6,
        __int64 a7,
        __int64 a8){
  _ETHREAD *CurrentThread; 
  unsigned int v11; 
  __int64 v13; 
  _HANDLE_TABLE *v14; 
  _HANDLE_TABLE_ENTRY *v15; 
  _HANDLE_TABLE_ENTRY *v16; 
  INT64 LowValue; 
  signed __int64 HighValue; 
  INT64 v19; 
  unsigned __int128 v20; 
  unsigned __int8 v21; 
  __int64 v22; 
  unsigned __int64 v23; 
  unsigned __int8 v24; 
  int v25; 
  int v26; 
  __int64 v27; 
  char v28; 
  INT64 v29; 
  unsigned __int64 v31; 
  PVOID v32; 
  unsigned int v33; 
  int v34; 
  INT64 v35; 
  unsigned __int64 v36; 
  _EX_PUSH_LOCK *v37; 
  __int64 v38; 
  signed __int64 v39; 
  ULONG_PTR v40; 
  signed __int64 v41; 
  int v42; 
  _HANDLE_TABLE_ENTRY_INFO *HandleExtraInfo; 
  int v44[8]; 
  ULONG_PTR BugCheckParameter4; 
  _HANDLE_TABLE_ENTRY CurrentValue; 
  struct _EX_RUNDOWN_REF *v47; 
  char v51; 
  _HANDLE_TABLE *HandleTable; 
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v11 = 0;
  v51 = 0;
  v13 = *((_QWORD *)CurrentThread + 23);
  v47 = (struct _EX_RUNDOWN_REF *)v13;
  *(_QWORD *)a6 = 0i64;
  if( a8 )
    *(_QWORD *)a8 = 0i64;
  if( (BugCheckParameter1 & 0xFFFFFFFF80000000ui64) == 0xFFFFFFFF80000000ui64 )
  {
    if( BugCheckParameter1 == -1i64 )
    {
      if( (POBJECT_TYPE *)a3 != PsProcessType && a3 )
        return 3221225508i64;
      v40 = *((_QWORD *)CurrentThread + 23);
      if( (a2 & 0xFFE00000) != 0 && a4 )
      {
        return(unsigned int)-1073741790;
      }
      else
      {
        if( a7 )
        {
          *(_DWORD *)(a7 + 4) = 0x1FFFFF;
          *(_DWORD *)a7 = 0;
        }
        if( ObpTraceFlags )
        {
          ObpPushStackInfo(v40 - 48, 1, 1i64, Tag);
          v11 = 0;
        }
        v41 = _InterlockedIncrement64((volatile signed __int64 *)(v40 - 48));
        if( v41 <= 1 )
          KeBugCheckEx(0x18u, 0i64, v40, 0x10ui64, v41);
        *(_QWORD *)a6 = v40;
      }
      return v11;
    }
    if( BugCheckParameter1 == -2i64 )
    {
      if( (POBJECT_TYPE *)a3 != PsThreadType && a3 )
        return 3221225508i64;
      if( (a2 & 0xFFE00000) != 0 && a4 )
      {
        return(unsigned int)-1073741790;
      }
      else
      {
        if( a7 )
        {
          *(_DWORD *)(a7 + 4) = 0x1FFFFF;
          *(_DWORD *)a7 = 0;
        }
        if( ObpTraceFlags )
        {
          ObpPushStackInfo((INT64)CurrentThread - 48, 1, 1i64, Tag);
          v11 = 0;
        }
        v39 = _InterlockedIncrement64((volatile signed __int64 *)CurrentThread - 6);
        if( v39 <= 1 )
          KeBugCheckEx(0x18u, 0i64, (ULONG_PTR)CurrentThread, 0x10ui64, v39);
        *(_QWORD *)a6 = CurrentThread;
      }
      return v11;
    }
    if( a4 )
      return 3221225480i64;
    v14 = (_HANDLE_TABLE *)ObpKernelHandleTable;
    BugCheckParameter1 ^= 0xFFFFFFFF80000000ui64;
    --*((_WORD *)CurrentThread + 242);
    HandleTable = v14;
    goto LABEL_10;
  }
  if( (MmVerifierData & 0x100) != 0 && !a4 )
    VfCheckUserHandle((VOID *)BugCheckParameter1);
  --*((_WORD *)CurrentThread + 242);
  if( v13 == *((_QWORD *)CurrentThread + 68) )
  {
    if( (*(_DWORD *)(v13 + 1124) & 0x4000000) == 0 )
    {
LABEL_110:
      v33 = -1073741816;
      goto LABEL_81;
    }
    v14 = *(_HANDLE_TABLE **)(v13 + 1392);
  }
  else
  {
    v14 = (_HANDLE_TABLE *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)v13);
    v51 = 1;
  }
  HandleTable = v14;
  if( !v14 )
    goto LABEL_110;
  if( v14 == (_HANDLE_TABLE *)ObpKernelHandleTable )
  {
LABEL_85:
    v33 = -1073741816;
    goto LABEL_79;
  }
LABEL_10:
  if( (BugCheckParameter1 & 0x3FC) == 0
    || (v15 = ExpLookupHandleTableEntry(v14, (_EXHANDLE)BugCheckParameter1), (v16 = v15) == 0i64) )
  {
LABEL_83:
    if( BugCheckParameter1 )
      ExHandleLogBadReference((ULONG_PTR)v14, BugCheckParameter1, *((_BYTE *)KeGetCurrentThread() + 562));
    goto LABEL_85;
  }
  _m_prefetchw(v15);
  LowValue = v15->LowValue;
  HighValue = v15->HighValue;
  CurrentValue.HighValue = HighValue;
  CurrentValue.LowValue = LowValue;
  v19 = LowValue;
  if( (LowValue & 0x1FFFE) == 0 )
    goto LABEL_46;
  while( 1 )
  {
    if( (v19 & 1) == 0 )
    {
      ExpBlockOnLockedHandleEntry(v14, v16, v19);
      _m_prefetchw(v16);
      HighValue = v16->HighValue;
      v14 = HandleTable;
      CurrentValue.LowValue = v16->LowValue;
      v19 = CurrentValue.LowValue;
      CurrentValue.HighValue = HighValue;
      goto LABEL_75;
    }
    *(_QWORD *)&v20 = v19;
    *((_QWORD *)&v20 + 1) = HighValue;
    v21 = _InterlockedCompareExchange128(&v16->VolatileLowValue, HighValue, v19 - 2, (signed __int64 *)&v20);
    HighValue = v20 >> 64;
    v22 = v20;
    v19 = v20;
    CurrentValue = (_HANDLE_TABLE_ENTRY)v20;
    if( v21 )
      break;
LABEL_75:
    if( (v19 & 0x1FFFE) == 0 )
    {
      do
      {
LABEL_46:
        while( 1 )
        {
          _m_prefetchw(v16);
          v35 = v16->LowValue;
          if( (v16->LowValue & 1) != 0 )
            break;
          if( !v35 )
            goto LABEL_83;
          ExpBlockOnLockedHandleEntry(v14, v16, v35);
          v14 = HandleTable;
        }
      }
      while( v35 != _InterlockedCompareExchange64(&v16->VolatileLowValue, v35 - 1, v35) );
      v23 = (v16->LowValue >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
      CurrentValue = *v16;
      v36 = (int)(ExSlowReplenishHandleTableEntry((unsigned __int64 *)v16) + 1);
      v38 = _InterlockedExchangeAdd64((volatile signed __int64 *)v23, v36);
      if( v38 <= 0 )
        KeBugCheckEx(0x18u, 0i64, v23 + 48, 0x10ui64, v36 + v38);
      _InterlockedExchangeAdd64(&v16->VolatileLowValue, 1ui64);
      _InterlockedOr(v44, 0);
      if( v37[6].Value )
        ExfUnblockPushLock(v37 + 6, 0i64);
      goto LABEL_51;
    }
  }
  if( (unsigned __int16)((unsigned __int64)v22 >> 1) != 16 )
  {
    v23 = (v22 >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
    goto LABEL_17;
  }
  CurrentValue.LowValue = v22 ^ ((unsigned int)v22 ^ (2 * (unsigned int)((unsigned __int64)v22 >> 1) - 2)) & 0x1FFFE;
  v23 = (CurrentValue.LowValue >> 16) & 0xFFFFFFFFFFFFFFF0ui64;
  ObpIncrPointerCountEx((volatile INT64 *)v23, 32752i64);
  v42 = ExFastReplenishHandleTableEntry(&v16->VolatileLowValue, (unsigned __int64 *)&CurrentValue, 32752);
  if( v42 )
    _InterlockedExchangeAdd64((volatile signed __int64 *)v23, -v42);
LABEL_51:
  LODWORD(HighValue) = CurrentValue.LeafHandleValue.0;
  v19 = CurrentValue.LowValue;
LABEL_17:
  if( ObpTraceFlags )
    ObpPushStackInfo(v23, 1, 1i64, Tag);
  v24 = ObHeaderCookie ^ *(_BYTE *)(v23 + 24) ^ BYTE1(v23);
  if( !a3 || *(_BYTE *)(a3 + 40) != v24 )
  {
    v32 = (PVOID)ObTypeIndexTable[v24];
    if( !v32 || v32 == MmBadPointer )
      KeBugCheckEx(0x189u, v23, (ULONG_PTR)v32, 0i64, 0i64);
    if( a3 )
    {
      v33 = -1073741788;
      goto LABEL_78;
    }
  }
  v25 = a2;
  v26 = HighValue & 0x1FFFFFF;
  if( !a4 )
  {
LABEL_24:
    v27 = v19 >> 17;
    if( a7 )
    {
      v34 = v27 & 7;
      *(_DWORD *)(a7 + 4) = v26;
      *(_DWORD *)a7 = v34;
      if( (v34 & 4) == 0 )
        goto LABEL_26;
    }
    else if( (v27 & 4) == 0 )
    {
LABEL_26:
      v28 = 0;
      goto LABEL_27;
    }
    v28 = 1;
LABEL_27:
    v29 = (INT64)HandleTable;
    if( a8 )
    {
      if( HandleTable->ExtraInfoPages )
      {
        HandleExtraInfo = ExpGetHandleExtraInfo(HandleTable, (VOID *)BugCheckParameter1);
        v25 = a2;
        if( HandleExtraInfo )
          *(_HANDLE_TABLE_ENTRY_INFO *)a8 = *HandleExtraInfo;
      }
    }
    if( v28 )
    {
      if( v25 )
      {
        LODWORD(BugCheckParameter4) = v25;
        if( !ObpAuditObjectAccess(
                v29,
                (VOID *)BugCheckParameter1,
                &v16->VolatileLowValue,
                (UINT8 *)v23,
                BugCheckParameter4) )
        {
          v33 = -1073741816;
          goto LABEL_78;
        }
      }
    }
    *(_QWORD *)a6 = v23 + 48;
    if( v51 )
      ExReleaseRundownProtection(v47 + 139);
    KeLeaveCriticalRegionThread((__int64)CurrentThread);
    return 0i64;
  }
  if( (~v26 & a2) != 0 )
  {
    v33 = -1073741790;
    goto LABEL_78;
  }
  if( (*(_BYTE *)(v23 + 26) & 0x40) == 0 )
    goto LABEL_24;
  v31 = v23 - *((unsigned __int8 *)ObpInfoMaskToOffset + (*(_BYTE *)(v23 + 26) & 0x7F));
  if( !*(_BYTE *)(*(_QWORD *)v31 + 24i64) )
  {
LABEL_35:
    v25 = a2;
    goto LABEL_24;
  }
  if( *(_QWORD *)(*(_QWORD *)v31 + 16i64) != 1i64 )
  {
    v19 = CurrentValue.LowValue;
    goto LABEL_35;
  }
  v33 = -1073700858;
LABEL_78:
  ObfDereferenceObjectWithTag((PVOID)(v23 + 48), Tag);
LABEL_79:
  if( v51 )
    ExReleaseRundownProtection(v47 + 139);
LABEL_81:
  KeLeaveCriticalRegionThread((__int64)CurrentThread);
  return v33;
}

Referenced by:

DbgkpCreateNotificationEvent
DbgkpWerInitializeDeferredLiveDump
ExpWnfCaptureScopeInstanceId
HalpAcquirePccInterface
MiAllocateVirtualMemoryPrepare
MmFreeVirtualMemory
MmPrefetchVirtualMemory
MmProcessWorkingSetControl
NtAlertThread
NtCreateEnclave
NtCreateThreadEx
NtCreateUserProcess
NtOpenProcessTokenEx
NtQueryInformationJobObject
NtRemoveProcessDebug
ObReferenceObjectByHandle
ObReferenceObjectByHandleWithTag
ObpLookupObjectName
PfpSourceGetPrefetchSupport
PopSetSpecialRequest
PsCreateSystemThreadEx
PsReferencePartitionByHandle
PspBuildCreateProcessContext
PspConvertSiloToServerSilo
PspCreateThread
VrpHandleIoctlGetVirtualRootKey