IopVerifierExAllocatePoolWithQuota_1
_WORD *__fastcall IopVerifierExAllocatePoolWithQuota_1(POOL_TYPE a1, UINT64 a2){
unsigned __int32 v2;
int v3;
unsigned __int32 v4;
unsigned __int32 v5;
_EPROCESS *Process;
VOID **PoolWithTag;
_WORD *v8;
__int16 v9;
unsigned __int64 v10;
__int64 v11;
char *v12;
__int64 v13;
unsigned __int64 v14;
struct _EPROCESS_QUOTA_BLOCK *QuotaBlock;
__int64 v16;
__int64 v17;
__int64 v18;
char v19;
UINT64 *CacheAlign;
UINT64 v21;
UINT64 v22;
unsigned __int64 v23;
bool v24;
signed __int64 v25;
unsigned __int64 v26;
unsigned __int64 v27;
unsigned __int64 v28;
__int64 v29;
__int64 v30;
_WORD *result;
unsigned __int64 v32;
unsigned __int64 v33;
unsigned __int64 v34;
UINT64 v35;
NTSTATUS v36;
int v37[8];
UINT64 pLimit;
__int64 v39;
__int64 v40;
char v41;
int v42;
v2 = a1;
if( !ViVerifierEnabled
|| (*(&stru_140CF2E80 + 1826) & 0xFFAFFFFF) == 0
&& (*(&stru_140CF2E80 + 7308) & 2) == 0
&& (*(&stru_140CF2E80 + 7308) & 4) == 0 )
{
v42 = 1;
v3 = 1;
if( (a1 & 8) != 0 )
{
v3 = 0;
v42 = 0;
v2 = a1 & 0xFFFFFFF7;
}
v4 = v2;
v5 = v2 + 8;
Process = KeGetCurrentThread()->ApcState.Process;
if( Process == PsInitialSystemProcess )
v5 = v4;
PoolWithTag = ExAllocatePoolWithTag(v5, a2, 538996553i64);
v8 = PoolWithTag;
if( ((unsigned __int16)PoolWithTag & 0xFFF) != 0 )
{
if( !ExpSpecialAllocations || (LODWORD(v35) = ExGetHeapFromVA(PoolWithTag), !ExpHpIsSpecialPoolHeap(v35)) )
{
if( (v5 & 8) != 0 )
{
v9 = *(v8 - 7);
v10 = (unsigned __int64)(v8 - 8);
v11 = ExpPoolQuotaCookie;
v12 = 0i64;
v13 = (unsigned __int8)v9;
*((_QWORD *)v8 - 1) = (unsigned __int64)(v8 - 8) ^ ExpPoolQuotaCookie;
if( (v9 & 0x400) != 0 )
{
v12 = (char *)(v10 - 16i64 * (unsigned __int8)*(_WORD *)v10);
v13 = (unsigned __int8)*((_WORD *)v12 + 1);
*((_QWORD *)v12 + 1) = (unsigned __int64)v12 ^ v11;
}
v14 = 16 * v13;
if( Process == PsInitialSystemProcess )
{
LABEL_21:
v29 = ExpPoolQuotaCookie;
*(_QWORD *)(v10 + 8) = (unsigned __int64)Process ^ v10 ^ ExpPoolQuotaCookie;
if( v12 )
*((_QWORD *)v12 + 1) = (unsigned __int64)Process ^ (unsigned __int64)v12 ^ v29;
if( ObpTraceFlags )
ObpPushStackInfo(
(_OBJECT_HEADER *)&Process[-1].DynamicEnforcedCetCompatibleRanges,
1u,
1ui64,
0x20206F49ui64);
v30 = _InterlockedIncrement64((volatile signed __int64 *)&Process[-1].DynamicEnforcedCetCompatibleRanges);
if( v30 <= 1 )
KeBugCheckEx(0x18u, 0i64, Process, (PVOID)0x10, (PVOID)v30);
}
else
{
QuotaBlock = Process->QuotaBlock;
v16 = v5 & 1;
v17 = (unsigned int)v16;
v39 = (unsigned int)v16;
v18 = 8 * v16;
v19 = PspResourceFlags[8 * v16];
CacheAlign = (UINT64 *)QuotaBlock->QuotaEntry[v16].CacheAlign;
v41 = PspResourceFlags[v18];
v40 = v18;
_m_prefetchw(CacheAlign);
v21 = *CacheAlign;
_InterlockedOr(v37, 0);
LABEL_13:
v22 = CacheAlign[8];
LABEL_14:
pLimit = v22;
while( 1 )
{
v23 = v14 + v21;
if( v14 + v21 < v21 )
break;
if( v23 <= v22 )
{
v25 = _InterlockedCompareExchange64((volatile signed __int64 *)CacheAlign, v23, v21);
v24 = v21 == v25;
v21 = v25;
if( !v24 )
goto LABEL_13;
_m_prefetchw(CacheAlign + 1);
v26 = CacheAlign[1];
if( v23 > v26 )
{
do
{
v33 = v26;
v26 = _InterlockedCompareExchange64((volatile signed __int64 *)CacheAlign + 1, v23, v26);
}
while( v26 != v33 && v23 > v26 );
}
if( (v19 & 4) != 0 )
{
v27 = v14
+ _InterlockedExchangeAdd64((volatile signed __int64 *)&Process->ProcessQuotaUsage[v17], v14);
_m_prefetchw(&Process->ProcessQuotaPeak[v17]);
v28 = Process->ProcessQuotaPeak[v17];
if( v27 > v28 )
{
do
{
v32 = v28;
v28 = _InterlockedCompareExchange64(
(volatile signed __int64 *)&Process->ProcessQuotaPeak[v17],
v27,
v28);
}
while( v28 != v32 && v27 > v28 );
}
}
goto LABEL_21;
}
if( (v19 & 1) == 0 || !CacheAlign[10] )
break;
v34 = _InterlockedExchange64((volatile __int64 *)CacheAlign + 9, 0i64);
if( v34 )
{
v22 = v34 + _InterlockedExchangeAdd64((volatile signed __int64 *)CacheAlign + 8, v34);
goto LABEL_14;
}
if( !PspExpandQuota((_PS_RESOURCE_TYPE)v17, (_PSP_QUOTA_ENTRY *)CacheAlign, v21, v14, &pLimit) )
break;
v22 = pLimit;
v17 = v39;
v19 = v41;
}
v36 = *(_DWORD *)&PspResourceFlags[v40 + 4];
if( v36 >= 0 )
goto LABEL_21;
ExFreePoolWithTag(v8, 0x20206F49u);
if( v42 )
RtlRaiseStatus(v36);
return 0i64;
}
}
}
}
else if( !PoolWithTag && v3 )
{
LABEL_55:
RtlRaiseStatus(-1073741670);
}
return v8;
}
result = ExAllocatePoolWithTagPriority(
a1,
a2,
0x20206F49ui64,
(_EX_POOL_PRIORITY)((MmVerifierData & 0x10 | 0x40) >> 1));
if( !result )
goto LABEL_55;
return result;
}Referenced by:
IopSetEaOrQuotaInformationFile
IopTrackLink
IopValidateJunctionTarget
IopXxxControlFile