PspChargeProcessWakeCounter

INT64 __fastcall PspChargeProcessWakeCounter(INT64 Object, INT64 a2, INT64 a3, INT64 a4, INT64 a5, CHAR a6, INT64 *a7){
  char v7; 
  int v9; 
  char v10; 
  bool v11; 
  INT64 v12; 
  bool v13; 
  int v14; 
  bool v15; 
  unsigned int v16; 
  volatile signed __int32 *v17; 
  int v18; 
  int v19; 
  int v20; 
  _PS_WAKE_REASON v21; 
  INT64 v22; 
  INT64 v23; 
  int v25; 
  INT64 v26; 
  int v27; 
  INT64 v28; 
  char v29; 
  unsigned int v30; 
  int v31; 
  int v32; 
  INT64 v33; 
  _ETHREAD *CurrentThread; 
  _EJOB *Objecta; 
  bool v36; 
  int v37; 
  _PS_WAKE_REASON v38; 
  v38 = (int)a3;
  v37 = a2;
  v7 = 0;
  v32 = 1;
  v31 = 0;
  v9 = a2 & 2;
  v29 = 0;
  v30 = a3;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v10 = 0;
  v11 = 0;
  --*((_WORD *)CurrentThread + 242);
  ExAcquirePushLockSharedEx(Object + 1080, 0i64);
  v12 = *(_QWORD *)(Object + 1296);
  v13 = v9 != 0;
  v36 = v9 != 0;
  Objecta = (_EJOB *)v12;
  if( !v12 || (v14 = *(_DWORD *)(v12 + 1320), v15 = v9 != 0, v36 = v9 != 0, (v14 & 0x1000) == 0) )
  {
    v16 = v30;
    goto LABEL_4;
  }
  if( v9 )
  {
    if( (v14 & 0x800000) != 0 )
    {
      v36 = v9 != 0;
      if( (int)a5 > 0 )
      {
LABEL_31:
        v16 = v30;
        goto LABEL_12;
      }
    }
  }
  v25 = v37;
  v26 = *((_QWORD *)KeGetCurrentThread() + 23);
  v33 = v26;
  if( (v37 & 1) != 0 )
  {
    v36 = v9 != 0;
    if( !PspCheckConditionalWakeCharge(v26, v12) )
      goto LABEL_31;
    v15 = v9 != 0;
    v25 = v37;
    v26 = v33;
  }
  if( (*(_DWORD *)(v26 + 1120) & 0x40) != 0 || !v9 )
  {
    v16 = v30;
    v13 = 0;
    v36 = 0;
  }
  else
  {
    v32 = 5;
    v16 = 7;
    if( v25 < 0 )
      v32 = 7;
    v13 = v15;
    v36 = v15;
  }
  v7 = 1;
LABEL_4:
  if( !a6 || v7 || *(_QWORD *)(Object + 2464) )
  {
    if( v13 )
    {
      v17 = (volatile signed __int32 *)(Object + 2508);
      v16 = 7;
    }
    else
    {
      v17 = (volatile signed __int32 *)(Object + 4 * ((int)v38 + 618i64));
    }
    v18 = _InterlockedExchangeAdd(v17, a5) + a5;
    v10 = 1;
    v19 = v18 & 0x7FFFFFFF;
    v11 = v18 < 0;
    if( v18 >= 0 )
      v19 = v18;
    v31 = v19;
    if( !v13 )
    {
      v31 = v19;
      if( *(_QWORD *)(Object + 2464) )
      {
        v27 = 1 << v38;
        if( (int)a5 <= 0 )
        {
          if( (v27 & *(_DWORD *)(Object + 2504)) != 0 && !v19 )
          {
            v29 = 1;
            v31 = 0;
            goto LABEL_12;
          }
        }
        else if( (v27 & *(_DWORD *)(Object + 2500)) != 0 && v19 == 1 )
        {
          v29 = 1;
          v31 = 1;
          goto LABEL_12;
        }
        v29 = 0;
        v31 = v19;
      }
    }
  }
LABEL_12:
  if( _InterlockedCompareExchange64((volatile signed __int64 *)(Object + 1080), 0i64, 17i64) != 17 )
    ExfReleasePushLockShared((INT64 *)(Object + 1080));
  KeAbPostRelease((PVOID)(Object + 1080));
  KeLeaveCriticalRegionThread((__int64)CurrentThread);
  if( v29 )
  {
    HIDWORD(v28) = 0;
    ZwUpdateWnfStateData();
    v20 = v31;
    if( (xmmword_140CFB490 & 0x400) != 0 && v31 == 1 )
      EtwTraceWakeEvent((VOID *)Object, v38);
  }
  else
  {
    v20 = v31;
  }
  if( a7 )
    *(_DWORD *)a7 = v20;
  if( v11 || v7 )
  {
    v23 = a4;
    v21 = v38;
    v22 = (int)a5;
    LODWORD(v28) = v32;
    PspChargeJobWakeCounter(Objecta, 0i64, (unsigned int)v38, (int)a5, v28, Object, a4);
  }
  else
  {
    v21 = v38;
    v22 = (int)a5;
    v23 = a4;
  }
  if( !v10 )
    return 0i64;
  if( (xmmword_140CFB490 & 0x2000) != 0 && !v36 )
    EtwTraceWakeCounter((VOID *)Object, v21, v22, (_EPROCESS *)Object, v23);
  if( !a6 )
    return 0i64;
  if( (int)a5 <= 0 )
  {
    ObDereferenceObjectDeferDeleteWithTag((PVOID)Object, 0x6B577350ui64);
    return 0i64;
  }
  ObfReferenceObjectWithTag((PVOID)Object, 0x6B577350u);
  return Object | v16;
}

Referenced by:

AlpcpSendMessage
PsChargeProcessWakeCounter
PsReleaseProcessWakeCounter
PspAdjustKeepAliveCountProcess