MiImageProtoChargedCommit

NTSTATUS __stdcall MiImageProtoChargedCommit(_CONTROL_AREA *ControlArea, _MMPTE *ProtoPte){
  unsigned int SessionId; 
  _CONTROL_AREA *i; 
  unsigned __int64 v6; 
  unsigned int v7; 
  _MI_PER_SESSION_PROTOS *SubsectionDriverProtos; 
  _RTL_BALANCED_NODE *SharedProtosAtDpcLevel; 
  unsigned __int64 v11; 
  unsigned __int64 SubsectionBase; 

  SessionId = MmGetSessionIdEx(KeGetCurrentThread()->ApcState.Process);
  for( i = ControlArea + 1; ; i = *(_CONTROL_AREA **)&i->gap8[8] )
  {
    if( !i )
      return 0;
    v6 = *(_QWORD *)i->gap8;
    v7 = (LOWORD(i->NumberOfPfnReferences) >> 1) & 0x1F;
    if( (unsigned __int64)ProtoPte >= v6 && (unsigned __int64)ProtoPte < v6 + 8i64 * HIDWORD(i->NumberOfMappedViews) )
      return v7 >= 4;
    if( (i->NumberOfPfnReferences & 0x20000) == 0 || (ControlArea->u.LongFlags & 0x4000000) == 0 )
      break;
    SharedProtosAtDpcLevel = MiGetSharedProtosAtDpcLevel(ControlArea, SessionId, (_SUBSECTION *)i);
    if( SharedProtosAtDpcLevel )
    {
      v11 = (unsigned __int64)SharedProtosAtDpcLevel[3].Children[0];
      if( (unsigned __int64)ProtoPte >= v11
        && (unsigned __int64)ProtoPte < v11 + 8i64 * HIDWORD(i->NumberOfMappedViews) )
      {
        return v7 >= 4;
      }
    }
LABEL_6:
    ;
  }
  SubsectionDriverProtos = MiGetSubsectionDriverProtos((_SUBSECTION *)i);
  if( !SubsectionDriverProtos )
    goto LABEL_6;
  SubsectionBase = (unsigned __int64)SubsectionDriverProtos->SubsectionBase;
  if( (unsigned __int64)ProtoPte < SubsectionBase
    || (unsigned __int64)ProtoPte >= SubsectionBase + 8i64 * HIDWORD(i->NumberOfMappedViews) )
  {
    goto LABEL_6;
  }
  v7 = 4;
  return v7 >= 4;
}

Referenced by:

MiDeleteSystemPagableVm