MiReleasePageFileInfo
VOID __fastcall MiReleasePageFileInfo(
INT64 a1,
UINT64 a2,
CHAR a3,
INT64 a4,
INT64 a5,
INT64 a6,
INT64 a7,
INT64 a8,
INT64 a9,
INT64 a10,
INT64 a11,
INT64 a12){
UINT64 v12;
unsigned __int64 v13;
UINT64 v14;
UINT64 v15;
__int64 v16;
INT64 *v17;
int v18;
KIRQL v19;
__int64 v20;
__int64 v21;
int v23;
v12 = a2;
if( qword_140C4DC80 && (a2 & 0x10) == 0 )
v12 = a2 & ~qword_140C4DC80;
v13 = HIDWORD(v12);
v14 = (a2 >> 1) & 1;
v15 = (a2 >> 2) & 1;
v23 = 0;
v16 = *(_QWORD *)(a1 + 8i64 * ((unsigned __int16)a2 >> 12) + 6944);
v17 = (INT64 *)(v16 + 232);
v18 = a3 & 1;
if( (a3 & 1) != 0 )
{
ExAcquireSpinLockExclusiveAtDpcLevel(v17);
v19 = 2;
}
else
{
v19 = ExAcquireSpinLockExclusive((PEX_SPIN_LOCK)v17);
}
v20 = *(_QWORD *)(v16 + 112);
if( (_DWORD)v14 )
{
_bittestandreset(*(signed __int32 **)(v20 + 32), v13);
++*(_QWORD *)(v16 + 48);
}
if( (_DWORD)v15 )
{
if( (a3 & 2) == 0 )
MiClearPageFileHash(v16, v13);
if( (*(_BYTE *)(v16 + 204) & 0x40) != 0 )
{
MiStoreSetEvictPageFile(v16, v13);
goto LABEL_13;
}
_bittestandreset(*(signed __int32 **)(v20 + 16), v13);
v21 = ++*(_QWORD *)(v16 + 24);
if( (unsigned int)v13 < *(_DWORD *)(v16 + 120) )
*(_DWORD *)(v16 + 120) = v13;
++*(_DWORD *)(v16 + 128);
if( v21 == 1 && (*(_BYTE *)(v16 + 206) & 1) != 0 )
v23 = 1;
}
if( ((_DWORD)v14 || !_bittest64(*(const signed __int64 **)(v20 + 32), v13))
&& ((_DWORD)v15 || !_bittest64(*(const signed __int64 **)(v20 + 16), v13)) )
{
MiCoalescePageFileBitmapsCache(v16, (unsigned int)v14, (unsigned int)v13);
_InterlockedExchange(
(volatile __int32 *)(*(_QWORD *)(v16 + 248) + 872i64),
(*(_DWORD *)(*(_QWORD *)(v16 + 248) + 872i64) & 0xFFFFFC00 | 0x200) + 1024);
}
LABEL_13:
ExReleaseSpinLockExclusiveFromDpcLevel((INT64 *)(v16 + 232));
if( !v18 )
__writecr8(v19);
if( v23 == 1 )
KeSetEvent((PRKEVENT)(a1 + 880), 0);
}Referenced by:
MiAllocateWsle
MiBuildForkPte
MiBuildReservationCluster
MiCompleteProtoPteFault
MiConvertPrivateToProto
MiConvertStandbyToProto
MiDecommitPages
MiDeleteBatch
MiDeleteClusterPage
MiDeletePteList
MiDeletePteRun
MiDeleteSubsectionPages
MiDeleteTransitionPte
MiDeleteVa
MiDeleteValidSystemPage
MiFinishHardFault
MiFreeModifiedReservations
MiHandleForkTransitionPte
MiInPageSingleKernelStack
MiLockCode
MiLockDriverPageRange
MiLockPageTablePage
MiLockPagedAddress
MiMakeOutswappedPageResident
MiMigratePfn
MiMoveDirtyBitsToPfns
MiOutSwapWorkingSetPte
MiPurgeImageSection
MiReservePageFileSpace
MiReservePageFileSpaceForPage
MiResolveProtoCombine
MiResolveTransitionFault
MiRevertValidPte
MiScanPagefileSpace
MiSetPagesModified
MiSetSystemCodeProtection
MiStoreWriteModifiedPages
MiTrimUnusedPageFileRegionsWorker
MiUpdateImportRelocationsOnDriverPrivatePages
MiWalkEntireImage
MiWalkVaRange
MiWriteComplete
MiWsleFree
MiZeroCfgSystemWideBitmapWorker
MmProtectPool
MmReplaceImportEntry
MmSetAddressRangeModifiedEx
MmUnlockPages
MmUnmapViewInSystemCache
MmUpdateUserShadowStackValue