MiReleaseFaultCharges

NTSTATUS __stdcall MiReleaseFaultCharges(PVOID BugCheckParameter2){
  __int64 v1; 
  UINT64 v3; 
  volatile INT64 *v4; 
  _BOOL8 v5; 
  KIRQL v6; 
  int v7; 
  NTSTATUS result; 
  v1 = *(_QWORD *)BugCheckParameter2;
  v3 = 0i64;
  v4 = 0i64;
  v5 = *(_QWORD *)(*(_QWORD *)BugCheckParameter2 + 64i64) != 0i64;
  v6 = ExAcquireSpinLockExclusive((PEX_SPIN_LOCK)(*(_QWORD *)BugCheckParameter2 + 72i64));
  v7 = *(_DWORD *)(v1 + 56);
  if( (v7 & 0x20) == 0 && *(_QWORD *)(v1 + 64) && (v7 & 0x400) == 0 )
    v3 = MiDecrementSubsections((_SUBSECTION *)BugCheckParameter2, (_SUBSECTION *)BugCheckParameter2, 4ui64);
  --*(_QWORD *)(v1 + 40);
  if( v3 )
    v4 = *(volatile INT64 **)(qword_140C4E388 + 8i64 * (*(_WORD *)(v1 + 60) & 0x3FF));
  MiCheckControlArea((_CONTROL_AREA *)v1, v6);
  if( v3 )
    return MiReturnCrossPartitionSectionCharges(v4, v5, v3);
  return result;
}

Referenced by:

MiFaultGetFileExtents
MmAccessFault