MiReleaseFaultCharges
NTSTATUS __stdcall MiReleaseFaultCharges(PVOID BugCheckParameter2){
__int64 v1;
UINT64 v3;
volatile INT64 *v4;
_BOOL8 v5;
KIRQL v6;
int v7;
NTSTATUS result;
v1 = *(_QWORD *)BugCheckParameter2;
v3 = 0i64;
v4 = 0i64;
v5 = *(_QWORD *)(*(_QWORD *)BugCheckParameter2 + 64i64) != 0i64;
v6 = ExAcquireSpinLockExclusive((PEX_SPIN_LOCK)(*(_QWORD *)BugCheckParameter2 + 72i64));
v7 = *(_DWORD *)(v1 + 56);
if( (v7 & 0x20) == 0 && *(_QWORD *)(v1 + 64) && (v7 & 0x400) == 0 )
v3 = MiDecrementSubsections((_SUBSECTION *)BugCheckParameter2, (_SUBSECTION *)BugCheckParameter2, 4ui64);
--*(_QWORD *)(v1 + 40);
if( v3 )
v4 = *(volatile INT64 **)(qword_140C4E388 + 8i64 * (*(_WORD *)(v1 + 60) & 0x3FF));
MiCheckControlArea((_CONTROL_AREA *)v1, v6);
if( v3 )
return MiReturnCrossPartitionSectionCharges(v4, v5, v3);
return result;
}Referenced by:
MiFaultGetFileExtents
MmAccessFault