MiCountSystemImageCommitment
__int64 __fastcall MiCountSystemImageCommitment(__int64 a1){
UINT64 v2;
_SECTION *v3;
_CONTROL_AREA *v4;
char *v5;
INT64 v6;
__int64 SessionVm;
int v8;
INT64 v9;
__int64 v10;
INT64 *SharedVm;
KIRQL v12;
char *v13;
INT64 v14;
int v15;
unsigned __int64 v16;
unsigned int v17;
_MMPTE *PteBase;
INT64 v19;
UNICODE_STRING *v20;
UINT8 v21;
UNICODE_STRING *v22;
int v23;
__int64 v24;
__int64 v25;
__int64 v26;
KIRQL v28;
char *v29;
__int64 v30;
INT64 v31;
if( (*(_DWORD *)(a1 + 196) & 0x12) != 0 )
return(unsigned __int64)*(unsigned int *)(a1 + 64) >> 12;
v2 = *(_QWORD *)(a1 + 48);
if( (unsigned int)MI_IS_PHYSICAL_ADDRESS((PVOID)v2) )
return(unsigned __int64)*(unsigned int *)(a1 + 64) >> 12;
v3 = *(_SECTION **)(a1 + 112);
if( !v3 )
return(unsigned __int64)*(unsigned int *)(a1 + 64) >> 12;
v4 = MiSectionControlArea(v3);
if( !*((_QWORD *)v4 + 18) )
return(unsigned __int64)*(unsigned int *)(a1 + 64) >> 12;
v5 = (char *)MmGetPteBase() + ((v2 >> 9) & 0x7FFFFFFFF8i64);
v6 = (INT64)v5;
if( (unsigned int)MiGetSystemRegionType(v2) == 1 )
SessionVm = MiGetSessionVm();
else
SessionVm = (__int64)MiGetAnyMultiplexedVm(1i64);
v30 = SessionVm;
v8 = *((_DWORD *)v4 + 14) & 0x800;
v9 = SessionVm;
v10 = 0i64;
v31 = (INT64)MiFreePrivateFixupEntryForSystemImage((VOID *)v2, 0i64);
SharedVm = MiGetSharedVm(v9);
v12 = ExAcquireSpinLockExclusive((PEX_SPIN_LOCK)SharedVm);
*((_DWORD *)SharedVm + 1) = 0;
v13 = (char *)v4 + 128;
v28 = v12;
v29 = (char *)v4 + 128;
if( v4 != (_CONTROL_AREA *)-128i64 )
{
v14 = v31;
while( 1 )
{
v15 = *((_DWORD *)v13 + 13) & 0x3FFFFFFF;
v16 = (unsigned int)(*((_DWORD *)v13 + 11) - v15);
if( (v13[32] & 0x3Eu) >= 8 )
{
v6 += 8i64 * (unsigned int)(*((_DWORD *)v13 + 11) - v15);
LABEL_12:
v10 += v16;
goto LABEL_36;
}
if( MiGetSubsectionDriverProtos(v13) )
{
v6 += 8 * v16;
goto LABEL_12;
}
v17 = 0;
if( !v16 )
goto LABEL_36;
PteBase = MmGetPteBase();
do
{
if( v14 && _bittest(*(const signed __int32 **)(*(_QWORD *)(v14 + 40) + 8i64), (v6 - (__int64)v5) >> 3) )
{
LABEL_19:
++v10;
goto LABEL_34;
}
v19 = MI_READ_PTE_LOCK_FREE(v6);
v31 = v19;
if( v19 )
{
if( v8 )
goto LABEL_19;
if( (v19 & 1) != 0 )
{
MI_READ_PTE_LOCK_FREE((INT64)&v31);
if( (MiGetWsleContents(0xFFFFFFFFFi64, ((v6 << 25) - ((_QWORD)PteBase << 25)) >> 16) & 0xF) == 9 )
goto LABEL_19;
LOBYTE(v23) = MI_PFN_IS_PROTO(v22, v20, v21, &v22->Length);
if( !v23 || (*(_QWORD *)(v24 + 40) & 0x1000000000i64) == 0 && *(__int64 *)(v24 + 8) > 0 )
goto LABEL_19;
v25 = v10 + 1;
if( (*(_DWORD *)(v24 + 16) & 0x400i64) != 0 )
v25 = v10;
v10 = v25;
}
else
{
v26 = v10 + 1;
if( (v19 & 0x400) != 0 && !MI_PROTO_FORMAT_COMBINED(v19) )
v26 = v10;
v10 = v26;
}
}
LABEL_34:
++v17;
v6 += 8i64;
}
while( v17 < v16 );
v13 = v29;
LABEL_36:
v13 = (char *)*((_QWORD *)v13 + 2);
v29 = v13;
if( !v13 )
{
v9 = v30;
v12 = v28;
break;
}
}
}
MiUnlockWorkingSetExclusive(v9, v12);
return v10;
}Referenced by:
MiSessionUpdateImageCharges