MiObtainSystemCharges
INT64 __stdcall MiObtainSystemCharges(_MI_PARTITION *Partition, UINT64 QuotaCharge, INT64 a3){
int v3;
__int64 v6;
__int64 v8;
v3 = a3;
if( !(unsigned int)MiChargeCommit(Partition, QuotaCharge, 1ui64) )
return 0i64;
v6 = 128i64;
if( v3 != 2 )
v6 = 0i64;
if( !(unsigned int)MiChargeResident((ULONG_PTR *)Partition, QuotaCharge, v6) )
{
MiReturnCommit(Partition, QuotaCharge);
return 0i64;
}
if( v3 == 1 || v3 == 11 )
{
v8 = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64);
_InterlockedExchangeAdd64((volatile signed __int64 *)(v8 + 48), QuotaCharge);
_InterlockedExchangeAdd64((volatile signed __int64 *)(v8 + 40), QuotaCharge);
}
else if( v3 != 2 )
{
if( v3 == 4 )
_InterlockedExchangeAdd64(&qword_140C4ED18, QuotaCharge);
else
_InterlockedExchangeAdd64(&qword_140C4ED00, QuotaCharge);
}
return 1i64;
}Referenced by:
MiGetLargePagesForSystemMapping
MiGetPageTablePages