MiQueuePageAccessLog
VOID __fastcall MiQueuePageAccessLog(PSLIST_ENTRY ListEntry){
INT64 v2;
unsigned int v3;
int v4;
*((_QWORD *)&ListEntry[1].Next + 1) = KUSER_SHARED_DATA.TickCountQuad;
*((_DWORD *)&ListEntry->Next + 3) = dword_140CEBED0;
if( !ExAcquireRundownProtection((PEX_RUNDOWN_REF)&stru_140CEBE88) )
goto LABEL_9;
v3 = word_140CEBEC0;
if( word_140CEBEC0 >= (unsigned int)dword_140CEBEA8 )
{
_InterlockedExchangeAdd((volatile signed __int32 *)&xmmword_140C4FC10, 0x64u);
v4 = 0;
}
else
{
RtlpInterlockedPushEntrySList((PSLIST_HEADER)&word_140CEBEC0, ListEntry);
if( v3 >= 8 && !Event.Header.SignalState )
KeSetEvent(&Event, 0);
v4 = 1;
}
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&stru_140CEBE88);
if( !v4 )
{
LABEL_9:
LOBYTE(v2) = 1;
MmFreeAccessPfnBuffer((_MM_PAGE_ACCESS_INFO_HEADER *)ListEntry, v2);
}
}Referenced by:
MiCheckAndProcessCcAccessLog
MiEmptyPageAccessLog
MiGetCcAccessLog
MiReturnCcAccessLog
MiTrimOrAgeWorkingSet