PspQueryWorkingSetWatch

INT64 __stdcall PspQueryWorkingSetWatch(
        PVOID ProcessHandle,
        PROCESSINFOCLASS ProcessInformationClass,
        PVOID ProcessInformation,
        UINT64 ProcessInformationLength,
        UINT64 *ReturnLength,
        INT8 PreviousMode){
  INT64 result; 
  int v8; 
  PVOID v9; 
  __int64 v10; 
  int v11; 
  _ETHREAD *CurrentThread; 
  __int64 v13; 
  signed __int32 v14; 
  unsigned int v15; 
  unsigned int v16; 
  __int64 i; 
  char *v18; 
  __int64 j; 
  PVOID Object; 
  char *v21; 
  _ETHREAD *v22; 
  __int64 v23; 
  unsigned int v26; 
  v26 = ProcessInformationLength;
  Object = 0i64;
  if( ProcessInformationClass == ProcessWorkingSetWatchEx )
  {
    if( (ProcessInformationLength & 0x1F) != 0 )
      return 3221225476i64;
    v8 = 32;
  }
  else
  {
    v8 = 16;
  }
  if( (unsigned int)ExIsRestrictedCaller(PreviousMode) )
    return 3221225506i64;
  LODWORD(result) = ObReferenceObjectByHandleWithTag(
                      ProcessHandle,
                      0x400u,
                      (POBJECT_TYPE)PsProcessType,
                      PreviousMode,
                      0x79517350u,
                      &Object,
                      0i64);
  if( (int)result >= 0 )
  {
    v9 = Object;
    v10 = *((_QWORD *)Object + 166);
    v23 = v10;
    if( !v10 )
    {
      v11 = -1073741823;
LABEL_17:
      ObfDereferenceObjectWithTag(v9, 0x79517350ui64);
      return(unsigned int)v11;
    }
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    v22 = CurrentThread;
    v11 = 0;
    v13 = 0i64;
    --*((_WORD *)CurrentThread + 242);
    _m_prefetchw((const void *)v10);
    v14 = _InterlockedOr((volatile signed __int32 *)v10, 1u);
    if( (v14 & 1) != 0 )
    {
      v11 = -2147483622;
    }
    else
    {
      v15 = (unsigned __int16)v14 >> 1;
      if( (unsigned __int16)v14 >> 1 )
      {
        if( (v14 & 0x7FFF0000) != 0 )
          KeWaitForGate((PVOID)(v10 + 16), 0);
        v16 = v8 * (v15 + 1);
        if( v26 >= v16 )
        {
          _m_prefetchw((const void *)(v10 + 8));
          v13 = *(_QWORD *)(v10 + 8);
          if( ProcessInformationClass == ProcessWorkingSetWatchEx )
          {
            for( i = 0i64; ; i = (unsigned int)(i + 1) )
            {
              v18 = (char *)ProcessInformation + 32 * (unsigned int)i;
              if( (unsigned int)i >= v15 )
                break;
              *(_OWORD *)v18 = *(_OWORD *)(v10 + 24 * i + 40);
              *((_OWORD *)v18 + 1) = *(unsigned __int64 *)(v10 + 24 * i + 56);
            }
            v21 = (char *)ProcessInformation + 32 * (unsigned int)i;
            *((_QWORD *)v18 + 2) = 0i64;
            *((_QWORD *)v18 + 3) = 0i64;
          }
          else
          {
            v18 = (char *)ProcessInformation;
            v21 = (char *)ProcessInformation;
            for( j = 0i64; (unsigned int)j < v15; j = (unsigned int)(j + 1) )
            {
              *(_OWORD *)v18 = *(_OWORD *)(v10 + 24 * j + 40);
              v18 += 16;
              v21 = v18;
            }
          }
          *(_QWORD *)v18 = 0i64;
          *((_QWORD *)v18 + 1) = v13;
          if( ReturnLength )
            *(_DWORD *)ReturnLength = v16;
        }
        else
        {
          v11 = -1073741789;
          if( ReturnLength )
            *(_DWORD *)ReturnLength = v16;
        }
        if( v11 >= 0 )
        {
          _InterlockedExchangeAdd64((volatile signed __int64 *)(v10 + 8), -v13);
          *(_DWORD *)v10 = 0;
          goto LABEL_16;
        }
      }
      else
      {
        v11 = -2147483622;
      }
      _interlockedbittestandreset((volatile signed __int32 *)v10, 0);
    }
LABEL_16:
    KeLeaveCriticalRegionThread((__int64)CurrentThread);
    v9 = Object;
    goto LABEL_17;
  }
  return result;
}

Referenced by:

NtQueryInformationProcess