MiRemovePteTracker

VOID __stdcall MiRemovePteTracker(MDL *MemoryDescriptorList, PVOID VirtualAddress, UINT64 NumberOfPtes){
  struct _SLIST_ENTRY *v5; 
  __int64 v6; 
  unsigned __int64 v7; 
  __int64 *v8; 
  __int64 *v9; 
  ULONG_PTR v10; 
  _MDL *v11; 
  void *v12; 
  __int64 v13; 
  __int64 **v14; 
  struct _KLOCK_QUEUE_HANDLE LockHandle; 
  memset(&LockHandle, 0, sizeof(LockHandle));
  v5 = 0i64;
  v6 = 40543i64 * (unsigned int)((unsigned __int64)VirtualAddress >> 12);
  v7 = (unsigned __int64)VirtualAddress & 0xFFFFFFFFFFFFF000ui64;
  KeAcquireInStackQueuedSpinLock(&qword_140C4E810, &LockHandle);
  v8 = &qword_140C4F570[2 * (((unsigned __int8)v6 ^ BYTE4(v6)) & 0xF)];
  v9 = (__int64 *)*v8;
  if( (__int64 *)*v8 == v8 )
    goto LABEL_16;
  do
  {
    v10 = v9[4];
    if( v7 == (v10 & 0xFFFFFFFFFFFFF000ui64) )
    {
      if( v5 )
        KeBugCheckEx(0xDAu, 1ui64, (ULONG_PTR)v9, (ULONG_PTR)MemoryDescriptorList, (ULONG_PTR)v5);
      if( v9[3] != NumberOfPtes )
        KeBugCheckEx(0xDAu, 2ui64, (ULONG_PTR)v9, v9[3], NumberOfPtes);
      if( MemoryDescriptorList && (MemoryDescriptorList->MdlFlags & 0x200) == 0 )
      {
        v11 = (_MDL *)v9[7];
        if( v11 != MemoryDescriptorList[1].Next )
          KeBugCheckEx(0xDAu, 4ui64, (ULONG_PTR)v9, (ULONG_PTR)v11, (ULONG_PTR)MemoryDescriptorList[1].Next);
        if( !byte_140C4EA94 )
        {
          if( (void *)v10 != MemoryDescriptorList->MappedSystemVa )
            KeBugCheckEx(0xDAu, 3ui64, (ULONG_PTR)v9, v10, (ULONG_PTR)MemoryDescriptorList->MappedSystemVa);
          v12 = (void *)v9[5];
          if( v12 != MemoryDescriptorList->StartVa )
            KeBugCheckEx(0xDAu, 5ui64, (ULONG_PTR)v9, (ULONG_PTR)v12, (ULONG_PTR)MemoryDescriptorList->StartVa);
        }
      }
      v13 = *v9;
      v14 = (__int64 **)v9[1];
      if( *(__int64 **)(*v9 + 8) != v9 || *v14 != v9 )
        __fastfail(3u);
      *v14 = (__int64 *)v13;
      v5 = (struct _SLIST_ENTRY *)v9;
      *(_QWORD *)(v13 + 8) = v14;
    }
    v9 = (__int64 *)*v9;
  }
  while( v9 != v8 );
  if( !v5 )
  {
LABEL_16:
    if( !byte_140C4E8FD )
      KeBugCheckEx(0xDAu, 6ui64, (ULONG_PTR)MemoryDescriptorList, v7, NumberOfPtes);
  }
  qword_140C4F670 -= NumberOfPtes;
  --qword_140C4F678;
  KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
  __writecr8(LockHandle.OldIrql);
  if( v5 )
    RtlpInterlockedPushEntrySList((PSLIST_HEADER)&xmmword_140C4E800, v5);
}

Referenced by:

MmFreeMappingAddress
MmUnlockPages
MmUnmapIoSpace
MmUnmapLockedPages