MmFreePoolMemory

INT64 __fastcall MmFreePoolMemory(UINT64 *a1, UINT64 *rdx0){
  ULONG_PTR v2; 
  ULONG_PTR v3; 
  unsigned __int64 v4; 
  int v5; 
  unsigned int v6; 
  unsigned int v7; 
  int v8; 
  __int64 AnyMultiplexedVm; 
  char *v10; 
  __int64 v11; 
  __int128 v13; 
  UINT64 a2[2]; 
  __int128 v15; 
  v2 = *rdx0;
  v3 = *a1;
  v4 = (*rdx0 >> 12) + ((*rdx0 & 0xFFF) != 0);
  v5 = MiDeterminePoolType(*a1);
  if( v5 == 32 )
    KeBugCheckEx(0x1Au, 0x5305ui64, v3, v2, v6);
  if( v5 == 33 )
    v7 = 1;
  else
    v7 = (v5 != 0) + 5;
  v8 = v6 | 0x4000;
  if( (v6 & 0x8000) == 0 )
    v8 = v6;
  LODWORD(AnyMultiplexedVm) = v8;
  if( (v8 & 0x4000) != 0 )
  {
    if( (v5 & 1) != 0 )
    {
      v13 = 0i64;
      *(_OWORD *)a2 = 0i64;
      v15 = 0i64;
      v10 = (char *)MmGetPteBase() + ((v3 >> 9) & 0x7FFFFFFFF8i64);
      if( (v5 & 0x20) != 0 )
        AnyMultiplexedVm = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64) + 256i64;
      else
        AnyMultiplexedVm = (__int64)MiGetAnyMultiplexedVm(2i64);
      MiDeleteSystemPagableVm(AnyMultiplexedVm, 0i64, (unsigned __int64)v10, v4, (v8 & 0x40000000) != 0, &v13);
      v11 = a2[1];
      MiReturnCommit(
        *(_MI_PARTITION **)(qword_140C4E388 + 8i64 * *(unsigned __int16 *)(AnyMultiplexedVm + 174)),
        a2[1] - *((_QWORD *)&v13 + 1));
      LOWORD(AnyMultiplexedVm) = v8;
    }
    else
    {
      if( (v8 & 0x40000000) == 0 && MmProtectFreedNonPagedPool )
        LODWORD(AnyMultiplexedVm) = v8 | 0x40000000;
      v11 = MiClearNonPagedPtes(v3, v4, AnyMultiplexedVm, 1u);
    }
    if( v11 )
      MiCountSystemPool(v7, v11, 0i64);
  }
  if( (AnyMultiplexedVm & 0x8000) != 0 )
  {
    if( v7 == 1 )
      _InterlockedExchangeAdd(
        (volatile signed __int32 *)(*(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64) + 868i64),
        -(int)(v4 >> 9));
    MiReturnSystemVa(v3, v2 + v3, v7);
  }
  return 0i64;
}

Referenced by:

MmAllocatePoolMemory
RtlpHpEnvFreeVA
RtlpHpVaMgrCtxFree