ExAllocatePoolWithQuotaTag

VOID *__stdcall ExAllocatePoolWithQuotaTag(POOL_TYPE PoolType, UINT64 NumberOfBytes, UINT64 Tag){
  unsigned __int32 v3; 
  __int32 v4; 
  unsigned int v5; 
  _EPROCESS *Process; 
  unsigned __int32 v7; 
  VOID **PoolWithTag; 
  char *v9; 
  __int16 v10; 
  char *v11; 
  __int64 v12; 
  char *v13; 
  __int64 v14; 
  unsigned __int64 v15; 
  __int64 v16; 
  UINT64 *CacheAlign; 
  char v18; 
  UINT64 v19; 
  UINT64 v20; 
  unsigned __int64 v21; 
  bool v22; 
  signed __int64 v23; 
  unsigned __int64 v24; 
  unsigned __int64 v25; 
  unsigned __int64 v26; 
  __int64 v27; 
  __int64 v28; 
  unsigned __int64 v30; 
  unsigned __int64 v31; 
  unsigned __int64 v32; 
  UINT64 v33; 
  NTSTATUS v34; 
  int v35[8]; 
  UINT64 pLimit; 
  __int64 v37; 
  char v38; 
  UINT32 Taga; 
  char *v40; 

  Taga = Tag;
  v3 = PoolType & 0xFFFFFFF7;
  v4 = PoolType & 8;
  v5 = Tag;
  Process = KeGetCurrentThread()->ApcState.Process;
  if( (PoolType & 8) == 0 )
    v3 = PoolType;
  v7 = v3 + 8;
  if( Process == PsInitialSystemProcess )
    v7 = v3;
  PoolWithTag = ExAllocatePoolWithTag(v7, NumberOfBytes, Tag);
  v9 = (char *)PoolWithTag;
  if( ((unsigned __int16)PoolWithTag & 0xFFF) == 0 )
  {
    if( !PoolWithTag && !v4 )
      RtlRaiseStatus(-1073741670);
    return v9;
  }
  if( ExpSpecialAllocations )
  {
    LODWORD(v33) = ExGetHeapFromVA(PoolWithTag);
    if( ExpHpIsSpecialPoolHeap(v33) )
      return v9;
  }
  if( (v7 & 8) == 0 )
    return v9;
  v10 = *((_WORD *)v9 - 7);
  v11 = v9 - 16;
  v12 = ExpPoolQuotaCookie;
  v13 = 0i64;
  v14 = (unsigned __int8)v10;
  v40 = 0i64;
  *((_QWORD *)v9 - 1) = (unsigned __int64)(v9 - 16) ^ ExpPoolQuotaCookie;
  if( (v10 & 0x400) != 0 )
  {
    v13 = &v11[-16 * (unsigned __int8)*(_WORD *)v11];
    v40 = v13;
    v14 = (unsigned __int8)*((_WORD *)v13 + 1);
    *((_QWORD *)v13 + 1) = (unsigned __int64)v13 ^ v12;
  }
  v15 = 16 * v14;
  if( Process == PsInitialSystemProcess )
  {
LABEL_21:
    v27 = ExpPoolQuotaCookie;
    *((_QWORD *)v11 + 1) = (unsigned __int64)Process ^ (unsigned __int64)v11 ^ ExpPoolQuotaCookie;
    if( v13 )
      *((_QWORD *)v13 + 1) = (unsigned __int64)Process ^ (unsigned __int64)v13 ^ v27;
    if( ObpTraceFlags )
      ObpPushStackInfo((_OBJECT_HEADER *)&Process[-1].DynamicEnforcedCetCompatibleRanges, 1u, 1ui64, v5);
    v28 = _InterlockedIncrement64((volatile signed __int64 *)&Process[-1].DynamicEnforcedCetCompatibleRanges);
    if( v28 <= 1 )
      KeBugCheckEx(0x18u, 0i64, Process, (PVOID)0x10, (PVOID)v28);
    return v9;
  }
  v16 = v7 & 1;
  CacheAlign = (UINT64 *)Process->QuotaBlock->QuotaEntry[(unsigned __int64)(unsigned int)v16].CacheAlign;
  v18 = PspResourceFlags[8 * v16];
  v38 = v18;
  v37 = 8 * v16;
  _m_prefetchw(CacheAlign);
  v19 = *CacheAlign;
  _InterlockedOr(v35, 0);
LABEL_12:
  v20 = CacheAlign[8];
LABEL_13:
  pLimit = v20;
  while( 1 )
  {
    v21 = v19 + v15;
    if( v19 + v15 < v19 )
      break;
    if( v21 <= v20 )
    {
      v23 = _InterlockedCompareExchange64((volatile signed __int64 *)CacheAlign, v21, v19);
      v22 = v19 == v23;
      v19 = v23;
      if( !v22 )
        goto LABEL_12;
      _m_prefetchw(CacheAlign + 1);
      v24 = CacheAlign[1];
      if( v21 > v24 )
      {
        do
        {
          v31 = v24;
          v24 = _InterlockedCompareExchange64((volatile signed __int64 *)CacheAlign + 1, v21, v24);
        }
        while( v24 != v31 && v21 > v24 );
      }
      if( (v18 & 4) != 0 )
      {
        v25 = v15 + _InterlockedExchangeAdd64((volatile signed __int64 *)&Process->ProcessQuotaUsage[v16], v15);
        _m_prefetchw(&Process->ProcessQuotaPeak[v16]);
        v26 = Process->ProcessQuotaPeak[v16];
        if( v25 > v26 )
        {
          do
          {
            v30 = v26;
            v26 = _InterlockedCompareExchange64((volatile signed __int64 *)&Process->ProcessQuotaPeak[v16], v25, v26);
          }
          while( v26 != v30 && v25 > v26 );
        }
      }
      goto LABEL_20;
    }
    if( (v18 & 1) == 0 || !CacheAlign[10] )
      break;
    v32 = _InterlockedExchange64((volatile __int64 *)CacheAlign + 9, 0i64);
    if( v32 )
    {
      v20 = v32 + _InterlockedExchangeAdd64((volatile signed __int64 *)CacheAlign + 8, v32);
      goto LABEL_13;
    }
    if( !PspExpandQuota((_PS_RESOURCE_TYPE)v16, (_PSP_QUOTA_ENTRY *)CacheAlign, v19, v15, &pLimit) )
      break;
    v20 = pLimit;
    v18 = v38;
  }
  v34 = *(_DWORD *)&PspResourceFlags[v37 + 4];
  if( v34 >= 0 )
  {
LABEL_20:
    v13 = v40;
    v5 = Taga;
    goto LABEL_21;
  }
  ExFreePoolWithTag(v9, Taga);
  if( !v4 )
    RtlRaiseStatus(v34);
  return 0i64;
}

Referenced by:

CmpAllocatePostBlock
CmpAllocateTransientPoolWithQuotaTag
CmpNameFromAttributes
CmpNotifyChangeKey
CmpSaveKeyByFileCopy
DbgkRegisterErrorPort
DbgkpQueueMessage
ExAllocatePool2
ExAllocatePool3
ExAllocatePoolMm
ExAllocatePoolWithQuota
ExGetWakeTimerList
ExLockUserBuffer
ExpGetDeviceDataInformation
ExpGetSystemFirmwareTableInformation
ExpQueryElamCertInfo
ExpQueryPortableWorkspaceEfiLauncherInformation
ExpQuerySystemInformation
ExpStringCapture
ExpWnfCreateNameInstance
ExpWnfSubscribeNameInstance
ExpWnfWriteStateData
FsRtlAllocateExtraCreateParameter
FsRtlAllocateExtraCreateParameterList
FsRtlAllocatePoolWithQuota
FsRtlAllocatePoolWithQuotaTag
IopAllocateIrpPrivate
IopAllocateMiniCompletionPacket
IopCreateFile
IopVerifierExAllocatePoolWithQuota
IopVerifierExAllocatePoolWithQuota_0
IopVerifierExAllocatePoolWithQuota_2
IopVerifierExAllocatePoolWithQuota_3
IopVerifierExAllocatePoolWithQuota_4
IopVerifierExAllocatePoolWithQuota_5
KeEnableProfiling
MiAllocatePool
NtCreateWorkerFactory
NtQueryDirectoryObject
NtQuerySecurityPolicy
NtQueueApcThreadEx
NtRegisterThreadTerminatePort
NtSetInformationJobObject
NtSetInformationProcess
NtTraceControl
PiControlAllocateBufferForUserModeCaller
PiControlMakeUserModeCallersCopy
PopCaptureReasonContext
PsCreateVsmEnclave
PsInitializeVsmEnclave
PsSetCpuQuotaInformation
PspBuildCreateProcessContext
PspCaptureUserProcessParameters
PspIsDfssEnabled
PspPrepareEnclaveThreadWait
PspReadIFEOPerfOptions
PspVsmEnclaveHashAllocator
RtlAcquirePrivilege
RtlAddResourceAttributeAce
RtlAllocateAndInitializeSidEx
RtlGetAppContainerParent
RtlInsertDynamicFunctionTable
RtlIsUntrustedObject
RtlQueryImageFileKeyOption
RtlQueryModuleInformation
RtlpGetPolicyValueForSystemCapability
RtlpProcessIFEOKeyFilter
VerifierExAllocatePoolWithQuotaTag
VerifierPortExAllocatePoolWithQuotaTag
VrpHandleIoctlLoadDifferencingHiveForHost