MiFindNextEnclaveBoundary

NTSTATUS __stdcall MiFindNextEnclaveBoundary(
        ULONG_PTR Process,
        VOID *Address,
        UINT64 MaximumSize,
        UINT64 *BytesToNextBoundary){
  _EPROCESS *v7; 
  _ETHREAD *CurrentThread; 
  _EPROCESS *v9; 
  NTSTATUS v10; 
  unsigned __int64 Root; 
  char v13; 
  unsigned __int64 v14; 
  unsigned __int64 v15; 
  unsigned __int64 v16; 
  _QWORD **v17; 
  unsigned __int64 v18; 
  _QWORD *v19; 
  _KAPC_STATE ApcState; 

  memset(&ApcState, 0, sizeof(ApcState));
  v7 = *(_EPROCESS **)&Process;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v9 = CurrentThread->Tcb.ApcState.Process;
  if( v9 != *(_EPROCESS **)&Process )
    KiStackAttachProcess(*(PVOID *)&Process, 0i64, &ApcState);
  v10 = 0;
  if( LODWORD(v7->Vm.Instance.VmWorkingSetList[7].NextPteToAccessClear) )
  {
    LOCK_ADDRESS_SPACE(CurrentThread, v7);
    Root = (unsigned __int64)v7->VadRoot.Root;
    v13 = 0;
    if( Root )
    {
      v14 = (unsigned __int64)Address >> 12;
      while( 1 )
      {
        if( v14 > (*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) )
        {
          v15 = *(_QWORD *)(Root + 8);
          if( !v15 )
          {
            v16 = Root;
            for( Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64;
                  Root;
                  Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64 )
            {
              if( *(_QWORD *)Root == v16 )
                break;
              v16 = Root;
            }
LABEL_13:
            if( Root )
            {
              while( (*(_DWORD *)(Root + 48) & 0x3100000) != 34603008 || (*(_DWORD *)(Root + 64) & 4) == 0 )
              {
                if( (*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) < ((unsigned __int64)Address + MaximumSize - 1) >> 12 )
                {
                  v17 = *(_QWORD ***)(Root + 8);
                  v18 = Root;
                  if( v17 )
                  {
                    v19 = *v17;
                    for( Root = *(_QWORD *)(Root + 8); v19; v19 = (_QWORD *)*v19 )
                      Root = (unsigned __int64)v19;
                  }
                  else
                  {
                    for( Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64;
                          Root;
                          Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64 )
                    {
                      if( *(_QWORD *)Root == v18 )
                        break;
                      v18 = Root;
                    }
                  }
                  if( Root )
                    continue;
                }
                goto LABEL_37;
              }
              MaximumSize = ((*(unsigned int *)(Root + 24) | ((unsigned __int64)*(unsigned __int8 *)(Root + 32) << 32)) << 12)
                          - (_QWORD)Address;
            }
LABEL_37:
            *BytesToNextBoundary = MaximumSize;
            goto LABEL_38;
          }
        }
        else
        {
          if( v14 >= (*(unsigned int *)(Root + 24) | ((unsigned __int64)*(unsigned __int8 *)(Root + 32) << 32)) )
          {
            v13 = 1;
            break;
          }
          v15 = *(_QWORD *)Root;
          if( !*(_QWORD *)Root )
            goto LABEL_13;
        }
        Root = v15;
      }
    }
    if( !v13 || (*(_DWORD *)(Root + 48) & 0x3100000) != 34603008 || (*(_DWORD *)(Root + 64) & 4) == 0 )
      goto LABEL_13;
    *BytesToNextBoundary = (((*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) << 12) | 0xFFF)
                         - (_QWORD)Address
                         + 1;
    v10 = 2 - ((*(_BYTE *)(Root + 64) & 1) != 0);
LABEL_38:
    UNLOCK_ADDRESS_SPACE(CurrentThread, v7);
  }
  else
  {
    *BytesToNextBoundary = MaximumSize;
  }
  if( v9 != v7 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  return v10;
}

Referenced by:

MmCopyVirtualMemory