MiFindNextEnclaveBoundary
NTSTATUS __stdcall MiFindNextEnclaveBoundary(
ULONG_PTR Process,
VOID *Address,
UINT64 MaximumSize,
UINT64 *BytesToNextBoundary){
_EPROCESS *v7;
_ETHREAD *CurrentThread;
_EPROCESS *v9;
NTSTATUS v10;
unsigned __int64 Root;
char v13;
unsigned __int64 v14;
unsigned __int64 v15;
unsigned __int64 v16;
_QWORD **v17;
unsigned __int64 v18;
_QWORD *v19;
_KAPC_STATE ApcState;
memset(&ApcState, 0, sizeof(ApcState));
v7 = *(_EPROCESS **)&Process;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v9 = CurrentThread->Tcb.ApcState.Process;
if( v9 != *(_EPROCESS **)&Process )
KiStackAttachProcess(*(PVOID *)&Process, 0i64, &ApcState);
v10 = 0;
if( LODWORD(v7->Vm.Instance.VmWorkingSetList[7].NextPteToAccessClear) )
{
LOCK_ADDRESS_SPACE(CurrentThread, v7);
Root = (unsigned __int64)v7->VadRoot.Root;
v13 = 0;
if( Root )
{
v14 = (unsigned __int64)Address >> 12;
while( 1 )
{
if( v14 > (*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) )
{
v15 = *(_QWORD *)(Root + 8);
if( !v15 )
{
v16 = Root;
for( Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64;
Root;
Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64 )
{
if( *(_QWORD *)Root == v16 )
break;
v16 = Root;
}
LABEL_13:
if( Root )
{
while( (*(_DWORD *)(Root + 48) & 0x3100000) != 34603008 || (*(_DWORD *)(Root + 64) & 4) == 0 )
{
if( (*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) < ((unsigned __int64)Address + MaximumSize - 1) >> 12 )
{
v17 = *(_QWORD ***)(Root + 8);
v18 = Root;
if( v17 )
{
v19 = *v17;
for( Root = *(_QWORD *)(Root + 8); v19; v19 = (_QWORD *)*v19 )
Root = (unsigned __int64)v19;
}
else
{
for( Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64;
Root;
Root = *(_QWORD *)(Root + 16) & 0xFFFFFFFFFFFFFFFCui64 )
{
if( *(_QWORD *)Root == v18 )
break;
v18 = Root;
}
}
if( Root )
continue;
}
goto LABEL_37;
}
MaximumSize = ((*(unsigned int *)(Root + 24) | ((unsigned __int64)*(unsigned __int8 *)(Root + 32) << 32)) << 12)
- (_QWORD)Address;
}
LABEL_37:
*BytesToNextBoundary = MaximumSize;
goto LABEL_38;
}
}
else
{
if( v14 >= (*(unsigned int *)(Root + 24) | ((unsigned __int64)*(unsigned __int8 *)(Root + 32) << 32)) )
{
v13 = 1;
break;
}
v15 = *(_QWORD *)Root;
if( !*(_QWORD *)Root )
goto LABEL_13;
}
Root = v15;
}
}
if( !v13 || (*(_DWORD *)(Root + 48) & 0x3100000) != 34603008 || (*(_DWORD *)(Root + 64) & 4) == 0 )
goto LABEL_13;
*BytesToNextBoundary = (((*(unsigned int *)(Root + 28) | ((unsigned __int64)*(unsigned __int8 *)(Root + 33) << 32)) << 12) | 0xFFF)
- (_QWORD)Address
+ 1;
v10 = 2 - ((*(_BYTE *)(Root + 64) & 1) != 0);
LABEL_38:
UNLOCK_ADDRESS_SPACE(CurrentThread, v7);
}
else
{
*BytesToNextBoundary = MaximumSize;
}
if( v9 != v7 )
KiUnstackDetachProcess(&ApcState, 0i64);
return v10;
}Referenced by:
MmCopyVirtualMemory