MiQueryMemoryPhysicalContiguity
NTSTATUS __stdcall MiQueryMemoryPhysicalContiguity(
PFN_WDFDRIVERERRORREPORTAPIMISSING *a1,
INT128 *a2,
INT64 a3,
CHAR a4){
INT64 v5;
__int64 v6;
unsigned __int64 v7;
NTSTATUS v8;
unsigned __int64 v9;
unsigned __int64 v10;
unsigned int v11;
__int64 v12;
char v13;
unsigned int v14;
__int64 *v15;
unsigned __int64 v16;
char *v17;
UINT64 v18;
_MDL *Pool;
__int16 v20;
int v21;
unsigned __int64 v22;
unsigned __int64 v23;
UINT64 v24;
__int64 v25;
UINT64 BugCheckOnFailure;
UINT64 Priority;
int v30;
__int64 v31;
unsigned int v32;
NTSTATUS v33;
_MDL *v34;
unsigned __int64 v35;
INT64 v36;
PVOID Process;
__int128 v38;
__int128 v39;
VOID *Address;
unsigned __int64 v41;
_ETHREAD *CurrentThread;
_KAPC_STATE ApcState;
char Src[32];
Process = a1;
v33 = 0;
memset(&ApcState, 0, sizeof(ApcState));
v5 = 0i64;
v34 = 0i64;
v6 = 0i64;
v30 = 0;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v7 = 40i64;
if( a3 != 40 )
{
v8 = -1073741820;
goto LABEL_52;
}
if( a4 )
ProbeForWrite((UINT64)a2, 40i64, 8i64);
v38 = *(_OWORD *)a2;
v39 = *((_OWORD *)a2 + 1);
Address = (VOID *)*((_QWORD *)a2 + 4);
v7 = DWORD2(v39);
if( (DWORD2(v39) & 0xFFFFFFFE) != 0 )
goto LABEL_51;
v9 = v38;
if( (unsigned __int64)v38 > 0x7FFFFFFEFFFFi64 )
goto LABEL_51;
v10 = v39;
if( !(_QWORD)v39 || (((_QWORD)v39 - 1i64) & (unsigned __int64)v39) != 0 || (unsigned __int64)v39 <= 0x1000 )
goto LABEL_51;
LOBYTE(v11) = MiGetLargestPageIndex();
v14 = v11;
v32 = v11;
if( v11 < 3 )
{
a3 = (unsigned __int64)v39 >> 12;
v15 = &MiLargePageSizes[v11];
do
{
if( *v15 == a3 )
break;
v32 = ++v14;
++v15;
}
while( v14 < 3 );
v7 = DWORD2(v39);
}
if( v14 == 3 )
{
LABEL_16:
v8 = -1073741637;
goto LABEL_52;
}
if( (v12 & *((_QWORD *)&v38 + 1)) != 0 || ((unsigned __int64)v38 & ~v12) != (_QWORD)v38 )
goto LABEL_51;
LODWORD(v36) = 2 * (v7 & 1);
v7 = *((_QWORD *)&v38 + 1) % (unsigned __int64)v39;
v41 = *((_QWORD *)&v38 + 1) / (unsigned __int64)v39;
v16 = 4 * (*((_QWORD *)&v38 + 1) / (unsigned __int64)v39);
v35 = v16;
if( v16 > 0x20 )
{
if( v16 <= 0xFFFFE000 )
{
LODWORD(v18) = MmSizeOfMdl(Address, v16);
Pool = (_MDL *)MiAllocatePool(64i64, v18, 0x20206D4Dui64);
v5 = (INT64)Pool;
v34 = Pool;
if( !Pool )
goto LABEL_24;
Pool->Next = 0i64;
v20 = (__int16)Address;
Pool->Size = 8 * (((v16 + ((unsigned __int16)Address & 0xFFF) + 4095i64) >> 12) + 6);
Pool->MdlFlags = 0;
Pool->StartVa = (void *)((unsigned __int64)Address & 0xFFFFFFFFFFFFF000ui64);
v21 = v20 & 0xFFF;
Pool->ByteOffset = v21;
Pool->ByteCount = v16;
LOBYTE(v21) = a4;
MmProbeAndLockPages(Pool, v21, IoWriteAccess);
if( (*(_BYTE *)(v5 + 10) & 5) != 0 )
{
v17 = *(char **)(v5 + 24);
}
else
{
LODWORD(Priority) = 1073741840;
LODWORD(BugCheckOnFailure) = 0;
v17 = (char *)MmMapLockedPagesSpecifyCache((_MDL *)v5, 0, MmCached, 0i64, BugCheckOnFailure, Priority);
}
if( !v17 )
{
LABEL_24:
v8 = -1073741670;
goto LABEL_52;
}
goto LABEL_29;
}
LABEL_51:
v8 = -1073741811;
goto LABEL_52;
}
v17 = Src;
if( v13 )
ProbeForWrite((UINT64)Address, v16, 4i64);
LABEL_29:
if( CurrentThread->Tcb.ApcState.Process != Process )
{
KiStackAttachProcess(Process, 0i64, &ApcState);
v30 = 1;
}
v22 = v9 >> 12;
v23 = v10 >> 12;
v31 = 0i64;
if( v41 )
{
while( 1 )
{
if( v6 )
{
if( v22 < (*(unsigned int *)(v6 + 24) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 32) << 32))
|| (v7 = *(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32), v22 > v7) )
{
MiUnlockAndDereferenceVadShared((PVOID)v6);
v6 = 0i64;
}
}
v24 = v22 << 12;
if( !v6 )
{
LODWORD(v25) = MiObtainReferencedVadEx(v22 << 12, 2, (INT64 *)&v33);
v6 = v25;
if( !v25 )
{
v8 = v33;
goto LABEL_54;
}
}
v22 += v23;
if( v22 - 1 > (*(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32)) )
break;
if( (*(_DWORD *)(v6 + 48) & 0x70) != 0 || (*(_DWORD *)(v6 + 48) & 0x100000) == 0 )
goto LABEL_16;
*(_DWORD *)&v17[4 * v31] = 0;
*(_DWORD *)&v17[4 * v31] ^= (*(_DWORD *)&v17[4 * v31] ^ MiQueryVaPhysicalContiguity(
(INT64)Process + 1664,
v24,
v32,
(unsigned int)v36)) & 3;
if( ++v31 >= v41 )
{
LODWORD(v16) = v35;
goto LABEL_44;
}
}
v8 = -1073741800;
}
else
{
LABEL_44:
if( v6 )
MiUnlockAndDereferenceVadShared((PVOID)v6);
v6 = 0i64;
v35 = 0i64;
if( v30 )
{
KiUnstackDetachProcess(&ApcState, 0i64);
v30 = 0;
}
if( v17 == Src )
memmove(Address, v17, v16);
v8 = 0;
}
LABEL_52:
if( v6 )
MiUnlockAndDereferenceVadShared((PVOID)v6);
LABEL_54:
if( v30 )
KiUnstackDetachProcess(&ApcState, 0i64);
if( v5 )
{
if( (*(_BYTE *)(v5 + 10) & 2) != 0 )
MmUnlockPages(v5, v7, a3);
ExFreePoolWithTag((PVOID)v5, 0);
}
return v8;
}Referenced by:
MmQueryVirtualMemory