MiQueryMemoryPhysicalContiguity

NTSTATUS __stdcall MiQueryMemoryPhysicalContiguity(
        PFN_WDFDRIVERERRORREPORTAPIMISSING *a1,
        INT128 *a2,
        INT64 a3,
        CHAR a4){
  INT64 v5; 
  __int64 v6; 
  unsigned __int64 v7; 
  NTSTATUS v8; 
  unsigned __int64 v9; 
  unsigned __int64 v10; 
  unsigned int v11; 
  __int64 v12; 
  char v13; 
  unsigned int v14; 
  __int64 *v15; 
  unsigned __int64 v16; 
  char *v17; 
  UINT64 v18; 
  _MDL *Pool; 
  __int16 v20; 
  int v21; 
  unsigned __int64 v22; 
  unsigned __int64 v23; 
  UINT64 v24; 
  __int64 v25; 
  UINT64 BugCheckOnFailure; 
  UINT64 Priority; 
  int v30; 
  __int64 v31; 
  unsigned int v32; 
  NTSTATUS v33; 
  _MDL *v34; 
  unsigned __int64 v35; 
  INT64 v36; 
  PVOID Process; 
  __int128 v38; 
  __int128 v39; 
  VOID *Address; 
  unsigned __int64 v41; 
  _ETHREAD *CurrentThread; 
  _KAPC_STATE ApcState; 
  char Src[32]; 

  Process = a1;
  v33 = 0;
  memset(&ApcState, 0, sizeof(ApcState));
  v5 = 0i64;
  v34 = 0i64;
  v6 = 0i64;
  v30 = 0;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v7 = 40i64;
  if( a3 != 40 )
  {
    v8 = -1073741820;
    goto LABEL_52;
  }
  if( a4 )
    ProbeForWrite((UINT64)a2, 40i64, 8i64);
  v38 = *(_OWORD *)a2;
  v39 = *((_OWORD *)a2 + 1);
  Address = (VOID *)*((_QWORD *)a2 + 4);
  v7 = DWORD2(v39);
  if( (DWORD2(v39) & 0xFFFFFFFE) != 0 )
    goto LABEL_51;
  v9 = v38;
  if( (unsigned __int64)v38 > 0x7FFFFFFEFFFFi64 )
    goto LABEL_51;
  v10 = v39;
  if( !(_QWORD)v39 || (((_QWORD)v39 - 1i64) & (unsigned __int64)v39) != 0 || (unsigned __int64)v39 <= 0x1000 )
    goto LABEL_51;
  LOBYTE(v11) = MiGetLargestPageIndex();
  v14 = v11;
  v32 = v11;
  if( v11 < 3 )
  {
    a3 = (unsigned __int64)v39 >> 12;
    v15 = &MiLargePageSizes[v11];
    do
    {
      if( *v15 == a3 )
        break;
      v32 = ++v14;
      ++v15;
    }
    while( v14 < 3 );
    v7 = DWORD2(v39);
  }
  if( v14 == 3 )
  {
LABEL_16:
    v8 = -1073741637;
    goto LABEL_52;
  }
  if( (v12 & *((_QWORD *)&v38 + 1)) != 0 || ((unsigned __int64)v38 & ~v12) != (_QWORD)v38 )
    goto LABEL_51;
  LODWORD(v36) = 2 * (v7 & 1);
  v7 = *((_QWORD *)&v38 + 1) % (unsigned __int64)v39;
  v41 = *((_QWORD *)&v38 + 1) / (unsigned __int64)v39;
  v16 = 4 * (*((_QWORD *)&v38 + 1) / (unsigned __int64)v39);
  v35 = v16;
  if( v16 > 0x20 )
  {
    if( v16 <= 0xFFFFE000 )
    {
      LODWORD(v18) = MmSizeOfMdl(Address, v16);
      Pool = (_MDL *)MiAllocatePool(64i64, v18, 0x20206D4Dui64);
      v5 = (INT64)Pool;
      v34 = Pool;
      if( !Pool )
        goto LABEL_24;
      Pool->Next = 0i64;
      v20 = (__int16)Address;
      Pool->Size = 8 * (((v16 + ((unsigned __int16)Address & 0xFFF) + 4095i64) >> 12) + 6);
      Pool->MdlFlags = 0;
      Pool->StartVa = (void *)((unsigned __int64)Address & 0xFFFFFFFFFFFFF000ui64);
      v21 = v20 & 0xFFF;
      Pool->ByteOffset = v21;
      Pool->ByteCount = v16;
      LOBYTE(v21) = a4;
      MmProbeAndLockPages(Pool, v21, IoWriteAccess);
      if( (*(_BYTE *)(v5 + 10) & 5) != 0 )
      {
        v17 = *(char **)(v5 + 24);
      }
      else
      {
        LODWORD(Priority) = 1073741840;
        LODWORD(BugCheckOnFailure) = 0;
        v17 = (char *)MmMapLockedPagesSpecifyCache((_MDL *)v5, 0, MmCached, 0i64, BugCheckOnFailure, Priority);
      }
      if( !v17 )
      {
LABEL_24:
        v8 = -1073741670;
        goto LABEL_52;
      }
      goto LABEL_29;
    }
LABEL_51:
    v8 = -1073741811;
    goto LABEL_52;
  }
  v17 = Src;
  if( v13 )
    ProbeForWrite((UINT64)Address, v16, 4i64);
LABEL_29:
  if( CurrentThread->Tcb.ApcState.Process != Process )
  {
    KiStackAttachProcess(Process, 0i64, &ApcState);
    v30 = 1;
  }
  v22 = v9 >> 12;
  v23 = v10 >> 12;
  v31 = 0i64;
  if( v41 )
  {
    while( 1 )
    {
      if( v6 )
      {
        if( v22 < (*(unsigned int *)(v6 + 24) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 32) << 32))
          || (v7 = *(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32), v22 > v7) )
        {
          MiUnlockAndDereferenceVadShared((PVOID)v6);
          v6 = 0i64;
        }
      }
      v24 = v22 << 12;
      if( !v6 )
      {
        LODWORD(v25) = MiObtainReferencedVadEx(v22 << 12, 2, (INT64 *)&v33);
        v6 = v25;
        if( !v25 )
        {
          v8 = v33;
          goto LABEL_54;
        }
      }
      v22 += v23;
      if( v22 - 1 > (*(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32)) )
        break;
      if( (*(_DWORD *)(v6 + 48) & 0x70) != 0 || (*(_DWORD *)(v6 + 48) & 0x100000) == 0 )
        goto LABEL_16;
      *(_DWORD *)&v17[4 * v31] = 0;
      *(_DWORD *)&v17[4 * v31] ^= (*(_DWORD *)&v17[4 * v31] ^ MiQueryVaPhysicalContiguity(
                                                                (INT64)Process + 1664,
                                                                v24,
                                                                v32,
                                                                (unsigned int)v36)) & 3;
      if( ++v31 >= v41 )
      {
        LODWORD(v16) = v35;
        goto LABEL_44;
      }
    }
    v8 = -1073741800;
  }
  else
  {
LABEL_44:
    if( v6 )
      MiUnlockAndDereferenceVadShared((PVOID)v6);
    v6 = 0i64;
    v35 = 0i64;
    if( v30 )
    {
      KiUnstackDetachProcess(&ApcState, 0i64);
      v30 = 0;
    }
    if( v17 == Src )
      memmove(Address, v17, v16);
    v8 = 0;
  }
LABEL_52:
  if( v6 )
    MiUnlockAndDereferenceVadShared((PVOID)v6);
LABEL_54:
  if( v30 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  if( v5 )
  {
    if( (*(_BYTE *)(v5 + 10) & 2) != 0 )
      MmUnlockPages(v5, v7, a3);
    ExFreePoolWithTag((PVOID)v5, 0);
  }
  return v8;
}

Referenced by:

MmQueryVirtualMemory