MmInitializeProcessAddressSpace

__int64 __fastcall MmInitializeProcessAddressSpace(
        ULONG_PTR BugCheckParameter1,
        ULONG_PTR a2,
        _DWORD *a3,
        unsigned int *a4,
        int a5){
  INT64 v9; 
  INT64 v10; 
  _MMSUPPORT_INSTANCE *v11; 
  __int64 v12; 
  int inserted; 
  void *v14; 
  UINT8 v15; 
  __int64 v17; 
  __int64 v18; 
  __int64 v19; 
  __int128 v20; 
  __int64 v21; 
  __int128 v22; 
  __int128 *v23; 
  __int128 v24; 
  __int128 v25; 
  __int64 v26; 
  __int128 v27; 
  __int128 v28; 
  UINT64 v29; 
  UINT64 *v30; 
  __int64 v31; 
  _QWORD *v32; 
  _ETHREAD *CurrentThread; 
  PVOID P; 
  _MMVAD_SHORT *VadList; 
  __int64 v36; 
  __int64 v37; 
  INT64 result[2]; 
  __int128 v39; 
  UINT64 v40[2]; 
  __int128 v41; 
  _KAPC_STATE ApcState; 
  UINT8 Src[224]; 
  memset(&ApcState, 0, sizeof(ApcState));
  memset((INT64)Src, 0i64);
  LODWORD(v9) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
  v10 = v9;
  if( v9 )
  {
    ExInitializeAutoExpandPushLock((_EX_PUSH_LOCK_AUTO_EXPAND *)(v9 + 408), 1ui64);
    if( a2 )
    {
      v17 = *(_QWORD *)(a2 + 1680);
      memmove(Src, (UINT8 *)(v17 + 48), 0xD8ui64);
      v18 = *(_QWORD *)(v17 + 264);
      v19 = 2i64;
      v20 = *(_OWORD *)(v17 + 456);
      v21 = *(_QWORD *)(v17 + 360);
      *(_OWORD *)result = *(_OWORD *)(v17 + 440);
      v22 = *(_OWORD *)(v17 + 472);
      v36 = v18;
      v23 = &v39;
      v39 = v20;
      v24 = *(_OWORD *)(v17 + 488);
      v37 = v21;
      *(_OWORD *)v40 = v22;
      v41 = v24;
      do
      {
        *(_QWORD *)v23 = 0i64;
        v23 += 2;
        --v19;
      }
      while( v19 );
    }
    else
    {
      v36 = 0i64;
      v37 = 0i64;
      memset((INT64)result, 0i64);
    }
    KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
    *(_QWORD *)(BugCheckParameter1 + 1224) = 0i64;
    *(_QWORD *)(BugCheckParameter1 + 1232) = 0i64;
    *(_QWORD *)(BugCheckParameter1 + 2008) = 0i64;
    if( (MmTrackLockedPages & 1) != 0 && (MmTrackLockedPages & 0x10000000) == 0 )
      MiInitializeLockedPagesTracking((_EPROCESS *)BugCheckParameter1);
    v11 = (_MMSUPPORT_INSTANCE *)(BugCheckParameter1 + 1664);
    P = 0i64;
    MiInitializeWorkingSetList(BugCheckParameter1 + 1664, v10, 0i64, 0i64);
    v12 = *(_QWORD *)(BugCheckParameter1 + 1680);
    *(_DWORD *)(v12 + 280) = 1;
    MiInitializeProcessPageTableCommitmentBitMaps(BugCheckParameter1);
    _InterlockedOr((volatile signed __int32 *)(BugCheckParameter1 + 1124), 0x400u);
    VadList = 0i64;
    inserted = MiComputeProcessUserVa(
                 (_EPROCESS *)BugCheckParameter1,
                 (_EPROCESS *)a2,
                 (_SECTION *)a3,
                 &VadList,
                 (VOID **)P);
    if( inserted >= 0 )
    {
      if( a2 || (*(_DWORD *)(BugCheckParameter1 + 2172) & 1) != 0 || (MiAllocateProcessVads(), (P = v14) != 0i64) )
      {
        InitializeSListHead((_SLIST_HEADER *)(v12 + 368));
        if( a2
          || (MiInitializeProcessBottomUpEntropy(BugCheckParameter1),
              MiInitializeProcessTopDownEntropy((_EPROCESS *)BugCheckParameter1, (_SECTION *)a3, v15),
              inserted = MiInitializeVadBitMap(0i64),
              inserted >= 0) )
        {
          inserted = MiInsertProcessVads(BugCheckParameter1, (_QWORD **)&P);
          if( inserted >= 0 )
          {
            if( a3 )
            {
              inserted = MiMapProcessExecutable(BugCheckParameter1, a3, a4);
LABEL_14:
              MiAllowWorkingSetExpansion((_MMSUPPORT_INSTANCE *)(BugCheckParameter1 + 1664));
LABEL_15:
              KiUnstackDetachProcess(&ApcState, 0i64);
              return(unsigned int)inserted;
            }
            if( (*(_DWORD *)(BugCheckParameter1 + 2172) & 1) != 0 && !a2 )
              goto LABEL_14;
            *a4 &= ~0x10u;
            if( !a2 )
            {
              KiUnstackDetachProcess(&ApcState, 0i64);
              return 0;
            }
            if( (*(_BYTE *)(a2 + 992) & 1) != 0 )
            {
              inserted = -1073741595;
            }
            else
            {
              *(_QWORD *)(BugCheckParameter1 + 1448) = *(_QWORD *)(a2 + 1448);
              *(_DWORD *)(BugCheckParameter1 + 1456) = *(_DWORD *)(a2 + 1456);
              *(_WORD *)(BugCheckParameter1 + 1460) = *(_WORD *)(a2 + 1460);
              *(_BYTE *)(BugCheckParameter1 + 1462) = *(_BYTE *)(a2 + 1462);
              *(_QWORD *)(BugCheckParameter1 + 1496) = *(_QWORD *)(a2 + 1496);
              memmove((UINT8 *)(v12 + 48), Src, 0xD8ui64);
              v25 = v39;
              v26 = v36;
              *(_OWORD *)(v12 + 440) = *(_OWORD *)result;
              *(_QWORD *)(v12 + 264) = v26;
              v27 = *(_OWORD *)v40;
              *(_OWORD *)(v12 + 456) = v25;
              v28 = v41;
              *(_OWORD *)(v12 + 472) = v27;
              *(_OWORD *)(v12 + 488) = v28;
              inserted = MiInitializeVadBitMap(1ui64);
              if( inserted >= 0 )
              {
                v30 = *(UINT64 **)(a2 + 1408);
                if( v30 )
                {
                  v29 = *v30;
                  if( *v30 )
                    **(_QWORD **)(BugCheckParameter1 + 1408) = v29;
                }
                if( (*a4 & 0x80u) == 0 )
                  inserted = 0;
                else
                  inserted = MiSessionCreate(v29);
                v31 = 2i64;
                *(_QWORD *)(v12 + 360) = (v37 + 1) & -(__int64)((a5 & 1) != 0);
                v32 = (_QWORD *)(v12 + 320);
                do
                {
                  v32[1] = v32;
                  *v32 = v32;
                  v32 += 2;
                  --v31;
                }
                while( v31 );
                KiUnstackDetachProcess(&ApcState, 0i64);
                if( inserted >= 0 )
                {
                  inserted = MiCloneProcessAddressSpace(a2, (_QWORD *)BugCheckParameter1, a5);
                  if( inserted >= 0 )
                  {
                    KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
                    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
                    if( v40[1] )
                      MiReferenceCfgVad((INT64)CurrentThread, v40[0], 1i64);
                    if( result[1] )
                      MiReferenceCfgVad((INT64)CurrentThread, result[0], 0i64);
                    KiUnstackDetachProcess(&ApcState, 0i64);
                  }
                }
                MiAllowWorkingSetExpansion(v11);
                return(unsigned int)inserted;
              }
            }
          }
        }
      }
      else
      {
        inserted = -1073741670;
      }
    }
    MiReturnProcessVads(P);
    goto LABEL_15;
  }
  return 3221225626i64;
}

Referenced by:

PspAllocateProcess