MmDuplicateMemory
NTSTATUS __fastcall MmDuplicateMemory(__int64 a1){
int v1;
unsigned __int8 CurrentIrql;
unsigned __int8 v4;
NTSTATUS result;
int v6;
_ETHREAD *CurrentThread;
INT64 *v8;
INT16 v9;
INT64 v10;
int v11;
int v12;
int v13;
unsigned __int8 v14;
int v15;
INT64 v16;
INT64 v17[2];
__int64 v18;
__int64 v19;
v1 = *(_DWORD *)(a1 + 32);
v19 = 0i64;
v18 = 0i64;
CurrentIrql = 17;
v4 = 17;
*(_OWORD *)v17 = 0i64;
LODWORD(v17[1]) = v1;
if( (v1 & 1) != 0 && (v1 & 0x404) != 0 )
return -1073741811;
if( (v1 & 8) != 0 )
{
v1 &= 0xFFFFFBFA;
LODWORD(v17[1]) = v1;
}
if( (v1 & 0x400) != 0 && (v1 & 4) != 0
|| (v1 & 0xC0) != 0 && ((v1 & 0xFFFFFC2E) != 0 || (v1 & 0x11) != 17 || (v1 & 0x40) != 0 && (v1 & 0x80u) != 0) )
{
return -1073741811;
}
if( (v1 & 0xA) == 0 )
CcNotifyWriteBehind(a1);
v17[0] = a1;
v6 = 0;
HIDWORD(v17[1]) = 8;
BYTE4(v18) = 0;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
result = KeWaitForSingleObject(
&stru_140C4E410,
WrVirtualMemory,
0,
0,
(PLARGE_INTEGER)((unsigned __int64)&v19 & -(__int64)((v17[1] & 0x200) != 0)));
if( result >= 0 )
{
if( result == 258 )
return 258;
if( (MiFlags & 4) == 0 )
MmLockPagableSectionByHandle(ExPageLockHandle);
--*((_WORD *)CurrentThread + 243);
ExAcquirePushLockExclusiveEx((UINT64)&qword_140C4E348, 0i64);
MiLockDynamicMemoryExclusive((__int64)&MiSystemPartition, (__int64)CurrentThread);
_InterlockedIncrement(&dword_140C4EC18);
MiUpdateMirrorBitmaps(v8);
if( !v11 )
{
v12 = -1073741670;
LABEL_49:
dword_140C4E40C = 0;
if( BYTE4(v18) == 1 )
_InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
if( qword_140C4E448 )
qword_140C4E448 = 0i64;
if( CurrentIrql != 17 )
{
if( v4 != 17 )
MiUnlockAllMemoryLists(v10, v9);
__writecr8(CurrentIrql);
}
if( v6 == 1 )
{
stru_140C4E428.Parameter = (void *)HIDWORD(v17[1]);
ExQueueWorkItem(&stru_140C4E428, HyperCriticalWorkQueue);
}
else
{
_InterlockedAdd(&dword_140C4EC18, 0xFFFFFFFF);
KeSetEvent(&stru_140C4E410, 0);
}
MiUnlockDynamicMemoryExclusive((_MI_PARTITION *)&MiSystemPartition, CurrentThread);
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&qword_140C4E348, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((volatile INT64 *)&qword_140C4E348);
KeAbPostRelease(&qword_140C4E348);
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
if( (MiFlags & 4) == 0 )
MmUnlockPagableImageSection(ExPageLockHandle, v16);
return v12;
}
MiActOnMirrorBitmap((unsigned __int64 *)&qword_140C4E460, 1);
v13 = 1;
LODWORD(v18) = 0;
if( (v17[1] & 1) != 0 )
{
LODWORD(v18) = 3;
LABEL_30:
v13 = 0;
LABEL_31:
v12 = (*(__int64(**)(void))a1)();
if( v12 < 0 )
goto LABEL_48;
dword_140C4E40C = 1;
v12 = MiMirrorBrownPhase((INT64)v17);
if( v12 < 0 )
goto LABEL_48;
if( (v17[1] & 2) == 0 && BYTE4(v18) == 1 )
{
_InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
BYTE4(v18) = 0;
}
CurrentIrql = KeGetCurrentIrql();
v12 = (*(__int64(__fastcall **)(_QWORD))(a1 + 8))(0i64);
if( v12 < 0 )
goto LABEL_48;
v4 = KeGetCurrentIrql();
if( *(_QWORD *)(a1 + 24) )
MiActOnMirrorBitmap((unsigned __int64 *)qword_140C4E450, 1);
if( v4 < 2u )
{
v14 = KeGetCurrentIrql();
__writecr8(2ui64);
v4 = v14;
}
MiLockAllMemoryLists();
qword_140C4E448 = (__int64)CurrentThread;
if( BYTE4(v18) == 1 )
{
_InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
BYTE4(v18) = 0;
}
dword_140C4E40C = 2;
v12 = MiMirrorBlackPhase((INT64)v17);
if( v12 < 0
|| (v12 = MiMirrorVerify(a1), v12 < 0)
|| (v15 = (*(__int64(__fastcall **)(__int64))(a1 + 8))(1i64),
qword_140C4E448 = 0i64,
v12 = v15,
v15 != 1073742484)
|| v13 )
{
LABEL_48:
v6 = 0;
}
else
{
v12 = 0;
MiResumeFromHibernate(HIDWORD(v17[1]));
v6 = 1;
}
goto LABEL_49;
}
if( (v17[1] & 0x400) == 0 )
{
if( (v17[1] & 4) != 0 )
{
HIDWORD(v17[1]) = 7;
LABEL_29:
LODWORD(v18) = 2;
goto LABEL_30;
}
if( (v17[1] & 8) == 0 )
goto LABEL_31;
}
HIDWORD(v17[1]) = 0;
goto LABEL_29;
}
return result;
}Referenced by:
IopLiveDumpCaptureMemoryPages
IopLiveDumpEstimateMemoryPages
MmCreateMirror
PopTransitionToSleep