MmDuplicateMemory

NTSTATUS __fastcall MmDuplicateMemory(__int64 a1){
  int v1; 
  unsigned __int8 CurrentIrql; 
  unsigned __int8 v4; 
  NTSTATUS result; 
  int v6; 
  _ETHREAD *CurrentThread; 
  INT64 *v8; 
  INT16 v9; 
  INT64 v10; 
  int v11; 
  int v12; 
  int v13; 
  unsigned __int8 v14; 
  int v15; 
  INT64 v16; 
  INT64 v17[2]; 
  __int64 v18; 
  __int64 v19; 
  v1 = *(_DWORD *)(a1 + 32);
  v19 = 0i64;
  v18 = 0i64;
  CurrentIrql = 17;
  v4 = 17;
  *(_OWORD *)v17 = 0i64;
  LODWORD(v17[1]) = v1;
  if( (v1 & 1) != 0 && (v1 & 0x404) != 0 )
    return -1073741811;
  if( (v1 & 8) != 0 )
  {
    v1 &= 0xFFFFFBFA;
    LODWORD(v17[1]) = v1;
  }
  if( (v1 & 0x400) != 0 && (v1 & 4) != 0
    || (v1 & 0xC0) != 0 && ((v1 & 0xFFFFFC2E) != 0 || (v1 & 0x11) != 17 || (v1 & 0x40) != 0 && (v1 & 0x80u) != 0) )
  {
    return -1073741811;
  }
  if( (v1 & 0xA) == 0 )
    CcNotifyWriteBehind(a1);
  v17[0] = a1;
  v6 = 0;
  HIDWORD(v17[1]) = 8;
  BYTE4(v18) = 0;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  result = KeWaitForSingleObject(
             &stru_140C4E410,
             WrVirtualMemory,
             0,
             0,
             (PLARGE_INTEGER)((unsigned __int64)&v19 & -(__int64)((v17[1] & 0x200) != 0)));
  if( result >= 0 )
  {
    if( result == 258 )
      return 258;
    if( (MiFlags & 4) == 0 )
      MmLockPagableSectionByHandle(ExPageLockHandle);
    --*((_WORD *)CurrentThread + 243);
    ExAcquirePushLockExclusiveEx((UINT64)&qword_140C4E348, 0i64);
    MiLockDynamicMemoryExclusive((__int64)&MiSystemPartition, (__int64)CurrentThread);
    _InterlockedIncrement(&dword_140C4EC18);
    MiUpdateMirrorBitmaps(v8);
    if( !v11 )
    {
      v12 = -1073741670;
LABEL_49:
      dword_140C4E40C = 0;
      if( BYTE4(v18) == 1 )
        _InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
      if( qword_140C4E448 )
        qword_140C4E448 = 0i64;
      if( CurrentIrql != 17 )
      {
        if( v4 != 17 )
          MiUnlockAllMemoryLists(v10, v9);
        __writecr8(CurrentIrql);
      }
      if( v6 == 1 )
      {
        stru_140C4E428.Parameter = (void *)HIDWORD(v17[1]);
        ExQueueWorkItem(&stru_140C4E428, HyperCriticalWorkQueue);
      }
      else
      {
        _InterlockedAdd(&dword_140C4EC18, 0xFFFFFFFF);
        KeSetEvent(&stru_140C4E410, 0);
      }
      MiUnlockDynamicMemoryExclusive((_MI_PARTITION *)&MiSystemPartition, CurrentThread);
      if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&qword_140C4E348, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
        ExfTryToWakePushLock((volatile INT64 *)&qword_140C4E348);
      KeAbPostRelease(&qword_140C4E348);
      KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
      if( (MiFlags & 4) == 0 )
        MmUnlockPagableImageSection(ExPageLockHandle, v16);
      return v12;
    }
    MiActOnMirrorBitmap((unsigned __int64 *)&qword_140C4E460, 1);
    v13 = 1;
    LODWORD(v18) = 0;
    if( (v17[1] & 1) != 0 )
    {
      LODWORD(v18) = 3;
LABEL_30:
      v13 = 0;
LABEL_31:
      v12 = (*(__int64(**)(void))a1)();
      if( v12 < 0 )
        goto LABEL_48;
      dword_140C4E40C = 1;
      v12 = MiMirrorBrownPhase((INT64)v17);
      if( v12 < 0 )
        goto LABEL_48;
      if( (v17[1] & 2) == 0 && BYTE4(v18) == 1 )
      {
        _InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
        BYTE4(v18) = 0;
      }
      CurrentIrql = KeGetCurrentIrql();
      v12 = (*(__int64(__fastcall **)(_QWORD))(a1 + 8))(0i64);
      if( v12 < 0 )
        goto LABEL_48;
      v4 = KeGetCurrentIrql();
      if( *(_QWORD *)(a1 + 24) )
        MiActOnMirrorBitmap((unsigned __int64 *)qword_140C4E450, 1);
      if( v4 < 2u )
      {
        v14 = KeGetCurrentIrql();
        __writecr8(2ui64);
        v4 = v14;
      }
      MiLockAllMemoryLists();
      qword_140C4E448 = (__int64)CurrentThread;
      if( BYTE4(v18) == 1 )
      {
        _InterlockedAdd(&dword_140C4EA8C, 0xFFFFFFFF);
        BYTE4(v18) = 0;
      }
      dword_140C4E40C = 2;
      v12 = MiMirrorBlackPhase((INT64)v17);
      if( v12 < 0
        || (v12 = MiMirrorVerify(a1), v12 < 0)
        || (v15 = (*(__int64(__fastcall **)(__int64))(a1 + 8))(1i64),
            qword_140C4E448 = 0i64,
            v12 = v15,
            v15 != 1073742484)
        || v13 )
      {
LABEL_48:
        v6 = 0;
      }
      else
      {
        v12 = 0;
        MiResumeFromHibernate(HIDWORD(v17[1]));
        v6 = 1;
      }
      goto LABEL_49;
    }
    if( (v17[1] & 0x400) == 0 )
    {
      if( (v17[1] & 4) != 0 )
      {
        HIDWORD(v17[1]) = 7;
LABEL_29:
        LODWORD(v18) = 2;
        goto LABEL_30;
      }
      if( (v17[1] & 8) == 0 )
        goto LABEL_31;
    }
    HIDWORD(v17[1]) = 0;
    goto LABEL_29;
  }
  return result;
}

Referenced by:

IopLiveDumpCaptureMemoryPages
IopLiveDumpEstimateMemoryPages
MmCreateMirror
PopTransitionToSleep