MiMakeDriverPagesPrivate
__int64 __fastcall MiMakeDriverPagesPrivate(__int64 a1, unsigned __int64 a2, unsigned __int64 a3, char a4){
char *v4;
unsigned int v5;
char v6;
__int64 SessionVm;
int v10;
INT64 v11;
INT64 v12;
int v13;
int v14;
unsigned __int64 v15;
INT64 DriverPage;
UINT8 v17;
INT64 v18;
ULONG_PTR v19;
__int64 v20;
NTSTATUS v21;
int v22;
unsigned __int64 v23;
UNICODE_STRING *PfnDb;
UNICODE_STRING *v25;
UINT8 v26;
PWCHAR v27;
int v28;
__int64 v29;
unsigned int v30;
_MMPFN *v31;
__int64 v32;
_KLDR_DATA_TABLE_ENTRY *v33;
char v34;
char v35;
char v36;
char *v37;
UINT8 v39;
char v40;
unsigned int a3a;
int v42;
unsigned int v43;
int v44;
UINT64 SpinCount;
__int64 v46;
unsigned __int64 v47;
__int64 v48;
RTL_BALANCED_NODE *v49;
INT64 a1a;
__int64 v51[10];
v4 = 0i64;
v5 = 0;
a3a = 0;
HIDWORD(SpinCount) = 0;
v6 = a4;
v49 = 0i64;
v40 = 0;
v48 = (_QWORD)MmGetPteBase() << 25;
if( (unsigned int)MiGetSystemRegionType((__int64)((a2 << 25) - v48) >> 16) == 1 )
{
v46 = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64);
SessionVm = MiGetSessionVm();
}
else
{
v46 = 0i64;
SessionVm = (__int64)MiGetAnyMultiplexedVm(1i64);
}
v11 = SessionVm;
v12 = a1 + 160;
v13 = 0;
a1a = *(_QWORD *)(qword_140C4E388 + 8i64 * *(unsigned __int16 *)(SessionVm + 174));
if( (v6 & 3) == 0 && ((unsigned __int8)v10 & BYTE2(MiFlags)) != 0 && (MiFlags & 0x8000) != 0 )
v13 = 2;
v14 = v10 | v13;
v42 = v6 & 4;
v15 = a2;
if( (v6 & 4) == 0 )
v14 = v13;
v43 = v14;
DriverPage = -1i64;
v47 = 0i64;
MiLockLoaderEntry(v12, 0i64);
v17 = MiLockWorkingSetShared(v11);
v39 = v17;
if( a2 > a3 )
goto LABEL_75;
while( 1 )
{
if( v4 )
{
if( (v15 & 0xFFF) != 0 )
goto LABEL_15;
MiUnlockPageTableInternal(v11, (UINT64)v4);
}
v4 = (char *)MmGetPteBase() + ((v15 >> 9) & 0x7FFFFFFFF8i64);
MiLockPageTableInternal(v11, (UINT64)v4, 0i64);
LABEL_15:
v18 = MI_READ_PTE_LOCK_FREE(v15);
v51[0] = v18;
v19 = v18;
if( !v18 )
goto LABEL_24;
if( (v18 & 1) == 0 )
{
if( (v18 & 0x400) != 0 )
{
MiUnlockPageTableInternal(v11, (UINT64)v4);
MiUnlockWorkingSetShared(v11, v39);
MiUnlockLoaderEntry(v12, 0i64);
v20 = (__int64)((v15 << 25) - v48) >> 16;
v21 = MmAccessFault(0i64, (PVOID)v20, 0, 0i64);
v22 = v21;
if( v21 < 0 && (v15 == a2 || (a4 & 8) == 0) )
KeBugCheckEx(0x1Au, 0x3000ui64, v20, v19, v21);
MiLockLoaderEntry(v12, 0i64);
MiLockWorkingSetShared(v11);
if( v22 >= 0 )
{
MiLockPageTableInternal(v11, (UINT64)v4, 0i64);
goto LABEL_25;
}
v4 = 0i64;
}
goto LABEL_24;
}
v23 = MI_READ_PTE_LOCK_FREE((INT64)v51);
PfnDb = (UNICODE_STRING *)MmGetPfnDb();
v25 = &PfnDb[3 * ((v23 >> 12) & 0xFFFFFFFFFi64)];
LOBYTE(v28) = MI_PFN_IS_PROTO(v25, PfnDb, v26, v27);
if( !v28
|| ((__int64)v25[2].Buffer & 0x1000000000i64) == 0 && (__int64)v25->Buffer > 0
|| (v6 & 1) != 0 && ((v19 & 0x800) != 0 || (v19 & 0x200) == 0) )
{
goto LABEL_24;
}
v30 = (*(_DWORD *)&v25[1].Length >> 5) & 0x1F;
if( (MiFlags & 0x10000) != 0 && (v46 || (v6 & 2) != 0) && ((*(_DWORD *)&v25[1].Length >> 5) & 2) != 0 )
{
v5 = -1073741755;
goto LABEL_72;
}
if( v42 && (*(_DWORD *)(v12 + 36) & 1) == 0 && (v25[2].MaximumLength & 0x800) != 0 )
goto LABEL_24;
if( DriverPage != -1 )
{
v31 = (_MMPFN *)(v29 + 48 * DriverPage);
if( (unsigned int)MiUseSlabAllocatorForDriverPage(a1a, v30, &a3a) )
{
if( !MiIsPfnFromSlabAllocation((INT64)v31) || !(unsigned int)MiCheckSlabPage((INT64)v31, a3a, v30) )
goto LABEL_46;
}
else if( MiIsPfnFromSlabAllocation((INT64)v31) )
{
LABEL_46:
if( v47 != v15 )
{
MiReleaseFreshPage(v31);
DriverPage = -1i64;
v47 = v15;
}
}
if( DriverPage != -1 )
{
v32 = (__int64)((v15 << 25) - v48) >> 16;
MiCopyOnWrite(v32, (UINT64 *)v15, DriverPage, v43);
v33 = (_KLDR_DATA_TABLE_ENTRY *)a1;
if( !v46 || v49 )
{
v35 = v40;
v34 = 1;
}
else
{
v49 = MiSessionLookupImage(*(_QWORD *)(a1 + 48));
v34 = 1;
v35 = v40;
if( v49[2].0 )
v35 = 1;
v40 = v35;
}
if( v35 && (MiDriverPageMustStayResident(v33, (_MMPTE *)v15), v36) )
{
v44 = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)&v25[1].Buffer, 0x3Fui64) )
{
do
KeYieldProcessorEx((UINT64 *)&v44);
while( (__int64)v25[1].Buffer < 0 );
}
MiRemoveLockedPageChargeAndDecRef((_MMPFN *)v25);
_InterlockedAnd64((volatile signed __int64 *)&v25[1].Buffer, 0x7FFFFFFFFFFFFFFFui64);
v37 = (char *)MmGetPfnDb() + 48 * DriverPage;
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)v37 + 6, 0x3Fui64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( *((__int64 *)v37 + 3) < 0 );
}
MiAddLockedPageCharge((INT64)v37, 1);
_InterlockedAnd64((volatile signed __int64 *)v37 + 3, 0x7FFFFFFFFFFFFFFFui64);
v34 = 1;
}
else
{
v37 = (char *)MmGetPfnDb() + 48 * DriverPage;
}
DriverPage = -1i64;
if( ((unsigned __int8)v34 & BYTE2(MiFlags)) != 0 && ((*((_QWORD *)v37 + 5) >> 60) & 7) == 3 )
MiMakeDriverPageStayResident(a1, v11, v32);
LABEL_24:
v15 += 8i64;
goto LABEL_25;
}
}
MiUnlockPageTableInternal(v11, (UINT64)v4);
MiUnlockWorkingSetShared(v11, v39);
MiUnlockLoaderEntry(v12, 0i64);
DriverPage = (INT64)MiAllocateDriverPage();
MiLockLoaderEntry(v12, 0i64);
MiLockWorkingSetShared(v11);
MiLockPageTableInternal(v11, (UINT64)v4, 0i64);
if( DriverPage == -1 )
{
v5 = -1073741801;
goto LABEL_72;
}
LABEL_25:
if( v15 > a3 )
break;
v6 = a4;
}
v5 = HIDWORD(SpinCount);
LABEL_72:
if( v4 )
MiUnlockPageTableInternal(v11, (UINT64)v4);
v17 = v39;
LABEL_75:
MiUnlockWorkingSetShared(v11, v17);
MiUnlockLoaderEntry(v12, 0i64);
if( DriverPage != -1 )
MiReleaseFreshPage((_MMPFN *)((char *)MmGetPfnDb() + 48 * DriverPage));
return v5;
}Referenced by:
MiBackSingleImageWithPagefile
MiLockCode
MiLockDriverPageRange
MiSetSystemCodeProtection
MiSplitDriverPage