HalAllocateCommonBufferVector

INT64 __fastcall HalAllocateCommonBufferVector(
        INT64 a1,
        UINT64 rdx0,
        UINT64 a3,
        MEMORY_CACHING_TYPE er9_0,
        UINT64 IdealNode,
        INT64 arg28,
        UINT64 a7,
        INT64 a8,
        INT64 *a9){
  UINT64 v9; 
  MDL *v10; 
  __int64 v11; 
  INT64 v12; 
  UINT64 v13; 
  INT64 v14; 
  unsigned __int8 CurrentIrql; 
  __int64 v17; 
  __int64 v18; 
  __int64 v19; 
  UINT64 v20; 
  __int64 v21; 
  __int64 v22; 
  __int64 v23; 
  unsigned __int64 v24; 
  LARGE_INTEGER v25; 
  int v26; 
  __int64 v27; 
  MEMORY_CACHING_TYPE v28; 
  struct _MDL *PartitionNodePagesForMdl; 
  char *v30; 
  UINT64 v31; 
  INT64 v32; 
  char *v33; 
  _QWORD *v34; 
  char *v35; 
  UINT64 v36; 
  INT64 v37; 
  UINT64 v38; 
  INT64 *v39; 
  _QWORD *v40; 
  __int64 v41; 
  MDL *v42; 
  _MDL *Next; 
  __int64 *v44; 
  unsigned __int8 v45; 
  unsigned __int64 v46; 
  __int64 v47; 
  __int64 v48; 
  UINT64 Priority; 
  UINT64 Flags; 
  _QWORD *v51; 
  ULONG_PTR BugCheckParameter3; 
  INT64 a6; 
  UINT64 a2; 
  UINT64 a4; 
  INT64 a5; 
  MEMORY_CACHING_TYPE CacheType; 
  CacheType = er9_0;
  a5 = a3;
  a4 = rdx0;
  v9 = a3;
  v10 = 0i64;
  a6 = 0i64;
  v11 = 0i64;
  v12 = 0i64;
  v13 = rdx0;
  v14 = a1;
  CurrentIrql = KeGetCurrentIrql();
  if( CurrentIrql > 2u )
    KeBugCheckEx(0x1DCu, 1ui64, CurrentIrql, 0i64, 0i64);
  if( (_DWORD)arg28 )
    return 3221225485i64;
  BugCheckParameter3 = *(_QWORD *)(a1 + 504);
  if( (int)HalpDmaReferenceDomainObject(BugCheckParameter3) < 0 )
    return 3221225626i64;
  v18 = HalpMmAllocCtxAlloc(v17, 72i64);
  v19 = v18;
  if( !v18 )
  {
    v33 = 0i64;
    goto LABEL_42;
  }
  memset(v18, 0i64);
  v20 = (unsigned int)a7;
  v21 = (unsigned int)a7;
  *(_QWORD *)(v19 + 32) = BugCheckParameter3;
  v23 = HalpMmAllocCtxAlloc(v22, 16 * v21);
  v51 = (_QWORD *)v23;
  v11 = v23;
  if( !v23 )
    goto LABEL_40;
  memset(v23, 0i64);
  *(_QWORD *)(v19 + 64) = v11;
  v24 = (a8 + 4095) & 0xFFFFFFFFFFFFF000ui64;
  if( *(_DWORD *)(BugCheckParameter3 + 64) != 2 )
  {
    v26 = 36;
    v27 = 0i64;
    while( 1i64 << v27 < v24 )
    {
      if( (unsigned __int64)++v27 >= 0x40 )
        goto LABEL_15;
    }
    v24 = 1i64 << v27;
LABEL_15:
    if( 1i64 << v27 == v24 )
    {
      v25.QuadPart = v24;
      goto LABEL_17;
    }
    v11 = (__int64)v51;
LABEL_40:
    v33 = 0i64;
    goto LABEL_31;
  }
  v25.QuadPart = 0i64;
  v26 = 20;
  v13 = 0i64;
  v9 = -1i64;
LABEL_17:
  LODWORD(Flags) = v26;
  *(_DWORD *)(v19 + 24) = a7;
  LODWORD(Priority) = IdealNode;
  v28 = CacheType;
  a2 = v24 * v20;
  *(_QWORD *)(v19 + 16) = v24;
  PartitionNodePagesForMdl = MmAllocatePartitionNodePagesForMdlEx(
                               (LARGE_INTEGER)v13,
                               (LARGE_INTEGER)v9,
                               v25,
                               v24 * v20,
                               v28,
                               Priority,
                               Flags,
                               0i64);
  v10 = PartitionNodePagesForMdl;
  if( !PartitionNodePagesForMdl )
  {
    v33 = 0i64;
    goto LABEL_30;
  }
  v30 = (char *)MmMapLockedPagesSpecifyCache(PartitionNodePagesForMdl, 0, CacheType, 0i64, 0, 0x40000010u);
  v33 = v30;
  if( !v30 )
    goto LABEL_30;
  *(_QWORD *)(v19 + 40) = v10;
  *(_QWORD *)(v19 + 48) = v30;
  if( v20 )
  {
    v34 = v51;
    v35 = v33;
    v31 = v20;
    do
    {
      *v34 = v35;
      v35 += v24;
      v34 += 2;
      --v31;
    }
    while( v31 );
  }
  if( *(_DWORD *)(BugCheckParameter3 + 64) != 2 )
  {
    if( v20 )
    {
      v40 = v51 + 1;
      v41 = 8 * (v24 >> 12);
      v42 = v10 + 1;
      do
      {
        Next = v42->Next;
        v42 = (MDL *)((char *)v42 + v41);
        *v40 = (_QWORD)Next << 12;
        v40 += 2;
        --v20;
      }
      while( v20 );
    }
    goto LABEL_35;
  }
  v36 = a2;
  if( (int)HalpDomainLaAllocate(BugCheckParameter3, a2, v32, &a4, (INT64)&a5, (INT64)&a6) < 0 )
  {
    v12 = a6;
    goto LABEL_30;
  }
  v38 = v36 + 4095;
  v12 = a6;
  if( (int)HalpIommuDomainMapLogical(*(_QWORD *)(BugCheckParameter3 + 40), v37, (INT64)&v10[1], v38 >> 12, a6) < 0 )
  {
LABEL_30:
    v11 = (__int64)v51;
LABEL_31:
    v14 = a1;
LABEL_42:
    HalpDmaDereferenceDomainObject((PVOID)BugCheckParameter3);
    if( v19 )
      HalpMmAllocCtxFree(v48, v19);
    if( v11 )
      HalpMmAllocCtxFree(v48, v11);
    if( v10 )
    {
      if( v33 )
        MmUnmapLockedPages(v33, v10);
      MiFreePagesFromMdl(v10, 0i64);
      ExFreePoolWithTag(v10, 0);
    }
    if( v12 )
      HalpDomainLaDelete(*(_QWORD *)(v14 + 504), v12);
    return 3221225626i64;
  }
  if( v20 )
  {
    v39 = v51 + 1;
    do
    {
      *v39 = v12;
      v12 += v24;
      v39 += 2;
      --v20;
    }
    while( v20 );
  }
LABEL_35:
  KeAcquireSpinLockRaiseToDpc((UINT64 *)(BugCheckParameter3 + 120), v31);
  v44 = (__int64 *)(BugCheckParameter3 + 104);
  v46 = v45;
  v47 = *(_QWORD *)(BugCheckParameter3 + 104);
  if( *(_QWORD *)(v47 + 8) != BugCheckParameter3 + 104 )
    __fastfail(3u);
  *(_QWORD *)(v19 + 8) = v44;
  *(_QWORD *)v19 = v47;
  *(_QWORD *)(v47 + 8) = v19;
  *v44 = v19;
  KxReleaseSpinLock((UINT64 *)(BugCheckParameter3 + 120));
  __writecr8(v46);
  *a9 = v19;
  return 0i64;
}

Referenced by:

No references.