MiCreatePagingFile
INT64 __stdcall MiCreatePagingFile(
UNICODE_STRING *PageFileName,
LARGE_INTEGER *MinimumSize,
LARGE_INTEGER *MaximumSize,
INT8 PreviousMode,
UINT64 Flags){
LONGLONG QuadPart;
unsigned __int64 v10;
void *v11;
PVOID v12;
unsigned __int16 v13;
ACL *v14;
int Acl;
int v16;
UINT32 v17;
struct _ACL *v18;
UINT32 v19;
unsigned int v20;
_HHIVE *v21;
UINT64 v22;
unsigned __int64 v23;
UINT64 v24;
__int64 v25;
int v26;
UINT64 v27;
struct _UNICODE_STRING *Pagefile;
struct _UNICODE_STRING *v29;
int v30;
unsigned int v31;
__int64 v33;
_MI_PARTITION *v34;
unsigned int v35;
unsigned int v36;
__int64 v37;
__int16 v38;
unsigned __int64 v39;
unsigned __int64 v40;
_MI_PAGING_FILE_SPACE_BITMAPS *v41;
unsigned __int64 v42;
UINT64 v43;
volatile INT64 *v44;
UINT64 *v45;
_MI_PAGING_FILE_SPACE_BITMAPS *PageFileSpaceBitmaps;
int v47;
UINT64 FileAttributes;
UINT64 FileAttributesa;
UINT64 ShareAccess;
UINT64 ShareAccessa;
UINT64 Disposition;
UINT64 Dispositiona;
UINT64 CreateOptions;
UINT64 CreateOptionsa;
UINT64 EaLength;
UINT64 EaLengtha;
UINT64 Options;
UINT64 Optionsa;
void *FileHandle;
unsigned int v61;
UINT64 MaximumDecrement;
struct _ACL *v63;
LARGE_INTEGER AllocationSize;
void *Src[2];
ULONG ReturnedLength;
PVOID v67;
PVOID P;
struct _IO_STATUS_BLOCK IoStatusBlock;
unsigned __int64 FileInformation;
PVOID Object;
__int64 FsInformation;
unsigned __int64 v73;
PADAPTER_OBJECT DmaAdapter;
unsigned __int64 v75;
_ETHREAD *CurrentThread;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
char SecurityDescriptor[32];
__int64 v79;
UNICODE_STRING PagingFileName;
_MI_PARTITION *Partition;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
IoStatusBlock = 0i64;
*(_OWORD *)Src = 0i64;
AllocationSize.QuadPart = 0i64;
FileInformation = 0i64;
FsInformation = 0i64;
ReturnedLength = 0;
memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
v79 = 0i64;
if( Partition != (_MI_PARTITION *)&MiSystemPartition && (_DWORD)Flags
|| (Flags & 0x7FFFFF) != 0
|| (Flags & 0x80000000) != 0i64 && (Flags & 0x42000000) != 0
|| (Flags & 0xFF7FFFFF) != 0 && (Flags & 0x800000) != 0 )
{
return 3221225714i64;
}
if( PreviousMode )
{
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeCreatePagefilePrivilege, PreviousMode) || PsIsCurrentThreadInServerSilo() )
return 3221225569i64;
if( ((unsigned __int8)PageFileName & 3) != 0
|| ((unsigned __int8)MaximumSize & 3) != 0
|| ((unsigned __int8)MinimumSize & 3) != 0 )
{
ExRaiseDatatypeMisalignment();
}
QuadPart = MinimumSize->QuadPart;
AllocationSize = *MinimumSize;
}
else
{
QuadPart = MinimumSize->QuadPart;
AllocationSize = *MinimumSize;
}
if( (unsigned __int64)QuadPart > 0xFFFFFFFE000i64 || QuadPart < 0x100000 )
return 3221225712i64;
v73 = MaximumSize->QuadPart;
v10 = v73;
if( v73 > 0xFFFFFFFE000i64 || QuadPart > (__int64)v73 )
return 3221225713i64;
*(UNICODE_STRING *)Src = *PageFileName;
WORD1(Src[0]) = Src[0];
if( (unsigned __int16)(LOWORD(Src[0]) - 1) > 0xFFu )
return 3221225523i64;
LODWORD(v11) = MiAllocatePool((struct _SLIST_ENTRY *)0x100);
v12 = v11;
P = v11;
if( !v11 )
return 3221225626i64;
if( PreviousMode )
{
v13 = (unsigned __int16)Src[0];
if( LOWORD(Src[0])
&& ((char *)Src[1] + LOWORD(Src[0]) > (void *)0x7FFFFFFF0000i64 || (char *)Src[1] + LOWORD(Src[0]) < Src[1]) )
{
MEMORY[0x7FFFFFFF0000] = 0;
v13 = (unsigned __int16)Src[0];
}
memmove((UINT8 *)v11, (UINT8 *)Src[1], v13);
}
else
{
memmove((UINT8 *)v11, (UINT8 *)Src[1], LOWORD(Src[0]));
}
Src[1] = v12;
if( (Flags & 0x800000) != 0 )
{
ExFreePoolWithTag(v12, 0);
return 3221225659i64;
}
v14 = 0i64;
MaximumDecrement = 0i64;
FileHandle = 0i64;
Acl = RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64);
if( Acl < 0 )
goto LABEL_86;
v16 = RtlLengthSid(SeAliasAdminsSid);
v17 = RtlLengthSid(SeLocalSystemSid) + 32 + v16;
LODWORD(v18) = MiAllocatePool((struct _SLIST_ENTRY *)0x100);
v63 = v18;
if( !v18 )
{
Acl = -1073741670;
v14 = 0i64;
goto LABEL_86;
}
v19 = v17;
v14 = v18;
Acl = RtlCreateAcl(v18, v19, 2u);
if( Acl < 0
|| (Acl = RtlAddAccessAllowedAce(v14, 2u, 0x1F01FFu, SeAliasAdminsSid), Acl < 0)
|| (Acl = RtlAddAccessAllowedAce(v14, 2u, 0x1F01FFu, SeLocalSystemSid), Acl < 0)
|| (Acl = RtlSetDaclSecurityDescriptor(SecurityDescriptor, 1u, v14, 0), Acl < 0) )
{
LABEL_86:
if( FileHandle )
ObCloseHandle(FileHandle, 0);
goto LABEL_88;
}
if( (Flags & 0x80000000) != 0i64 )
{
v20 = 3;
}
else
{
v20 = 0;
if( (Flags & 0x2000000) != 0 )
v20 = 2;
}
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)Src;
ObjectAttributes.SecurityDescriptor = SecurityDescriptor;
ObjectAttributes.SecurityQualityOfService = 0i64;
FileInformation = (AllocationSize.QuadPart + 4095) & 0xFFFFFFFFFFFFF000ui64;
LODWORD(Options) = 274;
LODWORD(EaLength) = 0;
LODWORD(CreateOptions) = 36872;
LODWORD(Disposition) = 0;
LODWORD(ShareAccess) = 2;
LODWORD(FileAttributes) = 6;
if( IoCreateFile(
&FileHandle,
0x140003ui64,
&ObjectAttributes,
&IoStatusBlock,
&AllocationSize,
FileAttributes,
ShareAccess,
Disposition,
CreateOptions,
0i64,
EaLength,
CreateFileTypeNone,
0i64,
Options) >= 0 )
{
Acl = MiEnablePartitionMappedWrites(Partition);
if( Acl >= 0 )
{
if( IoStatusBlock.Status < 0 || (Acl = ZwSetSecurityObject(FileHandle, 4ui64, SecurityDescriptor), Acl >= 0) )
{
ExFreePoolWithTag(v14, 0);
v14 = 0i64;
v63 = 0i64;
Acl = IoStatusBlock.Status;
if( IoStatusBlock.Status >= 0 )
{
Acl = ZwSetInformationFile(FileHandle, &IoStatusBlock, &FileInformation, 8ui64, FileEndOfFileInformation);
if( Acl >= 0 )
{
Acl = IoStatusBlock.Status;
if( IoStatusBlock.Status >= 0 )
{
Object = 0i64;
Acl = ObReferenceObjectByHandle(FileHandle, 3u, (POBJECT_TYPE)IoFileObjectType, 0, &Object, 0i64);
v21 = (_HHIVE *)Object;
DmaAdapter = (PADAPTER_OBJECT)Object;
if( Acl < 0 )
{
v14 = 0i64;
}
else
{
v23 = *((unsigned int *)IoGetRelatedDeviceObject((_FILE_OBJECT *)Object) + 18);
if( (unsigned int)v23 > 0x36 || (v25 = 0x60000000100100i64, !_bittest64(&v25, v23)) )
{
Acl = -1073741489;
goto LABEL_83;
}
LOBYTE(v26) = MiCheckPageFileMapping(v21, v22, v24);
Acl = v26;
if( v26 >= 0 )
{
Acl = IoQueryVolumeInformation(
(PFILE_OBJECT)v21,
FileFsDeviceInformation,
8u,
&FsInformation,
&ReturnedLength);
if( Acl >= 0 )
{
if( (FsInformation & 0x400000000i64) != 0 )
{
Acl = -1073741468;
goto LABEL_83;
}
Acl = PpPagePathAssign((PFILE_OBJECT)v21);
if( Acl < 0 )
goto LABEL_83;
FsRtlIssueFileNotificationFsctl(
(_FILE_OBJECT *)v21,
v27,
(_GUID *)&FILE_TYPE_NOTIFICATION_GUID_PAGE_FILE);
if( Partition == (_MI_PARTITION *)&MiSystemPartition )
{
Acl = MiZeroPageFileFirstPage((PFILE_OBJECT)v21);
if( Acl < 0 )
{
PpPagePathRelease((PFILE_OBJECT)v21);
goto LABEL_83;
}
}
Pagefile = (struct _UNICODE_STRING *)MiCreatePagefile(
(_DWORD)Partition,
(_DWORD)v21,
(_DWORD)FileHandle,
(unsigned __int64)AllocationSize.QuadPart >> 12,
v10 >> 12,
(__int64)Src,
Flags,
1);
v29 = Pagefile;
if( Pagefile )
{
MiInsertPageFileInList(Pagefile);
v31 = v30;
if( v30 < 0 )
{
MiDeletePagefile(v29, 1);
return v31;
}
else
{
if( Partition == (_MI_PARTITION *)&MiSystemPartition )
{
if( (BYTE4(v29[12].Buffer) & 0xF) == 0 && (dword_140D23180 & 3) != 0 )
SmpSystemStoreCreate();
if( !byte_140C4E400 && (BYTE4(v29[12].Buffer) & 0x10) == 0 )
{
PagingFileName = v29[6];
byte_140C4E400 = IoInitializeCrashDump(FileHandle, &PagingFileName);
}
}
return 0i64;
}
}
return 3221225626i64;
}
}
LABEL_83:
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
v14 = v63;
}
}
}
}
}
}
goto LABEL_86;
}
LODWORD(Optionsa) = 274;
LODWORD(EaLengtha) = 0;
LODWORD(CreateOptionsa) = 32776;
LODWORD(Dispositiona) = 1;
LODWORD(ShareAccessa) = 3;
LODWORD(FileAttributesa) = 6;
Acl = IoCreateFile(
&FileHandle,
0x100002ui64,
&ObjectAttributes,
&IoStatusBlock,
&AllocationSize,
FileAttributesa,
ShareAccessa,
Dispositiona,
CreateOptionsa,
0i64,
EaLengtha,
CreateFileTypeNone,
0i64,
Optionsa);
if( Acl >= 0 )
{
v67 = 0i64;
Acl = ObReferenceObjectByHandle(FileHandle, 3u, (POBJECT_TYPE)IoFileObjectType, 0, &v67, 0i64);
DmaAdapter = (PADAPTER_OBJECT)v67;
if( Acl >= 0 )
{
v33 = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 243);
ExAcquirePushLockExclusiveEx((UINT64)Partition + 1040, 0i64);
v34 = Partition;
v35 = *((_DWORD *)Partition + 1734);
v36 = 0;
v61 = 0;
if( !v35 )
goto LABEL_70;
while( 1 )
{
v37 = *((_QWORD *)v34 + v36 + 868);
v38 = *(_WORD *)(v37 + 204);
if( (v38 & 0x840) == 0 )
{
if( *(_QWORD *)(*(_QWORD *)(v37 + 56) + 40i64) == *((_QWORD *)v67 + 5) )
{
if( ((~v38 & 0x10) != 0) == ((v20 & 1) == 0) )
{
v33 = *((_QWORD *)v34 + v36 + 868);
LABEL_70:
if( v33 )
{
v39 = v73 >> 12;
v40 = (unsigned __int64)AllocationSize.QuadPart >> 12;
v75 = (unsigned int)((unsigned __int64)AllocationSize.QuadPart >> 12);
if( *(_QWORD *)(v33 + 16) > v75 )
{
Acl = -1073741584;
}
else
{
v41 = *(_MI_PAGING_FILE_SPACE_BITMAPS **)(v33 + 8);
if( (unsigned __int64)v41 <= (unsigned int)v39 )
{
if( (unsigned __int64)v41 >= (unsigned int)v39 )
goto LABEL_74;
if( (*(_BYTE *)(v33 + 204) & 0x10) != 0
|| (MaximumDecrement = (unsigned int)v39 - (_QWORD)v41,
(unsigned int)MiIncreaseCommitLimits(Partition, 0i64, MaximumDecrement, 0i64, 0i64)) )
{
v45 = 0i64;
if( (!*(_QWORD *)(v33 + 216) || (v45 = MiReservePageHash((unsigned int)v39)) != 0i64)
&& (PageFileSpaceBitmaps = MiCreatePageFileSpaceBitmaps((unsigned int)v39, v41)) != 0i64 )
{
MiExtendPagingFileMaximum(v33, (__int64)PageFileSpaceBitmaps, (unsigned __int64)v45);
if( (unsigned __int64)(*((_QWORD *)Partition + 933) + 100i64) > *((_QWORD *)Partition + 949)
&& (unsigned int)MiChargeCommit(Partition, 0xC8ui64, 0i64) == 1 )
{
MiReturnCommit(Partition, 0xC8ui64);
}
v36 = v61;
LABEL_74:
v42 = v75;
if( v75 > *(_QWORD *)(v33 + 16) )
{
while( v42 <= *(_QWORD *)v33 )
{
if( (unsigned int)MiCheckAndUpdatePagingFileMinimum(
(_MMPAGING_FILE *)v33,
(unsigned int)v40) == 1 )
goto LABEL_75;
}
MiIssuePageExtendRequest(Partition, v42 - *(_QWORD *)v33, 1ui64, v36);
v47 = Acl;
if( *(_QWORD *)(v33 + 16) < v42 )
v47 = -1073741670;
Acl = v47;
}
LABEL_75:
if( v20 >= 2 )
*(_WORD *)(v33 + 204) |= 0x80u;
}
else
{
Acl = -1073741670;
}
v43 = MaximumDecrement;
}
else
{
v43 = 0i64;
Acl = -1073741583;
}
LABEL_78:
v44 = (volatile INT64 *)((char *)Partition + 1040);
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)Partition + 130, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(v44);
KeAbPostRelease((PVOID)v44);
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
if( v43 )
MiReduceCommitLimits(Partition, 0i64, v43);
v12 = P;
goto LABEL_83;
}
Acl = -1073741583;
}
}
else
{
Acl = -1073741275;
}
}
else
{
Acl = -1073741811;
}
v43 = 0i64;
goto LABEL_78;
}
v34 = Partition;
}
v61 = ++v36;
if( v36 >= v35 )
goto LABEL_70;
}
}
goto LABEL_86;
}
FileHandle = 0i64;
LABEL_88:
if( v14 )
ExFreePoolWithTag(v14, 0);
ExFreePoolWithTag(v12, 0);
return(unsigned int)Acl;
}Referenced by:
NtCreatePagingFile
NtManagePartition