MiCreatePagingFile

INT64 __stdcall MiCreatePagingFile(
        UNICODE_STRING *PageFileName,
        LARGE_INTEGER *MinimumSize,
        LARGE_INTEGER *MaximumSize,
        INT8 PreviousMode,
        UINT64 Flags){
  LONGLONG QuadPart; 
  unsigned __int64 v10; 
  void *v11; 
  PVOID v12; 
  unsigned __int16 v13; 
  ACL *v14; 
  int Acl; 
  int v16; 
  UINT32 v17; 
  struct _ACL *v18; 
  UINT32 v19; 
  unsigned int v20; 
  _HHIVE *v21; 
  UINT64 v22; 
  unsigned __int64 v23; 
  UINT64 v24; 
  __int64 v25; 
  int v26; 
  UINT64 v27; 
  struct _UNICODE_STRING *Pagefile; 
  struct _UNICODE_STRING *v29; 
  int v30; 
  unsigned int v31; 
  __int64 v33; 
  _MI_PARTITION *v34; 
  unsigned int v35; 
  unsigned int v36; 
  __int64 v37; 
  __int16 v38; 
  unsigned __int64 v39; 
  unsigned __int64 v40; 
  _MI_PAGING_FILE_SPACE_BITMAPS *v41; 
  unsigned __int64 v42; 
  UINT64 v43; 
  volatile INT64 *v44; 
  UINT64 *v45; 
  _MI_PAGING_FILE_SPACE_BITMAPS *PageFileSpaceBitmaps; 
  int v47; 
  UINT64 FileAttributes; 
  UINT64 FileAttributesa; 
  UINT64 ShareAccess; 
  UINT64 ShareAccessa; 
  UINT64 Disposition; 
  UINT64 Dispositiona; 
  UINT64 CreateOptions; 
  UINT64 CreateOptionsa; 
  UINT64 EaLength; 
  UINT64 EaLengtha; 
  UINT64 Options; 
  UINT64 Optionsa; 
  void *FileHandle; 
  unsigned int v61; 
  UINT64 MaximumDecrement; 
  struct _ACL *v63; 
  LARGE_INTEGER AllocationSize; 
  void *Src[2]; 
  ULONG ReturnedLength; 
  PVOID v67; 
  PVOID P; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  unsigned __int64 FileInformation; 
  PVOID Object; 
  __int64 FsInformation; 
  unsigned __int64 v73; 
  PADAPTER_OBJECT DmaAdapter; 
  unsigned __int64 v75; 
  _ETHREAD *CurrentThread; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  char SecurityDescriptor[32]; 
  __int64 v79; 
  UNICODE_STRING PagingFileName; 
  _MI_PARTITION *Partition; 
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  IoStatusBlock = 0i64;
  *(_OWORD *)Src = 0i64;
  AllocationSize.QuadPart = 0i64;
  FileInformation = 0i64;
  FsInformation = 0i64;
  ReturnedLength = 0;
  memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
  v79 = 0i64;
  if( Partition != (_MI_PARTITION *)&MiSystemPartition && (_DWORD)Flags
    || (Flags & 0x7FFFFF) != 0
    || (Flags & 0x80000000) != 0i64 && (Flags & 0x42000000) != 0
    || (Flags & 0xFF7FFFFF) != 0 && (Flags & 0x800000) != 0 )
  {
    return 3221225714i64;
  }
  if( PreviousMode )
  {
    if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeCreatePagefilePrivilege, PreviousMode) || PsIsCurrentThreadInServerSilo() )
      return 3221225569i64;
    if( ((unsigned __int8)PageFileName & 3) != 0
      || ((unsigned __int8)MaximumSize & 3) != 0
      || ((unsigned __int8)MinimumSize & 3) != 0 )
    {
      ExRaiseDatatypeMisalignment();
    }
    QuadPart = MinimumSize->QuadPart;
    AllocationSize = *MinimumSize;
  }
  else
  {
    QuadPart = MinimumSize->QuadPart;
    AllocationSize = *MinimumSize;
  }
  if( (unsigned __int64)QuadPart > 0xFFFFFFFE000i64 || QuadPart < 0x100000 )
    return 3221225712i64;
  v73 = MaximumSize->QuadPart;
  v10 = v73;
  if( v73 > 0xFFFFFFFE000i64 || QuadPart > (__int64)v73 )
    return 3221225713i64;
  *(UNICODE_STRING *)Src = *PageFileName;
  WORD1(Src[0]) = Src[0];
  if( (unsigned __int16)(LOWORD(Src[0]) - 1) > 0xFFu )
    return 3221225523i64;
  LODWORD(v11) = MiAllocatePool((struct _SLIST_ENTRY *)0x100);
  v12 = v11;
  P = v11;
  if( !v11 )
    return 3221225626i64;
  if( PreviousMode )
  {
    v13 = (unsigned __int16)Src[0];
    if( LOWORD(Src[0])
      && ((char *)Src[1] + LOWORD(Src[0]) > (void *)0x7FFFFFFF0000i64 || (char *)Src[1] + LOWORD(Src[0]) < Src[1]) )
    {
      MEMORY[0x7FFFFFFF0000] = 0;
      v13 = (unsigned __int16)Src[0];
    }
    memmove((UINT8 *)v11, (UINT8 *)Src[1], v13);
  }
  else
  {
    memmove((UINT8 *)v11, (UINT8 *)Src[1], LOWORD(Src[0]));
  }
  Src[1] = v12;
  if( (Flags & 0x800000) != 0 )
  {
    ExFreePoolWithTag(v12, 0);
    return 3221225659i64;
  }
  v14 = 0i64;
  MaximumDecrement = 0i64;
  FileHandle = 0i64;
  Acl = RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64);
  if( Acl < 0 )
    goto LABEL_86;
  v16 = RtlLengthSid(SeAliasAdminsSid);
  v17 = RtlLengthSid(SeLocalSystemSid) + 32 + v16;
  LODWORD(v18) = MiAllocatePool((struct _SLIST_ENTRY *)0x100);
  v63 = v18;
  if( !v18 )
  {
    Acl = -1073741670;
    v14 = 0i64;
    goto LABEL_86;
  }
  v19 = v17;
  v14 = v18;
  Acl = RtlCreateAcl(v18, v19, 2u);
  if( Acl < 0
    || (Acl = RtlAddAccessAllowedAce(v14, 2u, 0x1F01FFu, SeAliasAdminsSid), Acl < 0)
    || (Acl = RtlAddAccessAllowedAce(v14, 2u, 0x1F01FFu, SeLocalSystemSid), Acl < 0)
    || (Acl = RtlSetDaclSecurityDescriptor(SecurityDescriptor, 1u, v14, 0), Acl < 0) )
  {
LABEL_86:
    if( FileHandle )
      ObCloseHandle(FileHandle, 0);
    goto LABEL_88;
  }
  if( (Flags & 0x80000000) != 0i64 )
  {
    v20 = 3;
  }
  else
  {
    v20 = 0;
    if( (Flags & 0x2000000) != 0 )
      v20 = 2;
  }
  ObjectAttributes.Length = 48;
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.Attributes = 576;
  ObjectAttributes.ObjectName = (_UNICODE_STRING *)Src;
  ObjectAttributes.SecurityDescriptor = SecurityDescriptor;
  ObjectAttributes.SecurityQualityOfService = 0i64;
  FileInformation = (AllocationSize.QuadPart + 4095) & 0xFFFFFFFFFFFFF000ui64;
  LODWORD(Options) = 274;
  LODWORD(EaLength) = 0;
  LODWORD(CreateOptions) = 36872;
  LODWORD(Disposition) = 0;
  LODWORD(ShareAccess) = 2;
  LODWORD(FileAttributes) = 6;
  if( IoCreateFile(
         &FileHandle,
         0x140003ui64,
         &ObjectAttributes,
         &IoStatusBlock,
         &AllocationSize,
         FileAttributes,
         ShareAccess,
         Disposition,
         CreateOptions,
         0i64,
         EaLength,
         CreateFileTypeNone,
         0i64,
         Options) >= 0 )
  {
    Acl = MiEnablePartitionMappedWrites(Partition);
    if( Acl >= 0 )
    {
      if( IoStatusBlock.Status < 0 || (Acl = ZwSetSecurityObject(FileHandle, 4ui64, SecurityDescriptor), Acl >= 0) )
      {
        ExFreePoolWithTag(v14, 0);
        v14 = 0i64;
        v63 = 0i64;
        Acl = IoStatusBlock.Status;
        if( IoStatusBlock.Status >= 0 )
        {
          Acl = ZwSetInformationFile(FileHandle, &IoStatusBlock, &FileInformation, 8ui64, FileEndOfFileInformation);
          if( Acl >= 0 )
          {
            Acl = IoStatusBlock.Status;
            if( IoStatusBlock.Status >= 0 )
            {
              Object = 0i64;
              Acl = ObReferenceObjectByHandle(FileHandle, 3u, (POBJECT_TYPE)IoFileObjectType, 0, &Object, 0i64);
              v21 = (_HHIVE *)Object;
              DmaAdapter = (PADAPTER_OBJECT)Object;
              if( Acl < 0 )
              {
                v14 = 0i64;
              }
              else
              {
                v23 = *((unsigned int *)IoGetRelatedDeviceObject((_FILE_OBJECT *)Object) + 18);
                if( (unsigned int)v23 > 0x36 || (v25 = 0x60000000100100i64, !_bittest64(&v25, v23)) )
                {
                  Acl = -1073741489;
                  goto LABEL_83;
                }
                LOBYTE(v26) = MiCheckPageFileMapping(v21, v22, v24);
                Acl = v26;
                if( v26 >= 0 )
                {
                  Acl = IoQueryVolumeInformation(
                          (PFILE_OBJECT)v21,
                          FileFsDeviceInformation,
                          8u,
                          &FsInformation,
                          &ReturnedLength);
                  if( Acl >= 0 )
                  {
                    if( (FsInformation & 0x400000000i64) != 0 )
                    {
                      Acl = -1073741468;
                      goto LABEL_83;
                    }
                    Acl = PpPagePathAssign((PFILE_OBJECT)v21);
                    if( Acl < 0 )
                      goto LABEL_83;
                    FsRtlIssueFileNotificationFsctl(
                      (_FILE_OBJECT *)v21,
                      v27,
                      (_GUID *)&FILE_TYPE_NOTIFICATION_GUID_PAGE_FILE);
                    if( Partition == (_MI_PARTITION *)&MiSystemPartition )
                    {
                      Acl = MiZeroPageFileFirstPage((PFILE_OBJECT)v21);
                      if( Acl < 0 )
                      {
                        PpPagePathRelease((PFILE_OBJECT)v21);
                        goto LABEL_83;
                      }
                    }
                    Pagefile = (struct _UNICODE_STRING *)MiCreatePagefile(
                                                           (_DWORD)Partition,
                                                           (_DWORD)v21,
                                                           (_DWORD)FileHandle,
                                                           (unsigned __int64)AllocationSize.QuadPart >> 12,
                                                           v10 >> 12,
                                                           (__int64)Src,
                                                           Flags,
                                                           1);
                    v29 = Pagefile;
                    if( Pagefile )
                    {
                      MiInsertPageFileInList(Pagefile);
                      v31 = v30;
                      if( v30 < 0 )
                      {
                        MiDeletePagefile(v29, 1);
                        return v31;
                      }
                      else
                      {
                        if( Partition == (_MI_PARTITION *)&MiSystemPartition )
                        {
                          if( (BYTE4(v29[12].Buffer) & 0xF) == 0 && (dword_140D23180 & 3) != 0 )
                            SmpSystemStoreCreate();
                          if( !byte_140C4E400 && (BYTE4(v29[12].Buffer) & 0x10) == 0 )
                          {
                            PagingFileName = v29[6];
                            byte_140C4E400 = IoInitializeCrashDump(FileHandle, &PagingFileName);
                          }
                        }
                        return 0i64;
                      }
                    }
                    return 3221225626i64;
                  }
                }
LABEL_83:
                if( DmaAdapter )
                  HalPutDmaAdapter(DmaAdapter);
                v14 = v63;
              }
            }
          }
        }
      }
    }
    goto LABEL_86;
  }
  LODWORD(Optionsa) = 274;
  LODWORD(EaLengtha) = 0;
  LODWORD(CreateOptionsa) = 32776;
  LODWORD(Dispositiona) = 1;
  LODWORD(ShareAccessa) = 3;
  LODWORD(FileAttributesa) = 6;
  Acl = IoCreateFile(
          &FileHandle,
          0x100002ui64,
          &ObjectAttributes,
          &IoStatusBlock,
          &AllocationSize,
          FileAttributesa,
          ShareAccessa,
          Dispositiona,
          CreateOptionsa,
          0i64,
          EaLengtha,
          CreateFileTypeNone,
          0i64,
          Optionsa);
  if( Acl >= 0 )
  {
    v67 = 0i64;
    Acl = ObReferenceObjectByHandle(FileHandle, 3u, (POBJECT_TYPE)IoFileObjectType, 0, &v67, 0i64);
    DmaAdapter = (PADAPTER_OBJECT)v67;
    if( Acl >= 0 )
    {
      v33 = 0i64;
      CurrentThread = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)CurrentThread + 243);
      ExAcquirePushLockExclusiveEx((UINT64)Partition + 1040, 0i64);
      v34 = Partition;
      v35 = *((_DWORD *)Partition + 1734);
      v36 = 0;
      v61 = 0;
      if( !v35 )
        goto LABEL_70;
      while( 1 )
      {
        v37 = *((_QWORD *)v34 + v36 + 868);
        v38 = *(_WORD *)(v37 + 204);
        if( (v38 & 0x840) == 0 )
        {
          if( *(_QWORD *)(*(_QWORD *)(v37 + 56) + 40i64) == *((_QWORD *)v67 + 5) )
          {
            if( ((~v38 & 0x10) != 0) == ((v20 & 1) == 0) )
            {
              v33 = *((_QWORD *)v34 + v36 + 868);
LABEL_70:
              if( v33 )
              {
                v39 = v73 >> 12;
                v40 = (unsigned __int64)AllocationSize.QuadPart >> 12;
                v75 = (unsigned int)((unsigned __int64)AllocationSize.QuadPart >> 12);
                if( *(_QWORD *)(v33 + 16) > v75 )
                {
                  Acl = -1073741584;
                }
                else
                {
                  v41 = *(_MI_PAGING_FILE_SPACE_BITMAPS **)(v33 + 8);
                  if( (unsigned __int64)v41 <= (unsigned int)v39 )
                  {
                    if( (unsigned __int64)v41 >= (unsigned int)v39 )
                      goto LABEL_74;
                    if( (*(_BYTE *)(v33 + 204) & 0x10) != 0
                      || (MaximumDecrement = (unsigned int)v39 - (_QWORD)v41,
                          (unsigned int)MiIncreaseCommitLimits(Partition, 0i64, MaximumDecrement, 0i64, 0i64)) )
                    {
                      v45 = 0i64;
                      if( (!*(_QWORD *)(v33 + 216) || (v45 = MiReservePageHash((unsigned int)v39)) != 0i64)
                        && (PageFileSpaceBitmaps = MiCreatePageFileSpaceBitmaps((unsigned int)v39, v41)) != 0i64 )
                      {
                        MiExtendPagingFileMaximum(v33, (__int64)PageFileSpaceBitmaps, (unsigned __int64)v45);
                        if( (unsigned __int64)(*((_QWORD *)Partition + 933) + 100i64) > *((_QWORD *)Partition + 949)
                          && (unsigned int)MiChargeCommit(Partition, 0xC8ui64, 0i64) == 1 )
                        {
                          MiReturnCommit(Partition, 0xC8ui64);
                        }
                        v36 = v61;
LABEL_74:
                        v42 = v75;
                        if( v75 > *(_QWORD *)(v33 + 16) )
                        {
                          while( v42 <= *(_QWORD *)v33 )
                          {
                            if( (unsigned int)MiCheckAndUpdatePagingFileMinimum(
                                                 (_MMPAGING_FILE *)v33,
                                                 (unsigned int)v40) == 1 )
                              goto LABEL_75;
                          }
                          MiIssuePageExtendRequest(Partition, v42 - *(_QWORD *)v33, 1ui64, v36);
                          v47 = Acl;
                          if( *(_QWORD *)(v33 + 16) < v42 )
                            v47 = -1073741670;
                          Acl = v47;
                        }
LABEL_75:
                        if( v20 >= 2 )
                          *(_WORD *)(v33 + 204) |= 0x80u;
                      }
                      else
                      {
                        Acl = -1073741670;
                      }
                      v43 = MaximumDecrement;
                    }
                    else
                    {
                      v43 = 0i64;
                      Acl = -1073741583;
                    }
LABEL_78:
                    v44 = (volatile INT64 *)((char *)Partition + 1040);
                    if( (_InterlockedExchangeAdd64((volatile signed __int64 *)Partition + 130, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
                      ExfTryToWakePushLock(v44);
                    KeAbPostRelease((PVOID)v44);
                    KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
                    if( v43 )
                      MiReduceCommitLimits(Partition, 0i64, v43);
                    v12 = P;
                    goto LABEL_83;
                  }
                  Acl = -1073741583;
                }
              }
              else
              {
                Acl = -1073741275;
              }
            }
            else
            {
              Acl = -1073741811;
            }
            v43 = 0i64;
            goto LABEL_78;
          }
          v34 = Partition;
        }
        v61 = ++v36;
        if( v36 >= v35 )
          goto LABEL_70;
      }
    }
    goto LABEL_86;
  }
  FileHandle = 0i64;
LABEL_88:
  if( v14 )
    ExFreePoolWithTag(v14, 0);
  ExFreePoolWithTag(v12, 0);
  return(unsigned int)Acl;
}

Referenced by:

NtCreatePagingFile
NtManagePartition