MiAllocateHyperSpace

UINT64 __fastcall MiAllocateHyperSpace(UINT64 a1){
  __int64 v2; 
  UINT64 result; 
  unsigned __int64 v4; 
  unsigned __int64 v5; 
  UINT64 v6; 
  v2 = *((_QWORD *)KeGetCurrentPrcb() + 4095);
  if( v2 )
  {
    result = MiGetUltraMapping((unsigned __int64 *)(v2 + 12448), 3u, a1, 0);
    *(_QWORD *)(v2 + 12344) = (char *)MmGetPteBase() + ((result >> 9) & 0x7FFFFFFFF8i64);
  }
  else
  {
    v4 = *((_QWORD *)KeGetCurrentPrcb() + 4160);
    v5 = v4 & 0xFFFFFFFFFFFFF000ui64;
    if( 64 - (v4 & 0xFFF) > a1 )
    {
      v6 = v5 + ((v4 & 0xFFF) << 12);
    }
    else
    {
      MiFlushHyperSpace();
      v4 = v5;
      v6 = v5;
    }
    result = v6;
    *((_QWORD *)KeGetCurrentPrcb() + 4160) = v4 + a1;
  }
  return result;
}

Referenced by:

MiCopyPage
MiFillPageWithImageExtentContents
MiGetPteMappingPair