HalpAllocateDomainCommonBufferInternal

INT64 __fastcall HalpAllocateDomainCommonBufferInternal(
        PVOID BugCheckParameter3,
        LARGE_INTEGER *a2,
        LARGE_INTEGER *a3,
        UINT64 a4,
        CHAR a5,
        INT64 a6,
        UINT64 a7,
        INT64 a8,
        INT64 a9){
  void *v9; 
  INT64 v10; 
  unsigned int v11; 
  int v15; 
  __int64 v16; 
  LONGLONG QuadPart; 
  unsigned __int64 v18; 
  int v19; 
  __int64 v20; 
  UINT64 v21; 
  void *ContiguousNodeMemory; 
  PHYSICAL_ADDRESS PhysicalAddress; 
  INT64 v24; 
  int v25; 
  _QWORD *PoolWithTag; 
  UINT64 v27; 
  unsigned __int64 v28; 
  unsigned __int8 v29; 
  unsigned __int64 v30; 
  unsigned __int64 v31; 
  bool v32; 
  unsigned __int64 v33; 
  unsigned int v35; 
  INT64 a5a; 
  INT64 a6a; 
  char v38; 
  INT64 v39; 
  PVOID P; 
  INT64 v41; 
  UINT64 a4a[2]; 
  P = 0i64;
  v9 = 0i64;
  v10 = 0i64;
  v38 = 0;
  v39 = 0i64;
  v11 = a4;
  v15 = HalpDmaReferenceDomainObject((INT64)BugCheckParameter3);
  if( v15 < 0 )
    return(unsigned int)v15;
  v16 = *((_QWORD *)BugCheckParameter3 + 9);
  if( v16 )
    *(_BYTE *)(v16 + 516) = 1;
  QuadPart = 0i64;
  if( a2 )
    QuadPart = a2->QuadPart;
  v18 = *((_QWORD *)BugCheckParameter3 + 2);
  if( a3 && v18 > a3->QuadPart )
    v18 = a3->QuadPart;
  if( a6 )
  {
    if( *(_DWORD *)a6 == 1 )
    {
      v19 = 4;
      goto LABEL_10;
    }
    if( *(_DWORD *)a6 )
    {
      v15 = -1073741811;
      goto LABEL_54;
    }
  }
  else
  {
    v19 = 4;
    if( *((_BYTE *)BugCheckParameter3 + 32) )
      goto LABEL_10;
  }
  v19 = 516;
LABEL_10:
  v20 = *((_QWORD *)BugCheckParameter3 + 3);
  if( (a5 & 1) != 0 )
  {
    v35 = 1;
    v11 = (v11 + 0x1FFFFF) & 0xFFE00000;
    do
    {
      if( 1i64 << v35 >= (unsigned __int64)v11 )
        break;
      ++v35;
    }
    while( v35 < 0x3F );
    v20 = 1i64 << v35;
  }
  LODWORD(a6a) = a7;
  LODWORD(a5a) = v19;
  v21 = v11;
  ContiguousNodeMemory = MmAllocateContiguousNodeMemory(
                           v11,
                           (LARGE_INTEGER)QuadPart,
                           (LARGE_INTEGER)v18,
                           (LARGE_INTEGER)v20,
                           a5a,
                           a6a);
  v9 = ContiguousNodeMemory;
  if( ContiguousNodeMemory )
  {
    PhysicalAddress = MmGetPhysicalAddress(ContiguousNodeMemory);
    v25 = *((_DWORD *)BugCheckParameter3 + 16);
    if( v25 == 2 )
    {
      a4a[0] = QuadPart;
      v41 = v18;
      v15 = HalpDomainLaAllocate((INT64)BugCheckParameter3, v21, v24, a4a, (INT64)&v41, (INT64)&v39);
      if( v15 < 0 )
        goto LABEL_54;
      v10 = v39;
      v38 = 1;
      v15 = HalpIommuDomainMapLogicalRange(
              *((_QWORD *)BugCheckParameter3 + 5),
              3i64,
              PhysicalAddress.QuadPart,
              v21,
              v39);
      if( v15 < 0 )
      {
LABEL_53:
        HalpDomainLaDelete((INT64)BugCheckParameter3, v10);
        goto LABEL_54;
      }
    }
    else
    {
      if( v25 == 3 )
      {
        v15 = HalpIommuDomainMapLogicalRange(
                *((_QWORD *)BugCheckParameter3 + 5),
                3i64,
                PhysicalAddress.QuadPart,
                v21,
                PhysicalAddress.QuadPart);
        if( v15 < 0 )
          goto LABEL_54;
      }
      v39 = PhysicalAddress.QuadPart;
      v10 = PhysicalAddress.QuadPart;
    }
    PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, 0x28ui64, 0x206C6148ui64);
    P = PoolWithTag;
    v28 = (unsigned __int64)PoolWithTag;
    if( !PoolWithTag )
    {
      v15 = -1073741670;
      goto LABEL_52;
    }
    PoolWithTag[3] = v9;
    PoolWithTag[4] = BugCheckParameter3;
    KeAcquireSpinLockRaiseToDpc((UINT64 *)BugCheckParameter3 + 12, v27);
    v30 = v29;
    v31 = *((_QWORD *)BugCheckParameter3 + 10);
    if( (*((_BYTE *)BugCheckParameter3 + 88) & 1) != 0 && v31 )
      v31 ^= (unsigned __int64)BugCheckParameter3 + 80;
    v32 = 0;
    if( v31 )
    {
      while( 1 )
      {
        if( *(_QWORD *)(v31 + 24) > (unsigned __int64)v9 )
        {
          v33 = *(_QWORD *)v31;
          if( (*((_BYTE *)BugCheckParameter3 + 88) & 1) != 0 )
          {
            if( !v33 )
              break;
            v33 ^= v31;
          }
          if( !v33 )
            break;
        }
        else
        {
          v33 = *(_QWORD *)(v31 + 8);
          if( (*((_BYTE *)BugCheckParameter3 + 88) & 1) != 0 )
          {
            if( !v33 )
              goto LABEL_25;
            v33 ^= v31;
          }
          if( !v33 )
          {
LABEL_25:
            v32 = 1;
            break;
          }
        }
        v31 = v33;
      }
    }
    RtlRbInsertNodeEx((unsigned __int64 *)BugCheckParameter3 + 10, v31, v32, v28);
    KxReleaseSpinLock((UINT64 *)BugCheckParameter3 + 12);
    __writecr8(v30);
    *(_QWORD *)a8 = v10;
    *(_QWORD *)a9 = v9;
  }
  else
  {
    v15 = -1073741670;
  }
  if( v15 >= 0 )
    return(unsigned int)v15;
LABEL_52:
  if( v38 )
    goto LABEL_53;
LABEL_54:
  HalpDmaDereferenceDomainObject(BugCheckParameter3);
  if( v9 )
    MmFreeContiguousMemory(v9);
  if( P )
    ExFreePoolWithTag(P, 0);
  return(unsigned int)v15;
}

Referenced by:

HalAllocateCommonBufferExV3
HalAllocateCommonBufferWithBounds
HalAllocateDomainCommonBuffer