MiMarkHugePfnBad

INT64 __fastcall MiMarkHugePfnBad(UINT64 rcx0, INT64 a2){
  _QWORD *v2; 
  _ETHREAD *CurrentThread; 
  unsigned int v4; 
  unsigned __int64 v5; 
  _QWORD *v7; 
  __int64 v8; 
  __int64 v9; 
  _QWORD *v11; 
  VOID *PoolWithTag; 
  void *v13; 
  _QWORD *v14; 
  void *v15; 
  bool v16; 
  _QWORD *v17; 
  _QWORD *v18; 
  unsigned __int64 v19; 
  __int64 v20; 
  unsigned __int64 v21; 
  unsigned __int8 v22; 
  INT64 v23; 
  struct _KLOCK_QUEUE_HANDLE LockHandle; 
  PVOID P; 
  int v26; 
  _QWORD *a1; 
  _ETHREAD *Thread; 
  v26 = a2;
  v2 = 0i64;
  memset(&LockHandle, 0, sizeof(LockHandle));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v4 = 0;
  v5 = (rcx0 >> 18) & 0x3FFFF;
  P = 0i64;
  Thread = CurrentThread;
  --*((_WORD *)CurrentThread + 243);
  ExAcquirePushLockExclusiveEx((UINT64)&qword_140C4E348, 0i64);
  v7 = (_QWORD *)(qword_140C4E3B0 + 8 * v5);
  while( 1 )
  {
    v8 = MiHugePfnPartition(v7);
    v9 = v8;
    if( !v8 )
    {
      if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&qword_140C4E348, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
        ExfTryToWakePushLock((volatile INT64 *)&qword_140C4E348);
      KeAbPostRelease(&qword_140C4E348);
      KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
      return 3221226548i64;
    }
    MiLockDynamicMemoryExclusive(v8, (__int64)CurrentThread);
    if( v9 == MiHugePfnPartition(v7) )
      break;
    MiUnlockDynamicMemoryExclusive((_MI_PARTITION *)v9, CurrentThread);
  }
  if( (*(_DWORD *)(v9 + 4) & 1) != 0
    || (KeAcquireInStackQueuedSpinLock((UINT64 *)(v9 + 4128), &LockHandle), !MiIsPageInHugePfn(rcx0)) )
  {
LABEL_15:
    v4 = -1073740748;
    goto LABEL_16;
  }
  while( 1 )
  {
    v11 = (_QWORD *)(qword_140C4E3B0 + 8 * v5);
    a1 = v11;
    if( (*v11 & 0x10000000000i64) != 0 )
    {
      P = v2;
      v2 = *(_QWORD **)(v9 + 4896);
      while( v2 )
      {
        v19 = v2[3] & 0x3FFFFi64;
        if( v5 > v19 )
        {
          v2 = (_QWORD *)v2[1];
        }
        else
        {
          if( v5 >= v19 )
            break;
          v2 = (_QWORD *)*v2;
        }
      }
      v4 = (*v11 & 0x1C0000i64) != 0x100000 ? 0x103 : 0;
      goto LABEL_42;
    }
    if( v2 )
      break;
    KeReleaseInStackQueuedSpinLock(&LockHandle);
    PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, 0x10000ui64, 0x7048694Dui64);
    v13 = PoolWithTag;
    if( !PoolWithTag )
    {
      v4 = -1073741670;
      goto LABEL_17;
    }
    memset((INT64)PoolWithTag, 0i64);
    v14 = ExAllocatePoolWithTag(NonPagedPoolNx, 0x28ui64, 0x7048694Dui64);
    v2 = v14;
    if( !v14 )
    {
      v15 = v13;
      v4 = -1073741670;
      goto LABEL_18;
    }
    v14[3] = v5;
    v14[4] = v13;
    KeAcquireInStackQueuedSpinLock((UINT64 *)(v9 + 4128), &LockHandle);
    if( !MiIsPageInHugePfn(rcx0) )
      goto LABEL_15;
  }
  v16 = 0;
  v17 = *(_QWORD **)(v9 + 4896);
  if( !v17 )
    goto LABEL_34;
  while( v5 < (v17[3] & 0x3FFFFui64) )
  {
    v18 = (_QWORD *)*v17;
    if( !*v17 )
      goto LABEL_34;
LABEL_32:
    v17 = v18;
  }
  v18 = (_QWORD *)v17[1];
  if( v18 )
    goto LABEL_32;
  v16 = 1;
LABEL_34:
  RtlAvlInsertNodeEx((unsigned __int64 *)(v9 + 4896), (__int64)v17, v16, v2);
  v11 = a1;
  *a1 |= 0x10000000000ui64;
LABEL_42:
  v20 = v2[4];
  v21 = rcx0 & 0x3FFFF;
  if( !_bittest64((const signed __int64 *)v20, v21) )
  {
    _bittestandset64((signed __int64 *)v20, v21);
    v20 = v2[4];
  }
  v22 = _bittest64((const signed __int64 *)(v20 + 0x8000), v21);
  if( (v26 & 0x10000000) != 0 )
  {
    if( !v22 )
      _bittestandset64((signed __int64 *)(v20 + 0x8000), v21);
  }
  else if( v22 )
  {
    _bittestandreset64((signed __int64 *)(v20 + 0x8000), v21);
  }
  if( (((*(_DWORD *)v11 & 0x1C0000) - 0x40000i64) & 0xFFFFFFFFFFFBFFFFui64) == 0 )
  {
    v23 = MiHugePfnPartition(v11);
    MiUnlinkHugeRange(v23, v5);
    MiInsertHugeRangeInList(v5, 160, 0i64);
  }
LABEL_16:
  KeReleaseInStackQueuedSpinLock(&LockHandle);
LABEL_17:
  v15 = P;
LABEL_18:
  MiUnlockDynamicMemoryExclusive((_MI_PARTITION *)v9, Thread);
  if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&qword_140C4E348, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock((volatile INT64 *)&qword_140C4E348);
  KeAbPostRelease(&qword_140C4E348);
  KiLeaveGuardedRegionUnsafe((__int64)Thread);
  if( v15 )
    ExFreePoolWithTag(v15, 0);
  if( v4 == -1073740748 )
    KeDelayExecutionThread(0, 0, (PLARGE_INTEGER)&Mi10Milliseconds);
  return v4;
}

Referenced by:

MmMarkPhysicalMemoryAsBad