MmManageFaultRange
NTSTATUS __stdcall MmManageFaultRange(PVOID BugCheckParameter3, PVOID BugCheckParameter4){
char v2;
char v3;
char *v4;
char v5;
int v8;
unsigned int v9;
__int64 *v10;
__int128 *v11;
__int64 v12;
_ETHREAD *CurrentThread;
__int64 v14;
unsigned __int64 *v15;
KIRQL v16;
__int64 *v17;
unsigned __int64 v18;
bool v19;
__int64 v20;
__int64 v21;
__int128 v23;
__int128 v24;
__int64 v25;
v4 = (char *)BugCheckParameter4 + (_QWORD)BugCheckParameter3 - 1;
v5 = v2;
v23 = 0i64;
v24 = 0i64;
v25 = 0i64;
v8 = v3 & 1;
if( (v3 & 1) != 0 )
{
v9 = 0;
v10 = qword_140C4C660;
while( 1 )
{
v11 = (__int128 *)(v10 - 3);
if( !*v10 && !_InterlockedCompareExchange64(v10, (signed __int64)BugCheckParameter3, 0i64) )
break;
++v9;
v10 += 5;
if( v9 >= 2 )
goto LABEL_5;
}
*((_QWORD *)v11 + 4) = v4;
LABEL_5:
if( v9 == 2 )
{
LODWORD(v12) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
v11 = (__int128 *)v12;
if( !v12 )
return v12;
*(_QWORD *)(v12 + 24) = BugCheckParameter3;
*(_QWORD *)(v12 + 32) = v4;
}
}
else
{
*((_QWORD *)&v24 + 1) = BugCheckParameter3;
v11 = &v23;
v25 = (__int64)BugCheckParameter4 + (_QWORD)BugCheckParameter3 - 1;
}
if( (v5 & 0x20) != 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v14 = *((_QWORD *)CurrentThread + 23);
if( (*(_DWORD *)(v14 + 1124) & 0x10000) == 0 )
KeBugCheckEx(
0x1Au,
0x5230ui64,
*((_QWORD *)CurrentThread + 23),
(ULONG_PTR)BugCheckParameter3,
(ULONG_PTR)BugCheckParameter4);
v15 = (unsigned __int64 *)(*(_QWORD *)(v14 + 1368) + 1008i64);
}
else
{
v15 = (unsigned __int64 *)&qword_140C4C640;
}
v16 = ExAcquireSpinLockExclusive(&dword_140C4C638);
v17 = (__int64 *)*v15;
v18 = v16;
if( !v8 )
{
while( v17 )
{
if( *((_QWORD *)v11 + 3) > (unsigned __int64)v17[4] )
{
v17 = (__int64 *)v17[1];
}
else
{
if( *((_QWORD *)v11 + 4) >= (unsigned __int64)v17[3] )
break;
v17 = (__int64 *)*v17;
}
}
if( (PVOID)v17[3] != BugCheckParameter3 || (char *)v17[4] != v4 )
KeBugCheckEx(0x1Au, 0x5231ui64, (ULONG_PTR)v17, (ULONG_PTR)BugCheckParameter3, (ULONG_PTR)BugCheckParameter4);
RtlAvlRemoveNode(v15, v17);
goto LABEL_18;
}
v19 = 0;
if( !v17 )
goto LABEL_17;
while( *((_QWORD *)v11 + 3) <= (unsigned __int64)v17[4] && *((_QWORD *)v11 + 4) < (unsigned __int64)v17[3] )
{
v20 = *v17;
if( !*v17 )
goto LABEL_17;
LABEL_21:
v17 = (__int64 *)v20;
}
v20 = v17[1];
if( v20 )
goto LABEL_21;
v19 = 1;
LABEL_17:
RtlAvlInsertNodeEx(v15, (__int64)v17, v19, v11);
v17 = 0i64;
LABEL_18:
ExReleaseSpinLockExclusiveFromDpcLevel((INT64 *)&dword_140C4C638);
__writecr8(v18);
if( v17 )
{
v21 = 0i64;
while( v17 != &qword_140C4C648[5 * v21] )
{
v21 = (unsigned int)(v21 + 1);
if( (unsigned int)v21 >= 2 )
goto LABEL_25;
}
v17 = 0i64;
LABEL_25:
if( v17 )
ExFreePoolWithTag(v17, 0);
}
LODWORD(v12) = 1;
return v12;
}Referenced by:
RtlpEnvRegisterFaultRange