MmManageFaultRange

NTSTATUS __stdcall MmManageFaultRange(PVOID BugCheckParameter3, PVOID BugCheckParameter4){
  char v2; 
  char v3; 
  char *v4; 
  char v5; 
  int v8; 
  unsigned int v9; 
  __int64 *v10; 
  __int128 *v11; 
  __int64 v12; 
  _ETHREAD *CurrentThread; 
  __int64 v14; 
  unsigned __int64 *v15; 
  KIRQL v16; 
  __int64 *v17; 
  unsigned __int64 v18; 
  bool v19; 
  __int64 v20; 
  __int64 v21; 
  __int128 v23; 
  __int128 v24; 
  __int64 v25; 
  v4 = (char *)BugCheckParameter4 + (_QWORD)BugCheckParameter3 - 1;
  v5 = v2;
  v23 = 0i64;
  v24 = 0i64;
  v25 = 0i64;
  v8 = v3 & 1;
  if( (v3 & 1) != 0 )
  {
    v9 = 0;
    v10 = qword_140C4C660;
    while( 1 )
    {
      v11 = (__int128 *)(v10 - 3);
      if( !*v10 && !_InterlockedCompareExchange64(v10, (signed __int64)BugCheckParameter3, 0i64) )
        break;
      ++v9;
      v10 += 5;
      if( v9 >= 2 )
        goto LABEL_5;
    }
    *((_QWORD *)v11 + 4) = v4;
LABEL_5:
    if( v9 == 2 )
    {
      LODWORD(v12) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
      v11 = (__int128 *)v12;
      if( !v12 )
        return v12;
      *(_QWORD *)(v12 + 24) = BugCheckParameter3;
      *(_QWORD *)(v12 + 32) = v4;
    }
  }
  else
  {
    *((_QWORD *)&v24 + 1) = BugCheckParameter3;
    v11 = &v23;
    v25 = (__int64)BugCheckParameter4 + (_QWORD)BugCheckParameter3 - 1;
  }
  if( (v5 & 0x20) != 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    v14 = *((_QWORD *)CurrentThread + 23);
    if( (*(_DWORD *)(v14 + 1124) & 0x10000) == 0 )
      KeBugCheckEx(
        0x1Au,
        0x5230ui64,
        *((_QWORD *)CurrentThread + 23),
        (ULONG_PTR)BugCheckParameter3,
        (ULONG_PTR)BugCheckParameter4);
    v15 = (unsigned __int64 *)(*(_QWORD *)(v14 + 1368) + 1008i64);
  }
  else
  {
    v15 = (unsigned __int64 *)&qword_140C4C640;
  }
  v16 = ExAcquireSpinLockExclusive(&dword_140C4C638);
  v17 = (__int64 *)*v15;
  v18 = v16;
  if( !v8 )
  {
    while( v17 )
    {
      if( *((_QWORD *)v11 + 3) > (unsigned __int64)v17[4] )
      {
        v17 = (__int64 *)v17[1];
      }
      else
      {
        if( *((_QWORD *)v11 + 4) >= (unsigned __int64)v17[3] )
          break;
        v17 = (__int64 *)*v17;
      }
    }
    if( (PVOID)v17[3] != BugCheckParameter3 || (char *)v17[4] != v4 )
      KeBugCheckEx(0x1Au, 0x5231ui64, (ULONG_PTR)v17, (ULONG_PTR)BugCheckParameter3, (ULONG_PTR)BugCheckParameter4);
    RtlAvlRemoveNode(v15, v17);
    goto LABEL_18;
  }
  v19 = 0;
  if( !v17 )
    goto LABEL_17;
  while( *((_QWORD *)v11 + 3) <= (unsigned __int64)v17[4] && *((_QWORD *)v11 + 4) < (unsigned __int64)v17[3] )
  {
    v20 = *v17;
    if( !*v17 )
      goto LABEL_17;
LABEL_21:
    v17 = (__int64 *)v20;
  }
  v20 = v17[1];
  if( v20 )
    goto LABEL_21;
  v19 = 1;
LABEL_17:
  RtlAvlInsertNodeEx(v15, (__int64)v17, v19, v11);
  v17 = 0i64;
LABEL_18:
  ExReleaseSpinLockExclusiveFromDpcLevel((INT64 *)&dword_140C4C638);
  __writecr8(v18);
  if( v17 )
  {
    v21 = 0i64;
    while( v17 != &qword_140C4C648[5 * v21] )
    {
      v21 = (unsigned int)(v21 + 1);
      if( (unsigned int)v21 >= 2 )
        goto LABEL_25;
    }
    v17 = 0i64;
LABEL_25:
    if( v17 )
      ExFreePoolWithTag(v17, 0);
  }
  LODWORD(v12) = 1;
  return v12;
}

Referenced by:

RtlpEnvRegisterFaultRange