MiInitializeImageProtos

VOID __fastcall MiInitializeImageProtos(_CONTROL_AREA *ControlArea, _MDL *Mdl, _MMPFN *HeaderPfn){
  _CONTROL_AREA *v3; 
  INT64 v4; 
  unsigned int v5; 
  char v6; 
  __int64 v7; 
  _MMPFN *v8; 
  __int64 v9; 
  unsigned __int64 v10; 
  unsigned __int64 v11; 
  UINT64 v12; 
  unsigned __int64 v13; 
  __int16 v14; 
  UINT64 PageForHeader; 
  void *v16; 
  void *v17; 
  char *v18; 
  unsigned __int64 ByteCount; 
  _MI_PARTITION *Partition; 
  UINT64 v21; 
  unsigned __int64 v22; 
  __int64 v23; 
  UINT64 PageIrql; 
  UINT64 SpinCount; 
  v3 = ControlArea;
  v4 = *((_WORD *)ControlArea + 30) & 0x3FF;
  Partition = *(_MI_PARTITION **)(qword_140C4E388 + 8 * v4);
  ByteCount = Mdl->ByteCount;
  MiGetEffectivePagePriorityThread((_ETHREAD *)KeGetCurrentThread(), (CHAR)Mdl, v4);
  v6 = v5;
  if( v5 > 5 )
  {
    v6 = 5;
  }
  else if( v5 )
  {
    v6 = v5 - 1;
  }
  v7 = (__int64)v3 + 128;
  LOBYTE(PageIrql) = 17;
  v8 = 0i64;
  if( v3 != (_CONTROL_AREA *)-128i64 )
  {
    do
    {
      v9 = *(_QWORD *)(v7 + 16);
      v10 = *(_QWORD *)(v7 + 8);
      v23 = v9;
      if( (*(_BYTE *)(v7 + 34) & 2) == 0 )
      {
        v11 = MiStartingOffset(v7, v10, 0xFFFFFFFF);
        v21 = MiEndingOffset((_SUBSECTION *)v7);
        v13 = v10 + 8i64 * *(unsigned int *)(v7 + 44);
        v22 = v13;
        if( v10 < v13 )
        {
          while( 1 )
          {
            if( (v10 & 0xFFF) != 0 && v8 )
              goto LABEL_9;
            if( v8 )
            {
              LOBYTE(v12) = PageIrql;
              MiUnlockProtoPoolPage(v8, v12);
            }
            v8 = MiLockProtoPoolPage((_MMPTE *)v10, (UINT8 *)&PageIrql);
            if( v8 )
            {
LABEL_9:
              if( v11 + 4096 > ByteCount )
              {
                v9 = 0i64;
                break;
              }
              v14 = MI_READ_PTE_LOCK_FREE(v10);
              if( (v14 & 1) == 0 && (v14 & 0xC00) != 2048i64 && (v14 & 0x400) != 0 )
              {
                PageForHeader = MiGetPageForHeader(Partition, (*((_DWORD *)v3 + 14) >> 20) & 0x3F);
                if( PageForHeader != -1i64 )
                {
                  if( (Mdl->MdlFlags & 5) == 0 )
                    MmMapLockedPagesSpecifyCache(Mdl, 0, MmCached, 0i64, 0, 0xC0000020);
                  LODWORD(v16) = MiMapPageInHyperSpaceWorker(PageForHeader, 0i64, 0x80000000ui64);
                  v17 = v16;
                  KeCopyPage(v16);
                  if( v11 + 4096 > v21 )
                    memset((INT64)v17 - (unsigned int)(v11 - v21 + 4096) + 4096, 0i64);
                  MiUnmapPageInHyperSpaceWorker(v17, 0x11u, 0x80000000ui64);
                  v18 = (char *)MmGetPfnDb() + 48 * PageForHeader;
                  MiReferenceControlAreaPfn(ControlArea, 0i64, 1ui64);
                  LODWORD(SpinCount) = 0;
                  while( _interlockedbittestandset64((volatile signed __int32 *)v18 + 6, 0x3Fui64) )
                  {
                    do
                      KeYieldProcessorEx(&SpinCount);
                    while( *((__int64 *)v18 + 3) < 0 );
                  }
                  MiInitializeTransitionPfn(PageForHeader, (MMPTE *)v10);
                  v18[35] ^= (v18[35] ^ v6) & 7;
                  MiRemoveLockedPageChargeAndDecRef((_MMPFN *)v18);
                  _InterlockedAnd64((volatile signed __int64 *)v18 + 3, 0x7FFFFFFFFFFFFFFFui64);
                  v13 = v22;
                }
                v3 = ControlArea;
              }
              v10 += 8i64;
              v11 += 4096i64;
            }
            else
            {
              MmAccessFault(2ui64, (PVOID)v10, 0, 0i64);
            }
            if( v10 >= v13 )
            {
              v9 = v23;
              break;
            }
          }
        }
        if( v8 )
        {
          LOBYTE(v12) = PageIrql;
          MiUnlockProtoPoolPage(v8, v12);
          v8 = 0i64;
        }
      }
      v7 = v9;
    }
    while( v9 );
  }
}

Referenced by:

MiCreateImageFileMap