MiZeroPage
unsigned int __fastcall MiZeroPage(__int64 a1, __int64 a2){
INT64 v3;
__int64 v4;
VOID *v5;
__int64 v6;
__int64 v7;
UINT64 v8;
_EX_PUSH_LOCK *v9;
int v10;
int v11;
INT64 v12;
int v13;
__int64 v14;
_QWORD *v15;
_RTL_BALANCED_NODE *v16;
char v17;
__int64 v18;
__int64 v19;
unsigned __int64 v20;
__int64 v21;
unsigned int v22;
_MI_TB_FLUSH_LIST v23;
char v24;
__int64 v25;
unsigned __int64 v26;
unsigned __int64 PteBase;
_MMPTE *PteLimit;
unsigned __int64 v29;
unsigned __int64 v30;
__int64 v31;
__int64 *v32;
__int64 v33;
unsigned __int64 v34;
__int64 *v35;
__int64 v36;
unsigned __int64 v37;
__int64 v38;
unsigned __int64 v39;
UINT64 v40;
__int64 v41;
unsigned __int64 i;
UINT64 v43;
int v44;
char ParentValue_high;
INT64 *v46;
UINT64 *v47;
signed __int32 v48;
bool v49;
signed __int32 v50;
char v51;
__int64 v52;
unsigned int v53;
unsigned int v54;
__int64 v55;
__int64 v56;
int v57;
__int64 v58;
int v59;
INT64 v60;
UINT64 v61;
int v62;
unsigned int result;
_EX_PUSH_LOCK *v64;
INT64 *v65;
UINT64 LargePageIndex;
_RTL_BALANCED_NODE *Node;
int v68;
unsigned int v69;
UINT64 v70;
unsigned __int8 CurrentIrql;
int v73;
_BOOL4 v74;
int v75;
char SpinCount[12];
PVOID P;
INT64 v78;
INT64 CurrentThread;
__int64 v80;
__int64 v81;
_KLOCK_QUEUE_HANDLE LockHandle;
_MI_TB_FLUSH_LIST TbFlushList[2];
__int64 v84;
__int64 v85;
__int64 Base;
__int128 v87;
__int128 v88;
__int128 v89;
__int128 v90;
__int128 v91;
__int128 v92;
__int128 v93;
__int128 v94;
__int128 v95;
__int64 v96;
*(_QWORD *)&SpinCount[4] = a2;
P = (PVOID)a1;
v80 = a1;
memset(&LockHandle, 0, sizeof(LockHandle));
v3 = *(_QWORD *)(a1 + 72);
v78 = v3;
CurrentThread = v3;
v4 = a1;
Node = (_RTL_BALANCED_NODE *)a1;
v5 = *(VOID **)(a1 + 40);
v6 = *(unsigned int *)(v4 + 64);
v70 = HIDWORD(v6);
LODWORD(LargePageIndex) = v6;
v81 = v6;
if( (unsigned int)v6 >= 3 )
{
v7 = 1i64;
}
else
{
v7 = MiLargePageSizes[v6];
if( *(_BYTE *)(v4 + 80) && !(_DWORD)v6 )
{
v70 = *(_QWORD *)(v4 + 224);
v5 = (VOID *)(*(_QWORD *)(v70 + 176) + ((unsigned __int64)*(unsigned __int16 *)(v4 + 216) << 21));
v4 = v70;
Node = (_RTL_BALANCED_NODE *)v70;
v7 = 512i64;
}
}
if( v4 == a1 )
++dword_140C2A0B8[v6];
v8 = v7 << 12;
if( (unsigned int)v6 <= 1 )
++dword_140C2A078[v6];
KeZeroPages(v5, v8);
v9 = *(_EX_PUSH_LOCK **)&SpinCount[4];
HIDWORD(v65) = 1;
v10 = 1;
v75 = 1;
v11 = 0;
HIDWORD(LargePageIndex) = 0;
v68 = 0;
v69 = 0;
CurrentThread = (INT64)KeGetCurrentThread();
if( MiColdPageSizeSupported() && !*(_BYTE *)(v12 + 195) && !*(_BYTE *)(v4 + 70) && !*(_BYTE *)(v4 + 69) )
{
v68 = 1;
v69 = MiSetZeroPageThreadPriority(*(INT64 *)&SpinCount[4], v12, 1i64);
--*(_WORD *)(CurrentThread + 486);
ExAcquirePushLockSharedEx(v9 + 24, 0i64);
}
P = 0i64;
if( v70 )
{
v11 = 1;
v3 = *(_QWORD *)(v70 + 168);
v78 = v3;
KeAcquireInStackQueuedSpinLock(
(PKSPIN_LOCK)(qword_140C50AD0 + 4544i64 * *(unsigned int *)(v70 + 184) + 4304),
&LockHandle);
}
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
v73 = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)(v3 + 24), 0x3Fui64) )
{
do
{
++v73;
_mm_pause();
}
while( *(__int64 *)(v3 + 24) < 0 );
}
if( v70 )
{
HIDWORD(v65) = 0;
v10 = 0;
if( BYTE5(Node[2].ParentValue) != 1 )
{
if( ++*(_DWORD *)(v70 + 192) != 512 )
{
v75 = 0;
goto LABEL_32;
}
v10 = 1;
}
HIDWORD(v65) = v10;
v13 = *(_DWORD *)(v70 + 188);
if( v13 == 1 )
{
v14 = *(_QWORD *)(v70 + 72);
v15 = *(_QWORD **)(v70 + 80);
if( *(_QWORD *)(v14 + 8) != v70 + 72 || *v15 != v70 + 72 )
__fastfail(3u);
*v15 = v14;
*(_QWORD *)(v14 + 8) = v15;
v10 = 1;
P = (PVOID)v70;
}
else
{
*(_DWORD *)(v70 + 188) = v13 - 1;
HIDWORD(v65) = v10;
}
}
LABEL_32:
v16 = Node;
v17 = BYTE5(Node[2].ParentValue);
LOBYTE(v65) = v17;
if( v10 != 1 )
{
LABEL_87:
v18 = a1;
goto LABEL_88;
}
if( v11 != 1 )
{
v19 = *(unsigned int *)(a1 + 64);
v20 = *(_QWORD *)(a1 + 32);
*(_QWORD *)TbFlushList = 0i64;
v87 = 0i64;
v88 = 0i64;
v89 = 0i64;
v90 = 0i64;
v91 = 0i64;
v92 = 0i64;
v93 = 0i64;
v94 = 0i64;
v95 = 0i64;
v96 = 0i64;
v21 = 0i64;
v22 = 0;
v84 = 20i64;
v23 = 0;
v24 = 0;
v25 = 0i64;
v85 = 0i64;
Base = 0i64;
if( (unsigned int)v19 <= 1 )
{
MiInsertLargeTbFlushEntry(TbFlushList, (unsigned int)(2 - v19), v20);
v21 = 1i64;
v25 = v85;
v22 = HIDWORD(v84);
v24 = TbFlushList[1];
v23 = TbFlushList[0];
}
v26 = v20;
PteBase = (unsigned __int64)MmGetPteBase();
PteLimit = MmGetPteLimit();
if( v20 >= PteBase )
{
do
{
if( v26 > (unsigned __int64)PteLimit )
break;
v26 = (__int64)((v26 << 25) - (PteBase << 25)) >> 16;
}
while( v26 >= PteBase );
}
v74 = (!*(&stru_140C4DB30 + 449)
|| v26 < *(&stru_140C4DB30 + 449)
|| v26 >= *(&stru_140C4DB30 + 449) + (*(&stru_140C4DB30 + 451) << 30))
&& (unsigned int)v19 <= 1;
if( v21 )
goto LABEL_82;
v29 = PteBase << 25;
v30 = (__int64)((v20 << 25) - (PteBase << 25)) >> 16;
if( (_DWORD)v19 != 3 )
{
if( (_DWORD)v19 == 2 )
{
v21 = 16i64;
MiInsertTbFlushEntry(TbFlushList, (VOID *)v30, 0x10ui64, 0i64);
}
else
{
v40 = MiLargePageSizes[v19];
if( (unsigned int)v19 <= 1 )
{
v41 = (unsigned int)(2 - v19);
do
{
MiInsertTbFlushEntry(TbFlushList, (VOID *)v30, v40, 0i64);
v30 = (__int64)((v30 << 25) - v29) >> 16;
v40 <<= 9;
--v41;
}
while( v41 );
}
v21 = 512i64;
}
goto LABEL_82;
}
v21 = 1i64;
v31 = 1i64;
if( v23 != 1 && (v24 & 8) == 0 && v30 >= (unsigned __int64)MmGetPteBase() && v30 <= (unsigned __int64)PteLimit )
{
v24 |= 8u;
LOBYTE(TbFlushList[1]) = v24;
}
if( v22 )
{
if( (v24 & 4) == 0 )
{
v32 = &Base + v22 - 1;
v33 = *v32;
if( (*v32 & 0xC00) == 0 )
{
v34 = *v32 & 0x3FF;
if( (v33 & 0xFFFFFFFFFFFFF000ui64) + ((v34 + 1) << 12) == v30 && v34 + 1 > v34 && v34 + 1 <= 0x3FF )
{
v85 = v25 + 1;
*v32 = ((unsigned __int16)v33 ^ (unsigned __int16)(v33 + 1)) & 0x3FF ^ (unsigned __int64)v33;
LABEL_82:
for( i = v20 + 8 * v21; v20 < i; v20 += 8i64 )
*(_QWORD *)v20 = 0i64;
if( v74 )
MiFlushTbList(TbFlushList);
v16 = Node;
v17 = (char)v65;
v3 = v78;
goto LABEL_87;
}
}
}
if( (v24 & 4) == 0 )
{
v35 = &Base + v22 - 1;
v36 = *v35;
if( (*v35 & 0xC00) == 0 && (v36 & 0xFFFFFFFFFFFFF000ui64) == v30 + 4096 )
{
v37 = *v35 & 0x3FF;
if( v37 + 1 > v37 && v37 + 1 <= 0x3FF )
{
v85 = v25 + 1;
*v35 = ((unsigned __int16)(v36 - 4096) ^ (unsigned __int16)(v36 - 4096 + 1)) & 0x3FF ^ (unsigned __int64)(v36 - 4096);
goto LABEL_82;
}
}
}
}
if( v22 < (unsigned int)v84 )
{
while( 1 )
{
v38 = 1024i64;
if( (unsigned __int64)(v31 - 1) <= 0x3FF )
v38 = v31;
v31 -= v38;
v39 = v30 & 0xFFFFFFFFFFFFF000ui64 | ((_WORD)v38 - 1) & 0x3FF;
v30 += v38 << 12;
*(&Base + v22) = v39;
v22 = HIDWORD(v84) + 1;
HIDWORD(v84) = v22;
v85 += v38;
if( v22 == (_DWORD)v84 && (TbFlushList[1] & 4) == 0 )
{
qsort((UINT64)&Base, v22, 8ui64, (INT64)MiTbFlushSort, v65, LargePageIndex, (UINT64)Node);
MiCompressTbFlushList(TbFlushList);
v22 = HIDWORD(v84);
if( HIDWORD(v84) == (_DWORD)v84 )
{
if( v31 )
break;
}
}
if( !v31 )
goto LABEL_82;
}
BYTE1(TbFlushList[1]) = 1;
v85 = HIDWORD(v84);
}
else
{
BYTE1(TbFlushList[1]) = 1;
}
goto LABEL_82;
}
v18 = a1;
MiFreeUltraMapping(*(_QWORD *)(*(_QWORD *)(a1 + 224) + 176i64));
v16 = Node;
LABEL_88:
v43 = v70;
if( v70 && v75 == 1 )
*(_QWORD *)(v18 + 224) = 0i64;
v44 = HIDWORD(v65);
if( HIDWORD(v65) == 1 || P )
{
ParentValue_high = HIBYTE(v16[2].ParentValue);
v46 = (INT64 *)((char *)&stru_140C4DB30 + 1920);
if( ParentValue_high )
v46 = (INT64 *)((char *)&stru_140C4DB30 + 1904);
v47 = (UINT64 *)((char *)&stru_140C4DB30 + 1928);
if( ParentValue_high )
v47 = (UINT64 *)((char *)&stru_140C4DB30 + 1912);
*(_DWORD *)SpinCount = 0;
if( _interlockedbittestandset((volatile signed __int32 *)v46, 0x1Fu) )
*(_DWORD *)SpinCount = ExpWaitForSpinLockExclusiveAndAcquire(v46, 0xFFu);
v48 = *(_DWORD *)v46;
while( (v48 & 0xBFFFFFFF) != 0x80000000 )
{
if( (v48 & 0x40000000) == 0 )
{
v50 = _InterlockedCompareExchange((volatile signed __int32 *)v46, v48 | 0x40000000, v48);
v49 = v48 == v50;
v48 = v50;
if( !v49 )
continue;
}
KeYieldProcessorEx((UINT64 *)SpinCount);
v48 = *(_DWORD *)v46;
}
RtlAvlRemoveNode(v47, (INT64 *)Node);
BYTE4(Node[2].ParentValue) = 0;
*(_DWORD *)v46 = 0;
v44 = HIDWORD(v65);
v43 = v70;
}
v51 = *(_BYTE *)(v80 + 80);
if( v17 == 1 )
{
if( v51 )
++dword_140C2A098[(unsigned int)v81];
else
++dword_140C2A0D8[(unsigned int)v81];
++dword_140C2A074;
LABEL_110:
v52 = 0i64;
LABEL_111:
v53 = LargePageIndex;
goto LABEL_112;
}
if( v51 )
{
++dword_140C2A088[(unsigned int)v81];
}
else if( BYTE6(Node[2].ParentValue) )
{
++dword_140C2A0A8[(unsigned int)v81];
}
else
{
++dword_140C2A0C8[(unsigned int)v81];
}
++dword_140C2A068;
if( v44 != 1 )
goto LABEL_110;
v52 = (v3 - (__int64)MmGetPfnDb()) / 48;
v53 = LargePageIndex;
if( (_DWORD)LargePageIndex == 3 )
{
v54 = 1;
++dword_140C2A06C;
*(_QWORD *)(a1 + 24) = 0i64;
*(_BYTE *)(v3 + 34) &= ~8u;
v55 = 128i64;
if( *(&stru_140C4DB30 + 42) )
{
if( (*(&stru_140C4DB30 + 336) & 0x80) != 0 )
v55 = 144i64;
else
v55 = *(&stru_140C4DB30 + 42) | 0x80i64;
}
*(_QWORD *)(v3 + 16) = v55;
if( BYTE6(Node[2].ParentValue) )
{
MiFreeListPageContentsChanged(v52);
}
else
{
if( v68 )
{
LODWORD(v56) = MiSearchNumaNodeTable((PVOID)v52);
v57 = *(_DWORD *)(v56 + 8);
v58 = (MiGetPfnChannel(v3) << *(&stru_140C4DB30 + 157)) | *(&stru_140C4DB30 + 66) & (unsigned int)v52 | (v57 << *(&stru_140C4DB30 + 156));
LOBYTE(v59) = MiFreeZeroPageSlistSufficient(*(INT64 *)&SpinCount[4], (unsigned int)v58, 0i64);
if( v59 )
{
if( *(_QWORD *)(*(_QWORD *)(*(_QWORD *)&SpinCount[4] + 2176i64) + 40 * v58) >= (unsigned __int64)(unsigned int)(4 * *(_DWORD *)(*(_QWORD *)&SpinCount[4] + 6300i64)) )
{
v54 = 1025;
HIDWORD(LargePageIndex) = 1;
}
}
}
MiUnlinkFreeOrZeroedPage(v52, 0i64, 0i64);
MiInsertPageInFreeOrZeroedList(v52, v54, v60, v61, (UINT64)v65, LargePageIndex);
}
goto LABEL_111;
}
v62 = 0;
if( v68 )
{
if( !BYTE6(Node[2].ParentValue) )
v62 = 1;
HIDWORD(LargePageIndex) = v62;
}
MiLargePageFreeToZero(v52, (unsigned int)LargePageIndex, v62);
LABEL_112:
_InterlockedAnd64((volatile signed __int64 *)(v3 + 24), 0x7FFFFFFFFFFFFFFFui64);
__writecr8(CurrentIrql);
if( v43 )
{
KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
__writecr8(LockHandle.OldIrql);
}
result = (unsigned int)P;
if( P )
result = (unsigned int)ExFreePoolWithTag(P, 0);
if( HIDWORD(LargePageIndex) )
result = MiChangePageHeatImmediate(v52, v53, 0i64);
if( v68 )
{
v64 = *(_EX_PUSH_LOCK **)&SpinCount[4];
if( _InterlockedCompareExchange64((volatile signed __int64 *)(*(_QWORD *)&SpinCount[4] + 192i64), 0i64, 17i64) != 17 )
ExfReleasePushLockShared(v64 + 24);
KeAbPostRelease(&v64[24]);
KiLeaveGuardedRegionUnsafe(CurrentThread);
return MiSetZeroPageThreadPriority((INT64)v64, CurrentThread, v69);
}
return result;
}Referenced by:
MiZeroLargePages
MiZeroPageThread