MiValidateInPage

NTSTATUS __stdcall MiValidateInPage(_MMINPAGE_SUPPORT *InPageSupport){
  _MDL *p_Mdl; 
  _CONTROL_AREA *v2; 
  unsigned int ByteCount; 
  INT64 SeImageStub; 
  UINT64 *v6; 
  __int64 v7; 
  unsigned int ByteOffset; 
  unsigned __int64 v9; 
  UINT64 *v10; 
  unsigned int v11; 
  int v12; 
  __int64 v13; 
  unsigned __int64 v14; 
  __int64 v15; 
  int v16; 
  int v17; 
  VOID *MappedSystemVa; 
  _EPROCESS *v19; 
  _CONTROL_AREA *v20; 
  __int64 v21; 
  _MMPTE *PteBase; 
  _MMPFN *v23; 
  UINT64 v24; 
  __int64 *v25; 
  __int64 v26; 
  NTSTATUS result; 
  NTSTATUS v28; 
  __int16 MdlFlags; 
  VOID *v30; 
  UINT64 v31; 
  __int64 v32; 
  int v33; 
  UINT64 Diff; 
  UINT64 DesiredProtection; 
  _MDL *MemoryDescriptorList; 
  _CONTROL_AREA *ControlArea; 
  int v38; 
  unsigned int VerifyType; 
  NTSTATUS v40; 
  VOID *MappingVa; 
  _EPROCESS *CallingProcess; 

  p_Mdl = &InPageSupport->Mdl;
  v2 = InPageSupport->ControlArea;
  ByteCount = InPageSupport->ByteCount;
  ControlArea = v2;
  if( InPageSupport->PrefetchMdl )
    p_Mdl = InPageSupport->PrefetchMdl;
  v40 = 0;
  SeImageStub = (INT64)v2->u2.SeImageStub;
  MemoryDescriptorList = p_Mdl;
  v6 = (UINT64 *)&p_Mdl[1];
  v7 = p_Mdl->ByteCount;
  ByteOffset = p_Mdl->ByteOffset;
  v9 = ((unsigned __int64)(((_WORD)ByteOffset + (unsigned __int16)LODWORD(p_Mdl->StartVa)) & 0xFFF) + v7 + 4095) >> 12;
  CallingProcess = KeGetCurrentThread()->ApcState.Process;
  v10 = (UINT64 *)(&p_Mdl[1].Next + (unsigned int)v9);
  InPageSupport->ReadOffset.QuadPart += ByteCount - (_DWORD)v7 - ByteOffset;
  v11 = ByteCount - p_Mdl->ByteOffset - p_Mdl->ByteCount;
  v12 = 2;
  VerifyType = 0;
  InPageSupport->u3.ImagePteOffset += ((v11 & 0xFFF) != 0) + (v11 >> 12);
  v13 = *(_QWORD *)(SeImageStub + 40);
  if( (v13 & 0xFFFFFFFFFFFFFFF8ui64) <= 8 )
    v12 = 0;
  LODWORD(v14) = MI_READ_PTE_LOCK_FREE((INT64)&MmGetPfnDb()[*v6].OriginalPte.u.Hard);
  v15 = (v14 >> 5) & 0x1F;
  v38 = v15;
  if( (v2->u2.WritableUserReferences & 0xC0000) != 0 && (v12 & 2) != 0 )
  {
    v16 = v12 | 1;
  }
  else
  {
    v16 = v12;
    if( (MiFlags & 0x40000) != 0 && (v15 & 2) != 0 )
      VerifyType = 3;
  }
  if( (InPageSupport->u1.e1._bf_0 & 0x10000) != 0 )
  {
    v16 |= 4u;
    if( (MiFlags & 0x4000) != 0 && (v16 & 1) != 0 )
      v16 &= ~4u;
  }
  v17 = v15 & 2;
  if( (v15 & 2) != 0 && (MiFlags & 0x40000) != 0 )
  {
    if( (MemoryDescriptorList->MdlFlags & 1) != 0 )
      MmUnmapLockedPages(MemoryDescriptorList->MappedSystemVa, MemoryDescriptorList);
    MiFlushEntireTbDueToAttributeChange();
  }
  MappedSystemVa = 0i64;
  MappingVa = 0i64;
  if( (v16 & 2) != 0
    && (unsigned int)v9 > 1
    && (MdlFlags = MemoryDescriptorList->MdlFlags, (MdlFlags & 0x4000) != 0)
    && ((MdlFlags & 5) == 0 ? (LODWORD(DesiredProtection) = -1073741808,
                               LODWORD(Diff) = 0,
                               MappedSystemVa = MmMapLockedPagesSpecifyCache(
                                                  MemoryDescriptorList,
                                                  0,
                                                  MmCached,
                                                  0i64,
                                                  Diff,
                                                  DesiredProtection)) : (MappedSystemVa = MemoryDescriptorList->MappedSystemVa),
        (MappingVa = MappedSystemVa) != 0i64) )
  {
    v30 = (VOID *)(v13 & 0xFFFFFFFFFFFFFFF8ui64);
    if( (v16 & 1) != 0 && !*(_QWORD *)(SeImageStub + 56) )
    {
      result = MiGetSectionStrongImageReference(SeImageStub);
      if( result < 0 )
        return result;
    }
    v31 = (unsigned int)((_DWORD)v9 << 12);
    v19 = CallingProcess;
    LODWORD(Diff) = v17 != 0 ? 2 : 0;
    if( SeValidateImageData(v30, MappingVa, v31, InPageSupport->ReadOffset.QuadPart, Diff, CallingProcess) < 0 )
    {
      MappedSystemVa = 0i64;
      MappingVa = 0i64;
    }
    else
    {
      MappedSystemVa = MappingVa;
    }
  }
  else
  {
    v19 = CallingProcess;
  }
  if( v6 >= v10 )
    return v40;
  v20 = ControlArea;
  v21 = 0i64;
  while( 1 )
  {
    PteBase = MmGetPteBase();
    v23 = &MmGetPfnDb()[*v6];
    v16 ^= ((unsigned __int8)v16 ^ (unsigned __int8)(2 * v16)) & 8;
    if( v23 == (_MMPFN *)*(&stru_140C4DB30 + 496) )
      goto LABEL_22;
    if( MappedSystemVa )
    {
      MiMarkPfnVerified(v23, VerifyType);
LABEL_30:
      PteBase = MmGetPteBase();
      goto LABEL_17;
    }
    if( (v16 & 2) == 0 )
      goto LABEL_17;
    LODWORD(DesiredProtection) = v38;
    v28 = MiValidateImagePfn(v20, InPageSupport->ReadOffset.QuadPart, v19, 0xFFFFFFFFui64, Diff, DesiredProtection, *v6);
    if( v28 >= 0 )
      goto LABEL_30;
    if( v28 == -1073741670 )
      break;
    v40 = -1073740748;
    if( (v16 & 1) == 0 || (MiFlags & 0x4000) == 0 )
      goto LABEL_30;
    PteBase = MmGetPteBase();
    if( (InPageSupport->u1.e1._bf_0 & 0x10000) != 0 )
      v16 |= 8u;
LABEL_17:
    if( (v16 & 8) == 0 )
      goto LABEL_22;
    if( (MemoryDescriptorList->MdlFlags & 1) != 0 )
    {
      v24 = (UINT64)MemoryDescriptorList->MappedSystemVa + 4096 * (v21 >> 3);
      v25 = (__int64 *)((char *)PteBase + ((v24 >> 9) & 0x7FFFFFFFF8i64));
      LODWORD(v26) = MI_READ_PTE_LOCK_FREE((INT64)v25);
      if( (v26 & 0x42) == 0 )
      {
        v32 = v26 | 0x842;
        LOBYTE(v33) = MiPteInShadowRange((UINT64)v25);
        if( v33 && (KeGetCurrentThread()->ApcState.Process->Flags3 & 0x1000) != 0 && (v32 & 1) != 0 )
          v32 |= 0x8000000000000000ui64;
        *v25 = v32;
        if( (MiFlags & 0x100) == 0 && (MiFlags & 0x200) == 0 )
          KeFlushSingleTb(v24, FlushKernel, 1i64);
      }
    }
    else
    {
      v24 = 0i64;
    }
    if( MiRelocateImagePfn(ControlArea, (VOID *)v24, InPageSupport->u3.ImagePteOffset, *v6, 0i64, DesiredProtection) < 0 )
      break;
    v20 = ControlArea;
LABEL_22:
    InPageSupport->ReadOffset.QuadPart += 4096i64;
    ++v6;
    ++InPageSupport->u3.ImagePteOffset;
    v21 += 8i64;
    if( v6 >= v10 )
      return v40;
    MappedSystemVa = MappingVa;
    v19 = CallingProcess;
  }
  InPageSupport->IoStatus.Status = -1073741670;
  return v40;
}

Referenced by:

MiWaitForInPageComplete