MiValidateInPage
NTSTATUS __stdcall MiValidateInPage(_MMINPAGE_SUPPORT *InPageSupport){
_MDL *p_Mdl;
_CONTROL_AREA *v2;
unsigned int ByteCount;
INT64 SeImageStub;
UINT64 *v6;
__int64 v7;
unsigned int ByteOffset;
unsigned __int64 v9;
UINT64 *v10;
unsigned int v11;
int v12;
__int64 v13;
unsigned __int64 v14;
__int64 v15;
int v16;
int v17;
VOID *MappedSystemVa;
_EPROCESS *v19;
_CONTROL_AREA *v20;
__int64 v21;
_MMPTE *PteBase;
_MMPFN *v23;
UINT64 v24;
__int64 *v25;
__int64 v26;
NTSTATUS result;
NTSTATUS v28;
__int16 MdlFlags;
VOID *v30;
UINT64 v31;
__int64 v32;
int v33;
UINT64 Diff;
UINT64 DesiredProtection;
_MDL *MemoryDescriptorList;
_CONTROL_AREA *ControlArea;
int v38;
unsigned int VerifyType;
NTSTATUS v40;
VOID *MappingVa;
_EPROCESS *CallingProcess;
p_Mdl = &InPageSupport->Mdl;
v2 = InPageSupport->ControlArea;
ByteCount = InPageSupport->ByteCount;
ControlArea = v2;
if( InPageSupport->PrefetchMdl )
p_Mdl = InPageSupport->PrefetchMdl;
v40 = 0;
SeImageStub = (INT64)v2->u2.SeImageStub;
MemoryDescriptorList = p_Mdl;
v6 = (UINT64 *)&p_Mdl[1];
v7 = p_Mdl->ByteCount;
ByteOffset = p_Mdl->ByteOffset;
v9 = ((unsigned __int64)(((_WORD)ByteOffset + (unsigned __int16)LODWORD(p_Mdl->StartVa)) & 0xFFF) + v7 + 4095) >> 12;
CallingProcess = KeGetCurrentThread()->ApcState.Process;
v10 = (UINT64 *)(&p_Mdl[1].Next + (unsigned int)v9);
InPageSupport->ReadOffset.QuadPart += ByteCount - (_DWORD)v7 - ByteOffset;
v11 = ByteCount - p_Mdl->ByteOffset - p_Mdl->ByteCount;
v12 = 2;
VerifyType = 0;
InPageSupport->u3.ImagePteOffset += ((v11 & 0xFFF) != 0) + (v11 >> 12);
v13 = *(_QWORD *)(SeImageStub + 40);
if( (v13 & 0xFFFFFFFFFFFFFFF8ui64) <= 8 )
v12 = 0;
LODWORD(v14) = MI_READ_PTE_LOCK_FREE((INT64)&MmGetPfnDb()[*v6].OriginalPte.u.Hard);
v15 = (v14 >> 5) & 0x1F;
v38 = v15;
if( (v2->u2.WritableUserReferences & 0xC0000) != 0 && (v12 & 2) != 0 )
{
v16 = v12 | 1;
}
else
{
v16 = v12;
if( (MiFlags & 0x40000) != 0 && (v15 & 2) != 0 )
VerifyType = 3;
}
if( (InPageSupport->u1.e1._bf_0 & 0x10000) != 0 )
{
v16 |= 4u;
if( (MiFlags & 0x4000) != 0 && (v16 & 1) != 0 )
v16 &= ~4u;
}
v17 = v15 & 2;
if( (v15 & 2) != 0 && (MiFlags & 0x40000) != 0 )
{
if( (MemoryDescriptorList->MdlFlags & 1) != 0 )
MmUnmapLockedPages(MemoryDescriptorList->MappedSystemVa, MemoryDescriptorList);
MiFlushEntireTbDueToAttributeChange();
}
MappedSystemVa = 0i64;
MappingVa = 0i64;
if( (v16 & 2) != 0
&& (unsigned int)v9 > 1
&& (MdlFlags = MemoryDescriptorList->MdlFlags, (MdlFlags & 0x4000) != 0)
&& ((MdlFlags & 5) == 0 ? (LODWORD(DesiredProtection) = -1073741808,
LODWORD(Diff) = 0,
MappedSystemVa = MmMapLockedPagesSpecifyCache(
MemoryDescriptorList,
0,
MmCached,
0i64,
Diff,
DesiredProtection)) : (MappedSystemVa = MemoryDescriptorList->MappedSystemVa),
(MappingVa = MappedSystemVa) != 0i64) )
{
v30 = (VOID *)(v13 & 0xFFFFFFFFFFFFFFF8ui64);
if( (v16 & 1) != 0 && !*(_QWORD *)(SeImageStub + 56) )
{
result = MiGetSectionStrongImageReference(SeImageStub);
if( result < 0 )
return result;
}
v31 = (unsigned int)((_DWORD)v9 << 12);
v19 = CallingProcess;
LODWORD(Diff) = v17 != 0 ? 2 : 0;
if( SeValidateImageData(v30, MappingVa, v31, InPageSupport->ReadOffset.QuadPart, Diff, CallingProcess) < 0 )
{
MappedSystemVa = 0i64;
MappingVa = 0i64;
}
else
{
MappedSystemVa = MappingVa;
}
}
else
{
v19 = CallingProcess;
}
if( v6 >= v10 )
return v40;
v20 = ControlArea;
v21 = 0i64;
while( 1 )
{
PteBase = MmGetPteBase();
v23 = &MmGetPfnDb()[*v6];
v16 ^= ((unsigned __int8)v16 ^ (unsigned __int8)(2 * v16)) & 8;
if( v23 == (_MMPFN *)*(&stru_140C4DB30 + 496) )
goto LABEL_22;
if( MappedSystemVa )
{
MiMarkPfnVerified(v23, VerifyType);
LABEL_30:
PteBase = MmGetPteBase();
goto LABEL_17;
}
if( (v16 & 2) == 0 )
goto LABEL_17;
LODWORD(DesiredProtection) = v38;
v28 = MiValidateImagePfn(v20, InPageSupport->ReadOffset.QuadPart, v19, 0xFFFFFFFFui64, Diff, DesiredProtection, *v6);
if( v28 >= 0 )
goto LABEL_30;
if( v28 == -1073741670 )
break;
v40 = -1073740748;
if( (v16 & 1) == 0 || (MiFlags & 0x4000) == 0 )
goto LABEL_30;
PteBase = MmGetPteBase();
if( (InPageSupport->u1.e1._bf_0 & 0x10000) != 0 )
v16 |= 8u;
LABEL_17:
if( (v16 & 8) == 0 )
goto LABEL_22;
if( (MemoryDescriptorList->MdlFlags & 1) != 0 )
{
v24 = (UINT64)MemoryDescriptorList->MappedSystemVa + 4096 * (v21 >> 3);
v25 = (__int64 *)((char *)PteBase + ((v24 >> 9) & 0x7FFFFFFFF8i64));
LODWORD(v26) = MI_READ_PTE_LOCK_FREE((INT64)v25);
if( (v26 & 0x42) == 0 )
{
v32 = v26 | 0x842;
LOBYTE(v33) = MiPteInShadowRange((UINT64)v25);
if( v33 && (KeGetCurrentThread()->ApcState.Process->Flags3 & 0x1000) != 0 && (v32 & 1) != 0 )
v32 |= 0x8000000000000000ui64;
*v25 = v32;
if( (MiFlags & 0x100) == 0 && (MiFlags & 0x200) == 0 )
KeFlushSingleTb(v24, FlushKernel, 1i64);
}
}
else
{
v24 = 0i64;
}
if( MiRelocateImagePfn(ControlArea, (VOID *)v24, InPageSupport->u3.ImagePteOffset, *v6, 0i64, DesiredProtection) < 0 )
break;
v20 = ControlArea;
LABEL_22:
InPageSupport->ReadOffset.QuadPart += 4096i64;
++v6;
++InPageSupport->u3.ImagePteOffset;
v21 += 8i64;
if( v6 >= v10 )
return v40;
MappedSystemVa = MappingVa;
v19 = CallingProcess;
}
InPageSupport->IoStatus.Status = -1073741670;
return v40;
}Referenced by:
MiWaitForInPageComplete