MiFillSystemPtes

INT64 __fastcall MiFillSystemPtes(UINT64 PointerPte, UINT64 NumberOfPages, INT64 a3, UINT64 a4, INT64 a5, INT64 a6){
  ULONG_PTR BugCheckParameter4; 
  unsigned int ProtectionPfnCompatible; 
  int v9; 
  UINT64 v11; 
  UINT64 PteBase; 
  unsigned __int64 v13; 
  _MMPTE *PteLimit; 
  unsigned __int64 LeafVa; 
  int v16; 
  __int64 v17; 
  int v18; 
  unsigned __int64 v19; 
  __int64 v20; 
  unsigned __int64 v21; 
  UINT64 v22; 
  unsigned __int16 v23; 
  unsigned __int64 v24; 
  __int64 v25; 
  unsigned __int64 v26; 
  unsigned __int64 v27; 
  __int64 v28; 
  UINT8 v29; 
  WCHAR *v30; 
  INT64 v31; 
  _MMPFN *PfnDb; 
  unsigned __int64 v33; 
  int v34; 
  UINT64 *v35; 
  INT64 v36; 
  UNICODE_STRING *v37; 
  int v38; 
  INT64 v39; 
  int v40; 
  __int64 v41; 
  int v42; 
  unsigned __int64 v43; 
  unsigned __int64 v45; 
  char v46; 
  unsigned __int8 v47; 
  UINT64 ValidPte; 
  unsigned int v49; 
  INT64 v50; 
  int v51; 
  _RTL_BALANCED_NODE *v52; 
  INT64 v53; 
  _RTL_BALANCED_NODE *v54; 
  ULONG_PTR v55; 
  _RTL_BALANCED_NODE *v56; 
  unsigned __int64 v57; 
  unsigned int v58; 
  INT64 v60; 
  unsigned __int16 v61; 
  BugCheckParameter4 = 0i64;
  v56 = 0i64;
  ProtectionPfnCompatible = a4;
  v54 = 0i64;
  v9 = 1;
  v58 = 1;
  *(_DWORD *)a6 = 0;
  v11 = NumberOfPages;
  if( (_DWORD)a4 )
  {
    if( (_DWORD)a4 != 31 )
    {
      if( (unsigned int)a4 >> 3 == 3 )
      {
        if( (a4 & 7) != 0 )
          v58 = 2;
        goto LABEL_10;
      }
      if( (unsigned int)a4 >> 3 == 1 )
        v9 = 0;
    }
    v58 = v9;
  }
  else
  {
    v58 = 3;
  }
LABEL_10:
  PteBase = (UINT64)MmGetPteBase();
  v13 = MmProtectToPteMask[a4 & 0x1F] & 0xFFFF000000000E5Eui64 | 0x21;
  PteLimit = MmGetPteLimit();
  if( PointerPte < PteBase || PointerPte > (unsigned __int64)PteLimit )
  {
    v19 = MmProtectToPteMask[a4 & 0x1F] & 0xFFFF000000000E5Eui64 | 0x121;
  }
  else
  {
    LeafVa = (__int64)((PointerPte << 25) - (PteBase << 25)) >> 16;
    if( PointerPte >= (unsigned __int64)MmGetPdeBase() && PointerPte <= (unsigned __int64)MmGetPdeLimit() )
    {
      if( (_MMPTE *)PointerPte == MmGetPxeSelfRef() )
      {
        v13 = MmProtectToPteMask[a4 & 0x1F] & 0x7FFF000000000E5Ei64 | 0x8000000000000021ui64;
      }
      else if( (a4 & 0x4000000) == 0 )
      {
        v13 = MmProtectToPteMask[a4 & 0x1F] & 0x7FFF000000000E5Ei64 | 0x21;
      }
      v16 = MiUserPdeOrAbove(PointerPte);
      v11 = NumberOfPages;
      if( v16 )
        v13 |= 4ui64;
      BugCheckParameter4 = 0i64;
    }
    v17 = v13 | 4;
    if( PointerPte > PteBase + 0x3FFFFFFF78i64 )
      v17 = v13;
    if( (ProtectionPfnCompatible & 0x4000000) != 0 )
      LeafVa = MiGetLeafVa((__int64)((PointerPte << 25) - (PteBase << 25)) >> 16);
    if( LeafVa >= 0xFFFF800000000000ui64 )
    {
      if( *((_BYTE *)&antNameB + ((LeafVa >> 39) & 0x1FF) - 256) == 1 )
      {
        v18 = BugCheckParameter4;
      }
      else if( LeafVa < PteBase || LeafVa > (unsigned __int64)MmGetPteLimit() )
      {
        if( LeafVa < qword_140C4F878 || (v18 = HIBYTE(word_140C4DD48), LeafVa > qword_140C4E0A8) )
          v18 = (unsigned __int8)word_140C4DD48;
      }
      else
      {
        v18 = BugCheckParameter4;
      }
    }
    else
    {
      v18 = HIBYTE(word_140C4DD48);
    }
    v19 = v17 | 0x100;
    if( !v18 )
      v19 = v17;
  }
  v55 = BugCheckParameter4;
  v20 = v19 | 0x42;
  v21 = BugCheckParameter4;
  v22 = v11;
  if( (ProtectionPfnCompatible & 5) != 4 )
    v20 = v19;
  v23 = v20 & 0xFFFB;
  if( (ProtectionPfnCompatible & 0x40000000) == 0 )
    v23 = v20;
  v24 = v20 & 0xFFFFFFFFFFFFFFFBui64;
  v25 = ((unsigned __int16)((unsigned __int8)word_140C4DD48 << 8) ^ v23) & 0x100;
  if( (ProtectionPfnCompatible & 0x40000000) == 0 )
    v24 = v20;
  v26 = v24 ^ v25;
  v27 = v26 & 0xFFFFFFFFFFFFFEFFui64;
  if( (ProtectionPfnCompatible & 0x8000000) == 0 )
    v27 = v26;
  v28 = v27 | 0x80;
  if( (ProtectionPfnCompatible & 0x4000000) == 0 )
    v28 = v27;
  v57 = v28 & 0xFAFFFFFFFFFFFFFFui64;
  if( !v11 )
    return 0i64;
  v29 = a5;
  v30 = (WCHAR *)((char *)MmGetPfnDb() + 40);
  v31 = a3 - 8;
  PfnDb = MmGetPfnDb();
  v33 = BugCheckParameter4;
  if( a3 >= 0 )
    v33 = a3 - 1;
  if( a3 >= 0 )
    v31 = BugCheckParameter4;
  v34 = a5 & 4;
  HIDWORD(v53) = v34;
  while( 1 )
  {
    if( v31 )
      v33 = *(_QWORD *)(v31 + 8);
    else
      ++v33;
    v35 = (UINT64 *)(v31 + 8);
    if( !v31 )
      v35 = 0i64;
    v31 = (INT64)v35;
    if( v34 && v33 == qword_140C4EAB8 )
      goto LABEL_114;
    if( v33 > 0xFFFFFFFFFi64 || ((*(_QWORD *)&v30[24 * v33] >> 50) & 1) == 0 )
    {
      if( v21 || (v21 = (unsigned __int64)MiIoSpaceRunIsConstant(v33, v35, v22)) != 0 )
      {
        if( v21 > 1 )
        {
          v51 = *(_DWORD *)(v21 + 40);
LABEL_107:
          ProtectionPfnCompatible &= 7u;
          if( v51 )
          {
            if( v51 == 2 )
              ProtectionPfnCompatible |= 0x18u;
          }
          else
          {
            ProtectionPfnCompatible |= 8u;
          }
          v49 = ProtectionPfnCompatible;
          goto LABEL_112;
        }
      }
      else
      {
        v21 = 1i64;
      }
      v50 = v55;
      if( v55 )
      {
        v52 = v56;
      }
      else
      {
        if( v31 )
          v50 = 1i64;
        else
          v50 = MiIoPagesInRun(v33, v22);
        v42 = MiReferenceIoPages(1ui64, v33, v50, v58, 0i64, &v54);
        if( v42 < 0 )
          goto LABEL_77;
        *(_DWORD *)a6 |= 1u;
        v52 = v54;
      }
      v55 = v50 - 1;
      v61 = *((_WORD *)v52[2].Children[0]->Children + (v33 & 0xFFFFFFFFFi64) - v52[1].ParentValue);
      v56 = v54;
      v51 = v61 >> 14;
      goto LABEL_107;
    }
    v36 = (INT64)PfnDb + 48 * v33;
    v37 = (UNICODE_STRING *)(v29 & 2);
    if( (v29 & 2) != 0 && ((*(_BYTE *)(v36 + 34) & 7) != 5 || !MiIsPfnFileOnly((INT64)PfnDb + 48 * v33)) )
      KeBugCheckEx(0x1Au, 0x1160Cui64, v33, 0i64, BugCheckParameter4);
    if( !*(_WORD *)(v36 + 32) && (!(_DWORD)v37 || (*(_BYTE *)(v36 + 34) & 7) != 5 || !MiIsPfnFileOnly(v36)) )
      MiShowBadMapper(v33, 5ui64);
    LOBYTE(v38) = MI_PFN_IS_PROTO((UNICODE_STRING *)v36, v37, v29, v30);
    if( v38 )
      goto LABEL_89;
    v41 = *(_QWORD *)(v36 + 40);
    if( (v41 & 0x1000000000i64) == 0 )
      break;
    LODWORD(v60) = v40;
    LODWORD(v53) = v40;
    if( (unsigned int)MiGetPfnPageSizeIndexUnsynchronized(v39, &v60, &v53) == 3 || (_DWORD)v60 != 6 )
    {
      v42 = -1073741800;
LABEL_77:
      v43 = (unsigned __int64)MmGetPteBase();
      goto LABEL_78;
    }
LABEL_89:
    v47 = *(_BYTE *)(v36 + 34);
    if( (v47 & 0xC0) == 0xC0 )
    {
      MiAssignInitialPageAttribute(v36, v58);
      v47 = *(_BYTE *)(v36 + 34);
    }
    if( v58 != v47 >> 6 )
    {
      ProtectionPfnCompatible = MiMakeProtectionPfnCompatible(ProtectionPfnCompatible, (_MMPFN *)v36);
      v49 = ProtectionPfnCompatible;
LABEL_112:
      ValidPte = MiMakeValidPte(PointerPte, v33, v49 | 0xA0000000);
      goto LABEL_113;
    }
    ValidPte = v57 | ((v33 & 0xFFFFFFFFFi64 | 0xA00000000000i64) << 12);
LABEL_113:
    v34 = HIDWORD(v53);
    BugCheckParameter4 = 0i64;
    v29 = a5;
    *(_QWORD *)PointerPte = ValidPte;
    v30 = (WCHAR *)((char *)MmGetPfnDb() + 40);
    PfnDb = MmGetPfnDb();
LABEL_114:
    PointerPte += 8i64;
    if( !--v22 )
      return 0i64;
  }
  v43 = (unsigned __int64)MmGetPteBase();
  v45 = (__int64)((*(_QWORD *)(v36 + 8) << 25) - (v43 << 25)) >> 16;
  if( v45 < v43 )
    goto LABEL_89;
  if( v45 > (unsigned __int64)MmGetPteLimit() )
    goto LABEL_89;
  if( (v41 & 0xFFFFFFFFFi64) == 0xFFFFFFFFDi64 )
    goto LABEL_89;
  v46 = *(_BYTE *)(v36 + 34);
  if( (v46 & 0x20) != 0 && (*(_QWORD *)(v36 + 24) & 0x3FFFFFFFFFFFFFFFi64) == 0 && *(_WORD *)(v36 + 32) )
    goto LABEL_89;
  if( (v46 & 8) != 0 || ((*(_QWORD *)v36 >> 13) & 0x7FFFFFFFFFF0i64 | 0xFFFF800000000000ui64) == 0xFFFF800000000030ui64 )
    goto LABEL_89;
  v42 = -1073741800;
LABEL_78:
  if( (*(_DWORD *)a6 & 1) != 0 )
    MiZeroAndFlushPtes(
      (__int64)((PointerPte << 25) + ((v22 - NumberOfPages) << 28) - (v43 << 25)) >> 16,
      NumberOfPages - v22);
  return(unsigned int)v42;
}

Referenced by:

MiLockAndMapEntireDriver
MiMapContiguousMemory
MiMapHotPatchImageInSystemSpace
MmMapLockedPagesSpecifyCache
MmMapMdl