MiFillSystemPtes
INT64 __fastcall MiFillSystemPtes(UINT64 PointerPte, UINT64 NumberOfPages, INT64 a3, UINT64 a4, INT64 a5, INT64 a6){
ULONG_PTR BugCheckParameter4;
unsigned int ProtectionPfnCompatible;
int v9;
UINT64 v11;
UINT64 PteBase;
unsigned __int64 v13;
_MMPTE *PteLimit;
unsigned __int64 LeafVa;
int v16;
__int64 v17;
int v18;
unsigned __int64 v19;
__int64 v20;
unsigned __int64 v21;
UINT64 v22;
unsigned __int16 v23;
unsigned __int64 v24;
__int64 v25;
unsigned __int64 v26;
unsigned __int64 v27;
__int64 v28;
UINT8 v29;
WCHAR *v30;
INT64 v31;
_MMPFN *PfnDb;
unsigned __int64 v33;
int v34;
UINT64 *v35;
INT64 v36;
UNICODE_STRING *v37;
int v38;
INT64 v39;
int v40;
__int64 v41;
int v42;
unsigned __int64 v43;
unsigned __int64 v45;
char v46;
unsigned __int8 v47;
UINT64 ValidPte;
unsigned int v49;
INT64 v50;
int v51;
_RTL_BALANCED_NODE *v52;
INT64 v53;
_RTL_BALANCED_NODE *v54;
ULONG_PTR v55;
_RTL_BALANCED_NODE *v56;
unsigned __int64 v57;
unsigned int v58;
INT64 v60;
unsigned __int16 v61;
BugCheckParameter4 = 0i64;
v56 = 0i64;
ProtectionPfnCompatible = a4;
v54 = 0i64;
v9 = 1;
v58 = 1;
*(_DWORD *)a6 = 0;
v11 = NumberOfPages;
if( (_DWORD)a4 )
{
if( (_DWORD)a4 != 31 )
{
if( (unsigned int)a4 >> 3 == 3 )
{
if( (a4 & 7) != 0 )
v58 = 2;
goto LABEL_10;
}
if( (unsigned int)a4 >> 3 == 1 )
v9 = 0;
}
v58 = v9;
}
else
{
v58 = 3;
}
LABEL_10:
PteBase = (UINT64)MmGetPteBase();
v13 = MmProtectToPteMask[a4 & 0x1F] & 0xFFFF000000000E5Eui64 | 0x21;
PteLimit = MmGetPteLimit();
if( PointerPte < PteBase || PointerPte > (unsigned __int64)PteLimit )
{
v19 = MmProtectToPteMask[a4 & 0x1F] & 0xFFFF000000000E5Eui64 | 0x121;
}
else
{
LeafVa = (__int64)((PointerPte << 25) - (PteBase << 25)) >> 16;
if( PointerPte >= (unsigned __int64)MmGetPdeBase() && PointerPte <= (unsigned __int64)MmGetPdeLimit() )
{
if( (_MMPTE *)PointerPte == MmGetPxeSelfRef() )
{
v13 = MmProtectToPteMask[a4 & 0x1F] & 0x7FFF000000000E5Ei64 | 0x8000000000000021ui64;
}
else if( (a4 & 0x4000000) == 0 )
{
v13 = MmProtectToPteMask[a4 & 0x1F] & 0x7FFF000000000E5Ei64 | 0x21;
}
v16 = MiUserPdeOrAbove(PointerPte);
v11 = NumberOfPages;
if( v16 )
v13 |= 4ui64;
BugCheckParameter4 = 0i64;
}
v17 = v13 | 4;
if( PointerPte > PteBase + 0x3FFFFFFF78i64 )
v17 = v13;
if( (ProtectionPfnCompatible & 0x4000000) != 0 )
LeafVa = MiGetLeafVa((__int64)((PointerPte << 25) - (PteBase << 25)) >> 16);
if( LeafVa >= 0xFFFF800000000000ui64 )
{
if( *((_BYTE *)&antNameB + ((LeafVa >> 39) & 0x1FF) - 256) == 1 )
{
v18 = BugCheckParameter4;
}
else if( LeafVa < PteBase || LeafVa > (unsigned __int64)MmGetPteLimit() )
{
if( LeafVa < qword_140C4F878 || (v18 = HIBYTE(word_140C4DD48), LeafVa > qword_140C4E0A8) )
v18 = (unsigned __int8)word_140C4DD48;
}
else
{
v18 = BugCheckParameter4;
}
}
else
{
v18 = HIBYTE(word_140C4DD48);
}
v19 = v17 | 0x100;
if( !v18 )
v19 = v17;
}
v55 = BugCheckParameter4;
v20 = v19 | 0x42;
v21 = BugCheckParameter4;
v22 = v11;
if( (ProtectionPfnCompatible & 5) != 4 )
v20 = v19;
v23 = v20 & 0xFFFB;
if( (ProtectionPfnCompatible & 0x40000000) == 0 )
v23 = v20;
v24 = v20 & 0xFFFFFFFFFFFFFFFBui64;
v25 = ((unsigned __int16)((unsigned __int8)word_140C4DD48 << 8) ^ v23) & 0x100;
if( (ProtectionPfnCompatible & 0x40000000) == 0 )
v24 = v20;
v26 = v24 ^ v25;
v27 = v26 & 0xFFFFFFFFFFFFFEFFui64;
if( (ProtectionPfnCompatible & 0x8000000) == 0 )
v27 = v26;
v28 = v27 | 0x80;
if( (ProtectionPfnCompatible & 0x4000000) == 0 )
v28 = v27;
v57 = v28 & 0xFAFFFFFFFFFFFFFFui64;
if( !v11 )
return 0i64;
v29 = a5;
v30 = (WCHAR *)((char *)MmGetPfnDb() + 40);
v31 = a3 - 8;
PfnDb = MmGetPfnDb();
v33 = BugCheckParameter4;
if( a3 >= 0 )
v33 = a3 - 1;
if( a3 >= 0 )
v31 = BugCheckParameter4;
v34 = a5 & 4;
HIDWORD(v53) = v34;
while( 1 )
{
if( v31 )
v33 = *(_QWORD *)(v31 + 8);
else
++v33;
v35 = (UINT64 *)(v31 + 8);
if( !v31 )
v35 = 0i64;
v31 = (INT64)v35;
if( v34 && v33 == qword_140C4EAB8 )
goto LABEL_114;
if( v33 > 0xFFFFFFFFFi64 || ((*(_QWORD *)&v30[24 * v33] >> 50) & 1) == 0 )
{
if( v21 || (v21 = (unsigned __int64)MiIoSpaceRunIsConstant(v33, v35, v22)) != 0 )
{
if( v21 > 1 )
{
v51 = *(_DWORD *)(v21 + 40);
LABEL_107:
ProtectionPfnCompatible &= 7u;
if( v51 )
{
if( v51 == 2 )
ProtectionPfnCompatible |= 0x18u;
}
else
{
ProtectionPfnCompatible |= 8u;
}
v49 = ProtectionPfnCompatible;
goto LABEL_112;
}
}
else
{
v21 = 1i64;
}
v50 = v55;
if( v55 )
{
v52 = v56;
}
else
{
if( v31 )
v50 = 1i64;
else
v50 = MiIoPagesInRun(v33, v22);
v42 = MiReferenceIoPages(1ui64, v33, v50, v58, 0i64, &v54);
if( v42 < 0 )
goto LABEL_77;
*(_DWORD *)a6 |= 1u;
v52 = v54;
}
v55 = v50 - 1;
v61 = *((_WORD *)v52[2].Children[0]->Children + (v33 & 0xFFFFFFFFFi64) - v52[1].ParentValue);
v56 = v54;
v51 = v61 >> 14;
goto LABEL_107;
}
v36 = (INT64)PfnDb + 48 * v33;
v37 = (UNICODE_STRING *)(v29 & 2);
if( (v29 & 2) != 0 && ((*(_BYTE *)(v36 + 34) & 7) != 5 || !MiIsPfnFileOnly((INT64)PfnDb + 48 * v33)) )
KeBugCheckEx(0x1Au, 0x1160Cui64, v33, 0i64, BugCheckParameter4);
if( !*(_WORD *)(v36 + 32) && (!(_DWORD)v37 || (*(_BYTE *)(v36 + 34) & 7) != 5 || !MiIsPfnFileOnly(v36)) )
MiShowBadMapper(v33, 5ui64);
LOBYTE(v38) = MI_PFN_IS_PROTO((UNICODE_STRING *)v36, v37, v29, v30);
if( v38 )
goto LABEL_89;
v41 = *(_QWORD *)(v36 + 40);
if( (v41 & 0x1000000000i64) == 0 )
break;
LODWORD(v60) = v40;
LODWORD(v53) = v40;
if( (unsigned int)MiGetPfnPageSizeIndexUnsynchronized(v39, &v60, &v53) == 3 || (_DWORD)v60 != 6 )
{
v42 = -1073741800;
LABEL_77:
v43 = (unsigned __int64)MmGetPteBase();
goto LABEL_78;
}
LABEL_89:
v47 = *(_BYTE *)(v36 + 34);
if( (v47 & 0xC0) == 0xC0 )
{
MiAssignInitialPageAttribute(v36, v58);
v47 = *(_BYTE *)(v36 + 34);
}
if( v58 != v47 >> 6 )
{
ProtectionPfnCompatible = MiMakeProtectionPfnCompatible(ProtectionPfnCompatible, (_MMPFN *)v36);
v49 = ProtectionPfnCompatible;
LABEL_112:
ValidPte = MiMakeValidPte(PointerPte, v33, v49 | 0xA0000000);
goto LABEL_113;
}
ValidPte = v57 | ((v33 & 0xFFFFFFFFFi64 | 0xA00000000000i64) << 12);
LABEL_113:
v34 = HIDWORD(v53);
BugCheckParameter4 = 0i64;
v29 = a5;
*(_QWORD *)PointerPte = ValidPte;
v30 = (WCHAR *)((char *)MmGetPfnDb() + 40);
PfnDb = MmGetPfnDb();
LABEL_114:
PointerPte += 8i64;
if( !--v22 )
return 0i64;
}
v43 = (unsigned __int64)MmGetPteBase();
v45 = (__int64)((*(_QWORD *)(v36 + 8) << 25) - (v43 << 25)) >> 16;
if( v45 < v43 )
goto LABEL_89;
if( v45 > (unsigned __int64)MmGetPteLimit() )
goto LABEL_89;
if( (v41 & 0xFFFFFFFFFi64) == 0xFFFFFFFFDi64 )
goto LABEL_89;
v46 = *(_BYTE *)(v36 + 34);
if( (v46 & 0x20) != 0 && (*(_QWORD *)(v36 + 24) & 0x3FFFFFFFFFFFFFFFi64) == 0 && *(_WORD *)(v36 + 32) )
goto LABEL_89;
if( (v46 & 8) != 0 || ((*(_QWORD *)v36 >> 13) & 0x7FFFFFFFFFF0i64 | 0xFFFF800000000000ui64) == 0xFFFF800000000030ui64 )
goto LABEL_89;
v42 = -1073741800;
LABEL_78:
if( (*(_DWORD *)a6 & 1) != 0 )
MiZeroAndFlushPtes(
(__int64)((PointerPte << 25) + ((v22 - NumberOfPages) << 28) - (v43 << 25)) >> 16,
NumberOfPages - v22);
return(unsigned int)v42;
}Referenced by:
MiLockAndMapEntireDriver
MiMapContiguousMemory
MiMapHotPatchImageInSystemSpace
MmMapLockedPagesSpecifyCache
MmMapMdl