MiTimeSingleLargePageZeroWorker

UINT64 __fastcall MiTimeSingleLargePageZeroWorker(INT64 rcx0, UINT64 a2){
  __int64 v2; 
  unsigned int v3; 
  signed __int32 v4; 
  unsigned int v5; 
  unsigned int v7; 
  unsigned __int8 CurrentIrql; 
  INT64 v9; 
  INT64 LargePagesDemoteAsNeeded; 
  __int64 v11; 
  int ProtectionPfnCompatible; 
  UINT64 *v13; 
  UINT64 ValidPte; 
  unsigned __int64 v15; 
  __int64 v16; 
  __int64 v17; 
  unsigned __int64 v18; 
  unsigned int i; 
  __int64 v20; 
  unsigned __int64 v21; 
  unsigned __int64 v22; 
  unsigned __int64 v23; 
  unsigned __int64 v24; 
  unsigned __int64 v25; 
  unsigned __int64 v26; 
  unsigned __int64 v27; 
  __int64 *v28; 
  signed __int32 v29[8]; 
  INT64 v30; 
  INT64 v31; 
  INT64 v32; 
  INT64 v33; 
  BOOL v34; 
  char SpinCount[20]; 
  __int64 v36; 
  INT64 v37[2]; 
  PVOID PageBase; 
  unsigned __int64 v39; 
  INT64 v40; 
  unsigned __int64 v41; 
  _DWORD a1[4]; 
  INT64 result[4]; 
  unsigned __int64 v44[12]; 
  __int64 v45[16]; 
  v40 = rcx0;
  v36 = 0i64;
  v2 = rcx0;
  v3 = a2;
  *(_OWORD *)a1 = 0i64;
  *(_OWORD *)&SpinCount[4] = 0i64;
  *(_OWORD *)v37 = 0i64;
  MiInitializeColorTable(a1, a2);
  MiInitializePageColorBase(0i64, v3 + 1, (INT64)v37);
  v4 = _InterlockedExchangeAdd((volatile signed __int32 *)v37[0], 1u);
  v5 = v37[1] & v4 | HIDWORD(v37[1]);
  memset((INT64)result, 0i64);
  if( !(unsigned int)MiCreateUltraThreadContext((INT64)result, v5, 2i64) )
    return 0i64;
  memset((INT64)v45, 0i64);
  v7 = 0;
  while( 1 )
  {
    CurrentIrql = KeGetCurrentIrql();
    __writecr8(2ui64);
    v41 = __rdtsc();
    _InterlockedOr(v29, 0);
    LODWORD(v33) = 2;
    LODWORD(v31) = 1;
    LODWORD(v30) = 4;
    v9 = MiUnlinkNodeLargePages(v2, 1ui64, 1i64, v3, v30, v31, (INT64)a1, v33, 0i64);
    if( v9 )
    {
      v11 = (v9 - (__int64)MmGetPfnDb()) / 48;
      v39 = v11;
      ProtectionPfnCompatible = MiMakeProtectionPfnCompatible(4ui64, (_MMPFN *)v9);
      PageBase = (PVOID)MiGetUltraMapping(v44, 1u, 512i64, 0);
      v13 = (UINT64 *)((char *)MmGetPdeBase() + (((unsigned __int64)PageBase >> 18) & 0x3FFFFFF8));
      ValidPte = MiMakeValidPte((UINT64)v13, v11, ProtectionPfnCompatible | 0xA4000000);
      v34 = MiPteInShadowRange((UINT64)v13);
      if( v34 && (*(_DWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 2172i64) & 0x1000) != 0 && (ValidPte & 1) != 0 )
        ValidPte |= 0x8000000000000000ui64;
      *v13 = ValidPte;
      KeZeroPages(PageBase, 0x200000ui64);
      v15 = ZeroPte;
      if( v34 && (*(_DWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 2172i64) & 0x1000) != 0 && (ZeroPte & 1) != 0 )
        v15 = ZeroPte | 0x8000000000000000ui64;
      *v13 = v15;
      *(_DWORD *)SpinCount = 0;
      while( _interlockedbittestandset64((volatile signed __int32 *)(v9 + 24), 0x3Fui64) )
      {
        do
          KeYieldProcessorEx((UINT64 *)SpinCount);
        while( *(__int64 *)(v9 + 24) < 0 );
      }
      v36 = 2i64;
      *(_OWORD *)&SpinCount[4] = v39;
      MiInsertLargePageInNodeList((INT64)&SpinCount[4]);
      v2 = v40;
    }
    else
    {
      __writecr8(CurrentIrql);
      LODWORD(v32) = 1;
      LODWORD(v31) = 2;
      LODWORD(v30) = 0;
      LargePagesDemoteAsNeeded = MiGetLargePagesDemoteAsNeeded(v2, v3, 0x200ui64, 0x200ui64, v30, v31, v32);
      v9 = LargePagesDemoteAsNeeded;
      if( LargePagesDemoteAsNeeded )
      {
        MiFreeLargePageChain(LargePagesDemoteAsNeeded);
        --v7;
        goto LABEL_28;
      }
    }
    _InterlockedOr(v29, 0);
    v16 = __rdtsc() - v41;
    __writecr8(CurrentIrql);
    if( !v9 )
      break;
    v45[v7] = v16;
    if( v7 >= 2 )
    {
      v17 = v7 - 2;
      v18 = 0i64;
      for( i = v17; i <= v7; v18 += v45[v20] )
        v20 = i++;
      v21 = v18 / 3;
      v22 = v18 / 3 / 0xA;
      v23 = v18 / 3 - v22;
      v24 = v22 + v21;
      if( (unsigned int)v17 > v7 )
        goto LABEL_31;
      do
      {
        v25 = v45[v17];
        if( v25 < v23 )
          break;
        if( v25 > v24 )
          break;
        v17 = (unsigned int)(v17 + 1);
      }
      while( (unsigned int)v17 <= v7 );
      if( (unsigned int)v17 > v7 )
        goto LABEL_31;
    }
LABEL_28:
    if( ++v7 >= 0x10 )
    {
      v21 = 0i64;
      goto LABEL_32;
    }
  }
  memset((INT64)v45, 0i64);
  v21 = 0i64;
LABEL_31:
  if( v21 )
    goto LABEL_37;
LABEL_32:
  v26 = 0i64;
  v27 = 0i64;
  v28 = v45;
  do
  {
    if( !*v28 )
      break;
    v26 += *v28;
    v27 = (unsigned int)(v27 + 1);
    ++v28;
  }
  while( (unsigned int)v27 < 0x10 );
  if( (_DWORD)v27 )
    v21 = v26 / v27;
LABEL_37:
  MiDeleteUltraThreadContext((INT64)result);
  return v21;
}

Referenced by:

MiTimeSingleLargePageZero