MiExtendSection

__int64 MiExtendSection(__int64 a1, _QWORD *a2, unsigned int a3, __int64 a4, ...){
  INT64 v4; 
  INT64 *v5; 
  unsigned __int64 v7; 
  unsigned int v8; 
  __int128 v9; 
  int v10; 
  __int128 v11; 
  __int128 v12; 
  unsigned __int64 v13; 
  unsigned __int64 v14; 
  UINT64 v15; 
  __int128 v16; 
  int v17; 
  __int128 v18; 
  __int128 v19; 
  __int128 v20; 
  unsigned __int64 v21; 
  unsigned int v22; 
  INT64 v23; 
  INT64 v24; 
  unsigned int v25; 
  __int64 v26; 
  __int16 v27; 
  unsigned int v28; 
  __int64 v29; 
  unsigned __int64 v30; 
  __int64 v31; 
  int appended; 
  __int16 v33; 
  unsigned __int64 v34; 
  ULONG_PTR v36; 
  ULONG_PTR v37; 
  unsigned __int64 v38; 
  unsigned __int64 v39; 
  unsigned __int64 v40; 
  unsigned int v41; 
  unsigned __int64 v42; 
  unsigned __int64 v43; 
  ULONG_PTR v44; 
  __int64 v45; 
  int v46; 
  __int64 v47; 
  NTSTATUS SubsectionCharges; 
  _MI_PARTITION *ControlAreaPartition; 
  volatile INT64 *v50; 
  ULONG_PTR v51; 
  INT64 v52; 
  unsigned __int64 v53; 
  unsigned __int64 v54; 
  __int64 v55; 
  INT64 v56[2]; 
  __int128 Privileges; 
  __int128 v58; 
  __int128 v59; 
  __int128 v60; 
  __int128 v61; 
  __int128 v62; 
  __int128 v63; 
  __int128 v64; 
  int v65; 
  _MI_PARTITION *v69; 
  UINT64 DanglingPageCount; 
  va_list DanglingPageCounta; 
  va_list va1; 
  va_start(va1, a4);
  va_start(DanglingPageCounta, a4);
  DanglingPageCount = va_arg(va1, _QWORD);
  v5 = v56;
  v52 = *(_QWORD *)a1;
  v4 = *(_QWORD *)a1;
  v7 = (8 * a4 + 4095) & 0xFFFFFFFFFFFFF000ui64;
  v8 = a3;
  *(_QWORD *)DanglingPageCount = 0i64;
  v55 = *(_QWORD *)v4;
  v9 = *(_OWORD *)(a1 + 16);
  v10 = *(_DWORD *)(v4 + 56);
  *(_OWORD *)v56 = *(_OWORD *)a1;
  v53 = v7;
  v11 = *(_OWORD *)(a1 + 32);
  Privileges = v9;
  v12 = *(_OWORD *)(a1 + 48);
  v13 = 0i64;
  v58 = v11;
  v14 = (-(__int64)((v10 & 0x40000000) != 0) & 0x100000) + 0x100000;
  v15 = 0i64;
  v16 = *(_OWORD *)(a1 + 64);
  v17 = 0;
  v54 = v14;
  v59 = v12;
  v18 = *(_OWORD *)(a1 + 80);
  v60 = v16;
  v19 = *(_OWORD *)(a1 + 96);
  v61 = v18;
  v20 = *(_OWORD *)(a1 + 128);
  v62 = v19;
  v63 = *(_OWORD *)(a1 + 112);
  v64 = v20;
  if( a3 )
    DWORD1(v59) ^= (DWORD1(v59) ^ (DWORD1(v59) - a3)) & 0x3FFFFFFF;
  v21 = 0i64;
  do
  {
    if( v7 - v13 > v14 )
      v22 = v14;
    else
      v22 = v7 - v13;
    LODWORD(v23) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
    v24 = v23;
    if( !v23 )
    {
      v36 = Privileges;
LABEL_49:
      SubsectionCharges = -1073741670;
      goto LABEL_50;
    }
    v25 = v22 >> 3;
    *(_QWORD *)(v23 + 88) = v23 + 80;
    *(_QWORD *)(v23 + 80) = v23 + 80;
    v5[2] = v23;
    *(_QWORD *)v23 = v52;
    *(_DWORD *)(v23 + 44) = v22 >> 3;
    v13 += v22;
    if( v13 > 8 * a4 )
      *(_DWORD *)(v23 + 52) ^= (*(_DWORD *)(v23 + 52) ^ ((v13 >> 3) - a4)) & 0x3FFFFFFF;
    v26 = v55;
    v27 = *(_WORD *)(v23 + 32) & 0xFFC1 | (2 * ((*(_BYTE *)(v55 + 14) >> 1) & 0x1F));
    *(_WORD *)(v23 + 32) = v27;
    if( v5 == v56 )
    {
      *((_WORD *)v5 + 17) &= 0xFu;
      v28 = *((_DWORD *)v5 + 11);
      v29 = *((unsigned int *)v5 + 9);
      v30 = (unsigned __int64)((_WORD)v5[4] & 0xFFC0) << 26;
      *((_DWORD *)v5 + 10) = v28;
      v21 = v29 | v30;
      v27 = *(_WORD *)(v24 + 32);
    }
    else
    {
      v28 = *((_DWORD *)v5 + 10);
    }
    v31 = v28;
    v7 = v53;
    v21 += v31;
    *(_DWORD *)(v24 + 36) = v21;
    *(_WORD *)(v24 + 32) = v27 & 0x3F | (WORD2(v21) << 6);
    if( v13 < v53 )
    {
      *(_DWORD *)(v24 + 40) = v25;
    }
    else
    {
      *(_DWORD *)(v24 + 40) = (*a2 >> 12) - v21;
      *(_WORD *)(v24 + 34) = *(_WORD *)(v24 + 34) & 0xF | (16 * *(_WORD *)a2);
    }
    v5 = (INT64 *)v24;
    v14 = v54;
  }
  while( v13 < v53 );
  if( v8 && MiControlAreaUsingExtents(v52) && *(_QWORD *)(a1 + 8) )
  {
    MiSubsectionNeedsExtents((_DWORD *)a1);
    *(_QWORD *)DanglingPageCount = a1;
  }
  appended = MiAppendSubsectionChain(a1, (INT64)v56, 0);
  if( !appended )
  {
LABEL_16:
    v33 = *(_WORD *)(v26 + 12);
    v34 = (*(unsigned int *)(v26 + 8) | ((unsigned __int64)(v33 & 0x3FF) << 32)) + a4 + v8;
    *(_DWORD *)(v26 + 8) += a4 + v8;
    *(_WORD *)(v26 + 12) = v33 ^ (v33 ^ WORD2(v34)) & 0x3FF;
    return 0i64;
  }
  v36 = Privileges;
LABEL_18:
  v37 = v36;
  if( (appended & 1) != 0 )
  {
    v38 = v53;
    v65 = v17 | 1;
    v39 = 0i64;
    while( 1 )
    {
      v40 = v38;
      v41 = v54;
      v42 = v40 - v39;
      if( v42 <= v54 )
        v41 = v42;
      v43 = v41;
      v39 += v41;
      LODWORD(v44) = MiAllocatePool((struct _SLIST_ENTRY *)0x112);
      v45 = v44;
      if( !v44 )
        break;
      v46 = *(_DWORD *)(v52 + 56) & 0x40000000;
      MiInitializePrototypePtes(v44, v43 >> 3, (unsigned __int16 *)v37, v46 == 0);
      if( v46 )
      {
        if( !*(_QWORD *)DanglingPageCount )
          *(_QWORD *)DanglingPageCount = v37;
      }
      else if( (v65 & 2) != 0 )
      {
        MiDecrementSubsectionViewCount((INT64 *)v37, 0);
      }
      MiSetSubsectionBase(v37, v45, 0xFFFFFFFF);
      MiUpdateSystemProtoPtesTree((RTL_BALANCED_NODE *)(v37 + 112), 1i64);
      v38 = v53;
      v37 = *(_QWORD *)(v37 + 16);
      if( v39 >= v53 )
      {
        v17 = v65;
        v8 = a3;
        goto LABEL_28;
      }
    }
    LOBYTE(v17) = v65;
    goto LABEL_49;
  }
  v17 |= 2u;
  while( 1 )
  {
    v47 = *(_DWORD *)(v37 + 44) - (*(_DWORD *)(v37 + 52) & 0x3FFFFFFFu);
    SubsectionCharges = MiGetSubsectionCharges(v37);
    if( SubsectionCharges < 0 )
      break;
    if( (int)MiIncrementSubsectionViewCount((INT64 *)v37, 56) <= 1 )
    {
      v15 += v47;
      break;
    }
    v37 = *(_QWORD *)(v37 + 16);
    if( !v37 )
    {
      if( v8 )
      {
        SubsectionCharges = MiGetSubsectionCharges(a1);
        if( SubsectionCharges < 0 )
          break;
        v15 += v8;
      }
LABEL_28:
      appended = MiAppendSubsectionChain(a1, (INT64)v56, v17);
      if( appended )
        goto LABEL_18;
      v26 = v55;
      goto LABEL_16;
    }
  }
LABEL_50:
  ControlAreaPartition = MiGetControlAreaPartition((_CONTROL_AREA *)v52);
  v69 = ControlAreaPartition;
  v50 = (volatile INT64 *)ControlAreaPartition;
  if( v15 )
  {
    MiReturnCrossPartitionSectionCharges((volatile INT64 *)ControlAreaPartition, 1i64, v15);
    v15 = 0i64;
  }
  if( v36 )
  {
    do
    {
      v51 = *(_QWORD *)(v36 + 16);
      if( (*(_DWORD *)(v52 + 56) & 0x40000000) != 0 )
      {
        if( *(_QWORD *)(v36 + 8) )
        {
          DanglingPageCount = 0i64;
          MiDeleteSubsectionPages((_SUBSECTION *)v36, (UINT64 *)DanglingPageCounta);
        }
      }
      else
      {
        if( (v17 & 2) != 0 && (*(_DWORD *)(v36 + 48) & 0x3FFFFFFF) != 0 )
          v15 += MiDecrementSubsectionViewCount((INT64 *)v36, 24);
        if( *(_QWORD *)(v36 + 8) )
        {
          MiUpdateSystemProtoPtesTree((RTL_BALANCED_NODE *)(v36 + 112), 0i64);
          ExFreePoolWithTag(*(PVOID *)(v36 + 8), 0);
        }
      }
      CmSiFreeMemory((PPRIVILEGE_SET)v36);
      v36 = v51;
    }
    while( v51 );
    v50 = (volatile INT64 *)v69;
  }
  if( v15 )
    MiReturnCrossPartitionSectionCharges(v50, 1i64, v15);
  return(unsigned int)SubsectionCharges;
}

Referenced by:

MmExtendSection