MiAllocateNewSubAllocatedRegion
NTSTATUS __stdcall MiAllocateNewSubAllocatedRegion(INT64 a1, UINT64 a2){
int v2;
UINT64 v3;
_EPROCESS *Process;
_MMVAD_SHORT *Pool;
_MMVAD_SHORT *v6;
INT64 v7;
unsigned int v8;
UINT64 v9;
__int64 ********v10;
UINT64 v11;
UINT64 ProtectionMask;
UINT64 v13;
int VadEventBitmap;
int v15;
unsigned int v16;
__int64 ******v17;
_DWORD *v18;
_EPROCESS *v19;
__int64 *******v20;
__int64 ******v21;
UINT64 *HINTHonored;
PVOID *StartingAddress;
UINT64 v25;
_ETHREAD *Thread;
_MMWSL_INSTANCE *VmWorkingSetList;
int v28;
UINT64 v29;
__int64 ********v30;
v28 = a1;
v2 = a1;
Thread = (_ETHREAD *)KeGetCurrentThread();
v3 = 512i64;
Process = Thread->Tcb.ApcState.Process;
VmWorkingSetList = Process->Vm.Instance.VmWorkingSetList;
if( a2 <= 0x10 )
{
Pool = (_MMVAD_SHORT *)MiAllocatePool(64i64, 0x40ui64, 0x53646156ui64);
v6 = Pool;
if( Pool )
{
v7 = 32i64;
v8 = Pool->u.LongFlags & 0xFFFFF27F;
Pool->VadNode.ParentValue = -2i64;
Pool->PushLock._bf_0 = 0i64;
Pool->u.LongFlags = v8 | 0x100200;
if( v2 != 1 )
v7 = 0i64;
LODWORD(v9) = MiGetUserReservationHighestAddress((INT64)Process, v7);
v10 = 0i64;
v11 = v9;
ProtectionMask = 0x200000i64;
do
{
LODWORD(StartingAddress) = 0x80000000;
LODWORD(HINTHonored) = (v6->u.LongFlags >> 7) & 0x1F;
v13 = v3 << 12;
v25 = v3;
v29 = ProtectionMask;
VadEventBitmap = MiSelectUserAddress(
0i64,
0i64,
v11,
v3 << 12,
ProtectionMask,
0i64,
HINTHonored,
StartingAddress);
if( VadEventBitmap >= 0 )
break;
if( ProtectionMask != 0x10000 )
ProtectionMask = 0x10000i64;
v3 >>= 1;
if( v29 != 0x10000 )
v3 = v25;
}
while( v3 >= 0x10 );
if( v3 >= 0x10 )
{
v6->StartingVpnHigh = 0;
v6->EndingVpnHigh = (v13 - 1) >> 44;
v6->StartingVpn = 0;
v6->EndingVpn = (v13 - 1) >> 12;
VadEventBitmap = MiCreateVadEventBitmap(Process, v6, v3, 0x40ui64);
if( VadEventBitmap < 0 )
{
LABEL_28:
ExFreePoolWithTag(v6, 0);
return VadEventBitmap;
}
v30 = MiLocateVadEvent((__int64)v6, 64) + 1;
v16 = ExGenRandom((_EX_GEN_RANDOM_DOMAIN)(v15 - 63));
v17 = (__int64 ******)(v30 + 2);
v30[4] = (__int64 *******)v6;
v30[2] = 0i64;
*((_DWORD *)v30 + 12) = v28 & 3 ^ (4 * (v16 % v3));
v30[3] = 0i64;
*((_DWORD *)v30 + 10) = 0;
*((_DWORD *)v30 + 11) = v3;
v18 = MiAddSecureEntry((_MI_PARTITION *)v6, 0i64, v13 - 1, -2147483647, 0);
if( v18 )
{
VadEventBitmap = MiInsertVadCharges(v6, (ULONG_PTR)Process);
if( VadEventBitmap >= 0 )
{
MiLockVad(Thread, v6);
MiInsertPrivateVad(v6, (_MI_PHYSICAL_VIEW *)Process, v19);
MiUnlockVad(Thread, v6);
LOCK_PAGE_TABLE_COMMITMENT(Thread, Process);
v20 = (__int64 *******)((char *)&VmWorkingSetList[8] + 16 * v28);
v21 = *v20;
if( (*v20)[1] != (__int64 *****)v20 )
__fastfail(3u);
*v17 = (__int64 *****)v21;
v30[3] = v20;
v21[1] = (__int64 *****)v17;
*v20 = v17;
UNLOCK_PAGE_TABLE_COMMITMENT(Thread, Process);
v10 = v30;
LABEL_13:
if( VadEventBitmap >= 0 )
return VadEventBitmap;
goto LABEL_24;
}
}
else
{
VadEventBitmap = -1073741670;
}
v10 = v30;
LABEL_24:
if( v10 )
MiFreeVadEventBitmap((ULONG_PTR)Process, v6, 0x40ui64);
if( v18 )
ExFreePoolWithTag(v18, 0);
goto LABEL_28;
}
v18 = 0i64;
goto LABEL_13;
}
}
return -1073741801;
}Referenced by:
MiAllocateFromSubAllocatedRegion