MiInsertPteTracker

VOID __stdcall MiInsertPteTracker(
        _MDL *MemoryDescriptorList,
        _MI_PTE_TRACKER_TYPE Type,
        UINT64 Flags,
        _MI_PFN_CACHE_ATTRIBUTE CacheAttribute){
  char v5; 
  char v6; 
  void *Pool; 
  _QWORD **v9; 
  _QWORD *v10; 
  _QWORD *v11; 
  unsigned __int64 v12; 
  __int64 v13; 
  char *v14; 
  unsigned __int64 v15; 
  __int64 v16; 
  __int64 v17; 
  unsigned __int64 v18; 
  unsigned __int64 MappedSystemVa; 
  __int64 v20; 
  char *v21; 
  __int64 v22; 
  __int64 v23; 
  UINT64 BackTraceHash; 
  _KLOCK_QUEUE_HANDLE LockHandle; 

  LODWORD(BackTraceHash) = 0;
  v5 = CacheAttribute;
  v6 = Flags;
  memset(&LockHandle, 0, sizeof(LockHandle));
  if( *(&stru_140C4DB30 + 1640) < 0xAu )
  {
    Pool = RtlpInterlockedPopEntrySList((PSLIST_HEADER)&stru_140C4DB30 + 205);
    goto LABEL_6;
  }
  RtlpInterlockedFlushSList();
  Pool = v9;
  if( v9 )
  {
    v10 = *v9;
    if( *v9 )
    {
      do
      {
        v11 = (_QWORD *)*v10;
        ExFreePoolWithTag(v10, 0);
        v10 = v11;
      }
      while( v11 );
    }
LABEL_6:
    if( Pool )
      goto LABEL_9;
  }
  Pool = MiAllocatePool(64i64, 0x80ui64, 0x79536D4Dui64);
  if( !Pool )
  {
    *(&stru_140C4DB30 + 3533) = 1;
    return;
  }
LABEL_9:
  if( Type == MiPteTrackerMdl )
  {
    v16 = (LODWORD(MemoryDescriptorList->StartVa) + MemoryDescriptorList->ByteOffset) & 0xFFF;
    v17 = MemoryDescriptorList->ByteCount + 4095i64;
    *((_QWORD *)Pool + 2) = MemoryDescriptorList;
    v15 = v17 + v16;
    *((_QWORD *)Pool + 5) = MemoryDescriptorList->StartVa;
    *((_DWORD *)Pool + 12) = MemoryDescriptorList->ByteOffset;
    *((_DWORD *)Pool + 13) = MemoryDescriptorList->ByteCount;
    goto LABEL_14;
  }
  if( Type == MiPteTrackerContiguous )
  {
    v13 = (LODWORD(MemoryDescriptorList->StartVa) + MemoryDescriptorList->ByteOffset) & 0xFFF;
    v14 = (char *)&MemoryDescriptorList->Process[1].SecurityPort + 7;
    *((_QWORD *)Pool + 2) = 1i64;
    v15 = (unsigned __int64)&v14[v13];
LABEL_14:
    v12 = v15 >> 12;
    goto LABEL_15;
  }
  v12 = (unsigned __int64)MemoryDescriptorList->Process >> 12;
  *((_QWORD *)Pool + 2) = 0i64;
LABEL_15:
  v18 = v12 + 1;
  if( (v6 & 2) == 0 )
    v18 = v12;
  *((_QWORD *)Pool + 3) = v18;
  RtlCaptureStackBackTrace(1ui64, 7ui64, (VOID **)Pool + 9, &BackTraceHash);
  MappedSystemVa = (unsigned __int64)MemoryDescriptorList->MappedSystemVa;
  *((_QWORD *)Pool + 4) = MappedSystemVa;
  *((_QWORD *)Pool + 7) = MemoryDescriptorList[1].Next;
  *((_DWORD *)Pool + 16) = (4 * (v5 & 3)) | v6 & 1 | *((_DWORD *)Pool + 16) & 0xFFFFFFE0 | ((v6 & 2) != 0 ? 0x10 : 0);
  v20 = 40543i64 * (unsigned int)(MappedSystemVa >> 12);
  KeAcquireInStackQueuedSpinLock((PKSPIN_LOCK)&stru_140C4DB30 + 412, &LockHandle);
  v21 = (char *)&stru_140C4DB30 + 16 * (((unsigned __int8)v20 ^ BYTE4(v20)) & 0xF) + 6720;
  v22 = *(_QWORD *)v21;
  if( *(char **)(*(_QWORD *)v21 + 8i64) != v21 )
    __fastfail(3u);
  *((_QWORD *)Pool + 1) = v21;
  *(_QWORD *)Pool = v22;
  *(_QWORD *)(v22 + 8) = Pool;
  *(_QWORD *)v21 = Pool;
  *(&stru_140C4DB30 + 872) += v18;
  v23 = ++*(&stru_140C4DB30 + 873);
  if( *(&stru_140C4DB30 + 873) > *(&stru_140C4DB30 + 874) )
    *(&stru_140C4DB30 + 874) = v23;
  KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
  __writecr8(LockHandle.OldIrql);
}

Referenced by:

MiMapContiguousMemory
MmAllocateMappingAddressEx
MmMapLockedPagesSpecifyCache
MmMapMdl