VmpFaultEntryInsert

__int64 __fastcall VmpFaultEntryInsert(__int64 a1, _RTL_BALANCED_NODE *a2, unsigned int a3){
  _RTL_BALANCED_NODE *v3; 
  _RTL_BALANCED_NODE *v5; 
  unsigned __int8 CurrentIrql; 
  INT64 *v7; 
  __int64 v8; 
  UINT64 v9; 
  BOOL v10; 
  UINT64 v11; 
  __int64 result; 

  v3 = a2;
  v5 = &a2[2 * a3];
  CurrentIrql = KeGetCurrentIrql();
  __writecr8(0xFui64);
  v7 = (INT64 *)(a1 + 64);
  ExAcquireSpinLockExclusiveAtDpcLevel((INT64 *)(a1 + 64));
  if( v3 < v5 )
  {
    v8 = a1 + 48;
    do
    {
      v9 = *(_QWORD *)v8;
      if( (*(_BYTE *)(v8 + 8) & 1) != 0 && v9 )
        v9 ^= v8;
      v10 = 0;
      if( v9 )
      {
        while( 1 )
        {
          if( ((unsigned __int64)v3[1].Children[0] & 0xFFFFFFFFFFFFFi64) >= (*(_QWORD *)(v9 + 24) & 0xFFFFFFFFFFFFFui64) )
          {
            v11 = *(_QWORD *)(v9 + 8);
            if( (*(_BYTE *)(v8 + 8) & 1) != 0 )
            {
              if( !v11 )
                goto LABEL_18;
              v11 ^= v9;
            }
            if( !v11 )
            {
LABEL_18:
              v10 = 1;
              break;
            }
          }
          else
          {
            v11 = *(_QWORD *)v9;
            if( (*(_BYTE *)(v8 + 8) & 1) != 0 )
            {
              if( !v11 )
                break;
              v11 ^= v9;
            }
            if( !v11 )
              break;
          }
          v9 = v11;
        }
      }
      RtlRbInsertNodeEx((UINT64 *)v8, v9, v10, (UINT64)v3);
      v3 += 2;
    }
    while( v3 < v5 );
  }
  ExReleaseSpinLockExclusiveFromDpcLevel(v7);
  result = CurrentIrql;
  __writecr8(CurrentIrql);
  return result;
}

Referenced by:

VmpAccessFaultBatch