VmpFaultEntryInsert
__int64 __fastcall VmpFaultEntryInsert(__int64 a1, _RTL_BALANCED_NODE *a2, unsigned int a3){
_RTL_BALANCED_NODE *v3;
_RTL_BALANCED_NODE *v5;
unsigned __int8 CurrentIrql;
INT64 *v7;
__int64 v8;
UINT64 v9;
BOOL v10;
UINT64 v11;
__int64 result;
v3 = a2;
v5 = &a2[2 * a3];
CurrentIrql = KeGetCurrentIrql();
__writecr8(0xFui64);
v7 = (INT64 *)(a1 + 64);
ExAcquireSpinLockExclusiveAtDpcLevel((INT64 *)(a1 + 64));
if( v3 < v5 )
{
v8 = a1 + 48;
do
{
v9 = *(_QWORD *)v8;
if( (*(_BYTE *)(v8 + 8) & 1) != 0 && v9 )
v9 ^= v8;
v10 = 0;
if( v9 )
{
while( 1 )
{
if( ((unsigned __int64)v3[1].Children[0] & 0xFFFFFFFFFFFFFi64) >= (*(_QWORD *)(v9 + 24) & 0xFFFFFFFFFFFFFui64) )
{
v11 = *(_QWORD *)(v9 + 8);
if( (*(_BYTE *)(v8 + 8) & 1) != 0 )
{
if( !v11 )
goto LABEL_18;
v11 ^= v9;
}
if( !v11 )
{
LABEL_18:
v10 = 1;
break;
}
}
else
{
v11 = *(_QWORD *)v9;
if( (*(_BYTE *)(v8 + 8) & 1) != 0 )
{
if( !v11 )
break;
v11 ^= v9;
}
if( !v11 )
break;
}
v9 = v11;
}
}
RtlRbInsertNodeEx((UINT64 *)v8, v9, v10, (UINT64)v3);
v3 += 2;
}
while( v3 < v5 );
}
ExReleaseSpinLockExclusiveFromDpcLevel(v7);
result = CurrentIrql;
__writecr8(CurrentIrql);
return result;
}Referenced by:
VmpAccessFaultBatch