MiObtainReferencedSecureVad
_MMVAD_SHORT *__fastcall MiObtainReferencedSecureVad(PVOID BugCheckParameter3, INT64 *a2){
_ETHREAD *CurrentThread;
_EPROCESS *Process;
unsigned __int64 v6;
_MMVAD *Address;
_MMVAD_SHORT *p_Core;
unsigned __int64 v9;
int v11;
*(_DWORD *)a2 = 0;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
Process = CurrentThread->Tcb.ApcState.Process;
--CurrentThread->Tcb.SpecialApcDisable;
ExAcquirePushLockSharedEx(&Process->AddressCreationLock, 0i64);
CurrentThread->$84F33738BEE95ACDF5C5BF1C8FDC7C8C::_bf_0 |= 2u;
if( (Process->Flags & 0x20) != 0 )
{
UNLOCK_ADDRESS_SPACE_SHARED(CurrentThread, Process);
*(_DWORD *)a2 = -1073741558;
return 0i64;
}
else
{
v6 = *((_QWORD *)BugCheckParameter3 + 1);
Address = MiLocateAddress((VOID *)v6);
p_Core = &Address->Core;
if( !Address )
KeBugCheckEx(0x1Au, (PVOID)0x15000, (PVOID)v6, BugCheckParameter3, 0i64);
if( !_InterlockedIncrement(&Address->Core.ReferenceCount) )
__fastfail(0xEu);
--CurrentThread->Tcb.SpecialApcDisable;
UNLOCK_ADDRESS_SPACE_SHARED(CurrentThread, Process);
v9 = v6 >> 12;
--CurrentThread->Tcb.SpecialApcDisable;
ExAcquirePushLockExclusiveEx(&p_Core->PushLock, 0i64);
CurrentThread->$84F33738BEE95ACDF5C5BF1C8FDC7C8C::_bf_0 |= 0x80u;
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
if( (p_Core->u.LongFlags & 4) != 0 )
{
MiWaitForVadDeletion(p_Core);
MiUnlockAndDereferenceVad(p_Core);
v11 = -1073741558;
if( (Process->Flags & 0x20) == 0 )
v11 = -1073741664;
*(_DWORD *)a2 = v11;
}
else
{
if( v9 >= (p_Core->StartingVpn | ((unsigned __int64)p_Core->StartingVpnHigh << 32))
&& v9 <= (p_Core->EndingVpn | ((unsigned __int64)p_Core->EndingVpnHigh << 32)) )
{
return p_Core;
}
MiUnlockAndDereferenceVad(p_Core);
*(_DWORD *)a2 = -1073741664;
}
return 0i64;
}
}Referenced by:
MiPerformImageHotPatch
MmStoreAllocateVirtualMemory
MmUnsecureVirtualMemory