MiMapLockedPagesInUserSpace

VOID *__stdcall MiMapLockedPagesInUserSpace(
        _MDL *MemoryDescriptorList,
        VOID *StartingVa,
        _MEMORY_CACHING_TYPE CacheType,
        VOID *BaseVa,
        UINT64 Priority){
  UINT64 *v6; 
  unsigned __int64 v7; 
  _MMVAD *Pool; 
  _MMVAD *v9; 
  _MDL *v10; 
  _EPROCESS *Process; 
  UINT64 v12; 
  UINT64 v13; 
  unsigned __int64 v14; 
  NTSTATUS v15; 
  char *v16; 
  NTSTATUS inserted; 
  char *v18; 
  UINT64 *p_Size; 
  UINT64 v20; 
  int v21; 
  _MMPFN *v22; 
  _EPROCESS *v23; 
  int v24; 
  __int64 v26; 
  _RTL_BALANCED_NODE **v27; 
  int v28; 
  unsigned __int64 v29; 
  unsigned __int64 v30; 
  _MMPFN *PfnDb; 
  UINT64 v32; 
  int v33; 
  UINT64 *HINTHonored; 
  PVOID *StartingAddress; 
  _EPROCESS *CurrentProcess; 
  _MDL *v37; 
  _ETHREAD *Thread; 
  unsigned __int64 v39; 
  _MMVAD *v40; 
  char *Vaa; 

  if( ((unsigned __int16)BaseVa & 0xFFF) != 0 )
    RtlRaiseStatus(-1073741503);
  v6 = (UINT64 *)&MemoryDescriptorList[1];
  v37 = MemoryDescriptorList + 1;
  v7 = (((unsigned __int16)StartingVa & 0xFFF) + 4095i64 + (unsigned __int64)MemoryDescriptorList->ByteCount) >> 12;
  Pool = (_MMVAD *)MiAllocatePool(64i64, 0x40ui64, 0x6C646156ui64);
  v40 = Pool;
  v9 = Pool;
  if( !Pool )
    RtlRaiseStatus(-1073741670);
  Pool->Core.PushLock._bf_0 = 0i64;
  v10 = 0i64;
  Pool->Core.VadNode.ParentValue = -2i64;
  Pool->Core.u.LongFlags = Pool->Core.u.LongFlags & 0xFFFFF01F | ((((((int)Priority >> 31) & 0xFD) + 4) & 0x1F) << 7) | 0x8100010;
  Thread = (_ETHREAD *)KeGetCurrentThread();
  Process = Thread->Tcb.ApcState.Process;
  CurrentProcess = Process;
  LOCK_ADDRESS_SPACE(Thread, Process);
  if( (Process->Flags & 0x20) != 0 )
  {
    inserted = -1073741558;
    goto LABEL_20;
  }
  LODWORD(v12) = MiGetUserReservationHighestAddress((INT64)Process, 0i64);
  v14 = (unsigned __int64)BaseVa;
  if( !BaseVa )
  {
    LODWORD(StartingAddress) = 0;
    LODWORD(HINTHonored) = (((int)Priority >> 31) & 0xFFFFFFFD) + 4;
    v15 = MiSelectUserAddress(0i64, v13, v12, v7 << 12, 0x10000ui64, 0i64, HINTHonored, StartingAddress);
    v16 = 0i64;
    inserted = v15;
    if( v15 >= 0 )
    {
      v14 = (unsigned __int64)BaseVa;
      goto LABEL_7;
    }
LABEL_20:
    v23 = CurrentProcess;
    goto LABEL_27;
  }
  MiIsVaRangeAvailable(Process, BaseVa, v7 << 12, 0i64);
  if( !v28 )
  {
    inserted = -1073741800;
    goto LABEL_20;
  }
LABEL_7:
  Vaa = v16;
  v18 = v16;
  v9->Core.StartingVpn = v14 >> 12;
  v9->Core.StartingVpnHigh = v14 >> 44;
  v39 = v14 + (v7 << 12) - 1;
  v9->Core.EndingVpn = v39 >> 12;
  v9->Core.EndingVpnHigh = v39 >> 12 >> 32;
  if( v7 )
  {
    p_Size = v6;
    do
    {
      v20 = *p_Size;
      MiIsPfn(*p_Size);
      if( v21 )
      {
        v22 = &MmGetPfnDb()[v20];
        inserted = MiLegitimatePageForDriversToMap((INT64)v22);
        if( inserted < 0 || !MiDoubleLockMdlPage(v22) )
          goto LABEL_20;
        v18 = Vaa;
      }
      else
      {
        LODWORD(v26) = MiSanitizePage(v20);
        inserted = MiReferenceIoPages(1u, v26, 1i64, CacheType, v27, v27);
        if( inserted < 0 )
          goto LABEL_20;
      }
      ++v18;
      v10 = v37;
      Vaa = v18;
      p_Size = (UINT64 *)&v37->Size;
      v37 = (_MDL *)((char *)v37 + 8);
    }
    while( (unsigned __int64)v18 < v7 );
  }
  v23 = CurrentProcess;
  inserted = MiInsertVadCharges(&v9->Core, (ULONG_PTR)CurrentProcess);
  if( inserted < 0 )
  {
LABEL_27:
    UNLOCK_ADDRESS_SPACE(Thread, v23);
    if( v10 )
    {
      v29 = 1i64;
      v30 = (unsigned __int64)((char *)v10 - (char *)v6 + 8) >> 3;
      if( v6 > (UINT64 *)v10 )
        v30 = 0i64;
      if( v30 )
      {
        PfnDb = MmGetPfnDb();
        do
        {
          v32 = *v6;
          MiIsPfn(*v6);
          if( v33 )
            MiDoubleUnlockMdlPage(&PfnDb[v32]);
          else
            MiDereferenceIoPages(1i64, v32, 1i64);
          ++v6;
          ++v29;
        }
        while( v29 <= v30 );
        v9 = v40;
      }
    }
    ExFreePoolWithTag(v9, 0);
    RtlRaiseStatus(inserted);
  }
  MiLockVad(Thread, &v9->Core);
  LODWORD(HINTHonored) = Priority;
  MiMapLockedPagesInUserSpaceHelper((VOID *)v14, v6, 0i64, CacheType, v7, v9, (UINT64)HINTHonored);
  UNLOCK_ADDRESS_SPACE_UNORDERED(Thread, CurrentProcess);
  MiReferenceVad(&v9->Core);
  v24 = 2;
  if( (((int)Priority >> 31) & 0xFFFFFFFD) != -3 )
    v24 = 4;
  if( !MiAddSecureEntry((_MI_PARTITION *)v9, v14, v39, v24, 0) )
  {
    MiDeleteVad(v9, 0i64);
    RtlRaiseStatus(-1073741670);
  }
  MiUnlockAndDereferenceVad(&v9->Core);
  return(VOID *)(v14 + MemoryDescriptorList->ByteOffset);
}

Referenced by:

MmMapLockedPagesSpecifyCache