ExGetSessionBigPoolInformation

NTSTATUS __stdcall ExGetSessionBigPoolInformation(
        VOID *SystemInformation,
        UINT64 SystemInformationLength,
        UINT64 *Length,
        UINT64 *SessionId){
  UINT64 *v4; 
  __int64 v5; 
  unsigned int v6; 
  NTSTATUS v7; 
  _QWORD *v8; 
  NTSTATUS result; 
  _EPROCESS *NextSession; 
  __int64 v11; 
  NTSTATUS v12; 
  int v13; 
  void *v14; 
  UINT64 v15; 
  NTSTATUS BigPoolInfo; 
  int v17; 
  char ReturnLength[12]; 
  UINT64 *v19; 
  unsigned int v20; 
  UINT64 *v21; 
  VOID *LockVariable; 
  _KAPC_STATE ApcState; 

  v21 = SessionId;
  v19 = Length;
  v20 = SystemInformationLength;
  v4 = Length;
  v5 = 0i64;
  LockVariable = 0i64;
  v17 = 1;
  v6 = 0;
  memset(ReturnLength, 0, sizeof(ReturnLength));
  v7 = 0;
  *(_DWORD *)Length = 0;
  v8 = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  if( (_DWORD)SystemInformationLength )
  {
    result = ExLockUserBuffer(
               SystemInformation,
               SystemInformationLength,
               KeGetCurrentThread()->PreviousMode,
               IoWriteAccess,
               (VOID **)&ReturnLength[4],
               &LockVariable);
    if( result < 0 )
      return result;
    v5 = *(_QWORD *)&ReturnLength[4];
  }
  NextSession = (_EPROCESS *)MmGetNextSession(0i64);
  if( !NextSession )
    goto LABEL_29;
  while( 1 )
  {
    v11 = v6 + v5;
    v12 = MmGetSessionId(NextSession);
    *(_DWORD *)&ReturnLength[4] = v12;
    if( *(_DWORD *)v21 == -1 || v12 == *(_DWORD *)v21 )
      break;
LABEL_20:
    NextSession = (_EPROCESS *)MmGetNextSession(NextSession);
    if( !NextSession )
      goto LABEL_24;
  }
  if( MmAttachSession(NextSession, &ApcState) < 0 )
  {
LABEL_19:
    if( *(_DWORD *)v21 != -1 )
      goto LABEL_23;
    goto LABEL_20;
  }
  if( v6 >= 0xFFFFFFD8 )
  {
    v7 = -1073741675;
    MmDetachSession(NextSession, &ApcState);
    HalPutDmaAdapter((PADAPTER_OBJECT)NextSession);
    goto LABEL_28;
  }
  if( (unsigned __int64)v6 + 40 <= v20 && (v13 = v17) != 0 )
  {
    v14 = (void *)(v6 + v5);
    v15 = v20 - v6;
  }
  else
  {
    v13 = 0;
    v14 = 0i64;
    v17 = 0;
    v15 = 0i64;
    v7 = -1073741820;
  }
  BigPoolInfo = ExGetBigPoolInfo(v14, v15, 0i64, (UINT64 *)ReturnLength);
  if( BigPoolInfo >= 0 || (v7 = BigPoolInfo, BigPoolInfo == -1073741820) )
  {
    if( v13 == 1 && BigPoolInfo >= 0 )
    {
      v8 = (_QWORD *)(v6 + v5);
      *(_DWORD *)(v11 + 8) = *(_DWORD *)&ReturnLength[4];
      *(_QWORD *)v11 = (unsigned int)(24 * *(_DWORD *)(v11 + 12) + 16);
    }
    v6 += *(_DWORD *)ReturnLength;
    MmDetachSession(NextSession, &ApcState);
    goto LABEL_19;
  }
  MmDetachSession(NextSession, &ApcState);
LABEL_23:
  HalPutDmaAdapter((PADAPTER_OBJECT)NextSession);
LABEL_24:
  if( v7 < 0 )
  {
LABEL_28:
    v4 = v19;
    goto LABEL_29;
  }
  v4 = v19;
  if( v8 )
    *v8 = 0i64;
LABEL_29:
  if( v5 )
    ExUnlockUserBuffer(LockVariable);
  *(_DWORD *)v4 = v6;
  return v7;
}

Referenced by:

ExpQuerySystemInformation