MmAllocateMappingAddressEx
NTSTATUS __stdcall MmAllocateMappingAddressEx(INT64 a1, UINT64 a2, INT64 a3){
unsigned __int64 v3;
int v4;
unsigned __int64 v5;
_MMPTE *v6;
_MMPTE *v7;
unsigned int v8;
__int64 v9;
unsigned __int64 Long;
int v11;
_RTL_BALANCED_NODE *Pool;
_MDL MemoryDescriptorList;
__int64 v15;
PVOID BugCheckParameter4;
v3 = (unsigned int)a2;
v4 = a3;
if( (a3 & 0xFFFFFFFE) != 0 )
return 0;
v5 = (unsigned __int64)(a1 + 4095) >> 12;
if( !v5 )
KeBugCheckEx(0xDAu, (PVOID)0x100, 0i64, (PVOID)(unsigned int)a2, BugCheckParameter4);
if( !(_DWORD)a2 )
return 0;
if( v5 >= 0x100000000i64 )
return 0;
Pool = (_RTL_BALANCED_NODE *)MiAllocatePool(64i64, 0x30ui64, 0x6D72694Dui64);
if( !Pool )
return 0;
v6 = MiReservePtes((_MI_SYSTEM_PTE_TYPE *)((char *)&stru_140C4DB30 + 4432), (unsigned int)v5);
v7 = v6;
if( !v6 )
{
ExFreePoolWithTag(Pool, 0);
return 0;
}
v8 = 0;
Pool[1].Children[1] = (_RTL_BALANCED_NODE *)v5;
v9 = (__int64)(((_QWORD)v6 << 25) - ((_QWORD)MmGetPteBase() << 25)) >> 16;
Pool[1].Children[0] = (_RTL_BALANCED_NODE *)v9;
*(_DWORD *)&Pool[1]._bf_0 = v3;
HIDWORD(Pool[1].ParentValue) = v4;
do
{
Long = ZeroPte.u.Long;
LOBYTE(v11) = MiPteInShadowRange((UINT64)v7);
if( v11 && (KeGetCurrentThread()->ApcState.Process->Flags3 & 0x1000) != 0 && (ZeroPte.u.Long & 1) != 0 )
Long = ZeroPte.u.Long | 0x8000000000000000ui64;
v7->u.Long = Long;
++v8;
++v7;
}
while( v8 < v5 );
if( (dword_140CFA17C & 1) != 0 )
{
MemoryDescriptorList.Next = 0i64;
*(_QWORD *)&MemoryDescriptorList.Size = 0i64;
MemoryDescriptorList.ByteCount = 0;
MemoryDescriptorList.ByteOffset = 0;
v15 = 0i64;
MemoryDescriptorList.MappedSystemVa = (void *)v9;
MemoryDescriptorList.StartVa = (void *)v3;
MemoryDescriptorList.Process = (_EPROCESS *)(v5 << 12);
MiInsertPteTracker(&MemoryDescriptorList, MiPteTrackerReserved, 0i64, MiCached);
}
MiInsertMappingNode(Pool);
return v9;
}Referenced by:
EtwpSavePersistedLogger
MmAllocateMappingAddress
PnprInitializeMappingReserve