MmAllocateMappingAddressEx

NTSTATUS __stdcall MmAllocateMappingAddressEx(INT64 a1, UINT64 a2, INT64 a3){
  unsigned __int64 v3; 
  int v4; 
  unsigned __int64 v5; 
  _MMPTE *v6; 
  _MMPTE *v7; 
  unsigned int v8; 
  __int64 v9; 
  unsigned __int64 Long; 
  int v11; 
  _RTL_BALANCED_NODE *Pool; 
  _MDL MemoryDescriptorList; 
  __int64 v15; 
  PVOID BugCheckParameter4; 

  v3 = (unsigned int)a2;
  v4 = a3;
  if( (a3 & 0xFFFFFFFE) != 0 )
    return 0;
  v5 = (unsigned __int64)(a1 + 4095) >> 12;
  if( !v5 )
    KeBugCheckEx(0xDAu, (PVOID)0x100, 0i64, (PVOID)(unsigned int)a2, BugCheckParameter4);
  if( !(_DWORD)a2 )
    return 0;
  if( v5 >= 0x100000000i64 )
    return 0;
  Pool = (_RTL_BALANCED_NODE *)MiAllocatePool(64i64, 0x30ui64, 0x6D72694Dui64);
  if( !Pool )
    return 0;
  v6 = MiReservePtes((_MI_SYSTEM_PTE_TYPE *)((char *)&stru_140C4DB30 + 4432), (unsigned int)v5);
  v7 = v6;
  if( !v6 )
  {
    ExFreePoolWithTag(Pool, 0);
    return 0;
  }
  v8 = 0;
  Pool[1].Children[1] = (_RTL_BALANCED_NODE *)v5;
  v9 = (__int64)(((_QWORD)v6 << 25) - ((_QWORD)MmGetPteBase() << 25)) >> 16;
  Pool[1].Children[0] = (_RTL_BALANCED_NODE *)v9;
  *(_DWORD *)&Pool[1]._bf_0 = v3;
  HIDWORD(Pool[1].ParentValue) = v4;
  do
  {
    Long = ZeroPte.u.Long;
    LOBYTE(v11) = MiPteInShadowRange((UINT64)v7);
    if( v11 && (KeGetCurrentThread()->ApcState.Process->Flags3 & 0x1000) != 0 && (ZeroPte.u.Long & 1) != 0 )
      Long = ZeroPte.u.Long | 0x8000000000000000ui64;
    v7->u.Long = Long;
    ++v8;
    ++v7;
  }
  while( v8 < v5 );
  if( (dword_140CFA17C & 1) != 0 )
  {
    MemoryDescriptorList.Next = 0i64;
    *(_QWORD *)&MemoryDescriptorList.Size = 0i64;
    MemoryDescriptorList.ByteCount = 0;
    MemoryDescriptorList.ByteOffset = 0;
    v15 = 0i64;
    MemoryDescriptorList.MappedSystemVa = (void *)v9;
    MemoryDescriptorList.StartVa = (void *)v3;
    MemoryDescriptorList.Process = (_EPROCESS *)(v5 << 12);
    MiInsertPteTracker(&MemoryDescriptorList, MiPteTrackerReserved, 0i64, MiCached);
  }
  MiInsertMappingNode(Pool);
  return v9;
}

Referenced by:

EtwpSavePersistedLogger
MmAllocateMappingAddress
PnprInitializeMappingReserve