MiApplyHotPatchToLoadedDriver

NTSTATUS __fastcall MiApplyHotPatchToLoadedDriver(INT64 *a1, UNICODE_STRING *a2, UINT64 a3){
  void *v3; 
  unsigned int v7; 
  MMPTE *PteAddress; 
  unsigned int v9; 
  int v10; 
  NTSTATUS result; 
  __int64 v12; 
  _SECTION *v13; 
  _CONTROL_AREA *v14; 
  unsigned int v15; 
  _SECTION *v16; 
  void *SystemAddressForImage; 
  NTSTATUS active; 
  int v19; 
  _CONTROL_AREA *v20; 
  UINT v21; 
  PVOID P; 
  INT64 rcx0; 
  UNICODE_STRING String1; 
  UNICODE_STRING BaseName; 
  UNICODE_STRING BaseDirectory; 
  UINT SharePages; 
  UNICODE_STRING *v28; 
  unsigned int v29; 
  v28 = a2;
  v3 = (void *)a1[6];
  P = 0i64;
  rcx0 = 0i64;
  SharePages = 0;
  v7 = 0;
  BaseName = 0i64;
  BaseDirectory = 0i64;
  String1 = 0i64;
  if( (unsigned int)MI_IS_PHYSICAL_ADDRESS(v3) )
  {
    PteAddress = MiGetPteAddress(v3);
    LOBYTE(v10) = MiMakeZeroedPageTables((char *)PteAddress + 8
                                                            * (((v9 >> 12) + ((v9 & 0xFFF) != 0) + 511i64) & 0xFFFFFFFFFFFFFE00ui64));
    if( !v10 )
      return -1073741670;
  }
  result = MiGenerateSystemImageNames(a2, 0i64, 0i64, &BaseName, &BaseDirectory, &String1);
  if( result >= 0 )
  {
    result = MiObtainSectionForDriver(&String1, a2, a3, 0x40000000, &P);
    if( result == 272 )
    {
      if( (*((_DWORD *)P + 49) & 0x20) == 0 )
        return 272;
      if( *((INT64 **)P + 35) == a1 )
        return MiApplyDriverHotPatch((INT64)P, (INT64)a1);
      return -1073741791;
    }
    if( result < 0 )
      return result;
    v12 = (__int64)P;
    v13 = (_SECTION *)*((_QWORD *)P + 14);
    if( !v13 )
    {
      ExFreePoolWithTag(P, 0);
      return -1073741792;
    }
    v14 = MiSectionControlArea(*((_SECTION **)P + 14));
    v15 = *(_DWORD *)(*(_QWORD *)v14 + 8i64);
    *(_DWORD *)(v12 + 64) = v15 << 12;
    v29 = v15;
    SystemAddressForImage = (void *)MiGetSystemAddressForImage(v16, 0i64, &SharePages);
    if( !SystemAddressForImage )
    {
      ObDereferenceObjectDeferDelete(v13);
      ExFreePoolWithTag((PVOID)v12, 0);
      return -1073741670;
    }
    MiCheckPurgeAndUpMapCount((__int64)v14);
    *(_QWORD *)(v12 + 48) = SystemAddressForImage;
    v19 = MiControlAreaRequiresCharge((INT64)v14);
    if( !v19 )
    {
      active = -1073740277;
      goto LABEL_18;
    }
    if( v19 == 2 )
    {
      active = MiReferenceActiveSubsection((ULONG_PTR)v14 + 128, 136, 0x11u);
      if( active < 0 )
      {
        v19 = 1;
LABEL_18:
        if( v12 )
        {
          if( v19 == 2 && (v7 & 4) == 0 )
          {
            v20 = MiSectionControlArea(*(_SECTION **)(v12 + 112));
            MiReturnCrossPartitionControlAreaCharges((INT64)v20);
          }
          MiUnloadSystemImage((PVOID)v12, v7);
        }
        return active;
      }
    }
    active = MiMapSystemImage(v13, SystemAddressForImage, 0i64);
    if( active < 0 )
      goto LABEL_18;
    _InterlockedExchangeAdd(&dword_140C4ED10, v29);
    v12 = (__int64)P;
    v21 = SharePages;
    v7 = 1;
    active = MiConstructLoaderEntry((__int64)P, (const void **)&BaseName, (const void **)&String1, 0, SharePages, &rcx0);
    if( active < 0 )
      goto LABEL_18;
    ExFreePoolWithTag((PVOID)v12, 0);
    v12 = rcx0;
    v7 = 5;
    if( v19 == 2 )
      *(_DWORD *)(rcx0 + 196) |= 0x80u;
    active = VslPrepareDriverForPatch(a1[6]);
    if( active < 0 )
      goto LABEL_18;
    if( !v21 )
      MiBackSingleImageWithPagefile(v12);
    active = MiHandleDriverNonPagedSections(v12, 0, 1);
    if( active < 0 )
      goto LABEL_18;
    active = MiApplyDriverHotPatch(v12, (INT64)a1);
    if( active < 0 )
      goto LABEL_18;
    if( (MiFlags & 0x80000) != 0 )
      *(_DWORD *)(v12 + 104) |= 0x2100u;
    MiDriverLoadSucceeded(v12, (INT64)v13, v28, (INT64)&String1, (INT64)&BaseName, 1);
    return 0;
  }
  return result;
}

Referenced by:

MiApplyHotPatchToDriver