MiQueryAddressSpan
unsigned __int64 __fastcall MiQueryAddressSpan(__int64 a1, unsigned __int64 a2, unsigned __int64 a3, ULONG_PTR a4){
int v4;
unsigned __int64 v7;
unsigned __int64 v8;
unsigned __int64 v9;
INT64 v11;
unsigned __int8 v12;
int v13;
int v14;
unsigned __int64 v15;
int v17;
int v18;
int v19;
__int64 v20[3];
__int16 v21;
__int16 v22;
int v23;
int v24;
v4 = 0;
v7 = *(unsigned int *)(a4 + 28) | ((unsigned __int64)*(unsigned __int8 *)(a4 + 33) << 32);
v23 = 0;
v8 = a3;
v18 = 0;
v9 = ((v7 << 12) | 0xFFF) + 1;
v20[0] = 0i64;
v17 = 0;
v24 = 0;
v19 = 0;
v21 = 0;
v22 = 0;
if( a3 > v9 || !a3 )
v8 = v9;
v11 = *((_QWORD *)KeGetCurrentThread() + 23) + 1664i64;
v12 = MiLockWorkingSetShared(v11);
*(_DWORD *)(a1 + 32) = MiQueryAddressState(a2, v8 - 1, v12, a4, 0i64, &v23, &v24, &v21, v20, &v17);
if( v23 )
{
v13 = MmProtectToValue[v23];
*(_DWORD *)(a1 + 36) = v13;
v14 = v24 | v13;
}
else
{
v14 = 0;
}
*(_DWORD *)(a1 + 36) = v14;
v15 = v20[0];
*(_WORD *)(a1 + 20) = v21;
while( v15 < v8 )
{
if( (unsigned int)MiQueryAddressState(v15, v8 - 1, v12, a4, a1, &v18, &v19, &v22, v20, &v17) != *(_DWORD *)(a1 + 32)
|| v18 != v23
|| v22 != v21
|| v19 != v24 )
{
break;
}
v15 = v20[0];
if( (++v4 & 0x1F) == 0 && MiWorkingSetIsContended(v11) || KeShouldYieldProcessor() )
{
MiUnlockWorkingSetShared(v11, v12);
MiLockWorkingSetShared(v11);
}
}
MiUnlockWorkingSetShared(v11, v12);
return v15;
}Referenced by:
MmQueryVirtualMemory