MiMakePteClean
VOID __fastcall MiMakePteClean(INT64 a1, INT64 a2){
INT64 v4;
unsigned __int64 PteBase;
unsigned __int64 v6;
unsigned int v7;
unsigned __int64 v8;
UINT64 v9;
v4 = MI_READ_PTE_LOCK_FREE(a1);
PteBase = (unsigned __int64)MmGetPteBase();
v6 = v4 & 0xFFFFFFFFFFFFFFBDui64;
v7 = 0;
v9 = v4 & 0xFFFFFFFFFFFFFFBDui64;
v8 = (__int64)((a1 << 25) - (PteBase << 25)) >> 16;
if( v8 < PteBase )
goto LABEL_2;
do
{
if( v8 > (unsigned __int64)MmGetPteLimit() )
break;
++v7;
v8 = (__int64)((v8 << 25) - (PteBase << 25)) >> 16;
}
while( v8 >= PteBase );
if( v7 )
{
v6 = v9;
MiRewritePteWithLockBit(*((_QWORD *)KeGetCurrentThread() + 23) + 1664i64, (volatile INT64 *)a1, v9);
MiInsertLargeTbFlushEntry(a2, v7, a1);
}
else
{
LABEL_2:
MiWriteValidPteNewProtection((INT64 *)a1, v6);
MiInsertTbFlushEntry(a2, v8, 1i64, 0i64);
}
MiPteInShadowRange((UINT64)&v9);
MiLockPageAndSetDirty((INT64)MmGetPfnDb() + 48 * ((v6 >> 12) & 0xFFFFFFFFFi64), 1i64);
}Referenced by:
NtGetWriteWatch