MiQueryMemoryPhysicalContiguity

__int64 __fastcall MiQueryMemoryPhysicalContiguity(ULONG_PTR a1, __int128 *a2, __int64 a3, KPROCESSOR_MODE a4){
  _MDL *v5; 
  INT64 v6; 
  unsigned int v7; 
  unsigned __int64 v8; 
  unsigned __int64 v9; 
  unsigned int LargestPageIndex; 
  char v11; 
  __int64 v12; 
  char v13; 
  unsigned int v14; 
  __int64 *v15; 
  UINT64 v16; 
  UINT8 *v17; 
  _MDL *v18; 
  __int16 v19; 
  unsigned __int64 v20; 
  unsigned __int64 v21; 
  UINT64 v22; 
  int v25; 
  __int64 v26; 
  unsigned int v27; 
  unsigned int v28; 
  _MDL *v29; 
  UINT64 v30; 
  INT64 v31; 
  ULONG_PTR BugCheckParameter1; 
  __int128 v33; 
  __int128 v34; 
  volatile void *Address; 
  unsigned __int64 v36; 
  _ETHREAD *CurrentThread; 
  _KAPC_STATE ApcState; 
  char Src[32]; 
  BugCheckParameter1 = a1;
  v28 = 0;
  memset(&ApcState, 0, sizeof(ApcState));
  v5 = 0i64;
  v29 = 0i64;
  v6 = 0i64;
  v25 = 0;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  if( a3 != 40 )
  {
    v7 = -1073741820;
    goto LABEL_52;
  }
  if( a4 )
    ProbeForWrite(a2, 0x28ui64, 8ui64);
  v33 = *a2;
  v34 = a2[1];
  Address = (volatile void *)*((_QWORD *)a2 + 4);
  if( (DWORD2(v34) & 0xFFFFFFFE) != 0 )
    goto LABEL_51;
  v8 = v33;
  if( (unsigned __int64)v33 > 0x7FFFFFFEFFFFi64 )
    goto LABEL_51;
  v9 = v34;
  if( !(_QWORD)v34 || (((_QWORD)v34 - 1i64) & (unsigned __int64)v34) != 0 || (unsigned __int64)v34 <= 0x1000 )
    goto LABEL_51;
  LargestPageIndex = MiGetLargestPageIndex();
  v14 = LargestPageIndex;
  v27 = LargestPageIndex;
  if( LargestPageIndex < 3 )
  {
    v15 = &MiLargePageSizes[LargestPageIndex];
    do
    {
      if( *v15 == (unsigned __int64)v34 >> 12 )
        break;
      v27 = ++v14;
      ++v15;
    }
    while( v14 < 3 );
    v11 = BYTE8(v34);
  }
  if( v14 == 3 )
  {
LABEL_16:
    v7 = -1073741637;
    goto LABEL_52;
  }
  if( (v12 & *((_QWORD *)&v33 + 1)) != 0 || ((unsigned __int64)v33 & ~v12) != (_QWORD)v33 )
    goto LABEL_51;
  LODWORD(v31) = 2 * (v11 & 1);
  v36 = *((_QWORD *)&v33 + 1) / (unsigned __int64)v34;
  v16 = 4 * (*((_QWORD *)&v33 + 1) / (unsigned __int64)v34);
  v30 = v16;
  if( v16 > 0x20 )
  {
    if( v16 <= 0xFFFFE000 )
    {
      MmSizeOfMdl((PVOID)Address, v16);
      LODWORD(v18) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
      v5 = v18;
      v29 = v18;
      if( !v18 )
        goto LABEL_24;
      v18->Next = 0i64;
      v19 = (__int16)Address;
      v18->Size = 8 * (((v16 + ((unsigned __int16)Address & 0xFFF) + 4095i64) >> 12) + 6);
      v18->MdlFlags = 0;
      v18->StartVa = (void *)((unsigned __int64)Address & 0xFFFFFFFFFFFFF000ui64);
      v18->ByteOffset = v19 & 0xFFF;
      v18->ByteCount = v16;
      MmProbeAndLockPages(v18, a4, IoWriteAccess);
      v17 = (UINT8 *)((v5->MdlFlags & 5) != 0 ? v5->MappedSystemVa : MmMapLockedPagesSpecifyCache(
                                                                       v5,
                                                                       0,
                                                                       MmCached,
                                                                       0i64,
                                                                       0,
                                                                       0x40000010u));
      if( !v17 )
      {
LABEL_24:
        v7 = -1073741670;
        goto LABEL_52;
      }
      goto LABEL_29;
    }
LABEL_51:
    v7 = -1073741811;
    goto LABEL_52;
  }
  v17 = (UINT8 *)Src;
  if( v13 )
    ProbeForWrite((VOID *)Address, v16, 4ui64);
LABEL_29:
  if( *((_QWORD *)CurrentThread + 23) != BugCheckParameter1 )
  {
    KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
    v25 = 1;
  }
  v20 = v8 >> 12;
  v21 = v9 >> 12;
  v26 = 0i64;
  if( v36 )
  {
    while( 1 )
    {
      if( v6
        && (v20 < (*(unsigned int *)(v6 + 24) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 32) << 32))
         || v20 > (*(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32))) )
      {
        MiUnlockAndDereferenceVadShared((PVOID)v6);
        v6 = 0i64;
      }
      v22 = v20 << 12;
      if( !v6 )
      {
        v6 = MiObtainReferencedVadEx(v20 << 12, 2, (INT64 *)&v28);
        if( !v6 )
        {
          v7 = v28;
          goto LABEL_54;
        }
      }
      v20 += v21;
      if( v20 - 1 > (*(unsigned int *)(v6 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v6 + 33) << 32)) )
        break;
      if( (*(_DWORD *)(v6 + 48) & 0x70) != 0 || (*(_DWORD *)(v6 + 48) & 0x100000) == 0 )
        goto LABEL_16;
      *(_DWORD *)&v17[4 * v26] = 0;
      *(_DWORD *)&v17[4 * v26] ^= (*(_DWORD *)&v17[4 * v26] ^ MiQueryVaPhysicalContiguity(
                                                                BugCheckParameter1 + 1664,
                                                                v22,
                                                                v27,
                                                                (unsigned int)v31)) & 3;
      if( ++v26 >= v36 )
      {
        v16 = v30;
        goto LABEL_44;
      }
    }
    v7 = -1073741800;
  }
  else
  {
LABEL_44:
    if( v6 )
      MiUnlockAndDereferenceVadShared((PVOID)v6);
    v6 = 0i64;
    v30 = 0i64;
    if( v25 )
    {
      KiUnstackDetachProcess(&ApcState, 0i64);
      v25 = 0;
    }
    if( v17 == (UINT8 *)Src )
      memmove((UINT8 *)Address, v17, v16);
    v7 = 0;
  }
LABEL_52:
  if( v6 )
    MiUnlockAndDereferenceVadShared((PVOID)v6);
LABEL_54:
  if( v25 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  if( v5 )
  {
    if( (v5->MdlFlags & 2) != 0 )
      MmUnlockPages(v5);
    ExFreePoolWithTag(v5, 0);
  }
  return v7;
}

Referenced by:

MmQueryVirtualMemory