PipGetPersistentMemory

INT64 __fastcall PipGetPersistentMemory(INT64 a1, INT64 a2, size_t *a3, VOID *a4, INT64 a5){
  unsigned __int64 *v5; 
  _QWORD *v6; 
  __int64 v8; 
  __int16 *v9; 
  _WORD *v10; 
  PVOID *v11; 
  PVOID *v12; 
  __int64 v13; 
  __int64 v14; 
  __int64 v15; 
  _WORD *v16; 
  __int64 v17; 
  PVOID v18; 
  WCHAR *v19; 
  struct _MDL *v20; 
  int DriverKsrGuid; 
  unsigned int v22; 
  __int64 v23; 
  _DWORD *PoolWithTag; 
  unsigned int v25; 
  unsigned __int64 *v26; 
  __int64 v27; 
  unsigned __int64 v28; 
  struct _MDL *v29; 
  struct _MDL *v30; 
  unsigned int v31; 
  unsigned int v32; 
  unsigned int i; 
  unsigned __int64 v34; 
  unsigned __int64 v35; 
  __int64 v36; 
  __int64 v37; 
  UINT8 *v38; 
  UINT64 v39; 
  int DeviceObjectLocation; 
  UINT64 v41; 
  __int64 v42; 
  size_t *v43; 
  char v45; 
  unsigned int v46; 
  unsigned int NumberOfBytes; 
  unsigned int NumberOfBytes_4; 
  PVOID P; 
  size_t *v50; 
  PCWCH String1; 
  int v52; 
  int v53; 
  __int128 v54; 
  UINT8 *dst; 
  INT64 v56; 
  __int64 v57; 
  GUID v58; 
  v5 = 0i64;
  v50 = a3;
  dst = (UINT8 *)a4;
  v56 = a2;
  v6 = (_QWORD *)a2;
  v52 = 0;
  v46 = 0;
  v58 = 0i64;
  if( a2 )
  {
    v8 = *(_QWORD *)(*(_QWORD *)(a2 + 312) + 40i64);
    if( !v8 || (*(_DWORD *)(v8 + 396) & 0x20000) != 0 )
    {
      IoAddTriageDumpDataBlock((PVOID)a2, *(unsigned __int16 *)(a2 + 2));
      v9 = (__int16 *)v6[1];
      if( v9 )
      {
        IoAddTriageDumpDataBlock(v9, (unsigned int)v9[1]);
        v10 = (_WORD *)(v6[1] + 56i64);
        if( *v10 )
        {
          IoAddTriageDumpDataBlock(v10, 2ui64);
          IoAddTriageDumpDataBlock(*(PVOID *)(v6[1] + 64i64), *(unsigned __int16 *)(v6[1] + 56i64));
        }
      }
      v11 = *(PVOID **)(v6[39] + 40i64);
      if( v11 )
      {
        v12 = v11 + 5;
        IoAddTriageDumpDataBlock(v11, 0x310ui64);
        if( *(_WORD *)v12 )
        {
          IoAddTriageDumpDataBlock(v12, 2ui64);
          IoAddTriageDumpDataBlock(v12[1], *(unsigned __int16 *)v12);
        }
        v13 = v6[39];
        v14 = *(_QWORD *)(v13 + 40);
        if( *(_WORD *)(v14 + 56) )
        {
          IoAddTriageDumpDataBlock((PVOID)(v14 + 56), 2ui64);
          IoAddTriageDumpDataBlock(
            *(PVOID *)(*(_QWORD *)(v6[39] + 40i64) + 64i64),
            *(unsigned __int16 *)(*(_QWORD *)(v6[39] + 40i64) + 56i64));
          v13 = v6[39];
        }
        v15 = *(_QWORD *)(*(_QWORD *)(v13 + 40) + 16i64);
        if( v15 )
        {
          v16 = (_WORD *)(v15 + 56);
          if( *v16 )
          {
            IoAddTriageDumpDataBlock(v16, 2ui64);
            v17 = *(_QWORD *)(*(_QWORD *)(v6[39] + 40i64) + 16i64);
            IoAddTriageDumpDataBlock(*(PVOID *)(v17 + 64), *(unsigned __int16 *)(v17 + 56));
          }
        }
      }
      KeBugCheckEx(0xCAu, 2ui64, (ULONG_PTR)v6, 0i64, 0i64);
    }
  }
  v45 = 0;
  String1 = 0i64;
  v18 = 0i64;
  P = 0i64;
  v19 = 0i64;
  NumberOfBytes = 0;
  v20 = 0i64;
  DriverKsrGuid = PipGetDriverKsrGuid(a1, &v58);
  if( DriverKsrGuid >= 0 )
  {
    v54 = 0i64;
    DriverKsrGuid = KsrEnumeratePersistedMemory(&v58, PipEnumeratePersistedMemory, &v54);
    if( DriverKsrGuid >= 0 )
    {
      if( !DWORD2(v54) )
        return(unsigned int)-1073741772;
      *(_QWORD *)&v54 = ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * DWORD2(v54), 0x61706E50ui64);
      if( !(_QWORD)v54 )
        return(unsigned int)-1073741670;
      DriverKsrGuid = KsrEnumeratePersistedMemory(&v58, PipEnumeratePersistedMemory, &v54);
      if( DriverKsrGuid < 0 )
        return(unsigned int)DriverKsrGuid;
      v22 = 0;
      NumberOfBytes_4 = 0;
      if( DWORD2(v54) )
      {
        v53 = a5;
        while( 1 )
        {
          v18 = 0i64;
          v20 = 0i64;
          v5 = 0i64;
          P = 0i64;
          if( v45 )
            goto LABEL_74;
          v57 = *(_QWORD *)(v54 + 8i64 * v22);
          v23 = v57;
          KsrQueryMetadata(&v58, v57, 0i64, 0i64, &NumberOfBytes);
          PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, NumberOfBytes, 0x61706E50ui64);
          P = PoolWithTag;
          if( !PoolWithTag )
          {
            DriverKsrGuid = -1073741670;
LABEL_71:
            v18 = 0i64;
            v20 = 0i64;
            v5 = 0i64;
            goto LABEL_74;
          }
          *PoolWithTag = 0;
          DriverKsrGuid = KsrQueryMetadata(&v58, v23, PoolWithTag, NumberOfBytes, &NumberOfBytes);
          if( DriverKsrGuid < 0 )
            goto LABEL_71;
          DriverKsrGuid = KsrClaimPersistedMemory(&v58, v23, 0i64, 0i64, 0, &v46);
          if( DriverKsrGuid == -1073741789 )
            DriverKsrGuid = 0;
          if( DriverKsrGuid < 0 )
            goto LABEL_71;
          v5 = (unsigned __int64 *)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * v46, 0x61706E50ui64);
          if( !v5 )
          {
            DriverKsrGuid = -1073741670;
LABEL_69:
            v18 = 0i64;
            v20 = 0i64;
            goto LABEL_74;
          }
          DriverKsrGuid = KsrClaimPersistedMemory(&v58, v23, v5, v46, 0, &v46);
          if( DriverKsrGuid < 0 )
            goto LABEL_69;
          v25 = 0;
          if( v46 )
          {
            v26 = v5;
            v27 = v46;
            do
            {
              v28 = *v26++;
              v25 += v28 >> 40;
              --v27;
            }
            while( v27 );
            v6 = (_QWORD *)v56;
          }
          v29 = (struct _MDL *)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * v25 + 48, 0x61706E50ui64);
          v20 = v29;
          if( !v29 )
          {
            v18 = 0i64;
            goto LABEL_74;
          }
          v29->Next = 0i64;
          v30 = v29 + 1;
          v31 = v25 << 12;
          v32 = 0;
          v29->StartVa = 0i64;
          v29->ByteOffset = 0;
          v29->Size = 8 * ((v31 >> 12) + 6);
          v29->ByteCount = v31;
          v29->MdlFlags = 2;
          for( i = v46; v32 < i; ++v32 )
          {
            v34 = v5[v32];
            v35 = v34 >> 40;
            v36 = v34 & 0xFFFFFFFFFFi64;
            if( (_DWORD)v35 )
            {
              v37 = (unsigned int)v35;
              do
              {
                v30->Next = (_MDL *)v36;
                v30 = (struct _MDL *)((char *)v30 + 8);
                ++v36;
                --v37;
              }
              while( v37 );
              i = v46;
            }
          }
          v18 = MmMapLockedPagesSpecifyCache(v20, 0, MmCached, 0i64, 0, 0x40000010u);
          if( !v18 )
          {
            DriverKsrGuid = -1073741670;
            goto LABEL_74;
          }
          if( *(_WORD *)P > 1u )
          {
            DriverKsrGuid = -1073741637;
            goto LABEL_74;
          }
          if( *((_DWORD *)P + 1) )
          {
            if( v6 )
            {
              DeviceObjectLocation = PipGetDeviceObjectLocation(v6);
              v19 = (WCHAR *)String1;
              DriverKsrGuid = DeviceObjectLocation;
              if( DeviceObjectLocation < 0 )
                goto LABEL_74;
              if( PnpCompareMultiSz((WCHAR *)String1, (WCHAR *)P + 8) )
              {
                v38 = dst;
                v39 = *(_QWORD *)v18;
                v45 = 1;
                if( !dst )
                {
                  v43 = v50;
                  DriverKsrGuid = -1073741789;
                  *v50 = v39;
LABEL_62:
                  if( v45 )
                    goto LABEL_74;
                  goto LABEL_73;
                }
                goto LABEL_55;
              }
            }
          }
          else if( !v6 )
          {
            v38 = dst;
            v39 = *(_QWORD *)v18;
            if( !dst )
            {
              *v50 = v39;
LABEL_50:
              DriverKsrGuid = -1073741789;
              goto LABEL_74;
            }
LABEL_55:
            v41 = *v50;
            *v50 = v39;
            if( v41 < v39 )
              goto LABEL_50;
            memmove(v38, (UINT8 *)v18 + 8, *(_QWORD *)v18);
            v45 = 1;
            if( (v53 & 1) != 0 )
            {
              LOBYTE(v42) = 1;
              KsrFreePersistedMemoryBlock(&v58, v57, v42);
              v45 = 1;
            }
          }
          ++NumberOfBytes_4;
          if( v19 )
          {
            ExFreePoolWithTag(v19, 0x61706E50u);
            v19 = 0i64;
            String1 = 0i64;
          }
          MmUnmapLockedPages(v18, v20);
          v18 = 0i64;
          ExFreePoolWithTag(v20, 0x61706E50u);
          v20 = 0i64;
          ExFreePoolWithTag(P, 0x61706E50u);
          P = 0i64;
          ExFreePoolWithTag(v5, 0x61706E50u);
          v22 = NumberOfBytes_4;
          v5 = 0i64;
          if( NumberOfBytes_4 >= DWORD2(v54) )
          {
            v43 = v50;
            goto LABEL_62;
          }
        }
      }
      v43 = v50;
LABEL_73:
      *v43 = 0i64;
      DriverKsrGuid = -1073741772;
LABEL_74:
      if( v19 )
        ExFreePoolWithTag(v19, 0x61706E50u);
      if( v18 )
        MmUnmapLockedPages(v18, v20);
      if( v20 )
        ExFreePoolWithTag(v20, 0x61706E50u);
      if( P )
        ExFreePoolWithTag(P, 0x61706E50u);
      if( v5 )
        ExFreePoolWithTag(v5, 0x61706E50u);
    }
  }
  return(unsigned int)DriverKsrGuid;
}

Referenced by:

IoAcquireKsrPersistentMemory
IoQueryKsrPersistentMemorySize
IoReserveKsrPersistentMemory