PipGetPersistentMemory
INT64 __fastcall PipGetPersistentMemory(INT64 a1, INT64 a2, size_t *a3, VOID *a4, INT64 a5){
unsigned __int64 *v5;
_QWORD *v6;
__int64 v8;
__int16 *v9;
_WORD *v10;
PVOID *v11;
PVOID *v12;
__int64 v13;
__int64 v14;
__int64 v15;
_WORD *v16;
__int64 v17;
PVOID v18;
WCHAR *v19;
struct _MDL *v20;
int DriverKsrGuid;
unsigned int v22;
__int64 v23;
_DWORD *PoolWithTag;
unsigned int v25;
unsigned __int64 *v26;
__int64 v27;
unsigned __int64 v28;
struct _MDL *v29;
struct _MDL *v30;
unsigned int v31;
unsigned int v32;
unsigned int i;
unsigned __int64 v34;
unsigned __int64 v35;
__int64 v36;
__int64 v37;
UINT8 *v38;
UINT64 v39;
int DeviceObjectLocation;
UINT64 v41;
__int64 v42;
size_t *v43;
char v45;
unsigned int v46;
unsigned int NumberOfBytes;
unsigned int NumberOfBytes_4;
PVOID P;
size_t *v50;
PCWCH String1;
int v52;
int v53;
__int128 v54;
UINT8 *dst;
INT64 v56;
__int64 v57;
GUID v58;
v5 = 0i64;
v50 = a3;
dst = (UINT8 *)a4;
v56 = a2;
v6 = (_QWORD *)a2;
v52 = 0;
v46 = 0;
v58 = 0i64;
if( a2 )
{
v8 = *(_QWORD *)(*(_QWORD *)(a2 + 312) + 40i64);
if( !v8 || (*(_DWORD *)(v8 + 396) & 0x20000) != 0 )
{
IoAddTriageDumpDataBlock((PVOID)a2, *(unsigned __int16 *)(a2 + 2));
v9 = (__int16 *)v6[1];
if( v9 )
{
IoAddTriageDumpDataBlock(v9, (unsigned int)v9[1]);
v10 = (_WORD *)(v6[1] + 56i64);
if( *v10 )
{
IoAddTriageDumpDataBlock(v10, 2ui64);
IoAddTriageDumpDataBlock(*(PVOID *)(v6[1] + 64i64), *(unsigned __int16 *)(v6[1] + 56i64));
}
}
v11 = *(PVOID **)(v6[39] + 40i64);
if( v11 )
{
v12 = v11 + 5;
IoAddTriageDumpDataBlock(v11, 0x310ui64);
if( *(_WORD *)v12 )
{
IoAddTriageDumpDataBlock(v12, 2ui64);
IoAddTriageDumpDataBlock(v12[1], *(unsigned __int16 *)v12);
}
v13 = v6[39];
v14 = *(_QWORD *)(v13 + 40);
if( *(_WORD *)(v14 + 56) )
{
IoAddTriageDumpDataBlock((PVOID)(v14 + 56), 2ui64);
IoAddTriageDumpDataBlock(
*(PVOID *)(*(_QWORD *)(v6[39] + 40i64) + 64i64),
*(unsigned __int16 *)(*(_QWORD *)(v6[39] + 40i64) + 56i64));
v13 = v6[39];
}
v15 = *(_QWORD *)(*(_QWORD *)(v13 + 40) + 16i64);
if( v15 )
{
v16 = (_WORD *)(v15 + 56);
if( *v16 )
{
IoAddTriageDumpDataBlock(v16, 2ui64);
v17 = *(_QWORD *)(*(_QWORD *)(v6[39] + 40i64) + 16i64);
IoAddTriageDumpDataBlock(*(PVOID *)(v17 + 64), *(unsigned __int16 *)(v17 + 56));
}
}
}
KeBugCheckEx(0xCAu, 2ui64, (ULONG_PTR)v6, 0i64, 0i64);
}
}
v45 = 0;
String1 = 0i64;
v18 = 0i64;
P = 0i64;
v19 = 0i64;
NumberOfBytes = 0;
v20 = 0i64;
DriverKsrGuid = PipGetDriverKsrGuid(a1, &v58);
if( DriverKsrGuid >= 0 )
{
v54 = 0i64;
DriverKsrGuid = KsrEnumeratePersistedMemory(&v58, PipEnumeratePersistedMemory, &v54);
if( DriverKsrGuid >= 0 )
{
if( !DWORD2(v54) )
return(unsigned int)-1073741772;
*(_QWORD *)&v54 = ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * DWORD2(v54), 0x61706E50ui64);
if( !(_QWORD)v54 )
return(unsigned int)-1073741670;
DriverKsrGuid = KsrEnumeratePersistedMemory(&v58, PipEnumeratePersistedMemory, &v54);
if( DriverKsrGuid < 0 )
return(unsigned int)DriverKsrGuid;
v22 = 0;
NumberOfBytes_4 = 0;
if( DWORD2(v54) )
{
v53 = a5;
while( 1 )
{
v18 = 0i64;
v20 = 0i64;
v5 = 0i64;
P = 0i64;
if( v45 )
goto LABEL_74;
v57 = *(_QWORD *)(v54 + 8i64 * v22);
v23 = v57;
KsrQueryMetadata(&v58, v57, 0i64, 0i64, &NumberOfBytes);
PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, NumberOfBytes, 0x61706E50ui64);
P = PoolWithTag;
if( !PoolWithTag )
{
DriverKsrGuid = -1073741670;
LABEL_71:
v18 = 0i64;
v20 = 0i64;
v5 = 0i64;
goto LABEL_74;
}
*PoolWithTag = 0;
DriverKsrGuid = KsrQueryMetadata(&v58, v23, PoolWithTag, NumberOfBytes, &NumberOfBytes);
if( DriverKsrGuid < 0 )
goto LABEL_71;
DriverKsrGuid = KsrClaimPersistedMemory(&v58, v23, 0i64, 0i64, 0, &v46);
if( DriverKsrGuid == -1073741789 )
DriverKsrGuid = 0;
if( DriverKsrGuid < 0 )
goto LABEL_71;
v5 = (unsigned __int64 *)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * v46, 0x61706E50ui64);
if( !v5 )
{
DriverKsrGuid = -1073741670;
LABEL_69:
v18 = 0i64;
v20 = 0i64;
goto LABEL_74;
}
DriverKsrGuid = KsrClaimPersistedMemory(&v58, v23, v5, v46, 0, &v46);
if( DriverKsrGuid < 0 )
goto LABEL_69;
v25 = 0;
if( v46 )
{
v26 = v5;
v27 = v46;
do
{
v28 = *v26++;
v25 += v28 >> 40;
--v27;
}
while( v27 );
v6 = (_QWORD *)v56;
}
v29 = (struct _MDL *)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * v25 + 48, 0x61706E50ui64);
v20 = v29;
if( !v29 )
{
v18 = 0i64;
goto LABEL_74;
}
v29->Next = 0i64;
v30 = v29 + 1;
v31 = v25 << 12;
v32 = 0;
v29->StartVa = 0i64;
v29->ByteOffset = 0;
v29->Size = 8 * ((v31 >> 12) + 6);
v29->ByteCount = v31;
v29->MdlFlags = 2;
for( i = v46; v32 < i; ++v32 )
{
v34 = v5[v32];
v35 = v34 >> 40;
v36 = v34 & 0xFFFFFFFFFFi64;
if( (_DWORD)v35 )
{
v37 = (unsigned int)v35;
do
{
v30->Next = (_MDL *)v36;
v30 = (struct _MDL *)((char *)v30 + 8);
++v36;
--v37;
}
while( v37 );
i = v46;
}
}
v18 = MmMapLockedPagesSpecifyCache(v20, 0, MmCached, 0i64, 0, 0x40000010u);
if( !v18 )
{
DriverKsrGuid = -1073741670;
goto LABEL_74;
}
if( *(_WORD *)P > 1u )
{
DriverKsrGuid = -1073741637;
goto LABEL_74;
}
if( *((_DWORD *)P + 1) )
{
if( v6 )
{
DeviceObjectLocation = PipGetDeviceObjectLocation(v6);
v19 = (WCHAR *)String1;
DriverKsrGuid = DeviceObjectLocation;
if( DeviceObjectLocation < 0 )
goto LABEL_74;
if( PnpCompareMultiSz((WCHAR *)String1, (WCHAR *)P + 8) )
{
v38 = dst;
v39 = *(_QWORD *)v18;
v45 = 1;
if( !dst )
{
v43 = v50;
DriverKsrGuid = -1073741789;
*v50 = v39;
LABEL_62:
if( v45 )
goto LABEL_74;
goto LABEL_73;
}
goto LABEL_55;
}
}
}
else if( !v6 )
{
v38 = dst;
v39 = *(_QWORD *)v18;
if( !dst )
{
*v50 = v39;
LABEL_50:
DriverKsrGuid = -1073741789;
goto LABEL_74;
}
LABEL_55:
v41 = *v50;
*v50 = v39;
if( v41 < v39 )
goto LABEL_50;
memmove(v38, (UINT8 *)v18 + 8, *(_QWORD *)v18);
v45 = 1;
if( (v53 & 1) != 0 )
{
LOBYTE(v42) = 1;
KsrFreePersistedMemoryBlock(&v58, v57, v42);
v45 = 1;
}
}
++NumberOfBytes_4;
if( v19 )
{
ExFreePoolWithTag(v19, 0x61706E50u);
v19 = 0i64;
String1 = 0i64;
}
MmUnmapLockedPages(v18, v20);
v18 = 0i64;
ExFreePoolWithTag(v20, 0x61706E50u);
v20 = 0i64;
ExFreePoolWithTag(P, 0x61706E50u);
P = 0i64;
ExFreePoolWithTag(v5, 0x61706E50u);
v22 = NumberOfBytes_4;
v5 = 0i64;
if( NumberOfBytes_4 >= DWORD2(v54) )
{
v43 = v50;
goto LABEL_62;
}
}
}
v43 = v50;
LABEL_73:
*v43 = 0i64;
DriverKsrGuid = -1073741772;
LABEL_74:
if( v19 )
ExFreePoolWithTag(v19, 0x61706E50u);
if( v18 )
MmUnmapLockedPages(v18, v20);
if( v20 )
ExFreePoolWithTag(v20, 0x61706E50u);
if( P )
ExFreePoolWithTag(P, 0x61706E50u);
if( v5 )
ExFreePoolWithTag(v5, 0x61706E50u);
}
}
return(unsigned int)DriverKsrGuid;
}Referenced by:
IoAcquireKsrPersistentMemory
IoQueryKsrPersistentMemorySize
IoReserveKsrPersistentMemory