MiAddMdlTracker
VOID __stdcall MiAddMdlTracker(_MDL *MemoryDescriptorList, UINT64 NumberOfPagesToLock, UINT64 Who){
_QWORD *Process;
int v4;
__int64 v7;
__int64 v8;
__int64 v9;
_BYTE *v10;
__int64 v11;
_QWORD *v12;
bool v13;
_QWORD *v14;
struct _KLOCK_QUEUE_HANDLE LockHandle;
void *retaddr;
UINT64 BackTraceHash;
__int64 v18;
Process = MemoryDescriptorList->Process;
v4 = Who;
memset(&LockHandle, 0, sizeof(LockHandle));
if( Process || (Process = PsInitialSystemProcess) != 0i64 )
{
v7 = Process[193];
if( v7 )
{
if( *(_DWORD *)(v7 + 32) )
{
LODWORD(v8) = ExAllocateFromNPagedLookasideList((NPAGED_LOOKASIDE_LIST *)qword_140C4E780);
v9 = v8;
if( v8 )
{
*(_QWORD *)(v8 + 24) = MemoryDescriptorList;
*(_QWORD *)(v8 + 40) = NumberOfPagesToLock;
*(_QWORD *)(v8 + 32) = MemoryDescriptorList->StartVa;
*(_DWORD *)(v8 + 48) = MemoryDescriptorList->ByteOffset;
*(_DWORD *)(v8 + 52) = MemoryDescriptorList->ByteCount;
*(_QWORD *)(v8 + 64) = MemoryDescriptorList[1].Next;
v18 = 0i64;
MetroHash64::Hash(
(const unsigned __int8 *)&MemoryDescriptorList[1],
8 * NumberOfPagesToLock,
(unsigned __int8 *const)&v18);
*(_DWORD *)(v9 + 60) = v18;
LODWORD(BackTraceHash) = 0;
memset(v9 + 72, 0i64);
if( !RtlCaptureStackBackTrace(0i64, 8ui64, (PVOID *)(v9 + 72), &BackTraceHash) )
{
*(_QWORD *)(v9 + 80) = retaddr;
MiGetInstructionPointer(v10);
*(_QWORD *)(v9 + 72) = v11;
}
*(_DWORD *)(v9 + 56) = v4;
*(_QWORD *)(v9 + 136) = Process;
KeAcquireInStackQueuedSpinLock((UINT64 *)(v7 + 24), &LockHandle);
v12 = *(_QWORD **)v7;
v13 = 0;
if( *(_QWORD *)v7 )
{
while( 1 )
{
if( (unsigned __int64)MemoryDescriptorList < v12[3] )
{
v14 = (_QWORD *)*v12;
if( !*v12 )
break;
}
else
{
if( (unsigned __int64)MemoryDescriptorList <= v12[3] )
KeBugCheckEx(0xD9u, 1ui64, (ULONG_PTR)v12, (ULONG_PTR)MemoryDescriptorList, *(_QWORD *)(v7 + 16));
v14 = (_QWORD *)v12[1];
if( !v14 )
{
v13 = 1;
break;
}
}
v12 = v14;
}
}
RtlAvlInsertNodeEx((unsigned __int64 *)v7, (__int64)v12, v13, (_QWORD *)v9);
*(_QWORD *)(v7 + 16) += NumberOfPagesToLock;
KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
__writecr8(LockHandle.OldIrql);
}
else
{
*(_DWORD *)(v7 + 32) = 0;
}
}
}
}
}Referenced by:
MiProbeAndLockComplete
MiProbeAndLockPages
MiSwitchToTransition