MiCreateUltraThreadContextHelper

INT64 __fastcall MiCreateUltraThreadContextHelper(INT64 a1, UINT64 a2, UINT64 a3){
  signed __int32 v3; 
  unsigned int v4; 
  bool v6; 
  signed __int32 v7; 
  UINT64 v8; 
  __int64 v9; 
  _MMPFN *PfnDb; 
  UINT64 Page; 
  UINT64 *v12; 
  __int64 v13; 
  _QWORD *v15; 
  struct _KPRCB *CurrentPrcb; 
  __int64 v17; 
  signed __int32 v18; 
  v3 = dword_140C4E96C;
  v4 = a3;
  if( dword_140C4E96C != dword_140C4E968 )
  {
    while( 1 )
    {
      v7 = _InterlockedCompareExchange(&dword_140C4E96C, v3 + 1, v3);
      v6 = v3 == v7;
      v3 = v7;
      if( v6 )
        break;
      if( v7 == dword_140C4E968 )
        return 0i64;
    }
    *(_QWORD *)a1 = 0i64;
    v8 = (unsigned int)a2;
    *(__m128i *)(a1 + 8) = _mm_load_si128((const __m128i *)&_xmm_ffffffffffffffffffffffffffffffff);
    if( !(_DWORD)a2 )
      goto LABEL_11;
    if( (unsigned int)a2 > 2ui64 )
      v8 = 2i64;
    if( (MiAcquireNonPagedResources((_MI_PARTITION *)&MiSystemPartition, (unsigned int)v8) & 0x80000000) == 0i64 )
    {
      v9 = 0i64;
      if( v8 )
      {
        PfnDb = MmGetPfnDb();
        while( 1 )
        {
          Page = MiGetPage((_MI_PARTITION *)&MiSystemPartition, v4, 0x30Aui64);
          if( Page == -1i64 )
            break;
          v12 = (UINT64 *)((char *)PfnDb + 48 * Page + 16);
          *v12 = ZeroPte;
          MiSetOriginalPtePfnFromFreeList(v12);
          *(_QWORD *)(a1 + 8 * v9 + 8) = v13;
          v9 = (unsigned int)(v9 + 1);
          if( (unsigned int)v9 >= v8 )
            goto LABEL_11;
        }
        _InterlockedDecrement(&dword_140C4E96C);
        if( (_DWORD)v9 )
        {
          v15 = (_QWORD *)(a1 + 8 * v9 + 8);
          do
          {
            MiReleaseFreshPage((_MMPFN *)((char *)PfnDb + 48 * *--v15));
            *v15 = -1i64;
            LODWORD(v9) = v9 - 1;
          }
          while( (_DWORD)v9 );
        }
        MiReturnCommit((_MI_PARTITION *)&MiSystemPartition, v8);
        CurrentPrcb = KeGetCurrentPrcb();
        v17 = *((int *)CurrentPrcb + 8391);
        if( (_DWORD)v17 != -1 )
        {
          if( v8 + v17 <= 0x100 )
          {
            do
            {
              if( v8 >= 0x80000 )
                break;
              v18 = _InterlockedCompareExchange((volatile signed __int32 *)CurrentPrcb + 8391, v17 + v8, v17);
              v6 = (_DWORD)v17 == v18;
              LODWORD(v17) = v18;
              if( v6 )
                return 0i64;
            }
            while( v18 != -1 && v8 + v18 <= 0x100 );
          }
          if( (int)v17 > 192
            && (_DWORD)v17 != -1
            && (_DWORD)v17 == _InterlockedCompareExchange((volatile signed __int32 *)CurrentPrcb + 8391, 192, v17) )
          {
            v8 += (int)v17 - 192;
          }
        }
        if( v8 )
          _InterlockedExchangeAdd64(&qword_140C526C0, v8);
        return 0i64;
      }
LABEL_11:
      *(_BYTE *)(a1 + 24) = 1;
      return 1i64;
    }
    _InterlockedDecrement(&dword_140C4E96C);
  }
  return 0i64;
}

Referenced by:

MiCreateUltraThreadContext
MiGetUltraMdlContext