00001
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
#include "mi.h"
00024
00025 #define MEM_CHECK_COMMIT_STATE 0x400000
00026
00027 #define MM_VALID_PTE_SIZE (256)
00028
00029
00030 MMPTE MmDecommittedPte = {
MM_DECOMMIT <<
MM_PROTECT_FIELD_SHIFT};
00031
00032
#if DBG
00033
extern PEPROCESS MmWatchProcess;
00034
VOID MmFooBar(VOID);
00035
#endif // DBG
00036
00037
00038
00039
#ifdef ALLOC_PRAGMA
00040
#pragma alloc_text(PAGE,NtFreeVirtualMemory)
00041
#pragma alloc_text(PAGE,MiIsEntireRangeCommitted)
00042
#endif
00043
00044
VOID
00045
MiProcessValidPteList (
00046 IN
PMMPTE *PteList,
00047 IN ULONG Count
00048 );
00049
00050 ULONG
00051
MiDecommitPages (
00052 IN PVOID StartingAddress,
00053 IN
PMMPTE EndingPte,
00054 IN
PEPROCESS Process,
00055 IN
PMMVAD_SHORT Vad
00056 );
00057
00058
VOID
00059
MiDeleteFreeVm (
00060 IN PVOID StartingAddress,
00061 IN PVOID EndingAddress
00062 );
00063
00064
00065
NTSTATUS
00066 NtFreeVirtualMemory(
00067 IN HANDLE ProcessHandle,
00068 IN OUT PVOID *BaseAddress,
00069 IN OUT PSIZE_T RegionSize,
00070 IN ULONG FreeType
00071 )
00072
00073
00074
00075
00076
00077
00078
00079
00080
00081
00082
00083
00084
00085
00086
00087
00088
00089
00090
00091
00092
00093
00094
00095
00096
00097
00098
00099
00100
00101
00102
00103
00104
00105
00106
00107
00108
00109
00110
00111
00112
00113
00114 {
00115
PMMVAD_SHORT Vad;
00116
PMMVAD_SHORT NewVad;
00117
PMMVAD PreviousVad;
00118
PMMVAD NextVad;
00119
PEPROCESS Process;
00120
KPROCESSOR_MODE PreviousMode;
00121 PVOID StartingAddress;
00122 PVOID EndingAddress;
00123
NTSTATUS Status;
00124 ULONG Attached =
FALSE;
00125 SIZE_T CapturedRegionSize;
00126 PVOID CapturedBase;
00127
PMMPTE StartingPte;
00128
PMMPTE EndingPte;
00129 SIZE_T OldQuota;
00130 SIZE_T QuotaCharge;
00131 SIZE_T CommitReduction;
00132 ULONG_PTR OldEnd;
00133 LOGICAL UserPhysicalPages;
00134
#if defined(_MIALT4K_)
00135
PVOID OriginalStartingAddress;
00136 PVOID OriginalEndingAddress;
00137 BOOLEAN EmulationFor4kPage =
FALSE;
00138
#endif
00139
00140
PAGED_CODE();
00141
00142
00143
00144
00145
00146
if ((FreeType & ~(MEM_DECOMMIT | MEM_RELEASE)) != 0) {
00147
return STATUS_INVALID_PARAMETER_4;
00148 }
00149
00150
00151
00152
00153
00154
if (((FreeType & (MEM_DECOMMIT | MEM_RELEASE)) == 0) ||
00155 ((FreeType & (MEM_DECOMMIT | MEM_RELEASE)) ==
00156 (MEM_DECOMMIT | MEM_RELEASE))) {
00157
return STATUS_INVALID_PARAMETER_4;
00158 }
00159
00160 PreviousMode = KeGetPreviousMode();
00161
00162
00163
00164
00165
00166
00167
try {
00168
00169
if (PreviousMode !=
KernelMode) {
00170
00171
ProbeForWritePointer (BaseAddress);
00172
ProbeForWriteUlong_ptr (RegionSize);
00173 }
00174
00175
00176
00177
00178
00179 CapturedBase = *BaseAddress;
00180
00181
00182
00183
00184
00185 CapturedRegionSize = *RegionSize;
00186
00187 } except (
ExSystemExceptionFilter()) {
00188
00189
00190
00191
00192
00193
00194
00195
return GetExceptionCode();
00196 }
00197
00198
#if DBG
00199
if (MmDebug &
MM_DBG_SHOW_NT_CALLS) {
00200
if ( !MmWatchProcess ) {
00201
DbgPrint(
"freevm processhandle %lx base %lx size %lx type %lx\n",
00202 ProcessHandle, CapturedBase, CapturedRegionSize, FreeType);
00203 }
00204 }
00205
#endif
00206
00207
00208
00209
00210
00211
00212
if (CapturedBase > MM_HIGHEST_USER_ADDRESS) {
00213
00214
00215
00216
00217
00218
return STATUS_INVALID_PARAMETER_2;
00219 }
00220
00221
if ((ULONG_PTR)MM_HIGHEST_USER_ADDRESS - (ULONG_PTR)CapturedBase <
00222 CapturedRegionSize) {
00223
00224
00225
00226
00227
00228
return STATUS_INVALID_PARAMETER_3;
00229
00230 }
00231
00232 EndingAddress = (PVOID)(((LONG_PTR)CapturedBase + CapturedRegionSize - 1) |
00233 (
PAGE_SIZE - 1));
00234
00235 StartingAddress = (PVOID)
PAGE_ALIGN(CapturedBase);
00236
00237
if ( ProcessHandle == NtCurrentProcess() ) {
00238 Process =
PsGetCurrentProcess();
00239 }
else {
00240
00241
00242
00243
00244
Status =
ObReferenceObjectByHandle ( ProcessHandle,
00245 PROCESS_VM_OPERATION,
00246
PsProcessType,
00247 PreviousMode,
00248 (PVOID *)&Process,
00249
NULL );
00250
00251
if (!
NT_SUCCESS(
Status)) {
00252
return Status;
00253 }
00254 }
00255
00256
00257
00258
00259
00260
00261
if (
PsGetCurrentProcess() != Process) {
00262
KeAttachProcess (&Process->
Pcb);
00263 Attached =
TRUE;
00264 }
00265
00266
00267
00268
00269
00270
00271
00272
00273
00274
LOCK_WS_AND_ADDRESS_SPACE (Process);
00275
00276
00277
00278
00279
00280
if (Process->
AddressSpaceDeleted != 0) {
00281
Status = STATUS_PROCESS_IS_TERMINATING;
00282
goto ErrorReturn;
00283 }
00284
00285
#if defined(_MIALT4K_)
00286
00287
if (CapturedRegionSize != 0) {
00288
00289 OriginalStartingAddress = (PVOID)
PAGE_4K_ALIGN (CapturedBase);
00290
00291 OriginalEndingAddress = (PVOID)(((LONG_PTR)CapturedBase + CapturedRegionSize - 1) |
00292 (
PAGE_4K - 1));
00293
00294
if (Process->
Wow64Process !=
NULL) {
00295
00296 EmulationFor4kPage =
TRUE;
00297
00298
00299
00300
00301
00302 StartingAddress =
PAGE_NEXT_ALIGN(OriginalStartingAddress);
00303
00304 EndingAddress =
00305 (PVOID)((ULONG_PTR)
PAGE_ALIGN ((ULONG_PTR)OriginalEndingAddress +
PAGE_4K) - 1);
00306
00307
if (StartingAddress > EndingAddress) {
00308
00309
00310
00311
00312
00313
UNLOCK_WS_UNSAFE (Process);
00314
00315
goto perform_free4kpages;
00316
00317 }
00318 }
00319 }
00320
00321
#endif
00322
00323 Vad = (
PMMVAD_SHORT)
MiLocateAddress (StartingAddress);
00324
00325
if (Vad ==
NULL) {
00326
00327
00328
00329
00330
00331
Status = STATUS_MEMORY_NOT_ALLOCATED;
00332
goto ErrorReturn;
00333 }
00334
00335
00336
00337
00338
00339
if (Vad->
EndingVpn <
MI_VA_TO_VPN (EndingAddress)) {
00340
00341
00342
00343
00344
00345
00346
Status = STATUS_UNABLE_TO_FREE_VM;
00347
goto ErrorReturn;
00348 }
00349
00350
00351
00352
00353
00354
00355
if ((Vad->
u.VadFlags.PrivateMemory == 0) ||
00356 (Vad->
u.VadFlags.PhysicalMapping == 1)) {
00357
Status = STATUS_UNABLE_TO_DELETE_SECTION;
00358
goto ErrorReturn;
00359 }
00360
00361
if (Vad->
u.VadFlags.NoChange == 1) {
00362
00363
00364
00365
00366
00367
00368
if (FreeType & MEM_RELEASE) {
00369
00370
00371
00372
00373
00374
00375
00376
Status =
MiCheckSecuredVad ((
PMMVAD)Vad,
00377
MI_VPN_TO_VA (Vad->
StartingVpn),
00378 ((Vad->
EndingVpn - Vad->
StartingVpn) <<
PAGE_SHIFT) +
00379 (
PAGE_SIZE - 1),
00380
MM_SECURE_DELETE_CHECK);
00381
00382 }
else {
00383
Status =
MiCheckSecuredVad ((
PMMVAD)Vad,
00384 CapturedBase,
00385 CapturedRegionSize,
00386
MM_SECURE_DELETE_CHECK);
00387 }
00388
if (!
NT_SUCCESS (
Status)) {
00389
goto ErrorReturn;
00390 }
00391 }
00392
00393 UserPhysicalPages =
FALSE;
00394
00395 PreviousVad =
MiGetPreviousVad (Vad);
00396 NextVad =
MiGetNextVad (Vad);
00397
if (FreeType & MEM_RELEASE) {
00398
00399
00400
00401
00402
00403
00404
00405
00406
00407
00408
00409
00410
00411
00412
00413
00414
if (CapturedRegionSize == 0) {
00415
00416
00417
00418
00419
00420
00421
if (
MI_VA_TO_VPN (CapturedBase) != Vad->
StartingVpn) {
00422
Status = STATUS_FREE_VM_NOT_AT_BASE;
00423
goto ErrorReturn;
00424 }
00425
00426
00427
00428
00429
00430 StartingAddress =
MI_VPN_TO_VA (Vad->
StartingVpn);
00431 EndingAddress =
MI_VPN_TO_VA_ENDING (Vad->
EndingVpn);
00432
00433
00434
00435
00436
00437
00438
00439
if (Vad->
u.VadFlags.UserPhysicalPages == 1) {
00440
MiPhysicalViewRemover (Process, (
PMMVAD)Vad);
00441
MiRemoveUserPhysicalPagesVad (Vad);
00442 UserPhysicalPages =
TRUE;
00443 }
00444
else if (Vad->
u.VadFlags.WriteWatch == 1) {
00445
MiPhysicalViewRemover (Process, (
PMMVAD)Vad);
00446 }
00447
00448
MiRemoveVad ((
PMMVAD)Vad);
00449
ExFreePool (Vad);
00450
00451
#if defined(_MIALT4K_)
00452
00453 OriginalStartingAddress = StartingAddress;
00454 OriginalEndingAddress = EndingAddress;
00455
00456
if (Process->
Wow64Process !=
NULL) {
00457
00458 EmulationFor4kPage =
TRUE;
00459
00460 }
else {
00461
00462 EmulationFor4kPage =
FALSE;
00463
00464 }
00465
00466
#endif
00467
00468 }
else {
00469
00470
00471
00472
00473
00474
00475
if (
MI_VA_TO_VPN (StartingAddress) == Vad->
StartingVpn) {
00476
if (
MI_VA_TO_VPN (EndingAddress) == Vad->
EndingVpn) {
00477
00478
00479
00480
00481
00482
00483
00484
00485
00486
00487
00488
if (Vad->
u.VadFlags.UserPhysicalPages == 1) {
00489
MiPhysicalViewRemover (Process, (
PMMVAD)Vad);
00490
MiRemoveUserPhysicalPagesVad (Vad);
00491 UserPhysicalPages =
TRUE;
00492 }
00493
else if (Vad->
u.VadFlags.WriteWatch == 1) {
00494
MiPhysicalViewRemover (Process, (
PMMVAD)Vad);
00495 }
00496
00497
MiRemoveVad ((
PMMVAD)Vad);
00498
ExFreePool (Vad);
00499
00500 }
else {
00501
00502
if ((Vad->
u.VadFlags.UserPhysicalPages == 1) ||
00503 (Vad->
u.VadFlags.WriteWatch == 1)) {
00504
00505
00506
00507
00508
00509
00510
Status = STATUS_FREE_VM_NOT_AT_BASE;
00511
goto ErrorReturn;
00512 }
00513
00514
00515
00516
00517
00518
00519 CommitReduction =
MiCalculatePageCommitment (
00520 StartingAddress,
00521 EndingAddress,
00522 (
PMMVAD)Vad,
00523 Process );
00524
00525 Vad->
StartingVpn =
MI_VA_TO_VPN ((PCHAR)EndingAddress + 1);
00526 Vad->
u.VadFlags.CommitCharge -= CommitReduction;
00527
ASSERT ((SSIZE_T)Vad->
u.VadFlags.CommitCharge >= 0);
00528
MiReturnPageFileQuota (CommitReduction, Process);
00529
MiReturnCommitment (CommitReduction);
00530
if (Process->
JobStatus &
PS_JOB_STATUS_REPORT_COMMIT_CHANGES) {
00531
PsChangeJobMemoryUsage (-(SSIZE_T)CommitReduction);
00532 }
00533
MM_TRACK_COMMIT (
MM_DBG_COMMIT_RETURN_NTFREEVM1,
00534 CommitReduction);
00535 Process->
CommitCharge -= CommitReduction;
00536 NextVad = (
PMMVAD)Vad;
00537 }
00538
00539 }
else {
00540
00541
if ((Vad->
u.VadFlags.UserPhysicalPages == 1) ||
00542 (Vad->
u.VadFlags.WriteWatch == 1)) {
00543
00544
00545
00546
00547
00548
00549
Status = STATUS_FREE_VM_NOT_AT_BASE;
00550
goto ErrorReturn;
00551 }
00552
00553
00554
00555
00556
00557
if (
MI_VA_TO_VPN (EndingAddress) == Vad->
EndingVpn) {
00558
00559
00560
00561
00562
00563 CommitReduction =
MiCalculatePageCommitment (
00564 StartingAddress,
00565 EndingAddress,
00566 (
PMMVAD)Vad,
00567 Process );
00568
00569 Vad->
u.VadFlags.CommitCharge -= CommitReduction;
00570
MiReturnPageFileQuota (CommitReduction, Process);
00571
MiReturnCommitment (CommitReduction);
00572
if (Process->
JobStatus &
PS_JOB_STATUS_REPORT_COMMIT_CHANGES) {
00573
PsChangeJobMemoryUsage (-(SSIZE_T)CommitReduction);
00574 }
00575
MM_TRACK_COMMIT (
MM_DBG_COMMIT_RETURN_NTFREEVM2,
00576 CommitReduction);
00577 Process->
CommitCharge -= CommitReduction;
00578
00579 Vad->
EndingVpn =
MI_VA_TO_VPN ((PCHAR)StartingAddress - 1);
00580 PreviousVad = (
PMMVAD)Vad;
00581
00582 }
else {
00583
00584
00585
00586
00587
00588
00589
00590
00591
00592
00593 NewVad =
ExAllocatePoolWithTag (
NonPagedPool,
00594
sizeof(
MMVAD_SHORT),
00595 'SdaV');
00596
if ( NewVad ==
NULL ) {
00597
Status = STATUS_INSUFFICIENT_RESOURCES;
00598
goto ErrorReturn;
00599 }
00600
00601 CommitReduction =
MiCalculatePageCommitment (
00602 StartingAddress,
00603 EndingAddress,
00604 (
PMMVAD)Vad,
00605 Process );
00606
00607 OldQuota = Vad->
u.VadFlags.CommitCharge - CommitReduction;
00608 OldEnd = Vad->
EndingVpn;
00609
00610 *NewVad = *Vad;
00611
00612 Vad->
EndingVpn =
MI_VA_TO_VPN ((PCHAR)StartingAddress - 1);
00613 NewVad->
StartingVpn =
MI_VA_TO_VPN ((PCHAR)EndingAddress + 1);
00614
00615
00616
00617
00618
00619
00620 NewVad->
u.VadFlags.CommitCharge = 0;
00621
00622
try {
00623
00624
00625
00626
00627
00628
00629
MiInsertVad ((
PMMVAD)NewVad);
00630
00631 } except (
EXCEPTION_EXECUTE_HANDLER) {
00632
00633
00634
00635
00636
00637
00638 Vad->EndingVpn = OldEnd;
00639
00640
ExFreePool (NewVad);
00641
Status = GetExceptionCode();
00642
goto ErrorReturn;
00643 }
00644
00645 Vad->u.VadFlags.CommitCharge -= CommitReduction;
00646
MiReturnPageFileQuota (CommitReduction, Process);
00647
MiReturnCommitment (CommitReduction);
00648
if (Process->
JobStatus &
PS_JOB_STATUS_REPORT_COMMIT_CHANGES) {
00649
PsChangeJobMemoryUsage (-(SSIZE_T)CommitReduction);
00650 }
00651
MM_TRACK_COMMIT (
MM_DBG_COMMIT_RETURN_NTFREEVM3,
00652 CommitReduction);
00653 Process->
CommitCharge -= CommitReduction;
00654
00655
00656
00657
00658
00659
00660
00661
00662
00663 QuotaCharge =
MiCalculatePageCommitment (
MI_VPN_TO_VA (Vad->StartingVpn),
00664 (PCHAR)StartingAddress - 1,
00665 (
PMMVAD)Vad,
00666 Process );
00667
00668 Vad->
u.VadFlags.CommitCharge = QuotaCharge;
00669
00670
00671
00672
00673
00674 NewVad->
u.VadFlags.CommitCharge = OldQuota - QuotaCharge;
00675 PreviousVad = (
PMMVAD)Vad;
00676 NextVad = (
PMMVAD)NewVad;
00677 }
00678 }
00679 }
00680
00681
00682
00683
00684
00685
MiReturnPageTablePageCommitment (StartingAddress,
00686 EndingAddress,
00687 Process,
00688 PreviousVad,
00689 NextVad);
00690
00691
if (UserPhysicalPages ==
TRUE) {
00692
MiDeletePageTablesForPhysicalRange (StartingAddress, EndingAddress);
00693 }
00694
else {
00695
00696
00697
00698
00699
00700
MiDeleteFreeVm (StartingAddress, EndingAddress);
00701 }
00702
00703
UNLOCK_WS_UNSAFE (Process);
00704
00705 CapturedRegionSize = 1 + (PCHAR)EndingAddress - (PCHAR)StartingAddress;
00706
00707
00708
00709
00710
00711 Process->
VirtualSize -= CapturedRegionSize;
00712
00713
#if defined(_MIALT4K_)
00714
if (EmulationFor4kPage ==
TRUE) {
00715
00716
goto perform_free4kpages;
00717
00718 }
00719
#endif
00720
00721
UNLOCK_ADDRESS_SPACE (Process);
00722
00723
if (Attached) {
00724
KeDetachProcess();
00725 }
00726
00727
if ( ProcessHandle != NtCurrentProcess() ) {
00728
ObDereferenceObject (Process);
00729 }
00730
00731
00732
00733
00734
00735
try {
00736
00737 *RegionSize = CapturedRegionSize;
00738 *BaseAddress = StartingAddress;
00739
00740 } except (
EXCEPTION_EXECUTE_HANDLER) {
00741
00742
00743
00744
00745
00746 }
00747
00748
#if DBG
00749
if (MmDebug &
MM_DBG_SHOW_NT_CALLS) {
00750
if ( MmWatchProcess ) {
00751
if ( MmWatchProcess ==
PsGetCurrentProcess() ) {
00752
DbgPrint(
"\n--- FREE Type 0x%lx Base %lx Size %lx\n",
00753 FreeType, StartingAddress, CapturedRegionSize);
00754 MmFooBar();
00755 }
00756 }
00757 }
00758
#endif
00759
00760
return STATUS_SUCCESS;
00761 }
00762
00763
if (Vad->
u.VadFlags.UserPhysicalPages == 1) {
00764
00765
00766
00767
00768
00769
00770
Status = STATUS_MEMORY_NOT_ALLOCATED;
00771
goto ErrorReturn;
00772 }
00773
00774
00775
00776
00777
00778
00779
00780
00781
00782
00783
00784
00785
00786
if (CapturedRegionSize == 0) {
00787
00788
if (
MI_VA_TO_VPN (CapturedBase) != Vad->
StartingVpn) {
00789
Status = STATUS_FREE_VM_NOT_AT_BASE;
00790
goto ErrorReturn;
00791 }
00792 EndingAddress =
MI_VPN_TO_VA_ENDING (Vad->
EndingVpn);
00793 }
00794
00795
#if defined(_MIALT4K_)
00796
00797 OriginalStartingAddress = StartingAddress;
00798 OriginalEndingAddress = EndingAddress;
00799
00800
if (Process->
Wow64Process !=
NULL) {
00801
00802 EmulationFor4kPage =
TRUE;
00803
00804 }
else {
00805
00806 EmulationFor4kPage =
FALSE;
00807
00808 }
00809
00810
#endif
00811
00812
#if 0
00813
if (FreeType &
MEM_CHECK_COMMIT_STATE) {
00814
if ( !
MiIsEntireRangeCommitted(StartingAddress,
00815 EndingAddress,
00816 Vad,
00817 Process)) {
00818
00819
00820
00821
00822
00823
00824
Status = STATUS_UNABLE_TO_DECOMMIT_VM;
00825
goto ErrorReturn;
00826 }
00827 }
00828
#endif //0
00829
00830
00831
00832
00833
00834
00835
00836
00837
00838 StartingPte =
MiGetPteAddress (StartingAddress);
00839 EndingPte =
MiGetPteAddress (EndingAddress);
00840
00841 CommitReduction = 1 + EndingPte - StartingPte;
00842
00843
00844
00845
00846
00847
00848 CommitReduction -=
MiDecommitPages (StartingAddress,
00849 EndingPte,
00850 Process,
00851 Vad);
00852
00853
00854
00855
00856
00857
ASSERT ((LONG)CommitReduction >= 0);
00858
MiReturnPageFileQuota (CommitReduction, Process);
00859
MiReturnCommitment (CommitReduction);
00860
MM_TRACK_COMMIT (
MM_DBG_COMMIT_RETURN_NTFREEVM4, CommitReduction);
00861 Vad->
u.VadFlags.CommitCharge -= CommitReduction;
00862
if (Process->
JobStatus &
PS_JOB_STATUS_REPORT_COMMIT_CHANGES) {
00863
PsChangeJobMemoryUsage (-(SSIZE_T)CommitReduction);
00864 }
00865 Process->
CommitCharge -= CommitReduction;
00866
ASSERT ((LONG)Vad->
u.VadFlags.CommitCharge >= 0);
00867
00868
00869
#if !(defined(_MIALT4K_))
00870
UNLOCK_WS_AND_ADDRESS_SPACE (Process);
00871
#else
00872
UNLOCK_WS_UNSAFE(Process);
00873
00874 perform_free4kpages:
00875
00876
if (EmulationFor4kPage ==
TRUE) {
00877
00878
if (FreeType & MEM_RELEASE) {
00879
00880
MiReleaseFor4kPage(OriginalStartingAddress,
00881 OriginalEndingAddress,
00882 Process);
00883
00884 }
else {
00885
00886
MiDecommitFor4kPage(OriginalStartingAddress,
00887 OriginalEndingAddress,
00888 Process);
00889
00890 }
00891
00892 StartingAddress = OriginalStartingAddress;
00893 EndingAddress = OriginalEndingAddress;
00894 }
00895
00896
UNLOCK_ADDRESS_SPACE (Process);
00897
00898
#endif
00899
00900
if (Attached) {
00901
KeDetachProcess();
00902 }
00903
if ( ProcessHandle != NtCurrentProcess() ) {
00904
ObDereferenceObject (Process);
00905 }
00906
00907
00908
00909
00910
00911
00912
try {
00913
00914 *RegionSize = 1 + (PCHAR)EndingAddress - (PCHAR)StartingAddress;
00915 *BaseAddress = StartingAddress;
00916
00917 } except (
EXCEPTION_EXECUTE_HANDLER) {
00918 NOTHING;
00919 }
00920
00921
return STATUS_SUCCESS;
00922
00923 ErrorReturn:
00924
UNLOCK_WS_AND_ADDRESS_SPACE (Process);
00925
00926
if (Attached) {
00927
KeDetachProcess();
00928 }
00929
00930
if ( ProcessHandle != NtCurrentProcess() ) {
00931
ObDereferenceObject (Process);
00932 }
00933
return Status;
00934 }
00935
00936 ULONG
00937 MiIsEntireRangeCommitted (
00938 IN PVOID StartingAddress,
00939 IN PVOID EndingAddress,
00940 IN
PMMVAD Vad,
00941 IN
PEPROCESS Process
00942 )
00943
00944
00945
00946
00947
00948
00949
00950
00951
00952
00953
00954
00955
00956
00957
00958
00959
00960
00961
00962
00963
00964
00965
00966
00967
00968
00969
00970
00971
00972
00973
00974 {
00975
PMMPTE PointerPte;
00976
PMMPTE LastPte;
00977
PMMPTE PointerPde;
00978
PMMPTE PointerPpe;
00979 ULONG FirstTime;
00980 ULONG Waited;
00981 PVOID Va;
00982
00983
PAGED_CODE();
00984
00985 FirstTime =
TRUE;
00986
00987 PointerPde =
MiGetPdeAddress (StartingAddress);
00988 PointerPte =
MiGetPteAddress (StartingAddress);
00989 LastPte =
MiGetPteAddress (EndingAddress);
00990
00991
00992
00993
00994
00995
00996
00997
00998 Va = (PVOID)((PCHAR)StartingAddress + 8);
00999
01000
while (PointerPte <= LastPte) {
01001
01002
if (
MiIsPteOnPdeBoundary(PointerPte) || (FirstTime)) {
01003
01004
01005
01006
01007
01008
01009 FirstTime =
FALSE;
01010 PointerPde =
MiGetPteAddress (PointerPte);
01011 PointerPpe =
MiGetPteAddress (PointerPde);
01012
01013
do {
01014
01015
while (!
MiDoesPpeExistAndMakeValid(PointerPpe, Process,
FALSE, &Waited)) {
01016
01017
01018
01019
01020
01021
01022 PointerPpe += 1;
01023
01024 PointerPde =
MiGetVirtualAddressMappedByPte (PointerPpe);
01025 PointerPte =
MiGetVirtualAddressMappedByPte (PointerPde);
01026 Va =
MiGetVirtualAddressMappedByPte (PointerPte);
01027
01028
if (PointerPte > LastPte) {
01029
01030
01031
01032
01033
01034
if (Vad->u.VadFlags.MemCommit == 0) {
01035
01036
01037
01038
01039
01040
01041
return FALSE;
01042 }
else {
01043
return TRUE;
01044 }
01045 }
01046
01047
01048
01049
01050
01051
if (Vad->u.VadFlags.MemCommit == 0) {
01052
01053
01054
01055
01056
01057
01058
return FALSE;
01059 }
01060 }
01061
01062 Waited = 0;
01063
01064
while (!
MiDoesPdeExistAndMakeValid(PointerPde, Process,
FALSE, &Waited)) {
01065
01066
01067
01068
01069
01070
01071 PointerPde += 1;
01072
01073 PointerPpe =
MiGetPteAddress (PointerPde);
01074 PointerPte =
MiGetVirtualAddressMappedByPte (PointerPde);
01075 Va =
MiGetVirtualAddressMappedByPte (PointerPte);
01076
01077
if (PointerPte > LastPte) {
01078
01079
01080
01081
01082
01083
if (Vad->u.VadFlags.MemCommit == 0) {
01084
01085
01086
01087
01088
01089
01090
return FALSE;
01091 }
else {
01092
return TRUE;
01093 }
01094 }
01095
01096
01097
01098
01099
01100
if (Vad->u.VadFlags.MemCommit == 0) {
01101
01102
01103
01104
01105
01106
01107
return FALSE;
01108 }
01109
#if defined (_WIN64)
01110
if (
MiIsPteOnPdeBoundary (PointerPde)) {
01111 PointerPpe =
MiGetPteAddress (PointerPde);
01112 Waited = 1;
01113
break;
01114 }
01115
#endif
01116
}
01117 }
while (Waited != 0);
01118 }
01119
01120
01121
01122
01123
01124
if (PointerPte->
u.Long == 0) {
01125
01126
01127
01128
01129
01130
if (Vad->u.VadFlags.MemCommit == 0) {
01131
01132
01133
01134
01135
01136
01137
return FALSE;
01138 }
01139 }
else {
01140
01141
01142
01143
01144
01145
if (
MiIsPteDecommittedPage (PointerPte)) {
01146
01147
01148
01149
01150
01151
return FALSE;
01152 }
01153 }
01154 PointerPte += 1;
01155 Va = (PVOID)((PCHAR)(Va) +
PAGE_SIZE);
01156 }
01157
return TRUE;
01158 }
01159
01160 ULONG
01161 MiDecommitPages (
01162 IN PVOID StartingAddress,
01163 IN
PMMPTE EndingPte,
01164 IN
PEPROCESS Process,
01165 IN
PMMVAD_SHORT Vad
01166 )
01167
01168
01169
01170
01171
01172
01173
01174
01175
01176
01177
01178
01179
01180
01181
01182
01183
01184
01185
01186
01187
01188
01189
01190
01191
01192
01193
01194
01195 {
01196
PMMPTE PointerPpe;
01197
PMMPTE PointerPde;
01198
PMMPTE PointerPte;
01199 PVOID Va;
01200 ULONG CommitReduction;
01201
PMMPTE CommitLimitPte;
01202 KIRQL OldIrql;
01203
PMMPTE ValidPteList[
MM_VALID_PTE_SIZE];
01204 ULONG count;
01205 ULONG WorkingSetIndex;
01206
PMMPFN Pfn1;
01207
PMMPFN Pfn2;
01208 PVOID SwapVa;
01209 ULONG Entry;
01210
MMWSLENTRY Locked;
01211
MMPTE PteContents;
01212 PVOID UsedPageTableHandle;
01213 PVOID UsedPageDirectoryHandle;
01214
01215 count = 0;
01216 CommitReduction = 0;
01217
01218
if (Vad->u.VadFlags.MemCommit) {
01219 CommitLimitPte =
MiGetPteAddress (
MI_VPN_TO_VA (Vad->EndingVpn));
01220 }
else {
01221 CommitLimitPte =
NULL;
01222 }
01223
01224
01225
01226
01227
01228
01229
01230
01231
01232 PointerPpe =
MiGetPpeAddress (StartingAddress);
01233 PointerPde =
MiGetPdeAddress (StartingAddress);
01234 PointerPte =
MiGetPteAddress (StartingAddress);
01235 Va = StartingAddress;
01236
01237
01238
01239
01240
01241
01242
01243
#if defined (_WIN64)
01244
MiMakePpeExistAndMakeValid (PointerPpe, Process,
FALSE);
01245
if (PointerPde->
u.Long == 0) {
01246 UsedPageDirectoryHandle =
MI_GET_USED_PTES_HANDLE (PointerPte);
01247
MI_INCREMENT_USED_PTES_BY_HANDLE (UsedPageDirectoryHandle);
01248 }
01249
#endif
01250
01251
MiMakePdeExistAndMakeValid(PointerPde, Process,
FALSE);
01252
01253
while (PointerPte <= EndingPte) {
01254
01255
if (
MiIsPteOnPdeBoundary (PointerPte)) {
01256
01257 PointerPde =
MiGetPdeAddress (Va);
01258 PointerPpe =
MiGetPpeAddress (Va);
01259
if (count != 0) {
01260
MiProcessValidPteList (&ValidPteList[0], count);
01261 count = 0;
01262 }
01263
01264
#if defined (_WIN64)
01265
MiMakePpeExistAndMakeValid (PointerPpe, Process,
FALSE);
01266
if (PointerPde->
u.Long == 0) {
01267 UsedPageDirectoryHandle =
MI_GET_USED_PTES_HANDLE (PointerPte);
01268
MI_INCREMENT_USED_PTES_BY_HANDLE (UsedPageDirectoryHandle);
01269 }
01270
#endif
01271
01272
MiMakePdeExistAndMakeValid(PointerPde, Process,
FALSE);
01273 }
01274
01275
01276
01277
01278
01279
01280
01281 PteContents = *PointerPte;
01282
01283
if (PteContents.
u.Long != 0) {
01284
01285
if (PointerPte->u.Long ==
MmDecommittedPte.
u.Long) {
01286
01287
01288
01289
01290
01291 CommitReduction += 1;
01292
01293 }
else {
01294
01295 Process->NumberOfPrivatePages -= 1;
01296
01297
if (PteContents.
u.Hard.Valid == 1) {
01298
01299
01300
01301
01302
01303 Pfn1 =
MI_PFN_ELEMENT (PteContents.
u.Hard.PageFrameNumber);
01304
01305
if (Pfn1->
u3.e1.PrototypePte) {
01306
01307
LOCK_PFN (OldIrql);
01308
MiDeletePte (PointerPte,
01309 Va,
01310
FALSE,
01311 Process,
01312
NULL,
01313
NULL);
01314
UNLOCK_PFN (OldIrql);
01315 Process->NumberOfPrivatePages += 1;
01316
MI_WRITE_INVALID_PTE (PointerPte,
MmDecommittedPte);
01317 }
else {
01318
01319
01320
01321
01322
01323
if (count ==
MM_VALID_PTE_SIZE) {
01324
MiProcessValidPteList (&ValidPteList[0], count);
01325 count = 0;
01326 }
01327 ValidPteList[count] = PointerPte;
01328 count += 1;
01329
01330
01331
01332
01333
01334
01335 WorkingSetIndex = Pfn1->
u1.WsIndex;
01336
01337
ASSERT (
PAGE_ALIGN(
MmWsle[WorkingSetIndex].u1.
Long) ==
01338 Va);
01339
01340
01341
01342
01343
01344 Locked =
MmWsle[WorkingSetIndex].
u1.e1;
01345
01346
MiRemoveWsle (WorkingSetIndex,
MmWorkingSetList);
01347
01348
01349
01350
01351
01352
01353
MiReleaseWsle (WorkingSetIndex, &Process->Vm);
01354
01355
if ((Locked.
LockedInWs == 1) || (Locked.
LockedInMemory == 1)) {
01356
01357
01358
01359
01360
01361
MmWorkingSetList->
FirstDynamic -= 1;
01362
01363
if (WorkingSetIndex !=
MmWorkingSetList->
FirstDynamic) {
01364
01365 SwapVa =
MmWsle[
MmWorkingSetList->
FirstDynamic].
u1.VirtualAddress;
01366 SwapVa =
PAGE_ALIGN (SwapVa);
01367 Pfn2 =
MI_PFN_ELEMENT (
01368
MiGetPteAddress (SwapVa)->u.Hard.PageFrameNumber);
01369
01370 Entry =
MiLocateWsle (SwapVa,
01371
MmWorkingSetList,
01372 Pfn2->
u1.WsIndex);
01373
01374
MiSwapWslEntries (Entry,
01375 WorkingSetIndex,
01376 &Process->Vm);
01377 }
01378 }
01379
MI_SET_PTE_IN_WORKING_SET (PointerPte, 0);
01380 }
01381 }
else if (PteContents.
u.Soft.Prototype) {
01382
01383
01384
01385
01386
01387
LOCK_PFN (OldIrql);
01388
MiDeletePte (PointerPte,
01389 Va,
01390
FALSE,
01391 Process,
01392
NULL,
01393
NULL);
01394
UNLOCK_PFN (OldIrql);
01395 Process->NumberOfPrivatePages += 1;
01396
MI_WRITE_INVALID_PTE (PointerPte,
MmDecommittedPte);
01397
01398 }
else if (PteContents.
u.Soft.Transition == 1) {
01399
01400
01401
01402
01403
01404
01405
LOCK_PFN (OldIrql);
01406 PteContents = *PointerPte;
01407
01408
if (PteContents.
u.Soft.Transition == 1) {
01409
01410
01411
01412
01413
01414 Pfn1 =
MI_PFN_ELEMENT (PteContents.
u.Trans.PageFrameNumber);
01415
01416
MI_SET_PFN_DELETED (Pfn1);
01417
01418
MiDecrementShareCount (Pfn1->
PteFrame);
01419
01420
01421
01422
01423
01424
01425
01426
01427
01428
if (Pfn1->
u3.e2.ReferenceCount == 0) {
01429
MiUnlinkPageFromList (Pfn1);
01430
MiReleasePageFileSpace (Pfn1->
OriginalPte);
01431
MiInsertPageInList (
MmPageLocationList[
FreePageList],
01432
MI_GET_PAGE_FRAME_FROM_TRANSITION_PTE(&PteContents));
01433 }
01434
01435 }
else {
01436
01437
01438
01439
01440
01441
ASSERT (PteContents.
u.Soft.Valid == 0);
01442
ASSERT (PteContents.
u.Soft.Prototype == 0);
01443
ASSERT (PteContents.
u.Soft.PageFileHigh != 0);
01444
MiReleasePageFileSpace (PteContents);
01445 }
01446
MI_WRITE_INVALID_PTE (PointerPte,
MmDecommittedPte);
01447
UNLOCK_PFN (OldIrql);
01448 }
else {
01449
01450
01451
01452
01453
01454
if (PteContents.
u.Soft.PageFileHigh != 0) {
01455
LOCK_PFN (OldIrql);
01456
MiReleasePageFileSpace (PteContents);
01457
UNLOCK_PFN (OldIrql);
01458 }
else {
01459
01460
01461
01462
01463
01464
01465 Process->NumberOfPrivatePages += 1;
01466 }
01467
01468
MI_WRITE_INVALID_PTE (PointerPte,
MmDecommittedPte);
01469 }
01470 }
01471
01472 }
else {
01473
01474
01475
01476
01477
01478
01479
01480
01481
01482
01483 UsedPageTableHandle =
MI_GET_USED_PTES_HANDLE (Va);
01484
01485
MI_INCREMENT_USED_PTES_BY_HANDLE (UsedPageTableHandle);
01486
01487
if (PointerPte > CommitLimitPte) {
01488
01489
01490
01491
01492
01493 CommitReduction += 1;
01494 }
01495
MI_WRITE_INVALID_PTE (PointerPte,
MmDecommittedPte);
01496 }
01497
01498 PointerPte += 1;
01499 Va = (PVOID)((PCHAR)Va +
PAGE_SIZE);
01500 }
01501
if (count != 0) {
01502
MiProcessValidPteList (&ValidPteList[0], count);
01503 }
01504
01505
return CommitReduction;
01506 }
01507
01508
01509
VOID
01510 MiProcessValidPteList (
01511 IN
PMMPTE *ValidPteList,
01512 IN ULONG Count
01513 )
01514
01515
01516
01517
01518
01519
01520
01521
01522
01523
01524
01525
01526
01527
01528
01529
01530
01531
01532
01533
01534
01535
01536
01537
01538 {
01539 ULONG i = 0;
01540
MMPTE_FLUSH_LIST PteFlushList;
01541
MMPTE PteContents;
01542
PMMPFN Pfn1;
01543 KIRQL OldIrql;
01544
01545 PteFlushList.
Count =
Count;
01546
01547
LOCK_PFN (OldIrql);
01548
01549
do {
01550 PteContents = *ValidPteList[i];
01551
ASSERT (PteContents.
u.Hard.Valid == 1);
01552 Pfn1 =
MI_PFN_ELEMENT (PteContents.
u.Hard.PageFrameNumber);
01553
01554
01555
01556
01557
01558
01559
MiDecrementShareAndValidCount (Pfn1->
PteFrame);
01560
01561
MI_SET_PFN_DELETED (Pfn1);
01562
01563
01564
01565
01566
01567
01568
MiDecrementShareCountOnly (
MI_GET_PAGE_FRAME_FROM_PTE (&PteContents));
01569
01570
if (
Count <
MM_MAXIMUM_FLUSH_COUNT) {
01571 PteFlushList.
FlushPte[i] = ValidPteList[i];
01572 PteFlushList.
FlushVa[i] =
01573
MiGetVirtualAddressMappedByPte (ValidPteList[i]);
01574 }
01575 *ValidPteList[i] =
MmDecommittedPte;
01576 i += 1;
01577 }
while (i !=
Count);
01578
01579
MiFlushPteList (&PteFlushList,
FALSE,
MmDecommittedPte);
01580
UNLOCK_PFN (OldIrql);
01581
return;
01582 }
01583
01584
01585
VOID
01586 MiDeleteFreeVm (
01587 IN PVOID StartingAddress,
01588 IN PVOID EndingAddress
01589 )
01590
01591
01592
01593
01594
01595
01596
01597
01598
01599
01600
01601
01602
01603
01604
01605
01606
01607
01608
01609
01610
01611
01612 {
01613 KIRQL OldIrql;
01614
01615
LOCK_PFN (OldIrql);
01616
01617
01618
01619
01620
01621
MiDeleteVirtualAddresses (StartingAddress,
01622 EndingAddress,
01623
FALSE,
01624 (
PMMVAD)
NULL);
01625
01626
UNLOCK_PFN (OldIrql);
01627
01628 }
01629