IoCaptureLiveDump

VOID __fastcall IoCaptureLiveDump(UINT64 BugcheckCode, UINT64 BugcheckParameter1, INT64 a3, INT64 a4){
  INT64 v5; 
  _KEVENT *v7; 
  _EX_RUNDOWN_REF *v8; 
  INT64 v9; 
  INT64 v10; 
  _ETHREAD *CurrentThread; 
  NTSTATUS inited; 
  VOID *v13; 
  VOID *v14; 
  UINT64 v15; 
  _EX_HOST *v16; 
  void(__fastcall **ExtensionTable)(__int64); 
  __int64 v18; 
  INT64 v19; 
  INT64 v20; 
  INT64 v21; 
  INT64 v22; 
  _KEVENT *v23; 
  INT64 v24; 
  INT64 v25; 
  VOID **PoolWithTag; 
  int v27; 
  _KEVENT *v28; 
  UINT64 v29; 
  INT64 v30; 
  int v31; 
  _IO_LIVEDUMP_CONTROL *v32; 
  _BYTE *v33; 
  int v34; 
  __int64 v35; 
  NTSTATUS v36; 
  __int64 v37; 
  __int64 v38; 
  INT64 v39; 
  UINT64 v40; 
  _IO_LIVEDUMP_CONTROL v41; 
  const _GUID *v42; 
  const _GUID *v43; 
  INT64 a5; 
  INT64 a5a; 
  INT64 a5b; 
  INT64 a6; 
  INT64 a6a; 
  INT64 a6b; 
  INT64 a7; 
  VOID *EventHandle; 
  VOID *Handle; 
  UINT64 v53; 
  int v54; 
  int v55; 
  __int64 v56; 
  _IO_LIVEDUMP_CONTROL *DestinationString[3]; 
  _KEVENT *v58; 
  _KEVENT *NotificationEvent; 
  INT64 v60; 
  __int64 v61; 
  unsigned __int64 v62; 
  __int64 v63; 
  unsigned __int64 v64; 
  __int128 v65; 
  _EVENT_DATA_DESCRIPTOR v66; 
  __int64 *v67; 
  __int64 v68; 
  INT64 *p_a7; 
  __int64 v70; 
  __int64 v71; 
  __int64 v72; 
  unsigned __int64 *v73; 
  __int64 v74; 
  _EVENT_DATA_DESCRIPTOR v75; 
  __int64 *v76; 
  __int64 v77; 
  unsigned __int64 *v78; 
  __int64 v79; 
  INT64 v80[2]; 
  int *v81; 
  int v82; 
  int v83; 
  __int64 v84; 
  _IO_LIVEDUMP_CONTROL *v85; 
  INT64 *v86; 

  DestinationString[0] = v85;
  v5 = a3;
  v54 = BugcheckCode;
  v60 = a3;
  *(_OWORD *)&DestinationString[1] = 0i64;
  EventHandle = 0i64;
  v7 = 0i64;
  v8 = 0i64;
  v63 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
  v9 = 0i64;
  Handle = 0i64;
  v53 = 0i64;
  v58 = 0i64;
  NotificationEvent = 0i64;
  v65 = 0i64;
  if( *(&stru_140CF2E80 + 4800) )
  {
    if( v86 )
      *v86 = 0i64;
    return;
  }
  if( (_DWORD)BufferChunkSizeInBytes != KUSER_SHARED_DATA.LargePageMinimum )
  {
    LODWORD(BufferChunkSizeInBytes) = KUSER_SHARED_DATA.LargePageMinimum;
    LODWORD(BufferChunkSizeInPages) = KUSER_SHARED_DATA.LargePageMinimum >> 12;
  }
  IopLiveDumpTraceInterfaceStart(0i64);
  if( v86 )
    *v86 = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  LOBYTE(a7) = ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 704, 0, v10);
  if( (_BYTE)a7 != 1 )
  {
    inited = -1073741267;
LABEL_11:
    v13 = EventHandle;
    v14 = Handle;
    v15 = v53;
    goto LABEL_37;
  }
  LODWORD(v16) = KeGetSupervisorStateExtensionHost();
  v8 = (_EX_RUNDOWN_REF *)v16;
  if( v16 )
  {
    ExtensionTable = (void(__fastcall **)(__int64))ExGetExtensionTable(v16);
    IptInterface = (__int64)ExtensionTable;
    if( !ExtensionTable )
      goto LABEL_17;
    LOBYTE(v18) = 1;
    (*ExtensionTable)(v18);
    if( !(*(unsigned __int8(**)(void))(IptInterface + 8))() )
    {
      (*(void(__fastcall **)(_QWORD))IptInterface)(0i64);
      ExReleaseExtensionTable(v8);
      IptInterface = 0i64;
    }
    if( !IptInterface )
LABEL_17:
      v8 = 0i64;
  }
  if( (DestinationString[0][6] & 0x10) != 0 )
  {
    RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\LowNonPagedPoolCondition");
    v7 = IoCreateNotificationEvent(
           (_UNICODE_STRING *)&DestinationString[1],
           &EventHandle,
           v19,
           v20,
           a5,
           a6,
           a7,
           (INT64)EventHandle);
    RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\LowMemoryCondition");
    v58 = IoCreateNotificationEvent(
            (_UNICODE_STRING *)&DestinationString[1],
            &Handle,
            v21,
            v22,
            a5a,
            a6a,
            a7,
            (INT64)EventHandle);
    v23 = v58;
    RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\HighCommitCondition");
    NotificationEvent = IoCreateNotificationEvent(
                          (_UNICODE_STRING *)&DestinationString[1],
                          (VOID **)&v53,
                          v24,
                          v25,
                          a5b,
                          a6b,
                          a7,
                          (INT64)EventHandle);
    if( IopLiveDumpIsUnderMemoryPressure(v7, v23) )
    {
      inited = -1073741248;
      goto LABEL_11;
    }
    v5 = v60;
  }
  PoolWithTag = ExAllocatePoolWithTag(0x200ui64, 0x430ui64, 1886217292i64);
  v9 = (INT64)PoolWithTag;
  if( !PoolWithTag )
  {
    inited = -1073741670;
    goto LABEL_11;
  }
  memset(PoolWithTag, 0i64, 0x430u);
  v27 = v54;
  *(_DWORD *)(v9 + 80) &= 0xFFFFFFF3;
  *(_DWORD *)v9 = v27;
  *(_QWORD *)(v9 + 32) = v84;
  *(_QWORD *)(v9 + 800) = EventHandle;
  *(_QWORD *)(v9 + 808) = Handle;
  *(_QWORD *)(v9 + 816) = v53;
  *(_QWORD *)(v9 + 832) = v58;
  v28 = NotificationEvent;
  *(_QWORD *)(v9 + 8) = BugcheckParameter1;
  v14 = 0i64;
  *(_QWORD *)(v9 + 16) = v5;
  v13 = 0i64;
  *(_QWORD *)(v9 + 24) = a4;
  v15 = 0i64;
  *(_QWORD *)(v9 + 840) = v28;
  IopLiveDumpContext = (_GUID *)v9;
  *(_QWORD *)(v9 + 824) = v7;
  IopLiveDumpInitRegistrySettings(v9);
  if( (*(_DWORD *)(v9 + 80) & 0x200) != 0 && !*(_QWORD *)(v9 + 1048) )
    goto LABEL_26;
  EtwActivityIdControl(5ui64, (_GUID *)(v9 + 848));
  EtwActivityIdControl(1ui64, (_GUID *)(v9 + 864));
  if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
  {
    v31 = *(_DWORD *)(v9 + 1040);
    v83 = 0;
    v55 = v31;
    v82 = 4;
    v81 = &v55;
    tlgWriteTransfer_EtwWriteTransfer(
      (__int64)&dword_140C04498,
      (unsigned __int8 *)&word_1400237BE,
      (const _GUID *)(v9 + 864),
      (const _GUID *)(v9 + 848),
      3u,
      (PEVENT_DATA_DESCRIPTOR)v80);
  }
  inited = IopLiveDumpValidateParameters(
             (_LIVEDUMP_CONTEXT *)v9,
             DestinationString[0],
             v29,
             v30,
             a5,
             a6,
             a7,
             (INT64)EventHandle);
  if( inited < 0 )
    goto LABEL_37;
  if( (*(_DWORD *)(v9 + 80) & 0x80u) != 0 )
  {
    KeQueryPerformanceCounter((_LARGE_INTEGER *)&stru_140C452E0 + 85);
    IopLiveDumpGetMillisecondCounter(1);
  }
  if( (*(_DWORD *)(v9 + 40) & 8) != 0 && !v86 )
  {
LABEL_26:
    inited = -1073741811;
  }
  else
  {
    inited = IopLiveDumpAllocAndInitResources((_LIVEDUMP_CONTEXT *)v9);
    if( inited >= 0 )
      inited = IopLiveDumpCaptureMemoryPages((_LIVEDUMP_CONTEXT *)v9);
  }
LABEL_37:
  if( IptInterface )
  {
    (*(void(__fastcall **)(_QWORD))IptInterface)(0i64);
    ExReleaseExtensionTable(v8);
    IptInterface = 0i64;
  }
  if( v13 )
    ZwClose((_HANDLE)v13);
  if( v14 )
    ZwClose((_HANDLE)v14);
  if( v15 )
    ZwClose(v15);
  v32 = DestinationString[0];
  if( (DestinationString[0][6] & 0x10) != 0 && inited == -1073741248 && IopLiveDumpIsTracingEnabled() == 1 )
    EtwWrite(*(&stru_140CF2E80 + 602), &LIVEDUMP_EVENT_MEMORY_PRESSURE_ABORT, 0, 0, 0i64);
  if( (_BYTE)a7 )
  {
    IopLiveDumpContext = 0i64;
    ExReleaseResourceLite((PERESOURCE)((char *)&stru_140C452E0 + 704));
  }
  KeLeaveCriticalRegion();
  if( inited >= 0 )
  {
    inited = SecureDump_GetSecureDumpSettings(v9 + 880);
    if( inited >= 0 )
    {
      if( *v33 )
      {
        v34 = *(_DWORD *)(v9 + 888);
        if( !v34 || !*(_BYTE *)(v9 + 881) || *(_DWORD *)(v9 + 884) != 4096 || (v34 & 0xFFF) != 0 )
          inited = -1073741823;
      }
      if( inited >= 0 )
      {
        if( (*(_DWORD *)(v9 + 40) & 8) != 0 )
        {
          inited = -1073741802;
          *v86 = v9;
        }
        else
        {
          IopLiveDumpTrace();
          v35 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
          if( *(_QWORD *)(v9 + 192) || *(_QWORD *)(v9 + 200) )
            v36 = IopLiveDumpWriteDumpFileWithExtraPages(v9);
          else
            v36 = IopLiveDumpWriteDumpFile((_LIVEDUMP_CONTEXT *)v9);
          inited = v36;
          if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
          {
            v37 = *(_QWORD *)(v9 + 560);
            v77 = 8i64;
            v38 = *(_QWORD *)(v37 + 4000);
            v76 = &v61;
            v61 = v38;
            v79 = 8i64;
            v78 = &v62;
            v62 = (*(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart - v35) / 0x2710ui64;
            tlgWriteTransfer_EtwWriteTransfer(
              (__int64)&dword_140C04498,
              (unsigned __int8 *)byte_140023905,
              (const _GUID *)(v9 + 864),
              (const _GUID *)(v9 + 848),
              4u,
              &v75);
          }
          IopLiveDumpTraceDumpFileWriteEnd((_LIVEDUMP_CONTEXT *)v9, 0i64, (unsigned int)inited);
          if( inited >= 0 && (*(_DWORD *)(v9 + 80) & 2) != 0 )
            inited = 261;
        }
      }
    }
  }
  IopLiveDumpTraceInterfaceEnd((UINT64)v33, 0i64, (unsigned int)inited);
  if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
  {
    v41 = v32[6];
    v67 = &v56;
    v42 = (const _GUID *)(v9 + 848);
    LODWORD(v56) = inited;
    LOBYTE(a7) = (v41 & 8) != 0;
    BYTE1(a7) = (v41 & 0x10) != 0;
    p_a7 = &a7;
    v71 = (__int64)&a7 + 1;
    v68 = 4i64;
    v70 = 1i64;
    v72 = 1i64;
    v74 = 8i64;
    v64 = (*(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart - v63) / 0x2710ui64;
    v73 = &v64;
    if( v9 )
    {
      v43 = (const _GUID *)(v9 + 864);
    }
    else
    {
      v42 = (const _GUID *)&v65;
      v43 = (const _GUID *)&v65;
    }
    tlgWriteTransfer_EtwWriteTransfer((__int64)&dword_140C04498, (unsigned __int8 *)&word_14002388E, v43, v42, 6u, &v66);
  }
  if( v9 )
  {
    if( (*(_DWORD *)(v9 + 40) & 8) == 0 )
      EtwActivityIdControl(2ui64, (_GUID *)(v9 + 848));
    if( inited != -1073741802 )
    {
      IopLiveDumpReleaseResources(v9, v39, v40);
      ExFreePoolWithTag((PVOID)v9, 0x706D644Cu);
    }
  }
}

Referenced by:

DbgkCaptureLiveKernelDump
DbgkpWerCaptureLiveFullDump