IoCaptureLiveDump
VOID __fastcall IoCaptureLiveDump(UINT64 BugcheckCode, UINT64 BugcheckParameter1, INT64 a3, INT64 a4){
INT64 v5;
_KEVENT *v7;
_EX_RUNDOWN_REF *v8;
INT64 v9;
INT64 v10;
_ETHREAD *CurrentThread;
NTSTATUS inited;
VOID *v13;
VOID *v14;
UINT64 v15;
_EX_HOST *v16;
void(__fastcall **ExtensionTable)(__int64);
__int64 v18;
INT64 v19;
INT64 v20;
INT64 v21;
INT64 v22;
_KEVENT *v23;
INT64 v24;
INT64 v25;
VOID **PoolWithTag;
int v27;
_KEVENT *v28;
UINT64 v29;
INT64 v30;
int v31;
_IO_LIVEDUMP_CONTROL *v32;
_BYTE *v33;
int v34;
__int64 v35;
NTSTATUS v36;
__int64 v37;
__int64 v38;
INT64 v39;
UINT64 v40;
_IO_LIVEDUMP_CONTROL v41;
const _GUID *v42;
const _GUID *v43;
INT64 a5;
INT64 a5a;
INT64 a5b;
INT64 a6;
INT64 a6a;
INT64 a6b;
INT64 a7;
VOID *EventHandle;
VOID *Handle;
UINT64 v53;
int v54;
int v55;
__int64 v56;
_IO_LIVEDUMP_CONTROL *DestinationString[3];
_KEVENT *v58;
_KEVENT *NotificationEvent;
INT64 v60;
__int64 v61;
unsigned __int64 v62;
__int64 v63;
unsigned __int64 v64;
__int128 v65;
_EVENT_DATA_DESCRIPTOR v66;
__int64 *v67;
__int64 v68;
INT64 *p_a7;
__int64 v70;
__int64 v71;
__int64 v72;
unsigned __int64 *v73;
__int64 v74;
_EVENT_DATA_DESCRIPTOR v75;
__int64 *v76;
__int64 v77;
unsigned __int64 *v78;
__int64 v79;
INT64 v80[2];
int *v81;
int v82;
int v83;
__int64 v84;
_IO_LIVEDUMP_CONTROL *v85;
INT64 *v86;
DestinationString[0] = v85;
v5 = a3;
v54 = BugcheckCode;
v60 = a3;
*(_OWORD *)&DestinationString[1] = 0i64;
EventHandle = 0i64;
v7 = 0i64;
v8 = 0i64;
v63 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
v9 = 0i64;
Handle = 0i64;
v53 = 0i64;
v58 = 0i64;
NotificationEvent = 0i64;
v65 = 0i64;
if( *(&stru_140CF2E80 + 4800) )
{
if( v86 )
*v86 = 0i64;
return;
}
if( (_DWORD)BufferChunkSizeInBytes != KUSER_SHARED_DATA.LargePageMinimum )
{
LODWORD(BufferChunkSizeInBytes) = KUSER_SHARED_DATA.LargePageMinimum;
LODWORD(BufferChunkSizeInPages) = KUSER_SHARED_DATA.LargePageMinimum >> 12;
}
IopLiveDumpTraceInterfaceStart(0i64);
if( v86 )
*v86 = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
LOBYTE(a7) = ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 704, 0, v10);
if( (_BYTE)a7 != 1 )
{
inited = -1073741267;
LABEL_11:
v13 = EventHandle;
v14 = Handle;
v15 = v53;
goto LABEL_37;
}
LODWORD(v16) = KeGetSupervisorStateExtensionHost();
v8 = (_EX_RUNDOWN_REF *)v16;
if( v16 )
{
ExtensionTable = (void(__fastcall **)(__int64))ExGetExtensionTable(v16);
IptInterface = (__int64)ExtensionTable;
if( !ExtensionTable )
goto LABEL_17;
LOBYTE(v18) = 1;
(*ExtensionTable)(v18);
if( !(*(unsigned __int8(**)(void))(IptInterface + 8))() )
{
(*(void(__fastcall **)(_QWORD))IptInterface)(0i64);
ExReleaseExtensionTable(v8);
IptInterface = 0i64;
}
if( !IptInterface )
LABEL_17:
v8 = 0i64;
}
if( (DestinationString[0][6] & 0x10) != 0 )
{
RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\LowNonPagedPoolCondition");
v7 = IoCreateNotificationEvent(
(_UNICODE_STRING *)&DestinationString[1],
&EventHandle,
v19,
v20,
a5,
a6,
a7,
(INT64)EventHandle);
RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\LowMemoryCondition");
v58 = IoCreateNotificationEvent(
(_UNICODE_STRING *)&DestinationString[1],
&Handle,
v21,
v22,
a5a,
a6a,
a7,
(INT64)EventHandle);
v23 = v58;
RtlInitUnicodeString((PUNICODE_STRING)&DestinationString[1], L"\\KernelObjects\\HighCommitCondition");
NotificationEvent = IoCreateNotificationEvent(
(_UNICODE_STRING *)&DestinationString[1],
(VOID **)&v53,
v24,
v25,
a5b,
a6b,
a7,
(INT64)EventHandle);
if( IopLiveDumpIsUnderMemoryPressure(v7, v23) )
{
inited = -1073741248;
goto LABEL_11;
}
v5 = v60;
}
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, 0x430ui64, 1886217292i64);
v9 = (INT64)PoolWithTag;
if( !PoolWithTag )
{
inited = -1073741670;
goto LABEL_11;
}
memset(PoolWithTag, 0i64, 0x430u);
v27 = v54;
*(_DWORD *)(v9 + 80) &= 0xFFFFFFF3;
*(_DWORD *)v9 = v27;
*(_QWORD *)(v9 + 32) = v84;
*(_QWORD *)(v9 + 800) = EventHandle;
*(_QWORD *)(v9 + 808) = Handle;
*(_QWORD *)(v9 + 816) = v53;
*(_QWORD *)(v9 + 832) = v58;
v28 = NotificationEvent;
*(_QWORD *)(v9 + 8) = BugcheckParameter1;
v14 = 0i64;
*(_QWORD *)(v9 + 16) = v5;
v13 = 0i64;
*(_QWORD *)(v9 + 24) = a4;
v15 = 0i64;
*(_QWORD *)(v9 + 840) = v28;
IopLiveDumpContext = (_GUID *)v9;
*(_QWORD *)(v9 + 824) = v7;
IopLiveDumpInitRegistrySettings(v9);
if( (*(_DWORD *)(v9 + 80) & 0x200) != 0 && !*(_QWORD *)(v9 + 1048) )
goto LABEL_26;
EtwActivityIdControl(5ui64, (_GUID *)(v9 + 848));
EtwActivityIdControl(1ui64, (_GUID *)(v9 + 864));
if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
{
v31 = *(_DWORD *)(v9 + 1040);
v83 = 0;
v55 = v31;
v82 = 4;
v81 = &v55;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&dword_140C04498,
(unsigned __int8 *)&word_1400237BE,
(const _GUID *)(v9 + 864),
(const _GUID *)(v9 + 848),
3u,
(PEVENT_DATA_DESCRIPTOR)v80);
}
inited = IopLiveDumpValidateParameters(
(_LIVEDUMP_CONTEXT *)v9,
DestinationString[0],
v29,
v30,
a5,
a6,
a7,
(INT64)EventHandle);
if( inited < 0 )
goto LABEL_37;
if( (*(_DWORD *)(v9 + 80) & 0x80u) != 0 )
{
KeQueryPerformanceCounter((_LARGE_INTEGER *)&stru_140C452E0 + 85);
IopLiveDumpGetMillisecondCounter(1);
}
if( (*(_DWORD *)(v9 + 40) & 8) != 0 && !v86 )
{
LABEL_26:
inited = -1073741811;
}
else
{
inited = IopLiveDumpAllocAndInitResources((_LIVEDUMP_CONTEXT *)v9);
if( inited >= 0 )
inited = IopLiveDumpCaptureMemoryPages((_LIVEDUMP_CONTEXT *)v9);
}
LABEL_37:
if( IptInterface )
{
(*(void(__fastcall **)(_QWORD))IptInterface)(0i64);
ExReleaseExtensionTable(v8);
IptInterface = 0i64;
}
if( v13 )
ZwClose((_HANDLE)v13);
if( v14 )
ZwClose((_HANDLE)v14);
if( v15 )
ZwClose(v15);
v32 = DestinationString[0];
if( (DestinationString[0][6] & 0x10) != 0 && inited == -1073741248 && IopLiveDumpIsTracingEnabled() == 1 )
EtwWrite(*(&stru_140CF2E80 + 602), &LIVEDUMP_EVENT_MEMORY_PRESSURE_ABORT, 0, 0, 0i64);
if( (_BYTE)a7 )
{
IopLiveDumpContext = 0i64;
ExReleaseResourceLite((PERESOURCE)((char *)&stru_140C452E0 + 704));
}
KeLeaveCriticalRegion();
if( inited >= 0 )
{
inited = SecureDump_GetSecureDumpSettings(v9 + 880);
if( inited >= 0 )
{
if( *v33 )
{
v34 = *(_DWORD *)(v9 + 888);
if( !v34 || !*(_BYTE *)(v9 + 881) || *(_DWORD *)(v9 + 884) != 4096 || (v34 & 0xFFF) != 0 )
inited = -1073741823;
}
if( inited >= 0 )
{
if( (*(_DWORD *)(v9 + 40) & 8) != 0 )
{
inited = -1073741802;
*v86 = v9;
}
else
{
IopLiveDumpTrace();
v35 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
if( *(_QWORD *)(v9 + 192) || *(_QWORD *)(v9 + 200) )
v36 = IopLiveDumpWriteDumpFileWithExtraPages(v9);
else
v36 = IopLiveDumpWriteDumpFile((_LIVEDUMP_CONTEXT *)v9);
inited = v36;
if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
{
v37 = *(_QWORD *)(v9 + 560);
v77 = 8i64;
v38 = *(_QWORD *)(v37 + 4000);
v76 = &v61;
v61 = v38;
v79 = 8i64;
v78 = &v62;
v62 = (*(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart - v35) / 0x2710ui64;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&dword_140C04498,
(unsigned __int8 *)byte_140023905,
(const _GUID *)(v9 + 864),
(const _GUID *)(v9 + 848),
4u,
&v75);
}
IopLiveDumpTraceDumpFileWriteEnd((_LIVEDUMP_CONTEXT *)v9, 0i64, (unsigned int)inited);
if( inited >= 0 && (*(_DWORD *)(v9 + 80) & 2) != 0 )
inited = 261;
}
}
}
}
IopLiveDumpTraceInterfaceEnd((UINT64)v33, 0i64, (unsigned int)inited);
if( (unsigned int)dword_140C04498 > 5 && tlgKeywordOn((__int64)&dword_140C04498, 0x200000000000i64) )
{
v41 = v32[6];
v67 = &v56;
v42 = (const _GUID *)(v9 + 848);
LODWORD(v56) = inited;
LOBYTE(a7) = (v41 & 8) != 0;
BYTE1(a7) = (v41 & 0x10) != 0;
p_a7 = &a7;
v71 = (__int64)&a7 + 1;
v68 = 4i64;
v70 = 1i64;
v72 = 1i64;
v74 = 8i64;
v64 = (*(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart - v63) / 0x2710ui64;
v73 = &v64;
if( v9 )
{
v43 = (const _GUID *)(v9 + 864);
}
else
{
v42 = (const _GUID *)&v65;
v43 = (const _GUID *)&v65;
}
tlgWriteTransfer_EtwWriteTransfer((__int64)&dword_140C04498, (unsigned __int8 *)&word_14002388E, v43, v42, 6u, &v66);
}
if( v9 )
{
if( (*(_DWORD *)(v9 + 40) & 8) == 0 )
EtwActivityIdControl(2ui64, (_GUID *)(v9 + 848));
if( inited != -1073741802 )
{
IopLiveDumpReleaseResources(v9, v39, v40);
ExFreePoolWithTag((PVOID)v9, 0x706D644Cu);
}
}
}Referenced by:
DbgkCaptureLiveKernelDump
DbgkpWerCaptureLiveFullDump