RtlApplyHotPatch
NTSTATUS __stdcall RtlApplyHotPatch(
INT64 a1,
INT64 a2,
INT64 a3,
INT64 a4,
INT64 a5,
INT8 a6,
INT64 a7,
INT64 a8,
INT64 a9,
INT64 a10,
INT64 a11,
INT64 a12,
INT64 a13,
INT64 a14,
INT64 a15,
PRTL_BITMAP BitMapHeader,
INT64 a17,
INT64 a18,
INT64 a19,
INT64 a20,
INT64 a21){
UINT8 *v21;
__int128 *v22;
unsigned int *v23;
INT64 v24;
INT64 v25;
PRTL_BITMAP v26;
int HotPatchSize;
__int128 *v28;
INT64 v29;
int v30;
int v31;
INT64 v32;
int v33;
int v34;
int v35;
__int64(__fastcall *v36)(__int64, _QWORD, _QWORD, INT8 *);
NTSTATUS result;
unsigned __int64 v38;
_QWORD *v39;
_BYTE *v40;
_QWORD *v41;
_WORD *v42;
__int64 v43;
_DWORD *v44;
INT64 v45;
_QWORD *v46;
int v47;
__int64 v48;
int v49;
UINT64 i;
unsigned int v51;
unsigned int ClearBitsAndSet;
VOID *v53;
_TABLE_SEARCH_RESULT v54;
INT64 v55;
__int64 v56;
INT64 v57;
int v58;
__int128 *v59;
__int128 v60;
__int64 v61;
int v65;
v65 = a4;
LODWORD(a20) = 0;
LODWORD(a19) = 0;
v56 = 0i64;
a21 = 0i64;
LODWORD(a7) = 0;
v21 = (UINT8 *)a2;
v58 = 0;
v22 = &v60;
v57 = 0i64;
v23 = (unsigned int *)a14;
v24 = a1;
v25 = a17;
v26 = BitMapHeader;
v61 = 0i64;
a6 = 0;
v60 = 0i64;
if( a18 )
v22 = (__int128 *)a18;
v59 = v22;
v55 = 0i64;
if( !a14 )
goto LABEL_46;
HotPatchSize = RtlGetHotPatchSize((_DWORD *)a13);
LODWORD(a18) = HotPatchSize;
while( 1 )
{
v31 = *v23;
if( !*v23 )
break;
v32 = 0i64;
LOBYTE(v33) = 0;
if( v31 < 0 )
{
if( (a15 & 2) != 0 )
{
v29 = v24;
v32 = a8;
v56 = *((_QWORD *)v28 + 2);
a21 = a10;
LODWORD(a7) = a11;
v58 = a9;
v55 = v24;
v57 = (INT64)v21;
}
}
else
{
v33 = a15 & 1;
if( (a15 & 1) != 0 )
{
v29 = a8;
v56 = *((_QWORD *)v28 + 1);
a21 = a3;
v57 = a9;
LODWORD(a7) = v30;
v58 = (int)v21;
v55 = a8;
}
HotPatchSize = a18;
v32 = v24 & -(__int64)(v33 != 0);
}
++v23;
v34 = v31 & 0xFC000;
v35 = v31 & 0xFFF;
if( !v32 )
{
v23 += (unsigned int)(v35 * HotPatchSize);
goto LABEL_42;
}
if( v35 )
{
while( 1 )
{
if( *(_QWORD *)v28 )
{
RtlpDetermineHotPatchExtent(v34, &a19, &a20);
result = v36(v56, (unsigned int)a19 + *v23, (unsigned int)a20, &a6);
if( result < 0 )
return result;
if( !a6 )
goto LABEL_40;
v29 = v55;
}
v38 = v23[1];
v39 = (_QWORD *)(v32 + *v23);
switch( v34 )
{
case 114688:
v40 = 0i64;
if( (_DWORD)a18 != 2 )
v40 = v23 + 2;
LODWORD(v41) = RtlpCheckFunctionPatchAppliedInOriginalImage((_BYTE *)(v32 + *v23), v40);
if( v41 == (_QWORD *)-1i64 )
return -1073741800;
if( v41 )
{
v45 = ((__int64)v41 - a21) >> 3;
*v41 = v43;
}
else
{
v45 = (unsigned int)*v44;
if( (unsigned int)v45 >= (unsigned int)a7 )
return -1073740628;
v46 = (_QWORD *)(a21 + 8 * v45);
*v46 = v43;
v47 = v58 + (_DWORD)v46 - v32;
if( v25 && (_BYTE)v33 )
{
v48 = 3 * v45;
*(_DWORD *)(v25 + 2 * v48) = *v23;
*(_WORD *)(v25 + 2 * v48 + 4) = *v42;
}
v49 = v58 + *v23;
*(v42 - 3) = 9727;
*v42 = -1813;
*((_DWORD *)v42 - 1) = v47 - v49;
++*v44;
}
if( v26 && (_BYTE)v33 )
_bittestandset((signed __int32 *)v26->Buffer, v45);
break;
case 180224:
*v39 = v38 + v57;
break;
case 376832:
*v39 = *(_QWORD *)(v38 + v29);
break;
default:
if( v34 == 491520 && *(_BYTE *)v38 == 0xFF )
*v39 += *(_QWORD *)(8 * v38);
break;
}
LABEL_40:
--v35;
v28 = v59;
v29 = v55;
v23 += (unsigned int)a18;
if( !v35 )
{
v21 = (UINT8 *)a2;
v30 = v65;
break;
}
}
}
LABEL_42:
v24 = a1;
if( !v23 )
break;
HotPatchSize = a18;
}
LABEL_46:
if( v26 )
{
for( i = 0i64; ; i = ClearBitsAndSet )
{
ClearBitsAndSet = (unsigned int)RtlFindClearBitsAndSet((_RTL_AVL_TABLE *)v26, (VOID *)1, i, v21, v53, v54);
if( ClearBitsAndSet == -1 )
break;
v51 = *(_DWORD *)(v25 + 6i64 * ClearBitsAndSet);
if( v51 )
{
*(_WORD *)(v51 + v24) = *(_WORD *)(v25 + 6i64 * ClearBitsAndSet + 4);
*(_DWORD *)(v25 + 6i64 * ClearBitsAndSet) = 0;
}
}
}
return 0;
}Referenced by:
MiApplyDriverHotPatch
MiApplyImageHotPatch
MiApplyImageHotPatchDpc
MiPerformImageHotPatch