RtlpxLookupFunctionTable
_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *__stdcall RtlpxLookupFunctionTable(
VOID *ControlPc,
_INVERTED_FUNCTION_TABLE_ENTRY *FunctionTableInfo){
_IMAGE_RUNTIME_FUNCTION_ENTRY *FunctionTable;
int *v5;
int v6;
unsigned int v7;
int v8;
int v9;
int v10;
void *v11;
int *v12;
unsigned __int64 v13;
unsigned int v14;
_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *result;
int v16;
__int64 v17;
unsigned int v18;
unsigned int v19;
int v20;
int v21;
void *v22;
int *v23;
unsigned __int64 v24;
unsigned int v25;
INT64 v26;
void *v27;
unsigned __int64 v28;
unsigned __int8 v29;
int v30;
unsigned int v31;
FunctionTable = 0i64;
v29 = 0;
FunctionTableInfo->ImageBase = 0i64;
FunctionTableInfo->SizeOfImage = 0;
v5 = RtlpInvertedFunctionTable[0];
v6 = RtlpInvertedFunctionTable[0][2];
if( (v6 & 1) != 0 )
{
v16 = 1;
v14 = 4096;
v30 = 1;
LABEL_29:
MmLockLoadedModuleListShared(&v29);
if( *RtlpInvertedFunctionTable[0] != 1 )
{
if( (KiSpeculationFeatures & 0x2000000) != 0 )
{
v18 = dword_140C4C9F0;
v19 = 4096;
}
else
{
v18 = 0;
v19 = 0;
}
v20 = *RtlpInvertedFunctionTable[0] - 1;
if( v20 >= 1 )
{
do
{
v21 = (v20 + v16) >> 1;
v22 = *(void **)&RtlpInvertedFunctionTable[0][6 * v21 + 6];
v23 = &RtlpInvertedFunctionTable[0][6 * v21];
v24 = (unsigned __int64)v22 + (unsigned int)v23[8];
if( ControlPc >= v22 )
{
if( (unsigned __int64)ControlPc > 0x7FFFFFFEFFFFi64
&& v19
&& (unsigned __int64)ControlPc >= v24 + v18
&& (unsigned __int64)ControlPc < v24 + v19 + v18
&& v22 != (void *)PsNtosImageBase
&& v22 != PsHalImageBase )
{
FunctionTableInfo->FunctionTable = (_IMAGE_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
FunctionTableInfo->ImageBase = (void *)(v24 + v18);
FunctionTable = (_IMAGE_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
FunctionTableInfo->SizeOfTable = RtlRetpolineStubsFunctionTableSize;
FunctionTableInfo->SizeOfImage = v19;
goto LABEL_62;
}
if( (unsigned __int64)ControlPc < v24 )
{
*(_OWORD *)&FunctionTableInfo->FunctionTable = *((_OWORD *)v23 + 1);
*(_QWORD *)&FunctionTableInfo->SizeOfImage = *((_QWORD *)v23 + 4);
FunctionTable = FunctionTableInfo->FunctionTable;
goto LABEL_62;
}
v16 = v21 + 1;
v30 = v21 + 1;
}
else
{
if( !v21 )
break;
v16 = v30;
v20 = v21 - 1;
}
}
while( v20 >= v16 );
}
}
if( *((_BYTE *)RtlpInvertedFunctionTable[0] + 12) )
{
if( (KiSpeculationFeatures & 0x2000000) != 0 )
{
v25 = dword_140C4C9F0;
}
else
{
v25 = 0;
v14 = 0;
}
v26 = PsLoadedModuleList;
if( PsLoadedModuleList )
{
if( (INT64 *)PsLoadedModuleList != &PsLoadedModuleList )
{
while( 1 )
{
v27 = *(void **)(v26 + 48);
v28 = (unsigned __int64)v27 + *(unsigned int *)(v26 + 64);
if( ControlPc >= v27 && (unsigned __int64)ControlPc < v28 )
{
FunctionTable = *(_IMAGE_RUNTIME_FUNCTION_ENTRY **)(v26 + 16);
FunctionTableInfo->FunctionTable = FunctionTable;
FunctionTableInfo->ImageBase = v27;
FunctionTableInfo->SizeOfImage = *(_DWORD *)(v26 + 64);
FunctionTableInfo->SizeOfTable = *(_DWORD *)(v26 + 24);
goto LABEL_62;
}
if( v14 && (unsigned __int64)ControlPc >= v28 + v25 && (unsigned __int64)ControlPc < v28 + v14 + v25 )
break;
v26 = *(_QWORD *)v26;
if( (INT64 *)v26 == &PsLoadedModuleList )
goto LABEL_62;
}
FunctionTable = (_IMAGE_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
FunctionTableInfo->FunctionTable = (_IMAGE_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
FunctionTableInfo->ImageBase = (void *)(v28 + v25);
FunctionTableInfo->SizeOfTable = RtlRetpolineStubsFunctionTableSize;
FunctionTableInfo->SizeOfImage = v14;
}
}
}
LABEL_62:
MmUnlockLoadedModuleListShared(v29);
return(_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *)FunctionTable;
}
if( *RtlpInvertedFunctionTable[0] == 1 )
{
v30 = 1;
goto LABEL_10;
}
if( (KiSpeculationFeatures & 0x2000000) != 0 )
{
v7 = 4096;
v31 = dword_140C4C9F0;
}
else
{
v31 = 0;
v7 = 0;
}
v8 = *RtlpInvertedFunctionTable[0] - 1;
v30 = 1;
v9 = 1;
if( v8 < 1 )
{
LABEL_10:
v14 = 4096;
if( !*((_BYTE *)RtlpInvertedFunctionTable[0] + 12) )
{
result = 0i64;
goto LABEL_18;
}
LABEL_21:
v16 = 1;
goto LABEL_29;
}
while( 1 )
{
v10 = (v9 + v8) >> 1;
v11 = *(void **)&RtlpInvertedFunctionTable[0][6 * v10 + 6];
v12 = &RtlpInvertedFunctionTable[0][6 * v10];
v13 = (unsigned __int64)v11 + (unsigned int)v12[8];
if( ControlPc < v11 )
{
if( !v10 )
goto LABEL_10;
v8 = v10 - 1;
goto LABEL_9;
}
if( (unsigned __int64)ControlPc > 0x7FFFFFFEFFFFi64 )
{
if( v7 )
{
v17 = v31;
if( (unsigned __int64)ControlPc >= v13 + v31
&& (unsigned __int64)ControlPc < v13 + v7 + v31
&& v11 != (void *)PsNtosImageBase
&& v11 != PsHalImageBase )
{
break;
}
}
}
if( (unsigned __int64)ControlPc < v13 )
{
*FunctionTableInfo = *(_INVERTED_FUNCTION_TABLE_ENTRY *)(v12 + 4);
result = (_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *)FunctionTableInfo->FunctionTable;
goto LABEL_17;
}
v9 = v10 + 1;
LABEL_9:
if( v8 < v9 )
goto LABEL_10;
}
FunctionTableInfo->SizeOfImage = v7;
FunctionTableInfo->ImageBase = (void *)(v13 + v17);
FunctionTableInfo->SizeOfTable = RtlRetpolineStubsFunctionTableSize;
result = (_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
FunctionTableInfo->FunctionTable = (_IMAGE_RUNTIME_FUNCTION_ENTRY *)&RtlRetpolineStubsFunctionTable;
LABEL_17:
v14 = 4096;
LABEL_18:
if( v5[2] != v6 )
goto LABEL_21;
return result;
}Referenced by:
KiVerifyPdata
RtlCreateInvertedFunctionTableCacheEntry
RtlLookupFunctionEntry
RtlLookupFunctionTable
RtlLookupFunctionTableEx
RtlPcToFileHeader
RtlpLookupFunctionEntryForStackWalks