KeBugCheck2
VOID __stdcall __noreturn KeBugCheck2(UINT64 *TotalTransitions){
_LDR_DATA_TABLE_ENTRY *v1;
UINT64 v2;
UINT64 v3;
const CHAR *v4;
UINT64 v5;
UINT64 v6;
_LDR_DATA_TABLE_ENTRY *v7;
UINT64 v8;
signed __int32 v9;
int v10;
signed __int32 v11;
char v12;
UINT8 v13;
signed __int32 v14;
int v15;
signed __int32 v16;
int v17;
UINT64 v18;
__int64 *v19;
__int64 v20;
_OWORD *v21;
__int128 v22;
char v23;
unsigned int v24;
UINT64 v25;
UINT64 v26;
int IsSessionAddress;
_ETHREAD *v28;
UNICODE_STRING *UnloadedDriver;
const CHAR *v30;
UINT64 *v31;
UINT64 v32;
_UNICODE_STRING *p_BaseDllName;
_ETHREAD *v34;
__int64 v35;
int v36;
int IsEmptyAffinity;
_KPRCB *v38;
__int64 CurrentIrql;
char v40;
int v41;
char v42;
unsigned int v43;
UINT64 v44;
_OWORD *v45;
__int64 *v46;
__int64 v47;
__int64 v48;
__int128 v49;
__int64 v50;
char v51;
char v52;
int v53;
char v54;
char v55;
UINT8 InKernelOrHal;
bool v57;
bool v58;
bool v59;
char v60;
_ETHREAD *Thread;
UINT64 BugCheckCode;
PCSTR Format;
int v64;
PVOID VirtualAddress;
int v66;
_KPRCB *Prcb;
_KERNEL_STACK_LIMITS Type;
_LDR_DATA_TABLE_ENTRY *DataTableEntry;
int v70;
UINT64 HighLimit;
void *Src;
PBOOLEAN Reboot;
INT64 result[22];
__int64 ContextSave[154];
char pszDest[176];
CHAR *PcValue;
UINT64 v78;
v4 = PcValue;
v5 = v2;
v6 = v78;
v7 = v1;
LODWORD(BugCheckCode) = (_DWORD)TotalTransitions;
v8 = v3;
memset((INT64)result, 0i64);
v57 = 1;
pszDest[0] = 0;
Thread = (_ETHREAD *)KeGetCurrentThread();
Reboot = (PBOOLEAN)KiBugCheckProgress;
v59 = IopAutoReboot != 0;
DataTableEntry = 0i64;
InKernelOrHal = 0;
LOBYTE(v64) = 0;
v60 = 0;
Format = 0i64;
VirtualAddress = 0i64;
v58 = 1;
v66 = 0;
HighLimit = 0i64;
Src = 0i64;
Type = BugcheckStackLimits;
if( KeGetCurrentIrql() < 2u )
{
KeGetCurrentIrql();
__writecr8(2ui64);
}
if( *((_QWORD *)KeGetCurrentThread() + 5) )
{
v13 = KeQueryCurrentStackInformation(&Type, (UINT64 *)&Src, &HighLimit);
v14 = KiBugCheckActive;
v15 = (16 * *((_DWORD *)KeGetCurrentPrcb() + 9)) | 3;
while( (v14 & 3) != 3 )
{
v16 = v14;
v14 = _InterlockedCompareExchange(&KiBugCheckActive, v15, v14);
if( v14 == v16 )
{
if( v13 )
{
if( (unsigned int)Type > MachineCheckStackLimits || (v17 = 929, !_bittest(&v17, Type)) )
{
v18 = HighLimit - (_QWORD)Src;
if( HighLimit - (unsigned __int64)Src > 0x6000 )
v18 = 24576i64;
memmove(&KiPreBugcheckStackSaveArea, (UINT8 *)Src, v18);
}
}
LABEL_22:
v54 = 1;
goto LABEL_8;
}
}
}
else
{
v9 = KiBugCheckActive;
v10 = (16 * *((_DWORD *)KeGetCurrentPrcb() + 9)) | 3;
while( (v9 & 3) != 3 )
{
v11 = v9;
v9 = _InterlockedCompareExchange(&KiBugCheckActive, v10, v9);
if( v9 == v11 )
goto LABEL_22;
}
}
v54 = 0;
LABEL_8:
if( KeSmapEnabled )
__stac();
Prcb = KeGetCurrentPrcb();
v70 = *((_DWORD *)Prcb + 9);
KeSaveSupervisorState(*((_QWORD *)Prcb + 216), KUSER_SHARED_DATA.XState.EnabledSupervisorFeatures | 0x100);
if( !HiberContext )
goto LABEL_11;
if( PopSimulateHiberBugcheck )
PoPowerDownActionInProgress = 0;
if( *(_BYTE *)(HiberContext + 3) )
{
if( v54 )
{
DbgPrintEx(
0x65u,
0,
"\n"
"A bugcheck occurred during the late stages of hibernate suspend or resume.\n"
"Due to verification temporarily enabled by Po during this time,\n"
"regular bugcheck processing may not work.\n"
"\n");
if( (_DWORD)BugCheckCode == 10 )
DbgPrintEx(
0x65u,
0,
"Memory was accessed during this time that was not properly marked\n"
"for the boot phase of hibernate! Check the callstack and parameters\n"
"to find the pages that need to be marked.\n"
"\n");
}
Reboot = 0i64;
v12 = 1;
}
else
{
LABEL_11:
v12 = 0;
}
v19 = ContextSave;
v20 = 9i64;
v55 = v12;
v21 = (_OWORD *)*((_QWORD *)Prcb + 4280);
do
{
*(_OWORD *)v19 = *v21;
*((_OWORD *)v19 + 1) = v21[1];
*((_OWORD *)v19 + 2) = v21[2];
*((_OWORD *)v19 + 3) = v21[3];
*((_OWORD *)v19 + 4) = v21[4];
*((_OWORD *)v19 + 5) = v21[5];
*((_OWORD *)v19 + 6) = v21[6];
v19 += 16;
v22 = v21[7];
v21 += 8;
*((_OWORD *)v19 - 1) = v22;
--v20;
}
while( v20 );
v23 = v54;
*(_OWORD *)v19 = *v21;
*((_OWORD *)v19 + 1) = v21[1];
*((_OWORD *)v19 + 2) = v21[2];
*((_OWORD *)v19 + 3) = v21[3];
*((_OWORD *)v19 + 4) = v21[4];
if( !v54 )
{
v28 = Thread;
goto LABEL_140;
}
if( ViVerifierEnabled )
VfNotifyVerifierOfEvent(2ui64);
if( !v12 )
KiSaveCurrentEtwTraceBuffer();
IoAddTriageDumpDataBlock(KseEngine, 0x60ui64);
v24 = BugCheckCode;
if( (_DWORD)BugCheckCode == 229 )
{
KiScanBugCheckCallbackList();
((void(__fastcall *)(_QWORD))off_140C008A8[0])(0i64);
HalReturnToFirmware(3);
}
*(&KiBugCheckData + 1) = (UINT64)v7;
xmmword_140C312D0 = v5;
if( (_DWORD)BugCheckCode == -1073741103 )
v24 = 195;
*(&xmmword_140C312D0 + 1) = v8;
KiBugCheckData = v24;
LODWORD(BugCheckCode) = v24;
qword_140C312E0 = (UINT64)PcValue;
if( v24 > 0xCB )
{
if( v24 != 216 )
{
if( v24 == 234 )
{
KiBugCheckDriver = (UINT16 *)v8;
goto LABEL_110;
}
if( v24 == 239 )
goto LABEL_57;
if( v24 != 252 )
{
if( v24 == 317 )
{
v66 = 8;
}
else if( v24 == 335 )
{
if( v5 < 0x100 && PcValue )
{
v34 = Thread;
if( *((_QWORD *)PcValue + 1) )
v34 = (_ETHREAD *)*((_QWORD *)PcValue + 1);
Thread = v34;
}
v35 = *((_QWORD *)KeGetCurrentThread() + 23);
v36 = *(_DWORD *)(v35 + 2172) >> 12;
LOBYTE(v36) = (*(_DWORD *)(v35 + 2172) & 0x1000) == 0;
v64 = v36;
}
goto LABEL_110;
}
LABEL_49:
if( !v78 )
{
if( !v8 || (v8 & 3) != 0 )
goto LABEL_110;
v6 = v8;
}
if( v24 == 142
|| (VirtualAddress = *(PVOID *)(v6 + 360), *((_BYTE *)KeGetCurrentThread() + 586) != 1)
|| !(unsigned int)MmIsSessionAddress(VirtualAddress)
|| (*(_DWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 2172i64) & 0x1000) != 0 )
{
LABEL_110:
v28 = Thread;
goto LABEL_111;
}
LABEL_57:
LOBYTE(v64) = 1;
goto LABEL_110;
}
DataTableEntry = v7;
p_BaseDllName = &v7->BaseDllName;
LABEL_109:
KiBugCheckDriver = &p_BaseDllName->Length;
goto LABEL_110;
}
switch( v24 )
{
case 0xCBu:
VirtualAddress = v7;
goto LABEL_110;
case 0xAu:
if( (unsigned __int64)PcValue >= ExPoolCodeStart && (unsigned __int64)PcValue < ExPoolCodeEnd )
{
KiBugCheckData = 197i64;
goto LABEL_110;
}
KiPcToFileHeader(PcValue, &DataTableEntry, 0i64, &InKernelOrHal);
if( InKernelOrHal != 1 )
{
KiBugCheckData = 209i64;
goto LABEL_110;
}
if( !KiPcToFileHeader(v7, &DataTableEntry, 1ui64, &InKernelOrHal) )
{
KiBugCheckDriver = (UINT16 *)MmLocateUnloadedDriver(v7);
if( KiBugCheckDriver )
KiBugCheckData = 212i64;
goto LABEL_110;
}
p_BaseDllName = &DataTableEntry->BaseDllName;
KiBugCheckData = 211i64;
goto LABEL_109;
case 0x4Cu:
v31 = &KiBugCheckData + 1;
KiBugCheckData = (unsigned int)v7;
v32 = v5 - (_QWORD)(&KiBugCheckData + 1);
LOBYTE(v64) = 1;
v30 = (const CHAR *)v8;
v60 = 1;
do
{
*v31 = *(UINT64 *)((char *)v31 + v32);
++v31;
}
while( (__int64)v31 < (__int64)&KiHardwareTrigger );
v28 = Thread;
goto LABEL_112;
}
if( v24 != 80 )
{
if( v24 == 123 )
{
v57 = (v8 & 1) == 0;
v58 = (v8 & 2) == 0;
goto LABEL_110;
}
if( v24 != 142 && v24 != 190 )
goto LABEL_110;
goto LABEL_49;
}
v25 = 0i64;
if( v78 )
goto LABEL_63;
if( v8 && (v8 & 3) == 0 )
{
v6 = v8;
LABEL_63:
VirtualAddress = *(PVOID *)(v6 + 360);
*(&xmmword_140C312D0 + 1) = (UINT64)VirtualAddress;
v25 = KiPcToFileHeader(VirtualAddress, &DataTableEntry, 0i64, &InKernelOrHal);
if( *((_BYTE *)KeGetCurrentThread() + 586) == 1
&& (unsigned int)MmIsSessionAddress(VirtualAddress)
&& (*(_DWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 2172i64) & 0x1000) == 0 )
{
LOBYTE(v64) = 1;
}
goto LABEL_67;
}
InKernelOrHal = 1;
LABEL_67:
if( (unsigned int)MmIsSpecialPoolAddress(v7) == 1 )
{
v26 = 213i64;
v12 = v55;
if( InKernelOrHal == 1 )
v26 = 204i64;
KiBugCheckData = v26;
goto LABEL_110;
}
if( VirtualAddress == v7 )
{
IsSessionAddress = MmIsSessionAddress(v7);
v28 = Thread;
if( IsSessionAddress == 1 && (unsigned __int64)(*((_QWORD *)Thread + 30) - 1i64) > 0xFFFF7FFFFFFFFFFEui64 )
{
KiBugCheckData = 207i64;
LABEL_76:
v12 = v55;
LABEL_111:
v30 = Format;
v4 = Format;
goto LABEL_112;
}
}
else
{
v28 = Thread;
}
if( v25 )
goto LABEL_76;
UnloadedDriver = MmLocateUnloadedDriver(v7);
v30 = Format;
v12 = v55;
v4 = Format;
KiBugCheckDriver = &UnloadedDriver->Length;
if( UnloadedDriver )
KiBugCheckData = 206i64;
LABEL_112:
if( v59 )
KiAttemptBugcheckRecovery();
off_140C008C8[0]();
HvlEnlightenments &= 0x2000u;
IoSaveBugCheckProgress(0x60ui64);
IsEmptyAffinity = KeIsEmptyAffinityEx(&KiNmiInProgress);
((void(__fastcall *)(bool))off_140C00698[0])(IsEmptyAffinity == 0);
KiFilterBugCheckInfo(&BugCheckCode, (__int64)&KiBugCheckData);
HvlLogGuestCrashInformation(
(unsigned int)KiBugCheckData,
*(&KiBugCheckData + 1),
xmmword_140C312D0,
*(&xmmword_140C312D0 + 1),
qword_140C312E0);
if( KiBugCheckDriver )
{
KiBugCheckUnicodeToAnsi(KiBugCheckDriver, (BYTE *)pszDest);
}
else if( VirtualAddress )
{
KiDumpParameterImages(pszDest, (unsigned __int64 *)&VirtualAddress, 1u, 1);
}
if( !KdPitchDebugger )
qword_140C00B48 = (__int64)ContextSave;
if( (_DWORD)BugCheckCode == 226
|| !(_BYTE)KdDebuggerEnabled && !KdEventLoggingEnabled
|| KiHypervisorInitiatedCrashDump
|| KdRefreshDebuggerNotPresent() && !KdEventLoggingPresent )
{
v23 = v54;
LABEL_140:
v38 = Prcb;
goto LABEL_141;
}
v38 = Prcb;
if( !*((_BYTE *)Prcb + 31718) )
{
DbgPrintEx(
0x65u,
0,
"\n*** Fatal System Error: 0x%08lx\n(0x%p,0x%p,0x%p,0x%p)\n\n",
(unsigned int)KiBugCheckData,
(const void *)*(&KiBugCheckData + 1),
(const void *)xmmword_140C312D0,
(const void *)*(&xmmword_140C312D0 + 1),
(const void *)qword_140C312E0);
if( KiBugCheckDriver )
DbgPrintEx(0x65u, 0, "Driver at fault: %s.\n", pszDest);
if( v60 )
{
if( v30 )
DbgPrintEx(0x65u, 0, v30);
if( v4 )
DbgPrintEx(0x65u, 0, v4);
}
}
if( (_BYTE)KdDebuggerEnabled && !(_BYTE)KdDebuggerNotPresent )
KiBugCheckDebugBreak(3ui64);
v23 = v54;
LABEL_141:
_disable();
CurrentIrql = KeGetCurrentIrql();
__writecr8(0xFui64);
if( v23 )
{
if( (unsigned int)KeNumberProcessors_0 > 1 && !KiHypervisorInitiatedCrashDump )
{
KiSetDebuggerOwner(v38);
KeCopyAffinityEx((__int64)result, &KeActiveProcessors.Count);
KeRemoveProcessorAffinityEx((unsigned __int16 *)result, *((_DWORD *)v38 + 9));
KiSendFreeze((_KAFFINITY_EX *)result, 0);
KeStallExecutionProcessor(0xF4240u);
}
IoInitializeBugCheckProgress((unsigned int)BugCheckCode, (UINT64)v7);
IoSaveBugCheckProgress(1ui64);
v40 = v58;
if( v12 )
{
v42 = v57;
}
else
{
if( CrashdmpDumpBlock && v58 )
v41 = v66;
else
v41 = v66 | 4;
v42 = v57;
v43 = v41 | 2;
if( v59 )
v43 = v41;
v44 = v43 | 1;
if( v57 )
v44 = v43;
KiDisplayBlueScreen(v44);
}
HvlPrepareForRootCrashdump();
if( !v12 )
{
KiInvokeBugCheckEntryCallbacks();
IoSaveBugCheckProgress(2ui64);
KiInvokeBugCheckAddTriageDumpDataCallbacks();
IoSaveBugCheckProgress(5ui64);
}
if( !(_BYTE)KdDebuggerEnabled && !KdPitchDebugger )
KdEnableDebuggerWithLock(0);
v45 = (_OWORD *)*((_QWORD *)v38 + 4280);
v46 = ContextSave;
v47 = 9i64;
v48 = 128i64;
do
{
*v45 = *(_OWORD *)v46;
v45[1] = *((_OWORD *)v46 + 1);
v45[2] = *((_OWORD *)v46 + 2);
v45[3] = *((_OWORD *)v46 + 3);
v45[4] = *((_OWORD *)v46 + 4);
v45[5] = *((_OWORD *)v46 + 5);
v45[6] = *((_OWORD *)v46 + 6);
v45 += 8;
v49 = *((_OWORD *)v46 + 7);
v46 += 16;
*(v45 - 1) = v49;
--v47;
}
while( v47 );
*v45 = *(_OWORD *)v46;
v45[1] = *((_OWORD *)v46 + 1);
v45[2] = *((_OWORD *)v46 + 2);
v45[3] = *((_OWORD *)v46 + 3);
v45[4] = *((_OWORD *)v46 + 4);
if( v40 )
{
if( (_DWORD)BugCheckCode == 265 )
{
KiMarkBugCheckRegions(*(&KiBugCheckData + 1), xmmword_140C312D0, *(&xmmword_140C312D0 + 1), qword_140C312E0);
if( qword_140C312E0 == 47 )
{
v50 = *(&xmmword_140C312D0 + 1);
MmIsAddressValid((PVOID)(*(&xmmword_140C312D0 + 1) + 1928));
if( v51 )
IoAddTriageDumpDataBlock(*(PVOID *)(v50 + 1928), 0x1000ui64);
}
}
KdDecodeDataBlock();
if( (_DWORD)BugCheckCode == 395 )
{
if( *(&KiBugCheckData + 1) != 396 )
{
LABEL_178:
IoWriteCrashDump(
KiBugCheckData,
(PVOID)*(&KiBugCheckData + 1),
(PVOID)xmmword_140C312D0,
(PVOID)*(&xmmword_140C312D0 + 1),
(PVOID)qword_140C312E0,
ContextSave,
(PKTHREAD)v28,
Reboot);
IoSaveBugCheckProgress(3ui64);
goto LABEL_186;
}
if( KdpBreakpointChangeCount )
IoAddTriageDumpDataBlock(&KdpBreakpointChangeCount, 4ui64);
IoAddTriageDumpDataBlock(VslpTraceLog, 0xA08ui64);
if( VslpHotpatchLog )
{
IoAddTriageDumpDataBlock(&VslpHotpatchLog, 8ui64);
IoAddTriageDumpDataBlock(VslpHotpatchLog, 0x50008ui64);
}
}
if( (_DWORD)BugCheckCode == 239 )
{
PoAddPowerTriageData();
if( (_DWORD)CriticalProcessExceptionData )
{
IoAddTriageDumpDataBlock(&CriticalProcessExceptionData, 0x30ui64);
if( (_WORD)xmmword_140C19570 )
IoAddTriageDumpDataBlock(*((PVOID *)&xmmword_140C19570 + 1), (unsigned __int16)xmmword_140C19570);
}
}
goto LABEL_178;
}
}
else
{
v52 = KiBugCheckActive;
if( v70 != (unsigned int)KiBugCheckActive >> 4 )
{
while( 1 )
{
KiCheckForFreezeExecution(0i64, 0i64);
_mm_pause();
}
}
if( KiHypervisorInitiatedCrashDump || (KiBugCheckActive & 0xCu) >= 8 )
{
while( 1 )
((void(__fastcall *)(__int64))off_140C005D8)(CurrentIrql);
}
IoSetBugCheckProgressFlag(0x20000ui64);
_InterlockedExchangeAdd(&KiBugCheckActive, 4u);
if( (v52 & 0xC) != 0 )
KiBugCheckDebugBreak(4ui64);
v42 = v57;
}
LABEL_186:
if( !VslVsmEnabled )
{
if( (HvlpFlags & 2) != 0 )
HvlNotifyRootCrashdump(2ui64);
HvlEnlightenments = HvlpEnlightenments;
((void(__fastcall *)(__int64 *, __int64, __int64))off_140C007A8[0])(v46, v47, v48);
}
IoSaveBugCheckProgress(0x63ui64);
if( !v55 )
KiScanBugCheckCallbackList();
off_140C008B8[0]();
IoSaveBugCheckProgress(4ui64);
if( v59 )
{
KiResumeForReboot = 1;
KiSendThawExecution(0);
KiBugcheckUnloadDebugSymbols();
((void(__fastcall *)(_QWORD))off_140C008A8[0])(0i64);
if( PoPowerDownActionInProgress && !PoPowerResetActionInProgress
|| PoModernStandbyActionInProgress
|| (v53 = 3, !v42) )
{
v53 = 1;
}
HalReturnToFirmware(v53);
}
KiBugCheckDebugBreak(4ui64);
}Referenced by:
KeBugCheckEx