KiUpdateSpeculationControl
void __fastcall KiUpdateSpeculationControl(__int64 a1){
struct _KPRCB *CurrentPrcb;
int v3;
unsigned __int8 v4;
bool v5;
int v6;
char v7;
char v8;
int v9;
__int64 v10;
int v11;
int v12;
char v13;
char v14;
char v15;
char v16;
char v17;
unsigned __int8 v18;
unsigned __int8 v19;
unsigned __int8 v20;
char v21;
int updated;
char v23;
int v24;
bool v25;
char v26;
signed __int16 v27;
signed __int16 v28;
int v29;
char v30;
char v31;
char v32;
int v33;
__int64 v34;
_DWORD v35[4];
char v36;
int v37;
BOOL v38;
CurrentPrcb = KeGetCurrentPrcb();
*(_OWORD *)v35 = *(_OWORD *)&KiSpeculationFeatures;
v3 = KiSpeculationFeatures;
if( (KiSpeculationFeatures & 0x100000) == 0 )
return;
_disable();
*((_BYTE *)CurrentPrcb + 248) &= 0x81u;
if( (v3 & 1) != 0 )
{
KiUpdateSpecCtrlEnhancedIBRS((INT64)CurrentPrcb, a1);
_enable();
return;
}
v4 = *((_BYTE *)CurrentPrcb + 250);
v5 = 0;
v36 = 0;
v6 = v3 & 0x2000000;
if( (v3 & 0x2000000) != 0 )
{
v7 = *((_BYTE *)CurrentPrcb + 1747);
if( (v7 & 2) == 0 && (v7 & 1) != 0 )
{
v4 = *((_BYTE *)CurrentPrcb + 1745);
v5 = (*((_BYTE *)CurrentPrcb + 1746) & 0x10) != 0;
v36 = 1;
}
}
if( (v3 & 0x400000) != 0 && KiSsbdMsr == 72 )
{
v4 |= 4u;
v8 = 4;
}
else
{
v8 = 0;
}
*((_BYTE *)CurrentPrcb + 251) = v8;
*((_BYTE *)CurrentPrcb + 253) = v8;
*((_BYTE *)CurrentPrcb + 1744) = v8;
v37 = v3 & 0x2000;
if( (v3 & 0x2000) != 0 )
{
*((_BYTE *)CurrentPrcb + 251) |= 0x80u;
*((_BYTE *)CurrentPrcb + 1744) |= 0x80u;
}
v9 = v3 & 0x8000000;
if( v9 )
{
*((_BYTE *)CurrentPrcb + 251) |= 2u;
*((_BYTE *)CurrentPrcb + 1744) |= 2u;
}
v34 = *((_QWORD *)CurrentPrcb + 30);
v10 = *(_QWORD *)(a1 + 2528);
v11 = v35[0];
v38 = (*(_DWORD *)(a1 + 2172) & 0x400000) != 0;
v33 = (*(_DWORD *)(a1 + 2172) >> 23) & 1;
if( (*(_DWORD *)(a1 + 2172) & 0x400000) == 0 )
v10 = 1i64;
v12 = v35[0] & 0x200000;
if( (v35[0] & 0x200000) == 0 )
{
if( !v10 )
{
if( (v35[0] & 2) != 0 )
{
if( (v35[0] & 0x40) != 0 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 2u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 2u;
}
else if( (v35[0] & 0x10) != 0 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 1u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 1u;
}
}
goto LABEL_24;
}
if( KiIsBranchConfusionMitigationEnabled(v35) )
{
v13 = *((_BYTE *)CurrentPrcb + 248) | 8;
*((_BYTE *)CurrentPrcb + 248) = v13;
if( (v11 & 8) == 0 )
*((_BYTE *)CurrentPrcb + 248) = v13 | 2;
if( (v11 & 2) != 0 )
{
if( (v11 & 0x40) != 0 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 2u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 2u;
}
else if( (v11 & 0x10) != 0 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 1u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 1u;
}
}
goto LABEL_70;
}
if( (v11 & 0x10) != 0 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 1u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 1u;
if( (v11 & 0x20) == 0 )
*((_BYTE *)CurrentPrcb + 248) |= 2u;
goto LABEL_70;
}
if( (v11 & 0x42) == 66 )
{
*((_BYTE *)CurrentPrcb + 1744) |= 2u;
if( !v6 )
*((_BYTE *)CurrentPrcb + 251) |= 2u;
}
v14 = *((_BYTE *)CurrentPrcb + 248);
if( v6 )
{
v15 = v14 | 0x10;
*((_BYTE *)CurrentPrcb + 248) = v15;
if( (v11 & 0x20) != 0 )
{
if( (v11 & 8) != 0 )
goto LABEL_70;
v16 = v15 | 0x40;
LABEL_69:
*((_BYTE *)CurrentPrcb + 248) = v16;
goto LABEL_70;
}
}
else
{
v15 = v14 | 8;
*((_BYTE *)CurrentPrcb + 248) = v15;
if( (v11 & 8) != 0 )
goto LABEL_70;
}
v16 = v15 | 2;
goto LABEL_69;
}
LABEL_70:
if( !v10 || (v11 & 0x800000) == 0 )
{
LABEL_24:
*((_BYTE *)CurrentPrcb + 1745) &= ~4u;
goto LABEL_25;
}
*((_BYTE *)CurrentPrcb + 1744) |= 4u;
*((_BYTE *)CurrentPrcb + 1745) |= 4u;
*((_BYTE *)CurrentPrcb + 251) |= 4u;
v4 |= 4u;
LABEL_25:
if( (v11 & 0x42) == 66 && ((v11 & 0x10000) != 0 || (*(_DWORD *)(a1 + 2512) & 0x40000000) != 0) )
{
*((_BYTE *)CurrentPrcb + 253) |= 2u;
if( v6 )
{
if( (PEPROCESS)a1 != PsInitialSystemProcess )
*((_BYTE *)CurrentPrcb + 251) |= 2u;
}
}
if( v9 )
*((_BYTE *)CurrentPrcb + 253) |= 2u;
if( (v11 & 0x800000) != 0 && (*(_DWORD *)(a1 + 2516) & 0x2000) != 0 )
*((_BYTE *)CurrentPrcb + 253) |= 4u;
if( !v34 || v34 == v10 || v34 == *(_QWORD *)(a1 + 2536) )
goto LABEL_88;
if( (v4 & 1) == 0 )
{
if( !v12 && (v11 & 0x10) == 0 && (!v6 || (*((_BYTE *)CurrentPrcb + 1747) & 2) != 0) )
goto LABEL_88;
LABEL_86:
v17 = *((_BYTE *)CurrentPrcb + 248) | 4;
*((_BYTE *)CurrentPrcb + 248) = v17;
if( (v11 & 8) == 0 )
*((_BYTE *)CurrentPrcb + 248) = v17 | 0x20;
goto LABEL_88;
}
if( (v11 & 2) == 0 )
{
v4 &= 4u;
goto LABEL_78;
}
if( (*((_WORD *)CurrentPrcb + 127) & 4) != 0 )
goto LABEL_77;
if( v6 && (*((_BYTE *)CurrentPrcb + 1747) & 1) == 0 )
{
v4 &= 4u;
LABEL_77:
LOBYTE(v11) = v35[0];
goto LABEL_78;
}
LOBYTE(v11) = v35[0];
if( (v35[0] & 0x40) != 0 )
v4 = v4 & 4 | 2;
LABEL_78:
if( (v4 & 1) != 0 )
goto LABEL_86;
v5 = 1;
v36 = 1;
LABEL_88:
v18 = v4 | 0x80;
if( !v37 )
v18 = v4;
v19 = v18 | 2;
if( !v9 )
v19 = v18;
if( v5 )
{
__writemsr(0x49u, 1ui64);
if( (v11 & 8) == 0 )
KiFlushCurrentRsb();
*((_BYTE *)CurrentPrcb + 248) &= 0xDBu;
*((_BYTE *)CurrentPrcb + 1746) &= 0xAFu;
*((_QWORD *)CurrentPrcb + 30) = 0i64;
*((_BYTE *)CurrentPrcb + 1745) = v19;
}
v20 = v19;
if( (*((_WORD *)CurrentPrcb + 127) & 4) == 0 )
goto LABEL_127;
if( v34 == v10 )
{
v21 = *((_BYTE *)CurrentPrcb + 253);
if( (*(_WORD *)(*((_QWORD *)CurrentPrcb + 1462) + 254i64) & 1) != 0 )
{
*((_BYTE *)CurrentPrcb + 253) = v21 & 0xFD;
if( v6 )
*((_BYTE *)CurrentPrcb + 251) &= ~2u;
}
else
{
*((_BYTE *)CurrentPrcb + 253) = v21 | 2;
if( v6 )
*((_BYTE *)CurrentPrcb + 251) |= 2u;
}
}
else
{
_InterlockedOr16((volatile signed __int16 *)CurrentPrcb + 127, 2u);
}
if( !v10 )
{
updated = KiUpdateStibpPairing(a1);
v23 = *((_BYTE *)CurrentPrcb + 1744) & 3;
v24 = updated;
*((_BYTE *)CurrentPrcb + 1745) = v23 | *((_BYTE *)CurrentPrcb + 1745) & 0xFC;
if( v6 && (*((_BYTE *)CurrentPrcb + 1747) & 1) != 0 )
v25 = v23 != 0;
else
v25 = (*((_BYTE *)CurrentPrcb + 251) & 3) != 0;
v26 = 1;
v20 = (v25 ? 2 : 0) | v19 & 0xFC;
if( !v38 )
_InterlockedOr16((volatile signed __int16 *)CurrentPrcb + 127, 2u);
goto LABEL_129;
}
if( !v33 )
{
LABEL_127:
v24 = 0;
goto LABEL_128;
}
_m_prefetchw((char *)CurrentPrcb + 254);
v27 = *((_WORD *)CurrentPrcb + 127);
do
{
v28 = v27;
v27 = _InterlockedCompareExchange16((volatile signed __int16 *)CurrentPrcb + 127, v27 | 0x100, v27);
}
while( v28 != v27 );
v29 = v27 & 1;
if( (KiSpeculationFeatures & 0x2000000) != 0 )
{
v30 = *((_BYTE *)CurrentPrcb + 1744);
if( (v30 & 3) == 0 )
*((_BYTE *)CurrentPrcb + 1744) = v30 | 2;
v31 = *((_BYTE *)CurrentPrcb + 1745);
if( (v31 & 3) == 0 )
*((_BYTE *)CurrentPrcb + 1745) = v31 | 2;
v20 = v19;
if( (*((_BYTE *)CurrentPrcb + 1747) & 1) == 0 )
goto LABEL_126;
}
else
{
v32 = *((_BYTE *)CurrentPrcb + 251);
if( (v32 & 3) == 0 )
*((_BYTE *)CurrentPrcb + 251) = v32 | 2;
v20 = v19;
}
if( (v19 & 3) == 0 )
v20 |= 2u;
LABEL_126:
_InterlockedOr16((volatile signed __int16 *)CurrentPrcb + 127, 2u);
v24 = v29;
LABEL_128:
v26 = v36;
LABEL_129:
if( v20 != *((_BYTE *)CurrentPrcb + 250) )
{
*((_BYTE *)CurrentPrcb + 250) = v20;
__writemsr(0x48u, v20);
}
if( v26 )
*((_BYTE *)CurrentPrcb + 1747) |= 2u;
_mm_lfence();
_enable();
if( v24 )
KiSynchronizeStibpPairing((INT64)CurrentPrcb);
}Referenced by:
KeOptimizeSpecCtrlSettings
SwapContext