KxIsrLinkage
VOID __fastcall KxIsrLinkage(UINT64 SecurityDomain, UINT64 BpbState, UINT64 a3, UINT64 a4, CHAR a5){
unsigned __int64 v5;
unsigned __int64 v6;
unsigned __int64 v7;
_M128A v8;
_M128A v9;
_M128A v10;
_M128A v11;
_M128A v12;
_M128A v13;
_KTRAP_FRAME *__shifted(_KTRAP_FRAME,0x80) TrapFrame;
_ETHREAD *CurrentThread;
unsigned __int8 v16;
bool v17;
__int64 ErrorCode_low;
__int64 v19;
unsigned __int64 v20;
unsigned __int8 CurrentIrql;
struct _KPRCB *CurrentPrcb;
__int64 v23;
UINT64 v24;
__int64 v25;
UINT64 v26;
int v27;
INT64 v28;
INT64 v29;
INT64 v30;
struct _KPRCB *v31;
unsigned __int64 v32;
UINT64 v33;
_ETHREAD *v34;
_KTHREAD *v35;
INT64 R9;
INT64 R8;
unsigned __int8 v38;
unsigned __int8 v39;
CHAR v42;
void *retaddr;
__int16 v44;
int v45;
void *v46;
__int16 v47;
TrapFrame = KeGetTrapFrame();
ADJ(TrapFrame)->ExceptionActive = 0;
ADJ(TrapFrame)->Rax = v5;
ADJ(TrapFrame)->Rcx = SecurityDomain;
ADJ(TrapFrame)->Rdx = BpbState;
ADJ(TrapFrame)->R8 = a3;
ADJ(TrapFrame)->R9 = a4;
ADJ(TrapFrame)->R10 = v6;
ADJ(TrapFrame)->R11 = v7;
if( (ADJ(TrapFrame)->SegCs & 1) != 0 )
{
if( (KiKvaShadow & 1) == 0 )
__swapgs();
_mm_lfence();
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
SecurityDomain = *(_QWORD *)(*((_QWORD *)CurrentThread + 68) + 2528i64);
__writegsqword(0x270u, SecurityDomain);
__writegsbyte(0x851u, *((_BYTE *)KeGetPcr() + 2128));
LOBYTE(SecurityDomain) = *((_BYTE *)KeGetPcr() + 632);
__writegsbyte(0x852u, SecurityDomain);
v16 = *((_BYTE *)KeGetPcr() + 635);
if( *((_BYTE *)KeGetPcr() + 634) != v16 )
{
__writegsbyte(0x27Au, v16);
SecurityDomain = 72i64;
HIDWORD(BpbState) = 0;
__writemsr(0x48u, v16);
}
LODWORD(BpbState) = *((unsigned __int8 *)KeGetPcr() + 632);
if( (BpbState & 8) != 0 )
{
SecurityDomain = 73i64;
__writemsr(0x49u, 1ui64);
BpbState = *((unsigned __int8 *)KeGetPcr() + 632);
LODWORD(BpbState) = (unsigned __int8)BpbState;
}
if( (BpbState & 2) != 0 )
__flush_rsb();
_mm_lfence();
__writegsbyte(0x853u, 0);
v17 = (*((_BYTE *)CurrentThread + 3) & 3) == 0;
LOWORD(ADJ(TrapFrame)->Dr7) = 0;
if( !v17 )
KiSaveDebugRegisterState();
}
else
{
_mm_lfence();
if( (*((_BYTE *)KeGetPcr() + 632) & 1) != 0 )
{
SecurityDomain = 72i64;
BpbState = 0i64;
__writemsr(0x48u, *((unsigned __int8 *)KeGetPcr() + 634));
}
else
{
_mm_lfence();
}
}
ADJ(TrapFrame)->MxCsr = _mm_getcsr();
_mm_setcsr(*((_DWORD *)KeGetPcr() + 96));
ADJ(TrapFrame)->Xmm0 = v8;
ADJ(TrapFrame)->Xmm1 = v9;
ADJ(TrapFrame)->Xmm2 = v10;
ADJ(TrapFrame)->Xmm3 = v11;
ADJ(TrapFrame)->Xmm4 = v12;
ADJ(TrapFrame)->Xmm5 = v13;
if( *((_BYTE *)KeGetPcr() + 32794) )
KeWakeProcessor();
if( (unsigned __int64)&ExpInterlockedPopEntrySListResume < ADJ(TrapFrame)->Rip
&& (unsigned __int64)&ExpInterlockedPopEntrySListEnd >= ADJ(TrapFrame)->Rip )
{
KiCheckForSListAddress(ADJ(TrapFrame));
}
ErrorCode_low = LOBYTE(ADJ(TrapFrame)->ErrorCode);
v19 = *((_QWORD *)KeGetCurrentPrcb() + ErrorCode_low + 1576);
__incgsdword(0x8000u);
if( (_BYTE)KeSmapEnabled )
__clac();
if( v19 )
{
(*(void(__fastcall **)(UINT64, UINT64))(v19 + 80))(SecurityDomain, BpbState);
return;
}
v20 = (unsigned int)ErrorCode_low >> 4;
CurrentIrql = KeGetCurrentIrql();
__writecr8(v20);
ADJ(TrapFrame)->PreviousIrql = CurrentIrql;
CurrentPrcb = KeGetCurrentPrcb();
if( ++*((_BYTE *)CurrentPrcb + 32) == 1 )
{
v23 = *((_QWORD *)CurrentPrcb + 1);
v24 = __rdtsc() - *((_QWORD *)CurrentPrcb + 4056);
*(_QWORD *)(v23 + 72) += v24;
v25 = *(unsigned int *)(v23 + 80);
*((_QWORD *)CurrentPrcb + 4056) += v24;
v26 = v24 + v25;
v27 = v26;
if( HIDWORD(v26) )
v27 = -1;
*(_DWORD *)(v23 + 80) = v27;
if( (*(_BYTE *)(v23 + 2) & 0x3E) != 0 )
KiEndThreadAccountingPeriod(KeGetCurrentPrcb(), (_KTHREAD *)v23, v24);
}
_enable();
if( KiBugCheckUnexpectedInterrupts )
{
ADJ(TrapFrame)->P5 = 0i64;
KiBugCheckDispatch(0x12u, 1ui64, LOBYTE(ADJ(TrapFrame)->ErrorCode), 0i64);
}
_disable();
HalPerformEndOfInterrupt(0i64);
v31 = KeGetCurrentPrcb();
if( *((_BYTE *)v31 + 32) > 1u )
goto LABEL_39;
v32 = __rdtsc();
v28 = (unsigned __int64)HIDWORD(v32) << 32;
v33 = (v28 | (unsigned int)v32) - *((_QWORD *)v31 + 4056);
*((_QWORD *)v31 + 4071) += v33;
*((_QWORD *)v31 + 4056) += v33;
v29 = v33;
if( (*(_BYTE *)(*((_QWORD *)v31 + 1) + 2i64) & 0x72) != 0 )
{
KiBeginThreadAccountingPeriod(v31, 0i64, v33);
v31 = KeGetCurrentPrcb();
++*((_BYTE *)v31 + 32);
}
LOBYTE(v28) = *((_BYTE *)v31 + 6);
*((_BYTE *)v31 + 6) = 0;
if( *((_BYTE *)v31 + 7) || !(_BYTE)v28 )
goto LABEL_39;
if( ADJ(TrapFrame)->PreviousIrql >= 2u )
{
HalRequestSoftwareInterrupt(2i64);
v31 = KeGetCurrentPrcb();
LABEL_39:
--*((_BYTE *)v31 + 32);
goto LABEL_40;
}
*((_BYTE *)v31 + 32) = 0;
KiDpcInterruptBypass();
LABEL_40:
__writecr8(ADJ(TrapFrame)->PreviousIrql);
_disable();
if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
{
_mm_setcsr(ADJ(TrapFrame)->MxCsr);
__iretq(retaddr, v44, v45, v46, v47);
}
if( (_BYTE)KeSmapEnabled )
__stac();
while( (*((_BYTE *)KeGetCurrentThread() + 194) & 3) != 0 )
{
__writecr8(1ui64);
_enable();
KiInitiateUserApc((_KTRAP_FRAME *)1);
_disable();
__writecr8(0i64);
}
if( (*((_BYTE *)KeGetPcr() + 638) & 2) != 0 )
KiUpdateStibpPairing(0i64);
v34 = (_ETHREAD *)KeGetCurrentThread();
if( (*(_DWORD *)v34 & 0x8000000) != 0 )
KiRestoreSetContextState((INT64)v34, v28, v29, v30, v42);
v35 = (_ETHREAD *)KeGetCurrentThread();
if( (*(_DWORD *)v35 & 0x40010000) != 0 && (*((_BYTE *)v35 + 2) & 1) != 0 )
KiCopyCounters((_KTHREAD *)v35);
_mm_setcsr(ADJ(TrapFrame)->MxCsr);
if( LOWORD(ADJ(TrapFrame)->Dr7) )
KiRestoreDebugRegisterState();
R9 = ADJ(TrapFrame)->R9;
R8 = ADJ(TrapFrame)->R8;
__writegsbyte(0x853u, 0);
v38 = *((_BYTE *)KeGetPcr() + 637);
if( *((_BYTE *)KeGetPcr() + 634) != v38 )
{
__writegsbyte(0x27Au, v38);
__writemsr(0x48u, v38);
}
v39 = _bittestandreset16(MK_FP(__GS__, 632i64), 2u);
if( v39 )
__writemsr(0x49u, 1ui64);
v39 = _bittestandreset16(MK_FP(__GS__, 632i64), 5u);
if( v39 )
__flush_rsb();
if( (KiKvaShadow & 1) == 0 )
{
__swapgs();
__iretq(retaddr, v44, v45, v46, v47);
}
KiKernelExit(ADJ(TrapFrame)->Rcx, ADJ(TrapFrame)->Rdx, R8, R9, a5);
}Referenced by:
KxIsrLinkageShadow