KxIsrLinkage

VOID __fastcall KxIsrLinkage(UINT64 SecurityDomain, UINT64 BpbState, UINT64 a3, UINT64 a4, CHAR a5){
  unsigned __int64 v5; 
  unsigned __int64 v6; 
  unsigned __int64 v7; 
  _M128A v8; 
  _M128A v9; 
  _M128A v10; 
  _M128A v11; 
  _M128A v12; 
  _M128A v13; 
  _KTRAP_FRAME *__shifted(_KTRAP_FRAME,0x80) TrapFrame; 
  _ETHREAD *CurrentThread; 
  unsigned __int8 v16; 
  bool v17; 
  __int64 ErrorCode_low; 
  __int64 v19; 
  unsigned __int64 v20; 
  unsigned __int8 CurrentIrql; 
  struct _KPRCB *CurrentPrcb; 
  __int64 v23; 
  UINT64 v24; 
  __int64 v25; 
  UINT64 v26; 
  int v27; 
  INT64 v28; 
  INT64 v29; 
  INT64 v30; 
  struct _KPRCB *v31; 
  unsigned __int64 v32; 
  UINT64 v33; 
  _ETHREAD *v34; 
  _KTHREAD *v35; 
  INT64 R9; 
  INT64 R8; 
  unsigned __int8 v38; 
  unsigned __int8 v39; 
  CHAR v42; 
  void *retaddr; 
  __int16 v44; 
  int v45; 
  void *v46; 
  __int16 v47; 
  TrapFrame = KeGetTrapFrame();
  ADJ(TrapFrame)->ExceptionActive = 0;
  ADJ(TrapFrame)->Rax = v5;
  ADJ(TrapFrame)->Rcx = SecurityDomain;
  ADJ(TrapFrame)->Rdx = BpbState;
  ADJ(TrapFrame)->R8 = a3;
  ADJ(TrapFrame)->R9 = a4;
  ADJ(TrapFrame)->R10 = v6;
  ADJ(TrapFrame)->R11 = v7;
  if( (ADJ(TrapFrame)->SegCs & 1) != 0 )
  {
    if( (KiKvaShadow & 1) == 0 )
      __swapgs();
    _mm_lfence();
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    SecurityDomain = *(_QWORD *)(*((_QWORD *)CurrentThread + 68) + 2528i64);
    __writegsqword(0x270u, SecurityDomain);
    __writegsbyte(0x851u, *((_BYTE *)KeGetPcr() + 2128));
    LOBYTE(SecurityDomain) = *((_BYTE *)KeGetPcr() + 632);
    __writegsbyte(0x852u, SecurityDomain);
    v16 = *((_BYTE *)KeGetPcr() + 635);
    if( *((_BYTE *)KeGetPcr() + 634) != v16 )
    {
      __writegsbyte(0x27Au, v16);
      SecurityDomain = 72i64;
      HIDWORD(BpbState) = 0;
      __writemsr(0x48u, v16);
    }
    LODWORD(BpbState) = *((unsigned __int8 *)KeGetPcr() + 632);
    if( (BpbState & 8) != 0 )
    {
      SecurityDomain = 73i64;
      __writemsr(0x49u, 1ui64);
      BpbState = *((unsigned __int8 *)KeGetPcr() + 632);
      LODWORD(BpbState) = (unsigned __int8)BpbState;
    }
    if( (BpbState & 2) != 0 )
      __flush_rsb();
    _mm_lfence();
    __writegsbyte(0x853u, 0);
    v17 = (*((_BYTE *)CurrentThread + 3) & 3) == 0;
    LOWORD(ADJ(TrapFrame)->Dr7) = 0;
    if( !v17 )
      KiSaveDebugRegisterState();
  }
  else
  {
    _mm_lfence();
    if( (*((_BYTE *)KeGetPcr() + 632) & 1) != 0 )
    {
      SecurityDomain = 72i64;
      BpbState = 0i64;
      __writemsr(0x48u, *((unsigned __int8 *)KeGetPcr() + 634));
    }
    else
    {
      _mm_lfence();
    }
  }
  ADJ(TrapFrame)->MxCsr = _mm_getcsr();
  _mm_setcsr(*((_DWORD *)KeGetPcr() + 96));
  ADJ(TrapFrame)->Xmm0 = v8;
  ADJ(TrapFrame)->Xmm1 = v9;
  ADJ(TrapFrame)->Xmm2 = v10;
  ADJ(TrapFrame)->Xmm3 = v11;
  ADJ(TrapFrame)->Xmm4 = v12;
  ADJ(TrapFrame)->Xmm5 = v13;
  if( *((_BYTE *)KeGetPcr() + 32794) )
    KeWakeProcessor();
  if( (unsigned __int64)&ExpInterlockedPopEntrySListResume < ADJ(TrapFrame)->Rip
    && (unsigned __int64)&ExpInterlockedPopEntrySListEnd >= ADJ(TrapFrame)->Rip )
  {
    KiCheckForSListAddress(ADJ(TrapFrame));
  }
  ErrorCode_low = LOBYTE(ADJ(TrapFrame)->ErrorCode);
  v19 = *((_QWORD *)KeGetCurrentPrcb() + ErrorCode_low + 1576);
  __incgsdword(0x8000u);
  if( (_BYTE)KeSmapEnabled )
    __clac();
  if( v19 )
  {
    (*(void(__fastcall **)(UINT64, UINT64))(v19 + 80))(SecurityDomain, BpbState);
    return;
  }
  v20 = (unsigned int)ErrorCode_low >> 4;
  CurrentIrql = KeGetCurrentIrql();
  __writecr8(v20);
  ADJ(TrapFrame)->PreviousIrql = CurrentIrql;
  CurrentPrcb = KeGetCurrentPrcb();
  if( ++*((_BYTE *)CurrentPrcb + 32) == 1 )
  {
    v23 = *((_QWORD *)CurrentPrcb + 1);
    v24 = __rdtsc() - *((_QWORD *)CurrentPrcb + 4056);
    *(_QWORD *)(v23 + 72) += v24;
    v25 = *(unsigned int *)(v23 + 80);
    *((_QWORD *)CurrentPrcb + 4056) += v24;
    v26 = v24 + v25;
    v27 = v26;
    if( HIDWORD(v26) )
      v27 = -1;
    *(_DWORD *)(v23 + 80) = v27;
    if( (*(_BYTE *)(v23 + 2) & 0x3E) != 0 )
      KiEndThreadAccountingPeriod(KeGetCurrentPrcb(), (_KTHREAD *)v23, v24);
  }
  _enable();
  if( KiBugCheckUnexpectedInterrupts )
  {
    ADJ(TrapFrame)->P5 = 0i64;
    KiBugCheckDispatch(0x12u, 1ui64, LOBYTE(ADJ(TrapFrame)->ErrorCode), 0i64);
  }
  _disable();
  HalPerformEndOfInterrupt(0i64);
  v31 = KeGetCurrentPrcb();
  if( *((_BYTE *)v31 + 32) > 1u )
    goto LABEL_39;
  v32 = __rdtsc();
  v28 = (unsigned __int64)HIDWORD(v32) << 32;
  v33 = (v28 | (unsigned int)v32) - *((_QWORD *)v31 + 4056);
  *((_QWORD *)v31 + 4071) += v33;
  *((_QWORD *)v31 + 4056) += v33;
  v29 = v33;
  if( (*(_BYTE *)(*((_QWORD *)v31 + 1) + 2i64) & 0x72) != 0 )
  {
    KiBeginThreadAccountingPeriod(v31, 0i64, v33);
    v31 = KeGetCurrentPrcb();
    ++*((_BYTE *)v31 + 32);
  }
  LOBYTE(v28) = *((_BYTE *)v31 + 6);
  *((_BYTE *)v31 + 6) = 0;
  if( *((_BYTE *)v31 + 7) || !(_BYTE)v28 )
    goto LABEL_39;
  if( ADJ(TrapFrame)->PreviousIrql >= 2u )
  {
    HalRequestSoftwareInterrupt(2i64);
    v31 = KeGetCurrentPrcb();
LABEL_39:
    --*((_BYTE *)v31 + 32);
    goto LABEL_40;
  }
  *((_BYTE *)v31 + 32) = 0;
  KiDpcInterruptBypass();
LABEL_40:
  __writecr8(ADJ(TrapFrame)->PreviousIrql);
  _disable();
  if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
  {
    _mm_setcsr(ADJ(TrapFrame)->MxCsr);
    __iretq(retaddr, v44, v45, v46, v47);
  }
  if( (_BYTE)KeSmapEnabled )
    __stac();
  while( (*((_BYTE *)KeGetCurrentThread() + 194) & 3) != 0 )
  {
    __writecr8(1ui64);
    _enable();
    KiInitiateUserApc((_KTRAP_FRAME *)1);
    _disable();
    __writecr8(0i64);
  }
  if( (*((_BYTE *)KeGetPcr() + 638) & 2) != 0 )
    KiUpdateStibpPairing(0i64);
  v34 = (_ETHREAD *)KeGetCurrentThread();
  if( (*(_DWORD *)v34 & 0x8000000) != 0 )
    KiRestoreSetContextState((INT64)v34, v28, v29, v30, v42);
  v35 = (_ETHREAD *)KeGetCurrentThread();
  if( (*(_DWORD *)v35 & 0x40010000) != 0 && (*((_BYTE *)v35 + 2) & 1) != 0 )
    KiCopyCounters((_KTHREAD *)v35);
  _mm_setcsr(ADJ(TrapFrame)->MxCsr);
  if( LOWORD(ADJ(TrapFrame)->Dr7) )
    KiRestoreDebugRegisterState();
  R9 = ADJ(TrapFrame)->R9;
  R8 = ADJ(TrapFrame)->R8;
  __writegsbyte(0x853u, 0);
  v38 = *((_BYTE *)KeGetPcr() + 637);
  if( *((_BYTE *)KeGetPcr() + 634) != v38 )
  {
    __writegsbyte(0x27Au, v38);
    __writemsr(0x48u, v38);
  }
  v39 = _bittestandreset16(MK_FP(__GS__, 632i64), 2u);
  if( v39 )
    __writemsr(0x49u, 1ui64);
  v39 = _bittestandreset16(MK_FP(__GS__, 632i64), 5u);
  if( v39 )
    __flush_rsb();
  if( (KiKvaShadow & 1) == 0 )
  {
    __swapgs();
    __iretq(retaddr, v44, v45, v46, v47);
  }
  KiKernelExit(ADJ(TrapFrame)->Rcx, ADJ(TrapFrame)->Rdx, R8, R9, a5);
}

Referenced by:

KxIsrLinkageShadow