KiMcheckAbort

VOID __fastcall KiMcheckAbort(UINT64 a1, UINT64 a2, UINT64 a3, UINT64 a4){
  unsigned __int64 v4; 
  unsigned __int64 v5; 
  unsigned __int64 v6; 
  _M128A v7; 
  _M128A v8; 
  _M128A v9; 
  _M128A v10; 
  _KTRAP_FRAME *__shifted(_KTRAP_FRAME,0x80) TrapFrame; 
  bool v12; 
  unsigned __int32 v13; 
  char *v14; 
  int v15; 
  int v16; 
  unsigned __int64 v17; 
  _M128A v18; 
  _M128A v19; 
  __int64 v20; 
  unsigned __int8 CurrentIrql; 
  INT64 v22; 
  unsigned __int64 Rsp; 
  unsigned __int64 v24; 
  unsigned __int64 v25; 
  _BYTE *Rip; 
  _WORD *v27; 
  _KTHREAD *CurrentThread; 
  unsigned __int64 *v29; 
  VOID(__fastcall *v30)(INT64, UINT64, UINT64, UINT64, CHAR); 
  unsigned __int64 *v31; 
  __m128i v32; 
  TrapFrame = KeGetTrapFrame();
  ADJ(TrapFrame)->ExceptionActive = 0;
  ADJ(TrapFrame)->Rax = v4;
  ADJ(TrapFrame)->Rcx = a1;
  ADJ(TrapFrame)->Rdx = a2;
  ADJ(TrapFrame)->R8 = a3;
  ADJ(TrapFrame)->R9 = a4;
  ADJ(TrapFrame)->R10 = v5;
  ADJ(TrapFrame)->R11 = v6;
  if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
  {
    ADJ(TrapFrame)->GsBase = __readmsr(0xC0000101);
    v13 = __segmentlimit(0x50u);
    if( v12 )
    {
      v16 = (v13 & 0x3FF) << 6;
      v15 = v13 >> 14;
    }
    else
    {
      if( !KUSER_SHARED_DATA.ProcessorFeatures[32] )
      {
        __sgdt(&ADJ(TrapFrame)->Xmm0);
        v14 = *(char **)(*(unsigned __int64 *)((char *)&ADJ(TrapFrame)->Xmm0.Low + 2) - 8000);
LABEL_8:
        __writemsr(0xC0000101, (unsigned __int64)v14);
        v17 = __readcr2();
        ADJ(TrapFrame)->FaultAddress = v17;
        KiSetSpecCtrlNmi();
        goto LABEL_13;
      }
      __asm { rdtscp }
      v15 = 1;
      v16 = 805306432;
    }
    v14 = (char *)*(&KiProcessorBlock + (unsigned int)KiProcessorNumberToIndexMappingTable[v16 | v15]) - 384;
    goto LABEL_8;
  }
  if( (KiKvaShadow & 1) == 0 )
    __swapgs();
  _mm_lfence();
  KiSetSpecCtrlNmi();
  v12 = (*(_BYTE *)(v20 + 3) & 3) == 0;
  LOWORD(ADJ(TrapFrame)->Dr7) = 0;
  if( !v12 )
    KiSaveDebugRegisterState();
LABEL_13:
  ADJ(TrapFrame)->MxCsr = _mm_getcsr();
  _mm_setcsr(*((_DWORD *)KeGetPcr() + 96));
  ADJ(TrapFrame)->Xmm0 = v7;
  ADJ(TrapFrame)->Xmm1 = v8;
  ADJ(TrapFrame)->Xmm2 = v9;
  ADJ(TrapFrame)->Xmm3 = v10;
  ADJ(TrapFrame)->Xmm4 = v18;
  ADJ(TrapFrame)->Xmm5 = v19;
  if( *((_BYTE *)KeGetPcr() + 32794) )
    KeWakeProcessor();
  if( (unsigned __int64)&ExpInterlockedPopEntrySListResume < ADJ(TrapFrame)->Rip
    && (unsigned __int64)&ExpInterlockedPopEntrySListEnd >= ADJ(TrapFrame)->Rip )
  {
    KiCheckForSListAddress(ADJ(TrapFrame));
  }
  __incgsdword(0x8000u);
  if( (_BYTE)KeSmapEnabled )
    __clac();
  CurrentIrql = KeGetCurrentIrql();
  __writecr8(0xFui64);
  ADJ(TrapFrame)->PreviousIrql = CurrentIrql;
  _enable();
  KiMcheckFastForward(ADJ(TrapFrame));
  __incgsbyte(0x7D67u);
  if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
  {
    Rsp = ADJ(TrapFrame)->Rsp;
    v24 = *(_QWORD *)(*((_QWORD *)KeGetPcr() + 1) + 52i64);
    if( Rsp <= v24 )
    {
      v22 = 24576i64;
      if( (KiKvaShadow & 1) != 0 )
        v22 = 464i64;
      if( Rsp > v24 - v22 )
        goto LABEL_28;
    }
    if( (KiKvaShadow & 1) != 0 )
    {
      v25 = *(_QWORD *)(*(_QWORD *)(*((_QWORD *)KeGetPcr() + 1) + 52i64) + 8i64);
      if( Rsp <= v25 && Rsp > v25 - 24544 )
      {
LABEL_28:
        ADJ(TrapFrame)->SegSs |= 4u;
        _InterlockedIncrement64(&KiMcheckNmiBlocking);
      }
    }
    Rip = (_BYTE *)ADJ(TrapFrame)->Rip;
    if( *Rip == 0xF4 )
    {
      v27 = Rip - 1;
      if( *v27 == 0xF4FB )
      {
        ADJ(TrapFrame)->EFlags &= ~0x200u;
        ADJ(TrapFrame)->Rip = (unsigned __int64)v27;
        _InterlockedIncrement64(&KiMcheckStiBlocking);
      }
    }
  }
  KxMcheckAbort((INT64)ADJ(TrapFrame), v22, &v32);
  if( (v32.m128i_i8[0] & 1) != 0 )
  {
    *(__m128i *)(*((_QWORD *)KeGetCurrentThread() + 5) - 416i64) = _mm_load_si128(&v32);
    ADJ(TrapFrame)->ExceptionActive = 1;
  }
  __writegsbyte(0x7D67u, *((_BYTE *)KeGetPcr() + 32103) - 1);
  _disable();
  __writecr8(ADJ(TrapFrame)->PreviousIrql);
  _disable();
  if( (ADJ(TrapFrame)->SegCs & 1) != 0 )
  {
    if( (_BYTE)KeSmapEnabled )
      __stac();
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    if( (*(_DWORD *)CurrentThread & 0x40010000) != 0 && (*((_BYTE *)CurrentThread + 2) & 1) != 0 )
      KiCopyCounters((_KTHREAD *)CurrentThread);
    _mm_setcsr(ADJ(TrapFrame)->MxCsr);
    if( LOWORD(ADJ(TrapFrame)->Dr7) )
      KiRestoreDebugRegisterState();
    if( ADJ(TrapFrame)->ExceptionActive )
    {
      v29 = (unsigned __int64 *)(*((_QWORD *)KeGetCurrentThread() + 5) - 40i64);
      *v29 = ADJ(TrapFrame)->Rip;
      v29[1] = ADJ(TrapFrame)->SegCs;
      v29[2] = ADJ(TrapFrame)->EFlags;
      v29[3] = ADJ(TrapFrame)->Rsp;
      v29[4] = ADJ(TrapFrame)->SegSs;
      ADJ(TrapFrame)->SegSs = 24;
      ADJ(TrapFrame)->SegCs = 16;
      ADJ(TrapFrame)->EFlags &= ~0x200u;
      v30 = KxMcheckAlternateReturn;
      if( (KiKvaShadow & 1) != 0 )
      {
        v31 = (unsigned __int64 *)*((_QWORD *)KeGetPcr() + 7);
        v31[2237] = *((_QWORD *)KeGetPcr() + 4608) & 0x7FFFFFFFFFFFFFFFi64;
        v31[2236] = (unsigned __int64)KeGetPcr();
        v31 += 2107;
        *v31 = *v29;
        v31[1] = v29[1];
        v31[2] = v29[2];
        v31[3] = v29[3];
        v31[4] = (unsigned __int64)v29;
        v29 = v31;
        v30 = KxMcheckAlternateReturnShadow;
      }
      ADJ(TrapFrame)->Rip = (unsigned __int64)v30;
      ADJ(TrapFrame)->Rsp = (unsigned __int64)v29;
    }
    else
    {
      __writegsbyte(0x853u, ADJ(TrapFrame)->InterruptRetpolineState);
      if( *((_BYTE *)KeGetPcr() + 635) )
        __writemsr(0x48u, ADJ(TrapFrame)->FaultIndicator);
    }
    if( (KiKvaShadow & 1) != 0 )
    {
LABEL_49:
      KiKernelIstMceExit();
      return;
    }
    __swapgs();
    _mm_lfence();
  }
  else
  {
    _mm_setcsr(ADJ(TrapFrame)->MxCsr);
    __writegsbyte(0x853u, ADJ(TrapFrame)->InterruptRetpolineState);
    if( *((_BYTE *)KeGetPcr() + 635) )
      __writemsr(0x48u, ADJ(TrapFrame)->FaultIndicator);
    __writemsr(0xC0000101, ADJ(TrapFrame)->GsBase);
    __writecr2(ADJ(TrapFrame)->FaultAddress);
    if( (KiKvaShadow & 1) != 0 )
      goto LABEL_49;
  }
  KiMcheckExit();
}

Referenced by:

KiMcheckAbortShadow