KiMcheckAbort
VOID __fastcall KiMcheckAbort(UINT64 a1, UINT64 a2, UINT64 a3, UINT64 a4){
unsigned __int64 v4;
unsigned __int64 v5;
unsigned __int64 v6;
_M128A v7;
_M128A v8;
_M128A v9;
_M128A v10;
_KTRAP_FRAME *__shifted(_KTRAP_FRAME,0x80) TrapFrame;
bool v12;
unsigned __int32 v13;
char *v14;
int v15;
int v16;
unsigned __int64 v17;
_M128A v18;
_M128A v19;
__int64 v20;
unsigned __int8 CurrentIrql;
INT64 v22;
unsigned __int64 Rsp;
unsigned __int64 v24;
unsigned __int64 v25;
_BYTE *Rip;
_WORD *v27;
_KTHREAD *CurrentThread;
unsigned __int64 *v29;
VOID(__fastcall *v30)(INT64, UINT64, UINT64, UINT64, CHAR);
unsigned __int64 *v31;
__m128i v32;
TrapFrame = KeGetTrapFrame();
ADJ(TrapFrame)->ExceptionActive = 0;
ADJ(TrapFrame)->Rax = v4;
ADJ(TrapFrame)->Rcx = a1;
ADJ(TrapFrame)->Rdx = a2;
ADJ(TrapFrame)->R8 = a3;
ADJ(TrapFrame)->R9 = a4;
ADJ(TrapFrame)->R10 = v5;
ADJ(TrapFrame)->R11 = v6;
if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
{
ADJ(TrapFrame)->GsBase = __readmsr(0xC0000101);
v13 = __segmentlimit(0x50u);
if( v12 )
{
v16 = (v13 & 0x3FF) << 6;
v15 = v13 >> 14;
}
else
{
if( !KUSER_SHARED_DATA.ProcessorFeatures[32] )
{
__sgdt(&ADJ(TrapFrame)->Xmm0);
v14 = *(char **)(*(unsigned __int64 *)((char *)&ADJ(TrapFrame)->Xmm0.Low + 2) - 8000);
LABEL_8:
__writemsr(0xC0000101, (unsigned __int64)v14);
v17 = __readcr2();
ADJ(TrapFrame)->FaultAddress = v17;
KiSetSpecCtrlNmi();
goto LABEL_13;
}
__asm { rdtscp }
v15 = 1;
v16 = 805306432;
}
v14 = (char *)*(&KiProcessorBlock + (unsigned int)KiProcessorNumberToIndexMappingTable[v16 | v15]) - 384;
goto LABEL_8;
}
if( (KiKvaShadow & 1) == 0 )
__swapgs();
_mm_lfence();
KiSetSpecCtrlNmi();
v12 = (*(_BYTE *)(v20 + 3) & 3) == 0;
LOWORD(ADJ(TrapFrame)->Dr7) = 0;
if( !v12 )
KiSaveDebugRegisterState();
LABEL_13:
ADJ(TrapFrame)->MxCsr = _mm_getcsr();
_mm_setcsr(*((_DWORD *)KeGetPcr() + 96));
ADJ(TrapFrame)->Xmm0 = v7;
ADJ(TrapFrame)->Xmm1 = v8;
ADJ(TrapFrame)->Xmm2 = v9;
ADJ(TrapFrame)->Xmm3 = v10;
ADJ(TrapFrame)->Xmm4 = v18;
ADJ(TrapFrame)->Xmm5 = v19;
if( *((_BYTE *)KeGetPcr() + 32794) )
KeWakeProcessor();
if( (unsigned __int64)&ExpInterlockedPopEntrySListResume < ADJ(TrapFrame)->Rip
&& (unsigned __int64)&ExpInterlockedPopEntrySListEnd >= ADJ(TrapFrame)->Rip )
{
KiCheckForSListAddress(ADJ(TrapFrame));
}
__incgsdword(0x8000u);
if( (_BYTE)KeSmapEnabled )
__clac();
CurrentIrql = KeGetCurrentIrql();
__writecr8(0xFui64);
ADJ(TrapFrame)->PreviousIrql = CurrentIrql;
_enable();
KiMcheckFastForward(ADJ(TrapFrame));
__incgsbyte(0x7D67u);
if( (ADJ(TrapFrame)->SegCs & 1) == 0 )
{
Rsp = ADJ(TrapFrame)->Rsp;
v24 = *(_QWORD *)(*((_QWORD *)KeGetPcr() + 1) + 52i64);
if( Rsp <= v24 )
{
v22 = 24576i64;
if( (KiKvaShadow & 1) != 0 )
v22 = 464i64;
if( Rsp > v24 - v22 )
goto LABEL_28;
}
if( (KiKvaShadow & 1) != 0 )
{
v25 = *(_QWORD *)(*(_QWORD *)(*((_QWORD *)KeGetPcr() + 1) + 52i64) + 8i64);
if( Rsp <= v25 && Rsp > v25 - 24544 )
{
LABEL_28:
ADJ(TrapFrame)->SegSs |= 4u;
_InterlockedIncrement64(&KiMcheckNmiBlocking);
}
}
Rip = (_BYTE *)ADJ(TrapFrame)->Rip;
if( *Rip == 0xF4 )
{
v27 = Rip - 1;
if( *v27 == 0xF4FB )
{
ADJ(TrapFrame)->EFlags &= ~0x200u;
ADJ(TrapFrame)->Rip = (unsigned __int64)v27;
_InterlockedIncrement64(&KiMcheckStiBlocking);
}
}
}
KxMcheckAbort((INT64)ADJ(TrapFrame), v22, &v32);
if( (v32.m128i_i8[0] & 1) != 0 )
{
*(__m128i *)(*((_QWORD *)KeGetCurrentThread() + 5) - 416i64) = _mm_load_si128(&v32);
ADJ(TrapFrame)->ExceptionActive = 1;
}
__writegsbyte(0x7D67u, *((_BYTE *)KeGetPcr() + 32103) - 1);
_disable();
__writecr8(ADJ(TrapFrame)->PreviousIrql);
_disable();
if( (ADJ(TrapFrame)->SegCs & 1) != 0 )
{
if( (_BYTE)KeSmapEnabled )
__stac();
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( (*(_DWORD *)CurrentThread & 0x40010000) != 0 && (*((_BYTE *)CurrentThread + 2) & 1) != 0 )
KiCopyCounters((_KTHREAD *)CurrentThread);
_mm_setcsr(ADJ(TrapFrame)->MxCsr);
if( LOWORD(ADJ(TrapFrame)->Dr7) )
KiRestoreDebugRegisterState();
if( ADJ(TrapFrame)->ExceptionActive )
{
v29 = (unsigned __int64 *)(*((_QWORD *)KeGetCurrentThread() + 5) - 40i64);
*v29 = ADJ(TrapFrame)->Rip;
v29[1] = ADJ(TrapFrame)->SegCs;
v29[2] = ADJ(TrapFrame)->EFlags;
v29[3] = ADJ(TrapFrame)->Rsp;
v29[4] = ADJ(TrapFrame)->SegSs;
ADJ(TrapFrame)->SegSs = 24;
ADJ(TrapFrame)->SegCs = 16;
ADJ(TrapFrame)->EFlags &= ~0x200u;
v30 = KxMcheckAlternateReturn;
if( (KiKvaShadow & 1) != 0 )
{
v31 = (unsigned __int64 *)*((_QWORD *)KeGetPcr() + 7);
v31[2237] = *((_QWORD *)KeGetPcr() + 4608) & 0x7FFFFFFFFFFFFFFFi64;
v31[2236] = (unsigned __int64)KeGetPcr();
v31 += 2107;
*v31 = *v29;
v31[1] = v29[1];
v31[2] = v29[2];
v31[3] = v29[3];
v31[4] = (unsigned __int64)v29;
v29 = v31;
v30 = KxMcheckAlternateReturnShadow;
}
ADJ(TrapFrame)->Rip = (unsigned __int64)v30;
ADJ(TrapFrame)->Rsp = (unsigned __int64)v29;
}
else
{
__writegsbyte(0x853u, ADJ(TrapFrame)->InterruptRetpolineState);
if( *((_BYTE *)KeGetPcr() + 635) )
__writemsr(0x48u, ADJ(TrapFrame)->FaultIndicator);
}
if( (KiKvaShadow & 1) != 0 )
{
LABEL_49:
KiKernelIstMceExit();
return;
}
__swapgs();
_mm_lfence();
}
else
{
_mm_setcsr(ADJ(TrapFrame)->MxCsr);
__writegsbyte(0x853u, ADJ(TrapFrame)->InterruptRetpolineState);
if( *((_BYTE *)KeGetPcr() + 635) )
__writemsr(0x48u, ADJ(TrapFrame)->FaultIndicator);
__writemsr(0xC0000101, ADJ(TrapFrame)->GsBase);
__writecr2(ADJ(TrapFrame)->FaultAddress);
if( (KiKvaShadow & 1) != 0 )
goto LABEL_49;
}
KiMcheckExit();
}Referenced by:
KiMcheckAbortShadow