SmFirstTimeInit
__int64 __fastcall SmFirstTimeInit(int a1, int edx0){
_ETHREAD *CurrentThread;
UINT64 v5;
VOID *v6;
unsigned __int64 v7;
char v8;
NTSTATUS MinimalProcess;
_ETHREAD *v10;
unsigned int SessionId;
unsigned __int8 v12;
int v13;
bool v14;
__int64 v15;
_KLOCK_ENTRY *v16;
__int64 v17;
UINT64 v19;
unsigned __int16 v20;
UINT64 v21;
UINT64 a3;
_HANDLE Handle[2];
PVOID Object;
_KAPC_STATE ApcState;
UINT64 a2;
int v27;
LODWORD(v21) = 1048579;
memset(&ApcState, 0, sizeof(ApcState));
a2 = 0x10000200100005i64;
*(_QWORD *)Handle = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v27 = 1048596;
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx(&BugCheckParameter2, 0i64);
if( dword_140D23148 )
{
if( dword_140D23148 != edx0 )
{
MinimalProcess = -1073741217;
goto LABEL_12;
}
}
else
{
dword_140D23148 = edx0;
}
if( ((unsigned __int8)StoreProcess & 8) == 0 )
{
MinimalProcess = SmRegistrationCtxStart(&CachesUpdatedEvent);
if( MinimalProcess < 0 )
goto LABEL_12;
LODWORD(StoreProcess) = (unsigned int)StoreProcess | 8;
}
v6 = (VOID *)MaximumWorkerThreads;
if( !MaximumWorkerThreads )
{
if( !MmStoreCheckPagefiles() )
{
MinimalProcess = -1073741637;
goto LABEL_12;
}
KiStackAttachProcess(PsInitialSystemProcess, 0i64, &ApcState);
LOBYTE(v19) = PsInitialSystemProcess->Protection.Level;
MinimalProcess = PsCreateMinimalProcess(
PsInitialSystemProcess,
(PS_PROTECTION)((char *)&stru_140C00F40 + 4392),
0i64,
v19,
0i64);
KiUnstackDetachProcess(&ApcState, 0i64);
if( MinimalProcess < 0 )
goto LABEL_12;
Object = 0i64;
MinimalProcess = ObReferenceObjectByHandle(*(VOID **)Handle, 0i64, 0i64, 0, &Object, 0i64);
if( MinimalProcess < 0 )
{
ZwClose(Handle[0]);
goto LABEL_12;
}
v6 = *(VOID **)Handle;
MaximumWorkerThreads = *(_QWORD *)Handle;
::Object = Object;
}
v7 = (unsigned int)StoreProcess;
if( ((unsigned __int8)StoreProcess & 2) == 0 )
{
v20 = dword_140D23148;
qword_140D23100 = (__int64)v6;
MinimalProcess = SMKM_STORE_MGR::SmStorePrepare((__int64)SmGlobals);
if( MinimalProcess >= 0 )
{
if( (dword_140D230F0 & 0x20) == 0
|| (MinimalProcess = SMKM_STORE_MGR::SmCompressCtxStart(
(__int64)&unk_140D22EB0,
(__int64)SmGlobals,
v20),
MinimalProcess >= 0) )
{
MinimalProcess = 0;
}
}
if( MinimalProcess < 0 )
{
SMKM_STORE_MGR::SmReInitialize((INT64)SmGlobals);
ObfDereferenceObjectWithTag(::Object, 0x746C6644ui64);
ZwClose(MaximumWorkerThreads);
::Object = 0i64;
MaximumWorkerThreads = 0i64;
goto LABEL_12;
}
v7 = (unsigned int)StoreProcess | 2;
LODWORD(StoreProcess) = (unsigned int)StoreProcess | 2;
}
if( (v7 & 0x10) != 0
|| (v7 = ((unsigned __int8)StoreProcess ^ (16 * MmStoreChargeResidentAvailableForRead(1i64))) & 0x10 ^ (unsigned int)StoreProcess,
LODWORD(StoreProcess) = v7,
(v7 & 0x10) != 0) )
{
if( dword_140D23144 )
{
if( a1 != dword_140D23144 )
{
MinimalProcess = -1073741800;
goto LABEL_12;
}
}
else
{
LODWORD(v21) = (a1 & 0xFFFF000 | 0x10000300u) >> 8;
HIDWORD(a2) = v21 & 0xFFFF0 | 0x100002;
LODWORD(a2) = v21 & 0xFFFF0 | 0x100005;
MinimalProcess = SmFpPreAllocate(&qword_140D23410, &a2, 3ui64);
if( MinimalProcess < 0 )
goto LABEL_12;
MinimalProcess = SmFpPreAllocate(FpContext, &v21, 1ui64);
if( MinimalProcess < 0 )
{
SmFpCleanup((_SM_FORWARD_PROGRESS_CTX *)&qword_140D23410);
memset(&qword_140D23410, 0i64, 0x70u);
word_140D23418 = 1;
qword_140D23428 = (__int64)&qword_140D23420;
qword_140D23420 = (__int64)&qword_140D23420;
byte_140D2341A = 6;
dword_140D2341C = 0;
goto LABEL_12;
}
dword_140D23144 = a1;
}
v8 = (char)StoreProcess;
if( ((unsigned __int8)StoreProcess & 0x20) == 0 )
{
MinimalProcess = ExAllocatePrivateWorkerPool(&PoolID, (UINT64)v6, v5);
if( MinimalProcess < 0 )
goto LABEL_12;
v8 = (unsigned __int8)StoreProcess | 0x20;
LODWORD(StoreProcess) = (unsigned int)StoreProcess | 0x20;
}
if( (v8 & 1) == 0 )
{
MinimalProcess = MmStoreRegister((_EPROCESS *)v7);
if( MinimalProcess < 0 )
goto LABEL_12;
LODWORD(StoreProcess) = (unsigned int)StoreProcess | 1;
}
MinimalProcess = 0;
}
else
{
MinimalProcess = -1073741670;
}
LABEL_12:
if( (_InterlockedExchangeAdd64(&BugCheckParameter2._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(&BugCheckParameter2);
LODWORD(a3) = 0;
v10 = (_ETHREAD *)KeGetCurrentThread();
if( MiGetSystemRegionType((UINT64)&BugCheckParameter2) == 1 )
SessionId = MmGetSessionIdEx(v10->Tcb.ApcState.Process);
else
SessionId = -1;
--v10->Tcb.SpecialApcDisable;
v12 = ++v10->Tcb.AbAllocationRegionCount;
v13 = ((char)v10->Tcb.AbEntrySummary | (char)v10->Tcb.AbOrphanedEntrySummary) ^ 0x3F;
while( 1 )
{
v14 = !_BitScanReverse((unsigned int *)&v15, v13);
HIDWORD(v21) = v15;
if( v14 )
break;
v16 = &v10->Tcb.LockEntries[v15];
v13 &= ~(1 << v15);
if( (v16->AcquiredByte & 1) != 0
&& (v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 & 1) == 0
&& (v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 & 0x7FFFFFFFFFFFFFFCi64) == ((unsigned __int64)&BugCheckParameter2 & 0x7FFFFFFFFFFFFFFCi64)
&& v16->LockState.SessionId == SessionId )
{
v16->AcquiredByte &= ~1u;
if( v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 )
{
if( v16 )
{
v16->CrossThreadReleasableAndBusyByte |= 2u;
if( v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 < 0 )
KiAbEntryRemoveFromTree(v16);
LODWORD(a3) = v16->BoostBitmap.AllFields & 0x1FFFF;
v16->BoostBitmap.AllFields &= 0xFFFE0000;
v16->ThreadLocalFlags &= ~1u;
v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 = 0i64;
v17 = v16 - v10->Tcb.LockEntries;
if( v12 == 1 )
v10->Tcb.AbEntrySummary |= 1 << v17;
else
_InterlockedOr8((volatile signed __int8 *)&v10->Tcb.AbOrphanedEntrySummary, 1 << v17);
goto LABEL_28;
}
break;
}
}
}
if( (*(&v10->Tcb.MiscFlags + 1) & 0x10000) == 0 )
KeBugCheckEx(0x162u, v10, &BugCheckParameter2, (PVOID)SessionId, 0i64);
LABEL_28:
--v10->Tcb.AbAllocationRegionCount;
KiAbThreadRemoveBoosts(&v10->Tcb, &BugCheckParameter2, &a3);
v14 = v10->Tcb.SpecialApcDisable++ == -1;
if( v14 && ($F25F8C4BA33AF922A5F1AF68CD89DDDF *)v10->Tcb.ApcState.ApcListHead[0].Flink != &v10->Tcb.152 )
KiCheckForKernelApcDelivery();
KeLeaveCriticalRegion();
return(unsigned int)MinimalProcess;
}Referenced by:
SmProcessCreateRequest