SmFirstTimeInit

__int64 __fastcall SmFirstTimeInit(int a1, int edx0){
  _ETHREAD *CurrentThread; 
  UINT64 v5; 
  VOID *v6; 
  unsigned __int64 v7; 
  char v8; 
  NTSTATUS MinimalProcess; 
  _ETHREAD *v10; 
  unsigned int SessionId; 
  unsigned __int8 v12; 
  int v13; 
  bool v14; 
  __int64 v15; 
  _KLOCK_ENTRY *v16; 
  __int64 v17; 
  UINT64 v19; 
  unsigned __int16 v20; 
  UINT64 v21; 
  UINT64 a3; 
  _HANDLE Handle[2]; 
  PVOID Object; 
  _KAPC_STATE ApcState; 
  UINT64 a2; 
  int v27; 

  LODWORD(v21) = 1048579;
  memset(&ApcState, 0, sizeof(ApcState));
  a2 = 0x10000200100005i64;
  *(_QWORD *)Handle = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v27 = 1048596;
  --CurrentThread->Tcb.KernelApcDisable;
  ExAcquirePushLockExclusiveEx(&BugCheckParameter2, 0i64);
  if( dword_140D23148 )
  {
    if( dword_140D23148 != edx0 )
    {
      MinimalProcess = -1073741217;
      goto LABEL_12;
    }
  }
  else
  {
    dword_140D23148 = edx0;
  }
  if( ((unsigned __int8)StoreProcess & 8) == 0 )
  {
    MinimalProcess = SmRegistrationCtxStart(&CachesUpdatedEvent);
    if( MinimalProcess < 0 )
      goto LABEL_12;
    LODWORD(StoreProcess) = (unsigned int)StoreProcess | 8;
  }
  v6 = (VOID *)MaximumWorkerThreads;
  if( !MaximumWorkerThreads )
  {
    if( !MmStoreCheckPagefiles() )
    {
      MinimalProcess = -1073741637;
      goto LABEL_12;
    }
    KiStackAttachProcess(PsInitialSystemProcess, 0i64, &ApcState);
    LOBYTE(v19) = PsInitialSystemProcess->Protection.Level;
    MinimalProcess = PsCreateMinimalProcess(
                       PsInitialSystemProcess,
                       (PS_PROTECTION)((char *)&stru_140C00F40 + 4392),
                       0i64,
                       v19,
                       0i64);
    KiUnstackDetachProcess(&ApcState, 0i64);
    if( MinimalProcess < 0 )
      goto LABEL_12;
    Object = 0i64;
    MinimalProcess = ObReferenceObjectByHandle(*(VOID **)Handle, 0i64, 0i64, 0, &Object, 0i64);
    if( MinimalProcess < 0 )
    {
      ZwClose(Handle[0]);
      goto LABEL_12;
    }
    v6 = *(VOID **)Handle;
    MaximumWorkerThreads = *(_QWORD *)Handle;
    ::Object = Object;
  }
  v7 = (unsigned int)StoreProcess;
  if( ((unsigned __int8)StoreProcess & 2) == 0 )
  {
    v20 = dword_140D23148;
    qword_140D23100 = (__int64)v6;
    MinimalProcess = SMKM_STORE_MGR::SmStorePrepare((__int64)SmGlobals);
    if( MinimalProcess >= 0 )
    {
      if( (dword_140D230F0 & 0x20) == 0
        || (MinimalProcess = SMKM_STORE_MGR::SmCompressCtxStart(
                               (__int64)&unk_140D22EB0,
                               (__int64)SmGlobals,
                               v20),
            MinimalProcess >= 0) )
      {
        MinimalProcess = 0;
      }
    }
    if( MinimalProcess < 0 )
    {
      SMKM_STORE_MGR::SmReInitialize((INT64)SmGlobals);
      ObfDereferenceObjectWithTag(::Object, 0x746C6644ui64);
      ZwClose(MaximumWorkerThreads);
      ::Object = 0i64;
      MaximumWorkerThreads = 0i64;
      goto LABEL_12;
    }
    v7 = (unsigned int)StoreProcess | 2;
    LODWORD(StoreProcess) = (unsigned int)StoreProcess | 2;
  }
  if( (v7 & 0x10) != 0
    || (v7 = ((unsigned __int8)StoreProcess ^ (16 * MmStoreChargeResidentAvailableForRead(1i64))) & 0x10 ^ (unsigned int)StoreProcess,
        LODWORD(StoreProcess) = v7,
        (v7 & 0x10) != 0) )
  {
    if( dword_140D23144 )
    {
      if( a1 != dword_140D23144 )
      {
        MinimalProcess = -1073741800;
        goto LABEL_12;
      }
    }
    else
    {
      LODWORD(v21) = (a1 & 0xFFFF000 | 0x10000300u) >> 8;
      HIDWORD(a2) = v21 & 0xFFFF0 | 0x100002;
      LODWORD(a2) = v21 & 0xFFFF0 | 0x100005;
      MinimalProcess = SmFpPreAllocate(&qword_140D23410, &a2, 3ui64);
      if( MinimalProcess < 0 )
        goto LABEL_12;
      MinimalProcess = SmFpPreAllocate(FpContext, &v21, 1ui64);
      if( MinimalProcess < 0 )
      {
        SmFpCleanup((_SM_FORWARD_PROGRESS_CTX *)&qword_140D23410);
        memset(&qword_140D23410, 0i64, 0x70u);
        word_140D23418 = 1;
        qword_140D23428 = (__int64)&qword_140D23420;
        qword_140D23420 = (__int64)&qword_140D23420;
        byte_140D2341A = 6;
        dword_140D2341C = 0;
        goto LABEL_12;
      }
      dword_140D23144 = a1;
    }
    v8 = (char)StoreProcess;
    if( ((unsigned __int8)StoreProcess & 0x20) == 0 )
    {
      MinimalProcess = ExAllocatePrivateWorkerPool(&PoolID, (UINT64)v6, v5);
      if( MinimalProcess < 0 )
        goto LABEL_12;
      v8 = (unsigned __int8)StoreProcess | 0x20;
      LODWORD(StoreProcess) = (unsigned int)StoreProcess | 0x20;
    }
    if( (v8 & 1) == 0 )
    {
      MinimalProcess = MmStoreRegister((_EPROCESS *)v7);
      if( MinimalProcess < 0 )
        goto LABEL_12;
      LODWORD(StoreProcess) = (unsigned int)StoreProcess | 1;
    }
    MinimalProcess = 0;
  }
  else
  {
    MinimalProcess = -1073741670;
  }
LABEL_12:
  if( (_InterlockedExchangeAdd64(&BugCheckParameter2._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock(&BugCheckParameter2);
  LODWORD(a3) = 0;
  v10 = (_ETHREAD *)KeGetCurrentThread();
  if( MiGetSystemRegionType((UINT64)&BugCheckParameter2) == 1 )
    SessionId = MmGetSessionIdEx(v10->Tcb.ApcState.Process);
  else
    SessionId = -1;
  --v10->Tcb.SpecialApcDisable;
  v12 = ++v10->Tcb.AbAllocationRegionCount;
  v13 = ((char)v10->Tcb.AbEntrySummary | (char)v10->Tcb.AbOrphanedEntrySummary) ^ 0x3F;
  while( 1 )
  {
    v14 = !_BitScanReverse((unsigned int *)&v15, v13);
    HIDWORD(v21) = v15;
    if( v14 )
      break;
    v16 = &v10->Tcb.LockEntries[v15];
    v13 &= ~(1 << v15);
    if( (v16->AcquiredByte & 1) != 0
      && (v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 & 1) == 0
      && (v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 & 0x7FFFFFFFFFFFFFFCi64) == ((unsigned __int64)&BugCheckParameter2 & 0x7FFFFFFFFFFFFFFCi64)
      && v16->LockState.SessionId == SessionId )
    {
      v16->AcquiredByte &= ~1u;
      if( v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 )
      {
        if( v16 )
        {
          v16->CrossThreadReleasableAndBusyByte |= 2u;
          if( v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 < 0 )
            KiAbEntryRemoveFromTree(v16);
          LODWORD(a3) = v16->BoostBitmap.AllFields & 0x1FFFF;
          v16->BoostBitmap.AllFields &= 0xFFFE0000;
          v16->ThreadLocalFlags &= ~1u;
          v16->LockState.$E8276A2CF8B819ED32D1B6FEB35D730A::_bf_0 = 0i64;
          v17 = v16 - v10->Tcb.LockEntries;
          if( v12 == 1 )
            v10->Tcb.AbEntrySummary |= 1 << v17;
          else
            _InterlockedOr8((volatile signed __int8 *)&v10->Tcb.AbOrphanedEntrySummary, 1 << v17);
          goto LABEL_28;
        }
        break;
      }
    }
  }
  if( (*(&v10->Tcb.MiscFlags + 1) & 0x10000) == 0 )
    KeBugCheckEx(0x162u, v10, &BugCheckParameter2, (PVOID)SessionId, 0i64);
LABEL_28:
  --v10->Tcb.AbAllocationRegionCount;
  KiAbThreadRemoveBoosts(&v10->Tcb, &BugCheckParameter2, &a3);
  v14 = v10->Tcb.SpecialApcDisable++ == -1;
  if( v14 && ($F25F8C4BA33AF922A5F1AF68CD89DDDF *)v10->Tcb.ApcState.ApcListHead[0].Flink != &v10->Tcb.152 )
    KiCheckForKernelApcDelivery();
  KeLeaveCriticalRegion();
  return(unsigned int)MinimalProcess;
}

Referenced by:

SmProcessCreateRequest