SmProcessCreateRequest
INT64 __fastcall SmProcessCreateRequest(INT64 a1, UINT64 a2, INT64 a3, CHAR a4){
int v5;
__int64 v7;
int v8;
UINT64 v9;
int TimeInit;
_DWORD *v11;
int v12;
__int64 NonPaged;
INT64 v14;
struct _EX_RUNDOWN_REF *v16;
int v17[8];
INT64 v18;
int v19;
int v20;
PPRIVILEGE_SET v21;
INT64 v22;
PPRIVILEGE_SET Privileges;
__int64 v24[2];
__int64 v25;
int v26;
int v27;
INT64 v28[8];
INT64 result[2];
__int128 v30;
__int128 v31;
__int128 v32;
__int128 v33;
__int64 v34;
v5 = a3;
v18 = a1;
v22 = a1;
v25 = 0i64;
v27 = 0;
v7 = 0i64;
v21 = 0i64;
v8 = -1;
v19 = -1;
Privileges = 0i64;
memset((INT64)result, 0i64);
if( v5 != 88 )
{
TimeInit = -1073741306;
LABEL_33:
v14 = v18;
goto LABEL_24;
}
if( a4 )
{
if( (a2 & 7) != 0 )
ExRaiseDatatypeMisalignment();
v9 = a2;
if( a2 >= 0x7FFFFFFF0000i64 )
v9 = 0x7FFFFFFF0000i64;
*(_BYTE *)v9 = *(_BYTE *)v9;
*(_BYTE *)(v9 + 87) = *(_BYTE *)(v9 + 87);
}
*(_OWORD *)result = *(_OWORD *)a2;
v30 = *(_OWORD *)(a2 + 16);
v31 = *(_OWORD *)(a2 + 32);
v32 = *(_OWORD *)(a2 + 48);
v33 = *(_OWORD *)(a2 + 64);
v34 = *(_QWORD *)(a2 + 80);
memset((INT64)v28, 0i64);
TimeInit = SmKmStoreCreatePrepare((unsigned int *)result, a4, &Privileges, (__int64)v28);
if( TimeInit < 0 )
goto LABEL_33;
v11 = (_DWORD *)v28[0];
v12 = *(_DWORD *)v28[0];
if( (*(_DWORD *)v28[0] & 0x400FF) != 0x40000 || (v12 & 0x300) != 0 )
goto LABEL_36;
if( !(_BYTE)v12 && (v12 & 0x160000) != 0x40000 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeLockMemoryPrivilege, a4) )
{
TimeInit = -1073741790;
goto LABEL_33;
}
if( (*v11 & 0x400FF) == 0x40000 && v11[2] > 0x20000u )
{
LABEL_36:
TimeInit = -1073741637;
goto LABEL_33;
}
NonPaged = SSHSupportAllocateNonPaged(0x1A50ui64, 0x74536D73u);
v7 = NonPaged;
if( !NonPaged )
{
TimeInit = -1073741670;
goto LABEL_33;
}
SMKM_STORE::SmStInitialize(NonPaged);
TimeInit = SmFirstTimeInit(v11[2], 4 - (unsigned int)((*v11 & 0x10000) != 0));
if( TimeInit < 0 )
goto LABEL_33;
v28[4] = (INT64)&SmGlobals;
v28[5] = (INT64)qword_140D23158;
v28[6] = (INT64)Handle;
*v11 |= 0x8000u;
TimeInit = SMKM_STORE::SmStStart(v7, (int **)v28);
if( TimeInit < 0 )
goto LABEL_33;
v25 = 0i64;
v27 = 0;
v24[0] = (__int64)&result[1];
v24[1] = *(_QWORD *)(v7 + 6200);
v26 = DWORD2(v30);
if( (result[0] & 0x200) != 0 )
v25 = *((_QWORD *)KeGetCurrentThread() + 23);
TimeInit = SmKmStoreAdd(v18, v7, (__int64)v24, (int *)(v7 + 6016));
if( TimeInit < 0 )
goto LABEL_33;
v19 = *(_DWORD *)(v7 + 6016);
v8 = v19;
_InterlockedOr(v17, 0);
byte_140D23168 = 5;
v7 = 0i64;
v21 = 0i64;
v20 = 1;
TimeInit = 0;
*(_DWORD *)(a2 + 80) = v8;
if( (result[0] & 0x100) != 0 )
v8 = -1;
v14 = v18;
LABEL_24:
if( v8 != -1 )
{
v16 = (struct _EX_RUNDOWN_REF *)SmKmStoreRefFromStoreIndex(v14, v8 & 0x3FF);
ExReleaseRundownProtection(v16 + 1);
}
if( v7 )
{
SMKM_STORE::SmStCleanup(v7);
CmSiFreeMemory((PPRIVILEGE_SET)v7);
}
if( Privileges )
CmSiFreeMemory(Privileges);
return(unsigned int)TimeInit;
}Referenced by:
SmSetStoreInformation
SmpDirtyStoreCreate