SmProcessCreateRequest

INT64 __fastcall SmProcessCreateRequest(INT64 a1, UINT64 a2, INT64 a3, CHAR a4){
  int v5; 
  __int64 v7; 
  int v8; 
  UINT64 v9; 
  int TimeInit; 
  _DWORD *v11; 
  int v12; 
  __int64 NonPaged; 
  INT64 v14; 
  struct _EX_RUNDOWN_REF *v16; 
  int v17[8]; 
  INT64 v18; 
  int v19; 
  int v20; 
  PPRIVILEGE_SET v21; 
  INT64 v22; 
  PPRIVILEGE_SET Privileges; 
  __int64 v24[2]; 
  __int64 v25; 
  int v26; 
  int v27; 
  INT64 v28[8]; 
  INT64 result[2]; 
  __int128 v30; 
  __int128 v31; 
  __int128 v32; 
  __int128 v33; 
  __int64 v34; 
  v5 = a3;
  v18 = a1;
  v22 = a1;
  v25 = 0i64;
  v27 = 0;
  v7 = 0i64;
  v21 = 0i64;
  v8 = -1;
  v19 = -1;
  Privileges = 0i64;
  memset((INT64)result, 0i64);
  if( v5 != 88 )
  {
    TimeInit = -1073741306;
LABEL_33:
    v14 = v18;
    goto LABEL_24;
  }
  if( a4 )
  {
    if( (a2 & 7) != 0 )
      ExRaiseDatatypeMisalignment();
    v9 = a2;
    if( a2 >= 0x7FFFFFFF0000i64 )
      v9 = 0x7FFFFFFF0000i64;
    *(_BYTE *)v9 = *(_BYTE *)v9;
    *(_BYTE *)(v9 + 87) = *(_BYTE *)(v9 + 87);
  }
  *(_OWORD *)result = *(_OWORD *)a2;
  v30 = *(_OWORD *)(a2 + 16);
  v31 = *(_OWORD *)(a2 + 32);
  v32 = *(_OWORD *)(a2 + 48);
  v33 = *(_OWORD *)(a2 + 64);
  v34 = *(_QWORD *)(a2 + 80);
  memset((INT64)v28, 0i64);
  TimeInit = SmKmStoreCreatePrepare((unsigned int *)result, a4, &Privileges, (__int64)v28);
  if( TimeInit < 0 )
    goto LABEL_33;
  v11 = (_DWORD *)v28[0];
  v12 = *(_DWORD *)v28[0];
  if( (*(_DWORD *)v28[0] & 0x400FF) != 0x40000 || (v12 & 0x300) != 0 )
    goto LABEL_36;
  if( !(_BYTE)v12 && (v12 & 0x160000) != 0x40000 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeLockMemoryPrivilege, a4) )
  {
    TimeInit = -1073741790;
    goto LABEL_33;
  }
  if( (*v11 & 0x400FF) == 0x40000 && v11[2] > 0x20000u )
  {
LABEL_36:
    TimeInit = -1073741637;
    goto LABEL_33;
  }
  NonPaged = SSHSupportAllocateNonPaged(0x1A50ui64, 0x74536D73u);
  v7 = NonPaged;
  if( !NonPaged )
  {
    TimeInit = -1073741670;
    goto LABEL_33;
  }
  SMKM_STORE::SmStInitialize(NonPaged);
  TimeInit = SmFirstTimeInit(v11[2], 4 - (unsigned int)((*v11 & 0x10000) != 0));
  if( TimeInit < 0 )
    goto LABEL_33;
  v28[4] = (INT64)&SmGlobals;
  v28[5] = (INT64)qword_140D23158;
  v28[6] = (INT64)Handle;
  *v11 |= 0x8000u;
  TimeInit = SMKM_STORE::SmStStart(v7, (int **)v28);
  if( TimeInit < 0 )
    goto LABEL_33;
  v25 = 0i64;
  v27 = 0;
  v24[0] = (__int64)&result[1];
  v24[1] = *(_QWORD *)(v7 + 6200);
  v26 = DWORD2(v30);
  if( (result[0] & 0x200) != 0 )
    v25 = *((_QWORD *)KeGetCurrentThread() + 23);
  TimeInit = SmKmStoreAdd(v18, v7, (__int64)v24, (int *)(v7 + 6016));
  if( TimeInit < 0 )
    goto LABEL_33;
  v19 = *(_DWORD *)(v7 + 6016);
  v8 = v19;
  _InterlockedOr(v17, 0);
  byte_140D23168 = 5;
  v7 = 0i64;
  v21 = 0i64;
  v20 = 1;
  TimeInit = 0;
  *(_DWORD *)(a2 + 80) = v8;
  if( (result[0] & 0x100) != 0 )
    v8 = -1;
  v14 = v18;
LABEL_24:
  if( v8 != -1 )
  {
    v16 = (struct _EX_RUNDOWN_REF *)SmKmStoreRefFromStoreIndex(v14, v8 & 0x3FF);
    ExReleaseRundownProtection(v16 + 1);
  }
  if( v7 )
  {
    SMKM_STORE::SmStCleanup(v7);
    CmSiFreeMemory((PPRIVILEGE_SET)v7);
  }
  if( Privileges )
    CmSiFreeMemory(Privileges);
  return(unsigned int)TimeInit;
}

Referenced by:

SmSetStoreInformation
SmpDirtyStoreCreate