DbgkpSendErrorMessage

__int64 __fastcall DbgkpSendErrorMessage(__int64 a1, char a2, __int64 a3){
  _ETHREAD *CurrentThread; 
  __int64 v6; 
  _EJOB *ProcessServerSilo; 
  __int64 *v8; 
  signed int started; 
  int ServerSiloServiceSessionId; 
  union _LARGE_INTEGER *Timeout; 
  NTSTATUS v12; 
  volatile signed __int32 *v13; 
  void *v14; 
  EXCEPTION_RECORD *v15; 
  __int128 v16; 
  __int128 v17; 
  __int128 v18; 
  __int128 v19; 
  UINT64 v20; 
  __int64 v21; 
  __int16 v22; 
  char v23; 
  int v24; 
  CHAR *MessageAttribute; 
  __int64 v26; 
  int v27; 
  UINT8 v28; 
  UINT8 v30; 
  UINT64 RequiredBufferSize; 
  PVOID Object; 
  union _LARGE_INTEGER v34; 
  EXCEPTION_RECORD *ExceptionRecord; 
  _ETHREAD *v36; 
  INT64 v37[2]; 
  __int128 v38; 
  __int128 v39; 
  __int128 v40; 
  INT64 result[12]; 
  ExceptionRecord = (EXCEPTION_RECORD *)a1;
  memset((INT64)result, 0i64);
  RequiredBufferSize = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v34.QuadPart = 0i64;
  v30 = 0;
  v36 = CurrentThread;
  v6 = *((_QWORD *)CurrentThread + 68);
  ProcessServerSilo = (_EJOB *)PsGetProcessServerSilo(v6);
  v8 = PsGetServerSiloGlobals((__int64)ProcessServerSilo) + 121;
  memset((INT64)v37, 0i64);
  if( (*(_DWORD *)(v6 + 2172) & 1) != 0 )
    return(unsigned int)-1073741637;
  MmGetSectionInformation(*(_QWORD *)(v6 + 1304), 1i64, (INT64)v37);
  ServerSiloServiceSessionId = PsGetServerSiloServiceSessionId(ProcessServerSilo);
  if( (unsigned int)MmGetSessionIdEx(v6) != ServerSiloServiceSessionId && (_DWORD)v39 != 1 && (a2 & 2) != 0 )
    v30 = DbgkpSuspendProcess((_EPROCESS *)v6);
  started = DbgkpStartSystemErrorHandler();
  if( started >= 0 )
  {
    if( DbgkErrorPortStartTimeout == -1 )
    {
      Timeout = 0i64;
    }
    else
    {
      Timeout = &v34;
      v34.QuadPart = -10000i64 * DbgkErrorPortStartTimeout;
    }
    v12 = KeWaitForSingleObject((PVOID)v8[3], Executive, 1, 0, Timeout);
    if( v12 == 258 || !v8[1] )
    {
      started = -1073740973;
    }
    else if( v12 == 257 || v12 == 192 )
    {
      started = -1073741749;
    }
    else
    {
      Object = 0i64;
      --*((_WORD *)CurrentThread + 242);
      started = 0;
      v13 = 0i64;
      ExAcquirePushLockSharedEx((UINT64)v8, 0i64);
      v14 = (void *)v8[2];
      if( (void *)v6 == v14 )
      {
        started = -1073741420;
      }
      else
      {
        v13 = (volatile signed __int32 *)v8[1];
        if( v13 )
        {
          Object = (PVOID)v8[2];
          ObfReferenceObjectWithTag(v14, 0x50676244u);
          _InterlockedIncrement(v13);
        }
        else
        {
          started = -1073740973;
        }
      }
      if( _InterlockedCompareExchange64(v8, 0i64, 17i64) != 17 )
        ExfReleasePushLockShared(v8);
      KeAbPostRelease(v8);
      KeLeaveCriticalRegionThread((__int64)CurrentThread);
      if( started >= 0 )
      {
        v15 = ExceptionRecord;
        *(_QWORD *)(a3 + 8) = 0i64;
        *(_QWORD *)(a3 + 16) = 0i64;
        *(_QWORD *)(a3 + 24) = 0i64;
        *(_QWORD *)(a3 + 32) = 0i64;
        *(_DWORD *)(a3 + 4) = 8;
        *(_WORD *)(a3 + 4) = -32761;
        *(_DWORD *)a3 = 17826024;
        *(_DWORD *)(a3 + 40) = 7;
        *(_DWORD *)(a3 + 44) = -2147418111;
        KeCopyExceptionRecord(a3 + 48, (INT64)v15);
        v16 = *(_OWORD *)v37;
        v17 = v38;
        *(_DWORD *)(a3 + 264) = 0;
        *(_OWORD *)(a3 + 200) = v16;
        v18 = v39;
        *(_OWORD *)(a3 + 216) = v17;
        v19 = v40;
        *(_OWORD *)(a3 + 232) = v18;
        *(_OWORD *)(a3 + 248) = v19;
        if( (*(_BYTE *)(v6 + 2170) & 7) != 0 )
        {
          *(_DWORD *)(a3 + 264) = 1;
          v20 = 1i64;
        }
        else
        {
          v20 = 0i64;
        }
        if( (*(_BYTE *)(v6 + 992) & 1) != 0 )
        {
          v20 = (unsigned int)v20 | 8;
          *(_DWORD *)(a3 + 264) = v20;
        }
        v21 = *(_QWORD *)(v6 + 1408);
        if( v21 )
        {
          v22 = *(_WORD *)(v21 + 8);
          if( v22 == 332 || v22 == 452 )
          {
            v20 = (unsigned int)v20 | 2;
            *(_DWORD *)(a3 + 264) = v20;
          }
        }
        if( (a2 & 1) != 0 )
        {
          v20 = (unsigned int)v20 | 4;
          v23 = 1;
          *(_DWORD *)(a3 + 264) = v20;
        }
        else
        {
          v23 = 0;
        }
        LOBYTE(v20) = 1;
        v24 = PsTestProtectedProcessIncompatibility(v20, (__int64)Object, v6) ? 1055744 : 0x1FFFFF;
        AlpcInitializeMessageAttribute(0x10000000ui64, (_ALPC_MESSAGE_ATTRIBUTES *)v37, 0xA0ui64, &RequiredBufferSize);
        HIDWORD(v37[0]) = 0x10000000;
        MessageAttribute = AlpcGetMessageAttribute((_ALPC_MESSAGE_ATTRIBUTES *)v37, 0x10000000ui64);
        *(_DWORD *)MessageAttribute = 0;
        *((_DWORD *)MessageAttribute + 5) = v24;
        *((_DWORD *)MessageAttribute + 4) = 4;
        *((_QWORD *)MessageAttribute + 1) = -2i64;
        RequiredBufferSize = 272i64;
        KeTestAlertThread(0);
        v26 = (__int64)v36;
        if( (*((_DWORD *)v36 + 324) & 1) != 0 )
          started = -1073741749;
        if( started >= 0 )
        {
          v27 = ZwAlpcSendWaitReceivePort();
          started = v27;
          if( v27 >= 0 )
          {
            if( v27 == 257 )
            {
              started = -1073741749;
            }
            else
            {
              if( (*(_WORD *)(a3 + 4) & 0x2000) != 0 )
                ZwAlpcSendWaitReceivePort();
              started = *(_DWORD *)(a3 + 44);
              if( started >= 0 && !v23 && started == 65538 )
              {
                v28 = v30;
                if( v30 )
                {
                  PsThawProcess(v6, 0);
                  KeLeaveCriticalRegion();
                  v28 = 0;
                }
                started = DbgkForwardException(ExceptionRecord, 1u, 1u) == 0 ? 0xC0000144 : 0;
                goto LABEL_53;
              }
            }
LABEL_52:
            v28 = v30;
LABEL_53:
            ObfDereferenceObjectWithTag(Object, 0x50676244ui64);
            if( _InterlockedExchangeAdd(v13, 0xFFFFFFFF) == 1 )
              DbgkpDeleteErrorPort((PVOID)v13);
            goto LABEL_58;
          }
          v26 = (__int64)v36;
        }
        if( started == -1073741769 )
          DbgkpRemoveErrorPort(v26, (ULONG_PTR)v8, v13);
        goto LABEL_52;
      }
    }
  }
  v28 = v30;
LABEL_58:
  if( v28 )
  {
    PsThawProcess(v6, 0);
    KeLeaveCriticalRegion();
  }
  return(unsigned int)started;
}

Referenced by:

DbgkForwardException
PsDispatchIumService