DbgkCopyProcessDebugPort
__int64 __fastcall DbgkCopyProcessDebugPort(_QWORD *BugCheckParameter1, __int64 a2, char *a3, bool *a4){
char *v5;
__int64 v8;
bool v9;
UINT64 v11;
char *v12;
NTSTATUS v13;
__int64 v14;
__int16 v15;
INT64 v16;
char v17;
char *v18;
INT64 result[14];
BugCheckParameter1[175] = 0i64;
v5 = a3;
if( a3 )
{
ObfReferenceObject(a3);
}
else
{
v8 = *(_QWORD *)(a2 + 1400);
v9 = v8 == 0;
if( !v8 )
{
LABEL_3:
*a4 = !v9;
return 0i64;
}
ExAcquireFastMutex(&DbgkpProcessDebugPortMutex);
v5 = *(char **)(a2 + 1400);
if( v5 )
{
if( (*(_DWORD *)(a2 + 1124) & 2) != 0 )
v5 = 0i64;
else
ObfReferenceObject(*(PVOID *)(a2 + 1400));
}
KeReleaseGuardedMutex(&DbgkpProcessDebugPortMutex);
}
v12 = v5;
v9 = v5 == 0i64;
if( !v5 )
goto LABEL_3;
LOBYTE(v11) = *((_BYTE *)KeGetCurrentThread() + 562);
if( PsTestProtectedProcessIncompatibility(v11, a2, (__int64)BugCheckParameter1) )
{
v13 = -1073740014;
}
else if( (*((_DWORD *)v5 + 24) & 4) == 0
|| (v14 = BugCheckParameter1[176]) != 0 && ((v15 = *(_WORD *)(v14 + 8), v15 == 332) || v15 == 452) )
{
v16 = BugCheckParameter1[124];
if( (v16 & 1) == 0
|| (memset((INT64)result, 0i64),
result[1] = v16,
result[2] = 1i64,
v13 = VslpEnterIumSecureMode(2u, 12, 0i64, (INT64)result),
v13 >= 0) )
{
v17 = 0;
ExAcquireFastMutex((FAST_MUTEX *)(v5 + 24));
if( (*((_DWORD *)v5 + 24) & 1) != 0 )
v17 = 1;
else
BugCheckParameter1[175] = v5;
KeReleaseGuardedMutex((_FAST_MUTEX *)(v5 + 24));
if( v17 )
HalPutDmaAdapter((PADAPTER_OBJECT)v5);
v18 = 0i64;
if( !v17 )
v18 = v12;
v9 = v18 == 0i64;
if( v18 )
{
DbgkpMarkProcessPeb((PEPROCESS)BugCheckParameter1);
v9 = v18 == 0i64;
}
goto LABEL_3;
}
}
else
{
v13 = -1073741637;
}
HalPutDmaAdapter((PADAPTER_OBJECT)v5);
return(unsigned int)v13;
}Referenced by:
No references.