NtCreateEnclave
NTSTATUS __stdcall NtCreateEnclave(
PVOID ProcessHandle,
PVOID *BaseAddress,
UINT64 ZeroBits,
UINT64 Size,
UINT64 InitialCommitment,
UINT64 EnclaveType,
PVOID EnclaveInformation,
UINT64 EnclaveInformationLength,
UINT64 *EnclaveError){
UINT8 *a7;
char v10;
__int64 v11;
unsigned __int64 v12;
NTSTATUS Enclave;
int v14;
char v15;
__int64 v16;
UINT8 *v17;
void *v18;
UINT64 v20;
UINT64 a8;
char v22;
UINT64 a2[2];
ULONG_PTR BugCheckParameter1;
VOID *a4;
UINT64 ZeroBitsa[2];
_KAPC_STATE ApcState;
a4 = (VOID *)Size;
ZeroBitsa[1] = (UINT64)BaseAddress;
ZeroBitsa[0] = ZeroBits;
a2[1] = (UINT64)EnclaveError;
BugCheckParameter1 = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
a2[0] = 0i64;
a7 = 0i64;
v10 = *((_BYTE *)KeGetCurrentThread() + 562);
v22 = v10;
if( EnclaveError && v10 == 1 )
{
v11 = (__int64)EnclaveError;
if( (unsigned __int64)EnclaveError >= 0x7FFFFFFF0000i64 )
v11 = 0x7FFFFFFF0000i64;
*(_DWORD *)v11 = *(_DWORD *)v11;
}
if( (_DWORD)EnclaveType == 1 )
{
LABEL_16:
if( qword_140C4EBC0 )
{
v14 = 4096;
v12 = InitialCommitment;
goto LABEL_18;
}
LABEL_14:
Enclave = -1073741637;
goto LABEL_47;
}
if( (_DWORD)EnclaveType == 2 )
{
if( (UKUSER_SHARED_DATA.EnclaveFeatureMask[0] & 4) == 0 )
goto LABEL_14;
goto LABEL_16;
}
if( (unsigned int)(EnclaveType - 16) > 1 )
goto LABEL_14;
v12 = InitialCommitment;
if( InitialCommitment )
{
LABEL_10:
Enclave = -1073741581;
goto LABEL_47;
}
if( (unsigned int)EnclaveInformationLength > 0x24 )
goto LABEL_12;
v14 = 0;
LABEL_18:
if( MiValidateZeroBits(ZeroBitsa) < 0 )
{
Enclave = -1073741583;
goto LABEL_47;
}
if( !a4 )
{
Enclave = -1073741582;
goto LABEL_47;
}
if( v12 > (unsigned __int64)a4 )
goto LABEL_10;
v15 = v22;
if( v22 == 1 )
{
v16 = (__int64)BaseAddress;
if( (unsigned __int64)BaseAddress >= 0x7FFFFFFF0000i64 )
v16 = 0x7FFFFFFF0000i64;
*(_QWORD *)v16 = *(_QWORD *)v16;
}
a2[0] = (UINT64)*BaseAddress;
if( (_DWORD)EnclaveInformationLength )
{
if( v14 && (_DWORD)EnclaveInformationLength != v14 )
{
LABEL_12:
Enclave = -1073741820;
goto LABEL_47;
}
LODWORD(v17) = MiAllocatePool((struct _SLIST_ENTRY *)0x100);
a7 = v17;
if( !v17 )
{
Enclave = -1073741670;
goto LABEL_47;
}
if( v22 == 1 )
{
if( (unsigned __int64)(unsigned int)EnclaveInformationLength - 1 > 0xFFFE )
{
if( ((unsigned __int8)EnclaveInformation & 3) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)EnclaveInformation + (unsigned int)EnclaveInformationLength > 0x7FFFFFFF0000i64
|| (char *)EnclaveInformation + (unsigned int)EnclaveInformationLength < EnclaveInformation )
{
MEMORY[0x7FFFFFFF0000] = 0;
}
}
else if( ((unsigned __int8)EnclaveInformation & 3) != 0 )
{
ExRaiseDatatypeMisalignment();
}
}
memmove(v17, (UINT8 *)EnclaveInformation, (unsigned int)EnclaveInformationLength);
v15 = v22;
}
if( ProcessHandle == (PVOID)-1i64 )
{
v18 = (void *)*((_QWORD *)KeGetCurrentThread() + 23);
}
else
{
Enclave = ObpReferenceObjectByHandleWithTag(
(ULONG_PTR)ProcessHandle,
8,
(__int64)PsProcessType,
v15,
0x6D566D4Du,
(__int64)&BugCheckParameter1,
0i64,
0i64);
if( Enclave < 0 )
goto LABEL_47;
v18 = (void *)BugCheckParameter1;
KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
}
LODWORD(a8) = EnclaveInformationLength;
LODWORD(v20) = EnclaveType;
Enclave = MiCreateEnclave((INT64)v18, a2, ZeroBitsa[0], a4, v12, v20, (INT64)a7, a8);
if( ProcessHandle != (PVOID)-1i64 )
{
KiUnstackDetachProcess(&ApcState, 0i64);
ObfDereferenceObjectWithTag(v18, 0x6D566D4Dui64);
}
LABEL_47:
if( a7 )
ExFreePoolWithTag(a7, 0);
if( Enclave >= 0 )
*BaseAddress = (PVOID)a2[0];
if( EnclaveError )
*(_DWORD *)EnclaveError = 0;
return Enclave;
}Referenced by:
No references.