IoConfigureCrashDump
NTSTATUS __stdcall IoConfigureCrashDump(_CRASHDUMP_CONFIGURATION Configuration, UINT8 SkipRegistry){
INT64 v2;
_ETHREAD *CurrentThread;
NTSTATUS v5;
NTSTATUS v6;
VOID *PageFileForCrashDump;
INT64 v9;
int v10;
_UNICODE_STRING *HostNtSystemRoot;
_UNICODE_STRING DestinationString;
_UNICODE_STRING PagingFileName;
WCHAR SourceString[8];
__int128 v15;
__int128 v16;
__int128 v17;
DestinationString = 0i64;
*(_OWORD *)SourceString = *(_OWORD *)L"C:\\pagefile.sys";
v16 = 0i64;
v15 = *(_OWORD *)L"ile.sys";
v17 = 0i64;
if( !SkipRegistry )
IopReadDumpRegistry(*(UINT64 **)&Configuration, 0i64);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
if( Configuration )
{
if( Configuration != CrashDumpReconfigure )
{
v6 = -1073741808;
goto LABEL_7;
}
if( *(&stru_140CF2E80 + 4800) )
{
v6 = -1073741637;
goto LABEL_7;
}
PageFileForCrashDump = MmGetPageFileForCrashDump();
if( !PageFileForCrashDump )
{
v6 = -1073741772;
goto LABEL_7;
}
ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 6976, 1, v9);
IopDisableCrashDump();
v6 = v10;
if( v10 >= 0 )
{
RtlInitUnicodeString(&DestinationString, SourceString);
HostNtSystemRoot = RtlGetHostNtSystemRoot();
PagingFileName = DestinationString;
*DestinationString.Buffer = *HostNtSystemRoot->Buffer;
if( IopInitializeCrashDump(PageFileForCrashDump, &PagingFileName) )
{
IopRemoveDumpCapsuleSupport();
v6 = 0;
}
else
{
if( CapsuleDumpAllowed )
IopInitDumpCapsuleSupport();
v6 = -1073741823;
}
}
}
else
{
if( !ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 6976, 1, v2) )
{
v6 = -1073741823;
goto LABEL_7;
}
IopDisableCrashDump();
v6 = v5;
IopRemoveDumpCapsuleSupport();
}
ExReleaseResourceLite((PERESOURCE)((char *)&stru_140C452E0 + 6976));
LABEL_7:
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
return v6;
}Referenced by:
NtSetSystemInformation
PoBroadcastSystemState
PoShutdownBugCheck