IoConfigureCrashDump

NTSTATUS __stdcall IoConfigureCrashDump(_CRASHDUMP_CONFIGURATION Configuration, UINT8 SkipRegistry){
  INT64 v2; 
  _ETHREAD *CurrentThread; 
  NTSTATUS v5; 
  NTSTATUS v6; 
  VOID *PageFileForCrashDump; 
  INT64 v9; 
  int v10; 
  _UNICODE_STRING *HostNtSystemRoot; 
  _UNICODE_STRING DestinationString; 
  _UNICODE_STRING PagingFileName; 
  WCHAR SourceString[8]; 
  __int128 v15; 
  __int128 v16; 
  __int128 v17; 

  DestinationString = 0i64;
  *(_OWORD *)SourceString = *(_OWORD *)L"C:\\pagefile.sys";
  v16 = 0i64;
  v15 = *(_OWORD *)L"ile.sys";
  v17 = 0i64;
  if( !SkipRegistry )
    IopReadDumpRegistry(*(UINT64 **)&Configuration, 0i64);
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  if( Configuration )
  {
    if( Configuration != CrashDumpReconfigure )
    {
      v6 = -1073741808;
      goto LABEL_7;
    }
    if( *(&stru_140CF2E80 + 4800) )
    {
      v6 = -1073741637;
      goto LABEL_7;
    }
    PageFileForCrashDump = MmGetPageFileForCrashDump();
    if( !PageFileForCrashDump )
    {
      v6 = -1073741772;
      goto LABEL_7;
    }
    ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 6976, 1, v9);
    IopDisableCrashDump();
    v6 = v10;
    if( v10 >= 0 )
    {
      RtlInitUnicodeString(&DestinationString, SourceString);
      HostNtSystemRoot = RtlGetHostNtSystemRoot();
      PagingFileName = DestinationString;
      *DestinationString.Buffer = *HostNtSystemRoot->Buffer;
      if( IopInitializeCrashDump(PageFileForCrashDump, &PagingFileName) )
      {
        IopRemoveDumpCapsuleSupport();
        v6 = 0;
      }
      else
      {
        if( CapsuleDumpAllowed )
          IopInitDumpCapsuleSupport();
        v6 = -1073741823;
      }
    }
  }
  else
  {
    if( !ExAcquireResourceExclusiveLite((UINT64)&stru_140C452E0 + 6976, 1, v2) )
    {
      v6 = -1073741823;
      goto LABEL_7;
    }
    IopDisableCrashDump();
    v6 = v5;
    IopRemoveDumpCapsuleSupport();
  }
  ExReleaseResourceLite((PERESOURCE)((char *)&stru_140C452E0 + 6976));
LABEL_7:
  KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
  return v6;
}

Referenced by:

NtSetSystemInformation
PoBroadcastSystemState
PoShutdownBugCheck