KiFastFailDispatch
void __fastcall KiFastFailDispatch(INT64 a1, INT64 a2, void *a3, unsigned __int64 a4, CHAR a5){
INT64 v5;
__int64 v6;
INT64 v7;
INT64 v8;
unsigned __int64 v9;
unsigned __int64 v10;
INT64 v11;
INT64 v12;
INT64 v13;
__int128 v14;
__int128 v15;
__int128 v16;
__int128 v17;
__int128 v18;
__int128 v19;
__int128 v20;
__int128 v21;
__int128 v22;
__int128 v23;
INT64 v24;
INT64 v25;
INT64 v26;
_ETHREAD *CurrentThread;
_ETHREAD *v28;
INT64 v29;
INT64 v30;
unsigned __int8 BpbUserSpecCtrl;
unsigned __int8 v32;
__int64 v35;
INT64 FirstChance;
INT64 v37;
INT64 v38[2];
INT64 v39[2];
INT64 v40[2];
INT64 v41[2];
INT64 v42[2];
__int128 v43;
__int128 v44;
__int128 v45;
__int128 v46;
__int128 v47;
INT64 v48;
INT64 v49;
INT64 v50;
INT64 v51;
INT64 v52;
INT64 v53;
INT64 v54;
INT64 v55;
INT64 v56;
INT64 v57;
INT64 v58;
INT64 v59;
_EXCEPTION_RECORD ExceptionRecord;
void *retaddr;
__int16 v62;
int v63;
void *v64;
__int16 v65;
*(_OWORD *)v38 = v14;
*(_OWORD *)v39 = v15;
*(_OWORD *)v40 = v16;
*(_OWORD *)v41 = v17;
*(_OWORD *)v42 = v18;
v43 = v19;
v44 = v20;
v45 = v21;
v46 = v22;
v47 = v23;
v54 = v5;
v55 = v7;
v56 = v8;
v57 = v11;
v58 = v12;
v59 = v13;
if( _bittest((const signed __int32 *)&KeGetCurrentThread()->116, 8u) && (*(_BYTE *)(v6 + 240) & 1) != 0 )
KiUmsExceptionEntry(
a1,
a2,
(INT64)a3,
a4,
FirstChance,
v37,
v38[0],
v38[1],
v39[0],
v39[1],
v40[0],
v40[1],
v41[0],
v41[1],
v42[0],
v42[1],
v43,
*((INT64 *)&v43 + 1),
v44,
*((INT64 *)&v44 + 1),
v45,
*((INT64 *)&v45 + 1),
v46,
*((INT64 *)&v46 + 1),
v47,
*((INT64 *)&v47 + 1),
v48,
v49,
v50,
v51,
v52,
v53,
v54,
v55,
v56,
v57,
v58,
v59);
ExceptionRecord.ExceptionCode = a1;
ExceptionRecord.ExceptionFlags = 1;
ExceptionRecord.ExceptionRecord = 0i64;
ExceptionRecord.ExceptionAddress = a3;
ExceptionRecord.NumberParameters = a2;
ExceptionRecord.ExceptionInformation[0] = a4;
ExceptionRecord.ExceptionInformation[1] = v9;
ExceptionRecord.ExceptionInformation[2] = v10;
LOBYTE(a4) = *(_BYTE *)(v6 + 240) & 1;
if( !(_BYTE)a4 )
KiBugCheckDispatch(0x139u, (void *)ExceptionRecord.ExceptionInformation[0], (void *)(v6 - 128), &ExceptionRecord);
KiDispatchException(&ExceptionRecord, (PKEXCEPTION_FRAME)&v35, (PKTRAP_FRAME)(v6 - 128), a4, 0);
_disable();
if( (*(_BYTE *)(v6 + 240) & 1) == 0 )
{
_mm_setcsr(*(_DWORD *)(v6 - 84));
__iretq(retaddr, v62, v63, v64, v65);
}
if( (_BYTE)KeSmapEnabled )
__stac();
while( (KeGetCurrentThread()->ApcState.UserApcPendingAll & 3) != 0 )
{
__writecr8(1ui64);
_enable();
KiInitiateUserApc((_KTRAP_FRAME *)1);
_disable();
__writecr8(0i64);
}
if( (*((_BYTE *)&KeGetPcr()->Prcb.2 + 14) & 2) != 0 )
KiUpdateStibpPairing(0i64);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( (*(_DWORD *)CurrentThread->Tcb.gap0 & 0x8000000) != 0 )
KiRestoreSetContextState((INT64)CurrentThread, v24, v25, v26, FirstChance);
v28 = (_ETHREAD *)KeGetCurrentThread();
if( (*(_DWORD *)v28->Tcb.gap0 & 0x40010000) != 0 )
{
if( (v28->Tcb.gap0[2] & 1) != 0 )
{
KiCopyCounters(&v28->Tcb);
v28 = (_ETHREAD *)KeGetCurrentThread();
}
if( (v28->Tcb.gap0[3] & 0x40) != 0 )
KiUmsExit(1);
}
_mm_setcsr(*(_DWORD *)(v6 - 84));
if( *(_WORD *)(v6 + 128) )
KiRestoreDebugRegisterState();
v29 = *(_QWORD *)(v6 - 48);
v30 = *(_QWORD *)(v6 - 56);
__writegsbyte(0x853u, 0);
BpbUserSpecCtrl = KeGetPcr()->Prcb.BpbUserSpecCtrl;
if( KeGetPcr()->Prcb.BpbCurrentSpecCtrl != BpbUserSpecCtrl )
{
__writegsbyte(0x27Au, BpbUserSpecCtrl);
__writemsr(0x48u, BpbUserSpecCtrl);
}
v32 = _bittestandreset16(MK_FP(__GS__, 632i64), 2u);
if( v32 )
__writemsr(0x49u, 1ui64);
v32 = _bittestandreset16(MK_FP(__GS__, 632i64), 5u);
if( v32 )
__flush_rsb();
if( (KiKvaShadow & 1) == 0 )
{
__swapgs();
__iretq(retaddr, v62, v63, v64, v65);
}
KiKernelExit(*(_QWORD *)(v6 - 72), *(_QWORD *)(v6 - 64), v30, v29, a5);
}Referenced by:
KiBoundFault
KiControlProtectionFault
KiRaiseSecurityCheckFailure