KeOptimizeSpecCtrlSettings
PVOID __stdcall KeOptimizeSpecCtrlSettings(PVOID Argument){
struct _KPRCB *CurrentPrcb;
int v3;
unsigned int v4;
signed __int32 v5;
unsigned int v6;
char v7;
char v8;
signed __int32 v9;
unsigned int v10;
int v11;
unsigned __int64 v12;
char v13;
unsigned __int64 v14;
int v15;
__int64 v16;
__int64 v17;
unsigned int i;
_DWORD *v19;
INT64 v20;
signed __int32 v21;
unsigned int v22;
char v23;
unsigned int v24;
UINT64 SpinCount;
UINT64 v27;
int v28;
UINT64 v29;
CurrentPrcb = KeGetCurrentPrcb();
if( ((*((_QWORD *)CurrentPrcb + 4235) - 1i64) & *((_QWORD *)CurrentPrcb + 4235)) != 0 )
_InterlockedOr(&KiSpeculationFeatures, 2u);
if( (_BYTE)HvlHypervisorConnected && HvlIsCoreSharingPossible() )
_InterlockedOr(&KiSpeculationFeatures, 2u);
if( (KiFeatureSettings & 0x80u) != 0 )
_InterlockedOr(&KiSpeculationFeatures, 0x1000000u);
if( *((_BYTE *)CurrentPrcb + 141) == 1 )
KiDetectAmdNonArchSsbdSupport((INT64)CurrentPrcb);
v3 = 0x800000;
v4 = 0x400000;
if( (KiSpeculationFeatures & 0x80u) != 0 && (KiSpeculationFeatures & 0x100) == 0 )
{
if( (KiFeatureSettings & 8) != 0 )
goto LABEL_16;
if( (KiFeatureSettings & 0x10) == 0 )
goto LABEL_17;
if( KiSsbdMsr != 72 )
LABEL_16:
_InterlockedOr(&KiSpeculationFeatures, 0x400000u);
else
_InterlockedOr(&KiSpeculationFeatures, 0x800000u);
}
LABEL_17:
if( (KiSpeculationFeatures & 4) == 0 )
_InterlockedOr(&KiSpeculationFeatures, 0x80000u);
if( (KiFeatureSettings & 4) != 0 )
{
_InterlockedOr(&KiSpeculationFeatures, 0x40000u);
}
else if( (KiFeatureSettings & 1) != 0 )
{
_InterlockedOr(&KiSpeculationFeatures, 0x40000u);
if( (_BYTE)HvlHypervisorConnected )
{
if( (HvlpFlags & 2) != 0 && HvlIsCoreSharingPossible() && (KiSpeculationFeatures & 0x40) != 0 )
{
*((_BYTE *)CurrentPrcb + 251) = 2;
*((_BYTE *)CurrentPrcb + 253) = 2;
*((_BYTE *)CurrentPrcb + 1744) = 2;
}
}
}
if( Argument )
{
LODWORD(SpinCount) = 0;
v5 = _InterlockedDecrement((volatile signed __int32 *)Argument);
v6 = ~v5 & 0x80000000;
if( (v5 & 0x7FFFFFFF) != 0 )
{
if( (*(_DWORD *)Argument & 0x80000000) != v6 )
{
do
KeYieldProcessorEx(&SpinCount);
while( (*(_DWORD *)Argument & 0x80000000) != v6 );
v3 = 0x800000;
v4 = 0x400000;
}
}
else
{
*(_DWORD *)Argument = v6 | *((_DWORD *)Argument + 1);
}
}
if( (KiSpeculationFeatures & 0x40000) != 0 || (KiSpeculationFeatures & 0x80000) != 0 )
{
if( (KiSpeculationFeatures & v3) != 0 )
{
_InterlockedOr(&KiSpeculationFeatures, v4);
_InterlockedAnd(&KiSpeculationFeatures, 0xFF7FFFFF);
}
if( (KiSpeculationFeatures & v4) != 0 )
{
v23 = *((_BYTE *)CurrentPrcb + 251);
if( KiSsbdMsr == 72 )
v23 |= 4u;
*((_BYTE *)CurrentPrcb + 251) = v23;
*((_BYTE *)CurrentPrcb + 253) = v23;
}
}
else
{
_InterlockedOr(&KiSpeculationFeatures, 0x100000u);
*((_BYTE *)CurrentPrcb + 249) |= 2u;
if( (KiSpeculationFeatures & 1) == 0 )
goto LABEL_48;
v7 = 1;
if( (KiSpeculationFeatures & 0x4000) != 0 )
v7 = 3;
*((_BYTE *)CurrentPrcb + 251) = v7;
*((_BYTE *)CurrentPrcb + 253) = v7;
*((_BYTE *)CurrentPrcb + 1744) = v7;
if( (KiSpeculationFeatures & v4) != 0 || (KiSpeculationFeatures & v3) != 0 )
{
v8 = *((_BYTE *)CurrentPrcb + 251);
if( KiSsbdMsr == 72 )
v8 |= 4u;
*((_BYTE *)CurrentPrcb + 251) = v8;
*((_BYTE *)CurrentPrcb + 253) = v8;
*((_BYTE *)CurrentPrcb + 1744) = v8;
}
*((_BYTE *)CurrentPrcb + 252) = 1;
if( (KiSpeculationFeatures & 0x4000) != 0 )
*((_BYTE *)CurrentPrcb + 252) |= 2u;
if( (KiSpeculationFeatures & 0x2000) != 0 )
*((_BYTE *)CurrentPrcb + 252) |= 0x80u;
if( (KiSpeculationFeatures & v3) != 0 )
{
LABEL_48:
if( (KiSpeculationFeatures & 0x10) != 0 )
{
*((_BYTE *)CurrentPrcb + 252) = 1;
}
else if( (KiSpeculationFeatures & 0x40) != 0 && (KiSpeculationFeatures & 2) != 0 )
{
*((_BYTE *)CurrentPrcb + 252) = 2;
}
if( (KiSpeculationFeatures & 0x4000) != 0 )
*((_BYTE *)CurrentPrcb + 252) |= 2u;
if( (KiSpeculationFeatures & 0x2000) != 0 )
*((_BYTE *)CurrentPrcb + 252) |= 0x80u;
if( ((KiSpeculationFeatures & v4) != 0 || (KiSpeculationFeatures & v3) != 0) && KiSsbdMsr == 72 )
*((_BYTE *)CurrentPrcb + 252) |= 4u;
if( (KiSpeculationFeatures & 1) == 0 )
{
if( Argument )
{
LODWORD(v27) = 0;
v9 = _InterlockedDecrement((volatile signed __int32 *)Argument);
v10 = ~v9 & 0x80000000;
if( (v9 & 0x7FFFFFFF) != 0 )
{
for( i = *(_DWORD *)Argument & 0x80000000; i != v10; i = *(_DWORD *)Argument & 0x80000000 )
KeYieldProcessorEx(&v27);
}
else
{
*(_DWORD *)Argument = v10 | *((_DWORD *)Argument + 1);
}
}
if( (KiSpeculationFeatures & 0x2000000) != 0 )
{
*((_BYTE *)CurrentPrcb + 1747) |= 4u;
KeExitRetpoline();
}
if( (KiSpeculationFeatures & 2) != 0
&& (KiSpeculationFeatures & 0x4000) == 0
&& !(_BYTE)HvlHypervisorConnected
&& ((KiSpeculationFeatures & 0x10) != 0 || (KiSpeculationFeatures & 0x40) != 0) )
{
_InterlockedOr(&KiSpeculationFeatures, 0x20000u);
*((_BYTE *)CurrentPrcb + 249) |= 1u;
}
v11 = 0;
if( (KiSpeculationFeatures & 2) != 0
&& (KiSpeculationFeatures & 0x40) != 0
&& (KiSpeculationFeatures & 0x10) != 0
&& (KiSpeculationFeatures & 0x4000) == 0
&& (KiSpeculationFeatures & 0x1000000) == 0 )
{
v12 = *((_QWORD *)CurrentPrcb + 4235);
if( (0x101010101010101i64
* ((((v12 - ((v12 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ (((v12 - ((v12 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
+ ((((v12 - ((v12 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ (((v12 - ((v12 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 56 == 2
&& (!(_BYTE)HvlHypervisorConnected
|| !HvlIsCoreSharingPossible()
|| (HvlpFlags & 2) != 0 && HvlIsStibpPairingRecommended()) )
{
v13 = *((_BYTE *)CurrentPrcb + 209) + 1;
_BitScanForward64(&v14, __ROR8__(v12, v13));
v15 = ((_BYTE)v14 + v13) & 0x3F;
v16 = v15 + (*((unsigned __int8 *)CurrentPrcb + 208) << 6);
v28 = v15;
KeGetPrcb((unsigned int)KiProcessorNumberToIndexMappingTable[v16]);
*((_QWORD *)CurrentPrcb + 1462) = v17;
v11 = 1;
*((_WORD *)CurrentPrcb + 127) = 6;
}
}
if( (KiFeatureSettings & 0x20) != 0 && (KiSpeculationFeatures & 2) != 0 && (KiSpeculationFeatures & 0x40) != 0
|| (KiSpeculationFeatures & 2) != 0
&& (KiSpeculationFeatures & 0x40) != 0
&& !v11
&& (KiSpeculationFeatures & 0x1000000) == 0
&& (_BYTE)HvlHypervisorConnected
&& HvlIsCoreSharingPossible() )
{
_InterlockedOr(&KiSpeculationFeatures, 0x10000u);
}
if( (KiSpeculationFeatures & 2) != 0
&& (KiSpeculationFeatures & 0x40) != 0
&& (KiSpeculationFeatures & 0x4000) != 0
&& !v11
&& (KiSpeculationFeatures & 0x1000000) == 0 )
{
_InterlockedOr(&KiSpeculationFeatures, 0x8000000u);
}
if( *((_BYTE *)CurrentPrcb + 141) != 1
|| (KiSpeculationFeatures & 0x10) != 0
|| (KiFeatureSettings & 0x40) != 0 )
{
if( KiIsBranchConfusionPresent((INT64)CurrentPrcb) )
{
_InterlockedOr(&KiSpeculationFeatures, 0x8000u);
if( (unsigned int)KiIsBranchConfusionMitigationDesired((INT64)CurrentPrcb, &KiSpeculationFeatures) )
{
if( !KiIsBranchConfusionMitigationSupported(v20, v19) )
_InterlockedOr(&KiSpeculationFeatures, 0x20000000u);
}
else
{
_InterlockedOr(&KiSpeculationFeatures, 0x10000000u);
}
}
if( Argument )
{
v21 = _InterlockedDecrement((volatile signed __int32 *)Argument);
v22 = ~v21 & 0x80000000;
if( (v21 & 0x7FFFFFFF) != 0 )
{
LODWORD(v29) = 0;
while( (*(_DWORD *)Argument & 0x80000000) != v22 )
KeYieldProcessorEx(&v29);
}
else
{
*(_DWORD *)Argument = v22 | *((_DWORD *)Argument + 1);
}
}
KiUpdateSpeculationControl(*((_QWORD *)KeGetCurrentThread() + 23));
}
else
{
_InterlockedOr(&KiSpeculationFeatures, 0x200000u);
}
v4 = 0x400000;
}
}
}
v24 = *((unsigned __int8 *)CurrentPrcb + 251);
*((_BYTE *)CurrentPrcb + 250) = v24;
if( (_BYTE)v24 )
__writemsr(0x48u, v24);
if( (KiSpeculationFeatures & v4) != 0 && KiSsbdMsr != 72 )
__writemsr(KiSsbdMsr, KiSsbdBit | __readmsr(KiSsbdMsr));
return 0i64;
}Referenced by:
No references.