KiTpBuildExcludedKernelTracepointRangeList
_RTL_RANGE_LIST *__stdcall KiTpBuildExcludedKernelTracepointRangeList(INT64 a1, INT64 a2, UINT64 a3){
VOID **PoolWithTag;
_RTL_RANGE_LIST *v4;
UINT64 v5;
__int64 v6;
ULONGLONG v7;
_IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *v8;
UINT64 Flags;
UINT64 ImageBase;
PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x20ui64, 1886549062i64);
v4 = (_RTL_RANGE_LIST *)PoolWithTag;
if( PoolWithTag )
{
*((_DWORD *)PoolWithTag + 4) = 0;
*((_DWORD *)PoolWithTag + 5) = 0;
*((_DWORD *)PoolWithTag + 6) = 0;
v5 = KiTpExcludedRoutines;
LODWORD(v6) = 0;
PoolWithTag[1] = PoolWithTag;
*PoolWithTag = PoolWithTag;
while( 1 )
{
ImageBase = 0i64;
v7 = v5;
v8 = RtlLookupFunctionEntry(v5, &ImageBase, 0i64);
if( v8 )
v7 = ImageBase + v8->UnwindData;
LODWORD(Flags) = 1;
if( RtlAddRange(v4, v5, v7, 0, Flags, 0i64, 0i64) < 0 )
break;
v6 = (unsigned int)(v6 + 1);
v5 = *(&KiTpExcludedRoutines + v6);
if( !v5 )
return v4;
}
RtlFreeRangeList(v4);
ExFreePoolWithTag(v4, 0x70727446u);
}
return 0i64;
}Referenced by:
KiTpIsExcludedKernelTracepointLocation