EtwpUpdateDisallowedGuids
NTSTATUS __stdcall EtwpUpdateDisallowedGuids(
_WMI_LOGGER_CONTEXT *LoggerContext,
UINT64 Count,
const _GUID *Guids,
VOID *NotifyNoChange,
const _GUID *a5,
VOID *a6,
VOID *NotifyAddition,
const _GUID *a8,
VOID *a9,
VOID *NotifyRemoval,
const _GUID *a11,
VOID *a12,
VOID *NotificationContext){
UINT64 v13;
NTSTATUS v14;
VOID **PoolWithTag;
_GUID *v18;
unsigned int v19;
__int64 v20;
__int64 v21;
_WMI_LOGGER_CONTEXT *v22;
_GUID *v23;
_GUID *v24;
_GUID *v25;
_GUID *v26;
NTSTATUS v27;
VOID **v28;
_QWORD *v29;
VOID **v30;
VOID **v31;
_QWORD *v32;
VOID **v33;
VOID **v34;
_QWORD *v35;
VOID **v36;
VOID **v37;
_QWORD *v38;
_EX_PUSH_LOCK *p_LoggerLock;
_GUID *v40;
PVOID *v41;
_GUID *v42;
_GUID **v43;
_GUID *v44;
void **v45;
PVOID *v46;
_QWORD *v47;
_QWORD *v48;
_QWORD *v49;
_QWORD *v50;
PVOID *v51;
_QWORD *v52;
__int64 v53;
_QWORD *v54;
_QWORD *v55;
PVOID *v56;
_GUID *v57;
const _GUID **v58;
const _GUID *v59;
void **v60;
PLARGE_INTEGER Timeout;
UINT64 v62;
PVOID P;
PVOID *p_P;
PVOID v65;
PVOID *v66;
unsigned __int16 v68;
_KMUTANT *Mutex;
v68 = Count;
v13 = (unsigned __int16)Count;
v14 = 0;
if( (unsigned __int16)Count > 0x200u )
return -1073741811;
p_P = &P;
P = &P;
v66 = &v65;
v65 = &v65;
if( (_WORD)Count )
{
PoolWithTag = ExAllocatePoolWithTag(1ui64, 16i64 * (unsigned __int16)Count, 1685550149i64);
v18 = (_GUID *)PoolWithTag;
if( !PoolWithTag )
{
LABEL_53:
v14 = -1073741670;
LABEL_54:
v46 = (PVOID *)P;
v47 = P;
while( v46 != &P )
{
v48 = (_QWORD *)*v47;
v49 = v47;
v47 = v48;
if( (_QWORD *)v48[1] != v49 )
goto LABEL_69;
v50 = (_QWORD *)v49[1];
if( (_QWORD *)*v50 != v49 )
goto LABEL_69;
*v50 = v48;
v48[1] = v50;
ExFreePoolWithTag((PVOID)v49[2], 0);
ExFreePoolWithTag(v49, 0);
v46 = (PVOID *)P;
}
v51 = (PVOID *)v65;
v52 = v65;
while( v51 != &v65 )
{
v53 = *v52;
v54 = v52;
v52 = (_QWORD *)v53;
if( *(_QWORD **)(v53 + 8) != v54 )
goto LABEL_69;
v55 = (_QWORD *)v54[1];
if( (_QWORD *)*v55 != v54 )
goto LABEL_69;
*v55 = v53;
*(_QWORD *)(v53 + 8) = v55;
ExFreePoolWithTag(v54, 0);
v51 = (PVOID *)v65;
}
return v14;
}
memmove(PoolWithTag, Guids, 16 * v13);
qsort((UINT64)v18, v13, 0x10ui64, (INT64)EtwpCompareGuid, (INT64 *)Timeout, v62, (UINT64)P);
v19 = 0;
if( (_DWORD)v13 != 1 )
{
while( 1 )
{
v20 = v19;
v21 = *(_QWORD *)&v18[v20].Data1 - *(_QWORD *)&v18[v20 + 1].Data1;
if( !v21 )
v21 = *(_QWORD *)v18[v20].Data4 - *(_QWORD *)v18[v20 + 1].Data4;
if( !v21 )
break;
if( ++v19 >= (int)v13 - 1 )
goto LABEL_13;
}
ExFreePoolWithTag(v18, 0);
v14 = -1073741811;
goto LABEL_54;
}
}
else
{
v18 = 0i64;
}
LABEL_13:
v22 = LoggerContext;
Mutex = &LoggerContext->LoggerMutex;
KeWaitForSingleObject((UINT64)&LoggerContext->LoggerMutex, 0, 0, 0, 0i64);
if( LoggerContext->DisallowedGuids.Count )
{
v23 = LoggerContext->DisallowedGuids.Guids;
v24 = &v23[LoggerContext->DisallowedGuids.Count];
}
else
{
v23 = 0i64;
v24 = 0i64;
}
if( (_WORD)v13 )
{
v25 = v18;
v26 = &v18[v13];
}
else
{
v25 = 0i64;
v26 = 0i64;
}
if( v23 < v24 )
{
while( v25 < v26 )
{
v27 = memcmp(v23, v25, 0x10ui64);
if( v27 )
{
if( v27 >= 0 )
{
v30 = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1953985605i64);
if( !v30 )
goto LABEL_52;
v31 = ExAllocatePoolWithTag(1ui64, 0x10ui64, 1953985605i64);
if( !v31 )
{
v33 = v30;
LABEL_51:
ExFreePoolWithTag(v33, 0);
goto LABEL_52;
}
*(_GUID *)v31 = *v25;
v30[2] = v31;
v32 = p_P;
if( *p_P != &P )
goto LABEL_69;
v30[1] = p_P;
*v30 = &P;
++v25;
*v32 = v30;
p_P = v30;
}
else
{
v28 = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1953985605i64);
if( !v28 )
goto LABEL_52;
v28[2] = v23;
v29 = v66;
if( *v66 != &v65 )
LABEL_69:
__fastfail(3u);
v28[1] = v66;
*v28 = &v65;
++v23;
*v29 = v28;
v66 = v28;
}
}
else
{
++v23;
++v25;
}
if( v23 >= v24 )
{
LABEL_37:
v22 = LoggerContext;
goto LABEL_38;
}
}
while( 1 )
{
v34 = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1953985605i64);
if( !v34 )
goto LABEL_52;
v34[2] = v23;
v35 = v66;
if( *v66 != &v65 )
goto LABEL_69;
v34[1] = v66;
*v34 = &v65;
++v23;
*v35 = v34;
v66 = v34;
if( v23 >= v24 )
goto LABEL_37;
}
}
LABEL_38:
if( v25 < v26 )
{
while( 1 )
{
v36 = ExAllocatePoolWithTag(1ui64, 0x18ui64, 1953985605i64);
if( !v36 )
break;
v37 = ExAllocatePoolWithTag(1ui64, 0x10ui64, 1953985605i64);
if( !v37 )
{
v33 = v36;
goto LABEL_51;
}
*(_GUID *)v37 = *v25;
v36[2] = v37;
v38 = p_P;
if( *p_P != &P )
goto LABEL_69;
v36[1] = p_P;
*v36 = &P;
++v25;
*v38 = v36;
p_P = v36;
if( v25 >= v26 )
goto LABEL_43;
}
LABEL_52:
KeReleaseMutex(Mutex, 0);
goto LABEL_53;
}
LABEL_43:
p_LoggerLock = &v22->LoggerLock;
ExAcquirePushLockExclusiveEx(&v22->LoggerLock, 0i64);
v22->DisallowedGuids.Count = v68;
v40 = v22->DisallowedGuids.Guids;
LoggerContext->DisallowedGuids.Guids = v18;
if( (_InterlockedExchangeAdd64(&p_LoggerLock->_bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(p_LoggerLock);
KeAbPostRelease(p_LoggerLock);
KeReleaseMutex(Mutex, 0);
v41 = (PVOID *)P;
v42 = (_GUID *)P;
while( v41 != &P )
{
v43 = (_GUID **)v42;
v42 = *(_GUID **)&v42->Data1;
EtwpDisallowedGuidAddition(v43[2], NotifyAddition);
v44 = *v43;
if( *(_GUID ***)(*v43)->Data4 != v43 )
goto LABEL_69;
v45 = (void **)v43[1];
if( *v45 != v43 )
goto LABEL_69;
*v45 = v44;
*(_QWORD *)v44->Data4 = v45;
ExFreePoolWithTag(v43[2], 0);
ExFreePoolWithTag(v43, 0);
v41 = (PVOID *)P;
}
v56 = (PVOID *)v65;
v57 = (_GUID *)v65;
while( v56 != &v65 )
{
v58 = (const _GUID **)v57;
v57 = *(_GUID **)&v57->Data1;
EtwpDisallowedGuidRemoval(v58[2], NotifyAddition);
v59 = *v58;
if( *(const _GUID ***)(*v58)->Data4 != v58 )
goto LABEL_69;
v60 = (void **)v58[1];
if( *v60 != v58 )
goto LABEL_69;
*v60 = (void *)v59;
*(_QWORD *)v59->Data4 = v60;
ExFreePoolWithTag(v58, 0);
v56 = (PVOID *)v65;
}
if( v40 )
ExFreePoolWithTag(v40, 0);
return v14;
}Referenced by:
No references.