EtwpUpdateProcessorTraceConfiguration

NTSTATUS __stdcall EtwpUpdateProcessorTraceConfiguration(INT64 a1, INT64 a2){
  __int64 v3; 
  NTSTATUS result; 

  v3 = *(_QWORD *)(a2 + 16);
  if( (*(_DWORD *)(a1 + 832) & 0x4000000) != 0 )
    return -1073741053;
  if( *(_QWORD *)(a1 + 1016) || (result = EtwpConstructIptData(a1), result >= 0) )
  {
    if( !**(_QWORD **)(a1 + 1016) )
    {
      _interlockedbittestandset(&KiCpuTracingFlags, 2u);
      result = (**(__int64(__fastcall ***)(__int64))(*(_QWORD *)(a1 + 1016) + 16i64))(v3);
      if( result >= 0 )
      {
        *(_QWORD *)(*(_QWORD *)(a1 + 1016) + 8i64) = v3;
        _InterlockedOr((volatile signed __int32 *)(a1 + 832), 0x4000000u);
        return 0;
      }
      else
      {
        _interlockedbittestandreset(&KiCpuTracingFlags, 2u);
        **(_QWORD **)(a1 + 1016) = 0i64;
      }
      return result;
    }
    return -1073741053;
  }
  return result;
}

Referenced by:

EtwSetPerformanceTraceInformation