EtwpUpdateTrace
NTSTATUS __stdcall EtwpUpdateTrace(_ETW_SILODRIVERSTATE *SiloState, _WMI_LOGGER_INFORMATION *LoggerInfo){
NTSTATUS result;
_WMI_LOGGER_INFORMATION *v5;
INT64 v6;
_ETHREAD *CurrentThread;
int v8;
int ClientSecurity;
unsigned int *v10;
_WMI_LOGGER_INFORMATION v11;
int v12;
unsigned int v13;
const _GUID *v14;
__int64 v15;
__int64 v16;
__int64 v17;
int v18;
unsigned int v19;
_WMI_LOGGER_INFORMATION v20;
int v21;
__int64 v22;
_ADAPTER_OBJECT *v23;
_UNICODE_STRING v24;
UINT64 v25;
unsigned int SystemMaximumBufferCount;
int v27;
_WMI_LOGGER_INFORMATION v28;
_MEMORY_CACHING_TYPE_ORIG *v29;
_DWORD *v30;
INT64 ClientSecurityQos;
INT64 ClientSecurityQos_8;
_UNICODE_STRING UnicodeString;
INT64 v34;
VOID *SecurityDescriptor;
v34 = 0i64;
WORD1(ClientSecurityQos_8) = 0;
UnicodeString = 0i64;
result = EtwpValidateLoggerInfo(LoggerInfo);
if( result >= 0 )
{
result = EtwpValidateFlagExtension(v5);
if( result >= 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
EtwpAcquireLoggerContext(
(INT64)SiloState,
(INT16)LoggerInfo,
(INT64)&v34,
v6,
v29,
ClientSecurityQos,
ClientSecurityQos_8);
ClientSecurity = v8;
if( v8 < 0 )
{
LABEL_8:
KeLeaveCriticalRegionThread(KeGetCurrentThread());
return ClientSecurity;
}
v10 = (unsigned int *)v34;
v11 = LoggerInfo[16];
v12 = *(_DWORD *)(v34 + 12);
v30 = (_DWORD *)(v34 + 12);
if( (v12 & 0x40) != 0
|| (v11 & 3) == 3
|| (LoggerInfo[16] & 0xC000) == 49152
|| (v11 & 2) != 0 && (v12 & 2) == 0
|| (v11 & 6) == 6 )
{
goto LABEL_6;
}
v13 = ((v12 | v11) & 0x100) == 0 ? 128 : 160;
if( *((_QWORD *)LoggerInfo + 17) && *((_WORD *)LoggerInfo + 64) )
v13 |= 0x40u;
ClientSecurity = EtwpCheckLoggerControlAccess(v13, (_WMI_LOGGER_CONTEXT *)v34);
if( ClientSecurity < 0 )
goto LABEL_7;
if( *((_QWORD *)LoggerInfo + 17) && *((_WORD *)LoggerInfo + 64) )
{
if( (v12 & 8) != 0 || (v11 & 8) != 0 || (v12 & 0x400) != 0 )
goto LABEL_6;
ClientSecurity = EtwpCaptureString((_UNICODE_STRING *)LoggerInfo + 8, &UnicodeString);
if( ClientSecurity < 0 )
goto LABEL_7;
v23 = (_ADAPTER_OBJECT *)*((_QWORD *)v10 + 92);
if( v23 )
{
HalPutDmaAdapter(v23);
*((_QWORD *)v10 + 92) = 0i64;
}
v10 = (unsigned int *)v34;
ClientSecurityQos = 0x20000000Ci64;
LOWORD(ClientSecurityQos_8) = 257;
ClientSecurity = SeCreateClientSecurity(
(PETHREAD)KeGetCurrentThread(),
(PSECURITY_QUALITY_OF_SERVICE)&ClientSecurityQos,
0,
(PSECURITY_CLIENT_CONTEXT)(v34 + 720));
if( ClientSecurity < 0 )
goto LABEL_7;
v24 = UnicodeString;
UnicodeString.Buffer = 0i64;
*(_UNICODE_STRING *)(v10 + 50) = v24;
EtwpSynchronizeWithLogger((_WMI_LOGGER_CONTEXT *)v10, 4ui64);
ClientSecurity = EtwpSynchronizeWithLogger((_WMI_LOGGER_CONTEXT *)v10, 2ui64);
if( ClientSecurity < 0 || !v10[84] )
goto LABEL_7;
}
if( (v12 & 0x400) != 0 )
goto LABEL_18;
if( (v11 & 0x100) != 0 )
{
v12 |= 0x100u;
if( !v10[56] )
v10[56] = (v12 & 0x10) != 0 ? 1000 : 1;
LABEL_18:
v14 = (const _GUID *)(v10 + 73);
v15 = *(_QWORD *)(v10 + 73);
v16 = HeapGuid - v15;
if( HeapGuid == v15 )
v16 = 0x4AA2F2756B3425A8i64 - *(_QWORD *)(v10 + 75);
if( v16 )
{
v17 = CritSecGuid - v15;
if( CritSecGuid == v15 )
v17 = 0x6B81390EF58D1581i64 - *(_QWORD *)(v10 + 75);
if( v17 )
{
LABEL_24:
ClientSecurity = EtwpCheckForStackTracingExtension(LoggerInfo, (_WMI_LOGGER_CONTEXT *)v10);
if( ClientSecurity >= 0 )
{
if( (*v30 & 0x2000000) == 0
|| (ClientSecurity = EtwpCheckSystemTraceAccess((_WMI_LOGGER_CONTEXT *)v10, 0x80ui64),
ClientSecurity >= 0)
&& (SiloState != (_ETW_SILODRIVERSTATE *)EtwpHostSiloState
|| (ClientSecurity = EtwpCheckForPoolTagFilterExtension((_WMI_LOGGER_CONTEXT *)v10, LoggerInfo, 0),
ClientSecurity >= 0))
&& (EtwpUpdateLoggerGroupMasks((_KTRAP_FRAME *)v10, LoggerInfo), ClientSecurity = v18, v18 >= 0) )
{
v19 = LoggerInfo[14];
if( v19 )
{
if( v10[1] )
SystemMaximumBufferCount = EtwpGetSystemMaximumBufferCount((_WMI_LOGGER_CONTEXT *)v10);
else
SystemMaximumBufferCount = 0;
if( v19 > SystemMaximumBufferCount )
{
LoggerInfo[14] = SystemMaximumBufferCount;
v19 = SystemMaximumBufferCount;
}
if( v19 > v10[63] )
v10[63] = v19;
}
if( (v12 & 0x400) == 0 )
{
v20 = LoggerInfo[17];
if( v20 )
{
if( v20 != v10[56] )
{
v10[56] = v20;
EtwpSynchronizeWithLogger((_WMI_LOGGER_CONTEXT *)v10, 4ui64);
}
}
}
if( (v11 & 0x80000) == 0 )
{
if( (v12 & 0x80000) != 0 )
v12 &= ~0x80000u;
goto LABEL_36;
}
if( v10[79] != 1 )
{
_InterlockedOr((volatile signed __int32 *)v10 + 209, 0x800u);
v12 |= 0x80000u;
if( ((_BYTE)KdDebuggerNotPresent || KdPitchDebugger) && !KdEventLoggingPresent )
{
v10 = (unsigned int *)v34;
}
else
{
v10 = (unsigned int *)v34;
EtwpSendDbgId((_WMI_LOGGER_CONTEXT *)v34);
}
LABEL_36:
if( (v11 & 0x80u) == 0
|| (SecurityDescriptor = 0i64,
EtwpGetSecurityDescriptorByGuid(v14, &SecurityDescriptor),
ClientSecurity = EtwpUpdateLoggerSecurityDescriptor(
(_WMI_LOGGER_CONTEXT *)v10,
SecurityDescriptor),
EtwpFreeSecurityDescriptor(&SecurityDescriptor),
ClientSecurity >= 0) )
{
*v30 = v12;
v21 = LoggerInfo[19];
if( v21 )
{
if( v10[56] || (v12 & 0x400) != 0 )
goto LABEL_87;
v27 = v10[63] - EtwpQueryUsedProcessorCount((_WMI_LOGGER_CONTEXT *)v10);
v21 = LoggerInfo[19];
v28 = v27 - 1;
if( v21 > v28 )
{
LoggerInfo[19] = v28;
v21 = v28;
}
if( v21 < 0 )
{
LABEL_87:
LoggerInfo[19] = 0;
v21 = 0;
}
}
v10[57] = v21;
ClientSecurity = EtwpGetLoggerInfoFromContext(LoggerInfo, (_WMI_LOGGER_CONTEXT *)v10);
if( EtwEventEnabled(*(&ExBootDevicesRemovedEvent + 241), &ETW_EVENT_UPDATE_TRACE) )
EtwpEventWriteTemplateSession(v22, &ETW_EVENT_UPDATE_TRACE, (__int64)v10);
}
goto LABEL_7;
}
ClientSecurity = -1073741637;
}
}
LABEL_7:
RtlFreeAnsiString(&UnicodeString);
EtwpReleaseLoggerContext((_WMI_LOGGER_CONTEXT *)v10, 1u);
goto LABEL_8;
}
v25 = 1i64;
}
else
{
v25 = 0i64;
}
EtwpUpdatePerProcessTracing(LoggerInfo, (UINT64)SiloState, *v10, v25);
goto LABEL_24;
}
if( (v12 & 0x100) == 0 )
goto LABEL_18;
if( *((_QWORD *)v10 + 102) )
{
v12 &= ~0x100u;
EtwpSynchronizeWithLogger((_WMI_LOGGER_CONTEXT *)v10, 8ui64);
goto LABEL_18;
}
LABEL_6:
ClientSecurity = -1073741811;
goto LABEL_7;
}
}
return result;
}Referenced by:
EtwWmitraceWorker