EtwpTraceIo
VOID __stdcall EtwpTraceIo(UINT64 Key, UINT64 DiskNumber, _IRP *Irp){
_ETHREAD *Thread;
_IO_STACK_LOCATION *CurrentStackLocation;
unsigned int v6;
int v7;
INT64 v8;
INT64 v9;
unsigned __int8 MajorFunction;
unsigned int Flags;
unsigned int Information;
__int16 v13;
int UniqueThread;
int v15;
_FILE_OBJECT *OriginalFileObject;
int CurrentLocation;
int StackCount;
_FILE_OBJECT **p_FileObject;
__int128 *v20;
__int16 v21;
union {_IRP *MasterIrp;int IrpCount;void *SystemBuffer;} v22;
int v23;
_GUID *p_Guid;
INT64 v25;
__int128 v26;
__int128 v27;
__int128 v28;
__int64 v29;
__int128 v30;
__int128 v31;
PGET_UPDATED_BUS_RESOURCE v32;
int v33;
int v34;
_GUID Guid;
Thread = Irp->Tail.Thread;
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
v29 = 0i64;
v6 = DiskNumber;
v7 = Key;
v30 = 0i64;
v31 = 0i64;
v26 = 0i64;
v27 = 0i64;
v28 = 0i64;
if( Thread )
{
LODWORD(v8) = PsGetThreadServerSilo((INT64)Thread);
v9 = v8;
}
else
{
v9 = 0i64;
}
MajorFunction = CurrentStackLocation->MajorFunction;
Flags = Irp->Flags;
if( CurrentStackLocation->MajorFunction != 9 )
{
Information = Irp->IoStatus.Information;
*(_QWORD *)&v26 = __PAIR64__(Flags, v6);
*(_QWORD *)&v28 = Irp;
*((_QWORD *)&v26 + 1) = Information;
v13 = (MajorFunction != 3) + 266;
*(_QWORD *)&v27 = *(_QWORD *)&CurrentStackLocation->Parameters.FileAttributes;
*((_QWORD *)&v28 + 1) = CurrentStackLocation->Parameters.SecurityContext;
if( Thread )
UniqueThread = (int)Thread->Cid.UniqueThread;
else
UniqueThread = -1;
LODWORD(v29) = UniqueThread;
if( (v7 & 0xFFFF0000) == 1448280064 )
{
HIDWORD(v26) = 1;
}
else
{
v15 = v7 & 0xFFFFFF;
if( v15 == 5460546 || v15 == 5467492 )
HIDWORD(v26) = 2;
}
if( (Flags & 8) != 0 )
{
v22.MasterIrp = (_IRP *)Irp->AssociatedIrp;
if( v22.MasterIrp )
{
OriginalFileObject = v22.MasterIrp->Tail.OriginalFileObject;
if( OriginalFileObject )
goto LABEL_25;
OriginalFileObject = v22.MasterIrp->Tail.CurrentStackLocation->FileObject;
LABEL_15:
if( OriginalFileObject )
goto LABEL_25;
}
}
else
{
OriginalFileObject = Irp->Tail.OriginalFileObject;
if( OriginalFileObject )
{
LABEL_25:
*((_QWORD *)&v27 + 1) = OriginalFileObject->FsContext;
goto LABEL_17;
}
CurrentLocation = (unsigned __int8)Irp->CurrentLocation;
StackCount = Irp->StackCount;
if( CurrentLocation <= StackCount )
{
p_FileObject = &CurrentStackLocation->FileObject;
while( 1 )
{
OriginalFileObject = *p_FileObject;
if( *p_FileObject )
goto LABEL_25;
LOBYTE(CurrentLocation) = CurrentLocation + 1;
p_FileObject += 9;
if( (unsigned __int8)CurrentLocation > StackCount )
goto LABEL_15;
}
}
}
*((_QWORD *)&v27 + 1) = 0i64;
LABEL_17:
v20 = &v26;
v33 = 52;
v21 = v13;
goto LABEL_18;
}
*(_QWORD *)&v30 = __PAIR64__(Flags, v6);
v21 = 270;
*((_QWORD *)&v30 + 1) = CurrentStackLocation->Parameters.SecurityContext;
*(_QWORD *)&v31 = Irp;
if( Thread )
v23 = (int)Thread->Cid.UniqueThread;
else
v23 = -1;
DWORD2(v31) = v23;
v20 = &v30;
v33 = 28;
LABEL_18:
v34 = 0;
LODWORD(v25) = 4200451;
v32 = (PGET_UPDATED_BUS_RESOURCE)v20;
EtwTraceSiloKernelEvent(v9, &v32, 1ui64, 0x100ui64, v21, v25);
if( EtwpHostSiloState != -4516 && (*(_DWORD *)(EtwpHostSiloState + 4516) & 0x100) != 0 )
{
Guid = 0i64;
if( IoGetActivityIdIrp(Irp, &Guid) )
p_Guid = 0i64;
else
p_Guid = &Guid;
EtwpDiskProvTraceDisk(v21, (__int64)&v32, Thread, (__int64)p_Guid);
}
}Referenced by:
No references.