EtwpTraceIo

VOID __stdcall EtwpTraceIo(UINT64 Key, UINT64 DiskNumber, _IRP *Irp){
  _ETHREAD *Thread; 
  _IO_STACK_LOCATION *CurrentStackLocation; 
  unsigned int v6; 
  int v7; 
  INT64 v8; 
  INT64 v9; 
  unsigned __int8 MajorFunction; 
  unsigned int Flags; 
  unsigned int Information; 
  __int16 v13; 
  int UniqueThread; 
  int v15; 
  _FILE_OBJECT *OriginalFileObject; 
  int CurrentLocation; 
  int StackCount; 
  _FILE_OBJECT **p_FileObject; 
  __int128 *v20; 
  __int16 v21; 
  union {_IRP *MasterIrp;int IrpCount;void *SystemBuffer;} v22; 
  int v23; 
  _GUID *p_Guid; 
  INT64 v25; 
  __int128 v26; 
  __int128 v27; 
  __int128 v28; 
  __int64 v29; 
  __int128 v30; 
  __int128 v31; 
  PGET_UPDATED_BUS_RESOURCE v32; 
  int v33; 
  int v34; 
  _GUID Guid; 

  Thread = Irp->Tail.Thread;
  CurrentStackLocation = Irp->Tail.CurrentStackLocation;
  v29 = 0i64;
  v6 = DiskNumber;
  v7 = Key;
  v30 = 0i64;
  v31 = 0i64;
  v26 = 0i64;
  v27 = 0i64;
  v28 = 0i64;
  if( Thread )
  {
    LODWORD(v8) = PsGetThreadServerSilo((INT64)Thread);
    v9 = v8;
  }
  else
  {
    v9 = 0i64;
  }
  MajorFunction = CurrentStackLocation->MajorFunction;
  Flags = Irp->Flags;
  if( CurrentStackLocation->MajorFunction != 9 )
  {
    Information = Irp->IoStatus.Information;
    *(_QWORD *)&v26 = __PAIR64__(Flags, v6);
    *(_QWORD *)&v28 = Irp;
    *((_QWORD *)&v26 + 1) = Information;
    v13 = (MajorFunction != 3) + 266;
    *(_QWORD *)&v27 = *(_QWORD *)&CurrentStackLocation->Parameters.FileAttributes;
    *((_QWORD *)&v28 + 1) = CurrentStackLocation->Parameters.SecurityContext;
    if( Thread )
      UniqueThread = (int)Thread->Cid.UniqueThread;
    else
      UniqueThread = -1;
    LODWORD(v29) = UniqueThread;
    if( (v7 & 0xFFFF0000) == 1448280064 )
    {
      HIDWORD(v26) = 1;
    }
    else
    {
      v15 = v7 & 0xFFFFFF;
      if( v15 == 5460546 || v15 == 5467492 )
        HIDWORD(v26) = 2;
    }
    if( (Flags & 8) != 0 )
    {
      v22.MasterIrp = (_IRP *)Irp->AssociatedIrp;
      if( v22.MasterIrp )
      {
        OriginalFileObject = v22.MasterIrp->Tail.OriginalFileObject;
        if( OriginalFileObject )
          goto LABEL_25;
        OriginalFileObject = v22.MasterIrp->Tail.CurrentStackLocation->FileObject;
LABEL_15:
        if( OriginalFileObject )
          goto LABEL_25;
      }
    }
    else
    {
      OriginalFileObject = Irp->Tail.OriginalFileObject;
      if( OriginalFileObject )
      {
LABEL_25:
        *((_QWORD *)&v27 + 1) = OriginalFileObject->FsContext;
        goto LABEL_17;
      }
      CurrentLocation = (unsigned __int8)Irp->CurrentLocation;
      StackCount = Irp->StackCount;
      if( CurrentLocation <= StackCount )
      {
        p_FileObject = &CurrentStackLocation->FileObject;
        while( 1 )
        {
          OriginalFileObject = *p_FileObject;
          if( *p_FileObject )
            goto LABEL_25;
          LOBYTE(CurrentLocation) = CurrentLocation + 1;
          p_FileObject += 9;
          if( (unsigned __int8)CurrentLocation > StackCount )
            goto LABEL_15;
        }
      }
    }
    *((_QWORD *)&v27 + 1) = 0i64;
LABEL_17:
    v20 = &v26;
    v33 = 52;
    v21 = v13;
    goto LABEL_18;
  }
  *(_QWORD *)&v30 = __PAIR64__(Flags, v6);
  v21 = 270;
  *((_QWORD *)&v30 + 1) = CurrentStackLocation->Parameters.SecurityContext;
  *(_QWORD *)&v31 = Irp;
  if( Thread )
    v23 = (int)Thread->Cid.UniqueThread;
  else
    v23 = -1;
  DWORD2(v31) = v23;
  v20 = &v30;
  v33 = 28;
LABEL_18:
  v34 = 0;
  LODWORD(v25) = 4200451;
  v32 = (PGET_UPDATED_BUS_RESOURCE)v20;
  EtwTraceSiloKernelEvent(v9, &v32, 1ui64, 0x100ui64, v21, v25);
  if( EtwpHostSiloState != -4516 && (*(_DWORD *)(EtwpHostSiloState + 4516) & 0x100) != 0 )
  {
    Guid = 0i64;
    if( IoGetActivityIdIrp(Irp, &Guid) )
      p_Guid = 0i64;
    else
      p_Guid = &Guid;
    EtwpDiskProvTraceDisk(v21, (__int64)&v32, Thread, (__int64)p_Guid);
  }
}

Referenced by:

No references.