EtwpGetPrivateSessionTraceHandle

NTSTATUS __stdcall EtwpGetPrivateSessionTraceHandle(){
  unsigned int v0; 
  INT64 v1; 
  unsigned __int16 *v2; 
  unsigned int v3; 
  _DWORD *v4; 
  _ETW_SILODRIVERSTATE *CurrentSiloState; 
  NTSTATUS v6; 
  char v7; 
  _EX_PUSH_LOCK *p_PrivHandleDemuxTable; 
  _ETHREAD *CurrentThread; 
  _DWORD *v10; 
  __int64 v11; 
  unsigned __int16 v12; 
  unsigned int i; 
  int v14; 
  INT64 PidDemuxList; 
  __int64 *j; 
  __int64 v18; 
  ULONG_PTR PushLock; 
  UINT64 Seed; 
  unsigned __int16 *v21; 
  _EPROCESS *Process; 

  v21 = v2;
  v3 = v0;
  v4 = (_DWORD *)v1;
  CurrentSiloState = EtwpGetCurrentSiloState(v1);
  v6 = 0;
  Process = 0i64;
  v7 = 0;
  p_PrivHandleDemuxTable = (_EX_PUSH_LOCK *)&CurrentSiloState->PrivHandleDemuxTable;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v18 = (__int64)p_PrivHandleDemuxTable;
  --CurrentThread->Tcb.KernelApcDisable;
  PushLock = (_DWORD)p_PrivHandleDemuxTable + 16;
  ExAcquirePushLockExclusiveEx(p_PrivHandleDemuxTable + 2, 0i64);
  if( v3 )
  {
    v10 = v4;
    v11 = v3;
    do
    {
      if( PsLookupProcessByProcessId((VOID *)(unsigned int)*v10, &Process) )
      {
        *v10 = 0;
      }
      else
      {
        if( EtwpCheckCurrentUserProcessAccess(Process) )
          *v10 = 0;
        ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
      }
      v10 += 2;
      --v11;
    }
    while( v11 );
  }
  do
LABEL_9:
    v12 = RtlRandomEx(&Seed) & 0x7FFF;
  while( v12 < 0x40u );
  for( i = 0; i < v3; ++i )
  {
    v14 = v4[2 * i];
    if( v14 )
    {
      PidDemuxList = EtwpGetPidDemuxList(v14, v18);
      if( PidDemuxList )
      {
        for( j = *(__int64 **)(PidDemuxList + 32); j != (__int64 *)(PidDemuxList + 32); j = (__int64 *)*j )
        {
          if( *((_WORD *)j + 9) == v12 )
            goto LABEL_9;
          if( *((_WORD *)j + 8) == LOWORD(v4[2 * i + 1]) )
          {
            if( *((_WORD *)j + 10) != HIWORD(v4[2 * i + 1]) )
              break;
            *((_WORD *)j + 9) = v12;
            v7 = 1;
          }
        }
      }
    }
  }
  ExReleasePushLockEx(PushLock, 0);
  KeLeaveCriticalRegion();
  if( !v7 )
    return -1073741275;
  *v21 = v12;
  return v6;
}

Referenced by:

NtTraceControl