EtwpEnableStackCaching

NTSTATUS __stdcall EtwpEnableStackCaching(_WMI_LOGGER_CONTEXT *LoggerContext, UINT64 CacheSize, UINT64 BucketCount){
  NTSTATUS v3; 
  unsigned int v5; 
  unsigned int v6; 
  char *PoolWithTag; 
  char *v8; 
  _QWORD *v9; 
  __int64 v10; 
  int v11; 
  unsigned int v12; 
  struct _SLIST_ENTRY *v13; 
  int v15[14]; 
  v3 = 0;
  if( *((_QWORD *)LoggerContext + 124) )
    return -1073741053;
  v5 = 3145728;
  v6 = 256;
  if( (unsigned int)CacheSize >= 0x300000 )
    v5 = CacheSize;
  if( v5 > 0x3200000 )
    v5 = 52428800;
  if( (unsigned int)BucketCount >= 0x100 )
    v6 = BucketCount;
  if( v6 > 0x1000 )
    v6 = 4096;
  PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, 24 * v6 + 32, 0x73777445ui64);
  v8 = PoolWithTag;
  if( PoolWithTag )
  {
    *(_QWORD *)(PoolWithTag + 12) = 0i64;
    *(_QWORD *)(PoolWithTag + 20) = 0i64;
    *((_DWORD *)PoolWithTag + 7) = 0;
    *((_DWORD *)PoolWithTag + 2) = v6;
    *(_QWORD *)PoolWithTag = LoggerContext;
    InitializeSListHead((_SLIST_HEADER *)(PoolWithTag + 16));
    v9 = v8 + 32;
    v10 = v6;
    do
    {
      v9[2] = 0i64;
      v9[1] = v9;
      *v9 = v9;
      v9 += 3;
      --v10;
    }
    while( v10 );
    v11 = 0;
    v12 = v5 / 0x128;
    if( !v12 )
    {
LABEL_19:
      *((_QWORD *)LoggerContext + 124) = v8;
      _InterlockedOr(v15, 0);
      _InterlockedOr((volatile signed __int32 *)LoggerContext + 208, 0x1000000u);
      return v3;
    }
    while( 1 )
    {
      v13 = (struct _SLIST_ENTRY *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x128ui64, 0x78777445ui64);
      if( !v13 )
        break;
      *((_DWORD *)&v13[1].Next + 2) = 0;
      RtlpInterlockedPushEntrySList((PSLIST_HEADER)(v8 + 16), v13);
      if( ++v11 >= v12 )
        goto LABEL_19;
    }
    EtwpFreeStackCache(v8);
  }
  return -1073741801;
}

Referenced by:

EtwSetPerformanceTraceInformation
EtwpCheckForStackTracingExtension