EtwpEnableStackCaching
NTSTATUS __stdcall EtwpEnableStackCaching(_WMI_LOGGER_CONTEXT *LoggerContext, UINT64 CacheSize, UINT64 BucketCount){
NTSTATUS v3;
unsigned int v5;
unsigned int v6;
char *PoolWithTag;
char *v8;
_QWORD *v9;
__int64 v10;
int v11;
unsigned int v12;
struct _SLIST_ENTRY *v13;
int v15[14];
v3 = 0;
if( *((_QWORD *)LoggerContext + 124) )
return -1073741053;
v5 = 3145728;
v6 = 256;
if( (unsigned int)CacheSize >= 0x300000 )
v5 = CacheSize;
if( v5 > 0x3200000 )
v5 = 52428800;
if( (unsigned int)BucketCount >= 0x100 )
v6 = BucketCount;
if( v6 > 0x1000 )
v6 = 4096;
PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, 24 * v6 + 32, 0x73777445ui64);
v8 = PoolWithTag;
if( PoolWithTag )
{
*(_QWORD *)(PoolWithTag + 12) = 0i64;
*(_QWORD *)(PoolWithTag + 20) = 0i64;
*((_DWORD *)PoolWithTag + 7) = 0;
*((_DWORD *)PoolWithTag + 2) = v6;
*(_QWORD *)PoolWithTag = LoggerContext;
InitializeSListHead((_SLIST_HEADER *)(PoolWithTag + 16));
v9 = v8 + 32;
v10 = v6;
do
{
v9[2] = 0i64;
v9[1] = v9;
*v9 = v9;
v9 += 3;
--v10;
}
while( v10 );
v11 = 0;
v12 = v5 / 0x128;
if( !v12 )
{
LABEL_19:
*((_QWORD *)LoggerContext + 124) = v8;
_InterlockedOr(v15, 0);
_InterlockedOr((volatile signed __int32 *)LoggerContext + 208, 0x1000000u);
return v3;
}
while( 1 )
{
v13 = (struct _SLIST_ENTRY *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x128ui64, 0x78777445ui64);
if( !v13 )
break;
*((_DWORD *)&v13[1].Next + 2) = 0;
RtlpInterlockedPushEntrySList((PSLIST_HEADER)(v8 + 16), v13);
if( ++v11 >= v12 )
goto LABEL_19;
}
EtwpFreeStackCache(v8);
}
return -1073741801;
}Referenced by:
EtwSetPerformanceTraceInformation
EtwpCheckForStackTracingExtension