ObQueryRefTraceInformation

INT64 __stdcall ObQueryRefTraceInformation(
        PVOID SystemInformation,
        UINT64 SystemInformationLength,
        UINT64 *ReturnLength){
  UINT64 *v3; 
  unsigned int v4; 
  unsigned int v6; 
  unsigned int v7; 
  _ETHREAD *CurrentThread; 
  char v9; 
  unsigned __int16 v10; 
  char *v11; 
  __int16 v12; 
  unsigned int i; 
  unsigned int j; 
  __int64 v15; 
  v3 = ReturnLength;
  v4 = SystemInformationLength;
  v6 = 0;
  if( *((_BYTE *)KeGetCurrentThread() + 562) )
    ProbeForWrite(SystemInformation, (unsigned int)SystemInformationLength, 8ui64);
  v7 = 40;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 243);
  ExAcquirePushLockExclusiveEx((UINT64)&ObpStackTraceLock, 0i64);
  v9 = ObpTraceFlags;
  if( (ObpTraceFlags & 2) != 0 )
  {
    v10 = 0;
    if( (ObpTraceFlags & 0x20) != 0 )
      v7 = ObpRuntimeTraceProcessName.Length + 42;
    if( (ObpTraceFlags & 0x10) != 0 )
    {
      while( v10 < 0x10u && *((_DWORD *)&ObpRuntimeTracePoolTags + v10) )
        ++v10;
      if( v10 )
        v7 += 10 * v10;
    }
    if( v7 <= v4 )
    {
      v11 = (char *)SystemInformation + 40;
      *(_OWORD *)SystemInformation = 0i64;
      *((_OWORD *)SystemInformation + 1) = 0i64;
      *((_QWORD *)SystemInformation + 4) = 0i64;
      *(_BYTE *)SystemInformation = 1;
      *((_BYTE *)SystemInformation + 1) = (ObpTraceFlags & 0x40) != 0;
      if( (v9 & 0x20) != 0 )
      {
        *((_WORD *)SystemInformation + 4) = ObpRuntimeTraceProcessName.Length;
        *((_WORD *)SystemInformation + 5) = ObpRuntimeTraceProcessName.MaximumLength;
        *((_QWORD *)SystemInformation + 2) = v11;
        memmove(
          (UINT8 *)SystemInformation + 40,
          (UINT8 *)ObpRuntimeTraceProcessName.Buffer,
          ObpRuntimeTraceProcessName.MaximumLength);
        v11 += 2 * ((unsigned __int64)ObpRuntimeTraceProcessName.MaximumLength >> 1);
      }
      if( (ObpTraceFlags & 0x10) != 0 )
      {
        v12 = 2 * (5 * v10 - 1);
        *((_WORD *)SystemInformation + 12) = v12;
        *((_WORD *)SystemInformation + 13) = v12 + 2;
        *((_QWORD *)SystemInformation + 4) = v11;
        for( i = 0; i < v10; ++i )
        {
          for( j = 0; ; ++j )
          {
            v15 = j + 5 * i;
            if( j >= 4 )
              break;
            *(_WORD *)&v11[2 * v15] = (unsigned __int8)(*((_DWORD *)&ObpRuntimeTracePoolTags + i) >> (8 * j));
          }
          *(_WORD *)&v11[2 * v15] = 59;
        }
        *(_WORD *)&v11[10 * v10 - 2] = 0;
      }
      v3 = ReturnLength;
    }
    else
    {
      v6 = -1073741820;
      v3 = ReturnLength;
    }
  }
  else if( v4 >= 0x28 )
  {
    *(_BYTE *)SystemInformation = 0;
  }
  else
  {
    v6 = -1073741820;
  }
  if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&ObpStackTraceLock, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock((volatile INT64 *)&ObpStackTraceLock);
  KeAbPostRelease(&ObpStackTraceLock);
  KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
  if( (int)(v6 + 0x80000000) < 0 || v6 == -1073741820 )
  {
    if( v3 )
      *(_DWORD *)v3 = v7;
  }
  return v6;
}

Referenced by:

ExpQuerySystemInformation