EtwpQueueStackWalkApc
void __fastcall EtwpQueueStackWalkApc(__int64 a1, unsigned __int8 a2, unsigned int *a3, unsigned int *a4){
char v4;
_KAPC *v5;
unsigned int v10;
void *v11;
void *v12;
UINT8 inserted;
signed int v14;
v4 = 0;
v5 = 0i64;
if( (struct _KTHREAD *)a1 != KeGetCurrentThread() )
return;
if( *(_DWORD *)(*(_QWORD *)(a1 + 544) + 888i64) + ((*(_DWORD *)(*(_QWORD *)(a1 + 544) + 632i64) >> 3) & 1) )
return;
if( *(_BYTE *)(a1 + 644) )
return;
v10 = (*((_WORD *)a3 + 417) & 7) + 24;
if( _interlockedbittestandset((volatile signed __int32 *)(a1 + 120), v10) )
return;
if( (*(_DWORD *)(a1 + 116) & 0x4000) == 0 )
goto LABEL_15;
if( !ExAcquireRundownProtectionCacheAwareEx(
*(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(*((_QWORD *)a3 + 135) + 448i64) + 8i64 * *a3),
1u) )
goto LABEL_15;
v4 = 1;
v5 = (_KAPC *)RtlpInterlockedPopEntrySList((PSLIST_HEADER)(a3 + 232));
if( !v5 )
goto LABEL_15;
KeInitializeApc(
(INT64)v5,
a1,
0i64,
(INT64)EtwpStackWalkApc,
(INT64)EtwpCancelStackWalkApc,
(INT64)EtwpStackWalkApc,
0,
(INT64)a3);
if( !a3[84] )
goto LABEL_15;
v11 = (void *)a4[1];
v12 = (void *)*a4;
if( a2 <= 2u )
inserted = KeInsertQueueApc(v5, v12, v11, 0i64);
else
inserted = KeTryToInsertQueueApc(v5, v12, v11);
if( !a3[84] )
{
if( inserted && !KeRemoveQueueApc(v5) )
return;
goto LABEL_15;
}
if( !inserted )
{
if( a2 > 2u )
EtwpQueueStackWalkDpc(a1, a3, a4);
LABEL_15:
_interlockedbittestandreset((volatile signed __int32 *)(a1 + 120), v10);
if( v4 )
ExReleaseRundownProtectionCacheAwareEx(
*(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(*((_QWORD *)a3 + 135) + 448i64) + 8i64 * *a3),
1u);
if( v5 )
RtlpInterlockedPushEntrySList((PSLIST_HEADER)(a3 + 232), (PSLIST_ENTRY)v5);
return;
}
_InterlockedIncrement((volatile signed __int32 *)a3 + 240);
v14 = a3[240];
if( v14 > (int)a3[241] )
a3[241] = v14;
}Referenced by:
EtwpStackTraceDispatcher
EtwpStackWalkDpc