EtwpQueueStackWalkApc

void __fastcall EtwpQueueStackWalkApc(__int64 a1, unsigned __int8 a2, unsigned int *a3, unsigned int *a4){
  char v4; 
  _KAPC *v5; 
  unsigned int v10; 
  void *v11; 
  void *v12; 
  UINT8 inserted; 
  signed int v14; 
  v4 = 0;
  v5 = 0i64;
  if( (struct _KTHREAD *)a1 != KeGetCurrentThread() )
    return;
  if( *(_DWORD *)(*(_QWORD *)(a1 + 544) + 888i64) + ((*(_DWORD *)(*(_QWORD *)(a1 + 544) + 632i64) >> 3) & 1) )
    return;
  if( *(_BYTE *)(a1 + 644) )
    return;
  v10 = (*((_WORD *)a3 + 417) & 7) + 24;
  if( _interlockedbittestandset((volatile signed __int32 *)(a1 + 120), v10) )
    return;
  if( (*(_DWORD *)(a1 + 116) & 0x4000) == 0 )
    goto LABEL_15;
  if( !ExAcquireRundownProtectionCacheAwareEx(
          *(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(*((_QWORD *)a3 + 135) + 448i64) + 8i64 * *a3),
          1u) )
    goto LABEL_15;
  v4 = 1;
  v5 = (_KAPC *)RtlpInterlockedPopEntrySList((PSLIST_HEADER)(a3 + 232));
  if( !v5 )
    goto LABEL_15;
  KeInitializeApc(
    (INT64)v5,
    a1,
    0i64,
    (INT64)EtwpStackWalkApc,
    (INT64)EtwpCancelStackWalkApc,
    (INT64)EtwpStackWalkApc,
    0,
    (INT64)a3);
  if( !a3[84] )
    goto LABEL_15;
  v11 = (void *)a4[1];
  v12 = (void *)*a4;
  if( a2 <= 2u )
    inserted = KeInsertQueueApc(v5, v12, v11, 0i64);
  else
    inserted = KeTryToInsertQueueApc(v5, v12, v11);
  if( !a3[84] )
  {
    if( inserted && !KeRemoveQueueApc(v5) )
      return;
    goto LABEL_15;
  }
  if( !inserted )
  {
    if( a2 > 2u )
      EtwpQueueStackWalkDpc(a1, a3, a4);
LABEL_15:
    _interlockedbittestandreset((volatile signed __int32 *)(a1 + 120), v10);
    if( v4 )
      ExReleaseRundownProtectionCacheAwareEx(
        *(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(*((_QWORD *)a3 + 135) + 448i64) + 8i64 * *a3),
        1u);
    if( v5 )
      RtlpInterlockedPushEntrySList((PSLIST_HEADER)(a3 + 232), (PSLIST_ENTRY)v5);
    return;
  }
  _InterlockedIncrement((volatile signed __int32 *)a3 + 240);
  v14 = a3[240];
  if( v14 > (int)a3[241] )
    a3[241] = v14;
}

Referenced by:

EtwpStackTraceDispatcher
EtwpStackWalkDpc