EtwpGetTrackingLockSlotForThread
INT64 __fastcall EtwpGetTrackingLockSlotForThread(INT64 a1, INT64 a2){
_ETHREAD *CurrentThread;
int v3;
INT64 v5;
int v6;
VOID *PoolWithTag;
signed __int64 v8;
INT64 v10;
int v11;
int v12;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v3 = a2;
if( (*((_DWORD *)CurrentThread + 324) & 1) != 0 )
return 0i64;
v5 = *((_QWORD *)CurrentThread + 178);
v6 = EtwpEthreadSyncTrackingSequence;
if( !v5 )
{
PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNxCacheAligned, 0x200ui64, 0x72546552ui64);
v8 = (signed __int64)PoolWithTag;
if( PoolWithTag )
{
memset((INT64)PoolWithTag, 0i64);
*(_QWORD *)(v8 + 16) = a1;
*(_DWORD *)(v8 + 28) = v3;
*(_DWORD *)(v8 + 40) = v6;
v5 = _InterlockedCompareExchange64((volatile signed __int64 *)CurrentThread + 178, v8, 0i64);
if( !v5 )
return v8;
ExFreePoolWithTag((PVOID)v8, 0);
goto LABEL_7;
}
return 0i64;
}
LABEL_7:
v10 = 0i64;
v11 = 0;
while( 1 )
{
v12 = *(_DWORD *)(v5 + 28);
if( v12 == v3 && *(_QWORD *)(v5 + 16) == a1 && *(_DWORD *)(v5 + 40) == v6 )
return v5;
if( !v10 )
{
if( v12 )
{
if( *(_DWORD *)(v5 + 40) < v6 )
{
v10 = v5;
LABEL_18:
v5 = v10;
if( v10 )
{
*(_QWORD *)(v10 + 16) = a1;
*(_DWORD *)(v10 + 28) = v3;
*(_QWORD *)(v10 + 32) = 0i64;
*(_QWORD *)v10 = 0i64;
*(_QWORD *)(v10 + 8) = 0i64;
*(_DWORD *)(v10 + 24) = 0;
*(_DWORD *)(v10 + 40) = v6;
*(_DWORD *)(v10 + 44) = 0;
}
return v5;
}
}
else
{
v10 = v5;
}
}
v5 += 64i64;
if( (unsigned int)++v11 >= 8 )
goto LABEL_18;
}
}Referenced by:
PerfLogExecutiveResourceAcquire
PerfLogExecutiveResourceRelease
PerfLogExecutiveResourceSetOwnerPointer
PerfLogExecutiveResourceWait