EtwpUpdateDisallowedGuids
INT64 __fastcall EtwpUpdateDisallowedGuids(
INT64 a1,
UINT16 a2,
const VOID *a3,
INT64 a4,
INT64 a5,
INT64 a6,
VOID *NotificationContext){
size_t v7;
unsigned int v8;
UINT8 *PoolWithTag;
WCHAR *v12;
unsigned int v13;
__int64 v14;
__int64 v15;
INT64 v16;
char *v17;
char *v18;
WCHAR *v19;
WCHAR *v20;
NTSTATUS v21;
PVOID *v22;
PVOID *v23;
_QWORD *v24;
_OWORD *v25;
PVOID *v26;
void *v27;
PVOID *v28;
PVOID *v29;
_QWORD *v30;
_OWORD *v31;
PVOID *v32;
volatile INT64 *v33;
void *v34;
PVOID *v35;
_GUID *v36;
_GUID **v37;
_GUID *v38;
void **v39;
PVOID *v40;
_QWORD *v41;
_QWORD *v42;
_QWORD *v43;
_QWORD *v44;
PVOID *v45;
_QWORD *v46;
__int64 v47;
_QWORD *v48;
_QWORD *v49;
PVOID *v50;
_GUID *v51;
const _GUID **v52;
const _GUID *v53;
void **v54;
PVOID P;
PVOID *p_P;
PVOID v57;
PVOID *v58;
struct _KMUTANT *Mutex;
v7 = a2;
v8 = 0;
if( a2 > 0x200u )
return 3221225485i64;
p_P = &P;
P = &P;
v58 = &v57;
v57 = &v57;
if( a2 )
{
PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, 16i64 * a2, 0x64777445ui64);
v12 = (WCHAR *)PoolWithTag;
if( !PoolWithTag )
{
LABEL_53:
v8 = -1073741670;
LABEL_54:
v40 = (PVOID *)P;
v41 = P;
while( v40 != &P )
{
v42 = (_QWORD *)*v41;
v43 = v41;
v41 = v42;
if( (_QWORD *)v42[1] != v43 )
goto LABEL_69;
v44 = (_QWORD *)v43[1];
if( (_QWORD *)*v44 != v43 )
goto LABEL_69;
*v44 = v42;
v42[1] = v44;
ExFreePoolWithTag((PVOID)v43[2], 0);
ExFreePoolWithTag(v43, 0);
v40 = (PVOID *)P;
}
v45 = (PVOID *)v57;
v46 = v57;
while( v45 != &v57 )
{
v47 = *v46;
v48 = v46;
v46 = (_QWORD *)v47;
if( *(_QWORD **)(v47 + 8) != v48 )
goto LABEL_69;
v49 = (_QWORD *)v48[1];
if( (_QWORD *)*v49 != v48 )
goto LABEL_69;
*v49 = v47;
*(_QWORD *)(v47 + 8) = v49;
ExFreePoolWithTag(v48, 0);
v45 = (PVOID *)v57;
}
return v8;
}
memmove(PoolWithTag, (UINT8 *)a3, 16 * v7);
qsort(v12, v7, (const WCHAR *)0x10, EtwpCompareGuid);
v13 = 0;
if( (_DWORD)v7 != 1 )
{
while( 1 )
{
v14 = 8i64 * v13;
v15 = *(_QWORD *)&v12[v14] - *(_QWORD *)&v12[v14 + 8];
if( !v15 )
v15 = *(_QWORD *)&v12[v14 + 4] - *(_QWORD *)&v12[v14 + 12];
if( !v15 )
break;
if( ++v13 >= (int)v7 - 1 )
goto LABEL_13;
}
ExFreePoolWithTag(v12, 0);
v8 = -1073741811;
goto LABEL_54;
}
}
else
{
v12 = 0i64;
}
LABEL_13:
v16 = a1;
Mutex = (struct _KMUTANT *)(a1 + 648);
KeWaitForSingleObject((PVOID)(a1 + 648), Executive, 0, 0, 0i64);
if( *(_WORD *)(a1 + 1048) )
{
v17 = *(char **)(a1 + 1056);
v18 = &v17[16 * *(unsigned __int16 *)(a1 + 1048)];
}
else
{
v17 = 0i64;
v18 = 0i64;
}
if( (_WORD)v7 )
{
v19 = v12;
v20 = &v12[8 * v7];
}
else
{
v19 = 0i64;
v20 = 0i64;
}
if( v17 < v18 )
{
while( v19 < v20 )
{
v21 = memcmp(v17, v19, 0x10ui64);
if( v21 )
{
if( v21 >= 0 )
{
v24 = ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
if( !v24 )
goto LABEL_52;
v25 = ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x74777445ui64);
if( !v25 )
{
v27 = v24;
LABEL_51:
ExFreePoolWithTag(v27, 0);
goto LABEL_52;
}
*v25 = *(_OWORD *)v19;
v24[2] = v25;
v26 = p_P;
if( *p_P != &P )
goto LABEL_69;
v24[1] = p_P;
*v24 = &P;
v19 += 8;
*v26 = v24;
p_P = (PVOID *)v24;
}
else
{
v22 = (PVOID *)ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
if( !v22 )
goto LABEL_52;
v22[2] = v17;
v23 = v58;
if( *v58 != &v57 )
LABEL_69:
__fastfail(3u);
v22[1] = v58;
*v22 = &v57;
v17 += 16;
*v23 = v22;
v58 = v22;
}
}
else
{
v17 += 16;
v19 += 8;
}
if( v17 >= v18 )
{
LABEL_37:
v16 = a1;
goto LABEL_38;
}
}
while( 1 )
{
v28 = (PVOID *)ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
if( !v28 )
goto LABEL_52;
v28[2] = v17;
v29 = v58;
if( *v58 != &v57 )
goto LABEL_69;
v28[1] = v58;
*v28 = &v57;
v17 += 16;
*v29 = v28;
v58 = v28;
if( v17 >= v18 )
goto LABEL_37;
}
}
LABEL_38:
if( v19 < v20 )
{
while( 1 )
{
v30 = ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
if( !v30 )
break;
v31 = ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x74777445ui64);
if( !v31 )
{
v27 = v30;
goto LABEL_51;
}
*v31 = *(_OWORD *)v19;
v30[2] = v31;
v32 = p_P;
if( *p_P != &P )
goto LABEL_69;
v30[1] = p_P;
*v30 = &P;
v19 += 8;
*v32 = v30;
p_P = (PVOID *)v30;
if( v19 >= v20 )
goto LABEL_43;
}
LABEL_52:
KeReleaseMutex(Mutex, 0);
goto LABEL_53;
}
LABEL_43:
v33 = (volatile INT64 *)(v16 + 704);
ExAcquirePushLockExclusiveEx(v16 + 704, 0i64);
*(_WORD *)(v16 + 1048) = a2;
v34 = *(void **)(v16 + 1056);
*(_QWORD *)(a1 + 1056) = v12;
if( (_InterlockedExchangeAdd64(v33, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(v33);
KeAbPostRelease((PVOID)v33);
KeReleaseMutex(Mutex, 0);
v35 = (PVOID *)P;
v36 = (_GUID *)P;
while( v35 != &P )
{
v37 = (_GUID **)v36;
v36 = *(_GUID **)&v36->Data1;
EtwpDisallowedGuidAddition(v37[2], NotificationContext);
v38 = *v37;
if( *(_GUID ***)(*v37)->Data4 != v37 )
goto LABEL_69;
v39 = (void **)v37[1];
if( *v39 != v37 )
goto LABEL_69;
*v39 = v38;
*(_QWORD *)v38->Data4 = v39;
ExFreePoolWithTag(v37[2], 0);
ExFreePoolWithTag(v37, 0);
v35 = (PVOID *)P;
}
v50 = (PVOID *)v57;
v51 = (_GUID *)v57;
while( v50 != &v57 )
{
v52 = (const _GUID **)v51;
v51 = *(_GUID **)&v51->Data1;
EtwpDisallowedGuidRemoval(v52[2], NotificationContext);
v53 = *v52;
if( *(const _GUID ***)(*v52)->Data4 != v52 )
goto LABEL_69;
v54 = (void **)v52[1];
if( *v54 != v52 )
goto LABEL_69;
*v54 = (void *)v53;
*(_QWORD *)v53->Data4 = v54;
ExFreePoolWithTag(v52, 0);
v50 = (PVOID *)v57;
}
if( v34 )
ExFreePoolWithTag(v34, 0);
return v8;
}Referenced by:
EtwpUpdateDisallowList