EtwpUpdateDisallowedGuids

INT64 __fastcall EtwpUpdateDisallowedGuids(
        INT64 a1,
        UINT16 a2,
        const VOID *a3,
        INT64 a4,
        INT64 a5,
        INT64 a6,
        VOID *NotificationContext){
  size_t v7; 
  unsigned int v8; 
  UINT8 *PoolWithTag; 
  WCHAR *v12; 
  unsigned int v13; 
  __int64 v14; 
  __int64 v15; 
  INT64 v16; 
  char *v17; 
  char *v18; 
  WCHAR *v19; 
  WCHAR *v20; 
  NTSTATUS v21; 
  PVOID *v22; 
  PVOID *v23; 
  _QWORD *v24; 
  _OWORD *v25; 
  PVOID *v26; 
  void *v27; 
  PVOID *v28; 
  PVOID *v29; 
  _QWORD *v30; 
  _OWORD *v31; 
  PVOID *v32; 
  volatile INT64 *v33; 
  void *v34; 
  PVOID *v35; 
  _GUID *v36; 
  _GUID **v37; 
  _GUID *v38; 
  void **v39; 
  PVOID *v40; 
  _QWORD *v41; 
  _QWORD *v42; 
  _QWORD *v43; 
  _QWORD *v44; 
  PVOID *v45; 
  _QWORD *v46; 
  __int64 v47; 
  _QWORD *v48; 
  _QWORD *v49; 
  PVOID *v50; 
  _GUID *v51; 
  const _GUID **v52; 
  const _GUID *v53; 
  void **v54; 
  PVOID P; 
  PVOID *p_P; 
  PVOID v57; 
  PVOID *v58; 
  struct _KMUTANT *Mutex; 
  v7 = a2;
  v8 = 0;
  if( a2 > 0x200u )
    return 3221225485i64;
  p_P = &P;
  P = &P;
  v58 = &v57;
  v57 = &v57;
  if( a2 )
  {
    PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, 16i64 * a2, 0x64777445ui64);
    v12 = (WCHAR *)PoolWithTag;
    if( !PoolWithTag )
    {
LABEL_53:
      v8 = -1073741670;
LABEL_54:
      v40 = (PVOID *)P;
      v41 = P;
      while( v40 != &P )
      {
        v42 = (_QWORD *)*v41;
        v43 = v41;
        v41 = v42;
        if( (_QWORD *)v42[1] != v43 )
          goto LABEL_69;
        v44 = (_QWORD *)v43[1];
        if( (_QWORD *)*v44 != v43 )
          goto LABEL_69;
        *v44 = v42;
        v42[1] = v44;
        ExFreePoolWithTag((PVOID)v43[2], 0);
        ExFreePoolWithTag(v43, 0);
        v40 = (PVOID *)P;
      }
      v45 = (PVOID *)v57;
      v46 = v57;
      while( v45 != &v57 )
      {
        v47 = *v46;
        v48 = v46;
        v46 = (_QWORD *)v47;
        if( *(_QWORD **)(v47 + 8) != v48 )
          goto LABEL_69;
        v49 = (_QWORD *)v48[1];
        if( (_QWORD *)*v49 != v48 )
          goto LABEL_69;
        *v49 = v47;
        *(_QWORD *)(v47 + 8) = v49;
        ExFreePoolWithTag(v48, 0);
        v45 = (PVOID *)v57;
      }
      return v8;
    }
    memmove(PoolWithTag, (UINT8 *)a3, 16 * v7);
    qsort(v12, v7, (const WCHAR *)0x10, EtwpCompareGuid);
    v13 = 0;
    if( (_DWORD)v7 != 1 )
    {
      while( 1 )
      {
        v14 = 8i64 * v13;
        v15 = *(_QWORD *)&v12[v14] - *(_QWORD *)&v12[v14 + 8];
        if( !v15 )
          v15 = *(_QWORD *)&v12[v14 + 4] - *(_QWORD *)&v12[v14 + 12];
        if( !v15 )
          break;
        if( ++v13 >= (int)v7 - 1 )
          goto LABEL_13;
      }
      ExFreePoolWithTag(v12, 0);
      v8 = -1073741811;
      goto LABEL_54;
    }
  }
  else
  {
    v12 = 0i64;
  }
LABEL_13:
  v16 = a1;
  Mutex = (struct _KMUTANT *)(a1 + 648);
  KeWaitForSingleObject((PVOID)(a1 + 648), Executive, 0, 0, 0i64);
  if( *(_WORD *)(a1 + 1048) )
  {
    v17 = *(char **)(a1 + 1056);
    v18 = &v17[16 * *(unsigned __int16 *)(a1 + 1048)];
  }
  else
  {
    v17 = 0i64;
    v18 = 0i64;
  }
  if( (_WORD)v7 )
  {
    v19 = v12;
    v20 = &v12[8 * v7];
  }
  else
  {
    v19 = 0i64;
    v20 = 0i64;
  }
  if( v17 < v18 )
  {
    while( v19 < v20 )
    {
      v21 = memcmp(v17, v19, 0x10ui64);
      if( v21 )
      {
        if( v21 >= 0 )
        {
          v24 = ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
          if( !v24 )
            goto LABEL_52;
          v25 = ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x74777445ui64);
          if( !v25 )
          {
            v27 = v24;
LABEL_51:
            ExFreePoolWithTag(v27, 0);
            goto LABEL_52;
          }
          *v25 = *(_OWORD *)v19;
          v24[2] = v25;
          v26 = p_P;
          if( *p_P != &P )
            goto LABEL_69;
          v24[1] = p_P;
          *v24 = &P;
          v19 += 8;
          *v26 = v24;
          p_P = (PVOID *)v24;
        }
        else
        {
          v22 = (PVOID *)ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
          if( !v22 )
            goto LABEL_52;
          v22[2] = v17;
          v23 = v58;
          if( *v58 != &v57 )
LABEL_69:
            __fastfail(3u);
          v22[1] = v58;
          *v22 = &v57;
          v17 += 16;
          *v23 = v22;
          v58 = v22;
        }
      }
      else
      {
        v17 += 16;
        v19 += 8;
      }
      if( v17 >= v18 )
      {
LABEL_37:
        v16 = a1;
        goto LABEL_38;
      }
    }
    while( 1 )
    {
      v28 = (PVOID *)ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
      if( !v28 )
        goto LABEL_52;
      v28[2] = v17;
      v29 = v58;
      if( *v58 != &v57 )
        goto LABEL_69;
      v28[1] = v58;
      *v28 = &v57;
      v17 += 16;
      *v29 = v28;
      v58 = v28;
      if( v17 >= v18 )
        goto LABEL_37;
    }
  }
LABEL_38:
  if( v19 < v20 )
  {
    while( 1 )
    {
      v30 = ExAllocatePoolWithTag(PagedPool, 0x18ui64, 0x74777445ui64);
      if( !v30 )
        break;
      v31 = ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x74777445ui64);
      if( !v31 )
      {
        v27 = v30;
        goto LABEL_51;
      }
      *v31 = *(_OWORD *)v19;
      v30[2] = v31;
      v32 = p_P;
      if( *p_P != &P )
        goto LABEL_69;
      v30[1] = p_P;
      *v30 = &P;
      v19 += 8;
      *v32 = v30;
      p_P = (PVOID *)v30;
      if( v19 >= v20 )
        goto LABEL_43;
    }
LABEL_52:
    KeReleaseMutex(Mutex, 0);
    goto LABEL_53;
  }
LABEL_43:
  v33 = (volatile INT64 *)(v16 + 704);
  ExAcquirePushLockExclusiveEx(v16 + 704, 0i64);
  *(_WORD *)(v16 + 1048) = a2;
  v34 = *(void **)(v16 + 1056);
  *(_QWORD *)(a1 + 1056) = v12;
  if( (_InterlockedExchangeAdd64(v33, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock(v33);
  KeAbPostRelease((PVOID)v33);
  KeReleaseMutex(Mutex, 0);
  v35 = (PVOID *)P;
  v36 = (_GUID *)P;
  while( v35 != &P )
  {
    v37 = (_GUID **)v36;
    v36 = *(_GUID **)&v36->Data1;
    EtwpDisallowedGuidAddition(v37[2], NotificationContext);
    v38 = *v37;
    if( *(_GUID ***)(*v37)->Data4 != v37 )
      goto LABEL_69;
    v39 = (void **)v37[1];
    if( *v39 != v37 )
      goto LABEL_69;
    *v39 = v38;
    *(_QWORD *)v38->Data4 = v39;
    ExFreePoolWithTag(v37[2], 0);
    ExFreePoolWithTag(v37, 0);
    v35 = (PVOID *)P;
  }
  v50 = (PVOID *)v57;
  v51 = (_GUID *)v57;
  while( v50 != &v57 )
  {
    v52 = (const _GUID **)v51;
    v51 = *(_GUID **)&v51->Data1;
    EtwpDisallowedGuidRemoval(v52[2], NotificationContext);
    v53 = *v52;
    if( *(const _GUID ***)(*v52)->Data4 != v52 )
      goto LABEL_69;
    v54 = (void **)v52[1];
    if( *v54 != v52 )
      goto LABEL_69;
    *v54 = (void *)v53;
    *(_QWORD *)v53->Data4 = v54;
    ExFreePoolWithTag(v52, 0);
    v50 = (PVOID *)v57;
  }
  if( v34 )
    ExFreePoolWithTag(v34, 0);
  return v8;
}

Referenced by:

EtwpUpdateDisallowList