EtwSetPerformanceTraceInformation

INT64 __stdcall EtwSetPerformanceTraceInformation(
        PVOID SystemInformation,
        UINT64 SystemInformationLength,
        INT8 PreviousMode){
  unsigned int v4; 
  int v6; 
  __int64 CurrentSiloState; 
  _ETW_SILODRIVERSTATE *v8; 
  INT64 v9; 
  int v10; 
  int v11; 
  unsigned int v12; 
  int v13; 
  int v14; 
  unsigned int v15; 
  UINT64 v16; 
  _ETHREAD *v17; 
  _WMI_LOGGER_CONTEXT *v18; 
  INT64 v19; 
  int updated; 
  unsigned int v21; 
  _KPROFILE_SOURCE *v22; 
  _KPROFILE_SOURCE *v23; 
  ULONG v24; 
  void *v25; 
  unsigned int v26; 
  unsigned int v27; 
  __int64 v28; 
  UINT64 LoggerId; 
  _ETHREAD *v30; 
  _WMI_LOGGER_CONTEXT *v31; 
  __int64 v32; 
  UINT64 v33; 
  _ETHREAD *v34; 
  _WMI_LOGGER_CONTEXT *v35; 
  UINT64 v37; 
  _ETHREAD *v38; 
  _WMI_LOGGER_CONTEXT *v39; 
  unsigned int v40; 
  WCHAR *v41; 
  WCHAR *v42; 
  unsigned int v43; 
  unsigned int v44; 
  WCHAR *PoolWithTag; 
  WCHAR *v46; 
  char v47; 
  int CpuVendor; 
  unsigned int v49; 
  unsigned int v50; 
  UINT64 *v51; 
  UINT64 v52; 
  _ETHREAD *v53; 
  _WMI_LOGGER_CONTEXT *v54; 
  UINT64 v55; 
  _ETHREAD *CurrentThread; 
  _WMI_LOGGER_CONTEXT *v57; 
  unsigned int v58; 
  unsigned int v59; 
  UINT64 v60; 
  _ETHREAD *v61; 
  _WMI_LOGGER_CONTEXT *v62; 
  __int64 *v63; 
  char v64; 
  int v65; 
  PVOID P; 
  int v67; 
  unsigned int BucketCount; 
  unsigned int BucketCount_4; 
  __int128 v70; 
  wchar_t *Src; 
  int v72; 
  unsigned int v73; 
  int v74; 
  unsigned int v75; 
  int v76; 
  int v77; 
  int v78; 
  INT64 v79[2]; 
  __int64 v80; 
  INT64 v81[2]; 
  __int64 v82; 
  __int64 v83; 
  __int64 v84; 
  __int64 v85; 
  __int64 v86; 
  __int64 v87; 
  INT64 v88[2]; 
  __int128 v89; 
  int v90; 
  UINT16 result[86]; 
  INT64 v92; 
  int v93; 
  INT64 a2; 
  int v95; 
  UINT8 dst[16]; 
  v4 = SystemInformationLength;
  if( (unsigned int)SystemInformationLength < 4 )
    return 3221225485i64;
  v6 = *(_DWORD *)SystemInformation;
  v65 = *(_DWORD *)SystemInformation;
  CurrentSiloState = EtwpGetCurrentSiloState();
  v8 = (_ETW_SILODRIVERSTATE *)CurrentSiloState;
  if( v6 > 16 )
  {
    if( v6 == 17 )
      goto LABEL_144;
    if( v6 != 18 )
    {
      switch( v6 )
      {
        case 19:
          if( v4 < 0x18 )
            return 3221225476i64;
          *(_OWORD *)v81 = *(_OWORD *)SystemInformation;
          v82 = *((_QWORD *)SystemInformation + 2);
          v55 = LOWORD(v81[1]);
          if( LOWORD(v81[1]) == 0xFFFF )
            v55 = *(unsigned __int8 *)(CurrentSiloState + 4208);
          CurrentThread = (_ETHREAD *)KeGetCurrentThread();
          --*((_WORD *)CurrentThread + 242);
          v57 = EtwpAcquireLoggerContextByLoggerId(v8, v55, 1u);
          v19 = (INT64)v57;
          if( !v57 )
            goto LABEL_153;
          v10 = EtwpCheckLoggerControlAccess(0x80ui64, v57);
          if( v10 < 0 )
            goto LABEL_79;
          updated = EtwpUpdateLastBranchTracingConfiguration(v19, (INT64)v81);
LABEL_78:
          v10 = updated;
          goto LABEL_79;
        case 20:
          goto LABEL_119;
        case 21:
          if( PreviousMode && !EtwpUserInAdminOrLogUsersGroup() )
            return 3221225506i64;
          if( v4 < 0x24 || *((_BYTE *)SystemInformation + 4) != 2 || v4 > 0x220 )
            return 3221225476i64;
          v43 = v4 - 34 + 184;
          v44 = (v4 - 34) >> 1;
          PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v43, 0x50777445ui64);
          v46 = PoolWithTag;
          P = PoolWithTag;
          if( !PoolWithTag )
            return 3221225495i64;
          wcsncpy_s(PoolWithTag + 92, v44, (WCHAR *)SystemInformation + 17, v44);
          a2 = *((_QWORD *)SystemInformation + 2);
          v95 = *((_DWORD *)SystemInformation + 6);
          *((_DWORD *)v46 + 2) = *((_DWORD *)SystemInformation + 7);
          v47 = *((_BYTE *)SystemInformation + 32);
          CpuVendor = KiGetCpuVendor();
          if( CpuVendor == 2 )
          {
            *(_BYTE *)v46 = *((_BYTE *)SystemInformation + 8);
            *((_BYTE *)v46 + 1) = *((_BYTE *)SystemInformation + 9);
            *((_BYTE *)v46 + 2) = *((_BYTE *)SystemInformation + 10);
            *((_BYTE *)v46 + 3) = *((_BYTE *)SystemInformation + 11);
            *((_BYTE *)v46 + 4) = *((_BYTE *)SystemInformation + 12);
            *((_BYTE *)v46 + 5) = *((_BYTE *)SystemInformation + 13);
          }
          else if( CpuVendor == 1 )
          {
            *(_BYTE *)v46 = *((_BYTE *)SystemInformation + 8);
            *((_BYTE *)v46 + 1) = *((_BYTE *)SystemInformation + 9);
          }
          EtwpGetMicroarchitecturalPmcAffinity((INT64)&a2, v46 + 8);
          v10 = ((__int64(__fastcall *)(__int64, _QWORD, WCHAR *))off_140C00A70[0])(20i64, v43, v46);
          if( v47 )
            v10 = EtwpAddMicroarchitecturalPmcToRegistry((UINT8 *)v46, (INT64)&a2);
          v25 = v46;
          break;
        case 22:
          v70 = 0i64;
          Src = 0i64;
          memset((INT64)result, 0i64);
          LODWORD(P) = 0;
          if( PreviousMode && !EtwpUserInAdminOrLogUsersGroup() )
            return 3221225506i64;
          if( v4 != 20 )
            return 3221225476i64;
          v92 = *((_QWORD *)SystemInformation + 1);
          v93 = *((_DWORD *)SystemInformation + 4);
          LODWORD(v70) = *((_DWORD *)SystemInformation + 1);
          v10 = ((__int64(__fastcall *)(__int64, __int64, __int128 *, PVOID *))off_140C00A68[0])(1i64, 24i64, &v70, &P);
          if( v10 < 0 )
            return(unsigned int)v10;
          v90 = v70;
          EtwpGetMicroarchitecturalPmcAffinity((INT64)&v92, &result[2]);
          v40 = wcsnlen(Src, 0xFFui64);
          v41 = (WCHAR *)ExAllocatePoolWithTag(PagedPool, 2i64 * (v40 + 1), 0x50777445ui64);
          v42 = v41;
          if( !v41 )
            return 3221225495i64;
          wcsncpy_s(v41, v40 + 1, Src, v40);
          v10 = ((__int64(__fastcall *)(__int64, __int64, int *))off_140C00A70[0])(21i64, 176i64, &v90);
          EtwpRemoveMicroarchitecturalPmcFromRegistry(v42, v40);
          v25 = v42;
          break;
        case 23:
          if( v4 >= 0x18 )
          {
            *(_OWORD *)v79 = *(_OWORD *)SystemInformation;
            v80 = *((_QWORD *)SystemInformation + 2);
            v37 = LOWORD(v79[1]);
            if( LOWORD(v79[1]) == 0xFFFF )
              v37 = *(unsigned __int8 *)(CurrentSiloState + 4208);
            v38 = (_ETHREAD *)KeGetCurrentThread();
            --*((_WORD *)v38 + 242);
            v39 = EtwpAcquireLoggerContextByLoggerId(v8, v37, 1u);
            v19 = (INT64)v39;
            if( v39 )
            {
              v10 = EtwpCheckLoggerControlAccess(0x80ui64, v39);
              if( v10 < 0 )
                goto LABEL_79;
              updated = EtwpUpdateProcessorTraceConfiguration(v19, (INT64)v79);
              goto LABEL_78;
            }
            goto LABEL_153;
          }
          return 3221225476i64;
        case 24:
          goto LABEL_119;
        case 25:
          return(unsigned int)EtwpSetCoverageSamplerInformation(SystemInformation, v4, PreviousMode);
        default:
          return(unsigned int)-1073741822;
      }
      v24 = 1350005829;
      goto LABEL_118;
    }
    return(unsigned int)EtwpSetSoftRestartInformation((INT64)SystemInformation, v4);
  }
  if( v6 == 16 )
  {
    if( v4 != 32 )
      return 3221225476i64;
    v32 = *((_QWORD *)SystemInformation + 1);
    v85 = v32;
    BucketCount_4 = *((_DWORD *)SystemInformation + 5);
    BucketCount = *((_DWORD *)SystemInformation + 6);
    if( !*((_BYTE *)SystemInformation + 16) )
      return 3221225659i64;
    v33 = (unsigned __int16)v32;
    if( (unsigned __int16)v32 == 0xFFFF )
      v33 = *(unsigned __int8 *)(CurrentSiloState + 4208);
    v34 = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)v34 + 242);
    v35 = EtwpAcquireLoggerContextByLoggerId(v8, v33, 1u);
    v19 = (INT64)v35;
    if( !v35 )
      goto LABEL_153;
    v10 = EtwpCheckLoggerControlAccess(0x80ui64, v35);
    if( v10 >= 0 )
    {
      updated = EtwpEnableStackCaching((_WMI_LOGGER_CONTEXT *)v19, BucketCount_4, BucketCount);
      goto LABEL_78;
    }
    goto LABEL_79;
  }
  if( v6 > 7 )
  {
    if( v6 != 10 )
    {
      if( v6 == 11 )
      {
        v64 = 0;
        if( v4 < 0x10 )
          return 3221225476i64;
        v26 = v4 - 16;
        if( (v26 & 3) != 0 )
          return 3221225485i64;
        v27 = v26 >> 2;
        if( v27 > 1 )
          return 3221225485i64;
        v28 = *((_QWORD *)SystemInformation + 1);
        v84 = v28;
        if( v27 )
        {
          if( *((_DWORD *)SystemInformation + 4) != 1316 )
            return 3221225485i64;
          v64 = 1;
        }
        if( SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemProfilePrivilege, PreviousMode) )
        {
          if( !PsIsCurrentThreadInServerSilo() )
          {
            LoggerId = (unsigned __int16)v28;
            if( (unsigned __int16)v28 == 0xFFFF )
              LoggerId = v8->SystemLoggerSettings.EtwpSystemLogger[0].LoggerId;
            v30 = (_ETHREAD *)KeGetCurrentThread();
            --*((_WORD *)v30 + 242);
            v31 = EtwpAcquireLoggerContextByLoggerId((_ETW_SILODRIVERSTATE *)EtwpHostSiloState, LoggerId, 1u);
            v19 = (INT64)v31;
            if( v31 )
            {
              v10 = EtwpCheckLoggerControlAccess(0x80ui64, v31);
              if( v10 >= 0 )
              {
                if( v64 )
                  _InterlockedOr((volatile signed __int32 *)(v19 + 832), 0x400u);
                else
                  _InterlockedAnd((volatile signed __int32 *)(v19 + 832), 0xFFFFFBFF);
              }
              goto LABEL_79;
            }
            goto LABEL_153;
          }
          return 3221225506i64;
        }
      }
      else
      {
        if( v6 != 12 )
        {
          if( v6 > 13 )
            goto LABEL_119;
          return(unsigned int)-1073741822;
        }
        if( v4 < 0x10 )
          return 3221225476i64;
        v9 = EtwpCheckCurrentUserGuidAccess((PVOID)&SystemTraceControlGuid, (PVOID)0x80);
        if( (int)v9 < 0 )
          return v9;
        if( SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemProfilePrivilege, PreviousMode) )
        {
          if( PsIsCurrentThreadInServerSilo() )
            return 3221225506i64;
          v21 = (v4 - 16) >> 2;
          if( v21 > EtwpMaxProfilingSources )
            return 3221225485i64;
          v22 = (_KPROFILE_SOURCE *)ExAllocatePoolWithTag(NonPagedPoolNx, 4i64 * v21, 0x58777445ui64);
          v23 = v22;
          P = v22;
          if( v22 )
          {
            memmove((UINT8 *)v22, (UINT8 *)SystemInformation + 16, 4i64 * v21);
            v10 = EtwpSetPmcProfileSource(v23, v21);
            v24 = 0;
            v25 = v23;
LABEL_118:
            ExFreePoolWithTag(v25, v24);
            return(unsigned int)v10;
          }
          return 3221225495i64;
        }
      }
      return 3221225569i64;
    }
LABEL_144:
    if( v4 >= 0x10 )
    {
      v58 = v4 - 16;
      if( (v58 & 3) == 0 )
      {
        v59 = v58 >> 2;
        if( (unsigned __int16)v59 <= 4u )
        {
          if( !PsIsCurrentThreadInServerSilo() )
          {
            v87 = *((_QWORD *)SystemInformation + 1);
            memmove(dst, (UINT8 *)SystemInformation + 16, 4i64 * (unsigned __int16)v59);
            v60 = (unsigned __int16)v87;
            if( (unsigned __int16)v87 == 0xFFFF )
              v60 = v8->SystemLoggerSettings.EtwpSystemLogger[0].LoggerId;
            v61 = (_ETHREAD *)KeGetCurrentThread();
            --*((_WORD *)v61 + 242);
            v62 = EtwpAcquireLoggerContextByLoggerId(v8, v60, 1u);
            v19 = (INT64)v62;
            if( v62 )
            {
              if( (*((_DWORD *)v62 + 3) & 0x2000000) == 0 )
              {
                EtwpReleaseLoggerContext((unsigned int *)v62, 1);
                v10 = -1073741811;
                goto LABEL_156;
              }
              v10 = EtwpCheckSystemTraceAccess((__int64)v62, 0x80ui64);
              if( v10 >= 0 )
              {
                v63 = EtwpPoolTagFilter;
                if( v65 != 10 )
                  v63 = EtwpObjectTypeFilter;
                EtwpUpdateTagFilter(dst, v59, (__int64)v63 + 20 * *(unsigned __int8 *)(v19 + 834));
              }
              goto LABEL_79;
            }
            goto LABEL_153;
          }
          return 3221225506i64;
        }
      }
      return 3221225485i64;
    }
    return 3221225476i64;
  }
  switch( v6 )
  {
    case 7:
      if( v4 == 16 )
      {
        v9 = EtwpCheckCurrentUserGuidAccess((PVOID)&SystemTraceControlGuid, (PVOID)0x80);
        v10 = v9;
        if( (int)v9 < 0 )
          return v9;
        if( PsIsCurrentThreadInServerSilo() )
          return 3221225506i64;
        v76 = *((_DWORD *)SystemInformation + 1);
        v77 = *((_DWORD *)SystemInformation + 2);
        v78 = *((_DWORD *)SystemInformation + 3);
        KeWaitForSingleObject(&EtwpGroupMaskMutex, Executive, 0, 0, 0i64);
        EtwpExecutiveResourceReleaseSampleRate = v76;
        EtwpExecutiveResourceContentionSampleRate = v77;
        EtwpExecutiveResourceTimeout = v78;
        goto LABEL_28;
      }
      return 3221225476i64;
    case 1:
      if( v4 != 48 )
        return 3221225476i64;
      v83 = *((_QWORD *)SystemInformation + 1);
      *(_OWORD *)v88 = *((_OWORD *)SystemInformation + 1);
      v89 = *((_OWORD *)SystemInformation + 2);
      v16 = (unsigned __int16)v83;
      if( (unsigned __int16)v83 == 0xFFFF )
        v16 = *(unsigned __int8 *)(CurrentSiloState + 4208);
      v17 = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)v17 + 242);
      v18 = EtwpAcquireLoggerContextByLoggerId(v8, v16, 1u);
      v19 = (INT64)v18;
      if( !v18 )
        goto LABEL_153;
      if( (*((_DWORD *)v18 + 3) & 0x2000000) == 0 )
      {
        EtwpReleaseLoggerContext((unsigned int *)v18, 1);
        KeLeaveCriticalRegion();
        return 3221225485i64;
      }
      v10 = EtwpCheckSystemTraceAccess((__int64)v18, 0x80ui64);
      if( v10 >= 0 )
      {
        updated = EtwpUpdateGroupMasks(v19, (INT64)v88);
        goto LABEL_78;
      }
LABEL_79:
      EtwpReleaseLoggerContext((unsigned int *)v19, 1);
LABEL_156:
      KeLeaveCriticalRegion();
      return(unsigned int)v10;
    case 3:
      if( v4 == 8 )
      {
        if( PsIsCurrentThreadInServerSilo() )
          return 3221225506i64;
        v15 = *((_DWORD *)SystemInformation + 1);
        v75 = v15;
        KeWaitForSingleObject(&EtwpGroupMaskMutex, Executive, 0, 0, 0i64);
        v10 = NtSetIntervalProfile(v15, ProfileTime);
        if( v10 >= 0 )
          LODWORD(EtwpProfileInterval) = v15;
LABEL_28:
        KeReleaseMutex(&EtwpGroupMaskMutex, 0);
        return(unsigned int)v10;
      }
      return 3221225476i64;
    case 5:
      if( ((v4 - 16) & 0xFFFFFFFB) == 0 )
      {
        v9 = EtwpCheckCurrentUserGuidAccess((PVOID)&SystemTraceControlGuid, (PVOID)0x80);
        v10 = v9;
        if( (int)v9 < 0 )
          return v9;
        if( PsIsCurrentThreadInServerSilo() )
          return 3221225506i64;
        v11 = *((_DWORD *)SystemInformation + 1);
        v72 = v11;
        if( !v11 )
          return 3221225485i64;
        v12 = *((_DWORD *)SystemInformation + 2);
        v73 = v12;
        if( v12 < 0x3E8 )
          return 3221225485i64;
        v13 = *((_DWORD *)SystemInformation + 3);
        v74 = v13;
        if( !v13 )
          return 3221225485i64;
        v14 = *(_DWORD *)EtwpSpinLockHoldThreshold;
        v67 = *(_DWORD *)EtwpSpinLockHoldThreshold;
        if( v4 == 20 )
        {
          v14 = *((_DWORD *)SystemInformation + 4);
          v67 = v14;
          if( (unsigned int)(v14 - 1) <= 0xF423E )
            return 3221225485i64;
        }
        KeWaitForSingleObject(&EtwpGroupMaskMutex, Executive, 0, 0, 0i64);
        *(_DWORD *)EtwpSpinLockHoldThreshold = v14;
        EtwpSpinLockSpinThreshold = v11;
        EtwpSpinLockAcquireSampleRate = v12;
        EtwpSpinLockContentionSampleRate = v13;
        goto LABEL_28;
      }
      return 3221225476i64;
  }
  if( v6 != 6 )
    return(unsigned int)-1073741822;
LABEL_119:
  if( v4 < 0x10 )
    return 3221225476i64;
  v49 = v4 - 16;
  if( (v49 & 3) == 0 )
  {
    if( !PsIsCurrentThreadInServerSilo() || (unsigned int)(v6 - 14) > 1 )
    {
      v50 = v49 >> 2;
      v51 = (UINT64 *)((char *)SystemInformation + 16);
      v86 = *((_QWORD *)SystemInformation + 1);
      v52 = (unsigned __int16)v86;
      if( (unsigned __int16)v86 == 0xFFFF )
        v52 = v8->SystemLoggerSettings.EtwpSystemLogger[0].LoggerId;
      v53 = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)v53 + 242);
      v54 = EtwpAcquireLoggerContextByLoggerId(v8, v52, 1u);
      v19 = (INT64)v54;
      if( v54 )
      {
        v10 = EtwpCheckLoggerControlAccess(0x80ui64, v54);
        if( v10 < 0 )
          goto LABEL_79;
        switch( v65 )
        {
          case 6:
            updated = EtwpUpdateStackTracing((_WMI_LOGGER_CONTEXT *)v19, v51, v50);
            break;
          case 15:
            updated = EtwpUpdatePmcCounters(v19, (INT64)v51, v50);
            break;
          case 14:
            updated = EtwpUpdatePmcEvents((_WMI_LOGGER_CONTEXT *)v19, v51, v50);
            break;
          case 20:
            EtwpUpdateLastBranchTracingEvents(v19, (INT64)v51, v50);
            goto LABEL_79;
          default:
            updated = EtwpUpdateProcessorTraceEvents(v19, (__int64)v51, v50);
            break;
        }
        goto LABEL_78;
      }
LABEL_153:
      v10 = -1073741162;
      goto LABEL_156;
    }
    return 3221225506i64;
  }
  return 3221225485i64;
}

Referenced by:

NtSetSystemInformation