EtwpApplyPayloadFilterInternal

INT64 __fastcall EtwpApplyPayloadFilterInternal(
        const _EVENT_DESCRIPTOR *EventDescriptor,
        UINT64 DataSegCount,
        _EVENT_DATA_DESCRIPTOR *DataSegsIn,
        INT64 UserModeDataSegs,
        UINT8 IsNativeProvider,
        _AGGREGATED_PAYLOAD_FILTER *PayloadFilter,
        UINT8 *WriteEventPtr){
  char v7; 
  int v9; 
  unsigned __int8 Version; 
  unsigned __int64 HashedEventIdBitmap; 
  char *v12; 
  unsigned int v13; 
  unsigned int v14; 
  unsigned int v15; 
  unsigned int v16; 
  bool v17; 
  unsigned int v18; 
  __int64 v19; 
  __int64 v20; 
  __int64 v22; 
  signed __int64 v23; 
  void *v24; 
  void *v25; 
  __int64 v26; 
  void *v27; 
  unsigned int v28; 
  int v29; 
  __int64 v30; 
  _EVENT_DATA_DESCRIPTOR *v31; 
  unsigned int v32; 
  __int64 v33; 
  __int64 v34; 
  unsigned __int64 Ptr; 
  unsigned __int64 v36; 
  char *v37; 
  unsigned int v38; 
  unsigned int v39; 
  _EVENT_DATA_DESCRIPTOR *v40; 
  char *v41; 
  BOOL *v42; 
  BOOL *v43; 
  unsigned int v44; 
  char v45; 
  __int64 v46; 
  __int64 v47; 
  int v48; 
  char v49; 
  unsigned int v50; 
  _WORD *v51; 
  unsigned int v52; 
  unsigned int v53; 
  unsigned int j; 
  _WORD *v55; 
  unsigned int v56; 
  _BYTE *v57; 
  unsigned int v58; 
  unsigned int v59; 
  unsigned int i; 
  unsigned int v61; 
  unsigned int v62; 
  __int64 v63; 
  unsigned __int64 v64; 
  _AGGREGATED_PAYLOAD_FILTER *v65; 
  unsigned __int16 *v66; 
  char v67; 
  char v68; 
  unsigned int v69; 
  _EVENT_PAYLOAD_PREDICATE *v70; 
  char v71; 
  char v72; 
  __int16 v73; 
  __int64 FieldIndex; 
  char v75; 
  UINT64 Size; 
  BOOL dst; 
  unsigned int v78; 
  unsigned int v79; 
  unsigned int v80; 
  unsigned int v81; 
  BOOL *p_dst; 
  _EVENT_DATA_DESCRIPTOR *v83; 
  unsigned __int8 v84; 
  ULONG SubAuthorityCount[2]; 
  int v86; 
  unsigned int v87; 
  BOOL *v88; 
  unsigned __int64 LowLimit; 
  unsigned __int16 Id; 
  unsigned int v91; 
  char *v92; 
  unsigned __int64 HighLimit; 
  _WORD *v94; 
  _BYTE *v95; 
  v7 = UserModeDataSegs;
  v9 = DataSegCount;
  v78 = DataSegCount;
  v95 = 0i64;
  v94 = 0i64;
  v87 = 0;
  v86 = 0;
  *(_QWORD *)SubAuthorityCount = 0i64;
  LOBYTE(dst) = 0;
  v80 = -1073741811;
  if( (unsigned int)DataSegCount > 0x80 )
    return 3221225485i64;
  Id = EventDescriptor->Id;
  Version = EventDescriptor->Version;
  v84 = Version;
  HashedEventIdBitmap = PayloadFilter->HashedEventIdBitmap;
  if( !_bittest64((const __int64 *)&HashedEventIdBitmap, Id % 0x3Fu) )
    goto LABEL_128;
  v79 = 0;
  v12 = (char *)PayloadFilter + PayloadFilter->EachEventTableOffset;
  v13 = 0;
  v14 = 0;
  v15 = PayloadFilter->EachEventTableLength / 0xCu;
  while( 1 )
  {
    v92 = v12;
    v16 = v13;
    v17 = v14 == v15;
    if( v14 >= v15 )
      break;
    if( *(_WORD *)v12 == Id && v12[2] == Version )
    {
      v17 = v14 == v15;
      break;
    }
    v18 = (unsigned __int8)v12[3];
    if( (unsigned __int16)v18 >= *((_WORD *)v12 + 3) )
      return 3221225485i64;
    v13 = (unsigned __int8)v12[3];
    v12 += 12;
    ++v14;
    if( v16 >= v18 )
      v13 = v16;
  }
  if( v17 )
  {
LABEL_128:
    *WriteEventPtr = 1;
    return 0i64;
  }
  v83 = 0i64;
  v19 = (unsigned int)(16 * v9);
  v91 = (unsigned __int8)v12[3] + 1;
  v20 = 4 * v91;
  HighLimit = 0i64;
  LowLimit = 0i64;
  IoGetStackLimits(&LowLimit, &HighLimit);
  if( (unsigned __int64)&HighLimit - LowLimit < (unsigned int)(v20 + v19 + 4096) )
    return 3221225626i64;
  v22 = v20 + 15;
  if( v20 + 15 <= (unsigned __int64)(unsigned int)v20 )
    v22 = 0xFFFFFFFFFFFFFF0i64;
  v23 = v22 & 0xFFFFFFFFFFFFFFF0ui64;
  v24 = alloca(v23);
  v25 = alloca(v23);
  p_dst = &dst;
  if( v7 )
  {
    v26 = v19 + 15;
    if( v19 + 15 <= (unsigned __int64)(unsigned int)v19 )
      v26 = 0xFFFFFFFFFFFFFF0i64;
    v27 = alloca(v26 & 0xFFFFFFFFFFFFFFF0ui64);
    v83 = (_EVENT_DATA_DESCRIPTOR *)&dst;
    v28 = 0;
    if( (_DWORD)v19 )
    {
      if( ((unsigned __int8)DataSegsIn & 3) != 0 )
        ExRaiseDatatypeMisalignment();
      if( (unsigned __int64)DataSegsIn + v19 > 0x7FFFFFFF0000i64
        || (_EVENT_DATA_DESCRIPTOR *)((char *)DataSegsIn + v19) < DataSegsIn )
      {
        MEMORY[0x7FFFFFFF0000] = 0;
      }
    }
    memmove((UINT8 *)&dst, (UINT8 *)DataSegsIn, (unsigned int)v19);
    v29 = 0;
    v30 = 0i64;
    v31 = v83;
    while( 1 )
    {
      v86 = v29;
      v32 = v78;
      if( (unsigned int)v30 >= v78 )
        break;
      v33 = v30;
      v34 = v83[v33].Size;
      if( (_DWORD)v34 )
      {
        Ptr = v83[v33].Ptr;
        v36 = Ptr + v34;
        if( v36 > 0x7FFFFFFF0000i64 || v36 < Ptr )
          MEMORY[0x7FFFFFFF0000] = 0;
      }
      v30 = (unsigned int)++v29;
    }
  }
  else
  {
    v31 = DataSegsIn;
    v83 = DataSegsIn;
    v32 = v78;
    v28 = 0;
  }
  v37 = (char *)PayloadFilter + PayloadFilter->PayloadDecoderTableOffset;
  v38 = 0;
  v80 = 0;
  v39 = 0;
  v40 = v31;
  v41 = &v37[4 * *((unsigned __int16 *)v12 + 2)];
  v42 = p_dst;
  v43 = p_dst;
  v88 = p_dst;
  v44 = 0;
  while( 1 )
  {
    v81 = v44;
    if( v44 >= v91 )
      break;
    if( v38 == v32 )
      return 3221225990i64;
    v45 = *v41 & 0xF;
    if( v45 == 7 )
    {
      if( *((_WORD *)v41 + 1) )
        return 3221225520i64;
      *((_BYTE *)v43 + 3) = v38;
      *v43 = *v43 & 0xFF000000 | ((v39 & 0xFFF) << 12);
      v32 = v78;
    }
    else
    {
      v46 = *((unsigned __int16 *)v41 + 1);
      if( v45 == 8 )
        v46 = IsNativeProvider != 0 ? 8 : 4;
      if( (*v41 & 0x10) != 0 )
      {
        if( (unsigned int)v46 >= v81 )
          return 3221225520i64;
        if( (unsigned __int8)((v37[4 * v46] & 0xF) - 1) > 1u )
          return 3221225520i64;
        if( (v37[4 * v46] & 0x30) != 0 )
          return 3221225520i64;
        if( *(_WORD *)&v37[4 * v46 + 2] > 8u )
          return 3221225520i64;
        if( v37[4 * v46 + 1] != 1 )
          return 3221225520i64;
        _mm_lfence();
        if( !EtwpGetFieldValue(
                (UINT8 *)(v31[HIBYTE(v42[v46])].Ptr + (((unsigned int)v42[v46] >> 12) & 0xFFF)),
                *(unsigned __int16 *)&v37[4 * v46 + 2],
                (UINT64 *)SubAuthorityCount) )
          return 3221225520i64;
        LODWORD(v46) = SubAuthorityCount[0];
        if( SubAuthorityCount[0] != *(_QWORD *)SubAuthorityCount )
          return 3221225520i64;
        v31 = v83;
        v42 = p_dst;
      }
      v47 = (unsigned __int8)v41[1];
      if( (*v41 & 0x20) != 0 )
      {
        if( (unsigned int)v47 >= v81 )
          return 3221225520i64;
        if( (unsigned __int8)((v37[4 * v47] & 0xF) - 1) > 1u )
          return 3221225520i64;
        if( (v37[4 * v47] & 0x30) != 0 )
          return 3221225520i64;
        if( *(_WORD *)&v37[4 * v47 + 2] > 8u )
          return 3221225520i64;
        if( v37[4 * v47 + 1] != 1 )
          return 3221225520i64;
        _mm_lfence();
        if( !EtwpGetFieldValue(
                (UINT8 *)(v31[HIBYTE(v42[v47])].Ptr + (((unsigned int)v42[v47] >> 12) & 0xFFF)),
                *(unsigned __int16 *)&v37[4 * v47 + 2],
                (UINT64 *)SubAuthorityCount) )
          return 3221225520i64;
        LODWORD(v47) = SubAuthorityCount[0];
        if( SubAuthorityCount[0] != *(_QWORD *)SubAuthorityCount )
          return 3221225520i64;
      }
      v48 = 0;
      if( !(_DWORD)v46 )
      {
        v49 = *v41;
        if( (*v41 & 0x10) != 0 || (_DWORD)v47 != 1 )
          return 3221225520i64;
        switch( v49 & 0xF )
        {
          case 3:
            v56 = v40->Size;
            if( v39 >= v56 )
              return 3221225485i64;
            v57 = (_BYTE *)(v40->Ptr + v39);
            v58 = v56 - v39;
            v59 = 0;
            for( i = 0; i < v58 && *v57; ++i )
            {
              v59 = i + 1;
              v87 = i + 1;
              v95 = ++v57;
            }
            if( v59 == v58 )
            {
              v79 = 1;
              v48 = 0;
            }
            else
            {
              v48 = 1;
            }
            LODWORD(v46) = v59;
            break;
          case 4:
            v50 = v40->Size - v39;
            if( v50 < 2 )
              return 3221225485i64;
            v51 = (_WORD *)(v40->Ptr + v39);
            v52 = v50 >> 1;
            v53 = 0;
            for( j = 0; ; ++j )
            {
              v55 = v51;
              if( j >= v52 || !*v51 )
                break;
              v53 = j + 1;
              v87 = j + 1;
              ++v51;
              v94 = v55 + 1;
            }
            if( v53 == v52 )
            {
              v79 = 2;
              v48 = 0;
            }
            else
            {
              v48 = 2;
            }
            if( v53 == v52 && v39 + 2i64 * v52 != v40->Size )
              return 3221225485i64;
            LODWORD(v46) = 2 * v53;
            break;
          case 6:
            if( v40->Size - v39 < 2 )
              return 3221225485i64;
            if( !EtwpGetFieldValue((UINT8 *)(v40->Ptr + v39 + 1i64), 1ui64, (UINT64 *)SubAuthorityCount) )
              return 3221225485i64;
            LODWORD(v46) = RtlLengthRequiredSid(SubAuthorityCount[0]);
            if( (_DWORD)v46 == -1 )
              return 3221225485i64;
            v48 = 0;
            break;
          default:
            return 3221225520i64;
        }
      }
      v61 = v47 * v46;
      if( v40->Size - v39 < v61 )
        return 3221225990i64;
      v38 = v80;
      v43 = v88;
      *((_BYTE *)v88 + 3) = v80;
      v62 = v61 & 0xFFF | *v43 & 0xFF000000 | ((v39 & 0xFFF) << 12);
      *v43 = v62;
      if( *((unsigned __int8 *)v43 + 3) != v38 || ((v62 >> 12) & 0xFFF) != v39 || (v62 & 0xFFF) != v61 )
        return 3221225990i64;
      v39 += v48 + v61;
      if( v39 > v40->Size )
        return 3221225473i64;
      v31 = v83;
      if( v39 != v40->Size )
      {
        v32 = v78;
        v28 = 0;
LABEL_107:
        v42 = p_dst;
        goto LABEL_108;
      }
      v80 = ++v38;
      v32 = v78;
      v28 = 0;
      if( v38 >= v78 )
        goto LABEL_107;
      v39 = 0;
      if( ++v40 >= &v83[v78] )
        return 3221225473i64;
      if( v79 )
      {
        if( v40->Size < v79 )
          return 3221225990i64;
        v39 = v79;
      }
      v79 = 0;
      if( v39 != v40->Size )
        goto LABEL_107;
      v80 = ++v38;
      v42 = p_dst;
      if( v38 < v78 )
      {
        v39 = 0;
        ++v40;
      }
    }
LABEL_108:
    v44 = v81 + 1;
    v41 += 4;
    v88 = ++v43;
  }
  if( v79 )
    return 3221225990i64;
  v63 = (__int64)v92;
  v64 = (unsigned __int64)&v37[4 * *((unsigned __int16 *)v92 + 2)];
  LowLimit = v64;
  v65 = PayloadFilter;
  v66 = (unsigned __int16 *)((char *)PayloadFilter
                           + 4 * *((unsigned __int16 *)v92 + 4)
                           + PayloadFilter->EventFilterTableOffset);
  v67 = 0;
  v68 = 0;
  BYTE2(dst) = 1;
  v69 = 0;
  while( v69 < *(unsigned __int16 *)(v63 + 10) )
  {
    v70 = &v65->PredicateTable[v66[1]];
    v71 = 1;
    v72 = 0;
    while( 1 )
    {
      BYTE1(dst) = v72;
      v88 = (BOOL *)v70;
      v73 = *v66;
      if( v28 >= ((*v66 >> 2) & 0x3Fu) )
        break;
      FieldIndex = v70->FieldIndex;
      LODWORD(Size) = p_dst[FieldIndex] & 0xFFF;
      if( !EtwpApplyPredicate(
              (UINT16 *)PayloadFilter,
              *(_BYTE *)(v64 + 4 * FieldIndex) & 0xF,
              (INT64)v70,
              v31[HIBYTE(p_dst[FieldIndex])].Ptr + (((unsigned __int64)p_dst[FieldIndex] >> 12) & 0xFFF),
              Size,
              &dst) )
        return 3221225520i64;
      v71 &= dst;
      v72 = dst | BYTE1(dst);
      ++v28;
      v70 = (_EVENT_PAYLOAD_PREDICATE *)(v88 + 6);
      v64 = LowLimit;
      v31 = v83;
    }
    if( (v73 & 2) == 0 )
      v72 = v71;
    if( (v73 & 1) != 0 )
    {
      v75 = v67 & v72;
      v67 = v72;
      v28 = 0;
      if( !BYTE2(dst) )
        v67 = v75;
      BYTE2(dst) = 0;
    }
    else
    {
      v68 |= v72;
      if( v68 == 1 )
        break;
      v28 = 0;
    }
    ++v69;
    v66 += 2;
    v63 = (__int64)v92;
    v65 = PayloadFilter;
  }
  *WriteEventPtr = v67 | v68;
  return 0i64;
}

Referenced by:

EtwpApplyEventIdPayloadFilter