EtwpApplyPayloadFilterInternal
INT64 __fastcall EtwpApplyPayloadFilterInternal(
const _EVENT_DESCRIPTOR *EventDescriptor,
UINT64 DataSegCount,
_EVENT_DATA_DESCRIPTOR *DataSegsIn,
INT64 UserModeDataSegs,
UINT8 IsNativeProvider,
_AGGREGATED_PAYLOAD_FILTER *PayloadFilter,
UINT8 *WriteEventPtr){
char v7;
int v9;
unsigned __int8 Version;
unsigned __int64 HashedEventIdBitmap;
char *v12;
unsigned int v13;
unsigned int v14;
unsigned int v15;
unsigned int v16;
bool v17;
unsigned int v18;
__int64 v19;
__int64 v20;
__int64 v22;
signed __int64 v23;
void *v24;
void *v25;
__int64 v26;
void *v27;
unsigned int v28;
int v29;
__int64 v30;
_EVENT_DATA_DESCRIPTOR *v31;
unsigned int v32;
__int64 v33;
__int64 v34;
unsigned __int64 Ptr;
unsigned __int64 v36;
char *v37;
unsigned int v38;
unsigned int v39;
_EVENT_DATA_DESCRIPTOR *v40;
char *v41;
BOOL *v42;
BOOL *v43;
unsigned int v44;
char v45;
__int64 v46;
__int64 v47;
int v48;
char v49;
unsigned int v50;
_WORD *v51;
unsigned int v52;
unsigned int v53;
unsigned int j;
_WORD *v55;
unsigned int v56;
_BYTE *v57;
unsigned int v58;
unsigned int v59;
unsigned int i;
unsigned int v61;
unsigned int v62;
__int64 v63;
unsigned __int64 v64;
_AGGREGATED_PAYLOAD_FILTER *v65;
unsigned __int16 *v66;
char v67;
char v68;
unsigned int v69;
_EVENT_PAYLOAD_PREDICATE *v70;
char v71;
char v72;
__int16 v73;
__int64 FieldIndex;
char v75;
UINT64 Size;
BOOL dst;
unsigned int v78;
unsigned int v79;
unsigned int v80;
unsigned int v81;
BOOL *p_dst;
_EVENT_DATA_DESCRIPTOR *v83;
unsigned __int8 v84;
ULONG SubAuthorityCount[2];
int v86;
unsigned int v87;
BOOL *v88;
unsigned __int64 LowLimit;
unsigned __int16 Id;
unsigned int v91;
char *v92;
unsigned __int64 HighLimit;
_WORD *v94;
_BYTE *v95;
v7 = UserModeDataSegs;
v9 = DataSegCount;
v78 = DataSegCount;
v95 = 0i64;
v94 = 0i64;
v87 = 0;
v86 = 0;
*(_QWORD *)SubAuthorityCount = 0i64;
LOBYTE(dst) = 0;
v80 = -1073741811;
if( (unsigned int)DataSegCount > 0x80 )
return 3221225485i64;
Id = EventDescriptor->Id;
Version = EventDescriptor->Version;
v84 = Version;
HashedEventIdBitmap = PayloadFilter->HashedEventIdBitmap;
if( !_bittest64((const __int64 *)&HashedEventIdBitmap, Id % 0x3Fu) )
goto LABEL_128;
v79 = 0;
v12 = (char *)PayloadFilter + PayloadFilter->EachEventTableOffset;
v13 = 0;
v14 = 0;
v15 = PayloadFilter->EachEventTableLength / 0xCu;
while( 1 )
{
v92 = v12;
v16 = v13;
v17 = v14 == v15;
if( v14 >= v15 )
break;
if( *(_WORD *)v12 == Id && v12[2] == Version )
{
v17 = v14 == v15;
break;
}
v18 = (unsigned __int8)v12[3];
if( (unsigned __int16)v18 >= *((_WORD *)v12 + 3) )
return 3221225485i64;
v13 = (unsigned __int8)v12[3];
v12 += 12;
++v14;
if( v16 >= v18 )
v13 = v16;
}
if( v17 )
{
LABEL_128:
*WriteEventPtr = 1;
return 0i64;
}
v83 = 0i64;
v19 = (unsigned int)(16 * v9);
v91 = (unsigned __int8)v12[3] + 1;
v20 = 4 * v91;
HighLimit = 0i64;
LowLimit = 0i64;
IoGetStackLimits(&LowLimit, &HighLimit);
if( (unsigned __int64)&HighLimit - LowLimit < (unsigned int)(v20 + v19 + 4096) )
return 3221225626i64;
v22 = v20 + 15;
if( v20 + 15 <= (unsigned __int64)(unsigned int)v20 )
v22 = 0xFFFFFFFFFFFFFF0i64;
v23 = v22 & 0xFFFFFFFFFFFFFFF0ui64;
v24 = alloca(v23);
v25 = alloca(v23);
p_dst = &dst;
if( v7 )
{
v26 = v19 + 15;
if( v19 + 15 <= (unsigned __int64)(unsigned int)v19 )
v26 = 0xFFFFFFFFFFFFFF0i64;
v27 = alloca(v26 & 0xFFFFFFFFFFFFFFF0ui64);
v83 = (_EVENT_DATA_DESCRIPTOR *)&dst;
v28 = 0;
if( (_DWORD)v19 )
{
if( ((unsigned __int8)DataSegsIn & 3) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)DataSegsIn + v19 > 0x7FFFFFFF0000i64
|| (_EVENT_DATA_DESCRIPTOR *)((char *)DataSegsIn + v19) < DataSegsIn )
{
MEMORY[0x7FFFFFFF0000] = 0;
}
}
memmove((UINT8 *)&dst, (UINT8 *)DataSegsIn, (unsigned int)v19);
v29 = 0;
v30 = 0i64;
v31 = v83;
while( 1 )
{
v86 = v29;
v32 = v78;
if( (unsigned int)v30 >= v78 )
break;
v33 = v30;
v34 = v83[v33].Size;
if( (_DWORD)v34 )
{
Ptr = v83[v33].Ptr;
v36 = Ptr + v34;
if( v36 > 0x7FFFFFFF0000i64 || v36 < Ptr )
MEMORY[0x7FFFFFFF0000] = 0;
}
v30 = (unsigned int)++v29;
}
}
else
{
v31 = DataSegsIn;
v83 = DataSegsIn;
v32 = v78;
v28 = 0;
}
v37 = (char *)PayloadFilter + PayloadFilter->PayloadDecoderTableOffset;
v38 = 0;
v80 = 0;
v39 = 0;
v40 = v31;
v41 = &v37[4 * *((unsigned __int16 *)v12 + 2)];
v42 = p_dst;
v43 = p_dst;
v88 = p_dst;
v44 = 0;
while( 1 )
{
v81 = v44;
if( v44 >= v91 )
break;
if( v38 == v32 )
return 3221225990i64;
v45 = *v41 & 0xF;
if( v45 == 7 )
{
if( *((_WORD *)v41 + 1) )
return 3221225520i64;
*((_BYTE *)v43 + 3) = v38;
*v43 = *v43 & 0xFF000000 | ((v39 & 0xFFF) << 12);
v32 = v78;
}
else
{
v46 = *((unsigned __int16 *)v41 + 1);
if( v45 == 8 )
v46 = IsNativeProvider != 0 ? 8 : 4;
if( (*v41 & 0x10) != 0 )
{
if( (unsigned int)v46 >= v81 )
return 3221225520i64;
if( (unsigned __int8)((v37[4 * v46] & 0xF) - 1) > 1u )
return 3221225520i64;
if( (v37[4 * v46] & 0x30) != 0 )
return 3221225520i64;
if( *(_WORD *)&v37[4 * v46 + 2] > 8u )
return 3221225520i64;
if( v37[4 * v46 + 1] != 1 )
return 3221225520i64;
_mm_lfence();
if( !EtwpGetFieldValue(
(UINT8 *)(v31[HIBYTE(v42[v46])].Ptr + (((unsigned int)v42[v46] >> 12) & 0xFFF)),
*(unsigned __int16 *)&v37[4 * v46 + 2],
(UINT64 *)SubAuthorityCount) )
return 3221225520i64;
LODWORD(v46) = SubAuthorityCount[0];
if( SubAuthorityCount[0] != *(_QWORD *)SubAuthorityCount )
return 3221225520i64;
v31 = v83;
v42 = p_dst;
}
v47 = (unsigned __int8)v41[1];
if( (*v41 & 0x20) != 0 )
{
if( (unsigned int)v47 >= v81 )
return 3221225520i64;
if( (unsigned __int8)((v37[4 * v47] & 0xF) - 1) > 1u )
return 3221225520i64;
if( (v37[4 * v47] & 0x30) != 0 )
return 3221225520i64;
if( *(_WORD *)&v37[4 * v47 + 2] > 8u )
return 3221225520i64;
if( v37[4 * v47 + 1] != 1 )
return 3221225520i64;
_mm_lfence();
if( !EtwpGetFieldValue(
(UINT8 *)(v31[HIBYTE(v42[v47])].Ptr + (((unsigned int)v42[v47] >> 12) & 0xFFF)),
*(unsigned __int16 *)&v37[4 * v47 + 2],
(UINT64 *)SubAuthorityCount) )
return 3221225520i64;
LODWORD(v47) = SubAuthorityCount[0];
if( SubAuthorityCount[0] != *(_QWORD *)SubAuthorityCount )
return 3221225520i64;
}
v48 = 0;
if( !(_DWORD)v46 )
{
v49 = *v41;
if( (*v41 & 0x10) != 0 || (_DWORD)v47 != 1 )
return 3221225520i64;
switch( v49 & 0xF )
{
case 3:
v56 = v40->Size;
if( v39 >= v56 )
return 3221225485i64;
v57 = (_BYTE *)(v40->Ptr + v39);
v58 = v56 - v39;
v59 = 0;
for( i = 0; i < v58 && *v57; ++i )
{
v59 = i + 1;
v87 = i + 1;
v95 = ++v57;
}
if( v59 == v58 )
{
v79 = 1;
v48 = 0;
}
else
{
v48 = 1;
}
LODWORD(v46) = v59;
break;
case 4:
v50 = v40->Size - v39;
if( v50 < 2 )
return 3221225485i64;
v51 = (_WORD *)(v40->Ptr + v39);
v52 = v50 >> 1;
v53 = 0;
for( j = 0; ; ++j )
{
v55 = v51;
if( j >= v52 || !*v51 )
break;
v53 = j + 1;
v87 = j + 1;
++v51;
v94 = v55 + 1;
}
if( v53 == v52 )
{
v79 = 2;
v48 = 0;
}
else
{
v48 = 2;
}
if( v53 == v52 && v39 + 2i64 * v52 != v40->Size )
return 3221225485i64;
LODWORD(v46) = 2 * v53;
break;
case 6:
if( v40->Size - v39 < 2 )
return 3221225485i64;
if( !EtwpGetFieldValue((UINT8 *)(v40->Ptr + v39 + 1i64), 1ui64, (UINT64 *)SubAuthorityCount) )
return 3221225485i64;
LODWORD(v46) = RtlLengthRequiredSid(SubAuthorityCount[0]);
if( (_DWORD)v46 == -1 )
return 3221225485i64;
v48 = 0;
break;
default:
return 3221225520i64;
}
}
v61 = v47 * v46;
if( v40->Size - v39 < v61 )
return 3221225990i64;
v38 = v80;
v43 = v88;
*((_BYTE *)v88 + 3) = v80;
v62 = v61 & 0xFFF | *v43 & 0xFF000000 | ((v39 & 0xFFF) << 12);
*v43 = v62;
if( *((unsigned __int8 *)v43 + 3) != v38 || ((v62 >> 12) & 0xFFF) != v39 || (v62 & 0xFFF) != v61 )
return 3221225990i64;
v39 += v48 + v61;
if( v39 > v40->Size )
return 3221225473i64;
v31 = v83;
if( v39 != v40->Size )
{
v32 = v78;
v28 = 0;
LABEL_107:
v42 = p_dst;
goto LABEL_108;
}
v80 = ++v38;
v32 = v78;
v28 = 0;
if( v38 >= v78 )
goto LABEL_107;
v39 = 0;
if( ++v40 >= &v83[v78] )
return 3221225473i64;
if( v79 )
{
if( v40->Size < v79 )
return 3221225990i64;
v39 = v79;
}
v79 = 0;
if( v39 != v40->Size )
goto LABEL_107;
v80 = ++v38;
v42 = p_dst;
if( v38 < v78 )
{
v39 = 0;
++v40;
}
}
LABEL_108:
v44 = v81 + 1;
v41 += 4;
v88 = ++v43;
}
if( v79 )
return 3221225990i64;
v63 = (__int64)v92;
v64 = (unsigned __int64)&v37[4 * *((unsigned __int16 *)v92 + 2)];
LowLimit = v64;
v65 = PayloadFilter;
v66 = (unsigned __int16 *)((char *)PayloadFilter
+ 4 * *((unsigned __int16 *)v92 + 4)
+ PayloadFilter->EventFilterTableOffset);
v67 = 0;
v68 = 0;
BYTE2(dst) = 1;
v69 = 0;
while( v69 < *(unsigned __int16 *)(v63 + 10) )
{
v70 = &v65->PredicateTable[v66[1]];
v71 = 1;
v72 = 0;
while( 1 )
{
BYTE1(dst) = v72;
v88 = (BOOL *)v70;
v73 = *v66;
if( v28 >= ((*v66 >> 2) & 0x3Fu) )
break;
FieldIndex = v70->FieldIndex;
LODWORD(Size) = p_dst[FieldIndex] & 0xFFF;
if( !EtwpApplyPredicate(
(UINT16 *)PayloadFilter,
*(_BYTE *)(v64 + 4 * FieldIndex) & 0xF,
(INT64)v70,
v31[HIBYTE(p_dst[FieldIndex])].Ptr + (((unsigned __int64)p_dst[FieldIndex] >> 12) & 0xFFF),
Size,
&dst) )
return 3221225520i64;
v71 &= dst;
v72 = dst | BYTE1(dst);
++v28;
v70 = (_EVENT_PAYLOAD_PREDICATE *)(v88 + 6);
v64 = LowLimit;
v31 = v83;
}
if( (v73 & 2) == 0 )
v72 = v71;
if( (v73 & 1) != 0 )
{
v75 = v67 & v72;
v67 = v72;
v28 = 0;
if( !BYTE2(dst) )
v67 = v75;
BYTE2(dst) = 0;
}
else
{
v68 |= v72;
if( v68 == 1 )
break;
v28 = 0;
}
++v69;
v66 += 2;
v63 = (__int64)v92;
v65 = PayloadFilter;
}
*WriteEventPtr = v67 | v68;
return 0i64;
}Referenced by:
EtwpApplyEventIdPayloadFilter