EtwpValidateTraceControlFilterDescriptors

INT64 __fastcall EtwpValidateTraceControlFilterDescriptors(UINT64 a1, INT64 a2, UINT64 a3, INT64 a4){
  unsigned __int64 v4; 
  _QWORD *v5; 
  unsigned int v7; 
  int v8; 
  unsigned int v9; 
  unsigned int v10; 
  unsigned __int64 v11; 
  unsigned int *v12; 
  unsigned __int64 v13; 
  int v14; 
  __int64 v15; 
  INT64 result; 
  __int128 v17; 
  v4 = (unsigned int)a3;
  v5 = (_QWORD *)a4;
  v7 = a1;
  v17 = 0i64;
  if( (unsigned int)a1 <= 0xD )
  {
    v8 = 0;
    v9 = 16 * a1;
    if( 16 * (int)a1 <= (unsigned int)a3 )
    {
      v10 = 0;
      if( (_DWORD)a1 )
      {
        v11 = v9;
        v12 = (unsigned int *)(a2 + 8);
        while( 1 )
        {
          v13 = *((_QWORD *)v12 - 1);
          if( v13 < v11 )
            break;
          if( v13 >= v4 )
            break;
          v14 = v12[1];
          if( v14 == -2147479552 )
            break;
          if( v14 == -2147483136 )
            break;
          if( v14 == -2147482624 )
            break;
          if( v14 == -2147483392 )
            break;
          if( v14 == 0x80000000 )
            break;
          if( v14 == -2147483646 )
            break;
          v15 = *v12;
          if( (unsigned int)v15 > 0x400 || v13 + v15 > v4 )
            break;
          v8 += v15;
          if( v14 == -2147483644 )
          {
            v5[10] = a2 + 16i64 * v10;
          }
          else
          {
            *((_QWORD *)&v17 + 1) = __PAIR64__(v14, v15);
            *(_QWORD *)&v17 = v13 + a2;
            result = EtwpAllocateFilter(v14, &v17, v5, 0i64);
            if( (int)result < 0 )
              return result;
            v5 = (_QWORD *)a4;
          }
          ++v10;
          v11 = v9;
          v12 += 4;
          if( v10 >= v7 )
            goto LABEL_20;
        }
      }
      else
      {
LABEL_20:
        if( v9 + v8 <= (unsigned int)v4 )
          return 0i64;
      }
    }
  }
  return 3221225485i64;
}

Referenced by:

EtwpNotifyGuid