EtwpDemuxPrivateTraceHandle

INT64 __fastcall EtwpDemuxPrivateTraceHandle(INT64 a1, UINT16 a2, UINT16 *a3){
  int v5; 
  __int64 v7; 
  _ETHREAD *CurrentThread; 
  UINT64 v9; 
  __int64 v10; 
  INT64 v11; 
  unsigned int v12; 
  int v13; 
  int v14; 
  INT64 v15; 
  __int64 **v16; 
  __int64 *i; 
  UINT64 v18; 
  v5 = a1;
  if( a2 >= 0x40u )
  {
    v7 = PsGetCurrentServerSiloGlobals()[108];
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 242);
    v9 = v7 + 4096;
    ExAcquirePushLockExclusiveEx(v7 + 4096, 0i64);
    v10 = v7 + 4080;
    LODWORD(v18) = v5;
    v11 = *(_QWORD *)(v7 + 4080);
    v12 = 0;
    if( (*(_BYTE *)(v10 + 8) & 1) != 0 )
    {
      if( v11 )
        v11 ^= v10;
      else
        v11 = 0i64;
    }
    v13 = *(_BYTE *)(v10 + 8) & 1;
    if( v11 )
    {
      do
      {
        v14 = PidNodeCompare(&v18, v11);
        if( v14 >= 0 )
        {
          if( v14 <= 0 )
            break;
          v15 = *(_QWORD *)(v11 + 8);
        }
        else
        {
          v15 = *(_QWORD *)v11;
        }
        if( v13 && v15 )
          v11 ^= v15;
        else
          v11 = v15;
      }
      while( v11 );
      if( v11 )
      {
        v16 = (__int64 **)(v11 + 32);
        for( i = *v16; i != (__int64 *)v16; i = (__int64 *)*i )
        {
          if( *((_WORD *)i + 9) == a2 )
          {
            *a3 = *((_WORD *)i + 8);
            goto LABEL_23;
          }
        }
      }
    }
    v12 = -1073741162;
LABEL_23:
    ExReleasePushLockEx(v9, 0i64);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    return v12;
  }
  else
  {
    *a3 = a2;
    return 0i64;
  }
}

Referenced by:

EtwpEnableGuid
EtwpNotifyGuid