EtwpCheckGuidAccessAndDoRundown

INT64 __fastcall EtwpCheckGuidAccessAndDoRundown(
        _ETW_SILODRIVERSTATE *SiloState,
        const _GUID *Guid,
        UINT64 TargetLoggerId,
        _EVENT_FILTER_DESCRIPTOR *FilterDescriptor,
        UINT8 Start){
  unsigned int v5; 
  char v7; 
  INT64 result; 
  unsigned int v9; 
  int v10; 
  UINT64 v11; 
  unsigned int v12; 
  _DWORD *v13; 
  unsigned int v14; 
  UINT64 **a5; 
  UINT64 a6; 
  UINT8 dst[16]; 
  __int128 v18; 
  unsigned int v19; 
  v5 = TargetLoggerId;
  *(_OWORD *)dst = 0i64;
  v7 = (char)FilterDescriptor;
  v18 = 0i64;
  result = EtwpCheckGuidAccess(&SystemTraceControlGuid, 0x80ui64, 0i64);
  v9 = result;
  if( (int)result >= 0 )
  {
    v10 = *(_DWORD *)(Start + 12i64);
    if( v10 == -2147483647 )
    {
      v11 = *(unsigned int *)(Start + 8i64);
      if( (unsigned int)v11 <= 0x20 && (v11 & 3) == 0 )
      {
        v12 = 1;
        if( v19 > 1 )
        {
          v13 = (_DWORD *)(Start + 24i64);
          while( v13[1] != -2147483644 || (*v13 & 3) == 0 )
          {
            ++v12;
            v13 += 4;
            if( v12 >= v19 )
              goto LABEL_10;
          }
          return 3221225485i64;
        }
LABEL_10:
        memmove(dst, *(UINT8 **)Start, v11);
        v14 = v19 - 1;
        a5 = (UINT64 **)(Start + 16i64);
        if( v19 <= 1 )
          v14 = 0;
        LODWORD(a6) = v14;
        if( v19 <= 1 )
          a5 = 0i64;
        EtwpLogKernelTraceRundown((UINT64)SiloState, (PVOID)v5, (__int128 *)dst, v7, a5, a6);
        return v9;
      }
      return 3221225485i64;
    }
    if( v10 == -2147483646 )
    {
      if( *(_DWORD *)(Start + 8i64) != 8 )
        return 3221225485i64;
      return(unsigned int)EtwpCheckLoggerAccessAndDoRundown(SiloState, **(unsigned __int16 **)Start, v5, v7);
    }
    else
    {
      return(unsigned int)-1073741811;
    }
  }
  return result;
}

Referenced by:

EtwpEnableDisableSpecialGuids