EtwpSendReplyDataBlock
NTSTATUS __stdcall EtwpSendReplyDataBlock(_ETWP_NOTIFICATION_HEADER *DataBlock){
_ETHREAD *CurrentThread;
void *ReplyObject;
unsigned int ReplyIndex;
NTSTATUS v5;
struct _DMA_ADAPTER *v6;
_QWORD *v7;
__int64 v8;
PADAPTER_OBJECT DmaAdapter;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
ReplyObject = DataBlock->ReplyObject;
ReplyIndex = DataBlock->ReplyIndex;
--*((_WORD *)CurrentThread + 242);
DmaAdapter = 0i64;
v5 = ObReferenceObjectByHandle(ReplyObject, 4u, EtwpRegistrationObjectType, 1, (PVOID *)&DmaAdapter, 0i64);
if( v5 >= 0 )
{
v6 = DmaAdapter;
if( (DmaAdapter[6].Size & 2) != 0 )
{
if( ReplyIndex >= 4 )
{
v5 = -1073741811;
}
else
{
v7 = (_QWORD *)_InterlockedExchange64((volatile __int64 *)&DmaAdapter[3] + ReplyIndex, 0i64);
if( v7 )
{
v8 = v7[4];
if( (*(_BYTE *)(v8 + 98) & 0x40) != 0 )
v5 = -1073741055;
else
v5 = EtwpQueueReply(*(_ETW_REPLY_QUEUE **)(v8 + 48), DataBlock);
EtwpReleaseQueueEntry(v7, 2);
}
else
{
v5 = -1073741811;
}
v6 = DmaAdapter;
}
}
else
{
v5 = -1073741816;
}
HalPutDmaAdapter(v6);
}
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return v5;
}Referenced by:
NtTraceControl