EtwpReserveWithPmcCounters
INT64 __fastcall EtwpReserveWithPmcCounters(INT64 a1, INT16 a2, INT64 a3, INT64 a4, INT64 *a5, INT16 a6){
int v6;
unsigned int v7;
unsigned int v8;
unsigned __int8 CurrentIrql;
INT64 v10;
INT64 v11;
__int64 v13;
__int64 v14;
v14 = *(_QWORD *)(a1 + 1000);
v6 = (unsigned __int8)*(_DWORD *)(v14 + 20);
v7 = 8 * v6 + 16;
v8 = v7 + a3;
CurrentIrql = KeGetCurrentIrql();
if( CurrentIrql < 2u )
{
KeGetCurrentIrql();
__writecr8(2ui64);
}
v10 = EtwpReserveTraceBuffer((UINT64 *)a1, v8, a4, a5, a6);
v11 = v10;
if( v10 )
{
*(_QWORD *)(v10 + 8) = *a5;
*(_WORD *)(v10 + 4) = v8;
*(_WORD *)(v10 + 6) = a2;
*(_DWORD *)v10 = (unsigned __int8)a6 | (v6 << 8) | 0xC0110000;
v13 = *(_QWORD *)(v14 + 8i64 * *((unsigned int *)KeGetPcr() + 105) + 24);
if( v13 )
((void(__fastcall *)(__int64, INT64))off_140C007D8[0])(v13, v10 + 16);
else
memset(v10 + 16, 0i64);
if( CurrentIrql < 2u )
__writecr8(CurrentIrql);
return v11 + v7;
}
else
{
if( CurrentIrql < 2u )
__writecr8(CurrentIrql);
return 0i64;
}
}Referenced by:
EtwpLogContextSwapEvent
EtwpLogKernelEvent