EtwpSetSoftRestartInformation

NTSTATUS __fastcall EtwpSetSoftRestartInformation(INT64 a1, UINT64 a2){
  unsigned int v2; 
  WCHAR v4; 
  NTSTATUS result; 
  UINT64 v6; 
  _ETHREAD *CurrentThread; 
  _WMI_LOGGER_CONTEXT *v8; 
  INT64 v9; 
  NTSTATUS v10; 
  _UNICODE_STRING *PoolWithTag; 
  char v12; 
  struct _UNICODE_STRING DestinationString; 
  _UNICODE_STRING UserString; 
  v2 = a2;
  DestinationString = 0i64;
  UserString = 0i64;
  if( !EtwpKsrCallbackObject || PsIsCurrentThreadInServerSilo() )
    return -1073741637;
  if( v2 < 0x18 )
    return -1073741811;
  RtlInitUnicodeString(&DestinationString, 0i64, v4);
  UserString.Buffer = (wchar_t *)(a1 + 18);
  UserString.Length = v2 - 18;
  UserString.MaximumLength = v2 - 18;
  if( (_WORD)v2 == 18 || (result = EtwpCaptureString(&UserString, &DestinationString), result >= 0) )
  {
    v12 = *(_BYTE *)(a1 + 16);
    v6 = (unsigned __int16)*(_QWORD *)(a1 + 8);
    if( (_DWORD)v6 == 0xFFFF )
      v6 = *(unsigned __int8 *)(EtwpHostSiloState + 4208);
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 242);
    v8 = EtwpAcquireLoggerContextByLoggerId((_ETW_SILODRIVERSTATE *)EtwpHostSiloState, v6, 1u);
    v9 = (INT64)v8;
    if( !v8 )
    {
      v10 = -1073741162;
      goto LABEL_32;
    }
    v10 = EtwpCheckLoggerControlAccess(0x80ui64, v8);
    if( v10 >= 0 )
    {
      PoolWithTag = *(_UNICODE_STRING **)(v9 + 1072);
      if( !v12 )
      {
        if( PoolWithTag && LOBYTE(PoolWithTag[2].Length) )
        {
          EtwpCancelMemoryPreservation((_WMI_LOGGER_CONTEXT *)v9);
          RtlFreeAnsiString(PoolWithTag + 1);
          LOBYTE(PoolWithTag[2].Length) = 0;
          v10 = 0;
        }
        else
        {
          v10 = -1073741054;
        }
        goto LABEL_32;
      }
      if( !PoolWithTag )
      {
        PoolWithTag = (_UNICODE_STRING *)ExAllocatePoolWithTag(PagedPool, 0x28ui64, 0x4B777445ui64);
        if( !PoolWithTag )
        {
          v10 = -1073741801;
          goto LABEL_32;
        }
        *PoolWithTag = 0i64;
        PoolWithTag[1] = 0i64;
        *(_QWORD *)&PoolWithTag[2].Length = 0i64;
        *(_QWORD *)(v9 + 1072) = PoolWithTag;
      }
      if( LOBYTE(PoolWithTag[2].Length) )
      {
        v10 = -1073741053;
      }
      else if( DestinationString.Length )
      {
        if( (*(_DWORD *)(v9 + 12) & 0x400) == 0 || *(_DWORD *)(v9 + 316) == 1 || (*(_DWORD *)(v9 + 4) & 0xFFF) != 0 )
        {
          v10 = -1073741637;
        }
        else
        {
          PoolWithTag[1] = DestinationString;
          DestinationString.Buffer = 0i64;
          LOBYTE(PoolWithTag[2].Length) = 1;
          v10 = 0;
          if( EtwpKsrPrepared )
          {
            v10 = EtwpPreserveLogger(v9);
            if( v10 < 0 )
            {
              LOBYTE(PoolWithTag[2].Length) = 0;
              RtlFreeAnsiString(PoolWithTag + 1);
            }
          }
        }
      }
      else
      {
        v10 = -1073741672;
      }
    }
LABEL_32:
    if( v9 )
      EtwpReleaseLoggerContext((unsigned int *)v9, 1);
    RtlFreeAnsiString(&DestinationString);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    return v10;
  }
  return result;
}

Referenced by:

EtwSetPerformanceTraceInformation