PfGetCompletedTrace
VOID __fastcall PfGetCompletedTrace(VOID *ElEntry){
unsigned int v1;
char v2;
unsigned int *v3;
__int64 v4;
unsigned int v5;
int v6;
BOOL v7;
int v8;
int *v9;
__int64 *v10;
__int64 v11;
__int64 v12;
unsigned int Length;
char v15;
unsigned int *v16;
v16 = v3;
v15 = v2;
Length = v1;
v4 = 0i64;
v5 = 0;
v6 = 1;
while( 1 )
{
ExAcquireFastMutex(&FastMutex);
if( !dword_140C4FB28 )
break;
dword_140C4FB28 = 0;
KeReleaseGuardedMutex(&FastMutex);
PfFbBufferListFlushStandby();
}
v7 = dword_140C4FB18 < (unsigned int)dword_140C4FB1C;
v8 = 0;
while( 1 )
{
v9 = &dword_140C4FB20;
if( v8 )
v9 = &dword_140C4FB18;
v10 = qword_140C4FB08;
if( v8 )
v10 = qword_140C4FAF8;
v11 = *v10;
if( (__int64 *)*v10 != v10 )
break;
if( (unsigned int)++v8 >= 2 )
goto LABEL_15;
}
v4 = *v10;
v5 = *(_DWORD *)(v11 + 24) + 16;
if( v5 > Length )
{
*v16 = v5;
goto LABEL_20;
}
v12 = *(_QWORD *)v11;
if( *(__int64 **)(v11 + 8) != v10 || *(_QWORD *)(v12 + 8) != v11 )
__fastfail(3u);
*v10 = v12;
*(_QWORD *)(v12 + 8) = v10;
--*v9;
LABEL_15:
if( !v7 && dword_140C4FB18 < (unsigned int)dword_140C4FB1C )
{
PfTAccessTracingStart((__int64)&PfTGlobals, (__int64)&PfKernelGlobals, 2);
KeSetEvent(&Event, 0);
}
KeReleaseGuardedMutex(&FastMutex);
v6 = 0;
if( v4 )
{
if( v15 )
ProbeForWrite(ElEntry, Length, 8ui64);
*(_OWORD *)ElEntry = 0i64;
*(_DWORD *)ElEntry = 1048577;
*((_QWORD *)ElEntry + 1) = ((KUSER_SHARED_DATA.TickCountMultiplier * HIDWORD(qword_140C50128)) << 8)
+ ((KUSER_SHARED_DATA.TickCountMultiplier * (unsigned __int64)(unsigned int)qword_140C50128) >> 24);
memmove((UINT8 *)ElEntry + 16, (UINT8 *)(v4 + 16), *(unsigned int *)(v4 + 24));
*v16 = v5;
PfTFreeTraceDump((_DWORD *)v4);
}
LABEL_20:
if( v6 )
KeReleaseGuardedMutex(&FastMutex);
}Referenced by:
PfQuerySuperfetchInformation