EtwpGetGuidSecurityDescriptor

INT64 __fastcall EtwpGetGuidSecurityDescriptor(_UNICODE_STRING *GuidName, VOID **SecurityDescriptor){
  void *ValueData; 
  UINT64 v3; 
  NTSTATUS v6; 
  int v7; 
  VOID *PoolWithTag; 
  ULONG Length; 
  ULONG ValueType; 
  ValueData = 0i64;
  v3 = 512i64;
  ValueType = 0;
  *SecurityDescriptor = 0i64;
  for( Length = 512; ; v3 = Length )
  {
    if( ValueData )
      ExFreePoolWithTag(ValueData, 0);
    ValueData = ExAllocatePoolWithTag(PagedPool, (unsigned int)v3, 0x50777445ui64);
    if( !ValueData )
      break;
    v6 = RtlQueryRegistryValueWithFallback(
           EtwpMutableSecurityKeyHandle,
           EtwpSecurityKeyHandle,
           GuidName,
           v3,
           &ValueType,
           ValueData,
           &Length);
    v7 = v6;
    if( v6 != -2147483643 && v6 != -1073741789 )
    {
      v3 = Length;
      goto LABEL_8;
    }
  }
  v7 = -1073741670;
LABEL_8:
  if( v7 >= 0 && ValueType == 3 )
  {
    if( SeValidSecurityDescriptor((unsigned int)v3, ValueData) )
    {
      PoolWithTag = ExAllocatePoolWithTag(PagedPool, v3, 0x50777445ui64);
      *SecurityDescriptor = PoolWithTag;
      if( PoolWithTag )
        memmove((UINT8 *)PoolWithTag, (UINT8 *)ValueData, v3);
      else
        v7 = -1073741670;
    }
    else
    {
      v7 = -1073741703;
    }
  }
  if( ValueData )
    ExFreePoolWithTag(ValueData, 0);
  return(unsigned int)v7;
}

Referenced by:

EtwpGetSecurityDescriptorByGuid
EtwpInitializeSecurity