EtwpValidatePayloadFilter

INT64 __fastcall EtwpValidatePayloadFilter(
        const _GUID *ProviderGuid,
        _AGGREGATED_PAYLOAD_FILTER *PayloadFilter,
        UINT64 Size){
  __int16 v5; 
  int PredicateCount; 
  __int64 EachEventTableOffset; 
  int v8; 
  int v9; 
  unsigned __int64 EachEventTableLength; 
  __int64 PayloadDecoderTableOffset; 
  int v12; 
  unsigned int PayloadDecoderTableLength; 
  __int64 EventFilterTableOffset; 
  int v15; 
  unsigned int EventFilterTableLength; 
  int UNICODEStringTableOffset; 
  int v18; 
  unsigned int UNICODEStringTableLength; 
  int v20; 
  unsigned int v21; 
  int v22; 
  char *v23; 
  _WORD *v24; 
  char *v25; 
  unsigned int v26; 
  unsigned int v27; 
  _EVENT_PAYLOAD_PREDICATE *PredicateTable; 
  int v29; 
  __int64 v30; 
  unsigned int v31; 
  char *v32; 
  unsigned int v33; 
  unsigned int v34; 
  unsigned int v35; 
  unsigned int v36; 
  unsigned int v37; 
  __int64 FieldIndex; 
  int v39; 
  char *v40; 
  int v41; 
  char *v42; 
  char *v43; 
  __int64 v44; 
  char *v45; 
  int v46; 
  char *v47; 
  char *v48; 
  int v49; 
  int v51; 
  int v52; 
  int v53; 
  char *v54; 
  int ANSIStringTableLength; 
  char *v56; 
  char *v57; 
  unsigned int v58; 
  unsigned int v59; 
  _WORD *v60; 
  char *v61; 
  __int64 ANSIStringTableOffset; 
  __int64 v63; 
  int v64; 
  int v65; 
  if( (unsigned int)Size >= 0x50 && PayloadFilter->Size == (_DWORD)Size && (unsigned int)Size <= 0x1000 )
  {
    v5 = *(_WORD *)PayloadFilter;
    if( (v5 & 0xFFF) == 2662 && (v5 & 0xF000) == 4096 )
    {
      PredicateCount = PayloadFilter->PredicateCount;
      if( (unsigned __int16)PredicateCount <= 0xAAu
        && !PayloadFilter->Reserved
        && *(_QWORD *)&ProviderGuid->Data1 == *(_QWORD *)&PayloadFilter->ProviderGuid.Data1
        && *(_QWORD *)ProviderGuid->Data4 == *(_QWORD *)PayloadFilter->ProviderGuid.Data4 )
      {
        EachEventTableOffset = PayloadFilter->EachEventTableOffset;
        v8 = 24 * PredicateCount + 56;
        v9 = PayloadFilter->PredicateCount;
        if( (_DWORD)EachEventTableOffset == v8 )
        {
          EachEventTableLength = PayloadFilter->EachEventTableLength;
          PayloadDecoderTableOffset = PayloadFilter->PayloadDecoderTableOffset;
          v12 = EachEventTableLength + v8;
          if( (_DWORD)PayloadDecoderTableOffset == v12 )
          {
            PayloadDecoderTableLength = PayloadFilter->PayloadDecoderTableLength;
            EventFilterTableOffset = PayloadFilter->EventFilterTableOffset;
            v15 = PayloadDecoderTableLength + v12;
            if( (_DWORD)EventFilterTableOffset == v15 )
            {
              EventFilterTableLength = PayloadFilter->EventFilterTableLength;
              UNICODEStringTableOffset = PayloadFilter->UNICODEStringTableOffset;
              v18 = EventFilterTableLength + v15;
              if( UNICODEStringTableOffset == v18 )
              {
                UNICODEStringTableLength = PayloadFilter->UNICODEStringTableLength;
                v20 = UNICODEStringTableLength + v18;
                if( PayloadFilter->ANSIStringTableOffset == v20 )
                {
                  ANSIStringTableLength = PayloadFilter->ANSIStringTableLength;
                  if( (_DWORD)Size == ANSIStringTableLength + v20
                    && EachEventTableLength == 12 * (EachEventTableLength / 0xC)
                    && (PayloadDecoderTableLength & 3) == 0
                    && (EventFilterTableLength & 3) == 0
                    && (UNICODEStringTableLength & 1) == 0
                    && (EachEventTableOffset & 3) == 0
                    && (PayloadDecoderTableOffset & 3) == 0
                    && (EventFilterTableOffset & 3) == 0
                    && (UNICODEStringTableOffset & 3) == 0 )
                  {
                    v21 = PayloadDecoderTableLength >> 2;
                    v22 = 0;
                    v52 = 0;
                    v23 = (char *)PayloadFilter + PayloadDecoderTableOffset;
                    v51 = 0;
                    v24 = (_WORD *)((char *)PayloadFilter + EventFilterTableOffset);
                    v64 = 0;
                    v25 = (char *)PayloadFilter + EachEventTableOffset;
                    v65 = 0;
                    v26 = EventFilterTableLength >> 2;
                    v27 = UNICODEStringTableLength >> 1;
                    PredicateTable = PayloadFilter->PredicateTable;
                    v58 = (unsigned int)EachEventTableLength / 0xC;
                    v56 = (char *)PayloadFilter + PayloadFilter->UNICODEStringTableOffset;
                    ANSIStringTableOffset = PayloadFilter->ANSIStringTableOffset;
                    v29 = 0;
                    v59 = v27;
                    v57 = (char *)PayloadFilter + ANSIStringTableOffset;
                    v61 = v23;
                    v30 = 0i64;
                    v60 = v24;
                    v53 = 0;
                    if( (unsigned int)EachEventTableLength / 0xC )
                    {
                      while( 1 )
                      {
                        v63 = v30 | (1i64 << (*(_WORD *)v25 % 0x3Fu));
                        if( *((unsigned __int16 *)v25 + 2) != v29 )
                          break;
                        v31 = *((unsigned __int16 *)v25 + 3);
                        if( v31 > v21 - v29 )
                          break;
                        v29 += v31;
                        v32 = v23;
                        v33 = 0;
                        v54 = v23;
                        if( *((_WORD *)v25 + 3) )
                        {
                          while( *((_WORD *)v23 + 1) < 0x40u
                               && (unsigned __int8)v23[1] < 0x40u
                               && (unsigned __int8)*v23 < 0x40u
                               && (*v23 & 0xFu) < 9 )
                          {
                            v23 += 4;
                            ++v33;
                            v61 = v23;
                            if( v33 >= v31 )
                              goto LABEL_33;
                          }
                          return 3221225485i64;
                        }
LABEL_33:
                        if( *((unsigned __int16 *)v25 + 4) != v51 )
                          break;
                        v34 = *((unsigned __int16 *)v25 + 5);
                        if( v34 > v26 - v51 )
                          break;
                        v22 = v34 + v51;
                        v51 += v34;
                        v35 = 0;
                        if( *((_WORD *)v25 + 5) )
                        {
                          while( (*v24 & 0xFCu) <= 0x20 )
                          {
                            if( (unsigned __int16)v24[1] != v52 )
                              break;
                            v36 = (unsigned __int8)*v24 >> 2;
                            if( v36 > v9 - v52 )
                              break;
                            v52 += v36;
                            v37 = 0;
                            if( v36 )
                            {
                              while( 1 )
                              {
                                FieldIndex = PredicateTable->FieldIndex;
                                if( (unsigned int)FieldIndex >= v21
                                  || (unsigned __int16)FieldIndex >= (unsigned __int16)v31
                                  || (unsigned __int16)FieldIndex > (unsigned __int8)v25[3] )
                                {
                                  return 3221225485i64;
                                }
                                v39 = (v32[4 * FieldIndex] & 0xF) - 3;
                                if( !v39 )
                                  break;
                                if( v39 == 1 )
                                {
                                  if( PredicateTable->Value[0] != v64 || PredicateTable->Value[1] )
                                    return 3221225485i64;
                                  v40 = v56;
                                  v41 = v64;
                                  v42 = (char *)PayloadFilter
                                      + PayloadFilter->UNICODEStringTableOffset
                                      + (unsigned __int64)PayloadFilter->UNICODEStringTableLength;
                                  v9 = PayloadFilter->PredicateCount;
                                  if( *(_WORD *)v56 )
                                  {
                                    do
                                    {
                                      if( v40 >= v42 - 2 )
                                        break;
                                      v40 += 2;
                                    }
                                    while( *(_WORD *)v40 );
                                    v9 = PayloadFilter->PredicateCount;
                                    v41 = v64;
                                  }
                                  v43 = v40 + 2;
                                  if( v43 > v42 )
                                    return 3221225485i64;
                                  v44 = (v43 - v56) >> 1;
                                  v56 = v43;
                                  v64 = v44 + v41;
LABEL_61:
                                  v32 = v54;
                                }
                                ++v37;
                                ++PredicateTable;
                                if( v37 >= v36 )
                                  goto LABEL_63;
                              }
                              if( PredicateTable->Value[0] != v65 || PredicateTable->Value[1] )
                                return 3221225485i64;
                              v45 = v57;
                              v46 = v65;
                              v47 = (char *)PayloadFilter
                                  + ANSIStringTableOffset
                                  + (unsigned __int16)ANSIStringTableLength;
                              if( *v57 )
                              {
                                do
                                {
                                  if( v45 >= v47 - 1 )
                                    break;
                                  ++v45;
                                }
                                while( *v45 );
                                v46 = v65;
                              }
                              v48 = v45 + 1;
                              if( v48 > v47 )
                                return 3221225485i64;
                              v49 = (_DWORD)v48 - (_DWORD)v57;
                              v57 = v48;
                              v65 = v49 + v46;
                              goto LABEL_61;
                            }
LABEL_63:
                            ++v35;
                            v24 = v60 + 2;
                            v60 += 2;
                            if( v35 >= v34 )
                            {
                              v23 = v61;
                              v22 = v51;
                              goto LABEL_65;
                            }
                          }
                          return 3221225485i64;
                        }
LABEL_65:
                        v25 += 12;
                        v30 = v63;
                        if( ++v53 >= v58 )
                        {
                          v27 = v59;
                          goto LABEL_67;
                        }
                      }
                    }
                    else
                    {
LABEL_67:
                      if( v30 == PayloadFilter->HashedEventIdBitmap
                        && v52 == v9
                        && v29 == v21
                        && v22 == v26
                        && v64 == v27
                        && v65 == ANSIStringTableLength )
                      {
                        return 0i64;
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
  return 3221225485i64;
}

Referenced by:

EtwpAllocatePayloadFilterData