EtwpValidateTraceControlFilterDescriptors
INT64 __fastcall EtwpValidateTraceControlFilterDescriptors(UINT64 a1, INT64 a2, UINT64 a3, INT64 a4){
unsigned __int64 v4;
_QWORD *v5;
unsigned int v7;
int v8;
unsigned int v9;
unsigned int v10;
unsigned __int64 v11;
unsigned int *v12;
unsigned __int64 v13;
int v14;
__int64 v15;
INT64 result;
__int128 v17;
v4 = (unsigned int)a3;
v5 = (_QWORD *)a4;
v7 = a1;
v17 = 0i64;
if( (unsigned int)a1 <= 0xD )
{
v8 = 0;
v9 = 16 * a1;
if( 16 * (int)a1 <= (unsigned int)a3 )
{
v10 = 0;
if( (_DWORD)a1 )
{
v11 = v9;
v12 = (unsigned int *)(a2 + 8);
while( 1 )
{
v13 = *((_QWORD *)v12 - 1);
if( v13 < v11 )
break;
if( v13 >= v4 )
break;
v14 = v12[1];
if( v14 == -2147479552 )
break;
if( v14 == -2147483136 )
break;
if( v14 == -2147482624 )
break;
if( v14 == -2147483392 )
break;
if( v14 == 0x80000000 )
break;
if( v14 == -2147483646 )
break;
v15 = *v12;
if( (unsigned int)v15 > 0x400 || v13 + v15 > v4 )
break;
v8 += v15;
if( v14 == -2147483644 )
{
v5[10] = a2 + 16i64 * v10;
}
else
{
*((_QWORD *)&v17 + 1) = __PAIR64__(v14, v15);
*(_QWORD *)&v17 = v13 + a2;
result = EtwpAllocateFilter(v14, &v17, v5, 0i64);
if( (int)result < 0 )
return result;
v5 = (_QWORD *)a4;
}
++v10;
v11 = v9;
v12 += 4;
if( v10 >= v7 )
goto LABEL_20;
}
}
else
{
LABEL_20:
if( v9 + v8 <= (unsigned int)v4 )
return 0i64;
}
}
}
return 3221225485i64;
}Referenced by:
EtwpNotifyGuid