EtwpCovSampHashMakeRoomAndAcquireLock
NTSTATUS __stdcall EtwpCovSampHashMakeRoomAndAcquireLock(PVOID BugCheckParameter2){
int v1;
CHAR **v2;
CHAR *Table;
_ETHREAD *CurrentThread;
CHAR **v5;
int v6;
unsigned int v8;
__int64 v9;
unsigned int v10;
unsigned int v11;
unsigned int v12;
unsigned int v13;
CHAR *v14;
_ETHREAD *v15;
__int64 *v16;
unsigned int v17;
__int64 *v18;
__int64 **v19;
PVOID *v20;
_QWORD *v21;
__int64 v22;
_QWORD *v23;
__int64 v25;
unsigned int v26;
PVOID *v27;
_ETHREAD *v28;
Table = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v5 = v2;
v6 = v1;
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx((_EX_PUSH_LOCK *)BugCheckParameter2, 0i64);
v8 = 0;
v9 = *((_QWORD *)BugCheckParameter2 + 144);
*((_QWORD *)BugCheckParameter2 + 1) = KeGetCurrentThread();
v10 = *(_DWORD *)(v9 + 20);
v11 = v6 + *(_DWORD *)(v9 + 16);
if( v11 >= (7 * v10) >> 3 )
{
while( 1 )
{
v12 = *((_DWORD *)BugCheckParameter2 + 10);
if( v10 < v12 )
{
v13 = 2 * v10;
if( !v10 )
v13 = *((_DWORD *)BugCheckParameter2 + 9);
while( (7 * v13) >> 3 < v11 )
v13 *= 2;
if( v13 >= v12 )
v13 = *((_DWORD *)BugCheckParameter2 + 10);
v12 = v13;
}
else if( *((_DWORD *)BugCheckParameter2 + 296) >= *((_DWORD *)BugCheckParameter2 + 11) )
{
goto LABEL_34;
}
*((_QWORD *)BugCheckParameter2 + 1) = 0i64;
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)BugCheckParameter2, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((_EX_PUSH_LOCK *)BugCheckParameter2);
KeAbPostRelease(BugCheckParameter2);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
if( Table )
EtwpCoverageSamplerFreeTable(Table);
Table = EtwpCoverageSamplerAllocateTable(v12);
v14 = Table;
if( !Table )
goto LABEL_36;
v15 = (_ETHREAD *)KeGetCurrentThread();
--v15->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx((_EX_PUSH_LOCK *)BugCheckParameter2, 0i64);
v16 = (__int64 *)*((_QWORD *)BugCheckParameter2 + 144);
*((_QWORD *)BugCheckParameter2 + 1) = KeGetCurrentThread();
v17 = *((_DWORD *)v16 + 5);
if( v6 + *((_DWORD *)v16 + 4) < (7 * v17) >> 3 )
goto LABEL_34;
if( v17 >= v12 )
break;
*((_QWORD *)BugCheckParameter2 + 144) = Table;
Table = (CHAR *)v16;
v18 = (__int64 *)*v16;
if( *(__int64 **)(*v16 + 8) != v16 )
goto LABEL_31;
v19 = (__int64 **)v16[1];
if( *v19 != v16 )
goto LABEL_31;
*v19 = v18;
v18[1] = (__int64)v19;
v20 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 147);
v21 = (_QWORD *)*((_QWORD *)BugCheckParameter2 + 144);
if( *v20 != (char *)BugCheckParameter2 + 1168 )
goto LABEL_31;
*v21 = (char *)BugCheckParameter2 + 1168;
v22 = 0i64;
v21[1] = v20;
*v20 = v21;
*((_QWORD *)BugCheckParameter2 + 147) = v21;
for( *(_DWORD *)(*((_QWORD *)BugCheckParameter2 + 144) + 16i64) = *((_DWORD *)v16 + 4);
(unsigned int)v22 < *((_DWORD *)v16 + 5);
v22 = (unsigned int)(v22 + 1) )
{
v23 = (_QWORD *)(v16[3] + 8 * v22);
if( *v23 )
{
EtwpCovSampHashLookupInTable();
MEMORY[0] = *v23;
if( (*((_DWORD *)v16 + 4))-- == 1 )
break;
}
}
if( v8 < 0x14 )
{
v25 = *((_QWORD *)BugCheckParameter2 + 144);
++v8;
v10 = *(_DWORD *)(v25 + 20);
v11 = v6 + *(_DWORD *)(v25 + 16);
if( v11 >= (7 * v10) >> 3 )
continue;
}
goto LABEL_34;
}
v26 = *((_DWORD *)BugCheckParameter2 + 296);
if( v26 >= *((_DWORD *)BugCheckParameter2 + 11) )
{
LABEL_34:
if( Table )
*v5 = Table;
goto LABEL_36;
}
*((_QWORD *)BugCheckParameter2 + 144) = Table;
Table = 0i64;
*((_DWORD *)BugCheckParameter2 + 296) = v26 + 1;
v27 = (PVOID *)*((_QWORD *)BugCheckParameter2 + 147);
if( *v27 != (char *)BugCheckParameter2 + 1168 )
LABEL_31:
__fastfail(3u);
*(_QWORD *)v14 = (char *)BugCheckParameter2 + 1168;
*((_QWORD *)v14 + 1) = v27;
*v27 = v14;
*((_QWORD *)BugCheckParameter2 + 147) = v14;
if( *((_DWORD *)BugCheckParameter2 + 296) == 2 )
{
KeSetEvent(*((PRKEVENT *)BugCheckParameter2 + 145), 0, 0);
goto LABEL_34;
}
}
LABEL_36:
if( *((struct _KTHREAD **)BugCheckParameter2 + 1) != KeGetCurrentThread() )
{
v28 = (_ETHREAD *)KeGetCurrentThread();
--v28->Tcb.KernelApcDisable;
ExAcquirePushLockExclusiveEx((_EX_PUSH_LOCK *)BugCheckParameter2, 0i64);
*((_QWORD *)BugCheckParameter2 + 1) = KeGetCurrentThread();
}
return *(_DWORD *)(*((_QWORD *)BugCheckParameter2 + 144) + 16i64) < (unsigned int)(7
* *(_DWORD *)(*((_QWORD *)BugCheckParameter2
+ 144)
+ 20i64)) >> 3 ? ((unsigned int)(7 * *(_DWORD *)(*((_QWORD *)BugCheckParameter2 + 144) + 20i64)) >> 3) - *(_DWORD *)(*((_QWORD *)BugCheckParameter2 + 144) + 16i64) : 0;
}Referenced by:
EtwpCovSampContextAddSamples