StartTraceW custom system logger: SeSystemProfilePrivilege present but disabled
On Windows build 26200.9457 (DisplayVersion 25H2), consider an elevated Administrator caller whose token contains SeSystemProfilePrivilege, but that privilege is Disabled. This is a direct StartTraceW custom controller, not WPR; the controller does not call AdjustTokenPrivileges.
Selected configuration: a unique custom session name (not "NT Kernel Logger"), a newly generated session GUID (not SystemTraceControlGuid), and a file-backed system/kernel logger. EVENT_TRACE_PROPERTIES is initially zeroed, with:
- Allocation and Wnode.BufferSize: 4096 bytes; Wnode.Flags: 0x00020000 (WNODE_FLAG_TRACED_GUID); Wnode.ClientContext: 1.
- BufferSize: 64 KiB; MinimumBuffers: 16; MaximumBuffers: 64; MaximumFileSize: 256 MiB; FlushTimer: 1 second.
- LogFileMode: 0x02000002 = EVENT_TRACE_SYSTEM_LOGGER_MODE | EVENT_TRACE_FILE_MODE_CIRCULAR.
- EnableFlags: 0x06000817 = EVENT_TRACE_FLAG_PROCESS (0x1) | EVENT_TRACE_FLAG_THREAD (0x2) | EVENT_TRACE_FLAG_IMAGE_LOAD (0x4) | EVENT_TRACE_FLAG_CSWITCH (0x10) | EVENT_TRACE_FLAG_DISPATCHER (0x800) | EVENT_TRACE_FLAG_FILE_IO (0x02000000) | EVENT_TRACE_FLAG_FILE_IO_INIT (0x04000000).
- LoggerNameOffset: sizeof(EVENT_TRACE_PROPERTIES), 120 bytes in the selected layout; LogFileNameOffset: 1024; Unicode session name and output filename within the allocation. Other initial fields are zero.
For this exact configuration, must SeSystemProfilePrivilege already be ENABLED in the caller token before StartTraceW, or is PRESENT/assigned but currently Disabled sufficient? Does StartTraceW/the ETW subsystem enable it internally, or require/check its enabled state? Please identify the documented access-check behavior or an authoritative Microsoft reference, and any build-specific qualification.