EtwpBuildMdlForTraceBuffer
__int64 __fastcall EtwpBuildMdlForTraceBuffer(__int64 a1, char *a2, struct _MDL **a3){
ULONG v3;
char *v4;
unsigned int v7;
_MDL *Mdl;
struct _MDL *v9;
__int64 v10;
_MDL *v11;
PHYSICAL_ADDRESS PhysicalAddress;
v3 = *(_DWORD *)a2;
v4 = a2;
v7 = 0;
Mdl = IoAllocateMdl(a2, *(_DWORD *)a2, 0, 0, 0i64);
v9 = Mdl;
if( Mdl )
{
if( (*(_DWORD *)(a1 + 832) & 0x20000000) != 0 )
{
v10 = v3 >> 12;
v11 = Mdl + 1;
if( (_DWORD)v10 )
{
do
{
PhysicalAddress = MmGetPhysicalAddress(v4);
v4 += 4096;
v11->Next = (_MDL *)((unsigned __int64)PhysicalAddress.QuadPart >> 12);
v11 = (_MDL *)((char *)v11 + 8);
--v10;
}
while( v10 );
}
}
else
{
MmBuildMdlForNonPagedPool(Mdl);
}
*a3 = v9;
}
else
{
return(unsigned int)-1073741670;
}
return v7;
}Referenced by:
EtwpPreserveLogger