EtwpAllocateTraceBuffer

CHAR *__fastcall EtwpAllocateTraceBuffer(INT64 a1, UINT64 a2){
  unsigned __int64 v3; 
  VOID **v4; 
  CHAR *v6; 
  PMDL PagesForMdl; 
  ULONG Flags; 
  v3 = (unsigned int)a2;
  v4 = (VOID **)(a1 + 1304);
  if( *v4 )
    return(CHAR *)EtwpAllocatePartitionMemory(v4, (unsigned int)a2);
  if( (*(_DWORD *)(a1 + 832) & 0x20000000) == 0 )
    return(CHAR *)ExAllocatePoolWithTag((_POOL_TYPE)*(_DWORD *)(a1 + 316), (unsigned int)a2, 0x42777445ui64);
  Flags = 101;
  v6 = 0i64;
  PagesForMdl = MmAllocatePagesForMdlEx(0i64, MmNotMapped, 0x200000u);
  if( PagesForMdl || (Flags = 37, (PagesForMdl = MmAllocatePagesForMdlEx(0i64, MmNotMapped, 0x200000u)) != 0i64) )
  {
    qsort((WCHAR *)&PagesForMdl[1], v3 >> 12, (const WCHAR *)8, EtwpComparePfn, 1, Flags);
    v6 = (CHAR *)MmMapLockedPagesSpecifyCache(PagesForMdl, 0, MmCached, 0i64, 0, 0x40000020u);
    if( v6 )
    {
      if( !*(_QWORD *)(a1 + 1312) )
      {
        *(_QWORD *)(a1 + 1312) = PagesForMdl;
        PagesForMdl = 0i64;
      }
    }
    else
    {
      MiFreePagesFromMdl(PagesForMdl, 0i64);
    }
    if( PagesForMdl )
      ExFreePoolWithTag(PagesForMdl, 0);
  }
  return v6;
}

Referenced by:

EtwpAllocateFreeBuffers
EtwpPreserveLogger