EtwpAllocateTraceBuffer
CHAR *__fastcall EtwpAllocateTraceBuffer(INT64 a1, UINT64 a2){
unsigned __int64 v3;
VOID **v4;
CHAR *v6;
PMDL PagesForMdl;
ULONG Flags;
v3 = (unsigned int)a2;
v4 = (VOID **)(a1 + 1304);
if( *v4 )
return(CHAR *)EtwpAllocatePartitionMemory(v4, (unsigned int)a2);
if( (*(_DWORD *)(a1 + 832) & 0x20000000) == 0 )
return(CHAR *)ExAllocatePoolWithTag((_POOL_TYPE)*(_DWORD *)(a1 + 316), (unsigned int)a2, 0x42777445ui64);
Flags = 101;
v6 = 0i64;
PagesForMdl = MmAllocatePagesForMdlEx(0i64, MmNotMapped, 0x200000u);
if( PagesForMdl || (Flags = 37, (PagesForMdl = MmAllocatePagesForMdlEx(0i64, MmNotMapped, 0x200000u)) != 0i64) )
{
qsort((WCHAR *)&PagesForMdl[1], v3 >> 12, (const WCHAR *)8, EtwpComparePfn, 1, Flags);
v6 = (CHAR *)MmMapLockedPagesSpecifyCache(PagesForMdl, 0, MmCached, 0i64, 0, 0x40000020u);
if( v6 )
{
if( !*(_QWORD *)(a1 + 1312) )
{
*(_QWORD *)(a1 + 1312) = PagesForMdl;
PagesForMdl = 0i64;
}
}
else
{
MiFreePagesFromMdl(PagesForMdl, 0i64);
}
if( PagesForMdl )
ExFreePoolWithTag(PagesForMdl, 0);
}
return v6;
}Referenced by:
EtwpAllocateFreeBuffers
EtwpPreserveLogger