ExSaAllocate
NTSTATUS __stdcall ExSaAllocate(UINT64 Flags){
unsigned int v1;
__int64 v2;
UINT64 v3;
NTSTATUS v4;
_ETHREAD *CurrentThread;
v2 = (unsigned int)Flags;
if( (v1 & 0xFFFFFFFE) != 0 )
KeBugCheckEx(0x16Du, v1, 0i64, 0i64, 0i64);
v3 = ExSaNonPagedSlotAllocator;
if( (v1 & 1) != 0 )
v3 = ExSaPagedSlotAllocator;
v4 = -1;
if( v3 && (unsigned int)v2 <= 0x1000 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 243);
v4 = ExpSaAllocatorAllocate(v3, (unsigned __int64)(v2 + 7) >> 3);
KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
}
return v4;
}Referenced by:
EtwpCovSampCaptureContextStart
ExpAllocateFannedOutPushLock