ExSaAllocate

NTSTATUS __stdcall ExSaAllocate(UINT64 Flags){
  unsigned int v1; 
  __int64 v2; 
  UINT64 v3; 
  NTSTATUS v4; 
  _ETHREAD *CurrentThread; 
  v2 = (unsigned int)Flags;
  if( (v1 & 0xFFFFFFFE) != 0 )
    KeBugCheckEx(0x16Du, v1, 0i64, 0i64, 0i64);
  v3 = ExSaNonPagedSlotAllocator;
  if( (v1 & 1) != 0 )
    v3 = ExSaPagedSlotAllocator;
  v4 = -1;
  if( v3 && (unsigned int)v2 <= 0x1000 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 243);
    v4 = ExpSaAllocatorAllocate(v3, (unsigned __int64)(v2 + 7) >> 3);
    KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
  }
  return v4;
}

Referenced by:

EtwpCovSampCaptureContextStart
ExpAllocateFannedOutPushLock