MiAgeWorkingSetTail
NTSTATUS __stdcall MiAgeWorkingSetTail(INT64 a1){
__int64 v1;
int i;
__int64 v4;
UINT64 v5;
_DWORD *v6;
char v8;
unsigned __int64 v9;
_KTBFLUSH_TYPE v10;
_EPROCESS *Process;
_KTBFLUSH_TARGET v12;
v1 = *(_QWORD *)(a1 + 168);
for( i = 0; ; i = 1 )
{
v4 = *(_QWORD *)(v1 + 56);
if( !v4 )
goto LABEL_4;
v5 = *(unsigned int *)(v4 + 12);
if( !(_DWORD)v5 )
goto LABEL_4;
v8 = *(_BYTE *)(v4 + 4);
v9 = *(&stru_140C4DB30 + 52);
if( (v8 & 2) == 0 )
{
v10 = *(_DWORD *)v4;
if( *(_DWORD *)v4 != 1 )
goto LABEL_24;
Process = KeGetCurrentThread()->ApcState.Process;
if( Process->VmContext || *(_QWORD *)&Process->Pcb.SecureState )
v9 = -1i64;
}
v10 = *(_DWORD *)v4;
if( *(_DWORD *)v4 != 1 )
{
LABEL_24:
v12 = FlushAllAwakeProcessors;
if( (v8 & 8) != 0 )
v12 = FlushAllProcessors;
goto LABEL_16;
}
v12 = FlushSubsetProcessors;
LABEL_16:
if( *(_BYTE *)(v4 + 5) || *(_QWORD *)(v4 + 16) > v9 )
{
if( (v8 & 1) != 0 )
KeFlushCurrentTbOnly(v10);
else
KeFlushTb(v10, v12);
*(_BYTE *)(v4 + 5) = 0;
}
else if( (v8 & 1) != 0 )
{
KeFlushMultipleRangeCurrentTb(v5, (_KTB_FLUSH_VA *)(v4 + 24), v10);
}
else
{
KeFlushMultipleRangeTb(v5, (_KTB_FLUSH_VA *)(v4 + 24), v10, v12);
}
*(_BYTE *)(v4 + 4) &= ~8u;
*(_DWORD *)(v4 + 12) = 0;
*(_QWORD *)(v4 + 16) = 0i64;
LABEL_4:
if( *(_DWORD *)(v1 + 76) )
MiFreeWsleList(*(_MMSUPPORT_INSTANCE **)(a1 + 24), (_MMWSLE_FLUSH_LIST *)(v1 + 64), 0i64);
v6 = *(_DWORD **)(v1 + 248);
if( !v6 || !*v6 || !MiQueryEPTAccessedState(a1, v6) )
break;
MiProcessVmAccessedInfo(
a1,
*(_DWORD **)(v1 + 248),
(__int64(__fastcall *)(__int64, _QWORD *, char *, unsigned __int64, __int64))MiAgeWorkingSetEPTCallback,
v1);
}
if( (*(_BYTE *)(a1 + 2) & 2) != 0 || i )
*(_BYTE *)(v1 + 6) = 1;
return 0;
}Referenced by:
MiAgePte