MmGetCacheAttributeEx
__int64 __fastcall MmGetCacheAttributeEx(unsigned __int64 a1, int a2, _DWORD *a3){
unsigned __int64 v5;
int v6;
_RTL_BALANCED_NODE *v7;
if( (a2 & 0xFFFFFFFE) != 0 )
return 3221225712i64;
v5 = a1 >> 12;
if( a1 >> 12 <= 0xFFFFFFFFFi64 && (((unsigned __int64)MmGetPfnDb()[v5].u4._bf_0 >> 50) & 1) != 0 )
{
if( !MmGetPfnDb()[v5].u3.ReferenceCount && (struct _KTHREAD *)*(&stru_140C4DB30 + 291) != KeGetCurrentThread() )
KeBugCheckEx(0x1Au, (PVOID)0x1232, (PVOID)v5, (PVOID)(*(_BYTE *)(&MmGetPfnDb()[v5].u3 + 1) & 7), 0i64);
v6 = *((unsigned __int8 *)&MmGetPfnDb()[v5].u3 + 2) >> 6;
}
else
{
if( (a2 & 1) == 0 )
return 3221225793i64;
v7 = MiLookupIoPageNode(v5);
if( v7 )
v6 = *((unsigned __int16 *)v7[2].Children[0]->Children + (v5 & 0xFFFFFFFFFi64) - v7[1].ParentValue) >> 14;
else
v6 = 3;
}
switch( v6 )
{
case 1:
*a3 = 1;
return 0i64;
case 0:
*a3 = 0;
return 0i64;
case 2:
*a3 = 2;
return 0i64;
}
return 3221225711i64;
}Referenced by:
MmGetCacheAttribute