CcPerformReadAhead

INT64 __fastcall CcPerformReadAhead(INT64 a1, FILE_OBJECT *a2){
  FILE_OBJECT *v2; 
  __int64 v3; 
  unsigned __int8 v4; 
  _LARGE_INTEGER v5; 
  unsigned int v6; 
  __int64 PrivateCacheMap; 
  _BOOL8 v8; 
  VOID *v9; 
  signed __int64 v10; 
  unsigned int v11; 
  unsigned int v12; 
  INT64 v13; 
  int v14; 
  _ETHREAD *v15; 
  int PagePriorityThread; 
  INT64 v17; 
  __int64 v18; 
  void *v19; 
  INT64 v20; 
  INT64 result; 
  ULONG_PTR BugCheckParameter4; 
  UINT64 PagePriority; 
  unsigned int v24; 
  UINT64 v25; 
  int v26; 
  int v27; 
  int v28; 
  struct _KLOCK_QUEUE_HANDLE LockHandle; 
  BOOL v31; 
  int v32; 
  unsigned int v33; 
  unsigned int v34; 
  UINT64 Length; 
  _LARGE_INTEGER SectionOffset; 
  PVOID P; 
  INT64 Partition; 
  __int64 v39; 
  INT64 SharedCacheMap; 
  unsigned int v41; 
  UINT64 FaultedData[2]; 
  int v43; 
  _FILE_OBJECT *FileObject; 
  __int64 v45; 
  __int64 v46; 
  LARGE_INTEGER FileOffset; 
  FILE_OBJECT *v48; 
  INT64 v49; 
  _ETHREAD *v50; 
  _ETHREAD *CurrentThread; 
  EVENT_DATA_DESCRIPTOR EventData; 
  EVENT_DATA_DESCRIPTOR v53; 
  _QWORD v54[2]; 
  unsigned int v55; 
  int v56; 
  __int64 v57; 
  _QWORD v58[2]; 
  unsigned int v59; 
  int v60; 
  __int64 v61; 
  v2 = a2;
  FileObject = a2;
  v49 = a1;
  v48 = a2;
  SharedCacheMap = 0i64;
  SectionOffset.QuadPart = 0i64;
  FileOffset.QuadPart = 0i64;
  LODWORD(Length) = 0;
  v24 = 0;
  v45 = 0i64;
  v46 = 0i64;
  v31 = 0;
  v25 = 0i64;
  v27 = 0;
  v28 = 0;
  P = 0i64;
  v32 = 0;
  v33 = 0;
  Partition = 0i64;
  memset(&LockHandle, 0, sizeof(LockHandle));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  *((_DWORD *)CurrentThread + 339) = 0;
  SharedCacheMap = (INT64)a2->SectionObjectPointer->SharedCacheMap;
  v45 = *(_QWORD *)(SharedCacheMap + 208);
  v46 = *(_QWORD *)(SharedCacheMap + 216);
  Partition = CcGetPartition((_QWORD *)SharedCacheMap);
  LOBYTE(v3) = 1;
  v4 = (*(__int64(__fastcall **)(__int64, __int64))(v45 + 16))(v46, v3);
  v26 = v4;
  if( v4 )
  {
    while( 1 )
    {
      P = 0i64;
      v5 = SectionOffset;
      v6 = v24;
      while( 1 )
      {
        KeAcquireInStackQueuedSpinLock((UINT64 *)(Partition + 128), &LockHandle);
        PrivateCacheMap = (__int64)v2->PrivateCacheMap;
        v39 = PrivateCacheMap;
        if( PrivateCacheMap )
        {
          KxAcquireSpinLock((UINT64 *)(PrivateCacheMap + 80));
          v6 = *(_DWORD *)(PrivateCacheMap + 52);
          v8 = v6 == 0;
          v31 = v6 == 0;
          v5 = *(_LARGE_INTEGER *)(PrivateCacheMap + 56);
          SectionOffset = v5;
          if( v6 > 0x800000 )
            v6 = 0x800000;
          v24 = v6;
          *(_DWORD *)(PrivateCacheMap + 52) = 0;
          if( !v8 )
            *(_QWORD *)(PrivateCacheMap + 64) = v5.QuadPart + v6;
          if( (*(_DWORD *)PrivateCacheMap & 0x200000) != 0 )
          {
            v32 = 1;
            v33 = *(_DWORD *)(PrivateCacheMap + 88);
          }
          KxReleaseSpinLock((UINT64 *)(PrivateCacheMap + 80));
          LODWORD(v25) = (*(_DWORD *)PrivateCacheMap >> 18) & 7;
        }
        KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
        __writecr8(LockHandle.OldIrql);
        if( !PrivateCacheMap || v31 )
          break;
        v10 = *(_QWORD *)(SharedCacheMap + 8);
        if( v5.QuadPart < v10 )
        {
          v28 = 1;
          if( v5.QuadPart + v6 >= v10 )
          {
            v6 = v10 - v5.LowPart;
            v27 = 1;
          }
          v6 = (v6 + 4095) & 0xFFFFF000;
          v24 = v6;
          v11 = v6;
          v41 = v6;
          FileOffset = v5;
          LODWORD(Length) = v6;
          if( v32 )
          {
            if( !v33 )
              KeBugCheckEx(0x34u, 0xA2Eui64, 0xFFFFFFFFC0000420ui64, 0i64, 0i64);
            v12 = v6;
            if( v6 > v33 )
              v12 = v33;
            v34 = v12;
          }
          else
          {
            v12 = v6;
            v34 = v6;
          }
          v13 = a1;
          if( (*(_DWORD *)(&PerfGlobalGroupMask + 2) & 0x20000) != 0 )
          {
            v54[1] = v5.QuadPart;
            v55 = v6;
            v54[0] = a1;
            v56 = v25;
            v57 = 0i64;
            EventData.Ptr = (unsigned __int64)v54;
            *(_QWORD *)&EventData.Size = 32i64;
            LODWORD(BugCheckParameter4) = 4200706;
            EtwTraceKernelEvent(&EventData, 1ui64, 0x80020000ui64, 0x1603u, BugCheckParameter4);
          }
          while( v11 )
          {
            if( v12 > v11 )
              v12 = v11;
            v34 = v12;
            if( (*(_DWORD *)(&PerfGlobalGroupMask + 2) & 0x20000) != 0 )
            {
              v61 = 0i64;
              v58[1] = v5.QuadPart;
              v59 = v12;
              v58[0] = v13;
              v60 = v25;
              v53.Ptr = (unsigned __int64)v58;
              *(_QWORD *)&v53.Size = 32i64;
              LODWORD(BugCheckParameter4) = 4200706;
              EtwTraceKernelEvent(&v53, 1ui64, 0x80020000ui64, 0x160Bu, BugCheckParameter4);
            }
            PagePriority = *(_QWORD *)(a1 + 24);
            MmPrefetchForCacheManager(FileObject, v5, v9, v12);
            HIDWORD(v25) |= v14;
            v11 -= v12;
            v41 = v11;
            v5.QuadPart += v12;
            SectionOffset = v5;
            v13 = a1;
          }
          v2 = FileObject;
        }
      }
      if( !P )
        break;
      v15 = (_ETHREAD *)KeGetCurrentThread();
      v50 = v15;
      PagePriorityThread = PsGetPagePriorityThread((__int64)v15);
      v43 = PagePriorityThread;
      LODWORD(FaultedData[0]) = 0;
      MmWaitForCacheManagerPrefetch((SINGLE_LIST_ENTRY *)P);
      PsSetPagePriorityThread((__int64)v15, v25);
      LODWORD(PagePriority) = v25;
      CcMapAndCopyFromCache(
        v2,
        FileOffset,
        (unsigned int)Length,
        1u,
        0i64,
        FaultedData,
        PagePriority,
        *(VOID **)(a1 + 24));
      PsSetPagePriorityThread((__int64)v15, PagePriorityThread);
    }
  }
  __addgsdword(0x8164u, *((_DWORD *)KeGetCurrentThread() + 339));
  if( v26 )
    (*(void(__fastcall **)(__int64))(v45 + 24))(v46);
  v17 = Partition;
  KeAcquireInStackQueuedSpinLock((UINT64 *)(Partition + 128), &LockHandle);
  v18 = (__int64)v2->PrivateCacheMap;
  v39 = v18;
  if( v18 )
  {
    KxAcquireSpinLock((UINT64 *)(v18 + 80));
    *(_DWORD *)v18 &= ~0x10000u;
    if( v27 && (v2->Flags & 0x20) != 0 )
      *(_QWORD *)(v18 + 64) = 0i64;
    if( !HIDWORD(v25) && v28 )
      *(_DWORD *)v18 &= ~0x20000u;
    KxReleaseSpinLock((UINT64 *)(v18 + 80));
  }
  KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
  __writecr8(LockHandle.OldIrql);
  ObfDereferenceObjectWithTag(v2, 0x746C6644ui64);
  v19 = *(void **)(a1 + 24);
  if( v19 )
    IoDiskIoAttributionDereference(v19);
  KeAcquireInStackQueuedSpinLock((UINT64 *)(v17 + 128), &LockHandle);
  v20 = SharedCacheMap;
  CcDecrementOpenCount(SharedCacheMap);
  *(_DWORD *)(v20 + 152) &= ~0x4000u;
  KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
  result = LockHandle.OldIrql;
  __writecr8(LockHandle.OldIrql);
  return result;
}

Referenced by:

CcWorkerThread