MiUpdatePrefetchPriority

char __fastcall MiUpdatePrefetchPriority(__int64 a1, unsigned __int64 a2, __int64 a3){
  int v5; 
  UINT64 *v6; 
  UINT64 v7; 
  INT64 Pml4eBase; 
  __int64 v9; 
  __int64 v10; 
  INT64 v11; 
  INT64 v12; 
  UINT64 SpinCount; 
  UINT64 v15; 
  v5 = *(_DWORD *)(a1 + 80) & 7;
  v6 = (UINT64 *)((char *)MmGetPteBase() + ((a2 >> 9) & 0x7FFFFFFFF8i64));
  v7 = *v6;
  Pml4eBase = (INT64)MmGetPml4eBase();
  if( (unsigned __int64)v6 >= Pml4eBase )
    LOBYTE(Pml4eBase) = (unsigned __int8)MmGetPxeUserLimit();
  v15 = *v6;
  if( (v7 & 1) != 0 )
  {
    MiPteInShadowRange((UINT64)&v15);
    v9 = (v7 >> 12) & 0xFFFFFFFFFi64;
    v10 = 6 * v9;
    Pml4eBase = *((_QWORD *)MmGetPfnDb() + 6 * v9 + 5);
    if( (Pml4eBase & 0x4000000000000i64) == 0 )
      return Pml4eBase;
    Pml4eBase = (INT64)MmGetPfnDb();
    v11 = Pml4eBase + 48 * v9;
    LODWORD(Pml4eBase) = *(_BYTE *)(Pml4eBase + 8 * v10 + 35) & 7;
    if( (_DWORD)Pml4eBase == v5 )
      return Pml4eBase;
    if( a3 )
    {
      LOBYTE(Pml4eBase) = *(_DWORD *)(a3 + 48) & 0x70;
      if( (_BYTE)Pml4eBase == 16 )
        return Pml4eBase;
    }
    else if( *(_QWORD *)(*(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1680i64) + 304i64) )
    {
      Pml4eBase = (INT64)MiLocateAddress(a2);
      if( !Pml4eBase )
        return Pml4eBase;
      LOBYTE(Pml4eBase) = *(_DWORD *)(Pml4eBase + 48) & 0x70;
      if( (_BYTE)Pml4eBase == 16 )
        return Pml4eBase;
    }
    LODWORD(SpinCount) = 0;
    while( _interlockedbittestandset64((volatile signed __int32 *)(v11 + 24), 0x3Fui64) )
    {
      do
        KeYieldProcessorEx(&SpinCount);
      while( *(__int64 *)(v11 + 24) < 0 );
    }
  }
  else
  {
    if( !v7 )
      return Pml4eBase;
    if( (v7 & 0x400) != 0 )
      return Pml4eBase;
    if( (v7 & 0x800) == 0 )
      return Pml4eBase;
    Pml4eBase = (INT64)MiLockTransitionLeafPage((_MMPTE *)v6, 0i64);
    v11 = Pml4eBase;
    if( !Pml4eBase )
      return Pml4eBase;
  }
  if( (unsigned int)MiGetPfnPriority(v11) != v5 )
    MiUpdatePfnPriority(v12);
  LOBYTE(Pml4eBase) = -1;
  _InterlockedAnd64((volatile signed __int64 *)(v11 + 24), 0x7FFFFFFFFFFFFFFFui64);
  return Pml4eBase;
}

Referenced by:

MiPrefetchJumpVad
MiValidFault