MiGetTopLevelPfn

UINT64 __fastcall MiGetTopLevelPfn(UINT64 P2){
  __int64 v1; 
  unsigned int v2; 
  _MMPFN *PfnDb; 
  int v4; 
  __int64 v5; 
  UINT64 v6; 
  __int64 v8; 
  __int128 *v9; 
  __int64 v10; 
  UINT64 SpinCount; 
  __int128 v13[2]; 
  v1 = *(_QWORD *)(P2 + 40);
  v2 = 0;
  PfnDb = MmGetPfnDb();
  v4 = 0;
  memset(v13, 0, sizeof(v13));
  v5 = v1 & 0xFFFFFFFFFi64;
  v6 = P2;
  if( v5 != (__int64)(P2 - (_QWORD)PfnDb) / 48 )
  {
    do
    {
      v8 = v5;
      v6 = (UINT64)PfnDb + 48 * v5;
      if( (unsigned int)++v4 > 4 )
        KeBugCheckEx(0x1Au, 0x9696ui64, P2, 0i64, 0i64);
      LODWORD(SpinCount) = 0;
      *((_QWORD *)v13 + (unsigned int)(v4 - 1)) = v6;
      while( _interlockedbittestandset64((volatile signed __int32 *)(v6 + 24), 0x3Fui64) )
      {
        do
          KeYieldProcessorEx(&SpinCount);
        while( *(__int64 *)(v6 + 24) < 0 );
      }
      v5 = *(_QWORD *)(v6 + 40) & 0xFFFFFFFFFi64;
    }
    while( v5 != v8 );
  }
  v9 = v13;
  do
  {
    v10 = *(_QWORD *)v9;
    if( !*(_QWORD *)v9 )
      break;
    if( v10 != v6 )
      _InterlockedAnd64((volatile signed __int64 *)(v10 + 24), 0x7FFFFFFFFFFFFFFFui64);
    ++v2;
    v9 = (__int128 *)((char *)v9 + 8);
  }
  while( v2 < 4 );
  return v6;
}

Referenced by:

MiCapturePfnVm
MiGetPagePrivilege
MiIdentifyPfn
MiRecheckCombineVm
MiReferenceOwningSession
MiRestoreTransitionPte
MiStoreCheckCandidatePage