# bfs_4484.sys-bfs_4652.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_1827994938__private_IsEnabledDeviceUsageNoInline](#feature_1827994938__private_isenableddeviceusagenoinline)
	* [Feature_1827994938__private_IsEnabledFallback](#feature_1827994938__private_isenabledfallback)
	* [Feature_3148938554__private_IsEnabledDeviceUsageNoInline](#feature_3148938554__private_isenableddeviceusagenoinline)
	* [Feature_3148938554__private_IsEnabledFallback](#feature_3148938554__private_isenabledfallback)
* [Modified](#modified)
	* [BfsInsertNotPresentPolicyEntry](#bfsinsertnotpresentpolicyentry)
	* [BfsInsertPolicyEntry](#bfsinsertpolicyentry)
	* [BfsCheckAndApplyPolicy](#bfscheckandapplypolicy)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [BfsDereferencePolicyEntryEx](#bfsdereferencepolicyentryex)

# Visual Chart Diff



```mermaid

flowchart LR

BfsInsertNotPresentPolicyEntry-4-old<--Match 92%-->BfsInsertNotPresentPolicyEntry-4-new
BfsInsertPolicyEntry-7-old<--Match 97%-->BfsInsertPolicyEntry-7-new
BfsCheckAndApplyPolicy-5-old<--Match 97%-->BfsCheckAndApplyPolicy-5-new

subgraph bfs_4652.sys
    BfsInsertNotPresentPolicyEntry-4-new
BfsInsertPolicyEntry-7-new
BfsCheckAndApplyPolicy-5-new
    subgraph Added
direction LR
Feature_1827994938__private_IsEnabledDeviceUsageNoInline
    Feature_1827994938__private_IsEnabledFallback
    Feature_3148938554__private_IsEnabledDeviceUsageNoInline
    Feature_3148938554__private_IsEnabledFallback
end
end

subgraph bfs_4484.sys
    BfsInsertNotPresentPolicyEntry-4-old
BfsInsertPolicyEntry-7-old
BfsCheckAndApplyPolicy-5-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.4819%
"unmatched_funcs_len" : 4
"matched_funcs_len" : 768
```



```mermaid
pie showData
    title Matched Function Similarity - 99.2188%
"matched_funcs_with_code_changes_len" : 3
"matched_funcs_with_non_code_changes_len" : 3
"matched_funcs_no_changes_len" : 762
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 bfs_4484.sys bfs_4652.sys
```


#### Verbose Args


<details>

```
--old ['bfs_4484.sys'] --new [['bfs_4652.sys']] --engine VersionTrackingDiff --output-path bfsj_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/0303532121000/Bfs.sys -O bfs.sys.x64.10.0.26100.4484
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/0A4643DB21000/Bfs.sys -O bfs.sys.x64.10.0.26100.4652
```


## Binary Metadata Diff


```diff
--- bfs_4484.sys Meta
+++ bfs_4652.sys Meta
@@ -1,44 +1,44 @@
-Program Name: bfs_4484.sys
+Program Name: bfs_4652.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
 # of Bytes: 141392
 # of Memory Blocks: 13
-# of Instructions: 17252
-# of Defined Data: 1339
-# of Functions: 384
-# of Symbols: 2798
+# of Instructions: 17323
+# of Defined Data: 1353
+# of Functions: 388
+# of Symbols: 2816
 # of Data Types: 346
 # of Data Type Categories: 22
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Wed Aug 19 18:43:31 SGT 2026
+Date Created: Wed Aug 19 18:43:35 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/bfs/bfs_4484.sys
-Executable MD5: fd0bafa07d9ad2fb80bbc6e42c88ac0a
-Executable SHA256: 0fb28e775b40c35f96ab4cb22df9c5ea5873fbaff012fa2268a253aa94361626
-FSRL: file:///tmp/bfs/bfs_4484.sys?MD5=fd0bafa07d9ad2fb80bbc6e42c88ac0a
+Executable Location: /tmp/bfs/bfs_4652.sys
+Executable MD5: f2670c81e9a869880b3f8c979e116cde
+Executable SHA256: 678c670cb8ba6b2a02260ccb27540f5894d5668b411404d07c16a262ab074411
+FSRL: file:///tmp/bfs/bfs_4652.sys?MD5=f2670c81e9a869880b3f8c979e116cde
 PDB Age: 1
 PDB File: bfs.pdb
-PDB GUID: 27938dfc-67a6-b418-1c4e-6ed79ec26ddf
+PDB GUID: ba8a289c-3772-7e9a-0d24-839eb5e90de8
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Bfs Filter Driver
-PE Property[FileVersion]: 10.0.26100.4484 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.4652 (WinBuild.160101.0800)
 PE Property[InternalName]: Bfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Bfs.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.4484
+PE Property[ProductVersion]: 10.0.26100.4652
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra bfs_4484.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs_4484.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs_4484.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra bfs_4652.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs_4652.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs_4652.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|4|
|deleted_funcs_len|0|
|modified_funcs_len|6|
|added_symbols_len|6|
|deleted_symbols_len|0|
|diff_time|3.3442752361297607|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 383, 'ExternalsName': 185})|
|items_to_process|16|
|diff_types|Counter({'address': 4, 'refcount': 3, 'code': 3, 'length': 3, 'called': 3, 'calling': 1})|
|unmatched_funcs_len|4|
|total_funcs_len|772|
|matched_funcs_len|768|
|matched_funcs_with_code_changes_len|3|
|matched_funcs_with_non_code_changes_len|3|
|matched_funcs_no_changes_len|762|
|match_func_similarity_percent|99.2188%|
|func_match_overall_percent|99.4819%|
|first_matches|Counter({'SymbolsHash': 383})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 383
"ExternalsName" : 185
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 383
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 4
"deleted_funcs_len" : 0
"modified_funcs_len" : 6
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 6
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_1827994938__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|bfs_4652.sys|
| :---: | :---: |
|name|Feature_1827994938__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_1827994938__private_IsEnabledDeviceUsageNoInline|
|refcount|2|
|length|49|
|called|Feature_1827994938__private_IsEnabledFallback|
|calling|BfsCheckAndApplyPolicy|
|paramcount|0|
|address|1c0009008|
|sig|ulonglong __fastcall Feature_1827994938__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1827994938__private_IsEnabledDeviceUsageNoInline
+++ Feature_1827994938__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_1827994938__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_1827994938__private_featureState;
+  if ((Feature_1827994938__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_1827994938__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_1827994938__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_1827994938__private_IsEnabledFallback

### Function Meta



|Key|bfs_4652.sys|
| :---: | :---: |
|name|Feature_1827994938__private_IsEnabledFallback|
|fullname|Feature_1827994938__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_1827994938__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1c0009040|
|sig|undefined __fastcall Feature_1827994938__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1827994938__private_IsEnabledFallback
+++ Feature_1827994938__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_1827994938__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_1827994938__private_descriptor);
+  return;
+}
+

```


## Feature_3148938554__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|bfs_4652.sys|
| :---: | :---: |
|name|Feature_3148938554__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_3148938554__private_IsEnabledDeviceUsageNoInline|
|refcount|5|
|length|49|
|called|Feature_3148938554__private_IsEnabledFallback|
|calling|BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry|
|paramcount|0|
|address|1c000905c|
|sig|ulonglong __fastcall Feature_3148938554__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3148938554__private_IsEnabledDeviceUsageNoInline
+++ Feature_3148938554__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_3148938554__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_3148938554__private_featureState;
+  if ((Feature_3148938554__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_3148938554__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_3148938554__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_3148938554__private_IsEnabledFallback

### Function Meta



|Key|bfs_4652.sys|
| :---: | :---: |
|name|Feature_3148938554__private_IsEnabledFallback|
|fullname|Feature_3148938554__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_3148938554__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1c0009094|
|sig|undefined __fastcall Feature_3148938554__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3148938554__private_IsEnabledFallback
+++ Feature_3148938554__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_3148938554__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_3148938554__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## BfsInsertNotPresentPolicyEntry

### Match Info



|Key|bfs_4484.sys - bfs_4652.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.46|
|i_ratio|0.78|
|m_ratio|0.98|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs_4484.sys|bfs_4652.sys|
| :---: | :---: | :---: |
|name|BfsInsertNotPresentPolicyEntry|BfsInsertNotPresentPolicyEntry|
|fullname|BfsInsertNotPresentPolicyEntry|BfsInsertNotPresentPolicyEntry|
|refcount|2|2|
|`length`|747|770|
|`called`|<details><summary>Expand for full list:<br>BfsDereferencePolicyEntryEx<br>BfsInsertEntryHashTable<br>BfsLookupPolicyEntryHashTable<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeInitializeEvent<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::RtlCopySid</summary>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|<details><summary>Expand for full list:<br>BfsDereferencePolicyEntryEx<br>BfsInsertEntryHashTable<br>BfsLookupPolicyEntryHashTable<br>Feature_3148938554__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeInitializeEvent<br>NTOSKRNL.EXE::KeLeaveCriticalRegion</summary>NTOSKRNL.EXE::RtlCopySid<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|
|calling|BfsPolicyEntryExists|BfsPolicyEntryExists|
|paramcount|4|4|
|`address`|1c00063a4|1c0006404|
|sig|ulonglong __fastcall BfsInsertNotPresentPolicyEntry(longlong param_1, undefined8 param_2, longlong param_3, longlong param_4)|ulonglong __fastcall BfsInsertNotPresentPolicyEntry(longlong param_1, undefined8 param_2, longlong param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsInsertNotPresentPolicyEntry Called Diff


```diff
--- BfsInsertNotPresentPolicyEntry called
+++ BfsInsertNotPresentPolicyEntry called
@@ -3,0 +4 @@
+Feature_3148938554__private_IsEnabledDeviceUsageNoInline
```


### BfsInsertNotPresentPolicyEntry Diff


```diff
--- BfsInsertNotPresentPolicyEntry
+++ BfsInsertNotPresentPolicyEntry
@@ -1,129 +1,138 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 ulonglong BfsInsertNotPresentPolicyEntry
                     (longlong param_1,undefined8 param_2,longlong param_3,longlong param_4)
 
 {
   uint uVar1;
   uint uVar2;
   longlong lVar3;
-  longlong lVar4;
+  ulonglong uVar4;
   ulonglong uVar5;
   longlong lVar6;
   ulonglong uVar7;
   ulonglong uVar8;
+  ulonglong uVar9;
+  ulonglong uVar10;
   undefined1 auStack_b8 [40];
   undefined1 *local_90;
   uint local_88 [2];
   undefined1 local_80 [32];
   uint *local_60;
   undefined8 local_58;
   ulonglong local_50;
   
   local_50 = __security_cookie ^ (ulonglong)auStack_b8;
-  uVar5 = 0;
   KeEnterCriticalRegion();
   ExAcquirePushLockExclusiveEx(param_1,0);
   lVar3 = BfsLookupPolicyEntryHashTable(*(undefined8 *)(param_1 + 8),param_2,param_3,param_4);
   if (lVar3 != 0) {
     uVar7 = 0x40000000;
     if (*(int *)(lVar3 + 0x38) != 0x10000000) {
-      uVar7 = uVar5;
+      uVar7 = 0;
     }
     ExReleasePushLockExclusiveEx(param_1,0);
     KeLeaveCriticalRegion();
     return uVar7;
   }
   uVar7 = 0x100;
-  lVar4 = ExAllocatePool2(0x100,(ulonglong)*(byte *)(param_3 + 1) * 4 + 8,0x53736642);
+  uVar4 = ExAllocatePool2(0x100,(ulonglong)*(byte *)(param_3 + 1) * 4 + 8,0x53736642);
   lVar3 = 0;
-  if (lVar4 == 0) {
-    uVar8 = 0xc0000017;
+  uVar8 = uVar4;
+  if (uVar4 == 0) {
+    uVar10 = 0xc0000017;
     uVar2 = 0xc0000017;
+    uVar9 = 0;
     uVar1 = local_88[0];
   }
   else {
     uVar7 = 0x100;
     uVar5 = ExAllocatePool2(0x100,(ulonglong)*(byte *)(param_4 + 1) * 4 + 8,0x53736642);
-    if (uVar5 == 0) {
-      uVar8 = 0xc0000017;
-      uVar2 = 0xc0000017;
-      uVar1 = local_88[0];
-    }
-    else {
-      uVar7 = (ulonglong)((uint)*(byte *)(param_3 + 1) * 4 + 8);
-      uVar2 = RtlCopySid(uVar7,lVar4,param_3);
-      uVar8 = (ulonglong)uVar2;
+    uVar9 = uVar5;
+    if (uVar5 == 0) goto LAB_0;
+    uVar7 = (ulonglong)((uint)*(byte *)(param_3 + 1) * 4 + 8);
+    uVar2 = RtlCopySid(uVar7,uVar4,param_3);
+    uVar10 = (ulonglong)uVar2;
+    uVar1 = local_88[0];
+    if (-1 < (int)uVar2) {
+      uVar7 = (ulonglong)((uint)*(byte *)(param_4 + 1) * 4 + 8);
+      uVar2 = RtlCopySid(uVar7,uVar5,param_4);
+      uVar10 = (ulonglong)uVar2;
       uVar1 = local_88[0];
       if (-1 < (int)uVar2) {
-        uVar7 = (ulonglong)((uint)*(byte *)(param_4 + 1) * 4 + 8);
-        uVar2 = RtlCopySid(uVar7,uVar5,param_4);
-        uVar8 = (ulonglong)uVar2;
+        uVar7 = 0x100;
+        lVar3 = ExAllocatePool2(0x100,0x98,0x45736642);
+        if (lVar3 != 0) {
+          LOCK();
+          *(int *)(lVar3 + 0x90) = *(int *)(lVar3 + 0x90) + 1;
+          UNLOCK();
+          uVar7 = 0x40;
+          lVar6 = ExAllocatePool2(0x40,0x18,0x76736642);
+          *(longlong *)(lVar3 + 0x28) = lVar6;
+          if (lVar6 != 0) {
+            *(ulonglong *)(lVar3 + 0x18) = uVar4;
+            uVar7 = Feature_3148938554__private_IsEnabledDeviceUsageNoInline();
+            *(ulonglong *)(lVar3 + 0x20) = uVar5;
+            uVar8 = 0;
+            if ((int)uVar7 == 0) {
+              uVar8 = uVar4;
+            }
+            uVar7 = Feature_3148938554__private_IsEnabledDeviceUsageNoInline();
+            *(undefined4 *)(lVar3 + 0x38) = 2;
+            *(undefined4 *)(lVar3 + 0x68) = 0;
+            *(undefined8 *)(lVar3 + 0x70) = 0;
+            *(undefined8 *)(lVar3 + 0x78) = 0;
+            *(undefined2 *)(lVar3 + 0x72) = 0;
+            uVar9 = 0;
+            if ((int)uVar7 == 0) {
+              uVar9 = uVar5;
+            }
+            *(undefined8 *)(lVar3 + 0x78) = 0;
+            *(undefined8 *)(lVar3 + 0x80) = 0;
+            *(undefined8 *)(lVar3 + 0x88) = 0;
+            *(undefined2 *)(lVar3 + 0x82) = 0;
+            *(undefined8 *)(lVar3 + 0x88) = 0;
+            KeInitializeEvent(*(undefined8 *)(lVar3 + 0x28),0,0);
+            uVar7 = *(ulonglong *)(param_1 + 8);
+            uVar2 = BfsInsertEntryHashTable(uVar7,param_2,lVar3);
+            uVar10 = (ulonglong)uVar2;
+            uVar1 = local_88[0];
+            if (-1 < (int)uVar2) goto LAB_1;
+            goto joined_r0x0001c0006661;
+          }
+        }
+LAB_0:
+        uVar10 = 0xc0000017;
+        uVar2 = 0xc0000017;
         uVar1 = local_88[0];
-        if (-1 < (int)uVar2) {
-          uVar7 = 0x100;
-          lVar3 = ExAllocatePool2(0x100,0x98,0x45736642);
-          if (lVar3 != 0) {
-            LOCK();
-            *(int *)(lVar3 + 0x90) = *(int *)(lVar3 + 0x90) + 1;
-            UNLOCK();
-            lVar6 = ExAllocatePool2(0x40,0x18,0x76736642);
-            uVar7 = 0;
-            *(longlong *)(lVar3 + 0x28) = lVar6;
-            if (lVar6 != 0) {
-              *(undefined4 *)(lVar3 + 0x68) = 0;
-              *(longlong *)(lVar3 + 0x18) = lVar4;
-              *(ulonglong *)(lVar3 + 0x20) = uVar5;
-              *(undefined4 *)(lVar3 + 0x38) = 2;
-              *(undefined8 *)(lVar3 + 0x70) = 0;
-              *(undefined8 *)(lVar3 + 0x78) = 0;
-              *(undefined2 *)(lVar3 + 0x72) = 0;
-              *(undefined8 *)(lVar3 + 0x78) = 0;
-              *(undefined8 *)(lVar3 + 0x80) = 0;
-              *(undefined8 *)(lVar3 + 0x88) = 0;
-              *(undefined2 *)(lVar3 + 0x82) = 0;
-              *(undefined8 *)(lVar3 + 0x88) = 0;
-              KeInitializeEvent(lVar6,0,0);
-              uVar7 = *(ulonglong *)(param_1 + 8);
-              uVar2 = BfsInsertEntryHashTable(uVar7,param_2,lVar3);
-              uVar8 = (ulonglong)uVar2;
-              uVar1 = local_88[0];
-              if (-1 < (int)uVar2) goto LAB_0;
-              goto joined_r0x0001c00065ea;
-            }
-          }
-          uVar8 = 0xc0000017;
-          uVar2 = 0xc0000017;
-          uVar1 = local_88[0];
-        }
       }
     }
   }
-joined_r0x0001c00065ea:
+joined_r0x0001c0006661:
   local_88[0] = uVar2;
-  if (3 < DAT_1) {
+  if (3 < DAT_2) {
     local_58 = 4;
     local_60 = local_88;
     local_90 = local_80;
-    _tlgWriteTransfer_EtwWriteTransfer(uVar7,&DAT_2);
+    _tlgWriteTransfer_EtwWriteTransfer(uVar7,&DAT_3);
     uVar1 = local_88[0];
   }
-LAB_0:
+LAB_1:
   local_88[0] = uVar1;
   ExReleasePushLockExclusiveEx(param_1);
   KeLeaveCriticalRegion();
-  if ((int)uVar8 < 0) {
+  if ((int)uVar10 < 0) {
     if (lVar3 != 0) {
       BfsDereferencePolicyEntryEx(lVar3,'\0');
     }
-    if (lVar4 != 0) {
-      ExFreePoolWithTag(lVar4,0);
+    if (uVar8 != 0) {
+      ExFreePoolWithTag(uVar8,0);
     }
-    if (uVar5 != 0) {
-      ExFreePoolWithTag(uVar5,0);
+    if (uVar9 != 0) {
+      ExFreePoolWithTag(uVar9,0);
     }
   }
-  return uVar8;
+  return uVar10;
 }
 

```


## BfsInsertPolicyEntry

### Match Info



|Key|bfs_4484.sys - bfs_4652.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.8|
|i_ratio|0.67|
|m_ratio|0.99|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs_4484.sys|bfs_4652.sys|
| :---: | :---: | :---: |
|name|BfsInsertPolicyEntry|BfsInsertPolicyEntry|
|fullname|BfsInsertPolicyEntry|BfsInsertPolicyEntry|
|refcount|2|2|
|`length`|1735|1752|
|`called`|<details><summary>Expand for full list:<br>BfsCreateStorage<br>BfsDereferencePolicyEntryEx<br>BfsInsertEntryHashTable<br>BfsLookupPolicyEntryHashTable<br>BfsOpenPolicyDirectory<br>FLTMGR.SYS::FltClose<br>Feature_Servicing_BfsGAFeature__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx</summary>NTOSKRNL.EXE::ExSetTimer<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeInitializeEvent<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeResetEvent<br>NTOSKRNL.EXE::KeSetEvent<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>NTOSKRNL.EXE::RtlConvertSidToUnicodeString<br>NTOSKRNL.EXE::RtlCopySid<br>NTOSKRNL.EXE::RtlFreeUnicodeString<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|<details><summary>Expand for full list:<br>BfsCreateStorage<br>BfsDereferencePolicyEntryEx<br>BfsInsertEntryHashTable<br>BfsLookupPolicyEntryHashTable<br>BfsOpenPolicyDirectory<br>FLTMGR.SYS::FltClose<br>Feature_3148938554__private_IsEnabledDeviceUsageNoInline<br>Feature_Servicing_BfsGAFeature__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag</summary>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::ExSetTimer<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeInitializeEvent<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeResetEvent<br>NTOSKRNL.EXE::KeSetEvent<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>NTOSKRNL.EXE::RtlConvertSidToUnicodeString<br>NTOSKRNL.EXE::RtlCopySid<br>NTOSKRNL.EXE::RtlFreeUnicodeString<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|
|calling|BfsGetPolicyEntry|BfsGetPolicyEntry|
|paramcount|7|7|
|`address`|1c0006698|1c0006710|
|sig|ulonglong __fastcall BfsInsertPolicyEntry(undefined8 * param_1, undefined8 param_2, longlong param_3, undefined8 param_4, longlong param_5, longlong param_6, longlong * param_7)|ulonglong __fastcall BfsInsertPolicyEntry(undefined8 * param_1, undefined8 param_2, longlong param_3, undefined8 param_4, longlong param_5, longlong param_6, longlong * param_7)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsInsertPolicyEntry Called Diff


```diff
--- BfsInsertPolicyEntry called
+++ BfsInsertPolicyEntry called
@@ -6,0 +7 @@
+Feature_3148938554__private_IsEnabledDeviceUsageNoInline
```


### BfsInsertPolicyEntry Diff


```diff
--- BfsInsertPolicyEntry
+++ BfsInsertPolicyEntry
@@ -1,275 +1,284 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 ulonglong BfsInsertPolicyEntry
                     (undefined8 *param_1,undefined8 param_2,longlong param_3,undefined8 param_4,
                     longlong param_5,longlong param_6,longlong *param_7)
 
 {
   longlong *plVar1;
   longlong *plVar2;
   code *pcVar3;
   bool bVar4;
   bool bVar5;
   uint uVar6;
   longlong lVar7;
   longlong lVar8;
   longlong lVar9;
   longlong lVar10;
   ulonglong uVar11;
   undefined8 uVar12;
   undefined8 *puVar13;
   undefined1 auStackY_118 [32];
   undefined8 local_e0;
   char local_d8;
   longlong local_d0;
-  longlong local_c8;
-  undefined8 local_c0;
-  longlong local_b8;
-  undefined8 *local_b0;
+  undefined8 local_c8;
+  longlong local_c0;
+  undefined8 *local_b8;
+  undefined8 local_b0;
   undefined8 local_a8;
-  undefined8 local_a0;
-  undefined8 uStack_98;
-  undefined8 local_90;
-  undefined8 uStack_88;
+  undefined8 uStack_a0;
+  undefined8 local_98;
+  undefined8 uStack_90;
+  longlong *local_88;
   undefined8 *local_60;
   undefined8 local_58;
   ulonglong local_50;
   
   local_50 = __security_cookie ^ (ulonglong)auStackY_118;
   lVar9 = 0;
   local_d0 = param_5;
-  local_c8 = param_6;
+  local_88 = param_7;
   bVar4 = false;
-  local_90 = 0;
-  uStack_88 = 0;
+  local_98 = 0;
+  uStack_90 = 0;
+  local_b0 = 0;
   local_a8 = 0;
-  local_a0 = 0;
-  uStack_98 = 0;
-  local_b8 = 0;
+  uStack_a0 = 0;
+  local_c0 = 0;
   local_d8 = '\0';
   bVar5 = false;
   local_e0 = param_2;
-  local_c0 = param_4;
-  local_b0 = param_1;
+  local_c8 = param_4;
+  local_b8 = param_1;
   KeEnterCriticalRegion();
   ExAcquirePushLockExclusiveEx(param_3,0);
   uVar11 = *(ulonglong *)(param_3 + 8);
-  lVar7 = BfsLookupPolicyEntryHashTable(uVar11,local_c0,param_5,param_6);
+  lVar7 = BfsLookupPolicyEntryHashTable(uVar11,local_c8,param_5,param_6);
+  lVar10 = local_d0;
   if (lVar7 == 0) {
     lVar8 = ExAllocatePool2(0x100,(ulonglong)*(byte *)(local_d0 + 1) * 4 + 8,0x53736642);
     if ((lVar8 == 0) ||
        (lVar9 = ExAllocatePool2(0x100,(ulonglong)*(byte *)(param_6 + 1) * 4 + 8,0x53736642),
        lVar9 == 0)) goto LAB_0;
-    uVar11 = (ulonglong)((uint)*(byte *)(local_d0 + 1) * 4 + 8);
-    uVar6 = RtlCopySid(uVar11,lVar8,local_d0);
+    uVar11 = (ulonglong)((uint)*(byte *)(lVar10 + 1) * 4 + 8);
+    uVar6 = RtlCopySid(uVar11,lVar8,lVar10);
     if ((int)uVar6 < 0) {
 LAB_1:
       if (3 < DAT_2) {
         local_e0 = CONCAT44(local_e0._4_4_,uVar6);
 LAB_3:
         local_60 = &local_e0;
         local_58 = 4;
         _tlgWriteTransfer_EtwWriteTransfer(uVar11,&DAT_4);
       }
     }
     else {
-      uVar11 = (ulonglong)((uint)*(byte *)(local_c8 + 1) * 4 + 8);
-      uVar6 = RtlCopySid(uVar11,lVar9,local_c8);
+      uVar11 = (ulonglong)((uint)*(byte *)(param_6 + 1) * 4 + 8);
+      uVar6 = RtlCopySid(uVar11,lVar9,param_6);
       if ((int)uVar6 < 0) goto LAB_1;
       lVar7 = ExAllocatePool2(0x100,0x98,0x45736642);
       if (lVar7 != 0) {
         LOCK();
         *(int *)(lVar7 + 0x90) = *(int *)(lVar7 + 0x90) + 1;
         UNLOCK();
         lVar10 = ExAllocatePool2(0x40,0x18,0x76736642);
         *(longlong *)(lVar7 + 0x28) = lVar10;
         if (lVar10 != 0) {
           *(longlong *)(lVar7 + 0x18) = lVar8;
+          uVar11 = Feature_3148938554__private_IsEnabledDeviceUsageNoInline();
           *(longlong *)(lVar7 + 0x20) = lVar9;
+          if ((int)uVar11 != 0) {
+            lVar8 = 0;
+          }
+          uVar11 = Feature_3148938554__private_IsEnabledDeviceUsageNoInline();
           *(undefined4 *)(lVar7 + 0x38) = 0x10000001;
           *(undefined4 *)(lVar7 + 0x68) = 0;
           *(undefined8 *)(lVar7 + 0x70) = 0;
           *(undefined8 *)(lVar7 + 0x78) = 0;
           *(undefined2 *)(lVar7 + 0x72) = 0;
+          if ((int)uVar11 != 0) {
+            lVar9 = 0;
+          }
           *(undefined8 *)(lVar7 + 0x78) = 0;
           *(undefined8 *)(lVar7 + 0x80) = 0;
           *(undefined8 *)(lVar7 + 0x88) = 0;
           *(undefined2 *)(lVar7 + 0x82) = 0;
           *(undefined8 *)(lVar7 + 0x88) = 0;
-          KeInitializeEvent(lVar10,0,0);
+          KeInitializeEvent(*(undefined8 *)(lVar7 + 0x28),0,0);
           uVar11 = *(ulonglong *)(param_3 + 8);
-          uVar6 = BfsInsertEntryHashTable(uVar11,local_c0,lVar7);
+          uVar6 = BfsInsertEntryHashTable(uVar11,local_c8,lVar7);
           if (-1 < (int)uVar6) {
             LOCK();
             *(int *)(lVar7 + 0x90) = *(int *)(lVar7 + 0x90) + 1;
             UNLOCK();
             plVar1 = (longlong *)(param_3 + 0x10);
             local_d8 = '\x01';
             if ((longlong *)*plVar1 == plVar1) {
               ExSetTimer(*(undefined8 *)(param_3 + 0x20),0xffffffffee1e5d00,300000000);
             }
             puVar13 = *(undefined8 **)(param_3 + 0x18);
             plVar2 = (longlong *)(lVar7 + 0x40);
             if ((longlong *)*puVar13 != plVar1) goto LAB_5;
             *plVar2 = (longlong)plVar1;
             *(undefined8 **)(lVar7 + 0x48) = puVar13;
             *puVar13 = plVar2;
             *(longlong **)(param_3 + 0x18) = plVar2;
             LOCK();
             *(undefined8 *)(lVar7 + 0x60) = _DAT_6;
             UNLOCK();
             goto LAB_7;
           }
           goto LAB_1;
         }
       }
 LAB_0:
       uVar11 = 0xc0000017;
       uVar6 = 0xc0000017;
       if (3 < DAT_2) {
         local_e0 = CONCAT44(local_e0._4_4_,0xc0000017);
         uVar6 = 0xc0000017;
         goto LAB_3;
       }
     }
 LAB_8:
     ExReleasePushLockExclusiveEx(param_3);
     KeLeaveCriticalRegion();
     bVar4 = false;
     bVar5 = false;
     if (-1 < (int)uVar6) goto LAB_9;
 LAB_10:
     if (lVar7 != 0) goto LAB_11;
   }
   else {
     lVar8 = lVar9;
     if ((*(uint *)(lVar7 + 0x38) >> 0x1c & 1) == 0) {
       if (*(uint *)(lVar7 + 0x38) != 2) {
         uVar6 = 0xc0000001;
         goto LAB_1;
       }
       *(undefined4 *)(lVar7 + 0x38) = 0x10000001;
       KeResetEvent(*(undefined8 *)(lVar7 + 0x28));
       LOCK();
       *(int *)(lVar7 + 0x90) = *(int *)(lVar7 + 0x90) + 1;
       UNLOCK();
 LAB_7:
       ExReleasePushLockExclusiveEx(param_3,0);
       KeLeaveCriticalRegion();
-      puVar13 = &local_a0;
+      puVar13 = &local_a8;
       uVar6 = RtlConvertSidToUnicodeString(puVar13,local_d0,1);
       if (-1 < (int)uVar6) {
-        puVar13 = &local_90;
         bVar4 = true;
-        uVar6 = RtlConvertSidToUnicodeString(puVar13,local_c8,1);
+        puVar13 = &local_98;
+        uVar6 = RtlConvertSidToUnicodeString(puVar13,param_6,1);
         if (-1 < (int)uVar6) {
           bVar5 = true;
-          puVar13 = local_b0;
-          uVar6 = BfsOpenPolicyDirectory(local_b0,local_e0,&local_a0,'\0',&local_b8);
+          puVar13 = local_b8;
+          uVar6 = BfsOpenPolicyDirectory(local_b8,local_e0,&local_a8,'\0',&local_c0);
           if (-1 < (int)uVar6) {
-            puVar13 = local_b0;
-            uVar11 = BfsCreateStorage((undefined4 *)local_b0,local_e0,local_b8,&local_90,&local_a8);
+            puVar13 = local_b8;
+            uVar11 = BfsCreateStorage((undefined4 *)local_b8,local_e0,local_c0,&local_98,&local_b0);
             uVar6 = (uint)uVar11;
             if (-1 < (int)uVar6) {
-              RtlFreeUnicodeString(&local_a0);
-              RtlFreeUnicodeString(&local_90);
+              RtlFreeUnicodeString(&local_a8);
+              RtlFreeUnicodeString(&local_98);
               KeEnterCriticalRegion();
               ExAcquirePushLockExclusiveEx(param_3);
-              *(undefined8 *)(lVar7 + 0x30) = local_a8;
+              *(undefined8 *)(lVar7 + 0x30) = local_b0;
               *(undefined4 *)(lVar7 + 0x38) = 0x10000000;
               KeSetEvent(*(undefined8 *)(lVar7 + 0x28),0,0);
-              *param_7 = lVar7;
+              *local_88 = lVar7;
               goto LAB_8;
             }
           }
         }
       }
       if (3 < DAT_2) {
         local_e0 = CONCAT44(local_e0._4_4_,uVar6);
         local_60 = &local_e0;
         local_58 = 4;
         _tlgWriteTransfer_EtwWriteTransfer(puVar13,&DAT_4);
       }
       goto LAB_10;
     }
     LOCK();
     *(int *)(lVar7 + 0x90) = *(int *)(lVar7 + 0x90) + 1;
     UNLOCK();
     ExReleasePushLockExclusiveEx(param_3);
     KeLeaveCriticalRegion();
     if (*(int *)(lVar7 + 0x38) != 0x10000001) {
 LAB_12:
       *param_7 = lVar7;
       return 0;
     }
     uVar12 = *(undefined8 *)(lVar7 + 0x28);
     KeWaitForSingleObject(uVar12,0,0,0);
     if (*(int *)(lVar7 + 0x38) == 0x10000000) goto LAB_12;
     uVar6 = 0xc0000001;
     if (3 < DAT_2) {
       local_e0 = CONCAT44(local_e0._4_4_,0xc0000001);
       local_60 = &local_e0;
       local_58 = 4;
       _tlgWriteTransfer_EtwWriteTransfer(uVar12,&DAT_4);
       lVar9 = 0;
       lVar8 = 0;
       uVar6 = 0xc0000001;
     }
 LAB_11:
     BfsDereferencePolicyEntryEx(lVar7,'\0');
   }
   if (local_d8 != '\0') {
     KeEnterCriticalRegion();
     ExAcquirePushLockExclusiveEx(param_3,0);
-    lVar7 = BfsLookupPolicyEntryHashTable(*(undefined8 *)(param_3 + 8),local_c0,local_d0,local_c8);
-    if (lVar7 == 0) {
+    lVar10 = BfsLookupPolicyEntryHashTable(*(undefined8 *)(param_3 + 8),local_c8,local_d0,param_6);
+    if (lVar10 == 0) {
       ExReleasePushLockExclusiveEx(param_3,0);
       KeLeaveCriticalRegion();
     }
     else {
-      plVar1 = (longlong *)(lVar7 + 0x40);
-      *(undefined4 *)(lVar7 + 0x38) = 1;
-      lVar10 = *plVar1;
-      if ((*(longlong **)(lVar10 + 8) != plVar1) ||
-         (plVar2 = *(longlong **)(lVar7 + 0x48), (longlong *)*plVar2 != plVar1)) {
+      plVar1 = (longlong *)(lVar10 + 0x40);
+      *(undefined4 *)(lVar10 + 0x38) = 1;
+      lVar7 = *plVar1;
+      if ((*(longlong **)(lVar7 + 8) != plVar1) ||
+         (plVar2 = *(longlong **)(lVar10 + 0x48), (longlong *)*plVar2 != plVar1)) {
 LAB_5:
         pcVar3 = (code *)swi(0x29);
         (*pcVar3)(3);
         pcVar3 = (code *)swi(3);
         uVar11 = (*pcVar3)();
         return uVar11;
       }
-      *plVar2 = lVar10;
-      *(longlong **)(lVar10 + 8) = plVar2;
+      *plVar2 = lVar7;
+      *(longlong **)(lVar7 + 8) = plVar2;
       uVar11 = Feature_Servicing_BfsGAFeature__private_IsEnabledDeviceUsageNoInline();
       if ((int)uVar11 != 0) {
         *plVar1 = 0;
-        *(undefined8 *)(lVar7 + 0x48) = 0;
+        *(undefined8 *)(lVar10 + 0x48) = 0;
       }
       ExReleasePushLockExclusiveEx(param_3);
       KeLeaveCriticalRegion();
-      KeSetEvent(*(undefined8 *)(lVar7 + 0x28),0,0);
-      BfsDereferencePolicyEntryEx(lVar7,'\0');
+      KeSetEvent(*(undefined8 *)(lVar10 + 0x28),0,0);
+      BfsDereferencePolicyEntryEx(lVar10,'\0');
     }
   }
   if (bVar4) {
-    RtlFreeUnicodeString(&local_a0);
+    RtlFreeUnicodeString(&local_a8);
   }
   if (bVar5) {
-    RtlFreeUnicodeString(&local_90);
+    RtlFreeUnicodeString(&local_98);
   }
   if (lVar8 != 0) {
     ExFreePoolWithTag(lVar8,0);
   }
   if (lVar9 != 0) {
     ExFreePoolWithTag(lVar9,0);
   }
 LAB_9:
-  if (local_b8 != 0) {
+  if (local_c0 != 0) {
     FltClose();
   }
   return (ulonglong)uVar6;
 }
 

```


## BfsCheckAndApplyPolicy

### Match Info



|Key|bfs_4484.sys - bfs_4652.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.96|
|i_ratio|0.82|
|m_ratio|0.97|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs_4484.sys|bfs_4652.sys|
| :---: | :---: | :---: |
|name|BfsCheckAndApplyPolicy|BfsCheckAndApplyPolicy|
|fullname|BfsCheckAndApplyPolicy|BfsCheckAndApplyPolicy|
|refcount|2|2|
|`length`|1290|1374|
|`called`|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsApplyPolicyAsUser<br>BfsDereferencePolicyEntryEx<br>BfsFileInPublisherDirectory<br>BfsGetFileName<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsPolicyEntryExists<br>BfsQueryAccessOnly<br>BfsQueueDeferredWorkItemAndWait</summary>FLTMGR.SYS::FltGetFileNameInformation<br>FLTMGR.SYS::FltReferenceFileNameInformation<br>FLTMGR.SYS::FltReleaseFileNameInformation<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::RtlCheckTokenCapability<br>NTOSKRNL.EXE::SeQueryInformationToken<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsApplyPolicyAsUser<br>BfsDereferencePolicyEntryEx<br>BfsFileInPublisherDirectory<br>BfsGetFileName<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsPolicyEntryExists<br>BfsQueryAccessOnly<br>BfsQueueDeferredWorkItemAndWait</summary>FLTMGR.SYS::FltGetFileNameInformation<br>FLTMGR.SYS::FltReferenceFileNameInformation<br>FLTMGR.SYS::FltReleaseFileNameInformation<br>Feature_1827994938__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::RtlCheckTokenCapability<br>NTOSKRNL.EXE::SeQueryInformationToken<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|
|calling|BfsPreCreateOperation|BfsPreCreateOperation|
|paramcount|5|5|
|address|1c0004900|1c0004900|
|sig|undefined1 __fastcall BfsCheckAndApplyPolicy(undefined8 * param_1, longlong param_2, ushort * param_3, ushort * param_4, longlong * param_5)|undefined1 __fastcall BfsCheckAndApplyPolicy(undefined8 * param_1, longlong param_2, ushort * param_3, ushort * param_4, longlong * param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsCheckAndApplyPolicy Called Diff


```diff
--- BfsCheckAndApplyPolicy called
+++ BfsCheckAndApplyPolicy called
@@ -14,0 +15 @@
+Feature_1827994938__private_IsEnabledDeviceUsageNoInline
```


### BfsCheckAndApplyPolicy Diff


```diff
--- BfsCheckAndApplyPolicy
+++ BfsCheckAndApplyPolicy
@@ -1,223 +1,234 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 undefined1
 BfsCheckAndApplyPolicy
           (undefined8 *param_1,longlong param_2,ushort *param_3,ushort *param_4,longlong *param_5)
 
 {
   uint uVar1;
   byte bVar2;
   uint uVar3;
   int iVar4;
   ulonglong uVar5;
   ushort *puVar6;
   undefined8 uVar7;
   longlong lVar8;
   undefined8 *puVar9;
   longlong lVar10;
   undefined1 uVar11;
   undefined1 auStackY_118 [32];
   uint local_e8;
   char local_e4;
   char local_e3 [3];
   longlong local_e0;
   longlong local_d8;
   undefined8 *local_d0;
   undefined8 *local_c8;
   ushort *local_c0;
   longlong local_b8;
   undefined8 local_b0;
   undefined8 uStack_a8;
   undefined8 local_a0;
   undefined8 uStack_98;
   ushort local_90 [24];
   uint *local_60;
   undefined8 local_58;
   ulonglong local_50;
   undefined1 uVar12;
   
   local_50 = __security_cookie ^ (ulonglong)auStackY_118;
   local_e3[0] = '\0';
   local_d0 = (undefined8 *)0x0;
   local_e0 = 0;
   local_d8 = 0;
   local_c8 = (undefined8 *)0x0;
   uVar12 = 0;
   uVar11 = 0;
   local_b0 = 0;
   uStack_a8 = 0;
   puVar6 = param_3;
   uVar3 = SeQueryInformationToken(param_3,1,&local_d0);
   uVar1 = local_e8;
   if ((-1 < (int)uVar3) &&
      (puVar6 = param_3, uVar3 = SeQueryInformationToken(param_3,0x1f,&local_c8), uVar1 = local_e8,
      -1 < (int)uVar3)) {
     uVar3 = FltGetFileNameInformation(param_4,0x101,&local_d8);
     if (uVar3 == 0xc0000201) {
       local_b8 = 0;
       local_c0 = param_3;
       uVar3 = BfsQueueDeferredWorkItemAndWait
                         ((longlong)param_1,param_2,param_4,&local_c0,
                          BfsQueryFileNameInformationCallback);
       local_d8 = local_b8;
     }
     puVar6 = (ushort *)(ulonglong)uVar3;
     uVar1 = local_e8;
     if (-1 < (int)uVar3) {
       bVar2 = BfsPolicyEntryExists(param_1,param_2,0x1c0016200,(byte *)*local_d0,(byte *)*local_c8);
       uVar11 = uVar12;
       if (bVar2 == 0) {
         puVar9 = (undefined8 *)&gBfsPolicyTable;
         uVar7 = BfsGetNotPresentPolicyEntry
                           (0x1c0016200,(byte *)*local_d0,(byte *)*local_c8,&local_e0);
         lVar10 = local_e0;
         uVar3 = (uint)uVar7;
         uVar1 = local_e8;
         if ((int)(uint)uVar7 < 0) goto joined_r0x0001c0004c71;
 LAB_0:
         local_e4 = '\0';
         puVar6 = (ushort *)0x0;
         uVar3 = RtlCheckTokenCapability
                           (0,*(undefined8 *)(*(longlong *)SeExports_exref + 0x250),&local_e4);
         if ((int)uVar3 < 0) {
           if (uVar3 != 0xc0000022) goto LAB_1;
 LAB_2:
           if ((local_d8 == 0) &&
              (uVar3 = FltGetFileNameInformation(param_4,0x101,&local_d8), puVar6 = param_4,
              (int)uVar3 < 0)) goto LAB_1;
           lVar8 = *param_5;
           if (lVar8 != 0) {
 LAB_3:
             *(undefined4 *)(lVar8 + 8) = 1;
             FltReferenceFileNameInformation(local_d8);
             *(longlong *)(*param_5 + 0x30) = local_d8;
             *(longlong *)(*param_5 + 0x40) = lVar10;
             LOCK();
             *(int *)(lVar10 + 0x90) = *(int *)(lVar10 + 0x90) + 1;
             UNLOCK();
             uVar11 = 1;
             *(uint *)*param_5 = *(uint *)*param_5 | 1;
             lVar10 = local_e0;
             uVar1 = local_e8;
             goto LAB_4;
           }
           puVar6 = (ushort *)0x100;
           lVar8 = ExAllocatePool2(0x100,0x58,0x43736642);
           *param_5 = lVar8;
           if (lVar8 != 0) goto LAB_3;
           uVar1 = local_e8;
-          if (DAT_5 < 4) goto LAB_1c0004d94;
+          if (DAT_5 < 4) goto LAB_1c0004de8;
           local_e8 = 0xc0000017;
         }
         else {
           if (local_e4 == '\0') goto LAB_2;
           puVar6 = param_3;
           uVar3 = BfsFileInPublisherDirectory(param_3,local_d8,(ushort *)local_e3,&local_b0);
           if ((int)uVar3 < 0) goto LAB_1;
           if (local_e3[0] == '\0') goto LAB_2;
           if (lVar10 == 0) {
 LAB_6:
+            puVar9 = param_1;
             uVar5 = BfsGetPolicyEntry(param_1,param_2,0x1c0016200,(byte *)*local_d0,
                                       (byte *)*local_c8,&local_e0);
             lVar10 = local_e0;
             uVar3 = (uint)uVar5;
-            puVar9 = param_1;
             uVar1 = local_e8;
             if ((int)(uint)uVar5 < 0) goto joined_r0x0001c0004c71;
           }
           else if (*(int *)(lVar10 + 0x38) == 2) {
             BfsDereferencePolicyEntryEx(lVar10,'\0');
             goto LAB_6;
+          }
+          uVar5 = Feature_1827994938__private_IsEnabledDeviceUsageNoInline();
+          if (((int)uVar5 != 0) && (*(int *)(lVar10 + 0x38) == 0x10000001)) {
+            uVar5 = BfsGetPolicyEntry(param_1,param_2,0x1c0016200,(byte *)*local_d0,
+                                      (byte *)*local_c8,&local_e0);
+            lVar10 = local_e0;
+            puVar9 = param_1;
+            uVar3 = (uint)uVar5;
+            uVar1 = local_e8;
+            if ((int)(uint)uVar5 < 0) goto joined_r0x0001c0004c71;
+            BfsDereferencePolicyEntryEx(local_e0,'\0');
           }
           BfsAddOrModifyEntry(*(longlong *)(lVar10 + 0x30),2,1,2,(ushort *)(local_d8 + 0x18),
                               (short *)&local_b0);
 LAB_7:
           uVar3 = BfsApplyPolicyAsUser((longlong)param_4,(longlong)param_3,local_d8,lVar10,param_5);
           puVar6 = param_4;
           if (-1 < (int)uVar3) {
             uVar11 = 1;
             uVar1 = local_e8;
             goto LAB_4;
           }
 LAB_1:
           uVar1 = local_e8;
           local_e8 = uVar3;
-          if (DAT_5 < 4) goto LAB_1c0004d94;
+          if (DAT_5 < 4) goto LAB_1c0004de8;
         }
         local_60 = &local_e8;
         local_58 = 4;
         _tlgWriteTransfer_EtwWriteTransfer(puVar6,&DAT_8);
         uVar1 = local_e8;
       }
       else {
         puVar9 = param_1;
         uVar5 = BfsGetPolicyEntry(param_1,param_2,0x1c0016200,(byte *)*local_d0,(byte *)*local_c8,
                                   &local_e0);
         uVar3 = (uint)uVar5;
         uVar1 = local_e8;
         if ((int)(uint)uVar5 < 0) {
 joined_r0x0001c0004c71:
           local_e8 = uVar3;
           lVar10 = local_e0;
           if (3 < DAT_5) {
             local_58 = 4;
             local_60 = &local_e8;
             _tlgWriteTransfer_EtwWriteTransfer(puVar9,&DAT_8);
             lVar10 = local_e0;
             uVar1 = local_e8;
           }
         }
         else {
           lVar8 = local_d8;
           puVar6 = BfsGetFileName(local_90,local_d8);
           lVar10 = local_e0;
           local_a0 = *(undefined8 *)puVar6;
           uStack_98 = *(undefined8 *)(puVar6 + 4);
           uVar5 = BfsGetPolicy(*(longlong *)(local_e0 + 0x30),(ushort *)(lVar8 + 0x18),&local_a0);
           iVar4 = (int)uVar5;
           if (iVar4 == 0) goto LAB_0;
           if (iVar4 == 1) goto LAB_7;
           uVar1 = local_e8;
           if (iVar4 == 2) {
             uVar7 = BfsQueryAccessOnly((*(uint *)(*(longlong *)(param_4 + 8) + 0x20) & 1) + 1,
                                        (longlong)param_4);
             if ((char)uVar7 != '\0') goto LAB_7;
             uVar7 = BfsQueryAccessOnly((*(uint *)(*(longlong *)(param_4 + 8) + 0x20) & 1) + 1,
                                        (longlong)param_4);
             uVar1 = local_e8;
             if ((char)uVar7 == '\0') goto LAB_2;
           }
         }
       }
 LAB_4:
       local_e8 = uVar1;
       uVar1 = local_e8;
       if (lVar10 != 0) {
         BfsDereferencePolicyEntryEx(lVar10,'\0');
         uVar1 = local_e8;
       }
       goto LAB_9;
     }
   }
   local_e8 = uVar3;
   if (3 < DAT_5) {
     local_60 = &local_e8;
     local_58 = 4;
     _tlgWriteTransfer_EtwWriteTransfer(puVar6,&DAT_8);
     uVar1 = local_e8;
   }
 LAB_9:
   local_e8 = uVar1;
   if (local_d8 != 0) {
     FltReleaseFileNameInformation();
   }
   if (local_d0 != (undefined8 *)0x0) {
     ExFreePoolWithTag(local_d0,0);
   }
   if (local_c8 != (undefined8 *)0x0) {
     ExFreePoolWithTag(local_c8,0);
   }
   return uVar11;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## wil_details_IsEnabledFallback

### Match Info



|Key|bfs_4484.sys - bfs_4652.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs_4484.sys|bfs_4652.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|5|7|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_2777415992__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|Feature_1827994938__private_IsEnabledFallback<br>Feature_2777415992__private_IsEnabledFallback<br>Feature_3148938554__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|
|paramcount|3|3|
|address|1c0003ff8|1c0003ff8|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -0,0 +1 @@
+Feature_1827994938__private_IsEnabledFallback
@@ -1,0 +3 @@
+Feature_3148938554__private_IsEnabledFallback
```


## BfsDereferencePolicyEntryEx

### Match Info



|Key|bfs_4484.sys - bfs_4652.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs_4484.sys|bfs_4652.sys|
| :---: | :---: | :---: |
|name|BfsDereferencePolicyEntryEx|BfsDereferencePolicyEntryEx|
|fullname|BfsDereferencePolicyEntryEx|BfsDereferencePolicyEntryEx|
|`refcount`|19|20|
|length|343|343|
|called|BfsCloseStorage<br>BfsRemoveEntryHashTable<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion|BfsCloseStorage<br>BfsRemoveEntryHashTable<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion|
|calling|<details><summary>Expand for full list:<br>BfsCheckAndApplyPolicy<br>BfsCheckAndReleaseIdlePolicy<br>BfsDeleteFileFromGlobalFileTable<br>BfsGetPolicyEntry<br>BfsGetRegistryPrefix<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPerformPrompt<br>BfsPostCreateOperation<br>BfsProcessQueryPolicyRequest<br>BfsProcessQueryPolicySizeRequest</summary>BfsProcessSetPolicyRequest<br>BfsRemovePolicyEntry<br>BfsUninitializePolicyTable</details>|<details><summary>Expand for full list:<br>BfsCheckAndApplyPolicy<br>BfsCheckAndReleaseIdlePolicy<br>BfsDeleteFileFromGlobalFileTable<br>BfsGetPolicyEntry<br>BfsGetRegistryPrefix<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPerformPrompt<br>BfsPostCreateOperation<br>BfsProcessQueryPolicyRequest<br>BfsProcessQueryPolicySizeRequest</summary>BfsProcessSetPolicyRequest<br>BfsRemovePolicyEntry<br>BfsUninitializePolicyTable</details>|
|paramcount|2|2|
|`address`|1c0004fa8|1c0004ffc|
|sig|undefined __fastcall BfsDereferencePolicyEntryEx(longlong param_1, char param_2)|undefined __fastcall BfsDereferencePolicyEntryEx(longlong param_1, char param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-19T18:44:04</sub>