# bfs-4768.sys-bfs-4946.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_1122292024__private_IsEnabledDeviceUsageNoInline](#feature_1122292024__private_isenableddeviceusagenoinline)
	* [Feature_1122292024__private_IsEnabledFallback](#feature_1122292024__private_isenabledfallback)
	* [NTOSKRNL.EXE::ZwQueryInformationFile](#ntoskrnlexezwqueryinformationfile)
* [Modified](#modified)
	* [BfsGetPolicyEntry](#bfsgetpolicyentry)
	* [BfsCreateStorage](#bfscreatestorage)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)

# Visual Chart Diff



```mermaid

flowchart LR

BfsGetPolicyEntry-6-old<--Match 86%-->BfsGetPolicyEntry-6-new
BfsCreateStorage-5-old<--Match 83%-->BfsCreateStorage-5-new

subgraph bfs-4946.sys
    BfsGetPolicyEntry-6-new
BfsCreateStorage-5-new
    subgraph Added
direction LR
Feature_1122292024__private_IsEnabledDeviceUsageNoInline
    Feature_1122292024__private_IsEnabledFallback
    NTOSKRNLEXE-ZwQueryInformationFile
end
end

subgraph bfs-4768.sys
    BfsGetPolicyEntry-6-old
BfsCreateStorage-5-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.6149%
"unmatched_funcs_len" : 3
"matched_funcs_len" : 776
```



```mermaid
pie showData
    title Matched Function Similarity - 99.6134%
"matched_funcs_with_code_changes_len" : 2
"matched_funcs_with_non_code_changes_len" : 1
"matched_funcs_no_changes_len" : 773
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj --project-name bfs-53142 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 bfs-4768.sys bfs-4946.sys
```


#### Verbose Args


<details>

```
--old ['bfs-4768.sys'] --new [['bfs-4946.sys']] --engine VersionTrackingDiff --output-path ./out --summary False --project-location ./proj --project-name bfs-53142 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/6E61E6CE21000/Bfs.sys -O bfs.sys.x64.10.0.26100.4768
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/F76C682121000/Bfs.sys -O bfs.sys.x64.10.0.26100.4946
```


## Binary Metadata Diff


```diff
--- bfs-4768.sys Meta
+++ bfs-4946.sys Meta
@@ -1,44 +1,44 @@
-Program Name: bfs-4768.sys
+Program Name: bfs-4946.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
 # of Bytes: 141392
 # of Memory Blocks: 13
-# of Instructions: 17323
-# of Defined Data: 1337
-# of Functions: 388
-# of Symbols: 2807
+# of Instructions: 17384
+# of Defined Data: 1371
+# of Functions: 391
+# of Symbols: 2824
 # of Data Types: 346
 # of Data Type Categories: 22
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sun Aug 16 12:16:28 SGT 2026
+Date Created: Sun Aug 16 12:16:32 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4768.sys
-Executable MD5: 863190f536e93744cb3b95fafe2c97cb
-Executable SHA256: b48b506471d541a47125d3017d458b0ed736f4dacb693ed5db0af36f82bc0974
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4768.sys?MD5=863190f536e93744cb3b95fafe2c97cb
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4946.sys
+Executable MD5: b0390a01b6fe7821bd0f7ce0e2c1bc4f
+Executable SHA256: 34c6bec796e53af24c22c969fca04e363b289ffffb103fac1cd9fd49c40b567d
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4946.sys?MD5=b0390a01b6fe7821bd0f7ce0e2c1bc4f
 PDB Age: 1
 PDB File: bfs.pdb
-PDB GUID: f9aa3571-55b5-c01e-12b0-c32ea765a245
+PDB GUID: 84469e2f-7da0-5e19-71a8-53947cfbd22a
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Bfs Filter Driver
-PE Property[FileVersion]: 10.0.26100.4768 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.4946 (WinBuild.160101.0800)
 PE Property[InternalName]: Bfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Bfs.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.4768
+PE Property[ProductVersion]: 10.0.26100.4946
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra bfs-4768.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs-4768.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs-4768.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra bfs-4946.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs-4946.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs-4946.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|3|
|deleted_funcs_len|0|
|modified_funcs_len|3|
|added_symbols_len|4|
|deleted_symbols_len|0|
|diff_time|2.730213165283203|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 387, 'ExternalsName': 185})|
|items_to_process|10|
|diff_types|Counter({'code': 2, 'length': 2, 'called': 2, 'refcount': 1, 'calling': 1, 'address': 1})|
|unmatched_funcs_len|3|
|total_funcs_len|779|
|matched_funcs_len|776|
|matched_funcs_with_code_changes_len|2|
|matched_funcs_with_non_code_changes_len|1|
|matched_funcs_no_changes_len|773|
|match_func_similarity_percent|99.6134%|
|func_match_overall_percent|99.6149%|
|first_matches|Counter({'SymbolsHash': 387})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 387
"ExternalsName" : 185
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 387
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 3
"deleted_funcs_len" : 0
"modified_funcs_len" : 3
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 4
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_1122292024__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|bfs-4946.sys|
| :---: | :---: |
|name|Feature_1122292024__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_1122292024__private_IsEnabledDeviceUsageNoInline|
|refcount|3|
|length|49|
|called|Feature_1122292024__private_IsEnabledFallback|
|calling|BfsCreateStorage<br>BfsGetPolicyEntry|
|paramcount|0|
|address|1c0009018|
|sig|ulonglong __fastcall Feature_1122292024__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1122292024__private_IsEnabledDeviceUsageNoInline
+++ Feature_1122292024__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_1122292024__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_1122292024__private_featureState;
+  if ((Feature_1122292024__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_1122292024__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_1122292024__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_1122292024__private_IsEnabledFallback

### Function Meta



|Key|bfs-4946.sys|
| :---: | :---: |
|name|Feature_1122292024__private_IsEnabledFallback|
|fullname|Feature_1122292024__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_1122292024__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1c0009050|
|sig|undefined __fastcall Feature_1122292024__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1122292024__private_IsEnabledFallback
+++ Feature_1122292024__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_1122292024__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_1122292024__private_descriptor);
+  return;
+}
+

```


## NTOSKRNL.EXE::ZwQueryInformationFile

### Function Meta



|Key|bfs-4946.sys|
| :---: | :---: |
|name|ZwQueryInformationFile|
|fullname|NTOSKRNL.EXE::ZwQueryInformationFile|
|refcount|2|
|length|0|
|called||
|calling|BfsCreateStorage|
|paramcount|0|
|address|EXTERNAL:0000004b|
|sig|undefined ZwQueryInformationFile(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTOSKRNL.EXE::ZwQueryInformationFile*
# Modified


*Modified functions contain code changes*
## BfsGetPolicyEntry

### Match Info



|Key|bfs-4768.sys - bfs-4946.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.61|
|i_ratio|0.74|
|m_ratio|0.99|
|b_ratio|0.86|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs-4768.sys|bfs-4946.sys|
| :---: | :---: | :---: |
|name|BfsGetPolicyEntry|BfsGetPolicyEntry|
|fullname|BfsGetPolicyEntry|BfsGetPolicyEntry|
|refcount|10|10|
|`length`|527|544|
|`called`|<details><summary>Expand for full list:<br>BfsDereferencePolicyEntryEx<br>BfsFinalHash<br>BfsInsertPolicyEntry<br>BfsLookupPolicyEntryHashTable<br>BfsUpdateHash<br>NTOSKRNL.EXE::ExAcquirePushLockSharedEx<br>NTOSKRNL.EXE::ExReleasePushLockSharedEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>NTOSKRNL.EXE::RtlLengthSid</summary>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|<details><summary>Expand for full list:<br>BfsDereferencePolicyEntryEx<br>BfsFinalHash<br>BfsInsertPolicyEntry<br>BfsLookupPolicyEntryHashTable<br>BfsUpdateHash<br>Feature_1122292024__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquirePushLockSharedEx<br>NTOSKRNL.EXE::ExReleasePushLockSharedEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeWaitForSingleObject</summary>NTOSKRNL.EXE::RtlLengthSid<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer</details>|
|calling|BfsCheckAndApplyPolicy<br>BfsDeleteFileFromGlobalFileTable<br>BfsGetRegistryPrefix<br>BfsPerformPrompt<br>BfsProcessQueryPolicyRequest<br>BfsProcessQueryPolicySizeRequest<br>BfsProcessSetPolicyRequest|BfsCheckAndApplyPolicy<br>BfsDeleteFileFromGlobalFileTable<br>BfsGetRegistryPrefix<br>BfsPerformPrompt<br>BfsProcessQueryPolicyRequest<br>BfsProcessQueryPolicySizeRequest<br>BfsProcessSetPolicyRequest|
|paramcount|6|6|
|address|1c0005e48|1c0005e48|
|sig|ulonglong __fastcall BfsGetPolicyEntry(undefined8 * param_1, undefined8 param_2, longlong param_3, byte * param_4, byte * param_5, longlong * param_6)|ulonglong __fastcall BfsGetPolicyEntry(undefined8 * param_1, undefined8 param_2, longlong param_3, byte * param_4, byte * param_5, longlong * param_6)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsGetPolicyEntry Called Diff


```diff
--- BfsGetPolicyEntry called
+++ BfsGetPolicyEntry called
@@ -5,0 +6 @@
+Feature_1122292024__private_IsEnabledDeviceUsageNoInline
```


### BfsGetPolicyEntry Diff


```diff
--- BfsGetPolicyEntry
+++ BfsGetPolicyEntry
@@ -1,80 +1,89 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 ulonglong BfsGetPolicyEntry(undefined8 *param_1,undefined8 param_2,longlong param_3,byte *param_4,
                            byte *param_5,longlong *param_6)
 
 {
   uint uVar1;
   undefined8 uVar2;
   longlong lVar3;
   ulonglong uVar4;
   ulonglong uVar5;
+  ulonglong uVar6;
   undefined1 auStackY_d8 [32];
   longlong local_98;
   longlong local_90;
   undefined8 local_88;
   longlong *local_60;
   undefined4 local_58;
   undefined4 local_54;
   ulonglong local_50;
   
   local_50 = __security_cookie ^ (ulonglong)auStackY_d8;
   local_98 = 0;
   local_88 = param_2;
   uVar1 = RtlLengthSid(param_4);
   BfsUpdateHash(param_4,uVar1,&local_98);
   uVar1 = RtlLengthSid(param_5);
   BfsUpdateHash(param_5,uVar1,&local_98);
   uVar2 = BfsFinalHash(&local_98);
   *param_6 = 0;
   KeEnterCriticalRegion();
   ExAcquirePushLockSharedEx(param_3,0);
   lVar3 = BfsLookupPolicyEntryHashTable(*(undefined8 *)(param_3 + 8),uVar2,param_4,param_5);
   local_90 = lVar3;
   if ((lVar3 == 0) || ((*(uint *)(lVar3 + 0x38) & 0x10000000) == 0)) {
     ExReleasePushLockSharedEx(param_3,0);
     KeLeaveCriticalRegion();
     uVar4 = BfsInsertPolicyEntry
                       (param_1,local_88,param_3,uVar2,(longlong)param_4,(longlong)param_5,&local_90)
     ;
-    uVar5 = uVar4 & 0xffffffff;
-    if (-1 < (int)uVar4) goto LAB_0;
-    if (DAT_2 < 4) goto LAB_1c0006007;
-    local_98 = CONCAT44(local_98._4_4_,(int)uVar4);
+    uVar6 = uVar4 & 0xffffffff;
+    uVar5 = Feature_1122292024__private_IsEnabledDeviceUsageNoInline();
+    if ((int)uVar5 == 0) {
+      if ((int)uVar4 < 0) goto LAB_0;
+    }
+    else if ((int)uVar4 < 0) {
+      return uVar6;
+    }
   }
   else {
     LOCK();
     *(int *)(lVar3 + 0x90) = *(int *)(lVar3 + 0x90) + 1;
     UNLOCK();
-    uVar5 = 0;
+    uVar6 = 0;
     ExReleasePushLockSharedEx(param_3);
     KeLeaveCriticalRegion();
-    if (*(int *)(lVar3 + 0x38) != 0x10000001) {
+    if (*(int *)(lVar3 + 0x38) == 0x10000001) {
+      param_1 = *(undefined8 **)(lVar3 + 0x28);
+      KeWaitForSingleObject(param_1,0,0,0);
+      if (*(int *)(lVar3 + 0x38) != 0x10000000) {
+        uVar6 = 0xc0000001;
 LAB_0:
-      LOCK();
-      *(undefined8 *)(local_90 + 0x60) = _DAT_3;
-      UNLOCK();
-      *param_6 = local_90;
-      return uVar5;
+        if (3 < DAT_1) {
+          local_54 = 0;
+          local_60 = &local_98;
+          local_98 = CONCAT44(local_98._4_4_,(int)uVar6);
+          local_58 = 4;
+          _tlgWriteTransfer_EtwWriteTransfer(param_1,&DAT_2);
+        }
+        goto LAB_3;
+      }
     }
-    param_1 = *(undefined8 **)(lVar3 + 0x28);
-    KeWaitForSingleObject(param_1,0,0,0);
-    if (*(int *)(lVar3 + 0x38) == 0x10000000) goto LAB_0;
-    uVar5 = 0xc0000001;
-    if (DAT_2 < 4) goto LAB_1c0006007;
-    local_98 = CONCAT44(local_98._4_4_,0xc0000001);
   }
-  local_54 = 0;
-  local_60 = &local_98;
-  local_58 = 4;
-  _tlgWriteTransfer_EtwWriteTransfer(param_1,&DAT_4);
-LAB_1:
-  if (local_90 == 0) {
-    return uVar5;
+  LOCK();
+  *(undefined8 *)(local_90 + 0x60) = _DAT_4;
+  UNLOCK();
+  *param_6 = local_90;
+  if (-1 < (int)uVar6) {
+    return uVar6;
   }
-  BfsDereferencePolicyEntryEx(local_90,'\0');
-  return uVar5;
+LAB_3:
+  if (local_90 != 0) {
+    BfsDereferencePolicyEntryEx(local_90,'\0');
+  }
+  return uVar6;
 }
 

```


## BfsCreateStorage

### Match Info



|Key|bfs-4768.sys - bfs-4946.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.31|
|i_ratio|0.49|
|m_ratio|0.93|
|b_ratio|0.83|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs-4768.sys|bfs-4946.sys|
| :---: | :---: | :---: |
|name|BfsCreateStorage|BfsCreateStorage|
|fullname|BfsCreateStorage|BfsCreateStorage|
|refcount|3|3|
|`length`|1025|1187|
|`called`|<details><summary>Expand for full list:<br>BfsAllocateBlock<br>BfsOpenRootDirectory<br>BfsReadBlock<br>BfsWriteBlock<br>FLTMGR.SYS::FltClose<br>FLTMGR.SYS::FltCreateFileEx2<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExInitializePushLock<br>NTOSKRNL.EXE::RtlInitializeBitMap<br>NTOSKRNL.EXE::RtlInitializeGenericTableAvl</summary>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer<br>memset</details>|<details><summary>Expand for full list:<br>BfsAllocateBlock<br>BfsOpenRootDirectory<br>BfsReadBlock<br>BfsWriteBlock<br>FLTMGR.SYS::FltClose<br>FLTMGR.SYS::FltCreateFileEx2<br>Feature_1122292024__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExInitializePushLock<br>NTOSKRNL.EXE::RtlInitializeBitMap</summary>NTOSKRNL.EXE::RtlInitializeGenericTableAvl<br>NTOSKRNL.EXE::ZwQueryInformationFile<br>__security_check_cookie<br>_tlgWriteTransfer_EtwWriteTransfer<br>memset</details>|
|calling|BfsInsertPolicyEntry<br>BfsLoadUserPolicyEntriesToGlobalFileTable|BfsInsertPolicyEntry<br>BfsLoadUserPolicyEntriesToGlobalFileTable|
|paramcount|5|5|
|`address`|1c000e89c|1c000e8fc|
|sig|ulonglong __fastcall BfsCreateStorage(undefined4 * param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4, undefined8 * param_5)|ulonglong __fastcall BfsCreateStorage(undefined4 * param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4, undefined8 * param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsCreateStorage Called Diff


```diff
--- BfsCreateStorage called
+++ BfsCreateStorage called
@@ -6,0 +7 @@
+Feature_1122292024__private_IsEnabledDeviceUsageNoInline
@@ -11,0 +13 @@
+NTOSKRNL.EXE::ZwQueryInformationFile
```


### BfsCreateStorage Diff


```diff
--- BfsCreateStorage
+++ BfsCreateStorage
@@ -1,201 +1,245 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 ulonglong BfsCreateStorage(undefined4 *param_1,undefined8 param_2,undefined8 param_3,
                           undefined8 param_4,undefined8 *param_5)
 
 {
   uint uVar1;
   uint uVar2;
   undefined4 *puVar3;
-  undefined4 *_Dst;
   ulonglong uVar4;
   undefined4 *puVar5;
   undefined4 *puVar6;
   undefined4 *puVar7;
-  undefined1 auStack_148 [32];
+  undefined4 *puVar8;
+  undefined1 auStack_188 [32];
+  undefined4 local_168;
+  undefined4 uStack_164;
+  undefined8 *local_160;
+  undefined8 *local_158;
+  undefined8 local_150;
+  undefined4 local_148;
+  undefined4 local_140;
+  undefined4 local_138;
+  undefined4 local_130;
   undefined8 local_128;
-  undefined8 *local_120;
-  undefined8 *local_118;
+  undefined4 local_120;
+  undefined4 local_118;
   undefined8 local_110;
-  undefined4 local_108;
-  undefined4 local_100;
-  undefined4 local_f8;
-  undefined4 local_f0;
-  undefined8 local_e8;
-  undefined4 local_e0;
-  undefined4 local_d8;
+  uint local_108;
+  int local_104;
+  undefined4 *local_100;
+  undefined8 local_f8;
+  longlong lStack_f0;
+  undefined8 *local_e8;
+  undefined8 local_e0;
+  undefined8 local_d8;
   undefined8 local_d0;
-  uint local_c8;
-  int local_c4;
-  longlong local_c0;
-  undefined8 *local_b8;
+  undefined8 local_c8;
+  undefined *local_c0;
+  undefined8 local_b8;
   undefined8 local_b0;
-  undefined8 local_a8;
-  undefined8 local_a0;
-  undefined8 local_98;
-  undefined *local_90;
-  undefined8 local_88;
-  undefined8 local_80;
-  longlong lStack_78;
-  undefined8 local_70 [4];
+  undefined8 uStack_a8;
+  undefined8 local_a0 [4];
+  uint *local_80;
+  undefined8 local_78;
+  undefined8 local_70;
+  longlong lStack_68;
+  undefined8 local_60;
   uint *local_50;
   undefined8 local_48;
   ulonglong local_40;
   
-  local_40 = __security_cookie ^ (ulonglong)auStack_148;
-  puVar6 = (undefined4 *)0x0;
-  local_d0 = 0;
-  local_b8 = param_5;
-  local_d8 = 0x100;
-  local_e0 = 0;
-  local_e8 = 0;
+  local_40 = __security_cookie ^ (ulonglong)auStack_188;
   puVar7 = (undefined4 *)0x0;
-  local_f0 = 0x860;
-  local_f8 = 3;
-  local_100 = 0;
+  local_110 = 0;
+  local_e8 = param_5;
+  local_118 = 0x100;
+  local_120 = 0;
+  local_128 = 0;
+  puVar8 = (undefined4 *)0x0;
+  local_130 = 0x860;
+  local_138 = 3;
+  local_140 = 0;
   *param_5 = 0;
-  local_108 = 0x80;
-  local_90 = &gBfsPolicyStorageFileDescriptor;
-  local_118 = &local_80;
-  local_110 = 0;
-  local_120 = &local_b0;
-  local_128 = CONCAT44(local_128._4_4_,0xc0110000);
-  local_80 = 0;
-  lStack_78 = 0;
-  local_b0 = 0x30;
-  local_98 = 0x240;
-  local_c0 = 0;
-  local_88 = 0;
-  local_a8 = param_3;
-  local_a0 = param_4;
-  uVar2 = FltCreateFileEx2(0,param_2,&local_c0,0);
+  local_148 = 0x80;
+  local_c0 = &gBfsPolicyStorageFileDescriptor;
+  local_158 = &local_f8;
+  local_150 = 0;
+  local_160 = &local_e0;
+  local_168 = 0xc0110000;
+  local_f8 = 0;
+  lStack_f0 = 0;
+  local_e0 = 0x30;
+  local_c8 = 0x240;
+  local_100 = (undefined4 *)0x0;
+  local_b8 = 0;
+  local_d8 = param_3;
+  local_d0 = param_4;
+  uVar2 = FltCreateFileEx2(0,param_2,&local_100,0);
   uVar4 = (ulonglong)uVar2;
-  _Dst = puVar6;
-  puVar3 = puVar6;
-  puVar5 = puVar6;
-  if ((int)uVar2 < 0) goto LAB_0;
-  param_1 = (undefined4 *)0x100;
-  puVar3 = (undefined4 *)ExAllocatePool2(0x100,200,0x73736642);
-  if (puVar3 == (undefined4 *)0x0) {
-LAB_1:
-    uVar2 = 0xc0000017;
-    uVar4 = 0xc0000017;
+  puVar3 = puVar7;
+  puVar5 = puVar7;
+  puVar6 = puVar7;
+  if ((int)uVar2 < 0) {
 LAB_0:
-    puVar6 = puVar5;
-    if (3 < DAT_2) {
-LAB_3:
-      local_c8 = uVar2;
-      local_50 = &local_c8;
+    if (3 < DAT_1) {
+      local_50 = &local_108;
+      local_160 = &local_70;
       local_48 = 4;
-      local_120 = local_70;
-      _tlgWriteTransfer_EtwWriteTransfer(param_1,&DAT_4);
+      local_108 = uVar2;
+LAB_2:
+      _tlgWriteTransfer_EtwWriteTransfer(param_1,&DAT_3);
     }
   }
   else {
+    param_1 = (undefined4 *)0x100;
+    puVar3 = (undefined4 *)ExAllocatePool2(0x100,200,0x73736642);
+    if (puVar3 == (undefined4 *)0x0) {
+      uVar2 = 0xc0000017;
+      uVar4 = 0xc0000017;
+      goto LAB_0;
+    }
     ExInitializePushLock(puVar3);
-    *(longlong *)(puVar3 + 2) = local_c0;
-    puVar5 = puVar7;
-    if (lStack_78 != 2) {
+    *(undefined4 **)(puVar3 + 2) = local_100;
+    uVar4 = Feature_1122292024__private_IsEnabledDeviceUsageNoInline();
+    if ((int)uVar4 == 0) {
+LAB_4:
+      if (lStack_f0 == 2) goto LAB_5;
       param_1 = (undefined4 *)0x100;
-      _Dst = (undefined4 *)ExAllocatePool2(0x100,0x4000,0x63736642);
-      if (_Dst != (undefined4 *)0x0) {
+      puVar5 = (undefined4 *)ExAllocatePool2(0x100,0x4000,0x63736642);
+      puVar6 = puVar8;
+      if (puVar5 != (undefined4 *)0x0) {
         param_1 = puVar3;
-        uVar2 = BfsReadBlock((longlong)puVar3,0,_Dst);
+        uVar2 = BfsReadBlock((longlong)puVar3,0,puVar5);
         uVar4 = (ulonglong)uVar2;
         if (-1 < (int)uVar2) {
-          *(undefined4 **)(puVar3 + 4) = _Dst;
-          RtlInitializeBitMap(puVar3 + 6,_Dst + 6,0x1ff40);
+          *(undefined4 **)(puVar3 + 4) = puVar5;
+          RtlInitializeBitMap(puVar3 + 6,puVar5 + 6,0x1ff40);
           param_1 = puVar3;
           uVar2 = BfsOpenRootDirectory((longlong)puVar3);
           uVar4 = (ulonglong)uVar2;
-          if (-1 < (int)uVar2) {
-            ExInitializePushLock(puVar3 + 0x12);
-            local_128 = 0;
-            RtlInitializeGenericTableAvl
-                      (puVar3 + 0x14,BfsCompareTableEntries,BfsAllocateTableEntry,BfsFreeTableEntry)
-            ;
+          if ((int)uVar2 < 0) goto LAB_6;
+          ExInitializePushLock(puVar3 + 0x12);
+          local_168 = 0;
+          uStack_164 = 0;
+          RtlInitializeGenericTableAvl
+                    (puVar3 + 0x14,BfsCompareTableEntries,BfsAllocateTableEntry,BfsFreeTableEntry);
+LAB_7:
+          *local_e8 = puVar3;
+          goto LAB_8;
+        }
+        goto LAB_6;
+      }
+LAB_9:
+      uVar2 = 0xc0000017;
+      uVar4 = 0xc0000017;
+LAB_6:
+      if (DAT_1 < 4) goto LAB_1c000ece5;
+LAB_11:
+      local_108 = uVar2;
+      local_80 = &local_108;
+      local_78 = 4;
+      local_160 = local_a0;
+      goto LAB_2;
+    }
+    if (lStack_f0 != 2) {
+      local_168 = 5;
+      local_b0 = 0;
+      uStack_a8 = 0;
+      local_60 = 0;
+      local_70 = 0;
+      lStack_68 = 0;
+      param_1 = local_100;
+      uVar2 = ZwQueryInformationFile(local_100,&local_b0,&local_70,0x18);
+      uVar4 = (ulonglong)uVar2;
+      if (-1 < (int)uVar2) {
+        if (lStack_68 == 0) {
+          lStack_f0 = 2;
+        }
+        goto LAB_4;
+      }
+      goto LAB_6;
+    }
 LAB_5:
-            *local_b8 = puVar3;
-            goto LAB_6;
-          }
-        }
-        goto LAB_0;
-      }
-      goto LAB_1;
-    }
-    local_c4 = 0;
-    local_c8 = 0;
+    local_104 = 0;
+    local_108 = 0;
     param_1 = (undefined4 *)0x100;
-    _Dst = (undefined4 *)ExAllocatePool2();
-    if (_Dst == (undefined4 *)0x0) goto LAB_1;
-    memset(_Dst,0,0x4000);
-    *_Dst = 0x43736642;
-    _Dst[2] = 0x4000;
-    _Dst[1] = _Dst[1] & 0xff000001 | 1;
-    *(undefined1 *)((longlong)_Dst + 7) = 0;
-    *(undefined4 **)(puVar3 + 4) = _Dst;
-    RtlInitializeBitMap(puVar3 + 6,_Dst + 6,0x1ff40);
+    puVar5 = (undefined4 *)ExAllocatePool2(0x100,0x4000,0x63736642);
+    if (puVar5 == (undefined4 *)0x0) goto LAB_9;
+    memset(puVar5,0,0x4000);
+    *puVar5 = 0x43736642;
+    puVar5[2] = 0x4000;
+    puVar5[1] = puVar5[1] & 0xff000001 | 1;
+    *(undefined1 *)((longlong)puVar5 + 7) = 0;
+    *(undefined4 **)(puVar3 + 4) = puVar5;
+    RtlInitializeBitMap(puVar3 + 6,puVar5 + 6,0x1ff40);
     ExInitializePushLock(puVar3 + 0x12);
-    local_128 = 0;
+    local_168 = 0;
+    uStack_164 = 0;
     RtlInitializeGenericTableAvl
               (puVar3 + 0x14,BfsCompareTableEntries,BfsAllocateTableEntry,BfsFreeTableEntry);
     param_1 = puVar3;
-    uVar4 = BfsAllocateBlock((longlong)puVar3,&local_c4);
+    uVar4 = BfsAllocateBlock((longlong)puVar3,&local_104);
     uVar2 = (uint)uVar4;
     uVar4 = uVar4 & 0xffffffff;
-    if ((int)uVar2 < 0) goto LAB_0;
-    if (local_c4 == 0) {
+    puVar6 = puVar8;
+    if ((int)uVar2 < 0) goto LAB_6;
+    if (local_104 == 0) {
       param_1 = puVar3;
-      uVar4 = BfsAllocateBlock((longlong)puVar3,(int *)&local_c8);
-      uVar1 = local_c8;
+      uVar4 = BfsAllocateBlock((longlong)puVar3,(int *)&local_108);
+      uVar1 = local_108;
       uVar2 = (uint)uVar4;
       uVar4 = uVar4 & 0xffffffff;
       if (-1 < (int)uVar2) {
         param_1 = (undefined4 *)0x100;
-        *(uint *)(*(longlong *)(puVar3 + 4) + 0xc) = local_c8;
-        puVar5 = (undefined4 *)ExAllocatePool2(0x100,0x4000,0x62736642);
-        if (puVar5 == (undefined4 *)0x0) goto LAB_1;
-        memset(puVar5 + 1,0,0x3ffc);
-        *puVar5 = 0x44736642;
+        *(uint *)(*(longlong *)(puVar3 + 4) + 0xc) = local_108;
+        puVar6 = (undefined4 *)ExAllocatePool2(0x100,0x4000,0x62736642);
+        if (puVar6 == (undefined4 *)0x0) goto LAB_9;
+        memset(puVar6 + 1,0,0x3ffc);
+        *puVar6 = 0x44736642;
         param_1 = puVar3;
-        uVar2 = BfsWriteBlock((longlong)puVar3,local_c4,_Dst);
+        uVar2 = BfsWriteBlock((longlong)puVar3,local_104,puVar5);
         uVar4 = (ulonglong)uVar2;
         if (-1 < (int)uVar2) {
           param_1 = puVar3;
-          uVar2 = BfsWriteBlock((longlong)puVar3,uVar1,puVar5);
+          uVar2 = BfsWriteBlock((longlong)puVar3,uVar1,puVar6);
           uVar4 = (ulonglong)uVar2;
           if (-1 < (int)uVar2) {
             param_1 = puVar3;
             uVar2 = BfsOpenRootDirectory((longlong)puVar3);
             uVar4 = (ulonglong)uVar2;
-            puVar6 = puVar5;
-            if (-1 < (int)uVar2) goto LAB_5;
+            puVar7 = puVar6;
+            if (-1 < (int)uVar2) goto LAB_7;
           }
         }
       }
-      goto LAB_0;
+      goto LAB_6;
     }
     uVar4 = 0xc0000032;
-    if (3 < DAT_2) {
-      local_c8 = 0xc0000032;
-      uVar2 = local_c8;
-      goto LAB_3;
-    }
-  }
-  if (local_c0 != 0) {
+    if (3 < DAT_1) {
+      local_108 = 0xc0000032;
+      puVar6 = puVar7;
+      uVar2 = local_108;
+      goto LAB_11;
+    }
+  }
+LAB_10:
+  puVar7 = puVar6;
+  if (local_100 != (undefined4 *)0x0) {
     FltClose();
   }
   if (puVar3 != (undefined4 *)0x0) {
     ExFreePoolWithTag(puVar3,0);
   }
-  if (_Dst != (undefined4 *)0x0) {
-    ExFreePoolWithTag(_Dst,0);
-  }
-LAB_6:
-  if (puVar6 != (undefined4 *)0x0) {
-    ExFreePoolWithTag(puVar6,0);
+  if (puVar5 != (undefined4 *)0x0) {
+    ExFreePoolWithTag(puVar5,0);
+  }
+LAB_8:
+  if (puVar7 != (undefined4 *)0x0) {
+    ExFreePoolWithTag(puVar7,0);
   }
   return uVar4;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## wil_details_IsEnabledFallback

### Match Info



|Key|bfs-4768.sys - bfs-4946.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs-4768.sys|bfs-4946.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|7|8|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1827994938__private_IsEnabledFallback<br>Feature_2777415992__private_IsEnabledFallback<br>Feature_3148938554__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|Feature_1122292024__private_IsEnabledFallback<br>Feature_1827994938__private_IsEnabledFallback<br>Feature_2777415992__private_IsEnabledFallback<br>Feature_3148938554__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|
|paramcount|3|3|
|address|1c0003ff8|1c0003ff8|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -0,0 +1 @@
+Feature_1122292024__private_IsEnabledFallback
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-16T12:16:57</sub>