# bfs-4946.sys-bfs-6584.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_3434922298__private_IsEnabledDeviceUsageNoInline](#feature_3434922298__private_isenableddeviceusagenoinline)
	* [Feature_3434922298__private_IsEnabledFallback](#feature_3434922298__private_isenabledfallback)
* [Modified](#modified)
	* [BfsCheckAndReleaseIdlePolicy](#bfscheckandreleaseidlepolicy)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [NTOSKRNL.EXE::ExReleasePushLockExclusiveEx](#ntoskrnlexeexreleasepushlockexclusiveex)
	* [NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx](#ntoskrnlexeexacquirepushlockexclusiveex)
	* [NTOSKRNL.EXE::KeEnterCriticalRegion](#ntoskrnlexekeentercriticalregion)
	* [NTOSKRNL.EXE::KeLeaveCriticalRegion](#ntoskrnlexekeleavecriticalregion)

# Visual Chart Diff



```mermaid

flowchart LR

BfsCheckAndReleaseIdlePolicy-1-old<--Match 78%-->BfsCheckAndReleaseIdlePolicy-1-new

subgraph bfs-6584.sys
    BfsCheckAndReleaseIdlePolicy-1-new
    subgraph Added
direction LR
Feature_3434922298__private_IsEnabledDeviceUsageNoInline
    Feature_3434922298__private_IsEnabledFallback
end
end

subgraph bfs-4946.sys
    BfsCheckAndReleaseIdlePolicy-1-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.7449%
"unmatched_funcs_len" : 2
"matched_funcs_len" : 782
```



```mermaid
pie showData
    title Matched Function Similarity - 99.2327%
"matched_funcs_with_code_changes_len" : 1
"matched_funcs_with_non_code_changes_len" : 5
"matched_funcs_no_changes_len" : 776
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj54105 --project-name bfs-54105 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 bfs-4946.sys bfs-6584.sys
```


#### Verbose Args


<details>

```
--old ['bfs-4946.sys'] --new [['bfs-6584.sys']] --engine VersionTrackingDiff --output-path ./out54105 --summary False --project-location ./proj54105 --project-name bfs-54105 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/F76C682121000/Bfs.sys -O bfs.sys.x64.10.0.26100.4946
wget https://msdl.microsoft.com/download/symbols/Bfs.sys/0ED7042921000/Bfs.sys -O bfs.sys.x64.10.0.26100.6584
```


## Binary Metadata Diff


```diff
--- bfs-4946.sys Meta
+++ bfs-6584.sys Meta
@@ -1,44 +1,44 @@
-Program Name: bfs-4946.sys
+Program Name: bfs-6584.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
-Minimum Address: 1c0000000
+Minimum Address: 140000000
 Maximum Address: ff0000184f
 # of Bytes: 141392
 # of Memory Blocks: 13
-# of Instructions: 17384
-# of Defined Data: 1347
-# of Functions: 391
-# of Symbols: 2824
+# of Instructions: 17430
+# of Defined Data: 1355
+# of Functions: 393
+# of Symbols: 2833
 # of Data Types: 346
 # of Data Type Categories: 22
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sun Aug 16 12:30:33 SGT 2026
+Date Created: Sun Aug 16 12:30:36 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4946.sys
-Executable MD5: b0390a01b6fe7821bd0f7ce0e2c1bc4f
-Executable SHA256: 34c6bec796e53af24c22c969fca04e363b289ffffb103fac1cd9fd49c40b567d
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-4946.sys?MD5=b0390a01b6fe7821bd0f7ce0e2c1bc4f
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-6584.sys
+Executable MD5: 84489a318a09ed2ab135437662b9a796
+Executable SHA256: d3ce3d0314cc9552eec9617afc0930bb168cdbbfb1b925ade4d048bc90a089c6
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/bfs-53142/bfs-6584.sys?MD5=84489a318a09ed2ab135437662b9a796
 PDB Age: 1
 PDB File: bfs.pdb
-PDB GUID: 84469e2f-7da0-5e19-71a8-53947cfbd22a
+PDB GUID: d8fa6165-e430-dd7d-d0dd-7ad16052fb80
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Bfs Filter Driver
-PE Property[FileVersion]: 10.0.26100.4946 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.6584 (WinBuild.160101.0800)
 PE Property[InternalName]: Bfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Bfs.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.4946
+PE Property[ProductVersion]: 10.0.26100.6584
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra bfs-4946.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs-4946.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs-4946.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra bfs-6584.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra bfs-6584.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra bfs-6584.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|2|
|deleted_funcs_len|0|
|modified_funcs_len|6|
|added_symbols_len|3|
|deleted_symbols_len|0|
|diff_time|2.561852216720581|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 390, 'ExternalsName': 186})|
|items_to_process|11|
|diff_types|Counter({'refcount': 5, 'address': 2, 'calling': 1, 'code': 1, 'length': 1, 'called': 1})|
|unmatched_funcs_len|2|
|total_funcs_len|784|
|matched_funcs_len|782|
|matched_funcs_with_code_changes_len|1|
|matched_funcs_with_non_code_changes_len|5|
|matched_funcs_no_changes_len|776|
|match_func_similarity_percent|99.2327%|
|func_match_overall_percent|99.7449%|
|first_matches|Counter({'SymbolsHash': 390})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 390
"ExternalsName" : 186
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 390
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 2
"deleted_funcs_len" : 0
"modified_funcs_len" : 6
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 3
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_3434922298__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|bfs-6584.sys|
| :---: | :---: |
|name|Feature_3434922298__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_3434922298__private_IsEnabledDeviceUsageNoInline|
|refcount|6|
|length|49|
|called|Feature_3434922298__private_IsEnabledFallback|
|calling|BfsCheckAndReleaseIdlePolicy|
|paramcount|0|
|address|140009174|
|sig|ulonglong __fastcall Feature_3434922298__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3434922298__private_IsEnabledDeviceUsageNoInline
+++ Feature_3434922298__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_3434922298__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_3434922298__private_featureState;
+  if ((Feature_3434922298__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_3434922298__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_3434922298__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_3434922298__private_IsEnabledFallback

### Function Meta



|Key|bfs-6584.sys|
| :---: | :---: |
|name|Feature_3434922298__private_IsEnabledFallback|
|fullname|Feature_3434922298__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_3434922298__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1400091ac|
|sig|undefined __fastcall Feature_3434922298__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3434922298__private_IsEnabledFallback
+++ Feature_3434922298__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_3434922298__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_3434922298__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## BfsCheckAndReleaseIdlePolicy

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.37|
|i_ratio|0.57|
|m_ratio|0.88|
|b_ratio|0.78|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|BfsCheckAndReleaseIdlePolicy|BfsCheckAndReleaseIdlePolicy|
|fullname|BfsCheckAndReleaseIdlePolicy|BfsCheckAndReleaseIdlePolicy|
|refcount|2|2|
|`length`|396|505|
|`called`|BfsDereferencePolicyEntryEx<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAcquirePushLockSharedEx<br>NTOSKRNL.EXE::ExCancelTimer<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::ExReleasePushLockSharedEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion|BfsDereferencePolicyEntryEx<br>Feature_3434922298__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExAcquirePushLockSharedEx<br>NTOSKRNL.EXE::ExCancelTimer<br>NTOSKRNL.EXE::ExReleasePushLockExclusiveEx<br>NTOSKRNL.EXE::ExReleasePushLockSharedEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion|
|calling|BfsIdleCheckWorkitemRoutine|BfsIdleCheckWorkitemRoutine|
|paramcount|1|1|
|`address`|1c0004e68|140004e68|
|sig|undefined __fastcall BfsCheckAndReleaseIdlePolicy(longlong param_1)|undefined __fastcall BfsCheckAndReleaseIdlePolicy(longlong param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### BfsCheckAndReleaseIdlePolicy Called Diff


```diff
--- BfsCheckAndReleaseIdlePolicy called
+++ BfsCheckAndReleaseIdlePolicy called
@@ -1,0 +2 @@
+Feature_3434922298__private_IsEnabledDeviceUsageNoInline
```


### BfsCheckAndReleaseIdlePolicy Diff


```diff
--- BfsCheckAndReleaseIdlePolicy
+++ BfsCheckAndReleaseIdlePolicy
@@ -1,90 +1,118 @@
 
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void BfsCheckAndReleaseIdlePolicy(longlong param_1)
 
 {
   undefined8 *puVar1;
   int *piVar2;
-  undefined8 ***pppuVar3;
-  undefined8 ***pppuVar4;
-  int iVar5;
-  undefined8 uVar6;
-  code *pcVar7;
+  int iVar3;
+  undefined8 ****ppppuVar4;
+  undefined8 uVar5;
+  code *pcVar6;
+  ulonglong uVar7;
   undefined8 *puVar8;
-  undefined8 ***pppuVar9;
-  undefined1 *puVar10;
+  undefined1 *puVar9;
+  undefined8 ****ppppuVar10;
   undefined1 auStack_38 [8];
   undefined1 auStack_30 [24];
-  undefined8 **local_18;
-  undefined8 **local_10;
+  undefined8 ***local_18;
+  undefined8 ***local_10;
   
-  puVar10 = auStack_38;
+  puVar9 = auStack_38;
   local_10 = &local_18;
-  pppuVar9 = (undefined8 ***)(_DAT_0 + -3000000000);
+  ppppuVar10 = (undefined8 ****)(_DAT_0 + -3000000000);
   local_18 = &local_18;
-  KeEnterCriticalRegion();
-  ExAcquirePushLockSharedEx(param_1,0);
+  uVar7 = Feature_3434922298__private_IsEnabledDeviceUsageNoInline();
+  if ((int)uVar7 == 0) {
+    KeEnterCriticalRegion();
+    ExAcquirePushLockSharedEx(param_1,0);
+  }
+  else {
+    KeEnterCriticalRegion();
+    ExAcquirePushLockExclusiveEx(param_1,0);
+  }
   puVar1 = (undefined8 *)(param_1 + 0x10);
   puVar8 = (undefined8 *)*puVar1;
   do {
     if (puVar8 == puVar1) {
-      ExReleasePushLockSharedEx(param_1,0);
-      KeLeaveCriticalRegion();
-      if ((undefined8 ***)local_18 != &local_18) {
+      uVar7 = Feature_3434922298__private_IsEnabledDeviceUsageNoInline();
+      if ((int)uVar7 == 0) {
+        ExReleasePushLockSharedEx(param_1,0);
+        KeLeaveCriticalRegion();
+      }
+      if ((undefined8 ****)local_18 != &local_18) {
+        uVar7 = Feature_3434922298__private_IsEnabledDeviceUsageNoInline();
+        puVar9 = auStack_38;
+        ppppuVar10 = (undefined8 ****)local_18;
+        if ((int)uVar7 != 0) goto LAB_1;
         KeEnterCriticalRegion();
         ExAcquirePushLockExclusiveEx(param_1,0);
-        pppuVar9 = (undefined8 ***)local_18;
-        while (pppuVar9 != &local_18) {
-LAB_1:
-          pppuVar3 = pppuVar9 + -10;
-          pppuVar4 = pppuVar9 + 8;
-          pppuVar9 = (undefined8 ***)*pppuVar9;
-          if (*(int *)pppuVar4 == 2) {
-            *(undefined8 *)(puVar10 + -8) = 0x1c0004f93;
-            BfsDereferencePolicyEntryEx((longlong)pppuVar3,'\x01');
-          }
-          *(undefined8 *)(puVar10 + -8) = 0x1c0004f9d;
-          BfsDereferencePolicyEntryEx((longlong)pppuVar3,'\x01');
-        }
-        if ((undefined8 *)*puVar1 == puVar1) {
-          uVar6 = *(undefined8 *)(param_1 + 0x20);
-          *(undefined8 *)(puVar10 + -8) = 0x1c0004fb8;
-          ExCancelTimer(uVar6,0);
-        }
-        *(undefined8 *)(puVar10 + -8) = 0x1c0004fc9;
+        puVar9 = auStack_38;
+        ppppuVar10 = (undefined8 ****)local_18;
+        goto LAB_1;
+      }
+LAB_2:
+      *(undefined8 *)(puVar9 + -8) = 0x140005026;
+      uVar7 = Feature_3434922298__private_IsEnabledDeviceUsageNoInline();
+      if ((int)uVar7 != 0) {
+        *(undefined8 *)(puVar9 + -8) = 0x140005036;
         ExReleasePushLockExclusiveEx(param_1,0);
-        *(undefined8 *)(puVar10 + -8) = 0x1c0004fd5;
+        *(undefined8 *)(puVar9 + -8) = 0x140005042;
         KeLeaveCriticalRegion();
       }
       return;
     }
-    if ((longlong)puVar8[4] < (longlong)pppuVar9) {
+    if ((longlong)puVar8[4] < (longlong)ppppuVar10) {
       LOCK();
       piVar2 = (int *)(puVar8 + 10);
-      iVar5 = *piVar2;
+      iVar3 = *piVar2;
       *piVar2 = *piVar2 + 1;
       UNLOCK();
-      if (iVar5 == 1) {
-        pppuVar3 = (undefined8 ***)(puVar8 + 2);
-        if ((undefined8 ***)*local_10 != &local_18) {
-          pcVar7 = (code *)swi(0x29);
-          (*pcVar7)(3);
-          puVar10 = auStack_30;
-          goto LAB_1;
+      if (iVar3 == 1) {
+        ppppuVar4 = (undefined8 ****)(puVar8 + 2);
+        if ((undefined8 ****)*local_10 != &local_18) {
+          pcVar6 = (code *)swi(0x29);
+          (*pcVar6)(3);
+          puVar9 = auStack_30;
+          do {
+            ppppuVar4 = (undefined8 ****)*ppppuVar10;
+            if (*(int *)(ppppuVar10 + 8) == 2) {
+              *(undefined8 *)(puVar9 + -8) = 0x140004fd1;
+              BfsDereferencePolicyEntryEx((longlong)(ppppuVar10 + -10),'\x01');
+            }
+            *(undefined8 *)(puVar9 + -8) = 0x140004fdb;
+            BfsDereferencePolicyEntryEx((longlong)(ppppuVar10 + -10),'\x01');
+            ppppuVar10 = ppppuVar4;
+LAB_1:
+          } while (ppppuVar10 != &local_18);
+          if ((undefined8 *)*puVar1 == puVar1) {
+            uVar5 = *(undefined8 *)(param_1 + 0x20);
+            *(undefined8 *)(puVar9 + -8) = 0x140004ff6;
+            ExCancelTimer(uVar5,0);
+          }
+          *(undefined8 *)(puVar9 + -8) = 0x140005000;
+          uVar7 = Feature_3434922298__private_IsEnabledDeviceUsageNoInline();
+          if ((int)uVar7 == 0) {
+            *(undefined8 *)(puVar9 + -8) = 0x140005010;
+            ExReleasePushLockExclusiveEx(param_1,0);
+            *(undefined8 *)(puVar9 + -8) = 0x14000501c;
+            KeLeaveCriticalRegion();
+          }
+          goto LAB_2;
         }
         puVar8[3] = local_10;
-        *pppuVar3 = &local_18;
-        *local_10 = pppuVar3;
-        local_10 = pppuVar3;
+        *ppppuVar4 = &local_18;
+        *local_10 = ppppuVar4;
+        local_10 = ppppuVar4;
       }
       else {
         LOCK();
         *(int *)(puVar8 + 10) = *(int *)(puVar8 + 10) + -1;
         UNLOCK();
       }
     }
     puVar8 = (undefined8 *)*puVar8;
   } while( true );
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## wil_details_IsEnabledFallback

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|8|9|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1122292024__private_IsEnabledFallback<br>Feature_1827994938__private_IsEnabledFallback<br>Feature_2777415992__private_IsEnabledFallback<br>Feature_3148938554__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|Feature_1122292024__private_IsEnabledFallback<br>Feature_1827994938__private_IsEnabledFallback<br>Feature_2777415992__private_IsEnabledFallback<br>Feature_3148938554__private_IsEnabledFallback<br>Feature_3434922298__private_IsEnabledFallback<br>Feature_752421176__private_IsEnabledFallback<br>Feature_AppSiloEnumeratePolicyCheck__private_IsEnabledFallback<br>Feature_Servicing_BfsGAFeature__private_IsEnabledFallback|
|paramcount|3|3|
|`address`|1c0003ff8|140003ff8|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -4,0 +5 @@
+Feature_3434922298__private_IsEnabledFallback
```


## NTOSKRNL.EXE::ExReleasePushLockExclusiveEx

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|ExReleasePushLockExclusiveEx|ExReleasePushLockExclusiveEx|
|fullname|NTOSKRNL.EXE::ExReleasePushLockExclusiveEx|NTOSKRNL.EXE::ExReleasePushLockExclusiveEx|
|`refcount`|36|37|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsExpandDirectory<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping</summary>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPostCreateOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable</details>|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsExpandDirectory<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping</summary>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPostCreateOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable</details>|
|paramcount|0|0|
|address|EXTERNAL:00000018|EXTERNAL:00000018|
|sig|undefined ExReleasePushLockExclusiveEx(void)|undefined ExReleasePushLockExclusiveEx(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|ExAcquirePushLockExclusiveEx|ExAcquirePushLockExclusiveEx|
|fullname|NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx|NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx|
|`refcount`|28|29|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsExpandDirectory<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping</summary>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPostCreateOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable</details>|<details><summary>Expand for full list:<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsExpandDirectory<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping</summary>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsPostCreateOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable</details>|
|paramcount|0|0|
|address|EXTERNAL:00000017|EXTERNAL:00000017|
|sig|undefined ExAcquirePushLockExclusiveEx(void)|undefined ExAcquirePushLockExclusiveEx(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## NTOSKRNL.EXE::KeEnterCriticalRegion

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|KeEnterCriticalRegion|KeEnterCriticalRegion|
|fullname|NTOSKRNL.EXE::KeEnterCriticalRegion|NTOSKRNL.EXE::KeEnterCriticalRegion|
|`refcount`|51|52|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>BfsAcquireNamedPipeMapping<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsCreateDirectory<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsDeviceIoControl<br>BfsEnumerateDirectory</summary>BfsEnumeratePolicy<br>BfsExpandDirectory<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsIdleCheckWorkitemRoutine<br>BfsInitializeGlobalFileTable<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsLocateDirectory<br>BfsPolicyEntryExists<br>BfsPostCreateOperation<br>BfsPreCreateOperation<br>BfsPreCreatePipeOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable<br>BfsUnload</details>|<details><summary>Expand for full list:<br>BfsAcquireNamedPipeMapping<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsCreateDirectory<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsDeviceIoControl<br>BfsEnumerateDirectory</summary>BfsEnumeratePolicy<br>BfsExpandDirectory<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsIdleCheckWorkitemRoutine<br>BfsInitializeGlobalFileTable<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsLocateDirectory<br>BfsPolicyEntryExists<br>BfsPostCreateOperation<br>BfsPreCreateOperation<br>BfsPreCreatePipeOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable<br>BfsUnload</details>|
|paramcount|0|0|
|address|EXTERNAL:00000081|EXTERNAL:00000081|
|sig|undefined KeEnterCriticalRegion(void)|undefined KeEnterCriticalRegion(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## NTOSKRNL.EXE::KeLeaveCriticalRegion

### Match Info



|Key|bfs-4946.sys - bfs-6584.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|bfs-4946.sys|bfs-6584.sys|
| :---: | :---: | :---: |
|name|KeLeaveCriticalRegion|KeLeaveCriticalRegion|
|fullname|NTOSKRNL.EXE::KeLeaveCriticalRegion|NTOSKRNL.EXE::KeLeaveCriticalRegion|
|`refcount`|66|67|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>BfsAcquireNamedPipeMapping<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsCreateDirectory<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsDeviceIoControl<br>BfsEnumerateDirectory</summary>BfsEnumeratePolicy<br>BfsExpandDirectory<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsIdleCheckWorkitemRoutine<br>BfsInitializeGlobalFileTable<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsLocateDirectory<br>BfsPolicyEntryExists<br>BfsPostCreateOperation<br>BfsPreCreateOperation<br>BfsPreCreatePipeOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable<br>BfsUnload</details>|<details><summary>Expand for full list:<br>BfsAcquireNamedPipeMapping<br>BfsAddOrModifyEntry<br>BfsAddPolicyToGlobalFileTable<br>BfsCheckAndReleaseIdlePolicy<br>BfsCheckDeleteList<br>BfsCreateDirectory<br>BfsDeleteEntry<br>BfsDereferencePolicyEntryEx<br>BfsDereferenceTableEntry<br>BfsDeviceIoControl<br>BfsEnumerateDirectory</summary>BfsEnumeratePolicy<br>BfsExpandDirectory<br>BfsGetNotPresentPolicyEntry<br>BfsGetPolicy<br>BfsGetPolicyEntry<br>BfsIdleCheckWorkitemRoutine<br>BfsInitializeGlobalFileTable<br>BfsInsertDirectory<br>BfsInsertDirectoryEntry<br>BfsInsertNamedPipeMapping<br>BfsInsertNotPresentPolicyEntry<br>BfsInsertPolicyEntry<br>BfsLocateDirectory<br>BfsPolicyEntryExists<br>BfsPostCreateOperation<br>BfsPreCreateOperation<br>BfsPreCreatePipeOperation<br>BfsProcessDelete<br>BfsReleaseNamedPipeMapping<br>BfsRemovePolicyEntry<br>BfsRemovePolicyFromGlobalFileTable<br>BfsUninitializePipeMappingTable<br>BfsUnload</details>|
|paramcount|0|0|
|address|EXTERNAL:00000083|EXTERNAL:00000083|
|sig|undefined KeLeaveCriticalRegion(void)|undefined KeLeaveCriticalRegion(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-16T12:31:03</sub>