# clfs_1301.sys-clfs_1455.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [WPP_SF_sdLL](#wpp_sf_sdll)
* [Added](#added)
* [Modified](#modified)
	* [CClfsBaseFilePersisted::WriteMetadataBlock](#cclfsbasefilepersistedwritemetadatablock)
	* [CClfsBaseFilePersisted::ExtendMetadataBlock](#cclfsbasefilepersistedextendmetadatablock)
	* [CClfsBaseFile::OffsetToAddr](#cclfsbasefileoffsettoaddr)
	* [CClfsBaseFile::ReleaseMetadataBlock](#cclfsbasefilereleasemetadatablock)
	* [CClfsLogFcbPhysical::MapCacheData](#cclfslogfcbphysicalmapcachedata)
	* [CClfsBaseFile::GetSymbol](#cclfsbasefilegetsymbol)
	* [CClfsBaseFile::AcquireSharedSecurityContext](#cclfsbasefileacquiresharedsecuritycontext)
	* [CClfsBaseFilePersisted::OpenImage](#cclfsbasefilepersistedopenimage)
	* [`CClfsBaseFilePersisted::CreateImage'::__l1::fin$0](#cclfsbasefilepersistedcreateimage__l1fin0)
	* [CClfsBaseFile::GetControlRecord](#cclfsbasefilegetcontrolrecord)
	* [CClfsLogFcbPhysical::UpdateCachedOwnerPage](#cclfslogfcbphysicalupdatecachedownerpage)
	* [CClfsBaseFile::ValidateRgOffsets](#cclfsbasefilevalidatergoffsets)
	* [CClfsBaseFile::ValidateOffsets](#cclfsbasefilevalidateoffsets)
	* [CClfsBaseFilePersisted::FlushControlRecord](#cclfsbasefilepersistedflushcontrolrecord)
	* [CClfsBaseFile::ValidateContainerContextOffsets](#cclfsbasefilevalidatecontainercontextoffsets)
	* [CClfsBaseFilePersisted::FlushImage](#cclfsbasefilepersistedflushimage)
	* [WPP_SF_sdLLH](#wpp_sf_sdllh)
	* [CClfsLogFcbPhysical::ReadLogBlock](#cclfslogfcbphysicalreadlogblock)
	* [CClfsBaseFile::ValidateProcessQNode](#cclfsbasefilevalidateprocessqnode)
	* [CClfsLogFcbPhysical::CacheBlock](#cclfslogfcbphysicalcacheblock)
	* [wil_details_FeatureReporting_ReportUsageToServiceDirect](#wil_details_featurereporting_reportusagetoservicedirect)
	* [CClfsBaseFilePersisted::CreateImage](#cclfsbasefilepersistedcreateimage)
	* [CClfsBaseFile::GetSymbol](#cclfsbasefilegetsymbol)
	* [wil_details_FeatureReporting_ReportUsageToService](#wil_details_featurereporting_reportusagetoservice)
	* [CClfsBaseFile::ValidateClientContextOffsets](#cclfsbasefilevalidateclientcontextoffsets)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [CClfsLogFcbPhysical::FindEndOfLog](#cclfslogfcbphysicalfindendoflog)
	* [CClfsLogFcbPhysical::ValidateRegionBlocks](#cclfslogfcbphysicalvalidateregionblocks)
	* [CClfsLogFcbPhysical::ToggleEphemeral](#cclfslogfcbphysicaltoggleephemeral)
	* [`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0](#cclfsbasefilepersistedextendmetadatablock__l1fin0)
	* [`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0](#cclfsbasefilepersistedwritemetadatablock__l1fin0)
	* [wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath](#wil_details_featurestatecache_tryenabledeviceusagefastpath)
	* [Feature_2458037564__private_IsEnabledFallback](#feature_2458037564__private_isenabledfallback)
	* [Feature_1868496191__private_IsEnabledFallback](#feature_1868496191__private_isenabledfallback)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [LsnToCacheOffset](#lsntocacheoffset)
	* [ReleaseContainerContext](#releasecontainercontext)
	* [RemoveSymbol](#removesymbol)
	* [GetBaseLogRecord](#getbaselogrecord)
	* [WPP_SF_sl](#wpp_sf_sl)
	* [ReleaseSharedSecurityDescriptor](#releasesharedsecuritydescriptor)
	* [memcpy](#memcpy)
	* [NTOSKRNL.EXE::RtlCompareMemory](#ntoskrnlexertlcomparememory)

# Visual Chart Diff



```mermaid

flowchart LR

CClfsBaseFilePersistedWriteMetadataBlock-3-old<--Match 13%-->CClfsBaseFilePersistedWriteMetadataBlock-3-new
CClfsBaseFilePersistedExtendMetadataBlock-3-old<--Match 79%-->CClfsBaseFilePersistedExtendMetadataBlock-3-new
CClfsBaseFileOffsetToAddr-2-old<--Match 56%-->CClfsBaseFileOffsetToAddr-2-new
CClfsBaseFileReleaseMetadataBlock-2-old<--Match 76%-->CClfsBaseFileReleaseMetadataBlock-2-new
CClfsLogFcbPhysicalMapCacheData-7-old<--Match 91%-->CClfsLogFcbPhysicalMapCacheData-7-new
CClfsBaseFileGetSymbol-4-old<--Match 88%-->CClfsBaseFileGetSymbol-4-new
CClfsBaseFileAcquireSharedSecurityContext-3-old<--Match 98%-->CClfsBaseFileAcquireSharedSecurityContext-3-new
CClfsBaseFilePersistedOpenImage-5-old<--Match 88%-->CClfsBaseFilePersistedOpenImage-5-new
CClfsBaseFilePersistedCreateImage__l1fin0-2-old<--Match 98%-->CClfsBaseFilePersistedCreateImage__l1fin0-2-new
CClfsBaseFileGetControlRecord-3-old<--Match 78%-->CClfsBaseFileGetControlRecord-3-new
CClfsLogFcbPhysicalUpdateCachedOwnerPage-4-old<--Match 59%-->CClfsLogFcbPhysicalUpdateCachedOwnerPage-4-new
CClfsBaseFileValidateRgOffsets-3-old<--Match 94%-->CClfsBaseFileValidateRgOffsets-3-new
CClfsBaseFileValidateOffsets-2-old<--Match 71%-->CClfsBaseFileValidateOffsets-2-new
CClfsBaseFilePersistedFlushControlRecord-1-old<--Match 93%-->CClfsBaseFilePersistedFlushControlRecord-1-new
CClfsBaseFileValidateContainerContextOffsets-3-old<--Match 98%-->CClfsBaseFileValidateContainerContextOffsets-3-new
CClfsBaseFilePersistedFlushImage-1-old<--Match 70%-->CClfsBaseFilePersistedFlushImage-1-new
WPP_SF_sdLLH-2-old<--Match 92%-->WPP_SF_sdLLH-2-new
CClfsLogFcbPhysicalReadLogBlock-10-old<--Match 96%-->CClfsLogFcbPhysicalReadLogBlock-10-new
CClfsBaseFileValidateProcessQNode-6-old<--Match 97%-->CClfsBaseFileValidateProcessQNode-6-new
CClfsLogFcbPhysicalCacheBlock-4-old<--Match 96%-->CClfsLogFcbPhysicalCacheBlock-4-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-old<--Match 95%-->wil_details_FeatureReporting_ReportUsageToServiceDirect-3-new
CClfsBaseFilePersistedCreateImage-8-old<--Match 68%-->CClfsBaseFilePersistedCreateImage-8-new
CClfsBaseFileGetSymbol-4-old<--Match 80%-->CClfsBaseFileGetSymbol-4-new
wil_details_FeatureReporting_ReportUsageToService-3-old<--Match 94%-->wil_details_FeatureReporting_ReportUsageToService-3-new
CClfsBaseFileValidateClientContextOffsets-3-old<--Match 99%-->CClfsBaseFileValidateClientContextOffsets-3-new
wil_details_IsEnabledFallback-3-old<--Match 94%-->wil_details_IsEnabledFallback-3-new
clfs_1301.sys<--9ommited-->clfs_1455.sys

subgraph clfs_1455.sys
    CClfsBaseFilePersistedWriteMetadataBlock-3-new
CClfsBaseFilePersistedExtendMetadataBlock-3-new
CClfsBaseFileOffsetToAddr-2-new
CClfsBaseFileReleaseMetadataBlock-2-new
CClfsLogFcbPhysicalMapCacheData-7-new
CClfsBaseFileGetSymbol-4-new
CClfsBaseFileAcquireSharedSecurityContext-3-new
CClfsBaseFilePersistedOpenImage-5-new
CClfsBaseFilePersistedCreateImage__l1fin0-2-new
CClfsBaseFileGetControlRecord-3-new
CClfsLogFcbPhysicalUpdateCachedOwnerPage-4-new
CClfsBaseFileValidateRgOffsets-3-new
CClfsBaseFileValidateOffsets-2-new
CClfsBaseFilePersistedFlushControlRecord-1-new
CClfsBaseFileValidateContainerContextOffsets-3-new
CClfsBaseFilePersistedFlushImage-1-new
WPP_SF_sdLLH-2-new
CClfsLogFcbPhysicalReadLogBlock-10-new
CClfsBaseFileValidateProcessQNode-6-new
CClfsLogFcbPhysicalCacheBlock-4-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-new
CClfsBaseFilePersistedCreateImage-8-new
CClfsBaseFileGetSymbol-4-new
wil_details_FeatureReporting_ReportUsageToService-3-new
CClfsBaseFileValidateClientContextOffsets-3-new
wil_details_IsEnabledFallback-3-new
    
end

subgraph clfs_1301.sys
    CClfsBaseFilePersistedWriteMetadataBlock-3-old
CClfsBaseFilePersistedExtendMetadataBlock-3-old
CClfsBaseFileOffsetToAddr-2-old
CClfsBaseFileReleaseMetadataBlock-2-old
CClfsLogFcbPhysicalMapCacheData-7-old
CClfsBaseFileGetSymbol-4-old
CClfsBaseFileAcquireSharedSecurityContext-3-old
CClfsBaseFilePersistedOpenImage-5-old
CClfsBaseFilePersistedCreateImage__l1fin0-2-old
CClfsBaseFileGetControlRecord-3-old
CClfsLogFcbPhysicalUpdateCachedOwnerPage-4-old
CClfsBaseFileValidateRgOffsets-3-old
CClfsBaseFileValidateOffsets-2-old
CClfsBaseFilePersistedFlushControlRecord-1-old
CClfsBaseFileValidateContainerContextOffsets-3-old
CClfsBaseFilePersistedFlushImage-1-old
WPP_SF_sdLLH-2-old
CClfsLogFcbPhysicalReadLogBlock-10-old
CClfsBaseFileValidateProcessQNode-6-old
CClfsLogFcbPhysicalCacheBlock-4-old
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-old
CClfsBaseFilePersistedCreateImage-8-old
CClfsBaseFileGetSymbol-4-old
wil_details_FeatureReporting_ReportUsageToService-3-old
CClfsBaseFileValidateClientContextOffsets-3-old
wil_details_IsEnabledFallback-3-old
    subgraph Deleted
direction LR
WPP_SF_sdLL
end
end

```


```mermaid
pie showData
    title Function Matches - 99.9724%
"unmatched_funcs_len" : 1
"matched_funcs_len" : 3622
```



```mermaid
pie showData
    title Matched Function Similarity - 98.6748%
"matched_funcs_with_code_changes_len" : 34
"matched_funcs_with_non_code_changes_len" : 14
"matched_funcs_no_changes_len" : 3574
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --max-ram-percent 60.0 --max-section-funcs 200 clfs_1301.sys clfs_1455.sys
```


#### Verbose Args


<details>

```
--old ['clfs_1301.sys'] --new [['clfs_1455.sys']] --engine VersionTrackingDiff --output-path clfs_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim False --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/253E228B86000/Clfs.Sys -O clfs.sys.x64.10.0.26100.1301
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/240E2DFF86000/Clfs.Sys -O clfs.sys.x64.10.0.26100.1455
```


## Binary Metadata Diff


```diff
--- clfs_1301.sys Meta
+++ clfs_1455.sys Meta
@@ -1,44 +1,44 @@
-Program Name: clfs_1301.sys
+Program Name: clfs_1455.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
-# of Bytes: 553000
+# of Bytes: 552928
 # of Memory Blocks: 14
-# of Instructions: 98049
-# of Defined Data: 3615
-# of Functions: 1813
-# of Symbols: 13930
+# of Instructions: 97780
+# of Defined Data: 3613
+# of Functions: 1810
+# of Symbols: 13903
 # of Data Types: 468
 # of Data Type Categories: 20
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sat Aug 22 13:50:34 SGT 2026
+Date Created: Sat Aug 22 13:50:37 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/clfs38/clfs_1301.sys
-Executable MD5: 3638700af2276425888c26f5a8f0905f
-Executable SHA256: 12ea662173adb00e038c8d9403e749ed73fb09b752a58430c8518eb670f0fe0b
-FSRL: file:///tmp/clfs38/clfs_1301.sys?MD5=3638700af2276425888c26f5a8f0905f
+Executable Location: /tmp/clfs38/clfs_1455.sys
+Executable MD5: 3497cc5ebe56582b93801ce7ae57b582
+Executable SHA256: b1782f78ca4f26082d331c269a7a3e554461963016746502efea481ff9cc3b13
+FSRL: file:///tmp/clfs38/clfs_1455.sys?MD5=3497cc5ebe56582b93801ce7ae57b582
 PDB Age: 1
 PDB File: clfs.pdb
-PDB GUID: 0f149475-b9a6-f036-7bdd-9c09bcf416fb
+PDB GUID: 8562e530-29b7-c579-6131-bdede9c8fe9e
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Common Log File System Driver
-PE Property[FileVersion]: 10.0.26100.1301 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.1455 (WinBuild.160101.0800)
 PE Property[InternalName]: clfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Clfs.Sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.1301
+PE Property[ProductVersion]: 10.0.26100.1455
 PE Property[Translation]: 4b00000
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra clfs_1301.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs_1301.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs_1301.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra clfs_1455.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs_1455.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs_1455.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|0|
|deleted_funcs_len|1|
|modified_funcs_len|48|
|added_symbols_len|6|
|deleted_symbols_len|9|
|diff_time|3.967658519744873|
|deleted_strings_len|0|
|added_strings_len|1|
|match_types|Counter({'SymbolsHash': 1795, 'ExternalsName': 244, 'ExactInstructionsFunctionHasher': 11, 'BulkBasicBlockMnemonicHash': 2, 'Implied Match': 2, 'ExactBytesFunctionHasher': 1})|
|items_to_process|64|
|diff_types|Counter({'address': 43, 'length': 39, 'code': 34, 'called': 19, 'calling': 15, 'refcount': 14, 'sig': 9, 'name': 4, 'fullname': 4})|
|unmatched_funcs_len|1|
|total_funcs_len|3623|
|matched_funcs_len|3622|
|matched_funcs_with_code_changes_len|34|
|matched_funcs_with_non_code_changes_len|14|
|matched_funcs_no_changes_len|3574|
|match_func_similarity_percent|98.6748%|
|func_match_overall_percent|99.9724%|
|first_matches|Counter({'SymbolsHash': 1795, 'ExactInstructionsFunctionHasher': 11, 'BulkBasicBlockMnemonicHash': 2, 'Implied Match': 2, 'ExactBytesFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1795
"ExternalsName" : 244
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 11
"BulkBasicBlockMnemonicHash" : 2
"Implied-Match" : 2
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1795
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 11
"BulkBasicBlockMnemonicHash" : 2
"Implied-Match" : 2
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 0
"deleted_funcs_len" : 1
"modified_funcs_len" : 48
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 6
"deleted_symbols_len" : 9
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 1
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1 @@
+s_CClfsBaseFilePersisted::FlushIm

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_CClfsBaseFilePersisted::FlushIm|1|FlushImage|

# Deleted

## WPP_SF_sdLL

### Function Meta



|Key|clfs_1301.sys|
| :---: | :---: |
|name|WPP_SF_sdLL|
|fullname|WPP_SF_sdLL|
|refcount|2|
|length|155|
|called|_guard_dispatch_icall|
|calling|CClfsBaseFile::GetControlRecord|
|paramcount|1|
|address|1c0010ef8|
|sig|undefined __fastcall WPP_SF_sdLL(undefined8 param_1)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- WPP_SF_sdLL
+++ WPP_SF_sdLL
@@ -1,25 +0,0 @@
-
-/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
-
-void WPP_SF_sdLL(undefined8 param_1)
-
-{
-  longlong lVar1;
-  longlong lVar2;
-  undefined4 local_18 [2];
-  undefined4 local_10 [4];
-  
-  local_18[0] = 6;
-  local_10[0] = 0xeb9;
-  lVar1 = -1;
-  do {
-    lVar2 = lVar1;
-    lVar1 = lVar2 + 1;
-  } while ("CClfsBaseFile::GetControlRecord"[lVar2 + 1] != '\0');
-  (*pfnWppTraceMessage)
-            (param_1,0x2b,&WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,0xf,
-             "CClfsBaseFile::GetControlRecord",lVar2 + 2,local_10,4,&stack0x00000030,4,local_18,4,0)
-  ;
-  return;
-}
-

```


# Added

# Modified


*Modified functions contain code changes*
## CClfsBaseFilePersisted::WriteMetadataBlock

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.27|
|i_ratio|0.16|
|m_ratio|0.99|
|b_ratio|0.13|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|WriteMetadataBlock|WriteMetadataBlock|
|fullname|CClfsBaseFilePersisted::WriteMetadataBlock|CClfsBaseFilePersisted::WriteMetadataBlock|
|refcount|8|8|
|`length`|981|874|
|`called`|CClfsAuthContainer::WriteSector<br>CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetSymbol<br>ClfsDecodeBlock<br>ClfsEncodeBlock<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::RtlCompareMemory<br>WPP_SF_sl|CClfsAuthContainer::WriteSector<br>CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ReleaseMetadataBlock<br>ClfsDecodeBlock<br>ClfsEncodeBlock<br>Feature_110180665__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>WPP_SF_sl|
|calling|CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::FlushImage<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart|CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::FlushImage<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart|
|paramcount|3|3|
|`address`|1c0060d00|1c006f4d0|
|sig|long __thiscall WriteMetadataBlock(CClfsBaseFilePersisted * this, ulong param_1, uchar param_2)|long __thiscall WriteMetadataBlock(CClfsBaseFilePersisted * this, ulong param_1, uchar param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::WriteMetadataBlock Called Diff


```diff
--- CClfsBaseFilePersisted::WriteMetadataBlock called
+++ CClfsBaseFilePersisted::WriteMetadataBlock called
@@ -3,2 +3,2 @@
-CClfsBaseFile::GetBaseLogRecord
-CClfsBaseFile::GetSymbol
+CClfsBaseFile::ReleaseContainerContext
+CClfsBaseFile::ReleaseMetadataBlock
@@ -6,0 +7 @@
+Feature_110180665__private_IsEnabledDeviceUsage
@@ -9 +9,0 @@
-NTOSKRNL.EXE::RtlCompareMemory
```


### CClfsBaseFilePersisted::WriteMetadataBlock Diff


```diff
--- CClfsBaseFilePersisted::WriteMetadataBlock
+++ CClfsBaseFilePersisted::WriteMetadataBlock
@@ -1,152 +1,144 @@
 
 /* public: long __cdecl CClfsBaseFilePersisted::WriteMetadataBlock(unsigned long,unsigned char)
    __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::WriteMetadataBlock(CClfsBaseFilePersisted *this,ulong param_1,uchar param_2)
 
 {
-  uint uVar1;
-  longlong lVar2;
-  bool bVar3;
+  longlong lVar1;
+  uint uVar2;
+  _CLFS_LOG_BLOCK_HEADER *p_Var3;
   bool bVar4;
-  _CLFS_CONTAINER_CONTEXT *p_Var5;
+  bool bVar5;
   char cVar6;
   long lVar7;
-  _CLFS_BASE_RECORD_HEADER *p_Var8;
-  longlong lVar9;
+  long lVar8;
+  ulonglong uVar9;
   undefined4 in_register_00000014;
   uint uVar10;
-  ulong uVar11;
-  ulonglong uVar13;
-  CClfsBaseFilePersisted *pCVar14;
-  _CLFS_LOG_BLOCK_HEADER *p_Var15;
-  _CLFS_CONTAINER_CONTEXT *local_res8;
-  ulong local_54;
-  long local_50;
-  _CLFS_CONTAINER_CONTEXT *local_48;
-  ulonglong local_40;
-  _CLFS_LOG_BLOCK_HEADER *local_38;
-  _CLFS_CONTAINER_CONTEXT *local_30;
-  ulonglong uVar12;
+  ulonglong uVar11;
+  CClfsBaseFilePersisted *pCVar12;
+  undefined1 auStackY_a8 [32];
+  ulonglong local_70;
+  long local_68;
+  _CLFS_CONTAINER_CONTEXT *local_60;
+  uint local_58;
+  _CLFS_LOG_BLOCK_HEADER *local_50;
+  undefined1 *local_48;
   
-  bVar4 = false;
-  uVar13 = 0;
-  local_38 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  local_48 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-  bVar3 = false;
-  local_res8 = (_CLFS_CONTAINER_CONTEXT *)this;
+  local_48 = auStackY_a8;
+  uVar11 = 0;
+  local_70 = local_70 & 0xffffffff00000000;
+  local_50 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+  local_60 = (_CLFS_CONTAINER_CONTEXT *)0x0;
+  bVar5 = false;
   cVar6 = ExAcquireResourceExclusiveLite
                     (*(undefined8 *)(this + 0x20),
                      CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
-  lVar9 = (ulonglong)param_1 * 0x18;
-  p_Var15 = *(_CLFS_LOG_BLOCK_HEADER **)(lVar9 + *(longlong *)(this + 0x30));
-  local_38 = p_Var15;
-  if (p_Var15 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-    local_50 = -0x3fe5fff3;
+  lVar1 = (ulonglong)param_1 * 0x18;
+  p_Var3 = *(_CLFS_LOG_BLOCK_HEADER **)(lVar1 + *(longlong *)(this + 0x30));
+  local_50 = p_Var3;
+  if (p_Var3 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+    local_68 = -0x3fe5fff3;
+    bVar4 = false;
+    lVar7 = local_68;
   }
   else {
-    bVar3 = true;
-    uVar10 = *(uint *)(p_Var15 + 0x28);
-    *(longlong *)(p_Var15 + uVar10) = *(longlong *)(p_Var15 + uVar10) + 1;
-    lVar2 = *(longlong *)(this + 0x30);
-    if ((*(ulonglong *)(p_Var15 + uVar10) & 1) == 0) {
-      if (param_2 == '\0') {
-        uVar1 = *(uint *)(lVar2 + 0xc + lVar9);
+    bVar5 = true;
+    uVar10 = *(uint *)(p_Var3 + 0x28);
+    *(longlong *)(p_Var3 + uVar10) = *(longlong *)(p_Var3 + uVar10) + 1;
+    if (((*(ulonglong *)(p_Var3 + uVar10) & 1) == 0) && (param_2 != '\0')) {
+      uVar2 = *(uint *)(*(longlong *)(this + 0x30) + 0xc + (ulonglong)(param_1 + 1) * 0x18);
+    }
+    else {
+      uVar2 = *(uint *)(*(longlong *)(this + 0x30) + 0xc + lVar1);
+    }
+    local_70 = (ulonglong)uVar2;
+    if ((*(ulonglong *)(p_Var3 + uVar10) & 1) != 0) {
+      p_Var3[2] = (_CLFS_LOG_BLOCK_HEADER)((char)p_Var3[2] + '\x01');
+    }
+    local_58 = 0;
+    uVar9 = uVar11;
+    while (uVar10 = (uint)uVar9, uVar10 < 0x400) {
+      local_68 = CClfsBaseFile::AcquireContainerContext((CClfsBaseFile *)this,uVar10,&local_60);
+      if (local_68 < 0) {
+        *(undefined8 *)(this + uVar9 * 8 + 0x1d8) = 0;
+        local_58 = uVar10 + 1;
+        uVar9 = (ulonglong)local_58;
       }
       else {
-        uVar1 = *(uint *)(lVar2 + 0xc + (ulonglong)(param_1 + 1) * 0x18);
+        *(undefined8 *)(this + uVar9 * 8 + 0x1d8) = *(undefined8 *)(local_60 + 0x18);
+        *(undefined8 *)(local_60 + 0x18) = 0;
+        CClfsBaseFile::ReleaseContainerContext((CClfsBaseFile *)this,&local_60);
+        local_58 = uVar10 + 1;
+        uVar9 = (ulonglong)local_58;
       }
     }
-    else {
-      uVar1 = *(uint *)(lVar9 + 0xc + lVar2);
-    }
-    local_40 = (ulonglong)uVar1;
-    uVar12 = uVar13;
-    if ((*(ulonglong *)(p_Var15 + uVar10) & 1) != 0) {
-      p_Var15[2] = (_CLFS_LOG_BLOCK_HEADER)((char)p_Var15[2] + '\x01');
-    }
-    while (uVar10 = (uint)uVar12, uVar10 < 0x400) {
-      lVar7 = CClfsBaseFile::AcquireContainerContext((CClfsBaseFile *)this,uVar10,&local_48);
-      p_Var5 = local_48;
-      if (lVar7 < 0) {
-        *(undefined8 *)(this + uVar12 * 8 + 0x1d8) = 0;
-      }
-      else {
-        *(undefined8 *)(this + uVar12 * 8 + 0x1d8) = *(undefined8 *)(local_48 + 0x18);
-        *(undefined8 *)(local_48 + 0x18) = 0;
-        local_30 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-        p_Var8 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
-        if (((p_Var8 != (_CLFS_BASE_RECORD_HEADER *)0x0) &&
-            (uVar1 = *(uint *)(p_Var5 + 0x10),
-            lVar7 = CClfsBaseFile::GetSymbol
-                              ((CClfsBaseFile *)this,
-                               *(long *)(p_Var8 + (ulonglong)uVar1 * 4 + 0x328),uVar1,&local_30),
-            -1 < lVar7)) && (lVar9 = RtlCompareMemory(local_30,p_Var5,0x30), lVar9 == 0x30)) {
-          ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
-          local_48 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-          p_Var15 = local_38;
-        }
-      }
-      uVar12 = (ulonglong)(uVar10 + 1);
-    }
-    local_50 = ClfsEncodeBlock(p_Var15,(uint)*(ushort *)(p_Var15 + 4) << 9,(uchar)p_Var15[2],'\x10',
-                               '\x01');
-    if (local_50 < 0) {
+    lVar7 = ClfsEncodeBlock(p_Var3,(uint)*(ushort *)(p_Var3 + 4) << 9,(uchar)p_Var3[2],'\x10','\x01'
+                           );
+    local_68 = lVar7;
+    if (lVar7 < 0) {
       if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-        WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x23,
-                  &WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,
+        WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x20,
+                  &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,
                   "CClfsBaseFilePersisted::WriteMetadataBlock");
       }
+      bVar4 = false;
     }
     else {
       bVar4 = true;
-      local_50 = CClfsAuthContainer::WriteSector
-                           (*(CClfsAuthContainer **)(this + 0x98),*(_KEVENT **)(this + 0xa0),
-                            (_CLFS_IO_WORKITEM *)0x0,
-                            *(void **)(*(longlong *)(this + 0x30) + (ulonglong)param_1 * 0x18),
-                            (uint)*(ushort *)(p_Var15 + 4),&local_40);
-      if (-1 < local_50) {
+      lVar7 = CClfsAuthContainer::WriteSector
+                        (*(CClfsAuthContainer **)(this + 0x98),*(_KEVENT **)(this + 0xa0),
+                         (_CLFS_IO_WORKITEM *)0x0,
+                         *(void **)(*(longlong *)(this + 0x30) + (ulonglong)param_1 * 0x18),
+                         (uint)*(ushort *)(p_Var3 + 4),&local_70);
+      local_68 = lVar7;
+      if (-1 < lVar7) {
         *(longlong *)(this + 0x1b8) = *(longlong *)(this + 0x1b8) + 1;
         *(longlong *)(this + 0x1c0) = *(longlong *)(this + 0xd0) + *(longlong *)(this + 0x1c0);
       }
     }
   }
-  if (bVar3) {
+  if (bVar5) {
     if (bVar4) {
-      ClfsDecodeBlock(p_Var15,(uint)*(ushort *)(p_Var15 + 4),(uchar)p_Var15[2],'\x10',
-                      (ulong *)&local_40);
+      lVar8 = ClfsDecodeBlock(p_Var3,(uint)*(ushort *)(p_Var3 + 4),(uchar)p_Var3[2],'\x10',
+                              (ulong *)&local_70);
+      local_70 = CONCAT44(local_70._4_4_,lVar8);
+      uVar9 = Feature_110180665__private_IsEnabledDeviceUsage();
+      if (((int)uVar9 != 0) && (lVar8 < 0)) {
+        if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+          WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x21,
+                    &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,
+                    "CClfsBaseFilePersisted::WriteMetadataBlock");
+        }
+        CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,param_1);
+        if (cVar6 != '\0') {
+          ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
+          lVar8 = (long)local_70;
+        }
+        return lVar8;
+      }
     }
-    local_54 = 0;
-    pCVar14 = this + 0x1d8;
+    pCVar12 = this + 0x1d8;
     do {
-      uVar11 = (ulong)uVar13;
-      if ((*(longlong *)pCVar14 != 0) &&
-         (lVar7 = CClfsBaseFile::AcquireContainerContext((CClfsBaseFile *)this,uVar11,&local_48),
-         p_Var5 = local_48, -1 < lVar7)) {
-        *(longlong *)(local_48 + 0x18) = *(longlong *)pCVar14;
-        local_res8 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-        p_Var8 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
-        if ((p_Var8 != (_CLFS_BASE_RECORD_HEADER *)0x0) &&
-           ((uVar10 = *(uint *)(p_Var5 + 0x10),
-            lVar7 = CClfsBaseFile::GetSymbol
-                              ((CClfsBaseFile *)this,
-                               *(long *)(p_Var8 + (ulonglong)uVar10 * 4 + 0x328),uVar10,&local_res8)
-            , -1 < lVar7 && (lVar9 = RtlCompareMemory(local_res8,p_Var5,0x30), lVar9 == 0x30)))) {
-          ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
-          local_48 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-          uVar11 = local_54;
-        }
+      if ((*(longlong *)pCVar12 != 0) &&
+         (lVar8 = CClfsBaseFile::AcquireContainerContext
+                            ((CClfsBaseFile *)this,(ulong)uVar11,&local_60), -1 < lVar8)) {
+        *(longlong *)(local_60 + 0x18) = *(longlong *)pCVar12;
+        CClfsBaseFile::ReleaseContainerContext((CClfsBaseFile *)this,&local_60);
       }
-      local_54 = uVar11 + 1;
-      uVar13 = (ulonglong)local_54;
-      pCVar14 = pCVar14 + 8;
-    } while (local_54 < 0x400);
+      uVar10 = (ulong)uVar11 + 1;
+      uVar11 = (ulonglong)uVar10;
+      pCVar12 = pCVar12 + 8;
+    } while (uVar10 < 0x400);
   }
   if (cVar6 != '\0') {
     ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
+    lVar7 = local_68;
   }
-  return local_50;
+  return lVar7;
 }
 

```


## CClfsBaseFilePersisted::ExtendMetadataBlock

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.13|
|i_ratio|0.37|
|m_ratio|1.0|
|b_ratio|0.79|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ExtendMetadataBlock|ExtendMetadataBlock|
|fullname|CClfsBaseFilePersisted::ExtendMetadataBlock|CClfsBaseFilePersisted::ExtendMetadataBlock|
|refcount|4|4|
|`length`|1314|1311|
|`called`|<details><summary>Expand for full list:<br>CClfsAuthContainer::Extend<br>CClfsAuthContainer::GetContainerSize<br>CClfsBaseFile::AcquireMetadataBlock<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::GetSize<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::IsShadowBlock<br>CClfsBaseFilePersisted::ProcessCurrentBlockForExtend</summary>CClfsBaseFilePersisted::WriteMetadataBlock<br>ClfsCreateEventObject<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::KeClearEvent<br>NTOSKRNL.EXE::KeSetEvent<br>NTOSKRNL.EXE::KeWaitForSingleObject</details>|<details><summary>Expand for full list:<br>CClfsAuthContainer::Extend<br>CClfsAuthContainer::GetContainerSize<br>CClfsBaseFile::AcquireMetadataBlock<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::GetSize<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::IsShadowBlock<br>CClfsBaseFilePersisted::ProcessCurrentBlockForExtend</summary>CClfsBaseFilePersisted::WriteMetadataBlock<br>ClfsCreateEventObject<br>Feature_110180665__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::KeClearEvent<br>NTOSKRNL.EXE::KeSetEvent<br>NTOSKRNL.EXE::KeWaitForSingleObject</details>|
|calling|CClfsBaseFilePersisted::AddSymbol<br>CClfsBaseFilePersisted::OpenImage<br>CClfsLogFcbPhysical::SetEndOfLog|CClfsBaseFilePersisted::AddSymbol<br>CClfsBaseFilePersisted::OpenImage<br>CClfsLogFcbPhysical::SetEndOfLog|
|paramcount|3|3|
|`address`|1c0039224|1c0039228|
|sig|long __thiscall ExtendMetadataBlock(CClfsBaseFilePersisted * this, _CLFS_METADATA_BLOCK_TYPE param_1, ulong param_2)|long __thiscall ExtendMetadataBlock(CClfsBaseFilePersisted * this, _CLFS_METADATA_BLOCK_TYPE param_1, ulong param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::ExtendMetadataBlock Called Diff


```diff
--- CClfsBaseFilePersisted::ExtendMetadataBlock called
+++ CClfsBaseFilePersisted::ExtendMetadataBlock called
@@ -13,0 +14 @@
+Feature_110180665__private_IsEnabledDeviceUsage
```


### CClfsBaseFilePersisted::ExtendMetadataBlock Diff


```diff
--- CClfsBaseFilePersisted::ExtendMetadataBlock
+++ CClfsBaseFilePersisted::ExtendMetadataBlock
@@ -1,224 +1,215 @@
 
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 /* public: long __cdecl CClfsBaseFilePersisted::ExtendMetadataBlock(enum
    _CLFS_METADATA_BLOCK_TYPE,unsigned long) __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::ExtendMetadataBlock
           (CClfsBaseFilePersisted *this,_CLFS_METADATA_BLOCK_TYPE param_1,ulong param_2)
 
 {
-  CClfsBaseFilePersisted *pCVar1;
-  ushort uVar2;
-  int iVar3;
-  _EVENT_TYPE _Var4;
-  bool bVar5;
-  uchar uVar6;
-  _EVENT_TYPE _Var7;
-  __uint64 _Var8;
-  ulonglong uVar9;
-  ulong uVar10;
-  undefined4 in_register_00000014;
-  _CLFS_METADATA_BLOCK_TYPE _Var11;
+  ushort uVar1;
+  int iVar2;
+  _EVENT_TYPE _Var3;
+  bool bVar4;
+  uchar uVar5;
+  _EVENT_TYPE _Var6;
+  __uint64 _Var7;
+  ulonglong uVar8;
+  uint uVar9;
+  CClfsBaseFilePersisted *pCVar10;
+  _CLFS_CONTROL_RECORD *p_Var11;
   uint uVar12;
   _CLFS_METADATA_BLOCK_TYPE _Var13;
-  ulonglong uVar14;
-  uint uVar15;
-  char local_78;
-  uint local_74;
-  _CLFS_CONTROL_RECORD *local_70;
-  _CLFS_METADATA_BLOCK_TYPE local_68;
-  uint local_64;
-  __uint64 local_60;
-  _EVENT_TYPE local_58;
-  uint local_54;
+  _CLFS_METADATA_BLOCK_TYPE _Var14;
+  ulonglong uVar15;
+  char local_88;
+  uint local_84;
+  _CLFS_CONTROL_RECORD *local_78;
+  uint local_70;
+  __uint64 local_68;
+  _EVENT_TYPE local_60;
+  uint local_5c;
+  uint local_58;
+  undefined4 local_54;
   uint local_50;
-  undefined4 local_4c;
-  uint local_48;
-  undefined8 local_40;
+  undefined8 local_48;
   
-  uVar14 = (ulonglong)(int)param_1;
-  _Var11 = 0;
-  local_60 = 0;
-  local_40 = 0;
-  local_70 = (_CLFS_CONTROL_RECORD *)0x0;
+  uVar15 = (ulonglong)(int)param_1;
+  p_Var11 = (_CLFS_CONTROL_RECORD *)0x0;
+  local_68 = 0;
+  local_48 = 0;
   uVar12 = 0;
-  local_68 = 0;
-  bVar5 = false;
-  iVar3 = *(int *)(this + 0x90);
-  if (iVar3 != 0) {
-    uVar12 = (param_2 - 1) + iVar3 & -iVar3;
-  }
-  local_78 = ExAcquireResourceExclusiveLite
-                       (*(undefined8 *)(this + 0x20),
-                        CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
-  _Var4 = *(_EVENT_TYPE *)(*(longlong *)(this + 0x30) + 8 + uVar14 * 0x18);
-  _Var7 = _Var4 + uVar12;
-  local_58 = 0xffffffff;
-  if (_Var7 >= _Var4) {
-    local_58 = _Var7;
-  }
-  local_74 = -(uint)(_Var7 < _Var4) & 0xc0000095;
-  if (-1 < (int)local_74) {
-    if (local_58 < 0xfff001) {
-      pCVar1 = this + 0xa8;
-      if ((*(_KEVENT **)pCVar1 != (_KEVENT *)0x0) ||
-         (local_74 = ClfsCreateEventObject(local_58,(_KEVENT **)pCVar1), -1 < (int)local_74)) {
-        LOCK();
-        iVar3 = *(int *)(this + 400);
-        *(int *)(this + 400) = 1;
-        UNLOCK();
-        if (iVar3 == 0) {
-          KeClearEvent(*(_KEVENT **)pCVar1);
-          bVar5 = true;
-          _Var11 = param_1;
-          if (*(ushort *)(this + 0x28) < 3) {
-            local_74 = 0xc01a000d;
-            _Var11 = local_68;
+  local_78 = (_CLFS_CONTROL_RECORD *)0x0;
+  bVar4 = false;
+  iVar2 = *(int *)(this + 0x90);
+  if (iVar2 != 0) {
+    uVar12 = (param_2 - 1) + iVar2 & -iVar2;
+  }
+  local_88 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20),1);
+  _Var3 = *(_EVENT_TYPE *)(*(longlong *)(this + 0x30) + 8 + uVar15 * 0x18);
+  _Var6 = _Var3 + uVar12;
+  local_60 = 0xffffffff;
+  if (_Var6 >= _Var3) {
+    local_60 = _Var6;
+  }
+  local_84 = -(uint)(_Var6 < _Var3) & 0xc0000095;
+  if ((int)local_84 < 0) {
+LAB_0:
+    _Var13 = 0;
+  }
+  else {
+    if (0xfff000 < local_60) {
+      local_84 = 0xc0000002;
+      goto LAB_0;
+    }
+    pCVar10 = this + 0xa8;
+    if ((*(_KEVENT **)pCVar10 == (_KEVENT *)0x0) &&
+       (local_84 = ClfsCreateEventObject(local_60,(_KEVENT **)pCVar10), (int)local_84 < 0))
+    goto LAB_0;
+    LOCK();
+    iVar2 = *(int *)(this + 400);
+    *(int *)(this + 400) = 1;
+    UNLOCK();
+    if (iVar2 != 0) {
+      CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
+      local_84 = KeWaitForSingleObject(*(_KEVENT **)pCVar10,0,0,0,0);
+      local_88 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20));
+      p_Var11 = local_78;
+      goto LAB_0;
+    }
+    KeClearEvent(*(_KEVENT **)pCVar10);
+    bVar4 = true;
+    _Var13 = param_1;
+    if (*(ushort *)(this + 0x28) < 3) {
+      local_84 = 0xc01a000d;
+      _Var13 = 0;
+      p_Var11 = local_78;
+    }
+    else {
+      for (; _Var13 < *(ushort *)(this + 0x28); _Var13 = _Var13 + 2) {
+        local_84 = CClfsBaseFile::AcquireMetadataBlock((CClfsBaseFile *)this,_Var13);
+        p_Var11 = local_78;
+        if ((int)local_84 < 0) goto LAB_1;
+      }
+      local_84 = CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_78,'\0');
+      p_Var11 = local_78;
+      if (-1 < (int)local_84) {
+        iVar2 = *(int *)(local_78 + 0x14);
+        if (iVar2 == 0) {
+          for (uVar9 = 0; local_70 = uVar9, uVar9 < *(ushort *)(this + 0x28); uVar9 = uVar9 + 1) {
+            local_84 = WriteMetadataBlock(this,uVar9,'\0');
+            if ((int)local_84 < 0) goto LAB_1;
           }
-          else {
-            for (; local_68 = _Var11, _Var11 < *(ushort *)(this + 0x28); _Var11 = _Var11 + 2) {
-              local_74 = CClfsBaseFile::AcquireMetadataBlock((CClfsBaseFile *)this,_Var11);
-              if ((int)local_74 < 0) goto LAB_0;
+          uVar9 = *(uint *)(*(longlong *)(this + 0x30) + 8 + uVar15 * 0x18) >> 9;
+          uVar12 = uVar12 >> 9;
+          *(short *)(p_Var11 + 0x18) = (short)param_1;
+          *(short *)(p_Var11 + 0x1a) = *(short *)(this + 0x28) + -1;
+          local_5c = uVar9;
+          local_58 = uVar12;
+          _Var7 = CClfsBaseFile::GetSize((CClfsBaseFile *)this);
+          *(uint *)(p_Var11 + 0x20) = (uint)(_Var7 >> 9) & 0x7fffff;
+          *(uint *)(p_Var11 + 0x24) = uVar12 * 2;
+          *(uint *)(p_Var11 + 0x1c) = uVar12 + uVar9;
+          *(undefined4 *)(p_Var11 + 0x14) = 1;
+          local_84 = FlushControlRecord(this);
+          if (-1 < (int)local_84) goto LAB_2;
+        }
+        else if (iVar2 == 1) {
+LAB_2:
+          local_84 = CClfsAuthContainer::GetContainerSize
+                               (*(CClfsAuthContainer **)(this + 0x98),&local_68);
+          if (-1 < (int)local_84) {
+            uVar12 = *(uint *)(p_Var11 + 0x24);
+            uVar9 = *(int *)(p_Var11 + 0x20) + uVar12;
+            uVar8 = 0xffffffff;
+            if (uVar9 >= uVar12) {
+              uVar8 = (ulonglong)uVar9;
             }
-            local_74 = CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_70,'\0');
-            if (-1 < (int)local_74) {
-              iVar3 = *(int *)(local_70 + 0x14);
-              if (iVar3 == 0) {
-                for (uVar15 = 0; local_64 = uVar15, uVar15 < *(ushort *)(this + 0x28);
-                    uVar15 = uVar15 + 1) {
-                  local_74 = WriteMetadataBlock(this,uVar15,'\0');
-                  if ((int)local_74 < 0) goto LAB_0;
+            local_54 = (undefined4)uVar8;
+            local_84 = -(uint)(uVar9 < uVar12) & 0xc0000095;
+            if (-1 < (int)local_84) {
+              uVar8 = uVar8 * 0x200;
+              local_50 = 0xffffffff;
+              if (uVar8 < 0x100000000) {
+                local_50 = (uint)uVar8;
+              }
+              local_84 = -(uint)(0xffffffff < uVar8) & 0xc0000095;
+              if (-1 < (int)local_84) {
+                if (local_68 < local_50) {
+                  CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
+                  local_84 = CClfsAuthContainer::Extend
+                                       (*(CClfsAuthContainer **)(this + 0x98),
+                                        *(ulong *)(p_Var11 + 0x24));
+                  local_88 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20));
+                  if ((int)local_84 < 0) goto LAB_1;
                 }
-                uVar15 = *(uint *)(*(longlong *)(this + 0x30) + 8 + uVar14 * 0x18) >> 9;
-                uVar12 = uVar12 >> 9;
-                *(short *)(local_70 + 0x18) = (short)param_1;
-                *(short *)(local_70 + 0x1a) = *(short *)(this + 0x28) + -1;
-                local_54 = uVar15;
-                local_50 = uVar12;
-                _Var8 = CClfsBaseFile::GetSize((CClfsBaseFile *)this);
-                *(uint *)(local_70 + 0x20) = (uint)(_Var8 >> 9) & 0x7fffff;
-                *(uint *)(local_70 + 0x24) = uVar12 * 2;
-                *(uint *)(local_70 + 0x1c) = uVar15 + uVar12;
-                *(undefined4 *)(local_70 + 0x14) = 1;
-                local_74 = FlushControlRecord(this);
-                if (-1 < (int)local_74) goto LAB_1;
-              }
-              else if (iVar3 == 1) {
-LAB_1:
-                local_74 = CClfsAuthContainer::GetContainerSize
-                                     (*(CClfsAuthContainer **)(this + 0x98),&local_60);
-                if (-1 < (int)local_74) {
-                  uVar15 = *(uint *)(local_70 + 0x24);
-                  uVar12 = uVar15 + *(int *)(local_70 + 0x20);
-                  uVar9 = 0xffffffff;
-                  if (uVar12 >= uVar15) {
-                    uVar9 = (ulonglong)uVar12;
-                  }
-                  local_4c = (undefined4)uVar9;
-                  local_74 = -(uint)(uVar12 < uVar15) & 0xc0000095;
-                  if (-1 < (int)local_74) {
-                    uVar9 = uVar9 * 0x200;
-                    local_48 = 0xffffffff;
-                    if (uVar9 < 0x100000000) {
-                      local_48 = (uint)uVar9;
+                local_84 = ProcessCurrentBlockForExtend(this,p_Var11);
+                if (-1 < (int)local_84) {
+                  *(undefined4 *)(p_Var11 + 0x14) = 2;
+                  local_84 = FlushControlRecord(this);
+                  while (-1 < (int)local_84) {
+LAB_3:
+                    if (*(int *)(p_Var11 + 0x14) != 2) break;
+                    uVar1 = *(ushort *)(p_Var11 + 0x1a);
+                    pCVar10 = (CClfsBaseFilePersisted *)(ulonglong)uVar1;
+                    uVar12 = (uint)uVar1;
+                    if (((uVar1 == *(ushort *)(p_Var11 + 0x18)) ||
+                        (uVar5 = IsShadowBlock(pCVar10,uVar12,(uint)*(ushort *)(p_Var11 + 0x18)),
+                        uVar5 != '\0')) &&
+                       (*(uint *)(*(longlong *)(this + 0x30) + 8 + (longlong)pCVar10 * 0x18) >> 9 <
+                        *(uint *)(p_Var11 + 0x1c))) {
+                      ExtendMetadataBlockDescriptor(this,uVar12,*(uint *)(p_Var11 + 0x24) >> 1);
                     }
-                    local_74 = -(uint)(0xffffffff < uVar9) & 0xc0000095;
-                    if (-1 < (int)local_74) {
-                      if (local_60 < local_48) {
-                        CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
-                        local_74 = CClfsAuthContainer::Extend
-                                             (*(CClfsAuthContainer **)(this + 0x98),
-                                              *(ulong *)(local_70 + 0x24));
-                        local_78 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20));
-                        if ((int)local_74 < 0) goto LAB_0;
-                      }
-                      local_74 = ProcessCurrentBlockForExtend(this,local_70);
-                      if (-1 < (int)local_74) {
-                        *(undefined4 *)(local_70 + 0x14) = 2;
-                        local_74 = FlushControlRecord(this);
-                        goto joined_r0x0001c00395c1;
-                      }
+                    local_84 = WriteMetadataBlock(this,(uint)*(ushort *)(p_Var11 + 0x1a),'\0');
+                    uVar8 = Feature_110180665__private_IsEnabledDeviceUsage();
+                    if (((int)uVar8 != 0) && ((int)local_84 < 0)) break;
+                    if (*(short *)(p_Var11 + 0x1a) == *(short *)(p_Var11 + 0x18)) {
+                      *(undefined4 *)(p_Var11 + 0x14) = 0;
                     }
+                    else {
+                      *(short *)(p_Var11 + 0x1a) = *(short *)(p_Var11 + 0x1a) + -1;
+                      local_84 = ProcessCurrentBlockForExtend(this,p_Var11);
+                      if ((int)local_84 < 0) break;
+                    }
+                    local_84 = FlushControlRecord(this);
                   }
                 }
-              }
-              else if (iVar3 == 2) {
-                do {
-                  if (*(int *)(local_70 + 0x14) != 2) break;
-                  uVar2 = *(ushort *)(local_70 + 0x1a);
-                  uVar9 = (ulonglong)uVar2;
-                  uVar10 = (ulong)uVar2;
-                  if (uVar2 == *(ushort *)(local_70 + 0x18)) {
-LAB_2:
-                    if (*(uint *)(*(longlong *)(this + 0x30) + 8 + uVar9 * 0x18) >> 9 <
-                        *(uint *)(local_70 + 0x1c)) {
-                      ExtendMetadataBlockDescriptor(this,uVar10,*(uint *)(local_70 + 0x24) >> 1);
-                    }
-                  }
-                  else {
-                    uVar6 = IsShadowBlock((CClfsBaseFilePersisted *)local_70,uVar10,
-                                          (uint)*(ushort *)(local_70 + 0x18));
-                    if (uVar6 != '\0') {
-                      uVar10 = (ulong)uVar9;
-                      goto LAB_2;
-                    }
-                  }
-                  WriteMetadataBlock(this,(uint)*(ushort *)(local_70 + 0x1a),'\0');
-                  if (*(short *)(local_70 + 0x1a) == *(short *)(local_70 + 0x18)) {
-                    *(undefined4 *)(local_70 + 0x14) = 0;
-                  }
-                  else {
-                    *(short *)(local_70 + 0x1a) = *(short *)(local_70 + 0x1a) + -1;
-                    local_74 = ProcessCurrentBlockForExtend(this,local_70);
-                    if ((int)local_74 < 0) break;
-                  }
-                  local_74 = FlushControlRecord(this);
-joined_r0x0001c00395c1:
-                } while (-1 < (int)local_74);
               }
             }
           }
         }
-        else {
-          CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
-          local_74 = KeWaitForSingleObject(*(_KEVENT **)pCVar1,0,0,0,0);
-          local_78 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20));
-          _Var11 = local_68;
-        }
+        else if (iVar2 == 2) goto LAB_3;
       }
     }
-    else {
-      local_74 = 0xc0000002;
-    }
-  }
-LAB_0:
-  while (_Var13 = (_CLFS_METADATA_BLOCK_TYPE)uVar14, _Var13 < _Var11) {
-    CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,_Var13);
-    uVar14 = (ulonglong)(_Var13 + 2);
-  }
-  if ((int)local_74 < 0) {
-    if (!bVar5) goto LAB_3;
-    local_74 = 0xc01a002b;
-    if (DAT_4 == 0) {
-      DAT_4 = 1;
-      _DAT_5 = 0xc01a002b;
-    }
-  }
-  if (bVar5) {
+  }
+LAB_1:
+  while (_Var14 = (_CLFS_METADATA_BLOCK_TYPE)uVar15, _Var14 < _Var13) {
+    CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,_Var14);
+    uVar15 = (ulonglong)(_Var14 + 2);
+  }
+  if ((int)local_84 < 0) {
+    if (!bVar4) goto LAB_4;
+    local_84 = 0xc01a002b;
+    if (DAT_5 == 0) {
+      DAT_5 = 1;
+      _DAT_6 = 0xc01a002b;
+    }
+  }
+  if (bVar4) {
     LOCK();
     *(undefined4 *)(this + 400) = 0;
     UNLOCK();
     KeSetEvent(*(undefined8 *)(this + 0xa8),0,0);
-  }
-LAB_3:
-  if (local_70 != (_CLFS_CONTROL_RECORD *)0x0) {
+    p_Var11 = local_78;
+  }
+LAB_4:
+  if (p_Var11 != (_CLFS_CONTROL_RECORD *)0x0) {
     CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
-    local_70 = (_CLFS_CONTROL_RECORD *)0x0;
-  }
-  if (local_78 != '\0') {
+  }
+  if (local_88 != '\0') {
     CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
   }
-  return local_74;
+  return local_84;
 }
 

```


## CClfsBaseFile::OffsetToAddr

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling,called|
|ratio|0.33|
|i_ratio|0.12|
|m_ratio|0.94|
|b_ratio|0.56|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|OffsetToAddr|OffsetToAddr|
|fullname|CClfsBaseFile::OffsetToAddr|CClfsBaseFile::OffsetToAddr|
|`refcount`|29|33|
|`length`|103|96|
|`called`||CClfsBaseFile::GetBaseLogRecord<br>Feature_110180665__private_IsEnabledDeviceUsage|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireSharedSecurityContext<br>CClfsBaseFile::FindClient<br>CClfsBaseFile::FindContainer<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseSharedSecurityDescriptor<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateProcessQNode</summary>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::AddClient<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::RemoveSymbol<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireSharedSecurityContext<br>CClfsBaseFile::FindClient<br>CClfsBaseFile::FindContainer<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseSharedSecurityDescriptor<br>CClfsBaseFile::ValidateClientContextOffsets</summary>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateProcessQNode<br>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::AddClient<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::RemoveSymbol<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|
|paramcount|2|2|
|`address`|1c0060a78|1c0060c80|
|sig|void * __thiscall OffsetToAddr(CClfsBaseFile * this, ulong param_1)|void * __thiscall OffsetToAddr(CClfsBaseFile * this, ulong param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::OffsetToAddr Called Diff


```diff
--- CClfsBaseFile::OffsetToAddr called
+++ CClfsBaseFile::OffsetToAddr called
@@ -0,0 +1,2 @@
+CClfsBaseFile::GetBaseLogRecord
+Feature_110180665__private_IsEnabledDeviceUsage
```


### CClfsBaseFile::OffsetToAddr Calling Diff


```diff
--- CClfsBaseFile::OffsetToAddr calling
+++ CClfsBaseFile::OffsetToAddr calling
@@ -6,0 +7,2 @@
+CClfsBaseFile::GetSymbol
+CClfsBaseFile::GetSymbol
@@ -10,0 +13 @@
+CClfsBaseFile::ValidateOffsets
```


### CClfsBaseFile::OffsetToAddr Diff


```diff
--- CClfsBaseFile::OffsetToAddr
+++ CClfsBaseFile::OffsetToAddr
@@ -1,27 +1,25 @@
 
 /* protected: void * __ptr64 __cdecl CClfsBaseFile::OffsetToAddr(unsigned long) __ptr64 */
 
 void * __thiscall CClfsBaseFile::OffsetToAddr(CClfsBaseFile *this,ulong param_1)
 
 {
-  uint uVar1;
-  longlong lVar2;
-  longlong lVar3;
+  longlong lVar1;
+  _CLFS_BASE_RECORD_HEADER *p_Var2;
+  ulonglong uVar3;
   uint uVar4;
   
-  lVar3 = 0;
-  lVar2 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
-  if ((*(short *)(this + 0x28) != 0) && (lVar2 != 0)) {
-    uVar4 = *(uint *)(lVar2 + 0x28);
-    uVar1 = *(uint *)(*(longlong *)(this + 0x30) + 0x38);
-    if ((uVar4 < uVar1) && ((0x6f < uVar4 && (0x1337 < uVar1 - uVar4)))) {
-      lVar3 = (ulonglong)uVar4 + lVar2;
-    }
+  lVar1 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
+  p_Var2 = GetBaseLogRecord(this);
+  uVar3 = Feature_110180665__private_IsEnabledDeviceUsage();
+  if (((((int)uVar3 == 0) || (lVar1 != 0)) &&
+      (uVar4 = *(int *)(lVar1 + 0x28) + param_1, param_1 <= uVar4)) &&
+     ((p_Var2 != (_CLFS_BASE_RECORD_HEADER *)0x0 && (uVar4 < (uint)*(ushort *)(lVar1 + 4) << 9)))) {
+    p_Var2 = p_Var2 + param_1;
   }
-  uVar4 = *(int *)(lVar2 + 0x28) + param_1;
-  if (((param_1 <= uVar4) && (lVar3 != 0)) && (uVar4 < (uint)*(ushort *)(lVar2 + 4) << 9)) {
-    return (void *)(lVar3 + (ulonglong)param_1);
+  else {
+    p_Var2 = (_CLFS_BASE_RECORD_HEADER *)0x0;
   }
-  return (void *)0x0;
+  return p_Var2;
 }
 

```


## CClfsBaseFile::ReleaseMetadataBlock

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling,called|
|ratio|0.5|
|i_ratio|0.46|
|m_ratio|0.92|
|b_ratio|0.76|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ReleaseMetadataBlock|ReleaseMetadataBlock|
|fullname|CClfsBaseFile::ReleaseMetadataBlock|CClfsBaseFile::ReleaseMetadataBlock|
|`refcount`|33|35|
|`length`|125|144|
|`called`|_guard_dispatch_icall|Feature_110180665__private_IsEnabledDeviceUsage<br>_guard_dispatch_icall|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::CreateSnapshot<br>CClfsBaseFile::~CClfsBaseFile<br>CClfsBaseFilePersisted::AcquireTruncateContext<br>CClfsBaseFilePersisted::CloseImage<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::FlushImage<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::ReadImage<br>CClfsBaseFilePersisted::ReleaseTruncateContext</summary>CClfsBaseFilePersisted::~CClfsBaseFilePersisted<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsBaseFileSnapshot::~CClfsBaseFileSnapshot<br>`CClfsBaseFile::CreateSnapshot'::__l1::fin$0<br>`CClfsBaseFilePersisted::AcquireTruncateContext'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::OpenImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::ReadImage'::__l1::fin$0<br>`CClfsBaseFileSnapshot::InitializeSnapshot'::__l1::fin$0</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::CreateSnapshot<br>CClfsBaseFile::~CClfsBaseFile<br>CClfsBaseFilePersisted::AcquireTruncateContext<br>CClfsBaseFilePersisted::CloseImage<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::FlushImage<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::ReadImage<br>CClfsBaseFilePersisted::ReleaseTruncateContext</summary>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsBaseFilePersisted::~CClfsBaseFilePersisted<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsBaseFileSnapshot::~CClfsBaseFileSnapshot<br>`CClfsBaseFile::CreateSnapshot'::__l1::fin$0<br>`CClfsBaseFilePersisted::AcquireTruncateContext'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::OpenImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::ReadImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0<br>`CClfsBaseFileSnapshot::InitializeSnapshot'::__l1::fin$0</details>|
|paramcount|2|2|
|`address`|1c0062cf8|1c006f434|
|sig|void __thiscall ReleaseMetadataBlock(CClfsBaseFile * this, _CLFS_METADATA_BLOCK_TYPE param_1)|void __thiscall ReleaseMetadataBlock(CClfsBaseFile * this, _CLFS_METADATA_BLOCK_TYPE param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ReleaseMetadataBlock Called Diff


```diff
--- CClfsBaseFile::ReleaseMetadataBlock called
+++ CClfsBaseFile::ReleaseMetadataBlock called
@@ -0,0 +1 @@
+Feature_110180665__private_IsEnabledDeviceUsage
```


### CClfsBaseFile::ReleaseMetadataBlock Calling Diff


```diff
--- CClfsBaseFile::ReleaseMetadataBlock calling
+++ CClfsBaseFile::ReleaseMetadataBlock calling
@@ -11,0 +12 @@
+CClfsBaseFilePersisted::WriteMetadataBlock
@@ -20,0 +22 @@
+`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0
```


### CClfsBaseFile::ReleaseMetadataBlock Diff


```diff
--- CClfsBaseFile::ReleaseMetadataBlock
+++ CClfsBaseFile::ReleaseMetadataBlock
@@ -1,25 +1,27 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* protected: void __cdecl CClfsBaseFile::ReleaseMetadataBlock(enum _CLFS_METADATA_BLOCK_TYPE)
    __ptr64 */
 
 void __thiscall
 CClfsBaseFile::ReleaseMetadataBlock(CClfsBaseFile *this,_CLFS_METADATA_BLOCK_TYPE param_1)
 
 {
   short *psVar1;
-  longlong lVar2;
+  ulonglong uVar2;
+  longlong lVar3;
   
-  lVar2 = (longlong)(int)param_1;
-  psVar1 = (short *)(*(longlong *)(this + 0x38) + lVar2 * 2);
-  *psVar1 = *psVar1 + -1;
-  if (*(short *)(*(longlong *)(this + 0x38) + lVar2 * 2) == 0) {
-    if (*(longlong *)(*(longlong *)(this + 0x30) + lVar2 * 0x18) != 0) {
+  lVar3 = (longlong)(int)param_1;
+  uVar2 = Feature_110180665__private_IsEnabledDeviceUsage();
+  if ((((int)uVar2 == 0) || (*(short *)(*(longlong *)(this + 0x38) + lVar3 * 2) != 0)) &&
+     (psVar1 = (short *)(*(longlong *)(this + 0x38) + lVar3 * 2), *psVar1 = *psVar1 + -1,
+     *(short *)(*(longlong *)(this + 0x38) + lVar3 * 2) == 0)) {
+    if (*(longlong *)(*(longlong *)(this + 0x30) + lVar3 * 0x18) != 0) {
       (**(code **)(*(longlong *)this + 0x10))(this);
     }
-    *(undefined8 *)(*(longlong *)(this + 0x30) + lVar2 * 0x18) = 0;
-    *(undefined8 *)(*(longlong *)(this + 0x30) + 0x18 + lVar2 * 0x18) = 0;
+    *(undefined8 *)(*(longlong *)(this + 0x30) + lVar3 * 0x18) = 0;
+    *(undefined8 *)(*(longlong *)(this + 0x30) + 0x18 + lVar3 * 0x18) = 0;
   }
   return;
 }
 

```


## CClfsLogFcbPhysical::MapCacheData

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.56|
|i_ratio|0.76|
|m_ratio|0.99|
|b_ratio|0.91|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|MapCacheData|MapCacheData|
|fullname|CClfsLogFcbPhysical::MapCacheData|CClfsLogFcbPhysical::MapCacheData|
|refcount|6|6|
|`length`|473|465|
|`called`|CClfsLogFcbCommon::FcbFromFileObject<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>Feature_2458037564__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::CcMapData<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>_guard_dispatch_icall|CClfsLogFcbCommon::FcbFromFileObject<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>NTOSKRNL.EXE::CcMapData<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>_guard_dispatch_icall|
|calling|CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks|CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks|
|paramcount|7|7|
|address|1c000ec80|1c000ec80|
|sig|long __thiscall MapCacheData(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, uchar param_4, void * * param_5, void * * param_6)|long __thiscall MapCacheData(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, uchar param_4, void * * param_5, void * * param_6)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::MapCacheData Called Diff


```diff
--- CClfsLogFcbPhysical::MapCacheData called
+++ CClfsLogFcbPhysical::MapCacheData called
@@ -3 +2,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::MapCacheData Diff


```diff
--- CClfsLogFcbPhysical::MapCacheData
+++ CClfsLogFcbPhysical::MapCacheData
@@ -1,73 +1,74 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsLogFcbPhysical::MapCacheData(struct _FILE_OBJECT * __ptr64 const,union
    _CLS_LSN const & __ptr64,unsigned long,unsigned char,void * __ptr64 & __ptr64,void * __ptr64 &
    __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::MapCacheData
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,_CLS_LSN *param_2,ulong param_3,
           uchar param_4,void **param_5,void **param_6)
 
 {
   CClfsLogFcbPhysical *pCVar1;
-  char cVar2;
-  char cVar3;
-  undefined4 uVar4;
-  CClfsLogFcbCommon *pCVar5;
-  __uint64 _Var6;
-  ulonglong uVar7;
+  ulonglong uVar2;
+  undefined4 uVar3;
+  char cVar4;
+  char cVar5;
+  CClfsLogFcbCommon *pCVar6;
+  __uint64 _Var7;
   ulonglong uVar8;
   code *pcVar9;
   undefined1 uVar10;
   int local_64;
   ulonglong local_58;
   void *local_50;
   longlong local_48;
   ulonglong local_40;
   CClfsLogFcbPhysical *local_38;
   
   local_58 = 0;
   local_50 = (void *)0x0;
   local_48 = 0;
   local_64 = 0;
-  cVar3 = '\0';
+  cVar5 = '\0';
   uVar10 = 0;
   pCVar1 = this + 200;
   local_38 = pCVar1;
-  cVar2 = ExAcquireResourceSharedLite(pCVar1,1);
+  cVar4 = ExAcquireResourceSharedLite(pCVar1,1);
   if (*(longlong *)(param_1 + 0x30) == 0) {
     pcVar9 = (code *)**(undefined8 **)this;
-    pCVar5 = CClfsLogFcbCommon::FcbFromFileObject(param_1);
-    local_64 = (*pcVar9)(this,param_1,pCVar5);
+    pCVar6 = CClfsLogFcbCommon::FcbFromFileObject(param_1);
+    local_64 = (*pcVar9)(this,param_1,pCVar6);
     if (local_64 < 0) goto LAB_0;
   }
-  _Var6 = LsnToCacheOffset(this,param_2);
-  local_58 = _Var6 + ((uint)((longlong)_Var6 >> 0x3f) & 0xfff) & 0xfffffffffffff000;
-  uVar8 = _Var6 - local_58;
-  uVar4 = 1;
+  _Var7 = LsnToCacheOffset(this,param_2);
+  local_58 = ((uint)((longlong)_Var7 >> 0x3f) & 0xfff) + _Var7 & 0xfffffffffffff000;
+  uVar8 = _Var7 - local_58;
+  uVar3 = 1;
   if (0 < *(int *)(this + 0x530)) {
-    uVar4 = 0x41;
+    uVar3 = 0x41;
   }
   local_40 = uVar8;
-  uVar7 = Feature_2458037564__private_IsEnabledDeviceUsage();
-  if (((int)uVar7 == 0) ||
-     (((-1 < (longlong)local_58 && (local_58 + param_3 < 0x8000000000000000)) &&
-      ((longlong)(local_58 + param_3) <= *(longlong *)(this + 0x50))))) {
-    cVar3 = CcMapData(param_1,&local_58,param_3,uVar4,&local_50,&local_48,uVar10);
-    *param_5 = local_50;
-    *param_6 = (void *)((uVar8 & 0xffffffff) + local_48);
+  if (-1 < (longlong)local_58) {
+    uVar2 = local_58 + param_3;
+    if ((((longlong)local_58 < 0) || (uVar2 < 0x8000000000000000)) &&
+       ((longlong)uVar2 <= *(longlong *)(this + 0x50))) {
+      cVar5 = CcMapData(param_1,&local_58,(ulonglong)param_3,uVar3,&local_50,&local_48,uVar10,uVar3)
+      ;
+      *param_5 = local_50;
+      *param_6 = (void *)((uVar8 & 0xffffffff) + local_48);
+      goto LAB_0;
+    }
   }
-  else {
-    local_64 = -0x3fe5fff3;
-  }
+  local_64 = -0x3fe5fff3;
 LAB_0:
-  if ((cVar3 == '\0') && (local_64 == 0)) {
+  if ((cVar5 == '\0') && (local_64 == 0)) {
     local_64 = -0x3fffffff;
   }
-  if (cVar2 != '\0') {
+  if (cVar4 != '\0') {
     ExReleaseResourceForThreadLite(pCVar1,SystemReserved1[0xf]);
   }
   return local_64;
 }
 

```


## CClfsBaseFile::GetSymbol

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.48|
|i_ratio|0.4|
|m_ratio|0.94|
|b_ratio|0.88|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|GetSymbol|GetSymbol|
|fullname|CClfsBaseFile::GetSymbol|CClfsBaseFile::GetSymbol|
|refcount|6|6|
|`length`|293|249|
|`called`|CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite|
|calling|CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFilePersisted::LoadContainerQ|CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|4|4|
|`address`|1c0061428|1c0060540|
|sig|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, uchar param_2, _CLFS_CLIENT_CONTEXT * * param_3)|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, uchar param_2, _CLFS_CLIENT_CONTEXT * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::GetSymbol Called Diff


```diff
--- CClfsBaseFile::GetSymbol called
+++ CClfsBaseFile::GetSymbol called
@@ -1 +1 @@
-CClfsBaseFile::GetBaseLogRecord
+CClfsBaseFile::OffsetToAddr
```


### CClfsBaseFile::GetSymbol Diff


```diff
--- CClfsBaseFile::GetSymbol
+++ CClfsBaseFile::GetSymbol
@@ -1,60 +1,52 @@
 
 /* public: long __cdecl CClfsBaseFile::GetSymbol(long,unsigned char,struct _CLFS_CLIENT_CONTEXT *
    __ptr64 * __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::GetSymbol
           (CClfsBaseFile *this,long param_1,uchar param_2,_CLFS_CLIENT_CONTEXT **param_3)
 
 {
-  char cVar1;
-  _CLFS_BASE_RECORD_HEADER *p_Var2;
-  uint uVar3;
+  longlong lVar1;
+  char cVar2;
+  _CLFS_CLIENT_CONTEXT *p_Var3;
+  undefined4 in_register_00000014;
   long lVar4;
-  longlong lVar5;
+  uint uVar5;
   bool bVar6;
   
   lVar4 = 0;
   if ((uint)param_1 < 0x1368) {
     return -0x3fe5fff3;
   }
   *param_3 = (_CLFS_CLIENT_CONTEXT *)0x0;
-  cVar1 = ExAcquireResourceSharedLite(*(undefined8 *)(this + 0x20));
-  lVar5 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
-  if ((lVar5 == 0) || (uVar3 = *(int *)(lVar5 + 0x28) + param_1 + 0x87U, uVar3 < param_1 + 0x87U)) {
+  cVar2 = ExAcquireResourceSharedLite
+                    (*(undefined8 *)(this + 0x20),
+                     CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
+  lVar1 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
+  if ((lVar1 == 0) || (uVar5 = *(int *)(lVar1 + 0x28) + param_1 + 0x87U, uVar5 < param_1 + 0x87U)) {
     bVar6 = false;
   }
   else {
-    bVar6 = uVar3 < (uint)*(ushort *)(lVar5 + 4) << 9;
+    bVar6 = uVar5 < (uint)*(ushort *)(lVar1 + 4) << 9;
   }
-  if (bVar6) {
-    p_Var2 = GetBaseLogRecord(this);
-    uVar3 = *(int *)(lVar5 + 0x28) + param_1;
-    if (((uVar3 < (uint)param_1) || (p_Var2 == (_CLFS_BASE_RECORD_HEADER *)0x0)) ||
-       ((uint)*(ushort *)(lVar5 + 4) << 9 <= uVar3)) {
-      p_Var2 = (_CLFS_BASE_RECORD_HEADER *)0x0;
+  if ((bVar6) && (p_Var3 = OffsetToAddr(this,param_1), p_Var3 != (_CLFS_CLIENT_CONTEXT *)0x0)) {
+    if (*(int *)(p_Var3 + -0xc) != param_1) {
+      lVar4 = -0x3ffffff8;
+      goto LAB_0;
     }
-    else {
-      p_Var2 = p_Var2 + (uint)param_1;
-    }
-    if (p_Var2 != (_CLFS_BASE_RECORD_HEADER *)0x0) {
-      if (*(int *)(p_Var2 + -0xc) != param_1) {
-        lVar4 = -0x3ffffff8;
-        goto LAB_0;
-      }
-      if ((((longlong)*(int *)(p_Var2 + -0x10) == (ulonglong)(*(int *)(p_Var2 + -0xc) + 0x88)) &&
-          (*(int *)p_Var2 == -0x3e020ff9)) &&
-         ((*(int *)(p_Var2 + 4) == 0x88 && (p_Var2[8] == (_CLFS_BASE_RECORD_HEADER)param_2)))) {
-        *param_3 = (_CLFS_CLIENT_CONTEXT *)p_Var2;
-        goto LAB_0;
-      }
+    if (((((longlong)*(int *)(p_Var3 + -0x10) == (ulonglong)(*(int *)(p_Var3 + -0xc) + 0x88)) &&
+         (*(int *)p_Var3 == -0x3e020ff9)) && (*(int *)(p_Var3 + 4) == 0x88)) &&
+       (p_Var3[8] == (_CLFS_CLIENT_CONTEXT)param_2)) {
+      *param_3 = p_Var3;
+      goto LAB_0;
     }
   }
   lVar4 = -0x3fe5fff3;
 LAB_0:
-  if (cVar1 != '\0') {
+  if (cVar2 != '\0') {
     UnlockImage(this);
   }
   return lVar4;
 }
 

```


## CClfsBaseFile::AcquireSharedSecurityContext

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.95|
|i_ratio|0.7|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|AcquireSharedSecurityContext|AcquireSharedSecurityContext|
|fullname|CClfsBaseFile::AcquireSharedSecurityContext|CClfsBaseFile::AcquireSharedSecurityContext|
|refcount|4|4|
|`length`|143|157|
|called|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|
|calling|CClfsBaseFile::QuerySharedSecurityInformation<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsLogFcbPhysical::AcquireClientSharedSecurityContext|CClfsBaseFile::QuerySharedSecurityInformation<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsLogFcbPhysical::AcquireClientSharedSecurityContext|
|paramcount|3|3|
|`address`|1c0037ce4|1c0037cf4|
|sig|long __thiscall AcquireSharedSecurityContext(CClfsBaseFile * this, void * param_1, _CLFS_SHARED_SECURITY_CONTEXT * * param_2)|long __thiscall AcquireSharedSecurityContext(CClfsBaseFile * this, void * param_1, _CLFS_SHARED_SECURITY_CONTEXT * * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::AcquireSharedSecurityContext Diff


```diff
--- CClfsBaseFile::AcquireSharedSecurityContext
+++ CClfsBaseFile::AcquireSharedSecurityContext
@@ -1,38 +1,35 @@
 
 /* public: long __cdecl CClfsBaseFile::AcquireSharedSecurityContext(void * __ptr64 const,struct
    _CLFS_SHARED_SECURITY_CONTEXT * __ptr64 & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::AcquireSharedSecurityContext
           (CClfsBaseFile *this,void *param_1,_CLFS_SHARED_SECURITY_CONTEXT **param_2)
 
 {
   char cVar1;
   _CLFS_SHARED_SECURITY_CONTEXT *p_Var2;
   int iVar3;
-  char cVar4;
   
   *param_2 = (_CLFS_SHARED_SECURITY_CONTEXT *)0x0;
   cVar1 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20),1);
-  cVar4 = cVar1;
   p_Var2 = OffsetToAddr(this,(ulong)param_1);
   if (p_Var2 == (_CLFS_SHARED_SECURITY_CONTEXT *)0x0) {
     iVar3 = -0x3fe5fff3;
-    cVar1 = cVar4;
   }
   else {
     *param_2 = p_Var2;
     LOCK();
     *(int *)(p_Var2 + 0xc) = *(int *)(p_Var2 + 0xc) + 1;
     UNLOCK();
     LOCK();
     *(int *)(*param_2 + 8) = *(int *)(*param_2 + 8) + 1;
     UNLOCK();
     iVar3 = 0;
   }
   if ((iVar3 < 0) && (cVar1 != '\0')) {
     UnlockImage(this);
   }
   return iVar3;
 }
 

```


## CClfsBaseFilePersisted::OpenImage

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length|
|ratio|0.71|
|i_ratio|0.49|
|m_ratio|0.98|
|b_ratio|0.88|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|OpenImage|OpenImage|
|fullname|CClfsBaseFilePersisted::OpenImage|CClfsBaseFilePersisted::OpenImage|
|refcount|3|3|
|`length`|1341|1369|
|called|<details><summary>Expand for full list:<br>CClfsAuthContainer::CClfsAuthContainer<br>CClfsAuthContainer::GetContainerSize<br>CClfsAuthContainer::GetRawSectorSize<br>CClfsAuthContainer::Initialize<br>CClfsAuthContainer::Open<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetSize<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::Initialize</summary>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadImage<br>CClfsContainer::IsNullSecurityDescriptor<br>NTOSKRNL.EXE::ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>WPP_SF_slS<br>_guard_dispatch_icall<br>memcpy</details>|<details><summary>Expand for full list:<br>CClfsAuthContainer::CClfsAuthContainer<br>CClfsAuthContainer::GetContainerSize<br>CClfsAuthContainer::GetRawSectorSize<br>CClfsAuthContainer::Initialize<br>CClfsAuthContainer::Open<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetSize<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::Initialize</summary>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadImage<br>CClfsContainer::IsNullSecurityDescriptor<br>NTOSKRNL.EXE::ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>WPP_SF_slS<br>_guard_dispatch_icall<br>memcpy</details>|
|calling|CClfsLogFcbPhysical::Initialize<br>CClfsRequest::AuthenticateLogFile|CClfsLogFcbPhysical::Initialize<br>CClfsRequest::AuthenticateLogFile|
|paramcount|5|5|
|address|1c0032664|1c0032664|
|sig|long __thiscall OpenImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, _CLFS_FILTER_CONTEXT * param_2, ulong param_3, uchar * param_4)|long __thiscall OpenImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, _CLFS_FILTER_CONTEXT * param_2, ulong param_3, uchar * param_4)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::OpenImage Diff


```diff
--- CClfsBaseFilePersisted::OpenImage
+++ CClfsBaseFilePersisted::OpenImage
@@ -1,209 +1,222 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: long __cdecl CClfsBaseFilePersisted::OpenImage(struct _UNICODE_STRING * __ptr64,struct
    _CLFS_FILTER_CONTEXT const & __ptr64,unsigned long,unsigned char & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::OpenImage
           (CClfsBaseFilePersisted *this,_UNICODE_STRING *param_1,_CLFS_FILTER_CONTEXT *param_2,
           ulong param_3,uchar *param_4)
 
 {
   ushort uVar1;
   ushort uVar2;
   uint uVar3;
   uchar *puVar4;
   uchar *puVar5;
   uchar uVar6;
   long lVar7;
   int iVar8;
   ulong uVar9;
   CClfsAuthContainer *pCVar10;
   undefined8 *puVar11;
   void *pvVar12;
-  undefined8 *puVar13;
+  undefined8 uVar13;
   _CLFS_BASE_RECORD_HEADER *p_Var14;
   __uint64 _Var15;
+  _CLFS_CONTROL_RECORD *p_Var16;
   uchar local_res20 [8];
   undefined8 in_stack_ffffffffffffff98;
-  undefined8 uVar16;
   undefined4 uVar17;
   void *local_50;
   _CLFS_CONTROL_RECORD *local_48 [2];
   
   uVar17 = (undefined4)((ulonglong)in_stack_ffffffffffffff98 >> 0x20);
-  puVar13 = (undefined8 *)0x0;
+  p_Var16 = (_CLFS_CONTROL_RECORD *)0x0;
   local_48[0] = (_CLFS_CONTROL_RECORD *)0x0;
   local_res20[0] = '\0';
   local_50 = (void *)0x1;
   puVar4 = param_4;
   if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-    uVar16 = CONCAT44(uVar17,0x1da8);
-    WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x21,
-               &WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,"CClfsBaseFilePersisted::OpenImage",
-               uVar16,*(wchar_t **)(param_1 + 8));
-    uVar17 = (undefined4)((ulonglong)uVar16 >> 0x20);
+    uVar13 = CONCAT44(uVar17,0x1d5d);
+    WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1d,
+               &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,"CClfsBaseFilePersisted::OpenImage",
+               uVar13,*(wchar_t **)(param_1 + 8));
+    uVar17 = (undefined4)((ulonglong)uVar13 >> 0x20);
     puVar4 = param_4;
   }
   *puVar4 = '\0';
   uVar3 = param_3 >> 9;
   param_4 = puVar4;
   lVar7 = Initialize(this,param_3);
+  puVar11 = (undefined8 *)0x0;
   if (lVar7 < 0) {
     return lVar7;
   }
   if (*(longlong *)(this + 0x98) == 0) {
     pCVar10 = (CClfsAuthContainer *)ExAllocateFromPagedLookasideList(&CClfsAuthContainer::m_laList);
-    puVar11 = puVar13;
     if (pCVar10 != (CClfsAuthContainer *)0x0) {
       puVar11 = (undefined8 *)
                 CClfsAuthContainer::CClfsAuthContainer
                           (pCVar10,param_3,*(_CLFS_AUTHENTICATION_MODE *)(this + 0xe8),
                            *(_DEVICE_OBJECT **)(this + 0xf0));
     }
     *(undefined8 **)(this + 0x98) = puVar11;
     if (puVar11 == (undefined8 *)0x0) {
       return -0x3fffff66;
     }
     (**(code **)*puVar11)();
     lVar7 = CClfsAuthContainer::Initialize
                       (*(CClfsAuthContainer **)(this + 0x98),(__uint64 *)&local_50,1);
     if (lVar7 < 0) {
       (**(code **)(**(longlong **)(this + 0x98) + 8))();
       *(undefined8 *)(this + 0x98) = 0;
       return lVar7;
     }
   }
   if (*(longlong *)(this + 0x20) == 0) {
     iVar8 = CClfsBaseFile::InitializeImageResource((CClfsBaseFile *)this);
     puVar5 = param_4;
     if (iVar8 < 0) goto LAB_0;
   }
   if (*(longlong *)(this + 0xe0) != 0) {
     ExFreePoolWithTag(*(longlong *)(this + 0xe0),0);
     *(undefined8 *)(this + 0xe0) = 0;
   }
   pvVar12 = (void *)ExAllocatePoolWithTag(1);
   *(void **)(this + 0xe0) = pvVar12;
   if (pvVar12 == (void *)0x0) {
 LAB_1:
     iVar8 = -0x3fffff66;
     puVar5 = param_4;
     goto LAB_0;
   }
   *(short *)(this + 0xda) = *(short *)param_1 + 2;
   uVar1 = *(ushort *)param_1;
   *(ushort *)(this + 0xd8) = uVar1;
   memcpy(pvVar12,*(void **)(param_1 + 8),(ulonglong)uVar1);
   *(undefined2 *)(*(longlong *)(this + 0xe0) + (ulonglong)(*(ushort *)(this + 0xd8) >> 1) * 2) = 0;
   if (*(int *)(param_2 + 0x10) != 0) {
     pvVar12 = (void *)ExAllocatePoolWithTag(1);
     *(void **)(this + 0xb8) = pvVar12;
     if (*(longlong *)(param_2 + 8) == 0) goto LAB_1;
     *(undefined4 *)(this + 0xc0) = *(undefined4 *)(param_2 + 0x10);
     memcpy(pvVar12,*(void **)(param_2 + 8),(ulonglong)*(uint *)(param_2 + 0x10));
   }
   *(undefined8 *)(this + 0xb0) = *(undefined8 *)param_2;
   uVar17 = 0;
   iVar8 = CClfsAuthContainer::Open
                     (*(CClfsAuthContainer **)(this + 0x98),param_1,param_2,(byte)uVar3 & 1,0,
                      local_res20);
+  uVar13 = 0;
   if (iVar8 < 0) {
+    puVar5 = param_4;
+    if (iVar8 != -0x3fffffef) goto LAB_0;
 LAB_2:
-    puVar5 = param_4;
-    if (iVar8 != -0x3fffffef) goto LAB_0;
+    iVar8 = -0x3fe5fff3;
+    puVar5 = param_4;
   }
   else {
     pCVar10 = *(CClfsAuthContainer **)(this + 0x98);
     if ((1 < *(int *)(pCVar10 + 0x88) - 2U) && (*(longlong *)(pCVar10 + 0x90) != 0)) {
-      puVar13 = *(undefined8 **)(*(longlong *)(pCVar10 + 0x90) + 0x1c);
-    }
-    *(undefined8 **)(this + 0xf8) = puVar13;
+      uVar13 = *(undefined8 *)(*(longlong *)(pCVar10 + 0x90) + 0x1c);
+    }
+    *(undefined8 *)(this + 0xf8) = uVar13;
     uVar9 = CClfsAuthContainer::GetRawSectorSize(pCVar10);
     *(ulong *)(this + 0x90) = uVar9;
     if (((0xfff < uVar9 - 1) || ((uVar9 & 0x1ff) != 0)) || (0x1000U % uVar9 != 0)) {
       iVar8 = -0x3fffff68;
       puVar5 = param_4;
       goto LAB_0;
     }
     iVar8 = ReadImage(this,local_48);
-    if (iVar8 < 0) goto LAB_2;
-    iVar8 = CClfsAuthContainer::GetContainerSize
-                      (*(CClfsAuthContainer **)(this + 0x98),(__uint64 *)(this + 0x88));
-    puVar5 = param_4;
-    if (iVar8 < 0) goto LAB_0;
-    p_Var14 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
-    if (p_Var14 != (_CLFS_BASE_RECORD_HEADER *)0x0) {
-      *(_CLFS_BASE_RECORD_HEADER **)(this + 0x40) = p_Var14 + 0x18;
-      *(undefined4 *)(this + 0x48) = 0xb;
-      *(CClfsBaseFilePersisted **)(this + 0x50) = this;
-      *(_CLFS_BASE_RECORD_HEADER **)(this + 0x58) = p_Var14 + 0x70;
-      *(undefined4 *)(this + 0x60) = 0xb;
-      *(CClfsBaseFilePersisted **)(this + 0x68) = this;
-      *(_CLFS_BASE_RECORD_HEADER **)(this + 0x70) = p_Var14 + 200;
-      *(undefined4 *)(this + 0x78) = 0xb;
-      *(CClfsBaseFilePersisted **)(this + 0x80) = this;
-      puVar5 = param_4;
-      if (*(int *)(local_48[0] + 0x14) == 0) goto LAB_0;
-      uVar1 = *(ushort *)(local_48[0] + 0x18);
-      if (((((uVar1 != 0) && (uVar1 < *(ushort *)(this + 0x28))) &&
-           (((uVar1 - 2 & 0xfffd) == 0 &&
-            ((uVar2 = *(ushort *)(local_48[0] + 0x1a), uVar2 != 0 &&
-             (uVar2 < *(ushort *)(this + 0x28))))))) && (uVar2 < 6)) && (uVar1 <= uVar2)) {
-        _Var15 = CClfsBaseFile::GetSize((CClfsBaseFile *)this);
-        if (*(uint *)(local_48[0] + 0x20) <= ((uint)(_Var15 >> 9) & 0x7fffff)) {
-          if (*(uint *)(local_48[0] + 0x1c) <=
-              (*(uint *)(*(longlong *)(this + 0x30) + 8 +
-                        (ulonglong)*(ushort *)(local_48[0] + 0x18) * 0x18) >> 9) +
-              (*(uint *)(local_48[0] + 0x24) >> 1)) {
-            iVar8 = ExtendMetadataBlock(this,(uint)*(ushort *)(local_48[0] + 0x18),
-                                        *(uint *)(local_48[0] + 0x24) >> 1);
-            puVar5 = param_4;
-            goto LAB_0;
+    if (iVar8 < 0) {
+      p_Var16 = local_48[0];
+      puVar5 = param_4;
+      if (iVar8 != -0x3fffffef) goto LAB_0;
+    }
+    else {
+      iVar8 = CClfsAuthContainer::GetContainerSize
+                        (*(CClfsAuthContainer **)(this + 0x98),(__uint64 *)(this + 0x88));
+      p_Var16 = local_48[0];
+      puVar5 = param_4;
+      if (iVar8 < 0) goto LAB_0;
+      p_Var14 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
+      p_Var16 = local_48[0];
+      if (p_Var14 != (_CLFS_BASE_RECORD_HEADER *)0x0) {
+        *(_CLFS_BASE_RECORD_HEADER **)(this + 0x40) = p_Var14 + 0x18;
+        *(undefined4 *)(this + 0x48) = 0xb;
+        *(CClfsBaseFilePersisted **)(this + 0x50) = this;
+        *(_CLFS_BASE_RECORD_HEADER **)(this + 0x58) = p_Var14 + 0x70;
+        *(undefined4 *)(this + 0x60) = 0xb;
+        *(CClfsBaseFilePersisted **)(this + 0x68) = this;
+        *(_CLFS_BASE_RECORD_HEADER **)(this + 0x70) = p_Var14 + 200;
+        *(undefined4 *)(this + 0x78) = 0xb;
+        *(CClfsBaseFilePersisted **)(this + 0x80) = this;
+        puVar5 = param_4;
+        if (*(int *)(local_48[0] + 0x14) == 0) goto LAB_0;
+        uVar1 = *(ushort *)(local_48[0] + 0x18);
+        if (((((uVar1 != 0) && (uVar1 < *(ushort *)(this + 0x28))) &&
+             (((uVar1 - 2 & 0xfffd) == 0 &&
+              ((uVar2 = *(ushort *)(local_48[0] + 0x1a), uVar2 != 0 &&
+               (uVar2 < *(ushort *)(this + 0x28))))))) && (uVar2 < 6)) && (uVar1 <= uVar2)) {
+          _Var15 = CClfsBaseFile::GetSize((CClfsBaseFile *)this);
+          if (*(uint *)(p_Var16 + 0x20) <= ((uint)(_Var15 >> 9) & 0x7fffff)) {
+            if (*(uint *)(p_Var16 + 0x1c) <=
+                (*(uint *)(*(longlong *)(this + 0x30) + 8 +
+                          (ulonglong)*(ushort *)(p_Var16 + 0x18) * 0x18) >> 9) +
+                (*(uint *)(p_Var16 + 0x24) >> 1)) {
+              iVar8 = ExtendMetadataBlock(this,(uint)*(ushort *)(p_Var16 + 0x18),
+                                          *(uint *)(p_Var16 + 0x24) >> 1);
+              puVar5 = param_4;
+              goto LAB_0;
+            }
           }
         }
+        goto LAB_2;
       }
     }
-  }
-  iVar8 = -0x3fe5fff3;
-  puVar5 = param_4;
+    iVar8 = -0x3fe5fff3;
+    p_Var16 = local_48[0];
+    puVar5 = param_4;
+  }
 LAB_0:
   param_4._4_4_ = (undefined4)((ulonglong)puVar5 >> 0x20);
   local_50 = (void *)0x0;
   if (-1 < iVar8) {
     if (local_res20[0] != '\0') {
       param_4._0_4_ = 0;
       lVar7 = QueryContainerSecurity
                         (*(CClfsAuthContainer **)(this + 0x98),&local_50,0,(ulong *)&param_4);
       puVar5 = (uchar *)CONCAT44(param_4._4_4_,param_4._0_4_);
       iVar8 = 0;
       if (lVar7 < 0) {
         iVar8 = lVar7;
       }
       if (-1 < iVar8) {
         uVar6 = CClfsContainer::IsNullSecurityDescriptor(local_50);
         if (uVar6 == '\0') {
           *puVar4 = '\x01';
         }
         ExFreePoolWithTag(local_50);
         puVar5 = (uchar *)CONCAT44(param_4._4_4_,param_4._0_4_);
       }
     }
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
       param_4 = puVar5;
-      WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x22,
-                 &WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,
-                 "CClfsBaseFilePersisted::OpenImage",CONCAT44(uVar17,0x1efc),
+      WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1e,
+                 &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,
+                 "CClfsBaseFilePersisted::OpenImage",CONCAT44(uVar17,0x1eb1),
                  *(wchar_t **)(param_1 + 8));
       puVar5 = param_4;
     }
   }
-  if (local_48[0] != (_CLFS_CONTROL_RECORD *)0x0) {
+  if (p_Var16 != (_CLFS_CONTROL_RECORD *)0x0) {
     param_4 = puVar5;
     CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
   }
   return iVar8;
 }
 

```


## `CClfsBaseFilePersisted::CreateImage'::__l1::fin$0

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.94|
|i_ratio|0.66|
|m_ratio|1.0|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|fin$0|fin$0|
|fullname|`CClfsBaseFilePersisted::CreateImage'::__l1::fin$0|`CClfsBaseFilePersisted::CreateImage'::__l1::fin$0|
|refcount|1|1|
|`length`|164|160|
|called|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsContainer::IsNullSecurityDescriptor<br>WPP_SF_slSD|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsContainer::IsNullSecurityDescriptor<br>WPP_SF_slSD|
|calling|||
|paramcount|2|2|
|`address`|1c007af0f|1c007aac6|
|sig|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### `CClfsBaseFilePersisted::CreateImage'::__l1::fin$0 Diff


```diff
--- `CClfsBaseFilePersisted::CreateImage'::__l1::fin$0
+++ `CClfsBaseFilePersisted::CreateImage'::__l1::fin$0
@@ -1,27 +1,26 @@
 
 void `CClfsBaseFilePersisted::CreateImage'::__l1::fin_0(undefined8 param_1,longlong param_2)
 
 {
   uchar uVar1;
   
   if ((*(longlong *)(param_2 + 0x50) != 0) &&
      (*(longlong *)(*(CClfsBaseFile **)(param_2 + 0xb0) + 0x1d0) == 0)) {
     CClfsBaseFile::ReleaseMetadataBlock(*(CClfsBaseFile **)(param_2 + 0xb0),0);
-    *(undefined8 *)(param_2 + 0x50) = 0;
   }
   if (-1 < *(int *)(param_2 + 0x44)) {
     if ((*(char *)(param_2 + 0xc0) != '\0') &&
        ((*(void **)(param_2 + 0xd8) == (void *)0x0 ||
         (uVar1 = CClfsContainer::IsNullSecurityDescriptor(*(void **)(param_2 + 0xd8)), uVar1 == '\0'
         )))) {
       **(undefined1 **)(param_2 + 0xe8) = 1;
     }
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1a & 1) != 0)) {
-      WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x20);
+      WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1c);
     }
     return;
   }
   return;
 }
 

```


## CClfsBaseFile::GetControlRecord

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.13|
|i_ratio|0.18|
|m_ratio|0.82|
|b_ratio|0.78|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|GetControlRecord|GetControlRecord|
|fullname|CClfsBaseFile::GetControlRecord|CClfsBaseFile::GetControlRecord|
|refcount|6|6|
|`length`|1091|752|
|`called`|CClfsBaseFile::AcquireMetadataBlock<br>Feature_1868496191__private_IsEnabledDeviceUsage<br>WPP_SF_sdHH<br>WPP_SF_sdLH<br>WPP_SF_sdLL<br>WPP_SF_sdLLH<br>WPP_SF_sddLL<br>WPP_SF_sdddLL|CClfsBaseFile::AcquireMetadataBlock<br>WPP_SF_sdHH<br>WPP_SF_sdLH<br>WPP_SF_sdLLH<br>WPP_SF_sddLL<br>WPP_SF_sdddLL|
|calling|CClfsBaseFilePersisted::AcquireTruncateContext<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::ReadImage|CClfsBaseFilePersisted::AcquireTruncateContext<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::ReadImage|
|paramcount|3|3|
|address|1c0039f64|1c0039f64|
|sig|long __thiscall GetControlRecord(CClfsBaseFile * this, _CLFS_CONTROL_RECORD * * param_1, uchar param_2)|long __thiscall GetControlRecord(CClfsBaseFile * this, _CLFS_CONTROL_RECORD * * param_1, uchar param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::GetControlRecord Called Diff


```diff
--- CClfsBaseFile::GetControlRecord called
+++ CClfsBaseFile::GetControlRecord called
@@ -2 +1,0 @@
-Feature_1868496191__private_IsEnabledDeviceUsage
@@ -5 +3,0 @@
-WPP_SF_sdLL
```


### CClfsBaseFile::GetControlRecord Diff


```diff
--- CClfsBaseFile::GetControlRecord
+++ CClfsBaseFile::GetControlRecord
@@ -1,154 +1,89 @@
 
 /* protected: long __cdecl CClfsBaseFile::GetControlRecord(struct _CLFS_CONTROL_RECORD * __ptr64 &
    __ptr64,unsigned char) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::GetControlRecord(CClfsBaseFile *this,_CLFS_CONTROL_RECORD **param_1,uchar param_2)
 
 {
-  ushort uVar1;
+  _CLFS_CONTROL_RECORD *p_Var1;
   ushort uVar2;
-  uint uVar3;
+  ushort uVar3;
   uint uVar4;
-  longlong lVar5;
-  long lVar6;
-  ulonglong uVar7;
+  uint uVar5;
+  longlong lVar6;
+  long lVar7;
   uint uVar8;
-  undefined2 uVar9;
-  _CLFS_CONTROL_RECORD *p_Var10;
-  _CLFS_CONTROL_RECORD *p_Var11;
-  longlong lVar12;
-  uint uVar13;
+  _CLFS_CONTROL_RECORD *p_Var9;
+  ulonglong uVar10;
+  ulonglong uVar11;
   
-  uVar13 = 0;
+  uVar10 = 0;
   *param_1 = (_CLFS_CONTROL_RECORD *)0x0;
-  lVar6 = AcquireMetadataBlock(this,0);
-  if (lVar6 < 0) {
-    return lVar6;
-  }
-  lVar5 = **(longlong **)(this + 0x30);
-  uVar3 = *(uint *)(*(longlong **)(this + 0x30) + 1);
-  p_Var11 = (_CLFS_CONTROL_RECORD *)((ulonglong)*(uint *)(lVar5 + 0x28) + lVar5);
-  if ((uint)*(ushort *)(lVar5 + 4) << 9 != uVar3) {
-    uVar7 = Feature_1868496191__private_IsEnabledDeviceUsage();
-    if ((int)uVar7 == 0) {
-      if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-        return -0x3fe5fff3;
-      }
-      if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-        return -0x3fe5fff3;
-      }
-      uVar9 = 0xe;
-    }
-    else {
-      if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-        return -0x3fe5fff3;
-      }
-      if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-        return -0x3fe5fff3;
-      }
-      uVar9 = 0xd;
-    }
-    WPP_SF_sdLH(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),uVar9);
-    return -0x3fe5fff3;
-  }
-  uVar7 = Feature_1868496191__private_IsEnabledDeviceUsage();
-  if ((((int)uVar7 == 0) && (param_2 == '\0')) && (*(short *)(p_Var11 + 0x48) != 6)) {
-    if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-      return -0x3fe5fff3;
-    }
-    if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-      return -0x3fe5fff3;
-    }
-    WPP_SF_sdLL(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
-    return -0x3fe5fff3;
-  }
-  uVar7 = Feature_1868496191__private_IsEnabledDeviceUsage();
-  uVar8 = *(uint *)(lVar5 + 0x28);
-  lVar12 = 0;
-  if ((int)uVar7 == 0) {
-    if ((((uVar3 <= uVar8) || (uVar8 < 0x70)) ||
-        ((uVar3 - uVar8 < 0x68 ||
-         (((ulonglong)((uVar3 - uVar8) - 0x50) < (ulonglong)*(ushort *)(p_Var11 + 0x48) * 0x18 ||
-          (uVar4 = *(uint *)(lVar5 + 0x68),
-          (ulonglong)uVar4 <
-          (ulonglong)(uVar8 + 0x50) + (ulonglong)*(ushort *)(p_Var11 + 0x48) * 0x18)))))) ||
-       ((uVar3 < uVar4 ||
-        ((uVar8 = (uint)*(ushort *)(lVar5 + 4) + (uint)*(ushort *)(lVar5 + 4) + uVar4, uVar8 < uVar4
-         || (uVar3 < uVar8)))))) {
-      if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-        return -0x3fe5fff3;
-      }
-      if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-        return -0x3fe5fff3;
-      }
-      uVar9 = 0x11;
-      goto LAB_0;
-    }
-  }
-  else if (((((uVar3 <= uVar8) || (uVar8 < 0x70)) || (uVar3 - uVar8 < 0x68)) ||
-           ((param_2 == '\0' && (*(short *)(p_Var11 + 0x48) != 6)))) ||
-          (((((ulonglong)((uVar3 - uVar8) - 0x50) < (ulonglong)*(ushort *)(p_Var11 + 0x48) * 0x18 ||
-             ((uVar4 = *(uint *)(lVar5 + 0x68),
-              (ulonglong)uVar4 <
-              (ulonglong)(uVar8 + 0x50) + (ulonglong)*(ushort *)(p_Var11 + 0x48) * 0x18 ||
-              (uVar3 < uVar4)))) ||
-            (uVar8 = (uint)*(ushort *)(lVar5 + 4) + (uint)*(ushort *)(lVar5 + 4) + uVar4,
-            uVar8 < uVar4)) || (uVar3 < uVar8)))) {
-    if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-      return -0x3fe5fff3;
-    }
-    if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-      return -0x3fe5fff3;
-    }
-    uVar9 = 0x10;
-LAB_0:
-    WPP_SF_sdLLH(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),uVar9);
-    return -0x3fe5fff3;
-  }
-  p_Var10 = p_Var11 + 0x58;
-  do {
-    if ((lVar12 < 4) || (*(int *)p_Var10 != 0)) {
-      uVar3 = *(uint *)(p_Var10 + 4);
-      if (uVar3 < uVar13) {
-        if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-          return -0x3fe5fff3;
+  lVar7 = AcquireMetadataBlock(this,0);
+  if (-1 < lVar7) {
+    lVar6 = **(longlong **)(this + 0x30);
+    uVar4 = *(uint *)(*(longlong **)(this + 0x30) + 1);
+    uVar8 = *(uint *)(lVar6 + 0x28);
+    p_Var1 = (_CLFS_CONTROL_RECORD *)(lVar6 + (ulonglong)uVar8);
+    if ((uint)*(ushort *)(lVar6 + 4) << 9 == uVar4) {
+      if ((((((uVar8 < uVar4) && (0x6f < uVar8)) && (0x67 < uVar4 - uVar8)) &&
+           ((param_2 != '\0' || (*(short *)(p_Var1 + 0x48) == 6)))) &&
+          ((((ulonglong)*(ushort *)(p_Var1 + 0x48) * 0x18 <= (ulonglong)((uVar4 - uVar8) - 0x50) &&
+            ((uVar5 = *(uint *)(lVar6 + 0x68),
+             (ulonglong)(uVar8 + 0x50) + (ulonglong)*(ushort *)(p_Var1 + 0x48) * 0x18 <=
+             (ulonglong)uVar5 && (uVar5 <= uVar4)))) &&
+           (uVar8 = (uint)*(ushort *)(lVar6 + 4) * 2 + uVar5, uVar5 <= uVar8)))) && (uVar8 <= uVar4)
+         ) {
+        p_Var9 = p_Var1 + 0x58;
+        uVar11 = uVar10;
+        do {
+          if (((longlong)uVar11 < 4) || (*(int *)p_Var9 != 0)) {
+            uVar4 = *(uint *)(p_Var9 + 4);
+            if (uVar4 < (uint)uVar10) {
+              if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+                WPP_SF_sdddLL(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
+              }
+              goto LAB_0;
+            }
+            uVar10 = (ulonglong)(*(int *)p_Var9 + uVar4);
+            if (*(int *)p_Var9 + uVar4 < uVar4) {
+              if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+                WPP_SF_sddLL(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
+              }
+              goto LAB_0;
+            }
+          }
+          uVar11 = uVar11 + 1;
+          p_Var9 = p_Var9 + 0x18;
+        } while ((longlong)uVar11 < 6);
+        if ((*(int *)(p_Var1 + 0x14) == 0) ||
+           ((((uVar2 = *(ushort *)(p_Var1 + 0x18), uVar2 != 0 && (uVar2 < *(ushort *)(this + 0x28)))
+             && ((uVar2 - 2 & 0xfffd) == 0)) &&
+            (((uVar3 = *(ushort *)(p_Var1 + 0x1a), uVar3 != 0 && (uVar3 < *(ushort *)(this + 0x28)))
+             && (uVar2 <= uVar3)))))) {
+          *param_1 = p_Var1;
+          return 0;
         }
-        if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-          return -0x3fe5fff3;
-        }
-        WPP_SF_sdddLL(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
-        return -0x3fe5fff3;
-      }
-      uVar13 = *(int *)p_Var10 + uVar3;
-      if (uVar13 < uVar3) {
-        if ((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-          return -0x3fe5fff3;
-        }
-        if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) == 0) {
-          return -0x3fe5fff3;
-        }
-        WPP_SF_sddLL(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
-        return -0x3fe5fff3;
-      }
-    }
-    lVar12 = lVar12 + 1;
-    p_Var10 = p_Var10 + 0x18;
-    if (5 < lVar12) {
-      if ((*(int *)(p_Var11 + 0x14) != 0) &&
-         ((((uVar1 = *(ushort *)(p_Var11 + 0x18), uVar1 == 0 || (*(ushort *)(this + 0x28) <= uVar1))
-           || ((uVar1 - 2 & 0xfffd) != 0)) ||
-          (((uVar2 = *(ushort *)(p_Var11 + 0x1a), uVar2 == 0 || (*(ushort *)(this + 0x28) <= uVar2))
-           || (uVar2 < uVar1)))))) {
         if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
            ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
           WPP_SF_sdHH(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
         }
-        return -0x3fe5fff3;
       }
-      *param_1 = p_Var11;
-      return 0;
+      else if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+              ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+        WPP_SF_sdLLH(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
+      }
     }
-  } while( true );
+    else if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+            ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+      WPP_SF_sdLH(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0xc);
+    }
+LAB_0:
+    lVar7 = -0x3fe5fff3;
+  }
+  return lVar7;
 }
 

```


## CClfsLogFcbPhysical::UpdateCachedOwnerPage

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.18|
|i_ratio|0.35|
|m_ratio|0.97|
|b_ratio|0.59|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|UpdateCachedOwnerPage|UpdateCachedOwnerPage|
|fullname|CClfsLogFcbPhysical::UpdateCachedOwnerPage|CClfsLogFcbPhysical::UpdateCachedOwnerPage|
|refcount|2|2|
|`length`|2668|2445|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::UpdateOwnerReferrals<br>CClfsLogFcbPhysical::UpdateOwnerSectors<br>ClfsGetFirstRecord<br>ClfsValidateSector</summary>Feature_2458037564__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>memcpy</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::UpdateOwnerReferrals<br>CClfsLogFcbPhysical::UpdateOwnerSectors<br>ClfsGetFirstRecord<br>ClfsValidateSector</summary>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>memcpy</details>|
|calling|CClfsLogFcbPhysical::RebuildOwnerPage|CClfsLogFcbPhysical::RebuildOwnerPage|
|paramcount|4|4|
|`address`|1c00630f4|1c006272c|
|sig|long __thiscall UpdateCachedOwnerPage(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar param_2, ulong param_3)|long __thiscall UpdateCachedOwnerPage(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar param_2, ulong param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::UpdateCachedOwnerPage Called Diff


```diff
--- CClfsLogFcbPhysical::UpdateCachedOwnerPage called
+++ CClfsLogFcbPhysical::UpdateCachedOwnerPage called
@@ -12 +11,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::UpdateCachedOwnerPage Diff


```diff
--- CClfsLogFcbPhysical::UpdateCachedOwnerPage
+++ CClfsLogFcbPhysical::UpdateCachedOwnerPage
@@ -1,382 +1,360 @@
 
 /* private: long __cdecl CClfsLogFcbPhysical::UpdateCachedOwnerPage(struct _FILE_OBJECT *
    __ptr64,unsigned char,unsigned long) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::UpdateCachedOwnerPage
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,uchar param_2,ulong param_3)
 
 {
-  _CLFS_LOG_BLOCK_HEADER *p_Var1;
-  CClfsLogFcbPhysical *pCVar2;
-  ushort uVar3;
-  ushort uVar4;
-  undefined8 uVar5;
-  undefined8 uVar6;
-  bool bVar7;
-  _CLFS_LOG_BLOCK_HEADER *p_Var8;
-  uchar uVar9;
-  _CLFS_LOG_BLOCK_HEADER _Var10;
+  CClfsLogFcbPhysical *pCVar1;
+  ushort uVar2;
+  undefined8 uVar3;
+  undefined8 uVar4;
+  int iVar5;
+  bool bVar6;
+  _CLFS_LOG_BLOCK_HEADER *p_Var7;
+  uchar uVar8;
+  _CLFS_LOG_BLOCK_HEADER _Var9;
+  uint uVar10;
   long lVar11;
   __uint64 *p_Var12;
   undefined8 *puVar13;
   _CLS_LSN *p_Var14;
-  __uint64 _Var15;
-  ulonglong uVar16;
-  _CLFS_LOG_BLOCK_HEADER *p_Var17;
-  _CLFS_LOG_BLOCK_HEADER *p_Var18;
-  __uint64 _Var19;
-  _CLFS_RECORD_HEADER *p_Var20;
-  longlong *plVar21;
-  uint uVar22;
+  ulonglong *puVar15;
+  __uint64 _Var16;
+  _CLFS_RECORD_HEADER *p_Var17;
+  longlong *plVar18;
+  ulonglong uVar19;
+  uint uVar20;
+  _CLFS_LOG_BLOCK_HEADER *p_Var21;
+  _CLFS_LOG_BLOCK_HEADER *p_Var22;
   uint uVar23;
-  _CLFS_LOG_BLOCK_HEADER *p_Var24;
-  _CLFS_LOG_BLOCK_HEADER *p_Var25;
-  long lVar26;
-  ulonglong uVar27;
+  longlong lVar24;
+  longlong lVar25;
+  uint uVar26;
+  ulong uVar27;
   _CLFS_LOG_BLOCK_HEADER *p_Var28;
-  longlong lVar29;
-  longlong lVar30;
-  uint uVar31;
-  bool bVar32;
+  bool bVar29;
   ulong local_res20;
   _CLS_LSN *in_stack_fffffffffffffe88;
-  _CLFS_LOG_BLOCK_HEADER *local_150;
-  uchar local_148 [4];
-  long local_144;
+  uchar local_150 [8];
+  undefined8 local_148;
   undefined8 local_140;
-  _CLFS_LOG_BLOCK_HEADER *local_138;
-  uint local_130;
-  undefined8 local_128;
+  uint local_138;
+  undefined8 local_130;
+  uint local_128;
+  uint local_124;
   undefined8 local_120;
   uint local_118;
-  uint local_114;
-  undefined8 local_110;
-  uint local_108;
-  uint local_104;
-  undefined8 local_100;
-  undefined8 local_f8;
-  int local_f0;
-  ulong local_ec;
-  undefined8 local_e8;
-  void *local_e0;
+  _CLFS_LOG_BLOCK_HEADER *local_110;
+  _CLFS_LOG_BLOCK_HEADER *local_108;
+  _CLFS_LOG_BLOCK_HEADER *local_100;
+  int local_f8;
+  ulong local_f4;
+  uint local_f0;
+  void *local_e8;
+  undefined8 local_e0;
   undefined8 local_d8;
-  undefined8 local_d0;
+  uint local_d0;
+  uint local_cc;
   uint local_c8;
-  uint local_c4;
   uint local_c0;
-  uint local_b8;
-  uint uStack_b4;
-  void *local_b0;
-  _CLFS_LOG_BLOCK_HEADER *local_a8;
-  uint local_a0;
-  __uint64 local_98;
-  ulonglong local_90;
-  ulong local_88;
-  undefined8 local_80;
-  _CLS_LSN local_78 [8];
-  _CLS_LSN local_70 [8];
+  uint uStack_bc;
+  void *local_b8;
+  uint local_b0;
+  uint uStack_ac;
+  uint local_a8;
+  ulong local_a4;
+  _CLFS_LOG_BLOCK_HEADER *local_a0;
+  undefined8 local_98;
+  undefined8 local_90;
+  _CLS_LSN local_88 [8];
+  _CLS_LSN local_80 [8];
+  __uint64 local_78;
+  __uint64 local_70;
   _CLS_LSN local_68 [8];
   _CLS_LSN local_60 [8];
   _CLS_LSN local_58 [8];
   _CLS_LSN local_50 [8];
   _CLS_LSN local_48 [8];
   _CLS_LSN local_40 [8];
   
-  uVar9 = (uchar)param_3;
-  uVar5 = *(undefined8 *)(this + 0x1e8);
-  local_f8 = 0;
+  uVar8 = (uchar)param_3;
+  uVar3 = *(undefined8 *)(this + 0x1e8);
+  local_e0 = 0;
+  local_130 = 0;
+  p_Var21 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+  uVar10 = 0;
+  local_b8 = (void *)0x0;
+  local_110 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+  local_e8 = (void *)0x0;
+  bVar29 = false;
+  bVar6 = false;
+  local_124 = 0;
+  local_138 = 0;
   local_128 = 0;
-  local_b0 = (void *)0x0;
-  local_150 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  local_e0 = (void *)0x0;
-  local_144 = 0;
-  bVar32 = false;
-  bVar7 = false;
-  local_114 = 0;
-  local_108 = 0;
-  local_130 = 0;
-  local_ec = 0;
-  local_138 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  local_120 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  pCVar2 = this + 0x568;
-  if (pCVar2 != (CClfsLogFcbPhysical *)0x0) {
-    bVar32 = *(longlong *)pCVar2 == -0x100000000;
-  }
-  local_148[0] = param_2;
-  local_80 = uVar5;
-  if (bVar32) {
+  local_f4 = 0;
+  pCVar1 = this + 0x568;
+  if (pCVar1 != (CClfsLogFcbPhysical *)0x0) {
+    bVar29 = *(longlong *)pCVar1 == -0x100000000;
+  }
+  local_150[0] = param_2;
+  local_90 = uVar3;
+  if (bVar29) {
     *(longlong *)(this + 0x560) = 0;
   }
   else {
-    uVar9 = '\0';
-    p_Var12 = (__uint64 *)AddLsnOffset(this,(_CLS_LSN *)&local_d0,(ulong)pCVar2);
-    local_f8 = *p_Var12;
-    *(longlong *)(this + 0x560) = *(longlong *)pCVar2;
-  }
-  *(__uint64 *)(this + 0x1e8) = local_f8;
-  pCVar2 = this + 0x558;
-  *(__uint64 *)pCVar2 = local_f8;
-  PurgeCacheSection(this,(_CLS_LSN *)&CLFS_LSN_NULL,(_CLS_LSN *)&CLFS_LSN_NULL,uVar9);
-  local_100 = *(longlong *)(this + 0x58);
-  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_d0,(__uint64 *)pCVar2);
+    uVar8 = '\0';
+    p_Var12 = (__uint64 *)AddLsnOffset(this,(_CLS_LSN *)&local_108,(ulong)pCVar1);
+    local_e0 = *p_Var12;
+    *(longlong *)(this + 0x560) = *(longlong *)pCVar1;
+  }
+  *(__uint64 *)(this + 0x1e8) = local_e0;
+  pCVar1 = this + 0x558;
+  *(__uint64 *)pCVar1 = local_e0;
+  PurgeCacheSection(this,(_CLS_LSN *)&CLFS_LSN_NULL,(_CLS_LSN *)&CLFS_LSN_NULL,uVar8);
+  local_100 = *(_CLFS_LOG_BLOCK_HEADER **)(this + 0x58);
+  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_108,(__uint64 *)pCVar1);
   *(undefined8 *)(this + 0x1e0) = *puVar13;
-  local_100 = *(longlong *)(this + 0x50);
-  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_d0,(__uint64 *)pCVar2);
-  uVar6 = *puVar13;
-  local_d0 = uVar6;
-  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_98,(ulong)&local_f8);
+  local_100 = *(_CLFS_LOG_BLOCK_HEADER **)(this + 0x50);
+  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_108,(__uint64 *)pCVar1);
+  uVar4 = *puVar13;
+  local_98 = uVar4;
+  puVar13 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_108,(ulong)&local_e0);
   local_d8 = *puVar13;
   *(undefined8 *)(this + 0x1f8) = local_d8;
-  p_Var25 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  lVar26 = 0;
-  if (local_f8._4_4_ < *(uint *)(this + 0x588)) {
-    local_104 = (param_3 >> 9) << 0x12;
-    local_f0 = param_3 - (local_104 >> 9);
-    p_Var18 = local_120;
-    p_Var17 = local_138;
+  if (local_e0._4_4_ < *(uint *)(this + 0x588)) {
+    uVar23 = (param_3 >> 9) << 0x12;
+    local_f8 = param_3 - (uVar23 >> 9);
+    p_Var28 = p_Var21;
     local_res20 = param_3;
-    for (; p_Var25 = local_150, lVar26 = local_144, local_c0 = local_104, local_104 < 0x80000;
-        local_104 = local_104 + local_118) {
-      local_118 = 0x80000 - local_104;
-      if (0x40000 < local_118) {
-        local_118 = 0x40000;
-      }
-      p_Var14 = (_CLS_LSN *)AddLsnOffset(this,local_78,(ulong)&local_f8);
-      _Var15 = LsnToCacheOffset(this,p_Var14);
-      local_90 = _Var15;
-      uVar16 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if (((int)uVar16 != 0) && ((local_90 & 0x8000000000000000) != 0)) {
+    while (uVar10 = (uint)p_Var28, local_f0 = uVar23, local_a8 = uVar23, uVar23 < 0x80000) {
+      uVar27 = 0x80000 - uVar23;
+      if (0x40000 < uVar27) {
+        uVar27 = 0x40000;
+      }
+      local_118 = uVar27;
+      p_Var14 = (_CLS_LSN *)AddLsnOffset(this,local_88,(ulong)&local_e0);
+      local_108 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,p_Var14);
+      if ((longlong)local_108 < 0) {
+        uVar10 = 0xc01a000d;
+        break;
+      }
+      local_a0 = local_108;
+      puVar15 = (ulonglong *)AddLsnOffset(this,local_80,(__uint64 *)(this + 0x558));
+      p_Var28 = (_CLFS_LOG_BLOCK_HEADER *)*puVar15;
+      local_140 = p_Var28;
+      local_100 = p_Var28;
+      if (bVar6) {
+        CcUnpinData(local_e8);
+        local_e8 = (void *)0x0;
+      }
+      if ((local_98._4_4_ < local_140._4_4_) ||
+         ((local_140._4_4_ == local_98._4_4_ && ((uint)uVar4 <= (uint)p_Var28)))) {
+        uVar10 = 0xc01a000a;
+        break;
+      }
+      uVar10 = MapCacheData(this,param_1,(_CLS_LSN *)&local_100,uVar27,
+                            (uchar)in_stack_fffffffffffffe88,&local_e8,&local_b8);
+      p_Var28 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar10;
+      if ((int)uVar10 < 0) break;
+      _Var16 = LsnToCacheOffset(this,(_CLS_LSN *)&local_e0);
+      local_78 = _Var16;
+      local_70 = LsnToCacheOffset(this,(_CLS_LSN *)&local_100);
+      uVar26 = local_128;
+      if (((longlong)_Var16 < 0) || ((longlong)local_70 < 0)) {
 LAB_0:
-        lVar26 = -0x3fe5fff3;
+        uVar10 = 0xc01a000d;
         break;
       }
-      local_98 = _Var15;
-      p_Var12 = (__uint64 *)AddLsnOffset(this,local_70,(__uint64 *)(this + 0x558));
-      p_Var24 = (_CLFS_LOG_BLOCK_HEADER *)*p_Var12;
-      local_120 = p_Var24;
-      local_a8 = p_Var24;
-      if (bVar7) {
-        CcUnpinData(local_e0);
-        local_e0 = (void *)0x0;
-      }
-      if ((local_d0._4_4_ < local_120._4_4_) ||
-         ((local_120._4_4_ == local_d0._4_4_ && ((uint)uVar6 <= (uint)p_Var24)))) {
+      bVar6 = true;
+      p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)
+                (_Var16 + ((uint)(local_f8 << 9) - local_70) + (ulonglong)uVar23);
+      local_140 = p_Var22;
+      if ((int)((ulonglong)p_Var22 >> 0x20) != 0) goto LAB_0;
+      local_f8 = 0;
+      local_140 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_138;
+      if (local_138 != 0) {
+        if (local_128 < local_138 + local_124) {
 LAB_1:
-        p_Var25 = local_150;
-        lVar26 = -0x3fe5fff6;
-        break;
-      }
-      local_144 = MapCacheData(this,param_1,(_CLS_LSN *)&local_a8,local_118,
-                               (uchar)in_stack_fffffffffffffe88,&local_e0,&local_b0);
-      lVar26 = local_144;
-      if (local_144 < 0) break;
-      uVar16 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar16 != 0) {
-        p_Var17 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_f8);
-        local_138 = p_Var17;
-        p_Var18 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_a8);
-        local_120 = p_Var18;
-        if (((longlong)p_Var17 < 0) || ((longlong)p_Var18 < 0)) goto LAB_0;
-      }
-      bVar7 = true;
-      uVar23 = local_f0 << 9;
-      uVar27 = (ulonglong)local_104;
-      uVar16 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar16 == 0) {
-        _Var15 = LsnToCacheOffset(this,(_CLS_LSN *)&local_a8);
-        _Var19 = LsnToCacheOffset(this,(_CLS_LSN *)&local_f8);
-        p_Var24 = (_CLFS_LOG_BLOCK_HEADER *)(((uVar23 + uVar27) - _Var15) + _Var19);
-      }
-      else {
-        p_Var24 = p_Var17 + uVar27 + ((ulonglong)uVar23 - (longlong)p_Var18);
-      }
-      local_e8 = p_Var24;
-      uVar16 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if (((int)uVar16 != 0) && (local_e8._4_4_ != 0)) goto LAB_0;
-      local_f0 = 0;
-      if (local_108 != 0) {
-        if (local_130 < local_108 + local_114) {
+          local_140 = p_Var22;
+          uVar10 = 0x80000005;
+          break;
+        }
+        memcpy(p_Var21 + local_124,(void *)(((ulonglong)p_Var22 & 0xffffffff) + (longlong)local_b8),
+               (size_t)local_140);
+        in_stack_fffffffffffffe88 = (_CLS_LSN *)&local_d8;
+        uVar8 = IsEof(this,p_Var21,local_150,(_CLS_LSN *)(this + 0x560),in_stack_fffffffffffffe88,
+                      (_CLS_LSN *)&local_130,&local_f4);
+        if (uVar8 != '\0') break;
+        p_Var17 = ClfsGetFirstRecord((uchar *)p_Var21,uVar26);
+        local_120 = *(longlong *)p_Var17;
+        iVar5 = (int)p_Var21;
+        plVar18 = (longlong *)AddLsnOffset(this,local_68,iVar5 + 0x18);
+        lVar24 = *plVar18;
+        local_148 = lVar24;
+        GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_c0,iVar5 + 0x18);
+        if ((uStack_bc <= local_148._4_4_) &&
+           ((local_148._4_4_ != uStack_bc || (local_c0 < (uint)lVar24)))) {
 LAB_2:
-          p_Var25 = local_150;
-          lVar26 = -0x7ffffffb;
+          uVar10 = 0xc01a000a;
           break;
         }
-        local_138 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_108;
-        memcpy(local_150 + local_114,
-               (void *)(((ulonglong)p_Var24 & 0xffffffff) + (longlong)local_b0),
-               (size_t)(ulonglong)local_108);
-        in_stack_fffffffffffffe88 = (_CLS_LSN *)&local_d8;
-        uVar9 = IsEof(this,local_150,local_148,(_CLS_LSN *)(this + 0x560),in_stack_fffffffffffffe88,
-                      (_CLS_LSN *)&local_128,&local_ec);
-        lVar26 = local_144;
-        if (uVar9 != '\0') break;
-        p_Var20 = ClfsGetFirstRecord((uchar *)local_150,local_130);
-        local_110 = *(longlong *)p_Var20;
-        local_120 = local_150 + 0x18;
-        plVar21 = (longlong *)AddLsnOffset(this,local_68,(ulong)local_120);
-        lVar29 = *plVar21;
-        local_140 = lVar29;
-        GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_b8,(int)local_150 + 0x18);
-        if ((uStack_b4 <= local_140._4_4_) &&
-           ((local_140._4_4_ != uStack_b4 || (local_b8 < (uint)lVar29)))) goto LAB_1;
-        if (CONCAT44(uStack_b4,local_b8) == lVar29) {
-          plVar21 = (longlong *)AddLsnOffset(this,local_60,(ulong)&local_140);
-          lVar29 = *plVar21;
-          local_140 = lVar29;
-        }
-        if ((*(uint *)(local_150 + 0x10) & 8) == 0) {
-          _Var10 = local_150[3];
+        if (CONCAT44(uStack_bc,local_c0) == lVar24) {
+          plVar18 = (longlong *)AddLsnOffset(this,local_60,(ulong)&local_148);
+          lVar24 = *plVar18;
+          local_148 = lVar24;
+        }
+        if ((*(uint *)(p_Var21 + 0x10) & 8) == 0) {
+          _Var9 = p_Var21[3];
         }
         else {
-          _Var10 = (_CLFS_LOG_BLOCK_HEADER)0x0;
-        }
-        local_144 = UpdateOwnerReferrals
-                              (this,(uchar)_Var10,(_CLS_LSN *)&local_110,(_CLS_LSN *)&local_140);
-        lVar26 = local_144;
-        if (local_144 < 0) break;
-        UpdateOwnerSectors(this,(uchar)_Var10,0,(uint)*(ushort *)(local_150 + 4));
-        uVar3 = *(ushort *)(local_150 + 6);
-        uVar4 = *(ushort *)(local_150 + 4);
-        if ((uint)uVar3 - (uint)uVar4 != 0) {
-          local_110 = lVar29;
-          plVar21 = (longlong *)AddLsnOffset(this,local_58,(ulong)local_120);
-          local_140 = *plVar21;
-          local_144 = UpdateOwnerReferrals(this,'\0',(_CLS_LSN *)&local_110,(_CLS_LSN *)&local_140);
-          lVar26 = local_144;
-          if (local_144 < 0) break;
-          UpdateOwnerSectors(this,'\0',0,(uint)uVar3 - (uint)uVar4);
-        }
-        p_Var24 = p_Var24 + (longlong)local_138;
-        local_114 = 0;
+          _Var9 = (_CLFS_LOG_BLOCK_HEADER)0x0;
+        }
+        uVar10 = UpdateOwnerReferrals
+                           (this,(uchar)_Var9,(_CLS_LSN *)&local_120,(_CLS_LSN *)&local_148);
+        if ((int)uVar10 < 0) break;
+        UpdateOwnerSectors(this,(uchar)_Var9,0,(uint)*(ushort *)(p_Var21 + 4));
+        local_138 = (uint)*(ushort *)(p_Var21 + 6) - (uint)*(ushort *)(p_Var21 + 4);
+        if (local_138 != 0) {
+          local_120 = lVar24;
+          plVar18 = (longlong *)AddLsnOffset(this,local_58,iVar5 + 0x18);
+          local_148 = *plVar18;
+          uVar10 = UpdateOwnerReferrals(this,'\0',(_CLS_LSN *)&local_120,(_CLS_LSN *)&local_148);
+          if ((int)uVar10 < 0) break;
+          UpdateOwnerSectors(this,'\0',0,local_138);
+        }
+        p_Var28 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar10;
+        local_124 = 0;
+        local_cc = 0;
+        local_138 = 0;
         local_c8 = 0;
-        local_108 = 0;
-        local_c4 = 0;
-        local_e8 = p_Var24;
-      }
-      while (uVar23 = (uint)p_Var24, uVar23 < local_118) {
-        p_Var28 = (_CLFS_LOG_BLOCK_HEADER *)(((ulonglong)p_Var24 & 0xffffffff) + (longlong)local_b0)
-        ;
-        uVar31 = local_118;
-        local_138 = p_Var28;
-        lVar11 = ClfsValidateSector((uchar *)p_Var28,(uchar)p_Var28[2],'@');
-        p_Var25 = local_150;
-        lVar26 = local_144;
+        p_Var22 = p_Var22 + (longlong)local_140;
+      }
+      while( true ) {
+        local_140 = p_Var22;
+        p_Var7 = local_140;
+        uVar10 = (uint)p_Var28;
+        uVar23 = (uint)local_140;
+        if (local_118 <= uVar23) break;
+        p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)
+                  (((ulonglong)local_140 & 0xffffffff) + (longlong)local_b8);
+        uVar26 = local_118;
+        local_140 = p_Var22;
+        lVar11 = ClfsValidateSector((uchar *)p_Var22,(uchar)p_Var22[2],'@');
         if (lVar11 < 0) goto LAB_3;
-        uVar22 = (uint)*(ushort *)(p_Var28 + 6) * 0x200;
-        if (uVar31 < uVar22 + uVar23) {
-          if (0x80000 < uVar22) goto LAB_3;
-          if (0x3f8 < local_res20 + *(ushort *)(p_Var28 + 6)) goto LAB_1;
-          if (local_130 < uVar22) {
-            if (local_150 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-              ExFreePoolWithTag(local_150,0);
+        uVar20 = (uint)*(ushort *)(p_Var22 + 6) * 0x200;
+        if (uVar26 < uVar20 + uVar23) {
+          if (0x80000 < uVar20) goto LAB_3;
+          if (0x3f8 < local_res20 + *(ushort *)(p_Var22 + 6)) goto LAB_2;
+          if (local_128 < uVar20) {
+            if (p_Var21 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+              ExFreePoolWithTag(p_Var21,0);
+              local_110 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
             }
-            local_130 = (uint)*(ushort *)(p_Var28 + 6) << 9;
-            local_a0 = local_130;
-            local_150 = (_CLFS_LOG_BLOCK_HEADER *)ExAllocatePoolWithTag(1,local_130,0x73666c43);
-            uVar31 = local_118;
-            if (local_150 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-              p_Var25 = local_150;
-              lVar26 = -0x3fffff66;
+            local_128 = (uint)*(ushort *)(p_Var22 + 6) << 9;
+            local_d0 = local_128;
+            local_110 = (_CLFS_LOG_BLOCK_HEADER *)ExAllocatePoolWithTag(1,local_128,0x73666c43);
+            uVar26 = local_118;
+            if (local_110 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+              uVar10 = 0xc000009a;
               goto LAB_3;
             }
           }
-          local_114 = uVar31 - uVar23;
-          local_c8 = local_114;
-          if (local_130 < local_114) goto LAB_2;
-          uVar16 = (ulonglong)local_114;
-          memcpy(local_150,p_Var28,(ulonglong)local_114);
-          uVar3 = *(ushort *)(p_Var28 + 6);
-          local_108 = (uint)uVar3 * 0x200 - local_114;
-          local_c4 = local_108;
+          p_Var21 = local_140;
+          local_124 = uVar26 - uVar23;
+          p_Var22 = local_140;
+          local_cc = local_124;
+          if (local_128 < local_124) goto LAB_1;
+          uVar19 = (ulonglong)local_124;
+          memcpy(local_110,local_140,(ulonglong)local_124);
+          uVar2 = *(ushort *)(p_Var21 + 6);
+          local_138 = (uint)uVar2 * 0x200 - local_124;
+          local_c8 = local_138;
         }
         else {
           in_stack_fffffffffffffe88 = (_CLS_LSN *)&local_d8;
-          uVar9 = IsEof(this,p_Var28,local_148,(_CLS_LSN *)(this + 0x560),in_stack_fffffffffffffe88,
-                        (_CLS_LSN *)&local_128,&local_ec);
-          lVar26 = local_144;
-          if (uVar9 != '\0') goto LAB_3;
-          p_Var20 = ClfsGetFirstRecord((uchar *)p_Var28,local_118);
-          lVar29 = *(longlong *)p_Var20;
-          local_120 = p_Var28 + 0x18;
-          local_110 = lVar29;
-          plVar21 = (longlong *)AddLsnOffset(this,local_50,(ulong)local_120);
-          lVar30 = *plVar21;
-          local_140 = lVar30;
-          GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_100,(ulong)local_120);
-          if ((local_100._4_4_ <= local_140._4_4_) &&
-             ((local_140._4_4_ != local_100._4_4_ || ((uint)local_100 < (uint)lVar30))))
-          goto LAB_1;
-          if (local_100 == lVar30) {
-            plVar21 = (longlong *)AddLsnOffset(this,local_48,(ulong)&local_140);
-            lVar30 = *plVar21;
-            local_140 = lVar30;
-          }
-          uVar23 = (uint)((ulonglong)lVar30 >> 0x20);
-          lVar26 = local_144;
-          if ((uVar23 < local_110._4_4_) ||
-             ((local_110._4_4_ == uVar23 && ((uint)lVar30 <= (uint)lVar29)))) goto LAB_3;
-          if ((*(uint *)(local_138 + 0x10) & 8) == 0) {
-            _Var10 = local_138[3];
+          uVar8 = IsEof(this,p_Var22,local_150,(_CLS_LSN *)(this + 0x560),in_stack_fffffffffffffe88,
+                        (_CLS_LSN *)&local_130,&local_f4);
+          if (uVar8 != '\0') goto LAB_3;
+          p_Var17 = ClfsGetFirstRecord((uchar *)p_Var22,local_118);
+          lVar24 = *(longlong *)p_Var17;
+          local_108 = p_Var22 + 0x18;
+          local_120 = lVar24;
+          plVar18 = (longlong *)AddLsnOffset(this,local_50,(ulong)local_108);
+          lVar25 = *plVar18;
+          local_148 = lVar25;
+          GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_b0,(ulong)local_108);
+          if ((uStack_ac <= local_148._4_4_) &&
+             ((local_148._4_4_ != uStack_ac || (local_b0 < (uint)lVar25)))) goto LAB_2;
+          if (CONCAT44(uStack_ac,local_b0) == lVar25) {
+            plVar18 = (longlong *)AddLsnOffset(this,local_48,(ulong)&local_148);
+            lVar25 = *plVar18;
+            local_148 = lVar25;
+          }
+          p_Var21 = local_140;
+          uVar23 = (uint)((ulonglong)lVar25 >> 0x20);
+          if ((uVar23 < local_120._4_4_) ||
+             ((local_120._4_4_ == uVar23 && ((uint)lVar25 <= (uint)lVar24)))) goto LAB_3;
+          if ((*(uint *)(local_140 + 0x10) & 8) == 0) {
+            _Var9 = local_140[3];
           }
           else {
-            _Var10 = (_CLFS_LOG_BLOCK_HEADER)0x0;
-          }
-          local_144 = UpdateOwnerReferrals
-                                (this,(uchar)_Var10,(_CLS_LSN *)&local_110,(_CLS_LSN *)&local_140);
-          lVar26 = local_144;
-          if (local_144 < 0) goto LAB_3;
-          UpdateOwnerSectors(this,(uchar)_Var10,0,(uint)*(ushort *)(local_138 + 4));
-          p_Var8 = local_138;
-          p_Var28 = local_138 + 6;
-          p_Var1 = local_138 + 4;
-          local_138 = (_CLFS_LOG_BLOCK_HEADER *)
-                      CONCAT44(local_138._4_4_,(uint)*(ushort *)p_Var28 - (uint)*(ushort *)p_Var1);
-          if ((uint)*(ushort *)p_Var28 - (uint)*(ushort *)p_Var1 != 0) {
-            local_110 = lVar30;
-            plVar21 = (longlong *)AddLsnOffset(this,local_40,(int)p_Var8 + 0x18);
-            local_140 = *plVar21;
-            local_144 = UpdateOwnerReferrals
-                                  (this,'\0',(_CLS_LSN *)&local_110,(_CLS_LSN *)&local_140);
-            lVar26 = local_144;
-            if (local_144 < 0) goto LAB_3;
-            UpdateOwnerSectors(this,'\0',0,(ulong)local_138);
-          }
-          uVar3 = *(ushort *)(p_Var8 + 6);
-          uVar16 = (ulonglong)uVar3 * 0x200;
-        }
-        local_res20 = local_res20 + uVar3;
-        p_Var24 = p_Var24 + uVar16;
-        local_e8 = p_Var24;
-        local_88 = local_res20;
-      }
+            _Var9 = (_CLFS_LOG_BLOCK_HEADER)0x0;
+          }
+          uVar10 = UpdateOwnerReferrals
+                             (this,(uchar)_Var9,(_CLS_LSN *)&local_120,(_CLS_LSN *)&local_148);
+          if ((int)uVar10 < 0) goto LAB_3;
+          UpdateOwnerSectors(this,(uchar)_Var9,0,(uint)*(ushort *)(p_Var21 + 4));
+          local_140 = (_CLFS_LOG_BLOCK_HEADER *)
+                      CONCAT44(local_140._4_4_,
+                               (uint)*(ushort *)(p_Var21 + 6) - (uint)*(ushort *)(p_Var21 + 4));
+          if ((uint)*(ushort *)(p_Var21 + 6) - (uint)*(ushort *)(p_Var21 + 4) != 0) {
+            local_120 = lVar25;
+            plVar18 = (longlong *)AddLsnOffset(this,local_40,(int)p_Var21 + 0x18);
+            local_148 = *plVar18;
+            uVar10 = UpdateOwnerReferrals(this,'\0',(_CLS_LSN *)&local_120,(_CLS_LSN *)&local_148);
+            if ((int)uVar10 < 0) goto LAB_3;
+            UpdateOwnerSectors(this,'\0',0,(ulong)local_140);
+          }
+          p_Var28 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar10;
+          uVar2 = *(ushort *)(p_Var21 + 6);
+          uVar19 = (ulonglong)uVar2 * 0x200;
+        }
+        local_res20 = local_res20 + uVar2;
+        p_Var21 = local_110;
+        p_Var22 = p_Var7 + uVar19;
+        local_a4 = local_res20;
+      }
+      uVar23 = local_f0 + local_118;
     }
   }
 LAB_3:
-  bVar32 = true;
-  if (local_e0 != (void *)0x0) {
+  bVar29 = true;
+  if (local_e8 != (void *)0x0) {
     CcUnpinData();
   }
-  if (p_Var25 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-    ExFreePoolWithTag(p_Var25,0);
-  }
-  *(undefined8 *)(this + 0x1e8) = uVar5;
+  if (local_110 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+    ExFreePoolWithTag(local_110,0);
+  }
+  *(undefined8 *)(this + 0x1e8) = uVar3;
   *(undefined8 *)(this + 0x1e0) = local_d8;
   if (this + 0x1f8 == (CClfsLogFcbPhysical *)0x0) {
-    bVar32 = false;
+    bVar29 = false;
   }
   else {
-    if (local_128._4_4_ < *(uint *)(this + 0x1fc)) {
-      return lVar26;
+    if (local_130._4_4_ < *(uint *)(this + 0x1fc)) {
+      return uVar10;
     }
-    if ((*(uint *)(this + 0x1fc) == local_128._4_4_) && ((uint)local_128 <= *(uint *)(this + 0x1f8))
+    if ((*(uint *)(this + 0x1fc) == local_130._4_4_) && ((uint)local_130 <= *(uint *)(this + 0x1f8))
        ) {
-      return lVar26;
+      return uVar10;
     }
   }
-  if (bVar32) {
-    *(undefined8 *)(this + 0x1f8) = local_128;
-  }
-  return lVar26;
+  if (bVar29) {
+    *(undefined8 *)(this + 0x1f8) = local_130;
+  }
+  return uVar10;
 }
 

```


## CClfsBaseFile::ValidateRgOffsets

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address|
|ratio|0.47|
|i_ratio|0.37|
|m_ratio|0.99|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateRgOffsets|ValidateRgOffsets|
|fullname|CClfsBaseFile::ValidateRgOffsets|CClfsBaseFile::ValidateRgOffsets|
|`refcount`|2|4|
|`length`|293|287|
|called|CClfsBaseFile::OffsetToAddr<br>NTOSKRNL.EXE::qsort|CClfsBaseFile::OffsetToAddr<br>NTOSKRNL.EXE::qsort|
|calling|CClfsBaseFilePersisted::LoadContainerQ|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|3|3|
|`address`|1c0060750|1c0060080|
|sig|long __thiscall ValidateRgOffsets(CClfsBaseFile * this, ulong * param_1, ulong param_2)|long __thiscall ValidateRgOffsets(CClfsBaseFile * this, ulong * param_1, ulong param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ValidateRgOffsets Diff


```diff
--- CClfsBaseFile::ValidateRgOffsets
+++ CClfsBaseFile::ValidateRgOffsets
@@ -1,66 +1,66 @@
 
 /* protected: long __cdecl CClfsBaseFile::ValidateRgOffsets(unsigned long * __ptr64,unsigned long)
    __ptr64 */
 
 long __thiscall CClfsBaseFile::ValidateRgOffsets(CClfsBaseFile *this,ulong *param_1,ulong param_2)
 
 {
   uint uVar1;
-  int *piVar2;
-  long lVar3;
-  uint uVar4;
-  int *piVar5;
-  ulonglong uVar6;
-  uint uVar7;
-  ulong uVar8;
+  ulong uVar2;
+  int *piVar3;
+  long lVar4;
+  uint uVar5;
+  int *piVar6;
+  ulonglong uVar7;
+  uint uVar8;
   
+  uVar8 = 0;
   uVar7 = 0;
-  uVar6 = 0;
-  uVar4 = 0;
-  piVar2 = *(int **)(*(longlong *)(this + 0x30) + 0x30);
-  if ((piVar2 == (int *)0x0) ||
-     (uVar1 = piVar2[0x1a], (int *)((ulonglong)uVar1 + (longlong)piVar2) < piVar2)) {
-    lVar3 = -0x3fe5fff3;
+  uVar5 = 0;
+  piVar3 = *(int **)(*(longlong *)(this + 0x30) + 0x30);
+  if ((piVar3 == (int *)0x0) ||
+     (uVar1 = piVar3[0x1a], (int *)((ulonglong)uVar1 + (longlong)piVar3) < piVar3)) {
+    lVar4 = -0x3fe5fff3;
   }
   else {
     qsort(param_1,0x47c,4,CompareOffsets);
     while( true ) {
-      lVar3 = 0;
-      if (0x47b < (uint)uVar6) break;
-      uVar8 = param_1[uVar6];
-      if (uVar8 - 1 < 0xfffffffe) {
-        piVar5 = OffsetToAddr(this,uVar8);
-        if ((piVar5 == (int *)0x0) || (uVar8 < 0x30)) {
+      lVar4 = 0;
+      if (0x47b < (uint)uVar7) break;
+      uVar2 = param_1[uVar7];
+      if (uVar2 - 1 < 0xfffffffe) {
+        piVar6 = OffsetToAddr(this,uVar2);
+        if ((piVar6 == (int *)0x0) || (uVar2 < 0x30)) {
           return -0x3fe5fff3;
         }
-        uVar4 = uVar7 + 0x30 + uVar4;
-        if (uVar4 < uVar7) {
+        uVar5 = uVar8 + 0x30 + uVar5;
+        if (uVar5 < uVar8) {
           return -0x3fe5fff3;
         }
-        if ((uVar7 != 0) && (uVar8 - 0x30 < uVar4)) {
+        if ((uVar8 != 0) && (uVar2 - 0x30 < uVar5)) {
           return -0x3fe5fff3;
         }
-        if (*piVar5 == -0x3e020ff8) {
-          uVar4 = 0x30;
+        if (*piVar6 == -0x3e020ff8) {
+          uVar5 = 0x30;
         }
         else {
-          if (*piVar5 != -0x3e020ff9) {
+          if (*piVar6 != -0x3e020ff9) {
             return -0x3fe5fff3;
           }
-          uVar4 = 0x88;
+          uVar5 = 0x88;
         }
-        if ((int *)((ulonglong)uVar4 + (longlong)piVar5) < piVar5) {
+        if ((int *)((ulonglong)uVar5 + (longlong)piVar6) < piVar6) {
           return -0x3fe5fff3;
         }
-        uVar7 = uVar8 - 0x30;
-        if ((int *)((ulonglong)uVar1 + (longlong)piVar2) <
-            (int *)((ulonglong)uVar4 + (longlong)piVar5)) {
+        uVar8 = uVar2 - 0x30;
+        if ((int *)((ulonglong)uVar1 + (longlong)piVar3) <
+            (int *)((ulonglong)uVar5 + (longlong)piVar6)) {
           return -0x3fe5fff3;
         }
       }
-      uVar6 = (ulonglong)((uint)uVar6 + 1);
+      uVar7 = (ulonglong)((uint)uVar7 + 1);
     }
   }
-  return lVar3;
+  return lVar4;
 }
 

```


## CClfsBaseFile::ValidateOffsets

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.28|
|i_ratio|0.45|
|m_ratio|0.88|
|b_ratio|0.71|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateOffsets|ValidateOffsets|
|fullname|CClfsBaseFile::ValidateOffsets|CClfsBaseFile::ValidateOffsets|
|refcount|2|2|
|`length`|1022|808|
|`called`|<details><summary>Expand for full list:<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateClientSymTblOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateContainerSymTblOffsets<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl<br>NTOSKRNL.EXE::RtlEnumerateGenericTableAvl<br>NTOSKRNL.EXE::RtlInitializeGenericTableAvl<br>NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl<br>WPP_SF_sdLD</summary></details>|<details><summary>Expand for full list:<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateClientSymTblOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateContainerSymTblOffsets<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl<br>NTOSKRNL.EXE::RtlEnumerateGenericTableAvl<br>NTOSKRNL.EXE::RtlInitializeGenericTableAvl<br>NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl</summary>WPP_SF_sdLD</details>|
|calling|CClfsBaseFilePersisted::LoadContainerQ|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|2|2|
|`address`|1c0061d24|1c0060640|
|sig|long __thiscall ValidateOffsets(CClfsBaseFile * this, _CLFS_BASE_RECORD_HEADER * param_1)|long __thiscall ValidateOffsets(CClfsBaseFile * this, _CLFS_BASE_RECORD_HEADER * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ValidateOffsets Called Diff


```diff
--- CClfsBaseFile::ValidateOffsets called
+++ CClfsBaseFile::ValidateOffsets called
@@ -0,0 +1 @@
+CClfsBaseFile::OffsetToAddr
```


### CClfsBaseFile::ValidateOffsets Diff


```diff
--- CClfsBaseFile::ValidateOffsets
+++ CClfsBaseFile::ValidateOffsets
@@ -1,132 +1,104 @@
 
 /* protected: long __cdecl CClfsBaseFile::ValidateOffsets(struct _CLFS_BASE_RECORD_HEADER * __ptr64
    const) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::ValidateOffsets(CClfsBaseFile *this,_CLFS_BASE_RECORD_HEADER *param_1)
 
 {
   _CLFS_BASE_RECORD_HEADER *p_Var1;
-  uint uVar2;
-  uint uVar3;
-  longlong lVar4;
-  char cVar5;
-  uint uVar6;
-  _CLFS_VALIDATE_OFFSET_TABLE *p_Var7;
-  longlong lVar8;
-  uint *puVar9;
-  uint *puVar10;
-  _CLFS_BASE_RECORD_HEADER *p_Var11;
-  longlong lVar12;
-  ulonglong uVar13;
-  undefined8 uVar14;
-  _CLFS_BASE_RECORD_HEADER *p_Var15;
+  _CLFS_BASE_RECORD_HEADER *p_Var2;
+  char cVar3;
+  uint uVar4;
+  _CLFS_VALIDATE_OFFSET_TABLE *p_Var5;
+  longlong lVar6;
+  ulong *puVar7;
+  ulong *puVar8;
+  void *pvVar9;
+  short *psVar10;
+  ulonglong uVar11;
+  undefined8 uVar12;
+  ulong uVar13;
+  _CLFS_BASE_RECORD_HEADER *p_Var14;
   
-  p_Var11 = *(_CLFS_BASE_RECORD_HEADER **)(*(longlong *)(this + 0x30) + 0x30);
-  p_Var7 = (_CLFS_VALIDATE_OFFSET_TABLE *)ExAllocatePoolWithTag(1,0x68,0x73666c43);
-  if (p_Var7 == (_CLFS_VALIDATE_OFFSET_TABLE *)0x0) {
+  p_Var2 = *(_CLFS_BASE_RECORD_HEADER **)(*(longlong *)(this + 0x30) + 0x30);
+  p_Var5 = (_CLFS_VALIDATE_OFFSET_TABLE *)ExAllocatePoolWithTag(1,0x68,0x73666c43);
+  if (p_Var5 == (_CLFS_VALIDATE_OFFSET_TABLE *)0x0) {
     return -0x3fffff66;
   }
-  RtlInitializeGenericTableAvl(p_Var7,CompareGenericoffsets,AllocOffsetNode,freeOffsetNode,p_Var7);
-  p_Var15 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)*(uint *)(p_Var11 + 0x68);
-  if (((((uint)*(ushort *)(p_Var11 + 4) << 9 < *(uint *)(p_Var11 + 0x68)) ||
+  RtlInitializeGenericTableAvl(p_Var5,CompareGenericoffsets,AllocOffsetNode,freeOffsetNode,p_Var5);
+  p_Var14 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)*(uint *)(p_Var2 + 0x68);
+  if (((((uint)*(ushort *)(p_Var2 + 4) << 9 < *(uint *)(p_Var2 + 0x68)) ||
        (p_Var1 = param_1 + 0x1338, p_Var1 + *(uint *)(param_1 + 0x1328) < p_Var1)) ||
-      (p_Var11 + (longlong)p_Var15 < p_Var11)) ||
-     (p_Var11 + (longlong)p_Var15 < p_Var1 + *(uint *)(param_1 + 0x1328))) {
+      (p_Var2 + (longlong)p_Var14 < p_Var2)) ||
+     (p_Var2 + (longlong)p_Var14 < p_Var1 + *(uint *)(param_1 + 0x1328))) {
 LAB_0:
-    uVar6 = 0xc01a000d;
+    uVar4 = 0xc01a000d;
   }
   else {
-    p_Var15 = param_1;
-    uVar6 = ValidateContainerContextOffsets(this,p_Var7,param_1);
-    if (((-1 < (int)uVar6) &&
-        (p_Var15 = param_1, uVar6 = ValidateClientContextOffsets(this,p_Var7,param_1),
-        -1 < (int)uVar6)) &&
-       ((p_Var15 = param_1, uVar6 = ValidateContainerSymTblOffsets(this,p_Var7,param_1),
-        -1 < (int)uVar6 &&
-        (p_Var15 = param_1, uVar6 = ValidateClientSymTblOffsets(this,p_Var7,param_1),
-        -1 < (int)uVar6)))) {
-      RtlNumberGenericTableElementsAvl(p_Var7);
-      puVar9 = (uint *)RtlEnumerateGenericTableAvl(p_Var7,1);
+    p_Var14 = param_1;
+    uVar4 = ValidateContainerContextOffsets(this,p_Var5,param_1);
+    if (((-1 < (int)uVar4) &&
+        (p_Var14 = param_1, uVar4 = ValidateClientContextOffsets(this,p_Var5,param_1),
+        -1 < (int)uVar4)) &&
+       ((p_Var14 = param_1, uVar4 = ValidateContainerSymTblOffsets(this,p_Var5,param_1),
+        -1 < (int)uVar4 &&
+        (p_Var14 = param_1, uVar4 = ValidateClientSymTblOffsets(this,p_Var5,param_1),
+        -1 < (int)uVar4)))) {
+      RtlNumberGenericTableElementsAvl(p_Var5);
+      puVar7 = (ulong *)RtlEnumerateGenericTableAvl(p_Var5,1);
       do {
-        puVar10 = (uint *)RtlEnumerateGenericTableAvl(p_Var7,0);
-        if (puVar9 == (uint *)0x0) break;
-        if (puVar10 == (uint *)0x0) {
-          uVar6 = *(int *)(param_1 + 0x1328) + 0x1338;
+        puVar8 = (ulong *)RtlEnumerateGenericTableAvl(p_Var5,0);
+        if (puVar7 == (ulong *)0x0) break;
+        if (puVar8 == (ulong *)0x0) {
+          uVar13 = *(int *)(param_1 + 0x1328) + 0x1338;
         }
         else {
-          uVar6 = *puVar10;
+          uVar13 = *puVar8;
         }
-        lVar8 = *(longlong *)(this + 0x30);
-        uVar2 = *puVar9;
-        lVar4 = *(longlong *)(lVar8 + 0x30);
-        if ((*(short *)(this + 0x28) == 0) || (lVar4 == 0)) {
-LAB_1:
-          lVar12 = 0;
-        }
-        else {
-          uVar3 = *(uint *)(lVar4 + 0x28);
-          if ((*(uint *)(lVar8 + 0x38) <= uVar3) ||
-             ((uVar3 < 0x70 ||
-              (lVar12 = lVar4 + (ulonglong)uVar3, *(uint *)(lVar8 + 0x38) - uVar3 < 0x1338))))
+        pvVar9 = OffsetToAddr(this,*puVar7);
+        if (((pvVar9 == (void *)0x0) || (uVar13 < *(uint *)((longlong)pvVar9 + 0x20))) ||
+           ((char)puVar7[1] == '\0')) goto LAB_0;
+        psVar10 = OffsetToAddr(this,*(uint *)((longlong)pvVar9 + 0x20));
+        if (psVar10 == (short *)0x0) {
+          uVar4 = 0xc000000d;
           goto LAB_1;
         }
-        uVar3 = *(uint *)(lVar4 + 0x28);
-        p_Var15 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)uVar3;
-        if (((uVar3 + uVar2 < uVar2) || (lVar12 == 0)) ||
-           ((uint)*(ushort *)(lVar4 + 4) << 9 <= uVar3 + uVar2)) goto LAB_0;
-        p_Var11 = (_CLFS_BASE_RECORD_HEADER *)0x0;
-        if (lVar12 + (ulonglong)uVar2 == 0) goto LAB_0;
-        uVar2 = *(uint *)(lVar12 + (ulonglong)uVar2 + 0x20);
-        if ((uVar6 < uVar2) || ((char)puVar9[1] == '\0')) goto LAB_0;
-        if ((*(short *)(this + 0x28) == 0) || (lVar4 == 0)) {
-          p_Var11 = (_CLFS_BASE_RECORD_HEADER *)0x0;
+        uVar11 = (ulonglong)(uVar13 - *(int *)((longlong)pvVar9 + 0x20) >> 1);
+        for (; (uVar11 != 0 && (*psVar10 != 0)); psVar10 = psVar10 + 1) {
+          uVar11 = uVar11 - 1;
         }
-        else if (((uVar3 < *(uint *)(lVar8 + 0x38)) && (0x6f < uVar3)) &&
-                (0x1337 < *(uint *)(lVar8 + 0x38) - uVar3)) {
-          p_Var11 = p_Var15 + lVar4;
-        }
-        if ((((uVar3 + uVar2 < uVar2) || (p_Var11 == (_CLFS_BASE_RECORD_HEADER *)0x0)) ||
-            ((uint)*(ushort *)(lVar4 + 4) << 9 <= uVar3 + uVar2)) ||
-           (p_Var11 = p_Var11 + uVar2, p_Var11 == (_CLFS_BASE_RECORD_HEADER *)0x0)) {
-          uVar6 = 0xc000000d;
-          goto LAB_2;
-        }
-        uVar13 = (ulonglong)(uVar6 - uVar2 >> 1);
-        for (; (uVar13 != 0 && (*(short *)p_Var11 != 0)); p_Var11 = p_Var11 + 2) {
-          uVar13 = uVar13 - 1;
-        }
-        uVar6 = ~-(uint)(uVar13 != 0) & 0xc000000d;
-        if (uVar13 == 0) goto LAB_2;
-        cVar5 = RtlDeleteElementGenericTableAvl(p_Var7);
-        if (cVar5 == '\0') goto LAB_0;
-        puVar9 = puVar10;
-      } while (puVar10 != (uint *)0x0);
+        uVar4 = ~-(uint)(uVar11 != 0) & 0xc000000d;
+        if (uVar11 == 0) goto LAB_1;
+        cVar3 = RtlDeleteElementGenericTableAvl(p_Var5);
+        if (cVar3 == '\0') goto LAB_0;
+        puVar7 = puVar8;
+      } while (puVar8 != (ulong *)0x0);
       if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-        WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1d,p_Var15,
+        WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x19,p_Var14,
                     "CClfsBaseFile::ValidateOffsets");
       }
-      goto LAB_3;
+      goto LAB_2;
     }
   }
-LAB_2:
+LAB_1:
   if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-    WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1e,p_Var15,
+    WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1a,p_Var14,
                 "CClfsBaseFile::ValidateOffsets");
   }
-  uVar14 = 1;
-  while (lVar8 = RtlEnumerateGenericTableAvl(p_Var7,uVar14), lVar8 != 0) {
-    cVar5 = RtlDeleteElementGenericTableAvl(p_Var7);
-    if (cVar5 == '\0') {
-      uVar6 = 0xc01a000d;
+  uVar12 = 1;
+  while (lVar6 = RtlEnumerateGenericTableAvl(p_Var5,uVar12), lVar6 != 0) {
+    cVar3 = RtlDeleteElementGenericTableAvl(p_Var5);
+    if (cVar3 == '\0') {
+      uVar4 = 0xc01a000d;
       break;
     }
-    uVar14 = 0;
+    uVar12 = 0;
   }
-LAB_3:
-  ExFreePoolWithTag(p_Var7,0);
-  return uVar6;
+LAB_2:
+  ExFreePoolWithTag(p_Var5,0);
+  return uVar4;
 }
 

```


## CClfsBaseFilePersisted::FlushControlRecord

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.38|
|i_ratio|0.54|
|m_ratio|0.99|
|b_ratio|0.93|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|FlushControlRecord|FlushControlRecord|
|fullname|CClfsBaseFilePersisted::FlushControlRecord|CClfsBaseFilePersisted::FlushControlRecord|
|refcount|14|14|
|`length`|171|170|
|called|CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>memcpy|CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>memcpy|
|calling|CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushImage<br>CClfsLogFcbPhysical::TruncateLogDiscardBlocks<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart<br>`CClfsLogFcbPhysical::TruncateLogDiscardBlocks'::__l1::fin$0|CClfsBaseFilePersisted::ExtendMetadataBlock<br>CClfsBaseFilePersisted::FlushImage<br>CClfsLogFcbPhysical::TruncateLogDiscardBlocks<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart<br>`CClfsLogFcbPhysical::TruncateLogDiscardBlocks'::__l1::fin$0|
|paramcount|1|1|
|`address`|1c0062988|1c006f284|
|sig|long __thiscall FlushControlRecord(CClfsBaseFilePersisted * this)|long __thiscall FlushControlRecord(CClfsBaseFilePersisted * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::FlushControlRecord Diff


```diff
--- CClfsBaseFilePersisted::FlushControlRecord
+++ CClfsBaseFilePersisted::FlushControlRecord
@@ -1,36 +1,37 @@
 
 /* private: long __cdecl CClfsBaseFilePersisted::FlushControlRecord(void) __ptr64 */
 
 long __thiscall CClfsBaseFilePersisted::FlushControlRecord(CClfsBaseFilePersisted *this)
 
 {
-  long lVar1;
-  ushort uVar2;
-  ulonglong uVar3;
-  _CLFS_CONTROL_RECORD *local_res10 [3];
+  _CLFS_CONTROL_RECORD *p_Var1;
+  long lVar2;
+  ushort uVar3;
+  ulonglong uVar4;
+  _CLFS_CONTROL_RECORD *local_res10;
   
-  local_res10[0] = (_CLFS_CONTROL_RECORD *)0x0;
-  lVar1 = CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,local_res10,'\0');
-  if (-1 < lVar1) {
-    if (local_res10[0] == (_CLFS_CONTROL_RECORD *)0x0) {
-      lVar1 = -0x3fe5fff3;
+  local_res10 = (_CLFS_CONTROL_RECORD *)0x0;
+  lVar2 = CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_res10,'\0');
+  p_Var1 = local_res10;
+  if (-1 < lVar2) {
+    if (local_res10 == (_CLFS_CONTROL_RECORD *)0x0) {
+      lVar2 = -0x3fe5fff3;
     }
     else {
-      *(undefined8 *)(local_res10[0] + 8) = 0xc1f5c1f500005f1c;
-      memcpy(local_res10[0] + 0x50,*(void **)(this + 0x30),
-             (ulonglong)*(ushort *)(this + 0x28) * 0x18);
-      uVar3 = 0;
+      *(undefined8 *)(local_res10 + 8) = 0xc1f5c1f500005f1c;
+      memcpy(local_res10 + 0x50,*(void **)(this + 0x30),(ulonglong)*(ushort *)(this + 0x28) * 0x18);
+      uVar4 = 0;
       if (*(short *)(this + 0x28) != 0) {
         do {
-          uVar2 = (short)uVar3 + 1;
-          *(undefined8 *)(local_res10[0] + uVar3 * 0x18 + 0x50) = 0;
-          uVar3 = (ulonglong)uVar2;
-        } while (uVar2 < *(ushort *)(this + 0x28));
+          uVar3 = (short)uVar4 + 1;
+          *(undefined8 *)(p_Var1 + uVar4 * 0x18 + 0x50) = 0;
+          uVar4 = (ulonglong)uVar3;
+        } while (uVar3 < *(ushort *)(this + 0x28));
       }
-      lVar1 = WriteMetadataBlock(this,0,'\x01');
+      lVar2 = WriteMetadataBlock(this,0,'\x01');
       CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
     }
   }
-  return lVar1;
+  return lVar2;
 }
 

```


## CClfsBaseFile::ValidateContainerContextOffsets

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.71|
|i_ratio|0.38|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateContainerContextOffsets|ValidateContainerContextOffsets|
|fullname|CClfsBaseFile::ValidateContainerContextOffsets|CClfsBaseFile::ValidateContainerContextOffsets|
|refcount|2|2|
|`length`|482|516|
|called|CClfsBaseFile::ContainerCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|CClfsBaseFile::ContainerCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|
|calling|CClfsBaseFile::ValidateOffsets|CClfsBaseFile::ValidateOffsets|
|paramcount|3|3|
|`address`|1c005efd0|1c00611a0|
|sig|long __thiscall ValidateContainerContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|long __thiscall ValidateContainerContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ValidateContainerContextOffsets Diff


```diff
--- CClfsBaseFile::ValidateContainerContextOffsets
+++ CClfsBaseFile::ValidateContainerContextOffsets
@@ -1,91 +1,91 @@
 
 /* protected: long __cdecl CClfsBaseFile::ValidateContainerContextOffsets(struct
    _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::ValidateContainerContextOffsets
           (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
           _CLFS_BASE_RECORD_HEADER *param_2)
 
 {
   uint uVar1;
   ulong uVar2;
   void *pvVar3;
   longlong lVar4;
-  _CLFS_VALIDATE_OFFSET_TABLE *this_00;
+  CClfsBaseFile *this_00;
   uint uVar5;
   _CLFS_BASE_RECORD_HEADER *p_Var6;
   _CLFS_BASE_RECORD_HEADER *p_Var7;
   _CLFS_BASE_RECORD_HEADER *p_Var8;
   _CLFS_BASE_RECORD_HEADER *p_Var9;
   char local_res20 [8];
   int local_38;
   undefined1 local_34;
   undefined2 local_33;
   undefined1 local_31;
   _CLFS_CONTAINER_CONTEXT *local_30;
   
   p_Var6 = (_CLFS_BASE_RECORD_HEADER *)0x0;
   local_38 = 0;
+  local_res20[0] = '\0';
   local_34 = 0;
-  local_res20[0] = '\0';
   local_33 = 0;
   local_31 = 0;
-  this_00 = (_CLFS_VALIDATE_OFFSET_TABLE *)this;
   p_Var7 = p_Var6;
-  p_Var8 = p_Var6;
-  p_Var9 = param_2;
+  p_Var8 = param_2;
+  p_Var9 = p_Var6;
   while( true ) {
-    uVar1 = (uint)p_Var8;
+    uVar1 = (uint)p_Var7;
     uVar5 = (uint)p_Var6;
     if (0x3ff < uVar5) break;
-    uVar2 = *(ulong *)(param_2 + (longlong)p_Var6 * 4 + 0x328);
-    if (uVar2 != 0) {
-      p_Var7 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)((ulong)p_Var7 + 1);
-      p_Var9 = param_2;
-      uVar1 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar2 + 0x2f,param_2);
-      if (((((int)uVar1 < 0) ||
-           (uVar1 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar2 - 0x30,p_Var9),
-           (int)uVar1 < 0)) || (pvVar3 = OffsetToAddr(this,uVar2), pvVar3 == (void *)0x0)) ||
-         ((*(ulong *)((longlong)pvVar3 + -0xc) != uVar2 ||
-          (*(int *)((longlong)pvVar3 + -0x10) != *(ulong *)((longlong)pvVar3 + -0xc) + 0x30))))
+    uVar1 = *(uint *)(param_2 + (longlong)p_Var6 * 4 + 0x328);
+    this_00 = (CClfsBaseFile *)(ulonglong)uVar1;
+    if (uVar1 != 0) {
+      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)((ulong)p_Var9 + 1);
+      p_Var8 = param_2;
+      uVar1 = ValidateCheckifWithinSymbolZone(this_00,uVar1 + 0x2f,param_2);
+      if ((((int)uVar1 < 0) ||
+          (uVar1 = ValidateCheckifWithinSymbolZone(this_00,(int)this_00 - 0x30,p_Var8),
+          (int)uVar1 < 0)) || (pvVar3 = OffsetToAddr(this,(ulong)this_00), pvVar3 == (void *)0x0))
+      goto LAB_0;
+      if ((*(int *)((longlong)pvVar3 + -0xc) != *(int *)(param_2 + (longlong)p_Var6 * 4 + 0x328)) ||
+         (*(int *)((longlong)pvVar3 + -0x10) != *(int *)((longlong)pvVar3 + -0xc) + 0x30))
       goto LAB_0;
       local_30 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-      p_Var9 = p_Var6;
-      uVar1 = GetSymbol(this,uVar2,uVar5,&local_30);
-      p_Var8 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)uVar1;
+      p_Var8 = p_Var6;
+      uVar1 = GetSymbol(this,*(int *)(param_2 + (longlong)p_Var6 * 4 + 0x328),uVar5,&local_30);
+      p_Var7 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)uVar1;
       if (((int)uVar1 < 0) ||
          ((*(uint *)(local_30 + 0x10) != uVar5 || (*(int *)local_30 != -0x3e020ff8))))
       goto LAB_0;
-      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)&DAT_1;
+      p_Var8 = (_CLFS_BASE_RECORD_HEADER *)&DAT_1;
       local_38 = *(int *)(param_2 + (longlong)p_Var6 * 4 + 0x328) + -0x30;
-      this_00 = param_1;
       lVar4 = RtlInsertElementGenericTableAvl(param_1,&local_38,8,local_res20);
       if ((local_res20[0] == '\0') || (lVar4 == 0)) goto LAB_0;
     }
     p_Var6 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)(uVar5 + 1);
   }
   uVar2 = ContainerCount(this);
-  if ((ulong)p_Var7 == uVar2) {
+  if ((ulong)p_Var9 == uVar2) {
     uVar5 = uVar1;
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1b,p_Var9,
+      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x17,p_Var8,
                   "CClfsBaseFile::ValidateContainerContextOffsets");
     }
   }
   else {
 LAB_0:
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1c,p_Var9,
+      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x18,p_Var8,
                   "CClfsBaseFile::ValidateContainerContextOffsets");
     }
     uVar5 = 0xc01a000d;
     if ((int)uVar1 < 0) {
       uVar5 = uVar1;
     }
   }
   return uVar5;
 }
 

```


## CClfsBaseFilePersisted::FlushImage

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.54|
|i_ratio|0.49|
|m_ratio|0.83|
|b_ratio|0.7|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|FlushImage|FlushImage|
|fullname|CClfsBaseFilePersisted::FlushImage|CClfsBaseFilePersisted::FlushImage|
|refcount|9|9|
|`length`|185|268|
|`called`|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>Feature_110180665__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>WPP_SF_sl|
|calling|CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsLogFcbPhysical::FlushMetadata<br>`CClfsBaseFilePersisted::AddContainer'::__l1::fin$0|CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsLogFcbPhysical::FlushMetadata<br>`CClfsBaseFilePersisted::AddContainer'::__l1::fin$0|
|paramcount|1|1|
|`address`|1c0060ae8|1c006165c|
|sig|long __thiscall FlushImage(CClfsBaseFilePersisted * this)|long __thiscall FlushImage(CClfsBaseFilePersisted * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::FlushImage Called Diff


```diff
--- CClfsBaseFilePersisted::FlushImage called
+++ CClfsBaseFilePersisted::FlushImage called
@@ -4,0 +5 @@
+Feature_110180665__private_IsEnabledDeviceUsage
@@ -5,0 +7 @@
+WPP_SF_sl
```


### CClfsBaseFilePersisted::FlushImage Diff


```diff
--- CClfsBaseFilePersisted::FlushImage
+++ CClfsBaseFilePersisted::FlushImage
@@ -1,26 +1,36 @@
 
 /* public: long __cdecl CClfsBaseFilePersisted::FlushImage(void) __ptr64 */
 
 long __thiscall CClfsBaseFilePersisted::FlushImage(CClfsBaseFilePersisted *this)
 
 {
   char cVar1;
   long lVar2;
+  ulonglong uVar3;
   
   cVar1 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20),1);
   lVar2 = WriteMetadataBlock(this,2,'\x01');
-  *(longlong *)(this + 0x1b8) = *(longlong *)(this + 0x1b8) + 1;
-  *(longlong *)(this + 0x1c0) = *(longlong *)(this + 0xd0) + *(longlong *)(this + 0x1c0);
-  if (*(longlong *)(this + 0x1d0) != 0) {
-    lVar2 = FlushControlRecord(this);
-    if (-1 < lVar2) {
-      CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
-      *(undefined8 *)(this + 0x1d0) = 0;
+  uVar3 = Feature_110180665__private_IsEnabledDeviceUsage();
+  if (((int)uVar3 == 0) || (-1 < lVar2)) {
+    *(longlong *)(this + 0x1b8) = *(longlong *)(this + 0x1b8) + 1;
+    *(longlong *)(this + 0x1c0) = *(longlong *)(this + 0xd0) + *(longlong *)(this + 0x1c0);
+    if (*(longlong *)(this + 0x1d0) != 0) {
+      lVar2 = FlushControlRecord(this);
+      if (-1 < lVar2) {
+        CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
+        *(undefined8 *)(this + 0x1d0) = 0;
+      }
     }
+  }
+  else if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+          ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1b & 1) != 0)) {
+    WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1f,
+              &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,"CClfsBaseFilePersisted::FlushImage")
+    ;
   }
   if (cVar1 != '\0') {
     CClfsBaseFile::UnlockImage((CClfsBaseFile *)this);
   }
   return lVar2;
 }
 

```


## WPP_SF_sdLLH

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.82|
|i_ratio|0.13|
|m_ratio|0.95|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|WPP_SF_sdLLH|WPP_SF_sdLLH|
|fullname|WPP_SF_sdLLH|WPP_SF_sdLLH|
|refcount|2|2|
|`length`|164|177|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|calling|CClfsBaseFile::GetControlRecord|CClfsBaseFile::GetControlRecord|
|paramcount|2|1|
|`address`|1c0010f9c|1c0010ed4|
|`sig`|undefined __fastcall WPP_SF_sdLLH(undefined8 param_1, undefined2 param_2)|undefined __fastcall WPP_SF_sdLLH(undefined8 param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### WPP_SF_sdLLH Diff


```diff
--- WPP_SF_sdLLH
+++ WPP_SF_sdLLH
@@ -1,21 +1,23 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 
-void WPP_SF_sdLLH(undefined8 param_1,undefined2 param_2)
+void WPP_SF_sdLLH(undefined8 param_1)
 
 {
   longlong lVar1;
   longlong lVar2;
+  undefined4 local_18 [6];
   
+  local_18[0] = 0xeb8;
   lVar1 = -1;
   do {
     lVar2 = lVar1;
     lVar1 = lVar2 + 1;
   } while ("CClfsBaseFile::GetControlRecord"[lVar2 + 1] != '\0');
   (*pfnWppTraceMessage)
-            (param_1,0x2b,&WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,param_2,
-             "CClfsBaseFile::GetControlRecord",lVar2 + 2,&stack0x00000028,4,&stack0x00000030,4,
+            (param_1,0x2b,&WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,0xd,
+             "CClfsBaseFile::GetControlRecord",lVar2 + 2,local_18,4,&stack0x00000030,4,
              &stack0x00000038,4,&stack0x00000040,2,0);
   return;
 }
 

```


## CClfsLogFcbPhysical::ReadLogBlock

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.74|
|i_ratio|0.71|
|m_ratio|0.99|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ReadLogBlock|ReadLogBlock|
|fullname|CClfsLogFcbPhysical::ReadLogBlock|CClfsLogFcbPhysical::ReadLogBlock|
|refcount|4|4|
|`length`|2201|2164|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::IsMainLocked<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::RawSectorAlign<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ValidateLogBlock<br>ClfsCheckAndResetReadInProgress<br>ClfsDecodeBlock<br>Feature_2458037564__private_IsEnabledDeviceUsage</summary>NTOSKRNL.EXE::CcCopyRead<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::KeBugCheckEx<br>_CLFS_READ_BUFFER::GetAddress<br>_guard_dispatch_icall<br>memset<br>operator>=</details>|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::IsMainLocked<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::RawSectorAlign<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ValidateLogBlock<br>ClfsCheckAndResetReadInProgress<br>ClfsDecodeBlock<br>NTOSKRNL.EXE::CcCopyRead</summary>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::KeBugCheckEx<br>_CLFS_READ_BUFFER::GetAddress<br>_guard_dispatch_icall<br>memset<br>operator>=</details>|
|calling|CClfsLogFcbPhysical::ReadLogBlock`adjustor{608}'|CClfsLogFcbPhysical::ReadLogBlock`adjustor{608}'|
|paramcount|10|10|
|address|1c000ee80|1c000ee80|
|sig|long __thiscall ReadLogBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, _CLFS_READ_BUFFER * param_4, ulong param_5, IClfsRequestAsync * param_6, ulong param_7, _CLS_LSN * param_8, ulong * param_9)|long __thiscall ReadLogBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, _CLFS_READ_BUFFER * param_4, ulong param_5, IClfsRequestAsync * param_6, ulong param_7, _CLS_LSN * param_8, ulong * param_9)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::ReadLogBlock Called Diff


```diff
--- CClfsLogFcbPhysical::ReadLogBlock called
+++ CClfsLogFcbPhysical::ReadLogBlock called
@@ -11 +10,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::ReadLogBlock Diff


```diff
--- CClfsLogFcbPhysical::ReadLogBlock
+++ CClfsLogFcbPhysical::ReadLogBlock
@@ -1,314 +1,309 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: virtual long __cdecl CClfsLogFcbPhysical::ReadLogBlock(struct _FILE_OBJECT *
    __ptr64,union _CLS_LSN const & __ptr64,unsigned long,struct _CLFS_READ_BUFFER const &
    __ptr64,unsigned long,struct IClfsRequestAsync * __ptr64,unsigned long,union _CLS_LSN &
    __ptr64,unsigned long & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::ReadLogBlock
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,_CLS_LSN *param_2,ulong param_3,
           _CLFS_READ_BUFFER *param_4,ulong param_5,IClfsRequestAsync *param_6,ulong param_7,
           _CLS_LSN *param_8,ulong *param_9)
 
 {
   bool bVar1;
   uchar uVar2;
   char cVar3;
   int iVar4;
   uint uVar5;
   ulong uVar6;
   int iVar7;
   _CLFS_LOG_BLOCK_HEADER *p_Var8;
   longlong *plVar9;
   undefined8 *puVar10;
   IClfsRequestAsync *pIVar11;
   __uint64 _Var12;
   ulonglong uVar13;
   longlong lVar14;
   ulonglong uVar15;
   ushort uVar16;
   uchar *puVar17;
   uchar *in_stack_fffffffffffffed8;
   char local_108;
   int local_104;
   ulong local_100;
   ulong local_f8;
   int local_f4;
   uint local_f0;
-  uint local_ec;
-  uint local_e8;
-  ulong local_e4;
-  ulonglong local_e0;
-  uchar *local_d8;
-  undefined8 local_d0;
-  ulonglong local_c8;
-  uint local_c0;
-  uint local_bc;
-  ulonglong local_b8;
+  ulonglong local_e8;
+  uint local_e0;
+  uint local_dc;
+  ulong local_d8 [2];
+  uchar *local_d0;
+  undefined8 local_c8;
+  __uint64 local_c0;
+  uint local_b8;
+  uint local_b4;
   _CLS_LSN *local_b0;
   undefined8 local_a8;
   undefined8 local_a0;
   _CLS_LSN *local_98;
   _CLFS_LOG_BLOCK_HEADER *local_90;
   undefined8 local_88;
   undefined8 uStack_80;
   undefined8 local_78;
   _CLS_LSN local_70 [8];
   undefined8 local_68;
-  ulonglong local_60;
-  _CLS_LSN local_58 [8];
+  __uint64 local_60;
+  ulonglong local_58;
   _CLS_LSN local_50 [8];
-  _CLS_LSN local_48 [16];
+  _CLS_LSN local_48 [8];
+  _CLS_LSN local_40 [8];
   
   lVar14 = -0x100000000;
-  local_d0 = -0x100000000;
+  local_c8 = -0x100000000;
   local_a8 = 0;
   local_a0 = 0;
-  local_e0 = 0;
+  local_c0 = 0;
   local_104 = 0;
-  local_e4 = 0;
+  local_d8[0] = 0;
   local_f8 = 0;
   local_f4 = 0;
   local_108 = '\0';
-  local_ec = *(uint *)(*(longlong *)(this + 0x2c8) + 0x90);
-  if (((local_ec - 1 < 0x1000) && ((local_ec & 0x1ff) == 0)) &&
-     ((int)(0x1000 % (ulonglong)local_ec) == 0)) {
+  local_e0 = *(uint *)(*(longlong *)(this + 0x2c8) + 0x90);
+  if (((local_e0 - 1 < 0x1000) && ((local_e0 & 0x1ff) == 0)) &&
+     ((int)(0x1000 % (ulonglong)local_e0) == 0)) {
     *param_9 = 0;
     *(undefined8 *)param_8 = 0xffffffff00000000;
     local_88 = *(undefined8 *)param_4;
     uStack_80 = *(undefined8 *)(param_4 + 8);
     local_78 = *(undefined8 *)(param_4 + 0x10);
     if (param_3 - 1 < 2) {
-      local_c0 = local_ec;
+      local_b8 = local_e0;
       p_Var8 = (_CLFS_LOG_BLOCK_HEADER *)_CLFS_READ_BUFFER::GetAddress(param_4);
       local_90 = p_Var8;
       if (p_Var8 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
         local_104 = -0x3fffff66;
         iVar4 = -0x3fffff66;
       }
       else {
-        local_d8 = _CLFS_READ_BUFFER::GetAddress((_CLFS_READ_BUFFER *)&local_88);
-        if (local_d8 == (uchar *)0x0) {
+        local_d0 = _CLFS_READ_BUFFER::GetAddress((_CLFS_READ_BUFFER *)&local_88);
+        if (local_d0 == (uchar *)0x0) {
           local_104 = -0x3fffff66;
           iVar4 = -0x3fffff66;
         }
         else {
-          local_e8 = param_7 & 1;
-          local_bc = local_e8;
-          if (((local_e8 != 0) || (*(longlong *)(param_1 + 0x30) != 0)) ||
+          local_dc = param_7 & 1;
+          local_b4 = local_dc;
+          if (((local_dc != 0) || (*(longlong *)(param_1 + 0x30) != 0)) ||
              (local_104 = (*(code *)**(undefined8 **)this)(this,param_1,this), iVar4 = local_104,
              -1 < local_104)) {
             uVar2 = CClfsLogFcbCommon::IsMainLocked((CClfsLogFcbCommon *)this);
             if (uVar2 == '\0') {
               local_108 = ExAcquireResourceSharedLite(this + 200,1);
             }
             cVar3 = (**(code **)(*(longlong *)this + 0x138))(this);
             if ((cVar3 == '\0') || ((param_7 & 8) == 0)) {
               if ((*(uint *)(this + 0x16c) >> 0xc & 1) == 0) {
-                puVar10 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_b8);
+                puVar10 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_b0);
                 local_b0 = (_CLS_LSN *)*puVar10;
                 if (((param_2 == (_CLS_LSN *)0x0) ||
                     (uVar5 = (uint)((ulonglong)local_b0 >> 0x20), uVar5 < *(uint *)(param_2 + 4)))
                    || ((*(uint *)(param_2 + 4) == uVar5 && ((uint)local_b0 <= *(uint *)param_2)))) {
                   local_b0 = (_CLS_LSN *)(this + 0x1e0);
                   local_98 = local_b0;
                   uVar2 = operator>=(param_2,local_b0);
                   if (uVar2 == '\0') {
                     cVar3 = (**(code **)(*(longlong *)this + 0x138))(this);
                     if (cVar3 != '\0') {
                       plVar9 = (longlong *)
-                               GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_b8,(ulong)param_2);
+                               GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_e8,(ulong)param_2);
                       lVar14 = *plVar9;
-                      local_d0 = lVar14;
+                      local_c8 = lVar14;
                     }
                     if (param_6 != (IClfsRequestAsync *)0x0) {
                       local_f4 = (**(code **)(*(longlong *)param_6 + 0x10))(param_6);
                     }
                     *param_9 = 0;
-                    uVar13 = *(ulonglong *)param_2;
+                    uVar15 = *(ulonglong *)param_2;
                     local_100 = param_5;
-                    uVar15 = uVar13 & 0xffffffff;
+                    uVar13 = uVar15 & 0xffffffff;
                     iVar4 = local_104;
                     while( true ) {
                       uVar2 = (uchar)in_stack_fffffffffffffed8;
-                      local_c8 = uVar13;
+                      local_e8 = uVar15;
                       if ((local_100 <= *param_9) || (local_98 == (_CLS_LSN *)0x0)) break;
-                      uVar5 = (uint)(uVar13 >> 0x20);
+                      uVar5 = (uint)(uVar15 >> 0x20);
                       if ((*(uint *)(local_98 + 4) < uVar5) ||
-                         ((uVar5 == *(uint *)(local_98 + 4) && (*(uint *)local_98 <= (uint)uVar15)))
+                         ((uVar5 == *(uint *)(local_98 + 4) && (*(uint *)local_98 <= (uint)uVar13)))
                          ) break;
                       local_f0 = local_100 - *param_9;
-                      uVar15 = (ulonglong)local_f0;
+                      uVar13 = (ulonglong)local_f0;
                       cVar3 = (**(code **)(*(longlong *)this + 0x138))(this);
                       if (cVar3 != '\0') {
-                        puVar10 = (undefined8 *)AddLsnOffset(this,local_70,(ulong)&local_c8);
+                        puVar10 = (undefined8 *)AddLsnOffset(this,local_70,(ulong)&local_e8);
                         local_68 = *puVar10;
                         uVar5 = (uint)((ulonglong)local_68 >> 0x20);
-                        if ((local_d0._4_4_ <= uVar5) &&
-                           ((uVar5 != local_d0._4_4_ || ((uint)lVar14 < (uint)local_68)))) {
-                          local_f0 = ((uint)lVar14 & 0xfffffe00) - ((uint)uVar13 & 0xfffffe00);
-                          uVar15 = (ulonglong)local_f0;
+                        if ((local_c8._4_4_ <= uVar5) &&
+                           ((uVar5 != local_c8._4_4_ || ((uint)lVar14 < (uint)local_68)))) {
+                          local_f0 = ((uint)lVar14 & 0xfffffe00) - ((uint)uVar15 & 0xfffffe00);
+                          uVar13 = (ulonglong)local_f0;
                         }
                       }
                       bVar1 = false;
                       if (((param_3 & 1) != 0) && (*param_9 == 0)) {
-                        uVar15 = (ulonglong)local_ec;
-                        local_f0 = local_ec;
+                        uVar13 = (ulonglong)local_e0;
+                        local_f0 = local_e0;
                         bVar1 = true;
                       }
-                      if (local_e8 == 0) {
-                        local_e0 = LsnToCacheOffset(this,(_CLS_LSN *)&local_c8);
-                        _Var12 = LsnToCacheOffset(this,local_b0);
-                        local_b8 = _Var12;
-                        uVar13 = Feature_2458037564__private_IsEnabledDeviceUsage();
-                        in_stack_fffffffffffffed8 = local_d8;
-                        if (((int)uVar13 != 0) &&
-                           (((local_e0 & 0x8000000000000000) != 0 || ((longlong)_Var12 < 0)))) {
+                      if (local_dc == 0) {
+                        _Var12 = LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
+                        local_c0 = _Var12;
+                        local_60 = LsnToCacheOffset(this,local_b0);
+                        in_stack_fffffffffffffed8 = local_d0;
+                        if (((longlong)_Var12 < 0) || ((longlong)local_60 < 0)) {
+LAB_0:
                           local_104 = -0x3fe5fff3;
                           iVar4 = -0x3fe5fff3;
-                          goto LAB_0;
-                        }
-                        if ((longlong)local_b8 < (longlong)(uVar15 + local_e0)) {
-                          uVar15 = (_Var12 & 0xffffffff00000000 | local_b8 & 0xffffffff) - local_e0;
-                          local_60 = uVar15;
-                          if ((int)(uVar15 >> 0x20) != 0) {
-                            local_104 = -0x3fe5fff3;
-                            iVar4 = -0x3fe5fff3;
-                            goto LAB_0;
-                          }
-                          local_f0 = (uint)uVar15;
-                          memset(local_d8 + (uVar15 & 0xffffffff),0,
+                          goto LAB_1;
+                        }
+                        if ((longlong)local_60 < (longlong)(uVar13 + local_c0)) {
+                          uVar13 = local_60 - local_c0;
+                          local_58 = uVar13;
+                          if ((int)(uVar13 >> 0x20) != 0) goto LAB_0;
+                          local_f0 = (uint)uVar13;
+                          memset(local_d0 + (uVar13 & 0xffffffff),0,
                                  (ulonglong)((local_100 - local_f0) - *param_9));
                         }
-                        cVar3 = CcCopyRead(param_1,&local_e0,uVar15 & 0xffffffff,1,
+                        cVar3 = CcCopyRead(param_1,&local_c0,uVar13 & 0xffffffff,1,
                                            in_stack_fffffffffffffed8,&local_a8);
                         uVar5 = local_f8;
                         if (cVar3 != '\0') {
                           if ((int)local_a8 != 0) {
                     /* WARNING: Subroutine does not return */
                             KeBugCheckEx(0xc1f5,0x3e,(longlong)(int)local_a8,this,0);
                           }
                           local_104 = 0;
                           uVar5 = (uint)local_a0;
                           local_f8 = (uint)local_a0;
-                          puVar10 = (undefined8 *)AddLsnOffset(this,local_58,(ulong)&local_c8);
+                          puVar10 = (undefined8 *)AddLsnOffset(this,local_50,(ulong)&local_e8);
                           *(undefined8 *)param_8 = *puVar10;
-                          goto joined_r0x0001c000f4da;
+                          goto joined_r0x0001c000f4b5;
                         }
                       }
                       else {
                         pIVar11 = param_6;
                         if (bVar1) {
                           pIVar11 = (IClfsRequestAsync *)0x0;
                         }
                         in_stack_fffffffffffffed8 = (uchar *)0x3;
-                        local_104 = ReadLog(this,(_CLS_LSN *)&local_c8,
-                                            (_CLFS_READ_BUFFER *)&local_88,(uint)uVar15 >> 9,3,
+                        local_104 = ReadLog(this,(_CLS_LSN *)&local_e8,
+                                            (_CLFS_READ_BUFFER *)&local_88,(uint)uVar13 >> 9,3,
                                             pIVar11,param_8,&local_f8);
                         uVar5 = local_f8;
                         iVar4 = local_104;
                         if (bVar1) {
-joined_r0x0001c000f4da:
+joined_r0x0001c000f4b5:
                           iVar4 = local_104;
                           if (param_6 != (IClfsRequestAsync *)0x0) {
                             (**(code **)(*(longlong *)param_6 + 0x58))(param_6,local_104,uVar5);
                           }
                         }
                       }
                       uVar2 = (uchar)in_stack_fffffffffffffed8;
                       if ((iVar4 == -0x3fffffef) || (iVar4 == -0x3fe5ffed)) break;
                       if ((bVar1) && (iVar4 == 0)) {
-                        uVar16 = *(ushort *)(local_d8 + 4);
-                        puVar17 = local_d8;
+                        uVar16 = *(ushort *)(local_d0 + 4);
+                        puVar17 = local_d0;
                         uVar6 = RawSectorAlign(this,(uint)uVar16 << 9);
                         if ((*puVar17 != '\0') &&
                            ((uVar16 != 0 && (param_5 = local_100, uVar6 < local_100)))) {
                           param_5 = uVar6;
                           local_100 = uVar6;
                         }
                       }
                       *param_9 = *param_9 + uVar5;
                       local_78 = CONCAT44(local_78._4_4_,(int)local_78 + uVar5);
-                      local_d8 = local_d8 + uVar5;
-                      if (iVar4 < 0) goto LAB_0;
+                      local_d0 = local_d0 + uVar5;
+                      if (iVar4 < 0) goto LAB_1;
                       cVar3 = (**(code **)(*(longlong *)this + 0x138))(this);
                       if ((cVar3 != '\0') && (*(longlong *)param_8 == lVar14)) {
-                        puVar10 = (undefined8 *)AddLsnOffset(this,local_50,(ulong)param_8);
+                        puVar10 = (undefined8 *)AddLsnOffset(this,local_48,(ulong)param_8);
                         *(undefined8 *)param_8 = *puVar10;
-                        plVar9 = (longlong *)AddLsnOffset(this,local_48,(ulong)&local_d0);
+                        plVar9 = (longlong *)AddLsnOffset(this,local_40,(ulong)&local_c8);
                         lVar14 = *plVar9;
-                        local_d0 = lVar14;
-                      }
-                      uVar13 = *(ulonglong *)param_8;
-                      uVar15 = uVar13;
+                        local_c8 = lVar14;
+                      }
+                      uVar15 = *(ulonglong *)param_8;
+                      uVar13 = uVar15;
                     }
                     if (local_108 != '\0') {
                       ExReleaseResourceForThreadLite(this + 200,SystemReserved1[0xf]);
                       local_108 = '\0';
                       local_100 = param_5;
                       iVar4 = local_104;
                     }
                     p_Var8 = local_90;
                     if (((param_6 == (IClfsRequestAsync *)0x0) && (-1 < iVar4)) &&
                        (local_104 = ValidateLogBlock(this,param_2,local_90,local_100,uVar2,'\x04',
-                                                     &local_e4), iVar4 = local_104, -1 < local_104))
+                                                     local_d8), iVar4 = local_104, -1 < local_104))
                     {
                       local_104 = ClfsDecodeBlock(p_Var8,(uint)*(ushort *)(p_Var8 + 4),
-                                                  (uchar)p_Var8[2],'\x04',&local_e4);
+                                                  (uchar)p_Var8[2],'\x04',local_d8);
                       iVar4 = local_104;
                     }
                   }
                   else {
                     if ((param_7 & 0x10) == 0) {
                       ClfsCheckAndResetReadInProgress((longlong)p_Var8,param_5);
                     }
                     local_104 = -0x3fffffef;
                     iVar4 = local_104;
                   }
                 }
                 else {
                   if ((param_7 & 0x10) == 0) {
                     ClfsCheckAndResetReadInProgress((longlong)p_Var8,param_5);
                   }
                   local_104 = -0x3fe5ffed;
                   iVar4 = local_104;
                 }
               }
               else {
                 local_104 = -0x3fe5ffd5;
                 CClfsLogFcbCommon::SetInvalidLogTag((CClfsLogFcbCommon *)this,0xf,-0x3fe5ffd5);
                 iVar4 = local_104;
               }
             }
             else {
               local_104 = -0x3fe5ffe2;
               iVar4 = local_104;
             }
           }
         }
       }
-LAB_0:
+LAB_1:
       if (local_108 != '\0') {
         ExReleaseResourceForThreadLite(this + 200,SystemReserved1[0xf]);
         iVar4 = local_104;
       }
       if ((iVar4 < 0) && (*param_9 = 0, param_6 != (IClfsRequestAsync *)0x0)) {
         (**(code **)(*(longlong *)param_6 + 0x58))(param_6,iVar4,0);
       }
       if (((local_f4 != 0) &&
           (iVar7 = (**(code **)(*(longlong *)param_6 + 0x18))(param_6), iVar7 != 0)) && (-1 < iVar4)
          ) {
         iVar4 = 0x103;
       }
     }
     else {
       iVar4 = -0x3fffff45;
     }
   }
   else {
     iVar4 = -0x3fffff68;
   }
   return iVar4;
 }
 

```


## CClfsBaseFile::ValidateProcessQNode

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.58|
|i_ratio|0.41|
|m_ratio|0.99|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateProcessQNode|ValidateProcessQNode|
|fullname|CClfsBaseFile::ValidateProcessQNode|CClfsBaseFile::ValidateProcessQNode|
|refcount|2|2|
|`length`|499|508|
|called|CClfsBaseFile::OffsetToAddr<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>NTOSKRNL.EXE::RtlLookupElementGenericTableAvl<br>WPP_SF_sl|CClfsBaseFile::OffsetToAddr<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>NTOSKRNL.EXE::RtlLookupElementGenericTableAvl<br>WPP_SF_sl|
|calling|CClfsBaseFile::ValidateTraverseTree|CClfsBaseFile::ValidateTraverseTree|
|paramcount|6|6|
|`address`|1c006087c|1c00601a8|
|sig|long __thiscall ValidateProcessQNode(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2, _CLFS_VALIDATION_QUEUE_NODE * param_3, ulong * param_4, ulong * param_5)|long __thiscall ValidateProcessQNode(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2, _CLFS_VALIDATION_QUEUE_NODE * param_3, ulong * param_4, ulong * param_5)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ValidateProcessQNode Diff


```diff
--- CClfsBaseFile::ValidateProcessQNode
+++ CClfsBaseFile::ValidateProcessQNode
@@ -1,80 +1,77 @@
 
 /* protected: long __cdecl CClfsBaseFile::ValidateProcessQNode(struct _CLFS_VALIDATE_OFFSET_TABLE *
    __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const,struct _CLFS_VALIDATION_QUEUE_NODE *
    __ptr64,unsigned long & __ptr64,unsigned long & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::ValidateProcessQNode
           (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
           _CLFS_BASE_RECORD_HEADER *param_2,_CLFS_VALIDATION_QUEUE_NODE *param_3,ulong *param_4,
           ulong *param_5)
 
 {
   uint uVar1;
   uint uVar2;
   int *piVar3;
   longlong lVar4;
-  ulong uVar5;
-  int iVar6;
-  uint uVar7;
+  int iVar5;
   char local_res20 [8];
-  uint local_28;
-  undefined1 local_24;
-  undefined2 local_23;
-  undefined1 local_21;
+  uint local_38;
+  undefined1 local_34;
+  undefined2 local_33;
+  undefined1 local_31;
   
-  local_28 = 0;
-  uVar7 = *(uint *)(param_3 + 0x10);
-  iVar6 = *(int *)(param_3 + 0x14);
-  local_24 = 0;
+  local_38 = 0;
+  uVar1 = *(uint *)(param_3 + 0x10);
+  iVar5 = *(int *)(param_3 + 0x14);
+  local_34 = 0;
   local_res20[0] = '\0';
-  local_23 = 0;
-  local_21 = 0;
-  if ((0x1337 < uVar7) && (uVar1 = *(uint *)(param_2 + 0x1328), uVar7 - 0x1338 <= uVar1)) {
-    uVar5 = uVar7 + 0x30;
-    piVar3 = OffsetToAddr(this,uVar5);
-    if ((piVar3 != (int *)0x0) && (*piVar3 == iVar6)) {
-      iVar6 = 0x30;
+  local_33 = 0;
+  local_31 = 0;
+  if ((0x1337 < uVar1) && (uVar1 - 0x1338 <= *(uint *)(param_2 + 0x1328))) {
+    piVar3 = OffsetToAddr(this,uVar1 + 0x30);
+    if ((piVar3 != (int *)0x0) && (*piVar3 == iVar5)) {
+      iVar5 = 0x30;
       if (*piVar3 != -0x3e020ff8) {
-        iVar6 = 0x88;
+        iVar5 = 0x88;
       }
-      uVar2 = uVar7 + 0x2f + iVar6;
-      if ((0x1337 < uVar2) && (uVar2 - 0x1338 <= uVar1)) {
-        local_28 = uVar7;
+      uVar2 = uVar1 + 0x2f + iVar5;
+      if ((0x1337 < uVar2) && (uVar2 - 0x1338 <= *(uint *)(param_2 + 0x1328))) {
+        local_38 = uVar1;
         if ((char)piVar3[-2] == '\0') {
-          lVar4 = RtlLookupElementGenericTableAvl(param_1,&local_28);
+          lVar4 = RtlLookupElementGenericTableAvl(param_1,&local_38);
           if ((lVar4 != 0) && (*(char *)(lVar4 + 4) == '\0')) {
             *(undefined1 *)(lVar4 + 4) = 1;
 LAB_0:
             *param_4 = piVar3[-8];
             *param_5 = piVar3[-6];
             return 0;
           }
         }
         else {
           if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
              ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-            WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x16,
-                      &WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,
+            WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x12,
+                      &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,
                       "CClfsBaseFile::ValidateProcessQNode");
           }
-          if ((piVar3[-3] == uVar5) && (piVar3[-4] == piVar3[-3] + iVar6)) {
-            local_24 = 1;
-            lVar4 = RtlInsertElementGenericTableAvl(param_1,&local_28,8,local_res20);
+          if ((piVar3[-3] == uVar1 + 0x30) && (piVar3[-4] == piVar3[-3] + iVar5)) {
+            local_34 = 1;
+            lVar4 = RtlInsertElementGenericTableAvl(param_1,&local_38,8,local_res20);
             if ((local_res20[0] != '\0') && (lVar4 != 0)) goto LAB_0;
           }
         }
       }
     }
   }
   if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-    WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x17,
-              &WPP_aa0fac7daf643391775354fdf4e452eb_Traceguids,"CClfsBaseFile::ValidateProcessQNode"
+    WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x13,
+              &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,"CClfsBaseFile::ValidateProcessQNode"
              );
   }
   *param_4 = 0;
   *param_5 = 0;
   return -0x3fe5fff3;
 }
 

```


## CClfsLogFcbPhysical::CacheBlock

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.67|
|i_ratio|0.72|
|m_ratio|0.97|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|CacheBlock|CacheBlock|
|fullname|CClfsLogFcbPhysical::CacheBlock|CClfsLogFcbPhysical::CacheBlock|
|refcount|6|6|
|`length`|372|350|
|`called`|CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>ClfsLsnCreate<br>ClfsValidateSector<br>Feature_2458037564__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::CcUnpinData<br>_guard_dispatch_icall<br>operator<=|CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>ClfsLsnCreate<br>ClfsValidateSector<br>NTOSKRNL.EXE::CcUnpinData<br>_guard_dispatch_icall<br>operator<=|
|calling|CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::ReadClientBlock<br>CClfsLogFcbPhysical::WriteRestart|CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::ReadClientBlock<br>CClfsLogFcbPhysical::WriteRestart|
|paramcount|4|4|
|`address`|1c0066050|1c00655b0|
|sig|long __thiscall CacheBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong * param_3)|long __thiscall CacheBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::CacheBlock Called Diff


```diff
--- CClfsLogFcbPhysical::CacheBlock called
+++ CClfsLogFcbPhysical::CacheBlock called
@@ -5 +4,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::CacheBlock Diff


```diff
--- CClfsLogFcbPhysical::CacheBlock
+++ CClfsLogFcbPhysical::CacheBlock
@@ -1,68 +1,64 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsLogFcbPhysical::CacheBlock(struct _FILE_OBJECT * __ptr64,union
    _CLS_LSN const & __ptr64,unsigned long & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::CacheBlock
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,_CLS_LSN *param_2,ulong *param_3)
 
 {
   uchar uVar1;
   long lVar2;
   ulonglong *puVar3;
-  __uint64 _Var4;
-  ulonglong uVar5;
-  uchar *puVar6;
-  uint uVar7;
-  void *pvVar8;
+  uchar *puVar4;
+  uint uVar5;
+  void *pvVar6;
   void *local_res20;
   uchar in_stack_ffffffffffffff98;
   uchar *local_40;
   ulonglong local_38;
   __uint64 local_30;
   undefined8 local_28;
   
-  pvVar8 = (void *)0x0;
+  pvVar6 = (void *)0x0;
   local_res20 = (void *)0x0;
   local_40 = (uchar *)0x0;
   *param_3 = 0;
   puVar3 = (ulonglong *)(**(code **)(*(longlong *)this + 0x160))(this,&local_38);
   local_38 = *puVar3;
   local_38 = ClfsLsnCreate((int)(local_38 >> 0x20),(uint)local_38 & 0xfffffe00,0);
   if (((param_2 == (_CLS_LSN *)0x0) ||
-      (uVar7 = (uint)(local_38 >> 0x20), uVar7 < *(uint *)(param_2 + 4))) ||
-     ((uVar7 == *(uint *)(param_2 + 4) && ((uint)local_38 <= *(uint *)param_2)))) {
+      (uVar5 = (uint)(local_38 >> 0x20), uVar5 < *(uint *)(param_2 + 4))) ||
+     ((uVar5 == *(uint *)(param_2 + 4) && ((uint)local_38 <= *(uint *)param_2)))) {
     uVar1 = operator<=((_CLS_LSN *)(this + 0x1e0),param_2);
     if (uVar1 == '\0') {
-      _Var4 = LsnToCacheOffset(this,param_2);
-      local_30 = _Var4;
-      uVar5 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if (((int)uVar5 == 0) || (-1 < (longlong)_Var4)) {
+      local_30 = LsnToCacheOffset(this,param_2);
+      if ((longlong)local_30 < 0) {
+        lVar2 = -0x3fe5fff3;
+      }
+      else {
         local_28 = 0x1000;
         lVar2 = MapCacheData(this,param_1,param_2,0x1000,in_stack_ffffffffffffff98,&local_res20,
                              &local_40);
-        pvVar8 = local_res20;
+        pvVar6 = local_res20;
         if ((-1 < lVar2) &&
-           (puVar6 = local_40, lVar2 = ClfsValidateSector(local_40,local_40[2],'@'),
-           pvVar8 = local_res20, -1 < lVar2)) {
-          *param_3 = (uint)*(ushort *)(puVar6 + 4);
+           (puVar4 = local_40, lVar2 = ClfsValidateSector(local_40,local_40[2],'@'),
+           pvVar6 = local_res20, -1 < lVar2)) {
+          *param_3 = (uint)*(ushort *)(puVar4 + 4);
         }
-      }
-      else {
-        lVar2 = -0x3fe5fff3;
       }
     }
     else {
       lVar2 = -0x3fffffef;
     }
   }
   else {
     lVar2 = -0x3fe5ffed;
   }
-  if (pvVar8 != (void *)0x0) {
-    CcUnpinData(pvVar8);
+  if (pvVar6 != (void *)0x0) {
+    CcUnpinData(pvVar6);
   }
   return lVar2;
 }
 

```


## wil_details_FeatureReporting_ReportUsageToServiceDirect

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.35|
|i_ratio|0.59|
|m_ratio|0.95|
|b_ratio|0.95|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|fullname|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|refcount|2|2|
|`length`|232|226|
|called|NTOSKRNL.EXE::RtlNotifyFeatureUsage<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil_details_FeatureReporting_RecordUsageInCache|NTOSKRNL.EXE::RtlNotifyFeatureUsage<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|3|3|
|`address`|1c001198c|1c00118c4|
|`sig`|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(longlong param_1, undefined8 param_2, ulonglong param_3)|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(undefined8 param_1, undefined8 param_2, ulonglong param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureReporting_ReportUsageToServiceDirect Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect
@@ -1,46 +1,47 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 bool wil_details_FeatureReporting_ReportUsageToServiceDirect
-               (longlong param_1,undefined8 param_2,ulonglong param_3)
+               (undefined8 param_1,undefined8 param_2,ulonglong param_3)
 
 {
   uint6 uVar1;
   uint *puVar2;
-  undefined1 auStack_98 [32];
-  uint *local_78;
-  undefined8 local_68;
-  uint local_60 [6];
-  uint local_48;
-  uint uStack_44;
-  uint uStack_40;
-  uint uStack_3c;
-  undefined8 local_38;
-  ulonglong local_30;
+  undefined1 auStack_88 [32];
+  uint *local_68;
+  undefined8 local_58;
+  uint local_50 [6];
+  uint local_38;
+  uint uStack_34;
+  uint uStack_30;
+  uint uStack_2c;
+  undefined8 local_28;
+  ulonglong local_20;
   
-  local_30 = __security_cookie ^ (ulonglong)auStack_98;
+  local_20 = __security_cookie ^ (ulonglong)auStack_88;
   puVar2 = wil_details_FeatureReporting_RecordUsageInCache
-                     (local_60,*(uint **)(param_1 + 8),param_3,(uint)((ulonglong)param_2 >> 0x20));
-  local_48 = *puVar2;
-  uStack_44 = puVar2[1];
-  uStack_40 = puVar2[2];
-  uStack_3c = puVar2[3];
-  local_38 = *(undefined8 *)(puVar2 + 4);
+                     (local_50,(uint *)&Feature_110180665__private_reporting,param_3,
+                      (uint)((ulonglong)param_2 >> 0x20));
+  local_38 = *puVar2;
+  uStack_34 = puVar2[1];
+  uStack_30 = puVar2[2];
+  uStack_2c = puVar2[3];
+  local_28 = *(undefined8 *)(puVar2 + 4);
   if (g_wil_details_recordFeatureUsage != (code *)0x0) {
-    local_78 = &local_48;
+    local_68 = &local_38;
     (*g_wil_details_recordFeatureUsage)
-              (*(undefined4 *)(param_1 + 0x18),param_3 & 0xffffffff,1,*(undefined8 *)(param_1 + 8));
+              (0x312fa1f,param_3 & 0xffffffff,1,&Feature_110180665__private_reporting);
   }
   if ((((uint)param_2 >> 10 & 1) != 0) && ((int)param_3 != 0xfe)) {
-    local_68._0_6_ = CONCAT24((short)(param_3 & 0xffffffff),*(undefined4 *)(param_1 + 0x18));
-    uVar1 = (uint6)local_68;
-    local_68 = (ulonglong)(uint6)local_68;
+    local_58._0_6_ = CONCAT24((short)(param_3 & 0xffffffff),0x312fa1f);
+    uVar1 = (uint6)local_58;
+    local_58 = (ulonglong)(uint6)local_58;
     if (((uint)param_2 >> 0xb & 1) != 0) {
-      local_68 = CONCAT26(1,uVar1);
+      local_58 = CONCAT26(1,uVar1);
     }
-    RtlNotifyFeatureUsage(&local_68);
+    RtlNotifyFeatureUsage(&local_58);
   }
-  return (int)local_38 == 0;
+  return (int)local_28 == 0;
 }
 

```


## CClfsBaseFilePersisted::CreateImage

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.17|
|i_ratio|0.54|
|m_ratio|1.0|
|b_ratio|0.68|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|CreateImage|CreateImage|
|fullname|CClfsBaseFilePersisted::CreateImage|CClfsBaseFilePersisted::CreateImage|
|refcount|2|2|
|`length`|1966|1945|
|called|<details><summary>Expand for full list:<br>CClfsAuthContainer::CClfsAuthContainer<br>CClfsAuthContainer::Create<br>CClfsAuthContainer::GetRawSectorSize<br>CClfsAuthContainer::Initialize<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::Initialize</summary>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsContainer::IsNullSecurityDescriptor<br>CNG.SYS::BCryptGenRandom<br>NTOSKRNL.EXE::ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExUuidCreate<br>WPP_SF_slSD<br>_guard_dispatch_icall<br>memcpy<br>memset</details>|<details><summary>Expand for full list:<br>CClfsAuthContainer::CClfsAuthContainer<br>CClfsAuthContainer::Create<br>CClfsAuthContainer::GetRawSectorSize<br>CClfsAuthContainer::Initialize<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::Initialize</summary>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsContainer::IsNullSecurityDescriptor<br>CNG.SYS::BCryptGenRandom<br>NTOSKRNL.EXE::ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExUuidCreate<br>WPP_SF_slSD<br>_guard_dispatch_icall<br>memcpy<br>memset</details>|
|calling|CClfsLogFcbPhysical::Initialize|CClfsLogFcbPhysical::Initialize|
|paramcount|8|8|
|`address`|1c0038784|1c00387a0|
|sig|long __thiscall CreateImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, ulong param_2, uchar param_3, _CLFS_FILTER_CONTEXT * param_4, void * param_5, ulong param_6, uchar * param_7)|long __thiscall CreateImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, ulong param_2, uchar param_3, _CLFS_FILTER_CONTEXT * param_4, void * param_5, ulong param_6, uchar * param_7)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::CreateImage Diff


```diff
--- CClfsBaseFilePersisted::CreateImage
+++ CClfsBaseFilePersisted::CreateImage
@@ -1,263 +1,272 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: long __cdecl CClfsBaseFilePersisted::CreateImage(struct _UNICODE_STRING *
    __ptr64,unsigned long,unsigned char,struct _CLFS_FILTER_CONTEXT const & __ptr64,void * __ptr64
    const,unsigned long,unsigned char & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::CreateImage
           (CClfsBaseFilePersisted *this,_UNICODE_STRING *param_1,ulong param_2,uchar param_3,
           _CLFS_FILTER_CONTEXT *param_4,void *param_5,ulong param_6,uchar *param_7)
 
 {
   CClfsBaseFilePersisted *pbBuffer;
-  undefined1 auVar1 [16];
-  uchar uVar2;
-  uint uVar3;
-  ulong uVar4;
-  CClfsAuthContainer *pCVar5;
-  undefined8 *puVar6;
-  undefined8 uVar7;
-  void *pvVar8;
-  undefined8 *puVar9;
-  longlong lVar10;
-  _CLFS_BASE_RECORD_HEADER *p_Var11;
-  ushort uVar12;
-  uint uVar13;
-  byte bVar14;
+  undefined8 *puVar1;
+  undefined1 auVar2 [16];
+  uchar uVar3;
+  long lVar4;
+  ulong uVar5;
+  CClfsAuthContainer *pCVar6;
+  void *pvVar7;
+  undefined8 uVar8;
+  longlong lVar9;
+  _CLFS_BASE_RECORD_HEADER *p_Var10;
+  ushort uVar11;
+  uint uVar12;
+  undefined2 uVar13;
+  _CLFS_CONTROL_RECORD *p_Var14;
+  _CLFS_CONTROL_RECORD *p_Var15;
+  _CLFS_CONTROL_RECORD *p_Var16;
+  byte bVar17;
   uint local_res18 [2];
   uchar local_res20;
   ulong local_60 [2];
   _CLFS_CONTROL_RECORD *local_58;
   __uint64 local_50 [3];
   
-  puVar9 = (undefined8 *)0x0;
+  p_Var16 = (_CLFS_CONTROL_RECORD *)0x0;
+  p_Var14 = (_CLFS_CONTROL_RECORD *)0x0;
   local_58 = (_CLFS_CONTROL_RECORD *)0x0;
   local_60[0] = 0;
   local_res18[0] = param_2 & 0xffffff00;
   local_50[0] = 1;
   *param_7 = '\0';
-  bVar14 = (byte)(param_6 >> 9);
+  bVar17 = (byte)(param_6 >> 9);
   local_res20 = param_3;
   if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1a & 1) != 0)) {
-    WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1f);
-  }
-  uVar3 = Initialize(this,param_6);
-  if ((-1 < (int)uVar3) &&
-     ((*(longlong *)(this + 0x20) != 0 ||
-      (uVar3 = CClfsBaseFile::InitializeImageResource((CClfsBaseFile *)this), -1 < (int)uVar3)))) {
-    pCVar5 = (CClfsAuthContainer *)ExAllocateFromPagedLookasideList(&CClfsAuthContainer::m_laList);
-    puVar6 = puVar9;
-    if (pCVar5 != (CClfsAuthContainer *)0x0) {
-      puVar6 = (undefined8 *)
-               CClfsAuthContainer::CClfsAuthContainer
-                         (pCVar5,param_6,*(_CLFS_AUTHENTICATION_MODE *)(this + 0xe8),
-                          *(_DEVICE_OBJECT **)(this + 0xf0));
-    }
-    *(undefined8 **)(this + 0x98) = puVar6;
-    if (puVar6 == (undefined8 *)0x0) {
-      uVar3 = 0xc000009a;
-    }
-    else {
-      (**(code **)*puVar6)();
-      uVar3 = CClfsAuthContainer::Initialize(*(CClfsAuthContainer **)(this + 0x98),local_50,1);
-      if (-1 < (int)uVar3) {
-        if (*(longlong *)(this + 0xe0) != 0) {
-          ExFreePoolWithTag(*(longlong *)(this + 0xe0),0);
-          *(undefined8 *)(this + 0xe0) = 0;
-        }
-        auVar1._8_8_ = 0;
-        auVar1._0_8_ = (ulonglong)*(ushort *)param_1 + 1;
-        uVar7 = SUB168(ZEXT816(2) * auVar1,0);
-        if (SUB168(ZEXT816(2) * auVar1,8) != 0) {
-          uVar7 = 0xffffffffffffffff;
-        }
-        pvVar8 = (void *)ExAllocatePoolWithTag(1,uVar7,0x73666c43);
-        *(void **)(this + 0xe0) = pvVar8;
-        if (pvVar8 != (void *)0x0) {
-          *(short *)(this + 0xda) = *(short *)param_1 + 2;
-          uVar12 = *(ushort *)param_1;
-          *(ushort *)(this + 0xd8) = uVar12;
-          memcpy(pvVar8,*(void **)(param_1 + 8),(ulonglong)uVar12);
-          *(undefined2 *)
-           (*(longlong *)(this + 0xe0) + (ulonglong)(*(ushort *)(this + 0xd8) >> 1) * 2) = 0;
-          if (*(int *)(param_4 + 0x10) != 0) {
-            pvVar8 = (void *)ExAllocatePoolWithTag(1,*(int *)(param_4 + 0x10),0x73666c43);
-            *(void **)(this + 0xb8) = pvVar8;
-            if (*(longlong *)(param_4 + 8) == 0) {
-              uVar3 = 0xc000009a;
-              (**(code **)(**(longlong **)(this + 0x98) + 8))();
-              *(undefined8 *)(this + 0x98) = 0;
-              goto LAB_0;
-            }
-            *(undefined4 *)(this + 0xc0) = *(undefined4 *)(param_4 + 0x10);
-            memcpy(pvVar8,*(void **)(param_4 + 8),(ulonglong)*(uint *)(param_4 + 0x10));
+    WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1b);
+  }
+  lVar4 = Initialize(this,param_6);
+  p_Var15 = p_Var16;
+  if ((lVar4 < 0) ||
+     ((p_Var15 = p_Var14, *(longlong *)(this + 0x20) == 0 &&
+      (lVar4 = CClfsBaseFile::InitializeImageResource((CClfsBaseFile *)this), lVar4 < 0))))
+  goto LAB_0;
+  pCVar6 = (CClfsAuthContainer *)ExAllocateFromPagedLookasideList(&CClfsAuthContainer::m_laList);
+  p_Var14 = p_Var16;
+  if (pCVar6 != (CClfsAuthContainer *)0x0) {
+    p_Var14 = (_CLFS_CONTROL_RECORD *)
+              CClfsAuthContainer::CClfsAuthContainer
+                        (pCVar6,param_6,*(_CLFS_AUTHENTICATION_MODE *)(this + 0xe8),
+                         *(_DEVICE_OBJECT **)(this + 0xf0));
+  }
+  *(_CLFS_CONTROL_RECORD **)(this + 0x98) = p_Var14;
+  if (p_Var14 == (_CLFS_CONTROL_RECORD *)0x0) {
+    lVar4 = -0x3fffff66;
+    p_Var15 = p_Var16;
+    goto LAB_0;
+  }
+  (*(code *)**(undefined8 **)p_Var14)();
+  lVar4 = CClfsAuthContainer::Initialize(*(CClfsAuthContainer **)(this + 0x98),local_50,1);
+  if (-1 < lVar4) {
+    if (*(longlong *)(this + 0xe0) != 0) {
+      ExFreePoolWithTag(*(longlong *)(this + 0xe0),0);
+      *(undefined8 *)(this + 0xe0) = 0;
+    }
+    auVar2._8_8_ = 0;
+    auVar2._0_8_ = (ulonglong)*(ushort *)param_1 + 1;
+    uVar8 = SUB168(ZEXT416(2) * auVar2,0);
+    if (SUB168(ZEXT416(2) * auVar2,8) != 0) {
+      uVar8 = 0xffffffffffffffff;
+    }
+    pvVar7 = (void *)ExAllocatePoolWithTag(1,uVar8,0x73666c43);
+    *(void **)(this + 0xe0) = pvVar7;
+    if (pvVar7 != (void *)0x0) {
+      *(short *)(this + 0xda) = *(short *)param_1 + 2;
+      uVar11 = *(ushort *)param_1;
+      *(ushort *)(this + 0xd8) = uVar11;
+      memcpy(pvVar7,*(void **)(param_1 + 8),(ulonglong)uVar11);
+      *(undefined2 *)(*(longlong *)(this + 0xe0) + (ulonglong)(*(ushort *)(this + 0xd8) >> 1) * 2) =
+           0;
+      if (*(int *)(param_4 + 0x10) == 0) {
+LAB_1:
+        *(undefined8 *)(this + 0xb0) = *(undefined8 *)param_4;
+        pbBuffer = this + 0xf8;
+        lVar4 = 0;
+        *(__uint64 *)pbBuffer = 0;
+        do {
+          if (*(__uint64 *)pbBuffer != 0) break;
+          lVar4 = BCryptGenRandom((BCRYPT_ALG_HANDLE)0x0,(PUCHAR)pbBuffer,8,2);
+        } while (-1 < lVar4);
+        if (-1 < lVar4) {
+          local_50[0] = 0x10000;
+          lVar4 = CClfsAuthContainer::Create
+                            (*(CClfsAuthContainer **)(this + 0x98),param_1,local_50,param_4,param_5,
+                             bVar17 & 1,*(__uint64 *)pbBuffer,(uchar *)local_res18);
+          if (lVar4 == -0x3fffff29) {
+            local_50[1] = 0x10000;
+            lVar4 = CClfsAuthContainer::Create
+                              (*(CClfsAuthContainer **)(this + 0x98),param_1,local_50 + 1,param_4,
+                               (void *)0x0,bVar17 & 1,*(__uint64 *)pbBuffer,(uchar *)local_res18);
           }
-          *(undefined8 *)(this + 0xb0) = *(undefined8 *)param_4;
-          pbBuffer = this + 0xf8;
-          *(__uint64 *)pbBuffer = 0;
-          do {
-            uVar3 = (uint)puVar9;
-            if (*(__uint64 *)pbBuffer != 0) break;
-            uVar3 = BCryptGenRandom((BCRYPT_ALG_HANDLE)0x0,(PUCHAR)pbBuffer,8,2);
-            puVar9 = (undefined8 *)(ulonglong)uVar3;
-          } while (-1 < (int)uVar3);
-          pCVar5 = *(CClfsAuthContainer **)(this + 0x98);
-          if (-1 < (int)uVar3) {
-            local_50[0] = 0x10000;
-            uVar3 = CClfsAuthContainer::Create
-                              (pCVar5,param_1,local_50,param_4,param_5,bVar14 & 1,
-                               *(__uint64 *)pbBuffer,(uchar *)local_res18);
-            if (uVar3 == 0xc00000d7) {
-              local_50[1] = 0x10000;
-              uVar3 = CClfsAuthContainer::Create
-                                (*(CClfsAuthContainer **)(this + 0x98),param_1,local_50 + 1,param_4,
-                                 (void *)0x0,bVar14 & 1,*(__uint64 *)pbBuffer,(uchar *)local_res18);
-            }
-            pCVar5 = *(CClfsAuthContainer **)(this + 0x98);
-            if (-1 < (int)uVar3) {
-              uVar4 = CClfsAuthContainer::GetRawSectorSize(pCVar5);
-              *(ulong *)(this + 0x90) = uVar4;
-              if (((uVar4 - 1 < 0x1000) && ((uVar4 & 0x1ff) == 0)) &&
-                 ((int)(0x1000 % (ulonglong)uVar4) == 0)) {
-                if ((uVar4 * 6 < 0x10001) && (uVar13 = uVar4 * -6 + 0x10000 >> 1, 0x13a7 < uVar13))
-                {
-                  *(undefined8 *)(this + 0x88) = 0x10000;
-                  uVar7 = ExAllocatePoolWithTag(0x200,0x90,0x73666c43);
-                  *(undefined8 *)(this + 0x30) = uVar7;
-                  lVar10 = ExAllocatePoolWithTag(0x200,0xc,0x73666c43);
-                  *(longlong *)(this + 0x38) = lVar10;
-                  if ((*(void **)(this + 0x30) == (void *)0x0) || (lVar10 == 0)) {
-                    uVar3 = 0xc000009a;
-                  }
-                  else {
-                    memset(*(void **)(this + 0x30),0,0x90);
-                    puVar9 = *(undefined8 **)(this + 0x38);
-                    *puVar9 = 0;
-                    *(undefined4 *)(puVar9 + 1) = 0;
-                    uVar3 = CreateMetadataBlock(this,0,local_60,uVar4 * 2);
-                    if (-1 < (int)uVar3) {
-                      CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_58,'\x01');
-                      CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
-                      *(undefined4 *)(local_58 + 0x14) = 0;
-                      *(undefined8 *)(local_58 + 8) = 0xc1f5c1f500005f1c;
-                      local_58[0x10] = (_CLFS_CONTROL_RECORD)0x1;
-                      uVar3 = CreateMetadataBlock(this,2,local_60,uVar13);
-                      if (-1 < (int)uVar3) {
-                        this[0x94] = (CClfsBaseFilePersisted)0x1;
-                        p_Var11 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
-                        if (p_Var11 == (_CLFS_BASE_RECORD_HEADER *)0x0) {
-                          uVar3 = 0xc01a000d;
+          pCVar6 = *(CClfsAuthContainer **)(this + 0x98);
+          if (-1 < lVar4) {
+            uVar5 = CClfsAuthContainer::GetRawSectorSize(pCVar6);
+            *(ulong *)(this + 0x90) = uVar5;
+            if (((uVar5 - 1 < 0x1000) && ((uVar5 & 0x1ff) == 0)) &&
+               ((int)(0x1000 % (ulonglong)uVar5) == 0)) {
+              if ((uVar5 * 6 < 0x10001) && (uVar12 = uVar5 * -6 + 0x10000 >> 1, 0x13a7 < uVar12)) {
+                *(undefined8 *)(this + 0x88) = 0x10000;
+                uVar8 = ExAllocatePoolWithTag(0x200,0x90,0x73666c43);
+                *(undefined8 *)(this + 0x30) = uVar8;
+                lVar9 = ExAllocatePoolWithTag(0x200,0xc,0x73666c43);
+                *(longlong *)(this + 0x38) = lVar9;
+                if ((*(void **)(this + 0x30) == (void *)0x0) || (lVar9 == 0)) {
+                  lVar4 = -0x3fffff66;
+                }
+                else {
+                  memset(*(void **)(this + 0x30),0,0x90);
+                  puVar1 = *(undefined8 **)(this + 0x38);
+                  *puVar1 = 0;
+                  *(undefined4 *)(puVar1 + 1) = 0;
+                  lVar4 = CreateMetadataBlock(this,0,local_60,uVar5 * 2);
+                  if (-1 < lVar4) {
+                    CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_58,'\x01');
+                    CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
+                    p_Var15 = local_58;
+                    *(undefined4 *)(local_58 + 0x14) = 0;
+                    *(undefined8 *)(local_58 + 8) = 0xc1f5c1f500005f1c;
+                    local_58[0x10] = (_CLFS_CONTROL_RECORD)0x1;
+                    lVar4 = CreateMetadataBlock(this,2,local_60,uVar12);
+                    if (-1 < lVar4) {
+                      uVar13 = 1;
+                      this[0x94] = (CClfsBaseFilePersisted)0x1;
+                      p_Var10 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
+                      if (p_Var10 == (_CLFS_BASE_RECORD_HEADER *)0x0) {
+                        lVar4 = -0x3fe5fff3;
+                      }
+                      else {
+                        *(undefined4 *)(p_Var10 + 0x120) = 0;
+                        *(undefined8 *)(p_Var10 + 0x128) = 0;
+                        *(undefined2 *)(p_Var10 + 0x1333) = uVar13;
+                        p_Var10[0x124] = SUB21(uVar13,0);
+                        *(undefined8 *)(p_Var10 + 0x130) = 0;
+                        *(undefined4 *)(p_Var10 + 0x1328) = 0;
+                        p_Var10[0x1332] = SUB21(uVar13,0);
+                        *(undefined8 *)p_Var10 = 0;
+                        *(undefined4 *)(p_Var10 + 8) = 0;
+                        *(undefined4 *)(p_Var10 + 0xc) = 0;
+                        *(undefined4 *)(p_Var10 + 0x10) = 0;
+                        *(undefined4 *)(p_Var10 + 0x14) = 0;
+                        for (uVar11 = 0; uVar11 < 0x14; uVar11 = uVar11 + 1) {
+                          lVar4 = ExUuidCreate(p_Var10 + 8);
+                          if (lVar4 != -0x3ffffdd3) goto LAB_2;
                         }
-                        else {
-                          *(undefined4 *)(p_Var11 + 0x120) = 0;
-                          *(undefined8 *)(p_Var11 + 0x128) = 0;
-                          *(undefined2 *)(p_Var11 + 0x1333) = 1;
-                          p_Var11[0x124] = (_CLFS_BASE_RECORD_HEADER)0x1;
-                          *(undefined8 *)(p_Var11 + 0x130) = 0;
-                          *(undefined4 *)(p_Var11 + 0x1328) = 0;
-                          p_Var11[0x1332] = (_CLFS_BASE_RECORD_HEADER)0x1;
-                          *(undefined8 *)p_Var11 = 0;
-                          *(undefined4 *)(p_Var11 + 8) = 0;
-                          *(undefined4 *)(p_Var11 + 0xc) = 0;
-                          *(undefined4 *)(p_Var11 + 0x10) = 0;
-                          *(undefined4 *)(p_Var11 + 0x14) = 0;
-                          for (uVar12 = 0; uVar12 < 0x14; uVar12 = uVar12 + 1) {
-                            uVar3 = ExUuidCreate(p_Var11 + 8);
-                            if (uVar3 != 0xc000022d) goto LAB_1;
+                        lVar4 = -0x3fffff7d;
+LAB_2:
+                        if (-1 < lVar4) {
+                          if (local_res20 != '\0') {
+                            p_Var10[0x1332] =
+                                 (_CLFS_BASE_RECORD_HEADER)((byte)p_Var10[0x1332] | 0x40);
                           }
-                          uVar3 = 0xc0000083;
-LAB_1:
-                          if (-1 < (int)uVar3) {
-                            if (local_res20 != '\0') {
-                              p_Var11[0x1332] =
-                                   (_CLFS_BASE_RECORD_HEADER)((byte)p_Var11[0x1332] | 0x40);
-                            }
-                            *(undefined8 *)(p_Var11 + 0x18) = 0;
-                            *(undefined8 *)(p_Var11 + 0x20) = 0;
-                            *(undefined8 *)(p_Var11 + 0x28) = 0;
-                            *(undefined8 *)(p_Var11 + 0x30) = 0;
-                            *(undefined8 *)(p_Var11 + 0x38) = 0;
-                            *(undefined4 *)(p_Var11 + 0x40) = 0;
-                            *(undefined8 *)(p_Var11 + 0x70) = 0;
-                            *(undefined8 *)(p_Var11 + 0x78) = 0;
-                            *(undefined8 *)(p_Var11 + 0x80) = 0;
-                            *(undefined8 *)(p_Var11 + 0x88) = 0;
-                            *(undefined8 *)(p_Var11 + 0x90) = 0;
-                            *(undefined4 *)(p_Var11 + 0x98) = 0;
-                            memset(p_Var11 + 0x138,0,0x1f0);
-                            memset(p_Var11 + 0x328,0,0x1000);
-                            *(undefined8 *)(p_Var11 + 200) = 0;
-                            *(undefined8 *)(p_Var11 + 0xd0) = 0;
-                            *(undefined8 *)(p_Var11 + 0xd8) = 0;
-                            *(undefined8 *)(p_Var11 + 0xe0) = 0;
-                            *(undefined8 *)(p_Var11 + 0xe8) = 0;
-                            *(undefined4 *)(p_Var11 + 0xf0) = 0;
-                            *(_CLFS_BASE_RECORD_HEADER **)(this + 0x40) = p_Var11 + 0x18;
-                            *(undefined4 *)(this + 0x48) = 0xb;
-                            *(CClfsBaseFilePersisted **)(this + 0x50) = this;
-                            *(_CLFS_BASE_RECORD_HEADER **)(this + 0x58) = p_Var11 + 0x70;
-                            *(undefined4 *)(this + 0x60) = 0xb;
-                            *(CClfsBaseFilePersisted **)(this + 0x68) = this;
-                            *(_CLFS_BASE_RECORD_HEADER **)(this + 0x70) = p_Var11 + 200;
-                            *(undefined4 *)(this + 0x78) = 0xb;
-                            *(CClfsBaseFilePersisted **)(this + 0x80) = this;
-                            uVar3 = AddMetaClient(this,param_1);
-                            if ((-1 < (int)uVar3) &&
-                               (uVar3 = CreateMetadataBlock(this,4,local_60,uVar4), -1 < (int)uVar3)
-                               ) {
-                              uVar3 = WriteMetadataBlock(this,4,'\x01');
-                              CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,4);
-                              if (-1 < (int)uVar3) {
-                                p_Var11[0x1332] =
-                                     (_CLFS_BASE_RECORD_HEADER)((byte)p_Var11[0x1332] | 2);
-                                *(undefined2 *)(local_58 + 0x48) = *(undefined2 *)(this + 0x28);
-                                *(_CLFS_CONTROL_RECORD **)(this + 0x1d0) = local_58;
-                              }
+                          *(undefined8 *)(p_Var10 + 0x18) = 0;
+                          *(undefined8 *)(p_Var10 + 0x20) = 0;
+                          *(undefined8 *)(p_Var10 + 0x28) = 0;
+                          *(undefined8 *)(p_Var10 + 0x30) = 0;
+                          *(undefined8 *)(p_Var10 + 0x38) = 0;
+                          *(undefined4 *)(p_Var10 + 0x40) = 0;
+                          *(undefined8 *)(p_Var10 + 0x70) = 0;
+                          *(undefined8 *)(p_Var10 + 0x78) = 0;
+                          *(undefined8 *)(p_Var10 + 0x80) = 0;
+                          *(undefined8 *)(p_Var10 + 0x88) = 0;
+                          *(undefined8 *)(p_Var10 + 0x90) = 0;
+                          *(undefined4 *)(p_Var10 + 0x98) = 0;
+                          memset(p_Var10 + 0x138,0,0x1f0);
+                          memset(p_Var10 + 0x328,0,0x1000);
+                          *(undefined8 *)(p_Var10 + 200) = 0;
+                          *(undefined8 *)(p_Var10 + 0xd0) = 0;
+                          *(undefined8 *)(p_Var10 + 0xd8) = 0;
+                          *(undefined8 *)(p_Var10 + 0xe0) = 0;
+                          *(undefined8 *)(p_Var10 + 0xe8) = 0;
+                          *(undefined4 *)(p_Var10 + 0xf0) = 0;
+                          *(_CLFS_BASE_RECORD_HEADER **)(this + 0x40) = p_Var10 + 0x18;
+                          *(undefined4 *)(this + 0x48) = 0xb;
+                          *(CClfsBaseFilePersisted **)(this + 0x50) = this;
+                          *(_CLFS_BASE_RECORD_HEADER **)(this + 0x58) = p_Var10 + 0x70;
+                          *(undefined4 *)(this + 0x60) = 0xb;
+                          *(CClfsBaseFilePersisted **)(this + 0x68) = this;
+                          *(_CLFS_BASE_RECORD_HEADER **)(this + 0x70) = p_Var10 + 200;
+                          *(undefined4 *)(this + 0x78) = 0xb;
+                          *(CClfsBaseFilePersisted **)(this + 0x80) = this;
+                          lVar4 = AddMetaClient(this,param_1);
+                          if ((-1 < lVar4) &&
+                             (lVar4 = CreateMetadataBlock(this,4,local_60,uVar5), -1 < lVar4)) {
+                            lVar4 = WriteMetadataBlock(this,4,'\x01');
+                            CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,4);
+                            if (-1 < lVar4) {
+                              p_Var10[0x1332] =
+                                   (_CLFS_BASE_RECORD_HEADER)((byte)p_Var10[0x1332] | 2);
+                              *(undefined2 *)(p_Var15 + 0x48) = *(undefined2 *)(this + 0x28);
+                              *(_CLFS_CONTROL_RECORD **)(this + 0x1d0) = p_Var15;
                             }
                           }
                         }
                       }
                     }
                   }
                 }
-                else {
-                  uVar3 = 0xc0000023;
-                }
               }
               else {
-                uVar3 = 0xc0000098;
+                lVar4 = -0x3fffffdd;
+                p_Var15 = p_Var16;
               }
-              goto LAB_0;
             }
+            else {
+              lVar4 = -0x3fffff68;
+            }
+            goto LAB_0;
           }
-          (**(code **)(*(longlong *)pCVar5 + 8))();
-          *(undefined8 *)(this + 0x98) = 0;
-          goto LAB_0;
+          goto LAB_3;
         }
-        uVar3 = 0xc000009a;
+        (**(code **)(*(longlong *)*(CClfsAuthContainer **)(this + 0x98) + 8))();
       }
-      (**(code **)(**(longlong **)(this + 0x98) + 8))();
+      else {
+        pvVar7 = (void *)ExAllocatePoolWithTag(1,*(int *)(param_4 + 0x10),0x73666c43);
+        *(void **)(this + 0xb8) = pvVar7;
+        if (*(longlong *)(param_4 + 8) != 0) {
+          *(undefined4 *)(this + 0xc0) = *(undefined4 *)(param_4 + 0x10);
+          memcpy(pvVar7,*(void **)(param_4 + 8),(ulonglong)*(uint *)(param_4 + 0x10));
+          goto LAB_1;
+        }
+        lVar4 = -0x3fffff66;
+        pCVar6 = *(CClfsAuthContainer **)(this + 0x98);
+LAB_3:
+        (**(code **)(*(longlong *)pCVar6 + 8))();
+      }
       *(undefined8 *)(this + 0x98) = 0;
-    }
-  }
+      p_Var15 = p_Var16;
+      goto LAB_0;
+    }
+    lVar4 = -0x3fffff66;
+  }
+  (**(code **)(**(longlong **)(this + 0x98) + 8))();
+  *(undefined8 *)(this + 0x98) = 0;
 LAB_0:
-  if ((local_58 != (_CLFS_CONTROL_RECORD *)0x0) && (*(longlong *)(this + 0x1d0) == 0)) {
+  if ((p_Var15 != (_CLFS_CONTROL_RECORD *)0x0) && (*(longlong *)(this + 0x1d0) == 0)) {
     CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
-    local_58 = (_CLFS_CONTROL_RECORD *)0x0;
-  }
-  if (-1 < (int)uVar3) {
+  }
+  if (-1 < lVar4) {
     if (((char)local_res18[0] != '\0') &&
        ((param_5 == (void *)0x0 ||
-        (uVar2 = CClfsContainer::IsNullSecurityDescriptor(param_5), uVar2 == '\0')))) {
+        (uVar3 = CClfsContainer::IsNullSecurityDescriptor(param_5), uVar3 == '\0')))) {
       *param_7 = '\x01';
     }
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-      WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x20);
-    }
-  }
-  return uVar3;
+      WPP_SF_slSD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1c);
+    }
+  }
+  return lVar4;
 }
 

```


## CClfsBaseFile::GetSymbol

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling,called|
|ratio|0.3|
|i_ratio|0.46|
|m_ratio|0.95|
|b_ratio|0.8|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|GetSymbol|GetSymbol|
|fullname|CClfsBaseFile::GetSymbol|CClfsBaseFile::GetSymbol|
|`refcount`|16|14|
|`length`|335|277|
|`called`|NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::OffsetToAddr<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsBaseFileSnapshot::ReadContainerQ</summary></details>|CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ|
|paramcount|4|4|
|`address`|1c00612d0|1c0060b60|
|sig|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, ulong param_2, _CLFS_CONTAINER_CONTEXT * * param_3)|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, ulong param_2, _CLFS_CONTAINER_CONTEXT * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::GetSymbol Called Diff


```diff
--- CClfsBaseFile::GetSymbol called
+++ CClfsBaseFile::GetSymbol called
@@ -0,0 +1 @@
+CClfsBaseFile::OffsetToAddr
```


### CClfsBaseFile::GetSymbol Calling Diff


```diff
--- CClfsBaseFile::GetSymbol calling
+++ CClfsBaseFile::GetSymbol calling
@@ -10 +9,0 @@
-CClfsBaseFilePersisted::WriteMetadataBlock
```


### CClfsBaseFile::GetSymbol Diff


```diff
--- CClfsBaseFile::GetSymbol
+++ CClfsBaseFile::GetSymbol
@@ -1,69 +1,47 @@
 
 /* public: long __cdecl CClfsBaseFile::GetSymbol(long,unsigned long,struct _CLFS_CONTAINER_CONTEXT *
    __ptr64 * __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::GetSymbol
           (CClfsBaseFile *this,long param_1,ulong param_2,_CLFS_CONTAINER_CONTEXT **param_3)
 
 {
-  uint uVar1;
-  longlong lVar2;
-  char cVar3;
+  longlong lVar1;
+  char cVar2;
+  _CLFS_CONTAINER_CONTEXT *p_Var3;
+  undefined4 in_register_00000014;
   uint uVar4;
-  _CLFS_CONTAINER_CONTEXT *p_Var5;
-  undefined4 in_register_00000014;
-  _CLFS_CONTAINER_CONTEXT *p_Var6;
-  uint uVar7;
-  long local_28;
+  long local_38;
   
-  p_Var6 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-  local_28 = 0;
+  local_38 = 0;
   if ((uint)param_1 < 0x1368) {
     return -0x3fe5fff3;
   }
   *param_3 = (_CLFS_CONTAINER_CONTEXT *)0x0;
-  cVar3 = ExAcquireResourceSharedLite
+  cVar2 = ExAcquireResourceSharedLite
                     (*(undefined8 *)(this + 0x20),
                      CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
-  lVar2 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
-  if (lVar2 != 0) {
-    uVar1 = *(uint *)(lVar2 + 0x28);
-    uVar4 = uVar1 + param_1 + 0x2fU;
-    if ((param_1 + 0x2fU <= uVar4) && (uVar7 = (uint)*(ushort *)(lVar2 + 4) << 9, uVar4 < uVar7)) {
-      if (*(short *)(this + 0x28) == 0) {
-LAB_0:
-        p_Var5 = p_Var6;
-      }
-      else {
-        uVar4 = *(uint *)(*(longlong *)(this + 0x30) + 0x38);
-        if (((uVar4 <= uVar1) || (uVar1 < 0x70)) ||
-           (p_Var5 = (_CLFS_CONTAINER_CONTEXT *)(lVar2 + (ulonglong)uVar1), uVar4 - uVar1 < 0x1338))
-        goto LAB_0;
-      }
-      if ((((uint)param_1 <= uVar1 + param_1) && (p_Var5 != (_CLFS_CONTAINER_CONTEXT *)0x0)) &&
-         (uVar1 + param_1 < uVar7)) {
-        p_Var6 = p_Var5 + (uint)param_1;
-      }
-      if (p_Var6 != (_CLFS_CONTAINER_CONTEXT *)0x0) {
-        if (*(int *)(p_Var6 + -0xc) != param_1) {
-          local_28 = -0x3ffffff8;
-          goto LAB_1;
-        }
-        if ((((longlong)*(int *)(p_Var6 + -0x10) == (ulonglong)(*(int *)(p_Var6 + -0xc) + 0x30)) &&
-            (*(int *)p_Var6 == -0x3e020ff8)) &&
-           ((*(int *)(p_Var6 + 4) == 0x30 && (*(ulong *)(p_Var6 + 0x10) == param_2)))) {
-          *param_3 = p_Var6;
-          goto LAB_1;
-        }
-      }
+  lVar1 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
+  if ((((lVar1 != 0) && (uVar4 = *(int *)(lVar1 + 0x28) + param_1 + 0x2fU, param_1 + 0x2fU <= uVar4)
+       ) && (uVar4 < (uint)*(ushort *)(lVar1 + 4) << 9)) &&
+     (p_Var3 = OffsetToAddr(this,param_1), p_Var3 != (_CLFS_CONTAINER_CONTEXT *)0x0)) {
+    if (*(int *)(p_Var3 + -0xc) != param_1) {
+      local_38 = -0x3ffffff8;
+      goto LAB_0;
+    }
+    if ((((longlong)*(int *)(p_Var3 + -0x10) == (ulonglong)(*(int *)(p_Var3 + -0xc) + 0x30)) &&
+        (*(int *)p_Var3 == -0x3e020ff8)) &&
+       ((*(int *)(p_Var3 + 4) == 0x30 && (*(ulong *)(p_Var3 + 0x10) == param_2)))) {
+      *param_3 = p_Var3;
+      goto LAB_0;
     }
   }
-  local_28 = -0x3fe5fff3;
-LAB_1:
-  if (cVar3 != '\0') {
+  local_38 = -0x3fe5fff3;
+LAB_0:
+  if (cVar2 != '\0') {
     ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
   }
-  return local_28;
+  return local_38;
 }
 

```


## wil_details_FeatureReporting_ReportUsageToService

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.63|
|i_ratio|0.5|
|m_ratio|0.94|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|fullname|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|refcount|2|2|
|`length`|125|114|
|called|_guard_dispatch_icall<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|_guard_dispatch_icall<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|
|calling|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|paramcount|3|3|
|`address`|1c0011908|1c0011848|
|`sig`|undefined __fastcall wil_details_FeatureReporting_ReportUsageToService(longlong param_1, undefined8 param_2, int param_3)|undefined __fastcall wil_details_FeatureReporting_ReportUsageToService(undefined8 param_1, undefined8 param_2, uint param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureReporting_ReportUsageToService Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToService
+++ wil_details_FeatureReporting_ReportUsageToService
@@ -1,26 +1,27 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 
 void wil_details_FeatureReporting_ReportUsageToService
-               (longlong param_1,undefined8 param_2,int param_3)
+               (undefined8 param_1,undefined8 param_2,uint param_3)
 
 {
   bool bVar1;
   uint uVar2;
   undefined7 extraout_var;
-  uint uVar3;
-  int local_res18 [4];
+  ulonglong uVar3;
+  uint uVar4;
+  uint local_res18 [4];
   
-  uVar3 = (uint)param_2 & 1;
+  uVar4 = (uint)param_2 & 1;
+  uVar3 = (ulonglong)param_3;
   local_res18[0] = param_3;
-  uVar2 = wil_details_MapReportingKind(param_3,uVar3);
-  bVar1 = wil_details_FeatureReporting_ReportUsageToServiceDirect(param_1,param_2,(ulonglong)uVar2);
+  uVar2 = wil_details_MapReportingKind(param_3,uVar4);
+  bVar1 = wil_details_FeatureReporting_ReportUsageToServiceDirect(uVar3,param_2,(ulonglong)uVar2);
   if (((int)CONCAT71(extraout_var,bVar1) != 0) &&
      (g_wil_details_pfnFeatureLoggingHook != (code *)0x0)) {
     (*g_wil_details_pfnFeatureLoggingHook)
-              (*(undefined4 *)(param_1 + 0x18),*(undefined8 *)(param_1 + 0x10),0,uVar3,local_res18,0
-               ,0,1);
+              (0x312fa1f,&Feature_110180665_logged_traits,0,uVar4,local_res18,0,0,1);
   }
   return;
 }
 

```


## CClfsBaseFile::ValidateClientContextOffsets

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.45|
|i_ratio|0.68|
|m_ratio|1.0|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateClientContextOffsets|ValidateClientContextOffsets|
|fullname|CClfsBaseFile::ValidateClientContextOffsets|CClfsBaseFile::ValidateClientContextOffsets|
|refcount|2|2|
|`length`|485|489|
|called|CClfsBaseFile::ClientCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|CClfsBaseFile::ClientCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|
|calling|CClfsBaseFile::ValidateOffsets|CClfsBaseFile::ValidateOffsets|
|paramcount|3|3|
|`address`|1c006212c|1c0061770|
|sig|long __thiscall ValidateClientContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|long __thiscall ValidateClientContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::ValidateClientContextOffsets Diff


```diff
--- CClfsBaseFile::ValidateClientContextOffsets
+++ CClfsBaseFile::ValidateClientContextOffsets
@@ -1,87 +1,86 @@
 
 /* protected: long __cdecl CClfsBaseFile::ValidateClientContextOffsets(struct
    _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::ValidateClientContextOffsets
           (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
           _CLFS_BASE_RECORD_HEADER *param_2)
 
 {
-  byte bVar1;
-  long lVar2;
+  uint uVar1;
+  byte bVar2;
   long lVar3;
-  void *pvVar4;
-  longlong lVar5;
-  _CLFS_VALIDATE_OFFSET_TABLE *this_00;
-  uint uVar6;
+  long lVar4;
+  void *pvVar5;
+  longlong lVar6;
+  CClfsBaseFile *this_00;
   uint uVar7;
-  ulonglong uVar8;
-  _CLFS_BASE_RECORD_HEADER *p_Var9;
-  ulong uVar10;
+  uint uVar8;
+  ulonglong uVar9;
+  _CLFS_BASE_RECORD_HEADER *p_Var10;
   char local_res20 [8];
   int local_38;
   undefined1 local_34;
   undefined2 local_33;
   undefined1 local_31;
   _CLFS_CLIENT_CONTEXT *local_30;
   
-  lVar3 = 0;
+  lVar4 = 0;
   local_38 = 0;
-  uVar6 = 0;
+  uVar7 = 0;
   local_res20[0] = '\0';
   local_34 = 0;
   local_33 = 0;
   local_31 = 0;
-  uVar8 = 0;
-  this_00 = (_CLFS_VALIDATE_OFFSET_TABLE *)this;
-  p_Var9 = param_2;
-  while (uVar7 = (uint)uVar8, uVar7 < 0x7c) {
-    uVar10 = *(ulong *)(param_2 + uVar8 * 4 + 0x138);
-    if (uVar10 - 1 < 0xfffffffe) {
-      uVar6 = uVar6 + 1;
-      p_Var9 = param_2;
-      lVar3 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar10 + 0x87,param_2);
-      if ((((lVar3 < 0) ||
-           (lVar3 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar10 - 0x30,p_Var9),
-           lVar3 < 0)) || (pvVar4 = OffsetToAddr(this,uVar10), pvVar4 == (void *)0x0)) ||
-         ((*(ulong *)((longlong)pvVar4 + -0xc) != uVar10 ||
-          (*(int *)((longlong)pvVar4 + -0x10) != *(ulong *)((longlong)pvVar4 + -0xc) + 0x88))))
+  uVar9 = 0;
+  p_Var10 = param_2;
+  while (uVar8 = (uint)uVar9, uVar8 < 0x7c) {
+    uVar1 = *(uint *)(param_2 + uVar9 * 4 + 0x138);
+    this_00 = (CClfsBaseFile *)(ulonglong)uVar1;
+    if (uVar1 - 1 < 0xfffffffe) {
+      uVar7 = uVar7 + 1;
+      p_Var10 = param_2;
+      lVar4 = ValidateCheckifWithinSymbolZone(this_00,uVar1 + 0x87,param_2);
+      if (((lVar4 < 0) ||
+          (lVar4 = ValidateCheckifWithinSymbolZone(this_00,(int)this_00 - 0x30,p_Var10), lVar4 < 0))
+         || (pvVar5 = OffsetToAddr(this,(ulong)this_00), pvVar5 == (void *)0x0)) goto LAB_0;
+      if ((*(int *)((longlong)pvVar5 + -0xc) != *(int *)(param_2 + uVar9 * 4 + 0x138)) ||
+         (*(int *)((longlong)pvVar5 + -0x10) != *(int *)((longlong)pvVar5 + -0xc) + 0x88))
       goto LAB_0;
       local_30 = (_CLFS_CLIENT_CONTEXT *)0x0;
-      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)CONCAT71((int7)((ulonglong)p_Var9 >> 8),(uchar)uVar8);
-      lVar3 = GetSymbol(this,uVar10,(uchar)uVar8,&local_30);
-      if ((lVar3 < 0) || (((byte)local_30[8] != uVar7 || (*(int *)local_30 != -0x3e020ff9))))
+      p_Var10 = (_CLFS_BASE_RECORD_HEADER *)CONCAT71((int7)((ulonglong)p_Var10 >> 8),(uchar)uVar9);
+      lVar4 = GetSymbol(this,*(int *)(param_2 + uVar9 * 4 + 0x138),(uchar)uVar9,&local_30);
+      if ((lVar4 < 0) || (((byte)local_30[8] != uVar8 || (*(int *)local_30 != -0x3e020ff9))))
       goto LAB_0;
-      local_38 = *(int *)(param_2 + uVar8 * 4 + 0x138) + -0x30;
-      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)&DAT_1;
-      this_00 = param_1;
-      lVar5 = RtlInsertElementGenericTableAvl(param_1,&local_38,8,local_res20);
-      if ((local_res20[0] == '\0') || (lVar5 == 0)) goto LAB_0;
+      local_38 = *(int *)(param_2 + uVar9 * 4 + 0x138) + -0x30;
+      p_Var10 = (_CLFS_BASE_RECORD_HEADER *)&DAT_1;
+      lVar6 = RtlInsertElementGenericTableAvl(param_1,&local_38,8,local_res20);
+      if ((local_res20[0] == '\0') || (lVar6 == 0)) goto LAB_0;
     }
-    uVar8 = (ulonglong)(uVar7 + 1);
+    uVar9 = (ulonglong)(uVar8 + 1);
   }
-  bVar1 = ClientCount(this);
-  if (uVar6 == bVar1) {
-    lVar2 = lVar3;
+  bVar2 = ClientCount(this);
+  if (uVar7 == bVar2) {
+    lVar3 = lVar4;
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x19,p_Var9,
+      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x15,p_Var10,
                   "CClfsBaseFile::ValidateClientContextOffsets");
     }
   }
   else {
 LAB_0:
     if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1a,p_Var9,
+      WPP_SF_sdLD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x16,p_Var10,
                   "CClfsBaseFile::ValidateClientContextOffsets");
     }
-    lVar2 = -0x3fe5fff3;
-    if (lVar3 < 0) {
-      lVar2 = lVar3;
+    lVar3 = -0x3fe5fff3;
+    if (lVar4 < 0) {
+      lVar3 = lVar4;
     }
   }
-  return lVar2;
+  return lVar3;
 }
 

```


## wil_details_IsEnabledFallback

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,refcount,length,sig,address,calling|
|ratio|0.48|
|i_ratio|0.43|
|m_ratio|0.96|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|3|2|
|`length`|140|135|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1868496191__private_IsEnabledFallback<br>Feature_2458037564__private_IsEnabledFallback|Feature_110180665__private_IsEnabledFallback|
|paramcount|3|2|
|`address`|1c0011d50|1c0011c74|
|`sig`|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(undefined4 * param_1, uint param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -1,2 +1 @@
-Feature_1868496191__private_IsEnabledFallback
-Feature_2458037564__private_IsEnabledFallback
+Feature_110180665__private_IsEnabledFallback
```


### wil_details_IsEnabledFallback Diff


```diff
--- wil_details_IsEnabledFallback
+++ wil_details_IsEnabledFallback
@@ -1,22 +1,26 @@
 
-uint wil_details_IsEnabledFallback(ulonglong param_1,int param_2,undefined8 *param_3)
+uint wil_details_IsEnabledFallback(undefined4 *param_1,uint param_2)
 
 {
   uint uVar1;
-  ulonglong local_res8;
+  undefined4 *puVar2;
+  ulonglong local_res18;
   
   uVar1 = (uint)param_1;
-  local_res8 = param_1 & 0xffffffff;
-  if ((param_1 & 2) == 0) {
-    local_res8 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
-                           ((uint *)*param_3,param_1,(longlong)param_3);
-    uVar1 = (uint)local_res8;
+  local_res18 = (ulonglong)param_1 & 0xffffffff;
+  if (((ulonglong)param_1 & 2) == 0) {
+    puVar2 = &Feature_110180665__private_featureState;
+    local_res18 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                            (&Feature_110180665__private_featureState,(ulonglong)param_1,0x1c0024860
+                            );
+    param_1 = puVar2;
+    uVar1 = (uint)local_res18;
   }
   if ((param_2 != 0) &&
-     (wil_details_FeatureReporting_ReportUsageToService((longlong)param_3,local_res8,param_2),
-     param_2 - 3U < 2)) {
-    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath((uint)local_res8,param_2,param_3);
+     (wil_details_FeatureReporting_ReportUsageToService(param_1,local_res18,param_2),
+     param_2 - 3 < 2)) {
+    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath((uint)local_res18,param_2);
   }
   return uVar1 & 1;
 }
 

```


## CClfsLogFcbPhysical::FindEndOfLog

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.97|
|i_ratio|0.86|
|m_ratio|1.0|
|b_ratio|0.84|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|FindEndOfLog|FindEndOfLog|
|fullname|CClfsLogFcbPhysical::FindEndOfLog|CClfsLogFcbPhysical::FindEndOfLog|
|refcount|2|2|
|`length`|1594|1580|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>ClfsLsnCreate<br>ClfsValidateSector<br>Feature_2458037564__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag</summary>_guard_dispatch_icall<br>memcpy</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>ClfsLsnCreate<br>ClfsValidateSector<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>_guard_dispatch_icall</summary>memcpy</details>|
|calling|CClfsLogFcbPhysical::Initialize|CClfsLogFcbPhysical::Initialize|
|paramcount|3|3|
|`address`|1c007593c|1c007562c|
|sig|long __thiscall FindEndOfLog(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2)|long __thiscall FindEndOfLog(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::FindEndOfLog Called Diff


```diff
--- CClfsLogFcbPhysical::FindEndOfLog called
+++ CClfsLogFcbPhysical::FindEndOfLog called
@@ -8 +7,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::FindEndOfLog Diff


```diff
--- CClfsLogFcbPhysical::FindEndOfLog
+++ CClfsLogFcbPhysical::FindEndOfLog
@@ -1,248 +1,247 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsLogFcbPhysical::FindEndOfLog(struct _FILE_OBJECT * __ptr64,union
    _CLS_LSN const & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::FindEndOfLog(CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,_CLS_LSN *param_2)
 
 {
   _CLS_LSN *p_Var1;
   ushort uVar2;
   undefined8 uVar3;
   bool bVar4;
   bool bVar5;
   ulonglong uVar6;
   char cVar7;
   long lVar8;
   ulonglong uVar9;
   undefined8 *puVar10;
   __uint64 _Var11;
   ulonglong uVar12;
   _CLFS_LOG_BLOCK_HEADER *p_Var13;
   uchar uVar14;
   _CLS_LSN *p_Var15;
   void *pvVar16;
   uint uVar17;
   ulonglong _Size;
   void *pvVar18;
   uchar local_res18;
   uchar local_res20 [8];
   _CLS_LSN *in_stack_fffffffffffffee8;
   uint local_f4;
   uint local_f0;
   _CLFS_LOG_BLOCK_HEADER *local_e8;
   longlong local_e0;
   uint local_d8;
   void *local_d0;
   void *local_c8;
   ulong local_c0;
   uint local_bc;
   uint local_b8;
   uint local_b4;
-  ulonglong local_b0;
+  __uint64 local_b0;
   uint local_a8;
   ulonglong local_a0;
   longlong local_98;
   ulonglong local_90;
   undefined8 local_88;
   _CLS_LSN *local_80;
   _CLS_LSN *local_78;
   _CLS_LSN *local_70;
   undefined8 local_68;
   ulonglong local_60;
   ulonglong local_58;
   ulonglong local_50;
   _CLS_LSN local_48 [8];
   ulonglong local_40;
   
   pvVar16 = (void *)0x0;
   local_c8 = (void *)0x0;
   local_d0 = (void *)0x0;
   local_e8 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
   local_res18 = '\0';
   local_f4 = 0;
   local_f0 = 0;
   local_c0 = 0;
   local_bc = 0;
   local_res20[0] = '\0';
   local_78 = (_CLS_LSN *)(this + 0x560);
   *(undefined8 *)local_78 = 0;
   uVar9 = ClfsLsnCreate(*(int *)(this + 0x588),0,0);
   local_70 = (_CLS_LSN *)(this + 0x1e0);
   *(ulonglong *)local_70 = uVar9;
   p_Var1 = (_CLS_LSN *)(this + 0x1f8);
   *(undefined8 *)p_Var1 = *(undefined8 *)param_2;
   local_e0 = *(longlong *)param_2;
   local_98 = *(longlong *)(this + 0x50);
   p_Var15 = (_CLS_LSN *)&local_98;
   local_80 = p_Var1;
   puVar10 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_68,(__uint64 *)(this + 0x558));
   uVar3 = *puVar10;
   local_88 = uVar3;
   _Var11 = LsnToCacheOffset(this,p_Var1);
-  local_b0 = _Var11;
-  uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
   uVar14 = (uchar)p_Var15;
   pvVar18 = pvVar16;
-  if (((int)uVar9 == 0) || ((local_b0 & 0x8000000000000000) == 0)) {
+  local_b0 = _Var11;
+  if ((longlong)_Var11 < 0) {
+    local_d8 = 0xc01a000d;
+  }
+  else {
 LAB_0:
     uVar14 = (uchar)p_Var15;
     if (local_res18 == '\0') {
       if (pvVar18 != (void *)0x0) {
         CcUnpinData(pvVar18);
         local_c8 = (void *)0x0;
         local_d0 = (void *)0x0;
         pvVar18 = (void *)0x0;
       }
       local_60 = _Var11 + ((uint)((longlong)_Var11 >> 0x3f) & 0x3ffff) & 0xfffffffffffc0000;
       uVar9 = _Var11 - local_60;
       if ((local_60 == 0) || (local_90 = local_60, 0x40000 < local_60)) {
         local_90 = 0x40000;
       }
       uVar6 = local_90;
       uVar14 = (uchar)&local_60;
       local_a0 = uVar9;
       local_58 = local_60;
       local_50 = uVar9;
       puVar10 = (undefined8 *)AddLsnOffset(this,local_48,(__uint64 *)(this + 0x558));
       local_68 = *puVar10;
       uVar17 = (uint)((ulonglong)local_68 >> 0x20);
       if ((uVar17 <= local_88._4_4_) &&
          ((uVar17 != local_88._4_4_ || ((uint)local_68 < (uint)uVar3)))) {
         p_Var15 = (_CLS_LSN *)0x0;
         local_d8 = MapCacheData(this,param_1,(_CLS_LSN *)&local_68,(ulong)uVar6,
                                 (uchar)in_stack_fffffffffffffee8,&local_c8,&local_d0);
         uVar14 = (uchar)p_Var15;
         pvVar16 = (void *)(ulonglong)local_d8;
         pvVar18 = local_c8;
         if (-1 < (int)local_d8) {
           bVar5 = true;
           bVar4 = true;
 LAB_1:
           do {
             pvVar18 = local_c8;
             if ((!bVar4) || (local_res18 != '\0')) goto LAB_0;
             _Size = (ulonglong)local_f0;
             if (local_f4 == 0) {
               local_a0 = uVar9 + _Size;
               local_f0 = 0;
               local_b4 = 0;
               while( true ) {
                 uVar9 = local_a0;
                 if (((!bVar4) || (local_res18 != '\0')) || ((longlong)uVar6 <= (longlong)local_a0))
                 goto LAB_1;
                 p_Var13 = (_CLFS_LOG_BLOCK_HEADER *)((longlong)local_d0 + local_a0);
                 lVar8 = ClfsValidateSector((uchar *)p_Var13,(uchar)p_Var13[2],'@');
                 bVar4 = bVar5;
                 if (lVar8 < 0) break;
                 cVar7 = (**(code **)(*(longlong *)this + 0x138))();
                 if (cVar7 == '\0') {
                   uVar2 = *(ushort *)(p_Var13 + 4);
                 }
                 else {
                   uVar2 = *(ushort *)(p_Var13 + 6);
                 }
                 uVar17 = (uint)uVar2 * 0x200;
                 local_98 = (ulonglong)uVar2 * 0x200;
                 local_90 = local_98 + uVar9;
                 if ((longlong)uVar6 < (longlong)local_90) {
                   if (local_bc < uVar17) {
                     if (local_e8 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
                       ExFreePoolWithTag(local_e8,0);
                     }
                     local_bc = uVar17;
                     local_a8 = uVar17;
                     local_e8 = (_CLFS_LOG_BLOCK_HEADER *)
                                ExAllocatePoolWithTag(1,(ulonglong)uVar2 << 9,0x73666c43);
                     uVar14 = (uchar)p_Var15;
                     if (local_e8 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
                       local_d8 = 0xc000009a;
                       pvVar18 = local_c8;
                       goto LAB_2;
                     }
                   }
                   local_f4 = (ulong)uVar6 - (int)uVar9;
                   local_b8 = local_f4;
                   memcpy(local_e8,(void *)((longlong)local_d0 + uVar9),(ulonglong)local_f4);
                   local_a0 = uVar9 + local_f4;
                   _Var11 = _Var11 + local_f4;
                   local_f0 = uVar17 - local_f4;
                   bVar5 = false;
                   local_b4 = local_f0;
                   local_b0 = _Var11;
                   bVar4 = bVar5;
                 }
                 else {
                   in_stack_fffffffffffffee8 = (_CLS_LSN *)&local_e0;
                   p_Var15 = local_78;
                   local_res18 = IsEof(this,p_Var13,local_res20,local_78,in_stack_fffffffffffffee8,
                                       local_80,&local_c0);
                   local_a0 = local_90;
                   _Var11 = _Var11 + local_98;
                   local_b0 = _Var11;
                   if ((longlong)uVar6 <= (longlong)local_90) {
                     bVar5 = false;
                     bVar4 = bVar5;
                   }
                 }
               }
               local_res18 = '\x01';
             }
             else {
               uVar12 = uVar6 - uVar9;
               if (_Size < uVar12) {
                 memcpy(local_e8 + local_f4,(void *)((longlong)local_d0 + uVar9),_Size);
                 in_stack_fffffffffffffee8 = (_CLS_LSN *)&local_e0;
                 p_Var15 = local_78;
                 local_res18 = IsEof(this,local_e8,local_res20,local_78,in_stack_fffffffffffffee8,
                                     local_80,&local_c0);
                 _Var11 = _Var11 + _Size;
                 local_f4 = 0;
                 local_b8 = 0;
                 local_b0 = _Var11;
                 bVar4 = bVar5;
               }
               else {
                 local_40 = uVar12;
                 memcpy(local_e8 + local_f4,(void *)((longlong)local_d0 + uVar9),uVar12 & 0xffffffff)
                 ;
                 local_f0 = local_f0 - (int)uVar12;
                 local_f4 = local_f4 + (int)uVar12;
                 _Var11 = _Var11 + (uVar12 & 0xffffffff);
                 bVar5 = false;
                 local_b8 = local_f4;
                 local_b4 = local_f0;
                 local_b0 = _Var11;
                 bVar4 = false;
               }
             }
           } while( true );
         }
         goto LAB_2;
       }
     }
     local_d8 = (uint)pvVar16;
     if (local_e0 == -0x100000000) {
       local_d8 = 0xc01a000d;
     }
   }
-  else {
-    local_d8 = 0xc01a000d;
-  }
 LAB_2:
   uVar17 = local_d8;
   if (local_e8 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
     ExFreePoolWithTag(local_e8,0);
   }
   if (pvVar18 != (void *)0x0) {
     CcUnpinData(pvVar18);
   }
   p_Var1 = local_70;
   if (local_e0 != -0x100000000) {
     PurgeCacheSection(this,(_CLS_LSN *)&local_e0,local_70,uVar14);
   }
   *(longlong *)p_Var1 = local_e0;
   return uVar17;
 }
 

```


## CClfsLogFcbPhysical::ValidateRegionBlocks

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.22|
|i_ratio|0.31|
|m_ratio|0.94|
|b_ratio|0.51|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ValidateRegionBlocks|ValidateRegionBlocks|
|fullname|CClfsLogFcbPhysical::ValidateRegionBlocks|CClfsLogFcbPhysical::ValidateRegionBlocks|
|refcount|2|2|
|`length`|4079|3611|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::GetNextRegionLsn<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::IsBlockBeyondBuffer<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>ClfsIsOwnerPage</summary>ClfsValidateSector<br>ClfsVerifyBlockOwnerEntry<br>Feature_2458037564__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>memcpy<br>operator!=<br>operator<=</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::GetNextRegionLsn<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::IsBlockBeyondBuffer<br>CClfsLogFcbPhysical::IsEof<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>ClfsIsOwnerPage</summary>ClfsValidateSector<br>ClfsVerifyBlockOwnerEntry<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>memcpy<br>operator!=<br>operator<=</details>|
|calling|CClfsLogFcbPhysical::FindLastOwnerPage|CClfsLogFcbPhysical::FindLastOwnerPage|
|paramcount|6|6|
|`address`|1c0075fb4|1c0075c94|
|sig|long __thiscall ValidateRegionBlocks(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar * param_2, _CLS_LSN * param_3, ulong * param_4, ulong * param_5)|long __thiscall ValidateRegionBlocks(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar * param_2, _CLS_LSN * param_3, ulong * param_4, ulong * param_5)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::ValidateRegionBlocks Called Diff


```diff
--- CClfsLogFcbPhysical::ValidateRegionBlocks called
+++ CClfsLogFcbPhysical::ValidateRegionBlocks called
@@ -14 +13,0 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::ValidateRegionBlocks Diff


```diff
--- CClfsLogFcbPhysical::ValidateRegionBlocks
+++ CClfsLogFcbPhysical::ValidateRegionBlocks
@@ -1,512 +1,447 @@
 
+/* WARNING: Type propagation algorithm not settling */
 /* private: long __cdecl CClfsLogFcbPhysical::ValidateRegionBlocks(struct _FILE_OBJECT *
    __ptr64,unsigned char * __ptr64 const,union _CLS_LSN & __ptr64,unsigned long & __ptr64,unsigned
    long & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::ValidateRegionBlocks
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,uchar *param_2,_CLS_LSN *param_3,
           ulong *param_4,ulong *param_5)
 
 {
   undefined8 uVar1;
   undefined8 uVar2;
   longlong lVar3;
   bool bVar4;
   uchar uVar5;
-  int iVar6;
-  long lVar7;
+  uint uVar6;
+  int iVar7;
   undefined8 *puVar8;
-  ulonglong uVar9;
-  _CLFS_LOG_BLOCK_HEADER *p_Var10;
-  _CLFS_LOG_BLOCK_HEADER *p_Var11;
-  _CLFS_LOG_BLOCK_HEADER *p_Var12;
-  _CLFS_LOG_BLOCK_HEADER *p_Var13;
-  _CLS_LSN *p_Var14;
-  __uint64 _Var15;
-  __uint64 _Var16;
-  _CLS_LSN *p_Var17;
-  uint uVar18;
-  ulong uVar19;
-  CClfsLogFcbPhysical *pCVar20;
+  _CLFS_LOG_BLOCK_HEADER *p_Var9;
+  _CLS_LSN *p_Var10;
+  __uint64 _Var11;
+  __uint64 _Var12;
+  _CLS_LSN *p_Var13;
+  _CLFS_LOG_BLOCK_HEADER *p_Var14;
+  ulonglong uVar15;
+  CClfsLogFcbPhysical *pCVar16;
   size_t _Size;
-  size_t sVar21;
-  uint uVar22;
-  undefined8 uVar23;
-  ulonglong uVar24;
-  _CLFS_LOG_BLOCK_HEADER *p_Var25;
+  ulong uVar17;
+  _CLFS_LOG_BLOCK_HEADER *p_Var18;
+  _CLFS_LOG_BLOCK_HEADER *p_Var19;
+  _CLFS_LOG_BLOCK_HEADER *p_Var20;
+  uint uVar21;
+  _CLFS_LOG_BLOCK_HEADER *p_Var22;
   _CLS_LSN *local_res20;
-  _CLS_LSN *in_stack_fffffffffffffe98;
-  _CLFS_LOG_BLOCK_HEADER *local_140;
-  _CLFS_LOG_BLOCK_HEADER local_138 [4];
-  uint local_134;
-  undefined8 local_130;
-  uint local_128;
-  char local_124;
-  char local_123;
-  ulonglong local_120;
-  uint local_118;
-  uint local_114;
-  undefined8 local_110;
-  _CLFS_LOG_BLOCK_HEADER *local_108;
+  _CLS_LSN *in_stack_fffffffffffffea8;
+  _CLFS_LOG_BLOCK_HEADER *local_130;
+  _CLFS_LOG_BLOCK_HEADER local_128 [4];
+  uint local_124;
+  char local_120;
+  char local_11f;
+  _CLFS_LOG_BLOCK_HEADER *local_118;
+  _CLFS_LOG_BLOCK_HEADER *local_110;
+  uint local_108;
+  uint local_104;
   uint local_100;
-  long local_fc;
   void *local_f8;
   undefined8 local_f0;
   undefined8 local_e8;
   void *local_e0;
-  _CLFS_LOG_BLOCK_HEADER *local_d8;
+  undefined8 local_d8;
   undefined8 local_d0;
-  undefined1 local_c8;
-  ulong local_c4;
-  int local_c0;
-  uint local_bc;
-  undefined8 local_b8;
-  ulonglong local_b0;
-  ulonglong local_a8;
-  _CLS_LSN *local_a0;
-  ulonglong local_98;
-  uint local_90;
-  _CLS_LSN local_88 [8];
-  ulonglong local_80;
-  undefined8 local_78;
-  _CLS_LSN local_70 [8];
+  undefined8 local_c8;
+  undefined1 local_c0;
+  ulong local_bc;
+  _CLFS_LOG_BLOCK_HEADER *local_b8;
+  int local_b0;
+  int local_ac;
+  uint local_a8;
+  uint local_a4;
+  __uint64 local_a0;
+  undefined8 local_98;
+  _CLS_LSN *local_90;
+  ulonglong local_88;
+  uint local_80;
+  _CLS_LSN local_78 [8];
+  undefined8 local_70;
   _CLS_LSN local_68 [8];
   _CLS_LSN local_60 [8];
   _CLS_LSN local_58 [8];
   _CLS_LSN local_50 [8];
   _CLS_LSN local_48 [8];
   _CLS_LSN local_40 [8];
   
-  local_b8 = *(undefined8 *)(this + 0x1e0);
+  local_98 = *(undefined8 *)(this + 0x1e0);
   uVar1 = *(undefined8 *)(this + 0x1e8);
   local_f0 = 0;
-  local_120 = 0;
+  p_Var14 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+  local_110 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
   local_f8 = (void *)0x0;
-  local_140 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+  local_130 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
   local_e0 = (void *)0x0;
-  local_fc = 0;
-  local_128 = 0;
-  local_114 = 0;
-  local_c4 = 0;
-  local_124 = '\0';
-  local_123 = '\x01';
-  local_108 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  local_d8 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-  local_d0 = *(undefined8 *)(param_2 + 0x18);
-  local_138[0] = *(_CLFS_LOG_BLOCK_HEADER *)(param_2 + 2);
+  local_104 = 0;
+  local_bc = 0;
+  local_120 = '\0';
+  local_11f = '\x01';
+  local_c8 = *(undefined8 *)(param_2 + 0x18);
+  local_128[0] = *(_CLFS_LOG_BLOCK_HEADER *)(param_2 + 2);
   *(undefined8 *)param_3 = 0xffffffff00000000;
   *param_4 = 0;
   *param_5 = 0;
-  p_Var14 = param_3;
+  p_Var10 = param_3;
   local_res20 = param_3;
-  local_78 = uVar1;
-  puVar8 = (undefined8 *)GetNextRegionLsn(this,(_CLS_LSN *)&local_98,(ulong)&local_d0);
+  local_70 = uVar1;
+  puVar8 = (undefined8 *)GetNextRegionLsn(this,(_CLS_LSN *)&local_88,(ulong)&local_c8);
   uVar2 = *puVar8;
   *(undefined8 *)param_3 = uVar2;
   *(undefined8 *)(this + 0x1e8) = uVar2;
-  pCVar20 = this + 0x558;
-  *(__uint64 *)pCVar20 = *(__uint64 *)param_3;
-  PurgeCacheSection(this,(_CLS_LSN *)&CLFS_LSN_NULL,(_CLS_LSN *)&CLFS_LSN_NULL,(uchar)p_Var14);
-  local_d0 = *(undefined8 *)(this + 0x58);
-  puVar8 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_98,(__uint64 *)pCVar20);
+  *(undefined8 *)(this + 0x558) = *(undefined8 *)param_3;
+  PurgeCacheSection(this,(_CLS_LSN *)&CLFS_LSN_NULL,(_CLS_LSN *)&CLFS_LSN_NULL,(uchar)p_Var10);
+  local_c8 = *(undefined8 *)(this + 0x58);
+  puVar8 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_88,(__uint64 *)(this + 0x558));
   *(undefined8 *)(this + 0x1e0) = *puVar8;
-  local_d0 = *(undefined8 *)(this + 0x50);
-  puVar8 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_98,(__uint64 *)pCVar20);
+  local_c8 = *(undefined8 *)(this + 0x50);
+  puVar8 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_88,(__uint64 *)(this + 0x558));
   uVar2 = *puVar8;
-  uVar22 = *(uint *)(param_2 + 0x2c);
-  uVar24 = 0;
-  while( true ) {
-    local_118 = (uint)uVar24;
-    lVar3 = uVar24 * 2;
-    local_d0 = uVar2;
-    if ((0x3f7 < local_118) || (param_2[lVar3 + 1 + (ulonglong)uVar22] == '\0')) break;
-    if ((param_2[lVar3 + (ulonglong)uVar22] == 0xff) &&
-       (param_2[lVar3 + 1 + (ulonglong)uVar22] == 0xff)) goto LAB_0;
-    uVar24 = (ulonglong)(local_118 + 1);
-  }
-  if ((local_118 == 0x3f8) || (param_2[lVar3 + 1 + (ulonglong)uVar22] != '\0')) {
+  uVar6 = *(uint *)(param_2 + 0x2c);
+  local_108 = 0;
+  while ((lVar3 = (ulonglong)local_108 * 2, local_c8 = uVar2, local_108 < 0x3f8 &&
+         (param_2[lVar3 + 1 + (ulonglong)uVar6] != '\0'))) {
+    if ((param_2[lVar3 + (ulonglong)uVar6] == 0xff) &&
+       (param_2[lVar3 + 1 + (ulonglong)uVar6] == 0xff)) goto LAB_0;
+    local_108 = local_108 + 1;
+  }
+  if ((local_108 == 0x3f8) || (param_2[lVar3 + 1 + (ulonglong)uVar6] != '\0')) {
 LAB_0:
-    local_140 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
-    lVar7 = -0x3fe5fffc;
+    uVar6 = 0xc01a0004;
+    local_130 = p_Var14;
   }
   else {
-    local_90 = (local_118 & 0xfffffe00) << 9;
-    local_c0 = local_118 - (local_118 & 0x7ffe00);
-    uVar24 = local_120;
-    p_Var11 = local_108;
-    p_Var12 = local_d8;
-    while( true ) {
-      local_a8 = CONCAT44(local_a8._4_4_,local_90);
-      if (0x7ffff < local_90) break;
-      local_134 = 0x80000 - local_90;
-      if (0x40000 < local_134) {
-        local_134 = 0x40000;
+    local_b0 = local_108 - (local_108 & 0x7ffe00);
+    p_Var19 = local_110;
+    p_Var22 = p_Var14;
+    for (local_a8 = (local_108 & 0xfffffe00) << 9; local_80 = local_a8, local_a8 < 0x80000;
+        local_a8 = local_a8 + local_124) {
+      uVar17 = 0x80000 - local_a8;
+      if (0x40000 < uVar17) {
+        uVar17 = 0x40000;
       }
+      local_124 = uVar17;
       puVar8 = (undefined8 *)AddLsnOffset(this,local_60,(ulong)local_res20);
-      local_e8 = *puVar8;
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-      if ((int)uVar9 == 0) {
-        local_98 = (ulonglong)p_Var10 & 0xfffffffffffc0000;
-        p_Var14 = local_50;
-      }
-      else {
-        local_108 = p_Var10;
-        if ((longlong)p_Var10 < 0) goto LAB_1;
-        local_80 = (ulonglong)(p_Var10 + ((uint)((longlong)p_Var10 >> 0x3f) & 0x3ffff)) &
-                   0xfffffffffffc0000;
-        p_Var14 = local_58;
-        p_Var11 = p_Var10;
-      }
-      puVar8 = (undefined8 *)AddLsnOffset(this,p_Var14,(__uint64 *)(this + 0x558));
-      uVar23 = *puVar8;
-      local_110 = uVar23;
-      if (local_124 != '\0') {
+      local_d0 = *puVar8;
+      local_a0 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+      if ((longlong)local_a0 < 0) goto LAB_1;
+      local_88 = local_a0 + ((uint)((longlong)local_a0 >> 0x3f) & 0x3ffff) & 0xfffffffffffc0000;
+      puVar8 = (undefined8 *)AddLsnOffset(this,local_58,(__uint64 *)(this + 0x558));
+      p_Var9 = (_CLFS_LOG_BLOCK_HEADER *)*puVar8;
+      local_e8 = p_Var9;
+      local_d8 = p_Var9;
+      if (local_120 != '\0') {
         CcUnpinData(local_e0);
         local_e0 = (void *)0x0;
       }
-      if ((local_d0._4_4_ < local_110._4_4_) ||
-         ((local_110._4_4_ == local_d0._4_4_ && ((uint)uVar2 <= (uint)uVar23)))) goto LAB_2;
-      local_fc = MapCacheData(this,param_1,(_CLS_LSN *)&local_110,local_134,
-                              (uchar)in_stack_fffffffffffffe98,&local_e0,&local_f8);
-      lVar7 = local_fc;
-      if (local_fc < 0) goto LAB_3;
-      local_124 = '\x01';
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar9 != 0) {
-        p_Var11 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-        local_108 = p_Var11;
-        p_Var12 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_110);
-        local_d8 = p_Var12;
-        if (((longlong)p_Var11 < 0) || ((longlong)p_Var12 < 0)) goto LAB_1;
-      }
-      uVar22 = local_c0 << 9;
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar9 == 0) {
-        _Var15 = LsnToCacheOffset(this,(_CLS_LSN *)&local_110);
-        _Var16 = LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-        p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)((uVar22 - _Var15) + _Var16);
-      }
-      else {
-        p_Var10 = p_Var11 + ((ulonglong)uVar22 - (longlong)p_Var12);
-      }
-      local_130 = p_Var10;
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if (((int)uVar9 != 0) && (local_130._4_4_ != 0)) goto LAB_1;
-      local_c0 = 0;
-      pCVar20 = this;
-      p_Var13 = GetOwnerPageInsideCachedBuffer(this,local_f8,local_134,uVar23);
-      sVar21 = (size_t)local_128;
-      local_d8 = p_Var13;
-      if (local_128 != 0) {
-        _Size = (size_t)local_134;
-        iVar6 = IsBlockBeyondBuffer(pCVar20,local_134,
-                                    (uint)(p_Var13 != (_CLFS_LOG_BLOCK_HEADER *)0x0),local_128);
-        if (iVar6 != 0) {
-          if (p_Var13 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-            if (local_114 < (int)_Size + (uint)local_120) goto LAB_4;
-            memcpy(local_140 + (local_120 & 0xffffffff),
-                   (void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),_Size);
-            uVar24 = uVar24 + _Size;
-            local_120._0_4_ = (uint)uVar24;
-            local_100 = (uint)*(ushort *)(local_140 + 4) * 0x200 - (uint)local_120;
+      if ((local_c8._4_4_ < local_d8._4_4_) ||
+         ((local_d8._4_4_ == local_c8._4_4_ && ((uint)uVar2 <= (uint)p_Var9)))) goto LAB_2;
+      uVar6 = MapCacheData(this,param_1,(_CLS_LSN *)&local_e8,uVar17,
+                           (uchar)in_stack_fffffffffffffea8,&local_e0,&local_f8);
+      p_Var14 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar6;
+      if ((int)uVar6 < 0) goto LAB_3;
+      local_120 = '\x01';
+      local_a0 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+      local_90 = (_CLS_LSN *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
+      if (((longlong)local_a0 < 0) || ((longlong)local_90 < 0)) goto LAB_1;
+      p_Var18 = (_CLFS_LOG_BLOCK_HEADER *)
+                (((ulonglong)(uint)(local_b0 << 9) - (longlong)local_90) + local_a0);
+      iVar7 = (int)((ulonglong)p_Var18 >> 0x20);
+      local_118 = p_Var18;
+      if (iVar7 != 0) goto LAB_1;
+      pCVar16 = this;
+      local_b0 = iVar7;
+      p_Var9 = GetOwnerPageInsideCachedBuffer(this,local_f8,local_124,p_Var9);
+      uVar17 = (ulong)p_Var22;
+      local_d8 = p_Var9;
+      if (uVar17 != 0) {
+        uVar15 = (ulonglong)local_124;
+        iVar7 = IsBlockBeyondBuffer(pCVar16,local_124,
+                                    (uint)(p_Var9 != (_CLFS_LOG_BLOCK_HEADER *)0x0),uVar17);
+        if (iVar7 != 0) {
+          if (p_Var9 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+            if (local_104 < (int)uVar15 + (uint)local_110) goto LAB_4;
           }
           else {
-            p_Var14 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_48,(ulong)&local_110);
-            uVar5 = operator!=(p_Var14,(_CLS_LSN *)(p_Var13 + 0x18));
+            p_Var10 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_50,(ulong)&local_e8);
+            uVar5 = operator!=(p_Var10,(_CLS_LSN *)(p_Var9 + 0x18));
             if ((uVar5 != '\0') || (uVar5 = ClfsIsOwnerPage((uchar *)local_d8), uVar5 == '\0'))
             goto LAB_2;
-            if (local_114 < (uint)local_120 + -0x1000 + local_134) goto LAB_4;
-            uVar22 = local_134 - 0x1000;
-            memcpy(local_140 + (local_120 & 0xffffffff),
-                   (void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),
-                   (ulonglong)uVar22);
-            uVar24 = uVar24 + uVar22;
-            local_120._0_4_ = (uint)uVar24;
-            local_100 = (uint)*(ushort *)(local_140 + 4) * 0x200 - (uint)local_120;
-          }
-          local_130 = (_CLFS_LOG_BLOCK_HEADER *)CONCAT44(local_130._4_4_,local_134);
-          p_Var10 = local_130;
-          uVar22 = local_134;
-          local_128 = local_100;
-          local_120 = uVar24;
+            if (local_104 < ((uint)local_110 - 0x1000) + local_124) goto LAB_4;
+            uVar15 = (ulonglong)(local_124 - 0x1000);
+          }
+          memcpy(local_130 + (uint)local_110,
+                 (void *)(((ulonglong)local_118 & 0xffffffff) + (longlong)local_f8),uVar15);
+          p_Var19 = p_Var19 + uVar15;
+          local_110._0_4_ = (uint)p_Var19;
+          local_100 = (uint)*(ushort *)(local_130 + 4) * 0x200 - (uint)local_110;
+          p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_100;
+          local_118 = (_CLFS_LOG_BLOCK_HEADER *)CONCAT44(local_118._4_4_,local_124);
+          p_Var18 = local_118;
+          uVar6 = local_124;
+          local_110 = p_Var19;
           goto LAB_5;
         }
-        if (local_114 < (int)sVar21 + (uint)local_120) goto LAB_4;
-        memcpy(local_140 + (local_120 & 0xffffffff),
-               (void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),sVar21);
-        in_stack_fffffffffffffe98 = (_CLS_LSN *)&local_b8;
-        p_Var13 = local_138;
-        uVar5 = IsEof(this,local_140,(uchar *)p_Var13,(_CLS_LSN *)(this + 0x560),
-                      in_stack_fffffffffffffe98,(_CLS_LSN *)&local_f0,&local_c4);
-        if (uVar5 != '\0') goto LAB_2;
-        p_Var25 = local_140;
-        uVar5 = ClfsVerifyBlockOwnerEntry(param_2,local_118,(ulong)p_Var13,local_140);
+        if (local_104 < (uint)local_110 + uVar17) goto LAB_4;
+        memcpy(local_130 + ((ulonglong)local_110 & 0xffffffff),
+               (void *)(((ulonglong)local_118 & 0xffffffff) + (longlong)local_f8),(size_t)p_Var22);
+        in_stack_fffffffffffffea8 = (_CLS_LSN *)&local_98;
+        p_Var19 = local_128;
+        uVar5 = IsEof(this,local_130,(uchar *)p_Var19,(_CLS_LSN *)(this + 0x560),
+                      in_stack_fffffffffffffea8,(_CLS_LSN *)&local_f0,&local_bc);
+        if (uVar5 != '\0') {
+          uVar6 = 0xc0000011;
+          goto LAB_3;
+        }
+        uVar5 = ClfsVerifyBlockOwnerEntry(param_2,local_108,(ulong)p_Var19,local_130);
         if (uVar5 == '\0') {
-          local_fc = -0x3fe5fff6;
-        }
-        *param_5 = (uint)*(ushort *)(p_Var25 + 4);
-        *param_4 = local_118;
-        local_118 = local_118 + *param_5;
-        p_Var10 = p_Var10 + sVar21;
-        uVar24 = 0;
-        local_120 = 0;
-        local_128 = 0;
+          p_Var14 = (_CLFS_LOG_BLOCK_HEADER *)0xc01a000a;
+        }
+        *param_5 = (uint)*(ushort *)(local_130 + 4);
+        *param_4 = local_108;
+        local_108 = local_108 + *param_5;
+        local_118 = p_Var18 + (longlong)p_Var22;
+        p_Var19 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+        local_110 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+        p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
         local_100 = 0;
-        local_130 = p_Var10;
+        p_Var18 = local_118;
       }
       while( true ) {
-        uVar22 = (uint)local_130;
+        uVar6 = (uint)local_118;
 LAB_5:
-        if (local_134 <= uVar22) break;
-        local_108 = (_CLFS_LOG_BLOCK_HEADER *)((ulonglong)uVar22 + (longlong)local_f8);
-        if (local_123 != '\0') {
-          local_138[0] = local_108[2];
-          local_123 = '\0';
-          local_c8 = 0;
-        }
-        lVar7 = ClfsValidateSector((uchar *)local_108,(uchar)local_108[2],'@');
-        if (lVar7 < 0) goto LAB_3;
-        p_Var14 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_40,(ulong)&local_110);
-        _Var15 = LsnToCacheOffset(this,p_Var14);
-        local_a0 = (_CLS_LSN *)(local_108 + 0x18);
-        local_b0 = CONCAT44(local_b0._4_4_,(uint)*(ushort *)(local_108 + 4) << 9);
-        _Var16 = LsnToCacheOffset(this,local_a0);
-        p_Var13 = local_108;
-        if (_Var15 == _Var16) {
-          if (local_134 < (uint)local_130 + (int)local_b0) {
+        if (local_124 <= uVar6) break;
+        local_b8 = (_CLFS_LOG_BLOCK_HEADER *)((ulonglong)uVar6 + (longlong)local_f8);
+        if (local_11f != '\0') {
+          local_128[0] = local_b8[2];
+          local_11f = '\0';
+          local_c0 = 0;
+        }
+        uVar6 = ClfsValidateSector((uchar *)local_b8,(uchar)local_b8[2],'@');
+        if ((int)uVar6 < 0) goto LAB_3;
+        p_Var10 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_48,(ulong)&local_e8);
+        _Var11 = LsnToCacheOffset(this,p_Var10);
+        local_90 = (_CLS_LSN *)(local_b8 + 0x18);
+        local_ac = (uint)*(ushort *)(local_b8 + 4) << 9;
+        _Var12 = LsnToCacheOffset(this,local_90);
+        p_Var9 = local_b8;
+        if (_Var11 == _Var12) {
+          if (local_124 < (uint)local_118 + local_ac) {
 LAB_6:
-            lVar7 = -0x3fe5fff6;
+            uVar6 = 0xc01a000a;
             goto LAB_3;
           }
-          uVar5 = ClfsIsOwnerPage((uchar *)local_108);
+          uVar5 = ClfsIsOwnerPage((uchar *)local_b8);
           if (uVar5 == '\0') goto LAB_2;
-          p_Var10 = p_Var10 + (ulonglong)*(ushort *)(p_Var13 + 4) * 0x200;
-          local_130 = p_Var10;
-        }
-        else if (local_134 < (int)local_b0 + (uint)local_130) {
+          local_118 = p_Var18 + (ulonglong)*(ushort *)(p_Var9 + 4) * 0x200;
+          p_Var18 = local_118;
+        }
+        else if (local_124 < local_ac + (uint)local_118) {
 LAB_7:
-          p_Var13 = local_108;
-          uVar22 = local_134 - (uint)local_130;
+          p_Var22 = local_b8;
+          uVar6 = local_124 - (uint)local_118;
           if (local_d8 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-            uVar22 = uVar22 - 0x1000;
-          }
-          uVar24 = (ulonglong)uVar22;
-          uVar18 = (uint)local_130;
-          local_120 = uVar24;
-          if (local_114 < (uint)*(ushort *)(local_108 + 4) << 9) {
-            if ((uint)*(ushort *)(local_108 + 4) << 9 < uVar22) goto LAB_6;
-            if (local_140 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-              ExFreePoolWithTag(local_140,0);
+            uVar6 = uVar6 - 0x1000;
+          }
+          p_Var19 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar6;
+          uVar21 = (uint)local_118;
+          local_110 = p_Var19;
+          if (local_104 < (uint)*(ushort *)(local_b8 + 4) << 9) {
+            if ((uint)*(ushort *)(local_b8 + 4) << 9 < uVar6) goto LAB_6;
+            if (local_130 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+              ExFreePoolWithTag(local_130,0);
             }
-            local_114 = (uint)*(ushort *)(p_Var13 + 4) << 9;
-            local_bc = local_114;
-            local_140 = (_CLFS_LOG_BLOCK_HEADER *)ExAllocatePoolWithTag(1,local_114,0x73666c43);
-            if (local_140 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-              lVar7 = -0x3fffff66;
+            local_104 = (uint)*(ushort *)(p_Var22 + 4) << 9;
+            local_a4 = local_104;
+            local_130 = (_CLFS_LOG_BLOCK_HEADER *)ExAllocatePoolWithTag(1,local_104,0x73666c43);
+            if (local_130 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+              uVar6 = 0xc000009a;
               goto LAB_3;
             }
-            uVar18 = (uint)local_130;
-          }
-          if (local_114 < (uint)local_120) goto LAB_4;
-          uVar9 = local_120 & 0xffffffff;
-          memcpy(local_140,(void *)((ulonglong)uVar18 + (longlong)local_f8),local_120 & 0xffffffff);
+            uVar21 = (uint)local_118;
+          }
+          if (local_104 < (uint)local_110) goto LAB_4;
+          uVar15 = (ulonglong)local_110 & 0xffffffff;
+          memcpy(local_130,(void *)((ulonglong)uVar21 + (longlong)local_f8),
+                 (ulonglong)local_110 & 0xffffffff);
           if (local_d8 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-            p_Var10 = p_Var10 + uVar9;
+            local_118 = p_Var18 + uVar15;
           }
           else {
-            p_Var14 = (_CLS_LSN *)(local_d8 + 0x18);
-            p_Var17 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_88,(ulong)&local_110);
-            uVar5 = operator!=(p_Var17,p_Var14);
+            p_Var10 = (_CLS_LSN *)(local_d8 + 0x18);
+            p_Var13 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_78,(ulong)&local_e8);
+            uVar5 = operator!=(p_Var13,p_Var10);
             if ((uVar5 != '\0') || (uVar5 = ClfsIsOwnerPage((uchar *)local_d8), uVar5 == '\0'))
             goto LAB_2;
-            p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_134;
-          }
-          local_128 = (uint)*(ushort *)(local_108 + 4) * 0x200 - (uint)local_120;
-          local_130 = p_Var10;
-          local_100 = local_128;
+            local_118 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_124;
+          }
+          local_100 = (uint)*(ushort *)(p_Var22 + 4) * 0x200 - (uint)local_110;
+          p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_100;
+          p_Var18 = local_118;
         }
         else {
-          p_Var14 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_70,(ulong)local_a0);
-          p_Var17 = (_CLS_LSN *)AddLsnOffset(this,local_68,(ulong)local_a0);
-          uVar5 = operator<=(p_Var17,p_Var14);
+          p_Var10 = (_CLS_LSN *)GetNextOwnerPageLsn(this,local_40,(ulong)local_90);
+          p_Var13 = (_CLS_LSN *)AddLsnOffset(this,local_68,(ulong)local_90);
+          uVar5 = operator<=(p_Var13,p_Var10);
           if (uVar5 == '\0') {
             goto LAB_7;
           }
-          in_stack_fffffffffffffe98 = (_CLS_LSN *)&local_b8;
-          p_Var13 = local_138;
-          uVar5 = IsEof(this,local_108,(uchar *)p_Var13,(_CLS_LSN *)(this + 0x560),
-                        in_stack_fffffffffffffe98,(_CLS_LSN *)&local_f0,&local_c4);
+          in_stack_fffffffffffffea8 = (_CLS_LSN *)&local_98;
+          p_Var9 = local_128;
+          uVar5 = IsEof(this,local_b8,(uchar *)p_Var9,(_CLS_LSN *)(this + 0x560),
+                        in_stack_fffffffffffffea8,(_CLS_LSN *)&local_f0,&local_bc);
           if (uVar5 != '\0') goto LAB_2;
-          p_Var25 = local_108;
-          uVar5 = ClfsVerifyBlockOwnerEntry(param_2,local_118,(ulong)p_Var13,local_108);
+          p_Var20 = local_b8;
+          uVar5 = ClfsVerifyBlockOwnerEntry(param_2,local_108,(ulong)p_Var9,local_b8);
           if (uVar5 == '\0') goto LAB_6;
-          *param_5 = (uint)*(ushort *)(p_Var25 + 4);
-          *param_4 = local_118;
-          local_118 = local_118 + *param_5;
-          p_Var10 = p_Var10 + (*param_5 << 9);
-          local_130 = p_Var10;
+          *param_5 = (uint)*(ushort *)(p_Var20 + 4);
+          *param_4 = local_108;
+          local_108 = local_108 + *param_5;
+          local_118 = p_Var18 + (*param_5 << 9);
+          p_Var18 = local_118;
         }
       }
-      local_90 = (int)local_a8 + local_134;
     }
-    CcUnpinData(local_e0);
+    CcUnpinData();
     local_e0 = (void *)0x0;
     bVar4 = false;
     puVar8 = (undefined8 *)AddLsnOffset(this,(_CLS_LSN *)&local_res20,(ulong)local_res20);
-    local_e8 = *puVar8;
-    uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-    p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-    if ((int)uVar9 == 0) {
-      local_a0 = (_CLS_LSN *)((ulonglong)p_Var10 & 0xfffffffffffc0000);
-      p_Var14 = (_CLS_LSN *)&local_res20;
+    local_d0 = *puVar8;
+    local_a0 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+    if ((longlong)local_a0 < 0) {
+LAB_1:
+      uVar6 = 0xc01a000d;
     }
     else {
-      local_108 = p_Var10;
-      if ((longlong)p_Var10 < 0) {
-LAB_1:
-        lVar7 = -0x3fe5fff3;
-        goto LAB_3;
-      }
       local_res20 = (_CLS_LSN *)
-                    ((ulonglong)(p_Var10 + ((uint)((longlong)p_Var10 >> 0x3f) & 0x3ffff)) &
-                    0xfffffffffffc0000);
-      p_Var14 = local_88;
-      p_Var11 = p_Var10;
-    }
-    puVar8 = (undefined8 *)AddLsnOffset(this,p_Var14,(__uint64 *)(this + 0x558));
-    uVar23 = *puVar8;
-    local_110 = uVar23;
-    while (lVar7 = local_fc, local_128 != 0) {
-      uVar19 = local_128;
-      if (0x40000 < local_128) {
-        uVar19 = 0x40000;
-      }
-      local_res20 = (_CLS_LSN *)CONCAT44(local_res20._4_4_,uVar19);
-      if (bVar4) {
-        CcUnpinData(local_e0);
-        local_e0 = (void *)0x0;
-        uVar19 = (ulong)local_res20;
-      }
-      if ((local_d0._4_4_ < local_110._4_4_) ||
-         ((local_110._4_4_ == local_d0._4_4_ && ((uint)uVar2 <= (uint)uVar23)))) goto LAB_2;
-      local_fc = MapCacheData(this,param_1,(_CLS_LSN *)&local_110,uVar19,
-                              (uchar)in_stack_fffffffffffffe98,&local_e0,&local_f8);
-      lVar7 = local_fc;
-      if (local_fc < 0) break;
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar9 != 0) {
-        p_Var11 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-        local_108 = p_Var11;
-        p_Var12 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_110);
-        local_d8 = p_Var12;
-        if (((longlong)p_Var11 < 0) || ((longlong)p_Var12 < 0)) goto LAB_1;
-      }
-      bVar4 = true;
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if ((int)uVar9 == 0) {
-        _Var15 = LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-        _Var16 = LsnToCacheOffset(this,(_CLS_LSN *)&local_110);
-        local_130 = (_CLFS_LOG_BLOCK_HEADER *)(_Var15 - _Var16);
-      }
-      else {
-        local_130 = p_Var11 + -(longlong)p_Var12;
-      }
-      uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-      if (((int)uVar9 != 0) && (local_130._4_4_ != 0)) goto LAB_1;
-      pCVar20 = this;
-      p_Var10 = GetOwnerPageInsideCachedBuffer
-                          (this,local_f8,(ulonglong)local_res20 & 0xffffffff,uVar23);
-      sVar21 = (ulonglong)local_res20 & 0xffffffff;
-      uVar22 = local_128;
-      iVar6 = IsBlockBeyondBuffer(pCVar20,(ulong)local_res20,
-                                  (uint)(p_Var10 != (_CLFS_LOG_BLOCK_HEADER *)0x0),local_128);
-      uVar9 = local_120 & 0xffffffff;
-      if (iVar6 == 0) {
-        if (local_114 < uVar22 + (uint)local_120) goto LAB_4;
-        memcpy(local_140 + uVar9,(void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),
-               (ulonglong)uVar22);
-        uVar24 = uVar24 + uVar22;
-        local_128 = 0;
-        local_100 = 0;
-        in_stack_fffffffffffffe98 = (_CLS_LSN *)&local_b8;
-        local_120 = uVar24;
-        uVar5 = IsEof(this,local_140,(uchar *)local_138,(_CLS_LSN *)(this + 0x560),
-                      in_stack_fffffffffffffe98,(_CLS_LSN *)&local_f0,&local_c4);
-        if (uVar5 != '\0') goto LAB_2;
-        *param_5 = (uint)*(ushort *)(local_140 + 4);
-        *param_4 = local_118;
-        local_118 = local_118 + *param_5;
-      }
-      else {
-        iVar6 = (int)sVar21;
-        if (p_Var10 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-          if (local_114 < iVar6 + (uint)local_120) goto LAB_4;
-          memcpy(local_140 + uVar9,
-                 (void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),sVar21);
-          local_100 = local_128 - (ulong)local_res20;
+                    (local_a0 + ((uint)((longlong)local_a0 >> 0x3f) & 0x3ffff) & 0xfffffffffffc0000)
+      ;
+      puVar8 = (undefined8 *)AddLsnOffset(this,local_78,(__uint64 *)(this + 0x558));
+      p_Var9 = (_CLFS_LOG_BLOCK_HEADER *)*puVar8;
+      local_e8 = p_Var9;
+      while( true ) {
+        uVar6 = (uint)p_Var14;
+        uVar21 = (uint)p_Var22;
+        if (uVar21 == 0) break;
+        uVar17 = uVar21;
+        if (0x40000 < uVar21) {
+          uVar17 = 0x40000;
+        }
+        local_res20 = (_CLS_LSN *)CONCAT44(local_res20._4_4_,uVar17);
+        if (bVar4) {
+          CcUnpinData(local_e0);
+          local_e0 = (void *)0x0;
+          uVar17 = (ulong)local_res20;
+        }
+        if ((local_c8._4_4_ < local_e8._4_4_) ||
+           ((local_e8._4_4_ == local_c8._4_4_ && ((uint)uVar2 <= (uint)p_Var9))))
+        goto LAB_2;
+        uVar6 = MapCacheData(this,param_1,(_CLS_LSN *)&local_e8,uVar17,
+                             (uchar)in_stack_fffffffffffffea8,&local_e0,&local_f8);
+        p_Var14 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)uVar6;
+        if ((int)uVar6 < 0) break;
+        _Var11 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+        local_a0 = _Var11;
+        local_90 = (_CLS_LSN *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
+        if (((longlong)_Var11 < 0) || ((longlong)local_90 < 0)) goto LAB_1;
+        bVar4 = true;
+        local_118 = (_CLFS_LOG_BLOCK_HEADER *)(_Var11 - (longlong)local_90);
+        if ((int)((ulonglong)local_118 >> 0x20) != 0) goto LAB_1;
+        pCVar16 = this;
+        p_Var18 = GetOwnerPageInsideCachedBuffer
+                            (this,local_f8,(ulonglong)local_res20 & 0xffffffff,p_Var9);
+        _Size = (ulonglong)local_res20 & 0xffffffff;
+        iVar7 = IsBlockBeyondBuffer(pCVar16,(ulong)local_res20,
+                                    (uint)(p_Var18 != (_CLFS_LOG_BLOCK_HEADER *)0x0),uVar21);
+        uVar15 = (ulonglong)local_110 & 0xffffffff;
+        if (iVar7 == 0) {
+          if (local_104 < (uint)local_110 + uVar21) goto LAB_4;
+          memcpy(local_130 + uVar15,
+                 (void *)(((ulonglong)local_118 & 0xffffffff) + (longlong)local_f8),(size_t)p_Var22)
+          ;
+          p_Var19 = p_Var19 + (longlong)p_Var22;
+          p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)0x0;
+          local_100 = 0;
+          in_stack_fffffffffffffea8 = (_CLS_LSN *)&local_98;
+          local_110 = p_Var19;
+          uVar5 = IsEof(this,local_130,(uchar *)local_128,(_CLS_LSN *)(this + 0x560),
+                        in_stack_fffffffffffffea8,(_CLS_LSN *)&local_f0,&local_bc);
+          if (uVar5 != '\0') goto LAB_2;
+          *param_5 = (uint)*(ushort *)(local_130 + 4);
+          *param_4 = local_108;
+          local_108 = local_108 + *param_5;
         }
         else {
-          if (local_114 < (uint)local_120 + -0x1000 + iVar6) goto LAB_4;
-          sVar21 = (size_t)(iVar6 - 0x1000U);
-          memcpy(local_140 + uVar9,
-                 (void *)(((ulonglong)local_130 & 0xffffffff) + (longlong)local_f8),
-                 (ulonglong)(iVar6 - 0x1000U));
-          local_100 = local_128 + (0x1000 - (ulong)local_res20);
-        }
-        uVar24 = uVar24 + sVar21;
-        local_128 = local_100;
-        local_120 = uVar24;
-        puVar8 = (undefined8 *)AddLsnOffset(this,local_88,(ulong)&local_e8);
-        local_e8 = *puVar8;
-        uVar9 = Feature_2458037564__private_IsEnabledDeviceUsage();
-        p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)LsnToCacheOffset(this,(_CLS_LSN *)&local_e8);
-        if ((int)uVar9 == 0) {
-          local_b0 = (ulonglong)p_Var10 & 0xfffffffffffc0000;
-          p_Var14 = local_70;
-        }
-        else {
-          local_108 = p_Var10;
-          if ((longlong)p_Var10 < 0) goto LAB_1;
-          local_a8 = (ulonglong)(p_Var10 + ((uint)((longlong)p_Var10 >> 0x3f) & 0x3ffff)) &
-                     0xfffffffffffc0000;
-          p_Var14 = local_68;
-          p_Var11 = p_Var10;
-        }
-        puVar8 = (undefined8 *)AddLsnOffset(this,p_Var14,(__uint64 *)(this + 0x558));
-        uVar23 = *puVar8;
-        local_110 = uVar23;
+          iVar7 = (int)_Size;
+          if (p_Var18 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+            if (local_104 < iVar7 + (uint)local_110) goto LAB_4;
+            memcpy(local_130 + uVar15,
+                   (void *)(((ulonglong)local_118 & 0xffffffff) + (longlong)local_f8),_Size);
+            iVar7 = -(ulong)local_res20;
+          }
+          else {
+            if (local_104 < (uint)local_110 + -0x1000 + iVar7) goto LAB_4;
+            _Size = (size_t)(iVar7 - 0x1000U);
+            memcpy(local_130 + uVar15,
+                   (void *)(((ulonglong)local_118 & 0xffffffff) + (longlong)local_f8),
+                   (ulonglong)(iVar7 - 0x1000U));
+            iVar7 = 0x1000 - (ulong)local_res20;
+          }
+          p_Var19 = p_Var19 + _Size;
+          local_100 = uVar21 + iVar7;
+          p_Var22 = (_CLFS_LOG_BLOCK_HEADER *)(ulonglong)local_100;
+          local_110 = p_Var19;
+          puVar8 = (undefined8 *)AddLsnOffset(this,local_78,(ulong)&local_d0);
+          local_d0 = *puVar8;
+          local_a0 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+          if ((longlong)local_a0 < 0) goto LAB_1;
+          local_d8 = (_CLFS_LOG_BLOCK_HEADER *)
+                     (local_a0 + ((uint)((longlong)local_a0 >> 0x3f) & 0x3ffff) & 0xfffffffffffc0000
+                     );
+          puVar8 = (undefined8 *)AddLsnOffset(this,local_68,(__uint64 *)(this + 0x558));
+          p_Var9 = (_CLFS_LOG_BLOCK_HEADER *)*puVar8;
+          local_e8 = p_Var9;
+        }
       }
     }
   }
 LAB_3:
-  bVar4 = true;
   if (local_e0 != (void *)0x0) {
     CcUnpinData();
   }
   *(undefined8 *)(this + 0x1e8) = uVar1;
-  *(undefined8 *)(this + 0x1e0) = local_b8;
-  pCVar20 = this + 0x1f8;
-  if (pCVar20 == (CClfsLogFcbPhysical *)0x0) {
+  *(undefined8 *)(this + 0x1e0) = local_98;
+  pCVar16 = this + 0x1f8;
+  if (pCVar16 == (CClfsLogFcbPhysical *)0x0) {
     bVar4 = false;
   }
-  else if ((local_f0._4_4_ < *(uint *)(this + 0x1fc)) ||
-          ((local_f0._4_4_ == *(uint *)(this + 0x1fc) && ((uint)local_f0 <= *(uint *)pCVar20))))
-  goto LAB_8;
+  else {
+    if ((local_f0._4_4_ < *(uint *)(this + 0x1fc)) ||
+       ((local_f0._4_4_ == *(uint *)(this + 0x1fc) && ((uint)local_f0 <= *(uint *)pCVar16))))
+    goto LAB_8;
+    bVar4 = true;
+  }
   if (bVar4) {
-    *(undefined8 *)pCVar20 = local_f0;
+    *(undefined8 *)pCVar16 = local_f0;
   }
 LAB_8:
-  if (local_140 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-    ExFreePoolWithTag(local_140,0);
-  }
-  return lVar7;
+  if (local_130 != (_CLFS_LOG_BLOCK_HEADER *)0x0) {
+    ExFreePoolWithTag(local_130,0);
+  }
+  return uVar6;
 LAB_4:
-  lVar7 = -0x7ffffffb;
+  uVar6 = 0x80000005;
   goto LAB_3;
 LAB_2:
-  lVar7 = -0x3fffffef;
+  uVar6 = 0xc0000011;
   goto LAB_3;
 }
 

```


## CClfsLogFcbPhysical::ToggleEphemeral

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.6|
|i_ratio|0.65|
|m_ratio|0.87|
|b_ratio|0.83|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ToggleEphemeral|ToggleEphemeral|
|fullname|CClfsLogFcbPhysical::ToggleEphemeral|CClfsLogFcbPhysical::ToggleEphemeral|
|refcount|2|2|
|`length`|259|326|
|`called`|CClfsLogFcbCommon::NotifyObservers<br>CClfsLogFcbCommon::Unlock<br>CClfsLogFcbPhysical::WrapContainers<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>_guard_dispatch_icall|CClfsLogFcbCommon::NotifyObservers<br>CClfsLogFcbCommon::Unlock<br>CClfsLogFcbPhysical::WrapContainers<br>Feature_110180665__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>_guard_dispatch_icall|
|calling|CClfsLogFcbPhysical::SetLogFileInfo|CClfsLogFcbPhysical::SetLogFileInfo|
|paramcount|3|3|
|`address`|1c0048988|1c0048838|
|sig|long __thiscall ToggleEphemeral(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar * param_2)|long __thiscall ToggleEphemeral(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, uchar * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::ToggleEphemeral Called Diff


```diff
--- CClfsLogFcbPhysical::ToggleEphemeral called
+++ CClfsLogFcbPhysical::ToggleEphemeral called
@@ -3,0 +4 @@
+Feature_110180665__private_IsEnabledDeviceUsage
```


### CClfsLogFcbPhysical::ToggleEphemeral Diff


```diff
--- CClfsLogFcbPhysical::ToggleEphemeral
+++ CClfsLogFcbPhysical::ToggleEphemeral
@@ -1,44 +1,59 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsLogFcbPhysical::ToggleEphemeral(struct _FILE_OBJECT * __ptr64,unsigned
    char & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::ToggleEphemeral(CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,uchar *param_2)
 
 {
   ushort uVar1;
   char cVar2;
-  long lVar3;
-  void *pvVar4;
+  int iVar3;
+  ulonglong uVar4;
+  void *pvVar5;
   undefined8 in_R9;
   
-  lVar3 = 0;
+  iVar3 = 0;
   *param_2 = '\0';
   cVar2 = ExAcquireResourceExclusiveLite((_ERESOURCE *)(this + 200),1,param_2,in_R9,0);
   uVar1 = *(ushort *)(this + 0x178);
   if ((uVar1 & 0x20) == 0) {
     *(ushort *)(this + 0x178) = uVar1 | 0x20;
     *(undefined8 *)(this + 0x1f0) = *(undefined8 *)(this + 0x1e8);
-    (**(code **)(*(longlong *)this + 0x70))(this);
-    pvVar4 = (void *)0x1;
+    uVar4 = Feature_110180665__private_IsEnabledDeviceUsage();
+    if ((int)uVar4 == 0) {
+      (**(code **)(*(longlong *)this + 0x70))(this);
+    }
+    else {
+      iVar3 = (**(code **)(*(longlong *)this + 0x70))(this);
+      if (iVar3 < 0) goto LAB_0;
+    }
+    pvVar5 = (void *)0x1;
   }
   else {
     if (0 < *(int *)(this + 0x52c)) {
-      lVar3 = -0x3fe5ffdf;
+      iVar3 = -0x3fe5ffdf;
       goto LAB_0;
     }
     *(ushort *)(this + 0x178) = uVar1 & 0xffdf;
-    (**(code **)(*(longlong *)this + 0x70))(this);
+    uVar4 = Feature_110180665__private_IsEnabledDeviceUsage();
+    if ((int)uVar4 == 0) {
+      (**(code **)(*(longlong *)this + 0x70))(this);
+    }
+    else {
+      iVar3 = (**(code **)(*(longlong *)this + 0x70))(this);
+      if (iVar3 < 0) goto LAB_0;
+    }
     WrapContainers(this,param_1);
     *param_2 = '\x01';
-    pvVar4 = (void *)0x2;
+    pvVar5 = (void *)0x2;
   }
-  CClfsLogFcbCommon::NotifyObservers((CClfsLogFcbCommon *)this,0xcf04,pvVar4,(void *)0x0);
+  CClfsLogFcbCommon::NotifyObservers((CClfsLogFcbCommon *)this,0xcf04,pvVar5,(void *)0x0);
 LAB_0:
   if (cVar2 != '\0') {
     CClfsLogFcbCommon::Unlock((_ERESOURCE *)(this + 200));
   }
-  return lVar3;
+  return iVar3;
 }
 

```


## `CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.73|
|i_ratio|0.53|
|m_ratio|1.0|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|fin$0|fin$0|
|fullname|`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0|`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0|
|refcount|1|1|
|`length`|230|226|
|called|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeSetEvent|CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeSetEvent|
|calling|||
|paramcount|2|2|
|`address`|1c007b07a|1c007ac2d|
|sig|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### `CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0 Diff


```diff
--- `CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0
+++ `CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0
@@ -1,48 +1,47 @@
 
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void `CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin_0(undefined8 param_1,longlong param_2)
 
 {
   longlong lVar1;
   _CLFS_METADATA_BLOCK_TYPE _Var2;
   
-  _Var2 = *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0xb8);
-  *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 200) = _Var2;
-  if (_Var2 < *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0x40)) {
+  _Var2 = *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 200);
+  *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0xd8) = _Var2;
+  if (_Var2 < *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0x38)) {
     do {
-      CClfsBaseFile::ReleaseMetadataBlock(*(CClfsBaseFile **)(param_2 + 0xb0),_Var2);
+      CClfsBaseFile::ReleaseMetadataBlock(*(CClfsBaseFile **)(param_2 + 0xc0),_Var2);
       _Var2 = _Var2 + 2;
-    } while (_Var2 < *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0x40));
-    *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 200) = _Var2;
+    } while (_Var2 < *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0x38));
+    *(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0xd8) = _Var2;
   }
   if (*(int *)(param_2 + 0x34) < 0) {
     if (*(char *)(param_2 + 0x31) == '\0') goto LAB_0;
     *(undefined4 *)(param_2 + 0x34) = 0xc01a002b;
     if (DAT_1 == 0) {
       DAT_1 = 1;
       _DAT_2 = 0xc01a002b;
     }
   }
-  else if (*(longlong *)(param_2 + 0x68) != 0) {
+  else if (*(longlong *)(param_2 + 0x70) != 0) {
     ExFreePoolWithTag();
   }
   if (*(char *)(param_2 + 0x31) != '\0') {
-    lVar1 = *(longlong *)(param_2 + 0xb0);
+    lVar1 = *(longlong *)(param_2 + 0xc0);
     LOCK();
     *(undefined4 *)(lVar1 + 400) = 0;
     UNLOCK();
     KeSetEvent(*(undefined8 *)(lVar1 + 0xa8),0,0);
   }
 LAB_0:
-  if (*(longlong *)(param_2 + 0x38) != 0) {
-    CClfsBaseFile::ReleaseMetadataBlock(*(CClfsBaseFile **)(param_2 + 0xb0),0);
-    *(undefined8 *)(param_2 + 0x38) = 0;
+  if (*(longlong *)(param_2 + 0x40) != 0) {
+    CClfsBaseFile::ReleaseMetadataBlock(*(CClfsBaseFile **)(param_2 + 0xc0),0);
   }
   if (*(char *)(param_2 + 0x30) != '\0') {
-    CClfsBaseFile::UnlockImage(*(CClfsBaseFile **)(param_2 + 0xb0));
+    CClfsBaseFile::UnlockImage(*(CClfsBaseFile **)(param_2 + 0xc0));
     *(undefined1 *)(param_2 + 0x30) = 0;
   }
   return;
 }
 

```


## `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.38|
|i_ratio|0.41|
|m_ratio|0.76|
|b_ratio|0.76|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|fin$0|fin$0|
|fullname|`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0|`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0|
|refcount|1|1|
|`length`|202|390|
|`called`|CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>ClfsDecodeBlock<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ReleaseMetadataBlock<br>ClfsDecodeBlock<br>Feature_110180665__private_IsEnabledDeviceUsage<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>WPP_SF_sl<br>_local_unwind|
|calling|||
|paramcount|2|2|
|`address`|1c0077e70|1c0079460|
|sig|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|undefined __fastcall fin$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0 Called Diff


```diff
--- `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0 called
+++ `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0 called
@@ -2,0 +3 @@
+CClfsBaseFile::ReleaseMetadataBlock
@@ -3,0 +5 @@
+Feature_110180665__private_IsEnabledDeviceUsage
@@ -4,0 +7,2 @@
+WPP_SF_sl
+_local_unwind
```


### `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0 Diff


```diff
--- `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0
+++ `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0
@@ -1,43 +1,64 @@
 
 void `CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin_0(undefined8 param_1,longlong param_2)
 
 {
   _CLFS_LOG_BLOCK_HEADER *p_Var1;
   long lVar2;
-  ulong uVar3;
-  CClfsBaseFile *pCVar4;
-  CClfsBaseFile *this;
+  ulonglong uVar3;
+  ulong uVar4;
+  CClfsBaseFile *pCVar5;
+  CClfsBaseFile *pCVar6;
   
   if (*(char *)(param_2 + 0x30) == '\0') {
-    this = *(CClfsBaseFile **)(param_2 + 0x90);
+    pCVar5 = *(CClfsBaseFile **)(param_2 + 0xb0);
   }
   else {
     if (*(char *)(param_2 + 0x31) != '\0') {
-      p_Var1 = *(_CLFS_LOG_BLOCK_HEADER **)(param_2 + 0x50);
-      ClfsDecodeBlock(p_Var1,(uint)*(ushort *)(p_Var1 + 4),(uchar)p_Var1[2],'\x10',
-                      (ulong *)(param_2 + 0x48));
+      p_Var1 = *(_CLFS_LOG_BLOCK_HEADER **)(param_2 + 0x58);
+      lVar2 = ClfsDecodeBlock(p_Var1,(uint)*(ushort *)(p_Var1 + 4),(uchar)p_Var1[2],'\x10',
+                              (ulong *)(param_2 + 0x38));
+      *(long *)(param_2 + 0x38) = lVar2;
+      uVar3 = Feature_110180665__private_IsEnabledDeviceUsage();
+      if (((int)uVar3 != 0) && (lVar2 < 0)) {
+        if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+          WPP_SF_sl(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x21,
+                    &WPP_b5613bfc0cb9389146ae0f0305815660_Traceguids,
+                    "CClfsBaseFilePersisted::WriteMetadataBlock");
+        }
+        pCVar5 = *(CClfsBaseFile **)(param_2 + 0xb0);
+        CClfsBaseFile::ReleaseMetadataBlock(pCVar5,*(_CLFS_METADATA_BLOCK_TYPE *)(param_2 + 0xb8));
+        if (*(char *)(param_2 + 200) != '\0') {
+          ExReleaseResourceForThreadLite(*(undefined8 *)(pCVar5 + 0x20),SystemReserved1[0xf]);
+          *(undefined1 *)(param_2 + 200) = 0;
+          lVar2 = *(long *)(param_2 + 0x38);
+        }
+        *(long *)(param_2 + 0xb0) = lVar2;
+        _local_unwind(*(undefined8 *)(param_2 + 0x60),&LAB_0);
+      }
     }
-    uVar3 = 0;
-    *(undefined4 *)(param_2 + 0x34) = 0;
-    this = *(CClfsBaseFile **)(param_2 + 0x90);
-    pCVar4 = this + 0x1d8;
+    uVar4 = 0;
+    *(undefined4 *)(param_2 + 0x50) = 0;
+    pCVar5 = *(CClfsBaseFile **)(param_2 + 0xb0);
+    pCVar6 = pCVar5 + 0x1d8;
     do {
-      if (*(longlong *)pCVar4 != 0) {
+      if (*(longlong *)pCVar6 != 0) {
         lVar2 = CClfsBaseFile::AcquireContainerContext
-                          (this,uVar3,(_CLFS_CONTAINER_CONTEXT **)(param_2 + 0x40));
+                          (pCVar5,uVar4,(_CLFS_CONTAINER_CONTEXT **)(param_2 + 0x48));
         if (-1 < lVar2) {
-          *(undefined8 *)(*(longlong *)(param_2 + 0x40) + 0x18) = *(undefined8 *)pCVar4;
-          CClfsBaseFile::ReleaseContainerContext(this,(_CLFS_CONTAINER_CONTEXT **)(param_2 + 0x40));
+          *(undefined8 *)(*(longlong *)(param_2 + 0x48) + 0x18) = *(undefined8 *)pCVar6;
+          CClfsBaseFile::ReleaseContainerContext
+                    (pCVar5,(_CLFS_CONTAINER_CONTEXT **)(param_2 + 0x48));
         }
       }
-      uVar3 = uVar3 + 1;
-      pCVar4 = pCVar4 + 8;
-    } while (uVar3 < 0x400);
-    *(ulong *)(param_2 + 0x34) = uVar3;
+      uVar4 = uVar4 + 1;
+      pCVar6 = pCVar6 + 8;
+    } while (uVar4 < 0x400);
+    *(ulong *)(param_2 + 0x50) = uVar4;
   }
-  if (*(char *)(param_2 + 0xa8) != '\0') {
-    ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
+  if (*(char *)(param_2 + 200) != '\0') {
+    ExReleaseResourceForThreadLite(*(undefined8 *)(pCVar5 + 0x20),SystemReserved1[0xf]);
   }
   return;
 }
 

```


## wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.4|
|i_ratio|0.37|
|m_ratio|0.9|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|fullname|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|refcount|2|2|
|`length`|91|76|
|called|||
|calling|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|paramcount|3|2|
|`address`|1c0011b8c|1c0011ac0|
|`sig`|undefined __fastcall wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1, int param_2, undefined8 * param_3)|undefined __fastcall wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1, int param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath Diff


```diff
--- wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
+++ wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
@@ -1,52 +1,41 @@
 
-void wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
-               (uint param_1,int param_2,undefined8 *param_3)
+void wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1,int param_2)
 
 {
-  uint *puVar1;
+  uint uVar1;
   uint uVar2;
   uint uVar3;
-  uint uVar4;
-  bool bVar5;
+  bool bVar4;
   
-  puVar1 = (uint *)*param_3;
   if (param_2 == 3) {
-    uVar4 = 0x10;
+    uVar3 = 0x10;
   }
   else {
     if (param_2 != 4) {
       return;
     }
-    uVar4 = 0x20;
+    uVar3 = 0x20;
   }
-  if ((*(char *)((longlong)param_3 + 0x1e) == '\0') && (*(char *)((longlong)param_3 + 0x1d) == '\0')
-     ) {
-    if ((*puVar1 & 2) != 0) {
-      uVar3 = *puVar1;
-      while ((uVar3 & 1) == (param_1 & 1)) {
-        LOCK();
-        uVar2 = *puVar1;
-        bVar5 = uVar3 == uVar2;
-        if (bVar5) {
-          *puVar1 = uVar4 | uVar3;
-          uVar2 = uVar3;
-        }
-        UNLOCK();
-        if (bVar5) {
-          return;
-        }
-        uVar3 = uVar2;
-        if ((uVar2 & 2) == 0) {
-          return;
-        }
+  if ((Feature_110180665__private_featureState & 2) != 0) {
+    uVar2 = Feature_110180665__private_featureState;
+    while ((uVar2 & 1) == (param_1 & 1)) {
+      LOCK();
+      bVar4 = uVar2 == Feature_110180665__private_featureState;
+      uVar1 = uVar3 | uVar2;
+      if (!bVar4) {
+        uVar2 = Feature_110180665__private_featureState;
+        uVar1 = Feature_110180665__private_featureState;
+      }
+      Feature_110180665__private_featureState = uVar1;
+      UNLOCK();
+      if (bVar4) {
+        return;
+      }
+      if ((uVar2 & 2) == 0) {
+        return;
       }
     }
-  }
-  else {
-    LOCK();
-    *puVar1 = *puVar1 | uVar4;
-    UNLOCK();
   }
   return;
 }
 

```


## Feature_2458037564__private_IsEnabledFallback

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,calling|
|ratio|0.8|
|i_ratio|0.67|
|m_ratio|0.89|
|b_ratio|0.89|
|match_types|Implied Match|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|`name`|Feature_2458037564__private_IsEnabledFallback|Feature_110180665__private_IsEnabledFallback|
|`fullname`|Feature_2458037564__private_IsEnabledFallback|Feature_110180665__private_IsEnabledFallback|
|refcount|2|2|
|`length`|21|14|
|called|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`calling`|Feature_2458037564__private_IsEnabledDeviceUsage|Feature_110180665__private_IsEnabledDeviceUsage|
|paramcount|2|2|
|`address`|1c00167c0|1c0010bd8|
|`sig`|undefined __fastcall Feature_2458037564__private_IsEnabledFallback(ulonglong param_1, int param_2)|undefined __fastcall Feature_110180665__private_IsEnabledFallback(undefined4 * param_1, uint param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### Feature_2458037564__private_IsEnabledFallback Calling Diff


```diff
--- Feature_2458037564__private_IsEnabledFallback calling
+++ Feature_110180665__private_IsEnabledFallback calling
@@ -1 +1 @@
-Feature_2458037564__private_IsEnabledDeviceUsage
+Feature_110180665__private_IsEnabledDeviceUsage
```


### Feature_2458037564__private_IsEnabledFallback Diff


```diff
--- Feature_2458037564__private_IsEnabledFallback
+++ Feature_110180665__private_IsEnabledFallback
@@ -1,8 +1,8 @@
 
-void Feature_2458037564__private_IsEnabledFallback(ulonglong param_1,int param_2)
+void Feature_110180665__private_IsEnabledFallback(undefined4 *param_1,uint param_2)
 
 {
-  wil_details_IsEnabledFallback(param_1,param_2,&Feature_2458037564__private_descriptor);
+  wil_details_IsEnabledFallback(param_1,param_2);
   return;
 }
 

```


## Feature_1868496191__private_IsEnabledFallback

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,calling|
|ratio|0.8|
|i_ratio|0.67|
|m_ratio|0.89|
|b_ratio|0.89|
|match_types|Implied Match|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|`name`|Feature_1868496191__private_IsEnabledFallback|Feature_110180665__private_IsEnabledFallback|
|`fullname`|Feature_1868496191__private_IsEnabledFallback|Feature_110180665__private_IsEnabledFallback|
|refcount|2|2|
|`length`|21|14|
|called|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`calling`|Feature_1868496191__private_IsEnabledDeviceUsage|Feature_110180665__private_IsEnabledDeviceUsage|
|paramcount|2|2|
|`address`|1c0010bf8|1c0010bd8|
|`sig`|undefined __fastcall Feature_1868496191__private_IsEnabledFallback(ulonglong param_1, int param_2)|undefined __fastcall Feature_110180665__private_IsEnabledFallback(undefined4 * param_1, uint param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### Feature_1868496191__private_IsEnabledFallback Calling Diff


```diff
--- Feature_1868496191__private_IsEnabledFallback calling
+++ Feature_110180665__private_IsEnabledFallback calling
@@ -1 +1 @@
-Feature_1868496191__private_IsEnabledDeviceUsage
+Feature_110180665__private_IsEnabledDeviceUsage
```


### Feature_1868496191__private_IsEnabledFallback Diff


```diff
--- Feature_1868496191__private_IsEnabledFallback
+++ Feature_110180665__private_IsEnabledFallback
@@ -1,8 +1,8 @@
 
-void Feature_1868496191__private_IsEnabledFallback(ulonglong param_1,int param_2)
+void Feature_110180665__private_IsEnabledFallback(undefined4 *param_1,uint param_2)
 
 {
-  wil_details_IsEnabledFallback(param_1,param_2,&Feature_1868496191__private_descriptor);
+  wil_details_IsEnabledFallback(param_1,param_2);
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## LsnToCacheOffset

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|LsnToCacheOffset|LsnToCacheOffset|
|fullname|CClfsLogFcbPhysical::LsnToCacheOffset|CClfsLogFcbPhysical::LsnToCacheOffset|
|`refcount`|34|28|
|length|123|123|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AcquireForLazyWrite<br>CClfsLogFcbPhysical::AcquireForReadAhead<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::ReadLogBlock<br>CClfsLogFcbPhysical::ReadLogPagingIo<br>CClfsLogFcbPhysical::SetCacheFileSizes</summary>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AcquireForLazyWrite<br>CClfsLogFcbPhysical::AcquireForReadAhead<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::ReadLogBlock<br>CClfsLogFcbPhysical::ReadLogPagingIo<br>CClfsLogFcbPhysical::SetCacheFileSizes</summary>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</details>|
|paramcount|2|2|
|`address`|1c0066310|1c0065860|
|sig|__uint64 __thiscall LsnToCacheOffset(CClfsLogFcbPhysical * this, _CLS_LSN * param_1)|__uint64 __thiscall LsnToCacheOffset(CClfsLogFcbPhysical * this, _CLS_LSN * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### LsnToCacheOffset Calling Diff


```diff

```


## ReleaseContainerContext

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.84|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ReleaseContainerContext|ReleaseContainerContext|
|fullname|CClfsBaseFile::ReleaseContainerContext|CClfsBaseFile::ReleaseContainerContext|
|`refcount`|43|45|
|length|230|230|
|called|CClfsBaseFile::GetSymbol<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::RtlCompareMemory|CClfsBaseFile::GetSymbol<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::RtlCompareMemory|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::MarkContainerQ<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsBaseFilePersisted::UnmarkContainerQ<br>CClfsLogFcbPhysical::AdvanceQHead<br>CClfsLogFcbPhysical::CloseContainers<br>CClfsLogFcbPhysical::DeleteBaseFileAndContainers<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::FlushLog<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetContainer</summary>CClfsLogFcbPhysical::InsertContainer<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WrapDeletePendingContainer<br>CClfsRequest::AuthenticateLogFile<br>`CClfsBaseFilePersisted::MarkContainerQ'::__l1::fin$0<br>`CClfsBaseFilePersisted::ModifySharedSecurityContext'::__l1::fin$0<br>`CClfsBaseFilePersisted::UnmarkContainerQ'::__l1::fin$0<br>`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0<br>`CClfsLogFcbPhysical::AdvanceQHead'::__l1::fin$0<br>`CClfsLogFcbPhysical::DeleteContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetArchiveDescriptors'::__l1::fin$0<br>`CClfsLogFcbPhysical::InsertContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapContainers'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapDeletePendingContainer'::__l1::fin$0<br>`CClfsRequest::AuthenticateLogFile'::__l1::fin$0</details>|<details><summary>Expand for full list:<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::MarkContainerQ<br>CClfsBaseFilePersisted::ModifySharedSecurityContext<br>CClfsBaseFilePersisted::UnmarkContainerQ<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsLogFcbPhysical::AdvanceQHead<br>CClfsLogFcbPhysical::CloseContainers<br>CClfsLogFcbPhysical::DeleteBaseFileAndContainers<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::FlushLog<br>CClfsLogFcbPhysical::GetArchiveDescriptors</summary>CClfsLogFcbPhysical::GetContainer<br>CClfsLogFcbPhysical::InsertContainer<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WrapDeletePendingContainer<br>CClfsRequest::AuthenticateLogFile<br>`CClfsBaseFilePersisted::MarkContainerQ'::__l1::fin$0<br>`CClfsBaseFilePersisted::ModifySharedSecurityContext'::__l1::fin$0<br>`CClfsBaseFilePersisted::UnmarkContainerQ'::__l1::fin$0<br>`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0<br>`CClfsLogFcbPhysical::AdvanceQHead'::__l1::fin$0<br>`CClfsLogFcbPhysical::DeleteContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetArchiveDescriptors'::__l1::fin$0<br>`CClfsLogFcbPhysical::InsertContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapContainers'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapDeletePendingContainer'::__l1::fin$0<br>`CClfsRequest::AuthenticateLogFile'::__l1::fin$0</details>|
|paramcount|2|2|
|`address`|1c00611e0|1c0060a70|
|sig|long __thiscall ReleaseContainerContext(CClfsBaseFile * this, _CLFS_CONTAINER_CONTEXT * * param_1)|long __thiscall ReleaseContainerContext(CClfsBaseFile * this, _CLFS_CONTAINER_CONTEXT * * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ReleaseContainerContext Calling Diff


```diff
--- CClfsBaseFile::ReleaseContainerContext calling
+++ CClfsBaseFile::ReleaseContainerContext calling
@@ -4,0 +5 @@
+CClfsBaseFilePersisted::WriteMetadataBlock
```


## RemoveSymbol

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|length,address|
|ratio|1.0|
|i_ratio|0.63|
|m_ratio|0.97|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|RemoveSymbol|RemoveSymbol|
|fullname|CClfsBaseFilePersisted::RemoveSymbol|CClfsBaseFilePersisted::RemoveSymbol|
|refcount|4|4|
|`length`|123|119|
|called|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|
|calling|CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::RemoveClient<br>CClfsBaseFilePersisted::RemoveContainer|CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::RemoveClient<br>CClfsBaseFilePersisted::RemoveContainer|
|paramcount|2|2|
|`address`|1c005ef1c|1c00613d8|
|sig|long __thiscall RemoveSymbol(CClfsBaseFilePersisted * this, long param_1)|long __thiscall RemoveSymbol(CClfsBaseFilePersisted * this, long param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

## GetBaseLogRecord

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|GetBaseLogRecord|GetBaseLogRecord|
|fullname|CClfsBaseFile::GetBaseLogRecord|CClfsBaseFile::GetBaseLogRecord|
|`refcount`|37|35|
|length|53|53|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::HighWaterMarkClientId<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFilePersisted::AddClient<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient</summary>CClfsBaseFilePersisted::AddSymbol<br>CClfsBaseFilePersisted::AllocSymbol<br>CClfsBaseFilePersisted::AreClientIdsAvailable<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::IncrementUsn<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::RemoveClient<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::HighWaterMarkClientId<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFilePersisted::AddClient<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient</summary>CClfsBaseFilePersisted::AddSymbol<br>CClfsBaseFilePersisted::AllocSymbol<br>CClfsBaseFilePersisted::AreClientIdsAvailable<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::IncrementUsn<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::RemoveClient<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|
|paramcount|1|1|
|`address`|1c0061560|1c0060500|
|sig|_CLFS_BASE_RECORD_HEADER * __thiscall GetBaseLogRecord(CClfsBaseFile * this)|_CLFS_BASE_RECORD_HEADER * __thiscall GetBaseLogRecord(CClfsBaseFile * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetBaseLogRecord Calling Diff


```diff
--- CClfsBaseFile::GetBaseLogRecord calling
+++ CClfsBaseFile::GetBaseLogRecord calling
@@ -4 +3,0 @@
-CClfsBaseFile::GetSymbol
@@ -6,0 +6 @@
+CClfsBaseFile::OffsetToAddr
@@ -25 +24,0 @@
-CClfsBaseFilePersisted::WriteMetadataBlock
```


## WPP_SF_sl

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.81|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|WPP_SF_sl|WPP_SF_sl|
|fullname|WPP_SF_sl|WPP_SF_sl|
|`refcount`|92|95|
|length|114|114|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::ValidateProcessQNode<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsBaseFileSnapshot::CopyImage<br>CClfsLogFcbPhysical::AppendRegion<br>CClfsLogFcbPhysical::RecoverTruncateLog<br>CClfsLogFcbPhysical::SetEndOfLog<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::ValidateScratchBlockOffsets<br>CClfsManagedLog::AddContainersForGrowth<br>CClfsRequest::Dispatch</summary>CClfsRequest_State::Cancel<br>CClfsRequest_State::Done<br>CClfsRequest_State::FinalizeReadRequest<br>CClfsRequest_State::FlushDone<br>CClfsRequest_State::ReadDone<br>CClfsRequest_State::WriteRestartDone<br>CClfsRequest_State::WriteRestartInProgress<br>ClfsAddLogContainer<br>ClfsAddLogContainerSet<br>ClfsAdvanceLogBase<br>ClfsAlignReservedLog<br>ClfsAllocReservedLog<br>ClfsCloseAndResetLogFile<br>ClfsCloseLogFileObject<br>ClfsCreateLogFile<br>ClfsCreateMarshallingAreaInternal<br>ClfsCreateScanContext<br>ClfsDeleteLogByPointer<br>ClfsDeleteLogFile<br>ClfsDeleteMarshallingArea<br>ClfsFinalize<br>ClfsFlushBuffers<br>ClfsFlushToLsn<br>ClfsFreeReservedLog<br>ClfsGetContainerName<br>ClfsGetIoStatistics<br>ClfsGetLogFileInformation<br>ClfsGetManagementSupportInterface<br>ClfsGetObservableInterface<br>ClfsGetPendingRequestQueueInterface<br>ClfsInitialize<br>ClfsQueryLogFileInformation<br>ClfsReadLogRecord<br>ClfsReadNextLogRecord<br>ClfsReadPreviousRestartArea<br>ClfsReadRestartArea<br>ClfsRemoveLogContainer<br>ClfsRemoveLogContainerSet<br>ClfsReserveAndAppendLogAligned<br>ClfsScanLogContainers<br>ClfsSetArchiveTail<br>ClfsSetLogFileInformation<br>ClfsTerminateReadLog<br>ClfsWriteRestartArea</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::ValidateProcessQNode<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::FlushImage<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsBaseFileSnapshot::CopyImage<br>CClfsLogFcbPhysical::AppendRegion<br>CClfsLogFcbPhysical::RecoverTruncateLog<br>CClfsLogFcbPhysical::SetEndOfLog<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::ValidateScratchBlockOffsets<br>CClfsManagedLog::AddContainersForGrowth</summary>CClfsRequest::Dispatch<br>CClfsRequest_State::Cancel<br>CClfsRequest_State::Done<br>CClfsRequest_State::FinalizeReadRequest<br>CClfsRequest_State::FlushDone<br>CClfsRequest_State::ReadDone<br>CClfsRequest_State::WriteRestartDone<br>CClfsRequest_State::WriteRestartInProgress<br>ClfsAddLogContainer<br>ClfsAddLogContainerSet<br>ClfsAdvanceLogBase<br>ClfsAlignReservedLog<br>ClfsAllocReservedLog<br>ClfsCloseAndResetLogFile<br>ClfsCloseLogFileObject<br>ClfsCreateLogFile<br>ClfsCreateMarshallingAreaInternal<br>ClfsCreateScanContext<br>ClfsDeleteLogByPointer<br>ClfsDeleteLogFile<br>ClfsDeleteMarshallingArea<br>ClfsFinalize<br>ClfsFlushBuffers<br>ClfsFlushToLsn<br>ClfsFreeReservedLog<br>ClfsGetContainerName<br>ClfsGetIoStatistics<br>ClfsGetLogFileInformation<br>ClfsGetManagementSupportInterface<br>ClfsGetObservableInterface<br>ClfsGetPendingRequestQueueInterface<br>ClfsInitialize<br>ClfsQueryLogFileInformation<br>ClfsReadLogRecord<br>ClfsReadNextLogRecord<br>ClfsReadPreviousRestartArea<br>ClfsReadRestartArea<br>ClfsRemoveLogContainer<br>ClfsRemoveLogContainerSet<br>ClfsReserveAndAppendLogAligned<br>ClfsScanLogContainers<br>ClfsSetArchiveTail<br>ClfsSetLogFileInformation<br>ClfsTerminateReadLog<br>ClfsWriteRestartArea<br>`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0</details>|
|paramcount|4|4|
|`address`|1c0010c14|1c0010bf0|
|sig|undefined __fastcall WPP_SF_sl(undefined8 param_1, undefined2 param_2, undefined8 param_3, char * param_4)|undefined __fastcall WPP_SF_sl(undefined8 param_1, undefined2 param_2, undefined8 param_3, char * param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### WPP_SF_sl Calling Diff


```diff
--- WPP_SF_sl calling
+++ WPP_SF_sl calling
@@ -2,0 +3 @@
+CClfsBaseFilePersisted::FlushImage
@@ -55,0 +57 @@
+`CClfsBaseFilePersisted::WriteMetadataBlock'::__l1::fin$0
```


## ReleaseSharedSecurityDescriptor

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|length,address|
|ratio|1.0|
|i_ratio|0.81|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|ReleaseSharedSecurityDescriptor|ReleaseSharedSecurityDescriptor|
|fullname|CClfsBaseFile::ReleaseSharedSecurityDescriptor|CClfsBaseFile::ReleaseSharedSecurityDescriptor|
|refcount|3|3|
|`length`|138|137|
|called|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::UnlockImage<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|
|calling|CClfsBaseFilePersisted::ModifySharedSecurityContext|CClfsBaseFilePersisted::ModifySharedSecurityContext|
|paramcount|2|2|
|`address`|1c003ae68|1c003ad14|
|sig|long __thiscall ReleaseSharedSecurityDescriptor(CClfsBaseFile * this, void * param_1)|long __thiscall ReleaseSharedSecurityDescriptor(CClfsBaseFile * this, void * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

## memcpy

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.82|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|memcpy|memcpy|
|fullname|memcpy|memcpy|
|`refcount`|78|77|
|length|537|537|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsAuthContainer::VerifyPatchContents<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFileSnapshot::CopyImage<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsContainer::DuplicateDefaultSecurityDescriptor</summary>CClfsContainer::DuplicateNullSecurityDescriptor<br>CClfsContainer::DuplicateSecurityDescriptor<br>CClfsContainer::ReadSectorUnaligned<br>CClfsContainer::SetDefaultSaclSecurityDescriptor<br>CClfsContainer::WriteSectorUnaligned<br>CClfsKernelMarshallingContext::AppendRecord<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::BinarySearchLsn<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FindLsnBlock<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryLogFileInfo<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::ReadLastOwnerPage<br>CClfsLogFcbPhysical::ReadQueuedOwnerPage<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbVirtual::QueryLogFileInfo<br>CClfsManagedLog::Initialize<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::QueryPolicy<br>CClfsManagedLogClientUser::Initialize<br>CClfsManagedLogClientUser::QueryRegistration<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsMerkleTree::FinishTreeInitialization<br>CClfsMerkleTree::GetRootHash<br>CClfsMerkleTree::ResizeTree<br>CClfsRequest::GetIoStatistics<br>ClfsAddLogContainerSet<br>ClfsGetIoStatistics<br>CmRegUtilUcValueSetUcString<br>SeSddlSecurityDescriptorFromSDDL<br>SepSddlAddAceToAcl<br>WppTraceCallback<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>memcpy_s</details>|<details><summary>Expand for full list:<br>CClfsAuthContainer::VerifyPatchContents<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::FlushControlRecord<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFileSnapshot::CopyImage<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsContainer::DuplicateDefaultSecurityDescriptor</summary>CClfsContainer::DuplicateNullSecurityDescriptor<br>CClfsContainer::DuplicateSecurityDescriptor<br>CClfsContainer::ReadSectorUnaligned<br>CClfsContainer::SetDefaultSaclSecurityDescriptor<br>CClfsContainer::WriteSectorUnaligned<br>CClfsKernelMarshallingContext::AppendRecord<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::BinarySearchLsn<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FindLsnBlock<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryLogFileInfo<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::ReadLastOwnerPage<br>CClfsLogFcbPhysical::ReadQueuedOwnerPage<br>CClfsLogFcbPhysical::TruncateLogRewriteOwnerPages<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbVirtual::QueryLogFileInfo<br>CClfsManagedLog::Initialize<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::QueryPolicy<br>CClfsManagedLogClientUser::Initialize<br>CClfsManagedLogClientUser::QueryRegistration<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsMerkleTree::FinishTreeInitialization<br>CClfsMerkleTree::GetRootHash<br>CClfsMerkleTree::ResizeTree<br>CClfsRequest::GetIoStatistics<br>ClfsAddLogContainerSet<br>ClfsGetIoStatistics<br>CmRegUtilUcValueSetUcString<br>SeSddlSecurityDescriptorFromSDDL<br>SepSddlAddAceToAcl<br>WppTraceCallback<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>memcpy_s</details>|
|paramcount|3|3|
|`address`|1c0017dc0|1c0017c80|
|sig|void * __cdecl memcpy(void * _Dst, void * _Src, size_t _Size)|void * __cdecl memcpy(void * _Dst, void * _Src, size_t _Size)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### memcpy Calling Diff


```diff

```


## NTOSKRNL.EXE::RtlCompareMemory

### Match Info



|Key|clfs_1301.sys - clfs_1455.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs_1301.sys|clfs_1455.sys|
| :---: | :---: | :---: |
|name|RtlCompareMemory|RtlCompareMemory|
|fullname|NTOSKRNL.EXE::RtlCompareMemory|NTOSKRNL.EXE::RtlCompareMemory|
|`refcount`|6|4|
|length|0|0|
|called|||
|`calling`|CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsContainer::IsEqualSecurityDescriptor|CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsContainer::IsEqualSecurityDescriptor|
|paramcount|0|0|
|address|EXTERNAL:00000012|EXTERNAL:00000012|
|sig|undefined RtlCompareMemory(void)|undefined RtlCompareMemory(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlCompareMemory Calling Diff


```diff
--- NTOSKRNL.EXE::RtlCompareMemory calling
+++ NTOSKRNL.EXE::RtlCompareMemory calling
@@ -3 +2,0 @@
-CClfsBaseFilePersisted::WriteMetadataBlock
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-22T13:51:18</sub>