# clfs-3037.sys-clfs-3470.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_2633002298__private_IsEnabledDeviceUsageNoInline](#feature_2633002298__private_isenableddeviceusagenoinline)
	* [Feature_2633002298__private_IsEnabledFallback](#feature_2633002298__private_isenabledfallback)
* [Modified](#modified)
	* [CClfsLogFcbPhysical::PurgeCacheSection](#cclfslogfcbphysicalpurgecachesection)
	* [CClfsLogFcbPhysical::WriteRestart](#cclfslogfcbphysicalwriterestart)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [LsnToCacheOffset](#lsntocacheoffset)
	* [ClfsLsnCreate](#clfslsncreate)
	* [ClfsLsnBlockOffset](#clfslsnblockoffset)
	* [operator!=](#operator)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [NotifyObservers](#notifyobservers)

# Visual Chart Diff



```mermaid

flowchart LR

CClfsLogFcbPhysicalPurgeCacheSection-4-old<--Match 60%-->CClfsLogFcbPhysicalPurgeCacheSection-4-new
CClfsLogFcbPhysicalWriteRestart-17-old<--Match 25%-->CClfsLogFcbPhysicalWriteRestart-17-new

subgraph clfs-3470.sys
    CClfsLogFcbPhysicalPurgeCacheSection-4-new
CClfsLogFcbPhysicalWriteRestart-17-new
    subgraph Added
direction LR
Feature_2633002298__private_IsEnabledDeviceUsageNoInline
    Feature_2633002298__private_IsEnabledFallback
end
end

subgraph clfs-3037.sys
    CClfsLogFcbPhysicalPurgeCacheSection-4-old
CClfsLogFcbPhysicalWriteRestart-17-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.9450%
"unmatched_funcs_len" : 2
"matched_funcs_len" : 3634
```



```mermaid
pie showData
    title Matched Function Similarity - 99.7799%
"matched_funcs_with_code_changes_len" : 2
"matched_funcs_with_non_code_changes_len" : 6
"matched_funcs_no_changes_len" : 3626
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj --project-name c24059 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 clfs-3037.sys clfs-3470.sys
```


#### Verbose Args


<details>

```
--old ['clfs-3037.sys'] --new [['clfs-3470.sys']] --engine VersionTrackingDiff --output-path ./out --summary False --project-location ./proj --project-name c24059 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/86AB2AC386000/Clfs.Sys -O clfs.sys.x64.10.0.26100.3037
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/22392E7A86000/Clfs.Sys -O clfs.sys.x64.10.0.26100.3470
```


## Binary Metadata Diff


```diff
--- clfs-3037.sys Meta
+++ clfs-3470.sys Meta
@@ -1,44 +1,44 @@
-Program Name: clfs-3037.sys
+Program Name: clfs-3470.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
-# of Bytes: 552992
+# of Bytes: 553000
 # of Memory Blocks: 14
-# of Instructions: 97917
-# of Defined Data: 3632
-# of Functions: 1817
-# of Symbols: 13943
+# of Instructions: 97923
+# of Defined Data: 3640
+# of Functions: 1819
+# of Symbols: 13951
 # of Data Types: 467
 # of Data Type Categories: 20
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sat Aug 15 18:02:55 SGT 2026
+Date Created: Sat Aug 15 18:02:59 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-3037.sys
-Executable MD5: 690dac65b6f4e458c6ede131dafc5483
-Executable SHA256: 2d6c1a9346fc4dc38be6ff74fdc9cbce830f04c7149c8d017bf84f87eb42c695
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-3037.sys?MD5=690dac65b6f4e458c6ede131dafc5483
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-3470.sys
+Executable MD5: a644e0e03a892cfcdaed280299563afb
+Executable SHA256: 8421376376af3bc5d1fb21749e3e03f46ed92c22b25c57d56dc6d51c9091cf84
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-3470.sys?MD5=a644e0e03a892cfcdaed280299563afb
 PDB Age: 1
 PDB File: clfs.pdb
-PDB GUID: a8eb2944-781b-29e2-7a5a-fd4805ae6a17
+PDB GUID: d6fcf763-3f2e-86ed-36fa-5330af461cdc
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Common Log File System Driver
-PE Property[FileVersion]: 10.0.26100.3037 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.3470 (WinBuild.160101.0800)
 PE Property[InternalName]: clfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Clfs.Sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.3037
+PE Property[ProductVersion]: 10.0.26100.3470
 PE Property[Translation]: 4b00000
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra clfs-3037.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-3037.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-3037.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra clfs-3470.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-3470.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-3470.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|2|
|deleted_funcs_len|0|
|modified_funcs_len|8|
|added_symbols_len|4|
|deleted_symbols_len|1|
|diff_time|4.2255988121032715|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 1804, 'ExternalsName': 244, 'ExactInstructionsFunctionHasher': 11, 'ExactBytesFunctionHasher': 1})|
|items_to_process|15|
|diff_types|Counter({'refcount': 6, 'calling': 4, 'code': 2, 'length': 2, 'address': 2, 'called': 2})|
|unmatched_funcs_len|2|
|total_funcs_len|3636|
|matched_funcs_len|3634|
|matched_funcs_with_code_changes_len|2|
|matched_funcs_with_non_code_changes_len|6|
|matched_funcs_no_changes_len|3626|
|match_func_similarity_percent|99.7799%|
|func_match_overall_percent|99.9450%|
|first_matches|Counter({'SymbolsHash': 1804, 'ExactInstructionsFunctionHasher': 11, 'ExactBytesFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1804
"ExternalsName" : 244
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 11
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1804
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 11
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 2
"deleted_funcs_len" : 0
"modified_funcs_len" : 8
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 4
"deleted_symbols_len" : 1
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_2633002298__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|clfs-3470.sys|
| :---: | :---: |
|name|Feature_2633002298__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_2633002298__private_IsEnabledDeviceUsageNoInline|
|refcount|3|
|length|49|
|called|Feature_2633002298__private_IsEnabledFallback|
|calling|CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::WriteRestart|
|paramcount|0|
|address|1c00167f8|
|sig|ulonglong __fastcall Feature_2633002298__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_2633002298__private_IsEnabledDeviceUsageNoInline
+++ Feature_2633002298__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_2633002298__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_2633002298__private_featureState;
+  if ((Feature_2633002298__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_2633002298__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_2633002298__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_2633002298__private_IsEnabledFallback

### Function Meta



|Key|clfs-3470.sys|
| :---: | :---: |
|name|Feature_2633002298__private_IsEnabledFallback|
|fullname|Feature_2633002298__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_2633002298__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1c0016830|
|sig|undefined __fastcall Feature_2633002298__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_2633002298__private_IsEnabledFallback
+++ Feature_2633002298__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_2633002298__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_2633002298__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## CClfsLogFcbPhysical::PurgeCacheSection

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.32|
|i_ratio|0.15|
|m_ratio|0.98|
|b_ratio|0.6|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|PurgeCacheSection|PurgeCacheSection|
|fullname|CClfsLogFcbPhysical::PurgeCacheSection|CClfsLogFcbPhysical::PurgeCacheSection|
|refcount|14|14|
|`length`|518|512|
|`called`|ClfsLsnBlockOffset<br>ClfsLsnCreate<br>NTOSKRNL.EXE::CcPurgeCacheSection<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsLogFcbPhysical::LsnToCacheOffset<br>Feature_2633002298__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::CcPurgeCacheSection<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|calling|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::Cleanup<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::SetArchiveTail<br>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::TruncateLog<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</summary>CClfsLogFcbPhysical::WriteRestart<br>`CClfsLogFcbPhysical::FindEndOfLog'::__l1::fin$0</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::Cleanup<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::SetArchiveTail<br>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::TruncateLog<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</summary>CClfsLogFcbPhysical::WriteRestart<br>`CClfsLogFcbPhysical::FindEndOfLog'::__l1::fin$0</details>|
|paramcount|4|4|
|`address`|1c0065b00|1c0065380|
|sig|uchar __thiscall PurgeCacheSection(CClfsLogFcbPhysical * this, _CLS_LSN * param_1, _CLS_LSN * param_2, uchar param_3)|uchar __thiscall PurgeCacheSection(CClfsLogFcbPhysical * this, _CLS_LSN * param_1, _CLS_LSN * param_2, uchar param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::PurgeCacheSection Called Diff


```diff
--- CClfsLogFcbPhysical::PurgeCacheSection called
+++ CClfsLogFcbPhysical::PurgeCacheSection called
@@ -1,2 +1,2 @@
-ClfsLsnBlockOffset
-ClfsLsnCreate
+CClfsLogFcbPhysical::LsnToCacheOffset
+Feature_2633002298__private_IsEnabledDeviceUsageNoInline
```


### CClfsLogFcbPhysical::PurgeCacheSection Diff


```diff
--- CClfsLogFcbPhysical::PurgeCacheSection
+++ CClfsLogFcbPhysical::PurgeCacheSection
@@ -1,86 +1,95 @@
 
 /* private: unsigned char __cdecl CClfsLogFcbPhysical::PurgeCacheSection(union _CLS_LSN const &
    __ptr64,union _CLS_LSN const & __ptr64,unsigned char) __ptr64 */
 
 uchar __thiscall
 CClfsLogFcbPhysical::PurgeCacheSection
           (CClfsLogFcbPhysical *this,_CLS_LSN *param_1,_CLS_LSN *param_2,uchar param_3)
 
 {
-  CClfsLogFcbPhysical *pCVar1;
-  bool bVar2;
-  char cVar3;
-  uint uVar4;
-  uint uVar5;
-  ulonglong uVar6;
-  ulonglong uVar7;
+  bool bVar1;
+  char cVar2;
+  uchar uVar3;
+  ulonglong uVar4;
+  __uint64 _Var5;
+  uint uVar6;
+  uint uVar7;
   ulonglong *puVar8;
-  uint uVar9;
+  ulonglong uVar9;
+  ulonglong uVar10;
   ulonglong local_res18;
   uchar local_res20;
-  ulonglong uVar10;
-  ulonglong uVar11;
+  undefined8 local_48;
+  undefined8 local_40;
   
-  bVar2 = false;
+  bVar1 = false;
   local_res18 = 0;
-  uVar6 = *(ulonglong *)param_1;
-  uVar7 = *(ulonglong *)param_2;
-  uVar9 = (uint)(uVar7 >> 0x20);
-  uVar5 = (uint)(uVar6 >> 0x20);
-  if ((uVar9 <= uVar5) && ((uVar5 != uVar9 || ((uint)uVar7 < (uint)uVar6)))) {
-    bVar2 = true;
+  uVar9 = *(ulonglong *)param_1;
+  uVar4 = *(ulonglong *)param_2;
+  uVar3 = '\0';
+  local_res20 = '\0';
+  uVar7 = (uint)(uVar4 >> 0x20);
+  uVar6 = (uint)(uVar9 >> 0x20);
+  if ((uVar7 <= uVar6) && ((uVar6 != uVar7 || ((uint)uVar4 < (uint)uVar9)))) {
+    bVar1 = true;
   }
-  if (bVar2) {
+  if (bVar1) {
     return '\x01';
   }
-  local_res20 = param_3;
-  uVar11 = uVar7;
-  if ((uVar6 & 0x1ff) != 0) {
-    uVar4 = ClfsLsnBlockOffset((uint *)param_1);
-    uVar6 = ClfsLsnCreate(uVar5,uVar4,0);
+  uVar10 = uVar9;
+  if ((uVar9 & 0x1ff) != 0) {
+    uVar10 = 0xffffffff00000000;
+    if (uVar6 != 0xffffffff) {
+      uVar10 = uVar9 & 0xffffffff00000000 | (ulonglong)((uint)uVar9 & 0xfffffe00);
+    }
   }
-  uVar10 = uVar6;
-  if ((uVar7 & 0x1ff) != 0) {
-    uVar5 = ClfsLsnBlockOffset((uint *)param_2);
-    uVar7 = ClfsLsnCreate(uVar9,uVar5,0);
-    uVar11 = uVar7;
+  uVar9 = uVar4;
+  if ((uVar4 & 0x1ff) != 0) {
+    uVar9 = 0xffffffff00000000;
+    if (uVar7 != 0xffffffff) {
+      uVar9 = uVar4 & 0xffffffff00000000 | (ulonglong)((uint)uVar4 & 0xfffffe00);
+    }
   }
-  cVar3 = ExAcquireResourceExclusiveLite(this + 200,1);
+  local_48 = uVar10;
+  local_40 = uVar9;
+  cVar2 = ExAcquireResourceExclusiveLite(this + 200,CONCAT71((uint7)(uVar4 >> 0x28),1));
   if ((*(longlong *)param_1 == 0) && (*(longlong *)param_2 == 0)) {
     puVar8 = (ulonglong *)0x0;
   }
   else {
-    pCVar1 = this + 0x558;
-    if (pCVar1 != (CClfsLogFcbPhysical *)0x0) {
-      uVar5 = *(uint *)(this + 0x55c);
-      uVar9 = (uint)(uVar10 >> 0x20);
-      if ((uVar5 <= uVar9) && ((uVar9 != uVar5 || (*(uint *)pCVar1 < (uint)uVar6)))) {
-        if (uVar6 == 0xffffffff00000000) {
-          local_res18 = 0xffffffffffffffff;
+    if (this + 0x558 != (CClfsLogFcbPhysical *)0x0) {
+      if ((*(uint *)(this + 0x55c) <= local_48._4_4_) &&
+         ((local_48._4_4_ != *(uint *)(this + 0x55c) || (*(uint *)(this + 0x558) < (uint)uVar10))))
+      {
+        uVar4 = Feature_2633002298__private_IsEnabledDeviceUsageNoInline();
+        _Var5 = LsnToCacheOffset(this,(_CLS_LSN *)&local_48);
+        if ((int)uVar4 != 0) {
+          local_48 = _Var5;
+          if ((longlong)_Var5 < 0) goto LAB_0;
+          _Var5 = _Var5 + ((uint)((longlong)_Var5 >> 0x3f) & 0xfff);
         }
-        else {
-          local_res18 = ((ulonglong)uVar9 * *(longlong *)(this + 0x2b8) +
-                        (ulonglong)((uint)uVar6 & 0xfffffe00)) -
-                        ((ulonglong)uVar5 * *(longlong *)(this + 0x2b8) +
-                        (ulonglong)(*(uint *)pCVar1 & 0xfffffe00));
+        local_res18 = _Var5 & 0xfffffffffffff000;
+      }
+      if (this + 0x558 != (CClfsLogFcbPhysical *)0x0) {
+        if ((local_40._4_4_ <= *(uint *)(this + 0x55c)) &&
+           ((local_40._4_4_ != *(uint *)(this + 0x55c) || ((uint)uVar9 < *(uint *)(this + 0x558)))))
+        {
+          uVar3 = '\x01';
+          local_res20 = '\x01';
+          goto LAB_0;
         }
-        local_res18 = local_res18 & 0xfffffffffffff000;
-      }
-      if (((this + 0x558 != (CClfsLogFcbPhysical *)0x0) &&
-          (uVar5 = (uint)(uVar11 >> 0x20), uVar5 <= *(uint *)(this + 0x55c))) &&
-         ((uVar5 != *(uint *)(this + 0x55c) || ((uint)uVar7 < *(uint *)(this + 0x558))))) {
-        local_res20 = '\x01';
-        goto LAB_0;
       }
     }
-    uVar11 = 0;
+    local_40 = 0;
     puVar8 = &local_res18;
   }
-  local_res20 = CcPurgeCacheSection(this + 0x288,puVar8,0,0,uVar10,uVar11);
+  uVar3 = CcPurgeCacheSection(this + 0x288,puVar8,0,0);
+  local_res20 = uVar3;
 LAB_0:
-  if (cVar3 != '\0') {
+  if (cVar2 != '\0') {
     ExReleaseResourceForThreadLite(this + 200,SystemReserved1[0xf]);
+    uVar3 = local_res20;
   }
-  return local_res20;
+  return uVar3;
 }
 

```


## CClfsLogFcbPhysical::WriteRestart

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.32|
|i_ratio|0.23|
|m_ratio|0.98|
|b_ratio|0.25|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|WriteRestart|WriteRestart|
|fullname|CClfsLogFcbPhysical::WriteRestart|CClfsLogFcbPhysical::WriteRestart|
|refcount|3|3|
|`length`|1911|1764|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbCommon::Unlock<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::WrapContainers<br>ClfsLsnLess<br>ClfsLsnRecordSequence<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>WPP_SF_sdD<br>_guard_dispatch_icall<br>operator<=</summary></details>|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::NotifyObservers<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbCommon::Unlock<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::WrapContainers<br>ClfsLsnBlockOffset<br>ClfsLsnCreate<br>ClfsLsnLess<br>ClfsLsnRecordSequence<br>Feature_2633002298__private_IsEnabledDeviceUsageNoInline</summary>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>WPP_SF_sdD<br>_guard_dispatch_icall<br>operator!=<br>operator<=</details>|
|calling|||
|paramcount|17|17|
|`address`|1c0065380|1c0076310|
|sig|long __thiscall WriteRestart(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, void * param_2, ulong param_3, __int64 * param_4, __int64 * param_5, __int64 * param_6, uchar param_7, uchar param_8, uchar param_9, IClfsRequestAsync * param_10, _CLS_LSN * param_11, _CLS_LSN * param_12, _CLS_LSN * param_13, _CLS_LSN * param_14, ulong * param_15, __int64 * param_16)|long __thiscall WriteRestart(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, void * param_2, ulong param_3, __int64 * param_4, __int64 * param_5, __int64 * param_6, uchar param_7, uchar param_8, uchar param_9, IClfsRequestAsync * param_10, _CLS_LSN * param_11, _CLS_LSN * param_12, _CLS_LSN * param_13, _CLS_LSN * param_14, ulong * param_15, __int64 * param_16)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::WriteRestart Called Diff


```diff
--- CClfsLogFcbPhysical::WriteRestart called
+++ CClfsLogFcbPhysical::WriteRestart called
@@ -0,0 +1 @@
+CClfsLogFcbCommon::NotifyObservers
@@ -5,0 +7,2 @@
+ClfsLsnBlockOffset
+ClfsLsnCreate
@@ -7,0 +11 @@
+Feature_2633002298__private_IsEnabledDeviceUsageNoInline
@@ -10,0 +15 @@
+operator!=
```


### CClfsLogFcbPhysical::WriteRestart Diff


```diff
--- CClfsLogFcbPhysical::WriteRestart
+++ CClfsLogFcbPhysical::WriteRestart
@@ -1,240 +1,231 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Type propagation algorithm not settling */
 /* public: virtual long __cdecl CClfsLogFcbPhysical::WriteRestart(struct _FILE_OBJECT * __ptr64,void
    * __ptr64,unsigned long,__int64 const & __ptr64,__int64 & __ptr64,__int64 const &
    __ptr64,unsigned char,unsigned char,unsigned char,struct IClfsRequestAsync * __ptr64,union
    _CLS_LSN const & __ptr64,union _CLS_LSN const & __ptr64,union _CLS_LSN & __ptr64,union _CLS_LSN &
    __ptr64,unsigned long & __ptr64,__int64 & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::WriteRestart
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,void *param_2,ulong param_3,
           __int64 *param_4,__int64 *param_5,__int64 *param_6,uchar param_7,uchar param_8,
           uchar param_9,IClfsRequestAsync *param_10,_CLS_LSN *param_11,_CLS_LSN *param_12,
           _CLS_LSN *param_13,_CLS_LSN *param_14,ulong *param_15,__int64 *param_16)
 
 {
-  _ERESOURCE *p_Var1;
-  _CLS_LSN *p_Var2;
+  _CLS_LSN *p_Var1;
+  CClfsLogFcbPhysical *pCVar2;
   undefined8 uVar3;
   bool bVar4;
   char cVar5;
   uchar uVar6;
-  int iVar7;
-  uint uVar8;
-  long lVar9;
-  undefined8 *puVar10;
+  uint uVar7;
+  long lVar8;
+  int iVar9;
+  ulonglong uVar10;
   _FILE_OBJECT *p_Var11;
-  ulonglong uVar12;
+  undefined8 *puVar12;
   longlong lVar13;
-  undefined8 uVar14;
-  CClfsLogFcbPhysical *pCVar15;
-  CClfsLogFcbPhysical *pCVar16;
-  bool bVar17;
+  bool bVar14;
   void *local_res18;
   ulong local_res20;
   undefined8 local_80;
   undefined8 local_78;
   undefined8 local_70;
   undefined8 local_68;
   undefined8 local_60;
-  undefined8 local_58;
-  __int64 local_50 [2];
-  undefined8 local_40;
+  __int64 local_58 [2];
+  undefined8 local_48 [2];
   
   local_78 = 0xffffffff00000000;
-  local_58 = 0xffffffff00000000;
+  local_60 = 0xffffffff00000000;
+  local_70 = 0;
   local_68 = 0;
-  local_60 = 0;
-  bVar17 = false;
+  bVar14 = false;
   if (param_2 == (void *)0x0) {
     return -0x3ffffff3;
   }
-  bVar4 = bVar17;
+  bVar4 = bVar14;
   if (param_12 != (_CLS_LSN *)0x0) {
     bVar4 = *(longlong *)param_12 == -0x100000000;
   }
   if (bVar4) {
     return -0x3ffffff3;
   }
   *param_15 = 0;
   *param_16 = 0;
-  p_Var1 = (_ERESOURCE *)(this + 200);
   local_res18 = param_2;
   local_res20 = param_3;
-  cVar5 = ExAcquireResourceExclusiveLite(p_Var1,1);
+  cVar5 = ExAcquireResourceExclusiveLite(this + 200,1);
   if ((*(uint *)(this + 0x16c) & 0x1000) == 0) {
-    if (param_9 == '\0') {
-      uVar12 = ClfsLsnLess((uint *)param_11,(uint *)(this + 0x1e8));
-      if ((char)uVar12 != '\0') {
+    uVar10 = Feature_2633002298__private_IsEnabledDeviceUsageNoInline();
+    if (((int)uVar10 == 0) ||
+       (uVar7 = ClfsLsnBlockOffset((uint *)param_11),
+       (ulonglong)uVar7 < *(ulonglong *)(this + 0x2b8))) {
+      if (param_9 == '\0') {
+        uVar10 = ClfsLsnLess((uint *)param_11,(uint *)(this + 0x1e8));
+        if ((char)uVar10 != '\0') {
 LAB_0:
-        iVar7 = -0x3fe5ffe4;
-        goto LAB_1;
-      }
-      if (param_7 != '\0') {
-        bVar4 = bVar17;
+          iVar9 = -0x3fe5ffe4;
+          goto LAB_1;
+        }
+        if (param_7 != '\0') {
+          bVar4 = bVar14;
+          if (param_11 != (_CLS_LSN *)0x0) {
+            bVar4 = *(longlong *)param_11 == -0x100000000;
+          }
+          if ((!bVar4) &&
+             (uVar10 = ClfsLsnLess((uint *)param_11,(uint *)(this + 0x1e0)), (char)uVar10 != '\0'))
+          {
+            p_Var11 = (_FILE_OBJECT *)(**(code **)(*(longlong *)param_10 + 0x38))(param_10);
+            lVar8 = CacheBlock(this,p_Var11,param_11,(ulong *)&local_80);
+            if (lVar8 < 0) goto LAB_0;
+          }
+        }
+      }
+      uVar7 = *(uint *)(this + 0x16c);
+      if ((((uVar7 & 0x100) == 0) && ((uVar7 >> 9 & 1) == 0)) ||
+         (param_10 == (IClfsRequestAsync *)0x0)) {
+        *(uint *)(this + 0x16c) = uVar7 | 0x100;
+        p_Var1 = (_CLS_LSN *)(this + 0x1e8);
+        *(undefined8 *)(this + 0x208) = *(undefined8 *)p_Var1;
+        *(undefined8 *)(this + 0x210) = *(undefined8 *)(this + 0x200);
+        lVar13 = -0x100000000;
         if (param_11 != (_CLS_LSN *)0x0) {
-          bVar4 = *(longlong *)param_11 == -0x100000000;
-        }
-        if ((!bVar4) &&
-           (uVar12 = ClfsLsnLess((uint *)param_11,(uint *)(this + 0x1e0)), (char)uVar12 != '\0')) {
-          p_Var11 = (_FILE_OBJECT *)(**(code **)(*(longlong *)param_10 + 0x38))(param_10);
-          lVar9 = CacheBlock(this,p_Var11,param_11,(ulong *)&local_80);
-          if (lVar9 < 0) goto LAB_0;
-        }
-      }
-    }
-    uVar8 = *(uint *)(this + 0x16c);
-    if ((((uVar8 & 0x100) == 0) && ((uVar8 >> 9 & 1) == 0)) ||
-       (param_10 == (IClfsRequestAsync *)0x0)) {
-      *(uint *)(this + 0x16c) = uVar8 | 0x100;
-      p_Var2 = (_CLS_LSN *)(this + 0x1e8);
-      *(undefined8 *)(this + 0x208) = *(undefined8 *)p_Var2;
-      *(undefined8 *)(this + 0x210) = *(undefined8 *)(this + 0x200);
-      lVar13 = -0x100000000;
-      if (param_11 != (_CLS_LSN *)0x0) {
-        bVar17 = *(longlong *)param_11 == -0x100000000;
-      }
-      if (bVar17) {
-        *(undefined8 *)(this + 0x218) = *(undefined8 *)p_Var2;
+          bVar14 = *(longlong *)param_11 == -0x100000000;
+        }
+        if (bVar14) {
+          *(undefined8 *)(this + 0x218) = *(undefined8 *)p_Var1;
+        }
+        else {
+          uVar6 = operator<=(p_Var1,param_11);
+          if (uVar6 == '\0') {
+            iVar9 = -0x3fe5ffe4;
+            goto LAB_2;
+          }
+          *(undefined8 *)(this + 0x218) = *(undefined8 *)param_11;
+        }
+        *(undefined8 *)(this + 0x220) = *(undefined8 *)param_12;
+        local_58[0] = *param_4;
+        iVar9 = (**(code **)(*(longlong *)this + 0x78))
+                          (this,param_1,local_res18,local_res20,local_58,param_5,param_6,0,param_10,
+                           &CLFS_LSN_NULL,&local_70,param_16,param_14,&local_78,&local_60);
+        if (-1 < iVar9) {
+          local_res18 = (void *)((ulonglong)local_res18 & 0xffffffff00000000);
+          local_58[1] = 0;
+          CClfsLogFcbCommon::Unlock((_ERESOURCE *)(this + 200));
+          iVar9 = (**(code **)(*(longlong *)this + 0xc0))(this,local_58 + 1,0,0,&local_res18);
+          if (iVar9 < 0) {
+            if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+               ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+              WPP_SF_sdD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x3b,
+                         &WPP_d2c63471f7133d4ef9a9fc725428b8f3_Traceguids,
+                         "CClfsLogFcbPhysical::WriteRestart");
+            }
+            iVar9 = -0x3fe5ffd1;
+          }
+          cVar5 = ExAcquireResourceExclusiveLite((_ERESOURCE *)(this + 200),1);
+        }
+        *(undefined8 *)param_13 = *(undefined8 *)param_14;
+        if (iVar9 == 0) {
+          *param_15 = (ulong)local_68;
+          puVar12 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_res18);
+          uVar3 = *puVar12;
+          local_80 = uVar3;
+          uVar6 = operator!=((_CLS_LSN *)(this + 0x218),p_Var1);
+          if (uVar6 != '\0') {
+            *(undefined8 *)p_Var1 = *(undefined8 *)(this + 0x218);
+          }
+          uVar7 = ClfsLsnRecordSequence((uint *)(this + 0x220));
+          uVar10 = ClfsLsnCreate(local_78._4_4_,(uint)local_78 & 0xfffffe00,uVar7);
+          *(ulonglong *)(this + 0x200) = uVar10;
+          if (((byte)this[0x178] & 0x20) == 0) {
+            *(undefined8 *)(this + 0x1f0) = *(undefined8 *)p_Var1;
+          }
+          iVar9 = (**(code **)(*(longlong *)this + 0x70))(this);
+          if (-1 < iVar9) {
+            p_Var11 = (_FILE_OBJECT *)(**(code **)(*(longlong *)param_10 + 0x38))(param_10);
+            WrapContainers(this,p_Var11);
+            uVar6 = '\0';
+            CClfsLogFcbCommon::NotifyObservers
+                      ((CClfsLogFcbCommon *)this,0xcf00,this + 0x218,(void *)0x0);
+            puVar12 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_res18);
+            local_48[0] = *puVar12;
+            uVar7 = (uint)((ulonglong)local_48[0] >> 0x20);
+            if ((local_80._4_4_ <= uVar7) &&
+               ((local_80._4_4_ != uVar7 || ((uint)uVar3 < (uint)local_48[0])))) {
+              PurgeCacheSection(this,(_CLS_LSN *)&local_80,(_CLS_LSN *)local_48,uVar6);
+            }
+          }
+        }
       }
       else {
-        uVar6 = operator<=(p_Var2,param_11);
-        if (uVar6 == '\0') {
-          iVar7 = -0x3fe5ffe4;
-          goto LAB_2;
-        }
-        *(undefined8 *)(this + 0x218) = *(undefined8 *)param_11;
-      }
-      pCVar16 = this + 0x218;
-      *(undefined8 *)(this + 0x220) = *(undefined8 *)param_12;
-      local_50[0] = *param_4;
-      iVar7 = (**(code **)(*(longlong *)this + 0x78))
-                        (this,param_1,local_res18,local_res20,local_50,param_5,param_6,0,param_10,
-                         &CLFS_LSN_NULL,&local_68,param_16,param_14,&local_78,&local_58);
-      if (-1 < iVar7) {
-        local_res18 = (void *)((ulonglong)local_res18 & 0xffffffff00000000);
-        local_50[1] = 0;
-        CClfsLogFcbCommon::Unlock(p_Var1);
-        iVar7 = (**(code **)(*(longlong *)this + 0xc0))(this,local_50 + 1,0,0,&local_res18);
-        if (iVar7 < 0) {
-          if (((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-             ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-            WPP_SF_sdD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x3b,
-                       &WPP_9aee851a2c70379e833bb3a93215b5a4_Traceguids,
-                       "CClfsLogFcbPhysical::WriteRestart");
-          }
-          iVar7 = -0x3fe5ffd1;
-        }
-        cVar5 = ExAcquireResourceExclusiveLite(p_Var1,1);
-      }
-      *(undefined8 *)param_13 = *(undefined8 *)param_14;
-      if (iVar7 == 0) {
-        *param_15 = (ulong)local_60;
-        puVar10 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_res18);
-        uVar3 = *puVar10;
-        if ((pCVar16 == (CClfsLogFcbPhysical *)0x0) || (p_Var2 == (_CLS_LSN *)0x0)) {
-          bVar17 = false;
+        (*(code *)**(undefined8 **)param_10)(param_10);
+        (**(code **)(*(longlong *)param_10 + 0x68))(param_10);
+        iVar9 = (**(code **)(*(longlong *)(this + 0x260) + 0x198))(this + 0x260,param_10);
+        if (iVar9 == 0) {
+          iVar9 = 0x103;
         }
         else {
-          bVar17 = *(longlong *)pCVar16 == *(longlong *)p_Var2;
-        }
-        if (!bVar17) {
-          *(longlong *)p_Var2 = *(longlong *)pCVar16;
-        }
-        local_70 = uVar3;
-        uVar8 = ClfsLsnRecordSequence((uint *)(this + 0x220));
-        uVar14 = 0;
-        local_80 = 0xffffffff00000000;
-        if ((local_78._4_4_ != -1) && ((uVar8 & 0xfffffe00) == 0)) {
-          local_80 = CONCAT44(local_78._4_4_,(uint)local_78 & 0xfffffe00 | uVar8);
-        }
-        *(undefined8 *)(this + 0x200) = local_80;
-        if (((byte)this[0x178] & 0x20) == 0) {
-          *(undefined8 *)(this + 0x1f0) = *(undefined8 *)p_Var2;
-        }
-        iVar7 = (**(code **)(*(longlong *)this + 0x70))(this);
-        if (-1 < iVar7) {
-          p_Var11 = (_FILE_OBJECT *)(**(code **)(*(longlong *)param_10 + 0x38))(param_10);
-          WrapContainers(this,p_Var11);
-          for (pCVar15 = *(CClfsLogFcbPhysical **)(this + 0x1a0); uVar6 = (uchar)uVar14,
-              pCVar15 != this + 0x1a0; pCVar15 = *(CClfsLogFcbPhysical **)pCVar15) {
-            uVar14 = 0;
-            (**(code **)(**(longlong **)(pCVar15 + 0x10) + 0x18))
-                      (*(longlong **)(pCVar15 + 0x10),0xcf00,pCVar16);
-          }
-          puVar10 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_res18);
-          local_40 = *puVar10;
-          uVar8 = (uint)((ulonglong)local_40 >> 0x20);
-          if ((local_70._4_4_ <= uVar8) &&
-             ((local_70._4_4_ != uVar8 || ((uint)uVar3 < (uint)local_40)))) {
-            PurgeCacheSection(this,(_CLS_LSN *)&local_70,(_CLS_LSN *)&local_40,uVar6);
-          }
-        }
-      }
-      lVar13 = -0x100000000;
-      goto LAB_2;
-    }
-    (*(code *)**(undefined8 **)param_10)(param_10);
-    (**(code **)(*(longlong *)param_10 + 0x68))(param_10);
-    iVar7 = (**(code **)(*(longlong *)(this + 0x260) + 0x198))(this + 0x260,param_10);
-    if (iVar7 == 0) {
-      iVar7 = 0x103;
+          (**(code **)(*(longlong *)param_10 + 8))(param_10);
+        }
+      }
     }
     else {
-      (**(code **)(*(longlong *)param_10 + 8))(param_10);
+      iVar9 = -0x3ffffff3;
     }
   }
   else {
-    iVar7 = -0x3fe5ffd5;
+    iVar9 = -0x3fe5ffd5;
     CClfsLogFcbCommon::SetInvalidLogTag((CClfsLogFcbCommon *)this,0xc,-0x3fe5ffd5);
   }
 LAB_1:
   lVar13 = -0x100000000;
 LAB_2:
-  bVar17 = false;
-  if (iVar7 != 0x103) {
-    pCVar16 = this + 0x208;
-    if (iVar7 < 0) {
-      bVar4 = bVar17;
-      if (pCVar16 != (CClfsLogFcbPhysical *)0x0) {
-        bVar4 = lVar13 == *(longlong *)pCVar16;
+  bVar14 = false;
+  if (iVar9 != 0x103) {
+    if (iVar9 < 0) {
+      pCVar2 = this + 0x208;
+      bVar4 = bVar14;
+      if (pCVar2 != (CClfsLogFcbPhysical *)0x0) {
+        bVar4 = lVar13 == *(longlong *)pCVar2;
       }
       if (!bVar4) {
-        *(longlong *)(this + 0x1e8) = *(longlong *)pCVar16;
+        *(longlong *)(this + 0x1e8) = *(longlong *)pCVar2;
         lVar13 = -0x100000000;
       }
-      pCVar15 = this + 0x210;
-      if (pCVar15 != (CClfsLogFcbPhysical *)0x0) {
-        bVar17 = lVar13 == *(longlong *)pCVar15;
-      }
-      if (!bVar17) {
-        *(longlong *)(this + 0x200) = *(longlong *)pCVar15;
+      pCVar2 = this + 0x210;
+      if (pCVar2 != (CClfsLogFcbPhysical *)0x0) {
+        bVar14 = lVar13 == *(longlong *)pCVar2;
+      }
+      if (!bVar14) {
+        *(longlong *)(this + 0x200) = *(longlong *)pCVar2;
         lVar13 = -0x100000000;
       }
       *(longlong *)param_14 = lVar13;
     }
     *(uint *)(this + 0x16c) = *(uint *)(this + 0x16c) & 0xfffffeff;
-    *(longlong *)pCVar16 = -0x100000000;
+    *(undefined8 *)(this + 0x208) = 0xffffffff00000000;
     *(undefined8 *)(this + 0x210) = 0xffffffff00000000;
     *(undefined8 *)(this + 0x218) = 0xffffffff00000000;
     *(undefined8 *)(this + 0x220) = 0xffffffff00000000;
     (**(code **)(*(longlong *)(this + 0x260) + 0x1b0))(this + 0x260,0);
   }
   if (cVar5 != '\0') {
     CClfsLogFcbCommon::Unlock((_ERESOURCE *)(this + 200));
   }
   if (param_8 != '\0') {
-    return iVar7;
-  }
-  if (iVar7 < 0) {
-    return iVar7;
-  }
-  if (iVar7 != 0x103) {
+    return iVar9;
+  }
+  if (iVar9 < 0) {
+    return iVar9;
+  }
+  if (iVar9 != 0x103) {
     (**(code **)(*(longlong *)this + 0xe8))(this);
-    return iVar7;
+    return iVar9;
   }
   return 0x103;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## LsnToCacheOffset

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|LsnToCacheOffset|LsnToCacheOffset|
|fullname|CClfsLogFcbPhysical::LsnToCacheOffset|CClfsLogFcbPhysical::LsnToCacheOffset|
|`refcount`|28|29|
|length|123|123|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AcquireForLazyWrite<br>CClfsLogFcbPhysical::AcquireForReadAhead<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::ReadLogBlock<br>CClfsLogFcbPhysical::ReadLogPagingIo<br>CClfsLogFcbPhysical::SetCacheFileSizes</summary>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AcquireForLazyWrite<br>CClfsLogFcbPhysical::AcquireForReadAhead<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetOwnerPageInsideCachedBuffer<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::ReadLogBlock<br>CClfsLogFcbPhysical::ReadLogPagingIo</summary>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WrapContainers</details>|
|paramcount|2|2|
|address|1c0064630|1c0064630|
|sig|__uint64 __thiscall LsnToCacheOffset(CClfsLogFcbPhysical * this, _CLS_LSN * param_1)|__uint64 __thiscall LsnToCacheOffset(CClfsLogFcbPhysical * this, _CLS_LSN * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### LsnToCacheOffset Calling Diff


```diff
--- CClfsLogFcbPhysical::LsnToCacheOffset calling
+++ CClfsLogFcbPhysical::LsnToCacheOffset calling
@@ -8,0 +9 @@
+CClfsLogFcbPhysical::PurgeCacheSection
```


## ClfsLsnCreate

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|ClfsLsnCreate|ClfsLsnCreate|
|fullname|ClfsLsnCreate|ClfsLsnCreate|
|`refcount`|32|31|
|length|56|56|
|called|||
|calling|<details><summary>Expand for full list:<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsKernelMarshallingContext::ReadNextLogRecord<br>CClfsLogFcbPhysical::AppendLog<br>CClfsLogFcbPhysical::BinarySearchLsn<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetNextBlockLsn<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::PurgeCacheSection</summary>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::SubtractLsnOffset<br>CClfsLogFcbPhysical::TruncateLogDiscardBlocks<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::ReserveAndAppendLog<br>CClfsLogFcbVirtual::WriteRestart<br>CClfsManagedLog::ComputeTargetPhysicalLsnForTailAdvance</details>|<details><summary>Expand for full list:<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsKernelMarshallingContext::ReadNextLogRecord<br>CClfsLogFcbPhysical::AppendLog<br>CClfsLogFcbPhysical::BinarySearchLsn<br>CClfsLogFcbPhysical::CacheBlock<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::GetNextBlockLsn<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::SetCacheFileSizes</summary>CClfsLogFcbPhysical::SubtractLsnOffset<br>CClfsLogFcbPhysical::TruncateLogDiscardBlocks<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WriteRestart<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::ReserveAndAppendLog<br>CClfsLogFcbVirtual::WriteRestart<br>CClfsManagedLog::ComputeTargetPhysicalLsnForTailAdvance</details>|
|paramcount|3|3|
|address|1c0008290|1c0008290|
|sig|ulonglong __fastcall ClfsLsnCreate(int param_1, uint param_2, uint param_3)|ulonglong __fastcall ClfsLsnCreate(int param_1, uint param_2, uint param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## ClfsLsnBlockOffset

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|ClfsLsnBlockOffset|ClfsLsnBlockOffset|
|fullname|ClfsLsnBlockOffset|ClfsLsnBlockOffset|
|`refcount`|45|44|
|length|19|19|
|called|||
|calling|<details><summary>Expand for full list:<br>CClfsFlushElt::GetContainerOffset<br>CClfsKernelMarshallingContext::AdvanceLogBase<br>CClfsKernelMarshallingContext::ReadLogRecord<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsKernelMarshallingContext::ReadNextLogRecord<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::CalculateAvailableFreeSpace<br>CClfsLogFcbPhysical::CompleteAsyncReadBlock<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::GetArchiveDescriptors</summary>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapPhysicalBlockOffset<br>CClfsLogFcbPhysical::PurgeCacheSection<br>CClfsLogFcbPhysical::ReadClientBlock<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ReadLogPagingIo<br>CClfsLogFcbPhysical::ReadOneRawSectorSync<br>CClfsLogFcbPhysical::SetArchiveTail<br>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::SubtractLsnOffset<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WriteOneRawSectorSync<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::ReserveAndAppendLog</details>|<details><summary>Expand for full list:<br>CClfsFlushElt::GetContainerOffset<br>CClfsKernelMarshallingContext::AdvanceLogBase<br>CClfsKernelMarshallingContext::ReadLogRecord<br>CClfsKernelMarshallingContext::ReadMarshalledLogRecord<br>CClfsKernelMarshallingContext::ReadNextLogRecord<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::CalculateAvailableFreeSpace<br>CClfsLogFcbPhysical::CompleteAsyncReadBlock<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::GetArchiveDescriptors</summary>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MapPhysicalBlockOffset<br>CClfsLogFcbPhysical::ReadClientBlock<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ReadLogPagingIo<br>CClfsLogFcbPhysical::ReadOneRawSectorSync<br>CClfsLogFcbPhysical::SetArchiveTail<br>CClfsLogFcbPhysical::SetCacheFileSizes<br>CClfsLogFcbPhysical::SubtractLsnOffset<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::VirtualToPhysicalLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WriteOneRawSectorSync<br>CClfsLogFcbPhysical::WriteRestart<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::ReserveAndAppendLog</details>|
|paramcount|1|1|
|address|1c0006740|1c0006740|
|sig|uint __fastcall ClfsLsnBlockOffset(uint * param_1)|uint __fastcall ClfsLsnBlockOffset(uint * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## operator!=

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|operator!=|operator!=|
|fullname|operator!=|operator!=|
|`refcount`|8|9|
|length|23|23|
|called|||
|`calling`|CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::WriteRestart|CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::CompleteAsyncWriteRestart<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::WriteRestart<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::WriteRestart|
|paramcount|2|2|
|address|1c000b3ec|1c000b3ec|
|sig|uchar __cdecl operator!=(_CLS_LSN * param_1, _CLS_LSN * param_2)|uchar __cdecl operator!=(_CLS_LSN * param_1, _CLS_LSN * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### operator!= Calling Diff


```diff
--- operator!= calling
+++ operator!= calling
@@ -4,0 +5 @@
+CClfsLogFcbPhysical::WriteRestart
```


## wil_details_IsEnabledFallback

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|5|6|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1453614395__private_IsEnabledFallback<br>Feature_2422851896__private_IsEnabledFallback<br>Feature_3228158265__private_IsEnabledFallback<br>Feature_Servicing_ClfsLogInstanceReuseIssue__private_IsEnabledFallback|Feature_1453614395__private_IsEnabledFallback<br>Feature_2422851896__private_IsEnabledFallback<br>Feature_2633002298__private_IsEnabledFallback<br>Feature_3228158265__private_IsEnabledFallback<br>Feature_Servicing_ClfsLogInstanceReuseIssue__private_IsEnabledFallback|
|paramcount|3|3|
|address|1c0011d28|1c0011d28|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -2,0 +3 @@
+Feature_2633002298__private_IsEnabledFallback
```


## NotifyObservers

### Match Info



|Key|clfs-3037.sys - clfs-3470.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|0.97|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-3037.sys|clfs-3470.sys|
| :---: | :---: | :---: |
|name|NotifyObservers|NotifyObservers|
|fullname|CClfsLogFcbCommon::NotifyObservers|CClfsLogFcbCommon::NotifyObservers|
|`refcount`|18|19|
|length|108|108|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|`calling`|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::ObservationContainerAvailable<br>CClfsLogFcbPhysical::ObservationContainerConsumed<br>CClfsLogFcbPhysical::ToggleEphemeral<br>CClfsLogFcbPhysical::UpdateClientBaseLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbVirtual::AdvanceLogBase<br>CClfsLogFcbVirtual::CompleteAsyncAdvanceLogBase<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart<br>CClfsLogFcbVirtual::WriteRestart</summary>`CClfsLogFcbPhysical::DeleteContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapContainers'::__l1::fin$0<br>`CClfsLogFcbVirtual::AdvanceLogBase'::__l1::fin$0<br>`CClfsLogFcbVirtual::CompleteAsyncAdvanceLogBase'::__l1::fin$0<br>`CClfsLogFcbVirtual::CompleteAsyncWriteRestart'::__l1::fin$0<br>`CClfsLogFcbVirtual::WriteRestart'::__l1::fin$0</details>|<details><summary>Expand for full list:<br>CClfsLogFcbPhysical::AdvanceLogBase<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::ObservationContainerAvailable<br>CClfsLogFcbPhysical::ObservationContainerConsumed<br>CClfsLogFcbPhysical::ToggleEphemeral<br>CClfsLogFcbPhysical::UpdateClientBaseLsn<br>CClfsLogFcbPhysical::WrapContainers<br>CClfsLogFcbPhysical::WriteRestart<br>CClfsLogFcbVirtual::AdvanceLogBase<br>CClfsLogFcbVirtual::CompleteAsyncAdvanceLogBase<br>CClfsLogFcbVirtual::CompleteAsyncWriteRestart</summary>CClfsLogFcbVirtual::WriteRestart<br>`CClfsLogFcbPhysical::DeleteContainer'::__l1::fin$0<br>`CClfsLogFcbPhysical::WrapContainers'::__l1::fin$0<br>`CClfsLogFcbVirtual::AdvanceLogBase'::__l1::fin$0<br>`CClfsLogFcbVirtual::CompleteAsyncAdvanceLogBase'::__l1::fin$0<br>`CClfsLogFcbVirtual::CompleteAsyncWriteRestart'::__l1::fin$0<br>`CClfsLogFcbVirtual::WriteRestart'::__l1::fin$0</details>|
|paramcount|4|4|
|address|1c000bdc0|1c000bdc0|
|sig|long __thiscall NotifyObservers(CClfsLogFcbCommon * this, ulong param_1, void * param_2, void * param_3)|long __thiscall NotifyObservers(CClfsLogFcbCommon * this, ulong param_1, void * param_2, void * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### NotifyObservers Calling Diff


```diff
--- CClfsLogFcbCommon::NotifyObservers calling
+++ CClfsLogFcbCommon::NotifyObservers calling
@@ -7,0 +8 @@
+CClfsLogFcbPhysical::WriteRestart
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-15T18:03:47</sub>