# clfs-4061.sys-clfs-4343.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_3984600376__private_IsEnabledDeviceUsageNoInline](#feature_3984600376__private_isenableddeviceusagenoinline)
	* [Feature_3984600376__private_IsEnabledFallback](#feature_3984600376__private_isenabledfallback)
* [Modified](#modified)
	* [CClfsLogFcbPhysical::ReadLogBlock](#cclfslogfcbphysicalreadlogblock)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [RtlLongLongAdd](#rtllonglongadd)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)

# Visual Chart Diff



```mermaid

flowchart LR

CClfsLogFcbPhysicalReadLogBlock-10-old<--Match 75%-->CClfsLogFcbPhysicalReadLogBlock-10-new

subgraph clfs-4343.sys
    CClfsLogFcbPhysicalReadLogBlock-10-new
    subgraph Added
direction LR
Feature_3984600376__private_IsEnabledDeviceUsageNoInline
    Feature_3984600376__private_IsEnabledFallback
end
end

subgraph clfs-4061.sys
    CClfsLogFcbPhysicalReadLogBlock-10-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.9452%
"unmatched_funcs_len" : 2
"matched_funcs_len" : 3646
```



```mermaid
pie showData
    title Matched Function Similarity - 99.9177%
"matched_funcs_with_code_changes_len" : 1
"matched_funcs_with_non_code_changes_len" : 2
"matched_funcs_no_changes_len" : 3643
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj --project-name c32713 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 clfs-4061.sys clfs-4343.sys
```


#### Verbose Args


<details>

```
--old ['clfs-4061.sys'] --new [['clfs-4343.sys']] --engine VersionTrackingDiff --output-path ./out --summary False --project-location ./proj --project-name c32713 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/551584DA86000/Clfs.Sys -O clfs.sys.x64.10.0.26100.4061
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/FC467E8986000/Clfs.Sys -O clfs.sys.x64.10.0.26100.4343
```


## Binary Metadata Diff


```diff
--- clfs-4061.sys Meta
+++ clfs-4343.sys Meta
@@ -1,44 +1,44 @@
-Program Name: clfs-4061.sys
+Program Name: clfs-4343.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
-# of Bytes: 553064
+# of Bytes: 553072
 # of Memory Blocks: 14
-# of Instructions: 98306
-# of Defined Data: 3643
-# of Functions: 1823
-# of Symbols: 13970
+# of Instructions: 98364
+# of Defined Data: 3651
+# of Functions: 1825
+# of Symbols: 13980
 # of Data Types: 467
 # of Data Type Categories: 20
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sat Aug 15 18:04:01 SGT 2026
+Date Created: Sat Aug 15 18:04:05 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-4061.sys
-Executable MD5: 04fe0d515da86b5b9449e21fc6f733c6
-Executable SHA256: 028f8033bb865b33cab1598eefcc8b698ba4d8cee78db3b7ba3657bfb9250772
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-4061.sys?MD5=04fe0d515da86b5b9449e21fc6f733c6
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-4343.sys
+Executable MD5: 1151b276ae75efe9690fe3b45fa7c6b3
+Executable SHA256: 7371fde5bb89adf3f815b8af715d12d862b0f6d9437035ea58b0909b708bf825
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/clfs2025/clfs-4343.sys?MD5=1151b276ae75efe9690fe3b45fa7c6b3
 PDB Age: 1
 PDB File: clfs.pdb
-PDB GUID: 115da712-8864-913e-4aee-9ec1e1a0e68c
+PDB GUID: d501fda6-12a8-ec64-60ab-b89e5fe18b63
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Common Log File System Driver
-PE Property[FileVersion]: 10.0.26100.4061 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.4343 (WinBuild.160101.0800)
 PE Property[InternalName]: clfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Clfs.Sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.4061
+PE Property[ProductVersion]: 10.0.26100.4343
 PE Property[Translation]: 4b00000
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra clfs-4061.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-4061.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-4061.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra clfs-4343.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-4343.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-4343.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|2|
|deleted_funcs_len|0|
|modified_funcs_len|3|
|added_symbols_len|4|
|deleted_symbols_len|1|
|diff_time|4.493160009384155|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 1810, 'ExternalsName': 244, 'ExactBytesFunctionHasher': 8, 'ExactInstructionsFunctionHasher': 4})|
|items_to_process|10|
|diff_types|Counter({'refcount': 2, 'address': 2, 'code': 1, 'length': 1, 'called': 1, 'calling': 1})|
|unmatched_funcs_len|2|
|total_funcs_len|3648|
|matched_funcs_len|3646|
|matched_funcs_with_code_changes_len|1|
|matched_funcs_with_non_code_changes_len|2|
|matched_funcs_no_changes_len|3643|
|match_func_similarity_percent|99.9177%|
|func_match_overall_percent|99.9452%|
|first_matches|Counter({'SymbolsHash': 1810, 'ExactBytesFunctionHasher': 8, 'ExactInstructionsFunctionHasher': 4})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1810
"ExternalsName" : 244
"ExactBytesFunctionHasher" : 8
"ExactInstructionsFunctionHasher" : 4
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1810
"ExactBytesFunctionHasher" : 8
"ExactInstructionsFunctionHasher" : 4
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 2
"deleted_funcs_len" : 0
"modified_funcs_len" : 3
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 4
"deleted_symbols_len" : 1
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_3984600376__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|clfs-4343.sys|
| :---: | :---: |
|name|Feature_3984600376__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_3984600376__private_IsEnabledDeviceUsageNoInline|
|refcount|3|
|length|49|
|called|Feature_3984600376__private_IsEnabledFallback|
|calling|CClfsLogFcbPhysical::ReadLogBlock|
|paramcount|0|
|address|1c0016a80|
|sig|ulonglong __fastcall Feature_3984600376__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3984600376__private_IsEnabledDeviceUsageNoInline
+++ Feature_3984600376__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,17 @@
+
+ulonglong Feature_3984600376__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)Feature_3984600376__private_featureState;
+  if ((Feature_3984600376__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_3984600376__private_IsEnabledFallback(local_res8,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_3984600376__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_3984600376__private_IsEnabledFallback

### Function Meta



|Key|clfs-4343.sys|
| :---: | :---: |
|name|Feature_3984600376__private_IsEnabledFallback|
|fullname|Feature_3984600376__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_3984600376__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|1c0016ab8|
|sig|undefined __fastcall Feature_3984600376__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3984600376__private_IsEnabledFallback
+++ Feature_3984600376__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_3984600376__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_3984600376__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## CClfsLogFcbPhysical::ReadLogBlock

### Match Info



|Key|clfs-4061.sys - clfs-4343.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.43|
|i_ratio|0.32|
|m_ratio|0.96|
|b_ratio|0.75|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-4061.sys|clfs-4343.sys|
| :---: | :---: | :---: |
|name|ReadLogBlock|ReadLogBlock|
|fullname|CClfsLogFcbPhysical::ReadLogBlock|CClfsLogFcbPhysical::ReadLogBlock|
|refcount|4|4|
|`length`|2271|2408|
|`called`|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::IsMainLocked<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::RawSectorAlign<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ValidateLogBlock<br>ClfsCheckAndResetReadInProgress<br>ClfsDecodeBlock<br>NTOSKRNL.EXE::CcCopyRead</summary>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::KeBugCheckEx<br>RtlLongLongAdd<br>_CLFS_READ_BUFFER::GetAddress<br>_guard_dispatch_icall<br>memset<br>operator>=</details>|<details><summary>Expand for full list:<br>CClfsLogFcbCommon::IsMainLocked<br>CClfsLogFcbCommon::SetInvalidLogTag<br>CClfsLogFcbPhysical::AddLsnOffset<br>CClfsLogFcbPhysical::GetNextOwnerPageLsn<br>CClfsLogFcbPhysical::LsnToCacheOffset<br>CClfsLogFcbPhysical::RawSectorAlign<br>CClfsLogFcbPhysical::ReadLog<br>CClfsLogFcbPhysical::ValidateLogBlock<br>ClfsCheckAndResetReadInProgress<br>ClfsDecodeBlock<br>Feature_3984600376__private_IsEnabledDeviceUsageNoInline</summary>NTOSKRNL.EXE::CcCopyRead<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::KeBugCheckEx<br>RtlLongLongAdd<br>_CLFS_READ_BUFFER::GetAddress<br>_guard_dispatch_icall<br>memset<br>operator>=</details>|
|calling|CClfsLogFcbPhysical::ReadLogBlock`adjustor{608}'|CClfsLogFcbPhysical::ReadLogBlock`adjustor{608}'|
|paramcount|10|10|
|address|1c000ef40|1c000ef40|
|sig|long __thiscall ReadLogBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, _CLFS_READ_BUFFER * param_4, ulong param_5, IClfsRequestAsync * param_6, ulong param_7, _CLS_LSN * param_8, ulong * param_9)|long __thiscall ReadLogBlock(CClfsLogFcbPhysical * this, _FILE_OBJECT * param_1, _CLS_LSN * param_2, ulong param_3, _CLFS_READ_BUFFER * param_4, ulong param_5, IClfsRequestAsync * param_6, ulong param_7, _CLS_LSN * param_8, ulong * param_9)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsLogFcbPhysical::ReadLogBlock Called Diff


```diff
--- CClfsLogFcbPhysical::ReadLogBlock called
+++ CClfsLogFcbPhysical::ReadLogBlock called
@@ -10,0 +11 @@
+Feature_3984600376__private_IsEnabledDeviceUsageNoInline
```


### CClfsLogFcbPhysical::ReadLogBlock Diff


```diff
--- CClfsLogFcbPhysical::ReadLogBlock
+++ CClfsLogFcbPhysical::ReadLogBlock
@@ -1,324 +1,345 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: virtual long __cdecl CClfsLogFcbPhysical::ReadLogBlock(struct _FILE_OBJECT *
    __ptr64,union _CLS_LSN const & __ptr64,unsigned long,struct _CLFS_READ_BUFFER const &
    __ptr64,unsigned long,struct IClfsRequestAsync * __ptr64,unsigned long,union _CLS_LSN &
    __ptr64,unsigned long & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsLogFcbPhysical::ReadLogBlock
           (CClfsLogFcbPhysical *this,_FILE_OBJECT *param_1,_CLS_LSN *param_2,ulong param_3,
           _CLFS_READ_BUFFER *param_4,ulong param_5,IClfsRequestAsync *param_6,ulong param_7,
           _CLS_LSN *param_8,ulong *param_9)
 
 {
   bool bVar1;
-  bool bVar2;
+  uchar *puVar2;
   uchar uVar3;
   char cVar4;
   int iVar5;
   uint uVar6;
   long lVar7;
   ulong uVar8;
   int iVar9;
   _CLFS_LOG_BLOCK_HEADER *p_Var10;
   longlong *plVar11;
   undefined8 *puVar12;
-  IClfsRequestAsync *pIVar13;
-  __uint64 _Var14;
-  ulonglong uVar15;
-  longlong lVar16;
-  ulonglong uVar17;
-  ushort uVar18;
-  uchar *puVar19;
-  ulong uVar20;
-  uchar *in_stack_fffffffffffffed8;
-  char local_108;
-  int local_104;
-  ulong local_100;
-  ulong local_f8;
-  int local_f4;
-  uint local_f0;
-  uint local_ec;
+  ulonglong uVar13;
+  IClfsRequestAsync *pIVar14;
+  __uint64 _Var15;
+  ulonglong uVar16;
+  ulong uVar17;
+  longlong lVar18;
+  ushort uVar19;
+  _CLS_LSN *p_Var20;
+  uchar *in_stack_fffffffffffffec8;
+  char local_118;
+  int local_114;
+  ulong local_10c;
+  ulong local_104;
+  int local_100;
+  uint local_fc;
+  uint local_f8;
+  uchar *local_f0;
   uint local_e8;
   ulong local_e4;
-  uchar *local_e0;
+  __uint64 local_e0;
   undefined8 local_d8;
   ulonglong local_d0;
-  __uint64 local_c8;
+  __int64 local_c8;
   uint local_c0;
   uint local_bc;
-  __int64 local_b8;
-  _CLS_LSN *local_b0;
+  _CLS_LSN *local_b8;
+  _CLFS_LOG_BLOCK_HEADER *local_b0;
   undefined8 local_a8;
   ulonglong local_a0;
   _CLS_LSN *local_98;
-  _CLFS_LOG_BLOCK_HEADER *local_90;
-  undefined8 local_88;
-  undefined8 uStack_80;
-  undefined8 local_78;
-  _CLS_LSN local_70 [8];
-  undefined8 local_68;
-  __uint64 local_60;
-  ulonglong local_58;
+  undefined8 local_90;
+  undefined8 uStack_88;
+  undefined8 local_80;
+  _CLS_LSN local_78 [8];
+  undefined8 local_70;
+  __uint64 local_68;
+  ulonglong local_60;
+  _CLS_LSN local_58 [8];
   _CLS_LSN local_50 [8];
-  _CLS_LSN local_48 [8];
-  _CLS_LSN local_40 [8];
+  _CLS_LSN local_48 [16];
   
-  lVar16 = -0x100000000;
+  lVar18 = -0x100000000;
   local_d8 = -0x100000000;
   local_a8 = 0;
   local_a0 = 0;
-  local_c8 = 0;
+  local_e0 = 0;
+  local_114 = 0;
+  local_e4 = 0;
   local_104 = 0;
-  local_e4 = 0;
-  local_f8 = 0;
-  local_f4 = 0;
-  local_108 = '\0';
-  local_ec = *(uint *)(*(longlong *)(this + 0x2c8) + 0x90);
-  if (((local_ec - 1 < 0x1000) && ((local_ec & 0x1ff) == 0)) &&
-     ((int)(0x1000 % (ulonglong)local_ec) == 0)) {
+  local_100 = 0;
+  local_118 = '\0';
+  local_f8 = *(uint *)(*(longlong *)(this + 0x2c8) + 0x90);
+  if (((local_f8 - 1 < 0x1000) && ((local_f8 & 0x1ff) == 0)) &&
+     ((int)(0x1000 % (ulonglong)local_f8) == 0)) {
     *param_9 = 0;
     *(undefined8 *)param_8 = 0xffffffff00000000;
-    local_88 = *(undefined8 *)param_4;
-    uStack_80 = *(undefined8 *)(param_4 + 8);
-    local_78 = *(undefined8 *)(param_4 + 0x10);
+    local_90 = *(undefined8 *)param_4;
+    uStack_88 = *(undefined8 *)(param_4 + 8);
+    local_80 = *(undefined8 *)(param_4 + 0x10);
     if (param_3 - 1 < 2) {
-      local_c0 = local_ec;
+      local_c0 = local_f8;
       p_Var10 = (_CLFS_LOG_BLOCK_HEADER *)_CLFS_READ_BUFFER::GetAddress(param_4);
-      local_90 = p_Var10;
+      local_b0 = p_Var10;
       if (p_Var10 == (_CLFS_LOG_BLOCK_HEADER *)0x0) {
-        local_104 = -0x3fffff66;
-        local_108 = '\0';
+        local_114 = -0x3fffff66;
+        local_118 = '\0';
         iVar5 = -0x3fffff66;
       }
       else {
-        local_e0 = _CLFS_READ_BUFFER::GetAddress((_CLFS_READ_BUFFER *)&local_88);
-        if (local_e0 == (uchar *)0x0) {
-          local_104 = -0x3fffff66;
-          local_108 = '\0';
+        local_f0 = _CLFS_READ_BUFFER::GetAddress((_CLFS_READ_BUFFER *)&local_90);
+        if (local_f0 == (uchar *)0x0) {
+          local_114 = -0x3fffff66;
+          local_118 = '\0';
           iVar5 = -0x3fffff66;
         }
         else {
           local_e8 = param_7 & 1;
           local_bc = local_e8;
-          if (((local_e8 != 0) || (*(longlong *)(param_1 + 0x30) != 0)) ||
-             (local_104 = (*(code *)**(undefined8 **)this)(this,param_1,this), iVar5 = local_104,
-             -1 < local_104)) {
+          if (((local_e8 == 0) && (*(longlong *)(param_1 + 0x30) == 0)) &&
+             (local_114 = (*(code *)**(undefined8 **)this)(this,param_1,this), local_114 < 0)) {
+            local_118 = '\0';
+            iVar5 = local_114;
+          }
+          else {
             uVar3 = CClfsLogFcbCommon::IsMainLocked((CClfsLogFcbCommon *)this);
             if (uVar3 == '\0') {
-              local_108 = ExAcquireResourceSharedLite(this + 200,1);
+              local_118 = ExAcquireResourceSharedLite(this + 200,1);
             }
             cVar4 = (**(code **)(*(longlong *)this + 0x138))(this);
             if ((cVar4 == '\0') || ((param_7 & 8) == 0)) {
               if ((*(uint *)(this + 0x16c) >> 0xc & 1) == 0) {
-                puVar12 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_b0);
-                local_b0 = (_CLS_LSN *)*puVar12;
+                puVar12 = (undefined8 *)(**(code **)(*(longlong *)this + 0x160))(this,&local_b8);
+                local_b8 = (_CLS_LSN *)*puVar12;
                 if (((param_2 == (_CLS_LSN *)0x0) ||
-                    (uVar6 = (uint)((ulonglong)local_b0 >> 0x20), uVar6 < *(uint *)(param_2 + 4)))
-                   || ((*(uint *)(param_2 + 4) == uVar6 && ((uint)local_b0 <= *(uint *)param_2)))) {
-                  local_b0 = (_CLS_LSN *)(this + 0x1e0);
-                  local_98 = local_b0;
-                  uVar3 = operator>=(param_2,local_b0);
+                    (uVar6 = (uint)((ulonglong)local_b8 >> 0x20), uVar6 < *(uint *)(param_2 + 4)))
+                   || ((*(uint *)(param_2 + 4) == uVar6 && ((uint)local_b8 <= *(uint *)param_2)))) {
+                  p_Var20 = (_CLS_LSN *)(this + 0x1e0);
+                  local_b8 = p_Var20;
+                  local_98 = p_Var20;
+                  uVar3 = operator>=(param_2,p_Var20);
                   if (uVar3 == '\0') {
                     cVar4 = (**(code **)(*(longlong *)this + 0x138))(this);
                     if (cVar4 != '\0') {
                       plVar11 = (longlong *)
-                                GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_b8,(ulong)param_2);
-                      lVar16 = *plVar11;
-                      local_d8 = lVar16;
+                                GetNextOwnerPageLsn(this,(_CLS_LSN *)&local_c8,(ulong)param_2);
+                      lVar18 = *plVar11;
+                      local_d8 = lVar18;
                     }
                     if (param_6 != (IClfsRequestAsync *)0x0) {
-                      local_f4 = (**(code **)(*(longlong *)param_6 + 0x10))(param_6);
+                      local_100 = (**(code **)(*(longlong *)param_6 + 0x10))(param_6);
                     }
                     *param_9 = 0;
-                    uVar17 = *(ulonglong *)param_2;
-                    local_100 = param_5;
-                    uVar15 = uVar17 & 0xffffffff;
-                    iVar5 = local_104;
+                    uVar13 = *(ulonglong *)param_2;
+                    local_10c = param_5;
+                    uVar16 = uVar13 & 0xffffffff;
+                    iVar5 = local_114;
                     while( true ) {
-                      uVar3 = (uchar)in_stack_fffffffffffffed8;
-                      local_d0 = uVar17;
-                      if ((local_100 <= *param_9) || (local_98 == (_CLS_LSN *)0x0)) break;
-                      uVar6 = (uint)(uVar17 >> 0x20);
-                      if ((*(uint *)(local_98 + 4) < uVar6) ||
-                         ((uVar6 == *(uint *)(local_98 + 4) && (*(uint *)local_98 <= (uint)uVar15)))
-                         ) break;
-                      local_f0 = local_100 - *param_9;
-                      uVar15 = (ulonglong)local_f0;
+                      uVar3 = (uchar)in_stack_fffffffffffffec8;
+                      local_d0 = uVar13;
+                      if ((local_10c <= *param_9) || (p_Var20 == (_CLS_LSN *)0x0)) break;
+                      uVar6 = (uint)(uVar13 >> 0x20);
+                      if ((*(uint *)(p_Var20 + 4) < uVar6) ||
+                         ((uVar6 == *(uint *)(p_Var20 + 4) && (*(uint *)p_Var20 <= (uint)uVar16))))
+                      break;
+                      local_fc = local_10c - *param_9;
+                      uVar16 = (ulonglong)local_fc;
                       cVar4 = (**(code **)(*(longlong *)this + 0x138))(this);
                       if (cVar4 != '\0') {
-                        puVar12 = (undefined8 *)AddLsnOffset(this,local_70,(ulong)&local_d0);
-                        local_68 = *puVar12;
-                        uVar6 = (uint)((ulonglong)local_68 >> 0x20);
+                        puVar12 = (undefined8 *)AddLsnOffset(this,local_78,(ulong)&local_d0);
+                        local_70 = *puVar12;
+                        uVar6 = (uint)((ulonglong)local_70 >> 0x20);
                         if ((local_d8._4_4_ <= uVar6) &&
-                           ((uVar6 != local_d8._4_4_ || ((uint)lVar16 < (uint)local_68)))) {
-                          local_f0 = ((uint)lVar16 & 0xfffffe00) - ((uint)uVar17 & 0xfffffe00);
-                          uVar15 = (ulonglong)local_f0;
+                           ((uVar6 != local_d8._4_4_ || ((uint)lVar18 < (uint)local_70)))) {
+                          local_fc = ((uint)lVar18 & 0xfffffe00) - ((uint)uVar13 & 0xfffffe00);
+                          uVar16 = (ulonglong)local_fc;
                         }
                       }
+                      uVar13 = Feature_3984600376__private_IsEnabledDeviceUsageNoInline();
+                      if (((int)uVar13 != 0) && ((int)(uVar16 % (ulonglong)local_f8) != 0)) {
+                        local_114 = -0x3ffffff3;
+                        iVar5 = local_114;
+                        goto LAB_0;
+                      }
                       bVar1 = false;
-                      bVar2 = false;
-                      if (((param_3 & 1) != 0) && (bVar2 = false, *param_9 == 0)) {
-                        uVar15 = (ulonglong)local_ec;
-                        local_f0 = local_ec;
+                      if (((param_3 & 1) != 0) && (*param_9 == 0)) {
+                        uVar16 = (ulonglong)local_f8;
+                        local_fc = local_f8;
                         bVar1 = true;
-                        bVar2 = true;
                       }
                       if (local_e8 == 0) {
-                        _Var14 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
-                        local_c8 = _Var14;
-                        local_60 = LsnToCacheOffset(this,local_b0);
-                        in_stack_fffffffffffffed8 = local_e0;
-                        if ((-1 < (longlong)_Var14) && (-1 < (longlong)local_60)) {
-                          if ((longlong)local_60 < (longlong)(uVar15 + _Var14)) {
-                            uVar15 = local_60 - _Var14;
-                            local_58 = uVar15;
-                            if ((int)(uVar15 >> 0x20) != 0) goto LAB_0;
-                            local_f0 = (uint)uVar15;
-                            memset(local_e0 + (uVar15 & 0xffffffff),0,
-                                   (ulonglong)((local_100 - local_f0) - *param_9));
-                            _Var14 = local_c8;
+                        _Var15 = LsnToCacheOffset(this,(_CLS_LSN *)&local_d0);
+                        local_e0 = _Var15;
+                        local_68 = LsnToCacheOffset(this,local_98);
+                        if (((longlong)_Var15 < 0) || ((longlong)local_68 < 0)) {
+LAB_1:
+                          local_114 = -0x3fe5fff3;
+                          iVar5 = local_114;
+                        }
+                        else {
+                          if ((longlong)local_68 < (longlong)(uVar16 + _Var15)) {
+                            uVar16 = local_68 - _Var15;
+                            local_60 = uVar16;
+                            if ((int)(uVar16 >> 0x20) != 0) goto LAB_1;
+                            local_fc = (uint)uVar16;
+                            memset(local_f0 + (uVar16 & 0xffffffff),0,
+                                   (ulonglong)((local_10c - local_fc) - *param_9));
                           }
-                          local_b8 = 0;
-                          if (((-1 < (longlong)_Var14) &&
-                              (lVar7 = RtlLongLongAdd(_Var14,uVar15 & 0xffffffff,&local_b8),
-                              -1 < lVar7)) && (local_b8 <= *(longlong *)(this + 0x50))) {
-                            cVar4 = CcCopyRead(param_1,&local_c8,uVar15 & 0xffffffff,1,
-                                               in_stack_fffffffffffffed8,&local_a8);
-                            uVar17 = local_a0;
-                            uVar20 = local_f8;
-                            bVar1 = bVar2;
+                          local_c8 = 0;
+                          uVar13 = Feature_3984600376__private_IsEnabledDeviceUsageNoInline();
+                          if ((int)uVar13 == 0) {
+                            if (((-1 < (longlong)local_e0) &&
+                                (lVar7 = RtlLongLongAdd(local_e0,uVar16 & 0xffffffff,&local_c8),
+                                -1 < lVar7)) && (local_c8 <= *(longlong *)(this + 0x50)))
+                            goto LAB_2;
+                          }
+                          else if (((-1 < (longlong)local_e0) &&
+                                   ((uint)uVar16 <= local_10c - *param_9)) &&
+                                  ((lVar7 = RtlLongLongAdd(local_e0,uVar16 & 0xffffffff,&local_c8),
+                                   -1 < lVar7 && (local_c8 <= *(longlong *)(this + 0x50))))) {
+LAB_2:
+                            in_stack_fffffffffffffec8 = local_f0;
+                            cVar4 = CcCopyRead(param_1,&local_e0,uVar16 & 0xffffffff,1,local_f0,
+                                               &local_a8);
+                            uVar13 = local_a0;
+                            uVar17 = local_104;
                             if (cVar4 != '\0') {
                               if ((int)local_a8 != 0) {
                     /* WARNING: Subroutine does not return */
                                 KeBugCheckEx(0xc1f5,0x3e,(longlong)(int)local_a8,this,0);
                               }
-                              local_104 = 0;
-                              uVar20 = (uint)local_a0;
-                              local_f8 = (uint)local_a0;
-                              puVar12 = (undefined8 *)AddLsnOffset(this,local_50,(ulong)&local_d0);
+                              local_114 = 0;
+                              uVar17 = (uint)local_a0;
+                              local_104 = (uint)local_a0;
+                              puVar12 = (undefined8 *)AddLsnOffset(this,local_58,(ulong)&local_d0);
                               *(undefined8 *)param_8 = *puVar12;
                               iVar5 = 0;
                               if (param_6 != (IClfsRequestAsync *)0x0) {
                                 (**(code **)(*(longlong *)param_6 + 0x58))
-                                          (param_6,0,uVar17 & 0xffffffff);
+                                          (param_6,0,uVar13 & 0xffffffff);
+                                iVar5 = 0;
                               }
                             }
-                            goto LAB_1;
+                            goto LAB_3;
                           }
+                          local_114 = -0x3fe5fff3;
+                          iVar5 = -0x3fe5fff3;
                         }
-LAB_0:
-                        local_104 = -0x3fe5fff3;
-                        iVar5 = local_104;
-                        goto LAB_2;
-                      }
-                      pIVar13 = param_6;
+                        goto LAB_0;
+                      }
+                      pIVar14 = param_6;
                       if (bVar1) {
-                        pIVar13 = (IClfsRequestAsync *)0x0;
-                      }
-                      in_stack_fffffffffffffed8 = (uchar *)0x3;
-                      local_104 = ReadLog(this,(_CLS_LSN *)&local_d0,(_CLFS_READ_BUFFER *)&local_88,
-                                          (uint)uVar15 >> 9,3,pIVar13,param_8,&local_f8);
-                      uVar20 = local_f8;
-                      iVar5 = local_104;
+                        pIVar14 = (IClfsRequestAsync *)0x0;
+                      }
+                      in_stack_fffffffffffffec8 = (uchar *)0x3;
+                      local_114 = ReadLog(this,(_CLS_LSN *)&local_d0,(_CLFS_READ_BUFFER *)&local_90,
+                                          (uint)uVar16 >> 9,3,pIVar14,param_8,&local_104);
+                      uVar17 = local_104;
+                      iVar5 = local_114;
                       if ((bVar1) && (param_6 != (IClfsRequestAsync *)0x0)) {
-                        (**(code **)(*(longlong *)param_6 + 0x58))(param_6,local_104,local_f8);
-                      }
-LAB_1:
-                      uVar3 = (uchar)in_stack_fffffffffffffed8;
+                        (**(code **)(*(longlong *)param_6 + 0x58))(param_6,local_114,local_104);
+                      }
+LAB_3:
+                      puVar2 = local_f0;
+                      uVar3 = (uchar)in_stack_fffffffffffffec8;
                       if ((iVar5 == -0x3fffffef) || (iVar5 == -0x3fe5ffed)) break;
                       if ((bVar1) && (iVar5 == 0)) {
-                        uVar18 = *(ushort *)(local_e0 + 4);
-                        puVar19 = local_e0;
-                        uVar8 = RawSectorAlign(this,(uint)uVar18 << 9);
-                        if ((*puVar19 != '\0') &&
-                           ((uVar18 != 0 && (param_5 = local_100, uVar8 < local_100)))) {
+                        uVar19 = *(ushort *)(local_f0 + 4);
+                        uVar8 = RawSectorAlign(this,(uint)uVar19 << 9);
+                        if ((*puVar2 != '\0') &&
+                           ((uVar19 != 0 && (param_5 = local_10c, uVar8 < local_10c)))) {
                           param_5 = uVar8;
-                          local_100 = uVar8;
+                          local_10c = uVar8;
                         }
                       }
-                      *param_9 = *param_9 + uVar20;
-                      local_78 = CONCAT44(local_78._4_4_,(int)local_78 + uVar20);
-                      local_e0 = local_e0 + uVar20;
-                      if (iVar5 < 0) goto LAB_2;
+                      *param_9 = *param_9 + uVar17;
+                      local_80 = CONCAT44(local_80._4_4_,(int)local_80 + uVar17);
+                      local_f0 = puVar2 + uVar17;
+                      if (iVar5 < 0) goto LAB_0;
                       cVar4 = (**(code **)(*(longlong *)this + 0x138))(this);
-                      if ((cVar4 != '\0') && (*(longlong *)param_8 == lVar16)) {
-                        puVar12 = (undefined8 *)AddLsnOffset(this,local_48,(ulong)param_8);
+                      if ((cVar4 != '\0') && (*(longlong *)param_8 == lVar18)) {
+                        puVar12 = (undefined8 *)AddLsnOffset(this,local_50,(ulong)param_8);
                         *(undefined8 *)param_8 = *puVar12;
-                        plVar11 = (longlong *)AddLsnOffset(this,local_40,(ulong)&local_d8);
-                        lVar16 = *plVar11;
-                        local_d8 = lVar16;
-                      }
-                      uVar17 = *(ulonglong *)param_8;
-                      uVar15 = uVar17;
-                    }
-                    if (local_108 != '\0') {
+                        plVar11 = (longlong *)AddLsnOffset(this,local_48,(ulong)&local_d8);
+                        lVar18 = *plVar11;
+                        local_d8 = lVar18;
+                      }
+                      uVar13 = *(ulonglong *)param_8;
+                      uVar16 = uVar13;
+                      p_Var20 = local_b8;
+                    }
+                    if (local_118 != '\0') {
                       ExReleaseResourceForThreadLite(this + 200,SystemReserved1[0xf]);
-                      local_108 = '\0';
-                      local_100 = param_5;
-                      iVar5 = local_104;
-                    }
-                    p_Var10 = local_90;
+                      local_118 = '\0';
+                      local_10c = param_5;
+                      iVar5 = local_114;
+                    }
+                    p_Var10 = local_b0;
                     if (((param_6 == (IClfsRequestAsync *)0x0) && (-1 < iVar5)) &&
-                       (local_104 = ValidateLogBlock(this,param_2,local_90,local_100,uVar3,'\x04',
-                                                     &local_e4), iVar5 = local_104, -1 < local_104))
+                       (local_114 = ValidateLogBlock(this,param_2,local_b0,local_10c,uVar3,'\x04',
+                                                     &local_e4), iVar5 = local_114, -1 < local_114))
                     {
-                      local_104 = ClfsDecodeBlock(p_Var10,(uint)*(ushort *)(p_Var10 + 4),
+                      local_114 = ClfsDecodeBlock(p_Var10,(uint)*(ushort *)(p_Var10 + 4),
                                                   (uchar)p_Var10[2],'\x04',&local_e4);
-                      iVar5 = local_104;
+                      iVar5 = local_114;
                     }
                   }
                   else {
                     if ((param_7 & 0x10) == 0) {
-                      ClfsCheckAndResetReadInProgress((longlong)p_Var10,param_5);
-                    }
-                    local_104 = -0x3fffffef;
+                      ClfsCheckAndResetReadInProgress((longlong)local_b0,param_5);
+                    }
+                    local_114 = -0x3fffffef;
                     iVar5 = -0x3fffffef;
                   }
                 }
                 else {
                   if ((param_7 & 0x10) == 0) {
                     ClfsCheckAndResetReadInProgress((longlong)p_Var10,param_5);
                   }
-                  local_104 = -0x3fe5ffed;
+                  local_114 = -0x3fe5ffed;
                   iVar5 = -0x3fe5ffed;
                 }
               }
               else {
-                local_104 = -0x3fe5ffd5;
+                local_114 = -0x3fe5ffd5;
                 CClfsLogFcbCommon::SetInvalidLogTag((CClfsLogFcbCommon *)this,0xf,-0x3fe5ffd5);
                 iVar5 = -0x3fe5ffd5;
               }
             }
             else {
-              local_104 = -0x3fe5ffe2;
+              local_114 = -0x3fe5ffe2;
               iVar5 = -0x3fe5ffe2;
             }
           }
         }
       }
-LAB_2:
-      if (local_108 != '\0') {
+LAB_0:
+      if (local_118 != '\0') {
         ExReleaseResourceForThreadLite(this + 200,SystemReserved1[0xf]);
-        iVar5 = local_104;
+        iVar5 = local_114;
       }
       if ((iVar5 < 0) && (*param_9 = 0, param_6 != (IClfsRequestAsync *)0x0)) {
         (**(code **)(*(longlong *)param_6 + 0x58))(param_6,iVar5,0);
       }
-      if (((local_f4 != 0) &&
+      if (((local_100 != 0) &&
           (iVar9 = (**(code **)(*(longlong *)param_6 + 0x18))(param_6), iVar9 != 0)) && (-1 < iVar5)
          ) {
         iVar5 = 0x103;
       }
     }
     else {
       iVar5 = -0x3fffff45;
     }
   }
   else {
     iVar5 = -0x3fffff68;
   }
   return iVar5;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## RtlLongLongAdd

### Match Info



|Key|clfs-4061.sys - clfs-4343.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-4061.sys|clfs-4343.sys|
| :---: | :---: | :---: |
|name|RtlLongLongAdd|RtlLongLongAdd|
|fullname|RtlLongLongAdd|RtlLongLongAdd|
|`refcount`|3|4|
|length|59|59|
|called|||
|calling|CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::ReadLogBlock|CClfsLogFcbPhysical::MapCacheData<br>CClfsLogFcbPhysical::ReadLogBlock|
|paramcount|3|3|
|`address`|1c00166d4|1c0016764|
|sig|long __cdecl RtlLongLongAdd(__int64 param_1, __int64 param_2, __int64 * param_3)|long __cdecl RtlLongLongAdd(__int64 param_1, __int64 param_2, __int64 * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

## wil_details_IsEnabledFallback

### Match Info



|Key|clfs-4061.sys - clfs-4343.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-4061.sys|clfs-4343.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|6|7|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1119414585__private_IsEnabledFallback<br>Feature_2633002298__private_IsEnabledFallback<br>Feature_2931883321__private_IsEnabledFallback<br>Feature_2985090360__private_IsEnabledFallback<br>Feature_3233339707__private_IsEnabledFallback|Feature_1119414585__private_IsEnabledFallback<br>Feature_2633002298__private_IsEnabledFallback<br>Feature_2931883321__private_IsEnabledFallback<br>Feature_2985090360__private_IsEnabledFallback<br>Feature_3233339707__private_IsEnabledFallback<br>Feature_3984600376__private_IsEnabledFallback|
|paramcount|3|3|
|`address`|1c0011e10|1c0011ea0|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -5,0 +6 @@
+Feature_3984600376__private_IsEnabledFallback
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-15T18:04:51</sub>