# clfs.sys 22000.832 vs 22000.978 (CVE-2022-37969, manual pair)

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [RtlStringLengthWorkerW](#rtlstringlengthworkerw)
* [Added](#added)
	* [Feature_Servicing_40191887__private_IsEnabled](#feature_servicing_40191887__private_isenabled)
	* [Feature_Servicing_41154977__private_IsEnabled](#feature_servicing_41154977__private_isenabled)
	* [ULongLongAdd](#ulonglongadd)
	* [wil_details_FeatureReporting_IncrementOpportunityInCache](#wil_details_featurereporting_incrementopportunityincache)
	* [wil_details_FeatureReporting_IncrementUsageInCache](#wil_details_featurereporting_incrementusageincache)
	* [wil_details_FeatureReporting_RecordUsageInCache](#wil_details_featurereporting_recordusageincache)
	* [wil_details_FeatureReporting_ReportUsageToService](#wil_details_featurereporting_reportusagetoservice)
	* [wil_details_FeatureReporting_ReportUsageToServiceDirect](#wil_details_featurereporting_reportusagetoservicedirect)
	* [wil_details_FeatureStateCache_GetCachedFeatureEnabledState](#wil_details_featurestatecache_getcachedfeatureenabledstate)
	* [wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState](#wil_details_featurestatecache_reevaluatecachedfeatureenabledstate)
	* [wil_details_GetCurrentFeatureEnabledState](#wil_details_getcurrentfeatureenabledstate)
	* [wil_details_MapReportingKind](#wil_details_mapreportingkind)
	* [WPP_SF_sd](#wpp_sf_sd)
	* [WPP_SF_sdLD](#wpp_sf_sdld)
	* [CClfsBaseFile::AllocOffsetNode](#cclfsbasefileallocoffsetnode)
	* [CClfsBaseFile::CompareGenericoffsets](#cclfsbasefilecomparegenericoffsets)
	* [CClfsBaseFile::ValidateCheckifWithinSymbolZone](#cclfsbasefilevalidatecheckifwithinsymbolzone)
	* [CClfsBaseFile::ValidateClientContextOffsets](#cclfsbasefilevalidateclientcontextoffsets)
	* [CClfsBaseFile::ValidateClientSymTblOffsets](#cclfsbasefilevalidateclientsymtbloffsets)
	* [CClfsBaseFile::ValidateContainerContextOffsets](#cclfsbasefilevalidatecontainercontextoffsets)
	* [CClfsBaseFile::ValidateContainerSymTblOffsets](#cclfsbasefilevalidatecontainersymtbloffsets)
	* [CClfsBaseFile::ValidateOffsets](#cclfsbasefilevalidateoffsets)
	* [CClfsBaseFile::ValidateProcessQNode](#cclfsbasefilevalidateprocessqnode)
	* [CClfsBaseFile::ValidateTraverseTree](#cclfsbasefilevalidatetraversetree)
	* [wil_RtlStagingConfig_QueryFeatureState](#wil_rtlstagingconfig_queryfeaturestate)
	* [NTOSKRNL.EXE::RtlEnumerateGenericTableAvl](#ntoskrnlexertlenumerategenerictableavl)
	* [NTOSKRNL.EXE::RtlNotifyFeatureUsage](#ntoskrnlexertlnotifyfeatureusage)
* [Modified](#modified)
	* [CClfsRequest::DeleteContainer](#cclfsrequestdeletecontainer)
	* [CClfsBaseFile::GetSymbol](#cclfsbasefilegetsymbol)
	* [RtlStringCbLengthW](#rtlstringcblengthw)
	* [CClfsRequest::AllocContainer](#cclfsrequestalloccontainer)
	* [CClfsBaseFilePersisted::LoadContainerQ](#cclfsbasefilepersistedloadcontainerq)
	* [CClfsBaseFilePersisted::CreateImage](#cclfsbasefilepersistedcreateimage)
	* [CClfsBaseFile::GetSymbol](#cclfsbasefilegetsymbol)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [__GSHandlerCheck](#__gshandlercheck)
	* [OffsetToAddr](#offsettoaddr)
	* [AcquireForReadAheadCallback](#acquireforreadaheadcallback)
	* [NTOSKRNL.EXE::RtlQueryFeatureConfiguration](#ntoskrnlexertlqueryfeatureconfiguration)
	* [NTOSKRNL.EXE::RtlInitializeGenericTableAvl](#ntoskrnlexertlinitializegenerictableavl)
	* [NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl](#ntoskrnlexertldeleteelementgenerictableavl)
	* [__security_check_cookie](#__security_check_cookie)
	* [NTOSKRNL.EXE::RtlLookupElementGenericTableAvl](#ntoskrnlexertllookupelementgenerictableavl)
	* [ContainerCount](#containercount)
	* [NTOSKRNL.EXE::ExFreePoolWithTag](#ntoskrnlexeexfreepoolwithtag)
	* [NTOSKRNL.EXE::RtlInsertElementGenericTableAvl](#ntoskrnlexertlinsertelementgenerictableavl)
	* [NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl](#ntoskrnlexertlnumbergenerictableelementsavl)
	* [ClientCount](#clientcount)
	* [NTOSKRNL.EXE::ExAllocatePoolWithTag](#ntoskrnlexeexallocatepoolwithtag)

# Visual Chart Diff



```mermaid

flowchart LR

CClfsRequestDeleteContainer-1-old<--Match 92%-->CClfsRequestDeleteContainer-1-new
CClfsBaseFileGetSymbol-4-old<--Match 91%-->CClfsBaseFileGetSymbol-4-new
RtlStringCbLengthW-3-old<--Match 63%-->RtlStringCbLengthW-3-new
CClfsRequestAllocContainer-1-old<--Match 92%-->CClfsRequestAllocContainer-1-new
CClfsBaseFilePersistedLoadContainerQ-9-old<--Match 72%-->CClfsBaseFilePersistedLoadContainerQ-9-new
CClfsBaseFilePersistedCreateImage-8-old<--Match 97%-->CClfsBaseFilePersistedCreateImage-8-new
CClfsBaseFileGetSymbol-4-old<--Match 98%-->CClfsBaseFileGetSymbol-4-new

subgraph clfs-10.0.22000.978.sys
    CClfsRequestDeleteContainer-1-new
CClfsBaseFileGetSymbol-4-new
RtlStringCbLengthW-3-new
CClfsRequestAllocContainer-1-new
CClfsBaseFilePersistedLoadContainerQ-9-new
CClfsBaseFilePersistedCreateImage-8-new
CClfsBaseFileGetSymbol-4-new
    subgraph Added
direction LR
Feature_Servicing_40191887__private_IsEnabled
    Feature_Servicing_41154977__private_IsEnabled
    ULongLongAdd
    wil_details_FeatureReporting_IncrementOpportunityInCache
    wil_details_FeatureReporting_IncrementUsageInCache
    wil_details_FeatureReporting_RecordUsageInCache
    wil_details_FeatureReporting_ReportUsageToService
    wil_details_FeatureReporting_ReportUsageToServiceDirect
    wil_details_FeatureStateCache_GetCachedFeatureEnabledState
    wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
    wil_details_GetCurrentFeatureEnabledState
    wil_details_MapReportingKind
    WPP_SF_sd
    WPP_SF_sdLD
    CClfsBaseFile-AllocOffsetNode
    CClfsBaseFile-CompareGenericoffsets
    CClfsBaseFile-ValidateCheckifWithinSymbolZone
    CClfsBaseFile-ValidateClientContextOffsets
    CClfsBaseFile-ValidateClientSymTblOffsets
    CClfsBaseFile-ValidateContainerContextOffsets
    CClfsBaseFile-ValidateContainerSymTblOffsets
    CClfsBaseFile-ValidateOffsets
    CClfsBaseFile-ValidateProcessQNode
    CClfsBaseFile-ValidateTraverseTree
    wil_RtlStagingConfig_QueryFeatureState
    NTOSKRNLEXE-RtlEnumerateGenericTableAvl
    NTOSKRNLEXE-RtlNotifyFeatureUsage
    2_more_added_funcs_omitted
end
end

subgraph clfs-10.0.22000.832.sys
    CClfsRequestDeleteContainer-1-old
CClfsBaseFileGetSymbol-4-old
RtlStringCbLengthW-3-old
CClfsRequestAllocContainer-1-old
CClfsBaseFilePersistedLoadContainerQ-9-old
CClfsBaseFilePersistedCreateImage-8-old
CClfsBaseFileGetSymbol-4-old
    subgraph Deleted
direction LR
RtlStringLengthWorkerW
end
end

```


```mermaid
pie showData
    title Function Matches - 99.0141%
"unmatched_funcs_len" : 28
"matched_funcs_len" : 2812
```



```mermaid
pie showData
    title Matched Function Similarity - 99.1465%
"matched_funcs_with_code_changes_len" : 7
"matched_funcs_with_non_code_changes_len" : 17
"matched_funcs_no_changes_len" : 2788
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2022-37969\ghidra_projects --project-name CVE-2022-37969 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2022-37969\symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 --md-title clfs.sys 22000.832 vs 22000.978 (CVE-2022-37969, manual pair) clfs-10.0.22000.832.sys clfs-10.0.22000.978.sys
```


#### Verbose Args


<details>

```
--old ['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2022-37969\\clfs-10.0.22000.832.sys'] --new [['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2022-37969\\clfs-10.0.22000.978.sys']] --engine VersionTrackingDiff --output-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2022-37969\output --summary False --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2022-37969\ghidra_projects --project-name CVE-2022-37969 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2022-37969\symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title clfs.sys 22000.832 vs 22000.978 (CVE-2022-37969, manual pair)
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/DC07D9616B000/Clfs.Sys -O clfs.sys.x64.10.0.22000.832
wget https://msdl.microsoft.com/download/symbols/Clfs.Sys/FD40E0C76D000/Clfs.Sys -O clfs.sys.x64.10.0.22000.1042
```


## Binary Metadata Diff


```diff
--- clfs-10.0.22000.832.sys Meta
+++ clfs-10.0.22000.978.sys Meta
@@ -1,44 +1,44 @@
-Program Name: clfs-10.0.22000.832.sys
+Program Name: clfs-10.0.22000.978.sys
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
-# of Bytes: 444316
+# of Bytes: 452604
 # of Memory Blocks: 13
-# of Instructions: 74654
-# of Defined Data: 7747
-# of Functions: 1407
-# of Symbols: 10570
-# of Data Types: 410
+# of Instructions: 76430
+# of Defined Data: 7848
+# of Functions: 1433
+# of Symbols: 10832
+# of Data Types: 427
 # of Data Type Categories: 19
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Tue Jul 28 08:24:42 SGT 2026
+Date Created: Tue Jul 28 08:24:48 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2022-37969/clfs-10.0.22000.832.sys
-Executable MD5: 78f0c768c60884ea20640595f01c3613
-Executable SHA256: 34cfa3482bc7859bf39a565cac3cd5542945b3d67d286706f069a501acd73f59
-FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2022-37969/clfs-10.0.22000.832.sys?MD5=78f0c768c60884ea20640595f01c3613
+Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2022-37969/clfs-10.0.22000.978.sys
+Executable MD5: 6f57698b3d09b1043e7ae4f3b4ebf81a
+Executable SHA256: b14babc26df1bd405e3597d1271225614b6ad64a9e5605e046fa939aeda4dded
+FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2022-37969/clfs-10.0.22000.978.sys?MD5=6f57698b3d09b1043e7ae4f3b4ebf81a
 PDB Age: 1
 PDB File: clfs.pdb
-PDB GUID: 03b05c2d-b699-e7ae-7bc9-134867cd9133
+PDB GUID: 28689d49-e00f-1891-150d-e173bfaecad1
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Common Log File System Driver
-PE Property[FileVersion]: 10.0.22000.832 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.22000.1042 (WinBuild.160101.0800)
 PE Property[InternalName]: clfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: Clfs.Sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.22000.832
+PE Property[ProductVersion]: 10.0.22000.1042
 PE Property[Translation]: 4b00000
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra clfs-10.0.22000.832.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-10.0.22000.832.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-10.0.22000.832.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra clfs-10.0.22000.978.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra clfs-10.0.22000.978.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra clfs-10.0.22000.978.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|27|
|deleted_funcs_len|1|
|modified_funcs_len|24|
|added_symbols_len|14|
|deleted_symbols_len|1|
|diff_time|19.541829586029053|
|deleted_strings_len|0|
|added_strings_len|5|
|match_types|Counter({'SymbolsHash': 1372, 'ExternalsName': 185, 'ExactInstructionsFunctionHasher': 30, 'StructuralGraphHash': 4, 'ExactBytesFunctionHasher': 1, 'BSIM': 1})|
|items_to_process|67|
|diff_types|Counter({'refcount': 19, 'address': 19, 'calling': 17, 'length': 8, 'code': 7, 'called': 4, 'name': 1, 'fullname': 1, 'sig': 1, 'parent': 1})|
|unmatched_funcs_len|28|
|total_funcs_len|2840|
|matched_funcs_len|2812|
|matched_funcs_with_code_changes_len|7|
|matched_funcs_with_non_code_changes_len|17|
|matched_funcs_no_changes_len|2788|
|match_func_similarity_percent|99.1465%|
|func_match_overall_percent|99.0141%|
|first_matches|Counter({'SymbolsHash': 1372, 'ExactInstructionsFunctionHasher': 30, 'StructuralGraphHash': 4, 'ExactBytesFunctionHasher': 1, 'BSIM': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1372
"ExternalsName" : 185
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 30
"BSIM" : 1
"StructuralGraphHash" : 4
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1372
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 30
"BSIM" : 1
"StructuralGraphHash" : 4
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 27
"deleted_funcs_len" : 1
"modified_funcs_len" : 24
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 14
"deleted_symbols_len" : 1
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 5
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1,5 @@
+s_CClfsBaseFile::ValidateClientCo
+s_CClfsBaseFile::ValidateContaine
+s_CClfsBaseFile::ValidateOffsets
+s_CClfsBaseFile::ValidateProcessQ
+s_CClfsBaseFile::ValidateTraverse

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_CClfsBaseFile::ValidateContaine|2|ValidateContainerContextOffsets|
|s_CClfsBaseFile::ValidateProcessQ|3|WPP_SF_sd|
|s_CClfsBaseFile::ValidateTraverse|1|ValidateTraverseTree|
|s_CClfsBaseFile::ValidateOffsets|2|ValidateOffsets|
|s_CClfsBaseFile::ValidateClientCo|2|ValidateClientContextOffsets|

# Deleted

## RtlStringLengthWorkerW

### Function Meta



|Key|clfs-10.0.22000.832.sys|
| :---: | :---: |
|name|RtlStringLengthWorkerW|
|fullname|RtlStringLengthWorkerW|
|refcount|4|
|length|63|
|called||
|calling|CClfsRequest::AllocContainer<br>CClfsRequest::DeleteContainer<br>RtlStringCbLengthW|
|paramcount|3|
|address|1c00103bc|
|sig|uint __fastcall RtlStringLengthWorkerW(short * param_1, longlong param_2, longlong * param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- RtlStringLengthWorkerW
+++ RtlStringLengthWorkerW
@@ -1,22 +0,0 @@
-
-uint RtlStringLengthWorkerW(short *param_1,longlong param_2,longlong *param_3)
-
-{
-  uint uVar1;
-  longlong lVar2;
-  
-  lVar2 = param_2;
-  for (; (lVar2 != 0 && (*param_1 != 0)); param_1 = param_1 + 1) {
-    lVar2 = lVar2 + -1;
-  }
-  uVar1 = ~-(uint)(lVar2 != 0) & 0xc000000d;
-  if (param_3 != (longlong *)0x0) {
-    if (lVar2 != 0) {
-      *param_3 = param_2 - lVar2;
-      return uVar1;
-    }
-    *param_3 = 0;
-  }
-  return uVar1;
-}
-

```


# Added

## Feature_Servicing_40191887__private_IsEnabled

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|Feature_Servicing_40191887__private_IsEnabled|
|fullname|Feature_Servicing_40191887__private_IsEnabled|
|refcount|2|
|length|94|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|calling|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|0|
|address|1c000c86c|
|sig|int __cdecl Feature_Servicing_40191887__private_IsEnabled(void)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- Feature_Servicing_40191887__private_IsEnabled
+++ Feature_Servicing_40191887__private_IsEnabled
@@ -0,0 +1,24 @@
+
+/* int __cdecl Feature_Servicing_40191887__private_IsEnabled(void) */
+
+int __cdecl Feature_Servicing_40191887__private_IsEnabled(void)
+
+{
+  uint uVar1;
+  uint uVar2;
+  wil_ReportingKind in_stack_ffffffffffffffe8;
+  __uint64 in_stack_fffffffffffffff0;
+  
+  uVar1 = wil_details_FeatureStateCache_GetCachedFeatureEnabledState
+                    ((wil_details_FeatureStateCache *)
+                     &Feature_Servicing_40191887__private_featureState,
+                     (wil_details_FeatureDescriptor *)&wil_details_featureDescriptors_a);
+  uVar2 = uVar1 >> 3 & 1;
+  wil_details_FeatureReporting_ReportUsageToService
+            ((wil_details_FeatureReportingCache *)&Feature_Servicing_40191887__private_reporting,
+             0x265478f,uVar1 >> 8 & 1,uVar1 >> 9 & 1,
+             (FEATURE_LOGGED_TRAITS *)&Feature_Servicing_40191887_logged_traits,uVar2,
+             in_stack_ffffffffffffffe8,in_stack_fffffffffffffff0);
+  return uVar2;
+}
+

```


## Feature_Servicing_41154977__private_IsEnabled

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|Feature_Servicing_41154977__private_IsEnabled|
|fullname|Feature_Servicing_41154977__private_IsEnabled|
|refcount|2|
|length|94|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|calling|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|0|
|address|1c000c8d4|
|sig|int __cdecl Feature_Servicing_41154977__private_IsEnabled(void)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- Feature_Servicing_41154977__private_IsEnabled
+++ Feature_Servicing_41154977__private_IsEnabled
@@ -0,0 +1,25 @@
+
+/* int __cdecl Feature_Servicing_41154977__private_IsEnabled(void) */
+
+int __cdecl Feature_Servicing_41154977__private_IsEnabled(void)
+
+{
+  uint uVar1;
+  uint uVar2;
+  wil_ReportingKind in_stack_ffffffffffffffe8;
+  __uint64 in_stack_fffffffffffffff0;
+  
+  uVar1 = wil_details_FeatureStateCache_GetCachedFeatureEnabledState
+                    ((wil_details_FeatureStateCache *)
+                     &Feature_Servicing_41154977__private_featureState,
+                     (wil_details_FeatureDescriptor *)
+                     &Feature_Servicing_41154977__private_descriptor);
+  uVar2 = uVar1 >> 3 & 1;
+  wil_details_FeatureReporting_ReportUsageToService
+            ((wil_details_FeatureReportingCache *)&Feature_Servicing_41154977__private_reporting,
+             0x273f9a1,uVar1 >> 8 & 1,uVar1 >> 9 & 1,
+             (FEATURE_LOGGED_TRAITS *)&Feature_Servicing_40191887_logged_traits,uVar2,
+             in_stack_ffffffffffffffe8,in_stack_fffffffffffffff0);
+  return uVar2;
+}
+

```


## ULongLongAdd

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ULongLongAdd|
|fullname|ULongLongAdd|
|refcount|3|
|length|26|
|called||
|calling|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|3|
|address|1c000c960|
|sig|long __cdecl ULongLongAdd(__uint64 param_1, __uint64 param_2, __uint64 * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- ULongLongAdd
+++ ULongLongAdd
@@ -0,0 +1,18 @@
+
+/* long __cdecl ULongLongAdd(unsigned __int64,unsigned __int64,unsigned __int64 * __ptr64) */
+
+long __cdecl ULongLongAdd(__uint64 param_1,__uint64 param_2,__uint64 *param_3)
+
+{
+  ulonglong uVar1;
+  ulonglong uVar2;
+  
+  uVar1 = param_1 + param_2;
+  uVar2 = 0xffffffffffffffff;
+  if (uVar1 >= param_1) {
+    uVar2 = uVar1;
+  }
+  *param_3 = uVar2;
+  return -(uint)(uVar1 < param_1) & 0x80070216;
+}
+

```


## wil_details_FeatureReporting_IncrementOpportunityInCache

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureReporting_IncrementOpportunityInCache|
|fullname|wil_details_FeatureReporting_IncrementOpportunityInCache|
|refcount|2|
|length|222|
|called||
|calling|wil_details_FeatureReporting_RecordUsageInCache|
|paramcount|4|
|address|1c000c984|
|sig|void __cdecl wil_details_FeatureReporting_IncrementOpportunityInCache(wil_details_FeatureReportingCache * param_1, wil_details_ServiceReportingKind param_2, uint param_3, wil_details_RecordUsageResult * param_4)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureReporting_IncrementOpportunityInCache
+++ wil_details_FeatureReporting_IncrementOpportunityInCache
@@ -0,0 +1,61 @@
+
+/* void __cdecl wil_details_FeatureReporting_IncrementOpportunityInCache(struct
+   wil_details_FeatureReportingCache * __ptr64,enum wil_details_ServiceReportingKind,unsigned
+   int,struct wil_details_RecordUsageResult * __ptr64) */
+
+void __cdecl
+wil_details_FeatureReporting_IncrementOpportunityInCache
+          (wil_details_FeatureReportingCache *param_1,wil_details_ServiceReportingKind param_2,
+          uint param_3,wil_details_RecordUsageResult *param_4)
+
+{
+  uint uVar1;
+  undefined4 uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  bool bVar6;
+  
+  uVar3 = *(uint *)param_1;
+  do {
+    uVar5 = uVar3;
+    *(undefined4 *)(param_4 + 4) = 0;
+    uVar1 = uVar5 | 1;
+    if ((uVar5 & 0x400000) >> 0x16 != (uint)(param_2 == 5)) {
+      uVar3 = (uVar5 & 0x3f8000) >> 0xf;
+      if (uVar3 != 0) {
+        *(uint *)(param_4 + 4) = uVar3;
+        uVar2 = 5;
+        if (param_2 != 1) {
+          uVar2 = 1;
+        }
+        uVar1 = uVar5 & 0xffc07fff | 1;
+        *(undefined4 *)(param_4 + 8) = uVar2;
+      }
+      uVar3 = 0;
+      if (param_2 == 5) {
+        uVar3 = 0x400000;
+      }
+      uVar1 = uVar3 | uVar1 & 0xffbfffff;
+    }
+    uVar3 = uVar1 >> 0xf & 0x7f;
+    uVar4 = uVar3 + 1;
+    if ((0x7f < uVar4) || (uVar4 < (uVar1 >> 0xf & 0x7f))) {
+      uVar4 = 1;
+      *(wil_details_ServiceReportingKind *)(param_4 + 8) = param_2;
+      *(uint *)(param_4 + 4) = uVar3;
+    }
+    LOCK();
+    uVar3 = *(uint *)param_1;
+    bVar6 = uVar5 == uVar3;
+    if (bVar6) {
+      *(uint *)param_1 = (uVar4 << 0xf ^ uVar1) & 0x3f8000 ^ uVar1;
+      uVar3 = uVar5;
+    }
+    UNLOCK();
+  } while (!bVar6);
+  *(undefined4 *)(param_4 + 0x10) = 0;
+  *(uint *)param_4 = ~uVar5 & 1;
+  return;
+}
+

```


## wil_details_FeatureReporting_IncrementUsageInCache

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureReporting_IncrementUsageInCache|
|fullname|wil_details_FeatureReporting_IncrementUsageInCache|
|refcount|2|
|length|228|
|called||
|calling|wil_details_FeatureReporting_RecordUsageInCache|
|paramcount|4|
|address|1c000ca6c|
|sig|void __cdecl wil_details_FeatureReporting_IncrementUsageInCache(wil_details_FeatureReportingCache * param_1, wil_details_ServiceReportingKind param_2, uint param_3, wil_details_RecordUsageResult * param_4)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureReporting_IncrementUsageInCache
+++ wil_details_FeatureReporting_IncrementUsageInCache
@@ -0,0 +1,56 @@
+
+/* void __cdecl wil_details_FeatureReporting_IncrementUsageInCache(struct
+   wil_details_FeatureReportingCache * __ptr64,enum wil_details_ServiceReportingKind,unsigned
+   int,struct wil_details_RecordUsageResult * __ptr64) */
+
+void __cdecl
+wil_details_FeatureReporting_IncrementUsageInCache
+          (wil_details_FeatureReportingCache *param_1,wil_details_ServiceReportingKind param_2,
+          uint param_3,wil_details_RecordUsageResult *param_4)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  bool bVar5;
+  
+  uVar4 = *(uint *)param_1;
+  do {
+    uVar3 = uVar4;
+    *(undefined4 *)(param_4 + 4) = 0;
+    uVar1 = uVar3 | 1;
+    if ((uVar3 & 0x4000) >> 0xe != (uint)(param_2 == 4)) {
+      uVar4 = (uVar3 & 0x3fe0) >> 5;
+      if (uVar4 != 0) {
+        *(uint *)(param_4 + 4) = uVar4;
+        *(uint *)(param_4 + 8) = ~-(uint)(param_2 != 0) & 4;
+        uVar1 = uVar3 & 0xffffc01f | 1;
+      }
+      uVar4 = 0;
+      if (param_2 == 4) {
+        uVar4 = 0x4000;
+      }
+      uVar1 = uVar4 | uVar1 & 0xffffbfff;
+    }
+    uVar4 = uVar1 >> 5 & 0x1ff;
+    uVar2 = uVar4 + 1;
+    if ((0x1ff < uVar2) || (uVar2 < (uVar1 >> 5 & 0x1ff))) {
+      uVar2 = 1;
+      *(wil_details_ServiceReportingKind *)(param_4 + 8) = param_2;
+      *(uint *)(param_4 + 4) = uVar4;
+    }
+    LOCK();
+    uVar4 = *(uint *)param_1;
+    bVar5 = uVar3 == uVar4;
+    if (bVar5) {
+      *(uint *)param_1 = (uVar2 << 5 ^ uVar1) & 0x3fe0 ^ uVar1;
+      uVar4 = uVar3;
+    }
+    UNLOCK();
+  } while (!bVar5);
+  *(undefined4 *)(param_4 + 0x10) = 0;
+  *(uint *)param_4 = ~uVar3 & 1;
+  return;
+}
+

```


## wil_details_FeatureReporting_RecordUsageInCache

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureReporting_RecordUsageInCache|
|fullname|wil_details_FeatureReporting_RecordUsageInCache|
|refcount|2|
|length|323|
|called|wil_details_FeatureReporting_IncrementOpportunityInCache<br>wil_details_FeatureReporting_IncrementUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|paramcount|4|
|address|1c000cb58|
|sig|wil_details_RecordUsageResult __cdecl wil_details_FeatureReporting_RecordUsageInCache(wil_details_FeatureReportingCache * param_1, wil_details_ServiceReportingKind param_2, uint param_3, uint param_4)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureReporting_RecordUsageInCache
+++ wil_details_FeatureReporting_RecordUsageInCache
@@ -0,0 +1,97 @@
+
+/* struct wil_details_RecordUsageResult __cdecl
+   wil_details_FeatureReporting_RecordUsageInCache(struct wil_details_FeatureReportingCache *
+   __ptr64,enum wil_details_ServiceReportingKind,unsigned int,unsigned int) */
+
+wil_details_FeatureReportingCache * __cdecl
+wil_details_FeatureReporting_RecordUsageInCache
+          (wil_details_FeatureReportingCache *param_1,wil_details_ServiceReportingKind param_2,
+          uint param_3,uint param_4)
+
+{
+  uint uVar1;
+  uint uVar2;
+  undefined4 in_register_00000014;
+  wil_details_FeatureReportingCache *pwVar3;
+  uint uVar4;
+  uint uVar5;
+  bool bVar6;
+  
+  pwVar3 = (wil_details_FeatureReportingCache *)CONCAT44(in_register_00000014,param_2);
+  *(undefined8 *)param_1 = 0;
+  *(undefined8 *)(param_1 + 8) = 0;
+  *(undefined8 *)(param_1 + 0x10) = 0;
+  if (param_3 == 0) {
+LAB_1c000cc82:
+    wil_details_FeatureReporting_IncrementUsageInCache
+              (pwVar3,param_3,param_3,(wil_details_RecordUsageResult *)param_1);
+  }
+  else {
+    if (param_3 == 1) {
+LAB_1c000cc75:
+      wil_details_FeatureReporting_IncrementOpportunityInCache
+                (pwVar3,param_3,param_3,(wil_details_RecordUsageResult *)param_1);
+      return param_1;
+    }
+    uVar5 = 0;
+    if ((int)param_3 < 2) {
+LAB_1c000cc17:
+      uVar4 = param_3 - 0x140;
+      if (uVar4 < 0x40) {
+        uVar1 = *(uint *)(pwVar3 + 4);
+        do {
+          if (((uVar1 & 0x10) == 0) || (uVar2 = 1, (uVar1 >> 5 & 0x3f) != uVar4)) {
+            uVar2 = uVar5;
+          }
+          *(uint *)(param_1 + 0x10) = uVar2;
+          LOCK();
+          uVar2 = *(uint *)(pwVar3 + 4);
+          bVar6 = uVar1 == uVar2;
+          if (bVar6) {
+            *(uint *)(pwVar3 + 4) = uVar1 & 0xfffff81f | (uVar4 & 0x3f) << 5 | 0x10;
+            uVar2 = uVar1;
+          }
+          uVar1 = uVar2;
+          UNLOCK();
+        } while (!bVar6);
+      }
+      *(uint *)(param_1 + 8) = param_3;
+      *(undefined4 *)(param_1 + 4) = 1;
+      *(undefined4 *)(param_1 + 0xc) = 0;
+      return param_1;
+    }
+    if (3 < (int)param_3) {
+      if (param_3 == 4) goto LAB_1c000cc82;
+      if (param_3 == 5) goto LAB_1c000cc75;
+      if (1 < param_3 - 6) goto LAB_1c000cc17;
+    }
+    if (param_3 == 2) {
+      uVar5 = 2;
+    }
+    else if (param_3 == 3) {
+      uVar5 = 8;
+    }
+    else if (param_3 == 6) {
+      uVar5 = 4;
+    }
+    else if (param_3 == 7) {
+      uVar5 = 0x10;
+    }
+    uVar4 = *(uint *)pwVar3;
+    do {
+      LOCK();
+      uVar1 = *(uint *)pwVar3;
+      bVar6 = uVar4 == uVar1;
+      if (bVar6) {
+        *(uint *)pwVar3 = uVar4 | uVar5 | 1;
+        uVar1 = uVar4;
+      }
+      uVar4 = uVar1;
+      UNLOCK();
+    } while (!bVar6);
+    *(uint *)param_1 = ~uVar4 & 1;
+    *(uint *)(param_1 + 0x10) = (uint)((uVar5 & uVar4) == uVar5);
+  }
+  return param_1;
+}
+

```


## wil_details_FeatureReporting_ReportUsageToService

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToService|
|fullname|wil_details_FeatureReporting_ReportUsageToService|
|refcount|3|
|length|135|
|called|_guard_dispatch_icall<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|
|calling|Feature_Servicing_40191887__private_IsEnabled<br>Feature_Servicing_41154977__private_IsEnabled|
|paramcount|8|
|address|1c000cca4|
|sig|void __cdecl wil_details_FeatureReporting_ReportUsageToService(wil_details_FeatureReportingCache * param_1, uint param_2, int param_3, int param_4, FEATURE_LOGGED_TRAITS * param_5, int param_6, wil_ReportingKind param_7, __uint64 param_8)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureReporting_ReportUsageToService
+++ wil_details_FeatureReporting_ReportUsageToService
@@ -0,0 +1,34 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* void __cdecl wil_details_FeatureReporting_ReportUsageToService(struct
+   wil_details_FeatureReportingCache * __ptr64,unsigned int,int,int,struct FEATURE_LOGGED_TRAITS
+   const * __ptr64,int,enum wil_ReportingKind,unsigned __int64) */
+
+void __cdecl
+wil_details_FeatureReporting_ReportUsageToService
+          (wil_details_FeatureReportingCache *param_1,uint param_2,int param_3,int param_4,
+          FEATURE_LOGGED_TRAITS *param_5,int param_6,wil_ReportingKind param_7,__uint64 param_8)
+
+{
+  wil_details_ServiceReportingKind wVar1;
+  int iVar2;
+  uint in_stack_ffffffffffffffd0;
+  undefined1 in_stack_ffffffffffffffd8;
+  undefined7 in_stack_ffffffffffffffd9;
+  
+  param_7 = 3;
+  wVar1 = wil_details_MapReportingKind(3,param_6);
+  iVar2 = wil_details_FeatureReporting_ReportUsageToServiceDirect
+                    (param_1,param_2,param_3,param_4,wVar1,in_stack_ffffffffffffffd0,
+                     CONCAT71(in_stack_ffffffffffffffd9,in_stack_ffffffffffffffd8));
+  if ((iVar2 != 0) &&
+     (g_wil_details_pfnFeatureLoggingHook !=
+      (_func_void_uint_FEATURE_LOGGED_TRAITS_ptr_FEATURE_ERROR_ptr_int_wil_ReportingKind_ptr_wil_VariantReportingKind_ptr_uchar___uint64
+       *)0x0)) {
+    (*g_wil_details_pfnFeatureLoggingHook)
+              (param_2,param_5,(FEATURE_ERROR *)0x0,param_6,&param_7,(wil_VariantReportingKind *)0x0
+               ,'\0',1);
+  }
+  return;
+}
+

```


## wil_details_FeatureReporting_ReportUsageToServiceDirect

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|fullname|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|refcount|2|
|length|237|
|called|NTOSKRNL.EXE::RtlNotifyFeatureUsage<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|7|
|address|1c000cd34|
|sig|int __cdecl wil_details_FeatureReporting_ReportUsageToServiceDirect(wil_details_FeatureReportingCache * param_1, uint param_2, int param_3, int param_4, wil_details_ServiceReportingKind param_5, uint param_6, __uint64 param_7)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect
@@ -0,0 +1,51 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* int __cdecl wil_details_FeatureReporting_ReportUsageToServiceDirect(struct
+   wil_details_FeatureReportingCache * __ptr64,unsigned int,int,int,enum
+   wil_details_ServiceReportingKind,unsigned int,unsigned __int64) */
+
+int __cdecl
+wil_details_FeatureReporting_ReportUsageToServiceDirect
+          (wil_details_FeatureReportingCache *param_1,uint param_2,int param_3,int param_4,
+          wil_details_ServiceReportingKind param_5,uint param_6,__uint64 param_7)
+
+{
+  uint6 uVar1;
+  undefined4 *puVar2;
+  undefined1 auStack_98 [32];
+  undefined4 *local_78;
+  undefined8 local_68;
+  wil_details_FeatureReportingCache local_60 [24];
+  undefined4 local_48;
+  undefined4 uStack_44;
+  undefined4 uStack_40;
+  undefined4 uStack_3c;
+  undefined8 local_38;
+  ulonglong local_30;
+  
+  local_30 = __security_cookie ^ (ulonglong)auStack_98;
+  puVar2 = (undefined4 *)
+           wil_details_FeatureReporting_RecordUsageInCache
+                     (local_60,(wil_details_ServiceReportingKind)param_1,param_5,param_4);
+  local_48 = *puVar2;
+  uStack_44 = puVar2[1];
+  uStack_40 = puVar2[2];
+  uStack_3c = puVar2[3];
+  local_38 = *(undefined8 *)(puVar2 + 4);
+  if (g_wil_details_recordFeatureUsage != 0) {
+    local_78 = &local_48;
+    (*(code *)g_wil_details_recordFeatureUsage)(param_2,param_5,1,param_1);
+  }
+  if ((param_3 != 0) && (param_5 != 0xfe)) {
+    local_68._0_6_ = CONCAT24((short)param_5,param_2);
+    uVar1 = (uint6)local_68;
+    local_68 = (ulonglong)(uint6)local_68;
+    if (param_4 != 0) {
+      local_68 = CONCAT26(1,uVar1);
+    }
+    RtlNotifyFeatureUsage(&local_68);
+  }
+  return (int)((int)local_38 == 0);
+}
+

```


## wil_details_FeatureStateCache_GetCachedFeatureEnabledState

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|fullname|wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|refcount|4|
|length|45|
|called|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|calling|Feature_Servicing_40191887__private_IsEnabled<br>Feature_Servicing_41154977__private_IsEnabled<br>wil_details_GetCurrentFeatureEnabledState|
|paramcount|2|
|address|1c000ce28|
|sig|wil_details_FeatureStateCache __cdecl wil_details_FeatureStateCache_GetCachedFeatureEnabledState(wil_details_FeatureStateCache * param_1, wil_details_FeatureDescriptor * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureStateCache_GetCachedFeatureEnabledState
+++ wil_details_FeatureStateCache_GetCachedFeatureEnabledState
@@ -0,0 +1,20 @@
+
+/* union wil_details_FeatureStateCache __cdecl
+   wil_details_FeatureStateCache_GetCachedFeatureEnabledState(union wil_details_FeatureStateCache *
+   __ptr64,struct wil_details_FeatureDescriptor const * __ptr64) */
+
+ulonglong __cdecl
+wil_details_FeatureStateCache_GetCachedFeatureEnabledState
+          (wil_details_FeatureStateCache *param_1,wil_details_FeatureDescriptor *param_2)
+
+{
+  undefined8 local_res8;
+  
+  local_res8 = (ulonglong)*(uint *)param_1;
+  if ((*(uint *)param_1 & 1) == 0) {
+    local_res8 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                           (param_1,local_res8,param_2);
+  }
+  return local_res8;
+}
+

```


## wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|fullname|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|refcount|2|
|length|240|
|called|_guard_dispatch_icall<br>wil_details_GetCurrentFeatureEnabledState|
|calling|wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|paramcount|3|
|address|1c000ce5c|
|sig|wil_details_FeatureStateCache __cdecl wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState(wil_details_FeatureStateCache * param_1, wil_details_FeatureStateCache param_2, wil_details_FeatureDescriptor * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+++ wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
@@ -0,0 +1,67 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* union wil_details_FeatureStateCache __cdecl
+   wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState(union
+   wil_details_FeatureStateCache * __ptr64,union wil_details_FeatureStateCache,struct
+   wil_details_FeatureDescriptor const * __ptr64) */
+
+ulonglong __cdecl
+wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+          (uint *param_1,ulonglong param_2,wil_details_FeatureDescriptor *param_3)
+
+{
+  int iVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  bool bVar6;
+  uint local_res8 [2];
+  undefined8 local_res10;
+  
+  iVar1 = 0;
+  local_res8[0] = 0;
+  local_res10 = param_2;
+  if (g_wil_details_ensureSubscribedToFeatureConfigurationChanges != 0) {
+    iVar1 = (*(code *)g_wil_details_ensureSubscribedToFeatureConfigurationChanges)();
+  }
+  uVar2 = wil_details_GetCurrentFeatureEnabledState(param_3,(int *)local_res8);
+  if (param_3[0x14] == (wil_details_FeatureDescriptor)0x0) {
+    local_res8[0] = local_res8[0] & -(uint)(iVar1 != 0);
+  }
+  while( true ) {
+    uVar5 = (uint)param_2;
+    local_res10 = CONCAT44(local_res10._4_4_,uVar5);
+    uVar4 = uVar5;
+    if ((local_res8[0] != 0) && ((param_2 & 1) == 0)) {
+      uVar3 = (uVar5 ^ uVar2) & 0x278 ^ uVar5;
+      uVar4 = uVar3 | 1;
+      local_res10 = CONCAT44(local_res10._4_4_,uVar3) | 1;
+    }
+    if ((param_2 & 2) == 0) {
+      uVar3 = uVar4 ^ (uVar2 ^ uVar4) & 0x100;
+      uVar4 = uVar3 | 2;
+      local_res10 = CONCAT44(local_res10._4_4_,uVar3) | 2;
+    }
+    LOCK();
+    uVar3 = *param_1;
+    bVar6 = uVar5 == uVar3;
+    if (bVar6) {
+      *param_1 = uVar4;
+      uVar3 = uVar5;
+    }
+    UNLOCK();
+    if (bVar6) break;
+    param_2 = (ulonglong)uVar3;
+  }
+  if (((param_2 & 2) == 0) && (g_wil_details_subscribeFeatureStateCacheToConfigurationChanges != 0))
+  {
+    (*(code *)g_wil_details_subscribeFeatureStateCacheToConfigurationChanges)
+              (param_1,param_3[0x14],iVar1);
+  }
+  if (local_res8[0] == 0) {
+    local_res10 = (ulonglong)(uVar4 ^ (uVar2 ^ uVar4) & 0x278);
+  }
+  return local_res10;
+}
+

```


## wil_details_GetCurrentFeatureEnabledState

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_GetCurrentFeatureEnabledState|
|fullname|wil_details_GetCurrentFeatureEnabledState|
|refcount|2|
|length|309|
|called|wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureStateCache_GetCachedFeatureEnabledState|
|calling|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|paramcount|2|
|address|1c000cf54|
|sig|wil_details_FeatureStateCache __cdecl wil_details_GetCurrentFeatureEnabledState(wil_details_FeatureDescriptor * param_1, int * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_GetCurrentFeatureEnabledState
+++ wil_details_GetCurrentFeatureEnabledState
@@ -0,0 +1,74 @@
+
+/* union wil_details_FeatureStateCache __cdecl wil_details_GetCurrentFeatureEnabledState(struct
+   wil_details_FeatureDescriptor const * __ptr64,int * __ptr64) */
+
+uint __cdecl
+wil_details_GetCurrentFeatureEnabledState(wil_details_FeatureDescriptor *param_1,int *param_2)
+
+{
+  wil_details_FeatureDescriptor wVar1;
+  wil_details_FeatureDescriptor *pwVar2;
+  int iVar3;
+  uint uVar4;
+  ulonglong uVar5;
+  uint uVar6;
+  undefined8 *puVar7;
+  bool bVar8;
+  uint local_28 [8];
+  
+  wVar1 = param_1[0x14];
+  uVar6 = *(uint *)(param_1 + 0x10);
+  *param_2 = 1;
+  local_28[4] = 0;
+  local_28[5] = 0;
+  local_28[0] = 0;
+  local_28[1] = 0;
+  local_28[2] = 0;
+  local_28[3] = 0;
+  iVar3 = wil_RtlStagingConfig_QueryFeatureState
+                    ((wil_FeatureState *)local_28,uVar6,(uint)((byte)((char)wVar1 - 2U) < 2),param_2
+                    );
+  uVar6 = (-(uint)(iVar3 != 0) & local_28[0] & 3) << 5 ^
+          (-(uint)(local_28[4] != 0) & 0x100 | -(uint)(local_28[5] != 0) & 0x200);
+  if ((uVar6 & 0x60) == 0) {
+    uVar4 = -(uint)(param_1[0x17] != (wil_details_FeatureDescriptor)0x0) & 0x10;
+  }
+  else {
+    uVar4 = 0;
+    if (local_28[0] == 2) {
+      uVar4 = 0x10;
+    }
+  }
+  uVar6 = (uVar4 | uVar6) ^ uVar4 >> 1;
+  if (((uVar6 & 8) != 0) && (puVar7 = *(undefined8 **)(param_1 + 0x18), puVar7 != (undefined8 *)0x0)
+     ) {
+    do {
+      pwVar2 = (wil_details_FeatureDescriptor *)*puVar7;
+      if (pwVar2 == (wil_details_FeatureDescriptor *)0x0) {
+        return uVar6;
+      }
+      if ((pwVar2[0x16] == (wil_details_FeatureDescriptor)0x0) &&
+         (pwVar2[0x15] == (wil_details_FeatureDescriptor)0x0)) {
+        uVar5 = wil_details_FeatureStateCache_GetCachedFeatureEnabledState
+                          (*(wil_details_FeatureStateCache **)pwVar2,pwVar2);
+        if ((uVar6 & 8) == 0) goto LAB_1c000d062;
+        bVar8 = (uVar5 & 8) == 0;
+LAB_1c000d059:
+        if (bVar8) goto LAB_1c000d062;
+        uVar4 = 8;
+      }
+      else {
+        if ((uVar6 & 8) != 0) {
+          bVar8 = pwVar2[0x17] == (wil_details_FeatureDescriptor)0x0;
+          goto LAB_1c000d059;
+        }
+LAB_1c000d062:
+        uVar4 = 0;
+      }
+      puVar7 = puVar7 + 1;
+      uVar6 = uVar6 & 0xfffffff7 | uVar4;
+    } while (uVar4 != 0);
+  }
+  return uVar6;
+}
+

```


## wil_details_MapReportingKind

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_details_MapReportingKind|
|fullname|wil_details_MapReportingKind|
|refcount|2|
|length|144|
|called||
|calling|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|2|
|address|1c000d090|
|sig|wil_details_ServiceReportingKind __cdecl wil_details_MapReportingKind(wil_ReportingKind param_1, int param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_details_MapReportingKind
+++ wil_details_MapReportingKind
@@ -0,0 +1,37 @@
+
+/* enum wil_details_ServiceReportingKind __cdecl wil_details_MapReportingKind(enum
+   wil_ReportingKind,int) */
+
+wil_details_ServiceReportingKind __cdecl
+wil_details_MapReportingKind(wil_ReportingKind param_1,int param_2)
+
+{
+  byte bVar1;
+  
+  if (param_1 != 0) {
+    if (param_1 == 1) {
+      return ~-(uint)(param_2 != 0) & 4;
+    }
+    if (param_1 == 2) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 5;
+    }
+    if (param_1 == 3) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 6;
+    }
+    if (param_1 == 4) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 7;
+    }
+    if (param_1 == 5) {
+      return (-(uint)(param_2 != 0) & 0xfffffffe) + 10;
+    }
+    if (param_1 == 6) {
+      return (-(uint)(param_2 != 0) & 0xfffffffe) + 0xb;
+    }
+    bVar1 = (char)param_1 + 0x9c;
+    if (bVar1 < 0x32) {
+      return (-(uint)(param_2 != 0) & 0xffffffce) + 0x96 + (uint)bVar1;
+    }
+  }
+  return 0xff;
+}
+

```


## WPP_SF_sd

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|WPP_SF_sd|
|fullname|WPP_SF_sd|
|refcount|3|
|length|100|
|called|_guard_dispatch_icall|
|calling|CClfsBaseFile::ValidateProcessQNode|
|paramcount|2|
|address|1c000d130|
|sig|undefined __fastcall WPP_SF_sd(undefined8 param_1, undefined2 param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- WPP_SF_sd
+++ WPP_SF_sd
@@ -0,0 +1,20 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+
+void WPP_SF_sd(undefined8 param_1,undefined2 param_2)
+
+{
+  longlong lVar1;
+  longlong lVar2;
+  
+  lVar1 = -1;
+  do {
+    lVar2 = lVar1;
+    lVar1 = lVar2 + 1;
+  } while ("CClfsBaseFile::ValidateProcessQNode"[lVar2 + 1] != '\0');
+  (*pfnWppTraceMessage)
+            (param_1,0x2b,&WPP_908d6a0d40fc35709bb8a8e2055db4b4_Traceguids,param_2,
+             "CClfsBaseFile::ValidateProcessQNode",lVar2 + 2,&stack0x00000028,4,0);
+  return;
+}
+

```


## WPP_SF_sdLD

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|WPP_SF_sdLD|
|fullname|WPP_SF_sdLD|
|refcount|8|
|length|159|
|called|_guard_dispatch_icall|
|calling|CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateTraverseTree|
|paramcount|4|
|address|1c000d19c|
|sig|undefined __fastcall WPP_SF_sdLD(undefined8 param_1, undefined2 param_2, undefined8 param_3, char * param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- WPP_SF_sdLD
+++ WPP_SF_sdLD
@@ -0,0 +1,29 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+
+void WPP_SF_sdLD(undefined8 param_1,undefined2 param_2,undefined8 param_3,char *param_4)
+
+{
+  longlong lVar1;
+  longlong lVar2;
+  
+  if (param_4 == (char *)0x0) {
+    lVar2 = 5;
+  }
+  else {
+    lVar1 = -1;
+    do {
+      lVar2 = lVar1;
+      lVar1 = lVar2 + 1;
+    } while (param_4[lVar1] != '\0');
+    lVar2 = lVar2 + 2;
+  }
+  if (param_4 == (char *)0x0) {
+    param_4 = "NULL";
+  }
+  (*pfnWppTraceMessage)
+            (param_1,0x2b,&WPP_908d6a0d40fc35709bb8a8e2055db4b4_Traceguids,param_2,param_4,lVar2,
+             &stack0x00000028,4,&stack0x00000030,4,&stack0x00000038,4,0);
+  return;
+}
+

```


## CClfsBaseFile::AllocOffsetNode

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|AllocOffsetNode|
|fullname|CClfsBaseFile::AllocOffsetNode|
|refcount|3|
|length|34|
|called|NTOSKRNL.EXE::ExAllocatePoolWithTag|
|calling||
|paramcount|2|
|address|1c0027390|
|sig|void * __cdecl AllocOffsetNode(_RTL_AVL_TABLE * param_1, ulong param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::AllocOffsetNode
+++ CClfsBaseFile::AllocOffsetNode
@@ -0,0 +1,13 @@
+
+/* protected: static void * __ptr64 __cdecl CClfsBaseFile::AllocOffsetNode(struct _RTL_AVL_TABLE *
+   __ptr64,unsigned long) */
+
+void * __cdecl CClfsBaseFile::AllocOffsetNode(_RTL_AVL_TABLE *param_1,ulong param_2)
+
+{
+  void *pvVar1;
+  
+  pvVar1 = (void *)ExAllocatePoolWithTag(1,param_2,0x73666c43);
+  return pvVar1;
+}
+

```


## CClfsBaseFile::CompareGenericoffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|CompareGenericoffsets|
|fullname|CClfsBaseFile::CompareGenericoffsets|
|refcount|3|
|length|18|
|called||
|calling||
|paramcount|3|
|address|1c00273c0|
|sig|_RTL_GENERIC_COMPARE_RESULTS __cdecl CompareGenericoffsets(_RTL_AVL_TABLE * param_1, void * param_2, void * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::CompareGenericoffsets
+++ CClfsBaseFile::CompareGenericoffsets
@@ -0,0 +1,15 @@
+
+/* protected: static enum _RTL_GENERIC_COMPARE_RESULTS __cdecl
+   CClfsBaseFile::CompareGenericoffsets(struct _RTL_AVL_TABLE * __ptr64,void * __ptr64,void *
+   __ptr64) */
+
+_RTL_GENERIC_COMPARE_RESULTS __cdecl
+CClfsBaseFile::CompareGenericoffsets(_RTL_AVL_TABLE *param_1,void *param_2,void *param_3)
+
+{
+  if (*(uint *)param_2 < *(uint *)param_3) {
+    return 0;
+  }
+  return 2 - (*(uint *)param_3 < *(uint *)param_2);
+}
+

```


## CClfsBaseFile::ValidateCheckifWithinSymbolZone

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateCheckifWithinSymbolZone|
|fullname|CClfsBaseFile::ValidateCheckifWithinSymbolZone|
|refcount|7|
|length|32|
|called||
|calling|CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateProcessQNode|
|paramcount|3|
|address|1c0027468|
|sig|long __thiscall ValidateCheckifWithinSymbolZone(CClfsBaseFile * this, ulong param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateCheckifWithinSymbolZone
+++ CClfsBaseFile::ValidateCheckifWithinSymbolZone
@@ -0,0 +1,15 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateCheckifWithinSymbolZone(unsigned long,struct
+   _CLFS_BASE_RECORD_HEADER * __ptr64) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateCheckifWithinSymbolZone
+          (CClfsBaseFile *this,ulong param_1,_CLFS_BASE_RECORD_HEADER *param_2)
+
+{
+  if ((0x1337 < param_1) && (param_1 - 0x1338 <= *(uint *)(param_2 + 0x1328))) {
+    return 0;
+  }
+  return -0x3fe5fff3;
+}
+

```


## CClfsBaseFile::ValidateClientContextOffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateClientContextOffsets|
|fullname|CClfsBaseFile::ValidateClientContextOffsets|
|refcount|2|
|length|469|
|called|CClfsBaseFile::ClientCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|
|calling|CClfsBaseFile::ValidateOffsets|
|paramcount|3|
|address|1c0027490|
|sig|long __thiscall ValidateClientContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateClientContextOffsets
+++ CClfsBaseFile::ValidateClientContextOffsets
@@ -0,0 +1,87 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateClientContextOffsets(struct
+   _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateClientContextOffsets
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2)
+
+{
+  ulong uVar1;
+  byte bVar2;
+  long lVar3;
+  long lVar4;
+  void *pvVar5;
+  longlong lVar6;
+  _CLFS_VALIDATE_OFFSET_TABLE *this_00;
+  uint uVar7;
+  ulonglong uVar8;
+  _CLFS_BASE_RECORD_HEADER *p_Var9;
+  uint uVar10;
+  char local_res20 [8];
+  int local_48;
+  undefined1 local_44;
+  undefined2 local_43;
+  undefined1 local_41;
+  _CLFS_CLIENT_CONTEXT *local_40;
+  
+  lVar3 = 0;
+  local_48 = 0;
+  uVar10 = 0;
+  uVar8 = 0;
+  local_res20[0] = '\0';
+  local_44 = 0;
+  local_43 = 0;
+  local_41 = 0;
+  this_00 = (_CLFS_VALIDATE_OFFSET_TABLE *)this;
+  p_Var9 = param_2;
+  do {
+    uVar1 = *(ulong *)(param_2 + uVar8 * 4 + 0x138);
+    if (uVar1 - 1 < 0xfffffffe) {
+      uVar10 = uVar10 + 1;
+      p_Var9 = param_2;
+      lVar3 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar1 + 0x87,param_2);
+      if ((((lVar3 < 0) ||
+           (lVar3 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar1 - 0x30,p_Var9),
+           lVar3 < 0)) || (pvVar5 = OffsetToAddr(this,uVar1), pvVar5 == (void *)0x0)) ||
+         ((*(ulong *)((longlong)pvVar5 + -0xc) != uVar1 ||
+          (*(int *)((longlong)pvVar5 + -0x10) != *(ulong *)((longlong)pvVar5 + -0xc) + 0x88))))
+      goto LAB_1c00275bb;
+      local_40 = (_CLFS_CLIENT_CONTEXT *)0x0;
+      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)CONCAT71((int7)((ulonglong)p_Var9 >> 8),(uchar)uVar8);
+      lVar3 = GetSymbol(this,uVar1,(uchar)uVar8,&local_40);
+      if ((lVar3 < 0) ||
+         (((uint)(byte)local_40[8] != (uint)uVar8 || (*(int *)local_40 != -0x3e020ff9))))
+      goto LAB_1c00275bb;
+      local_48 = *(int *)(param_2 + uVar8 * 4 + 0x138) + -0x30;
+      p_Var9 = (_CLFS_BASE_RECORD_HEADER *)0x8;
+      this_00 = param_1;
+      lVar6 = RtlInsertElementGenericTableAvl(param_1,&local_48,8,local_res20);
+      if ((local_res20[0] == '\0') || (lVar6 == 0)) goto LAB_1c00275bb;
+    }
+    uVar7 = (uint)uVar8 + 1;
+    uVar8 = (ulonglong)uVar7;
+  } while (uVar7 < 0x7c);
+  bVar2 = ClientCount(this);
+  if (uVar10 == bVar2) {
+    lVar4 = lVar3;
+    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
+      WPP_SF_sdLD(WPP_GLOBAL_Control[3],0xe,p_Var9,"CClfsBaseFile::ValidateClientContextOffsets");
+    }
+  }
+  else {
+LAB_1c00275bb:
+    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+      WPP_SF_sdLD(WPP_GLOBAL_Control[3],0xf,p_Var9,"CClfsBaseFile::ValidateClientContextOffsets");
+    }
+    lVar4 = -0x3fe5fff3;
+    if (lVar3 < 0) {
+      lVar4 = lVar3;
+    }
+  }
+  return lVar4;
+}
+

```


## CClfsBaseFile::ValidateClientSymTblOffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateClientSymTblOffsets|
|fullname|CClfsBaseFile::ValidateClientSymTblOffsets|
|refcount|2|
|length|116|
|called|CClfsBaseFile::ValidateTraverseTree|
|calling|CClfsBaseFile::ValidateOffsets|
|paramcount|3|
|address|1c002766c|
|sig|long __thiscall ValidateClientSymTblOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateClientSymTblOffsets
+++ CClfsBaseFile::ValidateClientSymTblOffsets
@@ -0,0 +1,30 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateClientSymTblOffsets(struct
+   _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateClientSymTblOffsets
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2)
+
+{
+  long lVar1;
+  uint uVar2;
+  longlong lVar3;
+  
+  lVar1 = 0;
+  uVar2 = 0;
+  lVar3 = 0;
+  while ((*(__uint64 *)(lVar3 + *(longlong *)(this + 0x40)) == 0 ||
+         (lVar1 = ValidateTraverseTree
+                            (this,param_1,param_2,*(__uint64 *)(lVar3 + *(longlong *)(this + 0x40)))
+         , -1 < lVar1))) {
+    uVar2 = uVar2 + 1;
+    lVar3 = lVar3 + 8;
+    if (10 < uVar2) {
+      return lVar1;
+    }
+  }
+  return lVar1;
+}
+

```


## CClfsBaseFile::ValidateContainerContextOffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateContainerContextOffsets|
|fullname|CClfsBaseFile::ValidateContainerContextOffsets|
|refcount|2|
|length|464|
|called|CClfsBaseFile::ContainerCount<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>WPP_SF_sdLD|
|calling|CClfsBaseFile::ValidateOffsets|
|paramcount|3|
|address|1c00276e8|
|sig|long __thiscall ValidateContainerContextOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateContainerContextOffsets
+++ CClfsBaseFile::ValidateContainerContextOffsets
@@ -0,0 +1,89 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateContainerContextOffsets(struct
+   _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateContainerContextOffsets
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2)
+
+{
+  long lVar1;
+  ulong uVar2;
+  long lVar3;
+  void *pvVar4;
+  longlong lVar5;
+  _CLFS_VALIDATE_OFFSET_TABLE *this_00;
+  uint uVar6;
+  _CLFS_BASE_RECORD_HEADER *p_Var7;
+  ulong uVar8;
+  _CLFS_BASE_RECORD_HEADER *p_Var9;
+  char local_res20 [8];
+  int local_48;
+  undefined1 local_44;
+  undefined2 local_43;
+  undefined1 local_41;
+  _CLFS_CONTAINER_CONTEXT *local_40;
+  
+  lVar1 = 0;
+  p_Var9 = param_2 + 0x328;
+  local_48 = 0;
+  uVar8 = 0;
+  local_res20[0] = '\0';
+  uVar6 = 0;
+  local_44 = 0;
+  local_43 = 0;
+  local_41 = 0;
+  this_00 = (_CLFS_VALIDATE_OFFSET_TABLE *)this;
+  p_Var7 = param_2;
+  do {
+    uVar2 = *(ulong *)p_Var9;
+    if (uVar2 != 0) {
+      uVar8 = uVar8 + 1;
+      p_Var7 = param_2;
+      lVar1 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar2 + 0x2f,param_2);
+      if ((((lVar1 < 0) ||
+           (lVar1 = ValidateCheckifWithinSymbolZone((CClfsBaseFile *)this_00,uVar2 - 0x30,p_Var7),
+           lVar1 < 0)) || (pvVar4 = OffsetToAddr(this,uVar2), pvVar4 == (void *)0x0)) ||
+         ((*(ulong *)((longlong)pvVar4 + -0xc) != uVar2 ||
+          (*(int *)((longlong)pvVar4 + -0x10) != *(ulong *)((longlong)pvVar4 + -0xc) + 0x30))))
+      goto LAB_1c002780e;
+      local_40 = (_CLFS_CONTAINER_CONTEXT *)0x0;
+      p_Var7 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)uVar6;
+      lVar1 = GetSymbol(this,uVar2,uVar6,&local_40);
+      if (((lVar1 < 0) ||
+          ((*(longlong *)(local_40 + 0x18) != 0 || (*(uint *)(local_40 + 0x10) != uVar6)))) ||
+         (*(int *)local_40 != -0x3e020ff8)) goto LAB_1c002780e;
+      local_48 = *(ulong *)p_Var9 - 0x30;
+      p_Var7 = (_CLFS_BASE_RECORD_HEADER *)0x8;
+      this_00 = param_1;
+      lVar5 = RtlInsertElementGenericTableAvl(param_1,&local_48,8,local_res20);
+      if ((local_res20[0] == '\0') || (lVar5 == 0)) goto LAB_1c002780e;
+    }
+    uVar6 = uVar6 + 1;
+    p_Var9 = p_Var9 + 4;
+  } while (uVar6 < 0x400);
+  uVar2 = ContainerCount(this);
+  if (uVar8 == uVar2) {
+    lVar3 = lVar1;
+    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
+      WPP_SF_sdLD(WPP_GLOBAL_Control[3],0x10,p_Var7,"CClfsBaseFile::ValidateContainerContextOffsets"
+                 );
+    }
+  }
+  else {
+LAB_1c002780e:
+    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+      WPP_SF_sdLD(WPP_GLOBAL_Control[3],0x11,p_Var7,"CClfsBaseFile::ValidateContainerContextOffsets"
+                 );
+    }
+    lVar3 = -0x3fe5fff3;
+    if (lVar1 < 0) {
+      lVar3 = lVar1;
+    }
+  }
+  return lVar3;
+}
+

```


## CClfsBaseFile::ValidateContainerSymTblOffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateContainerSymTblOffsets|
|fullname|CClfsBaseFile::ValidateContainerSymTblOffsets|
|refcount|2|
|length|116|
|called|CClfsBaseFile::ValidateTraverseTree|
|calling|CClfsBaseFile::ValidateOffsets|
|paramcount|3|
|address|1c0027948|
|sig|long __thiscall ValidateContainerSymTblOffsets(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateContainerSymTblOffsets
+++ CClfsBaseFile::ValidateContainerSymTblOffsets
@@ -0,0 +1,30 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateContainerSymTblOffsets(struct
+   _CLFS_VALIDATE_OFFSET_TABLE * __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateContainerSymTblOffsets
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2)
+
+{
+  long lVar1;
+  uint uVar2;
+  longlong lVar3;
+  
+  lVar1 = 0;
+  uVar2 = 0;
+  lVar3 = 0;
+  while ((*(__uint64 *)(lVar3 + *(longlong *)(this + 0x58)) == 0 ||
+         (lVar1 = ValidateTraverseTree
+                            (this,param_1,param_2,*(__uint64 *)(lVar3 + *(longlong *)(this + 0x58)))
+         , -1 < lVar1))) {
+    uVar2 = uVar2 + 1;
+    lVar3 = lVar3 + 8;
+    if (10 < uVar2) {
+      return lVar1;
+    }
+  }
+  return lVar1;
+}
+

```


## CClfsBaseFile::ValidateOffsets

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateOffsets|
|fullname|CClfsBaseFile::ValidateOffsets|
|refcount|2|
|length|770|
|called|<details><summary>Expand for full list:<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateClientSymTblOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateContainerSymTblOffsets<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl<br>NTOSKRNL.EXE::RtlEnumerateGenericTableAvl<br>NTOSKRNL.EXE::RtlInitializeGenericTableAvl<br>NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl</summary>RtlStringCbLengthW<br>WPP_SF_sdLD</details>|
|calling|CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|2|
|address|1c00279c4|
|sig|long __thiscall ValidateOffsets(CClfsBaseFile * this, _CLFS_BASE_RECORD_HEADER * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateOffsets
+++ CClfsBaseFile::ValidateOffsets
@@ -0,0 +1,101 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateOffsets(struct _CLFS_BASE_RECORD_HEADER * __ptr64
+   const) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateOffsets(CClfsBaseFile *this,_CLFS_BASE_RECORD_HEADER *param_1)
+
+{
+  _CLFS_BASE_RECORD_HEADER *p_Var1;
+  ulong uVar2;
+  _CLFS_BASE_RECORD_HEADER *p_Var3;
+  char cVar4;
+  long lVar5;
+  _CLFS_VALIDATE_OFFSET_TABLE *p_Var6;
+  ulong *puVar7;
+  ulong *puVar8;
+  void *pvVar9;
+  ushort *puVar10;
+  longlong lVar11;
+  undefined8 uVar12;
+  ulong uVar13;
+  _CLFS_BASE_RECORD_HEADER *p_Var14;
+  ulong *puVar15;
+  _CLFS_BASE_RECORD_HEADER local_res8 [8];
+  
+  p_Var3 = *(_CLFS_BASE_RECORD_HEADER **)(*(longlong *)(this + 0x30) + 0x30);
+  p_Var6 = (_CLFS_VALIDATE_OFFSET_TABLE *)ExAllocatePoolWithTag(1,0x68,0x73666c43);
+  if (p_Var6 == (_CLFS_VALIDATE_OFFSET_TABLE *)0x0) {
+    return -0x3fffff66;
+  }
+  RtlInitializeGenericTableAvl(p_Var6,CompareGenericoffsets,AllocOffsetNode,freeOffsetNode,p_Var6);
+  p_Var14 = (_CLFS_BASE_RECORD_HEADER *)(ulonglong)*(uint *)(p_Var3 + 0x68);
+  if (((((uint)*(ushort *)(p_Var3 + 4) << 9 < *(uint *)(p_Var3 + 0x68)) ||
+       (p_Var1 = param_1 + 0x1338, p_Var1 + *(uint *)(param_1 + 0x1328) < p_Var1)) ||
+      (p_Var3 + (longlong)p_Var14 < p_Var3)) ||
+     (p_Var3 + (longlong)p_Var14 < p_Var1 + *(uint *)(param_1 + 0x1328))) {
+LAB_1c0027c17:
+    lVar5 = -0x3fe5fff3;
+  }
+  else {
+    p_Var14 = param_1;
+    lVar5 = ValidateContainerContextOffsets(this,p_Var6,param_1);
+    if (((-1 < lVar5) &&
+        (p_Var14 = param_1, lVar5 = ValidateClientContextOffsets(this,p_Var6,param_1), -1 < lVar5))
+       && ((p_Var14 = param_1, lVar5 = ValidateContainerSymTblOffsets(this,p_Var6,param_1),
+           -1 < lVar5 &&
+           (p_Var14 = param_1, lVar5 = ValidateClientSymTblOffsets(this,p_Var6,param_1), -1 < lVar5)
+           ))) {
+      RtlNumberGenericTableElementsAvl(p_Var6);
+      puVar7 = (ulong *)RtlEnumerateGenericTableAvl(p_Var6,1);
+      puVar8 = (ulong *)RtlEnumerateGenericTableAvl(p_Var6,0);
+      if (puVar7 != (ulong *)0x0) {
+        while( true ) {
+          puVar15 = puVar8;
+          if (puVar15 == (ulong *)0x0) {
+            uVar13 = *(int *)(param_1 + 0x1328) + 0x1338;
+          }
+          else {
+            uVar13 = *puVar15;
+          }
+          pvVar9 = OffsetToAddr(this,*puVar7);
+          if (((pvVar9 == (void *)0x0) ||
+              (uVar2 = *(ulong *)((longlong)pvVar9 + 0x20), uVar13 < uVar2)) ||
+             ((char)puVar7[1] == '\0')) goto LAB_1c0027c17;
+          puVar10 = OffsetToAddr(this,uVar2);
+          p_Var14 = local_res8;
+          lVar5 = RtlStringCbLengthW(puVar10,(ulonglong)(uVar13 - uVar2),(__uint64 *)p_Var14);
+          if (lVar5 < 0) goto LAB_1c0027c1c;
+          cVar4 = RtlDeleteElementGenericTableAvl(p_Var6,puVar7);
+          if (cVar4 == '\0') goto LAB_1c0027c17;
+          if (puVar15 == (ulong *)0x0) break;
+          puVar8 = (ulong *)RtlEnumerateGenericTableAvl(p_Var6,0);
+          puVar7 = puVar15;
+        }
+      }
+      if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+         ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
+        WPP_SF_sdLD(WPP_GLOBAL_Control[3],0x12,p_Var14,"CClfsBaseFile::ValidateOffsets");
+      }
+      goto LAB_1c0027c95;
+    }
+  }
+LAB_1c0027c1c:
+  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+    WPP_SF_sdLD(WPP_GLOBAL_Control[3],0x13,p_Var14,"CClfsBaseFile::ValidateOffsets");
+  }
+  uVar12 = 1;
+  while (lVar11 = RtlEnumerateGenericTableAvl(p_Var6,uVar12), lVar11 != 0) {
+    cVar4 = RtlDeleteElementGenericTableAvl(p_Var6);
+    if (cVar4 == '\0') {
+      lVar5 = -0x3fe5fff3;
+      break;
+    }
+    uVar12 = 0;
+  }
+LAB_1c0027c95:
+  ExFreePoolWithTag(p_Var6,0);
+  return lVar5;
+}
+

```


## CClfsBaseFile::ValidateProcessQNode

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateProcessQNode|
|fullname|CClfsBaseFile::ValidateProcessQNode|
|refcount|2|
|length|453|
|called|CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ValidateCheckifWithinSymbolZone<br>NTOSKRNL.EXE::RtlInsertElementGenericTableAvl<br>NTOSKRNL.EXE::RtlLookupElementGenericTableAvl<br>WPP_SF_sd|
|calling|CClfsBaseFile::ValidateTraverseTree|
|paramcount|6|
|address|1c0027cd0|
|sig|long __thiscall ValidateProcessQNode(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2, ulong param_3, ulong * param_4, ulong * param_5)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateProcessQNode
+++ CClfsBaseFile::ValidateProcessQNode
@@ -0,0 +1,76 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateProcessQNode(struct _CLFS_VALIDATE_OFFSET_TABLE *
+   __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const,unsigned long,unsigned long &
+   __ptr64,unsigned long & __ptr64) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateProcessQNode
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2,ulong param_3,ulong *param_4,ulong *param_5)
+
+{
+  long lVar1;
+  int *piVar2;
+  longlong lVar3;
+  int iVar4;
+  ulong uVar5;
+  char local_28 [8];
+  ulong local_20;
+  undefined1 local_1c;
+  undefined2 local_1b;
+  undefined1 local_19;
+  
+  local_20 = 0;
+  local_1c = 0;
+  local_28[0] = '\0';
+  local_1b = 0;
+  local_19 = 0;
+  uVar5 = param_3;
+  lVar1 = ValidateCheckifWithinSymbolZone(this,param_3,param_2);
+  if (-1 < lVar1) {
+    piVar2 = OffsetToAddr(this,uVar5 + 0x30);
+    if (piVar2 != (int *)0x0) {
+      if (*piVar2 == -0x3e020ff8) {
+        iVar4 = 0x30;
+      }
+      else {
+        if (*piVar2 != -0x3e020ff9) goto LAB_1c0027dea;
+        iVar4 = 0x88;
+      }
+      lVar1 = ValidateCheckifWithinSymbolZone(this,param_3 + 0x2f + iVar4,param_2);
+      if (-1 < lVar1) {
+        local_20 = param_3;
+        if ((char)piVar2[-2] == '\0') {
+          lVar3 = RtlLookupElementGenericTableAvl(param_1,&local_20);
+          if ((lVar3 != 0) && (*(char *)(lVar3 + 4) == '\0')) {
+            *(undefined1 *)(lVar3 + 4) = 1;
+LAB_1c0027e77:
+            *param_4 = piVar2[-8];
+            *param_5 = piVar2[-6];
+            return lVar1;
+          }
+        }
+        else {
+          if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+             ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
+            WPP_SF_sd(WPP_GLOBAL_Control[3],0xb);
+          }
+          if ((piVar2[-3] == uVar5 + 0x30) && (piVar2[-4] == piVar2[-3] + iVar4)) {
+            local_1c = 1;
+            lVar3 = RtlInsertElementGenericTableAvl(param_1,&local_20,8,local_28);
+            if ((local_28[0] != '\0') && (lVar3 != 0)) goto LAB_1c0027e77;
+          }
+        }
+      }
+    }
+  }
+LAB_1c0027dea:
+  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
+    WPP_SF_sd(WPP_GLOBAL_Control[3],0xc);
+  }
+  *param_4 = 0;
+  *param_5 = 0;
+  return -0x3fe5fff3;
+}
+

```


## CClfsBaseFile::ValidateTraverseTree

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|ValidateTraverseTree|
|fullname|CClfsBaseFile::ValidateTraverseTree|
|refcount|3|
|length|580|
|called|CClfsBaseFile::ValidateProcessQNode<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>WPP_SF_sdLD|
|calling|CClfsBaseFile::ValidateClientSymTblOffsets<br>CClfsBaseFile::ValidateContainerSymTblOffsets|
|paramcount|4|
|address|1c0027fb0|
|sig|long __thiscall ValidateTraverseTree(CClfsBaseFile * this, _CLFS_VALIDATE_OFFSET_TABLE * param_1, _CLFS_BASE_RECORD_HEADER * param_2, __uint64 param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- CClfsBaseFile::ValidateTraverseTree
+++ CClfsBaseFile::ValidateTraverseTree
@@ -0,0 +1,101 @@
+
+/* protected: long __cdecl CClfsBaseFile::ValidateTraverseTree(struct _CLFS_VALIDATE_OFFSET_TABLE *
+   __ptr64,struct _CLFS_BASE_RECORD_HEADER * __ptr64 const,unsigned __int64) __ptr64 */
+
+long __thiscall
+CClfsBaseFile::ValidateTraverseTree
+          (CClfsBaseFile *this,_CLFS_VALIDATE_OFFSET_TABLE *param_1,
+          _CLFS_BASE_RECORD_HEADER *param_2,__uint64 param_3)
+
+{
+  longlong *******ppppppplVar1;
+  code *pcVar2;
+  ulong uVar3;
+  longlong ******pppppplVar4;
+  long lVar5;
+  longlong *******ppppppplVar6;
+  _CLFS_BASE_RECORD_HEADER *p_Var7;
+  ulong local_38;
+  ulong local_34;
+  longlong ******local_30;
+  longlong ******local_28;
+  
+  lVar5 = 0;
+  local_28 = (longlong ******)&local_30;
+  local_38 = 0;
+  local_34 = 0;
+  local_30 = (longlong ******)&local_30;
+  p_Var7 = (_CLFS_BASE_RECORD_HEADER *)0x73666c43;
+  ppppppplVar6 = (longlong *******)ExAllocatePoolWithTag(1,0x18);
+  if (ppppppplVar6 == (longlong *******)0x0) {
+    return -0x3fffff66;
+  }
+  while( true ) {
+    ppppppplVar6[1] = (longlong ******)ppppppplVar6;
+    *ppppppplVar6 = (longlong ******)ppppppplVar6;
+    *(int *)(ppppppplVar6 + 2) = (int)param_3;
+    if ((longlong *******)*local_28 != &local_30) break;
+    *ppppppplVar6 = (longlong ******)&local_30;
+    ppppppplVar6[1] = local_28;
+    *local_28 = (longlong *****)ppppppplVar6;
+    local_28 = (longlong ******)ppppppplVar6;
+    do {
+      pppppplVar4 = local_30;
+      if ((longlong *******)local_30 == &local_30) goto LAB_1c0028166;
+      if (((longlong *******)local_30[1] != &local_30) ||
+         (ppppppplVar6 = (longlong *******)*local_30, ppppppplVar6[1] != local_30))
+      goto LAB_1c00281ed;
+      ppppppplVar6[1] = (longlong ******)&local_30;
+      ppppppplVar1 = (longlong *******)(local_30 + 2);
+      p_Var7 = param_2;
+      local_30 = (longlong ******)ppppppplVar6;
+      lVar5 = ValidateProcessQNode(this,param_1,param_2,*(ulong *)ppppppplVar1,&local_38,&local_34);
+      ExFreePoolWithTag(pppppplVar4,0);
+      uVar3 = local_38;
+      if (lVar5 < 0) goto LAB_1c0028166;
+      if (local_38 != 0) {
+        p_Var7 = (_CLFS_BASE_RECORD_HEADER *)0x73666c43;
+        ppppppplVar6 = (longlong *******)ExAllocatePoolWithTag(1);
+        if (ppppppplVar6 == (longlong *******)0x0) goto LAB_1c002815d;
+        ppppppplVar6[1] = (longlong ******)ppppppplVar6;
+        *ppppppplVar6 = (longlong ******)ppppppplVar6;
+        *(ulong *)(ppppppplVar6 + 2) = uVar3;
+        if ((longlong *******)*local_28 != &local_30) goto LAB_1c00281ed;
+        ppppppplVar6[1] = local_28;
+        *ppppppplVar6 = (longlong ******)&local_30;
+        *local_28 = (longlong *****)ppppppplVar6;
+        local_28 = (longlong ******)ppppppplVar6;
+      }
+      param_3 = (__uint64)local_34;
+    } while (local_34 == 0);
+    p_Var7 = (_CLFS_BASE_RECORD_HEADER *)0x73666c43;
+    ppppppplVar6 = (longlong *******)ExAllocatePoolWithTag(1);
+    if (ppppppplVar6 == (longlong *******)0x0) goto LAB_1c002815d;
+  }
+LAB_1c00281ed:
+  pcVar2 = (code *)swi(0x29);
+  (*pcVar2)(3);
+  pcVar2 = (code *)swi(3);
+  lVar5 = (*pcVar2)();
+  return lVar5;
+LAB_1c002815d:
+  lVar5 = -0x3fffff66;
+LAB_1c0028166:
+  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
+    WPP_SF_sdLD(WPP_GLOBAL_Control[3],0xd,p_Var7,"CClfsBaseFile::ValidateTraverseTree");
+  }
+  while( true ) {
+    pppppplVar4 = local_30;
+    if ((longlong *******)local_30 == &local_30) {
+      return lVar5;
+    }
+    if (((longlong *******)local_30[1] != &local_30) ||
+       (ppppppplVar6 = (longlong *******)*local_30, ppppppplVar6[1] != local_30)) break;
+    ppppppplVar6[1] = (longlong ******)&local_30;
+    local_30 = (longlong ******)ppppppplVar6;
+    ExFreePoolWithTag(pppppplVar4,0);
+  }
+  goto LAB_1c00281ed;
+}
+

```


## wil_RtlStagingConfig_QueryFeatureState

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|wil_RtlStagingConfig_QueryFeatureState|
|fullname|wil_RtlStagingConfig_QueryFeatureState|
|refcount|2|
|length|197|
|called|NTOSKRNL.EXE::RtlQueryFeatureConfiguration<br>__security_check_cookie|
|calling|wil_details_GetCurrentFeatureEnabledState|
|paramcount|4|
|address|1c0028224|
|sig|int __cdecl wil_RtlStagingConfig_QueryFeatureState(wil_FeatureState * param_1, uint param_2, int param_3, int * param_4)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil_RtlStagingConfig_QueryFeatureState
+++ wil_RtlStagingConfig_QueryFeatureState
@@ -0,0 +1,39 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* int __cdecl wil_RtlStagingConfig_QueryFeatureState(struct wil_FeatureState * __ptr64,unsigned
+   int,int,int * __ptr64) */
+
+int __cdecl
+wil_RtlStagingConfig_QueryFeatureState
+          (wil_FeatureState *param_1,uint param_2,int param_3,int *param_4)
+
+{
+  int iVar1;
+  undefined1 auStack_48 [32];
+  undefined8 local_28;
+  undefined8 local_20;
+  undefined4 local_18;
+  ulonglong local_10;
+  
+  local_10 = __security_cookie ^ (ulonglong)auStack_48;
+  local_28 = 0;
+  local_20 = 0;
+  local_18 = 0;
+  iVar1 = RtlQueryFeatureConfiguration(param_2,param_3 == 0,&local_28,&local_20);
+  if (iVar1 == 0) {
+    *(uint *)param_1 = local_20._4_4_ >> 4 & 3;
+    param_1[4] = (wil_FeatureState)((byte)((ulonglong)local_20 >> 0x28) & 0x3f);
+    *(undefined4 *)(param_1 + 0xc) = local_18;
+    *(uint *)(param_1 + 8) = local_20._4_4_ >> 0xe & 3;
+    *(uint *)(param_1 + 0x14) = local_20._4_4_ >> 6 & 1;
+    *(uint *)(param_1 + 0x10) = local_20._4_4_ >> 7 & 1;
+  }
+  else {
+    if (iVar1 != 0x117) {
+      return 0;
+    }
+    *(uint *)(param_1 + 0x10) = local_20._4_4_ >> 7 & 1;
+  }
+  return 1;
+}
+

```


## NTOSKRNL.EXE::RtlEnumerateGenericTableAvl

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|RtlEnumerateGenericTableAvl|
|fullname|NTOSKRNL.EXE::RtlEnumerateGenericTableAvl|
|refcount|5|
|length|0|
|called||
|calling|CClfsBaseFile::ValidateOffsets|
|paramcount|0|
|address|EXTERNAL:00000025|
|sig|undefined RtlEnumerateGenericTableAvl(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTOSKRNL.EXE::RtlEnumerateGenericTableAvl*
## NTOSKRNL.EXE::RtlNotifyFeatureUsage

### Function Meta



|Key|clfs-10.0.22000.978.sys|
| :---: | :---: |
|name|RtlNotifyFeatureUsage|
|fullname|NTOSKRNL.EXE::RtlNotifyFeatureUsage|
|refcount|2|
|length|0|
|called||
|calling|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|paramcount|0|
|address|EXTERNAL:00000013|
|sig|undefined RtlNotifyFeatureUsage(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTOSKRNL.EXE::RtlNotifyFeatureUsage*
# Modified


*Modified functions contain code changes*
## CClfsRequest::DeleteContainer

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.4|
|i_ratio|0.55|
|m_ratio|0.94|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|DeleteContainer|DeleteContainer|
|fullname|CClfsRequest::DeleteContainer|CClfsRequest::DeleteContainer|
|refcount|2|2|
|`length`|669|756|
|`called`|NTOSKRNL.EXE::KeSetEvent<br>RtlStringCbLengthW<br>RtlStringLengthWorkerW<br>WPP_SF_slS<br>_guard_dispatch_icall|NTOSKRNL.EXE::KeSetEvent<br>RtlStringCbLengthW<br>WPP_SF_slS<br>_guard_dispatch_icall|
|calling|CClfsRequest::Dispatch|CClfsRequest::Dispatch|
|paramcount|1|1|
|`address`|1c0050b70|1c0052c34|
|sig|long __thiscall DeleteContainer(CClfsRequest * this)|long __thiscall DeleteContainer(CClfsRequest * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsRequest::DeleteContainer Called Diff


```diff
--- CClfsRequest::DeleteContainer called
+++ CClfsRequest::DeleteContainer called
@@ -3 +2,0 @@
-RtlStringLengthWorkerW
```


### CClfsRequest::DeleteContainer Diff


```diff
--- CClfsRequest::DeleteContainer
+++ CClfsRequest::DeleteContainer
@@ -1,101 +1,111 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsRequest::DeleteContainer(void) __ptr64 */
 
 long __thiscall CClfsRequest::DeleteContainer(CClfsRequest *this)
 
 {
-  longlong lVar1;
+  undefined1 uVar1;
   longlong lVar2;
   longlong *plVar3;
-  uint uVar4;
+  longlong lVar4;
   uint uVar5;
-  ulonglong uVar6;
+  uint uVar6;
   ulonglong uVar7;
   ulonglong uVar8;
-  wchar_t *pwVar9;
+  ulonglong uVar9;
   wchar_t *pwVar10;
-  ulonglong local_res10;
-  longlong local_res18;
-  __uint64 local_res20;
-  undefined4 in_stack_ffffffffffffff8c;
+  wchar_t *pwVar11;
+  longlong local_res10;
+  __uint64 local_res18;
+  longlong local_res20;
+  undefined4 in_stack_ffffffffffffff7c;
+  longlong local_50;
   undefined8 local_48;
   wchar_t *pwStack_40;
   
-  uVar6 = 0;
+  uVar7 = 0;
   local_48 = 0;
   pwStack_40 = (wchar_t *)0x0;
-  lVar1 = *(longlong *)(*(longlong *)(this + 0x30) + 0xb8);
-  uVar4 = *(uint *)(lVar1 + 0x10);
-  local_res18 = CONCAT44(local_res18._4_4_,uVar4);
-  uVar7 = uVar6;
-  if (uVar4 < 0x10) {
-    uVar4 = 0xc0000206;
+  lVar2 = *(longlong *)(*(longlong *)(this + 0x30) + 0xb8);
+  uVar6 = *(uint *)(lVar2 + 0x10);
+  uVar8 = uVar7;
+  if (uVar6 < 0x10) {
+    uVar6 = 0xc0000206;
   }
   else {
-    lVar2 = *(longlong *)(*(longlong *)(this + 0x30) + 0x18);
-    local_res10 = CONCAT71(local_res10._1_7_,*(undefined1 *)(lVar2 + 10));
-    local_res20 = 0;
-    pwVar9 = (wchar_t *)(lVar2 + 0x10);
-    uVar8 = uVar6;
-    pwVar10 = pwVar9;
-    for (; (uint)uVar7 < (uint)*(ushort *)(lVar2 + 8); uVar7 = (ulonglong)((uint)uVar7 + 1)) {
-      uVar4 = RtlStringCbLengthW((ushort *)pwVar10,(uVar4 - uVar8) - 0x10,&local_res20);
-      uVar6 = (ulonglong)uVar4;
-      if ((int)uVar4 < 0) goto LAB_0;
+    local_res20 = *(longlong *)(*(longlong *)(this + 0x30) + 0x18);
+    uVar1 = *(undefined1 *)(local_res20 + 10);
+    local_res18 = 0;
+    pwVar10 = (wchar_t *)(local_res20 + 0x10);
+    uVar9 = uVar7;
+    pwVar11 = pwVar10;
+    for (; (uint)uVar8 < (uint)*(ushort *)(local_res20 + 8); uVar8 = (ulonglong)((uint)uVar8 + 1)) {
+      uVar5 = RtlStringCbLengthW((ushort *)pwVar11,(uVar6 - uVar9) - 0x10,&local_res18);
+      uVar7 = (ulonglong)uVar5;
+      if ((int)uVar5 < 0) goto LAB_0;
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
         WPP_SF_slS(WPP_GLOBAL_Control[3],0x16,&WPP_718c7adf00f03a045b2a6a7d3a85311c_Traceguids,
-                   "CClfsRequest::DeleteContainer",CONCAT44(in_stack_ffffffffffffff8c,0x1b46),
-                   pwVar10);
+                   "CClfsRequest::DeleteContainer",CONCAT44(in_stack_ffffffffffffff7c,0x1b46),
+                   pwVar11);
       }
-      uVar8 = uVar8 + 2 + local_res20;
-      pwVar10 = (wchar_t *)((longlong)pwVar10 + local_res20 + 2);
-      uVar4 = (uint)local_res18;
+      uVar9 = uVar9 + 2 + local_res18;
+      pwVar11 = (wchar_t *)((longlong)pwVar11 + local_res18 + 2);
     }
-    lVar1 = *(longlong *)(lVar1 + 0x30);
-    plVar3 = *(longlong **)(*(longlong *)(lVar1 + 0x18) + 0x70);
+    lVar2 = *(longlong *)(lVar2 + 0x30);
+    plVar3 = *(longlong **)(*(longlong *)(lVar2 + 0x18) + 0x70);
     *(longlong **)(this + 0x90) = plVar3;
     (**(code **)(*plVar3 + 0x40))();
-    uVar8 = local_res10;
-    uVar7 = 0;
+    lVar4 = local_res20;
+    uVar8 = 0;
     while( true ) {
-      uVar4 = (uint)uVar6;
-      uVar6 = 0;
-      if ((uint)*(ushort *)(lVar2 + 8) <= (uint)uVar7) break;
+      uVar6 = (uint)uVar7;
+      uVar7 = 0;
+      if ((uint)*(ushort *)(lVar4 + 8) <= (uint)uVar8) break;
       local_48 = 0;
       pwStack_40 = (wchar_t *)0x0;
-      if (pwVar9 != (wchar_t *)0x0) {
-        local_res10 = 0;
-        uVar4 = RtlStringLengthWorkerW(pwVar9,0x7fff,(longlong *)&local_res10);
-        uVar6 = (ulonglong)uVar4;
-        if (-1 < (int)uVar4) {
-          local_res18 = local_res10 * 2;
-          local_48._0_4_ = CONCAT22((short)local_res18 + 2,(short)local_res18);
-          pwStack_40 = pwVar9;
+      if (pwVar10 != (wchar_t *)0x0) {
+        local_50 = 0x7fff;
+        for (pwVar11 = pwVar10; (local_50 != 0 && (*pwVar11 != L'\0')); pwVar11 = pwVar11 + 1) {
+          local_50 = local_50 + -1;
+        }
+        if (local_50 == 0) {
+          uVar7 = 0xc000000d;
+        }
+        if ((int)uVar7 < 0) {
+          local_res10 = 0;
+        }
+        else {
+          local_res10 = 0x7fff - local_50;
+        }
+        if (-1 < (int)uVar7) {
+          local_res20 = local_res10 * 2;
+          local_48 = (ulonglong)CONCAT22((short)local_res20 + 2,(short)local_res20);
+          pwStack_40 = pwVar10;
         }
       }
-      if ((int)uVar6 < 0) goto LAB_0;
-      uVar4 = (**(code **)(**(longlong **)(this + 0x90) + 0xe0))
-                        (*(longlong **)(this + 0x90),lVar1,&local_48,uVar8 & 0xff);
-      if (((int)uVar4 < 0) && (uVar6 = (ulonglong)uVar4, uVar4 != 0xc01a0011)) break;
-      pwVar9 = pwVar9 + (local_48 >> 1 & 0x7fff) + 1;
-      uVar7 = (ulonglong)((uint)uVar7 + 1);
+      if ((int)uVar7 < 0) goto LAB_0;
+      uVar6 = (**(code **)(**(longlong **)(this + 0x90) + 0xe0))
+                        (*(longlong **)(this + 0x90),lVar2,&local_48,uVar1);
+      if (((int)uVar6 < 0) && (uVar7 = (ulonglong)uVar6, uVar6 != 0xc01a0011)) break;
+      pwVar10 = pwVar10 + (local_48 >> 1 & 0x7fff) + 1;
+      uVar8 = (ulonglong)((uint)uVar8 + 1);
     }
   }
 LAB_1:
   uVar5 = *(uint *)(this + 0x10);
   if (((uVar5 & 1) != 0) && (*(longlong *)(*(longlong *)(this + 0x30) + 0x50) != 0)) {
     KeSetEvent(*(longlong *)(*(longlong *)(this + 0x30) + 0x50),0,0);
     uVar5 = *(uint *)(this + 0x10);
   }
   if ((uVar5 & 4) == 0) {
-    *(uint *)(*(longlong *)(this + 0x30) + 0x30) = uVar4;
-    *(ulonglong *)(*(longlong *)(this + 0x30) + 0x38) = uVar7;
+    *(uint *)(*(longlong *)(this + 0x30) + 0x30) = uVar6;
+    *(ulonglong *)(*(longlong *)(this + 0x30) + 0x38) = uVar8;
   }
-  return uVar4;
+  return uVar6;
 LAB_0:
-  uVar4 = 0xc00000e8;
+  uVar6 = 0xc00000e8;
   goto LAB_1;
 }
 

```


## CClfsBaseFile::GetSymbol

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling|
|ratio|0.94|
|i_ratio|0.6|
|m_ratio|0.97|
|b_ratio|0.91|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|GetSymbol|GetSymbol|
|fullname|CClfsBaseFile::GetSymbol|CClfsBaseFile::GetSymbol|
|`refcount`|4|6|
|`length`|234|252|
|called|CClfsBaseFile::IsValidOffset<br>CClfsBaseFile::OffsetToAddr<br>ClfsQuadAlign<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::IsValidOffset<br>CClfsBaseFile::OffsetToAddr<br>ClfsQuadAlign<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|`calling`|CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseClientContext|CClfsBaseFile::AcquireClientContext<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFilePersisted::LoadContainerQ|
|paramcount|4|4|
|`address`|1c002cdd8|1c002eb28|
|sig|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, uchar param_2, _CLFS_CLIENT_CONTEXT * * param_3)|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, uchar param_2, _CLFS_CLIENT_CONTEXT * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::GetSymbol Calling Diff


```diff
--- CClfsBaseFile::GetSymbol calling
+++ CClfsBaseFile::GetSymbol calling
@@ -3,0 +4,2 @@
+CClfsBaseFile::ValidateClientContextOffsets
+CClfsBaseFilePersisted::LoadContainerQ
```


### CClfsBaseFile::GetSymbol Diff


```diff
--- CClfsBaseFile::GetSymbol
+++ CClfsBaseFile::GetSymbol
@@ -1,48 +1,51 @@
 
 /* public: long __cdecl CClfsBaseFile::GetSymbol(long,unsigned char,struct _CLFS_CLIENT_CONTEXT *
    __ptr64 * __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::GetSymbol
           (CClfsBaseFile *this,long param_1,uchar param_2,_CLFS_CLIENT_CONTEXT **param_3)
 
 {
   char cVar1;
   uchar uVar2;
   ulong uVar3;
   _CLFS_CLIENT_CONTEXT *p_Var4;
   undefined4 in_register_00000014;
   int iVar5;
+  int iVar6;
   long local_38;
   
   local_38 = 0;
   if ((uint)param_1 < 0x1368) {
     return -0x3fe5fff3;
   }
   *param_3 = (_CLFS_CLIENT_CONTEXT *)0x0;
   cVar1 = ExAcquireResourceSharedLite
                     (*(undefined8 *)(this + 0x20),
                      CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
   uVar2 = IsValidOffset(this,param_1 + 0x87);
   if ((uVar2 != '\0') &&
      (p_Var4 = OffsetToAddr(this,param_1), p_Var4 != (_CLFS_CLIENT_CONTEXT *)0x0)) {
     iVar5 = *(int *)(p_Var4 + -0xc);
     if (iVar5 != param_1) {
       local_38 = -0x3ffffff8;
       goto LAB_0;
     }
+    iVar6 = 0x88;
     uVar3 = ClfsQuadAlign(0x88);
-    if (((longlong)*(int *)(p_Var4 + -0x10) == (ulonglong)(iVar5 + uVar3)) &&
+    if (((((longlong)*(int *)(p_Var4 + -0x10) == (ulonglong)(iVar5 + uVar3)) &&
+         (*(int *)p_Var4 == -0x3e020ff9)) && (*(int *)(p_Var4 + 4) == iVar6)) &&
        (p_Var4[8] == (_CLFS_CLIENT_CONTEXT)param_2)) {
       *param_3 = p_Var4;
       goto LAB_0;
     }
   }
   local_38 = -0x3fe5fff3;
 LAB_0:
   if (cVar1 != '\0') {
     ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
   }
   return local_38;
 }
 

```


## RtlStringCbLengthW

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling,called|
|ratio|0.48|
|i_ratio|0.16|
|m_ratio|0.83|
|b_ratio|0.63|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlStringCbLengthW|RtlStringCbLengthW|
|fullname|RtlStringCbLengthW|RtlStringCbLengthW|
|`refcount`|3|4|
|`length`|87|108|
|`called`|RtlStringLengthWorkerW||
|`calling`|CClfsRequest::AllocContainer<br>CClfsRequest::DeleteContainer|CClfsBaseFile::ValidateOffsets<br>CClfsRequest::AllocContainer<br>CClfsRequest::DeleteContainer|
|paramcount|3|3|
|`address`|1c001035c|1c00100a0|
|sig|long __cdecl RtlStringCbLengthW(ushort * param_1, __uint64 param_2, __uint64 * param_3)|long __cdecl RtlStringCbLengthW(ushort * param_1, __uint64 param_2, __uint64 * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### RtlStringCbLengthW Called Diff


```diff
--- RtlStringCbLengthW called
+++ RtlStringCbLengthW called
@@ -1 +0,0 @@
-RtlStringLengthWorkerW
```


### RtlStringCbLengthW Calling Diff


```diff
--- RtlStringCbLengthW calling
+++ RtlStringCbLengthW calling
@@ -0,0 +1 @@
+CClfsBaseFile::ValidateOffsets
```


### RtlStringCbLengthW Diff


```diff
--- RtlStringCbLengthW
+++ RtlStringCbLengthW
@@ -1,31 +1,35 @@
 
 /* long __cdecl RtlStringCbLengthW(unsigned short const * __ptr64,unsigned __int64,unsigned __int64
    * __ptr64) */
 
 long __cdecl RtlStringCbLengthW(ushort *param_1,__uint64 param_2,__uint64 *param_3)
 
 {
-  uint uVar1;
-  longlong lVar2;
-  longlong local_res8 [4];
+  ulonglong uVar1;
+  ulonglong uVar2;
+  uint uVar3;
+  ulonglong uVar4;
   
-  lVar2 = 0;
-  local_res8[0] = 0;
-  if ((param_1 == (ushort *)0x0) || (0x7fffffff < param_2 >> 1)) {
-    uVar1 = 0xc000000d;
+  uVar2 = 0;
+  uVar4 = param_2 >> 1;
+  if ((param_1 == (ushort *)0x0) || (uVar1 = uVar4, 0x7fffffff < uVar4)) {
+    uVar3 = 0xc000000d;
   }
   else {
-    uVar1 = RtlStringLengthWorkerW((short *)param_1,param_2 >> 1,local_res8);
-    lVar2 = local_res8[0];
+    for (; (uVar1 != 0 && (*param_1 != 0)); param_1 = param_1 + 1) {
+      uVar1 = uVar1 - 1;
+    }
+    uVar3 = ~-(uint)(uVar1 != 0) & 0xc000000d;
+    uVar2 = -(ulonglong)(uVar1 != 0) & uVar4 - uVar1;
   }
   if (param_3 != (__uint64 *)0x0) {
-    if ((int)uVar1 < 0) {
+    if ((int)uVar3 < 0) {
       *param_3 = 0;
     }
     else {
-      *param_3 = lVar2 * 2;
+      *param_3 = uVar2 * 2;
     }
   }
-  return uVar1;
+  return uVar3;
 }
 

```


## CClfsRequest::AllocContainer

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.32|
|i_ratio|0.47|
|m_ratio|0.94|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|AllocContainer|AllocContainer|
|fullname|CClfsRequest::AllocContainer|CClfsRequest::AllocContainer|
|refcount|2|2|
|`length`|715|799|
|`called`|NTOSKRNL.EXE::KeSetEvent<br>RtlStringCbLengthW<br>RtlStringLengthWorkerW<br>WPP_SF_slS<br>_guard_dispatch_icall|NTOSKRNL.EXE::KeSetEvent<br>RtlStringCbLengthW<br>WPP_SF_slS<br>_guard_dispatch_icall|
|calling|CClfsRequest::Dispatch|CClfsRequest::Dispatch|
|paramcount|1|1|
|`address`|1c0050740|1c00527b0|
|sig|long __thiscall AllocContainer(CClfsRequest * this)|long __thiscall AllocContainer(CClfsRequest * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsRequest::AllocContainer Called Diff


```diff
--- CClfsRequest::AllocContainer called
+++ CClfsRequest::AllocContainer called
@@ -3 +2,0 @@
-RtlStringLengthWorkerW
```


### CClfsRequest::AllocContainer Diff


```diff
--- CClfsRequest::AllocContainer
+++ CClfsRequest::AllocContainer
@@ -1,105 +1,127 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* private: long __cdecl CClfsRequest::AllocContainer(void) __ptr64 */
 
 long __thiscall CClfsRequest::AllocContainer(CClfsRequest *this)
 
 {
   longlong lVar1;
-  longlong *plVar2;
-  uint uVar3;
-  uint uVar4;
+  uint uVar2;
+  longlong *plVar3;
+  wchar_t *pwVar4;
   longlong *plVar5;
-  wchar_t *pwVar6;
-  longlong *plVar7;
+  longlong *plVar6;
+  uint uVar7;
   wchar_t *pwVar8;
   longlong *plVar9;
   longlong local_res10;
   __uint64 local_res18;
-  longlong local_res20;
-  undefined4 in_stack_ffffffffffffff7c;
-  undefined8 local_50;
-  wchar_t *pwStack_48;
+  longlong *local_res20;
+  undefined4 in_stack_ffffffffffffff6c;
+  undefined8 local_80;
+  wchar_t *pwStack_78;
+  int local_70;
+  wchar_t *local_68;
+  longlong *local_60;
+  longlong local_58;
+  wchar_t *local_50;
+  longlong local_48;
   
-  plVar7 = (longlong *)0x0;
-  local_50 = 0;
-  pwStack_48 = (wchar_t *)0x0;
-  lVar1 = *(longlong *)(*(longlong *)(this + 0x30) + 0xb8);
-  uVar3 = *(uint *)(lVar1 + 0x10);
-  local_res10 = CONCAT44(local_res10._4_4_,uVar3);
-  if (uVar3 < 0x10) {
-    uVar4 = 0xc0000206;
+  plVar5 = (longlong *)0x0;
+  local_80 = 0;
+  pwStack_78 = (wchar_t *)0x0;
+  local_60 = (longlong *)0x0;
+  local_58 = *(longlong *)(*(longlong *)(this + 0x30) + 0xb8);
+  uVar7 = *(uint *)(local_58 + 0x10);
+  if (uVar7 < 0x10) {
+    uVar2 = 0xc0000206;
   }
   else {
-    plVar2 = *(longlong **)(*(longlong *)(this + 0x30) + 0x18);
+    local_res20 = *(longlong **)(*(longlong *)(this + 0x30) + 0x18);
     local_res18 = 0;
-    local_res20 = 0;
-    pwVar6 = (wchar_t *)(plVar2 + 2);
-    plVar5 = plVar7;
-    pwVar8 = pwVar6;
-    plVar9 = plVar7;
-    while( true ) {
-      if ((uint)*(ushort *)(plVar2 + 1) <= (uint)plVar9) break;
-      uVar3 = RtlStringCbLengthW((ushort *)pwVar8,((ulonglong)uVar3 - local_res20) - 0x10,
+    pwVar4 = (wchar_t *)(local_res20 + 2);
+    plVar3 = plVar5;
+    plVar6 = plVar5;
+    pwVar8 = pwVar4;
+    for (plVar9 = plVar5; local_68 = pwVar8, (uint)plVar9 < (uint)*(ushort *)(local_res20 + 1);
+        plVar9 = (longlong *)(ulonglong)((uint)plVar9 + 1)) {
+      uVar2 = RtlStringCbLengthW((ushort *)pwVar8,((ulonglong)uVar7 - (longlong)plVar6) - 0x10,
                                  &local_res18);
-      plVar5 = (longlong *)(ulonglong)uVar3;
-      if ((int)uVar3 < 0) goto LAB_0;
+      plVar3 = (longlong *)(ulonglong)uVar2;
+      if ((int)uVar2 < 0) goto LAB_0;
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
         WPP_SF_slS(WPP_GLOBAL_Control[3],0x15,&WPP_718c7adf00f03a045b2a6a7d3a85311c_Traceguids,
-                   "CClfsRequest::AllocContainer",CONCAT44(in_stack_ffffffffffffff7c,0x1a32),pwVar8)
+                   "CClfsRequest::AllocContainer",CONCAT44(in_stack_ffffffffffffff6c,0x1a32),pwVar8)
         ;
       }
-      local_res20 = local_res20 + 2 + local_res18;
+      plVar6 = (longlong *)((longlong)plVar6 + local_res18 + 2);
       pwVar8 = (wchar_t *)((longlong)pwVar8 + local_res18 + 2);
-      plVar9 = (longlong *)(ulonglong)((uint)plVar9 + 1);
-      uVar3 = (uint)local_res10;
     }
-    lVar1 = *(longlong *)(lVar1 + 0x30);
-    plVar9 = *(longlong **)(*(longlong *)(lVar1 + 0x18) + 0x70);
-    *(longlong **)(this + 0x90) = plVar9;
-    (**(code **)(*plVar9 + 0x40))();
-    for (uVar3 = 0; uVar4 = (uint)plVar5, uVar3 < *(ushort *)(plVar2 + 1); uVar3 = uVar3 + 1) {
-      uVar4 = 0;
-      local_50 = 0;
-      pwStack_48 = (wchar_t *)0x0;
-      if (pwVar6 != (wchar_t *)0x0) {
-        local_res10 = 0;
-        uVar4 = RtlStringLengthWorkerW(pwVar6,0x7fff,&local_res10);
-        if (-1 < (int)uVar4) {
-          local_res20 = local_res10 * 2;
-          local_50._0_4_ = CONCAT22((short)local_res20 + 2,(short)local_res20);
-          pwStack_48 = pwVar6;
+    lVar1 = *(longlong *)(local_58 + 0x30);
+    plVar6 = *(longlong **)(*(longlong *)(lVar1 + 0x18) + 0x70);
+    *(longlong **)(this + 0x90) = plVar6;
+    (**(code **)(*plVar6 + 0x40))();
+    plVar6 = local_res20;
+    uVar7 = 0;
+    while( true ) {
+      uVar2 = (uint)plVar3;
+      local_68 = pwVar4;
+      if (*(ushort *)(plVar6 + 1) <= uVar7) break;
+      local_70 = 0;
+      local_80 = 0;
+      pwStack_78 = (wchar_t *)0x0;
+      if (pwVar4 != (wchar_t *)0x0) {
+        local_48 = 0x7fff;
+        for (local_50 = pwVar4; (local_48 != 0 && (*local_50 != L'\0')); local_50 = local_50 + 1) {
+          local_48 = local_48 + -1;
+        }
+        local_70 = 0;
+        if (local_48 == 0) {
+          local_70 = -0x3ffffff3;
+        }
+        if (local_70 < 0) {
+          local_res10 = 0;
+        }
+        else {
+          local_res10 = 0x7fff - local_48;
+        }
+        if (-1 < local_70) {
+          local_res20 = (longlong *)(local_res10 * 2);
+          local_80 = (ulonglong)CONCAT22((short)local_res20 + 2,(short)local_res20);
+          pwStack_78 = pwVar4;
         }
       }
-      if ((int)uVar4 < 0) goto LAB_0;
-      if (*plVar2 != -1) {
-        plVar7 = plVar2;
+      if (local_70 < 0) goto LAB_0;
+      if (*plVar6 != -1) {
+        plVar5 = plVar6;
       }
-      uVar4 = (**(code **)(**(longlong **)(this + 0x90) + 0xd8))
-                        (*(longlong **)(this + 0x90),lVar1,&local_50,plVar7);
-      plVar5 = (longlong *)(ulonglong)uVar4;
-      if ((int)uVar4 < 0) break;
-      pwVar6 = pwVar6 + (local_50 >> 1 & 0x7fff) + 1;
+      local_60 = plVar5;
+      uVar2 = (**(code **)(**(longlong **)(this + 0x90) + 0xd8))
+                        (*(longlong **)(this + 0x90),lVar1,&local_80,plVar5);
+      plVar3 = (longlong *)(ulonglong)uVar2;
+      if ((int)uVar2 < 0) break;
+      pwVar4 = pwVar4 + (local_80 >> 1 & 0x7fff) + 1;
+      uVar7 = uVar7 + 1;
     }
   }
 LAB_1:
-  uVar3 = *(uint *)(this + 0x10);
-  if (((uVar3 & 1) != 0) && (*(longlong *)(*(longlong *)(this + 0x30) + 0x50) != 0)) {
+  uVar7 = *(uint *)(this + 0x10);
+  if (((uVar7 & 1) != 0) && (*(longlong *)(*(longlong *)(this + 0x30) + 0x50) != 0)) {
     KeSetEvent(*(longlong *)(*(longlong *)(this + 0x30) + 0x50),0,0);
-    uVar3 = *(uint *)(this + 0x10);
+    uVar7 = *(uint *)(this + 0x10);
   }
-  if ((uVar3 & 4) == 0) {
-    *(uint *)(*(longlong *)(this + 0x30) + 0x30) = uVar4;
+  if ((uVar7 & 4) == 0) {
+    *(uint *)(*(longlong *)(this + 0x30) + 0x30) = uVar2;
     *(undefined8 *)(*(longlong *)(this + 0x30) + 0x38) = 0;
-    if (plVar7 != (longlong *)0x0) {
-      **(longlong **)(*(longlong *)(this + 0x30) + 0x18) = *plVar7;
+    if (plVar5 != (longlong *)0x0) {
+      **(longlong **)(*(longlong *)(this + 0x30) + 0x18) = *plVar5;
       *(undefined8 *)(*(longlong *)(this + 0x30) + 0x38) = 8;
     }
   }
-  return uVar4;
+  return uVar2;
 LAB_0:
-  uVar4 = 0xc00000e8;
+  uVar2 = 0xc00000e8;
   goto LAB_1;
 }
 

```


## CClfsBaseFilePersisted::LoadContainerQ

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,length,address,calling,called|
|ratio|0.17|
|i_ratio|0.37|
|m_ratio|0.89|
|b_ratio|0.72|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|LoadContainerQ|LoadContainerQ|
|fullname|CClfsBaseFilePersisted::LoadContainerQ|CClfsBaseFilePersisted::LoadContainerQ|
|refcount|3|3|
|`length`|3056|3847|
|`called`|<details><summary>Expand for full list:<br>CClfsBaseFile::ContainerCount<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::DestroyAbsoluteContainerPath<br>CClfsBaseFilePersisted::FlushImage<br>CClfsBaseFilePersisted::QueryBaseSecurity<br>CClfsBaseFilePersisted::QueryContainerSecurity</summary>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsContainer::CClfsContainer<br>CClfsContainer::Create<br>CClfsContainer::FinishInitializeFile<br>CClfsContainer::GetRawSectorSize<br>CClfsContainer::Open<br>CClfsContainer::Remove<br>ClfsIsContainerPathRelative<br>ClfsMgmtpApcRundown<br>ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::IoGetFileObjectGenericMapping<br>NTOSKRNL.EXE::RtlInitUnicodeString<br>NTOSKRNL.EXE::RtlSetBits<br>NTOSKRNL.EXE::SeAccessCheck<br>NTOSKRNL.EXE::SeCaptureSubjectContext<br>NTOSKRNL.EXE::SeLockSubjectContext<br>NTOSKRNL.EXE::SeReleaseSubjectContext<br>NTOSKRNL.EXE::SeUnlockSubjectContext<br>WPP_SF_sdiD<br>WPP_SF_sdiSdd<br>WPP_SF_sdidd<br>WPP_SF_slS<br>_guard_dispatch_icall<br>memcpy<br>memset<br>operator_delete<br>operator_new</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::ContainerCount<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::OffsetToAddr<br>CClfsBaseFile::ReleaseClientContext<br>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::DestroyAbsoluteContainerPath<br>CClfsBaseFilePersisted::FlushImage</summary>CClfsBaseFilePersisted::QueryBaseSecurity<br>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsContainer::CClfsContainer<br>CClfsContainer::Create<br>CClfsContainer::FinishInitializeFile<br>CClfsContainer::GetRawSectorSize<br>CClfsContainer::Open<br>CClfsContainer::Remove<br>ClfsIsContainerPathRelative<br>ClfsMgmtpApcRundown<br>ExAllocateFromPagedLookasideList<br>Feature_Servicing_40191887__private_IsEnabled<br>Feature_Servicing_41154977__private_IsEnabled<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite<br>NTOSKRNL.EXE::IoGetFileObjectGenericMapping<br>NTOSKRNL.EXE::RtlInitUnicodeString<br>NTOSKRNL.EXE::RtlSetBits<br>NTOSKRNL.EXE::SeAccessCheck<br>NTOSKRNL.EXE::SeCaptureSubjectContext<br>NTOSKRNL.EXE::SeLockSubjectContext<br>NTOSKRNL.EXE::SeReleaseSubjectContext<br>NTOSKRNL.EXE::SeUnlockSubjectContext<br>ULongLongAdd<br>WPP_SF_sdiD<br>WPP_SF_sdiSdd<br>WPP_SF_sdidd<br>WPP_SF_slS<br>_guard_dispatch_icall<br>memcpy<br>memset<br>operator_delete<br>operator_new</details>|
|`calling`|CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize|CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize|
|paramcount|9|9|
|`address`|1c0035ac0|1c0037820|
|sig|long __thiscall LoadContainerQ(CClfsBaseFilePersisted * this, ulong * param_1, ulong param_2, uchar param_3, uchar param_4, _CLS_LSN param_5, ulong * param_6, ulong * param_7, __uint64 * param_8)|long __thiscall LoadContainerQ(CClfsBaseFilePersisted * this, ulong * param_1, ulong param_2, uchar param_3, uchar param_4, _CLS_LSN param_5, ulong * param_6, ulong * param_7, __uint64 * param_8)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFilePersisted::LoadContainerQ Called Diff


```diff
--- CClfsBaseFilePersisted::LoadContainerQ called
+++ CClfsBaseFilePersisted::LoadContainerQ called
@@ -3,0 +4 @@
+CClfsBaseFile::GetSymbol
@@ -5,0 +7 @@
+CClfsBaseFile::ValidateOffsets
@@ -23,0 +26,2 @@
+Feature_Servicing_40191887__private_IsEnabled
+Feature_Servicing_41154977__private_IsEnabled
@@ -33,0 +38 @@
+ULongLongAdd
```


### CClfsBaseFilePersisted::LoadContainerQ Calling Diff


```diff

```


### CClfsBaseFilePersisted::LoadContainerQ Diff


```diff
--- CClfsBaseFilePersisted::LoadContainerQ
+++ CClfsBaseFilePersisted::LoadContainerQ
@@ -1,625 +1,755 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: long __cdecl CClfsBaseFilePersisted::LoadContainerQ(unsigned long * __ptr64
    const,unsigned long,unsigned char,unsigned char,union _CLS_LSN,unsigned long & __ptr64,unsigned
    long & __ptr64,unsigned __int64 & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::LoadContainerQ
           (CClfsBaseFilePersisted *this,ulong *param_1,uint param_2,uchar param_3,char param_4,
           undefined8 param_6,uint *param_7,uint *param_8,CClfsContainer *param_9)
 
 {
   undefined1 uVar1;
-  uint uVar2;
-  undefined1 auVar3 [16];
-  bool bVar4;
-  _KAPC *p_Var5;
-  _CLFS_CONTAINER_CONTEXT *p_Var6;
-  char cVar7;
-  uchar uVar8;
-  char cVar9;
-  ulong uVar10;
-  long lVar11;
-  long lVar12;
-  uint uVar13;
-  _CLFS_BASE_RECORD_HEADER *p_Var14;
-  CClfsContainer *pCVar15;
-  CClfsContainer *pCVar16;
-  void *pvVar17;
-  wchar_t *pwVar18;
-  undefined8 *puVar19;
-  undefined8 uVar20;
-  __uint64 _Var21;
+  undefined1 auVar2 [16];
+  bool bVar3;
+  _KAPC *p_Var4;
+  _CLFS_CONTAINER_CONTEXT *p_Var5;
+  char cVar6;
+  uchar uVar7;
+  char cVar8;
+  int iVar9;
+  long lVar10;
+  uint uVar11;
+  uint uVar12;
+  _CLFS_BASE_RECORD_HEADER *p_Var13;
+  void *pvVar14;
+  wchar_t *pwVar15;
+  undefined8 *puVar16;
+  undefined8 uVar17;
+  __uint64 _Var18;
+  uint uVar19;
+  CClfsContainer *pCVar20;
+  CClfsContainer *pCVar21;
   CClfsContainer *pCVar22;
   longlong lVar23;
-  ulong uVar24;
-  uint uVar25;
+  uint uVar24;
+  _UNICODE_STRING *p_Var25;
   _UNICODE_STRING *p_Var26;
-  _UNICODE_STRING *p_Var27;
-  _CLFS_BASE_RECORD_HEADER *p_Var28;
-  ulonglong uVar29;
-  _CLFS_FILTER_CONTEXT *p_Var30;
-  ulong *puVar31;
-  _CLFS_CONTAINER_CONTEXT *p_Var32;
-  undefined8 uVar33;
-  ulonglong uVar34;
-  uint *puVar35;
-  uint uVar36;
-  uint *puVar37;
-  _CLFS_BASE_RECORD_HEADER *_Src;
-  undefined4 uVar38;
-  undefined4 uVar39;
-  undefined4 uVar40;
+  _CLFS_BASE_RECORD_HEADER *p_Var27;
+  ulong uVar28;
+  _CLFS_BASE_RECORD_HEADER *p_Var29;
+  CClfsContainer *pCVar30;
+  _CLFS_CONTAINER_CONTEXT **pp_Var31;
+  ulonglong uVar32;
+  _CLFS_FILTER_CONTEXT *p_Var33;
+  ulong *puVar34;
+  _CLFS_CONTAINER_CONTEXT *p_Var35;
+  undefined8 uVar36;
+  ulonglong uVar37;
+  uint *puVar38;
+  ulonglong uVar39;
+  uint *puVar40;
   undefined4 uVar41;
+  undefined4 uVar42;
+  undefined4 uVar43;
+  undefined4 uVar44;
   uint local_res18 [2];
   uchar local_res20;
   uint *in_stack_fffffffffffffed8;
   long local_f8;
   uint local_f0;
   _KAPC *local_e8;
-  uint *local_e0;
-  uint local_d8;
-  _CLFS_CLIENT_CONTEXT *local_d0;
-  undefined8 local_c8;
-  undefined8 uStack_c0;
-  undefined8 local_b8;
-  undefined8 uStack_b0;
-  undefined4 local_a8;
-  undefined4 local_a4;
-  ulong local_a0;
-  _CLFS_CONTAINER_CONTEXT *local_98 [2];
-  undefined8 local_88;
-  undefined8 uStack_80;
-  ulonglong local_78;
-  _CLFS_BASE_RECORD_HEADER *local_70;
-  uint local_68;
-  undefined8 local_60;
-  undefined8 uStack_58;
-  undefined8 local_50;
-  undefined8 uStack_48;
+  _CLFS_CLIENT_CONTEXT *local_e0;
+  _CLFS_CONTAINER_CONTEXT *local_d8;
+  ulong local_d0;
+  uint *local_c8;
+  _CLFS_CONTAINER_CONTEXT *local_c0;
+  ulong local_b8;
+  undefined8 local_a8;
+  undefined8 uStack_a0;
+  undefined8 local_98;
+  undefined8 uStack_90;
+  undefined4 local_88;
+  undefined4 local_84 [3];
+  undefined8 local_78;
+  undefined8 uStack_70;
+  ulonglong local_68;
+  _CLFS_BASE_RECORD_HEADER *local_60;
+  undefined8 local_58;
+  undefined8 uStack_50;
+  undefined8 local_48;
+  undefined8 uStack_40;
   
-  puVar37 = param_8;
-  puVar35 = param_7;
+  puVar38 = param_8;
+  puVar40 = param_7;
+  pCVar20 = (CClfsContainer *)0x0;
+  local_68 = 0;
+  local_98 = 0;
+  uStack_90 = 0;
+  local_a8 = 0;
+  uStack_a0 = 0;
   local_78 = 0;
-  local_b8 = 0;
-  uStack_b0 = 0;
-  local_c8 = 0;
-  uStack_c0 = 0;
-  local_88 = 0;
-  uStack_80 = 0;
-  local_d0 = (_CLFS_CLIENT_CONTEXT *)0x0;
-  local_e0 = (uint *)0x0;
+  uStack_70 = 0;
+  local_e0 = (_CLFS_CLIENT_CONTEXT *)0x0;
+  pCVar21 = *(CClfsContainer **)(*(longlong *)(this + 0x30) + 0x30);
+  local_c8 = (uint *)0x0;
   local_e8 = (_KAPC *)0x0;
   param_6._0_4_ = 0;
   local_res18[0] = param_2 & 0xffffff00;
-  bVar4 = false;
-  local_60 = 0;
-  uStack_58 = 0;
-  local_50 = 0;
-  uStack_48 = 0;
-  local_a4 = 0;
-  local_a8 = 0;
+  bVar3 = false;
+  local_58 = 0;
+  uStack_50 = 0;
+  local_48 = 0;
+  uStack_40 = 0;
+  local_84[0] = 0;
+  local_88 = 0;
+  local_c0 = (_CLFS_CONTAINER_CONTEXT *)0x0;
+  local_d8 = (_CLFS_CONTAINER_CONTEXT *)0x0;
   *(__uint64 *)param_9 = 0;
   *param_7 = 0xffffffff;
   *param_8 = 0;
-  uVar13 = 0x1000;
+  pCVar30 = (CClfsContainer *)0x1000;
   local_res20 = param_3;
   memset(param_1,-1,0x1000);
-  cVar7 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20));
-  pCVar15 = (CClfsContainer *)this;
-  p_Var14 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
-  if (p_Var14 == (_CLFS_BASE_RECORD_HEADER *)0x0) {
+  cVar6 = ExAcquireResourceExclusiveLite(*(undefined8 *)(this + 0x20),1);
+  pCVar22 = (CClfsContainer *)this;
+  p_Var13 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
+  uVar12 = (uint)pCVar30;
+  if (p_Var13 == (_CLFS_BASE_RECORD_HEADER *)0x0) {
     local_f8 = -0x3fe5fff3;
-    lVar11 = -0x3fe5fff3;
-  }
-  else {
-    _Src = p_Var14 + 0x328;
-    pCVar15 = (CClfsContainer *)this;
-    local_70 = _Src;
-    uVar10 = CClfsBaseFile::ContainerCount((CClfsBaseFile *)this);
-    uVar24 = 0;
-    pCVar22 = (CClfsContainer *)0x0;
-    while ((uint)pCVar22 < 0x400) {
-      if (*(int *)(_Src + (longlong)pCVar22 * 4) != 0) {
-        uVar24 = uVar24 + 1;
+    lVar10 = local_f8;
+    goto LAB_0;
+  }
+  iVar9 = Feature_Servicing_41154977__private_IsEnabled();
+  uVar12 = (uint)pCVar30;
+  if (iVar9 == 0) {
+LAB_1:
+    pCVar22 = (CClfsContainer *)this;
+    local_60 = p_Var13 + 0x328;
+    local_d0 = CClfsBaseFile::ContainerCount((CClfsBaseFile *)this);
+    uVar28 = 0;
+    pCVar21 = pCVar20;
+    while( true ) {
+      uVar12 = (uint)pCVar30;
+      uVar19 = (uint)pCVar20;
+      if (0x3ff < uVar19) break;
+      lVar10 = *(long *)(p_Var13 + 0x328 + (longlong)pCVar20 * 4);
+      pCVar22 = pCVar20;
+      if (lVar10 != 0) {
+        uVar28 = uVar28 + 1;
+        local_d8 = (_CLFS_CONTAINER_CONTEXT *)0x0;
+        pCVar22 = (CClfsContainer *)this;
+        uVar11 = CClfsBaseFile::GetSymbol((CClfsBaseFile *)this,lVar10,uVar19,&local_d8);
+        uVar12 = (uint)pCVar20;
+        pCVar21 = (CClfsContainer *)(ulonglong)uVar11;
+        pCVar30 = pCVar20;
+        if ((int)uVar11 < 0) goto LAB_2;
       }
-      local_68 = (uint)pCVar22 + 1;
-      pCVar15 = pCVar22;
-      pCVar22 = (CClfsContainer *)(ulonglong)local_68;
+      pCVar20 = (CClfsContainer *)(ulonglong)(uVar19 + 1);
+      local_c0 = (_CLFS_CONTAINER_CONTEXT *)CONCAT44(local_c0._4_4_,uVar19 + 1);
     }
-    local_a0 = uVar10;
-    if (uVar10 == 0) {
-      *puVar35 = 0;
-      lVar11 = 0;
-      local_f8 = lVar11;
-      if (uVar24 != 0) {
-        lVar11 = -0x3fe5fff3;
-        local_f8 = lVar11;
+    if (local_d0 == 0) {
+      *puVar40 = 0;
+      puVar38 = param_8;
+      lVar10 = (long)pCVar21;
+      local_f8 = (long)pCVar21;
+      if (uVar28 != 0) {
+        lVar10 = -0x3fe5fff3;
+        local_f8 = -0x3fe5fff3;
       }
     }
-    else if (uVar24 == uVar10) {
+    else if (uVar28 == local_d0) {
+      iVar9 = Feature_Servicing_40191887__private_IsEnabled();
+      if (iVar9 != 0) {
+        pCVar22 = (CClfsContainer *)this;
+        lVar10 = CClfsBaseFile::ValidateOffsets((CClfsBaseFile *)this,p_Var13);
+        uVar12 = (uint)pCVar30;
+        puVar38 = param_8;
+        local_f8 = lVar10;
+        if (lVar10 < 0) goto LAB_0;
+      }
+      uVar37 = 0;
+      uVar32 = uVar37;
+      while( true ) {
+        uVar12 = (uint)pCVar30;
+        uVar19 = (uint)uVar32;
+        local_c0 = (_CLFS_CONTAINER_CONTEXT *)CONCAT44(local_c0._4_4_,uVar19);
+        if (0x7b < uVar19) break;
+        iVar9 = *(int *)(p_Var13 + 0x138 + uVar32 * 4);
+        if (iVar9 - 1U < 0xfffffffe) {
+          local_e0 = (_CLFS_CLIENT_CONTEXT *)0x0;
+          pCVar30 = (CClfsContainer *)(uVar32 & 0xff);
+          pCVar22 = (CClfsContainer *)this;
+          lVar10 = CClfsBaseFile::GetSymbol((CClfsBaseFile *)this,iVar9,(uchar)uVar32,&local_e0);
+          uVar12 = (uint)pCVar30;
+          if (lVar10 < 0) {
+            local_e0 = (_CLFS_CLIENT_CONTEXT *)0x0;
+            local_f8 = -0x3fe5fff3;
+            puVar38 = param_8;
+            lVar10 = -0x3fe5fff3;
+            goto LAB_0;
+          }
+        }
+        uVar32 = (ulonglong)(uVar19 + 1);
+      }
+      local_e0 = (_CLFS_CLIENT_CONTEXT *)0x0;
       pCVar22 = (CClfsContainer *)0x11f0;
-      pCVar15 = operator_new(0x11f0,1);
-      if (pCVar15 == (CClfsContainer *)0x0) {
+      pCVar30 = operator_new(0x11f0,1);
+      p_Var29 = local_60;
+      if (pCVar30 == (CClfsContainer *)0x0) {
         local_f8 = -0x3fffff66;
-        pCVar15 = pCVar22;
-        lVar11 = -0x3fffff66;
+        puVar38 = param_8;
+        lVar10 = -0x3fffff66;
       }
       else {
-        uVar29 = 0x1000;
-        memcpy(pCVar15,_Src,0x1000);
+        uVar32 = 0x1000;
+        memcpy(pCVar30,local_60,0x1000);
         lVar23 = 3;
-        pCVar22 = pCVar15 + 0x1000;
-        p_Var14 = p_Var14 + 0x138;
+        pCVar22 = pCVar30 + 0x1000;
+        p_Var13 = p_Var13 + 0x138;
         do {
-          p_Var28 = p_Var14;
-          pCVar16 = pCVar22;
-          _Var21 = *(__uint64 *)(p_Var28 + 8);
-          *(__uint64 *)pCVar16 = *(__uint64 *)p_Var28;
-          *(__uint64 *)(pCVar16 + 8) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x18);
-          *(__uint64 *)(pCVar16 + 0x10) = *(__uint64 *)(p_Var28 + 0x10);
-          *(__uint64 *)(pCVar16 + 0x18) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x28);
-          *(__uint64 *)(pCVar16 + 0x20) = *(__uint64 *)(p_Var28 + 0x20);
-          *(__uint64 *)(pCVar16 + 0x28) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x38);
-          *(__uint64 *)(pCVar16 + 0x30) = *(__uint64 *)(p_Var28 + 0x30);
-          *(__uint64 *)(pCVar16 + 0x38) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x48);
-          *(__uint64 *)(pCVar16 + 0x40) = *(__uint64 *)(p_Var28 + 0x40);
-          *(__uint64 *)(pCVar16 + 0x48) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x58);
-          *(__uint64 *)(pCVar16 + 0x50) = *(__uint64 *)(p_Var28 + 0x50);
-          *(__uint64 *)(pCVar16 + 0x58) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x68);
-          *(__uint64 *)(pCVar16 + 0x60) = *(__uint64 *)(p_Var28 + 0x60);
-          *(__uint64 *)(pCVar16 + 0x68) = _Var21;
-          _Var21 = *(__uint64 *)(p_Var28 + 0x78);
-          *(__uint64 *)(pCVar16 + 0x70) = *(__uint64 *)(p_Var28 + 0x70);
-          *(__uint64 *)(pCVar16 + 0x78) = _Var21;
+          p_Var27 = p_Var13;
+          pCVar21 = pCVar22;
+          _Var18 = *(__uint64 *)(p_Var27 + 8);
+          *(__uint64 *)pCVar21 = *(__uint64 *)p_Var27;
+          *(__uint64 *)(pCVar21 + 8) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x18);
+          *(__uint64 *)(pCVar21 + 0x10) = *(__uint64 *)(p_Var27 + 0x10);
+          *(__uint64 *)(pCVar21 + 0x18) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x28);
+          *(__uint64 *)(pCVar21 + 0x20) = *(__uint64 *)(p_Var27 + 0x20);
+          *(__uint64 *)(pCVar21 + 0x28) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x38);
+          *(__uint64 *)(pCVar21 + 0x30) = *(__uint64 *)(p_Var27 + 0x30);
+          *(__uint64 *)(pCVar21 + 0x38) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x48);
+          *(__uint64 *)(pCVar21 + 0x40) = *(__uint64 *)(p_Var27 + 0x40);
+          *(__uint64 *)(pCVar21 + 0x48) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x58);
+          *(__uint64 *)(pCVar21 + 0x50) = *(__uint64 *)(p_Var27 + 0x50);
+          *(__uint64 *)(pCVar21 + 0x58) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x68);
+          *(__uint64 *)(pCVar21 + 0x60) = *(__uint64 *)(p_Var27 + 0x60);
+          *(__uint64 *)(pCVar21 + 0x68) = _Var18;
+          _Var18 = *(__uint64 *)(p_Var27 + 0x78);
+          *(__uint64 *)(pCVar21 + 0x70) = *(__uint64 *)(p_Var27 + 0x70);
+          *(__uint64 *)(pCVar21 + 0x78) = _Var18;
           lVar23 = lVar23 + -1;
-          pCVar22 = pCVar16 + 0x80;
-          p_Var14 = p_Var28 + 0x80;
+          pCVar22 = pCVar21 + 0x80;
+          p_Var13 = p_Var27 + 0x80;
         } while (lVar23 != 0);
-        _Var21 = *(__uint64 *)(p_Var28 + 0x88);
-        *(__uint64 *)(pCVar16 + 0x80) = *(__uint64 *)(p_Var28 + 0x80);
-        *(__uint64 *)(pCVar16 + 0x88) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 0x98);
-        *(__uint64 *)(pCVar16 + 0x90) = *(__uint64 *)(p_Var28 + 0x90);
-        *(__uint64 *)(pCVar16 + 0x98) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 0xa8);
-        *(__uint64 *)(pCVar16 + 0xa0) = *(__uint64 *)(p_Var28 + 0xa0);
-        *(__uint64 *)(pCVar16 + 0xa8) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 0xb8);
-        *(__uint64 *)(pCVar16 + 0xb0) = *(__uint64 *)(p_Var28 + 0xb0);
-        *(__uint64 *)(pCVar16 + 0xb8) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 200);
-        *(__uint64 *)(pCVar16 + 0xc0) = *(__uint64 *)(p_Var28 + 0xc0);
-        *(__uint64 *)(pCVar16 + 200) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 0xd8);
-        *(__uint64 *)(pCVar16 + 0xd0) = *(__uint64 *)(p_Var28 + 0xd0);
-        *(__uint64 *)(pCVar16 + 0xd8) = _Var21;
-        _Var21 = *(__uint64 *)(p_Var28 + 0xe8);
-        *(__uint64 *)(pCVar16 + 0xe0) = *(__uint64 *)(p_Var28 + 0xe0);
-        *(__uint64 *)(pCVar16 + 0xe8) = _Var21;
+        _Var18 = *(__uint64 *)(p_Var27 + 0x88);
+        *(__uint64 *)(pCVar21 + 0x80) = *(__uint64 *)(p_Var27 + 0x80);
+        *(__uint64 *)(pCVar21 + 0x88) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 0x98);
+        *(__uint64 *)(pCVar21 + 0x90) = *(__uint64 *)(p_Var27 + 0x90);
+        *(__uint64 *)(pCVar21 + 0x98) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 0xa8);
+        *(__uint64 *)(pCVar21 + 0xa0) = *(__uint64 *)(p_Var27 + 0xa0);
+        *(__uint64 *)(pCVar21 + 0xa8) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 0xb8);
+        *(__uint64 *)(pCVar21 + 0xb0) = *(__uint64 *)(p_Var27 + 0xb0);
+        *(__uint64 *)(pCVar21 + 0xb8) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 200);
+        *(__uint64 *)(pCVar21 + 0xc0) = *(__uint64 *)(p_Var27 + 0xc0);
+        *(__uint64 *)(pCVar21 + 200) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 0xd8);
+        *(__uint64 *)(pCVar21 + 0xd0) = *(__uint64 *)(p_Var27 + 0xd0);
+        *(__uint64 *)(pCVar21 + 0xd8) = _Var18;
+        _Var18 = *(__uint64 *)(p_Var27 + 0xe8);
+        *(__uint64 *)(pCVar21 + 0xe0) = *(__uint64 *)(p_Var27 + 0xe0);
+        *(__uint64 *)(pCVar21 + 0xe8) = _Var18;
         local_f8 = CClfsBaseFile::ValidateRgOffsets
-                             ((CClfsBaseFile *)this,(ulong *)pCVar15,(ulong)uVar29);
-        operator_delete(pCVar15);
-        uVar13 = (uint)uVar29;
-        lVar11 = local_f8;
+                             ((CClfsBaseFile *)this,(ulong *)pCVar30,(ulong)uVar32);
+        operator_delete(pCVar30);
+        uVar12 = (uint)uVar32;
+        pCVar22 = pCVar30;
+        puVar38 = param_8;
+        lVar10 = local_f8;
         if (-1 < local_f8) {
-          uVar34 = 0;
-          local_d8 = 0;
-          uVar36 = 0;
+          local_b8 = 0;
           local_f0 = 0;
+          uVar39 = uVar37;
           while( true ) {
-            uVar13 = (uint)uVar29;
-            uVar25 = (uint)uVar34;
-            if ((0x3ff < uVar25) || (uVar10 <= uVar36)) break;
-            local_98[0] = (_CLFS_CONTAINER_CONTEXT *)0x0;
-            pCVar15 = (CClfsContainer *)&local_c8;
-            RtlInitUnicodeString(pCVar15,L"");
-            uVar13 = (uint)uVar29;
-            uVar2 = *(uint *)(_Src + uVar34 * 4);
-            if (uVar2 == 0) {
-              local_d8 = uVar25 + 1;
-              uVar34 = (ulonglong)local_d8;
+            uVar12 = (uint)uVar32;
+            uVar19 = (uint)uVar37;
+            uVar11 = (uint)uVar39;
+            if ((0x3ff < uVar19) || (local_d0 <= uVar11)) break;
+            local_d8 = (_CLFS_CONTAINER_CONTEXT *)0x0;
+            pCVar30 = (CClfsContainer *)&local_a8;
+            RtlInitUnicodeString(pCVar30,L"");
+            uVar12 = (uint)uVar32;
+            uVar24 = *(uint *)(p_Var29 + uVar37 * 4);
+            if (uVar24 == 0) {
+              local_b8 = uVar19 + 1;
+              uVar37 = (ulonglong)local_b8;
             }
             else {
-              if (uVar2 < 0x1338) goto LAB_0;
-              pCVar15 = (CClfsContainer *)this;
-              uVar29 = uVar34;
-              lVar11 = CClfsBaseFile::GetSymbol((CClfsBaseFile *)this,uVar2,uVar25,local_98);
-              uVar13 = (uint)uVar29;
-              if (((lVar11 < 0) ||
-                  (pCVar15 = (CClfsContainer *)this,
-                  pvVar17 = CClfsBaseFile::OffsetToAddr((CClfsBaseFile *)this,uVar2),
-                  pvVar17 == (void *)0x0)) ||
-                 (pCVar15 = (CClfsContainer *)this,
-                 pwVar18 = CClfsBaseFile::OffsetToAddr
-                                     ((CClfsBaseFile *)this,*(ulong *)((longlong)pvVar17 + -0x10)),
-                 pwVar18 == (wchar_t *)0x0)) goto LAB_0;
+              if ((((uVar24 < 0x1338) ||
+                   (pCVar30 = (CClfsContainer *)this, uVar12 = uVar19,
+                   lVar10 = CClfsBaseFile::GetSymbol((CClfsBaseFile *)this,uVar24,uVar19,&local_d8),
+                   lVar10 < 0)) ||
+                  (pCVar30 = (CClfsContainer *)this,
+                  pvVar14 = CClfsBaseFile::OffsetToAddr((CClfsBaseFile *)this,uVar24),
+                  pvVar14 == (void *)0x0)) ||
+                 (pCVar30 = (CClfsContainer *)this,
+                 pwVar15 = CClfsBaseFile::OffsetToAddr
+                                     ((CClfsBaseFile *)this,*(ulong *)((longlong)pvVar14 + -0x10)),
+                 pwVar15 == (wchar_t *)0x0)) goto LAB_3;
               if ((WPP_GLOBAL_Control != (CClfsContainer *)&WPP_GLOBAL_Control) &&
                  ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
                 in_stack_fffffffffffffed8 =
-                     (uint *)CONCAT44((int)((ulonglong)in_stack_fffffffffffffed8 >> 0x20),0x367f);
-                uVar13 = 0xc0014220;
-                WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x10,
-                           &WPP_0006c177c1ed3cd226388f19f52a716c_Traceguids,
+                     (uint *)CONCAT44((int)((ulonglong)in_stack_fffffffffffffed8 >> 0x20),0x3ac5);
+                uVar12 = 0xc00152f0;
+                WPP_SF_slS(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x19,
+                           &WPP_908d6a0d40fc35709bb8a8e2055db4b4_Traceguids,
                            "CClfsBaseFilePersisted::LoadContainerQ",in_stack_fffffffffffffed8,
-                           pwVar18);
+                           pwVar15);
               }
-              p_Var6 = local_98[0];
-              p_Var32 = local_98[0] + 8;
-              pCVar15 = param_9;
+              p_Var5 = local_d8;
+              p_Var35 = local_d8 + 8;
               if (*(__uint64 *)param_9 == 0) {
-                uVar29 = *(ulonglong *)p_Var32;
-                if ((uVar29 == 0) || ((uVar29 & 0x7ffff) != 0)) goto LAB_0;
-                *(ulonglong *)param_9 = uVar29;
+                uVar32 = *(ulonglong *)p_Var35;
+                if ((uVar32 == 0) || ((uVar32 & 0x7ffff) != 0)) goto LAB_4;
+                *(ulonglong *)param_9 = uVar32;
               }
-              else if (*(__uint64 *)param_9 != *(__uint64 *)p_Var32) goto LAB_0;
-              uVar13 = *(uint *)(local_98[0] + 0x14);
-              uVar29 = (ulonglong)uVar13;
-              if (uVar13 == 0xffffffff) {
-                *(undefined8 *)(local_98[0] + 0x18) = 0;
-                pCVar15 = (CClfsContainer *)this;
-                local_f8 = RemoveContainer(this,uVar25);
-                uVar13 = (uint)uVar29;
-                puVar35 = param_7;
-                puVar37 = param_8;
-                lVar11 = local_f8;
-                if (local_f8 < 0) goto LAB_1;
-                local_d8 = uVar25 + 1;
-                uVar34 = (ulonglong)local_d8;
-                _Src = local_70;
+              else if (*(__uint64 *)param_9 != *(__uint64 *)p_Var35) {
+LAB_4:
+                local_f8 = -0x3fe5fff3;
+                pCVar22 = param_9;
+                puVar38 = param_8;
+                puVar40 = param_7;
+                lVar10 = local_f8;
+                goto LAB_0;
+              }
+              uVar12 = *(uint *)(local_d8 + 0x14);
+              uVar32 = (ulonglong)uVar12;
+              if (uVar12 == 0xffffffff) {
+                *(undefined8 *)(local_d8 + 0x18) = 0;
+                pCVar30 = (CClfsContainer *)this;
+                local_f8 = RemoveContainer(this,uVar19);
+                uVar12 = (uint)uVar32;
+                pCVar22 = pCVar30;
+                puVar38 = param_8;
+                puVar40 = param_7;
+                lVar10 = local_f8;
+                if (local_f8 < 0) goto LAB_0;
+                local_b8 = uVar19 + 1;
+                uVar37 = (ulonglong)local_b8;
               }
               else {
-                uVar25 = *(uint *)(local_98[0] + 0x24);
-                if ((uVar25 & 8) != 0) {
+                uVar24 = *(uint *)(local_d8 + 0x24);
+                if ((uVar24 & 8) != 0) {
                   if ((WPP_GLOBAL_Control != (CClfsContainer *)&WPP_GLOBAL_Control) &&
                      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-                    uVar13 = 0xc0014220;
-                    WPP_SF_sdiD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x11,
-                                &WPP_0006c177c1ed3cd226388f19f52a716c_Traceguids,
+                    uVar12 = 0xc00152f0;
+                    WPP_SF_sdiD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1a,
+                                &WPP_908d6a0d40fc35709bb8a8e2055db4b4_Traceguids,
                                 "CClfsBaseFilePersisted::LoadContainerQ");
-                    uVar25 = *(uint *)(p_Var6 + 0x24);
-                  }
-                  uVar25 = uVar25 & 0xfffffff7;
-                  *(uint *)(p_Var6 + 0x24) = uVar25;
-                }
-                if ((uVar25 & 0x20) != 0) {
+                    uVar24 = *(uint *)(p_Var5 + 0x24);
+                  }
+                  uVar24 = uVar24 & 0xfffffff7;
+                  *(uint *)(p_Var5 + 0x24) = uVar24;
+                }
+                if ((uVar24 & 0x20) != 0) {
                   if ((WPP_GLOBAL_Control != (CClfsContainer *)&WPP_GLOBAL_Control) &&
                      ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x8000000) != 0)) {
-                    uVar13 = 0xc0014220;
-                    WPP_SF_sdiD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x12,
-                                &WPP_0006c177c1ed3cd226388f19f52a716c_Traceguids,
+                    uVar12 = 0xc00152f0;
+                    WPP_SF_sdiD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1b,
+                                &WPP_908d6a0d40fc35709bb8a8e2055db4b4_Traceguids,
                                 "CClfsBaseFilePersisted::LoadContainerQ");
-                    uVar25 = *(uint *)(p_Var6 + 0x24);
-                  }
-                  *(uint *)(p_Var6 + 0x24) = uVar25 & 0xffffffdf;
-                }
-                RtlInitUnicodeString(&local_c8);
-                uVar10 = (ulong)pwVar18;
-                uVar8 = ClfsIsContainerPathRelative((_UNICODE_STRING *)&local_c8);
-                if (uVar8 == '\0') {
-                  uVar38 = (undefined4)local_c8;
-                  uVar39 = local_c8._4_4_;
-                  uVar40 = (undefined4)uStack_c0;
-                  uVar41 = uStack_c0._4_4_;
+                    uVar24 = *(uint *)(p_Var5 + 0x24);
+                  }
+                  *(uint *)(p_Var5 + 0x24) = uVar24 & 0xffffffdf;
+                }
+                RtlInitUnicodeString(&local_a8);
+                uVar28 = (ulong)pwVar15;
+                uVar7 = ClfsIsContainerPathRelative((_UNICODE_STRING *)&local_a8);
+                if (uVar7 == '\0') {
+                  uVar41 = (undefined4)local_a8;
+                  uVar42 = local_a8._4_4_;
+                  uVar43 = (undefined4)uStack_a0;
+                  uVar44 = uStack_a0._4_4_;
                 }
                 else {
-                  p_Var27 = (_UNICODE_STRING *)&local_88;
-                  p_Var26 = (_UNICODE_STRING *)&local_c8;
-                  pCVar15 = (CClfsContainer *)this;
-                  lVar11 = CreateAbsoluteContainerPath(this,p_Var26,p_Var27);
-                  uVar13 = (uint)p_Var27;
-                  uVar10 = (ulong)p_Var26;
-                  puVar35 = param_7;
-                  puVar37 = param_8;
-                  local_f8 = lVar11;
-                  if (lVar11 < 0) goto LAB_1;
-                  bVar4 = true;
-                  uVar38 = (undefined4)local_88;
-                  uVar39 = local_88._4_4_;
-                  uVar40 = (undefined4)uStack_80;
-                  uVar41 = uStack_80._4_4_;
-                }
-                local_b8 = CONCAT44(uVar39,uVar38);
-                uStack_b0 = CONCAT44(uVar41,uVar40);
-                pCVar15 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001e900);
-                if (pCVar15 == (CClfsContainer *)0x0) {
-                  puVar19 = (undefined8 *)0x0;
+                  p_Var26 = (_UNICODE_STRING *)&local_78;
+                  p_Var25 = (_UNICODE_STRING *)&local_a8;
+                  pCVar22 = (CClfsContainer *)this;
+                  lVar10 = CreateAbsoluteContainerPath(this,p_Var25,p_Var26);
+                  uVar12 = (uint)p_Var26;
+                  uVar28 = (ulong)p_Var25;
+                  puVar38 = param_8;
+                  puVar40 = param_7;
+                  local_f8 = lVar10;
+                  if (lVar10 < 0) goto LAB_0;
+                  bVar3 = true;
+                  uVar41 = (undefined4)local_78;
+                  uVar42 = local_78._4_4_;
+                  uVar43 = (undefined4)uStack_70;
+                  uVar44 = uStack_70._4_4_;
+                }
+                local_98 = CONCAT44(uVar42,uVar41);
+                uStack_90 = CONCAT44(uVar44,uVar43);
+                pCVar22 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001f940);
+                if (pCVar22 == (CClfsContainer *)0x0) {
+                  puVar16 = (undefined8 *)0x0;
                 }
                 else {
-                  puVar19 = (undefined8 *)CClfsContainer::CClfsContainer(pCVar15,uVar10);
-                }
-                *(undefined8 **)(p_Var6 + 0x18) = puVar19;
-                if (puVar19 == (undefined8 *)0x0) {
-                  local_f8 = -0x3fffff66;
-                  pCVar15 = (CClfsContainer *)0x0;
-                  puVar35 = param_7;
-                  puVar37 = param_8;
-                  lVar11 = -0x3fffff66;
-                  goto LAB_1;
-                }
-                (**(code **)*puVar19)();
-                pCVar15 = *(CClfsContainer **)(p_Var6 + 0x18);
+                  puVar16 = (undefined8 *)CClfsContainer::CClfsContainer(pCVar22,uVar28);
+                }
+                *(undefined8 **)(p_Var5 + 0x18) = puVar16;
+                if (puVar16 == (undefined8 *)0x0) {
+                  lVar10 = -0x3fffff66;
+                  pCVar22 = (CClfsContainer *)0x0;
+                  puVar38 = param_8;
+                  puVar40 = param_7;
+                  local_f8 = lVar10;
+                  goto LAB_0;
+                }
+                (**(code **)*puVar16)();
+                pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
                 in_stack_fffffffffffffed8 = local_res18;
-                p_Var30 = (_CLFS_FILTER_CONTEXT *)(this + 0xb0);
-                p_Var27 = (_UNICODE_STRING *)&local_b8;
-                lVar11 = CClfsContainer::Open
-                                   (pCVar15,p_Var27,p_Var30,local_res20,
-                                    (uchar *)in_stack_fffffffffffffed8);
-                uVar13 = (uint)p_Var30;
-                uVar10 = (ulong)p_Var27;
-                if (lVar11 < 0) {
-                  if ((lVar11 != -0x3fffffcc) && (lVar11 != -0x3fffffef)) {
-                    local_f8 = lVar11;
-                    if (lVar11 == -0x3fffffc6) {
+                p_Var33 = (_CLFS_FILTER_CONTEXT *)(this + 0xb0);
+                p_Var26 = (_UNICODE_STRING *)&local_98;
+                local_f8 = CClfsContainer::Open
+                                     (pCVar22,p_Var26,p_Var33,local_res20,
+                                      (uchar *)in_stack_fffffffffffffed8);
+                uVar12 = (uint)p_Var33;
+                uVar28 = (ulong)p_Var26;
+                if (local_f8 < 0) {
+                  if ((local_f8 != -0x3fffffcc) && (local_f8 != -0x3fffffef)) {
+                    if (local_f8 == -0x3fffffc6) {
                       local_f8 = -0x3fe5fff1;
                     }
-                    goto LAB_2;
-                  }
-                  if ((*(uint *)(p_Var6 + 0x24) & 1) == 0) {
-                    lVar11 = -0x3fe5fff1;
+                    pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                    (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                    *(undefined8 *)(p_Var5 + 0x18) = 0;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    lVar10 = local_f8;
+                    goto LAB_0;
+                  }
+                  if ((*(uint *)(p_Var5 + 0x24) & 1) == 0) {
                     local_f8 = -0x3fe5fff1;
-                    puVar35 = param_7;
-                    puVar37 = param_8;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    lVar10 = local_f8;
+                    goto LAB_0;
+                  }
+                  if (local_f8 == -0x3fffffef) {
+                    p_Var26 = (_UNICODE_STRING *)&local_98;
+                    CClfsContainer::Remove(*(CClfsContainer **)(p_Var5 + 0x18),p_Var26);
+                    uVar28 = (ulong)p_Var26;
+                  }
+                  (**(code **)(**(longlong **)(p_Var5 + 0x18) + 8))();
+                  *(undefined8 *)(p_Var5 + 0x18) = 0;
+                  pCVar22 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001f940);
+                  if (pCVar22 == (CClfsContainer *)0x0) {
+                    puVar16 = (undefined8 *)0x0;
                   }
                   else {
-                    if (lVar11 == -0x3fffffef) {
-                      p_Var27 = (_UNICODE_STRING *)&local_b8;
-                      CClfsContainer::Remove(*(CClfsContainer **)(p_Var6 + 0x18),p_Var27);
-                      uVar10 = (ulong)p_Var27;
-                    }
-                    (**(code **)(**(longlong **)(p_Var6 + 0x18) + 8))();
-                    *(undefined8 *)(p_Var6 + 0x18) = 0;
-                    pCVar15 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001e900);
-                    if (pCVar15 == (CClfsContainer *)0x0) {
-                      puVar19 = (undefined8 *)0x0;
+                    puVar16 = (undefined8 *)CClfsContainer::CClfsContainer(pCVar22,uVar28);
+                  }
+                  *(undefined8 **)(p_Var5 + 0x18) = puVar16;
+                  if (puVar16 == (undefined8 *)0x0) {
+                    lVar10 = -0x3fffff66;
+                    pCVar22 = (CClfsContainer *)0x0;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    local_f8 = lVar10;
+                    goto LAB_0;
+                  }
+                  (**(code **)*puVar16)();
+                  if (local_c8 == (uint *)0x0) {
+                    if (param_4 == '\0') {
+                      local_c8 = operator_new((ulonglong)CClfsBaseFile::m_cbNoSecurity,1);
+                      if (local_c8 == (uint *)0x0) {
+                        local_f8 = -0x3fffff66;
+                        pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                        (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                        *(undefined8 *)(p_Var5 + 0x18) = 0;
+                        puVar38 = param_8;
+                        puVar40 = param_7;
+                        lVar10 = -0x3fffff66;
+                        goto LAB_0;
+                      }
+                      memcpy(local_c8,CClfsBaseFile::m_psdNoSecurity,
+                             (ulonglong)CClfsBaseFile::m_cbNoSecurity);
                     }
                     else {
-                      puVar19 = (undefined8 *)CClfsContainer::CClfsContainer(pCVar15,uVar10);
+                      puVar34 = (ulong *)&param_6;
+                      lVar10 = QueryBaseSecurity(this,&local_c8,puVar34);
+                      uVar12 = (uint)puVar34;
+                      if (lVar10 < 0) {
+                        local_f8 = -0x3fffff87;
+                        pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                        (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                        *(undefined8 *)(p_Var5 + 0x18) = 0;
+                        puVar38 = param_8;
+                        puVar40 = param_7;
+                        lVar10 = -0x3fffff87;
+                        goto LAB_0;
+                      }
+                      lVar10 = SetDefaultSaclSecurityDescriptor(&local_c8,(ulong *)&param_6);
+                      if (lVar10 < 0) {
+                        pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                        (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                        *(undefined8 *)(p_Var5 + 0x18) = 0;
+                        puVar38 = param_8;
+                        puVar40 = param_7;
+                        local_f8 = lVar10;
+                        goto LAB_0;
+                      }
                     }
-                    *(undefined8 **)(p_Var6 + 0x18) = puVar19;
-                    if (puVar19 != (undefined8 *)0x0) {
-                      (**(code **)*puVar19)();
-                      if (local_e0 == (uint *)0x0) {
-                        if (param_4 == '\0') {
-                          local_e0 = operator_new((ulonglong)CClfsBaseFile::m_cbNoSecurity,1);
-                          if (local_e0 != (uint *)0x0) {
-                            memcpy(local_e0,CClfsBaseFile::m_psdNoSecurity,
-                                   (ulonglong)CClfsBaseFile::m_cbNoSecurity);
-                            goto LAB_3;
-                          }
-                          local_f8 = -0x3fffff66;
-                        }
-                        else {
-                          puVar31 = (ulong *)&param_6;
-                          lVar12 = QueryBaseSecurity(this,&local_e0,puVar31);
-                          uVar13 = (uint)puVar31;
-                          if (lVar12 < 0) {
-                            local_f8 = -0x3fffff87;
-                          }
-                          else {
-                            local_f8 = SetDefaultSaclSecurityDescriptor(&local_e0,(ulong *)&param_6)
-                            ;
-                            if (-1 < local_f8) goto LAB_3;
-                          }
-                        }
-                      }
-                      else {
-LAB_3:
-                        in_stack_fffffffffffffed8 = local_e0;
-                        lVar12 = CClfsContainer::Create
-                                           (*(CClfsContainer **)(p_Var6 + 0x18),
-                                            (_UNICODE_STRING *)&local_b8,(__uint64 *)p_Var32,
-                                            (_CLFS_FILTER_CONTEXT *)(this + 0xb0),local_e0,
-                                            local_res20,(uchar *)local_res18);
-                        uVar13 = (uint)p_Var32;
-                        if (-1 < lVar12) goto LAB_4;
-                        local_f8 = -0x3fe5fff2;
-                      }
-                      goto LAB_2;
-                    }
-                    lVar11 = -0x3fffff66;
-                    local_f8 = -0x3fffff66;
-                    pCVar15 = (CClfsContainer *)0x0;
-                    puVar35 = param_7;
-                    puVar37 = param_8;
-                  }
-                  goto LAB_1;
-                }
-LAB_4:
-                uVar10 = CClfsContainer::GetRawSectorSize(*(CClfsContainer **)(p_Var6 + 0x18));
-                pCVar22 = param_9;
-                pCVar15 = *(CClfsContainer **)(p_Var6 + 0x18);
-                if (uVar10 != *(ulong *)(this + 0x90)) {
+                  }
+                  in_stack_fffffffffffffed8 = local_c8;
+                  lVar10 = CClfsContainer::Create
+                                     (*(CClfsContainer **)(p_Var5 + 0x18),
+                                      (_UNICODE_STRING *)&local_98,(__uint64 *)p_Var35,
+                                      (_CLFS_FILTER_CONTEXT *)(this + 0xb0),local_c8,local_res20,
+                                      (uchar *)local_res18);
+                  uVar12 = (uint)p_Var35;
+                  if (lVar10 < 0) {
+                    local_f8 = -0x3fe5fff2;
+                    pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                    (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                    *(undefined8 *)(p_Var5 + 0x18) = 0;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    lVar10 = -0x3fe5fff2;
+                    goto LAB_0;
+                  }
+                }
+                uVar28 = CClfsContainer::GetRawSectorSize(*(CClfsContainer **)(p_Var5 + 0x18));
+                pCVar30 = param_9;
+                pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                if (uVar28 != *(ulong *)(this + 0x90)) {
                   local_f8 = -0x3fe5ffff;
-LAB_5:
-                  (**(code **)(*(__uint64 *)pCVar15 + 8))();
-                  *(undefined8 *)(p_Var6 + 0x18) = 0;
-                  puVar35 = param_7;
-                  puVar37 = param_8;
-                  lVar11 = local_f8;
-                  goto LAB_1;
-                }
-                if (*(longlong *)(pCVar15 + 0x20) != 0) {
-                  local_78 = *(ulonglong *)(pCVar15 + 8);
-                }
-                if (local_78 < *(ulonglong *)param_9) {
-                  if ((*(uint *)(p_Var6 + 0x24) & 1) == 0) {
+                  (**(code **)(*(longlong *)pCVar22 + 8))();
+                  *(undefined8 *)(p_Var5 + 0x18) = 0;
+                  puVar38 = param_8;
+                  puVar40 = param_7;
+                  lVar10 = -0x3fe5ffff;
+                  goto LAB_0;
+                }
+                if (*(longlong *)(pCVar22 + 0x20) != 0) {
+                  local_68 = *(ulonglong *)(pCVar22 + 8);
+                }
+                if (local_68 < *(ulonglong *)param_9) {
+                  if ((*(uint *)(p_Var5 + 0x24) & 1) == 0) {
                     local_f8 = -0x3fe5fff3;
                   }
                   else {
                     if ((char)local_res18[0] != '\0') {
-                      uVar33 = 0;
-                      local_f8 = QueryContainerSecurity(pCVar15,&local_e8,0,(ulong *)&param_6);
-                      uVar13 = (uint)uVar33;
-                      if (local_f8 < 0) goto LAB_2;
-                      SeCaptureSubjectContext(&local_60);
-                      SeLockSubjectContext(&local_60);
+                      uVar36 = 0;
+                      lVar10 = QueryContainerSecurity(pCVar22,&local_e8,0,(ulong *)&param_6);
+                      uVar12 = (uint)uVar36;
+                      if (lVar10 < 0) {
+                        pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                        (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                        *(undefined8 *)(p_Var5 + 0x18) = 0;
+                        puVar38 = param_8;
+                        puVar40 = param_7;
+                        local_f8 = lVar10;
+                        goto LAB_0;
+                      }
+                      SeCaptureSubjectContext(&local_58);
+                      SeLockSubjectContext(&local_58);
                       uVar1 = *(undefined1 *)((longlong)SystemReserved1[0xf] + 0x232);
-                      uVar20 = IoGetFileObjectGenericMapping();
-                      p_Var5 = local_e8;
+                      uVar17 = IoGetFileObjectGenericMapping();
+                      p_Var4 = local_e8;
                       in_stack_fffffffffffffed8 =
                            (uint *)((ulonglong)in_stack_fffffffffffffed8 & 0xffffffff00000000);
-                      uVar33 = CONCAT71((int7)((ulonglong)uVar33 >> 8),1);
-                      uVar13 = (uint)uVar33;
-                      cVar9 = SeAccessCheck(local_e8,&local_60,uVar33,3,in_stack_fffffffffffffed8,0,
-                                            uVar20,uVar1,&local_a4,&local_a8);
-                      SeUnlockSubjectContext(&local_60);
-                      SeReleaseSubjectContext(&local_60);
-                      ClfsMgmtpApcRundown(p_Var5);
+                      uVar36 = CONCAT71((int7)((ulonglong)uVar36 >> 8),1);
+                      uVar12 = (uint)uVar36;
+                      cVar8 = SeAccessCheck(local_e8,&local_58,uVar36,3,in_stack_fffffffffffffed8,0,
+                                            uVar17,uVar1,local_84,&local_88);
+                      SeUnlockSubjectContext(&local_58);
+                      SeReleaseSubjectContext(&local_58);
+                      ClfsMgmtpApcRundown(p_Var4);
+                      if (cVar8 == '\0') {
+                        local_e8 = (_KAPC *)0x0;
+                        pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                        (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                        *(undefined8 *)(p_Var5 + 0x18) = 0;
+                        local_f8 = -0x3fffffde;
+                        puVar38 = param_8;
+                        puVar40 = param_7;
+                        lVar10 = -0x3fffffde;
+                        goto LAB_0;
+                      }
                       local_e8 = (_KAPC *)0x0;
-                      pCVar15 = *(CClfsContainer **)(p_Var6 + 0x18);
-                      if (cVar9 == '\0') {
-                        (**(code **)(*(__uint64 *)pCVar15 + 8))();
-                        *(undefined8 *)(p_Var6 + 0x18) = 0;
-                        lVar11 = -0x3fffffde;
-                        local_f8 = -0x3fffffde;
-                        puVar35 = param_7;
-                        puVar37 = param_8;
-                        goto LAB_1;
-                      }
-                      uVar34 = (ulonglong)local_d8;
-                      uVar36 = local_f0;
+                      pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                      uVar19 = local_b8;
+                      uVar11 = local_f0;
                     }
-                    lVar11 = CClfsContainer::FinishInitializeFile(pCVar15,(__uint64 *)pCVar22);
-                    local_f8 = lVar11;
-                    if (-1 < lVar11) goto LAB_6;
-                  }
-LAB_2:
-                  pCVar15 = *(CClfsContainer **)(p_Var6 + 0x18);
-                  goto LAB_5;
-                }
-LAB_6:
-                local_f8 = lVar11;
+                    local_f8 = CClfsContainer::FinishInitializeFile(pCVar22,(__uint64 *)pCVar30);
+                    if (-1 < local_f8) goto LAB_5;
+                  }
+                  pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                  (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                  *(undefined8 *)(p_Var5 + 0x18) = 0;
+                  puVar38 = param_8;
+                  puVar40 = param_7;
+                  lVar10 = local_f8;
+                  goto LAB_0;
+                }
+LAB_5:
                 if ((param_4 == '\0') && ((char)local_res18[0] != '\0')) {
-                  uVar13 = 0;
+                  uVar12 = 0;
                   local_f8 = QueryContainerSecurity
-                                       (*(CClfsContainer **)(p_Var6 + 0x18),&local_e8,0,
+                                       (*(CClfsContainer **)(p_Var5 + 0x18),&local_e8,0,
                                         (ulong *)&param_6);
-                  if (local_f8 < 0) goto LAB_2;
+                  if (local_f8 < 0) {
+                    pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                    (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                    *(undefined8 *)(p_Var5 + 0x18) = 0;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    lVar10 = local_f8;
+                    goto LAB_0;
+                  }
                   ClfsMgmtpApcRundown(local_e8);
                   local_e8 = (_KAPC *)0x0;
                 }
-                if ((*(uint *)(p_Var6 + 0x24) & 1) != 0) {
-                  *(undefined4 *)(p_Var6 + 0x24) = 2;
+                if ((*(uint *)(p_Var5 + 0x24) & 1) != 0) {
+                  *(undefined4 *)(p_Var5 + 0x24) = 2;
                   local_f8 = FlushImage(this);
-                  if (local_f8 < 0) goto LAB_2;
-                }
-                if (param_1[*(uint *)(p_Var6 + 0x14) & 0x3ff] != 0xffffffff) {
+                  if (local_f8 < 0) {
+                    pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                    (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                    *(undefined8 *)(p_Var5 + 0x18) = 0;
+                    puVar38 = param_8;
+                    puVar40 = param_7;
+                    lVar10 = local_f8;
+                    goto LAB_0;
+                  }
+                }
+                if (param_1[*(uint *)(p_Var5 + 0x14) & 0x3ff] != 0xffffffff) {
                   local_f8 = -0x3fe5fff3;
-                  pCVar15 = *(CClfsContainer **)(p_Var6 + 0x18);
-                  (**(code **)(*(__uint64 *)pCVar15 + 8))();
-                  *(undefined8 *)(p_Var6 + 0x18) = 0;
-                  puVar35 = param_7;
-                  puVar37 = param_8;
-                  lVar11 = -0x3fe5fff3;
-                  goto LAB_1;
-                }
-                param_1[*(uint *)(p_Var6 + 0x14) & 0x3ff] = (ulong)uVar34;
-                uVar13 = *(uint *)(p_Var6 + 0x14);
-                if (uVar13 < *param_7) {
-                  *param_7 = uVar13;
-                  uVar13 = *(uint *)(p_Var6 + 0x14);
-                }
-                if (*param_8 <= uVar13) {
-                  *param_8 = uVar13 + 1;
-                }
-                pCVar15 = (CClfsContainer *)(this + 0xe8);
-                uVar29 = 1;
-                RtlSetBits(pCVar15,uVar34);
-                uVar36 = uVar36 + 1;
-                local_d8 = (ulong)uVar34 + 1;
-                uVar34 = (ulonglong)local_d8;
-                _Src = local_70;
-                uVar10 = local_a0;
-                lVar11 = local_f8;
-                local_f0 = uVar36;
+                  pCVar22 = *(CClfsContainer **)(p_Var5 + 0x18);
+                  (**(code **)(*(__uint64 *)pCVar22 + 8))();
+                  *(undefined8 *)(p_Var5 + 0x18) = 0;
+                  puVar38 = param_8;
+                  puVar40 = param_7;
+                  lVar10 = -0x3fe5fff3;
+                  goto LAB_0;
+                }
+                param_1[*(uint *)(p_Var5 + 0x14) & 0x3ff] = uVar19;
+                uVar12 = *(uint *)(p_Var5 + 0x14);
+                if (uVar12 < *param_7) {
+                  *param_7 = uVar12;
+                  uVar12 = *(uint *)(p_Var5 + 0x14);
+                }
+                if (*param_8 <= uVar12) {
+                  *param_8 = uVar12 + 1;
+                }
+                pCVar30 = (CClfsContainer *)(this + 0xe8);
+                uVar32 = 1;
+                RtlSetBits(pCVar30,uVar19);
+                local_f0 = uVar11 + 1;
+                uVar39 = (ulonglong)local_f0;
+                local_b8 = uVar19 + 1;
+                uVar37 = (ulonglong)local_b8;
+                p_Var29 = local_60;
+                lVar10 = local_f8;
               }
             }
           }
-          puVar35 = param_7;
-          puVar37 = param_8;
-          if (uVar36 != uVar10) {
-            auVar3._8_8_ = 0;
-            auVar3._0_8_ = (ulonglong)(*(ushort *)(this + 0xd8) >> 1) + 1;
-            _Var21 = SUB168(ZEXT816(2) * auVar3,0);
-            if (SUB168(ZEXT816(2) * auVar3,8) != 0) {
-              _Var21 = 0xffffffffffffffff;
+          pCVar22 = pCVar30;
+          puVar38 = param_8;
+          puVar40 = param_7;
+          if (uVar11 != local_d0) {
+            auVar2._8_8_ = 0;
+            auVar2._0_8_ = (ulonglong)(*(ushort *)(this + 0xd8) >> 1) + 1;
+            _Var18 = SUB168(ZEXT816(2) * auVar2,0);
+            if (SUB168(ZEXT816(2) * auVar2,8) != 0) {
+              _Var18 = 0xffffffffffffffff;
             }
-            pCVar15 = operator_new(_Var21,1);
-            if (pCVar15 == (CClfsContainer *)0x0) {
-              pCVar15 = WPP_GLOBAL_Control;
-              if ((WPP_GLOBAL_Control == (CClfsContainer *)&WPP_GLOBAL_Control) ||
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1b & 1) == 0)) {
-LAB_0:
-                local_f8 = -0x3fe5fff3;
-                puVar35 = param_7;
-                puVar37 = param_8;
-                lVar11 = -0x3fe5fff3;
-              }
-              else {
-                pCVar15 = *(CClfsContainer **)(WPP_GLOBAL_Control + 0x18);
-                WPP_SF_sdidd(pCVar15);
-                lVar11 = -0x3fe5fff3;
-                local_f8 = -0x3fe5fff3;
-                puVar35 = param_7;
-                puVar37 = param_8;
+            pCVar30 = operator_new(_Var18,1);
+            if (pCVar30 == (CClfsContainer *)0x0) {
+              pCVar30 = WPP_GLOBAL_Control;
+              if ((WPP_GLOBAL_Control != (CClfsContainer *)&WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1b & 1) != 0)) {
+                pCVar30 = *(CClfsContainer **)(WPP_GLOBAL_Control + 0x18);
+                WPP_SF_sdidd(pCVar30);
               }
             }
             else {
-              memset(pCVar15,0,(ulonglong)*(ushort *)(this + 0xd8) + 2);
-              uVar13 = (uint)*(ushort *)(this + 0xd8);
-              memcpy(pCVar15,*(void **)(this + 0xe0),(ulonglong)*(ushort *)(this + 0xd8));
+              memset(pCVar30,0,(ulonglong)*(ushort *)(this + 0xd8) + 2);
+              uVar12 = (uint)*(ushort *)(this + 0xd8);
+              memcpy(pCVar30,*(void **)(this + 0xe0),(ulonglong)*(ushort *)(this + 0xd8));
               if ((WPP_GLOBAL_Control != (CClfsContainer *)&WPP_GLOBAL_Control) &&
                  ((*(uint *)(WPP_GLOBAL_Control + 0x2c) >> 0x1b & 1) != 0)) {
                 WPP_SF_sdiSdd(*(undefined8 *)(WPP_GLOBAL_Control + 0x18));
               }
-              operator_delete(pCVar15);
-              lVar11 = -0x3fe5fff3;
-              local_f8 = -0x3fe5fff3;
-              puVar35 = param_7;
-              puVar37 = param_8;
+              operator_delete(pCVar30);
             }
+LAB_3:
+            local_f8 = -0x3fe5fff3;
+            pCVar22 = pCVar30;
+            puVar38 = param_8;
+            puVar40 = param_7;
+            lVar10 = -0x3fe5fff3;
           }
         }
       }
     }
     else {
+LAB_2:
+      lVar10 = -0x3fe5fff3;
+      puVar38 = param_8;
+      local_f8 = lVar10;
+    }
+  }
+  else {
+    _Var18 = (__uint64)*(uint *)(pCVar21 + 0x68);
+    if ((uint)*(ushort *)(pCVar21 + 4) << 9 < *(uint *)(pCVar21 + 0x68)) {
       local_f8 = -0x3fe5fff3;
-      lVar11 = -0x3fe5fff3;
+      lVar10 = local_f8;
+      goto LAB_0;
     }
-  }
-LAB_1:
-  if (cVar7 != '\0') {
-    pCVar15 = *(CClfsContainer **)(this + 0x20);
-    ExReleaseResourceForThreadLite(pCVar15,SystemReserved1[0xf]);
-    lVar11 = local_f8;
-  }
-  if (bVar4) {
-    DestroyAbsoluteContainerPath((CClfsBaseFilePersisted *)pCVar15,(_UNICODE_STRING *)&local_88);
-  }
-  if (lVar11 < 0) {
-    if (*puVar35 != 0xffffffff) {
-      UnloadContainerQ(this,param_1,uVar13,*puVar35,*puVar37);
+    pCVar22 = (CClfsContainer *)(p_Var13 + 0x1338);
+    pp_Var31 = &local_c0;
+    lVar10 = ULongLongAdd((__uint64)pCVar22,(ulonglong)*(uint *)(p_Var13 + 0x1328),
+                          (__uint64 *)pp_Var31);
+    uVar12 = (uint)pp_Var31;
+    if (-1 < lVar10) {
+      pCVar30 = (CClfsContainer *)&local_d8;
+      lVar10 = ULongLongAdd((__uint64)pCVar21,_Var18,(__uint64 *)pCVar30);
+      uVar12 = (uint)pCVar30;
+      pCVar22 = pCVar21;
+      if ((-1 < lVar10) && (local_c0 <= local_d8)) goto LAB_1;
     }
-    *puVar37 = 0;
-    *puVar35 = 0;
-  }
-  if (local_d0 != (_CLFS_CLIENT_CONTEXT *)0x0) {
-    CClfsBaseFile::ReleaseClientContext((CClfsBaseFile *)this,&local_d0);
-  }
-  if (local_e0 != (uint *)0x0) {
-    operator_delete(local_e0);
+    local_f8 = -0x3fe5fff3;
+    lVar10 = local_f8;
+  }
+LAB_0:
+  if (cVar6 != '\0') {
+    pCVar22 = *(CClfsContainer **)(this + 0x20);
+    ExReleaseResourceForThreadLite(pCVar22,SystemReserved1[0xf]);
+    lVar10 = local_f8;
+  }
+  if (bVar3) {
+    DestroyAbsoluteContainerPath((CClfsBaseFilePersisted *)pCVar22,(_UNICODE_STRING *)&local_78);
+  }
+  if (lVar10 < 0) {
+    if (*puVar40 != 0xffffffff) {
+      UnloadContainerQ(this,param_1,uVar12,*puVar40,*puVar38);
+    }
+    *puVar38 = 0;
+    *puVar40 = 0;
+  }
+  if (local_e0 != (_CLFS_CLIENT_CONTEXT *)0x0) {
+    CClfsBaseFile::ReleaseClientContext((CClfsBaseFile *)this,&local_e0);
+  }
+  if (local_c8 != (uint *)0x0) {
+    operator_delete(local_c8);
   }
   if (local_e8 != (_KAPC *)0x0) {
     ClfsMgmtpApcRundown(local_e8);
   }
-  return lVar11;
+  return lVar10;
 }
 

```


## CClfsBaseFilePersisted::CreateImage

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.93|
|i_ratio|0.65|
|m_ratio|1.0|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|CreateImage|CreateImage|
|fullname|CClfsBaseFilePersisted::CreateImage|CClfsBaseFilePersisted::CreateImage|
|refcount|3|3|
|`length`|1905|1872|
|called|<details><summary>Expand for full list:<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsContainer::CClfsContainer<br>CClfsContainer::Create<br>CClfsContainer::GetRawSectorSize<br>ClfsCreateEventObject</summary>ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExUuidCreate<br>NTOSKRNL.EXE::KeClearEvent<br>NTOSKRNL.EXE::RtlCompareMemory<br>NTOSKRNL.EXE::RtlLengthSecurityDescriptor<br>WPP_SF_slSD<br>_guard_dispatch_icall<br>memcpy<br>memset</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::GetBaseLogRecord<br>CClfsBaseFile::GetControlRecord<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ReleaseMetadataBlock<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::WriteMetadataBlock<br>CClfsContainer::CClfsContainer<br>CClfsContainer::Create<br>CClfsContainer::GetRawSectorSize<br>ClfsCreateEventObject</summary>ExAllocateFromPagedLookasideList<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExUuidCreate<br>NTOSKRNL.EXE::KeClearEvent<br>NTOSKRNL.EXE::RtlCompareMemory<br>NTOSKRNL.EXE::RtlLengthSecurityDescriptor<br>WPP_SF_slSD<br>_guard_dispatch_icall<br>memcpy<br>memset</details>|
|calling|CClfsLogFcbPhysical::Initialize|CClfsLogFcbPhysical::Initialize|
|paramcount|8|8|
|`address`|1c003a1f0|1c003c270|
|sig|long __thiscall CreateImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, ulong param_2, uchar param_3, _CLFS_FILTER_CONTEXT * param_4, void * param_5, uchar param_6, uchar * param_7)|long __thiscall CreateImage(CClfsBaseFilePersisted * this, _UNICODE_STRING * param_1, ulong param_2, uchar param_3, _CLFS_FILTER_CONTEXT * param_4, void * param_5, uchar param_6, uchar * param_7)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### CClfsBaseFilePersisted::CreateImage Diff


```diff
--- CClfsBaseFilePersisted::CreateImage
+++ CClfsBaseFilePersisted::CreateImage
@@ -1,270 +1,266 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: long __cdecl CClfsBaseFilePersisted::CreateImage(struct _UNICODE_STRING *
    __ptr64,unsigned long,unsigned char,struct _CLFS_FILTER_CONTEXT const & __ptr64,void * __ptr64
    const,unsigned char,unsigned char & __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFilePersisted::CreateImage
           (CClfsBaseFilePersisted *this,_UNICODE_STRING *param_1,ulong param_2,uchar param_3,
           _CLFS_FILTER_CONTEXT *param_4,void *param_5,uchar param_6,uchar *param_7)
 
 {
   CClfsBaseFilePersisted *pCVar1;
   undefined1 auVar2 [16];
   long lVar3;
   ulong uVar4;
   uint uVar5;
   CClfsContainer *this_00;
   _CLFS_CONTROL_RECORD *p_Var6;
   void *pvVar7;
   undefined8 uVar8;
   longlong lVar9;
   _CLFS_BASE_RECORD_HEADER *p_Var10;
   ulonglong uVar11;
   undefined8 *puVar12;
   CClfsBaseFilePersisted *pCVar13;
   _UNICODE_STRING *p_Var14;
   ushort uVar15;
   uint uVar16;
   _CLFS_CONTROL_RECORD *p_Var17;
   _CLFS_CONTROL_RECORD *p_Var18;
   uint local_res18 [2];
   uchar local_res20;
   ulong local_60 [2];
   _CLFS_CONTROL_RECORD *local_58;
   __uint64 local_50 [3];
   
   p_Var18 = (_CLFS_CONTROL_RECORD *)0x0;
   p_Var17 = (_CLFS_CONTROL_RECORD *)0x0;
   local_58 = (_CLFS_CONTROL_RECORD *)0x0;
   local_60[0] = 0;
   local_res18[0] = param_2 & 0xffffff00;
   *param_7 = '\0';
   puVar12 = WPP_GLOBAL_Control;
   p_Var14 = param_1;
   local_res20 = param_3;
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) >> 0x1a & 1) != 0)) {
-    p_Var14 = (_UNICODE_STRING *)&DAT_0;
+    p_Var14 = (_UNICODE_STRING *)0x14;
     puVar12 = (undefined8 *)WPP_GLOBAL_Control[3];
-    WPP_SF_slSD(puVar12,0xb);
+    WPP_SF_slSD(puVar12,0x14);
   }
   uVar4 = (ulong)p_Var14;
   pCVar1 = this + 0xa0;
   if (*(_KEVENT **)pCVar1 == (_KEVENT *)0x0) {
     pCVar13 = pCVar1;
     lVar3 = ClfsCreateEventObject((_EVENT_TYPE)puVar12,(_KEVENT **)pCVar1);
     uVar4 = (ulong)pCVar13;
     if (-1 < lVar3) {
       KeClearEvent(*(_KEVENT **)pCVar1);
-      goto LAB_1;
+      goto LAB_0;
     }
     *(_KEVENT **)pCVar1 = (_KEVENT *)0x0;
   }
   else {
-LAB_1:
+LAB_0:
     if ((*(longlong *)(this + 0x20) != 0) ||
        (lVar3 = CClfsBaseFile::InitializeImageResource((CClfsBaseFile *)this), -1 < lVar3)) {
-      this_00 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001e900);
+      this_00 = (CClfsContainer *)ExAllocateFromPagedLookasideList(0x1c001f940);
       p_Var6 = p_Var18;
       if (this_00 != (CClfsContainer *)0x0) {
         p_Var6 = (_CLFS_CONTROL_RECORD *)CClfsContainer::CClfsContainer(this_00,uVar4);
       }
       *(_CLFS_CONTROL_RECORD **)(this + 0x98) = p_Var6;
       if (p_Var6 == (_CLFS_CONTROL_RECORD *)0x0) {
         lVar3 = -0x3fffff66;
       }
       else {
         if (*(longlong *)(this + 0xe0) != 0) {
           ExFreePoolWithTag(*(longlong *)(this + 0xe0),0);
           *(undefined8 *)(this + 0xe0) = 0;
         }
         auVar2._8_8_ = 0;
         auVar2._0_8_ = (ulonglong)*(ushort *)param_1 + 1;
         uVar8 = SUB168(ZEXT816(2) * auVar2,0);
         if (SUB168(ZEXT816(2) * auVar2,8) != 0) {
           uVar8 = 0xffffffffffffffff;
         }
         pvVar7 = (void *)ExAllocatePoolWithTag(1,uVar8,0x73666c43);
         *(void **)(this + 0xe0) = pvVar7;
         if (pvVar7 == (void *)0x0) {
-LAB_2:
+LAB_1:
           lVar3 = -0x3fffff66;
         }
         else {
           *(short *)(this + 0xda) = *(short *)param_1 + 2;
           uVar15 = *(ushort *)param_1;
           *(ushort *)(this + 0xd8) = uVar15;
           memcpy(pvVar7,*(void **)(param_1 + 8),(ulonglong)uVar15);
           *(undefined2 *)
            (*(longlong *)(this + 0xe0) + (ulonglong)(*(ushort *)(this + 0xd8) >> 1) * 2) = 0;
           if (*(int *)(param_4 + 0x10) != 0) {
             pvVar7 = (void *)ExAllocatePoolWithTag(1,*(int *)(param_4 + 0x10),0x73666c43);
             *(void **)(this + 0xb8) = pvVar7;
-            if (*(longlong *)(param_4 + 8) == 0) goto LAB_2;
+            if (*(longlong *)(param_4 + 8) == 0) goto LAB_1;
             *(undefined4 *)(this + 0xc0) = *(undefined4 *)(param_4 + 0x10);
             memcpy(pvVar7,*(void **)(param_4 + 8),(ulonglong)*(uint *)(param_4 + 0x10));
           }
           *(undefined8 *)(this + 0xb0) = *(undefined8 *)param_4;
           (**(code **)**(undefined8 **)(this + 0x98))();
           local_50[0] = 0x10000;
           lVar3 = CClfsContainer::Create
                             (*(CClfsContainer **)(this + 0x98),param_1,local_50,param_4,param_5,
                              param_6,(uchar *)local_res18);
           if (lVar3 == -0x3fffff29) {
             local_50[1] = 0x10000;
             lVar3 = CClfsContainer::Create
                               (*(CClfsContainer **)(this + 0x98),param_1,local_50 + 1,param_4,
                                (void *)0x0,param_6,(uchar *)local_res18);
           }
           if (lVar3 < 0) {
             (**(code **)(*(longlong *)*(CClfsContainer **)(this + 0x98) + 8))();
             *(undefined8 *)(this + 0x98) = 0;
             p_Var17 = p_Var18;
           }
           else {
             uVar4 = CClfsContainer::GetRawSectorSize(*(CClfsContainer **)(this + 0x98));
             *(ulong *)(this + 0x90) = uVar4;
             if ((uVar4 - 1 < 0x1000) && ((uVar4 & 0x1ff) == 0)) {
               if ((uVar4 * 6 < 0x10001) && (uVar16 = uVar4 * -6 + 0x10000 >> 1, 0x13a7 < uVar16)) {
                 *(undefined8 *)(this + 0x88) = 0x10000;
                 uVar8 = ExAllocatePoolWithTag(0x200,0x90,0x73666c43);
                 *(undefined8 *)(this + 0x30) = uVar8;
                 lVar9 = ExAllocatePoolWithTag(0x200,0xc,0x73666c43);
                 *(longlong *)(this + 0x38) = lVar9;
                 if ((*(void **)(this + 0x30) == (void *)0x0) || (lVar9 == 0)) {
                   lVar3 = -0x3fffff66;
                   p_Var17 = p_Var18;
                 }
                 else {
                   memset(*(void **)(this + 0x30),0,0x90);
                   puVar12 = *(undefined8 **)(this + 0x38);
                   *puVar12 = 0;
                   *(undefined4 *)(puVar12 + 1) = 0;
                   lVar3 = CreateMetadataBlock(this,0,local_60,uVar4 * 2);
                   p_Var17 = p_Var18;
                   if (-1 < lVar3) {
                     CClfsBaseFile::GetControlRecord((CClfsBaseFile *)this,&local_58);
                     CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
                     p_Var17 = local_58;
                     *(undefined4 *)(local_58 + 0x14) = 0;
                     *(undefined8 *)(local_58 + 8) = 0xc1f5c1f500005f1c;
                     local_58[0x10] = (_CLFS_CONTROL_RECORD)0x1;
                     lVar3 = CreateMetadataBlock(this,2,local_60,uVar16);
                     if (-1 < lVar3) {
                       this[0x94] = (CClfsBaseFilePersisted)0x1;
                       p_Var10 = CClfsBaseFile::GetBaseLogRecord((CClfsBaseFile *)this);
                       if (p_Var10 == (_CLFS_BASE_RECORD_HEADER *)0x0) {
                         lVar3 = -0x3fe5fff3;
                       }
                       else {
                         *(undefined4 *)(p_Var10 + 0x120) = 0;
                         *(undefined8 *)(p_Var10 + 0x128) = 0;
                         *(undefined2 *)(p_Var10 + 0x1333) = 1;
                         p_Var10[0x124] = (_CLFS_BASE_RECORD_HEADER)0x1;
                         *(undefined8 *)(p_Var10 + 0x130) = 0;
                         *(undefined4 *)(p_Var10 + 0x1328) = 0;
                         p_Var10[0x1332] = (_CLFS_BASE_RECORD_HEADER)0x1;
                         *(undefined8 *)p_Var10 = 0;
                         *(undefined4 *)(p_Var10 + 8) = 0;
                         *(undefined4 *)(p_Var10 + 0xc) = 0;
                         *(undefined4 *)(p_Var10 + 0x10) = 0;
                         *(undefined4 *)(p_Var10 + 0x14) = 0;
                         for (uVar15 = 0; uVar15 < 0x14; uVar15 = uVar15 + 1) {
                           lVar3 = ExUuidCreate(p_Var10 + 8);
-                          if (lVar3 != -0x3ffffdd3) goto LAB_3;
+                          if (lVar3 != -0x3ffffdd3) goto LAB_2;
                         }
                         lVar3 = -0x3fffff7d;
-LAB_3:
-                        p_Var17 = local_58;
+LAB_2:
                         if (-1 < lVar3) {
                           if (local_res20 != '\0') {
                             p_Var10[0x1332] =
                                  (_CLFS_BASE_RECORD_HEADER)((byte)p_Var10[0x1332] | 0x40);
                           }
                           *(undefined8 *)(p_Var10 + 0x18) = 0;
                           *(undefined8 *)(p_Var10 + 0x20) = 0;
                           *(undefined8 *)(p_Var10 + 0x28) = 0;
                           *(undefined8 *)(p_Var10 + 0x30) = 0;
                           *(undefined8 *)(p_Var10 + 0x38) = 0;
                           *(undefined4 *)(p_Var10 + 0x40) = 0;
                           *(undefined8 *)(p_Var10 + 0x70) = 0;
                           *(undefined8 *)(p_Var10 + 0x78) = 0;
                           *(undefined8 *)(p_Var10 + 0x80) = 0;
                           *(undefined8 *)(p_Var10 + 0x88) = 0;
                           *(undefined8 *)(p_Var10 + 0x90) = 0;
                           *(undefined4 *)(p_Var10 + 0x98) = 0;
                           memset(p_Var10 + 0x138,0,0x11f0);
                           *(undefined8 *)(p_Var10 + 200) = 0;
                           *(undefined8 *)(p_Var10 + 0xd0) = 0;
                           *(undefined8 *)(p_Var10 + 0xd8) = 0;
                           *(undefined8 *)(p_Var10 + 0xe0) = 0;
                           *(undefined8 *)(p_Var10 + 0xe8) = 0;
                           *(undefined4 *)(p_Var10 + 0xf0) = 0;
                           *(_CLFS_BASE_RECORD_HEADER **)(this + 0x40) = p_Var10 + 0x18;
                           *(undefined4 *)(this + 0x48) = 0xb;
                           *(CClfsBaseFilePersisted **)(this + 0x50) = this;
                           *(_CLFS_BASE_RECORD_HEADER **)(this + 0x58) = p_Var10 + 0x70;
                           *(undefined4 *)(this + 0x60) = 0xb;
                           *(CClfsBaseFilePersisted **)(this + 0x68) = this;
                           *(_CLFS_BASE_RECORD_HEADER **)(this + 0x70) = p_Var10 + 200;
                           *(undefined4 *)(this + 0x78) = 0xb;
                           *(CClfsBaseFilePersisted **)(this + 0x80) = this;
                           lVar3 = AddMetaClient(this,param_1);
-                          p_Var17 = local_58;
                           if ((-1 < lVar3) &&
-                             (lVar3 = CreateMetadataBlock(this,4,local_60,uVar4), p_Var17 = local_58
-                             , -1 < lVar3)) {
+                             (lVar3 = CreateMetadataBlock(this,4,local_60,uVar4), -1 < lVar3)) {
                             lVar3 = WriteMetadataBlock(this,4,'\x01');
                             CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,4);
-                            p_Var17 = local_58;
                             if (-1 < lVar3) {
                               p_Var10[0x1332] =
                                    (_CLFS_BASE_RECORD_HEADER)((byte)p_Var10[0x1332] | 2);
-                              *(undefined2 *)(local_58 + 0x48) = *(undefined2 *)(this + 0x28);
-                              *(_CLFS_CONTROL_RECORD **)(this + 0x1b8) = local_58;
+                              *(undefined2 *)(p_Var17 + 0x48) = *(undefined2 *)(this + 0x28);
+                              *(_CLFS_CONTROL_RECORD **)(this + 0x1b8) = p_Var17;
                             }
                           }
                         }
                       }
                     }
                   }
                 }
               }
               else {
                 lVar3 = -0x3fffffdd;
               }
             }
             else {
               lVar3 = -0x3fffff68;
             }
           }
         }
       }
     }
   }
   if ((p_Var17 != (_CLFS_CONTROL_RECORD *)0x0) && (*(longlong *)(this + 0x1b8) == 0)) {
     CClfsBaseFile::ReleaseMetadataBlock((CClfsBaseFile *)this,0);
   }
   pvVar7 = CClfsBaseFile::m_psdNoSecurity;
   if (lVar3 < 0) {
     return lVar3;
   }
   if ((char)local_res18[0] != '\0') {
     if (param_5 != (void *)0x0) {
       uVar16 = RtlLengthSecurityDescriptor(CClfsBaseFile::m_psdNoSecurity);
       uVar5 = RtlLengthSecurityDescriptor(param_5);
       if ((uVar5 == uVar16) && (uVar11 = RtlCompareMemory(pvVar7,param_5,uVar16), uVar11 == uVar16))
-      goto LAB_4;
+      goto LAB_3;
     }
     *param_7 = '\x01';
   }
-LAB_4:
+LAB_3:
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x4000000) != 0)) {
-    WPP_SF_slSD(WPP_GLOBAL_Control[3],0xc);
+    WPP_SF_slSD(WPP_GLOBAL_Control[3],0x15);
   }
   return lVar3;
 }
 

```


## CClfsBaseFile::GetSymbol

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling|
|ratio|0.96|
|i_ratio|0.73|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|GetSymbol|GetSymbol|
|fullname|CClfsBaseFile::GetSymbol|CClfsBaseFile::GetSymbol|
|`refcount`|12|14|
|`length`|316|330|
|called|CClfsBaseFile::IsValidOffset<br>ClfsQuadAlign<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::IsValidOffset<br>ClfsQuadAlign<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|`calling`|CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ|CClfsBaseFile::AcquireContainerContext<br>CClfsBaseFile::ReleaseContainerContext<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ|
|paramcount|4|4|
|`address`|1c002c2d0|1c002e010|
|sig|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, ulong param_2, _CLFS_CONTAINER_CONTEXT * * param_3)|long __thiscall GetSymbol(CClfsBaseFile * this, long param_1, ulong param_2, _CLFS_CONTAINER_CONTEXT * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CClfsBaseFile::GetSymbol Calling Diff


```diff
--- CClfsBaseFile::GetSymbol calling
+++ CClfsBaseFile::GetSymbol calling
@@ -3,0 +4 @@
+CClfsBaseFile::ValidateContainerContextOffsets
```


### CClfsBaseFile::GetSymbol Diff


```diff
--- CClfsBaseFile::GetSymbol
+++ CClfsBaseFile::GetSymbol
@@ -1,68 +1,69 @@
 
 /* public: long __cdecl CClfsBaseFile::GetSymbol(long,unsigned long,struct _CLFS_CONTAINER_CONTEXT *
    __ptr64 * __ptr64) __ptr64 */
 
 long __thiscall
 CClfsBaseFile::GetSymbol
           (CClfsBaseFile *this,long param_1,ulong param_2,_CLFS_CONTAINER_CONTEXT **param_3)
 
 {
   uint uVar1;
   longlong lVar2;
   char cVar3;
   uchar uVar4;
   uint uVar5;
   ulong uVar6;
   longlong lVar7;
   undefined4 in_register_00000014;
   _CLFS_CONTAINER_CONTEXT *p_Var8;
   int iVar9;
   long local_28;
   
   local_28 = 0;
   if ((uint)param_1 < 0x1368) {
     return -0x3fe5fff3;
   }
   *param_3 = (_CLFS_CONTAINER_CONTEXT *)0x0;
   cVar3 = ExAcquireResourceSharedLite
                     (*(undefined8 *)(this + 0x20),
                      CONCAT71((int7)(CONCAT44(in_register_00000014,param_1) >> 8),1));
   uVar4 = IsValidOffset(this,param_1 + 0x2f);
   if (uVar4 != '\0') {
     lVar2 = *(longlong *)(*(longlong *)(this + 0x30) + 0x30);
     if ((*(short *)(this + 0x28) == 0) || (lVar2 == 0)) {
       uVar5 = *(uint *)(lVar2 + 0x28);
 LAB_0:
       lVar7 = 0;
     }
     else {
       uVar5 = *(uint *)(lVar2 + 0x28);
       uVar1 = *(uint *)(*(longlong *)(this + 0x30) + 0x38);
       if (((uVar1 <= uVar5) || (uVar5 < 0x70)) ||
          (lVar7 = lVar2 + (ulonglong)uVar5, uVar1 - uVar5 < 0x1338)) goto LAB_0;
     }
     if ((((uint)param_1 <= uVar5 + param_1) && (lVar7 != 0)) &&
        ((uVar5 + param_1 < (uint)*(ushort *)(lVar2 + 4) << 9 &&
         (p_Var8 = (_CLFS_CONTAINER_CONTEXT *)((ulonglong)(uint)param_1 + lVar7),
         p_Var8 != (_CLFS_CONTAINER_CONTEXT *)0x0)))) {
       iVar9 = *(int *)(p_Var8 + -0xc);
       if (iVar9 != param_1) {
         local_28 = -0x3ffffff8;
         goto LAB_1;
       }
       uVar6 = ClfsQuadAlign(0x30);
-      if (((longlong)*(int *)(p_Var8 + -0x10) == (ulonglong)(iVar9 + uVar6)) &&
-         (*(ulong *)(p_Var8 + 0x10) == param_2)) {
+      if ((((longlong)*(int *)(p_Var8 + -0x10) == (ulonglong)(iVar9 + uVar6)) &&
+          (*(int *)p_Var8 == -0x3e020ff8)) &&
+         ((*(int *)(p_Var8 + 4) == 0x30 && (*(ulong *)(p_Var8 + 0x10) == param_2)))) {
         *param_3 = p_Var8;
         goto LAB_1;
       }
     }
   }
   local_28 = -0x3fe5fff3;
 LAB_1:
   if (cVar3 != '\0') {
     ExReleaseResourceForThreadLite(*(undefined8 *)(this + 0x20),SystemReserved1[0xf]);
   }
   return local_28;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## __GSHandlerCheck

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|__GSHandlerCheck|__GSHandlerCheck|
|fullname|__GSHandlerCheck|__GSHandlerCheck|
|`refcount`|12|14|
|length|29|29|
|called|__GSHandlerCheckCommon|__GSHandlerCheckCommon|
|calling|||
|paramcount|4|4|
|`address`|1c000c9c8|1c000d388|
|sig|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## OffsetToAddr

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.76|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|OffsetToAddr|OffsetToAddr|
|fullname|CClfsBaseFile::OffsetToAddr|CClfsBaseFile::OffsetToAddr|
|`refcount`|27|32|
|length|65|65|
|called|CClfsBaseFile::GetBaseLogRecord|CClfsBaseFile::GetBaseLogRecord|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireSharedSecurityContext<br>CClfsBaseFile::FindClient<br>CClfsBaseFile::FindContainer<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseSharedSecurityDescriptor<br>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::AddClient</summary>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::RemoveSymbol<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::AcquireSharedSecurityContext<br>CClfsBaseFile::FindClient<br>CClfsBaseFile::FindContainer<br>CClfsBaseFile::FindSharedSecurityDescriptor<br>CClfsBaseFile::FindSymbol<br>CClfsBaseFile::GetContainerName<br>CClfsBaseFile::GetSymbol<br>CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ReleaseSharedSecurityDescriptor<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets</summary>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateProcessQNode<br>CClfsBaseFile::ValidateRgOffsets<br>CClfsBaseFilePersisted::AddClient<br>CClfsBaseFilePersisted::AddContainer<br>CClfsBaseFilePersisted::AddMetaClient<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::RemoveContainer<br>CClfsBaseFilePersisted::RemoveSymbol<br>CClfsBaseFilePersisted::UnloadContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ</details>|
|paramcount|2|2|
|`address`|1c002cf40|1c002eca0|
|sig|void * __thiscall OffsetToAddr(CClfsBaseFile * this, ulong param_1)|void * __thiscall OffsetToAddr(CClfsBaseFile * this, ulong param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### OffsetToAddr Calling Diff


```diff
--- CClfsBaseFile::OffsetToAddr calling
+++ CClfsBaseFile::OffsetToAddr calling
@@ -9,0 +10,4 @@
+CClfsBaseFile::ValidateClientContextOffsets
+CClfsBaseFile::ValidateContainerContextOffsets
+CClfsBaseFile::ValidateOffsets
+CClfsBaseFile::ValidateProcessQNode
```


## AcquireForReadAheadCallback

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|0.9|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|AcquireForReadAheadCallback|AcquireForReadAheadCallback|
|fullname|CClfsLogFcbPhysical::AcquireForReadAheadCallback|CClfsLogFcbPhysical::AcquireForReadAheadCallback|
|`refcount`|281|290|
|length|31|31|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|calling|||
|paramcount|2|2|
|address|1c0002950|1c0002950|
|sig|uchar __cdecl AcquireForReadAheadCallback(void * param_1, uchar param_2)|uchar __cdecl AcquireForReadAheadCallback(void * param_1, uchar param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

## NTOSKRNL.EXE::RtlQueryFeatureConfiguration

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlQueryFeatureConfiguration|RtlQueryFeatureConfiguration|
|fullname|NTOSKRNL.EXE::RtlQueryFeatureConfiguration|NTOSKRNL.EXE::RtlQueryFeatureConfiguration|
|`refcount`|3|4|
|length|0|0|
|called|||
|`calling`|wil_details_PopulateInitialConfiguredFeatureStates<br>wil_details_UpdateFeatureConfiguredStates|wil_RtlStagingConfig_QueryFeatureState<br>wil_details_PopulateInitialConfiguredFeatureStates<br>wil_details_UpdateFeatureConfiguredStates|
|paramcount|0|0|
|address|EXTERNAL:00000007|EXTERNAL:00000007|
|sig|undefined RtlQueryFeatureConfiguration(void)|undefined RtlQueryFeatureConfiguration(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlQueryFeatureConfiguration Calling Diff


```diff
--- NTOSKRNL.EXE::RtlQueryFeatureConfiguration calling
+++ NTOSKRNL.EXE::RtlQueryFeatureConfiguration calling
@@ -0,0 +1 @@
+wil_RtlStagingConfig_QueryFeatureState
```


## NTOSKRNL.EXE::RtlInitializeGenericTableAvl

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlInitializeGenericTableAvl|RtlInitializeGenericTableAvl|
|fullname|NTOSKRNL.EXE::RtlInitializeGenericTableAvl|NTOSKRNL.EXE::RtlInitializeGenericTableAvl|
|`refcount`|3|4|
|length|0|0|
|called|||
|`calling`|CClfsLogFcbPhysical::CClfsLogFcbPhysical<br>CClfsRequest::InitializeGlobals|CClfsBaseFile::ValidateOffsets<br>CClfsLogFcbPhysical::CClfsLogFcbPhysical<br>CClfsRequest::InitializeGlobals|
|paramcount|0|0|
|`address`|EXTERNAL:00000075|EXTERNAL:00000023|
|sig|undefined RtlInitializeGenericTableAvl(void)|undefined RtlInitializeGenericTableAvl(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlInitializeGenericTableAvl Calling Diff


```diff
--- NTOSKRNL.EXE::RtlInitializeGenericTableAvl calling
+++ NTOSKRNL.EXE::RtlInitializeGenericTableAvl calling
@@ -0,0 +1 @@
+CClfsBaseFile::ValidateOffsets
```


## NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlDeleteElementGenericTableAvl|RtlDeleteElementGenericTableAvl|
|fullname|NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl|NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl|
|`refcount`|4|6|
|length|0|0|
|called|||
|`calling`|CClfsLogFcbPhysical::Release<br>CClfsLogFcbPhysical::ReleaseInternal<br>CClfsLogFcbPhysical::RemoveVirtualFcb|CClfsBaseFile::ValidateOffsets<br>CClfsLogFcbPhysical::Release<br>CClfsLogFcbPhysical::ReleaseInternal<br>CClfsLogFcbPhysical::RemoveVirtualFcb|
|paramcount|0|0|
|`address`|EXTERNAL:00000096|EXTERNAL:00000026|
|sig|undefined RtlDeleteElementGenericTableAvl(void)|undefined RtlDeleteElementGenericTableAvl(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl Calling Diff


```diff
--- NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl calling
+++ NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl calling
@@ -0,0 +1 @@
+CClfsBaseFile::ValidateOffsets
```


## __security_check_cookie

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|__security_check_cookie|__security_check_cookie|
|fullname|__security_check_cookie|__security_check_cookie|
|`refcount`|24|26|
|length|30|30|
|called|__report_gsfailure|__report_gsfailure|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::InitializeGlobals<br>CClfsContainer::Create<br>CClfsContainer::GetRawSectorSize<br>CClfsContainer::Open<br>CClfsContainer::QueryContainerInfo<br>CClfsContainer::WriteSector<br>CClfsKernelMarshallingContext::Initialize<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbVirtual::QueryLogFileInfo<br>CClfsManagedLog::FixupContainerName</summary>CClfsManagedLog::QueryLogBoundaryLsns<br>CClfsManagedLog::QueryLogContainerSize<br>CClfsManagedLog::QueryLogEphemeral<br>CClfsManagedLog::QueryLogSize<br>CClfsManagedLogClient::Initialize<br>CClfsRequest::GetIoStatistics<br>ClfsCreateLogFile<br>ClfsEnableThreadPrivilege<br>ClfsGetIoStatistics<br>__GSHandlerCheckCommon<br>wil_details_PopulateInitialConfiguredFeatureStates<br>wil_details_UpdateFeatureConfiguredStates</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::InitializeGlobals<br>CClfsContainer::Create<br>CClfsContainer::GetRawSectorSize<br>CClfsContainer::Open<br>CClfsContainer::QueryContainerInfo<br>CClfsContainer::WriteSector<br>CClfsKernelMarshallingContext::Initialize<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbVirtual::QueryLogFileInfo<br>CClfsManagedLog::FixupContainerName</summary>CClfsManagedLog::QueryLogBoundaryLsns<br>CClfsManagedLog::QueryLogContainerSize<br>CClfsManagedLog::QueryLogEphemeral<br>CClfsManagedLog::QueryLogSize<br>CClfsManagedLogClient::Initialize<br>CClfsRequest::GetIoStatistics<br>ClfsCreateLogFile<br>ClfsEnableThreadPrivilege<br>ClfsGetIoStatistics<br>__GSHandlerCheckCommon<br>wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_PopulateInitialConfiguredFeatureStates<br>wil_details_UpdateFeatureConfiguredStates</details>|
|paramcount|1|1|
|address|1c000c7e0|1c000c7e0|
|sig|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __security_check_cookie Calling Diff


```diff
--- __security_check_cookie calling
+++ __security_check_cookie calling
@@ -21,0 +22,2 @@
+wil_RtlStagingConfig_QueryFeatureState
+wil_details_FeatureReporting_ReportUsageToServiceDirect
```


## NTOSKRNL.EXE::RtlLookupElementGenericTableAvl

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlLookupElementGenericTableAvl|RtlLookupElementGenericTableAvl|
|fullname|NTOSKRNL.EXE::RtlLookupElementGenericTableAvl|NTOSKRNL.EXE::RtlLookupElementGenericTableAvl|
|`refcount`|2|3|
|length|0|0|
|called|||
|`calling`|CClfsRequest::Create|CClfsBaseFile::ValidateProcessQNode<br>CClfsRequest::Create|
|paramcount|0|0|
|`address`|EXTERNAL:0000007f|EXTERNAL:00000022|
|sig|undefined RtlLookupElementGenericTableAvl(void)|undefined RtlLookupElementGenericTableAvl(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlLookupElementGenericTableAvl Calling Diff


```diff
--- NTOSKRNL.EXE::RtlLookupElementGenericTableAvl calling
+++ NTOSKRNL.EXE::RtlLookupElementGenericTableAvl calling
@@ -0,0 +1 @@
+CClfsBaseFile::ValidateProcessQNode
```


## ContainerCount

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.76|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|ContainerCount|ContainerCount|
|fullname|CClfsBaseFile::ContainerCount|CClfsBaseFile::ContainerCount|
|`refcount`|14|15|
|length|107|107|
|called|CClfsBaseFile::GetBaseLogRecord<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::GetBaseLogRecord<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::MarkContainerQ<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnmarkContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ<br>CClfsLogFcbPhysical::Finalize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::InsertContainer</summary>CClfsLogFcbPhysical::ObservationContainerAvailable<br>CClfsLogFcbPhysical::ObservationContainerConsumed</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::ScanContainerInfo<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::LoadContainerQ<br>CClfsBaseFilePersisted::MarkContainerQ<br>CClfsBaseFilePersisted::ResetContainerQ<br>CClfsBaseFilePersisted::UnmarkContainerQ<br>CClfsBaseFileSnapshot::ReadContainerQ<br>CClfsLogFcbPhysical::Finalize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize</summary>CClfsLogFcbPhysical::InsertContainer<br>CClfsLogFcbPhysical::ObservationContainerAvailable<br>CClfsLogFcbPhysical::ObservationContainerConsumed</details>|
|paramcount|1|1|
|`address`|1c002cecc|1c002ec2c|
|sig|ulong __thiscall ContainerCount(CClfsBaseFile * this)|ulong __thiscall ContainerCount(CClfsBaseFile * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ContainerCount Calling Diff


```diff
--- CClfsBaseFile::ContainerCount calling
+++ CClfsBaseFile::ContainerCount calling
@@ -1,0 +2 @@
+CClfsBaseFile::ValidateContainerContextOffsets
```


## NTOSKRNL.EXE::ExFreePoolWithTag

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|ExFreePoolWithTag|ExFreePoolWithTag|
|fullname|NTOSKRNL.EXE::ExFreePoolWithTag|NTOSKRNL.EXE::ExFreePoolWithTag|
|`refcount`|184|187|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::InitializeGlobals<br>CClfsBaseFile::`scalar_deleting_destructor'<br>CClfsBaseFile::~CClfsBaseFile<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::CreateContainer<br>CClfsBaseFilePersisted::CreateContainerSecurityDescriptor<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::DestroyAbsoluteContainerPath<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor</summary>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadMetadataBlock<br>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFilePersisted::~CClfsBaseFilePersisted<br>CClfsBaseFileSnapshot::FreeMetadataBlock<br>CClfsBaseFileSnapshot::`vector_deleting_destructor'<br>CClfsContainer::WriteSector<br>CClfsDriver::Finalize<br>CClfsKernelMarshallingContext::DeallocateIocb<br>CClfsKernelMarshallingContext::Release<br>CClfsKernelMarshallingContext::~CClfsKernelMarshallingContext<br>CClfsLogFcbCommon::UninstallObserver<br>CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::DestroyBaseFileName<br>CClfsLogFcbPhysical::EraseClientBlocks<br>CClfsLogFcbPhysical::Finalize<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::ReleaseLsnMap<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::~CClfsLogFcbPhysical<br>CClfsManagedLog::AddContainersForGrowth<br>CClfsManagedLog::DeleteContainersForShrink<br>CClfsManagedLog::Finalize<br>CClfsManagedLog::GetContainerNameFromScanContext<br>CClfsManagedLog::GetNextSuffixFromExistingContainers<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::InvokeGrowWorker<br>CClfsManagedLog::UninstallPolicy<br>CClfsManagedLog::`scalar_deleting_destructor'<br>CClfsManagedLogClientKernel::`vector_deleting_destructor'<br>CClfsManagedLogClientUser::DestroyNotification<br>CClfsManagedLogClientUser::DestroyNotificationQueue<br>CClfsManagedLogClientUser::Finalize<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsManagedLogCollection::FindManagedLog<br>CClfsManagedLogCollection::FindOrCreateManagedLog<br>CClfsMdlReference::Release<br>CClfsRequest::FinalizeGlobals<br>CDynamicLsnQ::Initialize<br>CDynamicLsnQ::~CDynamicLsnQ<br>ClfsAddLogContainerSet<br>ClfsCreateLogFile<br>ClfsCreateLogFile$fin$0<br>ClfsCreateScanContext<br>ClfsCreateScanContext$fin$0<br>ClfsEnableThreadPrivilege<br>ClfsFinalize<br>ClfsMgmtpApcRundown<br>ClfsMgmtpAutoGrowWorker<br>ClfsScanLogContainers<br>`CClfsBaseFile::InitializeGlobals'::__l1::fin$0<br>`CClfsBaseFilePersisted::CheckSecureAccess'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateAbsoluteContainerPath'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateContainer'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateContainerSecurityDescriptor'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor'::__l1::fin$0<br>`CClfsBaseFilePersisted::OpenImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::QueryContainerSecurity'::__l1::fin$0<br>`CClfsBaseFilePersisted::ReadMetadataBlock'::__l1::fin$0<br>`CClfsContainer::WriteSector'::__l1::fin$0<br>`CClfsLogFcbPhysical::AddArchiveRef'::__l1::fin$0<br>`CClfsLogFcbPhysical::EraseClientBlocks'::__l1::fin$0<br>`CClfsLogFcbPhysical::FindEndOfLog'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetArchiveDescriptors'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings'::__l1::fin$0<br>`CClfsLogFcbPhysical::Initialize'::__l1::fin$0<br>`CClfsLogFcbPhysical::Initialize'::__l1::fin$1<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>`CClfsLogFcbPhysical::QueryPhysicalLsn'::__l1::fin$0<br>`CClfsLogFcbPhysical::TruncateLogModifyStreams'::__l1::fin$0<br>`CClfsLogFcbPhysical::TruncateLogStart'::__l1::fin$0<br>`CClfsLogFcbPhysical::UpdateCachedOwnerPage'::__l1::fin$0<br>`CClfsLogFcbPhysical::ValidateRegionBlocks'::__l1::fin$0<br>`CClfsManagedLog::DeleteContainersForShrink'::__l1::fin$0<br>`CClfsManagedLog::GetNextSuffixFromExistingContainers'::__l1::fin$0<br>`CClfsManagedLog::InvokeGrowWorker'::__l1::fin$0<br>`ClfsEnableThreadPrivilege'::__l1::fin$0<br>operator_delete</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::InitializeGlobals<br>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateTraverseTree<br>CClfsBaseFile::`scalar_deleting_destructor'<br>CClfsBaseFile::freeOffsetNode<br>CClfsBaseFile::~CClfsBaseFile<br>CClfsBaseFilePersisted::CheckSecureAccess<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::CreateContainer<br>CClfsBaseFilePersisted::CreateContainerSecurityDescriptor<br>CClfsBaseFilePersisted::CreateImage</summary>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::DestroyAbsoluteContainerPath<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadMetadataBlock<br>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFilePersisted::~CClfsBaseFilePersisted<br>CClfsBaseFileSnapshot::FreeMetadataBlock<br>CClfsBaseFileSnapshot::`vector_deleting_destructor'<br>CClfsContainer::WriteSector<br>CClfsDriver::Finalize<br>CClfsKernelMarshallingContext::DeallocateIocb<br>CClfsKernelMarshallingContext::Release<br>CClfsKernelMarshallingContext::~CClfsKernelMarshallingContext<br>CClfsLogFcbCommon::UninstallObserver<br>CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::DeleteContainer<br>CClfsLogFcbPhysical::DestroyBaseFileName<br>CClfsLogFcbPhysical::EraseClientBlocks<br>CClfsLogFcbPhysical::Finalize<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsLogFcbPhysical::~CClfsLogFcbPhysical<br>CClfsManagedLog::AddContainersForGrowth<br>CClfsManagedLog::DeleteContainersForShrink<br>CClfsManagedLog::Finalize<br>CClfsManagedLog::GetContainerNameFromScanContext<br>CClfsManagedLog::GetNextSuffixFromExistingContainers<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::InvokeGrowWorker<br>CClfsManagedLog::UninstallPolicy<br>CClfsManagedLog::`scalar_deleting_destructor'<br>CClfsManagedLogClientKernel::`vector_deleting_destructor'<br>CClfsManagedLogClientUser::DestroyNotification<br>CClfsManagedLogClientUser::DestroyNotificationQueue<br>CClfsManagedLogClientUser::Finalize<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsManagedLogCollection::FindManagedLog<br>CClfsManagedLogCollection::FindOrCreateManagedLog<br>CClfsMdlReference::Release<br>CClfsRequest::FinalizeGlobals<br>CDynamicLsnQ::Initialize<br>CDynamicLsnQ::~CDynamicLsnQ<br>ClfsAddLogContainerSet<br>ClfsCreateLogFile<br>ClfsCreateLogFile$fin$0<br>ClfsCreateScanContext<br>ClfsCreateScanContext$fin$0<br>ClfsEnableThreadPrivilege<br>ClfsFinalize<br>ClfsMgmtpApcRundown<br>ClfsMgmtpAutoGrowWorker<br>ClfsScanLogContainers<br>`CClfsBaseFile::InitializeGlobals'::__l1::fin$0<br>`CClfsBaseFilePersisted::CheckSecureAccess'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateAbsoluteContainerPath'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateContainer'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateContainerSecurityDescriptor'::__l1::fin$0<br>`CClfsBaseFilePersisted::CreateMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlock'::__l1::fin$0<br>`CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor'::__l1::fin$0<br>`CClfsBaseFilePersisted::OpenImage'::__l1::fin$0<br>`CClfsBaseFilePersisted::QueryContainerSecurity'::__l1::fin$0<br>`CClfsBaseFilePersisted::ReadMetadataBlock'::__l1::fin$0<br>`CClfsContainer::WriteSector'::__l1::fin$0<br>`CClfsLogFcbPhysical::AddArchiveRef'::__l1::fin$0<br>`CClfsLogFcbPhysical::EraseClientBlocks'::__l1::fin$0<br>`CClfsLogFcbPhysical::FindEndOfLog'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetArchiveDescriptors'::__l1::fin$0<br>`CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings'::__l1::fin$0<br>`CClfsLogFcbPhysical::Initialize'::__l1::fin$0<br>`CClfsLogFcbPhysical::Initialize'::__l1::fin$1<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>`CClfsLogFcbPhysical::QueryPhysicalLsn'::__l1::fin$0<br>`CClfsLogFcbPhysical::TruncateLogModifyStreams'::__l1::fin$0<br>`CClfsLogFcbPhysical::TruncateLogStart'::__l1::fin$0<br>`CClfsLogFcbPhysical::UpdateCachedOwnerPage'::__l1::fin$0<br>`CClfsLogFcbPhysical::ValidateRegionBlocks'::__l1::fin$0<br>`CClfsManagedLog::DeleteContainersForShrink'::__l1::fin$0<br>`CClfsManagedLog::GetNextSuffixFromExistingContainers'::__l1::fin$0<br>`CClfsManagedLog::InvokeGrowWorker'::__l1::fin$0<br>`ClfsEnableThreadPrivilege'::__l1::fin$0<br>operator_delete</details>|
|paramcount|0|0|
|address|EXTERNAL:00000002|EXTERNAL:00000002|
|sig|undefined ExFreePoolWithTag(void)|undefined ExFreePoolWithTag(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::ExFreePoolWithTag Calling Diff


```diff
--- NTOSKRNL.EXE::ExFreePoolWithTag calling
+++ NTOSKRNL.EXE::ExFreePoolWithTag calling
@@ -1,0 +2,2 @@
+CClfsBaseFile::ValidateOffsets
+CClfsBaseFile::ValidateTraverseTree
@@ -2,0 +5 @@
+CClfsBaseFile::freeOffsetNode
@@ -39 +41,0 @@
-CClfsLogFcbPhysical::ReleaseLsnMap
```


## NTOSKRNL.EXE::RtlInsertElementGenericTableAvl

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlInsertElementGenericTableAvl|RtlInsertElementGenericTableAvl|
|fullname|NTOSKRNL.EXE::RtlInsertElementGenericTableAvl|NTOSKRNL.EXE::RtlInsertElementGenericTableAvl|
|`refcount`|4|7|
|length|0|0|
|called|||
|`calling`|CClfsLogFcbPhysical::AddClient<br>CClfsLogFcbPhysical::OpenClient<br>CClfsRequest::Create|CClfsBaseFile::ValidateClientContextOffsets<br>CClfsBaseFile::ValidateContainerContextOffsets<br>CClfsBaseFile::ValidateProcessQNode<br>CClfsLogFcbPhysical::AddClient<br>CClfsLogFcbPhysical::OpenClient<br>CClfsRequest::Create|
|paramcount|0|0|
|`address`|EXTERNAL:0000007b|EXTERNAL:00000021|
|sig|undefined RtlInsertElementGenericTableAvl(void)|undefined RtlInsertElementGenericTableAvl(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlInsertElementGenericTableAvl Calling Diff


```diff
--- NTOSKRNL.EXE::RtlInsertElementGenericTableAvl calling
+++ NTOSKRNL.EXE::RtlInsertElementGenericTableAvl calling
@@ -0,0 +1,3 @@
+CClfsBaseFile::ValidateClientContextOffsets
+CClfsBaseFile::ValidateContainerContextOffsets
+CClfsBaseFile::ValidateProcessQNode
```


## NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|RtlNumberGenericTableElementsAvl|RtlNumberGenericTableElementsAvl|
|fullname|NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl|NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl|
|`refcount`|2|3|
|length|0|0|
|called|||
|`calling`|CClfsLogFcbPhysical::SetEndOfLog|CClfsBaseFile::ValidateOffsets<br>CClfsLogFcbPhysical::SetEndOfLog|
|paramcount|0|0|
|`address`|EXTERNAL:0000009f|EXTERNAL:00000024|
|sig|undefined RtlNumberGenericTableElementsAvl(void)|undefined RtlNumberGenericTableElementsAvl(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl Calling Diff


```diff
--- NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl calling
+++ NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl calling
@@ -0,0 +1 @@
+CClfsBaseFile::ValidateOffsets
```


## ClientCount

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|ClientCount|ClientCount|
|fullname|CClfsBaseFile::ClientCount|CClfsBaseFile::ClientCount|
|`refcount`|4|5|
|length|90|90|
|called|CClfsBaseFile::GetBaseLogRecord<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|CClfsBaseFile::GetBaseLogRecord<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExReleaseResourceForThreadLite|
|`calling`|CClfsBaseFile::LoadClientBaseLsn<br>CClfsLogFcbPhysical::CloseLog<br>CClfsLogFcbPhysical::DeleteLogIfNoVirtualStreams|CClfsBaseFile::LoadClientBaseLsn<br>CClfsBaseFile::ValidateClientContextOffsets<br>CClfsLogFcbPhysical::CloseLog<br>CClfsLogFcbPhysical::DeleteLogIfNoVirtualStreams|
|paramcount|1|1|
|`address`|1c0041338|1c0043398|
|sig|uchar __thiscall ClientCount(CClfsBaseFile * this)|uchar __thiscall ClientCount(CClfsBaseFile * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ClientCount Calling Diff


```diff
--- CClfsBaseFile::ClientCount calling
+++ CClfsBaseFile::ClientCount calling
@@ -1,0 +2 @@
+CClfsBaseFile::ValidateClientContextOffsets
```


## NTOSKRNL.EXE::ExAllocatePoolWithTag

### Match Info



|Key|clfs-10.0.22000.832.sys - clfs-10.0.22000.978.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|clfs-10.0.22000.832.sys|clfs-10.0.22000.978.sys|
| :---: | :---: | :---: |
|name|ExAllocatePoolWithTag|ExAllocatePoolWithTag|
|fullname|NTOSKRNL.EXE::ExAllocatePoolWithTag|NTOSKRNL.EXE::ExAllocatePoolWithTag|
|`refcount`|110|115|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CClfsBaseFile::InitializeGlobals<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::CreateContainer<br>CClfsBaseFilePersisted::CreateContainerSecurityDescriptor<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor<br>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadMetadataBlock</summary>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsContainer::InitializeGlobals<br>CClfsContainer::WriteSector<br>CClfsDriver::Initialize<br>CClfsDriver::SetIrpFunctions<br>CClfsKernelMarshallingContext::Initialize<br>CClfsLogFcbCommon::InstallObserver<br>CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::CreateBaseFileName<br>CClfsLogFcbPhysical::EraseClientBlocks<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsManagedLog::AddNewClient<br>CClfsManagedLog::AllocateAndBuildContainerNameTemplate<br>CClfsManagedLog::GetContainerNameFromScanContext<br>CClfsManagedLog::Initialize<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::InvokeGrowWorker<br>CClfsManagedLog::QueueAutoGrowWorker<br>CClfsManagedLogClientUser::CreateNotification<br>CClfsManagedLogClientUser::DeliverNotification<br>CClfsManagedLogCollection::AddNewManagedLog<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsRequest::InitializeGlobals<br>CClfsRequest::ReserveAndAppendLog<br>CClfsRequest::WriteRestart<br>CDynamicLsnQ::Initialize<br>ClfsAddLogContainerSet<br>ClfsCreateLogFile<br>ClfsCreateMarshallingAreaInternal<br>ClfsCreateScanContext<br>ClfsEnableThreadPrivilege<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>operator_new</details>|<details><summary>Expand for full list:<br>CClfsBaseFile::AllocOffsetNode<br>CClfsBaseFile::InitializeGlobals<br>CClfsBaseFile::InitializeImageResource<br>CClfsBaseFile::ValidateOffsets<br>CClfsBaseFile::ValidateTraverseTree<br>CClfsBaseFilePersisted::CreateAbsoluteContainerPath<br>CClfsBaseFilePersisted::CreateContainer<br>CClfsBaseFilePersisted::CreateContainerSecurityDescriptor<br>CClfsBaseFilePersisted::CreateImage<br>CClfsBaseFilePersisted::CreateMetadataBlock<br>CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor</summary>CClfsBaseFilePersisted::OpenImage<br>CClfsBaseFilePersisted::QueryContainerSecurity<br>CClfsBaseFilePersisted::ReadMetadataBlock<br>CClfsBaseFilePersisted::SetDefaultSaclSecurityDescriptor<br>CClfsBaseFileSnapshot::InitializeSnapshot<br>CClfsContainer::InitializeGlobals<br>CClfsContainer::WriteSector<br>CClfsDriver::Initialize<br>CClfsDriver::SetIrpFunctions<br>CClfsKernelMarshallingContext::Initialize<br>CClfsLogFcbCommon::InstallObserver<br>CClfsLogFcbPhysical::AddArchiveRef<br>CClfsLogFcbPhysical::CompleteFlush<br>CClfsLogFcbPhysical::CreateBaseFileName<br>CClfsLogFcbPhysical::EraseClientBlocks<br>CClfsLogFcbPhysical::FindEndOfLog<br>CClfsLogFcbPhysical::FlushMetadata<br>CClfsLogFcbPhysical::GetArchiveDescriptors<br>CClfsLogFcbPhysical::GetPhysicalToVirtualLsnMappings<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::Initialize<br>CClfsLogFcbPhysical::MarkLogFileContainers<br>CClfsLogFcbPhysical::QueryPhysicalLsn<br>CClfsLogFcbPhysical::TruncateLogModifyStreams<br>CClfsLogFcbPhysical::TruncateLogStart<br>CClfsLogFcbPhysical::UpdateCachedOwnerPage<br>CClfsLogFcbPhysical::ValidateContainerSize<br>CClfsLogFcbPhysical::ValidateRegionBlocks<br>CClfsManagedLog::AddNewClient<br>CClfsManagedLog::AllocateAndBuildContainerNameTemplate<br>CClfsManagedLog::GetContainerNameFromScanContext<br>CClfsManagedLog::Initialize<br>CClfsManagedLog::InstallDefaultNewContainerNamePolicies<br>CClfsManagedLog::InstallPolicy<br>CClfsManagedLog::InvokeGrowWorker<br>CClfsManagedLog::QueueAutoGrowWorker<br>CClfsManagedLogClientUser::CreateNotification<br>CClfsManagedLogClientUser::DeliverNotification<br>CClfsManagedLogCollection::AddNewManagedLog<br>CClfsManagedLogCollection::AllocateAndQueryPhysicalLogName<br>CClfsRequest::InitializeGlobals<br>CClfsRequest::ReserveAndAppendLog<br>CClfsRequest::WriteRestart<br>CDynamicLsnQ::Initialize<br>ClfsAddLogContainerSet<br>ClfsCreateLogFile<br>ClfsCreateMarshallingAreaInternal<br>ClfsCreateScanContext<br>ClfsEnableThreadPrivilege<br>`CClfsLogFcbPhysical::MarkLogFileContainers'::__l1::fin$0<br>operator_new</details>|
|paramcount|0|0|
|address|EXTERNAL:00000001|EXTERNAL:00000001|
|sig|undefined ExAllocatePoolWithTag(void)|undefined ExAllocatePoolWithTag(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::ExAllocatePoolWithTag Calling Diff


```diff
--- NTOSKRNL.EXE::ExAllocatePoolWithTag calling
+++ NTOSKRNL.EXE::ExAllocatePoolWithTag calling
@@ -0,0 +1 @@
+CClfsBaseFile::AllocOffsetNode
@@ -2,0 +4,2 @@
+CClfsBaseFile::ValidateOffsets
+CClfsBaseFile::ValidateTraverseTree
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-07-28T08:25:38</sub>