# pdc_1301.sys-pdc_1455.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_760025401__private_IsEnabledFallback](#feature_760025401__private_isenabledfallback)
	* [NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider](#ntoskrnlexertlunregisterfeatureusageprovider)
	* [NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification](#ntoskrnlexertlunregisterfeatureconfigurationchangenotification)
* [Modified](#modified)
	* [DriverEntry](#driverentry)
	* [PdcProcessMessage](#pdcprocessmessage)
	* [PdcpAlpcProcessMessages](#pdcpalpcprocessmessages)
	* [PdcAcquireLock](#pdcacquirelock)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [PdcReleaseLock](#pdcreleaselock)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [GetPdcLockThread](#getpdclockthread)

# Visual Chart Diff



```mermaid

flowchart LR

DriverEntry-4-old<--Match 95%-->DriverEntry-4-new
PdcProcessMessage-2-old<--Match 72%-->PdcProcessMessage-2-new
PdcpAlpcProcessMessages-0-old<--Match 83%-->PdcpAlpcProcessMessages-0-new
PdcAcquireLock-0-old<--Match 17%-->Feature_760025401__private_IsEnabledDeviceUsage-0-new

subgraph pdc_1455.sys
    DriverEntry-4-new
PdcProcessMessage-2-new
PdcpAlpcProcessMessages-0-new
Feature_760025401__private_IsEnabledDeviceUsage-0-new
    subgraph Added
direction LR
Feature_760025401__private_IsEnabledFallback
    NTOSKRNLEXE-RtlUnregisterFeatureUsageProvider
    NTOSKRNLEXE-RtlUnregisterFeatureConfigurationChangeNotification
end
end

subgraph pdc_1301.sys
    DriverEntry-4-old
PdcProcessMessage-2-old
PdcpAlpcProcessMessages-0-old
PdcAcquireLock-0-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.7608%
"unmatched_funcs_len" : 3
"matched_funcs_len" : 1251
```



```mermaid
pie showData
    title Matched Function Similarity - 99.2806%
"matched_funcs_with_code_changes_len" : 4
"matched_funcs_with_non_code_changes_len" : 5
"matched_funcs_no_changes_len" : 1242
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --max-ram-percent 60.0 --max-section-funcs 200 pdc_1301.sys pdc_1455.sys
```


#### Verbose Args


<details>

```
--old ['pdc_1301.sys'] --new [['pdc_1455.sys']] --engine VersionTrackingDiff --output-path pdc_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim False --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/pdc.sys/9E13773734000/pdc.sys -O pdc.sys.x64.10.0.26100.1301
wget https://msdl.microsoft.com/download/symbols/pdc.sys/3577C1F334000/pdc.sys -O pdc.sys.x64.10.0.26100.1455
```


## Binary Metadata Diff


```diff
--- pdc_1301.sys Meta
+++ pdc_1455.sys Meta
@@ -1,44 +1,44 @@
-Program Name: pdc_1301.sys
+Program Name: pdc_1455.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 1c0000000
 Maximum Address: ff0000184f
-# of Bytes: 219040
+# of Bytes: 219080
 # of Memory Blocks: 15
-# of Instructions: 26559
-# of Defined Data: 2268
-# of Functions: 625
-# of Symbols: 5820
+# of Instructions: 26623
+# of Defined Data: 2285
+# of Functions: 629
+# of Symbols: 5835
 # of Data Types: 2391
 # of Data Type Categories: 253
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sat Aug 22 14:34:18 SGT 2026
+Date Created: Sat Aug 22 14:34:20 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/pdc/pdc_1301.sys
-Executable MD5: afe7cd02573feff88274df14960993a6
-Executable SHA256: 5b22e887722d6f59f787354d6bca1cd8f91b1ad469be26d1de126729cd47588a
-FSRL: file:///tmp/pdc/pdc_1301.sys?MD5=afe7cd02573feff88274df14960993a6
+Executable Location: /tmp/pdc/pdc_1455.sys
+Executable MD5: bb00af593ba18a125b56e0abd617ca16
+Executable SHA256: 11ee9f3cbec684cfcae87497a67878e0f83d5b7a6e5c9417aefed7baf7af60a6
+FSRL: file:///tmp/pdc/pdc_1455.sys?MD5=bb00af593ba18a125b56e0abd617ca16
 PDB Age: 1
 PDB File: PDC.pdb
-PDB GUID: 4b9b4788-6587-9044-cd36-22c4ca399148
+PDB GUID: 8ff48182-a39a-2d26-9728-87d11ef85c91
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Power Dependency Coordinator Driver
-PE Property[FileVersion]: 10.0.26100.1301 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.1455 (WinBuild.160101.0800)
 PE Property[InternalName]: pdc.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: pdc.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.1301
+PE Property[ProductVersion]: 10.0.26100.1455
 PE Property[Translation]: 4b00000
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra pdc_1301.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra pdc_1301.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra pdc_1301.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra pdc_1455.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra pdc_1455.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra pdc_1455.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|3|
|deleted_funcs_len|0|
|modified_funcs_len|9|
|added_symbols_len|6|
|deleted_symbols_len|1|
|diff_time|3.2428267002105713|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 624, 'ExternalsName': 142, 'Implied Match': 1})|
|items_to_process|19|
|diff_types|Counter({'address': 7, 'refcount': 6, 'calling': 6, 'code': 4, 'length': 4, 'called': 4, 'name': 1, 'fullname': 1, 'sig': 1})|
|unmatched_funcs_len|3|
|total_funcs_len|1254|
|matched_funcs_len|1251|
|matched_funcs_with_code_changes_len|4|
|matched_funcs_with_non_code_changes_len|5|
|matched_funcs_no_changes_len|1242|
|match_func_similarity_percent|99.2806%|
|func_match_overall_percent|99.7608%|
|first_matches|Counter({'SymbolsHash': 624, 'Implied Match': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 624
"ExternalsName" : 142
"Implied-Match" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 624
"Implied-Match" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 3
"deleted_funcs_len" : 0
"modified_funcs_len" : 9
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 6
"deleted_symbols_len" : 1
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_760025401__private_IsEnabledFallback

### Function Meta



|Key|pdc_1455.sys|
| :---: | :---: |
|name|Feature_760025401__private_IsEnabledFallback|
|fullname|Feature_760025401__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_760025401__private_IsEnabledDeviceUsage|
|paramcount|2|
|address|1c00022d8|
|sig|undefined __fastcall Feature_760025401__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_760025401__private_IsEnabledFallback
+++ Feature_760025401__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_760025401__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_760025401__private_descriptor);
+  return;
+}
+

```


## NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider

### Function Meta



|Key|pdc_1455.sys|
| :---: | :---: |
|name|RtlUnregisterFeatureUsageProvider|
|fullname|NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider|
|refcount|2|
|length|0|
|called||
|calling|DriverEntry|
|paramcount|0|
|address|EXTERNAL:00000001|
|sig|undefined RtlUnregisterFeatureUsageProvider(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider*
## NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification

### Function Meta



|Key|pdc_1455.sys|
| :---: | :---: |
|name|RtlUnregisterFeatureConfigurationChangeNotification|
|fullname|NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification|
|refcount|2|
|length|0|
|called||
|calling|DriverEntry|
|paramcount|0|
|address|EXTERNAL:00000002|
|sig|undefined RtlUnregisterFeatureConfigurationChangeNotification(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification*
# Modified


*Modified functions contain code changes*
## DriverEntry

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.97|
|i_ratio|0.64|
|m_ratio|0.96|
|b_ratio|0.95|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|DriverEntry|DriverEntry|
|fullname|DriverEntry|DriverEntry|
|refcount|2|2|
|`length`|637|710|
|`called`|<details><summary>Expand for full list:<br>Feature_Servicing_RsAudio__private_IsEnabledDeviceUsage<br>InitializeTelemetryAssertsKMByDriverObject<br>McTemplateU0qq_EtwWriteTransfer<br>NTOSKRNL.EXE::ExSubscribeWnfStateChange<br>NTOSKRNL.EXE::IoCreateDevice<br>NTOSKRNL.EXE::IoDeleteDevice<br>PdcAcquireLock<br>PdcActivationClientRegister<br>PdcClientPolicyInitialize<br>PdcInitializeLock<br>PdcInitializePdc</summary>PdcLowPowerEpoch<br>PdcPpmInitialize<br>PdcPrint<br>PdcRegisterPdc<br>PdcReleaseLock<br>PdcTaskClientRegister<br>_guard_dispatch_icall</details>|<details><summary>Expand for full list:<br>Feature_Servicing_RsAudio__private_IsEnabledDeviceUsage<br>InitializeTelemetryAssertsKMByDriverObject<br>McTemplateU0qq_EtwWriteTransfer<br>NTOSKRNL.EXE::ExSubscribeWnfStateChange<br>NTOSKRNL.EXE::IoCreateDevice<br>NTOSKRNL.EXE::IoDeleteDevice<br>NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification<br>NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider<br>PdcAcquireLock<br>PdcActivationClientRegister<br>PdcClientPolicyInitialize</summary>PdcInitializeLock<br>PdcInitializePdc<br>PdcLowPowerEpoch<br>PdcPpmInitialize<br>PdcPrint<br>PdcRegisterPdc<br>PdcReleaseLock<br>PdcTaskClientRegister<br>_guard_dispatch_icall<br>wil_InitializeFeatureStaging</details>|
|calling|entry|entry|
|paramcount|4|4|
|address|1c002f078|1c002f078|
|sig|ulonglong __fastcall DriverEntry(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|ulonglong __fastcall DriverEntry(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### DriverEntry Called Diff


```diff
--- DriverEntry called
+++ DriverEntry called
@@ -6,0 +7,2 @@
+NTOSKRNL.EXE::RtlUnregisterFeatureConfigurationChangeNotification
+NTOSKRNL.EXE::RtlUnregisterFeatureUsageProvider
@@ -18,0 +21 @@
+wil_InitializeFeatureStaging
```


### DriverEntry Diff


```diff
--- DriverEntry
+++ DriverEntry
@@ -1,135 +1,144 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 ulonglong DriverEntry(longlong param_1,undefined8 param_2,undefined8 param_3,undefined8 param_4)
 
 {
   uint uVar1;
   ulonglong uVar2;
   undefined8 *puVar3;
   longlong lVar4;
   char *pcVar5;
   undefined8 uVar6;
   undefined8 local_res8;
   undefined8 in_stack_ffffffffffffffd8;
   undefined4 uVar7;
   ulonglong in_stack_ffffffffffffffe0;
   
   uVar7 = (undefined4)((ulonglong)in_stack_ffffffffffffffd8 >> 0x20);
+  wil_InitializeFeatureStaging();
   PdcPrint(2,"PDC: initializing %s\n","DriverEntry",param_4);
   uVar6 = 0x22;
   PdcDriverObject = param_1;
   uVar1 = IoCreateDevice(param_1,4,0,0x22,CONCAT44(uVar7,0x100),
                          in_stack_ffffffffffffffe0 & 0xffffffffffffff00,&PdcDevice);
   uVar2 = (ulonglong)uVar1;
   if ((int)uVar1 < 0) {
     pcVar5 = "PDC: IoCreateDevice: %08lx\n";
   }
   else {
     pcVar5 = "PDC: created device object: %p\n";
     PdcPrint(2,"PDC: created device object: %p\n",PdcDevice,uVar6);
     uVar1 = PdcInitializeLock();
     uVar2 = (ulonglong)uVar1;
     if ((int)uVar1 < 0) {
       pcVar5 = "PDC: PdcInitializeLock: %08lx\n";
     }
     else {
       PdcAcquireLock();
       InitializeTelemetryAssertsKMByDriverObject(param_1);
       uVar2 = PdcInitializePdc(0);
       uVar1 = (uint)uVar2;
       uVar2 = uVar2 & 0xffffffff;
       if ((int)uVar1 < 0) {
         pcVar5 = "PDC: PdcInitializePdc: %08lx\n";
       }
       else {
         uVar1 = PdcRegisterPdc();
         puVar3 = (undefined8 *)0x0;
         uVar2 = (ulonglong)uVar1;
         PdcLowPowerEpoch('\0');
         if (DAT_0 != (code *)0x0) {
           pcVar5 = (char *)CONCAT71((int7)((ulonglong)pcVar5 >> 8),1);
           puVar3 = (undefined8 *)0x0;
           (*DAT_0)();
         }
         PdcReleaseLock();
         if ((int)uVar1 < 0) {
           pcVar5 = "PDC: PdcRegisterPdc: %08lx\n";
         }
         else {
           uVar2 = PdcPpmInitialize();
           uVar1 = (uint)uVar2;
           uVar2 = uVar2 & 0xffffffff;
           if ((int)uVar1 < 0) {
             pcVar5 = "PDC: PdcPpmInitialize: %08lx\n";
           }
           else {
             uVar2 = Feature_Servicing_RsAudio__private_IsEnabledDeviceUsage();
             if ((int)uVar2 != 0) {
               PdcAcquireLock();
               local_res8 = 0;
               _PdcAudioPolicyContext = 0;
               _DAT_1 = 0;
               _DAT_2 = 0;
               _DAT_3 = 0;
               _DAT_4 = PdcAudioPolicyEvaluationWorker;
               uVar6 = 0;
               pcVar5 = &WNF_SEB_AUDIO_ACTIVITY;
               puVar3 = &local_res8;
               uVar1 = ExSubscribeWnfStateChange
                                 (puVar3,&WNF_SEB_AUDIO_ACTIVITY,1,0,
                                  PdcAudioPolicyHandleAudioActiveWnf,0);
               uVar2 = (ulonglong)uVar1;
               PdcReleaseLock();
               if ((int)uVar1 < 0) {
                 pcVar5 = "PDC: PdcAudioPolicyInitialize: %08lx\n";
                 goto LAB_5;
               }
             }
             uVar2 = PdcClientPolicyInitialize();
             uVar1 = (uint)uVar2;
             uVar2 = uVar2 & 0xffffffff;
             if ((int)uVar1 < 0) {
               pcVar5 = "PDC: PdcInitalizeClientPolicy: %08lx\n";
             }
             else {
               uVar2 = PdcActivationClientRegister(puVar3,pcVar5);
               uVar1 = (uint)uVar2;
               uVar2 = uVar2 & 0xffffffff;
               if ((int)uVar1 < 0) {
                 pcVar5 = "PDC: PdcRegisterInternalActivatorClient: %08lx\n";
               }
               else {
                 uVar1 = PdcTaskClientRegister();
                 uVar2 = (ulonglong)uVar1;
                 if (-1 < (int)uVar1) {
                   puVar3 = (undefined8 *)(param_1 + 0x70);
                   for (lVar4 = 0x1b; lVar4 != 0; lVar4 = lVar4 + -1) {
                     *puVar3 = PdcIrpInvalidRequest;
                     puVar3 = puVar3 + 1;
                   }
                   *(undefined8 *)(param_1 + 0x68) = 0;
                   return uVar2;
                 }
                 pcVar5 = "PDC: PdcRegisterInternalTaskClient: %08lx\n";
               }
             }
           }
         }
       }
     }
   }
 LAB_5:
   PdcPrint(1,pcVar5,(ulonglong)uVar1,uVar6);
   PdcPrint(1,"PDC: driver startup error: status: %08lx\n",uVar2,uVar6);
   lVar4 = PdcDevice;
   if (PdcDevice != 0) {
     IoDeleteDevice();
   }
   if ((DAT_6 & 2) != 0) {
     McTemplateU0qq_EtwWriteTransfer(lVar4,&PDC_INITIALIZATION,0,(int)uVar2);
   }
+  if (wil_details_featureChangeNotification != 0) {
+    RtlUnregisterFeatureConfigurationChangeNotification();
+    wil_details_featureChangeNotification = 0;
+  }
+  if (g_wil_details_featureUsageProvider != 0) {
+    RtlUnregisterFeatureUsageProvider();
+    g_wil_details_featureUsageProvider = 0;
+  }
   return uVar2;
 }
 

```


## PdcProcessMessage

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.46|
|i_ratio|0.58|
|m_ratio|0.98|
|b_ratio|0.72|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|PdcProcessMessage|PdcProcessMessage|
|fullname|PdcProcessMessage|PdcProcessMessage|
|refcount|2|2|
|`length`|1361|1407|
|`called`|<details><summary>Expand for full list:<br>MicrosoftTelemetryAssertTriggeredArgsMsgKM<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExReleasePushLockEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::ZwAlpcAcceptConnectPort<br>NTOSKRNL.EXE::ZwAlpcCancelMessage<br>NTOSKRNL.EXE::ZwAlpcOpenSenderProcess<br>NTOSKRNL.EXE::ZwClose<br>PdcAcquireLock<br>PdcAllocateUserClient</summary>PdcFreeClient<br>PdcPostprocessClient<br>PdcPrint<br>PdcProcessReceivedUserMessage<br>PdcReleaseLock<br>PdcSanitizeClientMessage<br>PdcValidateClient<br>__security_check_cookie<br>memset</details>|<details><summary>Expand for full list:<br>Feature_760025401__private_IsEnabledDeviceUsage<br>MicrosoftTelemetryAssertTriggeredArgsMsgKM<br>NTOSKRNL.EXE::ExAcquirePushLockExclusiveEx<br>NTOSKRNL.EXE::ExReleasePushLockEx<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::ZwAlpcAcceptConnectPort<br>NTOSKRNL.EXE::ZwAlpcCancelMessage<br>NTOSKRNL.EXE::ZwAlpcOpenSenderProcess<br>NTOSKRNL.EXE::ZwClose<br>PdcAcquireLock</summary>PdcAllocateUserClient<br>PdcFreeClient<br>PdcPostprocessClient<br>PdcPrint<br>PdcProcessReceivedUserMessage<br>PdcReleaseLock<br>PdcSanitizeClientMessage<br>PdcValidateClient<br>__security_check_cookie<br>memset</details>|
|calling|PdcpAlpcProcessMessages|PdcpAlpcProcessMessages|
|paramcount|2|2|
|`address`|1c001cda8|1c001d138|
|sig|undefined __fastcall PdcProcessMessage(undefined8 * param_1, longlong * param_2)|undefined __fastcall PdcProcessMessage(undefined8 * param_1, longlong * param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PdcProcessMessage Called Diff


```diff
--- PdcProcessMessage called
+++ PdcProcessMessage called
@@ -0,0 +1 @@
+Feature_760025401__private_IsEnabledDeviceUsage
```


### PdcProcessMessage Diff


```diff
--- PdcProcessMessage
+++ PdcProcessMessage
@@ -1,245 +1,264 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void PdcProcessMessage(undefined8 *param_1,longlong *param_2)
 
 {
-  longlong *plVar1;
-  short sVar2;
-  undefined4 uVar3;
-  undefined8 *puVar4;
-  code *pcVar5;
-  int iVar6;
+  short sVar1;
+  undefined4 uVar2;
+  undefined8 *puVar3;
+  code *pcVar4;
+  int iVar5;
+  ulonglong uVar6;
   longlong *plVar7;
   ushort uVar8;
   char *pcVar9;
-  longlong lVar10;
-  undefined1 *puVar11;
+  longlong *plVar10;
+  longlong lVar11;
   undefined1 *puVar12;
-  longlong *plVar13;
-  uint uVar14;
-  longlong *plVar16;
+  undefined1 *puVar13;
+  longlong *plVar14;
+  uint uVar15;
+  longlong *plVar17;
   undefined1 auStack_448 [8];
   undefined1 auStack_440 [24];
   undefined1 *local_428;
   longlong *local_420;
   undefined8 *local_418;
   undefined8 local_410;
   undefined1 local_408;
-  longlong local_3f8;
-  longlong *local_3f0;
-  ulonglong local_3e8;
+  ulonglong local_3f8;
+  longlong local_3f0;
+  longlong *local_3e8;
   undefined8 local_3e0;
   undefined8 uStack_3d8;
   undefined8 local_3d0;
   undefined8 uStack_3c8;
   undefined8 local_3c0;
   ulonglong uStack_3b8;
   char local_3a8 [800];
   undefined1 local_88 [16];
   undefined8 local_78;
   ulonglong local_38;
-  undefined8 *puVar15;
+  undefined8 *puVar16;
   
-  puVar11 = auStack_448;
+  puVar13 = auStack_448;
   puVar12 = auStack_448;
   local_38 = __security_cookie ^ (ulonglong)auStack_448;
-  plVar13 = (longlong *)0x0;
+  plVar14 = (longlong *)0x0;
   local_3c0 = 0;
-  local_3f8 = 0;
+  local_3f0 = 0;
   uStack_3b8 = uStack_3b8 & 0xffffffff00000000;
   local_3e0 = 0;
   uStack_3d8 = 0;
   local_3d0 = 0;
   uStack_3c8 = 0;
   memset(local_88,0,0x48);
-  local_3e8 = 0;
+  local_3f8 = 0;
   memset(local_3a8,0,800);
-  PdcAcquireLock();
+  uVar6 = Feature_760025401__private_IsEnabledDeviceUsage();
+  if ((int)uVar6 == 0) {
+    PdcAcquireLock();
+  }
   uVar8 = *(ushort *)((longlong)param_1 + 4);
-  uVar14 = uVar8 & 0xffff00ff;
-  puVar15 = (undefined8 *)(ulonglong)uVar14;
-  if (uVar14 == 1) {
+  uVar15 = uVar8 & 0xffff00ff;
+  puVar16 = (undefined8 *)(ulonglong)uVar15;
+  if (uVar15 == 1) {
     pcVar9 = local_3a8;
-    lVar10 = *param_2;
-    iVar6 = PdcSanitizeClientMessage
+    lVar11 = *param_2;
+    iVar5 = PdcSanitizeClientMessage
                       (param_1,(int)*(short *)((longlong)param_1 + 2),(undefined8 *)pcVar9);
-    if (iVar6 != 0) {
+    if (iVar5 != 0) {
       pcVar9 = "LPC_REQUEST";
       goto LAB_0;
     }
-    if ((((&DAT_1)[*(uint *)(*(longlong *)(lVar10 + 0x20) + 0x10)] != '\0') &&
-        (uVar14 = PdcProcessReceivedUserMessage(lVar10,local_3a8,pcVar9,(ulonglong)puVar15),
-        puVar12 = auStack_448, -1 < (int)uVar14)) ||
-       (iVar6 = ZwAlpcCancelMessage(PdcServerPort,0,param_2), puVar12 = auStack_448, -1 < iVar6))
+    if ((((&DAT_1)[*(uint *)(*(longlong *)(lVar11 + 0x20) + 0x10)] != '\0') &&
+        (uVar15 = PdcProcessReceivedUserMessage(lVar11,local_3a8,pcVar9,(ulonglong)puVar16),
+        puVar13 = auStack_448, -1 < (int)uVar15)) ||
+       (iVar5 = ZwAlpcCancelMessage(PdcServerPort,0,param_2), puVar13 = auStack_448, -1 < iVar5))
     goto LAB_2;
-    puVar15 = (undefined8 *)(ulonglong)*(uint *)((longlong)param_2 + 0x14);
+    puVar16 = (undefined8 *)(ulonglong)*(uint *)((longlong)param_2 + 0x14);
     pcVar9 = "%s: Unable to cancel ALPC message id=%x\n";
   }
   else {
-    puVar12 = auStack_448;
-    if (uVar14 != 3) {
-      if ((uVar14 == 5) || (uVar14 == 6)) {
-        puVar4 = (undefined8 *)*param_2;
-        puVar15 = puVar4;
-        PdcPrint(2,"%s: A client (%p) stopped.\n","PdcProcessMessage",puVar4);
+    puVar13 = auStack_448;
+    if (uVar15 != 3) {
+      if (uVar15 == 5) {
+LAB_3:
+        puVar3 = (undefined8 *)*param_2;
+        puVar16 = puVar3;
+        PdcPrint(2,"%s: A client (%p) stopped.\n","PdcProcessMessage",puVar3);
         KeEnterCriticalRegion();
         ExAcquirePushLockExclusiveEx(&PdcAlpcPushLock,0);
-        local_3f8 = puVar4[3];
-        plVar7 = puVar4 + 1;
-        puVar4[3] = 0;
-        lVar10 = *plVar7;
-        if ((*(longlong **)(lVar10 + 8) == plVar7) &&
-           (plVar13 = (longlong *)puVar4[2], (longlong *)*plVar13 == plVar7)) {
-          *plVar13 = lVar10;
-          *(longlong **)(lVar10 + 8) = plVar13;
+        local_3f0 = puVar3[3];
+        plVar10 = puVar3 + 1;
+        puVar3[3] = 0;
+        lVar11 = *plVar10;
+        if ((*(longlong **)(lVar11 + 8) == plVar10) &&
+           (plVar14 = (longlong *)puVar3[2], (longlong *)*plVar14 == plVar10)) {
+          *plVar14 = lVar11;
+          *(longlong **)(lVar11 + 8) = plVar14;
           ExReleasePushLockEx(&PdcAlpcPushLock,0);
           KeLeaveCriticalRegion();
-          PdcFreeClient((longlong *)puVar4[4]);
-          ZwClose(local_3f8);
-          puVar12 = auStack_448;
+          PdcFreeClient((longlong *)puVar3[4]);
+          ZwClose(local_3f0);
+          puVar13 = auStack_448;
           goto LAB_2;
         }
       }
       else {
-        if (uVar14 != 10) {
+        if (uVar15 == 6) {
+          uVar6 = Feature_760025401__private_IsEnabledDeviceUsage();
+          if ((int)uVar6 != 0) {
+            puVar16 = (undefined8 *)(ulonglong)(*(ushort *)((longlong)param_1 + 4) & 0xffff00ff);
+            goto LAB_4;
+          }
+          goto LAB_3;
+        }
+        if (uVar15 != 10) {
+LAB_4:
           pcVar9 = "%s: Not expecting message type=0x%x\n";
-          puVar11 = auStack_448;
-          goto LAB_3;
+          puVar12 = auStack_448;
+          goto LAB_5;
         }
         local_420 = &local_3e0;
         local_428 = (undefined1 *)CONCAT44(local_428._4_4_,0x400);
-        local_3f0 = (longlong *)0x0;
+        local_3e8 = (longlong *)0x0;
+        local_3f8 = 0;
         local_3e0 = CONCAT44(local_3e0._4_4_,0x30);
         uStack_3d8 = 0;
         uStack_3c8 = CONCAT44(uStack_3c8._4_4_,0x200);
         local_3d0 = 0;
         local_3c0 = 0;
         uStack_3b8 = 0;
-        uVar14 = ZwAlpcOpenSenderProcess(&local_3e8,PdcServerPort,param_1,0);
-        plVar16 = plVar13;
-        if (-1 < (int)uVar14) {
-          uVar14 = PdcSanitizeClientMessage
+        uVar15 = ZwAlpcOpenSenderProcess(&local_3f8,PdcServerPort,param_1,0);
+        plVar17 = plVar14;
+        if (-1 < (int)uVar15) {
+          uVar15 = PdcSanitizeClientMessage
                              (param_1,(int)*(short *)((longlong)param_1 + 2),(undefined8 *)local_3a8
                              );
-          if (uVar14 == 0) {
-            uVar14 = PdcValidateClient((longlong)local_3a8,local_3e8);
-            if ((uVar14 == 0) &&
-               (uVar14 = PdcAllocateUserClient((longlong)local_3a8,local_3e8,(longlong *)&local_3f0)
-               , plVar13 = (longlong *)0x0, plVar16 = local_3f0, -1 < (int)uVar14)) {
-              plVar13 = (longlong *)local_3f0[4];
+          if (uVar15 == 0) {
+            uVar15 = PdcValidateClient((longlong)local_3a8,local_3f8);
+            if ((uVar15 == 0) &&
+               (uVar15 = PdcAllocateUserClient((longlong)local_3a8,local_3f8,(longlong *)&local_3e8)
+               , plVar14 = (longlong *)0x0, plVar17 = local_3e8, -1 < (int)uVar15)) {
+              plVar14 = (longlong *)local_3e8[4];
             }
           }
           else {
             MicrosoftTelemetryAssertTriggeredArgsMsgKM
                       ("LPC_CONNECTION_REQUEST",9,(int)*(short *)((longlong)param_1 + 2),
                        "PdcSanitizeClientMessage failed");
           }
-          ZwClose(local_3e8);
+          ZwClose(local_3f8);
         }
         local_3e0 = CONCAT44(local_3e0._4_4_,0x30);
         uStack_3d8 = 0;
         uStack_3c8 = CONCAT44(uStack_3c8._4_4_,0x200);
         local_3d0 = 0;
         local_3c0 = 0;
         uStack_3b8 = 0;
         memset(local_88,0,0x48);
         local_78 = 800;
-        local_3f8 = 0;
-        if (plVar13 == (longlong *)0x0) {
-          local_420 = (longlong *)(longlong)(int)uVar14;
-          plVar7 = &local_3f8;
+        local_3f0 = 0;
+        if (plVar14 == (longlong *)0x0) {
+          local_420 = (longlong *)(longlong)(int)uVar15;
+          plVar7 = &local_3f0;
         }
         else {
-          plVar7 = plVar13 + 3;
-          local_420 = plVar13;
-        }
-        local_408 = plVar13 != (longlong *)0x0;
-        puVar15 = &local_3e0;
+          plVar7 = plVar14 + 3;
+          local_420 = plVar14;
+        }
+        local_408 = plVar14 != (longlong *)0x0;
+        puVar16 = &local_3e0;
         local_410 = 0;
         local_428 = local_88;
         local_418 = param_1;
-        iVar6 = ZwAlpcAcceptConnectPort(plVar7,PdcServerPort,0);
-        if (iVar6 < 0) {
+        iVar5 = ZwAlpcAcceptConnectPort(plVar7,PdcServerPort,0);
+        if (iVar5 < 0) {
           local_408 = 0;
           local_410 = 0;
-          local_420 = (longlong *)(longlong)iVar6;
+          local_420 = (longlong *)(longlong)iVar5;
           local_428 = local_88;
           local_418 = param_1;
-          ZwAlpcAcceptConnectPort(&local_3f8,PdcServerPort,0,&local_3e0);
-          puVar12 = auStack_448;
-          if (plVar13 != (longlong *)0x0) {
-            PdcFreeClient(plVar16);
-            puVar12 = auStack_448;
+          ZwAlpcAcceptConnectPort(&local_3f0,PdcServerPort,0,&local_3e0);
+          puVar13 = auStack_448;
+          if (plVar14 != (longlong *)0x0) {
+            PdcFreeClient(plVar17);
+            puVar13 = auStack_448;
           }
           goto LAB_2;
         }
-        puVar12 = auStack_448;
-        if (plVar13 == (longlong *)0x0) goto LAB_2;
+        puVar13 = auStack_448;
+        if (plVar14 == (longlong *)0x0) goto LAB_2;
         KeEnterCriticalRegion();
         ExAcquirePushLockExclusiveEx(&PdcAlpcPushLock,0);
-        plVar1 = plVar13 + 1;
-        plVar7 = DAT_4;
-        param_2 = plVar13;
-        if ((undefined *)*DAT_4 == &PdcClientPorts) {
-          *plVar1 = (longlong)&PdcClientPorts;
-          plVar13[2] = (longlong)DAT_4;
-          *DAT_4 = (longlong)plVar1;
-          DAT_4 = plVar1;
+        plVar7 = plVar14 + 1;
+        plVar10 = DAT_6;
+        param_2 = plVar14;
+        if ((undefined *)*DAT_6 == &PdcClientPorts) {
+          *plVar7 = (longlong)&PdcClientPorts;
+          plVar14[2] = (longlong)DAT_6;
+          *DAT_6 = (longlong)plVar7;
+          DAT_6 = plVar7;
           ExReleasePushLockEx(&PdcAlpcPushLock,0);
           KeLeaveCriticalRegion();
-          PdcPrint(2,"%s: A client connected, port context=%p\n","PdcProcessMessage",plVar13);
-          PdcPostprocessClient(plVar16);
-          puVar12 = auStack_448;
+          PdcPrint(2,"%s: A client connected, port context=%p\n","PdcProcessMessage",plVar14);
+          PdcPostprocessClient(plVar17);
+          puVar13 = auStack_448;
           goto LAB_2;
         }
       }
-      uVar8 = (ushort)plVar7;
-      pcVar5 = (code *)swi(0x29);
-      (*pcVar5)(3);
-      puVar12 = auStack_440;
+      uVar8 = (ushort)plVar10;
+      pcVar4 = (code *)swi(0x29);
+      (*pcVar4)(3);
+      puVar13 = auStack_440;
     }
-    lVar10 = *param_2;
+    lVar11 = *param_2;
     if ((uVar8 >> 0xd & 1) == 0) {
-      if ((&DAT_1)[*(uint *)(*(longlong *)(lVar10 + 0x20) + 0x10)] != '\0')
+      if ((&DAT_1)[*(uint *)(*(longlong *)(lVar11 + 0x20) + 0x10)] != '\0')
       goto LAB_2;
-      sVar2 = *(short *)((longlong)param_1 + 2);
+      sVar1 = *(short *)((longlong)param_1 + 2);
       pcVar9 = local_3a8;
-      *(undefined8 *)(puVar12 + -8) = 0x1c001d217;
-      iVar6 = PdcSanitizeClientMessage(param_1,(int)sVar2,(undefined8 *)pcVar9);
-      if (iVar6 == 0) {
-        *(undefined8 *)(puVar12 + -8) = 0x1c001d230;
-        PdcProcessReceivedUserMessage(lVar10,local_3a8,pcVar9,(ulonglong)puVar15);
+      *(undefined8 *)(puVar13 + -8) = 0x1c001d5cc;
+      iVar5 = PdcSanitizeClientMessage(param_1,(int)sVar1,(undefined8 *)pcVar9);
+      if (iVar5 == 0) {
+        *(undefined8 *)(puVar13 + -8) = 0x1c001d5e5;
+        PdcProcessReceivedUserMessage(lVar11,local_3a8,pcVar9,(ulonglong)puVar16);
         goto LAB_2;
       }
       pcVar9 = "LPC_DATAGRAM";
 LAB_0:
-      uVar3 = *(undefined4 *)(*(longlong *)(lVar10 + 0x20) + 0x10);
-      sVar2 = *(short *)((longlong)param_1 + 2);
-      *(undefined8 *)(puVar12 + -8) = 0x1c001d26b;
+      uVar2 = *(undefined4 *)(*(longlong *)(lVar11 + 0x20) + 0x10);
+      sVar1 = *(short *)((longlong)param_1 + 2);
+      *(undefined8 *)(puVar13 + -8) = 0x1c001d620;
       MicrosoftTelemetryAssertTriggeredArgsMsgKM
-                (pcVar9,uVar3,(int)sVar2,"PdcSanitizeClientMessage failed");
+                (pcVar9,uVar2,(int)sVar1,"PdcSanitizeClientMessage failed");
       goto LAB_2;
     }
-    uVar14 = *(uint *)((longlong)param_2 + 0x14);
-    *(undefined8 *)(puVar12 + -8) = 0x1c001d1bd;
+    uVar15 = *(uint *)((longlong)param_2 + 0x14);
+    *(undefined8 *)(puVar13 + -8) = 0x1c001d572;
     PdcPrint(1,"%s: ALPC message id=%x required continuation unexpectedly. Cancelling it.\n",
-             "PdcProcessMessage",(ulonglong)uVar14);
-    *(undefined8 *)(puVar12 + -8) = 0x1c001d1d0;
-    iVar6 = ZwAlpcCancelMessage(PdcServerPort,0,param_2);
-    if (-1 < iVar6) goto LAB_2;
-    puVar15 = (undefined8 *)(ulonglong)*(uint *)((longlong)param_2 + 0x14);
+             "PdcProcessMessage",(ulonglong)uVar15);
+    *(undefined8 *)(puVar13 + -8) = 0x1c001d585;
+    iVar5 = ZwAlpcCancelMessage(PdcServerPort,0,param_2);
+    if (-1 < iVar5) goto LAB_2;
+    puVar16 = (undefined8 *)(ulonglong)*(uint *)((longlong)param_2 + 0x14);
     pcVar9 = "%s: Unable to cancel ALPC message id=%x\n";
-    puVar11 = puVar12;
-  }
-LAB_3:
-  *(undefined8 *)(puVar11 + -8) = 0x1c001d2c9;
-  PdcPrint(1,pcVar9,"PdcProcessMessage",puVar15);
-  puVar12 = puVar11;
+    puVar12 = puVar13;
+  }
+LAB_5:
+  *(undefined8 *)(puVar12 + -8) = 0x1c001d67e;
+  PdcPrint(1,pcVar9,"PdcProcessMessage",puVar16);
+  puVar13 = puVar12;
 LAB_2:
-  *(undefined8 *)(puVar12 + -8) = 0x1c001d2ce;
-  PdcReleaseLock();
-  *(undefined8 *)(puVar12 + -8) = 0x1c001d2dd;
+  *(undefined8 *)(puVar13 + -8) = 0x1c001d683;
+  uVar6 = Feature_760025401__private_IsEnabledDeviceUsage();
+  if ((int)uVar6 == 0) {
+    *(undefined8 *)(puVar13 + -8) = 0x1c001d68c;
+    PdcReleaseLock();
+  }
+  *(undefined8 *)(puVar13 + -8) = 0x1c001d69b;
   return;
 }
 

```


## PdcpAlpcProcessMessages

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.65|
|i_ratio|0.63|
|m_ratio|0.86|
|b_ratio|0.83|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|PdcpAlpcProcessMessages|PdcpAlpcProcessMessages|
|fullname|PdcpAlpcProcessMessages|PdcpAlpcProcessMessages|
|refcount|3|3|
|`length`|285|349|
|`called`|NTOSKRNL.EXE::AlpcGetMessageAttribute<br>NTOSKRNL.EXE::AlpcInitializeMessageAttribute<br>NTOSKRNL.EXE::ZwAlpcSendWaitReceivePort<br>PdcPrint<br>PdcProcessMessage<br>__security_check_cookie<br>memset|<details><summary>Expand for full list:<br>Feature_760025401__private_IsEnabledDeviceUsage<br>GetPdcLockThread<br>NTOSKRNL.EXE::AlpcGetMessageAttribute<br>NTOSKRNL.EXE::AlpcInitializeMessageAttribute<br>NTOSKRNL.EXE::ZwAlpcSendWaitReceivePort<br>PdcAcquireLock<br>PdcPrint<br>PdcProcessMessage<br>PdcReleaseLock<br>__security_check_cookie<br>memset</summary></details>|
|calling|PdcAlpcInitializeChannel<br>PdcMessageCallback|PdcAlpcInitializeChannel<br>PdcMessageCallback|
|paramcount|0|0|
|`address`|1c001d460|1c001d820|
|sig|undefined __fastcall PdcpAlpcProcessMessages(void)|undefined __fastcall PdcpAlpcProcessMessages(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PdcpAlpcProcessMessages Called Diff


```diff
--- PdcpAlpcProcessMessages called
+++ PdcpAlpcProcessMessages called
@@ -0,0 +1,2 @@
+Feature_760025401__private_IsEnabledDeviceUsage
+GetPdcLockThread
@@ -3,0 +6 @@
+PdcAcquireLock
@@ -5,0 +9 @@
+PdcReleaseLock
```


### PdcpAlpcProcessMessages Diff


```diff
--- PdcpAlpcProcessMessages
+++ PdcpAlpcProcessMessages
@@ -1,43 +1,59 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void PdcpAlpcProcessMessages(void)
 
 {
-  uint uVar1;
-  longlong *plVar2;
+  bool bVar1;
+  uint uVar2;
+  ulonglong uVar3;
+  void *pvVar4;
+  longlong *plVar5;
   undefined1 auStack_438 [32];
   undefined8 *local_418;
   undefined8 *local_410;
   undefined1 *local_408;
   undefined8 *local_400;
   undefined8 local_3f8;
   undefined8 local_3f0;
   undefined8 local_3e8 [2];
   undefined1 local_3d8 [160];
   undefined8 local_338 [100];
   ulonglong local_18;
   
   local_18 = __security_cookie ^ (ulonglong)auStack_438;
   local_3f0 = 0;
   local_3e8[0] = 0;
+  bVar1 = false;
   memset(local_3d8,0,0xa0);
+  uVar3 = Feature_760025401__private_IsEnabledDeviceUsage();
+  if ((int)uVar3 != 0) {
+    pvVar4 = (void *)GetPdcLockThread();
+    if (pvVar4 != SystemReserved1[0xf]) {
+      PdcAcquireLock();
+      bVar1 = true;
+    }
+  }
   while( true ) {
     AlpcInitializeMessageAttribute(0x20000000,local_3d8,0xa0,&local_3f0);
     local_400 = local_3e8;
     local_408 = local_3d8;
     local_3f8 = 800;
     local_410 = &local_3f8;
     local_418 = local_338;
-    uVar1 = ZwAlpcSendWaitReceivePort(PdcServerPort,0,0,0);
-    if (uVar1 != 0) break;
-    plVar2 = (longlong *)AlpcGetMessageAttribute(local_3d8,0x20000000);
-    PdcProcessMessage(local_338,plVar2);
+    uVar2 = ZwAlpcSendWaitReceivePort(PdcServerPort,0,0,0);
+    if (uVar2 != 0) break;
+    plVar5 = (longlong *)AlpcGetMessageAttribute(local_3d8,0x20000000);
+    PdcProcessMessage(local_338,plVar5);
   }
-  if (uVar1 != 0x102) {
+  if (uVar2 != 0x102) {
     PdcPrint(1,"%s: ZwAlpcSendWaitReceivePort failed: 0x%x\n","PdcpAlpcProcessMessages",
-             (ulonglong)uVar1);
+             (ulonglong)uVar2);
+  }
+  uVar3 = Feature_760025401__private_IsEnabledDeviceUsage();
+  if (((int)uVar3 != 0) && (bVar1)) {
+    PdcReleaseLock();
   }
   return;
 }
 

```


## PdcAcquireLock

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|code,name,fullname,refcount,length,sig,address,calling,called|
|ratio|0.24|
|i_ratio|0.03|
|m_ratio|0.37|
|b_ratio|0.17|
|match_types|Implied Match|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|`name`|PdcAcquireLock|Feature_760025401__private_IsEnabledDeviceUsage|
|`fullname`|PdcAcquireLock|Feature_760025401__private_IsEnabledDeviceUsage|
|`refcount`|55|6|
|`length`|276|49|
|`called`|NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::KeClearEvent<br>NTOSKRNL.EXE::KeEnterCriticalRegion<br>NTOSKRNL.EXE::KeQueryUnbiasedInterruptTime<br>PdcSetTimer|Feature_760025401__private_IsEnabledFallback|
|`calling`|<details><summary>Expand for full list:<br>DriverEntry<br>PdcAcknowledgePhaseCallback<br>PdcAllocateUserClient<br>PdcAudioPolicyEvaluationWorker<br>PdcAudioPolicyHandleAudioActiveWnf<br>PdcCaptureSleepStudyStatistics<br>PdcChargePowerRequest<br>PdcClientPolicyInitialize<br>PdcEtwCallback<br>PdcHandleSignalQueue<br>PdcInitializeLock</summary>PdcLockStatsTelemetryWorkerRoutine<br>PdcMaintenanceResumeWorkItemCallback<br>PdcPoCompleteResiliencyCallback<br>PdcPortMessageWorkerThread<br>PdcProcessMessage<br>PdcQueryBootSessionStandbyActiveTime<br>PdcQueryResiliencyStats<br>PdcRegisterKernelClient<br>PdcSnapDiagnosticContext<br>PdcSuspendResume<br>PdcSystemIdle<br>PdcpAcDcSettingCallback<br>PdcpAcquireReleaseResiliencyBias<br>PdcpActivationWatchdog<br>PdcpArmEaRules<br>PdcpConfigureClientPolicyWorker<br>PdcpEaStartPolicyEvent<br>PdcpEaStopPolicyEvent<br>PdcpEnumerateBuiltinClientPolicies<br>PdcpEnumerateEaRules<br>PdcpEnumerateVetoPolicies<br>PdcpNotificationQueueWorker<br>PdcpNotificationWatchdog<br>PdcpPhasesWorker<br>PdcpPlatformInitializationCompleteCallback<br>PdcpPolicyClientShimHandleNearProximityInCall<br>PdcpPowerButtonSettingCallback<br>PdcpPpmProfileEvaluationWorker<br>PdcpPreRevocationWorker<br>PdcpProcessReceivedKernelMessage<br>PdcpProcessSynchKernelMessage<br>PdcpQueryResumeStats<br>PdcpRevocationWorker<br>PdcpSessionTimerCallback<br>PdcpTransitionWorker<br>PdcpVetoClientWorker<br>PdcpWnfScmPhaseCallback</details>|PdcProcessMessage<br>PdcpAlpcProcessMessages|
|paramcount|0|0|
|`address`|1c001e76c|1c00022a0|
|`sig`|undefined __fastcall PdcAcquireLock(void)|ulonglong __fastcall Feature_760025401__private_IsEnabledDeviceUsage(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PdcAcquireLock Called Diff


```diff
--- PdcAcquireLock called
+++ Feature_760025401__private_IsEnabledDeviceUsage called
@@ -1,5 +1 @@
-NTOSKRNL.EXE::ExAcquireResourceExclusiveLite
-NTOSKRNL.EXE::KeClearEvent
-NTOSKRNL.EXE::KeEnterCriticalRegion
-NTOSKRNL.EXE::KeQueryUnbiasedInterruptTime
-PdcSetTimer
+Feature_760025401__private_IsEnabledFallback
```


### PdcAcquireLock Calling Diff


```diff
--- PdcAcquireLock calling
+++ Feature_760025401__private_IsEnabledDeviceUsage calling
@@ -1,15 +0,0 @@
-DriverEntry
-PdcAcknowledgePhaseCallback
-PdcAllocateUserClient
-PdcAudioPolicyEvaluationWorker
-PdcAudioPolicyHandleAudioActiveWnf
-PdcCaptureSleepStudyStatistics
-PdcChargePowerRequest
-PdcClientPolicyInitialize
-PdcEtwCallback
-PdcHandleSignalQueue
-PdcInitializeLock
-PdcLockStatsTelemetryWorkerRoutine
-PdcMaintenanceResumeWorkItemCallback
-PdcPoCompleteResiliencyCallback
-PdcPortMessageWorkerThread
@@ -17,32 +2 @@
-PdcQueryBootSessionStandbyActiveTime
-PdcQueryResiliencyStats
-PdcRegisterKernelClient
-PdcSnapDiagnosticContext
-PdcSuspendResume
-PdcSystemIdle
-PdcpAcDcSettingCallback
-PdcpAcquireReleaseResiliencyBias
-PdcpActivationWatchdog
-PdcpArmEaRules
-PdcpConfigureClientPolicyWorker
-PdcpEaStartPolicyEvent
-PdcpEaStopPolicyEvent
-PdcpEnumerateBuiltinClientPolicies
-PdcpEnumerateEaRules
-PdcpEnumerateVetoPolicies
-PdcpNotificationQueueWorker
-PdcpNotificationWatchdog
-PdcpPhasesWorker
-PdcpPlatformInitializationCompleteCallback
-PdcpPolicyClientShimHandleNearProximityInCall
-PdcpPowerButtonSettingCallback
-PdcpPpmProfileEvaluationWorker
-PdcpPreRevocationWorker
-PdcpProcessReceivedKernelMessage
-PdcpProcessSynchKernelMessage
-PdcpQueryResumeStats
-PdcpRevocationWorker
-PdcpSessionTimerCallback
-PdcpTransitionWorker
-PdcpVetoClientWorker
-PdcpWnfScmPhaseCallback
+PdcpAlpcProcessMessages
```


### PdcAcquireLock Diff


```diff
--- PdcAcquireLock
+++ Feature_760025401__private_IsEnabledDeviceUsage
@@ -1,50 +1,17 @@
 
-/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
-
-void PdcAcquireLock(void)
+ulonglong Feature_760025401__private_IsEnabledDeviceUsage(void)
 
 {
-  longlong lVar1;
-  ulonglong uVar2;
-  uint uVar3;
-  ulonglong uVar4;
+  ulonglong uVar1;
+  undefined8 local_res8;
   
-  KeEnterCriticalRegion();
-  lVar1 = KeQueryUnbiasedInterruptTime();
-  ExAcquireResourceExclusiveLite(&PdcLock);
-  PdcLockThread = SystemReserved1[0xf];
-  _DAT_0 = KeQueryUnbiasedInterruptTime();
-  DAT_1 = DAT_1 + 1;
-  uVar2 = _DAT_0 - lVar1;
-  if (uVar2 < DAT_2) {
-    DAT_2 = uVar2;
-  }
-  if (DAT_3 < uVar2) {
-    DAT_3 = uVar2;
-  }
-  _DAT_4 = _DAT_4 + uVar2;
-  if (PdcLockStats == 0) {
-    uVar2 = 0;
+  local_res8 = (ulonglong)Feature_760025401__private_featureState;
+  if ((Feature_760025401__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_760025401__private_IsEnabledFallback(local_res8,3);
   }
   else {
-    uVar4 = 1;
-    uVar3 = 1;
-    if (1 < DAT_5) {
-      do {
-        uVar3 = (uint)uVar4;
-        if (uVar2 < *(ulonglong *)(&DAT_6 + uVar4 * 8)) break;
-        uVar3 = uVar3 + 1;
-        uVar4 = (ulonglong)uVar3;
-      } while (uVar3 < DAT_5);
-    }
-    uVar2 = (ulonglong)(uVar3 - 1);
+    uVar1 = (ulonglong)(Feature_760025401__private_featureState & 1);
   }
-  (&DAT_7)[uVar2] = (&DAT_7)[uVar2] + 1;
-  if (PdcLockWatchdogTimeoutMs != 0) {
-    KeClearEvent(&DAT_8);
-    PdcSetTimer(0x1c0013b40,(ulonglong)PdcLockWatchdogTimeoutMs);
-    _DAT_9 = KeQueryUnbiasedInterruptTime();
-  }
-  return;
+  return uVar1;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## PdcReleaseLock

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.68|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|PdcReleaseLock|PdcReleaseLock|
|fullname|PdcReleaseLock|PdcReleaseLock|
|`refcount`|60|61|
|length|374|374|
|called|NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::KeCancelTimer<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeQueryUnbiasedInterruptTime<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>PdcCheckForWork<br>PdcLockRecordBlackboxInformation|NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::KeCancelTimer<br>NTOSKRNL.EXE::KeLeaveCriticalRegion<br>NTOSKRNL.EXE::KeQueryUnbiasedInterruptTime<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>PdcCheckForWork<br>PdcLockRecordBlackboxInformation|
|`calling`|<details><summary>Expand for full list:<br>DriverEntry<br>PdcAcknowledgePhaseCallback<br>PdcAllocateUserClient<br>PdcAudioPolicyEvaluationWorker<br>PdcAudioPolicyHandleAudioActiveWnf<br>PdcCaptureSleepStudyStatistics<br>PdcChargePowerRequest<br>PdcClientPolicyInitialize<br>PdcEtwCallback<br>PdcHandleSignalQueue<br>PdcInitializeLock</summary>PdcLockStatsTelemetryWorkerRoutine<br>PdcMaintenanceResumeWorkItemCallback<br>PdcPoCompleteResiliencyCallback<br>PdcPortMessageWorkerThread<br>PdcProcessMessage<br>PdcQueryBootSessionStandbyActiveTime<br>PdcQueryResiliencyStats<br>PdcRegisterKernelClient<br>PdcSnapDiagnosticContext<br>PdcSuspendResume<br>PdcSystemIdle<br>PdcpAcDcSettingCallback<br>PdcpAcquireReleaseResiliencyBias<br>PdcpActivationWatchdog<br>PdcpArmEaRules<br>PdcpConfigureClientPolicyWorker<br>PdcpEaStartPolicyEvent<br>PdcpEaStopPolicyEvent<br>PdcpEnumerateBuiltinClientPolicies<br>PdcpEnumerateEaRules<br>PdcpEnumerateVetoPolicies<br>PdcpNotificationQueueWorker<br>PdcpNotificationWatchdog<br>PdcpPhasesWorker<br>PdcpPlatformInitializationCompleteCallback<br>PdcpPolicyClientShimHandleNearProximityInCall<br>PdcpPowerButtonSettingCallback<br>PdcpPpmProfileEvaluationWorker<br>PdcpPreRevocationWorker<br>PdcpProcessReceivedKernelMessage<br>PdcpProcessSynchKernelMessage<br>PdcpQueryResumeStats<br>PdcpRevocationWorker<br>PdcpSessionTimerCallback<br>PdcpTransitionWorker<br>PdcpVetoClientWorker<br>PdcpWnfScmPhaseCallback</details>|<details><summary>Expand for full list:<br>DriverEntry<br>PdcAcknowledgePhaseCallback<br>PdcAllocateUserClient<br>PdcAudioPolicyEvaluationWorker<br>PdcAudioPolicyHandleAudioActiveWnf<br>PdcCaptureSleepStudyStatistics<br>PdcChargePowerRequest<br>PdcClientPolicyInitialize<br>PdcEtwCallback<br>PdcHandleSignalQueue<br>PdcInitializeLock</summary>PdcLockStatsTelemetryWorkerRoutine<br>PdcMaintenanceResumeWorkItemCallback<br>PdcPoCompleteResiliencyCallback<br>PdcPortMessageWorkerThread<br>PdcProcessMessage<br>PdcQueryBootSessionStandbyActiveTime<br>PdcQueryResiliencyStats<br>PdcRegisterKernelClient<br>PdcSnapDiagnosticContext<br>PdcSuspendResume<br>PdcSystemIdle<br>PdcpAcDcSettingCallback<br>PdcpAcquireReleaseResiliencyBias<br>PdcpActivationWatchdog<br>PdcpAlpcProcessMessages<br>PdcpArmEaRules<br>PdcpConfigureClientPolicyWorker<br>PdcpEaStartPolicyEvent<br>PdcpEaStopPolicyEvent<br>PdcpEnumerateBuiltinClientPolicies<br>PdcpEnumerateEaRules<br>PdcpEnumerateVetoPolicies<br>PdcpNotificationQueueWorker<br>PdcpNotificationWatchdog<br>PdcpPhasesWorker<br>PdcpPlatformInitializationCompleteCallback<br>PdcpPolicyClientShimHandleNearProximityInCall<br>PdcpPowerButtonSettingCallback<br>PdcpPpmProfileEvaluationWorker<br>PdcpPreRevocationWorker<br>PdcpProcessReceivedKernelMessage<br>PdcpProcessSynchKernelMessage<br>PdcpQueryResumeStats<br>PdcpRevocationWorker<br>PdcpSessionTimerCallback<br>PdcpTransitionWorker<br>PdcpVetoClientWorker<br>PdcpWnfScmPhaseCallback</details>|
|paramcount|0|0|
|`address`|1c001ecd4|1c001f0d4|
|sig|undefined __fastcall PdcReleaseLock(void)|undefined __fastcall PdcReleaseLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PdcReleaseLock Calling Diff


```diff
--- PdcReleaseLock calling
+++ PdcReleaseLock calling
@@ -25,0 +26 @@
+PdcpAlpcProcessMessages
```


## wil_details_IsEnabledFallback

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|3|4|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_Connectivity_ModernStandbyImprovements__private_IsEnabledFallback<br>Feature_Servicing_RsAudio__private_IsEnabledFallback|Feature_760025401__private_IsEnabledFallback<br>Feature_Connectivity_ModernStandbyImprovements__private_IsEnabledFallback<br>Feature_Servicing_RsAudio__private_IsEnabledFallback|
|paramcount|3|3|
|address|1c00019e8|1c00019e8|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -0,0 +1 @@
+Feature_760025401__private_IsEnabledFallback
```


## GetPdcLockThread

### Match Info



|Key|pdc_1301.sys - pdc_1455.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pdc_1301.sys|pdc_1455.sys|
| :---: | :---: | :---: |
|name|GetPdcLockThread|GetPdcLockThread|
|fullname|GetPdcLockThread|GetPdcLockThread|
|`refcount`|3|4|
|length|8|8|
|called|||
|`calling`|PdcRecordLogEntry<br>PdcpPlatformInitializationCompleteCallback|PdcRecordLogEntry<br>PdcpAlpcProcessMessages<br>PdcpPlatformInitializationCompleteCallback|
|paramcount|0|0|
|`address`|1c0002284|1c00024b4|
|sig|undefined8 __fastcall GetPdcLockThread(void)|undefined8 __fastcall GetPdcLockThread(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### GetPdcLockThread Calling Diff


```diff
--- GetPdcLockThread calling
+++ GetPdcLockThread calling
@@ -1,0 +2 @@
+PdcpAlpcProcessMessages
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-22T14:35:12</sub>