# spoolsv-06.exe-spoolsv-07.exe Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [YAsyncGetRemoteNotifications](#yasyncgetremotenotifications)
* [Added](#added)
	* [`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''](#dynamic_initializer_for_nremotenotify_servertremotenotifyhandles_notifylistlock)
	* [NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel](#nremotenotify_servertremotenotifyhandleacquirechannel)
	* [NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications](#nremotenotify_servertremotenotifyserverasyncgetnotifications)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState](#wildetailsfeatureimpl__wilfeaturetraits_feature_1137672506getcachedfeatureenabledstate)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState](#wildetailsfeatureimpl__wilfeaturetraits_feature_1137672506getcurrentfeatureenabledstate)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage](#wildetailsfeatureimpl__wilfeaturetraits_feature_1137672506reportusage)
	* [NRemoteNotify_Server::TRemoteNotifyHandle::Unregister](#nremotenotify_servertremotenotifyhandleunregister)
	* [WPCInit](#wpcinit)
	* [NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled](#nremotenotify_routertremotenotifychannelrefreshcalled)
	* [DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>](#devmodesizepatchtelemetryfixdevmodeunsigned_short_const___ptr64___ptr64_devmodehandletype___ptr64unsigned_long___ptr64unsigned_short_const____ptr6410unsigned_short___ptr64)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState](#wildetailsfeatureimpl__wilfeaturetraits_feature_2040253753getcachedfeatureenabledstate)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState](#wildetailsfeatureimpl__wilfeaturetraits_feature_2040253753getcurrentfeatureenabledstate)
	* [wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage](#wildetailsfeatureimpl__wilfeaturetraits_feature_2040253753reportusage)
	* [`dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''](#dynamic_atexit_destructor_for_nremotenotify_servertremotenotifyhandles_notifylistlock)
	* [API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable](#api-ms-win-core-synch-l1-2-0dllwakeallconditionvariable)
	* [API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::InitializeConditionVariable](#api-ms-win-core-synch-l1-2-0dllinitializeconditionvariable)
	* [API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS](#api-ms-win-core-synch-l1-2-0dllsleepconditionvariablecs)
* [Modified](#modified)
	* [NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications](#nremotenotify_servertremotenotifyserverrefreshnotifications)
	* [LVerifyAndCorrectDevMode](#lverifyandcorrectdevmode)
	* [PrvRouterRefreshPrinterChangeNotification](#prvrouterrefreshprinterchangenotification)
	* [PrvClosePrinter](#prvcloseprinter)
	* [TRemoteWinspool::RpcAsyncGetRemoteNotifications](#tremotewinspoolrpcasyncgetremotenotifications)
	* [IsCurrentUserLocalAdmin](#iscurrentuserlocaladmin)
	* [InternalClosePrinter](#internalcloseprinter)
	* [FreeChange](#freechange)
	* [YClosePrinter](#ycloseprinter)
	* [PrvSpoolssInit](#prvspoolssinit)
	* [NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications](#nremotenotify_servertremotenotifyserverregisterfornotifications)
	* [PrvRouterFindNextPrinterChangeNotification](#prvrouterfindnextprinterchangenotification)
	* [NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications](#nremotenotify_servertremotenotifyserverunregisterfornotifications)
	* [NCoreLibrary::GetLastErrorAsHResult](#ncorelibrarygetlasterrorashresult)
	* [DevmodeSizePatchTelemetry::WriteDbgTraceInfo](#devmodesizepatchtelemetrywritedbgtraceinfo)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [NotifyNeeded](#notifyneeded)
	* [FindClosePrinterChangeNotificationWorker](#findcloseprinterchangenotificationworker)
	* [WilApi_GetFeatureEnabledState](#wilapi_getfeatureenabledstate)
	* [ReportUsageToService](#reportusagetoservice)
	* [Enter](#enter)
	* [push_back](#push_back)
	* [EnsureSubscribedToFeatureConfigurationChanges](#ensuresubscribedtofeatureconfigurationchanges)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount](#api-ms-win-core-synch-l1-1-0dllinitializecriticalsectionandspincount)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive](#api-ms-win-core-synch-l1-1-0dllacquiresrwlockexclusive)
	* [atexit](#atexit)
	* [~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>](#unique_storagewildetailsresource_policy_rtl_srwlock___ptr64void___cdecl_rtl_srwlock___ptr64void___cdecl_releasesrwlockexclusivestruct__rtl_srwlock___ptr64wistdintegral_constantunsigned___int641_rtl_srwlock___ptr64_rtl_srwlock___ptr640stdnullptr_t_)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection](#api-ms-win-core-synch-l1-1-0dlldeletecriticalsection)
	* [GetLastErrorAsHResult](#getlasterrorashresult)
	* [GetLastErrorAsFailHRNoBreak](#getlasterrorasfailhrnobreak)
	* [Release](#release)
	* [CreateRemoteNotifyData](#createremotenotifydata)
	* [API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError](#api-ms-win-core-errorhandling-l1-1-0dllsetlasterror)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection](#api-ms-win-core-synch-l1-1-0dllleavecriticalsection)
	* [_guard_dispatch_icall](#_guard_dispatch_icall)

# Visual Chart Diff



```mermaid

flowchart LR

NRemoteNotify_ServerTRemoteNotifyServerRefreshNotifications-3-old<--Match 57%-->NRemoteNotify_ServerTRemoteNotifyServerRefreshNotifications-3-new
LVerifyAndCorrectDevMode-5-old<--Match 24%-->LVerifyAndCorrectDevMode-5-new
PrvRouterRefreshPrinterChangeNotification-4-old<--Match 92%-->PrvRouterRefreshPrinterChangeNotification-4-new
PrvClosePrinter-1-old<--Match 4%-->PrvClosePrinter-1-new
TRemoteWinspoolRpcAsyncGetRemoteNotifications-3-old<--Match 0%-->TRemoteWinspoolRpcAsyncGetRemoteNotifications-3-new
IsCurrentUserLocalAdmin-1-old<--Match 72%-->IsCurrentUserLocalAdmin-1-new
InternalClosePrinter-2-old<--Match 76%-->InternalClosePrinter-2-new
FreeChange-1-old<--Match 90%-->FreeChange-1-new
YClosePrinter-2-old<--Match 67%-->YClosePrinter-2-new
PrvSpoolssInit-1-old<--Match 96%-->PrvSpoolssInit-1-new
NRemoteNotify_ServerTRemoteNotifyServerRegisterForNotifications-3-old<--Match 80%-->NRemoteNotify_ServerTRemoteNotifyServerRegisterForNotifications-3-new
PrvRouterFindNextPrinterChangeNotification-5-old<--Match 36%-->PrvRouterFindNextPrinterChangeNotification-5-new
NRemoteNotify_ServerTRemoteNotifyServerUnRegisterForNotifications-2-old<--Match 96%-->NRemoteNotify_ServerTRemoteNotifyServerUnRegisterForNotifications-2-new
NCoreLibraryGetLastErrorAsHResult-0-old<--Match 21%-->NRemoteNotify_RouterCreateRemoteNotifyChannel-0-new
DevmodeSizePatchTelemetryWriteDbgTraceInfo-2-old<--Match 43%-->wildetailsFeatureImpl__WilFeatureTraits_Feature_2040253753__private_IsEnabled-2-new

subgraph spoolsv-07.exe
    NRemoteNotify_ServerTRemoteNotifyServerRefreshNotifications-3-new
LVerifyAndCorrectDevMode-5-new
PrvRouterRefreshPrinterChangeNotification-4-new
PrvClosePrinter-1-new
TRemoteWinspoolRpcAsyncGetRemoteNotifications-3-new
IsCurrentUserLocalAdmin-1-new
InternalClosePrinter-2-new
FreeChange-1-new
YClosePrinter-2-new
PrvSpoolssInit-1-new
NRemoteNotify_ServerTRemoteNotifyServerRegisterForNotifications-3-new
PrvRouterFindNextPrinterChangeNotification-5-new
NRemoteNotify_ServerTRemoteNotifyServerUnRegisterForNotifications-2-new
NRemoteNotify_RouterCreateRemoteNotifyChannel-0-new
wildetailsFeatureImpl__WilFeatureTraits_Feature_2040253753__private_IsEnabled-2-new
    subgraph Added
direction LR
dynamic_initializer_for_NRemoteNotify_Server-TRemoteNotifyHandle-s_NotifyListLock
    NRemoteNotify_Server-TRemoteNotifyHandle-AcquireChannel
    NRemoteNotify_Server-TRemoteNotifyServer-AsyncGetNotifications
    wil-details-FeatureImpl__WilFeatureTraits_Feature_1137672506-GetCachedFeatureEnabledState
    wil-details-FeatureImpl__WilFeatureTraits_Feature_1137672506-GetCurrentFeatureEnabledState
    wil-details-FeatureImpl__WilFeatureTraits_Feature_1137672506-ReportUsage
    NRemoteNotify_Server-TRemoteNotifyHandle-Unregister
    WPCInit
    NRemoteNotify_Router-TRemoteNotifyChannel-RefreshCalled
    DevmodeSizePatchTelemetry-FixDevmodeunsigned_short_const___ptr64___ptr64_DEVMODEHANDLETYPE___ptr64unsigned_long___ptr64unsigned_short_const____ptr6410unsigned_short___ptr64
    wil-details-FeatureImpl__WilFeatureTraits_Feature_2040253753-GetCachedFeatureEnabledState
    wil-details-FeatureImpl__WilFeatureTraits_Feature_2040253753-GetCurrentFeatureEnabledState
    wil-details-FeatureImpl__WilFeatureTraits_Feature_2040253753-ReportUsage
    dynamic_atexit_destructor_for_NRemoteNotify_Server-TRemoteNotifyHandle-s_NotifyListLock
    API-MS-WIN-CORE-SYNCH-L1-2-0DLL-WakeAllConditionVariable
    API-MS-WIN-CORE-SYNCH-L1-2-0DLL-InitializeConditionVariable
    API-MS-WIN-CORE-SYNCH-L1-2-0DLL-SleepConditionVariableCS
end
end

subgraph spoolsv-06.exe
    NRemoteNotify_ServerTRemoteNotifyServerRefreshNotifications-3-old
LVerifyAndCorrectDevMode-5-old
PrvRouterRefreshPrinterChangeNotification-4-old
PrvClosePrinter-1-old
TRemoteWinspoolRpcAsyncGetRemoteNotifications-3-old
IsCurrentUserLocalAdmin-1-old
InternalClosePrinter-2-old
FreeChange-1-old
YClosePrinter-2-old
PrvSpoolssInit-1-old
NRemoteNotify_ServerTRemoteNotifyServerRegisterForNotifications-3-old
PrvRouterFindNextPrinterChangeNotification-5-old
NRemoteNotify_ServerTRemoteNotifyServerUnRegisterForNotifications-2-old
NCoreLibraryGetLastErrorAsHResult-0-old
DevmodeSizePatchTelemetryWriteDbgTraceInfo-2-old
    subgraph Deleted
direction LR
YAsyncGetRemoteNotifications
end
end

```


```mermaid
pie showData
    title Function Matches - 99.6703%
"unmatched_funcs_len" : 18
"matched_funcs_len" : 5441
```



```mermaid
pie showData
    title Matched Function Similarity - 99.2465%
"matched_funcs_with_code_changes_len" : 15
"matched_funcs_with_non_code_changes_len" : 26
"matched_funcs_no_changes_len" : 5400
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --max-ram-percent 60.0 --max-section-funcs 200 spoolsv-06.exe spoolsv-07.exe
```


#### Verbose Args


<details>

```
--old ['spoolsv-06.exe'] --new [['spoolsv-07.exe']] --engine VersionTrackingDiff --output-path out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim False --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/spoolsv.exe/261C621EF3000/spoolsv.exe -O spoolsv.exe.x64.10.0.28000.2336
wget https://msdl.microsoft.com/download/symbols/spoolsv.exe/8445204EF3000/spoolsv.exe -O spoolsv.exe.x64.10.0.28000.2525
```


## Binary Metadata Diff


```diff
--- spoolsv-06.exe Meta
+++ spoolsv-07.exe Meta
@@ -1,44 +1,44 @@
-Program Name: spoolsv-06.exe
+Program Name: spoolsv-07.exe
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 140000000
 Maximum Address: ff0000184f
-# of Bytes: 997648
+# of Bytes: 997808
 # of Memory Blocks: 10
-# of Instructions: 128116
-# of Defined Data: 15499
-# of Functions: 2720
-# of Symbols: 25898
-# of Data Types: 1726
-# of Data Type Categories: 188
+# of Instructions: 128822
+# of Defined Data: 15545
+# of Functions: 2739
+# of Symbols: 26007
+# of Data Types: 1737
+# of Data Type Categories: 187
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Fri Aug 28 16:10:42 SGT 2026
+Date Created: Fri Aug 28 16:10:52 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/Users/Jacob/Downloads/pdbs/spoolsv-06.exe
-Executable MD5: 6594a6c1d42575cc77295b48d4213728
-Executable SHA256: 0acfd274865ac57e47b277a2b76e42a4ee7cddb2814a98be1db60a88ddd2beff
-FSRL: file:///C:/Users/Jacob/Downloads/pdbs/spoolsv-06.exe?MD5=6594a6c1d42575cc77295b48d4213728
+Executable Location: /C:/Users/Jacob/Downloads/pdbs/spoolsv-07.exe
+Executable MD5: 6f8fada8432b0cce513642363b88c977
+Executable SHA256: dbaad571b941ef1dd39084497dc0004398b57f03defdf40817626b11741bdd84
+FSRL: file:///C:/Users/Jacob/Downloads/pdbs/spoolsv-07.exe?MD5=6f8fada8432b0cce513642363b88c977
 PDB Age: 1
 PDB File: spoolsv.pdb
-PDB GUID: 1b2c53f1-9c88-35d2-0bc8-3421d6d29521
+PDB GUID: 60fbbe55-de8f-d0fa-dbe2-bb7c24f1041e
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Spooler SubSystem App
-PE Property[FileVersion]: 10.0.28000.2336 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.28000.2525 (WinBuild.160101.0800)
 PE Property[InternalName]: spoolsv.exe
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: spoolsv.exe
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.28000.2336
+PE Property[ProductVersion]: 10.0.28000.2525
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra spoolsv-06.exe Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra spoolsv-06.exe Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra spoolsv-06.exe Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra spoolsv-07.exe Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra spoolsv-07.exe Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra spoolsv-07.exe Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|17|
|deleted_funcs_len|1|
|modified_funcs_len|41|
|added_symbols_len|12|
|deleted_symbols_len|6|
|diff_time|16.656458377838135|
|deleted_strings_len|0|
|added_strings_len|6|
|match_types|Counter({'SymbolsHash': 2695, 'ExternalsName': 398, 'SigCallingCalledHasher': 7, 'ExactInstructionsFunctionHasher': 6, 'Implied Match': 3, 'ExactBytesFunctionHasher': 2, 'BulkBasicBlockMnemonicHash': 1})|
|items_to_process|77|
|diff_types|Counter({'address': 41, 'refcount': 32, 'calling': 25, 'length': 16, 'called': 16, 'code': 15, 'name': 3, 'fullname': 3, 'sig': 3, 'parent': 3})|
|unmatched_funcs_len|18|
|total_funcs_len|5459|
|matched_funcs_len|5441|
|matched_funcs_with_code_changes_len|15|
|matched_funcs_with_non_code_changes_len|26|
|matched_funcs_no_changes_len|5400|
|match_func_similarity_percent|99.2465%|
|func_match_overall_percent|99.6703%|
|first_matches|Counter({'SymbolsHash': 2695, 'SigCallingCalledHasher': 7, 'ExactInstructionsFunctionHasher': 6, 'Implied Match': 3, 'ExactBytesFunctionHasher': 2, 'BulkBasicBlockMnemonicHash': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 2695
"ExternalsName" : 398
"ExactBytesFunctionHasher" : 2
"ExactInstructionsFunctionHasher" : 6
"SigCallingCalledHasher" : 7
"BulkBasicBlockMnemonicHash" : 1
"Implied-Match" : 3
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 2695
"ExactBytesFunctionHasher" : 2
"ExactInstructionsFunctionHasher" : 6
"SigCallingCalledHasher" : 7
"BulkBasicBlockMnemonicHash" : 1
"Implied-Match" : 3
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 17
"deleted_funcs_len" : 1
"modified_funcs_len" : 41
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 12
"deleted_symbols_len" : 6
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 6
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1,6 @@
+u_Invalid_dmDrive
+u_Invalid_sizes:
+u_Invalid_source
+u_New_devmode_siz
+u_Overflow_in_wCo
+u_Unexpected:_wFi

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|u_Invalid_sizes:_|1|LVerifyAndCorrectDevMode|
|u_Invalid_dmDrive|1|LVerifyAndCorrectDevMode|
|u_Overflow_in_wCo|1|LVerifyAndCorrectDevMode|
|u_New_devmode_siz|1|LVerifyAndCorrectDevMode|
|u_Unexpected:_wFi|1|LVerifyAndCorrectDevMode|
|u_Invalid_source_|1|LVerifyAndCorrectDevMode|

# Deleted

## YAsyncGetRemoteNotifications

### Function Meta



|Key|spoolsv-06.exe|
| :---: | :---: |
|name|YAsyncGetRemoteNotifications|
|fullname|YAsyncGetRemoteNotifications|
|refcount|2|
|length|140|
|called|GetLastErrorAsHResultAndFail<br>YImpersonateClient<br>YRevertToSelf<br>_guard_dispatch_icall$thunk$10345483385596137414|
|calling||
|paramcount|3|
|address|140027350|
|sig|long __cdecl YAsyncGetRemoteNotifications(_RPC_ASYNC_STATE * param_1, void * param_2, __MIDL_winspool_0021 * * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- YAsyncGetRemoteNotifications
+++ YAsyncGetRemoteNotifications
@@ -1,33 +0,0 @@
-
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
-/* long __cdecl YAsyncGetRemoteNotifications(struct _RPC_ASYNC_STATE * __ptr64,void * __ptr64,struct
-   __MIDL_winspool_0021 * __ptr64 * __ptr64) */
-
-long __cdecl
-YAsyncGetRemoteNotifications(_RPC_ASYNC_STATE *param_1,void *param_2,__MIDL_winspool_0021 **param_3)
-
-{
-  longlong *plVar1;
-  int iVar2;
-  long lVar3;
-  
-  iVar2 = YImpersonateClient(1);
-  if (iVar2 == 0) {
-    GetLastErrorAsHResultAndFail();
-  }
-  if (param_2 == (void *)0x0) {
-    lVar3 = -0x7ff8ffa9;
-  }
-  else if (*(int *)param_2 == 0x726d) {
-    plVar1 = *(longlong **)((longlong)param_2 + 8);
-    (**(code **)(*plVar1 + 8))(plVar1);
-    lVar3 = (**(code **)(*plVar1 + 0x18))(plVar1,param_1,param_3);
-  }
-  else {
-    lVar3 = -0x7ff8fffa;
-  }
-  YRevertToSelf(1);
-  return lVar3;
-}
-

```


# Added

## `dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|s_NotifyListLock''|
|fullname|`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''|
|refcount|3|
|length|63|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount<br>NCoreLibrary::GetLastErrorAsFailHRNoBreak<br>atexit|
|calling||
|paramcount|0|
|address|140002100|
|sig|undefined __fastcall s_NotifyListLock''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
+++ `dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
@@ -0,0 +1,20 @@
+
+void `dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock__(void)
+
+{
+  BOOL BVar1;
+  long lVar2;
+  
+  BVar1 = InitializeCriticalSectionAndSpinCount
+                    ((LPCRITICAL_SECTION)
+                     &NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock,0x80000000);
+  lVar2 = 0;
+  if (BVar1 == 0) {
+    lVar2 = NCoreLibrary::GetLastErrorAsFailHRNoBreak();
+  }
+  DAT_1400d61d8 = lVar2;
+  atexit(`dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::
+         s_NotifyListLock__);
+  return;
+}
+

```


## NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|AcquireChannel|
|fullname|NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel|
|refcount|3|
|length|105|
|called|NCoreLibrary::TCriticalSection::Enter<br>NCoreLibrary::TCriticalSection::Leave<br>_guard_dispatch_icall$thunk$10345483385596137414|
|calling|NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications|
|paramcount|1|
|address|140048a54|
|sig|TRemoteNotifyChannel * __cdecl AcquireChannel(void * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel
+++ NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel
@@ -0,0 +1,33 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+/* public: static class NRemoteNotify_Router::TRemoteNotifyChannel * __ptr64 __cdecl
+   NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel(void * __ptr64) */
+
+TRemoteNotifyChannel * __cdecl
+NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel(void *param_1)
+
+{
+  TRemoteNotifyHandle *pTVar1;
+  TRemoteNotifyChannel *pTVar2;
+  
+  pTVar2 = (TRemoteNotifyChannel *)0x0;
+  NCoreLibrary::TCriticalSection::Enter(&s_NotifyListLock);
+  pTVar1 = s_pNotifyListHead;
+  do {
+    if (pTVar1 == (TRemoteNotifyHandle *)0x0) {
+LAB_140048aa3:
+      NCoreLibrary::TCriticalSection::Leave(&s_NotifyListLock);
+      return pTVar2;
+    }
+    if (pTVar1 == param_1) {
+      if (*(int *)param_1 == 0x726d) {
+        pTVar2 = *(TRemoteNotifyChannel **)((longlong)param_1 + 8);
+        (**(code **)(*(longlong *)pTVar2 + 8))(pTVar2);
+      }
+      goto LAB_140048aa3;
+    }
+    pTVar1 = *(TRemoteNotifyHandle **)(pTVar1 + 0x18);
+  } while( true );
+}
+

```


## NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|AsyncGetNotifications|
|fullname|NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications|
|refcount|2|
|length|153|
|called|NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|TRemoteWinspool::RpcAsyncGetRemoteNotifications|
|paramcount|3|
|address|140048ac4|
|sig|long __cdecl AsyncGetNotifications(_RPC_ASYNC_STATE * param_1, void * param_2, __MIDL_winspool_0021 * * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications
+++ NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications
@@ -0,0 +1,40 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+/* public: static long __cdecl
+   NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications(struct _RPC_ASYNC_STATE *
+   __ptr64,void * __ptr64,struct __MIDL_winspool_0021 * __ptr64 * __ptr64) */
+
+long __cdecl
+NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications
+          (_RPC_ASYNC_STATE *param_1,void *param_2,__MIDL_winspool_0021 **param_3)
+
+{
+  bool bVar1;
+  long lVar2;
+  TRemoteNotifyChannel *pTVar3;
+  
+  bVar1 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                    ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                     &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                      ::__l2::impl);
+  if (bVar1) {
+    pTVar3 = TRemoteNotifyHandle::AcquireChannel(param_2);
+    if (pTVar3 == (TRemoteNotifyChannel *)0x0) {
+      return -0x7ff8fffa;
+    }
+  }
+  else {
+    if (param_2 == (void *)0x0) {
+      return -0x7ff8ffa9;
+    }
+    if (*(int *)param_2 != 0x726d) {
+      return -0x7ff8fffa;
+    }
+    pTVar3 = *(TRemoteNotifyChannel **)((longlong)param_2 + 8);
+    (**(code **)(*(longlong *)pTVar3 + 8))(pTVar3);
+  }
+  lVar2 = (**(code **)(*(longlong *)pTVar3 + 0x18))(pTVar3,param_1,param_3);
+  return lVar2;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|GetCachedFeatureEnabledState|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState|
|refcount|3|
|length|322|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|paramcount|1|
|address|140048b64|
|sig|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<__WilFeatureTraits_Feature_1137672506> * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
@@ -0,0 +1,80 @@
+
+/* WARNING: Removing unreachable block (ram,0x000140048bd1) */
+/* WARNING: Removing unreachable block (ram,0x000140048bd5) */
+/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
+/* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState(void) __ptr64 */
+
+void __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+          (FeatureImpl<__WilFeatureTraits_Feature_1137672506> *this)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  uint *in_RDX;
+  bool bVar6;
+  undefined *local_res10;
+  undefined8 local_28;
+  undefined4 *local_20;
+  
+  in_RDX[0] = 0;
+  uVar1 = Feature_1137672506__private_cppFeatureState;
+  in_RDX[1] = 0;
+  *in_RDX = Feature_1137672506__private_cppFeatureState;
+  if (((byte)uVar1 & 6) == 6) {
+    return;
+  }
+  uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
+  GetCurrentFeatureEnabledState(this,(int *)&local_res10);
+  uVar1 = (uint)local_res10;
+  uVar4 = *in_RDX;
+  do {
+    uVar5 = uVar4;
+    uVar3 = uVar5 | 0x40000;
+    *in_RDX = uVar3;
+    if ((uVar5 & 4) == 0) {
+      uVar3 = uVar5 & 0xfffffbff | 0x40000 | (uint)local_res10 & 0x400 | 4;
+      *in_RDX = uVar3;
+    }
+    LOCK();
+    bVar6 = uVar5 != Feature_1137672506__private_cppFeatureState;
+    uVar4 = uVar5;
+    if (bVar6) {
+      uVar3 = Feature_1137672506__private_cppFeatureState;
+      uVar4 = Feature_1137672506__private_cppFeatureState;
+    }
+    Feature_1137672506__private_cppFeatureState = uVar3;
+    UNLOCK();
+  } while (bVar6);
+  if (((uVar5 & 4) != 0) || (_g_enabledStateManager == 0)) goto LAB_140048c7b;
+  AcquireSRWLockExclusive((PSRWLOCK)&DAT_1400d6100);
+  local_res10 = &DAT_1400d6100;
+  if ((uVar2 == 0) || (uVar2 != DAT_1400d6114)) {
+LAB_140048c6d:
+    LOCK();
+    Feature_1137672506__private_cppFeatureState =
+         Feature_1137672506__private_cppFeatureState & 0xfffffffb;
+    UNLOCK();
+  }
+  else {
+    local_28 = 3;
+    local_20 = &Feature_1137672506__private_cppFeatureState;
+    bVar6 = details_abi::heap_buffer::push_back((heap_buffer *)&DAT_1400d6138,&local_28,0x10);
+    if (!bVar6) goto LAB_140048c6d;
+  }
+  unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+              *)&local_res10);
+LAB_140048c7b:
+  if ((*in_RDX & 2) == 0) {
+    *in_RDX = *in_RDX & 0xfffff63e | uVar1 & 0x9c1;
+  }
+  return;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|GetCurrentFeatureEnabledState|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState|
|refcount|2|
|length|166|
|called|wil::details::WilApi_GetFeatureEnabledState|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState|
|paramcount|2|
|address|140048cb0|
|sig|wil_details_FeatureStateCache __thiscall GetCurrentFeatureEnabledState(FeatureImpl<__WilFeatureTraits_Feature_1137672506> * this, int * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState
@@ -0,0 +1,43 @@
+
+/* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState(int * __ptr64) __ptr64 */
+
+int * __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState
+          (FeatureImpl<__WilFeatureTraits_Feature_1137672506> *this,int *param_1)
+
+{
+  uint uVar1;
+  bool bVar2;
+  FEATURE_ENABLED_STATE FVar3;
+  uint uVar4;
+  uint uVar5;
+  uint uVar6;
+  int *in_R8;
+  
+  FVar3 = WilApi_GetFeatureEnabledState(0x3bcadce,(FEATURE_CHANGE_TIME)param_1,in_R8);
+  param_1[0] = 0;
+  param_1[1] = 0;
+  uVar1 = ((FVar3 & 0x40) << 2 | FVar3 & 0x80) * 8;
+  if ((FVar3 & 0xffffff3f) == 0) {
+    uVar4 = 0x40;
+  }
+  else {
+    uVar4 = 0;
+    if ((FVar3 & 0xffffff3f) == 2) {
+      uVar4 = 0x40;
+    }
+  }
+  uVar5 = uVar4 | (FVar3 & 3) << 7 | uVar1;
+  bVar2 = false;
+  uVar6 = 1;
+  if ((((uVar1 & 0x400) != 0) && (0x7ff < uVar5)) || (uVar4 != 0)) {
+    bVar2 = true;
+  }
+  if ((uVar4 == 0) || (!bVar2)) {
+    uVar6 = 0;
+  }
+  *param_1 = uVar5 | uVar6;
+  return param_1;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|ReportUsage|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage|
|refcount|2|
|length|134|
|called|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::ReportUsageToService|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|paramcount|4|
|address|140049168|
|sig|void __thiscall ReportUsage(FeatureImpl<__WilFeatureTraits_Feature_1137672506> * this, bool param_1, ReportingKind param_2, __uint64 param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage
@@ -0,0 +1,30 @@
+
+/* public: void __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_1137672506>::ReportUsage(bool,enum wil::ReportingKind,unsigned
+   __int64) __ptr64 */
+
+void __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage
+          (FeatureImpl<__WilFeatureTraits_Feature_1137672506> *this,bool param_1,
+          ReportingKind param_2,__uint64 param_3)
+
+{
+  ulonglong *puVar1;
+  ulonglong uVar2;
+  __uint64 local_res20;
+  __uint64 in_stack_fffffffffffffff0;
+  
+  uVar2 = (ulonglong)Feature_1137672506__private_cppFeatureState;
+  local_res20 = param_3;
+  if ((Feature_1137672506__private_cppFeatureState & 4) == 0) {
+    puVar1 = (ulonglong *)GetCachedFeatureEnabledState(this);
+    uVar2 = *puVar1;
+  }
+  local_res20 = CONCAT26((short)(local_res20 >> 0x30),0x200000000);
+  ReportUsageToService
+            ((wil_details_FeatureReportingCache *)(this + 8),0x3bcadce,(uint)uVar2 >> 10 & 1,
+             (uint)(uVar2 >> 0xb) & 1,(FEATURE_LOGGED_TRAITS *)&local_res20,(uint)param_1,3,
+             in_stack_fffffffffffffff0);
+  return;
+}
+

```


## NRemoteNotify_Server::TRemoteNotifyHandle::Unregister

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|Unregister|
|fullname|NRemoteNotify_Server::TRemoteNotifyHandle::Unregister|
|refcount|2|
|length|88|
|called|NCoreLibrary::TCriticalSection::Enter<br>NCoreLibrary::TCriticalSection::Leave|
|calling|NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications|
|paramcount|1|
|address|140049328|
|sig|void __cdecl Unregister(TRemoteNotifyHandle * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- NRemoteNotify_Server::TRemoteNotifyHandle::Unregister
+++ NRemoteNotify_Server::TRemoteNotifyHandle::Unregister
@@ -0,0 +1,29 @@
+
+/* public: static void __cdecl NRemoteNotify_Server::TRemoteNotifyHandle::Unregister(class
+   NRemoteNotify_Server::TRemoteNotifyHandle * __ptr64) */
+
+void __cdecl NRemoteNotify_Server::TRemoteNotifyHandle::Unregister(TRemoteNotifyHandle *param_1)
+
+{
+  TRemoteNotifyHandle *pTVar1;
+  TRemoteNotifyHandle **ppTVar2;
+  
+  NCoreLibrary::TCriticalSection::Enter(&s_NotifyListLock);
+  ppTVar2 = &s_pNotifyListHead;
+  pTVar1 = s_pNotifyListHead;
+  do {
+    if (pTVar1 == (TRemoteNotifyHandle *)0x0) {
+LAB_14004936f:
+      NCoreLibrary::TCriticalSection::Leave(&s_NotifyListLock);
+      return;
+    }
+    if (pTVar1 == param_1) {
+      *ppTVar2 = (TRemoteNotifyHandle *)*(undefined8 *)(param_1 + 0x18);
+      *(undefined8 *)(param_1 + 0x18) = 0;
+      goto LAB_14004936f;
+    }
+    ppTVar2 = (TRemoteNotifyHandle **)(pTVar1 + 0x18);
+    pTVar1 = *ppTVar2;
+  } while( true );
+}
+

```


## WPCInit

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|WPCInit|
|fullname|WPCInit|
|refcount|2|
|length|102|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateEventW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::InitializeConditionVariable<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|PrvSpoolssInit|
|paramcount|0|
|address|14006e920|
|sig|int __cdecl WPCInit(void)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- WPCInit
+++ WPCInit
@@ -0,0 +1,25 @@
+
+/* int __cdecl WPCInit(void) */
+
+int __cdecl WPCInit(void)
+
+{
+  bool bVar1;
+  int iVar2;
+  
+  hEventPoll = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,0,0,(LPCWSTR)0x0);
+  iVar2 = 0;
+  if (hEventPoll != (HANDLE)0x0) {
+    InitializeCriticalSection(&RouterNotifySection);
+    bVar1 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                        ::__l2::impl);
+    if (bVar1) {
+      InitializeConditionVariable(&RemoteRefreshDrainCV);
+    }
+    iVar2 = 1;
+  }
+  return iVar2;
+}
+

```


## NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|RefreshCalled|
|fullname|NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled|
|refcount|3|
|length|49|
|called|NCoreLibrary::TCriticalSection::Enter<br>NCoreLibrary::TCriticalSection::Leave|
|calling|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications|
|paramcount|1|
|address|14007ba00|
|sig|void __thiscall RefreshCalled(TRemoteNotifyChannel * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled
+++ NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled
@@ -0,0 +1,13 @@
+
+/* public: void __cdecl NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled(void) __ptr64 */
+
+void __thiscall
+NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled(TRemoteNotifyChannel *this)
+
+{
+  NCoreLibrary::TCriticalSection::Enter((TCriticalSection *)(this + 0x28));
+  *(undefined1 *)(*(longlong *)(this + 0x20) + 0x38) = 0;
+  NCoreLibrary::TCriticalSection::Leave((TCriticalSection *)(this + 0x28));
+  return;
+}
+

```


## DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>|
|fullname|DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>|
|refcount|2|
|length|102|
|called|DevmodeSizePatchTelemetry::FixDevmode_<br>DevmodeSizePatchTelemetry::IsEnabled<br>wil::details::static_lazy<DevmodeSizePatchTelemetry>::get|
|calling|LVerifyAndCorrectDevMode|
|paramcount|5|
|address|140081368|
|sig|void __cdecl FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>(ushort * * param_1, _DEVMODEHANDLETYPE * param_2, ulong * param_3, ushort * param_4, ushort * param_5)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>
+++ DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>
@@ -0,0 +1,31 @@
+
+/* public: static void __cdecl DevmodeSizePatchTelemetry::FixDevmode<unsigned short const * __ptr64
+   & __ptr64,enum _DEVMODEHANDLETYPE & __ptr64,unsigned long & __ptr64,unsigned short const (&
+   __ptr64)[10],unsigned short & __ptr64>(unsigned short const * __ptr64 & __ptr64,enum
+   _DEVMODEHANDLETYPE & __ptr64,unsigned long & __ptr64,unsigned short const (&
+   __ptr64)[10],unsigned short & __ptr64) */
+
+void __cdecl
+DevmodeSizePatchTelemetry::
+FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>
+          (ushort **param_1,_DEVMODEHANDLETYPE *param_2,ulong *param_3,ushort *param_4,
+          ushort *param_5)
+
+{
+  bool bVar1;
+  uchar uVar2;
+  undefined7 uVar3;
+  
+  uVar2 = (uchar)param_1;
+  uVar3 = (undefined7)((ulonglong)param_1 >> 8);
+  bVar1 = IsEnabled(uVar2,(__uint64)param_2);
+  if (bVar1) {
+    wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
+              ((static_lazy<DevmodeSizePatchTelemetry> *)CONCAT71(uVar3,uVar2),
+               <lambda_e670ca4b9feaa84b0d1a9de084fa3046>::<lambda_invoker_cdecl>);
+    FixDevmode_((DevmodeSizePatchTelemetry *)CONCAT71(uVar3,uVar2),*param_1,*param_2,*param_3,
+                (ushort *)L"WrongSize",*param_5);
+  }
+  return;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|GetCachedFeatureEnabledState|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState|
|refcount|3|
|length|322|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled|
|paramcount|1|
|address|140081508|
|sig|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<__WilFeatureTraits_Feature_2040253753> * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
@@ -0,0 +1,80 @@
+
+/* WARNING: Removing unreachable block (ram,0x000140081575) */
+/* WARNING: Removing unreachable block (ram,0x000140081579) */
+/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
+/* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState(void) __ptr64 */
+
+void __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
+          (FeatureImpl<__WilFeatureTraits_Feature_2040253753> *this)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  uint *in_RDX;
+  bool bVar6;
+  undefined *local_res10;
+  undefined8 local_28;
+  undefined4 *local_20;
+  
+  in_RDX[0] = 0;
+  uVar1 = Feature_2040253753__private_cppFeatureState;
+  in_RDX[1] = 0;
+  *in_RDX = Feature_2040253753__private_cppFeatureState;
+  if (((byte)uVar1 & 6) == 6) {
+    return;
+  }
+  uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
+  GetCurrentFeatureEnabledState(this,(int *)&local_res10);
+  uVar1 = (uint)local_res10;
+  uVar4 = *in_RDX;
+  do {
+    uVar5 = uVar4;
+    uVar3 = uVar5 | 0x40000;
+    *in_RDX = uVar3;
+    if ((uVar5 & 4) == 0) {
+      uVar3 = uVar5 & 0xfffffbff | 0x40000 | (uint)local_res10 & 0x400 | 4;
+      *in_RDX = uVar3;
+    }
+    LOCK();
+    bVar6 = uVar5 != Feature_2040253753__private_cppFeatureState;
+    uVar4 = uVar5;
+    if (bVar6) {
+      uVar3 = Feature_2040253753__private_cppFeatureState;
+      uVar4 = Feature_2040253753__private_cppFeatureState;
+    }
+    Feature_2040253753__private_cppFeatureState = uVar3;
+    UNLOCK();
+  } while (bVar6);
+  if (((uVar5 & 4) != 0) || (_g_enabledStateManager == 0)) goto LAB_14008161f;
+  AcquireSRWLockExclusive((PSRWLOCK)&DAT_1400d6100);
+  local_res10 = &DAT_1400d6100;
+  if ((uVar2 == 0) || (uVar2 != DAT_1400d6114)) {
+LAB_140081611:
+    LOCK();
+    Feature_2040253753__private_cppFeatureState =
+         Feature_2040253753__private_cppFeatureState & 0xfffffffb;
+    UNLOCK();
+  }
+  else {
+    local_28 = 3;
+    local_20 = &Feature_2040253753__private_cppFeatureState;
+    bVar6 = details_abi::heap_buffer::push_back((heap_buffer *)&DAT_1400d6138,&local_28,0x10);
+    if (!bVar6) goto LAB_140081611;
+  }
+  unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+              *)&local_res10);
+LAB_14008161f:
+  if ((*in_RDX & 2) == 0) {
+    *in_RDX = *in_RDX & 0xfffff63e | uVar1 & 0x9c1;
+  }
+  return;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|GetCurrentFeatureEnabledState|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState|
|refcount|2|
|length|166|
|called|wil::details::WilApi_GetFeatureEnabledState|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState|
|paramcount|2|
|address|140081654|
|sig|wil_details_FeatureStateCache __thiscall GetCurrentFeatureEnabledState(FeatureImpl<__WilFeatureTraits_Feature_2040253753> * this, int * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState
@@ -0,0 +1,43 @@
+
+/* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState(int * __ptr64) __ptr64 */
+
+int * __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState
+          (FeatureImpl<__WilFeatureTraits_Feature_2040253753> *this,int *param_1)
+
+{
+  uint uVar1;
+  bool bVar2;
+  FEATURE_ENABLED_STATE FVar3;
+  uint uVar4;
+  uint uVar5;
+  uint uVar6;
+  int *in_R8;
+  
+  FVar3 = WilApi_GetFeatureEnabledState(0x3af3800,(FEATURE_CHANGE_TIME)param_1,in_R8);
+  param_1[0] = 0;
+  param_1[1] = 0;
+  uVar1 = ((FVar3 & 0x40) << 2 | FVar3 & 0x80) * 8;
+  if ((FVar3 & 0xffffff3f) == 0) {
+    uVar4 = 0x40;
+  }
+  else {
+    uVar4 = 0;
+    if ((FVar3 & 0xffffff3f) == 2) {
+      uVar4 = 0x40;
+    }
+  }
+  uVar5 = uVar4 | (FVar3 & 3) << 7 | uVar1;
+  bVar2 = false;
+  uVar6 = 1;
+  if ((((uVar1 & 0x400) != 0) && (0x7ff < uVar5)) || (uVar4 != 0)) {
+    bVar2 = true;
+  }
+  if ((uVar4 == 0) || (!bVar2)) {
+    uVar6 = 0;
+  }
+  *param_1 = uVar5 | uVar6;
+  return param_1;
+}
+

```


## wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|ReportUsage|
|fullname|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage|
|refcount|2|
|length|134|
|called|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState<br>wil::details::ReportUsageToService|
|calling|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled|
|paramcount|4|
|address|140081d9c|
|sig|void __thiscall ReportUsage(FeatureImpl<__WilFeatureTraits_Feature_2040253753> * this, bool param_1, ReportingKind param_2, __uint64 param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage
@@ -0,0 +1,30 @@
+
+/* public: void __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_2040253753>::ReportUsage(bool,enum wil::ReportingKind,unsigned
+   __int64) __ptr64 */
+
+void __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage
+          (FeatureImpl<__WilFeatureTraits_Feature_2040253753> *this,bool param_1,
+          ReportingKind param_2,__uint64 param_3)
+
+{
+  ulonglong *puVar1;
+  ulonglong uVar2;
+  __uint64 local_res20;
+  __uint64 in_stack_fffffffffffffff0;
+  
+  uVar2 = (ulonglong)Feature_2040253753__private_cppFeatureState;
+  local_res20 = param_3;
+  if ((Feature_2040253753__private_cppFeatureState & 4) == 0) {
+    puVar1 = (ulonglong *)GetCachedFeatureEnabledState(this);
+    uVar2 = *puVar1;
+  }
+  local_res20 = CONCAT26((short)(local_res20 >> 0x30),0x200000000);
+  ReportUsageToService
+            ((wil_details_FeatureReportingCache *)(this + 8),0x3af3800,(uint)uVar2 >> 10 & 1,
+             (uint)(uVar2 >> 0xb) & 1,(FEATURE_LOGGED_TRAITS *)&local_res20,(uint)param_1,3,
+             in_stack_fffffffffffffff0);
+  return;
+}
+

```


## `dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|s_NotifyListLock''|
|fullname|`dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''|
|refcount|3|
|length|47|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection|
|calling||
|paramcount|0|
|address|140083e50|
|sig|undefined __fastcall s_NotifyListLock''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
+++ `dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
@@ -0,0 +1,13 @@
+
+void `dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock__
+               (void)
+
+{
+  if (-1 < DAT_1400d61d8) {
+    DeleteCriticalSection
+              ((LPCRITICAL_SECTION)&NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock);
+    DAT_1400d61d8 = -0x7fffbffb;
+  }
+  return;
+}
+

```


## API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|WakeAllConditionVariable|
|fullname|API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable|
|refcount|2|
|length|0|
|called||
|calling|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications|
|paramcount|1|
|address|EXTERNAL:000000c5|
|sig|void __stdcall WakeAllConditionVariable(PCONDITION_VARIABLE ConditionVariable)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable*
## API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::InitializeConditionVariable

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|InitializeConditionVariable|
|fullname|API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::InitializeConditionVariable|
|refcount|2|
|length|0|
|called||
|calling|WPCInit|
|paramcount|1|
|address|EXTERNAL:000000c6|
|sig|void __stdcall InitializeConditionVariable(PCONDITION_VARIABLE ConditionVariable)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::InitializeConditionVariable*
## API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS

### Function Meta



|Key|spoolsv-07.exe|
| :---: | :---: |
|name|SleepConditionVariableCS|
|fullname|API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS|
|refcount|2|
|length|0|
|called||
|calling|InternalClosePrinter|
|paramcount|3|
|address|EXTERNAL:000000ca|
|sig|BOOL __stdcall SleepConditionVariableCS(PCONDITION_VARIABLE ConditionVariable, PCRITICAL_SECTION CriticalSection, DWORD dwMilliseconds)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS*
# Modified


*Modified functions contain code changes*
## NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.12|
|i_ratio|0.28|
|m_ratio|0.63|
|b_ratio|0.58|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|RefreshNotifications|RefreshNotifications|
|fullname|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications|
|refcount|2|2|
|`length`|274|626|
|`called`|NCoreLibrary::GetLastErrorAsHResult<br>NCoreLibrary::TCriticalSection::Enter<br>NCoreLibrary::TCriticalSection::Leave<br>NRemoteNotify_Library::CreateRemoteNotifyData<br>NRemoteNotify_Library::DecodeRemoteNotifyFilter<br>PrvRouterRefreshPrinterChangeNotification<br>_guard_dispatch_icall$thunk$10345483385596137414|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable<br>NCoreLibrary::GetLastErrorAsHResult<br>NRemoteNotify_Library::CreateRemoteNotifyData<br>NRemoteNotify_Library::DecodeRemoteNotifyFilter<br>NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled<br>NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel<br>PrvRouterRefreshPrinterChangeNotification<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled</summary></details>|
|calling|TRemoteWinspool::RpcSyncRefreshRemoteNotifications|TRemoteWinspool::RpcSyncRefreshRemoteNotifications|
|paramcount|3|3|
|`address`|140048c14|140048d60|
|sig|long __cdecl RefreshNotifications(void * param_1, __MIDL_winspool_0021 * param_2, __MIDL_winspool_0021 * * param_3)|long __cdecl RefreshNotifications(void * param_1, __MIDL_winspool_0021 * param_2, __MIDL_winspool_0021 * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications Called Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications called
+++ NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications called
@@ -0,0 +1,3 @@
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection
+API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::WakeAllConditionVariable
@@ -2,2 +4,0 @@
-NCoreLibrary::TCriticalSection::Enter
-NCoreLibrary::TCriticalSection::Leave
@@ -5,0 +7,2 @@
+NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled
+NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel
@@ -7,0 +11 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
+++ NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
@@ -1,51 +1,105 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* public: static long __cdecl NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications(void
    * __ptr64,struct __MIDL_winspool_0021 * __ptr64,struct __MIDL_winspool_0021 * __ptr64 * __ptr64)
     */
 
 long __cdecl
 NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
           (void *param_1,__MIDL_winspool_0021 *param_2,__MIDL_winspool_0021 **param_3)
 
 {
-  longlong *plVar1;
-  long lVar2;
-  int iVar3;
-  ulong local_res8 [2];
-  _RPC_V2_NOTIFY_OPTIONS *local_res20;
-  int *local_28;
-  _RPC_V2_NOTIFY_INFO *local_20;
+  int *piVar1;
+  bool bVar2;
+  long lVar3;
+  int iVar4;
+  TRemoteNotifyChannel *this;
+  ulong local_res20 [2];
+  int *local_38;
+  _RPC_V2_NOTIFY_INFO *local_30;
+  _RPC_V2_NOTIFY_OPTIONS *local_28 [2];
   
-  local_res8[0] = 0;
-  local_res20 = (_RPC_V2_NOTIFY_OPTIONS *)0x0;
-  local_20 = (_RPC_V2_NOTIFY_INFO *)0x0;
-  if (param_1 == (void *)0x0) {
-    return -0x7ff8ffa9;
+  local_res20[0] = 0;
+  local_28[0] = (_RPC_V2_NOTIFY_OPTIONS *)0x0;
+  local_30 = (_RPC_V2_NOTIFY_INFO *)0x0;
+  bVar2 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                    ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                     &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                      ::__l2::impl);
+  if (bVar2) {
+    this = TRemoteNotifyHandle::AcquireChannel(param_1);
+    if (this == (TRemoteNotifyChannel *)0x0) {
+      return -0x7ff8fffa;
+    }
   }
-  if (*(int *)param_1 == 0x726d) {
-    plVar1 = *(longlong **)((longlong)param_1 + 8);
-    (**(code **)(*plVar1 + 8))(plVar1);
-    lVar2 = NRemoteNotify_Library::DecodeRemoteNotifyFilter
-                      (param_2,(ulong *)0x0,(ulong *)0x0,local_res8,&local_res20);
-    if (-1 < lVar2) {
-      local_28 = (int *)0x0;
-      lVar2 = (**(code **)(*plVar1 + 0x30))(plVar1,&local_28);
-      if ((-1 < lVar2) &&
-         (((iVar3 = PrvRouterRefreshPrinterChangeNotification
-                              (local_28,local_res8[0],local_res20,&local_20), iVar3 != 0 ||
-           (lVar2 = NCoreLibrary::GetLastErrorAsHResult(), -1 < lVar2)) &&
-          (lVar2 = NRemoteNotify_Library::CreateRemoteNotifyData(0,0,local_20,param_3), -1 < lVar2))
-         )) {
-        NCoreLibrary::TCriticalSection::Enter((TCriticalSection *)(plVar1 + 5));
-        *(undefined1 *)(plVar1[4] + 0x38) = 0;
-        NCoreLibrary::TCriticalSection::Leave((TCriticalSection *)(plVar1 + 5));
+  else {
+    if (param_1 == (void *)0x0) {
+      return -0x7ff8ffa9;
+    }
+    if (*(int *)param_1 != 0x726d) {
+      return -0x7ff8fffa;
+    }
+    this = *(TRemoteNotifyChannel **)((longlong)param_1 + 8);
+    (**(code **)(*(longlong *)this + 8))(this);
+  }
+  lVar3 = NRemoteNotify_Library::DecodeRemoteNotifyFilter
+                    (param_2,(ulong *)0x0,(ulong *)0x0,local_res20,local_28);
+  if (-1 < lVar3) {
+    local_38 = (int *)0x0;
+    bVar2 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                        ::__l2::impl);
+    if (bVar2) {
+      EnterCriticalSection(&RouterNotifySection);
+      lVar3 = (**(code **)(*(longlong *)this + 0x30))(this,&local_38);
+      bVar2 = false;
+      if (-1 < lVar3) {
+        if (((local_38 == (int *)0x0) || (*local_38 != 0x6060)) ||
+           ((local_38[0x1b] != 0 ||
+            ((*(longlong *)(local_38 + 6) == 0 ||
+             ((*(byte *)(*(longlong *)(local_38 + 6) + 0xc) & 2) == 0)))))) {
+          lVar3 = -0x7ff8fffa;
+          bVar2 = false;
+        }
+        else {
+          local_38[0x1a] = local_38[0x1a] + 1;
+          lVar3 = 0;
+          bVar2 = true;
+        }
+      }
+      LeaveCriticalSection(&RouterNotifySection);
+      piVar1 = local_38;
+      if (bVar2) {
+        iVar4 = PrvRouterRefreshPrinterChangeNotification
+                          (local_38,local_res20[0],local_28[0],&local_30);
+        if (((iVar4 != 0) || (lVar3 = NCoreLibrary::GetLastErrorAsHResult(), -1 < lVar3)) &&
+           (lVar3 = NRemoteNotify_Library::CreateRemoteNotifyData(0,0,local_30,param_3), -1 < lVar3)
+           ) {
+          NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled(this);
+        }
+        EnterCriticalSection(&RouterNotifySection);
+        if (((piVar1 != (int *)0x0) && (0 < piVar1[0x1a])) &&
+           ((iVar4 = piVar1[0x1a] + -1, piVar1[0x1a] = iVar4, iVar4 == 0 && (piVar1[0x1b] != 0)))) {
+          WakeAllConditionVariable(&RemoteRefreshDrainCV);
+        }
+        LeaveCriticalSection(&RouterNotifySection);
       }
     }
-    (**(code **)(*plVar1 + 0x10))(plVar1);
-    return lVar2;
+    else {
+      lVar3 = (**(code **)(*(longlong *)this + 0x30))(this,&local_38);
+      if ((-1 < lVar3) &&
+         (((iVar4 = PrvRouterRefreshPrinterChangeNotification
+                              (local_38,local_res20[0],local_28[0],&local_30), iVar4 != 0 ||
+           (lVar3 = NCoreLibrary::GetLastErrorAsHResult(), -1 < lVar3)) &&
+          (lVar3 = NRemoteNotify_Library::CreateRemoteNotifyData(0,0,local_30,param_3), -1 < lVar3))
+         )) {
+        NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled(this);
+      }
+    }
   }
-  return -0x7ff8fffa;
+  (**(code **)(*(longlong *)this + 0x10))(this);
+  return lVar3;
 }
 

```


## LVerifyAndCorrectDevMode

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.27|
|i_ratio|0.14|
|m_ratio|0.81|
|b_ratio|0.24|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|LVerifyAndCorrectDevMode|LVerifyAndCorrectDevMode|
|fullname|LVerifyAndCorrectDevMode|LVerifyAndCorrectDevMode|
|refcount|2|2|
|`length`|857|1277|
|`called`|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_malloc<br>DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[6],unsigned_short&___ptr64><br>DevmodeSizePatchTelemetry::FixDevmode_<br>DevmodeSizePatchTelemetry::IsEnabled<br>DevmodeSizePatchTelemetry::WriteDbgTraceError<br>DevmodeSizePatchTelemetry::WriteDbgTraceInfo<br>memcpy<br>wil::details::static_lazy<DevmodeSizePatchTelemetry>::get|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_malloc<br>DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64><br>DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[6],unsigned_short&___ptr64><br>DevmodeSizePatchTelemetry::WriteDbgTraceError<br>DevmodeSizePatchTelemetry::WriteDbgTraceInfo<br>memcpy<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled|
|calling|LPatchDevmodeOfHandleType|LPatchDevmodeOfHandleType|
|paramcount|5|5|
|`address`|14008107c|140081838|
|sig|long __cdecl LVerifyAndCorrectDevMode(_devicemodeW * param_1, _devicemodeW * * param_2, int * param_3, ushort * param_4, _DEVMODEHANDLETYPE param_5)|long __cdecl LVerifyAndCorrectDevMode(_devicemodeW * param_1, _devicemodeW * * param_2, int * param_3, ushort * param_4, _DEVMODEHANDLETYPE param_5)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### LVerifyAndCorrectDevMode Called Diff


```diff
--- LVerifyAndCorrectDevMode called
+++ LVerifyAndCorrectDevMode called
@@ -1,0 +2 @@
+DevmodeSizePatchTelemetry::FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>
@@ -3,2 +3,0 @@
-DevmodeSizePatchTelemetry::FixDevmode_
-DevmodeSizePatchTelemetry::IsEnabled
@@ -8 +7 @@
-wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
```


### LVerifyAndCorrectDevMode Diff


```diff
--- LVerifyAndCorrectDevMode
+++ LVerifyAndCorrectDevMode
@@ -1,173 +1,268 @@
 
 /* long __cdecl LVerifyAndCorrectDevMode(struct _devicemodeW * __ptr64,struct _devicemodeW * __ptr64
    * __ptr64,int * __ptr64,unsigned short const * __ptr64,enum _DEVMODEHANDLETYPE) */
 
 long __cdecl
 LVerifyAndCorrectDevMode
           (_devicemodeW *param_1,_devicemodeW **param_2,int *param_3,ushort *param_4,
           _DEVMODEHANDLETYPE param_5)
 
 {
   ushort uVar1;
-  bool bVar2;
-  uint uVar3;
+  ushort uVar2;
+  bool bVar3;
   _devicemodeW *_Dst;
-  ulonglong uVar4;
-  uint uVar5;
-  char *this;
-  ushort uVar6;
-  ushort uVar7;
+  uint uVar4;
+  ulong *puVar5;
+  wchar_t *pwVar6;
+  ulonglong uVar7;
+  void *_Src;
   ulong *puVar8;
   ulong *puVar10;
-  wchar_t *pwVar11;
-  ulong *puVar12;
+  ushort *puVar11;
+  ushort uVar12;
+  uint uVar13;
+  uint uVar14;
+  ushort uVar15;
+  ushort *puVar16;
   ushort local_res8 [4];
   _devicemodeW **local_res10;
   int *local_res18;
   ushort *local_res20;
-  int local_68;
+  undefined8 in_stack_ffffffffffffff98;
+  undefined4 uVar17;
+  int local_58;
   ulong *puVar9;
   
+  uVar17 = (undefined4)((ulonglong)in_stack_ffffffffffffff98 >> 0x20);
   puVar9 = (ulong *)0x0;
   puVar8 = (ulong *)0x0;
-  local_68 = 0;
+  local_58 = 0;
   if (param_1 == (_devicemodeW *)0x0) {
     return 0x57;
   }
-  uVar7 = 0;
   if (param_1->dmSize == 0) {
     return 0x57;
   }
+  uVar12 = param_1->dmDriverExtra;
   uVar1 = param_1->dmSize;
-  uVar6 = param_1->dmDriverExtra;
   *param_3 = 0;
-  uVar5 = (uint)uVar1 + (uint)uVar6;
+  uVar4 = (uint)uVar1 + (uint)uVar12;
   local_res10 = param_2;
   local_res18 = param_3;
   local_res20 = param_4;
-  if (uVar6 < 4) {
-    DevmodeSizePatchTelemetry::WriteDbgTraceInfo
-              ("LVerifyAndCorrectDevMode",(ushort *)L"No driver private members, No Signature");
+  if (uVar12 < 4) {
+    pwVar6 = L"No driver private members, No Signature";
+    puVar10 = puVar9;
+LAB_0:
+    DevmodeSizePatchTelemetry::WriteDbgTraceInfo("LVerifyAndCorrectDevMode",(ushort *)pwVar6);
     *param_3 = 1;
-    puVar12 = puVar9;
-LAB_0:
+    uVar7 = 0;
     local_res8[0] = 0;
+    puVar16 = (ushort *)0x0;
   }
   else {
-    puVar12 = (ulong *)((longlong)param_1->dmDeviceName + (ulonglong)param_1->dmSize);
-    if (*puVar12 == 0x554e4944) {
+    puVar10 = (ulong *)((longlong)param_1->dmDeviceName + (ulonglong)param_1->dmSize);
+    if (*puVar10 == 0x554e4944) {
       DevmodeSizePatchTelemetry::WriteDbgTraceInfo
                 ("LVerifyAndCorrectDevMode",(ushort *)L"UNIDRV Signature");
-      uVar6 = param_1->dmDriverExtra;
-      if (uVar6 < 0x25c) {
-        pwVar11 = L"Unexpected DriverExtra size: %u DriverExtra size smaller than UNIDRVEXTRAF";
+      uVar12 = param_1->dmDriverExtra;
+      if (uVar12 < 0x25c) {
+        pwVar6 = L"Unexpected DriverExtra size: %u DriverExtra size smaller than UNIDRVEXTRAF";
         goto LAB_1;
       }
-      uVar7 = 0x25c;
-      uVar6 = (short)puVar12[2] - *(short *)((longlong)puVar12 + 6);
-      if ((uVar6 != 0x25c) && (uVar6 != 0x45c)) {
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                          ::__l2::impl);
+      if ((bVar3) && ((ushort)puVar10[2] < *(ushort *)((longlong)puVar10 + 6))) {
 LAB_2:
-        pwVar11 = L"Unexpected fixblock size: %u";
-        local_res8[0] = uVar6;
+        pwVar6 = L"Invalid sizes: wCoreFullSize < wCoreJTExpSize";
+        goto LAB_3;
+      }
+      puVar16 = (ushort *)0x25c;
+      uVar12 = (short)puVar10[2] - *(short *)((longlong)puVar10 + 6);
+      uVar7 = (ulonglong)uVar12;
+      local_res8[0] = uVar12;
+      wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                 &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                  ::__l2::impl);
+      if ((uVar12 - 0x25c & 0xfdff) != 0) {
+LAB_4:
+        pwVar6 = L"Unexpected fixblock size: %u";
 LAB_1:
         DevmodeSizePatchTelemetry::WriteDbgTraceError
-                  ("LVerifyAndCorrectDevMode",(ushort *)pwVar11,(ulonglong)uVar6);
+                  ("LVerifyAndCorrectDevMode",(ushort *)pwVar6,(ulonglong)uVar12);
         return 0x57;
       }
-      local_68 = 0x230;
-      *(short *)(puVar12 + 2) = *(short *)((longlong)puVar12 + 6) + 0x25c;
-      local_res8[0] = uVar6;
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                          ::__l2::impl);
+      if ((bVar3) && ((int)(0xffff - (uint)*(ushort *)((longlong)puVar10 + 6)) < 0x25c)) {
+LAB_5:
+        pwVar6 = L"Overflow in wCoreFullSize calculation";
+        goto LAB_3;
+      }
+      *(short *)(puVar10 + 2) = *(short *)((longlong)puVar10 + 6) + 0x25c;
+      local_58 = 0x230;
     }
     else {
-      if (*puVar12 != 0x56495250) {
-        DevmodeSizePatchTelemetry::WriteDbgTraceInfo
-                  ("LVerifyAndCorrectDevMode",(ushort *)L"UnKnown Signature");
-        *param_3 = 1;
+      if (*puVar10 != 0x56495250) {
+        pwVar6 = L"UnKnown Signature";
         goto LAB_0;
       }
       DevmodeSizePatchTelemetry::WriteDbgTraceInfo
                 ("LVerifyAndCorrectDevMode",(ushort *)L"PSDRV Signature");
-      uVar6 = param_1->dmDriverExtra;
-      uVar7 = 0x2f4;
-      if (uVar6 < 0x2f4) {
-        pwVar11 = L"Unexpected DriverExtra size: %u, DriverExtra size smaller than PSDRVEXTRAF ";
+      uVar12 = param_1->dmDriverExtra;
+      puVar16 = (ushort *)0x2f4;
+      if (uVar12 < 0x2f4) {
+        pwVar6 = L"Unexpected DriverExtra size: %u, DriverExtra size smaller than PSDRVEXTRAF ";
         goto LAB_1;
       }
-      uVar6 = *(short *)((longlong)puVar12 + 0x72) - (short)puVar12[0x1c];
-      if ((uVar6 != 0x2f4) && (uVar6 != 0x4f4)) goto LAB_2;
-      local_68 = 0x2c4;
-      *(short *)((longlong)puVar12 + 0x72) = (short)puVar12[0x1c] + 0x2f4;
-      local_res8[0] = uVar6;
-    }
-  }
-  uVar6 = local_res8[0];
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                          ::__l2::impl);
+      if ((bVar3) && (*(ushort *)((longlong)puVar10 + 0x72) < (ushort)puVar10[0x1c]))
+      goto LAB_2;
+      uVar12 = *(short *)((longlong)puVar10 + 0x72) - (short)puVar10[0x1c];
+      uVar7 = (ulonglong)uVar12;
+      local_res8[0] = uVar12;
+      wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                 &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                  ::__l2::impl);
+      if ((uVar12 - 0x2f4 & 0xfdff) != 0) goto LAB_4;
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                          ::__l2::impl);
+      if ((bVar3) && ((int)(0xffff - (uint)(ushort)puVar10[0x1c]) < 0x2f4)) goto LAB_5;
+      local_58 = 0x2c4;
+      *(short *)((longlong)puVar10 + 0x72) = (short)puVar10[0x1c] + 0x2f4;
+    }
+  }
+  uVar12 = (ushort)uVar7;
+  uVar15 = (ushort)puVar16;
+  puVar11 = puVar16;
   DevmodeSizePatchTelemetry::WriteDbgTraceInfo
             ("LVerifyAndCorrectDevMode",
-             (ushort *)L"Fix block actual size: %u  Fix block expected size: %u",
-             (ulonglong)local_res8[0],(ulonglong)uVar7);
-  param_1->dmDriverExtra = param_1->dmDriverExtra + (uVar7 - uVar6);
-  uVar3 = (uint)param_1->dmSize + (uint)param_1->dmDriverExtra;
-  _Dst = (_devicemodeW *)_o_malloc(uVar3);
+             (ushort *)L"Fix block actual size: %u  Fix block expected size: %u",uVar7);
+  bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                    ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                     &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                      ::__l2::impl);
+  if ((bVar3) && ((uVar2 = param_1->dmDriverExtra, uVar2 < uVar15 || (uVar2 < uVar12)))) {
+    DevmodeSizePatchTelemetry::WriteDbgTraceError
+              ("LVerifyAndCorrectDevMode",
+               (ushort *)
+               L"Invalid dmDriverExtra: %u is less than wFixBlockExpectedSize: %u or wFixBlockSize: %u"
+               ,(ulonglong)uVar2,puVar16,CONCAT44(uVar17,(int)uVar7));
+    return 0xd;
+  }
+  bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                    ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                     &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                      ::__l2::impl);
+  if ((bVar3) && (uVar15 < uVar12)) {
+    pwVar6 = L"Unexpected: wFixBlockExpectedSize < wFixBlockSize";
+    goto LAB_3;
+  }
+  param_1->dmDriverExtra = param_1->dmDriverExtra + (uVar15 - uVar12);
+  uVar13 = (uint)param_1->dmDriverExtra + (uint)param_1->dmSize;
+  _Dst = (_devicemodeW *)_o_malloc(uVar13);
   *local_res10 = _Dst;
   if (_Dst == (_devicemodeW *)0x0) {
     puVar8 = (ulong *)0x8;
-  }
-  else if (*local_res18 == 0) {
-    uVar4 = (ulonglong)(ushort)(uVar7 + param_1->dmSize + 0x200);
-    puVar10 = (ulong *)((longlong)param_1->dmDeviceName + uVar4);
-    if ((ulonglong)uVar5 < uVar4 + 0x10) {
-      puVar10 = puVar9;
-    }
-    if ((puVar10 == (ulong *)0x0) || (puVar10[1] != 0x4a544d53)) {
-      memcpy(_Dst,param_1,(ulonglong)uVar3);
-      this = "LVerifyAndCorrectDevMode";
-      if (uVar5 != uVar3) {
-        pwVar11 = L"Converted corrupted Devmode. The size was wrong";
-        DevmodeSizePatchTelemetry::WriteDbgTraceInfo
-                  ("LVerifyAndCorrectDevMode",
-                   (ushort *)L"Converted corrupted Devmode. The size was wrong");
-        if ((puVar12 != (ulong *)0x0) &&
-           (bVar2 = DevmodeSizePatchTelemetry::IsEnabled((uchar)this,(__uint64)pwVar11), bVar2)) {
-          wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
-                    ((static_lazy<DevmodeSizePatchTelemetry> *)this,
-                     <lambda_e670ca4b9feaa84b0d1a9de084fa3046>::<lambda_invoker_cdecl>);
-          DevmodeSizePatchTelemetry::FixDevmode_
-                    ((DevmodeSizePatchTelemetry *)this,local_res20,param_5,*puVar12,
-                     (ushort *)L"WrongSize",uVar6);
-        }
-        goto LAB_3;
-      }
-      DevmodeSizePatchTelemetry::WriteDbgTraceInfo
-                ("LVerifyAndCorrectDevMode",(ushort *)L"Devmode was already valid");
-      *local_res18 = 1;
-      if (puVar12 == (ulong *)0x0) goto LAB_3;
-      pwVar11 = L"Valid";
-    }
-    else {
-      uVar5 = (uint)uVar1 + local_68;
-      memcpy(_Dst,param_1,(ulonglong)uVar5);
-      memcpy((void *)((longlong)_Dst->dmDeviceName + (ulonglong)uVar5),
-             (void *)((longlong)param_1[2].dmFormName + ((ulonglong)uVar5 - 0x1e)),
-             (ulonglong)(uVar3 - uVar5));
-      DevmodeSizePatchTelemetry::WriteDbgTraceInfo
-                ("LVerifyAndCorrectDevMode",
-                 (ushort *)L"Converted corrupted Devmode. The JTExp was shifted");
-      puVar8 = puVar9;
-      if (puVar12 == (ulong *)0x0) goto LAB_3;
-      pwVar11 = L"JTExp";
-    }
-    DevmodeSizePatchTelemetry::
-    FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[6],unsigned_short&___ptr64>
-              (&local_res20,&param_5,puVar12,(ushort *)pwVar11,local_res8);
-    puVar8 = puVar9;
-  }
-  else {
-    memcpy(_Dst,param_1,(ulonglong)uVar3);
+    goto LAB_6;
+  }
+  if (*local_res18 != 0) {
+    memcpy(_Dst,param_1,(ulonglong)uVar13);
     DevmodeSizePatchTelemetry::WriteDbgTraceInfo
               ("LVerifyAndCorrectDevMode",(ushort *)L"Devmode was already valid");
     puVar8 = puVar9;
-  }
+    goto LAB_6;
+  }
+  bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                    ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                     &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                      ::__l2::impl);
+  uVar12 = param_1->dmSize;
+  if (bVar3) {
+    puVar5 = (ulong *)((longlong)puVar16 +
+                      (longlong)param_1[2].dmFormName + ((ulonglong)uVar12 - 0x1e));
+    if ((ulonglong)uVar4 < (longlong)puVar16 + (ulonglong)uVar12 + 0x210) {
+      puVar5 = puVar9;
+    }
+LAB_7:
+    if ((puVar5 == (ulong *)0x0) || (puVar5[1] != 0x4a544d53)) goto LAB_8;
+    uVar14 = (uint)uVar1 + local_58;
+    memcpy(*local_res10,param_1,(ulonglong)uVar14);
+    bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                        ::__l2::impl);
+    if (bVar3) {
+      if (uVar4 < uVar14 + 0x200 + (uVar13 - uVar14)) {
+        pwVar6 = L"Invalid source offset for second copy";
+        goto LAB_3;
+      }
+      _Src = (void *)((longlong)param_1->dmDeviceName + (ulonglong)(uVar14 + 0x200));
+    }
+    else {
+      _Src = (void *)((longlong)param_1[2].dmFormName + ((ulonglong)uVar14 - 0x1e));
+    }
+    memcpy((void *)((longlong)(*local_res10)->dmDeviceName + (ulonglong)uVar14),_Src,
+           (ulonglong)(uVar13 - uVar14));
+    DevmodeSizePatchTelemetry::WriteDbgTraceInfo
+              ("LVerifyAndCorrectDevMode",
+               (ushort *)L"Converted corrupted Devmode. The JTExp was shifted");
+    puVar8 = puVar9;
+    if (puVar10 == (ulong *)0x0) goto LAB_6;
+    pwVar6 = L"JTExp";
+  }
+  else {
+    uVar7 = (ulonglong)(ushort)(uVar12 + uVar15 + 0x200);
+    if (uVar7 + 0x10 <= (ulonglong)uVar4) {
+      puVar5 = (ulong *)((longlong)param_1->dmDeviceName + uVar7);
+      goto LAB_7;
+    }
+LAB_8:
+    bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_2040253753> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_2040253753>::GetImpl(void)'
+                        ::__l2::impl);
+    if ((bVar3) && (uVar4 < uVar13)) {
+      pwVar6 = L"New devmode size exceeds original";
 LAB_3:
+      DevmodeSizePatchTelemetry::WriteDbgTraceError("LVerifyAndCorrectDevMode",(ushort *)pwVar6);
+      return 0xd;
+    }
+    memcpy(*local_res10,param_1,(ulonglong)uVar13);
+    if (uVar4 != uVar13) {
+      DevmodeSizePatchTelemetry::WriteDbgTraceInfo
+                ("LVerifyAndCorrectDevMode",
+                 (ushort *)L"Converted corrupted Devmode. The size was wrong");
+      if (puVar10 != (ulong *)0x0) {
+        DevmodeSizePatchTelemetry::
+        FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[10],unsigned_short&___ptr64>
+                  (&local_res20,&param_5,puVar10,puVar11,local_res8);
+      }
+      goto LAB_6;
+    }
+    DevmodeSizePatchTelemetry::WriteDbgTraceInfo
+              ("LVerifyAndCorrectDevMode",(ushort *)L"Devmode was already valid");
+    *local_res18 = 1;
+    if (puVar10 == (ulong *)0x0) goto LAB_6;
+    pwVar6 = L"Valid";
+  }
+  DevmodeSizePatchTelemetry::
+  FixDevmode<unsigned_short_const*___ptr64&___ptr64,_DEVMODEHANDLETYPE&___ptr64,unsigned_long&___ptr64,unsigned_short_const_(&___ptr64)[6],unsigned_short&___ptr64>
+            (&local_res20,&param_5,puVar10,(ushort *)pwVar6,local_res8);
+  puVar8 = puVar9;
+LAB_6:
   return (long)puVar8;
 }
 

```


## PrvRouterRefreshPrinterChangeNotification

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.77|
|i_ratio|0.64|
|m_ratio|0.96|
|b_ratio|0.92|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|PrvRouterRefreshPrinterChangeNotification|PrvRouterRefreshPrinterChangeNotification|
|fullname|PrvRouterRefreshPrinterChangeNotification|PrvRouterRefreshPrinterChangeNotification|
|`refcount`|9|10|
|`length`|322|345|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>ClearPrinterNotifyInfo<br>_guard_dispatch_icall$thunk$10345483385596137414|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>ClearPrinterNotifyInfo<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>PrvRouterFindNextPrinterChangeNotification<br>RpcRouterRefreshPrinterChangeNotification|NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>PrvRouterFindNextPrinterChangeNotification<br>RpcRouterRefreshPrinterChangeNotification|
|paramcount|4|4|
|`address`|1400701e0|140070670|
|sig|int __fastcall PrvRouterRefreshPrinterChangeNotification(int * param_1, undefined4 param_2, undefined8 param_3, undefined8 param_4)|int __fastcall PrvRouterRefreshPrinterChangeNotification(int * param_1, undefined4 param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PrvRouterRefreshPrinterChangeNotification Called Diff


```diff
--- PrvRouterRefreshPrinterChangeNotification called
+++ PrvRouterRefreshPrinterChangeNotification called
@@ -5,0 +6 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### PrvRouterRefreshPrinterChangeNotification Diff


```diff
--- PrvRouterRefreshPrinterChangeNotification
+++ PrvRouterRefreshPrinterChangeNotification
@@ -1,50 +1,57 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 
 int PrvRouterRefreshPrinterChangeNotification
               (int *param_1,undefined4 param_2,undefined8 param_3,undefined8 param_4)
 
 {
   uint *puVar1;
   longlong lVar2;
-  int iVar3;
+  bool bVar3;
+  int iVar4;
   DWORD dwErrCode;
   
-                    /* 0x701e0  172  PrvRouterRefreshPrinterChangeNotification */
+                    /* 0x70670  172  PrvRouterRefreshPrinterChangeNotification */
   EnterCriticalSection(&RouterNotifySection);
   if ((((param_1 == (int *)0x0) || (*param_1 != 0x6060)) ||
       (lVar2 = *(longlong *)(param_1 + 6), lVar2 == 0)) || ((*(uint *)(lVar2 + 0xc) & 0x1002) == 0))
   {
     dwErrCode = 6;
   }
   else {
     if (*(longlong *)(*(longlong *)(param_1 + 2) + 0x1e0) != 0) {
       *(undefined4 *)(lVar2 + 0x10) = param_2;
       *(uint *)(*(longlong *)(param_1 + 6) + 0xc) =
            *(uint *)(*(longlong *)(param_1 + 6) + 0xc) & 0xfffe7fff;
       ClearPrinterNotifyInfo
                 (*(_PRINTER_NOTIFY_INFO **)(*(_CHANGE **)(param_1 + 6) + 0x50),
                  *(_CHANGE **)(param_1 + 6));
       LeaveCriticalSection(&RouterNotifySection);
-      iVar3 = (**(code **)(*(longlong *)(param_1 + 2) + 0x1e0))
-                        (*(undefined8 *)(param_1 + 4),
-                         *(undefined4 *)(*(longlong *)(param_1 + 6) + 0x10),param_3,param_4);
-      if (iVar3 != 0) {
-        return iVar3;
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                          ::__l2::impl);
+      if (!bVar3) {
+        param_2 = *(undefined4 *)(*(longlong *)(param_1 + 6) + 0x10);
+      }
+      iVar4 = (**(code **)(*(longlong *)(param_1 + 2) + 0x1e0))
+                        (*(undefined8 *)(param_1 + 4),param_2,param_3,param_4);
+      if (iVar4 != 0) {
+        return iVar4;
       }
       EnterCriticalSection(&RouterNotifySection);
       if (*(longlong *)(param_1 + 6) != 0) {
         puVar1 = (uint *)(*(longlong *)(param_1 + 6) + 0xc);
         *puVar1 = *puVar1 | 0x8000;
       }
       LeaveCriticalSection(&RouterNotifySection);
       return 0;
     }
     dwErrCode = 0x6d1;
   }
   SetLastError(dwErrCode);
   LeaveCriticalSection(&RouterNotifySection);
   return 0;
 }
 

```


## PrvClosePrinter

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.26|
|i_ratio|0.04|
|m_ratio|0.07|
|b_ratio|0.04|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|PrvClosePrinter|PrvClosePrinter|
|fullname|PrvClosePrinter|PrvClosePrinter|
|`refcount`|4|3|
|`length`|225|7|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>NCoreLibrary::TReferenceCount::Release<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>_guard_dispatch_icall$thunk$10345483385596137414|InternalClosePrinter|
|calling|||
|paramcount|1|1|
|`address`|14000d320|140004c40|
|sig|BOOL __stdcall PrvClosePrinter(HANDLE hPrinter)|BOOL __stdcall PrvClosePrinter(HANDLE hPrinter)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PrvClosePrinter Called Diff


```diff
--- PrvClosePrinter called
+++ PrvClosePrinter called
@@ -1,8 +1 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection
-FindClosePrinterChangeNotificationWorker
-FreePrinterHandle
-NCoreLibrary::TReferenceCount::Release
-PrvSpoolssTelemetry::WriteDbgTraceInfo
-_guard_dispatch_icall$thunk$10345483385596137414
+InternalClosePrinter
```


### PrvClosePrinter Diff


```diff
--- PrvClosePrinter
+++ PrvClosePrinter
@@ -1,37 +1,11 @@
-
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
 
 BOOL __stdcall PrvClosePrinter(HANDLE hPrinter)
 
 {
   int iVar1;
   
-                    /* 0xd320  67  PrvClosePrinter */
-  EnterCriticalSection(&RouterNotifySection);
-  if ((hPrinter == (HANDLE)0x0) || (*(int *)hPrinter != 0x6060)) {
-    LeaveCriticalSection(&RouterNotifySection);
-    SetLastError(6);
-  }
-  else {
-    if ((*(longlong *)((longlong)hPrinter + 0x18) != 0) &&
-       ((*(byte *)(*(longlong *)((longlong)hPrinter + 0x18) + 0xc) & 2) != 0)) {
-      FindClosePrinterChangeNotificationWorker(hPrinter,0);
-    }
-    LeaveCriticalSection(&RouterNotifySection);
-    if (*(longlong *)((longlong)hPrinter + 0x60) != 0) {
-      PrvSpoolssTelemetry::WriteDbgTraceInfo
-                ("InternalClosePrinter",(ushort *)L"Releasing PrinterPLM object");
-      NCoreLibrary::TReferenceCount::Release(*(TReferenceCount **)((longlong)hPrinter + 0x60));
-      *(undefined8 *)((longlong)hPrinter + 0x60) = 0;
-    }
-    iVar1 = (**(code **)(*(longlong *)((longlong)hPrinter + 8) + 0x118))
-                      (*(undefined8 *)((longlong)hPrinter + 0x10));
-    if (iVar1 != 0) {
-      FreePrinterHandle(hPrinter);
-      return 1;
-    }
-  }
-  return 0;
+                    /* 0x4c40  67  PrvClosePrinter */
+  iVar1 = InternalClosePrinter(hPrinter,0);
+  return iVar1;
 }
 

```


## TRemoteWinspool::RpcAsyncGetRemoteNotifications

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.38|
|i_ratio|0.0|
|m_ratio|0.08|
|b_ratio|0.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|RpcAsyncGetRemoteNotifications|RpcAsyncGetRemoteNotifications|
|fullname|TRemoteWinspool::RpcAsyncGetRemoteNotifications|TRemoteWinspool::RpcAsyncGetRemoteNotifications|
|`refcount`|1|2|
|`length`|5|87|
|`called`||GetLastErrorAsHResultAndFail<br>NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications<br>YImpersonateClient<br>YRevertToSelf|
|calling|||
|paramcount|3|3|
|`address`|140035280|140035070|
|sig|long __cdecl RpcAsyncGetRemoteNotifications(_RPC_ASYNC_STATE * param_1, void * param_2, __MIDL_winspool_0021 * * param_3)|long __cdecl RpcAsyncGetRemoteNotifications(_RPC_ASYNC_STATE * param_1, void * param_2, __MIDL_winspool_0021 * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### TRemoteWinspool::RpcAsyncGetRemoteNotifications Called Diff


```diff
--- TRemoteWinspool::RpcAsyncGetRemoteNotifications called
+++ TRemoteWinspool::RpcAsyncGetRemoteNotifications called
@@ -0,0 +1,4 @@
+GetLastErrorAsHResultAndFail
+NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications
+YImpersonateClient
+YRevertToSelf
```


### TRemoteWinspool::RpcAsyncGetRemoteNotifications Diff


```diff
--- TRemoteWinspool::RpcAsyncGetRemoteNotifications
+++ TRemoteWinspool::RpcAsyncGetRemoteNotifications
@@ -1,34 +1,21 @@
 
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
 /* public: static long __cdecl TRemoteWinspool::RpcAsyncGetRemoteNotifications(struct
    _RPC_ASYNC_STATE * __ptr64,void * __ptr64,struct __MIDL_winspool_0021 * __ptr64 * __ptr64) */
 
 long __cdecl
 TRemoteWinspool::RpcAsyncGetRemoteNotifications
           (_RPC_ASYNC_STATE *param_1,void *param_2,__MIDL_winspool_0021 **param_3)
 
 {
-  longlong *plVar1;
-  int iVar2;
-  long lVar3;
+  int iVar1;
+  long lVar2;
   
-  iVar2 = YImpersonateClient(1);
-  if (iVar2 == 0) {
+  iVar1 = YImpersonateClient(1);
+  if (iVar1 == 0) {
     GetLastErrorAsHResultAndFail();
   }
-  if (param_2 == (void *)0x0) {
-    lVar3 = -0x7ff8ffa9;
-  }
-  else if (*(int *)param_2 == 0x726d) {
-    plVar1 = *(longlong **)((longlong)param_2 + 8);
-    (**(code **)(*plVar1 + 8))(plVar1);
-    lVar3 = (**(code **)(*plVar1 + 0x18))(plVar1,param_1,param_3);
-  }
-  else {
-    lVar3 = -0x7ff8fffa;
-  }
+  lVar2 = NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications(param_1,param_2,param_3);
   YRevertToSelf(1);
-  return lVar3;
+  return lVar2;
 }
 

```


## IsCurrentUserLocalAdmin

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.58|
|i_ratio|0.51|
|m_ratio|0.72|
|b_ratio|0.72|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|IsCurrentUserLocalAdmin|IsCurrentUserLocalAdmin|
|fullname|IsCurrentUserLocalAdmin|IsCurrentUserLocalAdmin|
|refcount|2|2|
|`length`|422|241|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>McTemplateU0zqd_EtwEventWriteTransfer<br>NCoreLibrary::TReferenceCount::Release<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>RouterOpenPrinterW<br>_guard_dispatch_icall$thunk$10345483385596137414</summary></details>|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>InternalClosePrinter<br>McTemplateU0zqd_EtwEventWriteTransfer<br>RouterOpenPrinterW|
|calling|NRouter::TUserTokenTable::AddSession|NRouter::TUserTokenTable::AddSession|
|paramcount|1|1|
|`address`|140004f98|140005238|
|sig|ulong __cdecl IsCurrentUserLocalAdmin(int * param_1)|ulong __cdecl IsCurrentUserLocalAdmin(int * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### IsCurrentUserLocalAdmin Called Diff


```diff
--- IsCurrentUserLocalAdmin called
+++ IsCurrentUserLocalAdmin called
@@ -2,5 +2 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection
-FindClosePrinterChangeNotificationWorker
-FreePrinterHandle
+InternalClosePrinter
@@ -8,2 +3,0 @@
-NCoreLibrary::TReferenceCount::Release
-PrvSpoolssTelemetry::WriteDbgTraceInfo
@@ -11 +4,0 @@
-_guard_dispatch_icall$thunk$10345483385596137414
```


### IsCurrentUserLocalAdmin Diff


```diff
--- IsCurrentUserLocalAdmin
+++ IsCurrentUserLocalAdmin
@@ -1,75 +1,50 @@
 
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
 /* unsigned long __cdecl IsCurrentUserLocalAdmin(int * __ptr64) */
 
 ulong __cdecl IsCurrentUserLocalAdmin(int *param_1)
 
 {
-  _PRINTHANDLE *p_Var1;
-  int iVar2;
-  int *piVar3;
-  undefined8 uVar4;
-  _PRINTHANDLE *local_res8;
+  int iVar1;
+  int *piVar2;
+  undefined8 uVar3;
+  void *local_res8;
   _PRINTER_DEFAULTSW local_58;
   undefined8 local_40;
   undefined8 uStack_38;
   undefined8 local_30;
   undefined8 uStack_28;
   undefined8 local_20;
   undefined8 uStack_18;
   undefined8 local_10;
   
   local_58.DesiredAccess = 0xf0003;
   local_58._20_4_ = 0;
   local_58.pDatatype = (LPWSTR)0x0;
   local_58.pDevMode = (LPDEVMODEW)0x0;
-  local_res8 = (_PRINTHANDLE *)0x0;
+  local_res8 = (void *)0x0;
   *param_1 = 0;
   local_40 = 0;
   uStack_38 = 0;
   local_10 = 0;
   local_30 = 0;
   uStack_28 = 0;
   local_20 = 0;
   uStack_18 = 0;
   if ((Microsoft_Windows_DocumentsEnableBits & 2) != 0) {
-    piVar3 = param_1;
+    piVar2 = param_1;
     GetLastError();
-    McTemplateU0zqd_EtwEventWriteTransfer(piVar3,&DocPerf_OpenPrinter2_Start,(wchar_t *)0x0,0);
+    McTemplateU0zqd_EtwEventWriteTransfer(piVar2,&DocPerf_OpenPrinter2_Start,(wchar_t *)0x0,0);
   }
-  uVar4 = 0;
-  iVar2 = RouterOpenPrinterW((ushort *)0x0,&local_res8,&local_58,(uchar *)0x0,0,1);
+  uVar3 = 0;
+  iVar1 = RouterOpenPrinterW((ushort *)0x0,&local_res8,&local_58,(uchar *)0x0,0,1);
   if ((Microsoft_Windows_DocumentsEnableBits & 2) != 0) {
     GetLastError();
-    McTemplateU0zqd_EtwEventWriteTransfer(uVar4,&DocPerf_OpenPrinter2_Stop,(wchar_t *)0x0,0);
+    McTemplateU0zqd_EtwEventWriteTransfer(uVar3,&DocPerf_OpenPrinter2_Stop,(wchar_t *)0x0,0);
   }
-  if (iVar2 != 0) {
+  if (iVar1 != 0) {
     *param_1 = 1;
-    EnterCriticalSection(&RouterNotifySection);
-    p_Var1 = local_res8;
-    if ((local_res8 == (_PRINTHANDLE *)0x0) || (*(int *)local_res8 != 0x6060)) {
-      LeaveCriticalSection(&RouterNotifySection);
-      SetLastError(6);
-    }
-    else {
-      if ((*(longlong *)(local_res8 + 0x18) != 0) &&
-         ((*(byte *)(*(longlong *)(local_res8 + 0x18) + 0xc) & 2) != 0)) {
-        FindClosePrinterChangeNotificationWorker(local_res8,0);
-      }
-      LeaveCriticalSection(&RouterNotifySection);
-      if (*(longlong *)(p_Var1 + 0x60) != 0) {
-        PrvSpoolssTelemetry::WriteDbgTraceInfo
-                  ("InternalClosePrinter",(ushort *)L"Releasing PrinterPLM object");
-        NCoreLibrary::TReferenceCount::Release(*(TReferenceCount **)(p_Var1 + 0x60));
-        *(undefined8 *)(p_Var1 + 0x60) = 0;
-      }
-      iVar2 = (**(code **)(*(longlong *)(p_Var1 + 8) + 0x118))(*(undefined8 *)(p_Var1 + 0x10));
-      if (iVar2 != 0) {
-        FreePrinterHandle(p_Var1);
-      }
-    }
+    InternalClosePrinter(local_res8,0);
   }
   return 0;
 }
 

```


## InternalClosePrinter

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,refcount,length,address,calling,called|
|ratio|0.68|
|i_ratio|0.45|
|m_ratio|0.79|
|b_ratio|0.76|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|InternalClosePrinter|InternalClosePrinter|
|fullname|InternalClosePrinter|InternalClosePrinter|
|`refcount`|10|13|
|`length`|226|347|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>NCoreLibrary::TReferenceCount::Release<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>_guard_dispatch_icall$thunk$10345483385596137414|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>NCoreLibrary::TReferenceCount::Release<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|`calling`|ChoosePotentialDefaultPrinters<br>InternalAddPrinterConnection2<br>InternalDeletePrinterConnection<br>InternalInstallPrinterDriverPackageFromConnection<br>IsRedirectedPrinter<br>PrvPrinterHandleRundown<br>bGetDevModePerUserEvenForShares<br>sandbox::SandboxManagerUtil::GetDriverInfoHelper|<details><summary>Expand for full list:<br>ChoosePotentialDefaultPrinters<br>InternalAddPrinterConnection2<br>InternalDeletePrinterConnection<br>InternalInstallPrinterDriverPackageFromConnection<br>IsCurrentUserLocalAdmin<br>IsRedirectedPrinter<br>PrvClosePrinter<br>PrvPrinterHandleRundown<br>YClosePrinter<br>bGetDevModePerUserEvenForShares<br>sandbox::SandboxManagerUtil::GetDriverInfoHelper</summary></details>|
|paramcount|2|2|
|`address`|1400124b8|140004c50|
|sig|int __cdecl InternalClosePrinter(void * param_1, int param_2)|int __cdecl InternalClosePrinter(void * param_1, int param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### InternalClosePrinter Called Diff


```diff
--- InternalClosePrinter called
+++ InternalClosePrinter called
@@ -3,0 +4 @@
+API-MS-WIN-CORE-SYNCH-L1-2-0.DLL::SleepConditionVariableCS
@@ -8,0 +10 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### InternalClosePrinter Calling Diff


```diff
--- InternalClosePrinter calling
+++ InternalClosePrinter calling
@@ -4,0 +5 @@
+IsCurrentUserLocalAdmin
@@ -5,0 +7 @@
+PrvClosePrinter
@@ -6,0 +9 @@
+YClosePrinter
```


### InternalClosePrinter Diff


```diff
--- InternalClosePrinter
+++ InternalClosePrinter
@@ -1,37 +1,57 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* int __cdecl InternalClosePrinter(void * __ptr64,int) */
 
 int __cdecl InternalClosePrinter(void *param_1,int param_2)
 
 {
-  int iVar1;
+  bool bVar1;
+  int iVar2;
   
   EnterCriticalSection(&RouterNotifySection);
   if ((param_1 == (void *)0x0) || (*(int *)param_1 != 0x6060)) {
     LeaveCriticalSection(&RouterNotifySection);
     SetLastError(6);
   }
   else {
+    bVar1 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                        ::__l2::impl);
+    if (bVar1) {
+      *(undefined4 *)((longlong)param_1 + 0x6c) = 1;
+      while (*(int *)((longlong)param_1 + 0x68) != 0) {
+        SleepConditionVariableCS(&RemoteRefreshDrainCV,&RouterNotifySection,0xffffffff);
+      }
+    }
     if ((*(longlong *)((longlong)param_1 + 0x18) != 0) &&
        ((*(byte *)(*(longlong *)((longlong)param_1 + 0x18) + 0xc) & 2) != 0)) {
       FindClosePrinterChangeNotificationWorker(param_1,param_2);
     }
     LeaveCriticalSection(&RouterNotifySection);
     if (*(longlong *)((longlong)param_1 + 0x60) != 0) {
       PrvSpoolssTelemetry::WriteDbgTraceInfo
                 ("InternalClosePrinter",(ushort *)L"Releasing PrinterPLM object");
       NCoreLibrary::TReferenceCount::Release(*(TReferenceCount **)((longlong)param_1 + 0x60));
       *(undefined8 *)((longlong)param_1 + 0x60) = 0;
     }
-    iVar1 = (**(code **)(*(longlong *)((longlong)param_1 + 8) + 0x118))
+    iVar2 = (**(code **)(*(longlong *)((longlong)param_1 + 8) + 0x118))
                       (*(undefined8 *)((longlong)param_1 + 0x10));
-    if (iVar1 != 0) {
+    if (iVar2 != 0) {
       FreePrinterHandle(param_1);
       return 1;
+    }
+    bVar1 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                        ::__l2::impl);
+    if (bVar1) {
+      EnterCriticalSection(&RouterNotifySection);
+      *(undefined4 *)((longlong)param_1 + 0x6c) = 0;
+      LeaveCriticalSection(&RouterNotifySection);
     }
   }
   return 0;
 }
 

```


## FreeChange

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.62|
|i_ratio|0.41|
|m_ratio|0.9|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|FreeChange|FreeChange|
|fullname|FreeChange|FreeChange|
|refcount|7|7|
|`length`|423|490|
|`called`|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>LinkDelete<br>NCoreLibrary::EasyRelease<br>PrvDllFreeSplStr<br>PrvRouterFreePrinterNotifyInfo<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>_guard_dispatch_icall$thunk$10345483385596137414|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>LinkDelete<br>NCoreLibrary::EasyRelease<br>PrvDllFreeSplStr<br>PrvRouterFreePrinterNotifyInfo<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|FailChange<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>ReplyPrinterChangeNotificationWorker<br>SetupChange<br>ThreadNotifyProcessJob|FailChange<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>ReplyPrinterChangeNotificationWorker<br>SetupChange<br>ThreadNotifyProcessJob|
|paramcount|1|1|
|`address`|14006dbf4|14006e004|
|sig|int __cdecl FreeChange(_CHANGE * * param_1)|int __cdecl FreeChange(_CHANGE * * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### FreeChange Called Diff


```diff
--- FreeChange called
+++ FreeChange called
@@ -9,0 +10 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### FreeChange Diff


```diff
--- FreeChange
+++ FreeChange
@@ -1,63 +1,80 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* int __cdecl FreeChange(struct _CHANGE * __ptr64 * __ptr64) */
 
 int __cdecl FreeChange(_CHANGE **param_1)
 
 {
+  _CHANGE *p_Var1;
   _CHANGE *lpMem;
-  ushort **ppuVar1;
-  undefined8 uVar2;
-  code *pcVar3;
+  ushort **ppuVar2;
+  bool bVar3;
+  code *pcVar4;
+  undefined8 uVar5;
   undefined4 local_res8 [2];
   
   if ((param_1 != (_CHANGE **)0x0) && (lpMem = *param_1, lpMem != (_CHANGE *)0x0)) {
-    uVar2 = 0;
-    pcVar3 = (code *)0x0;
+    pcVar4 = (code *)0x0;
+    uVar5 = 0;
     *param_1 = (_CHANGE *)0x0;
     if (((byte)lpMem[0x38] & 2) != 0) {
       LinkDelete((_LINK *)(lpMem + 0x20),(_LINK **)&pChangeInfoHead);
     }
     if (*(longlong *)(lpMem + 0x28) != 0) {
       *(undefined8 *)(*(longlong *)(lpMem + 0x28) + 0x18) = 0;
       *(undefined8 *)(lpMem + 0x28) = 0;
     }
+    bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                      ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                       &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                        ::__l2::impl);
+    p_Var1 = lpMem + 0x80;
+    if (((bVar3) && (((byte)*p_Var1 & 8) != 0)) && (*(longlong **)(lpMem + 0x98) != (longlong *)0x0)
+       ) {
+      (**(code **)(**(longlong **)(lpMem + 0x98) + 0x38))();
+    }
     if ((*(int *)(lpMem + 0x14) != 0) || (((byte)lpMem[0xc] & 1) != 0)) {
       *(uint *)(lpMem + 0xc) = *(uint *)(lpMem + 0xc) | 0x100;
       PrvSpoolssTelemetry::WriteDbgTraceInfo
                 ("FreeChange",(ushort *)L"Change 0x%p in use, cRef %d.",lpMem);
       return 0;
     }
-    if (((byte)lpMem[0x80] & 8) != 0) {
-      (**(code **)(**(longlong **)(lpMem + 0x98) + 0x38))();
+    if (((byte)*p_Var1 & 8) != 0) {
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                          ::__l2::impl);
+      if (!bVar3) {
+        (**(code **)(**(longlong **)(lpMem + 0x98) + 0x38))();
+      }
       NCoreLibrary::EasyRelease(*(IUnknown **)(lpMem + 0x98));
       *(undefined8 *)(lpMem + 0x98) = 0;
     }
-    ppuVar1 = *(ushort ***)(lpMem + 0x18);
-    if (((ppuVar1 != (ushort **)0x0) && (ppuVar1 != &szMachineName)) &&
-       (ppuVar1 != &szMachineFullDNSName)) {
-      PrvDllFreeSplStr(ppuVar1);
+    ppuVar2 = *(ushort ***)(lpMem + 0x18);
+    if (((ppuVar2 != (ushort **)0x0) && (ppuVar2 != &szMachineName)) &&
+       (ppuVar2 != &szMachineFullDNSName)) {
+      PrvDllFreeSplStr(ppuVar2);
     }
     if (*(_PRINTER_NOTIFY_INFO **)(lpMem + 0x50) != (_PRINTER_NOTIFY_INFO *)0x0) {
       PrvRouterFreePrinterNotifyInfo(*(_PRINTER_NOTIFY_INFO **)(lpMem + 0x50));
       *(undefined8 *)(lpMem + 0x50) = 0;
     }
     PrvSpoolssTelemetry::WriteDbgTraceInfo
               ("FreeChange",(ushort *)L"Change 0x%p -> pPrintHandle 0x%p.",lpMem,
                *(undefined8 *)(lpMem + 0x28));
-    if (((byte)lpMem[0x80] & 2) != 0) {
-      pcVar3 = *(code **)(lpMem + 0x88);
-      uVar2 = *(undefined8 *)(lpMem + 0x90);
+    if (((byte)*p_Var1 & 2) != 0) {
+      pcVar4 = *(code **)(lpMem + 0x88);
+      uVar5 = *(undefined8 *)(lpMem + 0x90);
     }
     HeapFree(g_hSpoolssHeap,0,lpMem);
-    if (pcVar3 != (code *)0x0) {
+    if (pcVar4 != (code *)0x0) {
       LeaveCriticalSection(&RouterNotifySection);
       local_res8[0] = 0;
-      (*pcVar3)(2,uVar2,0,0,0,local_res8);
+      (*pcVar4)(2,uVar5,0,0,0,local_res8);
       EnterCriticalSection(&RouterNotifySection);
     }
   }
   return 1;
 }
 

```


## YClosePrinter

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.21|
|i_ratio|0.34|
|m_ratio|0.7|
|b_ratio|0.67|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|YClosePrinter|YClosePrinter|
|fullname|YClosePrinter|YClosePrinter|
|refcount|6|6|
|`length`|401|200|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>FindClosePrinterChangeNotificationWorker<br>FreePrinterHandle<br>NCoreLibrary::TReferenceCount::Release<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>RPCRT4.DLL::RpcImpersonateClient<br>RPCRT4.DLL::RpcRevertToSelf<br>SpoolerServiceTelemetry::WriteDbgTraceError</summary>_guard_dispatch_icall$thunk$10345483385596137414</details>|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>InternalClosePrinter<br>RPCRT4.DLL::RpcImpersonateClient<br>RPCRT4.DLL::RpcRevertToSelf<br>SpoolerServiceTelemetry::WriteDbgTraceError|
|calling|||
|paramcount|2|2|
|`address`|140010330|140004b70|
|sig|ulong __cdecl YClosePrinter(void * * param_1, Call_Route param_2)|ulong __cdecl YClosePrinter(void * * param_1, Call_Route param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### YClosePrinter Called Diff


```diff
--- YClosePrinter called
+++ YClosePrinter called
@@ -3,6 +3 @@
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection
-FindClosePrinterChangeNotificationWorker
-FreePrinterHandle
-NCoreLibrary::TReferenceCount::Release
-PrvSpoolssTelemetry::WriteDbgTraceInfo
+InternalClosePrinter
@@ -12 +6,0 @@
-_guard_dispatch_icall$thunk$10345483385596137414
```


### YClosePrinter Diff


```diff
--- YClosePrinter
+++ YClosePrinter
@@ -1,62 +1,34 @@
 
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
 /* unsigned long __cdecl YClosePrinter(void * __ptr64 * __ptr64,enum Call_Route) */
 
 ulong __cdecl YClosePrinter(void **param_1,Call_Route param_2)
 
 {
-  _PRINTHANDLE *p_Var1;
-  bool bVar2;
-  DWORD DVar3;
-  int iVar4;
+  DWORD DVar1;
+  int iVar2;
   
-  if ((param_2 == 1) && (DVar3 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0), DVar3 != 0)) {
-    SetLastError(DVar3);
-    goto LAB_0;
-  }
-  p_Var1 = *param_1;
-  EnterCriticalSection(&RouterNotifySection);
-  if ((p_Var1 == (_PRINTHANDLE *)0x0) || (*(int *)p_Var1 != 0x6060)) {
-    LeaveCriticalSection(&RouterNotifySection);
-    SetLastError(6);
-LAB_1:
-    bVar2 = false;
+  if ((param_2 == 1) && (DVar1 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0), DVar1 != 0)) {
+    SetLastError(DVar1);
   }
   else {
-    if ((*(longlong *)(p_Var1 + 0x18) != 0) &&
-       ((*(byte *)(*(longlong *)(p_Var1 + 0x18) + 0xc) & 2) != 0)) {
-      FindClosePrinterChangeNotificationWorker(p_Var1,0);
+    iVar2 = InternalClosePrinter(*param_1,0);
+    if (param_2 == 1) {
+      DVar1 = GetLastError();
+      RpcRevertToSelf();
+      SetLastError(DVar1);
     }
-    LeaveCriticalSection(&RouterNotifySection);
-    if (*(longlong *)(p_Var1 + 0x60) != 0) {
-      PrvSpoolssTelemetry::WriteDbgTraceInfo
-                ("InternalClosePrinter",(ushort *)L"Releasing PrinterPLM object");
-      NCoreLibrary::TReferenceCount::Release(*(TReferenceCount **)(p_Var1 + 0x60));
-      *(undefined8 *)(p_Var1 + 0x60) = 0;
+    *param_1 = (void *)0x0;
+    if (iVar2 != 0) {
+      LOCK();
+      ServerHandleCount = ServerHandleCount + -1;
+      UNLOCK();
+      return 0;
     }
-    iVar4 = (**(code **)(*(longlong *)(p_Var1 + 8) + 0x118))(*(undefined8 *)(p_Var1 + 0x10));
-    if (iVar4 == 0) goto LAB_1;
-    FreePrinterHandle(p_Var1);
-    bVar2 = true;
+    DVar1 = GetLastError();
+    SpoolerServiceTelemetry::WriteDbgTraceError
+              ("YClosePrinter",(ushort *)L"Failed. Error %d",(ulonglong)DVar1);
   }
-  if (param_2 == 1) {
-    DVar3 = GetLastError();
-    RpcRevertToSelf();
-    SetLastError(DVar3);
-  }
-  *param_1 = (void *)0x0;
-  if (bVar2) {
-    LOCK();
-    ServerHandleCount = ServerHandleCount + -1;
-    UNLOCK();
-    return 0;
-  }
-  DVar3 = GetLastError();
-  SpoolerServiceTelemetry::WriteDbgTraceError
-            ("YClosePrinter",(ushort *)L"Failed. Error %d",(ulonglong)DVar3);
-LAB_0:
-  DVar3 = GetLastError();
-  return DVar3;
+  DVar1 = GetLastError();
+  return DVar1;
 }
 

```


## PrvSpoolssInit

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.93|
|i_ratio|0.65|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|PrvSpoolssInit|PrvSpoolssInit|
|fullname|PrvSpoolssInit|PrvSpoolssInit|
|refcount|2|2|
|`length`|518|468|
|`called`|<details><summary>Expand for full list:<br>ADVAPI32.DLL::AllocateAndInitializeSid<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapCreate<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapSetInformation<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::DisableThreadLibraryCalls<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::TlsAlloc<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateEventW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount<br>API-MS-WIN-SECURITY-SDDL-L1-1-0.DLL::ConvertStringSidToSidW<br>InitializeSessionInfo<br>NCoreLibrary::CreateAutoEventHandle</summary>PrvSpoolssCleanup<br>ThreadInit<br>__security_check_cookie</details>|<details><summary>Expand for full list:<br>ADVAPI32.DLL::AllocateAndInitializeSid<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapCreate<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapSetInformation<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::DisableThreadLibraryCalls<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::TlsAlloc<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount<br>API-MS-WIN-SECURITY-SDDL-L1-1-0.DLL::ConvertStringSidToSidW<br>InitializeSessionInfo<br>NCoreLibrary::CreateAutoEventHandle<br>PrvSpoolssCleanup<br>ThreadInit</summary>WPCInit<br>__security_check_cookie</details>|
|calling|SPOOLER_main|SPOOLER_main|
|paramcount|1|1|
|`address`|14006ea28|14006eee8|
|sig|int __cdecl PrvSpoolssInit(HINSTANCE__ * param_1)|int __cdecl PrvSpoolssInit(HINSTANCE__ * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### PrvSpoolssInit Called Diff


```diff
--- PrvSpoolssInit called
+++ PrvSpoolssInit called
@@ -6,2 +5,0 @@
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateEventW
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSection
@@ -13,0 +12 @@
+WPCInit
```


### PrvSpoolssInit Diff


```diff
--- PrvSpoolssInit
+++ PrvSpoolssInit
@@ -1,74 +1,74 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* int __cdecl PrvSpoolssInit(struct HINSTANCE__ * __ptr64) */
 
 int __cdecl PrvSpoolssInit(HINSTANCE__ *param_1)
 
 {
   BOOL BVar1;
   int iVar2;
   long lVar3;
   ulonglong uVar4;
   undefined8 uVar5;
   TAutoHandle **ppTVar6;
   uint uVar7;
   undefined1 auStackY_78 [32];
   _SID_IDENTIFIER_AUTHORITY local_18;
   ulonglong local_10;
   
   local_10 = __security_cookie ^ (ulonglong)auStackY_78;
   g_hSpoolssHeap = HeapCreate(0,0,0);
   if (g_hSpoolssHeap != (HANDLE)0x0) {
     local_18.Value[0] = '\x02';
     local_18.Value[1] = '\0';
     local_18.Value[2] = '\0';
     local_18.Value[3] = '\0';
     HeapSetInformation(g_hSpoolssHeap,HeapCompatibilityInformation,&local_18,4);
     DisableThreadLibraryCalls(param_1);
     local_18.Value[0] = '\0';
     local_18.Value[1] = '\0';
     local_18.Value[2] = '\0';
     local_18.Value[3] = '\0';
     local_18.Value[4] = '\0';
     local_18.Value[5] = '\x0f';
     BVar1 = AllocateAndInitializeSid(&local_18,'\x02',2,1,0,0,0,0,0,0,&g_pAppContainerSid);
     uVar7 = (uint)(BVar1 != 0);
     iVar2 = ConvertStringSidToSidW
                       (L"S-1-15-3-1024-4044835139-2658482041-3127973164-329287231-3865880861-1938685643-461067658-1087000422"
                        ,&g_pLPACCapabilitySid);
     if (iVar2 != 0) {
       if (BVar1 == 0) goto LAB_0;
       BVar1 = InitializeCriticalSectionAndSpinCount(&RouterCriticalSection,0x80000000);
       uVar7 = 0;
       if (BVar1 == 0) goto LAB_0;
       DAT_1 = 1;
       BVar1 = InitializeCriticalSectionAndSpinCount(&DeviceArrivalCS,0x80000000);
       uVar7 = 0;
       if (BVar1 == 0) goto LAB_0;
       ppTVar6 = &pEventInit;
       DAT_2 = 1;
       uVar5 = 1;
       lVar3 = NCoreLibrary::CreateAutoEventHandle(1,&pEventInit);
-      if (((-1 < lVar3) &&
-          (uVar4 = InitializeSessionInfo(uVar5,(TUserTokenTable *)ppTVar6), -1 < (int)uVar4)) &&
-         (hEventPoll = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,0,0,(LPCWSTR)0x0),
-         hEventPoll != (HANDLE)0x0)) {
-        InitializeCriticalSection(&RouterNotifySection);
+      if ((-1 < lVar3) &&
+         (uVar4 = InitializeSessionInfo(uVar5,(TUserTokenTable *)ppTVar6), -1 < (int)uVar4)) {
+        iVar2 = WPCInit();
+        uVar7 = 0;
+        if (iVar2 == 0) goto LAB_0;
         DAT_3 = 1;
         iVar2 = ThreadInit();
         uVar7 = 0;
         if (iVar2 == 0) goto LAB_0;
         DAT_4 = 1;
         gdwTlsGetPrinterIndex = TlsAlloc();
         if (gdwTlsGetPrinterIndex != 0xffffffff) {
           return iVar2;
         }
       }
     }
   }
   uVar7 = 0;
 LAB_0:
   PrvSpoolssCleanup();
   return uVar7;
 }
 

```


## NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.26|
|i_ratio|0.24|
|m_ratio|0.97|
|b_ratio|0.8|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|RegisterForNotifications|RegisterForNotifications|
|fullname|NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications|NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications|
|refcount|2|2|
|`length`|365|387|
|`called`|NCoreLibrary::GetLastErrorAsHResult<br>NRemoteNotify_Library::DecodeRemoteNotifyFilter<br>NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>PrvRemoteFindFirstPrinterChangeNotification<br>_guard_dispatch_icall$thunk$10345483385596137414<br>operator_new|NCoreLibrary::GetLastErrorAsHResult<br>NCoreLibrary::TCriticalSection::Enter<br>NCoreLibrary::TCriticalSection::Leave<br>NRemoteNotify_Library::DecodeRemoteNotifyFilter<br>NRemoteNotify_Router::CreateRemoteNotifyChannel<br>PrvRemoteFindFirstPrinterChangeNotification<br>_guard_dispatch_icall$thunk$10345483385596137414<br>operator_new<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|TRemoteWinspool::RpcSyncRegisterForRemoteNotifications|TRemoteWinspool::RpcSyncRegisterForRemoteNotifications|
|paramcount|3|3|
|`address`|140048d30|140048fdc|
|sig|long __cdecl RegisterForNotifications(void * param_1, __MIDL_winspool_0021 * param_2, void * * param_3)|long __cdecl RegisterForNotifications(void * param_1, __MIDL_winspool_0021 * param_2, void * * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications Called Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications called
+++ NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications called
@@ -1,0 +2,2 @@
+NCoreLibrary::TCriticalSection::Enter
+NCoreLibrary::TCriticalSection::Leave
@@ -3 +5 @@
-NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel
+NRemoteNotify_Router::CreateRemoteNotifyChannel
@@ -6,0 +9 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications
+++ NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications
@@ -1,69 +1,74 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* public: static long __cdecl
    NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications(void * __ptr64,struct
    __MIDL_winspool_0021 * __ptr64,void * __ptr64 * __ptr64) */
 
 long __cdecl
 NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications
           (void *param_1,__MIDL_winspool_0021 *param_2,void **param_3)
 
 {
-  int iVar1;
-  TRemoteNotifyChannel *this;
-  IRemoteNotifyChannel *pIVar2;
-  ushort *puVar3;
-  undefined4 *puVar4;
-  ulong local_res10 [2];
+  TRemoteNotifyChannel *pTVar1;
+  bool bVar2;
+  long lVar3;
+  ushort *puVar4;
+  TRemoteNotifyHandle *pTVar5;
+  TRemoteNotifyChannel *local_res10 [2];
   ulong local_res20 [2];
-  _RPC_V2_NOTIFY_OPTIONS *local_28 [2];
+  _RPC_V2_NOTIFY_OPTIONS *local_38 [2];
   
-  if ((param_2 == (__MIDL_winspool_0021 *)0x0) || (param_3 == (void **)0x0)) {
-    iVar1 = -0x7ff8ffa9;
-  }
-  else {
+  if ((param_2 != (__MIDL_winspool_0021 *)0x0) && (param_3 != (void **)0x0)) {
+    local_res10[0] = (TRemoteNotifyChannel *)0x0;
     *param_3 = (void *)0x0;
-    this = operator_new(0xa0);
-    if ((this == (TRemoteNotifyChannel *)0x0) ||
-       (pIVar2 = (IRemoteNotifyChannel *)
-                 NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel(this,param_1),
-       pIVar2 == (IRemoteNotifyChannel *)0x0)) {
-      iVar1 = -0x7ff8fff2;
-    }
-    else {
-      iVar1 = *(int *)(pIVar2 + 8);
-      if (-1 < iVar1) {
-        local_res20[0] = 0;
-        local_res10[0] = 0;
-        local_28[0] = (_RPC_V2_NOTIFY_OPTIONS *)0x0;
-        iVar1 = NRemoteNotify_Library::DecodeRemoteNotifyFilter
-                          (param_2,local_res20,local_res10,(ulong *)0x0,local_28);
-        if ((-1 < iVar1) &&
-           ((puVar3 = PrvRemoteFindFirstPrinterChangeNotification
-                                (param_1,local_res20[0],local_res10[0],(void *)0x0,0,
-                                 (_PRINTER_NOTIFY_OPTIONS *)local_28[0],pIVar2), (int)puVar3 != 0 ||
-            (iVar1 = NCoreLibrary::GetLastErrorAsHResult(), -1 < iVar1)))) {
-          puVar4 = operator_new(0x18);
-          if (puVar4 == (undefined4 *)0x0) {
-            iVar1 = -0x7ff8fff2;
+    lVar3 = NRemoteNotify_Router::CreateRemoteNotifyChannel(param_1,local_res10);
+    pTVar1 = local_res10[0];
+    if (-1 < lVar3) {
+      local_res20[0] = 0;
+      local_res10[0] = (TRemoteNotifyChannel *)((ulonglong)local_res10[0] & 0xffffffff00000000);
+      local_38[0] = (_RPC_V2_NOTIFY_OPTIONS *)0x0;
+      lVar3 = NRemoteNotify_Library::DecodeRemoteNotifyFilter
+                        (param_2,local_res20,(ulong *)local_res10,(ulong *)0x0,local_38);
+      if (-1 < lVar3) {
+        puVar4 = PrvRemoteFindFirstPrinterChangeNotification
+                           (param_1,local_res20[0],(ulong)local_res10[0],(void *)0x0,0,
+                            (_PRINTER_NOTIFY_OPTIONS *)local_38[0],(IRemoteNotifyChannel *)pTVar1);
+        if (((int)puVar4 != 0) || (lVar3 = NCoreLibrary::GetLastErrorAsHResult(), -1 < lVar3)) {
+          pTVar5 = operator_new(0x20);
+          if (pTVar5 == (TRemoteNotifyHandle *)0x0) {
+            lVar3 = -0x7ff8fff2;
           }
           else {
-            *puVar4 = 0x726d;
-            *(IRemoteNotifyChannel **)(puVar4 + 2) = pIVar2;
-            puVar4[4] = 1;
-            (**(code **)(*(longlong *)pIVar2 + 8))(pIVar2);
-            iVar1 = 0;
-            *param_3 = puVar4;
+            *(undefined4 *)pTVar5 = 0x726d;
+            *(TRemoteNotifyChannel **)(pTVar5 + 8) = pTVar1;
+            *(undefined4 *)(pTVar5 + 0x10) = 1;
+            *(undefined8 *)(pTVar5 + 0x18) = 0;
+            (**(code **)(*(longlong *)pTVar1 + 8))(pTVar1);
+            lVar3 = 0;
+            bVar2 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::
+                    __private_IsEnabled((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                                        &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                                         ::__l2::impl);
+            if (bVar2) {
+              NCoreLibrary::TCriticalSection::Enter(&TRemoteNotifyHandle::s_NotifyListLock);
+              *(TRemoteNotifyHandle **)(pTVar5 + 0x18) = TRemoteNotifyHandle::s_pNotifyListHead;
+              TRemoteNotifyHandle::s_pNotifyListHead = pTVar5;
+              NCoreLibrary::TCriticalSection::Leave(&TRemoteNotifyHandle::s_NotifyListLock);
+            }
+            *param_3 = pTVar5;
             LOCK();
             g_TotalAsyncRegistrations = g_TotalAsyncRegistrations + 1;
             UNLOCK();
           }
         }
-        (**(code **)(*(longlong *)pIVar2 + 0x10))();
       }
     }
+    if (pTVar1 != (TRemoteNotifyChannel *)0x0) {
+      (**(code **)(*(longlong *)pTVar1 + 0x10))(pTVar1);
+    }
+    return lVar3;
   }
-  return iVar1;
+  return -0x7ff8ffa9;
 }
 

```


## PrvRouterFindNextPrinterChangeNotification

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.47|
|i_ratio|0.2|
|m_ratio|0.97|
|b_ratio|0.36|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|PrvRouterFindNextPrinterChangeNotification|PrvRouterFindNextPrinterChangeNotification|
|fullname|PrvRouterFindNextPrinterChangeNotification|PrvRouterFindNextPrinterChangeNotification|
|refcount|6|6|
|`length`|455|481|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ResetEvent<br>PrvRouterAllocPrinterNotifyInfo<br>PrvRouterRefreshPrinterChangeNotification<br>PrvSpoolssTelemetry::WriteDbgTraceInfo|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ResetEvent<br>NotifyNeeded<br>PrvDllAllocSplMem<br>PrvRouterRefreshPrinterChangeNotification<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|PrvSpoolerFindNextPrinterChangeNotification<br>RpcFindNextPrinterChangeNotification|PrvSpoolerFindNextPrinterChangeNotification<br>RpcFindNextPrinterChangeNotification|
|paramcount|5|5|
|`address`|14000dc10|140014410|
|sig|int __fastcall PrvRouterFindNextPrinterChangeNotification(int * param_1, ulonglong param_2, undefined4 * param_3, longlong param_4, longlong * param_5)|int __fastcall PrvRouterFindNextPrinterChangeNotification(int * param_1, ulonglong param_2, undefined4 * param_3, longlong param_4, longlong * param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PrvRouterFindNextPrinterChangeNotification Called Diff


```diff
--- PrvRouterFindNextPrinterChangeNotification called
+++ PrvRouterFindNextPrinterChangeNotification called
@@ -5 +5,2 @@
-PrvRouterAllocPrinterNotifyInfo
+NotifyNeeded
+PrvDllAllocSplMem
@@ -7,0 +9 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### PrvRouterFindNextPrinterChangeNotification Diff


```diff
--- PrvRouterFindNextPrinterChangeNotification
+++ PrvRouterFindNextPrinterChangeNotification
@@ -1,65 +1,77 @@
 
 int PrvRouterFindNextPrinterChangeNotification
               (int *param_1,ulonglong param_2,undefined4 *param_3,longlong param_4,longlong *param_5
               )
 
 {
-  longlong lVar1;
-  longlong lVar2;
+  _CHANGE *p_Var1;
+  bool bVar2;
   int iVar3;
-  _PRINTER_NOTIFY_INFO *p_Var4;
+  int iVar4;
+  undefined4 *puVar5;
+  size_t size;
+  undefined4 uVar6;
   
-                    /* 0xdc10  166  PrvRouterFindNextPrinterChangeNotification */
+                    /* 0x14410  166  PrvRouterFindNextPrinterChangeNotification */
   iVar3 = 0;
-  lVar1 = *(longlong *)(param_1 + 6);
+  p_Var1 = *(_CHANGE **)(param_1 + 6);
   if (param_5 != (longlong *)0x0) {
     *param_5 = 0;
   }
   if ((param_4 != 0) && ((*(uint *)(param_4 + 4) & 0xfffffffe) != 0)) {
     SetLastError(0x57);
     return 0;
   }
   EnterCriticalSection(&RouterNotifySection);
-  if (((*param_1 == 0x6060) && (lVar1 != 0)) && ((*(uint *)(lVar1 + 0xc) & 0x202) != 0)) {
-    *(undefined4 *)(lVar1 + 0x58) = 0;
-    *param_3 = *(undefined4 *)(lVar1 + 0x6c);
-    *(undefined4 *)(lVar1 + 0x6c) = 0;
-    if ((*(byte *)(lVar1 + 0x80) & 1) != 0) {
-      ResetEvent(*(HANDLE *)(lVar1 + 0x60));
+  if (((*param_1 == 0x6060) && (p_Var1 != (_CHANGE *)0x0)) &&
+     ((*(uint *)(p_Var1 + 0xc) & 0x202) != 0)) {
+    *(undefined4 *)(p_Var1 + 0x58) = 0;
+    *param_3 = *(undefined4 *)(p_Var1 + 0x6c);
+    *(undefined4 *)(p_Var1 + 0x6c) = 0;
+    if (((byte)p_Var1[0x80] & 1) != 0) {
+      ResetEvent(*(HANDLE *)(p_Var1 + 0x60));
     }
     if ((param_4 != 0) && ((*(byte *)(param_4 + 4) & 1) != 0)) {
       *(int *)(*(longlong *)(param_1 + 6) + 0x10) = *(int *)(*(longlong *)(param_1 + 6) + 0x10) + 1;
+      uVar6 = *(undefined4 *)(*(longlong *)(param_1 + 6) + 0x10);
       LeaveCriticalSection(&RouterNotifySection);
-      iVar3 = PrvRouterRefreshPrinterChangeNotification
-                        (param_1,*(undefined4 *)(*(longlong *)(param_1 + 6) + 0x10),param_4,param_5)
-      ;
+      bVar2 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                          ::__l2::impl);
+      if (!bVar2) {
+        uVar6 = *(undefined4 *)(*(longlong *)(param_1 + 6) + 0x10);
+      }
+      iVar3 = PrvRouterRefreshPrinterChangeNotification(param_1,uVar6,param_4,param_5);
       return iVar3;
     }
-    if ((param_5 != (longlong *)0x0) && ((param_2 & 1) != 0)) {
-      lVar2 = *(longlong *)(lVar1 + 0x50);
-      if (((*(uint *)(lVar1 + 0xc) >> 0x10 & 1) == 0) &&
-         (((*(int *)(lVar1 + 0x6c) != 0 || ((*(uint *)(lVar1 + 0xc) >> 0xf & 1) != 0)) ||
-          ((lVar2 != 0 && (((*(byte *)(lVar2 + 4) & 1) != 0 || (*(int *)(lVar2 + 8) != 0)))))))) {
-        *param_5 = lVar2;
-        *(undefined8 *)(lVar1 + 0x50) = 0;
-        if (*param_5 == 0) {
-          PrvSpoolssTelemetry::WriteDbgTraceInfo
-                    ("GetChangeInfo",
-                     (ushort *)L"RFNPCN: Discard with no pPrinterNotifyInfo.  pChange 0x%p.",lVar1);
-          p_Var4 = PrvRouterAllocPrinterNotifyInfo(0);
-          *param_5 = (longlong)p_Var4;
-          if (p_Var4 == (_PRINTER_NOTIFY_INFO *)0x0) goto LAB_0;
-          *(undefined4 *)(p_Var4 + 4) = 1;
+    if (((param_5 != (longlong *)0x0) && ((param_2 & 1) != 0)) &&
+       (iVar4 = NotifyNeeded(p_Var1), iVar4 != 0)) {
+      *param_5 = *(longlong *)(p_Var1 + 0x50);
+      *(undefined8 *)(p_Var1 + 0x50) = 0;
+      if (*param_5 == 0) {
+        PrvSpoolssTelemetry::WriteDbgTraceInfo
+                  ("GetChangeInfo",
+                   (ushort *)L"RFNPCN: Discard with no pPrinterNotifyInfo.  pChange 0x%p.",p_Var1);
+        size = (ulonglong)cDefaultPrinterNotifyInfoData * 0x20 + 0x10;
+        if ((0xffffffff < size) || (puVar5 = PrvDllAllocSplMem(size), puVar5 == (undefined4 *)0x0))
+        {
+          *param_5 = 0;
+          goto LAB_0;
         }
+        *puVar5 = 2;
+        puVar5[2] = 0;
+        *param_5 = (longlong)puVar5;
+        puVar5[1] = 1;
       }
     }
     iVar3 = 1;
   }
   else {
     SetLastError(6);
   }
 LAB_0:
   LeaveCriticalSection(&RouterNotifySection);
   return iVar3;
 }
 

```


## NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.51|
|i_ratio|0.73|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|UnRegisterForNotifications|UnRegisterForNotifications|
|fullname|NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications|NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications|
|refcount|3|3|
|`length`|273|297|
|`called`|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>RPCRT4.DLL::RpcSsContextLockExclusive<br>SafeDecrementReference<br>_guard_dispatch_icall$thunk$10345483385596137414<br>operator_delete[]|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>NRemoteNotify_Server::TRemoteNotifyHandle::Unregister<br>RPCRT4.DLL::RpcSsContextLockExclusive<br>SafeDecrementReference<br>_guard_dispatch_icall$thunk$10345483385596137414<br>operator_delete[]<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|calling|RMTNTFY_HANDLE_rundown<br>TRemoteWinspool::RpcSyncUnRegisterForRemoteNotifications|RMTNTFY_HANDLE_rundown<br>TRemoteWinspool::RpcSyncUnRegisterForRemoteNotifications|
|paramcount|2|2|
|`address`|140048ea4|1400491f8|
|sig|long __cdecl UnRegisterForNotifications(void * * param_1, int param_2)|long __cdecl UnRegisterForNotifications(void * * param_1, int param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications Called Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications called
+++ NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications called
@@ -2,0 +3 @@
+NRemoteNotify_Server::TRemoteNotifyHandle::Unregister
@@ -6,0 +8 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
```


### NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications Diff


```diff
--- NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications
+++ NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications
@@ -1,51 +1,59 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* public: static long __cdecl
    NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications(void * __ptr64 *
    __ptr64,int) */
 
 long __cdecl
 NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications(void **param_1,int param_2)
 
 {
-  int *piVar1;
+  TRemoteNotifyHandle *pTVar1;
   longlong *plVar2;
-  int iVar3;
+  bool bVar3;
   int iVar4;
-  ulong uVar5;
+  int iVar5;
+  ulong uVar6;
   undefined8 local_res8;
   
-  piVar1 = *param_1;
-  if (piVar1 == (int *)0x0) {
-    iVar3 = -0x7ff8ffa9;
+  pTVar1 = *param_1;
+  if (pTVar1 == (TRemoteNotifyHandle *)0x0) {
+    iVar4 = -0x7ff8ffa9;
   }
-  else if (*piVar1 == 0x726d) {
-    plVar2 = *(longlong **)(piVar1 + 2);
+  else if (*(int *)pTVar1 == 0x726d) {
+    plVar2 = *(longlong **)(pTVar1 + 8);
     local_res8 = 0;
     EnterCriticalSection(&RouterNotifySection);
-    iVar3 = (**(code **)(*plVar2 + 0x30))(plVar2,&local_res8);
-    if (-1 < iVar3) {
+    iVar4 = (**(code **)(*plVar2 + 0x30))(plVar2,&local_res8);
+    if (-1 < iVar4) {
       (**(code **)(*plVar2 + 0x38))(plVar2);
     }
     LeaveCriticalSection(&RouterNotifySection);
     (**(code **)(*plVar2 + 0x28))(plVar2);
-    iVar4 = RpcSsContextLockExclusive(0,*param_1);
-    if ((iVar4 == 0) || ((iVar4 == 6 && (param_2 != 0)))) {
-      uVar5 = SafeDecrementReference(piVar1 + 4);
-      if (uVar5 == 0) {
-        (**(code **)(**(longlong **)(piVar1 + 2) + 0x10))();
-        operator_delete__(piVar1);
+    iVar5 = RpcSsContextLockExclusive(0,*param_1);
+    if ((iVar5 == 0) || ((iVar5 == 6 && (param_2 != 0)))) {
+      bVar3 = wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled
+                        ((FeatureImpl<__WilFeatureTraits_Feature_1137672506> *)
+                         &`private:_static_class_wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>&___ptr64___cdecl_wil::Feature<__WilFeatureTraits_Feature_1137672506>::GetImpl(void)'
+                          ::__l2::impl);
+      if (bVar3) {
+        TRemoteNotifyHandle::Unregister(pTVar1);
+      }
+      uVar6 = SafeDecrementReference((long *)(pTVar1 + 0x10));
+      if (uVar6 == 0) {
+        (**(code **)(**(longlong **)(pTVar1 + 8) + 0x10))();
+        operator_delete__(pTVar1);
       }
       *param_1 = (void *)0x0;
     }
     LOCK();
     g_TotalAsyncRegistrations = g_TotalAsyncRegistrations + -1;
     UNLOCK();
   }
   else {
-    iVar3 = -0x7ff8fffa;
+    iVar4 = -0x7ff8fffa;
   }
-  return iVar3;
+  return iVar4;
 }
 

```


## NCoreLibrary::GetLastErrorAsHResult

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,name,fullname,refcount,length,sig,address,calling,called,parent|
|ratio|0.28|
|i_ratio|0.1|
|m_ratio|0.46|
|b_ratio|0.21|
|match_types|Implied Match|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|`name`|GetLastErrorAsHResult|CreateRemoteNotifyChannel|
|`fullname`|NCoreLibrary::GetLastErrorAsHResult|NRemoteNotify_Router::CreateRemoteNotifyChannel|
|`refcount`|53|2|
|`length`|33|97|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>operator_new|
|`calling`|<details><summary>Expand for full list:<br>CaptureUserInfo<br>CreateMediumIntegritySplWow64<br>GetLastErrorAsHResultAndFail<br>GetPerMachineConnections<br>GetPerUserConnections<br>GetThreadToken<br>GetUserTokens<br>InternalCreateSplWowProcess<br>IsTokenLocalSystem<br>IsUserAdmin<br>NCoreLibrary::CreateAutoEventHandle</summary>NCoreLibrary::SetAutoEventHandle<br>NRemoteNotify_Router::TRemoteNotifyChannel::WriteData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications<br>NRouter::TSessionCapture::GetTokenSession<br>NRouter::TUserTokenTable::TUserEntry::GetToken<br>NSecurityLibrary::TSidUserContext::GetAuthenticationIdAndIntegrity<br>NSecurityLibrary::TSidUserContext::GetSidAsString<br>NSecurityLibrary::TUserContext::Initialize<br>NSecurityLibrary::TUserContext::TImpersonate::~TImpersonate<br>NThreadingLibrary::TWorkCrew::Initialize<br>NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue<br>NThreadingLibrary::TWorkCrew::Shutdown<br>NThreadingLibrary::TWorkCrew::tpSimpleCallback<br>NUtilityLibrary::UserName<br>PrvCacheIsNameCluster<br>PrvCheckLocalCall<br>RemoveModernAttributes<br>RevertToSelfHelper<br>SetSpoolerPriorityClass<br>SplGetClientSessionId<br>TNameResolutionCache::AddName<br>sandbox::RevertToProcessSelf::RevertToProcessSelf<br>sandbox::RevertToProcessSelf::~RevertToProcessSelf</details>|NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications|
|paramcount|0|2|
|`address`|140008ac8|14007b2b8|
|`sig`|long __cdecl GetLastErrorAsHResult(void)|long __cdecl CreateRemoteNotifyChannel(void * param_1, TRemoteNotifyChannel * * param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|ANALYSIS|
|external|False|False|

### NCoreLibrary::GetLastErrorAsHResult Called Diff


```diff
--- NCoreLibrary::GetLastErrorAsHResult called
+++ NRemoteNotify_Router::CreateRemoteNotifyChannel called
@@ -1 +1,2 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
+NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel
+operator_new
```


### NCoreLibrary::GetLastErrorAsHResult Calling Diff


```diff
--- NCoreLibrary::GetLastErrorAsHResult calling
+++ NRemoteNotify_Router::CreateRemoteNotifyChannel calling
@@ -1,14 +0,0 @@
-CaptureUserInfo
-CreateMediumIntegritySplWow64
-GetLastErrorAsHResultAndFail
-GetPerMachineConnections
-GetPerUserConnections
-GetThreadToken
-GetUserTokens
-InternalCreateSplWowProcess
-IsTokenLocalSystem
-IsUserAdmin
-NCoreLibrary::CreateAutoEventHandle
-NCoreLibrary::SetAutoEventHandle
-NRemoteNotify_Router::TRemoteNotifyChannel::WriteData
-NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
@@ -16,20 +1,0 @@
-NRouter::TSessionCapture::GetTokenSession
-NRouter::TUserTokenTable::TUserEntry::GetToken
-NSecurityLibrary::TSidUserContext::GetAuthenticationIdAndIntegrity
-NSecurityLibrary::TSidUserContext::GetSidAsString
-NSecurityLibrary::TUserContext::Initialize
-NSecurityLibrary::TUserContext::TImpersonate::~TImpersonate
-NThreadingLibrary::TWorkCrew::Initialize
-NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue
-NThreadingLibrary::TWorkCrew::Shutdown
-NThreadingLibrary::TWorkCrew::tpSimpleCallback
-NUtilityLibrary::UserName
-PrvCacheIsNameCluster
-PrvCheckLocalCall
-RemoveModernAttributes
-RevertToSelfHelper
-SetSpoolerPriorityClass
-SplGetClientSessionId
-TNameResolutionCache::AddName
-sandbox::RevertToProcessSelf::RevertToProcessSelf
-sandbox::RevertToProcessSelf::~RevertToProcessSelf
```


### NCoreLibrary::GetLastErrorAsHResult Diff


```diff
--- NCoreLibrary::GetLastErrorAsHResult
+++ NRemoteNotify_Router::CreateRemoteNotifyChannel
@@ -1,15 +1,33 @@
 
-/* long __cdecl NCoreLibrary::GetLastErrorAsHResult(void) */
+/* long __cdecl NRemoteNotify_Router::CreateRemoteNotifyChannel(void * __ptr64,class
+   NRemoteNotify_Router::TRemoteNotifyChannel * __ptr64 * __ptr64) */
 
-long __cdecl NCoreLibrary::GetLastErrorAsHResult(void)
+long __cdecl
+NRemoteNotify_Router::CreateRemoteNotifyChannel(void *param_1,TRemoteNotifyChannel **param_2)
 
 {
-  DWORD DVar1;
+  int iVar1;
+  long lVar2;
+  TRemoteNotifyChannel *pTVar3;
   
-  DVar1 = GetLastError();
-  if (0 < (int)DVar1) {
-    DVar1 = DVar1 & 0xffff | 0x80070000;
+  if (param_2 == (TRemoteNotifyChannel **)0x0) {
+    lVar2 = -0x7ff8ffa9;
   }
-  return DVar1;
+  else {
+    *param_2 = (TRemoteNotifyChannel *)0x0;
+    pTVar3 = operator_new(0xa0);
+    if ((pTVar3 != (TRemoteNotifyChannel *)0x0) &&
+       (pTVar3 = (TRemoteNotifyChannel *)TRemoteNotifyChannel::TRemoteNotifyChannel(pTVar3,param_1),
+       pTVar3 != (TRemoteNotifyChannel *)0x0)) {
+      iVar1 = *(int *)(pTVar3 + 8);
+      if (iVar1 < 0) {
+        return iVar1;
+      }
+      *param_2 = pTVar3;
+      return iVar1;
+    }
+    lVar2 = -0x7ff8fff2;
+  }
+  return lVar2;
 }
 

```


## DevmodeSizePatchTelemetry::WriteDbgTraceInfo

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|code,name,fullname,refcount,length,sig,address,calling,called,parent|
|ratio|0.16|
|i_ratio|0.04|
|m_ratio|0.57|
|b_ratio|0.43|
|match_types|Implied Match|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|`name`|WriteDbgTraceInfo|__private_IsEnabled|
|`fullname`|DevmodeSizePatchTelemetry::WriteDbgTraceInfo|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled|
|`refcount`|25|12|
|`length`|179|53|
|`called`|DevmodeSizePatchTelemetry::IsEnabled<br>DevmodeSizePatchTelemetry::LogDbgTraceInfo_<br>StringCchVPrintfW<br>__chkstk<br>__security_check_cookie<br>wil::details::static_lazy<DevmodeSizePatchTelemetry>::get|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage|
|`calling`|LGetDevMode<br>LPatchDevmodeOfHandleType<br>LPatchUserDevmodes<br>LVerifyAndCorrectDevMode|LVerifyAndCorrectDevMode|
|paramcount|2|1|
|`address`|140006684|140081ed8|
|`sig`|void __cdecl WriteDbgTraceInfo(char * param_1, ushort * param_2, ...)|bool __thiscall __private_IsEnabled(FeatureImpl<__WilFeatureTraits_Feature_2040253753> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### DevmodeSizePatchTelemetry::WriteDbgTraceInfo Called Diff


```diff
--- DevmodeSizePatchTelemetry::WriteDbgTraceInfo called
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled called
@@ -1,6 +1,2 @@
-DevmodeSizePatchTelemetry::IsEnabled
-DevmodeSizePatchTelemetry::LogDbgTraceInfo_
-StringCchVPrintfW
-__chkstk
-__security_check_cookie
-wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage
```


### DevmodeSizePatchTelemetry::WriteDbgTraceInfo Calling Diff


```diff
--- DevmodeSizePatchTelemetry::WriteDbgTraceInfo calling
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled calling
@@ -1,3 +0,0 @@
-LGetDevMode
-LPatchDevmodeOfHandleType
-LPatchUserDevmodes
```


### DevmodeSizePatchTelemetry::WriteDbgTraceInfo Diff


```diff
--- DevmodeSizePatchTelemetry::WriteDbgTraceInfo
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
@@ -1,48 +1,18 @@
 
-/* WARNING: Function: __chkstk replaced with injection: alloca_probe */
-/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* public: static void __cdecl DevmodeSizePatchTelemetry::WriteDbgTraceInfo(char * __ptr64,unsigned
-   short * __ptr64,...) */
+/* public: bool __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_2040253753>::__private_IsEnabled(void) __ptr64 */
 
-void __cdecl DevmodeSizePatchTelemetry::WriteDbgTraceInfo(char *param_1,ushort *param_2,...)
+bool __thiscall
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::__private_IsEnabled
+          (FeatureImpl<__WilFeatureTraits_Feature_2040253753> *this)
 
 {
-  bool bVar1;
-  long lVar2;
-  DevmodeSizePatchTelemetry *pDVar3;
-  static_lazy<DevmodeSizePatchTelemetry> *this;
-  __uint64 _Var4;
-  undefined8 in_R8;
-  undefined8 in_R9;
-  undefined8 local_res18;
-  undefined8 local_res20;
-  undefined1 auStack_2048 [32];
-  undefined8 local_2028;
-  static_lazy<DevmodeSizePatchTelemetry> local_2018 [8192];
-  ulonglong local_18;
-  undefined8 uStack_10;
+  ReportingKind in_R8D;
+  __uint64 in_R9;
+  undefined1 local_res10;
   
-  uStack_10 = 0x14000669e;
-  local_18 = __security_cookie ^ (ulonglong)auStack_2048;
-  local_res18 = in_R8;
-  local_res20 = in_R9;
-  pDVar3 = wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
-                     ((static_lazy<DevmodeSizePatchTelemetry> *)param_1,
-                      <lambda_e670ca4b9feaa84b0d1a9de084fa3046>::<lambda_invoker_cdecl>);
-  if ((*(int **)(pDVar3 + 8) != (int *)0x0) && (**(int **)(pDVar3 + 8) != 0)) {
-    _Var4 = 0x1000;
-    local_2028 = 0;
-    this = local_2018;
-    lVar2 = StringCchVPrintfW((ushort *)this,0x1000,param_2,(char *)&local_res18);
-    if (-1 < lVar2) {
-      bVar1 = IsEnabled((uchar)this,_Var4);
-      if (bVar1) {
-        wil::details::static_lazy<DevmodeSizePatchTelemetry>::get
-                  (this,<lambda_e670ca4b9feaa84b0d1a9de084fa3046>::<lambda_invoker_cdecl>);
-        LogDbgTraceInfo_((DevmodeSizePatchTelemetry *)this,param_1,(ushort *)local_2018);
-      }
-    }
-  }
-  return;
+  GetCachedFeatureEnabledState(this);
+  ReportUsage(this,(bool)(local_res10 & 1),in_R8D,in_R9);
+  return (bool)(local_res10 & 1);
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## NotifyNeeded

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.65|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|NotifyNeeded|NotifyNeeded|
|fullname|NotifyNeeded|NotifyNeeded|
|`refcount`|2|3|
|length|54|54|
|called|||
|`calling`|ReplyPrinterChangeNotificationWorker<br>ThreadNotifyProcessJob|PrvRouterFindNextPrinterChangeNotification<br>ReplyPrinterChangeNotificationWorker<br>ThreadNotifyProcessJob|
|paramcount|1|1|
|`address`|140010c2c|1400109ac|
|sig|int __cdecl NotifyNeeded(_CHANGE * param_1)|int __cdecl NotifyNeeded(_CHANGE * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### NotifyNeeded Calling Diff


```diff
--- NotifyNeeded calling
+++ NotifyNeeded calling
@@ -0,0 +1 @@
+PrvRouterFindNextPrinterChangeNotification
```


## FindClosePrinterChangeNotificationWorker

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|FindClosePrinterChangeNotificationWorker|FindClosePrinterChangeNotificationWorker|
|fullname|FindClosePrinterChangeNotificationWorker|FindClosePrinterChangeNotificationWorker|
|`refcount`|6|3|
|length|330|330|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>CloseReplyRemote<br>FreeChange<br>PrvSpoolssTelemetry::WriteDbgTraceError<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>RemoveReplyClient<br>_guard_dispatch_icall$thunk$10345483385596137414|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>CloseReplyRemote<br>FreeChange<br>PrvSpoolssTelemetry::WriteDbgTraceError<br>PrvSpoolssTelemetry::WriteDbgTraceInfo<br>RemoveReplyClient<br>_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|InternalClosePrinter<br>IsCurrentUserLocalAdmin<br>PrvClosePrinter<br>PrvFindClosePrinterChangeNotification<br>YClosePrinter|InternalClosePrinter<br>PrvFindClosePrinterChangeNotification|
|paramcount|2|2|
|`address`|14006d5f8|14006da08|
|sig|ulong __cdecl FindClosePrinterChangeNotificationWorker(void * param_1, int param_2)|ulong __cdecl FindClosePrinterChangeNotificationWorker(void * param_1, int param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### FindClosePrinterChangeNotificationWorker Calling Diff


```diff
--- FindClosePrinterChangeNotificationWorker calling
+++ FindClosePrinterChangeNotificationWorker calling
@@ -2,2 +1,0 @@
-IsCurrentUserLocalAdmin
-PrvClosePrinter
@@ -5 +2,0 @@
-YClosePrinter
```


## WilApi_GetFeatureEnabledState

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.56|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|WilApi_GetFeatureEnabledState|WilApi_GetFeatureEnabledState|
|fullname|wil::details::WilApi_GetFeatureEnabledState|wil::details::WilApi_GetFeatureEnabledState|
|`refcount`|7|9|
|length|35|35|
|called|_guard_dispatch_icall$thunk$10345483385596137414|_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCurrentFeatureEnabledState|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCurrentFeatureEnabledState|
|paramcount|3|3|
|`address`|14001f3b8|14001f238|
|sig|FEATURE_ENABLED_STATE __cdecl WilApi_GetFeatureEnabledState(uint param_1, FEATURE_CHANGE_TIME param_2, int * param_3)|FEATURE_ENABLED_STATE __cdecl WilApi_GetFeatureEnabledState(uint param_1, FEATURE_CHANGE_TIME param_2, int * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WilApi_GetFeatureEnabledState Calling Diff


```diff
--- wil::details::WilApi_GetFeatureEnabledState calling
+++ wil::details::WilApi_GetFeatureEnabledState calling
@@ -0,0 +1,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCurrentFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCurrentFeatureEnabledState
```


## ReportUsageToService

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.69|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|ReportUsageToService|ReportUsageToService|
|fullname|wil::details::ReportUsageToService|wil::details::ReportUsageToService|
|`refcount`|8|10|
|length|813|813|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::WilApi_RecordFeatureUsage<br>wil_details_FeatureReporting_IncrementOpportunityInCache<br>wil_details_FeatureReporting_IncrementUsageInCache|_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::WilApi_RecordFeatureUsage<br>wil_details_FeatureReporting_IncrementOpportunityInCache<br>wil_details_FeatureReporting_IncrementUsageInCache|
|`calling`|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::ReportUsage|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::ReportUsage<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCurrentFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::ReportUsage|
|paramcount|8|8|
|`address`|14000ea38|14000e958|
|sig|void __cdecl ReportUsageToService(wil_details_FeatureReportingCache * param_1, uint param_2, int param_3, int param_4, FEATURE_LOGGED_TRAITS * param_5, int param_6, wil_ReportingKind param_7, __uint64 param_8)|void __cdecl ReportUsageToService(wil_details_FeatureReportingCache * param_1, uint param_2, int param_3, int param_4, FEATURE_LOGGED_TRAITS * param_5, int param_6, wil_ReportingKind param_7, __uint64 param_8)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ReportUsageToService Calling Diff


```diff
--- wil::details::ReportUsageToService calling
+++ wil::details::ReportUsageToService calling
@@ -0,0 +1,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::ReportUsage
```


## Enter

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.92|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|Enter|Enter|
|fullname|NCoreLibrary::TCriticalSection::Enter|NCoreLibrary::TCriticalSection::Enter|
|`refcount`|74|77|
|length|45|45|
|called|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|
|`calling`|<details><summary>Expand for full list:<br>CacheRefresh<br>DemandStart::IdleCallback<br>DemandStart::IdleThread<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::CreateChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::GetProvidorNotifyChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::SetProvidorNotifyChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::~TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::AsyncGetServerReferral<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::SetProvidorObjects<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::UnregisterForNotifications<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::operator_struct_NPrintAsyncNotifyProvider::IPrintAsyncNotifyRegistration*___ptr64</summary>NAsyncNotifyServer::TAsyncNotifyRPCObject::~TAsyncNotifyRPCObject<br>NAsyncNotifyServer::TAsyncSendGetNotificationCookie::FinishAsyncCallWithData<br>NRemoteNotify_Router::TRemoteNotifyChannel::Close<br>NRemoteNotify_Router::TRemoteNotifyChannel::ReadData<br>NRemoteNotify_Router::TRemoteNotifyChannel::SafeCleanUp<br>NRemoteNotify_Router::TRemoteNotifyChannel::WriteData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRouter::TSessionRegistration::Notify<br>NRouter::TSessionRegistration::Register<br>NRouter::TUserTokenTable::AcquireTokens<br>NRouter::TUserTokenTable::DeleteSession<br>NRouter::TUserTokenTable::FindExtra<br>NRouter::TUserTokenTable::FindToken<br>NRouter::TUserTokenTable::ReleaseTokens<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::NotifyConsumer<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Run<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::SetQueueControl<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Shutdown<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::Shutdown<br>NThreadingLibrary::TWorkCrew::tpLpcCallback<br>NThreadingLibrary::TWorkCrew::tpTimerCallback<br>NThreadingLibrary::TWorkCrew::tpWaitCallback<br>PrinterPLM::AddJobTimerCallback<br>PrinterPLM::StartDocTimerCallback<br>PrinterPLM::UpdateTimer<br>PrvSplUnregisterForSessionEvents<br>TFastCache<AddrInfoCacheEntry>::AddString<br>TFastCache<AddrInfoCacheEntry>::ExpireElement<br>TFastCache<AddrInfoCacheEntry>::IsStringInCache<br>TFastCache<NullCacheEntry>::AddString<br>TFastCache<NullCacheEntry>::ExpireElement<br>TNameResolutionCache::AddName<br>TNameResolutionCache::AddNameUsingIPList<br>TNameResolutionCache::AddNetBiosName<br>TNameResolutionCache::CheckIfNameIsInNodeCacheUsingIp<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::CreateAndAddNodeWithIPAddresses<br>TNameResolutionCache::DeleteNode<br>TNameResolutionCache::FindNameInCacheAndReference<br>TNameResolutionCache::IsNameInSomeNodeList<br>TNameResolutionCache::IsNodeInCache<br>TNameResolutionCache::Purge<br>TNameResolutionCache::RefreshNode<br>sandbox::SandboxManager::GetSandboxObject<br>sandbox::SandboxManager::ReleaseTimedOutIdleSandboxes<br>sandbox::SandboxManager::ResizeSandboxArray<br>sandbox::SandboxManagerUtil::GetDriverGroup<br>sandbox::SandboxManagerUtil::RefreshSettings</details>|<details><summary>Expand for full list:<br>CacheRefresh<br>DemandStart::IdleCallback<br>DemandStart::IdleThread<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::CreateChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::GetProvidorNotifyChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::SetProvidorNotifyChannel<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::~TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::AsyncGetServerReferral<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::SetProvidorObjects<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::UnregisterForNotifications<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::operator_struct_NPrintAsyncNotifyProvider::IPrintAsyncNotifyRegistration*___ptr64</summary>NAsyncNotifyServer::TAsyncNotifyRPCObject::~TAsyncNotifyRPCObject<br>NAsyncNotifyServer::TAsyncSendGetNotificationCookie::FinishAsyncCallWithData<br>NRemoteNotify_Router::TRemoteNotifyChannel::Close<br>NRemoteNotify_Router::TRemoteNotifyChannel::ReadData<br>NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled<br>NRemoteNotify_Router::TRemoteNotifyChannel::SafeCleanUp<br>NRemoteNotify_Router::TRemoteNotifyChannel::WriteData<br>NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel<br>NRemoteNotify_Server::TRemoteNotifyHandle::Unregister<br>NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications<br>NRouter::TSessionRegistration::Notify<br>NRouter::TSessionRegistration::Register<br>NRouter::TUserTokenTable::AcquireTokens<br>NRouter::TUserTokenTable::DeleteSession<br>NRouter::TUserTokenTable::FindExtra<br>NRouter::TUserTokenTable::FindToken<br>NRouter::TUserTokenTable::ReleaseTokens<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::NotifyConsumer<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Run<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::SetQueueControl<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Shutdown<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::Shutdown<br>NThreadingLibrary::TWorkCrew::tpLpcCallback<br>NThreadingLibrary::TWorkCrew::tpTimerCallback<br>NThreadingLibrary::TWorkCrew::tpWaitCallback<br>PrinterPLM::AddJobTimerCallback<br>PrinterPLM::StartDocTimerCallback<br>PrinterPLM::UpdateTimer<br>PrvSplUnregisterForSessionEvents<br>TFastCache<AddrInfoCacheEntry>::AddString<br>TFastCache<AddrInfoCacheEntry>::ExpireElement<br>TFastCache<AddrInfoCacheEntry>::IsStringInCache<br>TFastCache<NullCacheEntry>::AddString<br>TFastCache<NullCacheEntry>::ExpireElement<br>TNameResolutionCache::AddName<br>TNameResolutionCache::AddNameUsingIPList<br>TNameResolutionCache::AddNetBiosName<br>TNameResolutionCache::CheckIfNameIsInNodeCacheUsingIp<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::CreateAndAddNodeWithIPAddresses<br>TNameResolutionCache::DeleteNode<br>TNameResolutionCache::FindNameInCacheAndReference<br>TNameResolutionCache::IsNameInSomeNodeList<br>TNameResolutionCache::IsNodeInCache<br>TNameResolutionCache::Purge<br>TNameResolutionCache::RefreshNode<br>sandbox::SandboxManager::GetSandboxObject<br>sandbox::SandboxManager::ReleaseTimedOutIdleSandboxes<br>sandbox::SandboxManager::ResizeSandboxArray<br>sandbox::SandboxManagerUtil::GetDriverGroup<br>sandbox::SandboxManagerUtil::RefreshSettings</details>|
|paramcount|1|1|
|`address`|14000aa40|14000ac20|
|sig|void __thiscall Enter(TCriticalSection * this)|void __thiscall Enter(TCriticalSection * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### Enter Calling Diff


```diff
--- NCoreLibrary::TCriticalSection::Enter calling
+++ NCoreLibrary::TCriticalSection::Enter calling
@@ -15,0 +16 @@
+NRemoteNotify_Router::TRemoteNotifyChannel::RefreshCalled
@@ -18 +19,3 @@
-NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
+NRemoteNotify_Server::TRemoteNotifyHandle::AcquireChannel
+NRemoteNotify_Server::TRemoteNotifyHandle::Unregister
+NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications
@@ -27,0 +31 @@
+NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Run
@@ -30 +33,0 @@
-NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Run
```


## push_back

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.89|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|push_back|push_back|
|fullname|wil::details_abi::heap_buffer::push_back|wil::details_abi::heap_buffer::push_back|
|`refcount`|10|12|
|length|90|90|
|called|memcpy_s<br>wil::details_abi::heap_buffer::ensure|memcpy_s<br>wil::details_abi::heap_buffer::ensure|
|`calling`|wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|<details><summary>Expand for full list:<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details_abi::SubscriptionList::SubscribeUnderLock</summary></details>|
|paramcount|3|3|
|`address`|14001f7a8|14001f628|
|sig|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### push_back Calling Diff


```diff
--- wil::details_abi::heap_buffer::push_back calling
+++ wil::details_abi::heap_buffer::push_back calling
@@ -2,0 +3,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
```


## EnsureSubscribedToFeatureConfigurationChanges

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|EnsureSubscribedToFeatureConfigurationChanges|EnsureSubscribedToFeatureConfigurationChanges|
|fullname|wil::details::EnsureSubscribedToFeatureConfigurationChanges|wil::details::EnsureSubscribedToFeatureConfigurationChanges|
|`refcount`|9|11|
|length|32|32|
|called|wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl|wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl|
|`calling`|wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCachedFeatureEnabledState<br>wil::details::IsFeatureConfigured|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2885745976>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_WindowsProtectedPrintSpoolerWorker>::GetCachedFeatureEnabledState<br>wil::details::IsFeatureConfigured|
|paramcount|0|0|
|`address`|14001cbac|14001ca2c|
|sig|uint __cdecl EnsureSubscribedToFeatureConfigurationChanges(void)|uint __cdecl EnsureSubscribedToFeatureConfigurationChanges(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### EnsureSubscribedToFeatureConfigurationChanges Calling Diff


```diff
--- wil::details::EnsureSubscribedToFeatureConfigurationChanges calling
+++ wil::details::EnsureSubscribedToFeatureConfigurationChanges calling
@@ -0,0 +1,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|InitializeCriticalSectionAndSpinCount|InitializeCriticalSectionAndSpinCount|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount|
|`refcount`|18|19|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>InitializeSessionInfo<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::TAsyncNotifyRPCObject<br>NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::TWorkCrew<br>PrinterPLM::PrinterPLM<br>PrvSpoolssInit<br>SpoolerInitializeSpooler<br>Spooler_WindowsProtectedPrintMain</summary>TFastCache<AddrInfoCacheEntry>::TFastCache<AddrInfoCacheEntry><br>TNameResolutionCache::TNameResolutionCache<br>__scrt_initialize_thread_safe_statics<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>sandbox::SandboxConnection::SandboxConnection</details>|<details><summary>Expand for full list:<br>InitializeSessionInfo<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::TAsyncNotifyRPCObject<br>NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::TWorkCrew<br>PrinterPLM::PrinterPLM<br>PrvSpoolssInit<br>SpoolerInitializeSpooler<br>Spooler_WindowsProtectedPrintMain</summary>TFastCache<AddrInfoCacheEntry>::TFastCache<AddrInfoCacheEntry><br>TNameResolutionCache::TNameResolutionCache<br>__scrt_initialize_thread_safe_statics<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''<br>sandbox::SandboxConnection::SandboxConnection</details>|
|paramcount|2|2|
|`address`|EXTERNAL:0000008d|EXTERNAL:000000a0|
|sig|BOOL __stdcall InitializeCriticalSectionAndSpinCount(LPCRITICAL_SECTION lpCriticalSection, DWORD dwSpinCount)|BOOL __stdcall InitializeCriticalSectionAndSpinCount(LPCRITICAL_SECTION lpCriticalSection, DWORD dwSpinCount)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionAndSpinCount calling
@@ -15,0 +16 @@
+`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|AcquireSRWLockExclusive|AcquireSRWLockExclusive|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive|
|`refcount`|25|27|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState</summary>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState</summary>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000009e|EXTERNAL:00000094|
|sig|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive calling
@@ -9,0 +10,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
```


## atexit

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|atexit|atexit|
|fullname|atexit|atexit|
|`refcount`|28|29|
|length|23|23|
|called|_onexit|_onexit|
|`calling`|<details><summary>Expand for full list:<br>DevmodeSizePatchTelemetry::IsEnabled<br>__scrt_initialize_thread_safe_statics<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>`dynamic_initializer_for_'DemandStart::m_idleThread''<br>pre_c_initialization<br>sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor<br>wil::details::`dynamic_initializer_for_'g_enabledStateManager''<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''<br>wil::details::`dynamic_initializer_for_'g_threadFailureCallbacks''<br>wil::details::static_lazy<DevmodeSizePatchLogging>::get</summary>wil::details::static_lazy<DevmodeSizePatchTelemetry>::get<br>wil::details::static_lazy<PerfLibLogging>::get<br>wil::details::static_lazy<PerfLibTelemetry>::get<br>wil::details::static_lazy<PrintPLMLogging>::get<br>wil::details::static_lazy<PrintPLMTelemetry>::get<br>wil::details::static_lazy<PrvSpoolssLogging>::get<br>wil::details::static_lazy<PrvSpoolssTelemetry>::get<br>wil::details::static_lazy<SandboxLogging>::get<br>wil::details::static_lazy<SandboxTelemetry>::get<br>wil::details::static_lazy<SplLibLogging>::get<br>wil::details::static_lazy<SplLibTelemetry>::get<br>wil::details::static_lazy<SpoolerServiceLogging>::get<br>wil::details::static_lazy<SpoolerServiceTelemetry>::get<br>wil::details::static_lazy<UalPrintLogging>::get<br>wil::details::static_lazy<UalPrintTelemetry>::get</details>|<details><summary>Expand for full list:<br>DevmodeSizePatchTelemetry::IsEnabled<br>__scrt_initialize_thread_safe_statics<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>`dynamic_initializer_for_'DemandStart::m_idleThread''<br>`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''<br>pre_c_initialization<br>sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor<br>wil::details::`dynamic_initializer_for_'g_enabledStateManager''<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''<br>wil::details::`dynamic_initializer_for_'g_threadFailureCallbacks''</summary>wil::details::static_lazy<DevmodeSizePatchLogging>::get<br>wil::details::static_lazy<DevmodeSizePatchTelemetry>::get<br>wil::details::static_lazy<PerfLibLogging>::get<br>wil::details::static_lazy<PerfLibTelemetry>::get<br>wil::details::static_lazy<PrintPLMLogging>::get<br>wil::details::static_lazy<PrintPLMTelemetry>::get<br>wil::details::static_lazy<PrvSpoolssLogging>::get<br>wil::details::static_lazy<PrvSpoolssTelemetry>::get<br>wil::details::static_lazy<SandboxLogging>::get<br>wil::details::static_lazy<SandboxTelemetry>::get<br>wil::details::static_lazy<SplLibLogging>::get<br>wil::details::static_lazy<SplLibTelemetry>::get<br>wil::details::static_lazy<SpoolerServiceLogging>::get<br>wil::details::static_lazy<SpoolerServiceTelemetry>::get<br>wil::details::static_lazy<UalPrintLogging>::get<br>wil::details::static_lazy<UalPrintTelemetry>::get</details>|
|paramcount|1|1|
|`address`|140017cf4|140017b74|
|sig|int __cdecl atexit(_func_5014 * param_1)|int __cdecl atexit(_func_5014 * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### atexit Calling Diff


```diff
--- atexit calling
+++ atexit calling
@@ -4,0 +5 @@
+`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
```


## ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|fullname|wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|`refcount`|25|27|
|length|29|29|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|
|`calling`|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState</summary>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::EnsureSubscribedToUsageFlush<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState</summary>wil::details::FeatureImpl<__WilFeatureTraits_Feature_41618747>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_IppPsaEnterprise_Api>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_Enforce_Windows_Protected_Print_On_NXT>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_Print_PlatformStabilizationFixes_2026_Wave4>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_VirtualPrinter_API_Enhancements>::GetCachedFeatureEnabledState<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|140017634|1400174b4|
|sig|void __thiscall ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>(unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> * this)|void __thiscall ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>(unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> Calling Diff


```diff
--- wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> calling
+++ wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> calling
@@ -9,0 +10,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_2040253753>::GetCachedFeatureEnabledState
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|DeleteCriticalSection|DeleteCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection|
|`refcount`|18|19|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::~TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::~TAsyncNotifyRPCObject<br>NCoreLibrary::TCriticalSection::`scalar_deleting_destructor'<br>NRemoteNotify_Router::TRemoteNotifyChannel::~TRemoteNotifyChannel<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::~TWorkCrew<br>PrinterPLM::~PrinterPLM<br>PrvSpoolssCleanup<br>__scrt_uninitialize_thread_safe_statics<br>`dynamic_atexit_destructor_for_'DemandStart::m_idleLock''</summary>`sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor'::__l2::`dynamic_atexit_destructor_for_'g_sqmDirectJobCount''<br>`sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor'::__l2::`dynamic_atexit_destructor_for_'g_sqmSandboxJobCount''<br>sandbox::SandboxConnection::~SandboxConnection</details>|<details><summary>Expand for full list:<br>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::~TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::~TAsyncNotifyRPCObject<br>NCoreLibrary::TCriticalSection::`scalar_deleting_destructor'<br>NRemoteNotify_Router::TRemoteNotifyChannel::~TRemoteNotifyChannel<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::~TWorkCrew<br>PrinterPLM::~PrinterPLM<br>PrvSpoolssCleanup<br>__scrt_uninitialize_thread_safe_statics<br>`dynamic_atexit_destructor_for_'DemandStart::m_idleLock''</summary>`dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''<br>`sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor'::__l2::`dynamic_atexit_destructor_for_'g_sqmDirectJobCount''<br>`sandbox::PrintProcessorExecuteObserver::PrintDocThroughPrintProcessor'::__l2::`dynamic_atexit_destructor_for_'g_sqmSandboxJobCount''<br>sandbox::SandboxConnection::~SandboxConnection</details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000009c|EXTERNAL:0000008c|
|sig|void __stdcall DeleteCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall DeleteCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection calling
@@ -11,0 +12 @@
+`dynamic_atexit_destructor_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
```


## GetLastErrorAsHResult

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|GetLastErrorAsHResult|GetLastErrorAsHResult|
|fullname|NCoreLibrary::GetLastErrorAsHResult|NCoreLibrary::GetLastErrorAsHResult|
|`refcount`|53|54|
|length|33|33|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|
|calling|<details><summary>Expand for full list:<br>CaptureUserInfo<br>CreateMediumIntegritySplWow64<br>GetLastErrorAsHResultAndFail<br>GetPerMachineConnections<br>GetPerUserConnections<br>GetThreadToken<br>GetUserTokens<br>InternalCreateSplWowProcess<br>IsTokenLocalSystem<br>IsUserAdmin<br>NCoreLibrary::CreateAutoEventHandle</summary>NCoreLibrary::SetAutoEventHandle<br>NRemoteNotify_Router::TRemoteNotifyChannel::WriteData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications<br>NRouter::TSessionCapture::GetTokenSession<br>NRouter::TUserTokenTable::TUserEntry::GetToken<br>NSecurityLibrary::TSidUserContext::GetAuthenticationIdAndIntegrity<br>NSecurityLibrary::TSidUserContext::GetSidAsString<br>NSecurityLibrary::TUserContext::Initialize<br>NSecurityLibrary::TUserContext::TImpersonate::~TImpersonate<br>NThreadingLibrary::TWorkCrew::Initialize<br>NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue<br>NThreadingLibrary::TWorkCrew::Shutdown<br>NThreadingLibrary::TWorkCrew::tpSimpleCallback<br>NUtilityLibrary::UserName<br>PrvCacheIsNameCluster<br>PrvCheckLocalCall<br>RemoveModernAttributes<br>RevertToSelfHelper<br>SetSpoolerPriorityClass<br>SplGetClientSessionId<br>TNameResolutionCache::AddName<br>sandbox::RevertToProcessSelf::RevertToProcessSelf<br>sandbox::RevertToProcessSelf::~RevertToProcessSelf</details>|<details><summary>Expand for full list:<br>CaptureUserInfo<br>CreateMediumIntegritySplWow64<br>GetLastErrorAsHResultAndFail<br>GetPerMachineConnections<br>GetPerUserConnections<br>GetThreadToken<br>GetUserTokens<br>InternalCreateSplWowProcess<br>IsTokenLocalSystem<br>IsUserAdmin<br>NCoreLibrary::CreateAutoEventHandle</summary>NCoreLibrary::SetAutoEventHandle<br>NRemoteNotify_Router::TRemoteNotifyChannel::WriteData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications<br>NRouter::TSessionCapture::GetTokenSession<br>NRouter::TUserTokenTable::TUserEntry::GetToken<br>NSecurityLibrary::TSidUserContext::GetAuthenticationIdAndIntegrity<br>NSecurityLibrary::TSidUserContext::GetSidAsString<br>NSecurityLibrary::TUserContext::Initialize<br>NSecurityLibrary::TUserContext::TImpersonate::~TImpersonate<br>NThreadingLibrary::TWorkCrew::Initialize<br>NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue<br>NThreadingLibrary::TWorkCrew::Shutdown<br>NThreadingLibrary::TWorkCrew::tpSimpleCallback<br>NUtilityLibrary::UserName<br>PrvCacheIsNameCluster<br>PrvCheckLocalCall<br>RemoveModernAttributes<br>RevertToSelfHelper<br>SetSpoolerPriorityClass<br>SplGetClientSessionId<br>TNameResolutionCache::AddName<br>sandbox::RevertToProcessSelf::RevertToProcessSelf<br>sandbox::RevertToProcessSelf::~RevertToProcessSelf</details>|
|paramcount|0|0|
|`address`|140008ac8|140008ca8|
|sig|long __cdecl GetLastErrorAsHResult(void)|long __cdecl GetLastErrorAsHResult(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## GetLastErrorAsFailHRNoBreak

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.67|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|GetLastErrorAsFailHRNoBreak|GetLastErrorAsFailHRNoBreak|
|fullname|NCoreLibrary::GetLastErrorAsFailHRNoBreak|NCoreLibrary::GetLastErrorAsFailHRNoBreak|
|`refcount`|40|41|
|length|42|42|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|
|`calling`|<details><summary>Expand for full list:<br>BeginReplyClient<br>CallAddPrinterConnection<br>CallDeletePrinterConnection<br>ImpersonateLoggedOnUserHelper<br>ImpersonatePrinterClientHelper<br>InitializeSessionIDGenerator<br>InitializeSessionInfo<br>InternalAddPrinterConnection2<br>InternalDeletePrinterConnection<br>InternalEnumPerMachineConnections<br>InternalInstallPrinterDriverPackageFromConnection</summary>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::TAsyncNotifyRPCObject<br>NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>NSecurityLibrary::TSidUserContext::GetSidAsString<br>NSecurityLibrary::TSidUserContext::Initialize<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::TWorkCrew<br>PrinterPLM::Create<br>PrinterPLM::PrinterPLM<br>RemovePrinterConnectionInRegistry<br>RevertToPrinterSelfHelper<br>RpcManager::Initialize<br>SavePrinterConnectionInRegistry<br>TFastCache<AddrInfoCacheEntry>::TFastCache<AddrInfoCacheEntry><br>TFunction4HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,Call_Route>::Run<br>TFunction6HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,_GUID,_FILETIME,unsigned___int64,int*___ptr64,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,unsigned_short_const*___ptr64,unsigned_long,_CORE_PRINTER_DRIVERW*___ptr64,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,unsigned_short*___ptr64,unsigned_long*___ptr64,Call_Route>::Run<br>TFunction8HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short*___ptr64,unsigned_long,unsigned_long*___ptr64,Call_Route>::Run<br>TNameResolutionCache::TNameResolutionCache<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>sandbox::RevertToProcessSelf::RevertToProcessSelf<br>sandbox::SandboxConnection::SandboxConnection<br>sandbox::SandboxConnection::ValidateInternalPointer</details>|<details><summary>Expand for full list:<br>BeginReplyClient<br>CallAddPrinterConnection<br>CallDeletePrinterConnection<br>ImpersonateLoggedOnUserHelper<br>ImpersonatePrinterClientHelper<br>InitializeSessionIDGenerator<br>InitializeSessionInfo<br>InternalAddPrinterConnection2<br>InternalDeletePrinterConnection<br>InternalEnumPerMachineConnections<br>InternalInstallPrinterDriverPackageFromConnection</summary>NAsyncNotifyServer::TAsyncNotifyChannelRPCObject::TAsyncNotifyChannelRPCObject<br>NAsyncNotifyServer::TAsyncNotifyRPCObject::TAsyncNotifyRPCObject<br>NRemoteNotify_Router::TRemoteNotifyChannel::TRemoteNotifyChannel<br>NSecurityLibrary::TSidUserContext::GetSidAsString<br>NSecurityLibrary::TSidUserContext::Initialize<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::TWorkCrew<br>PrinterPLM::Create<br>PrinterPLM::PrinterPLM<br>RemovePrinterConnectionInRegistry<br>RevertToPrinterSelfHelper<br>RpcManager::Initialize<br>SavePrinterConnectionInRegistry<br>TFastCache<AddrInfoCacheEntry>::TFastCache<AddrInfoCacheEntry><br>TFunction4HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,Call_Route>::Run<br>TFunction6HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,_GUID,_FILETIME,unsigned___int64,int*___ptr64,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,unsigned_short_const*___ptr64,unsigned_long,_CORE_PRINTER_DRIVERW*___ptr64,Call_Route>::Run<br>TFunction7HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_long,unsigned_short*___ptr64,unsigned_long*___ptr64,Call_Route>::Run<br>TFunction8HR<unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short_const*___ptr64,unsigned_short*___ptr64,unsigned_long,unsigned_long*___ptr64,Call_Route>::Run<br>TNameResolutionCache::TNameResolutionCache<br>`dynamic_initializer_for_'DemandStart::m_idleLock''<br>`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''<br>sandbox::RevertToProcessSelf::RevertToProcessSelf<br>sandbox::SandboxConnection::SandboxConnection<br>sandbox::SandboxConnection::ValidateInternalPointer</details>|
|paramcount|0|0|
|`address`|140014d28|140014ba4|
|sig|long __cdecl GetLastErrorAsFailHRNoBreak(void)|long __cdecl GetLastErrorAsFailHRNoBreak(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetLastErrorAsFailHRNoBreak Calling Diff


```diff
--- NCoreLibrary::GetLastErrorAsFailHRNoBreak calling
+++ NCoreLibrary::GetLastErrorAsFailHRNoBreak calling
@@ -34,0 +35 @@
+`dynamic_initializer_for_'NRemoteNotify_Server::TRemoteNotifyHandle::s_NotifyListLock''
```


## Release

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|Release|Release|
|fullname|NCoreLibrary::TReferenceCount::Release|NCoreLibrary::TReferenceCount::Release|
|`refcount`|101|98|
|length|76|76|
|called|_guard_dispatch_icall$thunk$10345483385596137414|_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|<details><summary>Expand for full list:<br>CaptureUserInfo<br>InternalClosePrinter<br>IsCurrentUserLocalAdmin<br>NCoreLibrary::TGenericSP<RunnableWorkItem,NCoreLibrary::TRefPtrCOM<RunnableWorkItem>,RunnableWorkItem*___ptr64,0,RunnableWorkItem_const*___ptr64>::Reset<br>NRouter::TUserTokenTable::ReleaseTokens<br>NRouter::TUserTokenTable::TUserEntry::SetToken<br>NRouter::TUserTokenTable::TUserEntry::~TUserEntry<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Run</summary>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_><br>NThreadingLibrary::TWorkCrew::tpWaitCallback<br>PrinterPLM::Create<br>PrvClosePrinter<br>PrvEndDocPrinter<br>PrvRouterBroadcastMessage<br>PrvScheduleJob<br>PrvSetJobW<br>PrvSplProcessPnPEvent<br>PrvSplShutDownRouter<br>ReleasePushedConnectionProducerConsumerManager<br>RpcEnumPrinters<br>TFastCache<AddrInfoCacheEntry>::ExpireElement<br>TFastCache<NullCacheEntry>::ExpireElement<br>TFastCacheElement<AddrInfoCacheEntry>::UpdateElement<br>TFastCacheElement<NullCacheEntry>::UpdateElement<br>TNameResolutionCache::CacheGetAddrInfo<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::InternalCacheDnsQuery<br>TNameResolutionCache::InternalCacheGetAddrInfo<br>TNameResolutionCache::RefreshNode<br>TRemoteWinspool::RpcAsyncAbortPrinter<br>TRemoteWinspool::RpcAsyncAddForm<br>TRemoteWinspool::RpcAsyncAddJob<br>TRemoteWinspool::RpcAsyncAddMonitor<br>TRemoteWinspool::RpcAsyncAddPerMachineConnection<br>TRemoteWinspool::RpcAsyncAddPort<br>TRemoteWinspool::RpcAsyncAddPrintProcessor<br>TRemoteWinspool::RpcAsyncAddPrinter<br>TRemoteWinspool::RpcAsyncAddPrinterDriver<br>TRemoteWinspool::RpcAsyncCorePrinterDriverInstalled<br>TRemoteWinspool::RpcAsyncCreatePrinterIC<br>TRemoteWinspool::RpcAsyncDeleteForm<br>TRemoteWinspool::RpcAsyncDeleteMonitor<br>TRemoteWinspool::RpcAsyncDeletePerMachineConnection<br>TRemoteWinspool::RpcAsyncDeletePrintProcessor<br>TRemoteWinspool::RpcAsyncDeletePrinter<br>TRemoteWinspool::RpcAsyncDeletePrinterData<br>TRemoteWinspool::RpcAsyncDeletePrinterDataEx<br>TRemoteWinspool::RpcAsyncDeletePrinterDriver<br>TRemoteWinspool::RpcAsyncDeletePrinterDriverEx<br>TRemoteWinspool::RpcAsyncDeletePrinterDriverPackage<br>TRemoteWinspool::RpcAsyncDeletePrinterIC<br>TRemoteWinspool::RpcAsyncDeletePrinterKey<br>TRemoteWinspool::RpcAsyncEndDocPrinter<br>TRemoteWinspool::RpcAsyncEndPagePrinter<br>TRemoteWinspool::RpcAsyncEnumForms<br>TRemoteWinspool::RpcAsyncEnumJobs<br>TRemoteWinspool::RpcAsyncEnumMonitors<br>TRemoteWinspool::RpcAsyncEnumPerMachineConnections<br>TRemoteWinspool::RpcAsyncEnumPorts<br>TRemoteWinspool::RpcAsyncEnumPrintProcessorDatatypes<br>TRemoteWinspool::RpcAsyncEnumPrintProcessors<br>TRemoteWinspool::RpcAsyncEnumPrinterData<br>TRemoteWinspool::RpcAsyncEnumPrinterDataEx<br>TRemoteWinspool::RpcAsyncEnumPrinterDrivers<br>TRemoteWinspool::RpcAsyncEnumPrinterKey<br>TRemoteWinspool::RpcAsyncEnumPrinters<br>TRemoteWinspool::RpcAsyncGetCorePrinterDrivers<br>TRemoteWinspool::RpcAsyncGetForm<br>TRemoteWinspool::RpcAsyncGetJob<br>TRemoteWinspool::RpcAsyncGetPrintProcessorDirectory<br>TRemoteWinspool::RpcAsyncGetPrinterData<br>TRemoteWinspool::RpcAsyncGetPrinterDataEx<br>TRemoteWinspool::RpcAsyncGetPrinterDriver<br>TRemoteWinspool::RpcAsyncGetPrinterDriverDirectory<br>TRemoteWinspool::RpcAsyncGetPrinterDriverPackagePath<br>TRemoteWinspool::RpcAsyncInstallPrinterDriverFromPackage<br>TRemoteWinspool::RpcAsyncLogJobInfoForBranchOffice<br>TRemoteWinspool::RpcAsyncOpenPrinter<br>TRemoteWinspool::RpcAsyncPlayGdiScriptOnPrinterIC<br>TRemoteWinspool::RpcAsyncReadPrinter<br>TRemoteWinspool::RpcAsyncResetPrinter<br>TRemoteWinspool::RpcAsyncScheduleJob<br>TRemoteWinspool::RpcAsyncSendRecvBidiData<br>TRemoteWinspool::RpcAsyncSetForm<br>TRemoteWinspool::RpcAsyncSetJob<br>TRemoteWinspool::RpcAsyncSetPort<br>TRemoteWinspool::RpcAsyncSetPrinter<br>TRemoteWinspool::RpcAsyncSetPrinterData<br>TRemoteWinspool::RpcAsyncSetPrinterDataEx<br>TRemoteWinspool::RpcAsyncStartDocPrinter<br>TRemoteWinspool::RpcAsyncStartPagePrinter<br>TRemoteWinspool::RpcAsyncUploadPrinterDriverPackage<br>TRemoteWinspool::RpcAsyncWritePrinter<br>TRemoteWinspool::RpcAsyncXcvData<br>YClosePrinter</details>|<details><summary>Expand for full list:<br>CaptureUserInfo<br>InternalClosePrinter<br>NCoreLibrary::TGenericSP<RunnableWorkItem,NCoreLibrary::TRefPtrCOM<RunnableWorkItem>,RunnableWorkItem*___ptr64,0,RunnableWorkItem_const*___ptr64>::Reset<br>NRouter::TUserTokenTable::ReleaseTokens<br>NRouter::TUserTokenTable::TUserEntry::SetToken<br>NRouter::TUserTokenTable::TUserEntry::~TUserEntry<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Run<br>NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::~TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_><br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Enqueue<br>NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::~TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_></summary>NThreadingLibrary::TWorkCrew::tpWaitCallback<br>PrinterPLM::Create<br>PrvEndDocPrinter<br>PrvRouterBroadcastMessage<br>PrvScheduleJob<br>PrvSetJobW<br>PrvSplProcessPnPEvent<br>PrvSplShutDownRouter<br>ReleasePushedConnectionProducerConsumerManager<br>RpcEnumPrinters<br>TFastCache<AddrInfoCacheEntry>::ExpireElement<br>TFastCache<NullCacheEntry>::ExpireElement<br>TFastCacheElement<AddrInfoCacheEntry>::UpdateElement<br>TFastCacheElement<NullCacheEntry>::UpdateElement<br>TNameResolutionCache::CacheGetAddrInfo<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::InternalCacheDnsQuery<br>TNameResolutionCache::InternalCacheGetAddrInfo<br>TNameResolutionCache::RefreshNode<br>TRemoteWinspool::RpcAsyncAbortPrinter<br>TRemoteWinspool::RpcAsyncAddForm<br>TRemoteWinspool::RpcAsyncAddJob<br>TRemoteWinspool::RpcAsyncAddMonitor<br>TRemoteWinspool::RpcAsyncAddPerMachineConnection<br>TRemoteWinspool::RpcAsyncAddPort<br>TRemoteWinspool::RpcAsyncAddPrintProcessor<br>TRemoteWinspool::RpcAsyncAddPrinter<br>TRemoteWinspool::RpcAsyncAddPrinterDriver<br>TRemoteWinspool::RpcAsyncCorePrinterDriverInstalled<br>TRemoteWinspool::RpcAsyncCreatePrinterIC<br>TRemoteWinspool::RpcAsyncDeleteForm<br>TRemoteWinspool::RpcAsyncDeleteMonitor<br>TRemoteWinspool::RpcAsyncDeletePerMachineConnection<br>TRemoteWinspool::RpcAsyncDeletePrintProcessor<br>TRemoteWinspool::RpcAsyncDeletePrinter<br>TRemoteWinspool::RpcAsyncDeletePrinterData<br>TRemoteWinspool::RpcAsyncDeletePrinterDataEx<br>TRemoteWinspool::RpcAsyncDeletePrinterDriver<br>TRemoteWinspool::RpcAsyncDeletePrinterDriverEx<br>TRemoteWinspool::RpcAsyncDeletePrinterDriverPackage<br>TRemoteWinspool::RpcAsyncDeletePrinterIC<br>TRemoteWinspool::RpcAsyncDeletePrinterKey<br>TRemoteWinspool::RpcAsyncEndDocPrinter<br>TRemoteWinspool::RpcAsyncEndPagePrinter<br>TRemoteWinspool::RpcAsyncEnumForms<br>TRemoteWinspool::RpcAsyncEnumJobs<br>TRemoteWinspool::RpcAsyncEnumMonitors<br>TRemoteWinspool::RpcAsyncEnumPerMachineConnections<br>TRemoteWinspool::RpcAsyncEnumPorts<br>TRemoteWinspool::RpcAsyncEnumPrintProcessorDatatypes<br>TRemoteWinspool::RpcAsyncEnumPrintProcessors<br>TRemoteWinspool::RpcAsyncEnumPrinterData<br>TRemoteWinspool::RpcAsyncEnumPrinterDataEx<br>TRemoteWinspool::RpcAsyncEnumPrinterDrivers<br>TRemoteWinspool::RpcAsyncEnumPrinterKey<br>TRemoteWinspool::RpcAsyncEnumPrinters<br>TRemoteWinspool::RpcAsyncGetCorePrinterDrivers<br>TRemoteWinspool::RpcAsyncGetForm<br>TRemoteWinspool::RpcAsyncGetJob<br>TRemoteWinspool::RpcAsyncGetPrintProcessorDirectory<br>TRemoteWinspool::RpcAsyncGetPrinterData<br>TRemoteWinspool::RpcAsyncGetPrinterDataEx<br>TRemoteWinspool::RpcAsyncGetPrinterDriver<br>TRemoteWinspool::RpcAsyncGetPrinterDriverDirectory<br>TRemoteWinspool::RpcAsyncGetPrinterDriverPackagePath<br>TRemoteWinspool::RpcAsyncInstallPrinterDriverFromPackage<br>TRemoteWinspool::RpcAsyncLogJobInfoForBranchOffice<br>TRemoteWinspool::RpcAsyncOpenPrinter<br>TRemoteWinspool::RpcAsyncPlayGdiScriptOnPrinterIC<br>TRemoteWinspool::RpcAsyncReadPrinter<br>TRemoteWinspool::RpcAsyncResetPrinter<br>TRemoteWinspool::RpcAsyncScheduleJob<br>TRemoteWinspool::RpcAsyncSendRecvBidiData<br>TRemoteWinspool::RpcAsyncSetForm<br>TRemoteWinspool::RpcAsyncSetJob<br>TRemoteWinspool::RpcAsyncSetPort<br>TRemoteWinspool::RpcAsyncSetPrinter<br>TRemoteWinspool::RpcAsyncSetPrinterData<br>TRemoteWinspool::RpcAsyncSetPrinterDataEx<br>TRemoteWinspool::RpcAsyncStartDocPrinter<br>TRemoteWinspool::RpcAsyncStartPagePrinter<br>TRemoteWinspool::RpcAsyncUploadPrinterDriverPackage<br>TRemoteWinspool::RpcAsyncWritePrinter<br>TRemoteWinspool::RpcAsyncXcvData</details>|
|paramcount|1|1|
|`address`|140008af0|140008cd0|
|sig|long __thiscall Release(TReferenceCount * this)|long __thiscall Release(TReferenceCount * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### Release Calling Diff


```diff
--- NCoreLibrary::TReferenceCount::Release calling
+++ NCoreLibrary::TReferenceCount::Release calling
@@ -3 +2,0 @@
-IsCurrentUserLocalAdmin
@@ -8,0 +8 @@
+NThreadingLibrary::TProducerConsumerManager<TBroadcastMessage,NCoreLibrary::TFifoQueue<TBroadcastMessage*___ptr64>_>::Run
@@ -11 +10,0 @@
-NThreadingLibrary::TProducerConsumerManager<TPrinterConnectionEvent,NCoreLibrary::TFifoQueue<TPrinterConnectionEvent*___ptr64>_>::Run
@@ -15 +13,0 @@
-PrvClosePrinter
@@ -98 +95,0 @@
-YClosePrinter
```


## CreateRemoteNotifyData

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|CreateRemoteNotifyData|CreateRemoteNotifyData|
|fullname|NRemoteNotify_Library::CreateRemoteNotifyData|NRemoteNotify_Library::CreateRemoteNotifyData|
|`refcount`|4|5|
|length|296|296|
|called|NRemoteNotify_Library::FreePropertyCollection<br>PrvAllocSplStr<br>PrvDllAllocSplMem|NRemoteNotify_Library::FreePropertyCollection<br>PrvAllocSplStr<br>PrvDllAllocSplMem|
|calling|NRemoteNotify_Router::TRemoteNotifyChannel::EnqueueData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>ThreadNotifyProcessJob|NRemoteNotify_Router::TRemoteNotifyChannel::EnqueueData<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>ThreadNotifyProcessJob|
|paramcount|4|4|
|`address`|14007ab98|14007b038|
|sig|long __cdecl CreateRemoteNotifyData(ulong param_1, ulong param_2, _RPC_V2_NOTIFY_INFO * param_3, __MIDL_winspool_0021 * * param_4)|long __cdecl CreateRemoteNotifyData(ulong param_1, ulong param_2, _RPC_V2_NOTIFY_INFO * param_3, __MIDL_winspool_0021 * * param_4)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

## API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|SetLastError|SetLastError|
|fullname|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError|
|`refcount`|278|275|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>?NullAddPort@@YAHPEAGPEAUHWND__@@0@Z<br>ALLOCMEM<br>AddJobWorkerW<br>BasicMarshallDownStructure<br>BasicMarshallUpStructure<br>BoolFromHResult<br>ChooseDefaultPrinter<br>CustomMarshallDownEntry<br>CustomMarshallUpEntry<br>DeleteSubKeyTree<br>FindFirstPrinterChangeNotificationWorker</summary>FindProvidor<br>GetCachedDefaultDevModeAndSize<br>GetPortInfo2UsingPortInfo1<br>GetUniqueSessionKey<br>InternalClosePrinter<br>InternalGetDefaultPrinter<br>InternalSetDefaultPrinter<br>IsCurrentUserLocalAdmin<br>LPatchUserDevmodes<br>MarshallUpStructuresArrayWithPointerOffset<br>NCOMLibrary::ComLeakCleaner::Cleanup<br>NCOMLibrary::ComLeakCleaner::ComLeakCleaner<br>NCoreLibrary::FromHResult<br>NSecurityLibrary::ElevateIntegrityLevelIfLowDirectly<br>NullClusterSplIsAlive<br>NullDeletePrinterDriver<br>NullInternalGetPrinterDriver<br>NullReportJobProcessingProgress<br>OpenPrinterExW<br>PrinterPLM::~PrinterPLM<br>PrvAbortPrinter<br>PrvAddFormW<br>PrvAddJobW<br>PrvAddMonitorW<br>PrvAddPortExW<br>PrvAddPortW<br>PrvAddPrintProcessorW<br>PrvAddPrintProvidorW<br>PrvAddPrinterDriverExW<br>PrvAddPrinterDriverW<br>PrvAddPrinterExW<br>PrvAllocSplStr<br>PrvAppendPrinterNotifyInfoData<br>PrvBuildOtherNamesFromMachineName<br>PrvCheckLocalCall<br>PrvClosePrinter<br>PrvConfigurePortW<br>PrvCreatePrinterIC<br>PrvDeleteFormW<br>PrvDeletePortW<br>PrvDeletePrintProvidorW<br>PrvDeletePrinter<br>PrvDeletePrinterDataExW<br>PrvDeletePrinterDataW<br>PrvDeletePrinterIC<br>PrvDeletePrinterKeyW<br>PrvDllAllocSplMem<br>PrvEndDocPrinter<br>PrvEndPagePrinter<br>PrvEnumFormsW<br>PrvEnumJobsW<br>PrvEnumMonitorsW<br>PrvEnumPerMachineConnectionsW<br>PrvEnumPortsW<br>PrvEnumPrintProcessorDatatypesW<br>PrvEnumPrintProcessorsW<br>PrvEnumPrinterDataExW<br>PrvEnumPrinterDataW<br>PrvEnumPrinterDriversW<br>PrvEnumPrinterKeyW<br>PrvEnumPrintersW<br>PrvFindClosePrinterChangeNotification<br>PrvFlushPrinter<br>PrvGetFormW<br>PrvGetJobAttributesEx<br>PrvGetJobW<br>PrvGetPrintProcessorDirectoryW<br>PrvGetPrinterDataExW<br>PrvGetPrinterDataW<br>PrvGetPrinterDriverDirectoryW<br>PrvGetPrinterDriverExW<br>PrvGetPrinterDriverW<br>PrvGetPrinterW<br>PrvGetShrinkedSize<br>PrvImpersonatePrinterClient<br>PrvMarshallDownStructure<br>PrvMarshallDownStructuresArray<br>PrvMarshallUpStructure<br>PrvOldGetPrinterDriverW<br>PrvOpenPrinter2W<br>PrvPartialReplyPrinterChangeNotification<br>PrvPlayGdiScriptOnPrinterIC<br>PrvPrinterMessageBoxW<br>PrvReadPrinter<br>PrvReplyClosePrinter<br>PrvReplyOpenPrinter<br>PrvResetPrinterW<br>PrvRevertToPrinterSelf<br>PrvRouterAddPrinterConnection2<br>PrvRouterFindNextPrinterChangeNotification<br>PrvRouterInstallPrinterDriverPackageFromConnection<br>PrvRouterRefreshPrinterChangeNotification<br>PrvRouterReplyPrinter<br>PrvScheduleJob<br>PrvSeekPrinter<br>PrvSetFormW<br>PrvSetJobW<br>PrvSetPrinterDataExW<br>PrvSetPrinterDataW<br>PrvSetPrinterW<br>PrvSplCloseSpoolFileHandle<br>PrvSplCommitSpoolData<br>PrvSplGetClientUserHandle<br>PrvSplGetSpoolFileInfo<br>PrvSplPromptUIInUsersSession<br>PrvSplReadPrinter<br>PrvSplRegisterForSessionEvents<br>PrvSpoolerFindFirstPrinterChangeNotification<br>PrvStartDocPrinterW<br>PrvStartPagePrinter<br>PrvUpdatePrinterRegUser<br>PrvWaitForPrinterChange<br>PrvWritePrinter<br>PrvXcvDataW<br>PrvbGetDevModePerUser<br>PrvbSetDevModePerUser<br>ReadPrinters<br>RegOpenConnectionKey<br>ReplyPrinterChangeNotificationWorker<br>RouterOpenPrinterW<br>RpcAddPrinterConnection<br>RpcClientFindFirstPrinterChangeNotification<br>RpcEnumForms<br>RpcGetPrinterData<br>RpcGetPrinterDriver2<br>RpcRemoteFindFirstPrinterChangeNotificationEx<br>RpcSplOpenPrinter<br>RpcWritePrinter<br>SetupChange<br>SetupChangeBehavior<br>SetupClientInfo<br>SetupReplyNotification<br>SplCommitSpoolDataWorker<br>SplLibTelemetry::DefaultPrinterChanged<br>SpoolerInitAll<br>StartDocPrinterWorkerW<br>StrCatAlloc<br>StrNCatBuff<br>TNameResolutionCache::AddName<br>UpdateMRUPrinterIfApplicable<br>UpdateProvidorOrder<br>YAddPortEx<br>YAddPrinterDriver<br>YAddPrinterDriverEx<br>YClosePrinter<br>YEnumForms<br>YEnumPrinterDataEx<br>YGetJob<br>YGetPrinter<br>YGetPrinterData<br>YGetPrinterDataEx<br>YGetPrinterDriver2<br>YImpersonateClient<br>YOpenPrinterEx<br>YRevertToSelf<br>YSeekPrinter<br>YSetPort<br>YSetPrinterData<br>bGetDevModeLocation<br>sandbox::DocumentPropertiesAdapter::DocumentPropertiesW<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>wil::last_error_context::~last_error_context</details>|<details><summary>Expand for full list:<br>?NullAddPrinterConnection@@YAHPEAG@Z<br>ALLOCMEM<br>AddJobWorkerW<br>BasicMarshallDownStructure<br>BasicMarshallUpStructure<br>BoolFromHResult<br>ChooseDefaultPrinter<br>CustomMarshallDownEntry<br>CustomMarshallUpEntry<br>DeleteSubKeyTree<br>FindFirstPrinterChangeNotificationWorker</summary>FindProvidor<br>GetCachedDefaultDevModeAndSize<br>GetPortInfo2UsingPortInfo1<br>GetUniqueSessionKey<br>InternalClosePrinter<br>InternalGetDefaultPrinter<br>InternalSetDefaultPrinter<br>LPatchUserDevmodes<br>MarshallUpStructuresArrayWithPointerOffset<br>NCOMLibrary::ComLeakCleaner::Cleanup<br>NCOMLibrary::ComLeakCleaner::ComLeakCleaner<br>NCoreLibrary::FromHResult<br>NSecurityLibrary::ElevateIntegrityLevelIfLowDirectly<br>NullClusterSplIsAlive<br>NullDeletePrinterDriver<br>NullInternalGetPrinterDriver<br>NullReportJobProcessingProgress<br>OpenPrinterExW<br>PrinterPLM::~PrinterPLM<br>PrvAbortPrinter<br>PrvAddFormW<br>PrvAddJobW<br>PrvAddMonitorW<br>PrvAddPortExW<br>PrvAddPortW<br>PrvAddPrintProcessorW<br>PrvAddPrintProvidorW<br>PrvAddPrinterDriverExW<br>PrvAddPrinterDriverW<br>PrvAddPrinterExW<br>PrvAllocSplStr<br>PrvAppendPrinterNotifyInfoData<br>PrvBuildOtherNamesFromMachineName<br>PrvCheckLocalCall<br>PrvConfigurePortW<br>PrvCreatePrinterIC<br>PrvDeleteFormW<br>PrvDeletePortW<br>PrvDeletePrintProvidorW<br>PrvDeletePrinter<br>PrvDeletePrinterDataExW<br>PrvDeletePrinterDataW<br>PrvDeletePrinterIC<br>PrvDeletePrinterKeyW<br>PrvDllAllocSplMem<br>PrvEndDocPrinter<br>PrvEndPagePrinter<br>PrvEnumFormsW<br>PrvEnumJobsW<br>PrvEnumMonitorsW<br>PrvEnumPerMachineConnectionsW<br>PrvEnumPortsW<br>PrvEnumPrintProcessorDatatypesW<br>PrvEnumPrintProcessorsW<br>PrvEnumPrinterDataExW<br>PrvEnumPrinterDataW<br>PrvEnumPrinterDriversW<br>PrvEnumPrinterKeyW<br>PrvEnumPrintersW<br>PrvFindClosePrinterChangeNotification<br>PrvFlushPrinter<br>PrvGetFormW<br>PrvGetJobAttributesEx<br>PrvGetJobW<br>PrvGetPrintProcessorDirectoryW<br>PrvGetPrinterDataExW<br>PrvGetPrinterDataW<br>PrvGetPrinterDriverDirectoryW<br>PrvGetPrinterDriverExW<br>PrvGetPrinterDriverW<br>PrvGetPrinterW<br>PrvGetShrinkedSize<br>PrvImpersonatePrinterClient<br>PrvMarshallDownStructure<br>PrvMarshallDownStructuresArray<br>PrvMarshallUpStructure<br>PrvOldGetPrinterDriverW<br>PrvOpenPrinter2W<br>PrvPartialReplyPrinterChangeNotification<br>PrvPlayGdiScriptOnPrinterIC<br>PrvPrinterMessageBoxW<br>PrvReadPrinter<br>PrvReplyClosePrinter<br>PrvReplyOpenPrinter<br>PrvResetPrinterW<br>PrvRevertToPrinterSelf<br>PrvRouterAddPrinterConnection2<br>PrvRouterFindNextPrinterChangeNotification<br>PrvRouterInstallPrinterDriverPackageFromConnection<br>PrvRouterRefreshPrinterChangeNotification<br>PrvRouterReplyPrinter<br>PrvScheduleJob<br>PrvSeekPrinter<br>PrvSetFormW<br>PrvSetJobW<br>PrvSetPrinterDataExW<br>PrvSetPrinterDataW<br>PrvSetPrinterW<br>PrvSplCloseSpoolFileHandle<br>PrvSplCommitSpoolData<br>PrvSplGetClientUserHandle<br>PrvSplGetSpoolFileInfo<br>PrvSplPromptUIInUsersSession<br>PrvSplReadPrinter<br>PrvSplRegisterForSessionEvents<br>PrvSpoolerFindFirstPrinterChangeNotification<br>PrvStartDocPrinterW<br>PrvStartPagePrinter<br>PrvUpdatePrinterRegUser<br>PrvWaitForPrinterChange<br>PrvWritePrinter<br>PrvXcvDataW<br>PrvbGetDevModePerUser<br>PrvbSetDevModePerUser<br>ReadPrinters<br>RegOpenConnectionKey<br>ReplyPrinterChangeNotificationWorker<br>RouterOpenPrinterW<br>RpcAddPrinterConnection<br>RpcClientFindFirstPrinterChangeNotification<br>RpcEnumForms<br>RpcGetPrinterData<br>RpcGetPrinterDriver2<br>RpcRemoteFindFirstPrinterChangeNotificationEx<br>RpcSplOpenPrinter<br>RpcWritePrinter<br>SetupChange<br>SetupChangeBehavior<br>SetupClientInfo<br>SetupReplyNotification<br>SplCommitSpoolDataWorker<br>SplLibTelemetry::DefaultPrinterChanged<br>SpoolerInitAll<br>StartDocPrinterWorkerW<br>StrCatAlloc<br>StrNCatBuff<br>TNameResolutionCache::AddName<br>UpdateMRUPrinterIfApplicable<br>UpdateProvidorOrder<br>YAddPortEx<br>YAddPrinterDriver<br>YAddPrinterDriverEx<br>YClosePrinter<br>YEnumForms<br>YEnumPrinterDataEx<br>YGetJob<br>YGetPrinter<br>YGetPrinterData<br>YGetPrinterDataEx<br>YGetPrinterDriver2<br>YImpersonateClient<br>YOpenPrinterEx<br>YRevertToSelf<br>YSeekPrinter<br>YSetPort<br>YSetPrinterData<br>bGetDevModeLocation<br>sandbox::DocumentPropertiesAdapter::DocumentPropertiesW<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>sandbox::DriverJobAttributesAdapter::QueryAttributes<br>wil::last_error_context::~last_error_context</details>|
|paramcount|1|1|
|`address`|EXTERNAL:000000ad|EXTERNAL:000000a9|
|sig|void __stdcall SetLastError(DWORD dwErrCode)|void __stdcall SetLastError(DWORD dwErrCode)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError Calling Diff


```diff
--- API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError calling
+++ API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError calling
@@ -1 +1 @@
-?NullAddPort@@YAHPEAGPEAUHWND__@@0@Z
+?NullAddPrinterConnection@@YAHPEAG@Z
@@ -19 +18,0 @@
-IsCurrentUserLocalAdmin
@@ -47 +45,0 @@
-PrvClosePrinter
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|name|LeaveCriticalSection|LeaveCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|
|`refcount`|108|105|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>AcquireBroadcastProducerConsumerManager<br>AcquirePushedConnectionProducerConsumerManager<br>CaptureUserInfo<br>DemandStart::IdleThread<br>FailChange<br>FindClosePrinterChangeNotificationWorker<br>FindFirstPrinterChangeNotificationWorker<br>FreeChange<br>FreePrinterHandle<br>HandlePollNotifications<br>InternalAddPerMachineConnection</summary>InternalClosePrinter<br>InternalDeletePerMachineConnection<br>InternalEnumPerMachineConnections<br>IsCurrentUserLocalAdmin<br>NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications<br>NRouter::AcquireRouterWorkCrew<br>NRouter::InitializeRouterWorkCrew<br>NRouter::TUserTokenTable::AddSession<br>NThreadingLibrary::TWorkCrew::AddItem<br>NThreadingLibrary::TWorkCrew::CancelWorkThread<br>NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue<br>NThreadingLibrary::TWorkCrew::tpSimpleCallback<br>PrvAddPrintProvidorW<br>PrvAppendPrinterNotifyInfoData<br>PrvCacheIsNameInNodeList<br>PrvCallRouterFindFirstPrinterChangeNotification<br>PrvClosePrinter<br>PrvDeletePrintProvidorW<br>PrvFindClosePrinterChangeNotification<br>PrvIsNameTheLocalMachineOrAClusterSpooler<br>PrvPartialReplyPrinterChangeNotification<br>PrvProvidorFindFirstPrinterChangeNotification<br>PrvRemoteFindFirstPrinterChangeNotification<br>PrvReplyClosePrinter<br>PrvReplyOpenPrinter<br>PrvRouterBroadcastMessage<br>PrvRouterFindNextPrinterChangeNotification<br>PrvRouterRefreshPrinterChangeNotification<br>PrvRouterReplyPrinter<br>PrvSplRegisterForDeviceEvents<br>PrvSplShutDownRouter<br>PrvSplUnregisterForDeviceEvents<br>QueryRemove<br>ReenumeratePortsThread<br>ReplyPrinterChangeNotificationWorker<br>ReplyToChangeCallback<br>RouterOpenPrinterW<br>SetupChange<br>SetupChangeBehavior<br>SetupReplyNotification<br>SplSqmCounter::Add<br>SplSqmCounter::SqmCollect<br>SpoolerBeginForcedShutdown<br>SpoolerShutdown<br>SpoolerStatusUpdate<br>Spooler_WindowsProtectedPrintMain<br>TFastCache<NullCacheEntry>::IsStringInCache<br>TMAddJob<br>TMDestroy<br>TNameResolutionCache::AddName<br>TNameResolutionCache::CheckIfNameIsInNodeCacheUsingIp<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::IsNameCluster<br>TPrintProviderEnumerator::GetRouterCachePrintProvider<br>TPrintProviderEnumerator::TRoutableMethodsTable::GetPrintProviderFromConnection<br>TPrintProviderEnumerator::TRoutableMethodsTable::~TRoutableMethodsTable<br>ThreadNotify<br>ThreadNotifyNextJob<br>ThreadNotifyProcessJob<br>TryOpenPrinterAndCache<br>YClosePrinter<br>_Init_thread_footer<br>_Init_thread_wait_v2<br>sandbox::SandboxConnection::ResetInternalPointer<br>sandbox::SandboxConnection::ValidateInternalPointer<br>wil::details::unique_storage<wil::details::resource_policy<_RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(_RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_CRITICAL_SECTION*___ptr64,_RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(_RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_CRITICAL_SECTION*___ptr64,_RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_><br>xTMThreadProc</details>|<details><summary>Expand for full list:<br>AcquireBroadcastProducerConsumerManager<br>AcquirePushedConnectionProducerConsumerManager<br>CaptureUserInfo<br>DemandStart::IdleThread<br>FailChange<br>FindClosePrinterChangeNotificationWorker<br>FindFirstPrinterChangeNotificationWorker<br>FreeChange<br>FreePrinterHandle<br>HandlePollNotifications<br>InternalAddPerMachineConnection</summary>InternalClosePrinter<br>InternalDeletePerMachineConnection<br>InternalEnumPerMachineConnections<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications<br>NRouter::AcquireRouterWorkCrew<br>NRouter::InitializeRouterWorkCrew<br>NRouter::TUserTokenTable::AddSession<br>NThreadingLibrary::TWorkCrew::AddItem<br>NThreadingLibrary::TWorkCrew::CancelWorkThread<br>NThreadingLibrary::TWorkCrew::MoveWorkItemToCancelQueue<br>NThreadingLibrary::TWorkCrew::tpSimpleCallback<br>PrvAddPrintProvidorW<br>PrvAppendPrinterNotifyInfoData<br>PrvCacheIsNameInNodeList<br>PrvCallRouterFindFirstPrinterChangeNotification<br>PrvDeletePrintProvidorW<br>PrvFindClosePrinterChangeNotification<br>PrvIsNameTheLocalMachineOrAClusterSpooler<br>PrvPartialReplyPrinterChangeNotification<br>PrvProvidorFindFirstPrinterChangeNotification<br>PrvRemoteFindFirstPrinterChangeNotification<br>PrvReplyClosePrinter<br>PrvReplyOpenPrinter<br>PrvRouterBroadcastMessage<br>PrvRouterFindNextPrinterChangeNotification<br>PrvRouterRefreshPrinterChangeNotification<br>PrvRouterReplyPrinter<br>PrvSplRegisterForDeviceEvents<br>PrvSplShutDownRouter<br>PrvSplUnregisterForDeviceEvents<br>QueryRemove<br>ReenumeratePortsThread<br>ReplyPrinterChangeNotificationWorker<br>ReplyToChangeCallback<br>RouterOpenPrinterW<br>SetupChange<br>SetupChangeBehavior<br>SetupReplyNotification<br>SplSqmCounter::Add<br>SplSqmCounter::SqmCollect<br>SpoolerBeginForcedShutdown<br>SpoolerShutdown<br>SpoolerStatusUpdate<br>Spooler_WindowsProtectedPrintMain<br>TFastCache<NullCacheEntry>::IsStringInCache<br>TMAddJob<br>TMDestroy<br>TNameResolutionCache::AddName<br>TNameResolutionCache::CheckIfNameIsInNodeCacheUsingIp<br>TNameResolutionCache::CreateAndAddNode<br>TNameResolutionCache::IsNameCluster<br>TPrintProviderEnumerator::GetRouterCachePrintProvider<br>TPrintProviderEnumerator::TRoutableMethodsTable::GetPrintProviderFromConnection<br>TPrintProviderEnumerator::TRoutableMethodsTable::~TRoutableMethodsTable<br>ThreadNotify<br>ThreadNotifyNextJob<br>ThreadNotifyProcessJob<br>TryOpenPrinterAndCache<br>_Init_thread_footer<br>_Init_thread_wait_v2<br>sandbox::SandboxConnection::ResetInternalPointer<br>sandbox::SandboxConnection::ValidateInternalPointer<br>wil::details::unique_storage<wil::details::resource_policy<_RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(_RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_CRITICAL_SECTION*___ptr64,_RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(_RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_CRITICAL_SECTION*___ptr64,_RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_><br>xTMThreadProc</details>|
|paramcount|1|1|
|`address`|EXTERNAL:00000092|EXTERNAL:0000009c|
|sig|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection calling
@@ -15 +15 @@
-IsCurrentUserLocalAdmin
+NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
@@ -28 +27,0 @@
-PrvClosePrinter
@@ -72 +70,0 @@
-YClosePrinter
```


## _guard_dispatch_icall

### Match Info



|Key|spoolsv-06.exe - spoolsv-07.exe|
| :---: | :---: |
|diff_type|name,fullname,refcount,length,sig,address,calling,called,parent|
|ratio|0.42|
|i_ratio|0.0|
|m_ratio|0.12|
|b_ratio|0.0|
|match_types|Implied Match|

### Function Meta Diff



|Key|spoolsv-06.exe|spoolsv-07.exe|
| :---: | :---: | :---: |
|`name`|_guard_dispatch_icall|__private_IsEnabled|
|`fullname`|_guard_dispatch_icall|wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled|
|`refcount`|6|13|
|`length`|2|53|
|`called`||wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState<br>wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage|
|`calling`||FreeChange<br>InternalClosePrinter<br>NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications<br>NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications<br>PrvRouterFindNextPrinterChangeNotification<br>PrvRouterRefreshPrinterChangeNotification<br>WPCInit|
|paramcount|0|1|
|`address`|140082df0|140049388|
|`sig`|undefined __fastcall _guard_dispatch_icall(void)|bool __thiscall __private_IsEnabled(FeatureImpl<__WilFeatureTraits_Feature_1137672506> * this)|
|sym_type|Function|Function|
|sym_source|IMPORTED|ANALYSIS|
|external|False|False|

### _guard_dispatch_icall Called Diff


```diff
--- _guard_dispatch_icall called
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled called
@@ -0,0 +1,2 @@
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::GetCachedFeatureEnabledState
+wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::ReportUsage
```


### _guard_dispatch_icall Calling Diff


```diff
--- _guard_dispatch_icall calling
+++ wil::details::FeatureImpl<__WilFeatureTraits_Feature_1137672506>::__private_IsEnabled calling
@@ -0,0 +1,9 @@
+FreeChange
+InternalClosePrinter
+NRemoteNotify_Server::TRemoteNotifyServer::AsyncGetNotifications
+NRemoteNotify_Server::TRemoteNotifyServer::RefreshNotifications
+NRemoteNotify_Server::TRemoteNotifyServer::RegisterForNotifications
+NRemoteNotify_Server::TRemoteNotifyServer::UnRegisterForNotifications
+PrvRouterFindNextPrinterChangeNotification
+PrvRouterRefreshPrinterChangeNotification
+WPCInit
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-28T16:12:26</sub>