# storvsp.sys 26100.5074 vs 26100.7171 (CVE-2025-59516, manual pair)

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
* [Modified](#modified)
	* [VspVsmbFileIoctlVstorVsmbOpenFileValidate](#vspvsmbfileioctlvstorvsmbopenfilevalidate)
	* [VspIsValidSgRequest](#vspisvalidsgrequest)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [VspStartJob](#vspstartjob)

# Visual Chart Diff



```mermaid

flowchart LR

VspVsmbFileIoctlVstorVsmbOpenFileValidate-3-old<--Match 83%-->VspVsmbFileIoctlVstorVsmbOpenFileValidate-3-new
VspIsValidSgRequest-1-old<--Match 61%-->VspIsValidSgRequest-1-new

subgraph storvsp-10.0.26100.7171.sys
    VspVsmbFileIoctlVstorVsmbOpenFileValidate-3-new
VspIsValidSgRequest-1-new
    
end

subgraph storvsp-10.0.26100.5074.sys
    VspVsmbFileIoctlVstorVsmbOpenFileValidate-3-old
VspIsValidSgRequest-1-old
    
end

```


```mermaid
pie showData
    title Function Matches - 100.0000%
"unmatched_funcs_len" : 0
"matched_funcs_len" : 1386
```



```mermaid
pie showData
    title Matched Function Similarity - 99.6392%
"matched_funcs_with_code_changes_len" : 2
"matched_funcs_with_non_code_changes_len" : 3
"matched_funcs_no_changes_len" : 1381
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2025-59516\ghidra_projects --project-name CVE-2025-59516 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2025-59516\symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 --md-title storvsp.sys 26100.5074 vs 26100.7171 (CVE-2025-59516, manual pair) storvsp-10.0.26100.5074.sys storvsp-10.0.26100.7171.sys
```


#### Verbose Args


<details>

```
--old ['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2025-59516\\storvsp-10.0.26100.5074.sys'] --new [['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2025-59516\\storvsp-10.0.26100.7171.sys']] --engine VersionTrackingDiff --output-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2025-59516\output --summary False --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2025-59516\ghidra_projects --project-name CVE-2025-59516 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2025-59516\symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title storvsp.sys 26100.5074 vs 26100.7171 (CVE-2025-59516, manual pair)
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/storvsp.sys/A36F49704A000/storvsp.sys -O storvsp.sys.x64.10.0.26100.5074
wget https://msdl.microsoft.com/download/symbols/storvsp.sys/1B57A4EF4A000/storvsp.sys -O storvsp.sys.x64.10.0.26100.7171
```


## Binary Metadata Diff


```diff
--- storvsp-10.0.26100.5074.sys Meta
+++ storvsp-10.0.26100.7171.sys Meta
@@ -1,44 +1,44 @@
-Program Name: storvsp-10.0.26100.5074.sys
+Program Name: storvsp-10.0.26100.7171.sys
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 140000000
 Maximum Address: ff0000184f
 # of Bytes: 306824
 # of Memory Blocks: 14
-# of Instructions: 32946
-# of Defined Data: 6432
+# of Instructions: 32922
+# of Defined Data: 6602
 # of Functions: 693
-# of Symbols: 7498
+# of Symbols: 7672
 # of Data Types: 363
 # of Data Type Categories: 14
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Tue Jul 28 09:45:47 SGT 2026
+Date Created: Tue Jul 28 09:45:53 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2025-59516/storvsp-10.0.26100.5074.sys
-Executable MD5: cf63746aaa763a061ab572c3559a3ab9
-Executable SHA256: 053324dea4af932c81859635776a0a7c3bebc90251ba756ff3c7a0c7e4ddd8ef
-FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2025-59516/storvsp-10.0.26100.5074.sys?MD5=cf63746aaa763a061ab572c3559a3ab9
+Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2025-59516/storvsp-10.0.26100.7171.sys
+Executable MD5: fe47e9ed34f69fd6ef1977b247cb65b3
+Executable SHA256: be64b471dd527483387f613b6b1676eb4be0dc36f9105d54f613cf071d2649ce
+FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2025-59516/storvsp-10.0.26100.7171.sys?MD5=fe47e9ed34f69fd6ef1977b247cb65b3
 PDB Age: 1
 PDB File: storvsp.pdb
-PDB GUID: 82cb0d2b-d7d9-eaf2-254c-397ce48c80b0
+PDB GUID: 624a1050-28e4-882d-f56b-eeb359e915cf
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Storage vsp Driver
-PE Property[FileVersion]: 10.0.26100.5074 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.7171 (WinBuild.160101.0800)
 PE Property[InternalName]: storvsp.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: storvsp.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.5074
+PE Property[ProductVersion]: 10.0.26100.7171
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra storvsp-10.0.26100.5074.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra storvsp-10.0.26100.5074.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra storvsp-10.0.26100.5074.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra storvsp-10.0.26100.7171.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra storvsp-10.0.26100.7171.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra storvsp-10.0.26100.7171.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|0|
|deleted_funcs_len|0|
|modified_funcs_len|5|
|added_symbols_len|4|
|deleted_symbols_len|4|
|diff_time|14.09982943534851|
|deleted_strings_len|0|
|added_strings_len|2|
|match_types|Counter({'SymbolsHash': 690, 'ExternalsName': 243, 'ExactInstructionsFunctionHasher': 2})|
|items_to_process|13|
|diff_types|Counter({'address': 4, 'length': 3, 'called': 3, 'code': 2, 'refcount': 2, 'calling': 2, 'name': 1, 'fullname': 1, 'sig': 1})|
|unmatched_funcs_len|0|
|total_funcs_len|1386|
|matched_funcs_len|1386|
|matched_funcs_with_code_changes_len|2|
|matched_funcs_with_non_code_changes_len|3|
|matched_funcs_no_changes_len|1381|
|match_func_similarity_percent|99.6392%|
|func_match_overall_percent|100.0000%|
|first_matches|Counter({'SymbolsHash': 690, 'ExactInstructionsFunctionHasher': 2})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 690
"ExternalsName" : 243
"ExactInstructionsFunctionHasher" : 2
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 690
"ExactInstructionsFunctionHasher" : 2
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 0
"deleted_funcs_len" : 0
"modified_funcs_len" : 5
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 4
"deleted_symbols_len" : 4
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 2
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1,2 @@
+s_No_device_associated_while_vali
+s_VspIsValidSgRequest

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_No_device_associated_while_vali|2|VspIsValidSgRequest|
|s_VspIsValidSgRequest|1|VspIsValidSgRequest|

# Deleted

# Added

# Modified


*Modified functions contain code changes*
## VspVsmbFileIoctlVstorVsmbOpenFileValidate

### Match Info



|Key|storvsp-10.0.26100.5074.sys - storvsp-10.0.26100.7171.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.18|
|i_ratio|0.2|
|m_ratio|0.86|
|b_ratio|0.83|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|storvsp-10.0.26100.5074.sys|storvsp-10.0.26100.7171.sys|
| :---: | :---: | :---: |
|name|VspVsmbFileIoctlVstorVsmbOpenFileValidate|VspVsmbFileIoctlVstorVsmbOpenFileValidate|
|fullname|VspVsmbFileIoctlVstorVsmbOpenFileValidate|VspVsmbFileIoctlVstorVsmbOpenFileValidate|
|refcount|2|2|
|`length`|807|629|
|`called`|Feature_2561731899__private_IsEnabledDeviceUsageNoInline<br>StorVspTrace|StorVspTrace|
|calling|VspVsmbHandleRelativeCreateFileRequest|VspVsmbHandleRelativeCreateFileRequest|
|paramcount|3|3|
|`address`|140008430|140008440|
|sig|long __cdecl VspVsmbFileIoctlVstorVsmbOpenFileValidate(_VSTOR_VSMB_OPEN_FILE_REQUEST * param_1, uint param_2, uint param_3)|long __cdecl VspVsmbFileIoctlVstorVsmbOpenFileValidate(_VSTOR_VSMB_OPEN_FILE_REQUEST * param_1, uint param_2, uint param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### VspVsmbFileIoctlVstorVsmbOpenFileValidate Called Diff


```diff
--- VspVsmbFileIoctlVstorVsmbOpenFileValidate called
+++ VspVsmbFileIoctlVstorVsmbOpenFileValidate called
@@ -1 +0,0 @@
-Feature_2561731899__private_IsEnabledDeviceUsageNoInline
```


### VspVsmbFileIoctlVstorVsmbOpenFileValidate Diff


```diff
--- VspVsmbFileIoctlVstorVsmbOpenFileValidate
+++ VspVsmbFileIoctlVstorVsmbOpenFileValidate
@@ -1,223 +1,181 @@
 
 /* long __cdecl VspVsmbFileIoctlVstorVsmbOpenFileValidate(struct _VSTOR_VSMB_OPEN_FILE_REQUEST const
    * __ptr64,unsigned int,unsigned int) */
 
 long __cdecl
 VspVsmbFileIoctlVstorVsmbOpenFileValidate
           (_VSTOR_VSMB_OPEN_FILE_REQUEST *param_1,uint param_2,uint param_3)
 
 {
   char *pcVar1;
-  ulonglong uVar2;
-  _VSTOR_VSMB_OPEN_FILE_REQUEST *p_Var3;
-  ushort uVar4;
+  ushort uVar2;
+  uint uVar3;
+  long lVar4;
   uint uVar5;
-  long lVar6;
+  uint uVar6;
   uint uVar7;
-  uint uVar8;
+  _VSTOR_VSMB_OPEN_FILE_REQUEST *p_Var8;
   uint uVar9;
   uint uVar10;
-  uint uVar11;
   
   if (param_2 < 0x44) {
-    uVar4 = 0x2e3;
+    uVar2 = 0x2e2;
   }
   else {
-    uVar7 = *(ushort *)(param_1 + 0x40) + 0x44;
-    if (uVar7 < 0x44) {
-      uVar4 = 0x2e4;
+    uVar3 = *(ushort *)(param_1 + 0x40) + 0x44;
+    if (uVar3 < 0x44) {
+      uVar2 = 0x2e3;
       goto LAB_0;
     }
-    if (uVar7 <= param_2) {
-      if (*(int *)(param_1 + 0x28) == 0) {
+    if (uVar3 <= param_2) {
+      uVar7 = *(uint *)(param_1 + 0x28);
+      if (uVar7 == 0) {
 LAB_1:
-        if (*(int *)(param_1 + 0x2c) != 0) {
+        if (*(int *)(param_1 + 0x2c) == 0) {
 LAB_2:
-          uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-          if ((int)uVar2 != 0) {
-            uVar4 = 0x2ff;
-            goto LAB_3;
-          }
-        }
+          uVar7 = *(uint *)(param_1 + 0x30);
+          if (uVar7 == 0) {
+LAB_3:
+            if (*(int *)(param_1 + 0x34) == 0) {
 LAB_4:
-        if (*(int *)(param_1 + 0x30) == 0) {
+              uVar7 = *(uint *)(param_1 + 0x38);
+              if (uVar7 == 0) {
 LAB_5:
-          if (*(int *)(param_1 + 0x34) != 0) {
+                if (*(int *)(param_1 + 0x3c) != 0) {
 LAB_6:
-            uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-            if ((int)uVar2 != 0) {
-              uVar4 = 0x336;
-              goto LAB_3;
+                  uVar2 = 0x330;
+                  goto LAB_7;
+                }
+              }
+              else {
+                if (*(int *)(param_1 + 0x3c) == 0) {
+                  if (uVar7 == 0) goto LAB_5;
+                  goto LAB_6;
+                }
+                if (uVar7 < uVar3) {
+                  uVar2 = 0x326;
+                  goto LAB_7;
+                }
+                uVar3 = uVar7 + *(int *)(param_1 + 0x3c);
+                if (uVar3 < uVar7) {
+                  uVar2 = 0x32a;
+LAB_0:
+                  StorVspTrace((_GUID *)"VspVsmbFileIoctlVstorVsmbOpenFileValidate",uVar2,2,
+                               (_GUID *)0x8,"Cleanup with status 0x%08X");
+                  return -0x3fffff6b;
+                }
+                if (param_2 < uVar3) {
+                  uVar2 = 0x32b;
+                  goto LAB_8;
+                }
+              }
+              if (0x6f < param_3) {
+                if (*(int *)param_1 == 1) {
+                  return 0;
+                }
+                uVar2 = 0x335;
+                goto LAB_7;
+              }
+              uVar2 = 0x334;
+              goto LAB_8;
             }
           }
+          else {
+            uVar6 = *(uint *)(param_1 + 0x34);
+            if (uVar6 != 0) {
+              if (uVar7 < uVar3) {
+                uVar2 = 0x2fb;
+                goto LAB_7;
+              }
+              if (uVar6 + uVar7 < uVar7) {
+                uVar2 = 0x2ff;
+                goto LAB_0;
+              }
+              if (param_2 < uVar6 + uVar7) {
+                uVar2 = 0x300;
+                goto LAB_8;
+              }
+              p_Var8 = param_1 + uVar7;
+              uVar7 = 0;
+              do {
+                uVar9 = uVar7 + 0x18;
+                if (uVar9 < uVar7) {
+                  uVar2 = 0x306;
+                  goto LAB_0;
+                }
+                if (uVar6 < uVar9) {
+                  uVar2 = 0x307;
+                  goto LAB_8;
+                }
+                uVar5 = *(int *)(p_Var8 + 0x14) + uVar9;
+                if (uVar5 < uVar9) {
+                  uVar2 = 0x30b;
+                  goto LAB_0;
+                }
+                if (uVar6 < uVar5) {
+                  uVar2 = 0x30c;
+                  goto LAB_8;
+                }
+                uVar9 = *(uint *)(p_Var8 + 0x10);
+                if (uVar9 == 0) break;
+                uVar10 = uVar9 + uVar7;
+                if (uVar10 < uVar7) {
+                  uVar2 = 0x310;
+                  goto LAB_0;
+                }
+                if (uVar6 < uVar10) {
+                  uVar2 = 0x311;
+                  goto LAB_8;
+                }
+                if (uVar10 < uVar5) {
+                  uVar2 = 0x312;
+                  goto LAB_7;
+                }
+                p_Var8 = p_Var8 + uVar9;
+                uVar7 = uVar10;
+              } while (p_Var8 != (_VSTOR_VSMB_OPEN_FILE_REQUEST *)0x0);
+              goto LAB_4;
+            }
+            if (uVar7 == 0) goto LAB_3;
+          }
+          uVar2 = 799;
         }
         else {
-          if (*(int *)(param_1 + 0x34) == 0) {
-            if (*(int *)(param_1 + 0x30) == 0) goto LAB_5;
-            goto LAB_6;
-          }
-          uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-          uVar5 = *(uint *)(param_1 + 0x30);
-          if ((int)uVar2 != 0) {
-            if (uVar5 < uVar7) {
-              uVar4 = 0x309;
-              goto LAB_3;
-            }
-            uVar10 = *(uint *)(param_1 + 0x34);
-            if (uVar5 + uVar10 < uVar5) {
-              uVar4 = 0x30d;
-              goto LAB_0;
-            }
-            if (uVar5 + uVar10 <= param_2) goto LAB_7;
-            uVar4 = 0x30e;
-            goto LAB_8;
-          }
-          uVar10 = *(uint *)(param_1 + 0x34);
-          uVar7 = uVar5 + uVar10;
-          if (uVar7 < uVar5) {
-            uVar4 = 0x312;
-            goto LAB_0;
-          }
-          if (param_2 < uVar7) {
-            uVar4 = 0x313;
-            goto LAB_8;
-          }
-LAB_7:
-          p_Var3 = param_1 + uVar5;
-          uVar5 = 0;
-          do {
-            uVar8 = uVar5 + 0x18;
-            if (uVar8 < uVar5) {
-              uVar4 = 0x31b;
-              goto LAB_0;
-            }
-            if (uVar10 < uVar8) {
-              uVar4 = 0x31c;
-              goto LAB_8;
-            }
-            uVar11 = *(int *)(p_Var3 + 0x14) + uVar8;
-            if (uVar11 < uVar8) {
-              uVar4 = 800;
-              goto LAB_0;
-            }
-            if (uVar10 < uVar11) {
-              uVar4 = 0x321;
-              goto LAB_8;
-            }
-            uVar8 = *(uint *)(p_Var3 + 0x10);
-            if (uVar8 == 0) break;
-            uVar9 = uVar8 + uVar5;
-            if (uVar9 < uVar5) {
-              uVar4 = 0x325;
-              goto LAB_0;
-            }
-            if (uVar10 < uVar9) {
-              uVar4 = 0x326;
-              goto LAB_8;
-            }
-            if (uVar9 < uVar11) {
-              uVar4 = 0x327;
-              goto LAB_3;
-            }
-            p_Var3 = p_Var3 + uVar8;
-            uVar5 = uVar9;
-          } while (p_Var3 != (_VSTOR_VSMB_OPEN_FILE_REQUEST *)0x0);
+LAB_9:
+          uVar2 = 0x2f4;
         }
-        if (*(int *)(param_1 + 0x38) == 0) {
-LAB_9:
-          if (*(int *)(param_1 + 0x3c) != 0) {
-LAB_10:
-            uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-            if ((int)uVar2 != 0) {
-              uVar4 = 0x352;
-              goto LAB_3;
-            }
-          }
-        }
-        else {
-          if (*(int *)(param_1 + 0x3c) == 0) {
-            if (*(int *)(param_1 + 0x38) == 0) goto LAB_9;
-            goto LAB_10;
-          }
-          uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-          uVar5 = *(uint *)(param_1 + 0x38);
-          if ((int)uVar2 != 0) {
-            if (uVar5 < uVar7) {
-              uVar4 = 0x340;
-              goto LAB_3;
-            }
-            if (*(int *)(param_1 + 0x3c) + uVar5 < uVar5) {
-              uVar4 = 0x344;
-              goto LAB_0;
-            }
-            if (*(int *)(param_1 + 0x3c) + uVar5 <= param_2) goto LAB_11;
-            uVar4 = 0x345;
-            goto LAB_8;
-          }
-          if (*(int *)(param_1 + 0x3c) + uVar5 < uVar5) {
-            uVar4 = 0x349;
-LAB_0:
-            StorVspTrace((_GUID *)"VspVsmbFileIoctlVstorVsmbOpenFileValidate",uVar4,2,(_GUID *)0x8,
-                         "Cleanup with status 0x%08X");
-            return -0x3fffff6b;
-          }
-          if (param_2 < *(int *)(param_1 + 0x3c) + uVar5) {
-            uVar4 = 0x34a;
-            goto LAB_8;
-          }
-        }
-LAB_11:
-        if (param_3 < 0x70) {
-          uVar4 = 0x357;
-          goto LAB_8;
-        }
-        if (*(int *)param_1 == 1) {
-          return 0;
-        }
-        uVar4 = 0x358;
       }
       else {
         if (*(int *)(param_1 + 0x2c) == 0) {
-          if (*(int *)(param_1 + 0x28) == 0) goto LAB_1;
+          if (uVar7 == 0) goto LAB_1;
+          goto LAB_9;
+        }
+        if (uVar3 <= uVar7) {
+          uVar6 = *(int *)(param_1 + 0x2c) + uVar7;
+          if (uVar6 < uVar7) {
+            uVar2 = 0x2ee;
+            goto LAB_0;
+          }
+          if (param_2 < uVar6) {
+            uVar2 = 0x2ef;
+            goto LAB_8;
+          }
           goto LAB_2;
         }
-        uVar2 = Feature_2561731899__private_IsEnabledDeviceUsageNoInline();
-        uVar5 = *(uint *)(param_1 + 0x28);
-        if ((int)uVar2 == 0) {
-          uVar7 = *(int *)(param_1 + 0x2c) + uVar5;
-          if (uVar7 < uVar5) {
-            uVar4 = 0x2f6;
-            goto LAB_0;
-          }
-          if (param_2 < uVar7) {
-            uVar4 = 0x2f7;
-            goto LAB_8;
-          }
-          goto LAB_4;
-        }
-        if (uVar7 <= uVar5) {
-          if (*(int *)(param_1 + 0x2c) + uVar5 < uVar5) {
-            uVar4 = 0x2f1;
-            goto LAB_0;
-          }
-          if (*(int *)(param_1 + 0x2c) + uVar5 <= param_2) goto LAB_4;
-          uVar4 = 0x2f2;
-          goto LAB_8;
-        }
-        uVar4 = 0x2ed;
+        uVar2 = 0x2ea;
       }
-LAB_3:
-      lVar6 = -0x3ffffff3;
+LAB_7:
+      lVar4 = -0x3ffffff3;
       pcVar1 = "Cleanup [status = ((NTSTATUS)0xC000000DL)]";
-      goto LAB_12;
+      goto LAB_10;
     }
-    uVar4 = 0x2e5;
+    uVar2 = 0x2e4;
   }
 LAB_8:
-  lVar6 = -0x3fffffdd;
+  lVar4 = -0x3fffffdd;
   pcVar1 = "Cleanup [status = ((NTSTATUS)0xC0000023L)]";
-LAB_12:
-  StorVspTrace((_GUID *)"VspVsmbFileIoctlVstorVsmbOpenFileValidate",uVar4,2,(_GUID *)0x8,pcVar1);
-  return lVar6;
+LAB_10:
+  StorVspTrace((_GUID *)"VspVsmbFileIoctlVstorVsmbOpenFileValidate",uVar2,2,(_GUID *)0x8,pcVar1);
+  return lVar4;
 }
 

```


## VspIsValidSgRequest

### Match Info



|Key|storvsp-10.0.26100.5074.sys - storvsp-10.0.26100.7171.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.26|
|i_ratio|0.2|
|m_ratio|0.73|
|b_ratio|0.61|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|storvsp-10.0.26100.5074.sys|storvsp-10.0.26100.7171.sys|
| :---: | :---: | :---: |
|name|VspIsValidSgRequest|VspIsValidSgRequest|
|fullname|VspIsValidSgRequest|VspIsValidSgRequest|
|refcount|3|3|
|`length`|92|186|
|`called`||Feature_1128825144__private_IsEnabledDeviceUsageNoInline<br>StorVspTrace|
|calling|VspStartJob<br>VspValidateRequest|VspStartJob<br>VspValidateRequest|
|paramcount|1|1|
|`address`|140008d54|14000c6d4|
|sig|uchar __cdecl VspIsValidSgRequest(_VSP_REQUEST_PRIVATE * param_1)|uchar __cdecl VspIsValidSgRequest(_VSP_REQUEST_PRIVATE * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### VspIsValidSgRequest Called Diff


```diff
--- VspIsValidSgRequest called
+++ VspIsValidSgRequest called
@@ -0,0 +1,2 @@
+Feature_1128825144__private_IsEnabledDeviceUsageNoInline
+StorVspTrace
```


### VspIsValidSgRequest Diff


```diff
--- VspIsValidSgRequest
+++ VspIsValidSgRequest
@@ -1,25 +1,38 @@
 
 /* unsigned char __cdecl VspIsValidSgRequest(struct _VSP_REQUEST_PRIVATE * __ptr64) */
 
 uchar __cdecl VspIsValidSgRequest(_VSP_REQUEST_PRIVATE *param_1)
 
 {
-  char cVar1;
-  undefined8 *puVar2;
-  int iVar3;
-  int iVar4;
+  int *piVar1;
+  char cVar2;
+  longlong lVar3;
+  ulonglong uVar4;
+  undefined8 *puVar5;
+  int iVar6;
+  int iVar7;
   
-  iVar3 = 0;
-  puVar2 = *(undefined8 **)(param_1 + 0x10);
-  if ((*(char *)(*(longlong *)(param_1 + 0x50) + 0x888) != '\0') &&
-     (((((cVar1 = *(char *)(*(longlong *)(param_1 + 8) + 0x10), iVar4 = 0, cVar1 == '\b' ||
-         (iVar4 = iVar3, cVar1 == '\n')) || (cVar1 == '(')) || ((cVar1 == '*' || (cVar1 == -0x78))))
-      || ((cVar1 == -0x76 || ((cVar1 == -0x58 || (cVar1 == -0x56)))))))) {
-    for (; puVar2 != (undefined8 *)0x0; puVar2 = (undefined8 *)*puVar2) {
-      iVar4 = iVar4 + *(int *)(puVar2 + 5);
+  puVar5 = *(undefined8 **)(param_1 + 0x10);
+  lVar3 = *(longlong *)(param_1 + 8);
+  iVar7 = 0;
+  iVar6 = 0;
+  uVar4 = Feature_1128825144__private_IsEnabledDeviceUsageNoInline();
+  if (((int)uVar4 == 0) || (*(longlong *)(param_1 + 0x50) != 0)) {
+    if ((*(char *)(*(longlong *)(param_1 + 0x50) + 0x888) != '\0') &&
+       (((((cVar2 = *(char *)(lVar3 + 0x10), cVar2 == '\b' || (cVar2 == '\n')) || (cVar2 == '(')) ||
+         ((iVar7 = iVar6, cVar2 == '*' || (cVar2 == -0x78)))) ||
+        ((cVar2 == -0x76 || ((cVar2 == -0x58 || (cVar2 == -0x56)))))))) {
+      for (; puVar5 != (undefined8 *)0x0; puVar5 = (undefined8 *)*puVar5) {
+        piVar1 = (int *)(puVar5 + 5);
+        iVar7 = iVar7 + *piVar1;
+      }
+      return iVar7 == *(int *)(lVar3 + 0xc);
     }
-    return iVar4 == *(int *)(*(longlong *)(param_1 + 8) + 0xc);
+  }
+  else {
+    StorVspTrace((_GUID *)"VspIsValidSgRequest",0xca1,3,(_GUID *)0x2,
+                 "No device associated while validating SG request");
   }
   return '\0';
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## VspStartJob

### Match Info



|Key|storvsp-10.0.26100.5074.sys - storvsp-10.0.26100.7171.sys|
| :---: | :---: |
|diff_type|length|
|ratio|0.51|
|i_ratio|0.55|
|m_ratio|0.98|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|storvsp-10.0.26100.5074.sys|storvsp-10.0.26100.7171.sys|
| :---: | :---: | :---: |
|name|VspStartJob|VspStartJob|
|fullname|VspStartJob|VspStartJob|
|refcount|7|7|
|`length`|1045|1080|
|called|<details><summary>Expand for full list:<br>HAL.DLL::KeQueryPerformanceCounter<br>NTOSKRNL.EXE::ExAcquireRundownProtection<br>NTOSKRNL.EXE::ExReleaseRundownProtection<br>NTOSKRNL.EXE::MmMapLockedPagesSpecifyCache<br>StorVspTrace<br>VspAdapterHandleInquiry<br>VspAdapterHandleReportLuns<br>VspDeviceIssueQoSStatusRequest<br>VspDeviceProcessQoSStatusResponse<br>VspHandleAbsentLun0Inquiry<br>VspIsValidSgRequest</summary>VspRequestComplete<br>_guard_dispatch_icall</details>|<details><summary>Expand for full list:<br>HAL.DLL::KeQueryPerformanceCounter<br>NTOSKRNL.EXE::ExAcquireRundownProtection<br>NTOSKRNL.EXE::ExReleaseRundownProtection<br>NTOSKRNL.EXE::MmMapLockedPagesSpecifyCache<br>StorVspTrace<br>VspAdapterHandleInquiry<br>VspAdapterHandleReportLuns<br>VspDeviceIssueQoSStatusRequest<br>VspDeviceProcessQoSStatusResponse<br>VspHandleAbsentLun0Inquiry<br>VspIsValidSgRequest</summary>VspRequestComplete<br>_guard_dispatch_icall</details>|
|calling|VspDeviceReplayFailedRequestsWorkItemRoutine<br>VspHandleSCSIRequest<br>VspKickJobsList<br>VspPvtKmclProcessingComplete<br>VspStartProcessingJobs<br>VspWorker|VspDeviceReplayFailedRequestsWorkItemRoutine<br>VspHandleSCSIRequest<br>VspKickJobsList<br>VspPvtKmclProcessingComplete<br>VspStartProcessingJobs<br>VspWorker|
|paramcount|2|2|
|address|140003a30|140003a30|
|sig|void __cdecl VspStartJob(_VSP_REQUEST_PRIVATE * param_1, _LARGE_INTEGER * param_2)|void __cdecl VspStartJob(_VSP_REQUEST_PRIVATE * param_1, _LARGE_INTEGER * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-07-28T09:46:35</sub>