# tapisrv.dll 22621.3296 vs 22621.3447 (CVE-2024-26230, manual pair)

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
* [Modified](#modified)
	* [TRequestMakeCall](#trequestmakecall)
	* [TUISPIDLLCallback](#tuispidllcallback)
	* [LRegisterRequestRecipient](#lregisterrequestrecipient)
	* [FreeDialogInstance](#freedialoginstance)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [KERNEL32.DLL::LeaveCriticalSection](#kernel32dllleavecriticalsection)
	* [TRACELogPrint](#tracelogprint)
	* [USER32.DLL::LoadIconW](#user32dllloadiconw)
	* [KERNEL32.DLL::EnterCriticalSection](#kernel32dllentercriticalsection)
	* [DereferenceObject](#dereferenceobject)
	* [WaitForExclusiveClientAccess](#waitforexclusiveclientaccess)

# Visual Chart Diff



```mermaid

flowchart LR

TRequestMakeCall-5-old<--Match 82%-->TRequestMakeCall-5-new
TUISPIDLLCallback-5-old<--Match 95%-->TUISPIDLLCallback-5-new
LRegisterRequestRecipient-4-old<--Match 91%-->LRegisterRequestRecipient-4-new
FreeDialogInstance-4-old<--Match 82%-->FreeDialogInstance-4-new

subgraph tapisrv-10.0.22621.3447.dll
    TRequestMakeCall-5-new
TUISPIDLLCallback-5-new
LRegisterRequestRecipient-4-new
FreeDialogInstance-4-new
    
end

subgraph tapisrv-10.0.22621.3296.dll
    TRequestMakeCall-5-old
TUISPIDLLCallback-5-old
LRegisterRequestRecipient-4-old
FreeDialogInstance-4-old
    
end

```


```mermaid
pie showData
    title Function Matches - 100.0000%
"unmatched_funcs_len" : 0
"matched_funcs_len" : 1488
```



```mermaid
pie showData
    title Matched Function Similarity - 99.1935%
"matched_funcs_with_code_changes_len" : 4
"matched_funcs_with_non_code_changes_len" : 8
"matched_funcs_no_changes_len" : 1476
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2024-26230\ghidra_projects --project-name CVE-2024-26230 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2024-26230\symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 --md-title tapisrv.dll 22621.3296 vs 22621.3447 (CVE-2024-26230, manual pair) tapisrv-10.0.22621.3296.dll tapisrv-10.0.22621.3447.dll
```


#### Verbose Args


<details>

```
--old ['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2024-26230\\tapisrv-10.0.22621.3296.dll'] --new [['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2024-26230\\tapisrv-10.0.22621.3447.dll']] --engine VersionTrackingDiff --output-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2024-26230\output --summary False --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2024-26230\ghidra_projects --project-name CVE-2024-26230 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2024-26230\symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title tapisrv.dll 22621.3296 vs 22621.3447 (CVE-2024-26230, manual pair)
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/TAPISRV.EXE/10EA915D53000/TAPISRV.EXE -O tapisrv.exe.x64.10.0.22621.3430
wget https://msdl.microsoft.com/download/symbols/TAPISRV.EXE/B2914E4953000/TAPISRV.EXE -O tapisrv.exe.x64.10.0.22621.1376
```


## Binary Metadata Diff


```diff
--- tapisrv-10.0.22621.3296.dll Meta
+++ tapisrv-10.0.22621.3447.dll Meta
@@ -1,44 +1,44 @@
-Program Name: tapisrv-10.0.22621.3296.dll
+Program Name: tapisrv-10.0.22621.3447.dll
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
 # of Bytes: 346192
 # of Memory Blocks: 9
-# of Instructions: 56136
+# of Instructions: 56157
 # of Defined Data: 3657
 # of Functions: 744
-# of Symbols: 10054
-# of Data Types: 890
+# of Symbols: 10055
+# of Data Types: 889
 # of Data Type Categories: 37
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Tue Jul 28 08:11:01 SGT 2026
+Date Created: Tue Jul 28 08:11:06 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2024-26230/tapisrv-10.0.22621.3296.dll
-Executable MD5: 747facb924b9da35ecdbda51f7cc277c
-Executable SHA256: ddba2598af6b2bbfb85ee3984215a496c38e21addb19cc8d1cbf5d81e0e94aca
-FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2024-26230/tapisrv-10.0.22621.3296.dll?MD5=747facb924b9da35ecdbda51f7cc277c
+Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2024-26230/tapisrv-10.0.22621.3447.dll
+Executable MD5: 3461e756b70479a197ab9a86e05c9077
+Executable SHA256: 677c601de9662c52f1b93cbdbe77c1f583f1e02462dc07f2726edfe0967f2167
+FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2024-26230/tapisrv-10.0.22621.3447.dll?MD5=3461e756b70479a197ab9a86e05c9077
 PDB Age: 1
 PDB File: tapisrv.pdb
-PDB GUID: 80fce49f-55b1-6bc2-43a7-b90ba38fad76
+PDB GUID: 20d2542f-bd81-8098-be82-050323f99d99
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Microsoft® Windows(TM) Telephony Server
-PE Property[FileVersion]: 10.0.22621.3430 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.22621.1376 (WinBuild.160101.0800)
 PE Property[InternalName]: Telephony Service
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: TAPISRV.EXE
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.22621.3430
+PE Property[ProductVersion]: 10.0.22621.1376
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra tapisrv-10.0.22621.3296.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra tapisrv-10.0.22621.3296.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra tapisrv-10.0.22621.3296.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra tapisrv-10.0.22621.3447.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra tapisrv-10.0.22621.3447.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra tapisrv-10.0.22621.3447.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|0|
|deleted_funcs_len|0|
|modified_funcs_len|12|
|added_symbols_len|3|
|deleted_symbols_len|5|
|diff_time|15.930518627166748|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 743, 'ExternalsName': 198, 'ExactInstructionsFunctionHasher': 1})|
|items_to_process|20|
|diff_types|Counter({'address': 11, 'length': 6, 'refcount': 6, 'code': 4, 'called': 3, 'calling': 3, 'sig': 2})|
|unmatched_funcs_len|0|
|total_funcs_len|1488|
|matched_funcs_len|1488|
|matched_funcs_with_code_changes_len|4|
|matched_funcs_with_non_code_changes_len|8|
|matched_funcs_no_changes_len|1476|
|match_func_similarity_percent|99.1935%|
|func_match_overall_percent|100.0000%|
|first_matches|Counter({'SymbolsHash': 743, 'ExactInstructionsFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 743
"ExternalsName" : 198
"ExactInstructionsFunctionHasher" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 743
"ExactInstructionsFunctionHasher" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 0
"deleted_funcs_len" : 0
"modified_funcs_len" : 12
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 3
"deleted_symbols_len" : 5
```

## Strings


*No string differences found*

# Deleted

# Added

# Modified


*Modified functions contain code changes*
## TRequestMakeCall

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.59|
|i_ratio|0.46|
|m_ratio|0.95|
|b_ratio|0.82|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|TRequestMakeCall|TRequestMakeCall|
|fullname|TRequestMakeCall|TRequestMakeCall|
|refcount|3|3|
|`length`|982|901|
|`called`|Feature_11509055__private_IsEnabled<br>GetPriorityListTReqCall<br>IsBadStringParam<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>NotifyHighestPriorityRequestRecipient<br>ServerFree<br>StringCbCopyW<br>TRACELogPrint|GetPriorityListTReqCall<br>IsBadStringParam<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>NotifyHighestPriorityRequestRecipient<br>ServerFree<br>StringCbCopyW<br>TRACELogPrint|
|calling|||
|paramcount|5|5|
|`address`|1800312e0|180031390|
|sig|undefined __fastcall TRequestMakeCall(undefined8 param_1, uint * param_2, undefined8 param_3, uint * param_4, int * param_5)|undefined __fastcall TRequestMakeCall(undefined8 param_1, uint * param_2, undefined8 param_3, uint * param_4, int * param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### TRequestMakeCall Called Diff


```diff
--- TRequestMakeCall called
+++ TRequestMakeCall called
@@ -1 +0,0 @@
-Feature_11509055__private_IsEnabled
```


### TRequestMakeCall Diff


```diff
--- TRequestMakeCall
+++ TRequestMakeCall
@@ -1,155 +1,136 @@
 
 void TRequestMakeCall(undefined8 param_1,uint *param_2,undefined8 param_3,uint *param_4,int *param_5
                      )
 
 {
   short *psVar1;
   STRSAFE_LPWSTR pwVar2;
   bool bVar3;
-  uint uVar4;
   undefined7 extraout_var;
   undefined7 extraout_var_00;
   undefined7 extraout_var_01;
   undefined7 extraout_var_02;
-  STRSAFE_LPWSTR pwVar5;
-  undefined *puVar6;
-  char *pcVar7;
-  STRSAFE_LPWSTR pwVar8;
-  uint *puVar9;
+  STRSAFE_LPWSTR pwVar4;
+  char *pcVar5;
+  uint uVar6;
+  STRSAFE_LPWSTR pwVar7;
+  uint *puVar8;
   short *local_res10;
   
   if (param_2[7] == 0) {
-    uVar4 = (uint)param_3;
-    puVar9 = param_4;
-    bVar3 = IsBadStringParam(uVar4,(longlong)param_4,param_2[2]);
+    uVar6 = (uint)param_3;
+    puVar8 = param_4;
+    bVar3 = IsBadStringParam(uVar6,(longlong)param_4,param_2[2]);
     if (((((int)CONCAT71(extraout_var,bVar3) == 0) &&
          ((param_2[3] == 0xffffffff ||
-          (bVar3 = IsBadStringParam(uVar4,(longlong)param_4,param_2[3]),
+          (bVar3 = IsBadStringParam(uVar6,(longlong)param_4,param_2[3]),
           (int)CONCAT71(extraout_var_00,bVar3) == 0)))) &&
         ((param_2[4] == 0xffffffff ||
-         (bVar3 = IsBadStringParam(uVar4,(longlong)param_4,param_2[4]),
+         (bVar3 = IsBadStringParam(uVar6,(longlong)param_4,param_2[4]),
          (int)CONCAT71(extraout_var_01,bVar3) == 0)))) &&
        ((((param_2[5] == 0xffffffff ||
-          (bVar3 = IsBadStringParam(uVar4,(longlong)param_4,param_2[5]),
-          (int)CONCAT71(extraout_var_02,bVar3) == 0)) && (param_2[6] <= uVar4)) &&
-        (pwVar5 = HeapAlloc(ghTapisrvHeap,8,0x1e8), pwVar5 != (STRSAFE_LPWSTR)0x0)))) {
-      TRACELogPrint(0x40002,"Request:  0x%p",pwVar5,puVar9);
-      StringCbCopyW(pwVar5,0xa0,(STRSAFE_LPCWSTR)((ulonglong)param_2[2] + (longlong)param_4));
-      pcVar7 = "   DestAddress: [%ls]";
-      pwVar8 = pwVar5;
-      TRACELogPrint(0x40002,"   DestAddress: [%ls]",pwVar5,puVar9);
+          (bVar3 = IsBadStringParam(uVar6,(longlong)param_4,param_2[5]),
+          (int)CONCAT71(extraout_var_02,bVar3) == 0)) && (param_2[6] <= uVar6)) &&
+        (pwVar4 = HeapAlloc(ghTapisrvHeap,8,0x1e8), pwVar4 != (STRSAFE_LPWSTR)0x0)))) {
+      TRACELogPrint(0x40002,"Request:  0x%p",pwVar4,puVar8);
+      StringCbCopyW(pwVar4,0xa0,(STRSAFE_LPCWSTR)((ulonglong)param_2[2] + (longlong)param_4));
+      pcVar5 = "   DestAddress: [%ls]";
+      pwVar7 = pwVar4;
+      TRACELogPrint(0x40002,"   DestAddress: [%ls]",pwVar4,puVar8);
       if (param_2[3] != 0xffffffff) {
-        pwVar8 = pwVar5 + 0x50;
-        StringCbCopyW(pwVar8,0x50,(STRSAFE_LPCWSTR)((ulonglong)param_2[3] + (longlong)param_4));
-        pcVar7 = "   AppName: [%ls]";
-        TRACELogPrint(0x40002,"   AppName: [%ls]",pwVar8,puVar9);
+        pwVar7 = pwVar4 + 0x50;
+        StringCbCopyW(pwVar7,0x50,(STRSAFE_LPCWSTR)((ulonglong)param_2[3] + (longlong)param_4));
+        pcVar5 = "   AppName: [%ls]";
+        TRACELogPrint(0x40002,"   AppName: [%ls]",pwVar7,puVar8);
       }
       if (param_2[4] != 0xffffffff) {
-        pwVar8 = pwVar5 + 0x78;
-        StringCbCopyW(pwVar8,0x50,(STRSAFE_LPCWSTR)((ulonglong)param_2[4] + (longlong)param_4));
-        pcVar7 = "   CalledParty: [%ls]";
-        TRACELogPrint(0x40002,"   CalledParty: [%ls]",pwVar8,puVar9);
+        pwVar7 = pwVar4 + 0x78;
+        StringCbCopyW(pwVar7,0x50,(STRSAFE_LPCWSTR)((ulonglong)param_2[4] + (longlong)param_4));
+        pcVar5 = "   CalledParty: [%ls]";
+        TRACELogPrint(0x40002,"   CalledParty: [%ls]",pwVar7,puVar8);
       }
       if (param_2[5] != 0xffffffff) {
-        pwVar8 = pwVar5 + 0xa0;
-        StringCbCopyW(pwVar8,0xa0,(STRSAFE_LPCWSTR)((ulonglong)param_2[5] + (longlong)param_4));
-        pcVar7 = "   Comment: [%ls]";
-        TRACELogPrint(0x40002,"   Comment: [%ls]",pwVar8,puVar9);
+        pwVar7 = pwVar4 + 0xa0;
+        StringCbCopyW(pwVar7,0xa0,(STRSAFE_LPCWSTR)((ulonglong)param_2[5] + (longlong)param_4));
+        pcVar5 = "   Comment: [%ls]";
+        TRACELogPrint(0x40002,"   Comment: [%ls]",pwVar7,puVar8);
       }
-      puVar6 = &gPriorityListCritSec;
       EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
       bVar3 = DAT_0 == (STRSAFE_LPWSTR)0x0;
-      pwVar2 = pwVar5;
+      pwVar2 = pwVar4;
       if (!bVar3) {
-        *(STRSAFE_LPWSTR *)(DAT_0 + 0xf0) = pwVar5;
+        *(STRSAFE_LPWSTR *)(DAT_0 + 0xf0) = pwVar4;
         pwVar2 = DAT_1;
       }
       DAT_1 = pwVar2;
-      DAT_0 = pwVar5;
-      uVar4 = Feature_11509055__private_IsEnabled();
-      if (uVar4 == 0) {
-        puVar6 = &gPriorityListCritSec;
-        LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
-      }
-      uVar4 = param_2[6];
+      DAT_0 = pwVar4;
+      *param_4 = param_2[6];
       param_4[2] = 0x18;
       param_4[1] = 0x18;
-      *param_4 = uVar4;
       param_2[8] = 0;
       if (bVar3) {
         if (DAT_2 == 0) {
           local_res10 = (short *)0x0;
-          uVar4 = Feature_11509055__private_IsEnabled();
-          if (uVar4 == 0) {
-            EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
-          }
-          GetPriorityListTReqCall(&local_res10,pcVar7,pwVar8,puVar9);
+          GetPriorityListTReqCall(&local_res10,pcVar5,pwVar7,puVar8);
           psVar1 = local_res10;
           if ((local_res10 == (short *)0x0) || (*local_res10 == 0)) {
             DAT_0 = (STRSAFE_LPWSTR)0x0;
             DAT_1 = (STRSAFE_LPWSTR)0x0;
-            ServerFree(pwVar5);
+            ServerFree(pwVar4);
             *param_2 = 0xfffffffe;
           }
           else {
             param_4[2] = *param_4;
             param_4[1] = *param_4;
-            uVar4 = param_2[6];
-            if (uVar4 < 0x19) {
+            uVar6 = param_2[6];
+            if (uVar6 < 0x19) {
               *param_2 = 0xfffffff0;
               DAT_0 = (STRSAFE_LPWSTR)0x0;
               DAT_1 = (STRSAFE_LPWSTR)0x0;
-              ServerFree(pwVar5);
+              ServerFree(pwVar4);
               LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
               ServerFree(psVar1);
               return;
             }
             param_4[5] = 0x18;
-            param_4[4] = uVar4 - 0x18;
+            param_4[4] = uVar6 - 0x18;
             param_2[8] = 1;
             StringCbCopyW((STRSAFE_LPWSTR)((ulonglong)param_4[5] + (longlong)param_4),
                           (ulonglong)param_4[4],local_res10 + 1);
             ServerFree(psVar1);
           }
-          uVar4 = Feature_11509055__private_IsEnabled();
-          if (uVar4 == 0) {
-            LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
-          }
         }
         else {
-          NotifyHighestPriorityRequestRecipient(puVar6,pcVar7,pwVar8,puVar9);
+          NotifyHighestPriorityRequestRecipient(1,pcVar5,pwVar7,puVar8);
         }
       }
       if (*param_2 == 0) {
         param_2[6] = 0;
         *param_5 = param_4[2] + 0x3c;
       }
-      uVar4 = Feature_11509055__private_IsEnabled();
-      if (uVar4 != 0) {
-        LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
-      }
+      LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
       TRACELogPrint(0x80002,"TapiEpilogSync (tapiRequestMakeCall) exit, returning x%x",
-                    (ulonglong)*param_2,puVar9);
+                    (ulonglong)*param_2,puVar8);
     }
     else {
       *param_2 = 0xfffffff0;
     }
   }
   else {
     EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
-    pwVar5 = DAT_1;
-    while (pwVar5 != (STRSAFE_LPWSTR)0x0) {
-      pwVar8 = *(STRSAFE_LPWSTR *)(pwVar5 + 0xf0);
-      ServerFree(pwVar5);
-      pwVar5 = pwVar8;
+    pwVar4 = DAT_1;
+    while (pwVar4 != (STRSAFE_LPWSTR)0x0) {
+      pwVar7 = *(STRSAFE_LPWSTR *)(pwVar4 + 0xf0);
+      ServerFree(pwVar4);
+      pwVar4 = pwVar7;
     }
     DAT_0 = (STRSAFE_LPWSTR)0x0;
     DAT_1 = (STRSAFE_LPWSTR)0x0;
     LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
     TRACELogPrint(0x10002,"TRequestMakeCall: couldn\'t exec proxy, deleting requests",param_3,
                   param_4);
     *param_2 = 0xfffffffe;
   }
   return;
 }
 

```


## TUISPIDLLCallback

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.6|
|i_ratio|0.59|
|m_ratio|0.95|
|b_ratio|0.95|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|TUISPIDLLCallback|TUISPIDLLCallback|
|fullname|TUISPIDLLCallback|TUISPIDLLCallback|
|refcount|3|3|
|`length`|496|554|
|`called`|DereferenceObject<br>GetLineLookupEntry<br>GetPhoneLookupEntry<br>IsBadSizeOffset<br>ReferenceObject<br>_guard_xfg_dispatch_icall_nop|DereferenceObject<br>GetLineLookupEntry<br>GetPhoneLookupEntry<br>IsBadSizeOffset<br>KERNEL32.DLL::LeaveCriticalSection<br>ReferenceObject<br>WaitForExclusiveClientAccess<br>_guard_xfg_dispatch_icall_nop|
|calling|||
|paramcount|5|5|
|`address`|18002fe00|180030860|
|`sig`|undefined __fastcall TUISPIDLLCallback(longlong param_1, int * param_2, uint param_3, longlong param_4, int * param_5)|undefined __fastcall TUISPIDLLCallback(int * param_1, int * param_2, uint param_3, longlong param_4, int * param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### TUISPIDLLCallback Called Diff


```diff
--- TUISPIDLLCallback called
+++ TUISPIDLLCallback called
@@ -4,0 +5 @@
+KERNEL32.DLL::LeaveCriticalSection
@@ -5,0 +7 @@
+WaitForExclusiveClientAccess
```


### TUISPIDLLCallback Diff


```diff
--- TUISPIDLLCallback
+++ TUISPIDLLCallback
@@ -1,89 +1,102 @@
 
 /* WARNING: Function: _guard_xfg_dispatch_icall_nop replaced with injection: guard_dispatch_icall */
 
-void TUISPIDLLCallback(longlong param_1,int *param_2,uint param_3,longlong param_4,int *param_5)
+void TUISPIDLLCallback(int *param_1,int *param_2,uint param_3,longlong param_4,int *param_5)
 
 {
   uint *puVar1;
   uint *puVar2;
   bool bVar3;
   int iVar4;
   undefined7 extraout_var;
   int *piVar5;
-  uint *puVar6;
-  uint uVar7;
-  longlong lVar9;
+  longlong lVar6;
+  uint *puVar7;
+  uint uVar8;
   code *pcVar10;
   ulonglong uVar12;
-  ulonglong uVar8;
+  ulonglong uVar9;
   code *pcVar11;
   
   uVar12 = (ulonglong)(uint)param_2[2];
   pcVar11 = (code *)0x0;
   pcVar10 = (code *)0x0;
   puVar1 = (uint *)(param_2 + 4);
   puVar2 = (uint *)(param_2 + 5);
   bVar3 = IsBadSizeOffset(param_3,0,(ulonglong)*puVar2,*puVar1,4);
   if ((int)CONCAT71(extraout_var,bVar3) == 0) {
     iVar4 = param_2[3];
     if (iVar4 == 1) {
-      if ((((byte)DAT_0 & 2) != 0) && ((*(byte *)(param_1 + 0xd8) & 1) == 0)) {
-        if (*(uint *)(param_1 + 0x60) <= (uint)param_2[2]) goto LAB_1;
+      if ((((byte)DAT_0 & 2) != 0) && ((*(byte *)(param_1 + 0x36) & 1) == 0)) {
+        if ((uint)param_1[0x18] <= (uint)param_2[2]) goto LAB_1;
         uVar12 = (ulonglong)
-                 *(uint *)(*(longlong *)(param_1 + 0x58) + (ulonglong)(uint)param_2[2] * 4);
+                 *(uint *)(*(longlong *)(param_1 + 0x16) + (ulonglong)(uint)param_2[2] * 4);
       }
-      puVar6 = GetLineLookupEntry((uint)uVar12);
+      puVar7 = GetLineLookupEntry((uint)uVar12);
 LAB_2:
-      pcVar11 = pcVar10;
-      if ((puVar6 != (uint *)0x0) && (*(longlong *)(puVar6 + 6) != 0)) {
-        pcVar11 = *(code **)(*(longlong *)(puVar6 + 6) + 0x3d0);
+      if ((puVar7 != (uint *)0x0) && (*(longlong *)(puVar7 + 6) != 0)) {
+        pcVar10 = *(code **)(*(longlong *)(puVar7 + 6) + 0x3d0);
       }
     }
     else {
       if (iVar4 == 2) {
-        if ((((byte)DAT_0 & 2) != 0) && ((*(byte *)(param_1 + 0xd8) & 1) == 0)) {
-          if (*(uint *)(param_1 + 0x78) <= (uint)param_2[2]) {
+        if ((((byte)DAT_0 & 2) != 0) && ((*(byte *)(param_1 + 0x36) & 1) == 0)) {
+          if ((uint)param_1[0x1e] <= (uint)param_2[2]) {
             *param_2 = -0x6fffffe4;
             return;
           }
           uVar12 = (ulonglong)
-                   *(uint *)(*(longlong *)(param_1 + 0x70) + (ulonglong)(uint)param_2[2] * 4);
+                   *(uint *)(*(longlong *)(param_1 + 0x1c) + (ulonglong)(uint)param_2[2] * 4);
         }
-        puVar6 = GetPhoneLookupEntry((uint)uVar12);
+        puVar7 = GetPhoneLookupEntry((uint)uVar12);
         goto LAB_2;
       }
-      uVar7 = iVar4 - 3;
-      uVar8 = (ulonglong)uVar7;
-      if (uVar7 == 0) {
-        for (lVar9 = *(longlong *)(param_1 + 0xb8); pcVar11 = pcVar10, lVar9 != 0;
-            lVar9 = *(longlong *)(lVar9 + 0x50)) {
-          if (param_2[2] == *(int *)(lVar9 + 0x10)) {
-            pcVar11 = *(code **)(lVar9 + 0x20);
-            break;
+      uVar8 = iVar4 - 3;
+      uVar9 = (ulonglong)uVar8;
+      if (uVar8 == 0) {
+        piVar5 = WaitForExclusiveClientAccess(param_1);
+        if (piVar5 != (int *)0x0) {
+          lVar6 = *(longlong *)(param_1 + 0x2e);
+          if (lVar6 != 0) {
+            do {
+              if (param_2[2] == *(int *)(lVar6 + 0x14)) {
+                pcVar11 = *(code **)(lVar6 + 0x20);
+                break;
+              }
+              lVar6 = *(longlong *)(lVar6 + 0x50);
+            } while (lVar6 != 0);
           }
+          LeaveCriticalSection
+                    ((LPCRITICAL_SECTION)
+                     (gLockTable +
+                     ((ulonglong)param_1 >> 4 & (ulonglong)gdwPointerToLockTableIndexBits) * 0x28));
+          pcVar10 = pcVar11;
         }
       }
-      else if ((uVar7 == 1) &&
-              (piVar5 = ReferenceObject(1,param_2[2],0x474f4c44), piVar5 != (int *)0x0)) {
-        uVar12 = *(ulonglong *)(piVar5 + 0xc);
-        pcVar11 = *(code **)(*(longlong *)(piVar5 + 10) + 0x3d0);
-        DereferenceObject(uVar8,param_2[2],1);
+      else {
+        pcVar10 = pcVar11;
+        if ((uVar8 == 1) &&
+           (piVar5 = ReferenceObject(1,param_2[2],0x474f4c44), piVar5 != (int *)0x0)) {
+          uVar12 = *(ulonglong *)(piVar5 + 0xc);
+          pcVar10 = *(code **)(*(longlong *)(piVar5 + 10) + 0x3d0);
+          DereferenceObject(uVar9,param_2[2],1);
+        }
       }
     }
-    if (pcVar11 != (code *)0x0) {
-      iVar4 = (*pcVar11)(uVar12,param_2[3],(ulonglong)*puVar1 + param_4,*puVar2);
+    if (pcVar10 != (code *)0x0) {
+      iVar4 = (*pcVar10)(uVar12,param_2[3],(ulonglong)*puVar1 + param_4,*puVar2);
       if (iVar4 == 0) {
         param_2[6] = *puVar1;
         param_2[7] = *puVar2;
         *param_5 = *puVar1 + *puVar2 + 0x3c;
       }
       goto LAB_3;
     }
   }
 LAB_1:
   iVar4 = -0x7fffffb8;
 LAB_3:
   *param_2 = iVar4;
   return;
 }
 

```


## LRegisterRequestRecipient

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.86|
|i_ratio|0.61|
|m_ratio|0.96|
|b_ratio|0.91|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|LRegisterRequestRecipient|LRegisterRequestRecipient|
|fullname|LRegisterRequestRecipient|LRegisterRequestRecipient|
|refcount|3|3|
|`length`|742|814|
|`called`|GetHighestPriorityRequestRecipient<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>NotifyHighestPriorityRequestRecipient<br>ServerFree<br>TRACELogPrint<br>WaitForExclusiveLineAppAccess|Feature_2656700732__private_IsEnabled<br>GetHighestPriorityRequestRecipient<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>NotifyHighestPriorityRequestRecipient<br>ServerFree<br>TRACELogPrint<br>WaitForExclusiveLineAppAccess|
|calling|||
|paramcount|4|4|
|`address`|180012c00|180012c80|
|sig|undefined __fastcall LRegisterRequestRecipient(longlong param_1, uint * param_2, undefined8 param_3, void * param_4)|undefined __fastcall LRegisterRequestRecipient(longlong param_1, uint * param_2, undefined8 param_3, void * param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### LRegisterRequestRecipient Called Diff


```diff
--- LRegisterRequestRecipient called
+++ LRegisterRequestRecipient called
@@ -0,0 +1 @@
+Feature_2656700732__private_IsEnabled
```


### LRegisterRequestRecipient Diff


```diff
--- LRegisterRequestRecipient
+++ LRegisterRequestRecipient
@@ -1,136 +1,151 @@
 
 void LRegisterRequestRecipient(longlong param_1,uint *param_2,undefined8 param_3,void *param_4)
 
 {
-  uint uVar1;
-  LPVOID pvVar2;
+  LPVOID pvVar1;
+  uint uVar2;
   int *piVar3;
   undefined8 *puVar4;
   undefined *puVar5;
   LPVOID pvVar6;
   char *pcVar7;
   undefined8 uVar8;
   longlong lVar9;
   int iVar10;
   uint uVar11;
   undefined8 uVar12;
   
   piVar3 = WaitForExclusiveLineAppAccess((ulonglong)param_2[2],param_1);
   iVar10 = 0;
   if (piVar3 == (int *)0x0) {
     *param_2 = (-(uint)(DAT_0 != 0) & 0xffffffc4) + 0x80000050;
     goto LAB_1;
   }
-  uVar1 = param_2[4];
-  if ((uVar1 & 3) == 0 || (uVar1 & 0xfffffffc) != 0) {
+  uVar2 = param_2[4];
+  if (((uVar2 & 3) == 0) || ((uVar2 & 0xfffffffc) != 0)) {
     *param_2 = 0x80000038;
   }
   else {
-    uVar11 = uVar1 & 2;
+    uVar11 = uVar2 & 2;
     if (param_2[5] == 0) {
       if ((uVar11 != 0) && (piVar3[0xd] == 0)) {
         pcVar7 = "App is not registered for mediacall";
         goto LAB_2;
       }
-      if ((uVar1 & 1) != 0) {
+      if ((uVar2 & 1) != 0) {
         pvVar6 = *(LPVOID *)(piVar3 + 0xe);
         if (pvVar6 == (LPVOID)0x0) {
           TRACELogPrint(0x10002,"App is not registered for makecall",param_3,param_4);
           *param_2 = 0x80000048;
         }
         else {
           EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
           if (*(longlong *)((longlong)pvVar6 + 0x18) != 0) {
             *(undefined8 *)(*(longlong *)((longlong)pvVar6 + 0x18) + 0x10) =
                  *(undefined8 *)((longlong)pvVar6 + 0x10);
           }
           lVar9 = *(longlong *)((longlong)pvVar6 + 0x10);
           puVar4 = *(undefined8 **)((longlong)pvVar6 + 0x18);
           if (lVar9 != 0) {
             *(undefined8 **)(lVar9 + 0x18) = *(undefined8 **)((longlong)pvVar6 + 0x18);
             puVar4 = DAT_3;
           }
           DAT_3 = puVar4;
-          LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
+          uVar2 = Feature_2656700732__private_IsEnabled();
+          if (uVar2 == 0) {
+            LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
+          }
           ServerFree(pvVar6);
           piVar3[0xe] = 0;
           piVar3[0xf] = 0;
           DAT_4 = GetHighestPriorityRequestRecipient(pvVar6,lVar9,param_3,param_4);
           pvVar6 = DAT_5;
           if (DAT_5 != (LPVOID)0x0) {
             if (DAT_4 == (longlong *)0x0) {
               DAT_6 = 0;
               DAT_5 = (LPVOID)0x0;
               while (pvVar6 != (LPVOID)0x0) {
-                pvVar2 = *(LPVOID *)((longlong)pvVar6 + 0x1e0);
+                pvVar1 = *(LPVOID *)((longlong)pvVar6 + 0x1e0);
                 ServerFree(pvVar6);
-                pvVar6 = pvVar2;
+                pvVar6 = pvVar1;
               }
               TRACELogPrint(0x40002,"LRegisterRequestRecipient: deleting pending MakeCall requests",
                             param_3,param_4);
             }
             else {
               NotifyHighestPriorityRequestRecipient(DAT_5,lVar9,param_3,param_4);
             }
+          }
+          uVar2 = Feature_2656700732__private_IsEnabled();
+          if (uVar2 != 0) {
+            LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
           }
         }
       }
       if (uVar11 == 0) {
         iVar10 = piVar3[0xd];
       }
       piVar3[0xd] = iVar10;
     }
     else if ((uVar11 == 0) || (piVar3[0xd] == 0)) {
       iVar10 = 1;
-      if ((uVar1 & 1) != 0) {
+      if ((uVar2 & 1) != 0) {
         if (*(longlong *)(piVar3 + 0xe) != 0) {
           pcVar7 = "App is already registered for makecall";
           goto LAB_2;
         }
         uVar8 = 8;
         uVar12 = 0x20;
         puVar4 = HeapAlloc(ghTapisrvHeap,8,0x20);
         if (puVar4 == (undefined8 *)0x0) {
           TRACELogPrint(0x10002,"Failed alloc for requestrecip struct",uVar12,param_4);
           *param_2 = 0x80000044;
           goto LAB_7;
         }
         *puVar4 = piVar3;
+        puVar5 = &gPriorityListCritSec;
         *(uint *)(puVar4 + 1) = param_2[3];
         EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
         puVar4[3] = DAT_3;
         if (DAT_3 != (undefined8 *)0x0) {
           DAT_3[2] = puVar4;
         }
-        puVar5 = &gPriorityListCritSec;
         DAT_3 = puVar4;
-        LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
+        uVar2 = Feature_2656700732__private_IsEnabled();
+        if (uVar2 == 0) {
+          puVar5 = &gPriorityListCritSec;
+          LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
+        }
         *(undefined8 **)(piVar3 + 0xe) = puVar4;
         DAT_4 = GetHighestPriorityRequestRecipient(puVar5,uVar8,uVar12,param_4);
         if (DAT_5 != (LPVOID)0x0) {
           NotifyHighestPriorityRequestRecipient(puVar5,uVar8,uVar12,param_4);
+        }
+        uVar2 = Feature_2656700732__private_IsEnabled();
+        if (uVar2 != 0) {
+          LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
         }
       }
       if (uVar11 == 0) {
         iVar10 = piVar3[0xd];
       }
       piVar3[0xd] = iVar10;
     }
     else {
       pcVar7 = "App is already registered for mediacall";
 LAB_2:
       TRACELogPrint(0x10002,pcVar7,param_3,param_4);
       *param_2 = 0x80000048;
     }
   }
 LAB_7:
   LeaveCriticalSection
             ((LPCRITICAL_SECTION)
              (gLockTable +
              ((ulonglong)piVar3 >> 4 & (ulonglong)gdwPointerToLockTableIndexBits) * 0x28));
 LAB_1:
   TRACELogPrint(0x80002,"lineRegisterRequestRecipient: exit, returning x%x",(ulonglong)*param_2,
                 param_4);
   return;
 }
 

```


## FreeDialogInstance

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.34|
|i_ratio|0.68|
|m_ratio|1.0|
|b_ratio|0.82|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|FreeDialogInstance|FreeDialogInstance|
|fullname|FreeDialogInstance|FreeDialogInstance|
|refcount|5|5|
|`length`|3678|3718|
|called|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegDeleteValueW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegQueryValueExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegSetValueExW<br>DereferenceObject<br>GetLineLookupEntry<br>GetPhoneLookupEntry<br>KERNEL32.DLL::CloseHandle<br>KERNEL32.DLL::DeleteCriticalSection<br>KERNEL32.DLL::EnterCriticalSection</summary>KERNEL32.DLL::FreeLibrary<br>KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetPrivateProfileSectionNamesW<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>KERNEL32.DLL::ReleaseMutex<br>KERNEL32.DLL::Sleep<br>KERNEL32.DLL::WaitForSingleObject<br>KERNEL32.DLL::WritePrivateProfileStringW<br>KERNEL32.DLL::lstrlenW<br>LineEventProc<br>MSVCRT.DLL::wcsncmp<br>MyCloseMutex<br>MyGetPrivateProfileString<br>PhoneEventProc<br>ReferenceObject<br>ServerFree<br>ServerInit<br>StringCbCopyA<br>StringCbPrintfW<br>TRACELogPrint<br>WaitForExclusiveClientAccess<br>__report_rangecheckfailure<br>__security_check_cookie<br>_guard_xfg_dispatch_icall_nop</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegDeleteValueW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegQueryValueExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegSetValueExW<br>DereferenceObject<br>GetLineLookupEntry<br>GetPhoneLookupEntry<br>KERNEL32.DLL::CloseHandle<br>KERNEL32.DLL::DeleteCriticalSection<br>KERNEL32.DLL::EnterCriticalSection</summary>KERNEL32.DLL::FreeLibrary<br>KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetPrivateProfileSectionNamesW<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>KERNEL32.DLL::ReleaseMutex<br>KERNEL32.DLL::Sleep<br>KERNEL32.DLL::WaitForSingleObject<br>KERNEL32.DLL::WritePrivateProfileStringW<br>KERNEL32.DLL::lstrlenW<br>LineEventProc<br>MSVCRT.DLL::wcsncmp<br>MyCloseMutex<br>MyGetPrivateProfileString<br>PhoneEventProc<br>ReferenceObject<br>ServerFree<br>ServerInit<br>StringCbCopyA<br>StringCbPrintfW<br>TRACELogPrint<br>WaitForExclusiveClientAccess<br>__report_rangecheckfailure<br>__security_check_cookie<br>_guard_xfg_dispatch_icall_nop</details>|
|calling|CleanUpClient<br>DestroytLineApp|CleanUpClient<br>DestroytLineApp|
|paramcount|4|4|
|`address`|180028c90|1800296c0|
|`sig`|undefined __fastcall FreeDialogInstance(LPCRITICAL_SECTION param_1, wchar_t * * param_2, undefined8 param_3, undefined8 param_4)|undefined __fastcall FreeDialogInstance(LPCRITICAL_SECTION param_1, LPWSTR param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### FreeDialogInstance Diff


```diff
--- FreeDialogInstance
+++ FreeDialogInstance
@@ -1,481 +1,487 @@
 
+/* WARNING: Control flow encountered bad instruction data */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_xfg_dispatch_icall_nop replaced with injection: guard_dispatch_icall */
 /* WARNING: Type propagation algorithm not settling */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
-void FreeDialogInstance(LPCRITICAL_SECTION param_1,wchar_t **param_2,undefined8 param_3,
+void FreeDialogInstance(LPCRITICAL_SECTION param_1,LPWSTR param_2,undefined8 param_3,
                        undefined8 param_4)
 
 {
-  HANDLE pvVar1;
-  code *pcVar2;
-  short sVar3;
-  LSTATUS LVar4;
-  int iVar5;
-  DWORD DVar6;
-  LPWSTR pWVar7;
-  ulonglong uVar8;
+  LSTATUS LVar1;
+  int iVar2;
+  DWORD DVar3;
+  wchar_t **ppwVar4;
+  ulonglong uVar5;
   LPWSTR lpszReturnBuffer;
-  LPCRITICAL_SECTION p_Var9;
-  ushort *puVar10;
-  uint *puVar11;
-  LPVOID pvVar12;
-  int *piVar13;
-  ushort uVar14;
-  longlong lVar15;
-  LPVOID *ppvVar16;
-  LPWSTR pWVar17;
-  wchar_t *pwVar18;
-  char *pcVar19;
-  uint uVar20;
+  LPWSTR pWVar6;
+  wchar_t *pwVar7;
+  uint *puVar8;
+  LPVOID pvVar9;
+  int *piVar10;
+  wchar_t wVar11;
+  LPVOID *ppvVar12;
+  LPCRITICAL_SECTION lpCriticalSection;
+  wchar_t **ppwVar13;
+  wchar_t *pwVar14;
+  char *pcVar15;
+  uint uVar16;
   DWORD nSize;
-  LPCRITICAL_SECTION _Str1;
-  short *psVar21;
-  LPVOID pvVar22;
-  undefined8 uVar23;
-  _RTL_CRITICAL_SECTION_DEBUG *p_Var24;
-  undefined8 uVar25;
-  ulonglong uVar26;
-  LPCRITICAL_SECTION *pp_Var27;
-  _RTL_CRITICAL_SECTION_DEBUG *p_Var28;
+  LPWSTR _Str1;
+  LPVOID pvVar17;
+  LPWSTR *ppWVar18;
+  _RTL_CRITICAL_SECTION_DEBUG *p_Var19;
+  longlong lVar20;
+  ulonglong uVar21;
+  _RTL_CRITICAL_SECTION_DEBUG *p_Var22;
+  bool bVar23;
   undefined1 auStackY_368 [32];
   uint local_338;
   DWORD local_334;
   HKEY local_330;
   DWORD local_328;
   uint local_324;
-  ulonglong local_320;
-  int local_318;
-  int local_314;
-  uint local_310;
-  LPCRITICAL_SECTION local_308;
+  int local_320;
+  int local_31c;
+  uint local_318;
+  LPCRITICAL_SECTION local_310;
+  wchar_t **local_308;
   LPWSTR local_300;
-  wchar_t **local_2f8;
+  LPWSTR local_2f8;
   LPCWSTR local_2f0;
-  LPWSTR local_2e8;
-  wchar_t **local_2e0;
+  wchar_t **local_2e8;
+  LPWSTR local_2e0;
   wchar_t *local_2d8;
   wchar_t *local_2d0;
   wchar_t local_2c8 [32];
   wchar_t local_288 [31];
   undefined2 auStack_24a [265];
   ulonglong local_38;
   
   local_38 = __security_cookie ^ (ulonglong)auStackY_368;
-  local_2e0 = param_2 + 1;
-  local_308 = param_1;
-  local_2f8 = param_2;
-  pWVar7 = (LPWSTR)ReferenceObject(param_1,*(uint *)local_2e0,0x474f4c44);
-  local_300 = pWVar7;
-  local_2e8 = pWVar7;
-  TRACELogPrint(0x80002,"FreeDialogInstance: enter, pDlgInst=x%p",pWVar7,param_4);
-  if (*(int *)pWVar7 == 0x474f4c44) {
-    pWVar7[0] = L'义';
-    pWVar7[1] = L'䱖';
+  pWVar6 = param_2 + 4;
+  local_310 = param_1;
+  local_300 = param_2;
+  local_2e0 = pWVar6;
+  ppwVar4 = (wchar_t **)ReferenceObject(param_1,*(uint *)pWVar6,0x474f4c44);
+  local_308 = ppwVar4;
+  local_2e8 = ppwVar4;
+  TRACELogPrint(0x80002,"FreeDialogInstance: enter, pDlgInst=x%p",ppwVar4,param_4);
+  uVar16 = *(uint *)(ppwVar4 + 2);
+  if (param_1[6].LockCount == uVar16) {
+    if (*(int *)ppwVar4 == 0x474f4c44) {
+      *(int *)ppwVar4 = 0x4c564e49;
+    }
+    else {
+      param_2[0] = L'H';
+      param_2[1] = L'耀';
+    }
   }
   else {
-    *(undefined4 *)param_2 = 0x80000048;
-  }
-  uVar20 = 0;
+    param_2[0] = L'H';
+    param_2[1] = L'耀';
+    DereferenceObject((ulonglong)uVar16,*(uint *)pWVar6,1);
+  }
+  uVar16 = 0;
   if (*(int *)param_2 != 0) {
     return;
   }
-  if (*(longlong *)(pWVar7 + 0xc) == 0) {
-    if (*(code **)(*(longlong *)(pWVar7 + 0x14) + 0x3c8) != (code *)0x0) {
-      (**(code **)(*(longlong *)(pWVar7 + 0x14) + 0x3c8))(*(undefined8 *)(pWVar7 + 0x18));
+  if (ppwVar4[3] == (wchar_t *)0x0) {
+    if (*(code **)(ppwVar4[5] + 0x1e4) != (code *)0x0) {
+      (**(code **)(ppwVar4[5] + 0x1e4))(ppwVar4[6]);
     }
     goto LAB_0;
   }
-  if (*(longlong *)(pWVar7 + 0x1c) == 0) {
-    if ((*(int *)(pWVar7 + 0x20) != 0) && (*(int *)((longlong)param_2 + 0xc) == 0)) {
+  if (ppwVar4[7] == (wchar_t *)0x0) {
+    if ((*(int *)(ppwVar4 + 8) != 0) && (*(int *)(param_2 + 6) == 0)) {
       WaitForSingleObject(ghProvRegistryMutex,0xffffffff);
-      LVar4 = RegOpenKeyExW((HKEY)&DAT_1,
+      LVar1 = RegOpenKeyExW((HKEY)&DAT_1,
                             L"Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Providers",0,
                             0xf003f,&local_330);
-      if (LVar4 != 0) goto LAB_2;
-      uVar23 = 4;
+      if (LVar1 != 0) goto LAB_2;
+      ppWVar18 = (LPWSTR *)0x4;
       local_334 = 4;
       local_338 = 0;
       RegQueryValueExW(local_330,L"NumProviders",(LPDWORD)0x0,&local_328,(LPBYTE)&local_338,
                        &local_334);
       if (local_338 != 0) {
         do {
           StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderID");
           local_334 = 4;
-          local_318 = 0;
-          RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,(LPBYTE)&local_318,&local_334
+          local_320 = 0;
+          RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,(LPBYTE)&local_320,&local_334
                           );
-          if (local_318 == *(int *)(pWVar7 + 8)) break;
-          uVar20 = uVar20 + 1;
-        } while (uVar20 < local_338);
+          if (local_320 == *(int *)((longlong)ppwVar4 + 0x14)) break;
+          uVar16 = uVar16 + 1;
+        } while (uVar16 < local_338);
       }
 LAB_3:
-      if (uVar20 < local_338 - 1) {
-        local_324 = uVar20 + 1;
+      if (uVar16 < local_338 - 1) {
+        local_324 = uVar16 + 1;
         StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderID");
         local_334 = 0x208;
-        LVar4 = RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,
+        LVar1 = RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,
                                  (LPBYTE)(auStack_24a + 1),&local_334);
-        if (LVar4 == 0) {
-          if (0x207 < ((ulonglong)local_334 & 0xfffffffffffffffe) - 2) goto LAB_4;
+        if (LVar1 == 0) {
+          uVar5 = ((ulonglong)local_334 & 0xfffffffffffffffe) - 2;
+          if (0x207 < uVar5) goto LAB_4;
           *(undefined2 *)((longlong)auStack_24a + ((ulonglong)local_334 & 0xfffffffffffffffe)) = 0;
           StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderID");
           RegSetValueExW(local_330,local_2c8,0,4,(BYTE *)(auStack_24a + 1),4);
         }
         StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderFilename");
         local_334 = 0x208;
-        LVar4 = RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,
+        LVar1 = RegQueryValueExW(local_330,local_2c8,(LPDWORD)0x0,&local_328,
                                  (LPBYTE)(auStack_24a + 1),&local_334);
-        uVar20 = local_324;
-        if (LVar4 == 0) {
-          if (0x207 < ((ulonglong)local_334 & 0xfffffffffffffffe) - 2) {
+        uVar16 = local_324;
+        if (LVar1 == 0) {
+          uVar5 = ((ulonglong)local_334 & 0xfffffffffffffffe) - 2;
+          if (0x207 < uVar5) {
 LAB_4:
+            bVar23 = SBORROW8(uVar5,0x208);
             __report_rangecheckfailure();
-            pcVar2 = (code *)swi(3);
-            (*pcVar2)();
-            return;
+            if (!bVar23) {
+              return;
+            }
+                    /* WARNING: Bad instruction - Truncating control flow here */
+            halt_baddata();
           }
           *(undefined2 *)((longlong)auStack_24a + ((ulonglong)local_334 & 0xfffffffffffffffe)) = 0;
           StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderFilename");
-          iVar5 = lstrlenW(auStack_24a + 1);
-          RegSetValueExW(local_330,local_2c8,0,1,(BYTE *)(auStack_24a + 1),iVar5 * 2 + 2);
-          uVar20 = local_324;
+          iVar2 = lstrlenW(auStack_24a + 1);
+          RegSetValueExW(local_330,local_2c8,0,1,(BYTE *)(auStack_24a + 1),iVar2 * 2 + 2);
+          uVar16 = local_324;
         }
         goto LAB_3;
       }
       StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderID");
       RegDeleteValueW(local_330,local_2c8);
       StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderFilename");
       RegDeleteValueW(local_330,local_2c8);
       local_338 = local_338 - 1;
-      uVar25 = 0;
-      pwVar18 = L"NumProviders";
+      pwVar14 = L"NumProviders";
       RegSetValueExW(local_330,L"NumProviders",0,4,(BYTE *)&local_338,4);
       RegCloseKey(local_330);
       ReleaseMutex(ghProvRegistryMutex);
-      nSize = 0;
       lpszReturnBuffer = (LPWSTR)0x0;
-      p_Var9 = (LPCRITICAL_SECTION)0x0;
+      local_300 = (LPWSTR)0x0;
       local_2d8 = gszLines;
       local_2d0 = gszPhones;
-      pWVar17 = (LPWSTR)0x0;
+      pWVar6 = lpszReturnBuffer;
       if (gbNTServer != 0) {
-        TRACELogPrint(0x40002,"FreeDialogInstance: getting user names",uVar25,uVar23);
+        TRACELogPrint(0x40002,"FreeDialogInstance: getting user names",0,ppWVar18);
+        nSize = 0;
         do {
           if (lpszReturnBuffer == (LPWSTR)0x0) {
             nSize = 0x100;
           }
           else {
             ServerFree(lpszReturnBuffer);
             nSize = nSize * 2;
           }
-          pwVar18 = (wchar_t *)0x8;
+          pwVar14 = (wchar_t *)0x8;
           local_324 = nSize;
           lpszReturnBuffer = HeapAlloc(ghTapisrvHeap,8,(ulonglong)(nSize * 2));
+          pWVar6 = (LPWSTR)0x0;
           if (lpszReturnBuffer == (LPWSTR)0x0) goto LAB_5;
           *lpszReturnBuffer = L'\0';
-          DVar6 = GetPrivateProfileSectionNamesW(lpszReturnBuffer,nSize,gszFileName);
-        } while (nSize - 2 <= DVar6);
-        uVar25 = 0x80;
+          DVar3 = GetPrivateProfileSectionNamesW(lpszReturnBuffer,nSize,gszFileName);
+        } while (nSize - 2 <= DVar3);
+        lVar20 = 0x80;
         local_324 = 0x80;
         local_300 = lpszReturnBuffer;
-        p_Var9 = HeapAlloc(ghTapisrvHeap,8,0x80);
-        local_308 = p_Var9;
-        if (p_Var9 == (LPCRITICAL_SECTION)0x0) {
-          pcVar19 = "FreeDialogInstance: Memory failure";
-          TRACELogPrint(0x10002,"FreeDialogInstance: Memory failure",uVar25,uVar23);
-          pwVar18 = (wchar_t *)pcVar19;
-          pWVar17 = lpszReturnBuffer;
+        pWVar6 = HeapAlloc(ghTapisrvHeap,8,0x80);
+        local_2f8 = pWVar6;
+        if (pWVar6 == (LPWSTR)0x0) {
+          pcVar15 = "FreeDialogInstance: Memory failure";
+LAB_6:
+          TRACELogPrint(0x10002,pcVar15,lVar20,ppWVar18);
+          pwVar14 = (wchar_t *)pcVar15;
         }
         else {
-          pwVar18 = (wchar_t *)0x28;
+          pwVar14 = (wchar_t *)0x28;
           StringCbPrintfW(local_288,0x28,L"%d");
-          uVar8 = 0xffffffffffffffff;
+          uVar5 = 0xffffffffffffffff;
           do {
-            uVar8 = uVar8 + 1;
-            local_320 = uVar8;
-          } while (local_288[uVar8] != L'\0');
-          for (; pWVar17 = local_300, *lpszReturnBuffer != L'\0';
-              lpszReturnBuffer = lpszReturnBuffer + 1) {
-            local_2f8 = &local_2d8;
-            for (local_310 = 0; local_310 < 2; local_310 = local_310 + 1) {
-              local_314 = 0;
-              pwVar18 = *local_2f8;
-              pp_Var27 = &local_308;
-              local_2f0 = pwVar18;
-              uVar20 = MyGetPrivateProfileString(lpszReturnBuffer,pwVar18,0,pp_Var27,&local_324);
-              p_Var9 = local_308;
-              _Str1 = local_308;
-              if (uVar20 == 0) {
-                while (*(short *)&_Str1->DebugInfo != 0) {
-                  pwVar18 = local_288;
-                  iVar5 = wcsncmp((wchar_t *)_Str1,pwVar18,uVar8 & 0xffffffff);
-                  lVar15 = 0;
-                  if (iVar5 == 0) {
-                    local_314 = 1;
-                    psVar21 = (short *)((longlong)&_Str1->DebugInfo + (uVar8 & 0xffffffff) * 2);
-                    if (*psVar21 != 0x2c) {
-                      pcVar19 = "FreeDialogInstance: Corrupted tsec.ini";
-                      TRACELogPrint(0x10002,"FreeDialogInstance: Corrupted tsec.ini",0,pp_Var27);
-                      pwVar18 = (wchar_t *)pcVar19;
-                      pWVar17 = local_300;
-                      goto LAB_5;
+            uVar5 = uVar5 + 1;
+          } while (local_288[uVar5] != L'\0');
+          for (; *lpszReturnBuffer != L'\0'; lpszReturnBuffer = lpszReturnBuffer + 1) {
+            local_318 = 0;
+            local_308 = &local_2d8;
+            do {
+              local_31c = 0;
+              pwVar14 = *local_308;
+              ppWVar18 = &local_2f8;
+              local_2f0 = pwVar14;
+              uVar16 = MyGetPrivateProfileString(lpszReturnBuffer,pwVar14,0,ppWVar18,&local_324);
+              pWVar6 = local_2f8;
+              if (uVar16 == 0) {
+                if (*local_2f8 != L'\0') {
+                  local_310 = (LPCRITICAL_SECTION)(uVar5 & 0xffffffff);
+                  _Str1 = local_2f8;
+                  do {
+                    pwVar14 = local_288;
+                    iVar2 = wcsncmp(_Str1,pwVar14,(size_t)local_310);
+                    lVar20 = 0;
+                    if (iVar2 == 0) {
+                      local_31c = 1;
+                      if (_Str1[(longlong)local_310] != L',') {
+                        pcVar15 = "FreeDialogInstance: Corrupted tsec.ini";
+                        goto LAB_6;
+                      }
+                      pwVar7 = _Str1 + (longlong)local_310 + 1;
+                      wVar11 = *pwVar7;
+                      if (wVar11 != L',') {
+                        pwVar14 = (wchar_t *)(ulonglong)(ushort)wVar11;
+                        do {
+                          wVar11 = L'\0';
+                          if ((short)pwVar14 == 0) break;
+                          pwVar7 = pwVar7 + 1;
+                          wVar11 = *pwVar7;
+                          pwVar14 = (wchar_t *)(ulonglong)(ushort)wVar11;
+                        } while (wVar11 != L',');
+                      }
+                      if (wVar11 == L'\0') {
+                        if (pWVar6 < _Str1) {
+                          _Str1[-1] = L'\0';
+                        }
+                        else {
+                          *pWVar6 = L'\0';
+                        }
+                        break;
+                      }
+                      while( true ) {
+                        pwVar7 = pwVar7 + 1;
+                        if (*pwVar7 == L'\0') break;
+                        _Str1[lVar20] = *pwVar7;
+                        lVar20 = lVar20 + 1;
+                      }
+                      _Str1[lVar20] = L'\0';
+                      pwVar14 = (wchar_t *)0x0;
                     }
-                    puVar10 = (ushort *)(psVar21 + 1);
-                    uVar14 = *puVar10;
-                    if (uVar14 != 0x2c) {
-                      pwVar18 = (wchar_t *)(ulonglong)uVar14;
+                    else {
+                      wVar11 = *_Str1;
+                      if (wVar11 == L'\0') break;
                       do {
-                        uVar14 = 0;
-                        if ((short)pwVar18 == 0) break;
-                        puVar10 = puVar10 + 1;
-                        uVar14 = *puVar10;
-                        pwVar18 = (wchar_t *)(ulonglong)uVar14;
-                      } while (uVar14 != 0x2c);
+                        if (wVar11 == L',') break;
+                        _Str1 = _Str1 + 1;
+                        wVar11 = *_Str1;
+                      } while (wVar11 != L'\0');
+                      if (wVar11 == L'\0') break;
+                      pwVar7 = _Str1 + 1;
+                      wVar11 = *pwVar7;
+                      if (wVar11 == L'\0') break;
+                      do {
+                        if (wVar11 == L',') break;
+                        pwVar7 = pwVar7 + 1;
+                        wVar11 = *pwVar7;
+                      } while (wVar11 != L'\0');
+                      if (wVar11 == L'\0') break;
+                      _Str1 = pwVar7 + 1;
                     }
-                    if (uVar14 == 0) {
-                      if (p_Var9 < _Str1) {
-                        *(undefined2 *)((longlong)&_Str1[-1].SpinCount + 6) = 0;
-                        uVar8 = local_320;
-                      }
-                      else {
-                        *(undefined2 *)&p_Var9->DebugInfo = 0;
-                        uVar8 = local_320;
-                      }
-                      break;
-                    }
-                    while( true ) {
-                      puVar10 = puVar10 + 1;
-                      if (*puVar10 == 0) break;
-                      *(ushort *)((longlong)&_Str1->DebugInfo + lVar15 * 2) = *puVar10;
-                      lVar15 = lVar15 + 1;
-                    }
-                    *(undefined2 *)((longlong)&_Str1->DebugInfo + lVar15 * 2) = 0;
-                    pwVar18 = (wchar_t *)0x0;
-                    uVar8 = local_320;
-                  }
-                  else {
-                    sVar3 = *(short *)&_Str1->DebugInfo;
-                    uVar8 = local_320;
-                    if (sVar3 == 0) break;
-                    do {
-                      if (sVar3 == 0x2c) break;
-                      _Str1 = (LPCRITICAL_SECTION)((longlong)&_Str1->DebugInfo + 2);
-                      sVar3 = *(short *)&_Str1->DebugInfo;
-                    } while (sVar3 != 0);
-                    if (sVar3 == 0) break;
-                    psVar21 = (short *)((longlong)&_Str1->DebugInfo + 2);
-                    sVar3 = *psVar21;
-                    if (sVar3 == 0) break;
-                    do {
-                      if (sVar3 == 0x2c) break;
-                      psVar21 = psVar21 + 1;
-                      sVar3 = *psVar21;
-                    } while (sVar3 != 0);
-                    if (sVar3 == 0) break;
-                    _Str1 = (LPCRITICAL_SECTION)(psVar21 + 1);
-                  }
+                  } while (*_Str1 != L'\0');
                 }
-                if (local_314 != 0) {
-                  pwVar18 = local_2f0;
-                  WritePrivateProfileStringW(lpszReturnBuffer,local_2f0,(LPCWSTR)p_Var9,gszFileName)
-                  ;
+                if (local_31c != 0) {
+                  pwVar14 = local_2f0;
+                  WritePrivateProfileStringW(lpszReturnBuffer,local_2f0,pWVar6,gszFileName);
                 }
               }
-              local_2f8 = local_2f8 + 1;
-            }
+              local_318 = local_318 + 1;
+              local_308 = local_308 + 1;
+            } while (local_318 < 2);
             for (; *lpszReturnBuffer != L'\0'; lpszReturnBuffer = lpszReturnBuffer + 1) {
             }
           }
         }
       }
 LAB_5:
-      ServerFree(pWVar17);
-      ServerFree(p_Var9);
+      ServerFree(local_300);
+      ServerFree(pWVar6);
       EnterCriticalSection((LPCRITICAL_SECTION)&gMgmtCritSec);
-      EnterCriticalSection((LPCRITICAL_SECTION)&DAT_6);
-      _DAT_7 = 0x2bc7;
-      _DAT_8 = GetCurrentThreadId();
-      StringCbCopyA(&DAT_9,(size_t)pwVar18,"server\\server.c");
-      p_Var24 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
-      if (DAT_10 == (LPVOID)0x0) {
-LAB_11:
+      EnterCriticalSection((LPCRITICAL_SECTION)&DAT_7);
+      _DAT_8 = 0x2bce;
+      _DAT_9 = GetCurrentThreadId();
+      StringCbCopyA(&DAT_10,(size_t)pwVar14,"server\\server.c");
+      p_Var19 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
+      if (DAT_11 == (LPVOID)0x0) {
+LAB_12:
         LeaveCriticalSection((LPCRITICAL_SECTION)&gMgmtCritSec);
-        _DAT_12 = 0x2bd9;
+        _DAT_13 = 0x2be0;
       }
       else {
-        pvVar22 = DAT_10;
+        pvVar17 = DAT_11;
         do {
-          if (*(int *)((longlong)pvVar22 + 0x20) == *(int *)(pWVar7 + 8)) break;
-          pvVar22 = *(LPVOID *)((longlong)pvVar22 + 0x30);
-        } while (pvVar22 != (LPVOID)0x0);
-        if (pvVar22 == (LPVOID)0x0) goto LAB_11;
-        uVar8 = (ulonglong)DAT_13;
-        p_Var28 = p_Var24;
-        if (DAT_13 != 0) {
-          do {
-            puVar11 = GetLineLookupEntry((uint)p_Var24);
-            if (((puVar11 != (uint *)0x0) && (*(LPVOID *)(puVar11 + 6) == pvVar22)) &&
-               (puVar11[8] == (uint)p_Var28)) {
-              LineEventProc((_RTL_CRITICAL_SECTION_DEBUG *)0x0,(_RTL_CRITICAL_SECTION_DEBUG *)0x0,
-                            0x19,p_Var24,p_Var28,p_Var28);
-              uVar8 = (ulonglong)DAT_13;
-              p_Var28 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
-            }
-            uVar20 = (uint)p_Var24 + 1;
-            p_Var24 = (_RTL_CRITICAL_SECTION_DEBUG *)(ulonglong)uVar20;
-          } while (uVar20 < (uint)uVar8);
-        }
-        uVar8 = (ulonglong)p_Var28 & 0xffffffff;
-        uVar26 = (ulonglong)DAT_14;
+          if (*(int *)((longlong)pvVar17 + 0x20) == *(int *)((longlong)ppwVar4 + 0x14)) break;
+          pvVar17 = *(LPVOID *)((longlong)pvVar17 + 0x30);
+        } while (pvVar17 != (LPVOID)0x0);
+        if (pvVar17 == (LPVOID)0x0) goto LAB_12;
+        uVar5 = (ulonglong)DAT_14;
+        p_Var22 = p_Var19;
         if (DAT_14 != 0) {
           do {
-            puVar11 = GetPhoneLookupEntry((uint)uVar8);
-            if (((puVar11 != (uint *)0x0) && (*(LPVOID *)(puVar11 + 6) == pvVar22)) &&
-               (puVar11[8] == (uint)p_Var28)) {
-              PhoneEventProc((int *)0x0,0x1a,uVar8,(LPHANDLE)0x0,(uint)p_Var28);
-              uVar26 = (ulonglong)DAT_14;
-              p_Var28 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
+            puVar8 = GetLineLookupEntry((uint)p_Var19);
+            if (((puVar8 != (uint *)0x0) && (*(LPVOID *)(puVar8 + 6) == pvVar17)) &&
+               (puVar8[8] == (uint)p_Var22)) {
+              LineEventProc((_RTL_CRITICAL_SECTION_DEBUG *)0x0,(_RTL_CRITICAL_SECTION_DEBUG *)0x0,
+                            0x19,p_Var19,p_Var22,p_Var22);
+              uVar5 = (ulonglong)DAT_14;
+              p_Var22 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
             }
-            uVar20 = (uint)uVar8 + 1;
-            uVar8 = (ulonglong)uVar20;
-          } while (uVar20 < (uint)uVar26);
+            uVar16 = (uint)p_Var19 + 1;
+            p_Var19 = (_RTL_CRITICAL_SECTION_DEBUG *)(ulonglong)uVar16;
+          } while (uVar16 < (uint)uVar5);
+        }
+        uVar5 = (ulonglong)p_Var22 & 0xffffffff;
+        uVar21 = (ulonglong)DAT_15;
+        if (DAT_15 != 0) {
+          do {
+            puVar8 = GetPhoneLookupEntry((uint)uVar5);
+            if (((puVar8 != (uint *)0x0) && (*(LPVOID *)(puVar8 + 6) == pvVar17)) &&
+               (puVar8[8] == (uint)p_Var22)) {
+              PhoneEventProc((int *)0x0,0x1a,uVar5,(LPHANDLE)0x0,(uint)p_Var22);
+              uVar21 = (ulonglong)DAT_15;
+              p_Var22 = (_RTL_CRITICAL_SECTION_DEBUG *)0x0;
+            }
+            uVar16 = (uint)uVar5 + 1;
+            uVar5 = (ulonglong)uVar16;
+          } while (uVar16 < (uint)uVar21);
         }
         LeaveCriticalSection((LPCRITICAL_SECTION)&gMgmtCritSec);
-        ppvVar16 = &DAT_15;
-        if (DAT_15 != (LPVOID)0x0) {
-          pvVar12 = DAT_15;
+        ppvVar12 = &DAT_16;
+        if (DAT_16 != (LPVOID)0x0) {
+          pvVar9 = DAT_16;
           do {
-            if (*(int *)((longlong)pvVar12 + 4) == *(int *)((longlong)pvVar22 + 0x20)) break;
-            ppvVar16 = (LPVOID *)((longlong)pvVar12 + 0x28);
-            pvVar12 = *ppvVar16;
-          } while (pvVar12 != (LPVOID)0x0);
-          if (pvVar12 != (LPVOID)0x0) {
-            *ppvVar16 = *(LPVOID *)((longlong)pvVar12 + 0x28);
-            ServerFree(*(LPVOID *)((longlong)pvVar12 + 8));
-            ServerFree(*(LPVOID *)((longlong)pvVar12 + 0x18));
-            ServerFree(pvVar12);
+            if (*(int *)((longlong)pvVar9 + 4) == *(int *)((longlong)pvVar17 + 0x20)) break;
+            ppvVar12 = (LPVOID *)((longlong)pvVar9 + 0x28);
+            pvVar9 = *ppvVar12;
+          } while (pvVar9 != (LPVOID)0x0);
+          if (pvVar9 != (LPVOID)0x0) {
+            *ppvVar12 = *(LPVOID *)((longlong)pvVar9 + 0x28);
+            ServerFree(*(LPVOID *)((longlong)pvVar9 + 8));
+            ServerFree(*(LPVOID *)((longlong)pvVar9 + 0x18));
+            ServerFree(pvVar9);
           }
         }
-        if (*(longlong *)((longlong)pvVar22 + 0x30) != 0) {
-          *(undefined8 *)(*(longlong *)((longlong)pvVar22 + 0x30) + 0x28) =
-               *(undefined8 *)((longlong)pvVar22 + 0x28);
-        }
-        pvVar12 = *(LPVOID *)((longlong)pvVar22 + 0x30);
-        if (*(longlong *)((longlong)pvVar22 + 0x28) != 0) {
-          *(LPVOID *)(*(longlong *)((longlong)pvVar22 + 0x28) + 0x30) =
-               *(LPVOID *)((longlong)pvVar22 + 0x30);
-          pvVar12 = DAT_10;
-        }
-        DAT_10 = pvVar12;
-        pwVar18 = (wchar_t *)(ulonglong)*(uint *)((longlong)pvVar22 + 0x20);
-        (**(code **)((longlong)pvVar22 + 0x3e0))(*(undefined4 *)((longlong)pvVar22 + 0x1c));
+        if (*(longlong *)((longlong)pvVar17 + 0x30) != 0) {
+          *(undefined8 *)(*(longlong *)((longlong)pvVar17 + 0x30) + 0x28) =
+               *(undefined8 *)((longlong)pvVar17 + 0x28);
+        }
+        pvVar9 = *(LPVOID *)((longlong)pvVar17 + 0x30);
+        if (*(longlong *)((longlong)pvVar17 + 0x28) != 0) {
+          *(LPVOID *)(*(longlong *)((longlong)pvVar17 + 0x28) + 0x30) =
+               *(LPVOID *)((longlong)pvVar17 + 0x30);
+          pvVar9 = DAT_11;
+        }
+        DAT_11 = pvVar9;
+        pwVar14 = (wchar_t *)(ulonglong)*(uint *)((longlong)pvVar17 + 0x20);
+        (**(code **)((longlong)pvVar17 + 0x3e0))(*(undefined4 *)((longlong)pvVar17 + 0x1c));
         Sleep(5000);
-        FreeLibrary(*(HMODULE *)((longlong)pvVar22 + 0x10));
-        MyCloseMutex(*(HANDLE *)((longlong)pvVar22 + 8));
-        CloseHandle(*(HANDLE *)((longlong)pvVar22 + 0x50));
-        DeleteCriticalSection((LPCRITICAL_SECTION)((longlong)pvVar22 + 0x58));
-        ServerFree(*(LPVOID *)((longlong)pvVar22 + 0x40));
-        ServerFree(pvVar22);
-        _DAT_12 = 0x2c42;
-      }
-      _DAT_16 = GetCurrentThreadId();
-      StringCbCopyA(&DAT_17,(size_t)pwVar18,"server\\server.c");
-      LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_6);
+        FreeLibrary(*(HMODULE *)((longlong)pvVar17 + 0x10));
+        MyCloseMutex(*(HANDLE *)((longlong)pvVar17 + 8));
+        CloseHandle(*(HANDLE *)((longlong)pvVar17 + 0x50));
+        DeleteCriticalSection((LPCRITICAL_SECTION)((longlong)pvVar17 + 0x58));
+        ServerFree(*(LPVOID *)((longlong)pvVar17 + 0x40));
+        ServerFree(pvVar17);
+        _DAT_13 = 0x2c49;
+      }
+      _DAT_17 = GetCurrentThreadId();
+      StringCbCopyA(&DAT_18,(size_t)pwVar14,"server\\server.c");
+      LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_7);
     }
   }
   else {
-    if (*(int *)((longlong)param_2 + 0xc) == 0) {
+    if (*(int *)(param_2 + 6) == 0) {
       WaitForSingleObject(ghProvRegistryMutex,0xffffffff);
-      LVar4 = RegOpenKeyExW((HKEY)&DAT_1,
+      LVar1 = RegOpenKeyExW((HKEY)&DAT_1,
                             L"Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Providers",0,
                             0xf003f,&local_330);
-      if (LVar4 == 0) {
+      if (LVar1 == 0) {
         local_334 = 4;
         local_338 = 0;
         RegQueryValueExW(local_330,L"NumProviders",(LPDWORD)0x0,&local_328,(LPBYTE)&local_338,
                          &local_334);
         StringCbPrintfW(local_2c8,0x40,L"%s%d",L"ProviderID");
-        RegSetValueExW(local_330,local_2c8,0,4,(BYTE *)(pWVar7 + 8),4);
+        RegSetValueExW(local_330,local_2c8,0,4,(BYTE *)((longlong)ppwVar4 + 0x14),4);
         StringCbPrintfW(local_288,0x40,L"%s%d",L"ProviderFilename");
-        iVar5 = lstrlenW(*(LPCWSTR *)(pWVar7 + 0x1c));
-        RegSetValueExW(local_330,local_288,0,1,*(BYTE **)(pWVar7 + 0x1c),iVar5 * 2 + 2);
+        iVar2 = lstrlenW(ppwVar4[7]);
+        RegSetValueExW(local_330,local_288,0,1,(BYTE *)ppwVar4[7],iVar2 * 2 + 2);
         local_338 = local_338 + 1;
-        pwVar18 = L"NumProviders";
+        pwVar14 = L"NumProviders";
         RegSetValueExW(local_330,L"NumProviders",0,4,(BYTE *)&local_338,4);
         RegCloseKey(local_330);
         ReleaseMutex(ghProvRegistryMutex);
-        EnterCriticalSection((LPCRITICAL_SECTION)&DAT_6);
-        _DAT_7 = 0x2a26;
-        _DAT_8 = GetCurrentThreadId();
-        StringCbCopyA(&DAT_9,(size_t)pwVar18,"server\\server.c");
-        if (((DAT_18 != 0) || (DAT_18004dd88 != 0)) || (((byte)DAT_18004dd60 & 2) != 0)) {
-          uVar8 = ServerInit(1);
-          *(int *)param_2 = (int)uVar8;
-        }
-        _DAT_12 = 0x2a30;
-        _DAT_16 = GetCurrentThreadId();
-        StringCbCopyA(&DAT_17,(size_t)pwVar18,"server\\server.c");
-        LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_6);
-LAB_19:
-        ServerFree(*(LPVOID *)(pWVar7 + 0x1c));
-        goto LAB_20;
+        EnterCriticalSection((LPCRITICAL_SECTION)&DAT_7);
+        _DAT_8 = 0x2a2d;
+        _DAT_9 = GetCurrentThreadId();
+        StringCbCopyA(&DAT_10,(size_t)pwVar14,"server\\server.c");
+        if (((DAT_19 != 0) || (DAT_18004dd88 != 0)) || (((byte)DAT_18004dd60 & 2) != 0)) {
+          uVar5 = ServerInit(1);
+          *(int *)param_2 = (int)uVar5;
+        }
+        _DAT_13 = 0x2a37;
+        _DAT_17 = GetCurrentThreadId();
+        StringCbCopyA(&DAT_18,(size_t)pwVar14,"server\\server.c");
+        LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_7);
+LAB_20:
+        ServerFree(ppwVar4[7]);
+        goto LAB_21;
       }
     }
     else {
       WaitForSingleObject(ghProvRegistryMutex,0xffffffff);
-      LVar4 = RegOpenKeyExW((HKEY)&DAT_1,
+      LVar1 = RegOpenKeyExW((HKEY)&DAT_1,
                             L"Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Providers",0,
                             0xf003f,&local_330);
-      if (LVar4 == 0) {
+      if (LVar1 == 0) {
         local_334 = 4;
         local_338 = 0;
         RegQueryValueExW(local_330,L"NextProviderID",(LPDWORD)0x0,&local_328,(LPBYTE)&local_338,
                          &local_334);
-        if (*(int *)(pWVar7 + 8) + 1U == local_338) {
-          RegSetValueExW(local_330,L"NextProviderID",0,4,(BYTE *)(pWVar7 + 8),4);
+        if (*(int *)((longlong)ppwVar4 + 0x14) + 1U == local_338) {
+          RegSetValueExW(local_330,L"NextProviderID",0,4,(BYTE *)((longlong)ppwVar4 + 0x14),4);
         }
         RegCloseKey(local_330);
         ReleaseMutex(ghProvRegistryMutex);
-        goto LAB_19;
+        goto LAB_20;
       }
     }
 LAB_2:
     ReleaseMutex(ghProvRegistryMutex);
   }
-LAB_20:
-  FreeLibrary(*(HMODULE *)(pWVar7 + 0xc));
-  *(undefined4 *)param_2 = *(undefined4 *)((longlong)param_2 + 0xc);
+LAB_21:
+  FreeLibrary((HMODULE)ppwVar4[3]);
+  *(undefined4 *)param_2 = *(undefined4 *)(param_2 + 6);
 LAB_0:
-  p_Var9 = param_1;
-  piVar13 = WaitForExclusiveClientAccess((int *)param_1);
-  if (piVar13 != (int *)0x0) {
-    if (*(longlong *)(pWVar7 + 0x28) == 0) {
-      pWVar17 = local_2e8 + 0x24;
+  lpCriticalSection = param_1;
+  piVar10 = WaitForExclusiveClientAccess((int *)param_1);
+  if (piVar10 != (int *)0x0) {
+    if (ppwVar4[10] == (wchar_t *)0x0) {
+      ppwVar13 = local_2e8 + 9;
     }
     else {
-      pWVar17 = pWVar7 + 0x24;
-      *(longlong *)(*(longlong *)(pWVar7 + 0x28) + 0x48) = *(longlong *)pWVar17;
-    }
-    pvVar1 = *(HANDLE *)(pWVar7 + 0x28);
-    if (*(longlong *)pWVar17 == 0) {
-      if (*(longlong *)(pWVar7 + 0xc) == 0) {
-        param_1[4].SpinCount = (ULONG_PTR)pvVar1;
+      ppwVar13 = ppwVar4 + 9;
+      *(wchar_t **)(ppwVar4[10] + 0x24) = *ppwVar13;
+    }
+    pwVar14 = ppwVar4[10];
+    if (*ppwVar13 == (wchar_t *)0x0) {
+      if (ppwVar4[3] == (wchar_t *)0x0) {
+        param_1[4].SpinCount = (ULONG_PTR)pwVar14;
       }
       else {
-        param_1[4].LockSemaphore = pvVar1;
+        param_1[4].LockSemaphore = pwVar14;
       }
     }
     else {
-      *(HANDLE *)(*(longlong *)pWVar17 + 0x50) = pvVar1;
-    }
-    p_Var9 = (LPCRITICAL_SECTION)
-             (gLockTable +
-             ((ulonglong)param_1 >> 4 & (ulonglong)gdwPointerToLockTableIndexBits) * 0x28);
-    LeaveCriticalSection(p_Var9);
-  }
-  DereferenceObject(p_Var9,*(uint *)local_2e0,2);
+      *(wchar_t **)(*ppwVar13 + 0x28) = pwVar14;
+    }
+    lpCriticalSection =
+         (LPCRITICAL_SECTION)
+         (gLockTable + ((ulonglong)param_1 >> 4 & (ulonglong)gdwPointerToLockTableIndexBits) * 0x28)
+    ;
+    LeaveCriticalSection(lpCriticalSection);
+  }
+  DereferenceObject(lpCriticalSection,*(uint *)local_2e0,2);
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## KERNEL32.DLL::LeaveCriticalSection

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|LeaveCriticalSection|LeaveCriticalSection|
|fullname|KERNEL32.DLL::LeaveCriticalSection|KERNEL32.DLL::LeaveCriticalSection|
|`refcount`|228|229|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>AcquireHashTableEntryLock<br>AppendNewDeviceInfo<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>ClientDetach<br>CreateCallMonitors<br>CreateTapiSCP<br>CreatetCallClient<br>DequeueSPEvent<br>DereferenceObject</summary>DestroytCall<br>DestroytCallClient<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhoneApp<br>DestroytPhoneClient<br>EventNotificationThread<br>FreeDialogInstance<br>FreeOldDllListProc<br>GetAsyncEvents<br>GetCallClientListFromCall<br>GetCallIDs<br>GetClientList<br>GetDeviceInfo<br>GetHighestPriorityRequestRecipient<br>GetLineAppListFromClient<br>GetPhoneAppListFromClient<br>GetPriorityListForMediaModes<br>GetPriorityListTReqCall<br>GetTCClient<br>GetUIDllName<br>InitializeClient<br>InsertDevNameAddrInfo<br>LAccept<br>LAnswer<br>LCompleteTransfer_PostProcess<br>LGetAppPriority<br>LGetConfRelatedCalls<br>LGetID<br>LGetRequest<br>LHandoff<br>LInitialize<br>LMakeCall_PostProcess<br>LMonitorDigits<br>LMonitorMedia<br>LMonitorTones<br>LNegotiateAPIVersion<br>LProxyResponse<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetCallPrivilege<br>LSetNumRings<br>LSetStatusMessages<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetDeviceFlags<br>MSetLineInfo<br>MSetPhoneInfo<br>MSetServerConfig<br>NewObject<br>NotifyHighestPriorityRequestRecipient<br>OnProxyLineClose<br>OnProxyLineOpen<br>OnProxySCPInit<br>OnProxySCPShutdown<br>PCONTEXT_HANDLE_TYPE_rundown<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PSetStatusMessages<br>PhoneEventProc<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReferenceObject<br>RemoveCallClientFromLineClientList<br>RemoveDeviceInfoEntry<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SendProxyRequest<br>ServiceMain<br>ServiceShutdown<br>SetCallConfList<br>SetDeviceInfo<br>SetDrvCallFlags<br>SetGlobalEventMasks<br>SettCallClientEventMasks<br>SettClientEventMasks<br>SettLineAppEventMasks<br>SettLineClientEventMasks<br>SettPhoneAppEventMasks<br>SettPhoneClientEventMasks<br>TGetEventMasksOrSubMasks<br>TGetPermissibleMasks<br>TRequestMakeCall<br>TSetEventMasksOrSubMasks<br>TSetPermissibleMasks<br>UpdateCallHubHashing<br>UpdateTapiSCP<br>WaitForExclusiveClientAccess<br>WaitForExclusiveLineAppAccess<br>WaitForExclusiveLineClientAccess<br>WaitForExclusivePhoneAppAccess<br>WaitForExclusivePhoneClientAccess<br>WaitForExclusivetCallAccess<br>WaitForMutex<br>WriteEventBuffer<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AcquireHashTableEntryLock<br>AppendNewDeviceInfo<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>ClientDetach<br>CreateCallMonitors<br>CreateTapiSCP<br>CreatetCallClient<br>DequeueSPEvent<br>DereferenceObject</summary>DestroytCall<br>DestroytCallClient<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhoneApp<br>DestroytPhoneClient<br>EventNotificationThread<br>FreeDialogInstance<br>FreeOldDllListProc<br>GetAsyncEvents<br>GetCallClientListFromCall<br>GetCallIDs<br>GetClientList<br>GetDeviceInfo<br>GetHighestPriorityRequestRecipient<br>GetLineAppListFromClient<br>GetPhoneAppListFromClient<br>GetPriorityListForMediaModes<br>GetPriorityListTReqCall<br>GetTCClient<br>GetUIDllName<br>InitializeClient<br>InsertDevNameAddrInfo<br>LAccept<br>LAnswer<br>LCompleteTransfer_PostProcess<br>LGetAppPriority<br>LGetConfRelatedCalls<br>LGetID<br>LGetRequest<br>LHandoff<br>LInitialize<br>LMakeCall_PostProcess<br>LMonitorDigits<br>LMonitorMedia<br>LMonitorTones<br>LNegotiateAPIVersion<br>LProxyResponse<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetCallPrivilege<br>LSetNumRings<br>LSetStatusMessages<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetDeviceFlags<br>MSetLineInfo<br>MSetPhoneInfo<br>MSetServerConfig<br>NewObject<br>NotifyHighestPriorityRequestRecipient<br>OnProxyLineClose<br>OnProxyLineOpen<br>OnProxySCPInit<br>OnProxySCPShutdown<br>PCONTEXT_HANDLE_TYPE_rundown<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PSetStatusMessages<br>PhoneEventProc<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReferenceObject<br>RemoveCallClientFromLineClientList<br>RemoveDeviceInfoEntry<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SendProxyRequest<br>ServiceMain<br>ServiceShutdown<br>SetCallConfList<br>SetDeviceInfo<br>SetDrvCallFlags<br>SetGlobalEventMasks<br>SettCallClientEventMasks<br>SettClientEventMasks<br>SettLineAppEventMasks<br>SettLineClientEventMasks<br>SettPhoneAppEventMasks<br>SettPhoneClientEventMasks<br>TGetEventMasksOrSubMasks<br>TGetPermissibleMasks<br>TRequestMakeCall<br>TSetEventMasksOrSubMasks<br>TSetPermissibleMasks<br>TUISPIDLLCallback<br>UpdateCallHubHashing<br>UpdateTapiSCP<br>WaitForExclusiveClientAccess<br>WaitForExclusiveLineAppAccess<br>WaitForExclusiveLineClientAccess<br>WaitForExclusivePhoneAppAccess<br>WaitForExclusivePhoneClientAccess<br>WaitForExclusivetCallAccess<br>WaitForMutex<br>WriteEventBuffer<br>xxxLOpen</details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000007c|EXTERNAL:0000007e|
|sig|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### KERNEL32.DLL::LeaveCriticalSection Calling Diff


```diff
--- KERNEL32.DLL::LeaveCriticalSection calling
+++ KERNEL32.DLL::LeaveCriticalSection calling
@@ -97,0 +98 @@
+TUISPIDLLCallback
```


## TRACELogPrint

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.85|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|TRACELogPrint|TRACELogPrint|
|fullname|TRACELogPrint|TRACELogPrint|
|`refcount`|486|485|
|length|446|446|
|called|KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetLocalTime<br>KERNEL32.DLL::OutputDebugStringA<br>KERNEL32.DLL::lstrlenA<br>RTUTILS.DLL::TraceVprintfExA<br>StringCbCatA<br>StringCbPrintfA<br>StringVPrintfWorkerA<br>TraceLevel<br>__security_check_cookie|KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetLocalTime<br>KERNEL32.DLL::OutputDebugStringA<br>KERNEL32.DLL::lstrlenA<br>RTUTILS.DLL::TraceVprintfExA<br>StringCbCatA<br>StringCbPrintfA<br>StringVPrintfWorkerA<br>TraceLevel<br>__security_check_cookie|
|calling|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddProviderToIdArrayList<br>AllowAccessToScpProperties<br>BuildCountryListCache<br>BuildDeviceInfoList<br>ClientAttach<br>ClientDetach<br>ClientRequest<br>CompletionProc<br>CompletionProcSP</summary>CreateProxyRequest<br>CreateSCP<br>CreatetCall<br>CreatetCallAndClient<br>CreatetCallClient<br>DestroytCall<br>DestroytCallClient<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhone<br>DestroytPhoneApp<br>DestroytPhoneClient<br>EventNotificationThread<br>FMsgDisabled<br>FreeDialogInstance<br>GetAsyncEvents<br>GetCallListFromLine<br>GetDeviceAccess<br>GetDeviceIDFromPermanentID<br>GetDomainAndUserNames<br>GetLineClientListFromLine<br>GetMediaModesPriorityLists<br>GetPriorityList<br>GetPriorityListTReqCall<br>GetProviderFriendlyName<br>GetProviderSortedArray<br>GetUIDllName<br>InitSecurityDescriptor<br>InitializeClient<br>InsertIntoTable<br>IsBadSizeOffset<br>LClose<br>LDevSpecific<br>LForward<br>LGetAppPriority<br>LGetCallAddressID<br>LGetCallIDs<br>LGetConfRelatedCalls<br>LGetCountry<br>LGetCountryGroups<br>LGetHubRelatedCalls<br>LGetID<br>LGetIDEx<br>LGetNewCalls<br>LGetProviderList<br>LGetProxyStatus<br>LGetRequest<br>LGetStatusMessages<br>LHandoff<br>LInitialize<br>LMakeCall<br>LNegotiateAPIVersion<br>LProxyMessage<br>LProxyResponse<br>LReceiveMSPData<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetCallPrivilege<br>LSetMediaMode<br>LShutdown<br>LineEpilogAsync<br>LineEpilogSync<br>LineEventProc<br>LineEventProcSP<br>LineProlog<br>LoadCountryNameString<br>LoadNewDll<br>MGetAvailableProviders<br>MSetServerConfig<br>ManagementProc<br>NegotiateAPIVersionForAllDevices<br>NewToOldLineforwardlist<br>NotifyHighestPriorityRequestRecipient<br>PCONTEXT_HANDLE_TYPE_rundown<br>PGetIDEx<br>PGetStatusMessages<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PShutdown<br>PhoneEpilogAsync<br>PhoneEpilogSync<br>PhoneEventProc<br>PhoneEventProcSP<br>PhoneProlog<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReadAndInitMapper<br>RemoveSCP<br>ReportStatusToSCMgr<br>SPEventHandlerThread<br>SendBufferMsgToLineClients<br>SendMsgToLineClients<br>ServerInit<br>ServiceControl<br>ServiceMain<br>ServiceShutdown<br>SetDeviceInfo<br>StoreADialingRuleInReg<br>TPerformance<br>TReadLocations<br>TRequestMakeCall<br>TWriteLocations<br>UpdateSCP<br>UpdateTapiSCP<br>ValidateButtonInfo<br>ValidateCallParams<br>VerifyDomainName<br>WriteEventBuffer<br>WriteServiceConfig<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddProviderToIdArrayList<br>AllowAccessToScpProperties<br>BuildCountryListCache<br>BuildDeviceInfoList<br>ClientAttach<br>ClientDetach<br>ClientRequest<br>CompletionProc<br>CompletionProcSP</summary>CreateProxyRequest<br>CreateSCP<br>CreatetCall<br>CreatetCallAndClient<br>CreatetCallClient<br>DestroytCall<br>DestroytCallClient<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhone<br>DestroytPhoneApp<br>DestroytPhoneClient<br>EventNotificationThread<br>FMsgDisabled<br>FreeDialogInstance<br>GetAsyncEvents<br>GetCallListFromLine<br>GetDeviceAccess<br>GetDeviceIDFromPermanentID<br>GetDomainAndUserNames<br>GetLineClientListFromLine<br>GetMediaModesPriorityLists<br>GetPriorityList<br>GetPriorityListTReqCall<br>GetProviderFriendlyName<br>GetProviderSortedArray<br>GetUIDllName<br>InitSecurityDescriptor<br>InitializeClient<br>InsertIntoTable<br>IsBadSizeOffset<br>LClose<br>LDevSpecific<br>LForward<br>LGetAppPriority<br>LGetCallAddressID<br>LGetCallIDs<br>LGetConfRelatedCalls<br>LGetCountry<br>LGetCountryGroups<br>LGetHubRelatedCalls<br>LGetID<br>LGetIDEx<br>LGetNewCalls<br>LGetProviderList<br>LGetProxyStatus<br>LGetRequest<br>LGetStatusMessages<br>LHandoff<br>LInitialize<br>LMakeCall<br>LNegotiateAPIVersion<br>LProxyMessage<br>LProxyResponse<br>LReceiveMSPData<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetCallPrivilege<br>LSetMediaMode<br>LShutdown<br>LineEpilogAsync<br>LineEpilogSync<br>LineEventProc<br>LineEventProcSP<br>LineProlog<br>LoadCountryNameString<br>LoadNewDll<br>MGetAvailableProviders<br>MSetServerConfig<br>ManagementProc<br>NegotiateAPIVersionForAllDevices<br>NewToOldLineforwardlist<br>NotifyHighestPriorityRequestRecipient<br>PCONTEXT_HANDLE_TYPE_rundown<br>PGetIDEx<br>PGetStatusMessages<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PShutdown<br>PhoneEpilogAsync<br>PhoneEpilogSync<br>PhoneEventProc<br>PhoneEventProcSP<br>PhoneProlog<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReadAndInitMapper<br>RemoveSCP<br>ReportStatusToSCMgr<br>SPEventHandlerThread<br>SendBufferMsgToLineClients<br>SendMsgToLineClients<br>ServerInit<br>ServiceControl<br>ServiceMain<br>ServiceShutdown<br>SetDeviceInfo<br>StoreADialingRuleInReg<br>TPerformance<br>TReadLocations<br>TRequestMakeCall<br>TWriteLocations<br>UpdateSCP<br>UpdateTapiSCP<br>ValidateButtonInfo<br>ValidateCallParams<br>VerifyDomainName<br>WriteEventBuffer<br>WriteServiceConfig<br>xxxLOpen</details>|
|paramcount|4|4|
|`address`|18003a494|18003a4f4|
|sig|undefined __fastcall TRACELogPrint(uint param_1, STRSAFE_LPCSTR param_2, undefined8 param_3, undefined8 param_4)|undefined __fastcall TRACELogPrint(uint param_1, STRSAFE_LPCSTR param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## USER32.DLL::LoadIconW

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|LoadIconW|LoadIconW|
|fullname|USER32.DLL::LoadIconW|USER32.DLL::LoadIconW|
|`refcount`|1|3|
|length|0|0|
|called|||
|`calling`||ServiceMain|
|paramcount|2|2|
|address|EXTERNAL:000000b8|EXTERNAL:000000b8|
|sig|HICON __stdcall LoadIconW(HINSTANCE hInstance, LPCWSTR lpIconName)|HICON __stdcall LoadIconW(HINSTANCE hInstance, LPCWSTR lpIconName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### USER32.DLL::LoadIconW Calling Diff


```diff
--- USER32.DLL::LoadIconW calling
+++ USER32.DLL::LoadIconW calling
@@ -0,0 +1 @@
+ServiceMain
```


## KERNEL32.DLL::EnterCriticalSection

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|EnterCriticalSection|EnterCriticalSection|
|fullname|KERNEL32.DLL::EnterCriticalSection|KERNEL32.DLL::EnterCriticalSection|
|`refcount`|122|121|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AcquireHashTableEntryLock<br>AppendNewDeviceInfo<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>ClientDetach<br>CreateTapiSCP<br>CreatetCallClient<br>DequeueSPEvent<br>DereferenceObject<br>DestroytCallClient</summary>DestroytLineApp<br>DestroytLineClient<br>DestroytPhoneApp<br>DestroytPhoneClient<br>DoCallHubHashing<br>EventNotificationThread<br>FreeDialogInstance<br>FreeOldDllListProc<br>GetAsyncEvents<br>GetCallIDs<br>GetClientList<br>GetDeviceInfo<br>GetHighestPriorityRequestRecipient<br>GetPriorityListForMediaModes<br>GetPriorityListTReqCall<br>GetTCClient<br>InitializeClient<br>InsertDevNameAddrInfo<br>LGetAppPriority<br>LGetRequest<br>LInitialize<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetDeviceFlags<br>MSetLineInfo<br>MSetPhoneInfo<br>MSetServerConfig<br>NewObject<br>NotifyHighestPriorityRequestRecipient<br>OnProxyLineClose<br>OnProxyLineOpen<br>OnProxySCPInit<br>OnProxySCPShutdown<br>PCONTEXT_HANDLE_TYPE_rundown<br>PInitialize<br>POpen<br>PhoneEventProc<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReferenceObject<br>RemoveCallClientFromLineClientList<br>RemoveDeviceInfoEntry<br>ServiceMain<br>ServiceShutdown<br>SetDrvCallFlags<br>SetGlobalEventMasks<br>SettLineAppEventMasks<br>SettLineClientEventMasks<br>SettPhoneAppEventMasks<br>SettPhoneClientEventMasks<br>TGetEventMasksOrSubMasks<br>TGetPermissibleMasks<br>TRequestMakeCall<br>TSetEventMasksOrSubMasks<br>TSetPermissibleMasks<br>UpdateTapiSCP<br>WaitForExclusiveClientAccess<br>WaitForExclusiveLineAppAccess<br>WaitForExclusiveLineClientAccess<br>WaitForExclusivePhoneAppAccess<br>WaitForExclusivePhoneClientAccess<br>WaitForExclusivetCallAccess<br>WaitForMutex<br>WriteEventBuffer<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AcquireHashTableEntryLock<br>AppendNewDeviceInfo<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>ClientDetach<br>CreateTapiSCP<br>CreatetCallClient<br>DequeueSPEvent<br>DereferenceObject<br>DestroytCallClient</summary>DestroytLineApp<br>DestroytLineClient<br>DestroytPhoneApp<br>DestroytPhoneClient<br>DoCallHubHashing<br>EventNotificationThread<br>FreeDialogInstance<br>FreeOldDllListProc<br>GetAsyncEvents<br>GetCallIDs<br>GetClientList<br>GetDeviceInfo<br>GetHighestPriorityRequestRecipient<br>GetPriorityListForMediaModes<br>GetPriorityListTReqCall<br>GetTCClient<br>InitializeClient<br>InsertDevNameAddrInfo<br>LGetAppPriority<br>LGetRequest<br>LInitialize<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetDeviceFlags<br>MSetLineInfo<br>MSetPhoneInfo<br>MSetServerConfig<br>NewObject<br>NotifyHighestPriorityRequestRecipient<br>OnProxyLineClose<br>OnProxyLineOpen<br>OnProxySCPInit<br>OnProxySCPShutdown<br>PCONTEXT_HANDLE_TYPE_rundown<br>PInitialize<br>POpen<br>PhoneEventProc<br>QueueSPEvent<br>ReadAndInitManagementDlls<br>ReferenceObject<br>RemoveCallClientFromLineClientList<br>RemoveDeviceInfoEntry<br>ServiceMain<br>ServiceShutdown<br>SetDrvCallFlags<br>SetGlobalEventMasks<br>SettLineAppEventMasks<br>SettLineClientEventMasks<br>SettPhoneAppEventMasks<br>SettPhoneClientEventMasks<br>TGetEventMasksOrSubMasks<br>TGetPermissibleMasks<br>TRequestMakeCall<br>TSetEventMasksOrSubMasks<br>TSetPermissibleMasks<br>UpdateTapiSCP<br>WaitForExclusiveClientAccess<br>WaitForExclusiveLineAppAccess<br>WaitForExclusiveLineClientAccess<br>WaitForExclusivePhoneAppAccess<br>WaitForExclusivePhoneClientAccess<br>WaitForExclusivetCallAccess<br>WaitForMutex<br>WriteEventBuffer<br>xxxLOpen</details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000007a|EXTERNAL:0000007c|
|sig|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## DereferenceObject

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|DereferenceObject|DereferenceObject|
|fullname|DereferenceObject|DereferenceObject|
|`refcount`|108|109|
|length|249|249|
|called|KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::LeaveCriticalSection<br>_guard_xfg_dispatch_icall_nop|KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::LeaveCriticalSection<br>_guard_xfg_dispatch_icall_nop|
|calling|<details><summary>Expand for full list:<br>ClientAttach<br>ClientDetach<br>ClientRequest<br>CompletionProcSP<br>CreatetCall<br>CreatetCallClient<br>DestroytCall<br>DestroytCallClient<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient</summary>DestroytPhone<br>DestroytPhoneApp<br>DestroytPhoneClient<br>DoCallHubHashing<br>FreeDialogInstance<br>FreetCall<br>GetPhoneVersions<br>GetUIDllName<br>IsValidCallHub<br>IsValidLineApp<br>LAddToConference<br>LCompleteTransfer<br>LCompleteTransfer_PostProcess<br>LDevSpecific<br>LGatherDigits<br>LGenerateDigits<br>LGenerateTone<br>LGetCallAddressID<br>LGetCallIDs<br>LGetConfRelatedCalls<br>LGetHubRelatedCalls<br>LGetNewCalls<br>LGetStatusMessages<br>LInitialize<br>LMakeCall_PostProcess<br>LProxyMessage<br>LProxyResponse<br>LReceiveMSPData<br>LSetCallPrivilege<br>LSetupConference<br>LSetupConference_PostProcess<br>LSetupTransfer<br>LSwapHold<br>LineEpilogAsync<br>LineEpilogSync<br>LineEventProc<br>PCONTEXT_HANDLE_TYPE_rundown<br>PClose<br>PGetID<br>PGetStatus<br>PGetStatusMessages<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PSelectExtVersion<br>PSetStatusMessages<br>PhoneEpilogAsync<br>PhoneEventProc<br>PhoneProlog<br>ReferenceCall<br>SPEventHandlerThread<br>SetDrvCallFlags<br>TGetEventMasksOrSubMasks<br>TSetEventMasksOrSubMasks<br>TUISPIDLLCallback<br>WaitForExclusiveLineAppAccess<br>WaitForExclusivePhoneAppAccess<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>ClientAttach<br>ClientDetach<br>ClientRequest<br>CompletionProcSP<br>CreatetCall<br>CreatetCallClient<br>DestroytCall<br>DestroytCallClient<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient</summary>DestroytPhone<br>DestroytPhoneApp<br>DestroytPhoneClient<br>DoCallHubHashing<br>FreeDialogInstance<br>FreetCall<br>GetPhoneVersions<br>GetUIDllName<br>IsValidCallHub<br>IsValidLineApp<br>LAddToConference<br>LCompleteTransfer<br>LCompleteTransfer_PostProcess<br>LDevSpecific<br>LGatherDigits<br>LGenerateDigits<br>LGenerateTone<br>LGetCallAddressID<br>LGetCallIDs<br>LGetConfRelatedCalls<br>LGetHubRelatedCalls<br>LGetNewCalls<br>LGetStatusMessages<br>LInitialize<br>LMakeCall_PostProcess<br>LProxyMessage<br>LProxyResponse<br>LReceiveMSPData<br>LSetCallPrivilege<br>LSetupConference<br>LSetupConference_PostProcess<br>LSetupTransfer<br>LSwapHold<br>LineEpilogAsync<br>LineEpilogSync<br>LineEventProc<br>PCONTEXT_HANDLE_TYPE_rundown<br>PClose<br>PGetID<br>PGetStatus<br>PGetStatusMessages<br>PInitialize<br>PNegotiateAPIVersion<br>POpen<br>PSelectExtVersion<br>PSetStatusMessages<br>PhoneEpilogAsync<br>PhoneEventProc<br>PhoneProlog<br>ReferenceCall<br>SPEventHandlerThread<br>SetDrvCallFlags<br>TGetEventMasksOrSubMasks<br>TSetEventMasksOrSubMasks<br>TUISPIDLLCallback<br>WaitForExclusiveLineAppAccess<br>WaitForExclusivePhoneAppAccess<br>xxxLOpen</details>|
|paramcount|3|3|
|`address`|18003a9c4|18003aa24|
|sig|undefined __fastcall DereferenceObject(undefined8 param_1, uint param_2, int param_3)|undefined __fastcall DereferenceObject(undefined8 param_1, uint param_2, int param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## WaitForExclusiveClientAccess

### Match Info



|Key|tapisrv-10.0.22621.3296.dll - tapisrv-10.0.22621.3447.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.84|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tapisrv-10.0.22621.3296.dll|tapisrv-10.0.22621.3447.dll|
| :---: | :---: | :---: |
|name|WaitForExclusiveClientAccess|WaitForExclusiveClientAccess|
|fullname|WaitForExclusiveClientAccess|WaitForExclusiveClientAccess|
|`refcount`|28|29|
|length|126|126|
|called|KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::LeaveCriticalSection|KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::LeaveCriticalSection|
|`calling`|<details><summary>Expand for full list:<br>EventNotificationThread<br>FreeDialogInstance<br>GetAsyncEvents<br>GetLineAppListFromClient<br>GetPhoneAppListFromClient<br>GetUIDllName<br>LGetID<br>LInitialize<br>LineEventProc<br>MSetLineInfo<br>MSetPhoneInfo</summary>MSetServerConfig<br>PInitialize<br>PhoneEventProc<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SetDeviceInfo<br>SettClientEventMasks<br>TGetEventMasksOrSubMasks<br>WriteEventBuffer</details>|<details><summary>Expand for full list:<br>EventNotificationThread<br>FreeDialogInstance<br>GetAsyncEvents<br>GetLineAppListFromClient<br>GetPhoneAppListFromClient<br>GetUIDllName<br>LGetID<br>LInitialize<br>LineEventProc<br>MSetLineInfo<br>MSetPhoneInfo</summary>MSetServerConfig<br>PInitialize<br>PhoneEventProc<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SetDeviceInfo<br>SettClientEventMasks<br>TGetEventMasksOrSubMasks<br>TUISPIDLLCallback<br>WriteEventBuffer</details>|
|paramcount|1|1|
|`address`|18001ef44|18001f014|
|sig|int * __fastcall WaitForExclusiveClientAccess(int * param_1)|int * __fastcall WaitForExclusiveClientAccess(int * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### WaitForExclusiveClientAccess Calling Diff


```diff
--- WaitForExclusiveClientAccess calling
+++ WaitForExclusiveClientAccess calling
@@ -19,0 +20 @@
+TUISPIDLLCallback
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-07-28T08:11:58</sub>