# udfs.sys 10.0.26100.8972 vs 10.0.26100.9168 (CVE-2026-62699)

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_2661530937__private_IsEnabledFallback](#feature_2661530937__private_isenabledfallback)
* [Modified](#modified)
	* [UdfUpdateVcbPhase0](#udfupdatevcbphase0)
	* [UdfUpdateVolumeStructures](#udfupdatevolumestructures)
	* [UdfIsRemount](#udfisremount)
	* [UdfMountVolume$fin$0](#udfmountvolumefin0)
	* [UdfQueryOnDiskVolInfo](#udfqueryondiskvolinfo)
	* [UdfUpdateVcbPhase0$fin$1](#udfupdatevcbphase0fin1)
	* [UdfSetVolumeDirtyState](#udfsetvolumedirtystate)
	* [UdfMountVolume](#udfmountvolume)
	* [UdfVerifyVolume](#udfverifyvolume)
	* [UdfQueryFreeBlocksAndNWA](#udfqueryfreeblocksandnwa)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [WPP_SF_](#wpp_sf_)
	* [NTOSKRNL.EXE::CcUnpinData](#ntoskrnlexeccunpindata)
	* [NTOSKRNL.EXE::ExAcquireResourceExclusiveLite](#ntoskrnlexeexacquireresourceexclusivelite)
	* [WPP_SF_dD](#wpp_sf_dd)
	* [UdfUnpinData](#udfunpindata)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [UdfFreePool](#udffreepool)
	* [NTOSKRNL.EXE::CcPurgeCacheSection](#ntoskrnlexeccpurgecachesection)
	* [memset](#memset)
	* [NTOSKRNL.EXE::ExRaiseStatus](#ntoskrnlexeexraisestatus)
	* [UdfDeleteInternalStream](#udfdeleteinternalstream)
	* [UdfAcquireResource](#udfacquireresource)
	* [UdfTearDownSpecialScb](#udfteardownspecialscb)

# Visual Chart Diff



```mermaid

flowchart LR

UdfUpdateVcbPhase0-2-old<--Match 73%-->UdfUpdateVcbPhase0-2-new
UdfUpdateVolumeStructures-3-old<--Match 89%-->UdfUpdateVolumeStructures-3-new
UdfIsRemount-4-old<--Match 63%-->UdfIsRemount-4-new
UdfMountVolumefin0-2-old<--Match 76%-->UdfMountVolumefin0-2-new
UdfQueryOnDiskVolInfo-2-old<--Match 90%-->UdfQueryOnDiskVolInfo-2-new
UdfUpdateVcbPhase0fin1-2-old<--Match 66%-->UdfUpdateVcbPhase0fin1-2-new
UdfSetVolumeDirtyState-2-old<--Match 91%-->UdfSetVolumeDirtyState-2-new
UdfMountVolume-2-old<--Match 68%-->UdfMountVolume-2-new
UdfVerifyVolume-2-old<--Match 47%-->UdfVerifyVolume-2-new
UdfQueryFreeBlocksAndNWA-3-old<--Match 20%-->Feature_2661530937__private_IsEnabledDeviceUsageNoInline-3-new

subgraph udfs-10.0.26100.9168.sys
    UdfUpdateVcbPhase0-2-new
UdfUpdateVolumeStructures-3-new
UdfIsRemount-4-new
UdfMountVolumefin0-2-new
UdfQueryOnDiskVolInfo-2-new
UdfUpdateVcbPhase0fin1-2-new
UdfSetVolumeDirtyState-2-new
UdfMountVolume-2-new
UdfVerifyVolume-2-new
Feature_2661530937__private_IsEnabledDeviceUsageNoInline-3-new
    subgraph Added
direction LR
Feature_2661530937__private_IsEnabledFallback
end
end

subgraph udfs-10.0.26100.8972.sys
    UdfUpdateVcbPhase0-2-old
UdfUpdateVolumeStructures-3-old
UdfIsRemount-4-old
UdfMountVolumefin0-2-old
UdfQueryOnDiskVolInfo-2-old
UdfUpdateVcbPhase0fin1-2-old
UdfSetVolumeDirtyState-2-old
UdfMountVolume-2-old
UdfVerifyVolume-2-old
UdfQueryFreeBlocksAndNWA-3-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.9501%
"unmatched_funcs_len" : 1
"matched_funcs_len" : 2003
```



```mermaid
pie showData
    title Matched Function Similarity - 98.8018%
"matched_funcs_with_code_changes_len" : 10
"matched_funcs_with_non_code_changes_len" : 14
"matched_funcs_no_changes_len" : 1979
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name CVE-2026-62699 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 --md-title udfs.sys 10.0.26100.8972 vs 10.0.26100.9168 (CVE-2026-62699) udfs-10.0.26100.8972.sys udfs-10.0.26100.9168.sys
```


#### Verbose Args


<details>

```
--old ['udfs-10.0.26100.8972.sys'] --new [['udfs-10.0.26100.9168.sys']] --engine VersionTrackingDiff --output-path output --summary False --project-location ghidra_projects --project-name CVE-2026-62699 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title udfs.sys 10.0.26100.8972 vs 10.0.26100.9168 (CVE-2026-62699)
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/udfs.sys/9F02359162000/udfs.sys -O udfs.sys.x64.10.0.26100.8972
wget https://msdl.microsoft.com/download/symbols/udfs.sys/9FDAC34E62000/udfs.sys -O udfs.sys.x64.10.0.26100.9168
```


## Binary Metadata Diff


```diff
--- udfs-10.0.26100.8972.sys Meta
+++ udfs-10.0.26100.9168.sys Meta
@@ -1,44 +1,44 @@
-Program Name: udfs-10.0.26100.8972.sys
+Program Name: udfs-10.0.26100.9168.sys
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 140000000
 Maximum Address: ff0000184f
 # of Bytes: 407632
 # of Memory Blocks: 13
-# of Instructions: 74466
-# of Defined Data: 5095
-# of Functions: 1001
-# of Symbols: 8181
+# of Instructions: 74643
+# of Defined Data: 5106
+# of Functions: 1003
+# of Symbols: 8183
 # of Data Types: 152
 # of Data Type Categories: 11
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Sat Aug 22 12:18:12 SGT 2026
+Date Created: Sat Aug 22 12:18:19 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2026-62699/udfs-10.0.26100.8972.sys
-Executable MD5: d208bba4cef98c21a9dc117b622fe9d6
-Executable SHA256: 8a29f2c834fb955f3813b0fea3d880a57a93866f439a890c18d0dfa45376491a
-FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2026-62699/udfs-10.0.26100.8972.sys?MD5=d208bba4cef98c21a9dc117b622fe9d6
+Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2026-62699/udfs-10.0.26100.9168.sys
+Executable MD5: 47f2e0f8837ee5bd9e1ca6696834601b
+Executable SHA256: 8ac119f739b481d6e97ac332738436649ad1ac62bc82c5730b4ac93c0046a4a3
+FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2026-62699/udfs-10.0.26100.9168.sys?MD5=47f2e0f8837ee5bd9e1ca6696834601b
 PDB Age: 1
 PDB File: udfs.pdb
-PDB GUID: deb89c65-7b79-6c64-a50b-3952e9623a25
+PDB GUID: 7522be2c-ed99-682b-06f4-d63c98a52a01
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: UDF File System Driver
-PE Property[FileVersion]: 10.0.26100.8972 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.9168 (WinBuild.160101.0800)
 PE Property[InternalName]: udfs.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: udfs.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.8972
+PE Property[ProductVersion]: 10.0.26100.9168
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra udfs-10.0.26100.8972.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra udfs-10.0.26100.8972.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra udfs-10.0.26100.8972.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra udfs-10.0.26100.9168.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra udfs-10.0.26100.9168.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra udfs-10.0.26100.9168.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|1|
|deleted_funcs_len|0|
|modified_funcs_len|24|
|added_symbols_len|7|
|deleted_symbols_len|5|
|diff_time|20.237098455429077|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 998, 'ExternalsName': 227, 'ExactBytesFunctionHasher': 1, 'BSIM': 1, 'Implied Match': 1})|
|items_to_process|37|
|diff_types|Counter({'address': 16, 'refcount': 14, 'calling': 12, 'code': 10, 'length': 10, 'called': 10, 'sig': 5, 'name': 1, 'fullname': 1})|
|unmatched_funcs_len|1|
|total_funcs_len|2004|
|matched_funcs_len|2003|
|matched_funcs_with_code_changes_len|10|
|matched_funcs_with_non_code_changes_len|14|
|matched_funcs_no_changes_len|1979|
|match_func_similarity_percent|98.8018%|
|func_match_overall_percent|99.9501%|
|first_matches|Counter({'SymbolsHash': 998, 'ExactBytesFunctionHasher': 1, 'BSIM': 1, 'Implied Match': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 998
"ExternalsName" : 227
"ExactBytesFunctionHasher" : 1
"BSIM" : 1
"Implied-Match" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 998
"ExactBytesFunctionHasher" : 1
"BSIM" : 1
"Implied-Match" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 1
"deleted_funcs_len" : 0
"modified_funcs_len" : 24
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 7
"deleted_symbols_len" : 5
```

## Strings


*No string differences found*

# Deleted

# Added

## Feature_2661530937__private_IsEnabledFallback

### Function Meta



|Key|udfs-10.0.26100.9168.sys|
| :---: | :---: |
|name|Feature_2661530937__private_IsEnabledFallback|
|fullname|Feature_2661530937__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_2661530937__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|140011b6c|
|sig|undefined __fastcall Feature_2661530937__private_IsEnabledFallback(ulonglong param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_2661530937__private_IsEnabledFallback
+++ Feature_2661530937__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_2661530937__private_IsEnabledFallback(ulonglong param_1,int param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_2661530937__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## UdfUpdateVcbPhase0

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.18|
|i_ratio|0.59|
|m_ratio|1.0|
|b_ratio|0.73|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfUpdateVcbPhase0|UdfUpdateVcbPhase0|
|fullname|UdfUpdateVcbPhase0|UdfUpdateVcbPhase0|
|refcount|2|2|
|`length`|6646|6611|
|`called`|<details><summary>Expand for full list:<br>NTOSKRNL.EXE::CcMapData<br>NTOSKRNL.EXE::CcPurgeCacheSection<br>NTOSKRNL.EXE::CcSetFileSizes<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAcquireFastMutex<br>NTOSKRNL.EXE::ExAcquireFastMutexUnsafe<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseFastMutex<br>NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>UdfCStringToWString</summary>UdfCleanupIcbContext<br>UdfConvertUdfTimeToNtTime<br>UdfCreateInternalStream<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfCreateScb<br>UdfDeleteInternalStream<br>UdfInitializeIcbContextFromScb<br>UdfInitializeScbFromIcbContext<br>UdfInitializeVmcb<br>UdfLookupActiveIcb<br>UdfRaiseStatusEx<br>UdfReadWriteSectors<br>UdfTeardownStructures<br>UdfUdfIdentifierContained<br>UdfUninitializeScbMcb<br>UdfUnpinData<br>UdfVerifyDescriptor<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_dD<br>WPP_SF_i<br>memcmp<br>memset</details>|<details><summary>Expand for full list:<br>Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::CcMapData<br>NTOSKRNL.EXE::CcSetFileSizes<br>NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExAcquireFastMutex<br>NTOSKRNL.EXE::ExAcquireFastMutexUnsafe<br>NTOSKRNL.EXE::ExAllocatePoolWithTag<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseFastMutex<br>NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>UdfCStringToWString</summary>UdfCleanupIcbContext<br>UdfConvertUdfTimeToNtTime<br>UdfCreateInternalStream<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfCreateScb<br>UdfInitializeIcbContextFromScb<br>UdfInitializeScbFromIcbContext<br>UdfInitializeVmcb<br>UdfLookupActiveIcb<br>UdfRaiseStatusEx<br>UdfReadWriteSectors<br>UdfTearDownSpecialScb<br>UdfUdfIdentifierContained<br>UdfUninitializeScbMcb<br>UdfUnpinData<br>UdfVerifyDescriptor<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_dD<br>WPP_SF_i<br>memcmp</details>|
|calling|UdfMountVolume|UdfMountVolume|
|paramcount|2|2|
|`address`|1400478c0|140056a20|
|`sig`|undefined __fastcall UdfUpdateVcbPhase0(undefined8 * param_1, ulonglong param_2)|undefined __fastcall UdfUpdateVcbPhase0(undefined8 * param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfUpdateVcbPhase0 Called Diff


```diff
--- UdfUpdateVcbPhase0 called
+++ UdfUpdateVcbPhase0 called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
@@ -2 +2,0 @@
-NTOSKRNL.EXE::CcPurgeCacheSection
@@ -17 +16,0 @@
-UdfDeleteInternalStream
@@ -24 +23 @@
-UdfTeardownStructures
+UdfTearDownSpecialScb
@@ -34 +32,0 @@
-memset
```


### UdfUpdateVcbPhase0 Diff


```diff
--- UdfUpdateVcbPhase0
+++ UdfUpdateVcbPhase0
@@ -1,681 +1,633 @@
 
-/* WARNING: Removing unreachable block (ram,0x000140049298) */
-/* WARNING: Removing unreachable block (ram,0x0001400492ad) */
+/* WARNING: Removing unreachable block (ram,0x00014005832a) */
+/* WARNING: Removing unreachable block (ram,0x00014005833f) */
 
-void UdfUpdateVcbPhase0(undefined8 *param_1,ulonglong param_2)
+void UdfUpdateVcbPhase0(undefined8 *param_1,longlong param_2)
 
 {
   uint *puVar1;
-  char *pcVar2;
-  ushort uVar3;
-  ushort uVar4;
+  longlong *plVar2;
+  char *pcVar3;
+  longlong lVar4;
   void *pvVar5;
-  char cVar6;
-  int iVar7;
-  short *psVar8;
-  ushort *puVar9;
-  ulonglong uVar10;
-  ulonglong uVar11;
-  ushort uVar12;
-  longlong lVar13;
-  undefined8 *puVar14;
-  longlong *plVar15;
-  undefined2 uVar16;
+  int iVar6;
+  short *psVar7;
+  ulonglong uVar8;
+  ulonglong uVar9;
+  ushort uVar10;
+  uint uVar11;
+  longlong lVar12;
+  undefined8 *puVar13;
+  longlong lVar14;
+  ushort uVar15;
+  undefined8 uVar16;
   uint uVar17;
-  longlong lVar18;
-  undefined8 uVar19;
-  uint uVar20;
-  ulonglong local_res18;
-  ulonglong local_res20;
-  ushort local_1d4;
-  ulonglong local_1d0;
-  ushort local_1c8;
-  longlong local_1c0;
-  int local_1b8;
-  undefined2 local_1b4;
-  int local_1b0;
-  longlong *local_1a8;
-  undefined8 *local_1a0;
-  ulonglong local_198;
-  undefined8 *local_190;
-  longlong local_188;
-  longlong local_180;
-  longlong *local_178;
-  ushort *local_170;
-  ushort *local_168;
-  uint local_160;
-  uint local_15c;
-  uint local_158;
-  ushort *local_150;
-  int *local_148;
-  uint local_13c;
-  uint local_138;
-  int local_134;
-  uint local_130;
-  longlong *local_128;
-  uint *local_120;
-  int *local_118;
-  longlong local_108 [12];
-  void *local_a8;
-  void *local_a0;
-  void *local_98;
-  void *local_90;
-  void *local_88;
-  void *local_80;
-  void *local_78;
-  void *local_70;
-  void *local_68;
-  void *local_58;
-  void *local_50;
-  void *local_48;
-  void *local_40;
+  ushort *puVar18;
+  uint uVar19;
+  longlong *plVar20;
+  ulonglong local_170;
+  ushort local_158;
+  longlong local_150;
+  ushort *local_148;
+  int local_140 [2];
+  undefined8 *local_138;
+  ulonglong local_130;
+  longlong local_128;
+  ushort *local_120;
+  longlong *local_118;
+  longlong local_110;
+  uint local_108;
+  uint local_104;
+  ushort *local_100;
+  int *local_f8 [2];
+  longlong *local_e8;
+  undefined8 *local_e0;
+  uint *local_d8;
+  longlong local_d0;
+  int *local_c8;
+  longlong local_c0;
+  longlong local_b8;
+  longlong local_a8 [14];
   
-  local_res18 = param_2;
-  memset(local_108,0,0x60);
-  local_1b8 = 0;
-  local_1b4 = 0;
-  uVar20 = 0;
-  local_1b0 = 0;
-  local_170 = (ushort *)0x0;
-  local_168 = (ushort *)0x0;
-  local_1c0 = 0;
-  local_198 = 0;
-  local_150 = (ushort *)0x0;
-  local_148 = (int *)0x0;
+  local_a8[0] = 0;
+  local_a8[1] = 0;
+  local_a8[2] = 0;
+  local_a8[3] = 0;
+  local_a8[4] = 0;
+  local_a8[5] = 0;
+  local_a8[6] = 0;
+  local_a8[7] = 0;
+  local_a8[8] = 0;
+  local_a8[9] = 0;
+  local_a8[10] = 0;
+  local_a8[0xb] = 0;
+  uVar11 = 0;
+  local_140[0] = 0;
+  local_148 = (ushort *)0x0;
+  local_100 = (ushort *)0x0;
+  local_150 = 0;
+  local_130 = 0;
+  local_120 = (ushort *)0x0;
+  local_f8[0] = (int *)0x0;
+  local_c0 = param_2;
+  local_b8 = param_2;
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-    WPP_SF_i(WPP_GLOBAL_Control[3],0x12,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,param_2);
-  }
-  lVar18 = param_2 + 0x670;
-  local_188 = lVar18;
-  ExAcquireFastMutexUnsafe(lVar18);
-  local_a8 = SystemReserved1[0xf];
-  puVar14 = (undefined8 *)(param_2 + 0x6a8);
-  *puVar14 = SystemReserved1[0xf];
-  local_190 = puVar14;
-  psVar8 = UdfCreateScb((longlong)param_1,0,0x933,0,(undefined1 *)0x0);
-  *(short **)(param_2 + 0x110) = psVar8;
-  *(short **)(*(longlong *)(psVar8 + 0x44) + 0x10) = psVar8;
-  uVar10 = param_2 + 0x630;
-  local_res20 = uVar10;
-  ExAcquireFastMutexUnsafe(uVar10);
-  local_a0 = SystemReserved1[0xf];
-  local_1a0 = (undefined8 *)(param_2 + 0x668);
-  *local_1a0 = SystemReserved1[0xf];
+    WPP_SF_i(WPP_GLOBAL_Control[3],0x12,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,param_2);
+  }
+  lVar14 = param_2 + 0x670;
+  local_128 = lVar14;
+  ExAcquireFastMutexUnsafe(lVar14);
+  local_138 = (undefined8 *)(param_2 + 0x6a8);
+  *local_138 = SystemReserved1[0xf];
+  psVar7 = UdfCreateScb((longlong)param_1,0,0x933,0,(undefined1 *)0x0);
+  *(short **)(param_2 + 0x110) = psVar7;
+  *(short **)(*(longlong *)(psVar7 + 0x44) + 0x10) = psVar7;
+  lVar12 = param_2 + 0x630;
+  local_d0 = lVar12;
+  ExAcquireFastMutexUnsafe(lVar12);
+  puVar13 = (undefined8 *)(param_2 + 0x668);
+  *puVar13 = SystemReserved1[0xf];
   *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) =
        *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) + 1;
   *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) =
        *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) + 1;
-  lVar13 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 8);
-  *(int *)(lVar13 + 0x100) = *(int *)(lVar13 + 0x100) + 1;
-  lVar13 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 8);
-  *(int *)(lVar13 + 0x104) = *(int *)(lVar13 + 0x104) + 1;
-  *local_1a0 = 0;
-  ExReleaseFastMutexUnsafe(uVar10);
-  lVar13 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
-  *(uint *)(lVar13 + 0x4c) = *(uint *)(lVar13 + 0x4c) | 1;
-  *puVar14 = 0;
-  ExReleaseFastMutexUnsafe(lVar18);
+  lVar4 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 8);
+  *(int *)(lVar4 + 0x100) = *(int *)(lVar4 + 0x100) + 1;
+  lVar4 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 8);
+  *(int *)(lVar4 + 0x104) = *(int *)(lVar4 + 0x104) + 1;
+  *puVar13 = 0;
+  local_e0 = puVar13;
+  ExReleaseFastMutexUnsafe(lVar12);
+  lVar4 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
+  *(uint *)(lVar4 + 0x4c) = *(uint *)(lVar4 + 0x4c) | 1;
+  *local_138 = 0;
+  ExReleaseFastMutexUnsafe(lVar14);
   *(undefined8 *)(*(longlong *)(param_2 + 0x110) + 0x18) = 0xc00000;
   *(undefined8 *)(*(longlong *)(param_2 + 0x110) + 0x28) = 0xc00000;
   *(undefined8 *)(*(longlong *)(param_2 + 0x110) + 0x20) = 0xc00000;
   pvVar5 = SystemReserved1[0xf];
-  local_98 = SystemReserved1[0xf];
-  lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
-  if (SystemReserved1[0xf] != *(void **)(lVar18 + 0x40)) {
-    ExAcquireFastMutex(*(longlong *)(lVar18 + 0x50) + 0xd8);
+  lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
+  if (SystemReserved1[0xf] != *(void **)(lVar14 + 0x40)) {
+    ExAcquireFastMutex(*(longlong *)(lVar14 + 0x50) + 0xd8);
     *(void **)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 0x40) = pvVar5;
   }
-  lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
-  *(int *)(lVar18 + 0x48) = *(int *)(lVar18 + 0x48) + 1;
+  lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
+  *(int *)(lVar14 + 0x48) = *(int *)(lVar14 + 0x48) + 1;
   puVar1 = (uint *)(param_2 + 0x30);
-  local_120 = puVar1;
-  local_118 = (int *)(param_2 + 0x44);
+  local_c8 = (int *)(param_2 + 0x44);
+  local_d8 = puVar1;
   UdfInitializeVmcb((undefined4 *)(param_2 + 0x3d8));
   *puVar1 = *puVar1 | 0x400;
-  lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
-  *(int *)(lVar18 + 0x48) = *(int *)(lVar18 + 0x48) + -1;
-  lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
-  if (*(int *)(lVar18 + 0x48) == 0) {
-    *(undefined8 *)(lVar18 + 0x40) = 0;
+  lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
+  *(int *)(lVar14 + 0x48) = *(int *)(lVar14 + 0x48) + -1;
+  lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88);
+  if (*(int *)(lVar14 + 0x48) == 0) {
+    *(undefined8 *)(lVar14 + 0x40) = 0;
     ExReleaseFastMutex(*(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x110) + 0x88) + 0x50) +
                        0xd8);
   }
   *(uint *)(*(longlong *)(param_2 + 0x110) + 0xd4) =
        *(uint *)(*(longlong *)(param_2 + 0x110) + 0xd4) | 0x81;
   UdfCreateInternalStream
             ((longlong)param_1,param_2,*(longlong *)(param_2 + 0x110),(undefined4 *)&DAT_0);
   CcSetFileSizes(*(undefined8 *)(*(longlong *)(param_2 + 0x110) + 0x1f8),
                  *(longlong *)(param_2 + 0x110) + 0x18);
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-    WPP_SF_(WPP_GLOBAL_Control[3],0x13,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
-  }
-  uVar12 = 0;
-  local_1c8 = 0;
+    WPP_SF_(WPP_GLOBAL_Control[3],0x13,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
+  }
+  uVar10 = 0;
+  local_158 = 0;
   while( true ) {
-    plVar15 = (longlong *)(param_2 + 0x10);
-    local_128 = plVar15;
-    if (*(ushort *)(*plVar15 + 4) <= local_1c8) break;
-    local_178 = (longlong *)(ulonglong)local_1c8;
-    local_180 = (longlong)local_178 * 0x38;
-    if (*(int *)(local_180 + 0x60 + *plVar15) == 3) {
-      ExAcquireFastMutexUnsafe(local_res20);
-      local_90 = SystemReserved1[0xf];
-      *local_1a0 = SystemReserved1[0xf];
+    plVar2 = (longlong *)(param_2 + 0x10);
+    if (*(ushort *)(*plVar2 + 4) <= local_158) break;
+    local_118 = (longlong *)(ulonglong)local_158;
+    local_110 = (longlong)local_118 * 0x38;
+    if (*(int *)(local_110 + 0x60 + *plVar2) == 3) {
+      ExAcquireFastMutexUnsafe(lVar12);
+      *puVar13 = SystemReserved1[0xf];
       *puVar1 = *puVar1 | 0x4000000;
-      *(ushort *)(*plVar15 + 0x54) = local_1c8;
-      *local_1a0 = 0;
-      ExReleaseFastMutexUnsafe(local_res20);
-      local_1b8 = *(undefined4 *)(((longlong)local_178 + 2) * 0x38 + *plVar15);
-      local_1b4 = *(undefined2 *)(*plVar15 + 0x6c + local_180);
-      local_1d0 = (ulonglong)CONCAT24(local_1b4,local_1b8) | 0x8000000000000000;
-      ExAcquireFastMutexUnsafe(local_188);
-      local_68 = SystemReserved1[0xf];
-      *local_190 = SystemReserved1[0xf];
-      psVar8 = UdfCreateScb((longlong)param_1,local_1d0,0x933,0,(undefined1 *)0x0);
-      *(short **)(param_2 + 0x140) = psVar8;
-      *(short **)(*(longlong *)(psVar8 + 0x44) + 0x10) = psVar8;
-      ExAcquireFastMutexUnsafe(local_res20);
-      local_88 = SystemReserved1[0xf];
-      *local_1a0 = SystemReserved1[0xf];
+      *(ushort *)(*plVar2 + 0x54) = local_158;
+      *puVar13 = 0;
+      ExReleaseFastMutexUnsafe(lVar12);
+      local_170 = (ulonglong)
+                  CONCAT24(*(undefined2 *)(*plVar2 + 0x6c + local_110),
+                           *(undefined4 *)(((longlong)local_118 + 2) * 0x38 + *plVar2)) |
+                  0x8000000000000000;
+      ExAcquireFastMutexUnsafe(local_128);
+      *local_138 = SystemReserved1[0xf];
+      psVar7 = UdfCreateScb((longlong)param_1,local_170,0x933,0,(undefined1 *)0x0);
+      *(short **)(param_2 + 0x140) = psVar7;
+      *(short **)(*(longlong *)(psVar7 + 0x44) + 0x10) = psVar7;
+      ExAcquireFastMutexUnsafe(lVar12);
+      *puVar13 = SystemReserved1[0xf];
       *(int *)(*(longlong *)(param_2 + 0x140) + 0xcc) =
            *(int *)(*(longlong *)(param_2 + 0x140) + 0xcc) + 1;
       *(int *)(*(longlong *)(param_2 + 0x140) + 0xd0) =
            *(int *)(*(longlong *)(param_2 + 0x140) + 0xd0) + 1;
-      lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88) + 8);
-      *(int *)(lVar18 + 0x100) = *(int *)(lVar18 + 0x100) + 1;
-      lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88) + 8);
-      *(int *)(lVar18 + 0x104) = *(int *)(lVar18 + 0x104) + 1;
-      local_178 = param_1 + 2;
-      *(int *)(*local_178 + 0x108) = *(int *)(*local_178 + 0x108) + 2;
-      *(int *)(*local_178 + 0x100) = *(int *)(*local_178 + 0x100) + 2;
-      *(int *)(*local_178 + 0x10c) = *(int *)(*local_178 + 0x10c) + 1;
-      *local_1a0 = 0;
-      ExReleaseFastMutexUnsafe(local_res20);
-      lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88);
-      *(uint *)(lVar18 + 0x4c) = *(uint *)(lVar18 + 0x4c) | 1;
-      UdfInitializeIcbContextFromScb((longlong)param_1,local_108,*(longlong *)(param_2 + 0x140));
-      UdfLookupActiveIcb((longlong)param_1,local_108,*(int *)(*(longlong *)(param_2 + 0x140) + 0xb0)
-                        );
-      UdfInitializeScbFromIcbContext(param_1,*(short **)(param_2 + 0x140),local_108,0);
-      UdfCleanupIcbContext((longlong)param_1,local_108);
-      *local_190 = 0;
-      ExReleaseFastMutexUnsafe(local_188);
+      lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88) + 8);
+      *(int *)(lVar14 + 0x100) = *(int *)(lVar14 + 0x100) + 1;
+      lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88) + 8);
+      *(int *)(lVar14 + 0x104) = *(int *)(lVar14 + 0x104) + 1;
+      local_118 = param_1 + 2;
+      *(int *)(*local_118 + 0x108) = *(int *)(*local_118 + 0x108) + 2;
+      *(int *)(*local_118 + 0x100) = *(int *)(*local_118 + 0x100) + 2;
+      *(int *)(*local_118 + 0x10c) = *(int *)(*local_118 + 0x10c) + 1;
+      *puVar13 = 0;
+      ExReleaseFastMutexUnsafe(lVar12);
+      lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x140) + 0x88);
+      *(uint *)(lVar14 + 0x4c) = *(uint *)(lVar14 + 0x4c) | 1;
+      UdfInitializeIcbContextFromScb((longlong)param_1,local_a8,*(longlong *)(param_2 + 0x140));
+      UdfLookupActiveIcb((longlong)param_1,local_a8,*(int *)(*(longlong *)(param_2 + 0x140) + 0xb0))
+      ;
+      UdfInitializeScbFromIcbContext(param_1,*(short **)(param_2 + 0x140),local_a8,0);
+      UdfCleanupIcbContext((longlong)param_1,local_a8);
+      *local_138 = 0;
+      ExReleaseFastMutexUnsafe(local_128);
       UdfCreateInternalStream
                 ((longlong)param_1,param_2,*(longlong *)(param_2 + 0x140),
                  (undefined4 *)&DAT_1);
-      local_1b8 = *(int *)(*plVar15 + 0x78 + local_180);
-      local_1b4 = *(undefined2 *)(*plVar15 + 0x6c + local_180);
-      if (local_1b8 == -1) {
+      iVar6 = *(int *)(*plVar2 + 0x78 + local_110);
+      if (iVar6 == -1) {
         if ((*puVar1 & 0x20000000) == 0) {
           if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
              ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-            WPP_SF_(WPP_GLOBAL_Control[3],0x14,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
+            WPP_SF_(WPP_GLOBAL_Control[3],0x14,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
           }
           *puVar1 = *puVar1 | 0x4010;
         }
       }
       else {
-        local_1d0 = (ulonglong)CONCAT24(local_1b4,local_1b8) | 0x8000000000000000;
-        ExAcquireFastMutexUnsafe(local_188);
-        local_80 = SystemReserved1[0xf];
-        *local_190 = SystemReserved1[0xf];
-        psVar8 = UdfCreateScb((longlong)param_1,local_1d0,0x933,0,(undefined1 *)0x0);
-        *(short **)(param_2 + 0x150) = psVar8;
-        *(short **)(*(longlong *)(psVar8 + 0x44) + 0x10) = psVar8;
-        ExAcquireFastMutexUnsafe(local_res20);
-        local_78 = SystemReserved1[0xf];
-        *local_1a0 = SystemReserved1[0xf];
+        local_170 = (ulonglong)CONCAT24(*(undefined2 *)(*plVar2 + 0x6c + local_110),iVar6) |
+                    0x8000000000000000;
+        ExAcquireFastMutexUnsafe(local_128);
+        *local_138 = SystemReserved1[0xf];
+        psVar7 = UdfCreateScb((longlong)param_1,local_170,0x933,0,(undefined1 *)0x0);
+        *(short **)(param_2 + 0x150) = psVar7;
+        *(short **)(*(longlong *)(psVar7 + 0x44) + 0x10) = psVar7;
+        ExAcquireFastMutexUnsafe(lVar12);
+        *puVar13 = SystemReserved1[0xf];
         *(int *)(*(longlong *)(param_2 + 0x150) + 0xcc) =
              *(int *)(*(longlong *)(param_2 + 0x150) + 0xcc) + 1;
         *(int *)(*(longlong *)(param_2 + 0x150) + 0xd0) =
              *(int *)(*(longlong *)(param_2 + 0x150) + 0xd0) + 1;
-        lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88) + 8);
-        *(int *)(lVar18 + 0x100) = *(int *)(lVar18 + 0x100) + 1;
-        lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88) + 8);
-        *(int *)(lVar18 + 0x104) = *(int *)(lVar18 + 0x104) + 1;
-        *(int *)(*local_178 + 0x108) = *(int *)(*local_178 + 0x108) + 2;
-        *(int *)(*local_178 + 0x100) = *(int *)(*local_178 + 0x100) + 2;
-        *(int *)(*local_178 + 0x10c) = *(int *)(*local_178 + 0x10c) + 1;
-        *local_1a0 = 0;
-        ExReleaseFastMutexUnsafe(local_res20);
-        lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88);
-        *(uint *)(lVar18 + 0x4c) = *(uint *)(lVar18 + 0x4c) | 1;
-        UdfInitializeIcbContextFromScb((longlong)param_1,local_108,*(longlong *)(param_2 + 0x150));
-        UdfLookupActiveIcb((longlong)param_1,local_108,
+        lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88) + 8);
+        *(int *)(lVar14 + 0x100) = *(int *)(lVar14 + 0x100) + 1;
+        lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88) + 8);
+        *(int *)(lVar14 + 0x104) = *(int *)(lVar14 + 0x104) + 1;
+        *(int *)(*local_118 + 0x108) = *(int *)(*local_118 + 0x108) + 2;
+        *(int *)(*local_118 + 0x100) = *(int *)(*local_118 + 0x100) + 2;
+        *(int *)(*local_118 + 0x10c) = *(int *)(*local_118 + 0x10c) + 1;
+        *puVar13 = 0;
+        ExReleaseFastMutexUnsafe(lVar12);
+        lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x150) + 0x88);
+        *(uint *)(lVar14 + 0x4c) = *(uint *)(lVar14 + 0x4c) | 1;
+        UdfInitializeIcbContextFromScb((longlong)param_1,local_a8,*(longlong *)(param_2 + 0x150));
+        UdfLookupActiveIcb((longlong)param_1,local_a8,
                            *(int *)(*(longlong *)(param_2 + 0x150) + 0xb0));
-        UdfInitializeScbFromIcbContext(param_1,*(short **)(param_2 + 0x150),local_108,0);
-        UdfCleanupIcbContext((longlong)param_1,local_108);
-        *local_190 = 0;
-        ExReleaseFastMutexUnsafe(local_188);
+        UdfInitializeScbFromIcbContext(param_1,*(short **)(param_2 + 0x150),local_a8,0);
+        UdfCleanupIcbContext((longlong)param_1,local_a8);
+        *local_138 = 0;
+        ExReleaseFastMutexUnsafe(local_128);
         UdfCreateInternalStream
                   ((longlong)param_1,param_2,*(longlong *)(param_2 + 0x150),
                    (undefined4 *)&DAT_2);
       }
-      local_1b8 = *(undefined4 *)(*plVar15 + 0x74 + local_180);
-      local_1b4 = *(undefined2 *)(*plVar15 + 0x6c + local_180);
-      local_1d0 = (ulonglong)CONCAT24(local_1b4,local_1b8) | 0x8000000000000000;
-      ExAcquireFastMutexUnsafe(local_188);
-      local_70 = SystemReserved1[0xf];
-      *local_190 = SystemReserved1[0xf];
-      psVar8 = UdfCreateScb((longlong)param_1,local_1d0,0x933,0,(undefined1 *)0x0);
-      local_1a8 = (longlong *)(param_2 + 0x148);
-      *local_1a8 = (longlong)psVar8;
-      *(short **)(*(longlong *)(psVar8 + 0x44) + 0x10) = psVar8;
-      ExAcquireFastMutexUnsafe(local_res20);
-      local_40 = SystemReserved1[0xf];
-      *local_1a0 = SystemReserved1[0xf];
-      *(int *)(*local_1a8 + 0xcc) = *(int *)(*local_1a8 + 0xcc) + 1;
-      *(int *)(*local_1a8 + 0xd0) = *(int *)(*local_1a8 + 0xd0) + 1;
-      lVar18 = *(longlong *)(*(longlong *)(*local_1a8 + 0x88) + 8);
-      *(int *)(lVar18 + 0x100) = *(int *)(lVar18 + 0x100) + 1;
-      lVar18 = *(longlong *)(*(longlong *)(*local_1a8 + 0x88) + 8);
-      *(int *)(lVar18 + 0x104) = *(int *)(lVar18 + 0x104) + 1;
-      *(int *)(*local_178 + 0x108) = *(int *)(*local_178 + 0x108) + 2;
-      *(int *)(*local_178 + 0x100) = *(int *)(*local_178 + 0x100) + 2;
-      *(int *)(*local_178 + 0x10c) = *(int *)(*local_178 + 0x10c) + 1;
-      *local_1a0 = 0;
-      ExReleaseFastMutexUnsafe(local_res20);
-      *(uint *)(*(longlong *)(*local_1a8 + 0x88) + 0x4c) =
-           *(uint *)(*(longlong *)(*local_1a8 + 0x88) + 0x4c) | 1;
-      UdfInitializeIcbContextFromScb((longlong)param_1,local_108,*local_1a8);
-      UdfLookupActiveIcb((longlong)param_1,local_108,*(int *)(*local_1a8 + 0xb0));
-      UdfInitializeScbFromIcbContext(param_1,(short *)*local_1a8,local_108,0);
-      UdfCleanupIcbContext((longlong)param_1,local_108);
-      *local_190 = 0;
-      ExReleaseFastMutexUnsafe(local_188);
-      if (*(char *)(*plVar15 + 0x7c + local_180) == '\0') {
-        ExAcquireFastMutexUnsafe(local_res20);
-        local_50 = SystemReserved1[0xf];
-        *local_1a0 = SystemReserved1[0xf];
-        UdfUninitializeScbMcb(*local_1a8);
-        lVar18 = *local_1a8;
-        *(undefined8 *)(lVar18 + 0xe8) = 0;
-        *(undefined8 *)(lVar18 + 0xf0) = 0;
-        *(undefined8 *)(lVar18 + 0xf8) = 0;
-        *(undefined8 *)(lVar18 + 0x100) = 0;
-        lVar18 = *local_1a8;
-        *(undefined8 *)(lVar18 + 0x108) = 0;
-        *(undefined8 *)(lVar18 + 0x110) = 0;
-        *(undefined8 *)(lVar18 + 0x118) = 0;
-        *(undefined8 *)(lVar18 + 0x120) = 0;
-        *(int *)(*local_178 + 0x108) = *(int *)(*local_178 + 0x108) + -1;
-        *(int *)(*local_178 + 0x100) = *(int *)(*local_178 + 0x100) + -1;
-        *(undefined4 *)(*local_178 + 0x10c) = *(undefined4 *)(*local_178 + 0x10c);
-        *local_1a0 = 0;
-        ExReleaseFastMutexUnsafe(local_res20);
+      local_170 = (ulonglong)
+                  CONCAT24(*(undefined2 *)(*plVar2 + 0x6c + local_110),
+                           *(undefined4 *)(*plVar2 + 0x74 + local_110)) | 0x8000000000000000;
+      ExAcquireFastMutexUnsafe(local_128);
+      *local_138 = SystemReserved1[0xf];
+      psVar7 = UdfCreateScb((longlong)param_1,local_170,0x933,0,(undefined1 *)0x0);
+      plVar20 = (longlong *)(param_2 + 0x148);
+      *plVar20 = (longlong)psVar7;
+      *(short **)(*(longlong *)(psVar7 + 0x44) + 0x10) = psVar7;
+      local_e8 = plVar20;
+      ExAcquireFastMutexUnsafe(lVar12);
+      *puVar13 = SystemReserved1[0xf];
+      *(int *)(*plVar20 + 0xcc) = *(int *)(*plVar20 + 0xcc) + 1;
+      *(int *)(*plVar20 + 0xd0) = *(int *)(*plVar20 + 0xd0) + 1;
+      lVar14 = *(longlong *)(*(longlong *)(*plVar20 + 0x88) + 8);
+      *(int *)(lVar14 + 0x100) = *(int *)(lVar14 + 0x100) + 1;
+      lVar14 = *(longlong *)(*(longlong *)(*plVar20 + 0x88) + 8);
+      *(int *)(lVar14 + 0x104) = *(int *)(lVar14 + 0x104) + 1;
+      *(int *)(*local_118 + 0x108) = *(int *)(*local_118 + 0x108) + 2;
+      *(int *)(*local_118 + 0x100) = *(int *)(*local_118 + 0x100) + 2;
+      *(int *)(*local_118 + 0x10c) = *(int *)(*local_118 + 0x10c) + 1;
+      *puVar13 = 0;
+      ExReleaseFastMutexUnsafe(lVar12);
+      *(uint *)(*(longlong *)(*plVar20 + 0x88) + 0x4c) =
+           *(uint *)(*(longlong *)(*plVar20 + 0x88) + 0x4c) | 1;
+      UdfInitializeIcbContextFromScb((longlong)param_1,local_a8,*plVar20);
+      UdfLookupActiveIcb((longlong)param_1,local_a8,*(int *)(*plVar20 + 0xb0));
+      UdfInitializeScbFromIcbContext(param_1,(short *)*plVar20,local_a8,0);
+      UdfCleanupIcbContext((longlong)param_1,local_a8);
+      *local_138 = 0;
+      ExReleaseFastMutexUnsafe(local_128);
+      if (*(char *)(*plVar2 + 0x7c + local_110) == '\0') {
+        ExAcquireFastMutexUnsafe(lVar12);
+        *puVar13 = SystemReserved1[0xf];
+        UdfUninitializeScbMcb(*plVar20);
+        lVar14 = *plVar20;
+        *(undefined8 *)(lVar14 + 0xe8) = 0;
+        *(undefined8 *)(lVar14 + 0xf0) = 0;
+        *(undefined8 *)(lVar14 + 0xf8) = 0;
+        *(undefined8 *)(lVar14 + 0x100) = 0;
+        lVar14 = *plVar20;
+        *(undefined8 *)(lVar14 + 0x108) = 0;
+        *(undefined8 *)(lVar14 + 0x110) = 0;
+        *(undefined8 *)(lVar14 + 0x118) = 0;
+        *(undefined8 *)(lVar14 + 0x120) = 0;
+        *(int *)(*local_118 + 0x108) = *(int *)(*local_118 + 0x108) + -1;
+        *(int *)(*local_118 + 0x100) = *(int *)(*local_118 + 0x100) + -1;
+        *(undefined4 *)(*local_118 + 0x10c) = *(undefined4 *)(*local_118 + 0x10c);
+        *puVar13 = 0;
+        ExReleaseFastMutexUnsafe(lVar12);
       }
       else {
-        ExAcquireFastMutexUnsafe(local_res20);
-        local_58 = SystemReserved1[0xf];
-        *local_1a0 = SystemReserved1[0xf];
+        ExAcquireFastMutexUnsafe(lVar12);
+        *puVar13 = SystemReserved1[0xf];
         *puVar1 = *puVar1 | 0x8000000;
-        *local_1a0 = 0;
-        ExReleaseFastMutexUnsafe(local_res20);
-        UdfCreateInternalStream((longlong)param_1,param_2,*local_1a8,(undefined4 *)&DAT_3);
+        *puVar13 = 0;
+        ExReleaseFastMutexUnsafe(lVar12);
+        UdfCreateInternalStream((longlong)param_1,param_2,*plVar20,(undefined4 *)&DAT_3);
       }
       break;
     }
-    local_1c8 = local_1c8 + 1;
-  }
-  if ((*(byte *)(*plVar15 + 6) & 2) != 0) {
+    local_158 = local_158 + 1;
+  }
+  if ((*(byte *)(*plVar2 + 6) & 2) != 0) {
     if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-      WPP_SF_(WPP_GLOBAL_Control[3],0x15,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
+      WPP_SF_(WPP_GLOBAL_Control[3],0x15,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
     }
     if ((*puVar1 & 0x4000000) != 0) {
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-        WPP_SF_(WPP_GLOBAL_Control[3],0x16,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
+        WPP_SF_(WPP_GLOBAL_Control[3],0x16,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
       }
                     /* WARNING: Subroutine does not return */
       UdfRaiseStatusEx((longlong)param_1,0xc0000032,'\0');
     }
     if (*(uint *)(param_2 + 0xf8) < 0x100) {
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-        WPP_SF_(WPP_GLOBAL_Control[3],0x17,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
+        WPP_SF_(WPP_GLOBAL_Control[3],0x17,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
       }
                     /* WARNING: Subroutine does not return */
       UdfRaiseStatusEx((longlong)param_1,0xc000014f,'\0');
     }
     *(int *)(param_1[2] + 0x108) = *(int *)(param_1[2] + 0x108) + 2;
     *(int *)(param_1[2] + 0x100) = *(int *)(param_1[2] + 0x100) + 2;
     *(int *)(param_1[2] + 0x10c) = *(int *)(param_1[2] + 0x10c) + 1;
-    iVar7 = *(int *)(param_2 + 0x44);
-    local_13c = iVar7 * 2 - 1U & -iVar7;
-    puVar9 = (ushort *)ExAllocatePoolWithTag(0x411,local_13c);
-    local_170 = puVar9;
+    local_148 = (ushort *)ExAllocatePoolWithTag(0x411,*local_c8 * 2 - 1U & -*local_c8);
+    puVar18 = local_148;
     if ((*(uint *)(param_2 + 0x54) & 0x80) == 0) {
-      uVar20 = 3;
+      uVar11 = 3;
     }
 LAB_4:
-    local_160 = uVar20;
-    if (3 < uVar20) goto LAB_5;
-    if (uVar20 == 0) {
-      iVar7 = 0x98;
-    }
-    else if (uVar20 == 1) {
-      iVar7 = 0x96;
-    }
-    else {
-      iVar7 = 0;
-      if (uVar20 == 2) {
-        iVar7 = 2;
-      }
-    }
-    local_138 = *(int *)(param_2 + 0xf8) - iVar7;
-    uVar10 = (ulonglong)local_138;
-    local_res20 = CONCAT44(local_res20._4_4_,local_138);
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-      WPP_SF_D(WPP_GLOBAL_Control[3],0x18,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,local_138
-              );
-      uVar10 = local_res20 & 0xffffffff;
-    }
-    local_1d4 = 0;
-    while( true ) {
-      lVar18 = *plVar15;
-      if (*(ushort *)(lVar18 + 4) <= local_1d4) break;
-      lVar13 = (ulonglong)local_1d4 * 0x38;
-      if (*(int *)(lVar13 + 0x60 + lVar18) == 1) {
-        uVar17 = *(uint *)(lVar13 + 0x68 + lVar18);
-        if ((uVar17 <= (uint)uVar10) && ((uint)uVar10 < *(int *)(lVar13 + 0x6c + lVar18) + uVar17))
-        break;
-      }
-      local_1d4 = local_1d4 + 1;
-    }
-    if (local_1d4 == *(ushort *)(lVar18 + 4)) {
+    local_108 = uVar11;
+    if (uVar11 < 4) {
+      if (uVar11 == 0) {
+        iVar6 = 0x98;
+      }
+      else if (uVar11 == 1) {
+        iVar6 = 0x96;
+      }
+      else {
+        iVar6 = 0;
+        if (uVar11 == 2) {
+          iVar6 = 2;
+        }
+      }
+      uVar19 = *(int *)(param_2 + 0xf8) - iVar6;
+      uVar15 = uVar10;
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-        uVar16 = 0x19;
-LAB_6:
-        WPP_SF_(WPP_GLOBAL_Control[3],uVar16,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
-      }
-    }
-    else {
-      if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-         ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-        WPP_SF_D(WPP_GLOBAL_Control[3],0x1a,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,
-                 (uint)local_1d4);
-        uVar10 = local_res20 & 0xffffffff;
-      }
-      local_134 = (int)uVar10 -
-                  *(int *)((ulonglong)local_1d4 * 0x38 + 0x68 + *(longlong *)(param_2 + 0x10));
-      local_res20 = CONCAT44(local_res20._4_4_,local_134);
-      local_130 = *(int *)(param_2 + 0x44) * 2 - 1U & -*(int *)(param_2 + 0x44);
-      uVar10 = UdfReadWriteSectors((longlong)param_1,
-                                   uVar10 << ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
-                                   (ulonglong)local_130,'\x01',puVar9,
-                                   *(undefined8 *)(param_2 + 0x18),'\0');
-      if ((int)uVar10 < 0) {
+        WPP_SF_D(WPP_GLOBAL_Control[3],0x18,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,uVar19)
+        ;
+      }
+      while( true ) {
+        lVar14 = *plVar2;
+        if ((*(ushort *)(lVar14 + 4) <= uVar15) ||
+           (((lVar12 = (ulonglong)uVar15 * 0x38, *(int *)(lVar12 + 0x60 + lVar14) == 1 &&
+             (uVar17 = *(uint *)(lVar12 + 0x68 + lVar14), uVar17 <= uVar19)) &&
+            (uVar19 < *(int *)(lVar12 + 0x6c + lVar14) + uVar17)))) break;
+        uVar15 = uVar15 + 1;
+      }
+      if (uVar15 == *(ushort *)(lVar14 + 4)) {
         if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
            ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-          uVar16 = 0x1b;
-          goto LAB_6;
+          WPP_SF_(WPP_GLOBAL_Control[3],0x19,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
         }
+        uVar11 = uVar11 + 1;
       }
       else {
-        if ((*puVar9 == 0x105) || (*puVar9 == 0x10a)) {
-          uVar10 = UdfVerifyDescriptor((longlong)param_1,(short *)puVar9,0,
-                                       (ulonglong)*(uint *)(param_2 + 0x44),(uint)local_res20,1);
-          if ((char)uVar10 != '\0') {
-            uVar17 = 0xf8;
-            if (*(short *)(param_2 + 0x858) != 10) {
-              uVar17 = 0;
+        if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+           ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+          WPP_SF_D(WPP_GLOBAL_Control[3],0x1a,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                   (uint)uVar15);
+        }
+        uVar17 = uVar19 - *(int *)((ulonglong)uVar15 * 0x38 + 0x68 + *(longlong *)(param_2 + 0x10));
+        uVar8 = UdfReadWriteSectors((longlong)param_1,
+                                    (ulonglong)uVar19 <<
+                                    ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
+                                    (ulonglong)
+                                    (*(int *)(param_2 + 0x44) * 2 - 1U & -*(int *)(param_2 + 0x44)),
+                                    '\x01',puVar18,*(undefined8 *)(param_2 + 0x18),'\0');
+        if ((int)uVar8 < 0) {
+          if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+             ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+            WPP_SF_(WPP_GLOBAL_Control[3],0x1b,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
+          }
+          uVar11 = uVar11 + 1;
+        }
+        else if (((*puVar18 == 0x105) || (*puVar18 == 0x10a)) &&
+                (uVar8 = UdfVerifyDescriptor((longlong)param_1,(short *)puVar18,0,
+                                             (ulonglong)*(uint *)(param_2 + 0x44),uVar17,1),
+                (char)uVar8 != '\0')) {
+          uVar19 = 0xf8;
+          if (*(short *)(param_2 + 0x858) != 10) {
+            uVar19 = 0;
+          }
+          if (uVar19 != *(byte *)((longlong)puVar18 + 0x1b)) {
+            if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+               ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+              WPP_SF_dD(WPP_GLOBAL_Control[3],0x1d,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                        (uint)*(byte *)((longlong)puVar18 + 0x1b));
             }
-            if (uVar17 != *(byte *)((longlong)puVar9 + 0x1b)) {
-              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                WPP_SF_dD(WPP_GLOBAL_Control[3],0x1d,
-                          &WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,
-                          (uint)*(byte *)((longlong)puVar9 + 0x1b));
-              }
-              goto LAB_7;
-            }
-            if (((puVar9[0x18] != 0) && ((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control))
-               && ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-              WPP_SF_D(WPP_GLOBAL_Control[3],0x1e,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,
-                       (uint)puVar9[0x18]);
-            }
-            uVar10 = *(ulonglong *)(puVar9 + 0x1c);
-            uVar11 = 0x9c;
-            if (*(short *)(param_2 + 0x858) != 10) {
-              uVar11 = 0x28;
-            }
-            if (((uVar10 < uVar11) || (0x1000000 < uVar10)) || ((uVar10 & 3) != 0)) {
-              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                WPP_SF_i(WPP_GLOBAL_Control[3],0x1f,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids
-                         ,uVar10);
-              }
-            }
-            else {
-              UdfUnpinData(0x28,&local_1c0);
-              UdfCreateOrResetVatAndVmcbStreams
-                        (param_1,param_2,(uint)local_res20,(longlong)puVar9,local_1d4);
-              lVar18 = *(longlong *)(local_res18 + 0x158);
-              if (*(short *)(param_2 + 0x858) == 10) {
-                local_198 = 0;
-                CcMapData(*(undefined8 *)(lVar18 + 0x1f8),&local_198,*(undefined4 *)(param_2 + 0x44)
-                          ,1,&local_1c0,&local_150);
-                uVar3 = local_150[1];
-                uVar4 = *local_150;
-                if (((ulonglong)uVar3 + 0x98 == (ulonglong)uVar4) &&
-                   ((uVar3 == 0 || ((0x1f < uVar3 && ((uVar3 & 3) == 0)))))) {
-                  *(uint *)(param_2 + 0x1d8) = (uint)uVar4;
-                  *(uint *)(param_2 + 0x1dc) =
-                       *(int *)(*(longlong *)(local_res18 + 0x158) + 0x20) - (uint)uVar4 >> 2;
-                  if (local_150[1] < 0x20) {
-                    *(uint *)(param_2 + 0x850) = *(uint *)(param_2 + 0x850) & 0xffffffef;
-                  }
-                  else {
-                    local_168 = local_150 + 0x4c;
-                    pcVar2 = (char *)((longlong)local_150 + 0x99);
-                    iVar7 = memcmp((void *)((longlong)local_150 + 0x99),&DAT_8,0x17);
-                    if (iVar7 != 0) {
-                      *(uint *)(param_2 + 0x850) = *(uint *)(param_2 + 0x850) & 0xffffffef;
-                    }
-                    UdfCStringToWString(pcVar2,0x17,(undefined2 *)(param_2 + 0x974));
-                  }
-                  *(undefined4 *)(param_2 + 0x5b8) = *(undefined4 *)(local_150 + 0x44);
-                  *(undefined4 *)(param_2 + 0x5bc) = *(undefined4 *)(local_150 + 0x46);
-                  puVar14 = WPP_GLOBAL_Control;
-                  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                    uVar16 = 0x21;
-LAB_9:
-                    puVar14 = (undefined8 *)WPP_GLOBAL_Control[3];
-                    WPP_SF_D(puVar14,uVar16,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,
-                             *(undefined4 *)(param_2 + 0x1dc));
-                  }
-LAB_10:
-                  UdfConvertUdfTimeToNtTime(puVar14,puVar9 + 0x2a,(longlong *)(param_2 + 0x8a0));
-                  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                    WPP_SF_(WPP_GLOBAL_Control[3],0x24,
-                            &WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
-                  }
-                  goto LAB_5;
-                }
+            uVar11 = uVar11 + 1;
+            goto LAB_4;
+          }
+          if (((puVar18[0x18] != 0) && ((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control))
+             && ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+            WPP_SF_D(WPP_GLOBAL_Control[3],0x1e,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                     (uint)puVar18[0x18]);
+          }
+          uVar8 = *(ulonglong *)(puVar18 + 0x1c);
+          uVar9 = 0x9c;
+          if (*(short *)(param_2 + 0x858) != 10) {
+            uVar9 = 0x28;
+          }
+          if (((uVar9 <= uVar8) && (uVar8 < 0x1000001)) && ((uVar8 & 3) == 0)) {
+            UdfUnpinData(0x28,&local_150);
+            UdfCreateOrResetVatAndVmcbStreams(param_1,param_2,uVar17,(longlong)puVar18,uVar15);
+            plVar20 = (longlong *)(local_c0 + 0x158);
+            lVar14 = *plVar20;
+            if (*(short *)(param_2 + 0x858) == 10) {
+              local_130 = 0;
+              CcMapData(*(undefined8 *)(lVar14 + 0x1f8));
+              uVar15 = local_120[1];
+              if ((ulonglong)uVar15 + 0x98 != (ulonglong)*local_120) {
+LAB_5:
                 if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
                    ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
                   WPP_SF_dD(WPP_GLOBAL_Control[3],0x20,
-                            &WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,(uint)uVar4);
+                            &WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,(uint)*local_120);
                 }
-              }
-              else {
-                local_198 = *(longlong *)(lVar18 + 0x20) - 0x24;
-                uVar19 = 0x20;
-                CcMapData(*(undefined8 *)(lVar18 + 0x1f8),&local_198,0x20,1,&local_1c0,&local_168);
-                uVar19 = UdfUdfIdentifierContained
-                                   ((longlong)local_168,&UdfVatTableIdentifier,uVar19,0x150);
-                if ((char)uVar19 != '\0') {
-                  *(undefined4 *)(param_2 + 0x1d8) = 0;
-                  *(int *)(param_2 + 0x1dc) =
-                       (int)((ulonglong)*(uint *)(*(longlong *)(local_res18 + 0x158) + 0x20) - 0x24
-                            >> 2);
-                  UdfCStringToWString((char *)((longlong)local_168 + 1),0x17,
-                                      (undefined2 *)(param_2 + 0x974));
-                  puVar14 = WPP_GLOBAL_Control;
-                  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                    uVar16 = 0x23;
-                    goto LAB_9;
-                  }
-                  goto LAB_10;
-                }
+                uVar11 = uVar11 + 1;
+                goto LAB_4;
+              }
+              if (uVar15 != 0) {
+                if ((uVar15 < 0x20) || ((uVar15 & 3) != 0)) goto LAB_5;
+                plVar20 = (longlong *)(local_b8 + 0x158);
+              }
+              uVar8 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+              if (((int)uVar8 != 0) && (*(uint *)(*plVar20 + 0x20) < *local_120 + 4)) {
                 if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
                    ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-                  uVar16 = 0x22;
-                  goto LAB_6;
+                  WPP_SF_dD(WPP_GLOBAL_Control[3],0x21,
+                            &WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,(uint)*local_120);
                 }
-              }
+                uVar11 = uVar11 + 1;
+                goto LAB_4;
+              }
+              uVar15 = *local_120;
+              *(uint *)(param_2 + 0x1d8) = (uint)uVar15;
+              *(uint *)(param_2 + 0x1dc) = *(int *)(*plVar20 + 0x20) - (uint)uVar15 >> 2;
+              if (local_120[1] < 0x20) {
+                *(uint *)(param_2 + 0x850) = *(uint *)(param_2 + 0x850) & 0xffffffef;
+              }
+              else {
+                local_100 = local_120 + 0x4c;
+                pcVar3 = (char *)((longlong)local_120 + 0x99);
+                iVar6 = memcmp((void *)((longlong)local_120 + 0x99),&DAT_6,0x17);
+                if (iVar6 != 0) {
+                  *(uint *)(param_2 + 0x850) = *(uint *)(param_2 + 0x850) & 0xffffffef;
+                }
+                UdfCStringToWString(pcVar3,0x17,(undefined2 *)(param_2 + 0x974));
+              }
+              *(undefined4 *)(param_2 + 0x5b8) = *(undefined4 *)(local_120 + 0x44);
+              *(undefined4 *)(param_2 + 0x5bc) = *(undefined4 *)(local_120 + 0x46);
+              puVar13 = WPP_GLOBAL_Control;
+              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+                puVar13 = (undefined8 *)WPP_GLOBAL_Control[3];
+                WPP_SF_D(puVar13,0x22,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                         *(undefined4 *)(param_2 + 0x1dc));
+              }
+            }
+            else {
+              local_130 = *(longlong *)(lVar14 + 0x20) - 0x24;
+              uVar16 = 0x20;
+              CcMapData(*(undefined8 *)(lVar14 + 0x1f8),&local_130,0x20,1,&local_150,&local_100);
+              puVar18 = local_100;
+              uVar16 = UdfUdfIdentifierContained
+                                 ((longlong)local_100,&UdfVatTableIdentifier,uVar16,0x150);
+              if ((char)uVar16 == '\0') {
+                if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                   ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+                  WPP_SF_(WPP_GLOBAL_Control[3],0x23,
+                          &WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
+                }
+                uVar11 = uVar11 + 1;
+                puVar18 = local_148;
+                goto LAB_4;
+              }
+              *(undefined4 *)(param_2 + 0x1d8) = 0;
+              *(int *)(param_2 + 0x1dc) = (int)((ulonglong)*(uint *)(*plVar20 + 0x20) - 0x24 >> 2);
+              UdfCStringToWString((char *)((longlong)puVar18 + 1),0x17,
+                                  (undefined2 *)(param_2 + 0x974));
+              puVar13 = WPP_GLOBAL_Control;
+              puVar18 = local_148;
+              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+                puVar13 = (undefined8 *)WPP_GLOBAL_Control[3];
+                WPP_SF_D(puVar13,0x24,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                         *(undefined4 *)(param_2 + 0x1dc));
+                puVar18 = local_148;
+              }
+            }
+            UdfConvertUdfTimeToNtTime(puVar13,puVar18 + 0x2a,(longlong *)(param_2 + 0x8a0));
+            if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+               ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+              WPP_SF_(WPP_GLOBAL_Control[3],0x25,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
             }
             goto LAB_7;
           }
+          if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+             ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+            WPP_SF_i(WPP_GLOBAL_Control[3],0x1f,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                     uVar8);
+          }
+          uVar11 = uVar11 + 1;
         }
-        if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-          WPP_SF_D(WPP_GLOBAL_Control[3],0x1c,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids,
-                   (uint)*puVar9);
+        else {
+          if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+             ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+            WPP_SF_D(WPP_GLOBAL_Control[3],0x1c,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids,
+                     (uint)*puVar18);
+          }
+          uVar11 = uVar11 + 1;
         }
       }
+      goto LAB_4;
     }
 LAB_7:
-    uVar20 = uVar20 + 1;
-    goto LAB_4;
-  }
-LAB_11:
-  if (local_1c0 != 0) {
-    CcUnpinData();
-    local_1c0 = 0;
-  }
-  if (local_170 != (ushort *)0x0) {
-    ExFreePoolWithTag(local_170,0);
-  }
-  return;
-LAB_5:
-  if (uVar20 == 4) {
+    if (uVar11 == 4) {
+      if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+         ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
+        WPP_SF_(WPP_GLOBAL_Control[3],0x26,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
+      }
+                    /* WARNING: Subroutine does not return */
+      UdfRaiseStatusEx((longlong)param_1,0xc0000032,'\0');
+    }
+    while( true ) {
+      lVar14 = *(longlong *)(param_2 + 0x10);
+      if ((*(ushort *)(lVar14 + 4) <= uVar10) ||
+         (*(int *)((ulonglong)uVar10 * 0x38 + 0x60 + lVar14) == 2)) break;
+      uVar10 = uVar10 + 1;
+    }
+    local_130 = *(longlong *)(*(longlong *)(param_2 + 0x158) + 0x20) - 0x24U >> 2;
+    *(int *)((ulonglong)uVar10 * 0x38 + 0x68 + lVar14) = (int)local_130;
     if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-      WPP_SF_(WPP_GLOBAL_Control[3],0x25,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
-    }
-                    /* WARNING: Subroutine does not return */
-    UdfRaiseStatusEx((longlong)param_1,0xc0000032,'\0');
-  }
-  while( true ) {
-    lVar18 = *(longlong *)(param_2 + 0x10);
-    if ((*(ushort *)(lVar18 + 4) <= uVar12) ||
-       (*(int *)((ulonglong)uVar12 * 0x38 + 0x60 + lVar18) == 2)) break;
-    uVar12 = uVar12 + 1;
-  }
-  local_198 = *(longlong *)(*(longlong *)(param_2 + 0x158) + 0x20) - 0x24U >> 2;
-  *(int *)((ulonglong)uVar12 * 0x38 + 0x68 + lVar18) = (int)local_198;
-  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40000) != 0)) {
-    WPP_SF_(WPP_GLOBAL_Control[3],0x26,&WPP_b3a3a4b3cfe732ecec3faa58b912f9b0_Traceguids);
-  }
-  if ((*(uint *)(param_2 + 0x30) & 0x4000) == 0 ||
-      (*(byte *)(*(longlong *)(param_2 + 0x158) + 0xd4) & 2) != 0) {
-    *(ushort **)(param_2 + 0x1d0) = puVar9;
-    local_170 = (ushort *)0x0;
-  }
-  if (local_1c0 != 0) {
+      WPP_SF_(WPP_GLOBAL_Control[3],0x27,&WPP_5aac6ac6300130da5a6e55f2cc186d11_Traceguids);
+    }
+    uVar11 = *(uint *)(*(longlong *)(param_2 + 0x158) + 0xd4);
+    if (((uVar11 & 2) != 0) || ((*(uint *)(param_2 + 0x30) & 0x4000) == 0)) {
+      *(ushort **)(param_2 + 0x1d0) = puVar18;
+      local_148 = (ushort *)0x0;
+    }
+    UdfUnpinData((ulonglong)uVar11,&local_150);
+    ExAcquireFastMutexUnsafe(param_2 + 0x630);
+    *(void **)(param_2 + 0x668) = SystemReserved1[0xf];
+    *(int *)(param_1[2] + 0x108) = *(int *)(param_1[2] + 0x108) + -2;
+    *(int *)(param_1[2] + 0x100) = *(int *)(param_1[2] + 0x100) + -2;
+    *(int *)(param_1[2] + 0x10c) = *(int *)(param_1[2] + 0x10c) + -1;
+    *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) =
+         *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) + -1;
+    *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) =
+         *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) + -1;
+    *(undefined8 *)(param_2 + 0x668) = 0;
+    ExReleaseFastMutexUnsafe(param_2 + 0x630);
+    UdfTearDownSpecialScb(param_1,*(uint **)(param_2 + 0x110),local_140);
+    *(uint *)(param_2 + 0x30) = *(uint *)(param_2 + 0x30) & 0xfffffbff;
+    uVar11 = *(uint *)(param_2 + 0x1dc);
+    local_130 = (ulonglong)*(uint *)(param_2 + 0x1d8) + (ulonglong)(uVar11 - 1) * 4;
+    uVar17 = (uint)(local_130 >> 2) & 0x3ff;
+    uVar19 = uVar11;
+    if (uVar17 <= uVar11) {
+      uVar19 = uVar17;
+    }
+    local_104 = uVar19;
+    if (uVar19 != 0) {
+      CcMapData(*(undefined8 *)(*(longlong *)(param_2 + 0x158) + 0x1f8),&local_130,
+                (0x400 - uVar19) * 4,1,&local_150,local_f8);
+      for (; (uVar19 != 0 && (*local_f8[0] == -1)); local_f8[0] = local_f8[0] + -1) {
+        *(int *)(param_2 + 0x1dc) = *(int *)(param_2 + 0x1dc) + -1;
+        uVar19 = uVar19 - 1;
+        local_104 = uVar19;
+      }
+      UdfUnpinData(local_f8[0],&local_150);
+    }
+    ExAcquireFastMutexUnsafe(param_2 + 0x670);
+    *(void **)(param_2 + 0x6a8) = SystemReserved1[0xf];
+    psVar7 = UdfCreateScb((longlong)param_1,0,0x933,0,(undefined1 *)0x0);
+    *(short **)(param_2 + 0x160) = psVar7;
+    ExAcquireFastMutexUnsafe(param_2 + 0x630);
+    *(void **)(param_2 + 0x668) = SystemReserved1[0xf];
+    *(int *)(*(longlong *)(param_2 + 0x160) + 0xcc) =
+         *(int *)(*(longlong *)(param_2 + 0x160) + 0xcc) + 1;
+    *(int *)(*(longlong *)(param_2 + 0x160) + 0xd0) =
+         *(int *)(*(longlong *)(param_2 + 0x160) + 0xd0) + 1;
+    lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 8);
+    *(int *)(lVar14 + 0x100) = *(int *)(lVar14 + 0x100) + 1;
+    lVar14 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 8);
+    *(int *)(lVar14 + 0x104) = *(int *)(lVar14 + 0x104) + 1;
+    *(int *)(param_1[2] + 0x108) = *(int *)(param_1[2] + 0x108) + 2;
+    *(int *)(param_1[2] + 0x100) = *(int *)(param_1[2] + 0x100) + 2;
+    *(int *)(param_1[2] + 0x10c) = *(int *)(param_1[2] + 0x10c) + 1;
+    *(undefined8 *)(param_2 + 0x668) = 0;
+    ExReleaseFastMutexUnsafe(param_2 + 0x630);
+    lVar14 = *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88);
+    *(uint *)(lVar14 + 0x4c) = *(uint *)(lVar14 + 0x4c) | 1;
+    *(undefined8 *)(param_2 + 0x6a8) = 0;
+    ExReleaseFastMutexUnsafe(param_2 + 0x670);
+    *(longlong *)(*(longlong *)(param_2 + 0x160) + 8) =
+         *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 0x50) + 8;
+    *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x10) =
+         *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 0x50) + 0x70;
+    lVar14 = (ulonglong)uVar11 << ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f);
+    *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x28) = lVar14;
+    *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x20) = lVar14;
+    uVar8 = (ulonglong)(*(int *)(param_2 + 0x44) - 1);
+    *(ulonglong *)(*(longlong *)(param_2 + 0x160) + 0x18) =
+         *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x20) + uVar8 & ~uVar8;
+    UdfCreateInternalStream
+              ((longlong)param_1,param_2,*(longlong *)(param_2 + 0x160),(undefined4 *)&DAT_8
+              );
+    *(uint *)(*(longlong *)(param_2 + 0x160) + 0xd4) =
+         *(uint *)(*(longlong *)(param_2 + 0x160) + 0xd4) | 1;
+  }
+  if (local_150 != 0) {
     CcUnpinData();
-    local_1c0 = 0;
-  }
-  ExAcquireFastMutexUnsafe(param_2 + 0x630);
-  local_48 = SystemReserved1[0xf];
-  *(void **)(param_2 + 0x668) = SystemReserved1[0xf];
-  *(int *)(param_1[2] + 0x108) = *(int *)(param_1[2] + 0x108) + -2;
-  *(int *)(param_1[2] + 0x100) = *(int *)(param_1[2] + 0x100) + -2;
-  *(int *)(param_1[2] + 0x10c) = *(int *)(param_1[2] + 0x10c) + -1;
-  *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) =
-       *(int *)(*(longlong *)(param_2 + 0x110) + 0xcc) + -1;
-  *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) =
-       *(int *)(*(longlong *)(param_2 + 0x110) + 0xd0) + -1;
-  *(undefined8 *)(param_2 + 0x668) = 0;
-  ExReleaseFastMutexUnsafe(param_2 + 0x630);
-  puVar1 = *(uint **)(param_2 + 0x110);
-  local_res18 = local_res18 & 0xffffffffffffff00;
-  if (puVar1 != (uint *)0x0) {
-    LOCK();
-    puVar1[0x33] = puVar1[0x33] + 1;
-    UNLOCK();
-    plVar15 = (longlong *)(*(longlong *)(puVar1 + 0x6a) + 8);
-    if (((*plVar15 != 0) && (cVar6 = CcPurgeCacheSection(plVar15,0), cVar6 == '\0')) &&
-       (plVar15 = (longlong *)0xc000001b, local_1b0 == 0)) {
-      local_1b0 = -0x3fffffe5;
-    }
-    if ((short)*puVar1 == 0x933) {
-      UdfDeleteInternalStream(plVar15,(longlong)puVar1);
-    }
-    LOCK();
-    puVar1[0x33] = puVar1[0x33] - 1;
-    UNLOCK();
-    UdfTeardownStructures(param_1,puVar1,'\0',0,(undefined1 *)&local_res18);
-  }
-  *(uint *)(param_2 + 0x30) = *(uint *)(param_2 + 0x30) & 0xfffffbff;
-  local_158 = *(uint *)(param_2 + 0x1dc);
-  local_198 = (ulonglong)*(uint *)(param_2 + 0x1d8) + (ulonglong)(local_158 - 1) * 4;
-  uVar17 = (uint)(local_198 >> 2) & 0x3ff;
-  uVar20 = local_158;
-  if (uVar17 <= local_158) {
-    uVar20 = uVar17;
-  }
-  local_15c = uVar20;
-  if (uVar20 != 0) {
-    CcMapData(*(undefined8 *)(*(longlong *)(param_2 + 0x158) + 0x1f8),&local_198,
-              (0x400 - uVar20) * 4,1,&local_1c0,&local_148);
-    for (; (uVar20 != 0 && (*local_148 == -1)); local_148 = local_148 + -1) {
-      *(int *)(param_2 + 0x1dc) = *(int *)(param_2 + 0x1dc) + -1;
-      uVar20 = uVar20 - 1;
-      local_15c = uVar20;
-    }
-    if (local_1c0 != 0) {
-      CcUnpinData();
-      local_1c0 = 0;
-    }
-  }
-  ExAcquireFastMutexUnsafe(param_2 + 0x670);
-  *(void **)(param_2 + 0x6a8) = SystemReserved1[0xf];
-  psVar8 = UdfCreateScb((longlong)param_1,0,0x933,0,(undefined1 *)0x0);
-  *(short **)(param_2 + 0x160) = psVar8;
-  ExAcquireFastMutexUnsafe(param_2 + 0x630);
-  *(void **)(param_2 + 0x668) = SystemReserved1[0xf];
-  *(int *)(*(longlong *)(param_2 + 0x160) + 0xcc) =
-       *(int *)(*(longlong *)(param_2 + 0x160) + 0xcc) + 1;
-  *(int *)(*(longlong *)(param_2 + 0x160) + 0xd0) =
-       *(int *)(*(longlong *)(param_2 + 0x160) + 0xd0) + 1;
-  lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 8);
-  *(int *)(lVar18 + 0x100) = *(int *)(lVar18 + 0x100) + 1;
-  lVar18 = *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 8);
-  *(int *)(lVar18 + 0x104) = *(int *)(lVar18 + 0x104) + 1;
-  *(int *)(param_1[2] + 0x108) = *(int *)(param_1[2] + 0x108) + 2;
-  *(int *)(param_1[2] + 0x100) = *(int *)(param_1[2] + 0x100) + 2;
-  *(int *)(param_1[2] + 0x10c) = *(int *)(param_1[2] + 0x10c) + 1;
-  *(undefined8 *)(param_2 + 0x668) = 0;
-  ExReleaseFastMutexUnsafe(param_2 + 0x630);
-  lVar18 = *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88);
-  *(uint *)(lVar18 + 0x4c) = *(uint *)(lVar18 + 0x4c) | 1;
-  *(undefined8 *)(param_2 + 0x6a8) = 0;
-  ExReleaseFastMutexUnsafe(param_2 + 0x670);
-  *(longlong *)(*(longlong *)(param_2 + 0x160) + 8) =
-       *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 0x50) + 8;
-  *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x10) =
-       *(longlong *)(*(longlong *)(*(longlong *)(param_2 + 0x160) + 0x88) + 0x50) + 0x70;
-  lVar18 = (ulonglong)local_158 << ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f);
-  *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x28) = lVar18;
-  *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x20) = lVar18;
-  uVar10 = (ulonglong)(*(int *)(param_2 + 0x44) - 1);
-  *(ulonglong *)(*(longlong *)(param_2 + 0x160) + 0x18) =
-       *(longlong *)(*(longlong *)(param_2 + 0x160) + 0x20) + uVar10 & ~uVar10;
-  UdfCreateInternalStream
-            ((longlong)param_1,param_2,*(longlong *)(param_2 + 0x160),(undefined4 *)&DAT_12);
-  *(uint *)(*(longlong *)(param_2 + 0x160) + 0xd4) =
-       *(uint *)(*(longlong *)(param_2 + 0x160) + 0xd4) | 1;
-  goto LAB_11;
+    local_150 = 0;
+  }
+  if (local_148 != (ushort *)0x0) {
+    ExFreePoolWithTag(local_148,0);
+  }
+  return;
 }
 

```


## UdfUpdateVolumeStructures

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.08|
|i_ratio|0.46|
|m_ratio|0.94|
|b_ratio|0.89|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfUpdateVolumeStructures|UdfUpdateVolumeStructures|
|fullname|UdfUpdateVolumeStructures|UdfUpdateVolumeStructures|
|refcount|3|3|
|`length`|962|1092|
|`called`|NTOSKRNL.EXE::ExReleaseResourceLite<br>UdfAcquireResource<br>UdfConvertNtTimeToUdfTime<br>UdfMapOrPinBitmapLbnRange<br>UdfReadTrackInfo<br>UdfReadWriteSectors<br>UdfUnpinCurrentBitmapPage<br>UdfUpdateChecksumAndCrc<br>__security_check_cookie<br>memmove|<details><summary>Expand for full list:<br>Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>UdfAcquireResource<br>UdfConvertNtTimeToUdfTime<br>UdfMapOrPinBitmapLbnRange<br>UdfReadTrackInfo<br>UdfReadWriteSectors<br>UdfUnpinCurrentBitmapPage<br>UdfUpdateChecksumAndCrc<br>__security_check_cookie<br>memcpy</summary></details>|
|calling|UdfSetVolumeDirtyState<br>UdfStopBackgroundFormat|UdfSetVolumeDirtyState<br>UdfStopBackgroundFormat|
|paramcount|3|3|
|`address`|140038708|140038758|
|`sig`|ulonglong __fastcall UdfUpdateVolumeStructures(longlong param_1, longlong param_2, char param_3)|ulonglong __fastcall UdfUpdateVolumeStructures(ulonglong param_1, longlong param_2, char param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfUpdateVolumeStructures Called Diff


```diff
--- UdfUpdateVolumeStructures called
+++ UdfUpdateVolumeStructures called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
@@ -10 +11 @@
-memmove
+memcpy
```


### UdfUpdateVolumeStructures Diff


```diff
--- UdfUpdateVolumeStructures
+++ UdfUpdateVolumeStructures
@@ -1,157 +1,170 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
-ulonglong UdfUpdateVolumeStructures(longlong param_1,longlong param_2,char param_3)
+ulonglong UdfUpdateVolumeStructures(ulonglong param_1,longlong param_2,char param_3)
 
 {
-  int iVar1;
-  bool bVar2;
-  undefined8 uVar3;
-  ulonglong uVar4;
-  ulonglong uVar5;
-  longlong lVar6;
-  char *pcVar7;
-  longlong lVar8;
-  longlong lVar9;
-  int iVar10;
+  uint uVar1;
+  ushort uVar2;
+  int iVar3;
+  bool bVar4;
+  undefined8 uVar5;
+  int iVar6;
+  uint uVar7;
+  ulonglong uVar8;
+  ulonglong uVar9;
+  longlong lVar10;
   char *pcVar11;
-  undefined1 auStackY_b8 [32];
-  undefined4 local_70;
+  longlong lVar12;
+  ulonglong unaff_RBX;
+  char *pcVar13;
+  undefined1 auStackY_c8 [32];
+  undefined4 local_80;
+  longlong local_70;
+  ulonglong local_68;
   longlong local_60;
-  longlong local_58;
-  longlong local_50;
-  undefined8 local_48;
-  undefined8 uStack_40;
-  undefined8 local_38;
-  undefined8 uStack_30;
-  undefined4 local_28;
-  ulonglong local_20;
+  ulonglong local_58;
+  undefined8 local_50;
+  undefined8 uStack_48;
+  undefined8 local_40;
+  undefined8 uStack_38;
+  undefined4 local_30;
+  ulonglong local_28;
   
-  local_20 = __security_cookie ^ (ulonglong)auStackY_b8;
-  local_60 = 0;
-  bVar2 = false;
-  local_48 = 0;
-  uStack_40 = 0;
-  local_38 = 0;
-  uStack_30 = 0;
-  local_28 = 0;
-  local_58 = param_1;
-  local_50 = param_2;
-  uVar4 = UdfReadTrackInfo(*(undefined8 *)(param_2 + 0x18),(char)*(undefined4 *)(param_2 + 0x1e0),
-                           &local_48,0x24);
-  if (-1 < (int)uVar4) {
+  local_28 = __security_cookie ^ (ulonglong)auStackY_c8;
+  local_70 = 0;
+  bVar4 = false;
+  local_50 = 0;
+  uStack_48 = 0;
+  local_40 = 0;
+  uStack_38 = 0;
+  local_30 = 0;
+  local_68 = param_1;
+  local_60 = param_2;
+  iVar6 = UdfReadTrackInfo(*(undefined8 *)(param_2 + 0x18),(char)*(undefined4 *)(param_2 + 0x1e0),
+                           &local_50,0x24);
+  if (iVar6 < 0) {
+    return unaff_RBX;
+  }
+  if (param_3 == '\0') {
+    local_80._0_2_ = CONCAT11(uStack_38._2_1_,uStack_38._3_1_);
+    local_80._0_3_ = CONCAT12(uStack_38._1_1_,(undefined2)local_80);
+    local_80 = CONCAT13((undefined1)uStack_38,(undefined3)local_80);
+    *(undefined1 *)(param_2 + 0x2ac) = uStack_48._7_1_;
+    *(undefined1 *)(param_2 + 0x2ad) = uStack_48._6_1_;
+    *(undefined1 *)(param_2 + 0x2ae) = uStack_48._5_1_;
+    *(undefined1 *)(param_2 + 0x2af) = uStack_48._4_1_;
+  }
+  else {
+    local_80._0_2_ = CONCAT11(uStack_48._6_1_,uStack_48._7_1_);
+    local_80._0_3_ = CONCAT12(uStack_48._5_1_,(undefined2)local_80);
+    local_80 = CONCAT13(uStack_48._4_1_,(undefined3)local_80);
+    if (local_80 < 0xfef0) {
+      local_80 = 0xfef0;
+    }
+    *(uint *)(param_2 + 0x2ac) = local_80;
+  }
+  lVar12 = *(longlong *)(param_2 + 0x10);
+  lVar10 = (ulonglong)*(ushort *)(lVar12 + 0x5c) * 0x38;
+  iVar6 = local_80 - *(int *)(lVar10 + 0x68 + lVar12);
+  if (param_3 == '\0') {
+    iVar6 = iVar6 + (-0x100 - *(int *)(lVar12 + 0x20));
+  }
+  if (*(int *)(lVar10 + 0x6c + lVar12) == iVar6) {
+    return unaff_RBX;
+  }
+  iVar3 = *(int *)(param_2 + 0x294);
+  *(int *)(param_2 + 0x29c) = *(int *)(param_2 + 0x29c) + (iVar6 - iVar3);
+  *(int *)(param_2 + 0x298) = *(int *)(param_2 + 0x298) + (iVar6 - iVar3);
+  if (param_3 != '\0') {
+    *(int *)(param_2 + 0x2a8) = iVar3 - iVar6;
+    *(int *)(param_2 + 0x2a8) = (iVar3 - iVar6) + *(int *)(lVar12 + 0x20) + 0x100;
+  }
+  *(int *)(param_2 + 0x294) = iVar6;
+  pcVar13 = *(char **)((ulonglong)*(ushort *)(lVar12 + 0x5c) * 0x38 + 0x80 + lVar12);
+  *(int *)(pcVar13 + 0xc0) = iVar6;
+  UdfUpdateChecksumAndCrc(pcVar13,0x200);
+  uVar9 = param_1;
+  uVar8 = UdfReadWriteSectors(param_1,(ulonglong)*(uint *)(pcVar13 + 0xc) <<
+                                      ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
+                              (ulonglong)*(uint *)(param_2 + 0x44),'\x01',pcVar13,
+                              *(undefined8 *)(param_2 + 0x18),'\x01');
+  if (-1 < (int)uVar8) {
+    *(int *)((ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) * 0x38 + 0x6c +
+            *(longlong *)(param_2 + 0x10)) = iVar6;
+    UdfAcquireResource(param_1,param_2 + 0x228,'\0',0);
+    bVar4 = true;
+    UdfMapOrPinBitmapLbnRange(param_1,0,0);
     if (param_3 == '\0') {
-      local_70._0_2_ = CONCAT11(uStack_30._2_1_,uStack_30._3_1_);
-      local_70._0_3_ = CONCAT12(uStack_30._1_1_,(undefined2)local_70);
-      local_70 = CONCAT13((undefined1)uStack_30,(undefined3)local_70);
-      *(undefined1 *)(param_2 + 0x2ac) = uStack_40._7_1_;
-      *(undefined1 *)(param_2 + 0x2ad) = uStack_40._6_1_;
-      *(undefined1 *)(param_2 + 0x2ae) = uStack_40._5_1_;
-      *(undefined1 *)(param_2 + 0x2af) = uStack_40._4_1_;
+      pcVar13 = *(char **)(param_2 + 0x200);
     }
     else {
-      local_70._0_2_ = CONCAT11(uStack_40._6_1_,uStack_40._7_1_);
-      local_70._0_3_ = CONCAT12(uStack_40._5_1_,(undefined2)local_70);
-      local_70 = CONCAT13(uStack_40._4_1_,(undefined3)local_70);
-      if (local_70 < 0xfef0) {
-        local_70 = 0xfef0;
+      pcVar13 = *(char **)(*(longlong *)(param_2 + 0x68) + 0x18);
+      memcpy(pcVar13,*(void **)(param_2 + 0x200),(ulonglong)*(uint *)(param_2 + 0x58));
+    }
+    *(int *)(pcVar13 + 0x10) = iVar6;
+    *(uint *)(pcVar13 + 0x14) = iVar6 + 7U >> 3;
+    pcVar11 = pcVar13;
+    UdfUpdateChecksumAndCrc(pcVar13,0x18);
+    UdfUnpinCurrentBitmapPage(pcVar11,param_2,0);
+    lVar12 = *(longlong *)(param_2 + 0x10);
+    lVar10 = (ulonglong)*(ushort *)(lVar12 + 0x5c) * 0x38;
+    uVar9 = param_1;
+    uVar8 = UdfReadWriteSectors(param_1,(ulonglong)
+                                        (uint)(*(int *)(lVar10 + 0x78 + lVar12) +
+                                              *(int *)(lVar10 + 0x68 + lVar12)) <<
+                                        ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
+                                (ulonglong)*(uint *)(param_2 + 0x58),'\x01',pcVar13,
+                                *(undefined8 *)(param_2 + 0x18),'\x01');
+    if ((-1 < (int)uVar8) && (param_3 != '\0')) {
+      pcVar13 = *(char **)(param_2 + 0x590);
+      uVar9 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+      if ((int)uVar9 != 0) {
+        local_58 = (ulonglong)*(uint *)(pcVar13 + 0x48) << 3;
+        uVar9 = 0xffffffff;
+        if (0xffffffff < local_58) goto LAB_0;
+        uVar7 = (int)local_58 + 0x50;
+        if ((((uVar7 < 0x50) || (uVar1 = (int)local_58 + 0x80, uVar1 < uVar7)) ||
+            (uVar7 = (*(int *)(param_2 + 0x44) + 0x1ffU & -*(int *)(param_2 + 0x44)) + 0xfff &
+                     0xfffff000, uVar9 = (ulonglong)uVar7, uVar7 < uVar1)) ||
+           (uVar2 = *(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c), uVar9 = (ulonglong)uVar2,
+           *(uint *)(pcVar13 + 0x48) <= (uint)uVar2)) goto LAB_0;
       }
-      *(uint *)(param_2 + 0x2ac) = local_70;
-    }
-    lVar9 = *(longlong *)(param_2 + 0x10);
-    lVar6 = (ulonglong)*(ushort *)(lVar9 + 0x5c) * 0x38;
-    iVar10 = local_70 - *(int *)(lVar6 + 0x68 + lVar9);
-    if (param_3 == '\0') {
-      iVar10 = iVar10 + (-0x100 - *(int *)(lVar9 + 0x20));
-    }
-    if (*(int *)(lVar6 + 0x6c + lVar9) == iVar10) {
-      uVar4 = 0;
-    }
-    else {
-      iVar1 = *(int *)(param_2 + 0x294);
-      *(int *)(param_2 + 0x29c) = *(int *)(param_2 + 0x29c) + (iVar10 - iVar1);
-      *(int *)(param_2 + 0x298) = *(int *)(param_2 + 0x298) + (iVar10 - iVar1);
-      if (param_3 != '\0') {
-        *(int *)(param_2 + 0x2a8) = iVar1 - iVar10;
-        *(int *)(param_2 + 0x2a8) = (iVar1 - iVar10) + *(int *)(lVar9 + 0x20) + 0x100;
-      }
-      *(int *)(param_2 + 0x294) = iVar10;
-      pcVar11 = *(char **)((ulonglong)*(ushort *)(lVar9 + 0x5c) * 0x38 + 0x80 + lVar9);
-      *(int *)(pcVar11 + 0xc0) = iVar10;
-      UdfUpdateChecksumAndCrc(pcVar11,0x200);
-      lVar9 = param_1;
-      uVar5 = UdfReadWriteSectors(param_1,(ulonglong)*(uint *)(pcVar11 + 0xc) <<
-                                          ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
-                                  (ulonglong)*(uint *)(param_2 + 0x44),'\x01',pcVar11,
-                                  *(undefined8 *)(param_2 + 0x18),'\x01');
-      uVar4 = uVar5 & 0xffffffff;
-      if (-1 < (int)uVar5) {
-        *(int *)((ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) * 0x38 + 0x6c +
-                *(longlong *)(param_2 + 0x10)) = iVar10;
-        UdfAcquireResource(param_1,param_2 + 0x228,'\0',0);
-        bVar2 = true;
-        UdfMapOrPinBitmapLbnRange(param_1,0,0);
-        if (param_3 == '\0') {
-          pcVar11 = *(char **)(param_2 + 0x200);
-        }
-        else {
-          pcVar11 = *(char **)(*(longlong *)(param_2 + 0x68) + 0x18);
-          memmove(pcVar11,*(void **)(param_2 + 0x200),(ulonglong)*(uint *)(param_2 + 0x58));
-        }
-        *(int *)(pcVar11 + 0x10) = iVar10;
-        *(uint *)(pcVar11 + 0x14) = iVar10 + 7U >> 3;
-        pcVar7 = pcVar11;
-        UdfUpdateChecksumAndCrc(pcVar11,0x18);
-        UdfUnpinCurrentBitmapPage(pcVar7,param_2,0);
-        lVar6 = *(longlong *)(param_2 + 0x10);
-        lVar8 = (ulonglong)*(ushort *)(lVar6 + 0x5c) * 0x38;
-        lVar9 = param_1;
-        uVar5 = UdfReadWriteSectors(param_1,(ulonglong)
-                                            (uint)(*(int *)(lVar8 + 0x78 + lVar6) +
-                                                  *(int *)(lVar8 + 0x68 + lVar6)) <<
-                                            ((byte)*(undefined4 *)(param_2 + 0x48) & 0x3f),
-                                    (ulonglong)*(uint *)(param_2 + 0x58),'\x01',pcVar11,
-                                    *(undefined8 *)(param_2 + 0x18),'\x01');
-        uVar4 = uVar5 & 0xffffffff;
-        if ((-1 < (int)uVar5) && (param_3 != '\0')) {
-          pcVar11 = *(char **)(param_2 + 0x590);
-          iVar10 = *(int *)(pcVar11 + 0x48);
-          pcVar11[0x4c] = '0';
-          uVar3 = uRam00000001400242d8;
-          pcVar11[0x4d] = '\0';
-          pcVar11[0x4e] = '\0';
-          pcVar11[0x4f] = '\0';
-          *(undefined8 *)(pcVar11 + (ulonglong)(uint)(iVar10 * 2) * 4 + 0x50) = _UdfMsRegId;
-          *(undefined8 *)(pcVar11 + (ulonglong)(uint)(iVar10 * 2) * 4 + 0x50 + 8) = uVar3;
-          uVar3 = uRam00000001400242e8;
-          *(undefined8 *)(pcVar11 + (ulonglong)(uint)(iVar10 * 2) * 4 + 0x60) = _DAT_0;
-          *(undefined8 *)(pcVar11 + (ulonglong)(uint)(iVar10 * 2) * 4 + 0x60 + 8) = uVar3;
-          *(undefined4 *)
-           (pcVar11 + (ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) * 4 + 0x50) =
-               *(undefined4 *)(param_2 + 0x29c);
-          lVar9 = (ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) +
-                  (ulonglong)*(uint *)(pcVar11 + 0x48);
-          *(undefined4 *)(pcVar11 + lVar9 * 4 + 0x50) = *(undefined4 *)(param_2 + 0x294);
-          local_60 = _DAT_1;
-          UdfConvertNtTimeToUdfTime(lVar9,&local_60,(ushort *)(pcVar11 + 0x10));
-          UdfUpdateChecksumAndCrc
-                    (pcVar11,*(int *)(pcVar11 + 0x4c) + 0x50 + *(int *)(pcVar11 + 0x48) * 8);
-          uVar4 = UdfReadWriteSectors(param_1,(ulonglong)
-                                              (uint)(*(int *)(param_2 + 0x578) <<
-                                                    ((byte)*(undefined4 *)(param_2 + 0x48) & 0x1f)),
-                                      (ulonglong)*(uint *)(param_2 + 0x44),'\x01',pcVar11,
-                                      *(undefined8 *)(param_2 + 0x18),'\x01');
-          uVar4 = uVar4 & 0xffffffff;
-          lVar9 = param_1;
-        }
-      }
-      if (bVar2) {
-        UdfUnpinCurrentBitmapPage(lVar9,param_2,0);
-        ExReleaseResourceLite(param_2 + 0x228);
-      }
+      iVar6 = *(int *)(pcVar13 + 0x48);
+      pcVar13[0x4c] = '0';
+      uVar5 = uRam00000001400242d8;
+      pcVar13[0x4d] = '\0';
+      pcVar13[0x4e] = '\0';
+      pcVar13[0x4f] = '\0';
+      *(undefined8 *)(pcVar13 + (ulonglong)(uint)(iVar6 * 2) * 4 + 0x50) = _UdfMsRegId;
+      *(undefined8 *)(pcVar13 + (ulonglong)(uint)(iVar6 * 2) * 4 + 0x50 + 8) = uVar5;
+      uVar5 = uRam00000001400242e8;
+      *(undefined8 *)(pcVar13 + (ulonglong)(uint)(iVar6 * 2) * 4 + 0x60) = _DAT_1;
+      *(undefined8 *)(pcVar13 + (ulonglong)(uint)(iVar6 * 2) * 4 + 0x60 + 8) = uVar5;
+      *(undefined4 *)
+       (pcVar13 + (ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) * 4 + 0x50) =
+           *(undefined4 *)(param_2 + 0x29c);
+      lVar12 = (ulonglong)*(ushort *)(*(longlong *)(param_2 + 0x10) + 0x5c) +
+               (ulonglong)*(uint *)(pcVar13 + 0x48);
+      *(undefined4 *)(pcVar13 + lVar12 * 4 + 0x50) = *(undefined4 *)(param_2 + 0x294);
+      local_70 = _DAT_2;
+      UdfConvertNtTimeToUdfTime(lVar12,&local_70,(ushort *)(pcVar13 + 0x10));
+      UdfUpdateChecksumAndCrc
+                (pcVar13,*(int *)(pcVar13 + 0x4c) + 0x50 + *(int *)(pcVar13 + 0x48) * 8);
+      UdfReadWriteSectors(param_1,(ulonglong)
+                                  (uint)(*(int *)(param_2 + 0x578) <<
+                                        ((byte)*(undefined4 *)(param_2 + 0x48) & 0x1f)),
+                          (ulonglong)*(uint *)(param_2 + 0x44),'\x01',pcVar13,
+                          *(undefined8 *)(param_2 + 0x18),'\x01');
+      uVar9 = param_1;
     }
   }
-  return uVar4;
+LAB_0:
+  if (bVar4) {
+    UdfUnpinCurrentBitmapPage(uVar9,param_2,0);
+    ExReleaseResourceLite(param_2 + 0x228);
+  }
+  return unaff_RBX;
 }
 

```


## UdfIsRemount

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.27|
|i_ratio|0.41|
|m_ratio|0.9|
|b_ratio|0.63|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfIsRemount|UdfIsRemount|
|fullname|UdfIsRemount|UdfIsRemount|
|refcount|2|2|
|`length`|721|866|
|`called`|UdfEquivalentPcb<br>WPP_SF_<br>WPP_SF_c<br>WPP_SF_i<br>WPP_SF_iD<br>memcmp|Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>UdfEquivalentPcb<br>WPP_SF_<br>WPP_SF_c<br>WPP_SF_i<br>WPP_SF_iD<br>memcmp|
|calling|UdfMountVolume|UdfMountVolume|
|paramcount|4|4|
|`address`|140056658|140055b54|
|sig|char __fastcall UdfIsRemount(undefined8 param_1, undefined8 * param_2, longlong * param_3, longlong param_4)|char __fastcall UdfIsRemount(undefined8 param_1, undefined8 * param_2, longlong * param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfIsRemount Called Diff


```diff
--- UdfIsRemount called
+++ UdfIsRemount called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
```


### UdfIsRemount Diff


```diff
--- UdfIsRemount
+++ UdfIsRemount
@@ -1,82 +1,118 @@
 
 char UdfIsRemount(undefined8 param_1,undefined8 *param_2,longlong *param_3,longlong param_4)
 
 {
   undefined8 *puVar1;
   longlong lVar2;
   longlong lVar3;
   longlong lVar4;
   longlong lVar5;
   void *_Buf2;
-  void *_Buf1;
   char cVar6;
-  int iVar7;
-  ulonglong uVar8;
-  undefined8 *puVar9;
+  bool bVar7;
+  int iVar8;
+  ulonglong uVar9;
+  uint uVar10;
+  undefined8 *_Buf1;
+  undefined8 *_Buf1_00;
+  char unaff_BL;
+  uint uVar11;
+  undefined8 *puVar12;
   
   lVar2 = param_2[1];
   cVar6 = '\0';
-  if (UdfNoRemounts == '\0') {
-    puVar9 = DAT_0;
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-      WPP_SF_i(WPP_GLOBAL_Control[3],0x37,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,param_2);
-      puVar9 = DAT_0;
+  bVar7 = false;
+  uVar11 = 0;
+  if (UdfNoRemounts != '\0') {
+    return unaff_BL;
+  }
+  uVar9 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+  lVar3 = param_2[0xb2];
+  if ((int)uVar9 == 0) {
+    uVar11 = 0;
+    if (lVar3 != 0) {
+      uVar11 = *(int *)(lVar3 + 0x4c) + (*(int *)(lVar3 + 0x48) + 10) * 8;
     }
-    for (; (undefined8 **)puVar9 != &DAT_0; puVar9 = (undefined8 *)*puVar9) {
-      puVar1 = puVar9 + -4;
+  }
+  else {
+    if (((lVar3 == 0) || (uVar9 = (ulonglong)*(uint *)(lVar3 + 0x48) << 3, 0xffffffff < uVar9)) ||
+       (uVar10 = (int)uVar9 + 0x50, uVar10 < 0x50)) goto LAB_0;
+    uVar11 = *(int *)(lVar3 + 0x4c) + uVar10;
+    if (uVar11 < uVar10) {
+      uVar11 = 0xffffffff;
+      goto LAB_0;
+    }
+    if (((*(int *)((longlong)param_2 + 0x44) + 0x1ffU & -*(int *)((longlong)param_2 + 0x44)) + 0xfff
+        & 0xfffff000) < uVar11) goto LAB_0;
+  }
+  bVar7 = true;
+LAB_0:
+  _Buf1 = WPP_GLOBAL_Control;
+  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
+    _Buf1 = (undefined8 *)WPP_GLOBAL_Control[3];
+    WPP_SF_i(_Buf1,0x37,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,param_2);
+  }
+  puVar12 = DAT_1;
+  if ((undefined8 **)DAT_1 != &DAT_1) {
+    do {
+      puVar1 = puVar12 + -4;
       *param_3 = (longlong)puVar1;
-      if ((((param_2 != puVar1) && (lVar3 = puVar9[-3], lVar3 != lVar2)) &&
-          (*(longlong *)(lVar3 + 0x10) == *(longlong *)(lVar2 + 0x10))) &&
-         (((*(int *)((longlong)puVar9 + 0x14) == 0 &&
-           (uVar8 = UdfEquivalentPcb(&DAT_0,puVar9[-2],param_2[2]), (char)uVar8 != '\0')) &&
-          ((*(int *)((longlong)puVar9 + 0x34) == *(int *)((longlong)param_2 + 0x54) &&
-           ((*(int *)(puVar9[0x20] + 0xb8) == *(int *)(param_4 + 0x194) &&
-            (((*(uint *)(puVar9 + 2) ^ *(uint *)(param_2 + 6)) >> 0xe & 1) == 0)))))))) {
-        lVar4 = puVar9[0x27];
+      if (((param_2 != puVar1) && (lVar3 = puVar12[-3], lVar3 != lVar2)) &&
+         ((*(longlong *)(lVar3 + 0x10) == *(longlong *)(lVar2 + 0x10) &&
+          ((((*(int *)((longlong)puVar12 + 0x14) == 0 &&
+             (uVar9 = UdfEquivalentPcb(_Buf1,puVar12[-2],param_2[2]), (char)uVar9 != '\0')) &&
+            (*(int *)((longlong)puVar12 + 0x34) == *(int *)((longlong)param_2 + 0x54))) &&
+           ((_Buf1 = (undefined8 *)puVar12[0x20],
+            *(int *)((undefined8 *)puVar12[0x20] + 0x17) == *(int *)(param_4 + 0x194) &&
+            (_Buf1 = (undefined8 *)(ulonglong)*(uint *)(param_2 + 6),
+            ((*(uint *)(puVar12 + 2) ^ *(uint *)(param_2 + 6)) >> 0xe & 1) == 0)))))))) {
+        lVar4 = puVar12[0x27];
         lVar5 = param_2[0x2b];
+        _Buf1 = (undefined8 *)(ulonglong)(lVar4 != 0);
         if ((((lVar4 != 0) == (lVar5 != 0)) &&
-            (*(short *)((longlong)puVar9 + 0x83c) == *(short *)((longlong)param_2 + 0x85c))) &&
+            (*(short *)((longlong)puVar12 + 0x83c) == *(short *)((longlong)param_2 + 0x85c))) &&
            ((lVar5 == 0 ||
             ((*(longlong *)(lVar5 + 0xb8) == *(longlong *)(lVar4 + 0xb8) &&
              (*(longlong *)(lVar5 + 0x20) == *(longlong *)(lVar4 + 0x20))))))) {
-          _Buf2 = (void *)puVar9[0xae];
-          _Buf1 = (void *)param_2[0xb2];
-          if (((_Buf2 == (void *)0x0) == (_Buf1 == (void *)0x0)) &&
-             ((((_Buf1 == (void *)0x0 ||
-                ((*(int *)((longlong)_Buf1 + 0x48) == *(int *)((longlong)_Buf2 + 0x48) &&
-                 (iVar7 = memcmp(_Buf1,_Buf2,
-                                 (ulonglong)*(uint *)((longlong)_Buf1 + 0x4c) + 0x50 +
-                                 (ulonglong)(uint)(*(int *)((longlong)_Buf1 + 0x48) * 2) * 4),
-                 iVar7 == 0)))) && (*(int *)(lVar3 + 0x18) == *(int *)(lVar2 + 0x18))) &&
-              ((*(ushort *)(lVar2 + 6) == *(ushort *)(lVar3 + 6) &&
-               (iVar7 = memcmp((void *)(lVar3 + 0x20),(void *)(lVar2 + 0x20),
-                               (ulonglong)*(ushort *)(lVar2 + 6)), iVar7 == 0)))))) {
-            if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              WPP_SF_iD(WPP_GLOBAL_Control[3],0x38,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,
-                        puVar1);
+          _Buf2 = (void *)puVar12[0xae];
+          _Buf1_00 = (undefined8 *)param_2[0xb2];
+          _Buf1 = (undefined8 *)(ulonglong)(_Buf2 == (void *)0x0);
+          if (((_Buf2 == (void *)0x0) == (_Buf1_00 == (undefined8 *)0x0)) &&
+             (((_Buf1_00 == (undefined8 *)0x0 ||
+               (((bVar7 && (*(int *)(_Buf1_00 + 9) == *(int *)((longlong)_Buf2 + 0x48))) &&
+                (iVar8 = memcmp(_Buf1_00,_Buf2,(ulonglong)uVar11), _Buf1 = _Buf1_00, iVar8 == 0))))
+              && ((*(int *)(lVar3 + 0x18) == *(int *)(lVar2 + 0x18) &&
+                  (*(ushort *)(lVar2 + 6) == *(ushort *)(lVar3 + 6))))))) {
+            _Buf1 = (undefined8 *)(lVar3 + 0x20);
+            iVar8 = memcmp(_Buf1,(void *)(lVar2 + 0x20),(ulonglong)*(ushort *)(lVar2 + 6));
+            if (iVar8 == 0) {
+              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
+                WPP_SF_iD(WPP_GLOBAL_Control[3],0x38,
+                          &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,puVar1);
+              }
+              if ((((char)((byte)*(undefined4 *)(*param_3 + 0x30) ^
+                          (byte)*(undefined4 *)(param_2 + 6)) < '\0') &&
+                  ((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
+                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
+                WPP_SF_(WPP_GLOBAL_Control[3],0x39,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids)
+                ;
+              }
+              cVar6 = '\x01';
+              break;
             }
-            if ((((char)((byte)*(undefined4 *)(*param_3 + 0x30) ^ (byte)*(undefined4 *)(param_2 + 6)
-                        ) < '\0') && ((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
-               ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              WPP_SF_(WPP_GLOBAL_Control[3],0x39,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-            }
-            cVar6 = '\x01';
-            break;
           }
         }
       }
-    }
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-      WPP_SF_c(WPP_GLOBAL_Control[3],0x3a,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,
-               (-cVar6 & 0xeU) + 0x46);
-    }
+      puVar12 = (undefined8 *)*puVar12;
+    } while ((undefined8 **)puVar12 != &DAT_1);
   }
-  else {
-    cVar6 = '\0';
+  if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
+    WPP_SF_c(WPP_GLOBAL_Control[3],0x3a,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,
+             (-cVar6 & 0xeU) + 0x46);
   }
-  return cVar6;
+  return unaff_BL;
 }
 

```


## UdfMountVolume$fin$0

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.67|
|i_ratio|0.54|
|m_ratio|0.88|
|b_ratio|0.76|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfMountVolume$fin$0|UdfMountVolume$fin$0|
|fullname|UdfMountVolume$fin$0|UdfMountVolume$fin$0|
|refcount|1|1|
|`length`|272|345|
|`called`|NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::IoDeleteDevice<br>UdfDeletePcb<br>UdfDismountVcb<br>UdfFreePool|NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::IoDeleteDevice<br>UdfDeletePcb<br>UdfDismountVcb|
|calling|||
|paramcount|2|2|
|`address`|1400592e0|140059d70|
|sig|undefined __fastcall UdfMountVolume$fin$0(char param_1, longlong param_2)|undefined __fastcall UdfMountVolume$fin$0(char param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfMountVolume$fin$0 Called Diff


```diff
--- UdfMountVolume$fin$0 called
+++ UdfMountVolume$fin$0 called
@@ -0,0 +1 @@
+NTOSKRNL.EXE::ExFreePoolWithTag
@@ -5 +5,0 @@
-UdfFreePool
```


### UdfMountVolume$fin$0 Diff


```diff
--- UdfMountVolume$fin$0
+++ UdfMountVolume$fin$0
@@ -1,49 +1,59 @@
 
 void UdfMountVolume_fin_0(char param_1,longlong param_2)
 
 {
   longlong lVar1;
   void *pvVar2;
   char cVar3;
   longlong lVar4;
   
-  if (((param_1 == '\0') && (*(int *)(param_2 + 0x44) == 0)) || (*(char *)(param_2 + 0x4a) == '\0'))
+  if (((param_1 == '\0') && (*(int *)(param_2 + 0x40) == 0)) || (*(char *)(param_2 + 0x45) == '\0'))
   {
-    lVar4 = *(longlong *)(param_2 + 0xd8);
+    lVar4 = *(longlong *)(param_2 + 0xd0);
   }
   else {
-    lVar4 = *(longlong *)(param_2 + 0xd8);
+    lVar4 = *(longlong *)(param_2 + 0xd0);
     *(uint *)(*(longlong *)(lVar4 + 0x20) + 0x30) =
          *(uint *)(*(longlong *)(lVar4 + 0x20) + 0x30) | 2;
   }
-  lVar1 = *(longlong *)(param_2 + 0xe0);
+  lVar1 = *(longlong *)(param_2 + 0xd8);
   if (lVar1 != 0) {
     *(undefined8 *)(lVar1 + 8) = 0;
   }
-  if (*(longlong *)(param_2 + 0x88) != 0) {
-    UdfDeletePcb(*(longlong *)(param_2 + 0x88));
+  if (*(longlong *)(param_2 + 0x90) != 0) {
+    UdfDeletePcb(*(longlong *)(param_2 + 0x90));
   }
-  pvVar2 = *(void **)(param_2 + 0x78);
+  pvVar2 = *(void **)(param_2 + 200);
   if (pvVar2 == (void *)0x0) {
-    if (*(longlong *)(param_2 + 0x50) != 0) {
+    if (*(longlong *)(param_2 + 0x60) != 0) {
       IoDeleteDevice();
       *(undefined8 *)(lVar1 + 8) = 0;
     }
   }
   else {
     *(undefined8 *)(lVar4 + 0x10) = 0;
     *(int *)((longlong)pvVar2 + 0x100) =
          *(int *)((longlong)pvVar2 + 0x100) - *(int *)((longlong)pvVar2 + 0x108);
     cVar3 = UdfDismountVcb(lVar4,pvVar2,'\0');
     if (cVar3 != '\0') {
       ExReleaseResourceLite((longlong)pvVar2 + 0x5c8);
     }
   }
   ExReleaseResourceLite(&DAT_0);
-  UdfFreePool((longlong *)(param_2 + 0xb0));
-  UdfFreePool((longlong *)(param_2 + 0x90));
-  UdfFreePool((longlong *)(param_2 + 0x98));
-  UdfFreePool((longlong *)(param_2 + 0xb8));
+  if (*(longlong *)(param_2 + 0xb0) != 0) {
+    ExFreePoolWithTag(*(longlong *)(param_2 + 0xb0),0);
+  }
+  if (*(longlong *)(param_2 + 0x78) != 0) {
+    ExFreePoolWithTag(*(longlong *)(param_2 + 0x78),0);
+    *(undefined8 *)(param_2 + 0x78) = 0;
+  }
+  if (*(longlong *)(param_2 + 0x80) != 0) {
+    ExFreePoolWithTag(*(longlong *)(param_2 + 0x80),0);
+    *(undefined8 *)(param_2 + 0x80) = 0;
+  }
+  if (*(longlong *)(param_2 + 0x50) != 0) {
+    ExFreePoolWithTag(*(longlong *)(param_2 + 0x50),0);
+  }
   return;
 }
 

```


## UdfQueryOnDiskVolInfo

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.44|
|i_ratio|0.78|
|m_ratio|0.92|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfQueryOnDiskVolInfo|UdfQueryOnDiskVolInfo|
|fullname|UdfQueryOnDiskVolInfo|UdfQueryOnDiskVolInfo|
|refcount|2|2|
|`length`|533|622|
|`called`|UdfCStringToWString<br>UdfCompleteRequest<br>UdfConvertUdfTimeToNtTime<br>UdfDecodeFileObject|Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>UdfCStringToWString<br>UdfCompleteRequest<br>UdfConvertUdfTimeToNtTime<br>UdfDecodeFileObject|
|calling|UdfUserFsctl|UdfUserFsctl|
|paramcount|2|2|
|address|1400352e8|1400352e8|
|sig|uint __fastcall UdfQueryOnDiskVolInfo(longlong param_1, longlong param_2)|uint __fastcall UdfQueryOnDiskVolInfo(longlong param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfQueryOnDiskVolInfo Called Diff


```diff
--- UdfQueryOnDiskVolInfo called
+++ UdfQueryOnDiskVolInfo called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
```


### UdfQueryOnDiskVolInfo Diff


```diff
--- UdfQueryOnDiskVolInfo
+++ UdfQueryOnDiskVolInfo
@@ -1,125 +1,144 @@
 
 uint UdfQueryOnDiskVolInfo(longlong param_1,longlong param_2)
 
 {
   short sVar1;
   undefined8 *puVar2;
   longlong lVar3;
   short *psVar4;
   undefined8 uVar5;
   undefined8 *puVar6;
   uint uVar7;
-  longlong lVar8;
-  char *pcVar9;
-  undefined8 *puVar10;
-  undefined8 *puVar11;
-  undefined8 uVar12;
-  longlong lVar13;
+  ulonglong uVar8;
+  int iVar9;
+  longlong lVar10;
+  char *pcVar11;
+  uint uVar12;
+  undefined8 *puVar13;
+  undefined8 *puVar14;
+  undefined8 uVar15;
+  longlong lVar16;
   ulonglong local_res8;
   undefined8 local_res10;
   
   local_res8 = 0;
   puVar2 = *(undefined8 **)(param_2 + 0x18);
   lVar3 = *(longlong *)(param_1 + 0x10);
   if (puVar2 == (undefined8 *)0x0) {
     uVar7 = 0xc00000e8;
 LAB_0:
     UdfCompleteRequest(param_1,param_2,uVar7);
     return uVar7;
   }
-  uVar12 = 0x150;
+  uVar15 = 0x150;
   if (*(uint *)(*(longlong *)(param_2 + 0xb8) + 8) < 0x150) {
     uVar7 = 0xc0000023;
     goto LAB_0;
   }
-  lVar8 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 0x30);
-  uVar7 = UdfDecodeFileObject(lVar8,&local_res10,&local_res8);
+  lVar10 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 0x30);
+  uVar7 = UdfDecodeFileObject(lVar10,&local_res10,&local_res8);
   if ((uVar7 - 2 & 0xfffffffd) != 0) {
     uVar7 = 0xc000000d;
     goto LAB_0;
   }
-  lVar13 = 2;
+  lVar16 = 2;
   if ((*(byte *)(*(longlong *)(lVar3 + 0x10) + 6) & 2) == 0) {
-    lVar8 = *(longlong *)(lVar3 + 0x590);
-    if (lVar8 == 0) goto LAB_1;
-    pcVar9 = (char *)(lVar8 + (ulonglong)(uint)(*(int *)(lVar8 + 0x48) * 2) * 4 + 0x51);
-    UdfCStringToWString(pcVar9,0x17,(undefined2 *)(lVar3 + 0x974));
+    if (*(longlong *)(lVar3 + 0x590) == 0) goto LAB_1;
+    uVar8 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+    if ((int)uVar8 == 0) {
+LAB_2:
+      pcVar11 = (char *)(*(longlong *)(lVar3 + 0x590) +
+                         (ulonglong)(uint)(*(int *)(*(longlong *)(lVar3 + 0x590) + 0x48) * 2) * 4 +
+                        0x51);
+      UdfCStringToWString(pcVar11,0x17,(undefined2 *)(lVar3 + 0x974));
+    }
+    else {
+      pcVar11 = (char *)((ulonglong)*(uint *)(*(longlong *)(lVar3 + 0x590) + 0x48) << 3);
+      if (pcVar11 < (char *)0x100000000) {
+        iVar9 = (int)pcVar11;
+        uVar7 = iVar9 + 0x50;
+        pcVar11 = (char *)(ulonglong)uVar7;
+        if (((0x4f < uVar7) && (uVar12 = iVar9 + 0x7e, uVar7 <= uVar12)) &&
+           (uVar7 = (*(int *)(lVar3 + 0x44) + 0x1ffU & -*(int *)(lVar3 + 0x44)) + 0xfff & 0xfffff000
+           , pcVar11 = (char *)(ulonglong)uVar7, uVar12 <= uVar7)) goto LAB_2;
+      }
+    }
     UdfConvertUdfTimeToNtTime
-              (pcVar9,(ushort *)(*(longlong *)(lVar3 + 0x590) + 0x10),(longlong *)(lVar3 + 0x8a0));
+              (pcVar11,(ushort *)(*(longlong *)(lVar3 + 0x590) + 0x10),(longlong *)(lVar3 + 0x8a0));
   }
   else {
     psVar4 = *(short **)(lVar3 + 0x1d0);
     if (psVar4 == (short *)0x0) goto LAB_1;
     sVar1 = *psVar4;
     uVar7 = 0x54;
     if (sVar1 != 0x105) {
       uVar7 = 0x5c;
     }
     UdfConvertUdfTimeToNtTime
-              (lVar8,(ushort *)((ulonglong)uVar7 + (longlong)psVar4),(longlong *)(lVar3 + 0x8a0));
+              (lVar10,(ushort *)((ulonglong)uVar7 + (longlong)psVar4),(longlong *)(lVar3 + 0x8a0));
     uVar7 = 0x80;
     if (sVar1 != 0x105) {
       uVar7 = 0xa8;
     }
     UdfCStringToWString((char *)((longlong)psVar4 + (ulonglong)uVar7 + 1),0x17,
                         (undefined2 *)(lVar3 + 0x974));
   }
-  uVar12 = 0x150;
+  uVar15 = 0x150;
 LAB_1:
   if (((*(byte *)(*(longlong *)(lVar3 + 0x10) + 6) & 2) == 0) ||
-     ((short)uVar12 != *(short *)(lVar3 + 0x85a))) {
+     ((short)uVar15 != *(short *)(lVar3 + 0x85a))) {
     *(ulonglong *)(lVar3 + 0x868) = (ulonglong)*(uint *)(lVar3 + 0x5bc);
     *(ulonglong *)(lVar3 + 0x870) = (ulonglong)*(uint *)(lVar3 + 0x5b8);
   }
   puVar6 = (undefined8 *)(lVar3 + 0x868);
   do {
-    puVar11 = puVar6;
-    puVar10 = puVar2;
-    uVar5 = puVar11[1];
-    *puVar10 = *puVar11;
-    puVar10[1] = uVar5;
-    uVar5 = puVar11[3];
-    puVar10[2] = puVar11[2];
-    puVar10[3] = uVar5;
-    uVar5 = puVar11[5];
-    puVar10[4] = puVar11[4];
-    puVar10[5] = uVar5;
-    uVar5 = puVar11[7];
-    puVar10[6] = puVar11[6];
-    puVar10[7] = uVar5;
-    uVar5 = puVar11[9];
-    puVar10[8] = puVar11[8];
-    puVar10[9] = uVar5;
-    uVar5 = puVar11[0xb];
-    puVar10[10] = puVar11[10];
-    puVar10[0xb] = uVar5;
-    uVar5 = puVar11[0xd];
-    puVar10[0xc] = puVar11[0xc];
-    puVar10[0xd] = uVar5;
-    uVar5 = puVar11[0xf];
-    puVar10[0xe] = puVar11[0xe];
-    puVar10[0xf] = uVar5;
-    lVar13 = lVar13 + -1;
-    puVar2 = puVar10 + 0x10;
-    puVar6 = puVar11 + 0x10;
-  } while (lVar13 != 0);
-  uVar5 = puVar11[0x11];
-  puVar10[0x10] = puVar11[0x10];
-  puVar10[0x11] = uVar5;
-  uVar5 = puVar11[0x13];
-  puVar10[0x12] = puVar11[0x12];
-  puVar10[0x13] = uVar5;
-  uVar5 = puVar11[0x15];
-  puVar10[0x14] = puVar11[0x14];
-  puVar10[0x15] = uVar5;
-  uVar5 = puVar11[0x17];
-  puVar10[0x16] = puVar11[0x16];
-  puVar10[0x17] = uVar5;
-  uVar5 = puVar11[0x19];
-  puVar10[0x18] = puVar11[0x18];
-  puVar10[0x19] = uVar5;
-  *(undefined8 *)(param_2 + 0x38) = uVar12;
+    puVar14 = puVar6;
+    puVar13 = puVar2;
+    uVar5 = puVar14[1];
+    *puVar13 = *puVar14;
+    puVar13[1] = uVar5;
+    uVar5 = puVar14[3];
+    puVar13[2] = puVar14[2];
+    puVar13[3] = uVar5;
+    uVar5 = puVar14[5];
+    puVar13[4] = puVar14[4];
+    puVar13[5] = uVar5;
+    uVar5 = puVar14[7];
+    puVar13[6] = puVar14[6];
+    puVar13[7] = uVar5;
+    uVar5 = puVar14[9];
+    puVar13[8] = puVar14[8];
+    puVar13[9] = uVar5;
+    uVar5 = puVar14[0xb];
+    puVar13[10] = puVar14[10];
+    puVar13[0xb] = uVar5;
+    uVar5 = puVar14[0xd];
+    puVar13[0xc] = puVar14[0xc];
+    puVar13[0xd] = uVar5;
+    uVar5 = puVar14[0xf];
+    puVar13[0xe] = puVar14[0xe];
+    puVar13[0xf] = uVar5;
+    lVar16 = lVar16 + -1;
+    puVar2 = puVar13 + 0x10;
+    puVar6 = puVar14 + 0x10;
+  } while (lVar16 != 0);
+  uVar5 = puVar14[0x11];
+  puVar13[0x10] = puVar14[0x10];
+  puVar13[0x11] = uVar5;
+  uVar5 = puVar14[0x13];
+  puVar13[0x12] = puVar14[0x12];
+  puVar13[0x13] = uVar5;
+  uVar5 = puVar14[0x15];
+  puVar13[0x14] = puVar14[0x14];
+  puVar13[0x15] = uVar5;
+  uVar5 = puVar14[0x17];
+  puVar13[0x16] = puVar14[0x16];
+  puVar13[0x17] = uVar5;
+  uVar5 = puVar14[0x19];
+  puVar13[0x18] = puVar14[0x18];
+  puVar13[0x19] = uVar5;
+  *(undefined8 *)(param_2 + 0x38) = uVar15;
   UdfCompleteRequest(param_1,param_2,0);
   return 0;
 }
 

```


## UdfUpdateVcbPhase0$fin$1

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.63|
|i_ratio|0.52|
|m_ratio|0.86|
|b_ratio|0.66|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfUpdateVcbPhase0$fin$1|UdfUpdateVcbPhase0$fin$1|
|fullname|UdfUpdateVcbPhase0$fin$1|UdfUpdateVcbPhase0$fin$1|
|refcount|1|1|
|`length`|107|145|
|`called`|NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>UdfCleanupIcbContext<br>UdfFreePool<br>UdfUnpinData|NTOSKRNL.EXE::CcUnpinData<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>UdfCleanupIcbContext|
|calling|||
|paramcount|2|2|
|`address`|14005946d|14005b25d|
|sig|undefined __fastcall UdfUpdateVcbPhase0$fin$1(undefined8 param_1, longlong param_2)|undefined __fastcall UdfUpdateVcbPhase0$fin$1(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfUpdateVcbPhase0$fin$1 Called Diff


```diff
--- UdfUpdateVcbPhase0$fin$1 called
+++ UdfUpdateVcbPhase0$fin$1 called
@@ -0,0 +1,2 @@
+NTOSKRNL.EXE::CcUnpinData
+NTOSKRNL.EXE::ExFreePoolWithTag
@@ -3,2 +4,0 @@
-UdfFreePool
-UdfUnpinData
```


### UdfUpdateVcbPhase0$fin$1 Diff


```diff
--- UdfUpdateVcbPhase0$fin$1
+++ UdfUpdateVcbPhase0$fin$1
@@ -1,19 +1,25 @@
 
 void UdfUpdateVcbPhase0_fin_1(undefined8 param_1,longlong param_2)
 
 {
   longlong lVar1;
   
-  UdfUnpinData(param_1,(longlong *)(param_2 + 0x58));
+  if (*(longlong *)(param_2 + 0x68) != 0) {
+    CcUnpinData();
+    *(undefined8 *)(param_2 + 0x68) = 0;
+  }
   if (*(char *)(param_2 + 0x41) != '\0') {
-    UdfCleanupIcbContext(*(longlong *)(param_2 + 0x220),(void *)(param_2 + 0x110));
+    UdfCleanupIcbContext(*(longlong *)(param_2 + 0x1c0),(void *)(param_2 + 0x110));
   }
   if (*(char *)(param_2 + 0x40) != '\0') {
-    lVar1 = *(longlong *)(param_2 + 0x228);
+    lVar1 = *(longlong *)(param_2 + 0x1c8);
     *(undefined8 *)(lVar1 + 0x6a8) = 0;
     ExReleaseFastMutexUnsafe(lVar1 + 0x670);
   }
-  UdfFreePool((longlong *)(param_2 + 0xa8));
+  if (*(longlong *)(param_2 + 0x70) != 0) {
+    ExFreePoolWithTag(*(longlong *)(param_2 + 0x70),0);
+    *(undefined8 *)(param_2 + 0x70) = 0;
+  }
   return;
 }
 

```


## UdfSetVolumeDirtyState

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.18|
|i_ratio|0.6|
|m_ratio|0.91|
|b_ratio|0.91|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfSetVolumeDirtyState|UdfSetVolumeDirtyState|
|fullname|UdfSetVolumeDirtyState|UdfSetVolumeDirtyState|
|refcount|4|4|
|`length`|689|799|
|`called`|UdfConvertNtTimeToUdfTime<br>UdfPowTrackInfoUpdate<br>UdfQuickGrowSession<br>UdfReadWriteSectors<br>UdfRmwInitQuickGrowFormat<br>UdfRmwStopQuickGrowFormat<br>UdfSeqCacheFormatEmptySession<br>UdfUpdateChecksumAndCrc<br>UdfUpdateVolumeStructures<br>UdfWriteVATAndFlushBuffers|<details><summary>Expand for full list:<br>Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>UdfConvertNtTimeToUdfTime<br>UdfPowTrackInfoUpdate<br>UdfQuickGrowSession<br>UdfReadWriteSectors<br>UdfRmwInitQuickGrowFormat<br>UdfRmwStopQuickGrowFormat<br>UdfSeqCacheFormatEmptySession<br>UdfUpdateChecksumAndCrc<br>UdfUpdateVolumeStructures<br>UdfWriteVATAndFlushBuffers</summary></details>|
|calling|UdfMarkVolumeClean<br>UdfMarkVolumeCorrupt<br>UdfMarkVolumeOpenAndQueueCloseDpc|UdfMarkVolumeClean<br>UdfMarkVolumeCorrupt<br>UdfMarkVolumeOpenAndQueueCloseDpc|
|paramcount|2|2|
|`address`|140016c24|140016c74|
|`sig`|ulonglong __fastcall UdfSetVolumeDirtyState(undefined8 * param_1, char param_2)|undefined __fastcall UdfSetVolumeDirtyState(undefined8 * param_1, char param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfSetVolumeDirtyState Called Diff


```diff
--- UdfSetVolumeDirtyState called
+++ UdfSetVolumeDirtyState called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
```


### UdfSetVolumeDirtyState Diff


```diff
--- UdfSetVolumeDirtyState
+++ UdfSetVolumeDirtyState
@@ -1,148 +1,179 @@
 
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
-ulonglong UdfSetVolumeDirtyState(undefined8 *param_1,char param_2)
+void UdfSetVolumeDirtyState(undefined8 *param_1,char param_2)
 
 {
-  undefined8 *puVar1;
-  char *pcVar2;
-  undefined8 uVar3;
-  ushort uVar4;
-  int iVar5;
-  ulonglong uVar6;
-  undefined4 extraout_var;
-  undefined4 extraout_var_00;
-  undefined8 *puVar7;
-  undefined4 uVar8;
-  uint uVar9;
+  uint uVar1;
+  undefined8 *puVar2;
+  char *pcVar3;
+  undefined8 uVar4;
+  ushort uVar5;
+  int iVar6;
+  int extraout_EAX;
+  uint uVar7;
+  ulonglong uVar8;
+  undefined8 *puVar9;
   undefined4 uVar10;
+  undefined4 uVar11;
+  undefined8 *puVar12;
+  uint uVar13;
   longlong local_res8;
   
-  puVar1 = (undefined8 *)param_1[2];
-  uVar9 = *(uint *)(puVar1 + 0x10a);
-  pcVar2 = (char *)puVar1[0xb2];
-  puVar7 = param_1;
-  if ((char)uVar9 < '\0') {
-    if ((*(uint *)(puVar1 + 6) >> 0x1d & 1) == 0) {
-      if (puVar1[0x2c] == 0) {
-        uVar6 = UdfQuickGrowSession(puVar1[3],
-                                    (-((*(uint *)((longlong)puVar1 + 0x54) & 8) != 0) & 0xf0U) +
+  puVar2 = (undefined8 *)param_1[2];
+  uVar13 = *(uint *)(puVar2 + 0x10a);
+  pcVar3 = (char *)puVar2[0xb2];
+  puVar9 = param_1;
+  puVar12 = param_1;
+  if ((char)uVar13 < '\0') {
+    if ((*(uint *)(puVar2 + 6) >> 0x1d & 1) == 0) {
+      if (puVar2[0x2c] == 0) {
+        iVar6 = UdfQuickGrowSession(puVar2[3],
+                                    (-((*(uint *)((longlong)puVar2 + 0x54) & 8) != 0) & 0xf0U) +
                                     0x20);
-        if ((int)uVar6 < 0) {
-          return uVar6;
+        if (iVar6 < 0) {
+          return;
         }
-        *(uint *)(puVar1[3] + 0x30) = *(uint *)(puVar1[3] + 0x30) & 0xfffffffd;
+        *(uint *)(puVar2[3] + 0x30) = *(uint *)(puVar2[3] + 0x30) & 0xfffffffd;
         *(uint *)((longlong)param_1 + 0x1c) = *(uint *)((longlong)param_1 + 0x1c) | 0x2000;
-        uVar6 = UdfUpdateVolumeStructures((longlong)param_1,(longlong)puVar1,'\0');
-        *(uint *)((longlong)param_1 + 0x1c) = *(uint *)((longlong)param_1 + 0x1c) & 0xffffdfff;
+        puVar12 = (undefined8 *)UdfUpdateVolumeStructures((ulonglong)param_1,(longlong)puVar2,'\0');
+        *(uint *)((longlong)puVar12 + 0x1c) = *(uint *)((longlong)puVar12 + 0x1c) & 0xffffdfff;
+        puVar9 = param_1;
+        iVar6 = extraout_EAX;
       }
       else {
-        iVar5 = UdfSeqCacheFormatEmptySession(param_1);
-        uVar6 = CONCAT44(extraout_var,iVar5);
+        iVar6 = UdfSeqCacheFormatEmptySession(param_1);
       }
     }
     else {
-      puVar7 = puVar1;
-      uVar6 = UdfPowTrackInfoUpdate((longlong)puVar1);
+      puVar9 = puVar2;
+      uVar8 = UdfPowTrackInfoUpdate((longlong)puVar2);
+      iVar6 = (int)uVar8;
     }
-    if ((int)uVar6 < 0) {
-      return uVar6;
+    if (iVar6 < 0) {
+      return;
     }
-    uVar9 = *(uint *)(puVar1 + 0x10a) & 0xffffff7f;
-    *(uint *)(puVar1 + 0x10a) = uVar9;
-    if ((*(uint *)((longlong)puVar1 + 0x54) & 0x8000000) == 0) {
-      uVar4 = DAT_0 & 4;
+    uVar13 = *(uint *)(puVar2 + 0x10a) & 0xffffff7f;
+    *(uint *)(puVar2 + 0x10a) = uVar13;
+    if ((*(uint *)((longlong)puVar2 + 0x54) & 0x8000000) == 0) {
+      uVar5 = DAT_0 & 4;
     }
     else {
-      uVar4 = DAT_0 & 8;
+      uVar5 = DAT_0 & 8;
     }
-    if (uVar4 != 0) {
-      uVar9 = uVar9 | 0x10;
-      *(uint *)(puVar1 + 0x10a) = uVar9;
+    if (uVar5 != 0) {
+      uVar13 = uVar13 | 0x10;
+      *(uint *)(puVar2 + 0x10a) = uVar13;
     }
   }
-  if (puVar1[0x2c] == 0) {
-    uVar9 = *(int *)(pcVar2 + 0x48) * 2;
-    pcVar2[0x4c] = '0';
-    uVar3 = uRam00000001400242d8;
-    pcVar2[0x4d] = '\0';
-    pcVar2[0x4e] = '\0';
-    pcVar2[0x4f] = '\0';
-    *(undefined8 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x50) = _UdfMsRegId;
-    *(undefined8 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x50 + 8) = uVar3;
-    uVar3 = uRam00000001400242e8;
-    *(undefined8 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x60) = _DAT_1;
-    *(undefined8 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x60 + 8) = uVar3;
-    *(uint *)(pcVar2 + 0x1c) = (uint)(param_2 != '\0');
+  if (puVar2[0x2c] != 0) {
     if (param_2 != '\0') {
-      uVar8 = 0xffffffff;
-      uVar10 = 0xffffffff;
-      if ((*(uint *)(puVar1 + 6) >> 0x1d & 1) == 0) {
-        uVar10 = *(undefined4 *)((longlong)puVar1 + 0x29c);
+      UdfWriteVATAndFlushBuffers((longlong)puVar12,(longlong)puVar2);
+      return;
+    }
+    if ((uVar13 & 0x10) != 0) {
+      return;
+    }
+    if ((*(uint *)((longlong)puVar2 + 0x54) & 0x8000000) == 0) {
+      uVar5 = DAT_0 & 4;
+    }
+    else {
+      uVar5 = DAT_0 & 8;
+    }
+    if (uVar5 == 0) {
+      return;
+    }
+    *(uint *)(puVar2 + 0x10a) = uVar13 | 0x10;
+    return;
+  }
+  uVar8 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+  uVar11 = 0xffffffff;
+  if ((int)uVar8 != 0) {
+    uVar13 = *(uint *)(pcVar3 + 0x48);
+    if (0xffffffff < (ulonglong)uVar13 << 3) {
+      return;
+    }
+    iVar6 = (int)((ulonglong)uVar13 << 3);
+    uVar7 = iVar6 + 0x50;
+    if (uVar7 < 0x50) {
+      return;
+    }
+    uVar1 = iVar6 + 0x80;
+    if (uVar1 < uVar7) {
+      return;
+    }
+    if (((*(int *)((longlong)puVar2 + 0x44) + 0x1ffU & -*(int *)((longlong)puVar2 + 0x44)) + 0xfff &
+        0xfffff000) < uVar1) {
+      return;
+    }
+    puVar9 = (undefined8 *)puVar2[2];
+    if (uVar13 <= *(ushort *)((longlong)puVar9 + 0x5c)) {
+      return;
+    }
+    if (((*(uint *)(puVar2 + 6) >> 0x1a & 1) != 0) &&
+       (uVar13 <= *(ushort *)((longlong)puVar9 + 0x54))) {
+      return;
+    }
+  }
+  uVar13 = *(int *)(pcVar3 + 0x48) * 2;
+  pcVar3[0x4c] = '0';
+  uVar4 = uRam00000001400242d8;
+  pcVar3[0x4d] = '\0';
+  pcVar3[0x4e] = '\0';
+  pcVar3[0x4f] = '\0';
+  *(undefined8 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x50) = _UdfMsRegId;
+  *(undefined8 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x50 + 8) = uVar4;
+  uVar4 = uRam00000001400242e8;
+  *(undefined8 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x60) = _DAT_1;
+  *(undefined8 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x60 + 8) = uVar4;
+  *(uint *)(pcVar3 + 0x1c) = (uint)(param_2 != '\0');
+  if (param_2 != '\0') {
+    uVar10 = 0xffffffff;
+    if ((*(uint *)(puVar2 + 6) >> 0x1d & 1) == 0) {
+      uVar10 = *(undefined4 *)((longlong)puVar2 + 0x29c);
+    }
+    *(undefined4 *)(pcVar3 + (ulonglong)*(ushort *)(puVar2[2] + 0x5c) * 4 + 0x50) = uVar10;
+    puVar9 = (undefined8 *)
+             ((ulonglong)*(ushort *)(puVar2[2] + 0x5c) + (ulonglong)*(uint *)(pcVar3 + 0x48));
+    *(undefined4 *)(pcVar3 + (longlong)puVar9 * 4 + 0x50) =
+         *(undefined4 *)((longlong)puVar2 + 0x294);
+    if ((*(uint *)(puVar2 + 6) >> 0x1a & 1) != 0) {
+      if ((*(uint *)(puVar2 + 6) >> 0x1d & 1) == 0) {
+        uVar11 = *(undefined4 *)((longlong)puVar2 + 0x364);
       }
-      *(undefined4 *)(pcVar2 + (ulonglong)*(ushort *)(puVar1[2] + 0x5c) * 4 + 0x50) = uVar10;
-      puVar7 = (undefined8 *)
-               ((ulonglong)*(ushort *)(puVar1[2] + 0x5c) + (ulonglong)*(uint *)(pcVar2 + 0x48));
-      *(undefined4 *)(pcVar2 + (longlong)puVar7 * 4 + 0x50) =
-           *(undefined4 *)((longlong)puVar1 + 0x294);
-      if ((*(uint *)(puVar1 + 6) >> 0x1a & 1) != 0) {
-        if ((*(uint *)(puVar1 + 6) >> 0x1d & 1) == 0) {
-          uVar8 = *(undefined4 *)((longlong)puVar1 + 0x364);
-        }
-        *(undefined4 *)(pcVar2 + (ulonglong)*(ushort *)(puVar1[2] + 0x54) * 4 + 0x50) = uVar8;
-        if (((*(uint *)(puVar1 + 6) >> 0x1d & 1) == 0) || (puVar1[0x28] == 0)) {
-          uVar10 = *(undefined4 *)((longlong)puVar1 + 0x35c);
-        }
-        else {
-          uVar10 = *(undefined4 *)(puVar1[0x28] + 0x144);
-        }
-        puVar7 = (undefined8 *)
-                 ((ulonglong)*(ushort *)(puVar1[2] + 0x54) + (ulonglong)*(uint *)(pcVar2 + 0x48));
-        *(undefined4 *)(pcVar2 + (longlong)puVar7 * 4 + 0x50) = uVar10;
-      }
-      *(undefined4 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x70) = *(undefined4 *)(puVar1 + 0xb7);
-      *(undefined4 *)(pcVar2 + (ulonglong)uVar9 * 4 + 0x74) =
-           *(undefined4 *)((longlong)puVar1 + 0x5bc);
-      *(undefined8 *)(pcVar2 + 0x28) = puVar1[0xb8];
-    }
-    local_res8 = _DAT_2;
-    UdfConvertNtTimeToUdfTime(puVar7,&local_res8,(ushort *)(pcVar2 + 0x10));
-    UdfUpdateChecksumAndCrc(pcVar2,*(int *)(pcVar2 + 0x4c) + (*(int *)(pcVar2 + 0x48) + 10) * 8);
-    uVar6 = UdfReadWriteSectors((longlong)param_1,
-                                (ulonglong)
-                                (uint)(*(int *)(puVar1 + 0xaf) <<
-                                      ((byte)*(undefined4 *)(puVar1 + 9) & 0x1f)),
-                                (ulonglong)*(uint *)((longlong)puVar1 + 0x44),'\x01',pcVar2,
-                                puVar1[3],'\x01');
-    if ((int)uVar6 < 0) {
-      return uVar6;
-    }
-    if ((*(uint *)(puVar1 + 0x10a) & 0x40) != 0) {
-      if (param_2 == '\0') {
-        UdfRmwStopQuickGrowFormat(param_1,(longlong)puVar1);
+      *(undefined4 *)(pcVar3 + (ulonglong)*(ushort *)(puVar2[2] + 0x54) * 4 + 0x50) = uVar11;
+      if (((*(uint *)(puVar2 + 6) >> 0x1d & 1) == 0) || (puVar2[0x28] == 0)) {
+        uVar11 = *(undefined4 *)((longlong)puVar2 + 0x35c);
       }
       else {
-        UdfRmwInitQuickGrowFormat(param_1,(longlong)puVar1);
+        uVar11 = *(undefined4 *)(puVar2[0x28] + 0x144);
       }
+      puVar9 = (undefined8 *)
+               ((ulonglong)*(ushort *)(puVar2[2] + 0x54) + (ulonglong)*(uint *)(pcVar3 + 0x48));
+      *(undefined4 *)(pcVar3 + (longlong)puVar9 * 4 + 0x50) = uVar11;
+    }
+    *(undefined4 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x70) = *(undefined4 *)(puVar2 + 0xb7);
+    *(undefined4 *)(pcVar3 + (ulonglong)uVar13 * 4 + 0x74) =
+         *(undefined4 *)((longlong)puVar2 + 0x5bc);
+    *(undefined8 *)(pcVar3 + 0x28) = puVar2[0xb8];
+  }
+  local_res8 = _DAT_2;
+  UdfConvertNtTimeToUdfTime(puVar9,&local_res8,(ushort *)(pcVar3 + 0x10));
+  UdfUpdateChecksumAndCrc(pcVar3,*(int *)(pcVar3 + 0x4c) + (*(int *)(pcVar3 + 0x48) + 10) * 8);
+  uVar8 = UdfReadWriteSectors((longlong)puVar12,
+                              (ulonglong)
+                              (uint)(*(int *)(puVar2 + 0xaf) <<
+                                    ((byte)*(undefined4 *)(puVar2 + 9) & 0x1f)),
+                              (ulonglong)*(uint *)((longlong)puVar2 + 0x44),'\x01',pcVar3,puVar2[3],
+                              '\x01');
+  if ((-1 < (int)uVar8) && ((*(uint *)(puVar2 + 0x10a) & 0x40) != 0)) {
+    if (param_2 == '\0') {
+      UdfRmwStopQuickGrowFormat(puVar12,(longlong)puVar2);
+    }
+    else {
+      UdfRmwInitQuickGrowFormat(puVar12,(longlong)puVar2);
     }
   }
-  else {
-    if (param_2 != '\0') {
-      iVar5 = UdfWriteVATAndFlushBuffers((longlong)param_1,(longlong)puVar1);
-      return CONCAT44(extraout_var_00,iVar5);
-    }
-    if ((uVar9 & 0x10) == 0) {
-      if ((*(uint *)((longlong)puVar1 + 0x54) & 0x8000000) == 0) {
-        uVar4 = DAT_0 & 4;
-      }
-      else {
-        uVar4 = DAT_0 & 8;
-      }
-      if (uVar4 != 0) {
-        *(uint *)(puVar1 + 0x10a) = uVar9 | 0x10;
-      }
-    }
-  }
-  return 0;
+  return;
 }
 

```


## UdfMountVolume

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.07|
|i_ratio|0.32|
|m_ratio|1.0|
|b_ratio|0.68|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfMountVolume|UdfMountVolume|
|fullname|UdfMountVolume|UdfMountVolume|
|refcount|2|2|
|`length`|5858|5675|
|`called`|<details><summary>Expand for full list:<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExRaiseStatus<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::FsRtlNotifyVolumeEvent<br>NTOSKRNL.EXE::FsRtlVolumeDeviceToCorrelationId<br>NTOSKRNL.EXE::IoBuildAsynchronousFsdRequest<br>NTOSKRNL.EXE::IoCreateDevice<br>NTOSKRNL.EXE::IoDeleteDevice<br>NTOSKRNL.EXE::IoFreeIrp<br>NTOSKRNL.EXE::IoRegisterPlugPlayNotification</summary>NTOSKRNL.EXE::IoSynchronousCallDriver<br>NTOSKRNL.EXE::IoVolumeDeviceToGuid<br>NTOSKRNL.EXE::KeInitializeSpinLock<br>NTOSKRNL.EXE::ObfDereferenceObject<br>NTOSKRNL.EXE::ObfReferenceObject<br>UdfCStringToWString<br>UdfCompletePcb<br>UdfCompleteRequest<br>UdfConvertUdfTimeToNtTime<br>UdfDeletePcb<br>UdfDetermineMediaSupportsStreaming<br>UdfDetermineMediaType<br>UdfDetermineMediaWritable<br>UdfDetermineVolumeBounding<br>UdfDismountVcb<br>UdfFindAnchorVolumeDescriptor<br>UdfFindFileSetDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfHighBit<br>UdfInitRmwSupport<br>UdfInitializeAllocationSupport<br>UdfInitializePowAllocationSupport<br>UdfInitializeVcb<br>UdfIsMediaWriteProtected<br>UdfIsRemount<br>UdfQueryFreeBlocksAndNWA<br>UdfRaiseStatusEx<br>UdfReMountOldVcb<br>UdfRecognizeVolume<br>UdfScanForDismountedVcb<br>UdfSeqCacheInitialize<br>UdfSeqCacheTearDown<br>UdfSetVcbEccBlockSize<br>UdfTearDownRmwSupport<br>UdfTelemetryGuard<br>UdfTelemetryMount<br>UdfToggleMediaEjectDisable<br>UdfTransitionSpareTableToRo<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase1<br>UdfUpdateVolumeLabel<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_i<br>WPP_SF_iD<br>__security_check_cookie</details>|<details><summary>Expand for full list:<br>Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::FsRtlNotifyVolumeEvent<br>NTOSKRNL.EXE::FsRtlVolumeDeviceToCorrelationId<br>NTOSKRNL.EXE::IoBuildAsynchronousFsdRequest<br>NTOSKRNL.EXE::IoCreateDevice<br>NTOSKRNL.EXE::IoDeleteDevice<br>NTOSKRNL.EXE::IoFreeIrp<br>NTOSKRNL.EXE::IoRegisterPlugPlayNotification</summary>NTOSKRNL.EXE::IoSynchronousCallDriver<br>NTOSKRNL.EXE::IoVolumeDeviceToGuid<br>NTOSKRNL.EXE::KeInitializeSpinLock<br>NTOSKRNL.EXE::ObfDereferenceObject<br>NTOSKRNL.EXE::ObfReferenceObject<br>UdfAcquireResource<br>UdfCStringToWString<br>UdfCompletePcb<br>UdfCompleteRequest<br>UdfConvertUdfTimeToNtTime<br>UdfDeletePcb<br>UdfDetermineMediaSupportsStreaming<br>UdfDetermineMediaType<br>UdfDetermineMediaWritable<br>UdfDetermineVolumeBounding<br>UdfDismountVcb<br>UdfFindAnchorVolumeDescriptor<br>UdfFindFileSetDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfHighBit<br>UdfInitRmwSupport<br>UdfInitializeAllocationSupport<br>UdfInitializePowAllocationSupport<br>UdfInitializeVcb<br>UdfIsMediaWriteProtected<br>UdfIsRemount<br>UdfQueryFreeBlocksAndNWA<br>UdfRaiseStatusEx<br>UdfReMountOldVcb<br>UdfRecognizeVolume<br>UdfScanForDismountedVcb<br>UdfSeqCacheInitialize<br>UdfSeqCacheTearDown<br>UdfSetVcbEccBlockSize<br>UdfTearDownRmwSupport<br>UdfTelemetryGuard<br>UdfTelemetryMount<br>UdfToggleMediaEjectDisable<br>UdfTransitionSpareTableToRo<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase1<br>UdfUpdateVolumeLabel<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_i<br>WPP_SF_iD<br>__security_check_cookie</details>|
|calling|UdfCommonFsControl|UdfCommonFsControl|
|paramcount|2|2|
|`address`|1400451c0|140050aa0|
|sig|uint __fastcall UdfMountVolume(short * param_1, longlong param_2)|uint __fastcall UdfMountVolume(short * param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfMountVolume Called Diff


```diff
--- UdfMountVolume called
+++ UdfMountVolume called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
@@ -3 +3,0 @@
-NTOSKRNL.EXE::ExRaiseStatus
@@ -16,0 +17 @@
+UdfAcquireResource
```


### UdfMountVolume Diff


```diff
--- UdfMountVolume
+++ UdfMountVolume
@@ -1,756 +1,802 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* WARNING: Removing unreachable block (ram,0x000140046050) */
-/* WARNING: Removing unreachable block (ram,0x000140046098) */
-/* WARNING: Removing unreachable block (ram,0x000140046034) */
-/* WARNING: Removing unreachable block (ram,0x00014004607c) */
+/* WARNING: Removing unreachable block (ram,0x0001400518be) */
+/* WARNING: Removing unreachable block (ram,0x000140051905) */
+/* WARNING: Removing unreachable block (ram,0x0001400518a2) */
+/* WARNING: Removing unreachable block (ram,0x0001400518e9) */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 uint UdfMountVolume(short *param_1,longlong param_2)
 
 {
   undefined8 *puVar1;
-  undefined8 *puVar2;
-  bool bVar3;
-  char cVar4;
-  undefined4 uVar5;
-  uint uVar6;
-  int iVar7;
-  longlong lVar8;
-  ulonglong uVar9;
-  ushort uVar10;
-  undefined8 uVar11;
-  undefined2 uVar12;
-  short *psVar13;
-  byte bVar14;
-  longlong lVar15;
-  longlong lVar16;
+  longlong lVar2;
+  longlong lVar3;
+  undefined8 *puVar4;
+  char cVar5;
+  bool bVar6;
+  char extraout_AL;
+  char cVar7;
+  uint uVar8;
+  int iVar9;
+  longlong lVar10;
+  ulonglong uVar11;
+  ulonglong uVar12;
+  ushort uVar13;
+  undefined8 uVar14;
+  short *psVar15;
+  undefined2 uVar16;
   uint uVar17;
-  char *pcVar18;
-  char *pcVar19;
-  char *pcVar20;
-  char *pcVar21;
+  short *psVar18;
+  undefined4 uVar19;
+  short *psVar20;
+  short *psVar21;
   short *psVar22;
-  undefined1 auStackY_158 [32];
-  char local_118 [4];
-  uint local_114;
-  undefined1 local_110;
-  undefined1 local_10f;
-  byte local_10e;
+  short *psVar23;
+  short *psVar24;
+  undefined1 auStackY_168 [32];
+  char local_124;
+  byte local_123;
+  longlong local_120;
+  short *local_118;
+  undefined1 local_110 [8];
   longlong local_108;
-  uint local_100 [2];
-  short *local_f8;
-  short local_f0 [2];
-  uint local_ec;
-  short *local_e8;
-  short *local_e0;
-  uint local_d8;
-  uint local_d4;
-  longlong local_d0;
+  uint local_100;
+  short local_fc [2];
+  uint local_f8;
+  uint local_f4;
+  longlong local_f0;
+  longlong local_e8;
+  uint local_e0;
+  uint local_dc;
+  longlong local_d8;
+  undefined4 local_d0 [2];
   longlong local_c8;
   longlong local_c0;
-  undefined4 local_b8;
-  uint local_b4;
-  longlong local_b0;
-  char *local_a8;
-  char *local_a0;
-  uint local_98;
+  short *local_b8;
+  uint local_b0;
+  short *local_a8;
+  short *local_a0;
+  short *local_98;
   longlong local_90;
-  longlong local_88;
-  short *local_80;
-  longlong local_78;
-  char *local_70;
-  undefined8 local_68;
-  undefined8 uStack_60;
+  short *local_88;
+  longlong local_80;
+  ulonglong local_78;
+  undefined8 local_70;
+  undefined8 uStack_68;
+  undefined8 local_60;
   undefined8 local_58;
-  undefined8 local_50;
-  undefined8 uStack_48;
-  undefined8 local_40;
-  undefined8 uStack_38;
-  ulonglong local_30;
+  undefined8 uStack_50;
+  undefined8 local_48;
+  undefined8 uStack_40;
+  ulonglong local_38;
   
-  local_30 = __security_cookie ^ (ulonglong)auStackY_158;
-  pcVar18 = (char *)0x0;
+  local_38 = __security_cookie ^ (ulonglong)auStackY_168;
+  psVar20 = (short *)0x0;
   local_108 = 0;
-  local_e0 = (short *)0x0;
-  local_f8 = (short *)0x0;
-  local_d0 = 0;
-  lVar15 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 0x10);
-  lVar16 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 8);
-  local_90 = 0;
-  local_b8 = 0;
-  local_68 = 0;
-  uStack_60 = 0;
+  psVar18 = (short *)0x0;
+  local_a0 = (short *)0x0;
+  local_a8 = (short *)0x0;
+  local_d8 = 0;
+  lVar2 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 0x10);
+  lVar10 = *(longlong *)(*(longlong *)(param_2 + 0xb8) + 8);
+  local_120 = 0;
+  local_d0[0] = 0;
+  local_70 = 0;
+  uStack_68 = 0;
+  local_60 = 0;
+  psVar22 = (short *)0x0;
+  local_b8 = (short *)0x0;
+  local_f0 = 0;
+  local_e8 = 0;
+  psVar24 = (short *)0x0;
+  local_118 = (short *)0x0;
+  local_110[0] = 0;
+  local_124 = '\0';
+  local_dc = local_dc & 0xffffff00;
+  local_fc[0] = -1;
+  local_e0 = 0;
+  local_100 = 0;
+  local_f4 = 0;
+  local_f8 = 0;
+  local_48 = 0;
+  uStack_40 = 0;
+  local_c8 = lVar10;
+  local_c0 = param_2;
+  local_98 = param_1;
+  local_90 = lVar10;
+  local_80 = lVar2;
+  if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+     ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+    WPP_SF_i(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x11,
+             &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,*(undefined8 *)(lVar10 + 0x10));
+  }
   local_58 = 0;
-  local_a8 = (char *)0x0;
-  local_c8 = 0;
-  local_c0 = 0;
-  pcVar20 = (char *)0x0;
-  local_a0 = (char *)0x0;
-  local_110 = 0;
-  local_118[0] = '\0';
-  local_d4 = local_d4 & 0xffffff00;
-  local_f0[0] = -1;
-  local_d8 = 0;
-  local_100[0] = 0;
-  local_b4 = 0;
-  local_ec = 0;
-  local_40 = 0;
-  uStack_38 = 0;
-  local_b0 = lVar15;
-  local_80 = param_1;
-  local_78 = lVar16;
-  if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-     ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-    WPP_SF_i(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x11,
-             &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,*(undefined8 *)(lVar16 + 0x10));
-  }
-  local_50 = 0;
-  uStack_48 = 0;
-  lVar8 = *(longlong *)(lVar16 + 0x10);
-  *(longlong *)(param_1 + 0x10) = lVar8;
-  bVar14 = *(byte *)(lVar8 + 0x30) >> 1 & 1;
-  local_10e = bVar14;
-  if ((UdfDisable != '\0') || ((*(uint *)(*(longlong *)(lVar16 + 0x10) + 0x34) & 4) != 0)) {
-    UdfCompleteRequest((longlong)param_1,param_2,0xc000014f);
+  uStack_50 = 0;
+  lVar3 = *(longlong *)(lVar10 + 0x10);
+  *(longlong *)(param_1 + 0x10) = lVar3;
+  local_123 = *(byte *)(lVar3 + 0x30) >> 1 & 1;
+  if ((UdfDisable != '\0') || ((*(uint *)(*(longlong *)(lVar10 + 0x10) + 0x34) & 4) != 0)) {
+    UdfCompleteRequest((longlong)param_1,local_c0,0xc000014f);
     return 0xc000014f;
   }
   if ((DAT_0 & 1) != 0) {
-    UdfCompleteRequest((longlong)param_1,param_2,0xc00002eb);
+    UdfCompleteRequest((longlong)param_1,local_c0,0xc00002eb);
     return 0xc00002eb;
   }
   *(uint *)(param_1 + 0xe) = *(uint *)(param_1 + 0xe) | 0x800;
-  if ((*(uint *)(*(longlong *)(lVar16 + 0x10) + 0x34) & 1) != 0) {
-    uVar5 = 0x24800;
-    if (*(int *)(*(longlong *)(lVar16 + 0x10) + 0x48) != 2) {
-      uVar5 = 0x74800;
+  if ((*(uint *)(*(longlong *)(lVar10 + 0x10) + 0x34) & 1) != 0) {
+    uVar19 = 0x24800;
+    if (*(int *)(*(longlong *)(lVar10 + 0x10) + 0x48) != 2) {
+      uVar19 = 0x74800;
     }
-    local_e8 = (short *)CONCAT44(local_e8._4_4_,uVar5);
-    local_88 = IoBuildAsynchronousFsdRequest(9,lVar15,0);
-    if (local_88 == 0) {
-      uVar6 = 0xc000009a;
+    lVar10 = IoBuildAsynchronousFsdRequest(9,lVar2,0);
+    if (lVar10 == 0) {
+      uVar8 = 0xc000009a;
     }
     else {
-      lVar8 = *(longlong *)(local_88 + 0xb8);
-      *(byte *)(lVar8 + -0x46) = *(byte *)(lVar8 + -0x46) | 2;
-      *(undefined4 **)(local_88 + 0x18) = &local_b8;
-      *(undefined4 *)(lVar8 + -0x30) = local_e8._0_4_;
-      *(undefined4 *)(lVar8 + -0x40) = 4;
-      *(undefined4 *)(lVar8 + -0x38) = 0;
-      *(undefined1 *)(lVar8 + -0x48) = 0xe;
-      uVar6 = IoSynchronousCallDriver(lVar15,local_88);
-      IoFreeIrp(local_88);
-      lVar15 = local_b0;
-      if (-1 < (int)uVar6) goto LAB_1;
+      lVar3 = *(longlong *)(lVar10 + 0xb8);
+      *(byte *)(lVar3 + -0x46) = *(byte *)(lVar3 + -0x46) | 2;
+      *(undefined4 **)(lVar10 + 0x18) = local_d0;
+      *(undefined4 *)(lVar3 + -0x30) = uVar19;
+      *(undefined4 *)(lVar3 + -0x40) = 4;
+      *(undefined4 *)(lVar3 + -0x38) = 0;
+      *(undefined1 *)(lVar3 + -0x48) = 0xe;
+      uVar8 = IoSynchronousCallDriver(lVar2,lVar10);
+      IoFreeIrp(lVar10);
+      lVar10 = local_c8;
+      if (-1 < (int)uVar8) goto LAB_1;
     }
-    UdfCompleteRequest((longlong)param_1,param_2,uVar6);
-    if ((char **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-      return uVar6;
+    UdfCompleteRequest((longlong)param_1,local_c0,uVar8);
+    if ((short **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
+      return uVar8;
     }
-    if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) == 0) {
-      return uVar6;
+    if ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) == 0) {
+      return uVar8;
     }
-    uVar12 = 0x12;
+    uVar16 = 0x12;
     goto LAB_2;
   }
 LAB_1:
-  uVar5 = 0x2404c;
-  if (*(int *)(*(longlong *)(lVar16 + 0x10) + 0x48) != 2) {
-    uVar5 = 0x70000;
+  uVar19 = 0x2404c;
+  if (*(int *)(*(longlong *)(lVar10 + 0x10) + 0x48) != 2) {
+    uVar19 = 0x70000;
   }
-  local_e8 = (short *)CONCAT44(local_e8._4_4_,uVar5);
-  local_88 = IoBuildAsynchronousFsdRequest(9,lVar15,0);
-  if (local_88 == 0) {
-    uVar6 = 0xc000009a;
+  lVar10 = IoBuildAsynchronousFsdRequest(9,lVar2,0);
+  if (lVar10 == 0) {
+    uVar8 = 0xc000009a;
   }
   else {
-    lVar8 = *(longlong *)(local_88 + 0xb8);
-    *(byte *)(lVar8 + -0x46) = *(byte *)(lVar8 + -0x46) | 2;
-    *(undefined8 **)(local_88 + 0x18) = &local_68;
-    *(undefined4 *)(lVar8 + -0x30) = local_e8._0_4_;
-    *(undefined4 *)(lVar8 + -0x40) = 0x18;
-    *(undefined4 *)(lVar8 + -0x38) = 0;
-    *(undefined1 *)(lVar8 + -0x48) = 0xe;
-    uVar6 = IoSynchronousCallDriver(lVar15,local_88);
-    IoFreeIrp(local_88);
-    local_114 = uVar6;
-    if (-1 < (int)uVar6) {
+    lVar3 = *(longlong *)(lVar10 + 0xb8);
+    *(byte *)(lVar3 + -0x46) = *(byte *)(lVar3 + -0x46) | 2;
+    *(undefined8 **)(lVar10 + 0x18) = &local_70;
+    *(undefined4 *)(lVar3 + -0x30) = uVar19;
+    *(undefined4 *)(lVar3 + -0x40) = 0x18;
+    *(undefined4 *)(lVar3 + -0x38) = 0;
+    *(undefined1 *)(lVar3 + -0x48) = 0xe;
+    uVar8 = IoSynchronousCallDriver(lVar2,lVar10);
+    IoFreeIrp(lVar10);
+    if (-1 < (int)uVar8) {
       ExAcquireResourceExclusiveLite(&DAT_3,1);
       UdfScanForDismountedVcb((longlong)param_1);
-      pcVar21 = pcVar18;
-      if ((local_58._4_4_ == 0) ||
-         (uVar6 = local_58._4_4_, iVar7 = UdfHighBit(local_58._4_4_), lVar15 = local_b0,
-         (uVar6 & ~(1 << ((byte)iVar7 & 0x1f))) != 0)) {
-        if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-          WPP_SF_iD(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x14,
-                    &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,&local_68);
+      if ((local_60._4_4_ == 0) ||
+         (uVar8 = local_60._4_4_, iVar9 = UdfHighBit(local_60._4_4_),
+         (uVar8 & ~(1 << ((byte)iVar9 & 0x1f))) != 0)) {
+        if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+           ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+          WPP_SF_iD(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x14,
+                    &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,&local_70);
         }
-        local_114 = 0xc0000183;
-        psVar22 = local_e0;
-        goto LAB_4;
-      }
-      if (0x1000 < uVar6) {
-        if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-          uVar12 = 0x15;
+        uVar8 = 0xc0000183;
+        lVar10 = local_120;
+      }
+      else if (uVar8 < 0x1001) {
+        uVar8 = UdfDetermineVolumeBounding
+                          ((longlong)param_1,lVar2,&local_e0,&local_100,&local_f4,&local_124);
+        uVar17 = local_e0;
+        lVar10 = local_120;
+        if (uVar8 != 0xc000014f) {
+          local_f8 = local_e0;
+          cVar5 = UdfRecognizeVolume((undefined8 *)param_1,lVar2,local_60._4_4_,&local_f8,local_110,
+                                     local_fc);
+          cVar7 = local_124;
+          if (cVar5 == '\0') {
+            if ((*(int *)(lVar2 + 0x48) != 2) || (local_124 != '\0')) {
+              if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                uVar16 = 0x17;
+                goto LAB_4;
+              }
+              goto LAB_5;
+            }
+            if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+               ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+              WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x16,
+                      &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+            }
+          }
+          if (((cVar7 != '\0') &&
+              (local_e0 = local_f8, uVar17 = local_f8,
+              (short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
+             ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+            WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x18,
+                     &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,local_f8);
+          }
+          uVar8 = IoCreateDevice(DAT_6,0xa20,0,3);
+          if ((int)uVar8 < 0) {
+            lVar10 = local_120;
+            if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+               ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+              WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x19,
+                       &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,uVar8);
+              lVar10 = local_120;
+            }
+          }
+          else {
+            if (*(uint *)(local_108 + 0x98) < *(uint *)(lVar2 + 0x98)) {
+              *(uint *)(local_108 + 0x98) = *(uint *)(lVar2 + 0x98);
+            }
+            *(undefined4 *)(local_108 + 0x154) = 0;
+            lVar10 = local_108 + 0x158;
+            *(longlong *)(local_108 + 0x160) = lVar10;
+            *(longlong *)lVar10 = lVar10;
+            *(undefined4 *)(local_108 + 0x150) = 0;
+            KeInitializeSpinLock(local_108 + 0x168);
+            *(longlong *)(local_c8 + 8) = local_108;
+            UdfInitializeVcb((longlong)param_1,(undefined4 *)(local_108 + 0x170),lVar2,local_c8);
+            lVar3 = local_108;
+            *(char *)(local_108 + 0x4c) = *(char *)(lVar2 + 0x4c) + '\x01';
+            *(undefined2 *)(local_108 + 0x130) = local_60._4_2_;
+            *(uint *)(local_108 + 0x30) = *(uint *)(local_108 + 0x30) & 0xffffff7f;
+            psVar18 = (short *)(local_108 + 0x170);
+            local_c8 = 0;
+            local_90 = 0;
+            local_108 = 0;
+            *(uint *)(lVar3 + 0x264) = uVar17;
+            *(uint *)(lVar3 + 0x268) = local_100;
+            *(short **)(param_1 + 8) = psVar18;
+            local_a0 = psVar18;
+            UdfAcquireResource((longlong)param_1,lVar3 + 0x738,'\0',0);
+            iVar9 = IoVolumeDeviceToGuid(*(undefined8 *)(lVar3 + 0x188),&local_58);
+            if (-1 < iVar9) {
+              _DAT_7 = (undefined4)local_58;
+              uRam0000000140024a20 = local_58._4_4_;
+              uRam0000000140024a24 = (undefined4)uStack_50;
+              uRam0000000140024a28 = uStack_50._4_4_;
+            }
+            uVar14 = *(undefined8 *)(lVar3 + 0x188);
+            iVar9 = FsRtlVolumeDeviceToCorrelationId(uVar14,&local_48);
+            if (-1 < iVar9) {
+              *(undefined8 *)(lVar3 + 0xb58) = local_48;
+              *(undefined8 *)(lVar3 + 0xb60) = uStack_40;
+            }
+            UdfDetermineMediaType(uVar14,lVar2,(int *)(lVar3 + 0x1c4));
+            uVar8 = UdfDetermineMediaSupportsStreaming((longlong)param_1,(longlong)psVar18);
+            if ((char)uVar8 != '\0') {
+              *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x40000000;
+            }
+            uVar11 = UdfDetermineMediaWritable((longlong)param_1,(longlong)psVar18,local_f4);
+            if ((char)uVar11 == '\0') {
+              *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x4010;
+              if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x1a,
+                        &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+              }
+            }
+            else {
+              uVar8 = *(uint *)(lVar3 + 0x1c4);
+              if ((uVar8 != 7) && ((uVar8 & 1) != 0)) {
+                iVar9 = 0x10;
+                if ((uVar8 & 8) == 0) {
+                  iVar9 = 0x20;
+                }
+                UdfSetVcbEccBlockSize((longlong)psVar18,iVar9);
+              }
+              if (((*(int *)(lVar3 + 0x1c4) - 7U & 0xfffffff7) == 0) &&
+                 (bVar6 = UdfIsMediaWriteProtected((longlong)param_1,lVar2), bVar6)) {
+                if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                   ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                  WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x1b,
+                          &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                }
+                *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x90;
+              }
+              if ((*(uint *)(lVar3 + 0x1c4) & 0x12) == 0) {
+                UdfInitRmwSupport((longlong)param_1,(longlong)psVar18);
+              }
+              if ((*(uint *)(lVar3 + 0x1c4) & 0x10) != 0) {
+                *(uint *)(lVar3 + 0x418) = 0x500000 >> ((byte)*(undefined4 *)(lVar3 + 0x1b8) & 0x1f)
+                ;
+              }
+            }
+            *(short *)(lVar3 + 0x9c8) = local_fc[0];
+            *(int *)(*(longlong *)(lVar3 + 0x178) + 0x1c) =
+                 *(int *)(*(longlong *)(lVar3 + 0x178) + 0x1c) + 1;
+            lVar2 = *(longlong *)(*(longlong *)(lVar3 + 0x178) + 0x10);
+            *(uint *)(lVar2 + 0x30) = *(uint *)(lVar2 + 0x30) & 0xfffffffd;
+            if ((*(uint *)(lVar3 + 0x1c4) & 0x10) == 0) {
+              *(uint *)(lVar3 + 0x264) = local_f8;
+            }
+            do {
+              uVar8 = UdfFindAnchorVolumeDescriptor
+                                ((longlong)param_1,(longlong)psVar18,(longlong *)&local_b8);
+              if ((int)uVar8 < 0) {
+                if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                   ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                  WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x1c,
+                           &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,
+                           *(undefined4 *)(lVar3 + 0x264));
+                }
+                lVar10 = local_120;
+                psVar22 = local_b8;
+                psVar24 = local_118;
+                if ((*(int *)(lVar3 + 0x264) == 0) || (local_f8 != 0)) goto LAB_8;
+                *(undefined4 *)(lVar3 + 0x264) = 0;
+              }
+              psVar22 = local_b8;
+            } while ((int)uVar8 < 0);
+            *(short *)(lVar3 + 0x9cc) = local_b8[3];
+            uVar8 = UdfFindVolumeDescriptors
+                              ((longlong)param_1,(longlong)psVar18,(uint *)(local_b8 + 8),&local_d8,
+                               &local_f0,&local_e8);
+            if ((int)uVar8 < 0) {
+              uVar8 = UdfFindVolumeDescriptors
+                                ((longlong)param_1,(longlong)psVar18,(uint *)(psVar22 + 0xc),
+                                 &local_d8,&local_f0,&local_e8);
+            }
+            else if (*(int *)(psVar22 + 0xc) != 0) {
+              *(int *)(lVar3 + 0x6f4) =
+                   (*(int *)(lVar3 + 0x6f0) - *(int *)(psVar22 + 10)) + *(int *)(psVar22 + 0xe);
+            }
+            if ((int)uVar8 < 0) {
+              lVar10 = local_120;
+              psVar24 = local_118;
+              if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                uVar16 = 0x1d;
+LAB_9:
+                WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),uVar16,
+                         &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,uVar8);
+                lVar10 = local_120;
+                psVar24 = local_118;
+              }
+            }
+            else {
+              uVar8 = UdfCompletePcb((longlong)param_1,(longlong)psVar18,local_d8);
+              if ((int)uVar8 < 0) {
+                lVar10 = local_120;
+                psVar24 = local_118;
+                if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                   ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                  uVar16 = 0x1e;
+                  goto LAB_9;
+                }
+              }
+              else {
+                *(longlong *)(lVar3 + 0x180) = local_d8;
+                uVar11 = 0;
+                local_d8 = 0;
+                if (*(short *)(*(longlong *)(lVar3 + 0x180) + 0x5c) == -1) {
+                  if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                     ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                    WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x1f,
+                            &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                  }
+                  *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x4010;
+                }
+                else if (((*(uint *)(lVar3 + 0x1c4) & 0x110) == 0x10) &&
+                        (*(short *)(*(longlong *)(lVar3 + 0x180) + 0x5a) == -1)) {
+                  if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                     ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                    WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x20,
+                            &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                  }
+                  *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x10;
+                  *(uint *)(lVar3 + 0x9c0) = *(uint *)(lVar3 + 0x9c0) & 0xffffff7f;
+                  *(uint *)(lVar3 + 0x1c4) = *(uint *)(lVar3 + 0x1c4) & 0x388;
+                }
+                if ((((*(uint *)(lVar3 + 0x1a0) & 0x2000) != 0) &&
+                    (((*(byte *)(*(longlong *)(lVar3 + 0x180) + 6) & 4) == 0 ||
+                     (*(int *)(*(longlong *)(lVar3 + 0x180) + 0x4c) == 0)))) ||
+                   (((*(uint *)(lVar3 + 0x1c4) & 0x14) != 0 &&
+                    ((*(byte *)(*(longlong *)(lVar3 + 0x180) + 6) & 4) != 0)))) {
+                  psVar24 = WPP_GLOBAL_Control;
+                  if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                     ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                    psVar24 = *(short **)(WPP_GLOBAL_Control + 0xc);
+                    WPP_SF_(psVar24,0x21,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                  }
+                  *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x10;
+                  *(uint *)(lVar3 + 0x1c4) = *(uint *)(lVar3 + 0x1c4) & 0x388;
+                  UdfTearDownRmwSupport(psVar24,(longlong)psVar18);
+                }
+                if ((*(uint *)(lVar3 + 0x1a0) & 0x1000010) == 0x1000010) {
+                  UdfTransitionSpareTableToRo((longlong)param_1,(longlong)psVar18);
+                }
+                if ((*(byte *)(*(longlong *)(lVar3 + 0x180) + 6) & 2) == 0) {
+                  iVar9 = UdfFindLogicalVolumeIntegrityDescriptor
+                                    ((longlong)param_1,(longlong)psVar18,(uint *)(local_e8 + 0x1b0),
+                                     (longlong *)(lVar3 + 0x700));
+                  if (-1 < iVar9) {
+                    *(undefined4 *)(lVar3 + 0x6e8) =
+                         *(undefined4 *)(*(longlong *)(lVar3 + 0x700) + 0xc);
+                    uVar12 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+                    if ((int)uVar12 == 0) {
+LAB_10:
+                      puVar4 = *(undefined8 **)(lVar3 + 0x700);
+                      puVar1 = (undefined8 *)
+                               ((longlong)puVar4 +
+                               ((ulonglong)(uint)(*(int *)(puVar4 + 9) * 2) + 0x14) * 4);
+                      if ((puVar4 <= puVar1) &&
+                         ((puVar1 <= puVar1 + 6 &&
+                          (puVar1 + 6 <
+                           (undefined8 *)
+                           (((ulonglong)
+                             ((*(int *)(lVar3 + 0x1b4) + 0x1ffU & -*(int *)(lVar3 + 0x1b4)) + 0xfff)
+                            & 0xfffff000) + (longlong)puVar4))))) {
+                        *(undefined4 *)(lVar3 + 0x728) = *(undefined4 *)(puVar1 + 4);
+                        *(undefined4 *)(lVar3 + 0x72c) = *(undefined4 *)((longlong)puVar1 + 0x24);
+                        *(undefined8 *)(lVar3 + 0x730) = puVar4[5];
+                        uVar14 = puVar1[1];
+                        *(undefined8 *)(lVar3 + 0x708) = *puVar1;
+                        *(undefined8 *)(lVar3 + 0x710) = uVar14;
+                        uVar14 = puVar1[3];
+                        *(undefined8 *)(lVar3 + 0x718) = puVar1[2];
+                        *(undefined8 *)(lVar3 + 0x720) = uVar14;
+                        if ((*(int *)((longlong)puVar4 + 0x1c) != 1) &&
+                           ((*(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x30,
+                            (short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control &&
+                            ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)))) {
+                          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x22,
+                                  &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                        }
+                        goto LAB_11;
+                      }
+                    }
+                    else {
+                      uVar8 = *(uint *)(*(longlong *)(lVar3 + 0x700) + 0x4c);
+                      if ((((0x2d < uVar8) &&
+                           (local_78 = (ulonglong)*(uint *)(*(longlong *)(lVar3 + 0x700) + 0x48) <<
+                                       3, local_78 < 0x100000000)) &&
+                          (uVar17 = (int)local_78 + 0x50, 0x4f < uVar17)) &&
+                         ((uVar8 = uVar8 + uVar17, uVar17 <= uVar8 &&
+                          (uVar8 <= ((*(int *)(lVar3 + 0x1b4) + 0x1ffU & -*(int *)(lVar3 + 0x1b4)) +
+                                     0xfff & 0xfffff000))))) goto LAB_10;
+                    }
+                    uVar8 = 0xc0000032;
+                    lVar10 = local_120;
+                    psVar24 = local_118;
+                    goto LAB_8;
+                  }
+                  if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                     ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                    WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x23,
+                            &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                  }
+                  *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x10;
+                }
+LAB_11:
+                UdfUpdateVcbPhase0((undefined8 *)param_1,(longlong)psVar18);
+                uVar8 = UdfFindFileSetDescriptor
+                                  ((longlong)param_1,(longlong)psVar18,(uint *)(local_e8 + 0xf8),
+                                   (ulonglong *)&local_118);
+                psVar24 = local_118;
+                lVar10 = local_120;
+                if (-1 < (int)uVar8) {
+                  if ((*(byte *)(local_118 + 0xdd) & 3) != 0) {
+                    *(uint *)(lVar3 + 0x1a0) = *(uint *)(lVar3 + 0x1a0) | 0x10;
+                  }
+                  UdfCStringToWString((char *)(local_f0 + 0x185),0x17,(undefined2 *)(lVar3 + 0xaa0))
+                  ;
+                  UdfCStringToWString((char *)(psVar24 + 0xa8),0x20,(undefined2 *)(lVar3 + 0xa18));
+                  psVar24 = local_118;
+                  UdfCStringToWString((char *)(local_118 + 0xb8),0x20,(undefined2 *)(lVar3 + 0xa5c))
+                  ;
+                  uVar13 = *(ushort *)(lVar3 + 0x9ca);
+                  *(ushort *)(lVar3 + 0x9e8) = (uVar13 >> 0xc) * 10 + (uVar13 >> 8 & 0xf);
+                  uVar13 = ((uVar13 & 0xff) >> 4) * 10 + (uVar13 & 0xf);
+                  *(ushort *)(lVar3 + 0x9ea) = uVar13;
+                  UdfConvertUdfTimeToNtTime
+                            ((ulonglong)uVar13,(ushort *)(local_f0 + 0x178),
+                             (longlong *)(lVar3 + 0xa08));
+                  UdfUpdateVolumeLabel
+                            ((longlong)param_1,(void *)(*(longlong *)(lVar3 + 0x178) + 0x20),
+                             (wchar_t *)(*(longlong *)(lVar3 + 0x178) + 6),(char *)(psVar24 + 0x38))
+                  ;
+                  lVar2 = *(longlong *)(lVar3 + 0x178);
+                  local_f4 = 0;
+                  local_88 = psVar24;
+                  local_100 = 0;
+                  psVar20 = psVar24;
+                  uVar8 = 0x200;
+                  while( true ) {
+                    uVar17 = uVar8 - 1;
+                    local_b0 = uVar17;
+                    if (uVar8 == 0) break;
+                    *(char *)((longlong)local_fc + ((ulonglong)(uVar17 & 3) - 4)) =
+                         (char)*psVar20 +
+                         *(char *)((longlong)local_fc + ((ulonglong)(uVar17 & 3) - 4));
+                    psVar20 = (short *)((longlong)psVar20 + 1);
+                    local_88 = psVar20;
+                    uVar11 = (ulonglong)local_100;
+                    uVar8 = uVar17;
+                  }
+                  local_f4 = (uint)uVar11;
+                  *(char *)(lVar2 + 0x18) = (char)(uVar11 >> 0x18);
+                  *(char *)(lVar2 + 0x19) = (char)(uVar11 >> 0x10);
+                  psVar15 = (short *)(uVar11 >> 8);
+                  *(char *)(lVar2 + 0x1a) = (char)(uVar11 >> 8);
+                  *(char *)(lVar2 + 0x1b) = (char)uVar11;
+                  psVar21 = psVar24;
+                  local_88 = psVar20;
+                  cVar7 = UdfIsRemount(psVar15,(undefined8 *)psVar18,(longlong *)&local_a8,
+                                       (longlong)psVar24);
+                  psVar20 = local_a8;
+                  psVar18 = (short *)CONCAT71((int7)((ulonglong)psVar18 >> 8),cVar7);
+                  psVar23 = psVar18;
+                  if (extraout_AL != '\0') {
+                    *(short **)(param_1 + 8) = local_a8;
+                    uVar8 = *(uint *)(local_a8 + 0x428);
+                    *(uint *)(local_a8 + 0x428) = uVar8 & 0xffffff2f;
+                    *(uint *)(local_a8 + 0x428) =
+                         (uVar8 ^ *(uint *)(psVar18 + 0x428)) & 0xd0 ^ uVar8;
+                    uVar8 = *(uint *)(local_a8 + 0x18);
+                    psVar15 = (short *)(ulonglong)uVar8;
+                    *(uint *)(local_a8 + 0x18) = uVar8 & 0xffffbf4f;
+                    uVar8 = (uVar8 ^ *(uint *)(psVar18 + 0x18)) & 0x40b0 ^ uVar8;
+                    *(uint *)(local_a8 + 0x18) = uVar8;
+                    if (((uVar8 >> 0xe & 1) == 0) &&
+                       (((byte)*(undefined4 *)(local_a8 + 0x428) & 10) == 2)) {
+                      *(uint *)(local_a8 + 0x18) = uVar8 & 0xffffffcf;
+                    }
+                    psVar23 = psVar20;
+                    if ((*(uint *)(psVar18 + 0x18) >> 0xd & 1) == 0) {
+                      if ((*(uint *)(psVar18 + 0x18) >> 0x15 & 1) != 0) {
+                        if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                           ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x25,
+                                  &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                        }
+                        psVar15 = param_1;
+                        UdfSeqCacheTearDown((longlong)param_1,(longlong)psVar20);
+                        uVar14 = *(undefined8 *)(psVar18 + 0x38);
+                        *(undefined8 *)(psVar20 + 0x34) = *(undefined8 *)(psVar18 + 0x34);
+                        *(undefined8 *)(psVar20 + 0x38) = uVar14;
+                        *(undefined8 *)(psVar20 + 0x3c) = *(undefined8 *)(psVar18 + 0x3c);
+                        *(uint *)(psVar20 + 0x18) = *(uint *)(psVar20 + 0x18) | 0x200000;
+                        *(uint *)(psVar18 + 0x18) = *(uint *)(psVar18 + 0x18) & 0xffdfffff;
+                      }
+                    }
+                    else {
+                      psVar15 = WPP_GLOBAL_Control;
+                      if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                         ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                        psVar15 = *(short **)(WPP_GLOBAL_Control + 0xc);
+                        WPP_SF_(psVar15,0x24,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                      }
+                      UdfTearDownRmwSupport(psVar15,(longlong)psVar20);
+                      *(undefined8 *)(psVar20 + 0x34) = *(undefined8 *)(psVar18 + 0x34);
+                      *(uint *)(psVar20 + 0x18) = *(uint *)(psVar20 + 0x18) | 0x2000;
+                      *(uint *)(psVar18 + 0x18) = *(uint *)(psVar18 + 0x18) & 0xffffdfff;
+                    }
+                  }
+                  if (((*(longlong *)(psVar23 + 0xb0) != 0) ||
+                      ((*(uint *)(psVar23 + 0x18) & 0x20000000) != 0)) &&
+                     ((*(uint *)(psVar23 + 0x18) & 0x4000) == 0)) {
+                    if (*(longlong *)(psVar23 + 0xb0) == 0) {
+                      psVar15 = psVar18;
+                      uVar11 = UdfInitializePowAllocationSupport((longlong)psVar18);
+                      if ((int)uVar11 < 0) {
+                    /* WARNING: Subroutine does not return */
+                        UdfRaiseStatusEx((longlong)param_1,(int)uVar11,'\0');
+                      }
+                    }
+                    else {
+                      psVar15 = psVar23;
+                      iVar9 = UdfQueryFreeBlocksAndNWA
+                                        ((longlong)psVar23,(undefined4 *)(psVar23 + 0x14e),
+                                         (undefined4 *)(psVar23 + 0x156));
+                      if (iVar9 < 0) {
+                    /* WARNING: Subroutine does not return */
+                        UdfRaiseStatusEx((longlong)param_1,iVar9,'\0');
+                      }
+                      psVar24 = local_118;
+                      if (((char)*(undefined4 *)(psVar23 + 0x428) < '\0') &&
+                         (*(uint *)(psVar23 + 0x14e) <= *(uint *)(psVar23 + 0x154))) {
+                        psVar15 = WPP_GLOBAL_Control;
+                        if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                           ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                          psVar15 = *(short **)(WPP_GLOBAL_Control + 0xc);
+                          WPP_SF_(psVar15,0x26,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                        }
+                        *(uint *)(psVar23 + 0x18) = *(uint *)(psVar23 + 0x18) | 0x4010;
+                        *(uint *)(psVar23 + 0x428) = *(uint *)(psVar23 + 0x428) & 0xffffff7f;
+                        *(uint *)(psVar23 + 0x2a) = *(uint *)(psVar23 + 0x2a) & 0x388;
+                        psVar24 = local_118;
+                      }
+                    }
+                    if ((*(uint *)(psVar23 + 0x18) & 0x10) == 0) {
+                      psVar15 = param_1;
+                      UdfSeqCacheInitialize((longlong)param_1,(longlong)psVar23);
+                    }
+                  }
+                  if (extraout_AL == '\0') {
+                    psVar20 = psVar18;
+                    UdfUpdateVcbPhase1(param_1,(longlong)psVar18,(longlong)psVar24);
+                    if ((*(uint *)(psVar18 + 0x18) & 0x10) == 0) {
+                      if ((*(uint *)(psVar18 + 0x428) & 0x10) == 0) {
+                        if (((*(uint *)(psVar18 + 0x18) >> 0x15 & 1) != 0) ||
+                           ((*(uint *)(psVar18 + 0x428) & 0x40) != 0)) {
+                          if ((*(uint *)(psVar18 + 0x2a) & 0x8000000) == 0) {
+                            uVar13 = DAT_0 & 4;
+                          }
+                          else {
+                            uVar13 = DAT_0 & 8;
+                          }
+                          if (uVar13 != 0) goto LAB_12;
+                        }
+                      }
+                      else {
+LAB_12:
+                        psVar20 = (short *)0x0;
+                        psVar21 = DAT_6;
+                        uVar8 = IoRegisterPlugPlayNotification(3);
+                        lVar10 = local_120;
+                        if ((int)uVar8 < 0) goto LAB_8;
+                        *(uint *)(psVar18 + 0x18) = *(uint *)(psVar18 + 0x18) | 0x2000000;
+                        psVar15 = WPP_GLOBAL_Control;
+                        if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                           ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                          psVar20 = (short *)0x28;
+                          psVar15 = *(short **)(WPP_GLOBAL_Control + 0xc);
+                          WPP_SF_(psVar15,0x28,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+                        }
+                        if ((*(uint *)(psVar18 + 0x428) & 0x10) != 0) {
+                          psVar21 = (short *)0x0;
+                          psVar20 = psVar18;
+                          UdfToggleMediaEjectDisable(psVar15,(longlong)psVar18,1,'\0');
+                        }
+                      }
+                    }
+                    if (((*(uint *)(psVar18 + 0x2a) & 0x14) == 0) &&
+                       ((*(uint *)(psVar18 + 0x18) & 0x1000000) != 0)) {
+                      local_dc = local_dc & 0xff;
+                      if (*(uint *)(*(longlong *)(psVar18 + 8) + 0x4c) <=
+                          *(uint *)(*(longlong *)(psVar18 + 8) + 0x24) >> 2) {
+                        local_dc = 1;
+                      }
+                      psVar20 = (short *)(ulonglong)local_dc;
+                    }
+                    lVar10 = *(longlong *)(*(longlong *)(psVar18 + 0x90) + 0x1f8);
+                    ObfReferenceObject(lVar10);
+                    uVar11 = UdfTelemetryGuard();
+                    if ((char)uVar11 != '\0') {
+                      UdfTelemetryMount((ulonglong)(psVar18 + 0x4f4),psVar20,(longlong)psVar18,
+                                        (ulonglong)psVar21);
+                    }
+                    *(int *)(psVar18 + 0x80) = *(int *)(psVar18 + 0x80) - *(int *)(psVar18 + 0x84);
+                    ObfDereferenceObject(*(undefined8 *)(psVar18 + 0xc));
+                    psVar18[0x1a] = 2;
+                    psVar18[0x1b] = 0;
+                    ExReleaseResourceLite(psVar18 + 0x2e4);
+                    local_a0 = (short *)0x0;
+                    uVar8 = 0;
+                    psVar18 = (short *)0x0;
+                  }
+                  else {
+                    UdfReMountOldVcb((ulonglong)psVar15,(longlong)psVar20,(longlong)psVar18,local_80
+                                    );
+                    if (*(longlong *)(psVar20 + 0x94) != 0) {
+                      UdfInitializeAllocationSupport((undefined8 *)param_1,(longlong)psVar20);
+                    }
+                    if ((*(uint *)(psVar20 + 0x18) & 4) != 0) {
+                      *(uint *)(psVar20 + 0x18) = *(uint *)(psVar20 + 0x18) & 0xfffffffb;
+                      local_120 = *(longlong *)(*(longlong *)(psVar20 + 0x90) + 0x1f8);
+                      ObfReferenceObject();
+                    }
+                    if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                       ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+                      WPP_SF_i(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),0x27,
+                               &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,psVar20);
+                    }
+                    uVar8 = 0;
+                    lVar10 = local_120;
+                  }
+                }
+              }
+            }
+          }
+        }
+      }
+      else {
+        if (((short **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+           ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) != 0)) {
+          uVar16 = 0x15;
+LAB_4:
+          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),uVar16,
+                  &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+        }
 LAB_5:
-          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),uVar12,
-                  &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-        }
-LAB_6:
-        local_114 = 0xc000014f;
-        psVar22 = local_e0;
-        goto LAB_4;
-      }
-      local_114 = UdfDetermineVolumeBounding
-                            ((longlong)param_1,local_b0,&local_d8,local_100,&local_b4,local_118);
-      psVar22 = local_e0;
-      if (local_114 == 0xc000014f) goto LAB_4;
-      local_ec = local_d8;
-      cVar4 = UdfRecognizeVolume((undefined8 *)param_1,lVar15,local_58._4_4_,&local_ec,&local_110,
-                                 local_f0);
-      if (cVar4 == '\0') {
-        if ((*(int *)(lVar15 + 0x48) != 2) || (local_118[0] != '\0')) {
-          if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-             ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-            uVar12 = 0x17;
-            goto LAB_5;
-          }
-          goto LAB_6;
-        }
-        if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x16,
-                  &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-        }
-      }
-      if (((local_118[0] != '\0') &&
-          (local_d8 = local_ec, (char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
-         ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-        WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x18,
-                 &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,local_ec);
-      }
-      local_114 = IoCreateDevice(DAT_7,0xa20,0,3);
-      if ((int)local_114 < 0) {
-        psVar22 = local_e0;
-        if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-          WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x19,
-                   &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,local_114);
-          psVar22 = local_e0;
-        }
-        goto LAB_4;
-      }
-      if (*(uint *)(local_108 + 0x98) < *(uint *)(lVar15 + 0x98)) {
-        *(uint *)(local_108 + 0x98) = *(uint *)(lVar15 + 0x98);
-      }
-      *(undefined4 *)(local_108 + 0x154) = 0;
-      lVar8 = local_108 + 0x158;
-      *(longlong *)(local_108 + 0x160) = lVar8;
-      *(longlong *)lVar8 = lVar8;
-      *(undefined4 *)(local_108 + 0x150) = 0;
-      KeInitializeSpinLock(local_108 + 0x168);
-      *(longlong *)(lVar16 + 8) = local_108;
-      UdfInitializeVcb((longlong)param_1,(undefined4 *)(local_108 + 0x170),lVar15,lVar16);
-      lVar8 = local_108;
-      *(char *)(local_108 + 0x4c) = *(char *)(lVar15 + 0x4c) + '\x01';
-      *(undefined2 *)(local_108 + 0x130) = local_58._4_2_;
-      *(uint *)(local_108 + 0x30) = *(uint *)(local_108 + 0x30) & 0xffffff7f;
-      psVar22 = (short *)(local_108 + 0x170);
-      lVar15 = 0;
-      local_78 = 0;
-      local_108 = 0;
-      *(uint *)(lVar8 + 0x264) = local_d8;
-      *(uint *)(lVar8 + 0x268) = local_100[0];
-      *(short **)(param_1 + 8) = psVar22;
-      local_10f = (*(uint *)(param_1 + 0xe) & 4) != 0;
-      local_e0 = psVar22;
-      cVar4 = ExAcquireResourceExclusiveLite(lVar8 + 0x738);
-      if (cVar4 == '\0') {
-        param_1[0xc] = 0xd8;
-        param_1[0xd] = -0x4000;
-                    /* WARNING: Subroutine does not return */
-        ExRaiseStatus(0xc00000d8);
-      }
-      iVar7 = IoVolumeDeviceToGuid(*(undefined8 *)(lVar8 + 0x188),&local_50);
-      if (-1 < iVar7) {
-        _DAT_8 = (undefined4)local_50;
-        uRam0000000140024a20 = local_50._4_4_;
-        uRam0000000140024a24 = (undefined4)uStack_48;
-        uRam0000000140024a28 = uStack_48._4_4_;
-      }
-      uVar11 = *(undefined8 *)(lVar8 + 0x188);
-      iVar7 = FsRtlVolumeDeviceToCorrelationId(uVar11,&local_40);
-      lVar16 = local_b0;
-      if (-1 < iVar7) {
-        *(undefined8 *)(lVar8 + 0xb58) = local_40;
-        *(undefined8 *)(lVar8 + 0xb60) = uStack_38;
-      }
-      UdfDetermineMediaType(uVar11,local_b0,(int *)(lVar8 + 0x1c4));
-      uVar6 = UdfDetermineMediaSupportsStreaming((longlong)param_1,(longlong)psVar22);
-      if ((char)uVar6 != '\0') {
-        *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x40000000;
-      }
-      uVar9 = UdfDetermineMediaWritable((longlong)param_1,(longlong)psVar22,local_b4);
-      if ((char)uVar9 == '\0') {
-        *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x4010;
-        if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-          WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1a,
-                  &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-        }
-      }
-      else {
-        uVar6 = *(uint *)(lVar8 + 0x1c4);
-        if ((uVar6 != 7) && ((uVar6 & 1) != 0)) {
-          iVar7 = 0x10;
-          if ((uVar6 & 8) == 0) {
-            iVar7 = 0x20;
-          }
-          UdfSetVcbEccBlockSize((longlong)psVar22,iVar7);
-        }
-        if (((*(int *)(lVar8 + 0x1c4) - 7U & 0xfffffff7) == 0) &&
-           (bVar3 = UdfIsMediaWriteProtected((longlong)param_1,lVar16), bVar3)) {
-          if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-             ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-            WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1b,
-                    &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-          }
-          *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x90;
-        }
-        if ((*(uint *)(lVar8 + 0x1c4) & 0x12) == 0) {
-          UdfInitRmwSupport((longlong)param_1,(longlong)psVar22);
-        }
-        if ((*(uint *)(lVar8 + 0x1c4) & 0x10) != 0) {
-          *(uint *)(lVar8 + 0x418) = 0x500000 >> ((byte)*(undefined4 *)(lVar8 + 0x1b8) & 0x1f);
-        }
-      }
-      *(short *)(lVar8 + 0x9c8) = local_f0[0];
-      *(int *)(*(longlong *)(lVar8 + 0x178) + 0x1c) =
-           *(int *)(*(longlong *)(lVar8 + 0x178) + 0x1c) + 1;
-      lVar16 = *(longlong *)(*(longlong *)(lVar8 + 0x178) + 0x10);
-      *(uint *)(lVar16 + 0x30) = *(uint *)(lVar16 + 0x30) & 0xfffffffd;
-      if ((*(uint *)(lVar8 + 0x1c4) & 0x10) == 0) {
-        *(uint *)(lVar8 + 0x264) = local_ec;
-      }
-      do {
-        local_114 = UdfFindAnchorVolumeDescriptor
-                              ((longlong)param_1,(longlong)psVar22,(longlong *)&local_a8);
-        pcVar18 = pcVar20;
-        lVar16 = lVar15;
-        if ((int)local_114 < 0) {
-          if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-             ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-            WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1c,
-                     &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,*(undefined4 *)(lVar8 + 0x264)
-                    );
-          }
-          pcVar21 = local_a8;
-          if ((*(int *)(lVar8 + 0x264) == 0) || (local_ec != 0)) goto LAB_4;
-          *(undefined4 *)(lVar8 + 0x264) = 0;
-        }
-        pcVar21 = local_a8;
-      } while ((int)local_114 < 0);
-      *(undefined2 *)(lVar8 + 0x9cc) = *(undefined2 *)(local_a8 + 6);
-      local_114 = UdfFindVolumeDescriptors
-                            ((longlong)param_1,(longlong)psVar22,(uint *)(local_a8 + 0x10),&local_d0
-                             ,&local_c8,&local_c0);
-      if ((int)local_114 < 0) {
-        local_114 = UdfFindVolumeDescriptors
-                              ((longlong)param_1,(longlong)psVar22,(uint *)(pcVar21 + 0x18),
-                               &local_d0,&local_c8,&local_c0);
-      }
-      else if (*(int *)(pcVar21 + 0x18) != 0) {
-        *(int *)(lVar8 + 0x6f4) =
-             (*(int *)(lVar8 + 0x6f0) - *(int *)(pcVar21 + 0x14)) + *(int *)(pcVar21 + 0x1c);
-      }
-      if ((int)local_114 < 0) {
-        lVar16 = 0;
-        if (((char **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
-           (lVar16 = lVar15, (*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) == 0))
-        goto LAB_4;
-        uVar12 = 0x1d;
-      }
-      else {
-        local_114 = UdfCompletePcb((longlong)param_1,(longlong)psVar22,local_d0);
-        if (-1 < (int)local_114) {
-          *(longlong *)(lVar8 + 0x180) = local_d0;
-          local_d0 = 0;
-          if (*(short *)(*(longlong *)(lVar8 + 0x180) + 0x5c) == -1) {
-            if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x1f,
-                      &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-            }
-            *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x4010;
-          }
-          else if ((((*(uint *)(lVar8 + 0x1c4) & 0x10) != 0) &&
-                   ((*(uint *)(lVar8 + 0x1c4) >> 8 & 1) == 0)) &&
-                  (*(short *)(*(longlong *)(lVar8 + 0x180) + 0x5a) == -1)) {
-            if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x20,
-                      &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-            }
-            *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x10;
-            *(uint *)(lVar8 + 0x9c0) = *(uint *)(lVar8 + 0x9c0) & 0xffffff7f;
-            *(uint *)(lVar8 + 0x1c4) = *(uint *)(lVar8 + 0x1c4) & 0x388;
-          }
-          if ((((*(uint *)(lVar8 + 0x1a0) & 0x2000) != 0) &&
-              (((*(byte *)(*(longlong *)(lVar8 + 0x180) + 6) & 4) == 0 ||
-               (*(int *)(*(longlong *)(lVar8 + 0x180) + 0x4c) == 0)))) ||
-             (((*(uint *)(lVar8 + 0x1c4) & 0x14) != 0 &&
-              ((*(byte *)(*(longlong *)(lVar8 + 0x180) + 6) & 4) != 0)))) {
-            pcVar20 = WPP_GLOBAL_Control;
-            if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              pcVar20 = *(char **)(WPP_GLOBAL_Control + 0x18);
-              WPP_SF_(pcVar20,0x21,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-            }
-            *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x10;
-            *(uint *)(lVar8 + 0x1c4) = *(uint *)(lVar8 + 0x1c4) & 0x388;
-            UdfTearDownRmwSupport(pcVar20,(longlong)psVar22);
-          }
-          if ((*(uint *)(lVar8 + 0x1a0) & 0x1000010) == 0x1000010) {
-            UdfTransitionSpareTableToRo((longlong)param_1,(longlong)psVar22);
-          }
-          if ((*(byte *)(*(longlong *)(lVar8 + 0x180) + 6) & 2) == 0) {
-            local_114 = UdfFindLogicalVolumeIntegrityDescriptor
-                                  ((longlong)param_1,(longlong)psVar22,(uint *)(local_c0 + 0x1b0),
-                                   (longlong *)(lVar8 + 0x700));
-            if ((int)local_114 < 0) {
-              if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x23,
-                        &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-              }
-              *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x10;
-            }
-            else {
-              puVar2 = *(undefined8 **)(lVar8 + 0x700);
-              *(undefined4 *)(lVar8 + 0x6e8) = *(undefined4 *)((longlong)puVar2 + 0xc);
-              puVar1 = (undefined8 *)
-                       ((longlong)puVar2 + ((ulonglong)(uint)(*(int *)(puVar2 + 9) * 2) + 0x14) * 4)
-              ;
-              if (((puVar1 < puVar2) || (puVar1 + 6 < puVar1)) ||
-                 ((undefined8 *)
-                  (((ulonglong)
-                    ((*(int *)(lVar8 + 0x1b4) + 0x1ffU & -*(int *)(lVar8 + 0x1b4)) + 0xfff) &
-                   0xfffff000) + (longlong)puVar2) <= puVar1 + 6)) {
-                local_114 = 0xc0000032;
-                goto LAB_4;
-              }
-              *(undefined4 *)(lVar8 + 0x728) = *(undefined4 *)(puVar1 + 4);
-              *(undefined4 *)(lVar8 + 0x72c) = *(undefined4 *)((longlong)puVar1 + 0x24);
-              *(undefined8 *)(lVar8 + 0x730) = puVar2[5];
-              uVar11 = puVar1[1];
-              *(undefined8 *)(lVar8 + 0x708) = *puVar1;
-              *(undefined8 *)(lVar8 + 0x710) = uVar11;
-              uVar11 = puVar1[3];
-              *(undefined8 *)(lVar8 + 0x718) = puVar1[2];
-              *(undefined8 *)(lVar8 + 0x720) = uVar11;
-              if (((*(int *)((longlong)puVar2 + 0x1c) != 1) &&
-                  (*(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x30,
-                  (char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x22,
-                        &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-              }
-            }
-          }
-          UdfUpdateVcbPhase0((undefined8 *)param_1,(ulonglong)psVar22);
-          local_114 = UdfFindFileSetDescriptor
-                                ((longlong)param_1,(longlong)psVar22,(uint *)(local_c0 + 0xf8),
-                                 (ulonglong *)&local_a0);
-          pcVar18 = local_a0;
-          if ((int)local_114 < 0) goto LAB_4;
-          if ((local_a0[0x1ba] & 3U) != 0) {
-            *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x10;
-          }
-          UdfCStringToWString((char *)(local_c8 + 0x185),0x17,(undefined2 *)(lVar8 + 0xaa0));
-          UdfCStringToWString(pcVar18 + 0x150,0x20,(undefined2 *)(lVar8 + 0xa18));
-          UdfCStringToWString(pcVar18 + 0x170,0x20,(undefined2 *)(lVar8 + 0xa5c));
-          uVar10 = *(ushort *)(lVar8 + 0x9ca);
-          *(ushort *)(lVar8 + 0x9e8) = (uVar10 >> 0xc) * 10 + (uVar10 >> 8 & 0xf);
-          uVar10 = ((uVar10 & 0xff) >> 4) * 10 + (uVar10 & 0xf);
-          *(ushort *)(lVar8 + 0x9ea) = uVar10;
-          UdfConvertUdfTimeToNtTime
-                    ((ulonglong)uVar10,(ushort *)(local_c8 + 0x178),(longlong *)(lVar8 + 0xa08));
-          UdfUpdateVolumeLabel
-                    ((longlong)param_1,(void *)(*(longlong *)(lVar8 + 0x178) + 0x20),
-                     (wchar_t *)(*(longlong *)(lVar8 + 0x178) + 6),pcVar18 + 0x70);
-          lVar15 = *(longlong *)(lVar8 + 0x178);
-          local_e8 = (short *)((ulonglong)local_e8 & 0xffffffff00000000);
-          local_70 = pcVar18;
-          local_100[0] = 0;
-          pcVar20 = pcVar18;
-          uVar6 = 0x200;
-          while( true ) {
-            uVar17 = uVar6 - 1;
-            local_98 = uVar17;
-            if (uVar6 == 0) break;
-            *(char *)((longlong)local_100 + (ulonglong)(uVar17 & 3)) =
-                 *pcVar20 + *(char *)((longlong)local_100 + (ulonglong)(uVar17 & 3));
-            pcVar20 = pcVar20 + 1;
-            local_70 = pcVar20;
-            uVar6 = uVar17;
-          }
-          local_e8 = (short *)CONCAT44(local_e8._4_4_,local_100[0]);
-          *(char *)(lVar15 + 0x18) = (char)(local_100[0] >> 0x18);
-          *(char *)(lVar15 + 0x19) = (char)(local_100[0] >> 0x10);
-          *(char *)(lVar15 + 0x1a) = (char)(local_100[0] >> 8);
-          *(char *)(lVar15 + 0x1b) = (char)local_100[0];
-          pcVar19 = pcVar18;
-          local_70 = pcVar20;
-          local_118[0] = UdfIsRemount((ulonglong)(local_100[0] >> 8),(undefined8 *)psVar22,
-                                      (longlong *)&local_f8,(longlong)pcVar18);
-          psVar13 = psVar22;
-          if (local_118[0] != '\0') {
-            *(short **)(param_1 + 8) = local_f8;
-            uVar6 = *(uint *)(local_f8 + 0x428);
-            *(uint *)(local_f8 + 0x428) = uVar6 & 0xffffff2f;
-            *(uint *)(local_f8 + 0x428) = (uVar6 ^ *(uint *)(lVar8 + 0x9c0)) & 0xd0 ^ uVar6;
-            uVar6 = *(uint *)(local_f8 + 0x18);
-            *(uint *)(local_f8 + 0x18) = uVar6 & 0xffffbf4f;
-            uVar6 = (uVar6 ^ *(uint *)(lVar8 + 0x1a0)) & 0x40b0 ^ uVar6;
-            *(uint *)(local_f8 + 0x18) = uVar6;
-            if (((uVar6 >> 0xe & 1) == 0) && (((byte)*(undefined4 *)(local_f8 + 0x428) & 10) == 2))
-            {
-              *(uint *)(local_f8 + 0x18) = uVar6 & 0xffffffcf;
-            }
-            if ((*(uint *)(lVar8 + 0x1a0) >> 0xd & 1) == 0) {
-              psVar13 = local_f8;
-              if ((*(uint *)(lVar8 + 0x1a0) >> 0x15 & 1) == 0) goto LAB_9;
-              if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x25,
-                        &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-              }
-              UdfSeqCacheTearDown((longlong)param_1,(longlong)local_f8);
-              uVar11 = *(undefined8 *)(lVar8 + 0x1e0);
-              *(undefined8 *)(local_f8 + 0x34) = *(undefined8 *)(lVar8 + 0x1d8);
-              *(undefined8 *)(local_f8 + 0x38) = uVar11;
-              *(undefined8 *)(local_f8 + 0x3c) = *(undefined8 *)(lVar8 + 0x1e8);
-              *(uint *)(local_f8 + 0x18) = *(uint *)(local_f8 + 0x18) | 0x200000;
-              uVar6 = *(uint *)(lVar8 + 0x1a0) & 0xffdfffff;
-            }
-            else {
-              pcVar20 = WPP_GLOBAL_Control;
-              if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                pcVar20 = *(char **)(WPP_GLOBAL_Control + 0x18);
-                WPP_SF_(pcVar20,0x24,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-              }
-              UdfTearDownRmwSupport(pcVar20,(longlong)local_f8);
-              *(undefined8 *)(local_f8 + 0x34) = *(undefined8 *)(lVar8 + 0x1d8);
-              *(uint *)(local_f8 + 0x18) = *(uint *)(local_f8 + 0x18) | 0x2000;
-              uVar6 = *(uint *)(lVar8 + 0x1a0) & 0xffffdfff;
-            }
-            *(uint *)(lVar8 + 0x1a0) = uVar6;
-            psVar13 = local_f8;
-          }
-LAB_9:
-          local_e8 = psVar13;
-          if (((*(longlong *)(psVar13 + 0xb0) != 0) ||
-              ((*(uint *)(psVar13 + 0x18) & 0x20000000) != 0)) &&
-             ((*(uint *)(psVar13 + 0x18) & 0x4000) == 0)) {
-            if (*(longlong *)(psVar13 + 0xb0) == 0) {
-              uVar9 = UdfInitializePowAllocationSupport((longlong)psVar22);
-              local_114 = (uint)uVar9;
-              if ((int)local_114 < 0) {
-                    /* WARNING: Subroutine does not return */
-                UdfRaiseStatusEx((longlong)param_1,local_114,'\0');
-              }
-            }
-            else {
-              local_114 = UdfQueryFreeBlocksAndNWA
-                                    ((longlong)psVar13,(undefined4 *)(psVar13 + 0x14e),
-                                     (undefined4 *)(psVar13 + 0x156));
-              if ((int)local_114 < 0) {
-                    /* WARNING: Subroutine does not return */
-                UdfRaiseStatusEx((longlong)param_1,local_114,'\0');
-              }
-              if (((char)*(undefined4 *)(local_e8 + 0x428) < '\0') &&
-                 (*(uint *)(local_e8 + 0x14e) <= *(uint *)(local_e8 + 0x154))) {
-                pcVar19 = WPP_GLOBAL_Control;
-                if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                   ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                  WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x26,
-                          &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-                }
-                *(uint *)(local_e8 + 0x18) = *(uint *)(local_e8 + 0x18) | 0x4010;
-                *(uint *)(local_e8 + 0x428) = *(uint *)(local_e8 + 0x428) & 0xffffff7f;
-                *(uint *)(local_e8 + 0x2a) = *(uint *)(local_e8 + 0x2a) & 0x388;
-              }
-            }
-            psVar13 = local_e8;
-            if ((*(uint *)(local_e8 + 0x18) & 0x10) == 0) {
-              psVar13 = param_1;
-              UdfSeqCacheInitialize((longlong)param_1,(longlong)local_e8);
-            }
-          }
-          if (local_118[0] != '\0') {
-            UdfReMountOldVcb((ulonglong)psVar13,(longlong)local_f8,(longlong)psVar22,local_b0);
-            if (*(longlong *)(local_f8 + 0x94) != 0) {
-              UdfInitializeAllocationSupport((undefined8 *)param_1,(longlong)local_f8);
-            }
-            if ((*(uint *)(local_f8 + 0x18) & 4) != 0) {
-              *(uint *)(local_f8 + 0x18) = *(uint *)(local_f8 + 0x18) & 0xfffffffb;
-              local_90 = *(longlong *)(*(longlong *)(local_f8 + 0x90) + 0x1f8);
-              ObfReferenceObject();
-            }
-            if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-              WPP_SF_i(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x27,
-                       &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,local_f8);
-            }
-            local_114 = 0;
-            goto LAB_4;
-          }
-          UdfUpdateVcbPhase1(param_1,(longlong)psVar22,(longlong)pcVar18);
-          uVar6 = *(uint *)(lVar8 + 0x1a0);
-          psVar13 = (short *)(ulonglong)uVar6;
-          if ((uVar6 & 0x10) == 0) {
-            if ((*(uint *)(lVar8 + 0x9c0) & 0x10) == 0) {
-              if ((uVar6 >> 0x15 & 1) != 0 || (*(uint *)(lVar8 + 0x9c0) & 0x40) != 0) {
-                if ((*(uint *)(lVar8 + 0x1c4) & 0x8000000) == 0) {
-                  uVar10 = DAT_0 & 4;
-                }
-                else {
-                  uVar10 = DAT_0 & 8;
-                }
-                if (uVar10 != 0) goto LAB_10;
-              }
-            }
-            else {
-LAB_10:
-              psVar13 = (short *)0x0;
-              pcVar19 = DAT_7;
-              local_114 = IoRegisterPlugPlayNotification
-                                    (3,0,*(undefined8 *)(*(longlong *)(lVar8 + 0x290) + 0x1f8));
-              if ((int)local_114 < 0) goto LAB_4;
-              *(uint *)(lVar8 + 0x1a0) = *(uint *)(lVar8 + 0x1a0) | 0x2000000;
-              pcVar20 = WPP_GLOBAL_Control;
-              if (((char **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-                 ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) != 0)) {
-                psVar13 = (short *)0x28;
-                pcVar20 = *(char **)(WPP_GLOBAL_Control + 0x18);
-                WPP_SF_(pcVar20,0x28,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-              }
-              if ((*(uint *)(lVar8 + 0x9c0) & 0x10) != 0) {
-                pcVar19 = (char *)0x0;
-                psVar13 = psVar22;
-                UdfToggleMediaEjectDisable(pcVar20,(longlong)psVar22,1,'\0');
-              }
-            }
-          }
-          if (((*(uint *)(lVar8 + 0x1c4) & 0x14) == 0) &&
-             ((*(uint *)(lVar8 + 0x1a0) & 0x1000000) != 0)) {
-            local_d4 = local_d4 & 0xff;
-            if (*(uint *)(*(longlong *)(lVar8 + 0x180) + 0x4c) <=
-                *(uint *)(*(longlong *)(lVar8 + 0x180) + 0x24) >> 2) {
-              local_d4 = 1;
-            }
-            psVar13 = (short *)(ulonglong)local_d4;
-          }
-          local_90 = *(longlong *)(*(longlong *)(lVar8 + 0x290) + 0x1f8);
-          ObfReferenceObject();
-          uVar9 = UdfTelemetryGuard();
-          if ((char)uVar9 != '\0') {
-            UdfTelemetryMount(lVar8 + 0xb58,psVar13,(longlong)psVar22,(ulonglong)pcVar19);
-          }
-          *(int *)(lVar8 + 0x270) = *(int *)(lVar8 + 0x270) - *(int *)(lVar8 + 0x278);
-          ObfDereferenceObject(*(undefined8 *)(lVar8 + 0x188));
-          *(undefined4 *)(lVar8 + 0x1a4) = 2;
-          ExReleaseResourceLite(lVar8 + 0x738);
-          local_e0 = (short *)0x0;
-          local_114 = 0;
-          psVar22 = (short *)0x0;
-          goto LAB_4;
-        }
-        if (((char **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
-           ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) == 0)) goto LAB_4;
-        uVar12 = 0x1e;
-      }
-      WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),uVar12,
-               &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,local_114);
-      lVar16 = lVar15;
-LAB_4:
-      if ((local_114 != 0) && (bVar14 != 0)) {
+        uVar8 = 0xc000014f;
+        psVar18 = psVar20;
+        lVar10 = local_120;
+        psVar22 = psVar20;
+        psVar24 = psVar20;
+      }
+LAB_8:
+      lVar2 = local_c8;
+      if ((uVar8 != 0) && (local_123 != 0)) {
         *(uint *)(*(longlong *)(param_1 + 0x10) + 0x30) =
              *(uint *)(*(longlong *)(param_1 + 0x10) + 0x30) | 2;
       }
-      if (lVar16 != 0) {
-        *(undefined8 *)(lVar16 + 8) = 0;
-      }
-      if (local_d0 != 0) {
-        UdfDeletePcb(local_d0);
-      }
-      if (psVar22 == (short *)0x0) {
+      if (local_c8 != 0) {
+        *(undefined8 *)(local_c8 + 8) = 0;
+      }
+      if (local_d8 != 0) {
+        UdfDeletePcb(local_d8);
+      }
+      if (psVar18 == (short *)0x0) {
         if (local_108 != 0) {
           IoDeleteDevice();
-          *(undefined8 *)(lVar16 + 8) = 0;
+          *(undefined8 *)(lVar2 + 8) = 0;
         }
       }
       else {
         param_1[8] = 0;
         param_1[9] = 0;
         param_1[10] = 0;
         param_1[0xb] = 0;
-        *(int *)(psVar22 + 0x80) = *(int *)(psVar22 + 0x80) - *(int *)(psVar22 + 0x84);
-        cVar4 = UdfDismountVcb((longlong)param_1,psVar22,'\0');
-        if (cVar4 != '\0') {
-          ExReleaseResourceLite(psVar22 + 0x2e4);
+        *(int *)(psVar18 + 0x80) = *(int *)(psVar18 + 0x80) - *(int *)(psVar18 + 0x84);
+        cVar7 = UdfDismountVcb((longlong)param_1,psVar18,'\0');
+        if (cVar7 != '\0') {
+          ExReleaseResourceLite(psVar18 + 0x2e4);
         }
       }
       ExReleaseResourceLite(&DAT_3);
-      if (pcVar21 != (char *)0x0) {
-        ExFreePoolWithTag(pcVar21,0);
-      }
-      if (local_c8 != 0) {
-        ExFreePoolWithTag(local_c8,0);
-        local_c8 = 0;
-      }
-      if (local_c0 != 0) {
-        ExFreePoolWithTag(local_c0,0);
-        local_c0 = 0;
-      }
-      if (pcVar18 != (char *)0x0) {
-        ExFreePoolWithTag(pcVar18,0);
-      }
-      lVar15 = local_90;
-      if (local_90 != 0) {
-        FsRtlNotifyVolumeEvent(local_90,6);
-        if ((char)local_d4 != '\0') {
-          FsRtlNotifyVolumeEvent(lVar15,9);
+      if (psVar22 != (short *)0x0) {
+        ExFreePoolWithTag(psVar22,0);
+      }
+      if (local_f0 != 0) {
+        ExFreePoolWithTag(local_f0,0);
+        local_f0 = 0;
+      }
+      if (local_e8 != 0) {
+        ExFreePoolWithTag(local_e8,0);
+        local_e8 = 0;
+      }
+      if (psVar24 != (short *)0x0) {
+        ExFreePoolWithTag(psVar24,0);
+      }
+      if (lVar10 != 0) {
+        FsRtlNotifyVolumeEvent(lVar10,6);
+        if ((char)local_dc != '\0') {
+          FsRtlNotifyVolumeEvent(lVar10,9);
         }
-        ObfDereferenceObject(lVar15);
-      }
-      uVar6 = local_114;
-      UdfCompleteRequest((longlong)param_1,param_2,local_114);
-      if ((char **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-        return uVar6;
-      }
-      if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) == 0) {
-        return uVar6;
-      }
-      WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),0x29,
-               &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,uVar6);
-      return uVar6;
+        ObfDereferenceObject(lVar10);
+      }
+      UdfCompleteRequest((longlong)param_1,local_c0,uVar8);
+      if ((short **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
+        return uVar8;
+      }
+      if ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) == 0) {
+        return uVar8;
+      }
+      uVar16 = 0x29;
+      goto LAB_2;
     }
   }
-  UdfCompleteRequest((longlong)param_1,param_2,uVar6);
-  if ((char **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
-    return uVar6;
+  UdfCompleteRequest((longlong)param_1,local_c0,uVar8);
+  if ((short **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) {
+    return uVar8;
   }
-  if ((*(uint *)(WPP_GLOBAL_Control + 0x2c) & 0x800) == 0) {
-    return uVar6;
+  if ((*(uint *)(WPP_GLOBAL_Control + 0x16) & 0x800) == 0) {
+    return uVar8;
   }
-  uVar12 = 0x13;
+  uVar16 = 0x13;
 LAB_2:
-  WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x18),uVar12,
-           &WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,uVar6);
-  return uVar6;
+  WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0xc),uVar16,
+           &WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,uVar8);
+  return uVar8;
 }
 

```


## UdfVerifyVolume

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.28|
|i_ratio|0.52|
|m_ratio|1.0|
|b_ratio|0.47|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfVerifyVolume|UdfVerifyVolume|
|fullname|UdfVerifyVolume|UdfVerifyVolume|
|refcount|2|2|
|`length`|2212|2203|
|`called`|<details><summary>Expand for full list:<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::RtlCompareMemory<br>UdfAcquireResource<br>UdfCompletePcb<br>UdfCompleteRequest<br>UdfDeletePcb<br>UdfEquivalentPcb<br>UdfFindAnchorVolumeDescriptor<br>UdfFindFileSetDescriptor</summary>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfFlushVolume<br>UdfFspClose<br>UdfIsMediaWriteProtected<br>UdfKillCleanVolumeTimer<br>UdfMarkAllScbsForVerify<br>UdfPerformDevIoCtrl<br>UdfPrepareDeviceForWrite<br>UdfResetVmcb<br>UdfSeqCacheSyncCache<br>UdfSeqCacheTearDown<br>UdfTearDownAllocationSupport<br>UdfTearDownRmwSupport<br>UdfToggleMediaEjectDisable<br>UdfUpdateVolumeLabel<br>UdfUpdateVolumeSerialNumber<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_i<br>__security_check_cookie<br>memcmp</details>|<details><summary>Expand for full list:<br>Feature_2661530937__private_IsEnabledDeviceUsageNoInline<br>NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExReleaseResourceLite<br>NTOSKRNL.EXE::RtlCompareMemory<br>UdfAcquireResource<br>UdfCompletePcb<br>UdfCompleteRequest<br>UdfDeletePcb<br>UdfEquivalentPcb<br>UdfFindAnchorVolumeDescriptor<br>UdfFindFileSetDescriptor</summary>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfFlushVolume<br>UdfFreePool<br>UdfFspClose<br>UdfIsMediaWriteProtected<br>UdfKillCleanVolumeTimer<br>UdfMarkAllScbsForVerify<br>UdfPerformDevIoCtrl<br>UdfPrepareDeviceForWrite<br>UdfResetVmcb<br>UdfSeqCacheSyncCache<br>UdfSeqCacheTearDown<br>UdfTearDownAllocationSupport<br>UdfTearDownRmwSupport<br>UdfToggleMediaEjectDisable<br>UdfUpdateVolumeLabel<br>UdfUpdateVolumeSerialNumber<br>WPP_SF_<br>WPP_SF_D<br>WPP_SF_i<br>__security_check_cookie<br>memcmp</details>|
|calling|UdfCommonFsControl|UdfCommonFsControl|
|paramcount|2|2|
|`address`|140004814|140009560|
|`sig`|uint __fastcall UdfVerifyVolume(ulonglong * param_1, longlong param_2)|void * __fastcall UdfVerifyVolume(ulonglong * param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfVerifyVolume Called Diff


```diff
--- UdfVerifyVolume called
+++ UdfVerifyVolume called
@@ -0,0 +1 @@
+Feature_2661530937__private_IsEnabledDeviceUsageNoInline
@@ -2 +2,0 @@
-NTOSKRNL.EXE::ExFreePoolWithTag
@@ -14,0 +15 @@
+UdfFreePool
```


### UdfVerifyVolume Diff


```diff
--- UdfVerifyVolume
+++ UdfVerifyVolume
@@ -1,297 +1,299 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
-uint UdfVerifyVolume(ulonglong *param_1,longlong param_2)
+void * UdfVerifyVolume(ulonglong *param_1,longlong param_2)
 
 {
-  uint uVar1;
+  longlong lVar1;
   longlong lVar2;
-  longlong lVar3;
   void *_Buf1;
-  longlong lVar4;
-  uint uVar5;
-  int iVar6;
-  ulonglong uVar7;
-  undefined8 uVar8;
-  uint uVar9;
-  ulonglong *puVar10;
-  undefined2 uVar11;
-  undefined4 uVar12;
-  ulonglong uVar13;
-  ulonglong *puVar14;
-  char *pcVar15;
-  bool bVar16;
+  char *pcVar3;
+  uint uVar4;
+  int iVar5;
+  ulonglong uVar6;
+  undefined8 uVar7;
+  uint uVar8;
+  ulonglong *puVar9;
+  undefined2 uVar10;
+  undefined4 uVar11;
+  void *_Buf2;
+  ulonglong uVar12;
+  ulonglong *puVar13;
+  void *pvVar14;
+  bool bVar15;
   undefined1 auStackY_148 [32];
   undefined8 in_stack_fffffffffffffef0;
   wchar_t local_f0 [2];
   int local_ec;
-  longlong local_e8;
+  void *local_e8;
   int local_e0 [2];
   longlong local_d8;
-  char *local_d0;
+  longlong local_d0;
   longlong local_c8;
-  longlong local_c0;
-  void *local_b8;
+  char *local_c0;
+  longlong local_b8;
   longlong local_b0;
   ulonglong *local_a8;
   longlong local_a0;
   ulonglong *local_98;
-  undefined8 local_90;
+  ulonglong local_90;
   longlong lStack_88;
   undefined1 local_78 [64];
   ulonglong local_38;
   
   local_38 = __security_cookie ^ (ulonglong)auStackY_148;
-  lVar2 = *(longlong *)(param_2 + 0xb8);
-  local_b0 = *(longlong *)(lVar2 + 8);
-  lVar3 = *(longlong *)(lVar2 + 0x10);
-  puVar14 = (ulonglong *)(lVar3 + 0x170);
-  uVar5 = 0;
+  lVar1 = *(longlong *)(param_2 + 0xb8);
+  local_b0 = *(longlong *)(lVar1 + 8);
+  lVar2 = *(longlong *)(lVar1 + 0x10);
+  puVar13 = (ulonglong *)(lVar2 + 0x170);
+  _Buf2 = (void *)0x0;
   local_d8 = 0;
+  local_d0 = 0;
+  local_b8 = 0;
   local_c8 = 0;
-  local_c0 = 0;
-  local_e8 = 0;
-  local_b8 = (void *)0x0;
-  local_d0 = (char *)0x0;
-  local_ec = *(int *)(lVar3 + 0x1b0);
+  local_e8 = (void *)0x0;
+  local_c0 = (char *)0x0;
+  local_ec = *(int *)(lVar2 + 0x1b0);
   local_90 = 0;
   lStack_88 = 0;
   local_f0[0] = L'\0';
   local_e0[0] = 0;
   param_1[4] = *(ulonglong *)(local_b0 + 0x10);
   *(uint *)((longlong)param_1 + 0x1c) = *(uint *)((longlong)param_1 + 0x1c) | 0x2000;
-  local_a8 = puVar14;
+  local_a8 = puVar13;
   local_a0 = param_2;
   local_98 = param_1;
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-    WPP_SF_i(WPP_GLOBAL_Control[3],0x2a,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,puVar14);
+    WPP_SF_i(WPP_GLOBAL_Control[3],0x2a,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,puVar13);
   }
   ExAcquireResourceExclusiveLite(&DAT_0,1);
-  UdfAcquireResource((longlong)param_1,lVar3 + 0x738,'\0',0);
-  if ((UdfNoRemounts != '\0') || (*(int *)(lVar3 + 0x1a4) - 3U < 2)) goto LAB_1;
-  if ((*(uint *)(*(longlong *)(*(longlong *)(lVar3 + 0x178) + 0x10) + 0x30) & 2) == 0) {
-    uVar5 = 0;
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       (uVar5 = 0, (*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-      WPP_SF_(WPP_GLOBAL_Control[3],0x2b,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-    }
-    goto LAB_2;
-  }
-  puVar10 = *(ulonglong **)(local_b0 + 0x10);
-  if ((*(uint *)((longlong)puVar10 + 0x34) & 1) == 0) {
-LAB_3:
+  UdfAcquireResource((longlong)param_1,lVar2 + 0x738,'\0',0);
+  if ((UdfNoRemounts == '\0') && (1 < *(int *)(lVar2 + 0x1a4) - 3U)) {
+    pvVar14 = _Buf2;
+    if ((*(uint *)(*(longlong *)(*(longlong *)(lVar2 + 0x178) + 0x10) + 0x30) & 2) == 0) {
+      if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+         (pvVar14 = (void *)0x0, (*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0))
+      {
+        WPP_SF_(WPP_GLOBAL_Control[3],0x2b,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+      }
+      goto LAB_1;
+    }
+    puVar9 = *(ulonglong **)(local_b0 + 0x10);
+    if ((*(uint *)((longlong)puVar9 + 0x34) & 1) != 0) {
+      uVar11 = 0x24800;
+      if ((int)puVar9[9] != 2) {
+        uVar11 = 0x74800;
+      }
+      uVar4 = UdfPerformDevIoCtrl(puVar9,uVar11,*(undefined8 *)(lVar2 + 0x188),(void *)0x0,0,
+                                  &local_ec,4,in_stack_fffffffffffffef0,'\x01',
+                                  (undefined4 *)&local_90);
+      pvVar14 = (void *)(ulonglong)uVar4;
+      if (-1 < (int)uVar4) goto LAB_2;
+      if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+         ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
+        WPP_SF_(WPP_GLOBAL_Control[3],0x2c,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+      }
+      if ((*(byte *)(lVar1 + 2) & 1) == 0) goto LAB_1;
+      if (((undefined8 **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
+         ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) == 0)) goto LAB_3;
+      uVar10 = 0x2d;
+      goto LAB_4;
+    }
+LAB_2:
     if (lStack_88 != 4) {
       local_ec = 0;
     }
-    uVar1 = *(uint *)(lVar3 + 0x1a0);
-    if (((uVar1 >> 0xe & 1) == 0) && ((uVar1 & 0x200000) != 0)) {
-      uVar9 = *(uint *)(*(longlong *)(lVar3 + 0x1d8) + 4) & 2;
-      puVar10 = (ulonglong *)(ulonglong)uVar9;
-      if ((uVar1 >> 0x1d & 1) == 0) {
-        bVar16 = uVar9 != 0;
+    uVar4 = *(uint *)(lVar2 + 0x1a0);
+    if (((uVar4 >> 0xe & 1) == 0) && ((uVar4 & 0x200000) != 0)) {
+      uVar8 = *(uint *)(*(longlong *)(lVar2 + 0x1d8) + 4) & 2;
+      puVar9 = (ulonglong *)(ulonglong)uVar8;
+      if ((uVar4 >> 0x1d & 1) == 0) {
+        bVar15 = uVar8 != 0;
       }
       else {
-        if (uVar9 != 0) goto LAB_4;
-        bVar16 = false;
-      }
-      if ((!bVar16) &&
-         (puVar10 = puVar14, uVar5 = UdfSeqCacheSyncCache((longlong)puVar14), (int)uVar5 < 0))
-      goto LAB_1;
-    }
-LAB_4:
-    if ((local_ec == 0) ||
-       ((*(int *)(lVar3 + 0x1b0) != local_ec || ((*(uint *)(lVar3 + 0x1a0) & 2) == 0)))) {
-      if (((*(uint *)(lVar3 + 0x9c0) & 2) == 0) && (*(int *)(lVar3 + 0x950) == 0))
-      goto LAB_1;
-      iVar6 = UdfFindAnchorVolumeDescriptor((longlong)param_1,(longlong)puVar14,&local_c8);
-      lVar2 = local_c8;
-      if (iVar6 < 0) {
-        if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-           ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-          uVar11 = 0x2e;
+        if (uVar8 != 0) goto LAB_5;
+        bVar15 = false;
+      }
+      if (!bVar15) {
+        puVar9 = puVar13;
+        uVar4 = UdfSeqCacheSyncCache((longlong)puVar13);
+        pvVar14 = (void *)(ulonglong)uVar4;
+        if ((int)uVar4 < 0) goto LAB_3;
+      }
+    }
 LAB_5:
-          WPP_SF_(WPP_GLOBAL_Control[3],uVar11,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-        }
-      }
-      else {
-        iVar6 = UdfFindVolumeDescriptors
-                          ((longlong)param_1,(longlong)puVar14,(uint *)(local_c8 + 0x10),&local_d8,
-                           &local_c0,&local_e8);
-        if (iVar6 < 0) {
+    if (((local_ec == 0) || (*(int *)(lVar2 + 0x1b0) != local_ec)) ||
+       ((*(uint *)(lVar2 + 0x1a0) & 2) == 0)) {
+      if (((*(uint *)(lVar2 + 0x9c0) & 2) != 0) || (*(int *)(lVar2 + 0x950) != 0)) {
+        iVar5 = UdfFindAnchorVolumeDescriptor((longlong)param_1,(longlong)puVar13,&local_d0);
+        if (iVar5 < 0) {
           if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
              ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-            uVar11 = 0x2f;
-            goto LAB_5;
+            uVar10 = 0x2e;
+LAB_4:
+            WPP_SF_(WPP_GLOBAL_Control[3],uVar10,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
           }
         }
         else {
-          puVar10 = param_1;
-          uVar5 = UdfCompletePcb((longlong)param_1,(longlong)puVar14,local_d8);
-          if ((int)uVar5 < 0) {
+          iVar5 = UdfFindVolumeDescriptors
+                            ((longlong)param_1,(longlong)puVar13,(uint *)(local_d0 + 0x10),&local_d8
+                             ,&local_b8,&local_c8);
+          if (iVar5 < 0) {
             if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
                ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-              uVar11 = 0x30;
-              goto LAB_5;
+              uVar10 = 0x2f;
+              goto LAB_4;
             }
           }
           else {
-            uVar7 = UdfEquivalentPcb(puVar10,local_d8,*(longlong *)(lVar3 + 0x180));
-            if ((char)uVar7 != '\0') {
-              if (((*(int *)(lVar3 + 0x1c4) - 7U & 0xfffffff7) != 0) ||
-                 (bVar16 = UdfIsMediaWriteProtected
-                                     ((longlong)param_1,*(undefined8 *)(lVar3 + 0x188)), !bVar16)) {
+            puVar9 = param_1;
+            uVar4 = UdfCompletePcb((longlong)param_1,(longlong)puVar13,local_d8);
+            if ((int)uVar4 < 0) {
+              if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                 ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
+                uVar10 = 0x30;
+                goto LAB_4;
+              }
+            }
+            else {
+              uVar6 = UdfEquivalentPcb(puVar9,local_d8,*(longlong *)(lVar2 + 0x180));
+              if ((char)uVar6 == '\0') {
+                if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+                   ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
+                  uVar10 = 0x31;
+                  goto LAB_4;
+                }
+              }
+              else if (((*(int *)(lVar2 + 0x1c4) - 7U & 0xfffffff7) != 0) ||
+                      (bVar15 = UdfIsMediaWriteProtected
+                                          ((longlong)param_1,*(undefined8 *)(lVar2 + 0x188)),
+                      !bVar15)) {
                 UdfDeletePcb(local_d8);
                 local_d8 = 0;
-                if ((*(byte *)(*(longlong *)(lVar3 + 0x180) + 6) & 2) == 0) {
+                if ((*(byte *)(*(longlong *)(lVar2 + 0x180) + 6) & 2) == 0) {
                   UdfFindLogicalVolumeIntegrityDescriptor
-                            ((longlong)param_1,(longlong)puVar14,(uint *)(local_e8 + 0x1b0),
-                             (longlong *)&local_b8);
+                            ((longlong)param_1,(longlong)puVar13,(uint *)(local_c8 + 0x1b0),
+                             (longlong *)&local_e8);
+                  uVar6 = Feature_2661530937__private_IsEnabledDeviceUsageNoInline();
+                  _Buf2 = local_e8;
+                  if (((int)uVar6 != 0) && (local_e8 != (void *)0x0)) {
+                    local_90 = (ulonglong)*(uint *)((longlong)local_e8 + 0x48) << 3;
+                    if ((0xffffffff < local_90) ||
+                       (((uVar4 = (int)local_90 + 0x50, uVar4 < 0x50 ||
+                         (uVar8 = *(int *)((longlong)local_e8 + 0x4c) + uVar4, uVar8 < uVar4)) ||
+                        (((*(int *)(lVar2 + 0x1b4) + 0x1ffU & -*(int *)(lVar2 + 0x1b4)) + 0xfff &
+                         0xfffff000) < uVar8)))) {
+                      UdfFreePool((longlong *)&local_e8);
+                      _Buf2 = local_e8;
+                    }
+                  }
                 }
-                uVar5 = UdfFindFileSetDescriptor
-                                  ((longlong)param_1,(longlong)puVar14,(uint *)(local_e8 + 0xf8),
-                                   (ulonglong *)&local_d0);
-                if (-1 < (int)uVar5) {
-                  puVar10 = param_1;
-                  UdfUpdateVolumeLabel((longlong)param_1,local_78,local_f0,local_d0 + 0x70);
-                  pcVar15 = local_d0;
-                  UdfUpdateVolumeSerialNumber((ulonglong)puVar10,(undefined1 *)local_e0,local_d0);
-                  if (((((*(int *)(*(longlong *)(lVar3 + 0x290) + 0xb8) == *(int *)(pcVar15 + 0x194)
-                         ) && (_Buf1 = *(void **)(lVar3 + 0x700),
-                              (_Buf1 == (void *)0x0) == (local_b8 == (void *)0x0))) &&
-                       ((local_b8 == (void *)0x0 ||
-                        ((*(int *)((longlong)_Buf1 + 0x48) == *(int *)((longlong)local_b8 + 0x48) &&
-                         (iVar6 = memcmp(_Buf1,local_b8,
-                                         (ulonglong)*(uint *)((longlong)local_b8 + 0x4c) + 0x50 +
-                                         (ulonglong)(uint)(*(int *)((longlong)local_b8 + 0x48) * 2)
-                                         * 4), iVar6 == 0)))))) &&
-                      (lVar4 = *(longlong *)(lVar3 + 0x178), *(int *)(lVar4 + 0x18) == local_e0[0]))
-                     && ((*(wchar_t *)(lVar4 + 6) == local_f0[0] &&
-                         (*(short *)(lVar3 + 0x9cc) == *(short *)(lVar2 + 6))))) {
-                    uVar13 = (ulonglong)(ushort)local_f0[0];
-                    puVar10 = (ulonglong *)(lVar4 + 0x20);
-                    uVar7 = RtlCompareMemory(puVar10,local_78);
-                    if (uVar13 == uVar7) goto LAB_6;
+                uVar4 = UdfFindFileSetDescriptor
+                                  ((longlong)param_1,(longlong)puVar13,(uint *)(local_c8 + 0xf8),
+                                   (ulonglong *)&local_c0);
+                pcVar3 = local_c0;
+                pvVar14 = (void *)(ulonglong)uVar4;
+                if (-1 < (int)uVar4) {
+                  puVar9 = param_1;
+                  UdfUpdateVolumeLabel((longlong)param_1,local_78,local_f0,local_c0 + 0x70);
+                  UdfUpdateVolumeSerialNumber((ulonglong)puVar9,(undefined1 *)local_e0,pcVar3);
+                  if (((((*(int *)(*(longlong *)(lVar2 + 0x290) + 0xb8) == *(int *)(pcVar3 + 0x194))
+                        && (_Buf1 = *(void **)(lVar2 + 0x700),
+                           (_Buf1 == (void *)0x0) == (_Buf2 == (void *)0x0))) &&
+                       ((_Buf2 == (void *)0x0 ||
+                        ((*(int *)((longlong)_Buf1 + 0x48) == *(int *)((longlong)_Buf2 + 0x48) &&
+                         (iVar5 = memcmp(_Buf1,_Buf2,
+                                         (ulonglong)*(uint *)((longlong)_Buf2 + 0x4c) +
+                                         ((ulonglong)(uint)(*(int *)((longlong)_Buf2 + 0x48) * 2) +
+                                         0x14) * 4), iVar5 == 0)))))) &&
+                      (lVar1 = *(longlong *)(lVar2 + 0x178), *(int *)(lVar1 + 0x18) == local_e0[0]))
+                     && ((*(wchar_t *)(lVar1 + 6) == local_f0[0] &&
+                         (*(short *)(lVar2 + 0x9cc) == *(short *)(local_d0 + 6))))) {
+                    uVar12 = (ulonglong)(ushort)local_f0[0];
+                    puVar9 = (ulonglong *)(lVar1 + 0x20);
+                    uVar6 = RtlCompareMemory(puVar9,local_78);
+                    if (uVar12 == uVar6) goto LAB_6;
                   }
                   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
                      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-                    uVar11 = 0x32;
-                    goto LAB_5;
+                    uVar10 = 0x32;
+                    goto LAB_4;
                   }
-                  goto LAB_7;
                 }
               }
-LAB_1:
-              uVar5 = 0xc0000012;
-              goto LAB_2;
-            }
-            if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-               ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-              uVar11 = 0x31;
-              goto LAB_5;
             }
           }
         }
       }
     }
     else {
 LAB_6:
-      if (*(int *)(lVar3 + 0x1a4) != 2) goto LAB_2;
-      if (((*(uint *)(lVar3 + 0x1a0) & 0x4000) != 0) ||
-         (uVar8 = UdfPrepareDeviceForWrite(puVar10,param_1[4],*(uint *)(lVar3 + 0x1c4),'\x01'),
-         (char)uVar8 != '\0')) {
+      if (*(int *)(lVar2 + 0x1a4) != 2) goto LAB_1;
+      if (((*(uint *)(lVar2 + 0x1a0) & 0x4000) != 0) ||
+         (uVar7 = UdfPrepareDeviceForWrite(puVar9,param_1[4],*(uint *)(lVar2 + 0x1c4),'\x01'),
+         (char)uVar7 != '\0')) {
         if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
            ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-          WPP_SF_(WPP_GLOBAL_Control[3],0x34,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
+          WPP_SF_(WPP_GLOBAL_Control[3],0x34,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
         }
-        *(undefined4 *)(lVar3 + 0x1a4) = 2;
+        *(undefined4 *)(lVar2 + 0x1a4) = 2;
         *(uint *)(*(longlong *)(local_b0 + 0x10) + 0x30) =
              *(uint *)(*(longlong *)(local_b0 + 0x10) + 0x30) & 0xfffffffd;
-        uVar5 = 0;
-        goto LAB_2;
+        pvVar14 = (void *)0x0;
+        goto LAB_1;
       }
       if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
          ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-        uVar11 = 0x33;
-        goto LAB_5;
-      }
-    }
-  }
-  else {
-    uVar12 = 0x24800;
-    if ((int)puVar10[9] != 2) {
-      uVar12 = 0x74800;
-    }
-    uVar5 = UdfPerformDevIoCtrl(puVar10,uVar12,*(undefined8 *)(lVar3 + 0x188),(void *)0x0,0,
-                                &local_ec,4,in_stack_fffffffffffffef0,'\x01',(undefined4 *)&local_90
-                               );
-    if (-1 < (int)uVar5) goto LAB_3;
+        uVar10 = 0x33;
+        goto LAB_4;
+      }
+    }
+  }
+LAB_3:
+  pvVar14 = (void *)0xc0000012;
+LAB_1:
+  *(int *)(lVar2 + 0x1b0) = local_ec;
+  if (*(int *)(lVar2 + 0x1a4) == 0) {
+    pvVar14 = (void *)0xc0000012;
+  }
+  else if ((*(int *)(lVar2 + 0x1a4) == 2) && ((int)pvVar14 == -0x3fffffee)) {
     if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
        ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-      WPP_SF_(WPP_GLOBAL_Control[3],0x2c,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-    }
-    if ((*(byte *)(lVar2 + 2) & 1) == 0) goto LAB_2;
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-      uVar11 = 0x2d;
-      goto LAB_5;
-    }
-  }
-LAB_7:
-  uVar5 = 0xc0000012;
-LAB_2:
-  *(int *)(lVar3 + 0x1b0) = local_ec;
-  if (*(int *)(lVar3 + 0x1a4) == 0) {
-    uVar5 = 0xc0000012;
-  }
-  else if ((*(int *)(lVar3 + 0x1a4) == 2) && (uVar5 == 0xc0000012)) {
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-      WPP_SF_(WPP_GLOBAL_Control[3],0x35,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids);
-    }
-    UdfFlushVolume(param_1,puVar14,0,(ulonglong *)0x0,'\x01','\0');
-    UdfFspClose((longlong)puVar14);
-    if ((*(uint *)(lVar3 + 0x1a0) & 0x400) != 0) {
-      UdfResetVmcb(lVar3 + 0x548);
-    }
-    puVar10 = param_1;
-    UdfTearDownAllocationSupport((longlong)param_1,(longlong)puVar14);
-    UdfTearDownRmwSupport(puVar10,(longlong)puVar14);
-    UdfSeqCacheTearDown((longlong)param_1,(longlong)puVar14);
+      WPP_SF_(WPP_GLOBAL_Control[3],0x35,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids);
+    }
+    UdfFlushVolume(param_1,puVar13,0,(ulonglong *)0x0,'\x01','\0');
+    UdfFspClose((longlong)puVar13);
+    if ((*(uint *)(lVar2 + 0x1a0) & 0x400) != 0) {
+      UdfResetVmcb(lVar2 + 0x548);
+    }
+    puVar9 = param_1;
+    UdfTearDownAllocationSupport((longlong)param_1,(longlong)puVar13);
+    UdfTearDownRmwSupport(puVar9,(longlong)puVar13);
+    UdfSeqCacheTearDown((longlong)param_1,(longlong)puVar13);
     UdfMarkAllScbsForVerify((longlong)param_1);
-    if ((*(uint *)(lVar3 + 0x1a0) & 0x4000) == 0) {
-      UdfAcquireResource((longlong)param_1,lVar3 + 0x958,'\0',0);
-      puVar10 = puVar14;
-      UdfKillCleanVolumeTimer((longlong)puVar14);
-      UdfToggleMediaEjectDisable(puVar10,(longlong)puVar14,0,'\x01');
-      ExReleaseResourceLite(lVar3 + 0x958);
-    }
-    *(undefined4 *)(lVar3 + 0x1a4) = 0;
-  }
-  ExReleaseResourceLite(lVar3 + 0x738);
+    if ((*(uint *)(lVar2 + 0x1a0) & 0x4000) == 0) {
+      UdfAcquireResource((longlong)param_1,lVar2 + 0x958,'\0',0);
+      puVar9 = puVar13;
+      UdfKillCleanVolumeTimer((longlong)puVar13);
+      UdfToggleMediaEjectDisable(puVar9,(longlong)puVar13,0,'\x01');
+      ExReleaseResourceLite(lVar2 + 0x958);
+    }
+    *(undefined4 *)(lVar2 + 0x1a4) = 0;
+  }
+  ExReleaseResourceLite(lVar2 + 0x738);
   ExReleaseResourceLite(&DAT_0);
-  if (local_c8 != 0) {
-    ExFreePoolWithTag(local_c8,0);
-  }
-  if (local_c0 != 0) {
-    ExFreePoolWithTag(local_c0,0);
-    local_c0 = 0;
-  }
-  if (local_e8 != 0) {
-    ExFreePoolWithTag(local_e8,0);
-    local_e8 = 0;
-  }
-  if (local_b8 != (void *)0x0) {
-    ExFreePoolWithTag(local_b8,0);
-  }
-  if (local_d0 != (char *)0x0) {
-    ExFreePoolWithTag(local_d0,0);
-  }
+  UdfFreePool(&local_d0);
+  UdfFreePool(&local_b8);
+  UdfFreePool(&local_c8);
+  UdfFreePool((longlong *)&local_e8);
+  UdfFreePool((longlong *)&local_c0);
   if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
      ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x200000) != 0)) {
-    WPP_SF_D(WPP_GLOBAL_Control[3],0x36,&WPP_37eefc73765d327f9a27054026a0a87a_Traceguids,uVar5);
-  }
-  UdfCompleteRequest((longlong)param_1,local_a0,uVar5);
-  return uVar5;
+    WPP_SF_D(WPP_GLOBAL_Control[3],0x36,&WPP_57e8b94a97643b1480d0cdc940af9b9b_Traceguids,
+             (uint)pvVar14);
+  }
+  UdfCompleteRequest((longlong)param_1,local_a0,(uint)pvVar14);
+  return pvVar14;
 }
 

```


## UdfQueryFreeBlocksAndNWA

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,calling,called|
|ratio|0.24|
|i_ratio|0.02|
|m_ratio|0.29|
|b_ratio|0.2|
|match_types|Implied Match|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|`name`|UdfQueryFreeBlocksAndNWA|Feature_2661530937__private_IsEnabledDeviceUsageNoInline|
|`fullname`|UdfQueryFreeBlocksAndNWA|Feature_2661530937__private_IsEnabledDeviceUsageNoInline|
|refcount|8|8|
|`length`|267|49|
|`called`|UdfReadTrackInfo<br>WPP_SF_D<br>WPP_SF_dD<br>__security_check_cookie|Feature_2661530937__private_IsEnabledFallback|
|`calling`|UdfAcquireDeviceShared<br>UdfMountVolume<br>UdfRmwBgFormatWorker<br>UdfSeqCacheCloseSession<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheIssueWriteForBuffer<br>UdfWriteVATAndFlushBuffers|UdfIsRemount<br>UdfMountVolume<br>UdfQueryOnDiskVolInfo<br>UdfSetVolumeDirtyState<br>UdfUpdateVcbPhase0<br>UdfUpdateVolumeStructures<br>UdfVerifyVolume|
|paramcount|3|0|
|`address`|14000c3cc|140011b34|
|`sig`|int __fastcall UdfQueryFreeBlocksAndNWA(longlong param_1, undefined4 * param_2, undefined4 * param_3)|ulonglong __fastcall Feature_2661530937__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfQueryFreeBlocksAndNWA Called Diff


```diff
--- UdfQueryFreeBlocksAndNWA called
+++ Feature_2661530937__private_IsEnabledDeviceUsageNoInline called
@@ -1,4 +1 @@
-UdfReadTrackInfo
-WPP_SF_D
-WPP_SF_dD
-__security_check_cookie
+Feature_2661530937__private_IsEnabledFallback
```


### UdfQueryFreeBlocksAndNWA Calling Diff


```diff
--- UdfQueryFreeBlocksAndNWA calling
+++ Feature_2661530937__private_IsEnabledDeviceUsageNoInline calling
@@ -1 +1 @@
-UdfAcquireDeviceShared
+UdfIsRemount
@@ -3,5 +3,5 @@
-UdfRmwBgFormatWorker
-UdfSeqCacheCloseSession
-UdfSeqCacheFormatEmptySession
-UdfSeqCacheIssueWriteForBuffer
-UdfWriteVATAndFlushBuffers
+UdfQueryOnDiskVolInfo
+UdfSetVolumeDirtyState
+UdfUpdateVcbPhase0
+UdfUpdateVolumeStructures
+UdfVerifyVolume
```


### UdfQueryFreeBlocksAndNWA Diff


```diff
--- UdfQueryFreeBlocksAndNWA
+++ Feature_2661530937__private_IsEnabledDeviceUsageNoInline
@@ -1,50 +1,17 @@
 
-/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-
-int UdfQueryFreeBlocksAndNWA(longlong param_1,undefined4 *param_2,undefined4 *param_3)
+ulonglong Feature_2661530937__private_IsEnabledDeviceUsageNoInline(void)
 
 {
-  int iVar1;
-  undefined1 auStack_78 [32];
-  undefined4 local_58;
-  undefined8 local_48;
-  undefined8 uStack_40;
-  undefined8 local_38;
-  undefined8 uStack_30;
-  undefined4 local_28;
-  ulonglong local_20;
+  ulonglong uVar1;
+  undefined8 local_res8;
   
-  local_20 = __security_cookie ^ (ulonglong)auStack_78;
-  local_28 = 0;
-  local_48 = 0;
-  uStack_40 = 0;
-  local_38 = 0;
-  uStack_30 = 0;
-  iVar1 = UdfReadTrackInfo(*(undefined8 *)(param_1 + 0x18),(char)*(undefined4 *)(param_1 + 0x1e0),
-                           &local_48,0x24);
-  if (iVar1 < 0) {
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40) != 0)) {
-      WPP_SF_D(WPP_GLOBAL_Control[3],0x21,&WPP_b7ad1693dfbe3c78145e46ce564de75b_Traceguids,iVar1);
-    }
+  local_res8 = (ulonglong)Feature_2661530937__private_featureState;
+  if ((Feature_2661530937__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_2661530937__private_IsEnabledFallback(local_res8,3);
   }
   else {
-    *(undefined1 *)param_2 = local_38._3_1_;
-    *(undefined1 *)((longlong)param_2 + 1) = local_38._2_1_;
-    *(undefined1 *)((longlong)param_2 + 2) = local_38._1_1_;
-    *(undefined1 *)((longlong)param_2 + 3) = (undefined1)local_38;
-    *(undefined1 *)param_3 = uStack_40._7_1_;
-    *(undefined1 *)((longlong)param_3 + 1) = uStack_40._6_1_;
-    *(undefined1 *)((longlong)param_3 + 2) = uStack_40._5_1_;
-    *(undefined1 *)((longlong)param_3 + 3) = uStack_40._4_1_;
-    if (((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-       ((*(uint *)((longlong)WPP_GLOBAL_Control + 0x2c) & 0x40) != 0)) {
-      local_58 = *param_3;
-      WPP_SF_dD(WPP_GLOBAL_Control[3],0x22,&WPP_b7ad1693dfbe3c78145e46ce564de75b_Traceguids,*param_2
-               );
-    }
-    iVar1 = 0;
+    uVar1 = (ulonglong)(Feature_2661530937__private_featureState & 1);
   }
-  return iVar1;
+  return uVar1;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## WPP_SF_

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|WPP_SF_|WPP_SF_|
|fullname|WPP_SF_|WPP_SF_|
|`refcount`|182|184|
|length|36|36|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|calling|<details><summary>Expand for full list:<br>UdfAllocateBlockForIcb<br>UdfCheckForOpenRMedia<br>UdfCleanVolumeDpcFn<br>UdfCommonCreate<br>UdfCommonDevControl<br>UdfCommonRead<br>UdfCommonWrite<br>UdfCompletePcb<br>UdfCompleteScbOpen<br>UdfCreateNewFile<br>UdfDetermineMediaWritable</summary>UdfDetermineVolumeBounding<br>UdfFindAnchorVolumeDescriptor<br>UdfFindDataInMetadataStream<br>UdfFindDirEntry<br>UdfFindFileSetDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindPrefix<br>UdfFindVolumeDescriptors<br>UdfFlushVolume<br>UdfFreeAllocation<br>UdfGenerateFullNameForLcb<br>UdfInitRmwSupport<br>UdfInitializeAllocationContext<br>UdfInitializeAllocationSupport<br>UdfInitializePcb<br>UdfInitializePowAllocationSupport<br>UdfInitializeUniqueIdTable<br>UdfIsRemount<br>UdfLoadSparingTables<br>UdfLookupActiveIcb<br>UdfMarkVolumeClean<br>UdfMarkVolumeOpenAndQueueCloseDpc<br>UdfMountVolume<br>UdfOpenObjectFromDirContext<br>UdfOpenStreamDirectory<br>UdfPerformVerify<br>UdfPowAssignTrackInfo<br>UdfPowMakeCompatible<br>UdfPowReserveMetaDataBlocks<br>UdfPowTrackInfoUpdate<br>UdfPrepareDeviceForWrite<br>UdfProcessException<br>UdfRecognizeVolume<br>UdfRmwBgFormatWorker<br>UdfRmwExecuteIoRuns<br>UdfRmwFlushCache<br>UdfRmwGetCacheRun<br>UdfRmwMakeCacheRunValid<br>UdfSendSptCdb<br>UdfSeqCacheCloseSession<br>UdfSeqCacheFlushCache<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheInitialize<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetDispositionInfo<br>UdfSetFileAllocationSize<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfSparePacket<br>UdfStopBackgroundFormat<br>UdfTeardownStructures<br>UdfTransitionSpareTableToRo<br>UdfUpdateDirNames<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase1<br>UdfUpdateVolumeLabel<br>UdfValidateAndRemoveStreamSuffix<br>UdfValidateSubtreeForRename<br>UdfVerifyVcb<br>UdfVerifyVolume<br>UdfVerifyVolume$fin$0<br>UdfVmcbLbnToVbn</details>|<details><summary>Expand for full list:<br>UdfAllocateBlockForIcb<br>UdfCheckForOpenRMedia<br>UdfCleanVolumeDpcFn<br>UdfCommonCreate<br>UdfCommonDevControl<br>UdfCommonRead<br>UdfCommonWrite<br>UdfCompletePcb<br>UdfCompleteScbOpen<br>UdfCreateNewFile<br>UdfDetermineMediaWritable</summary>UdfDetermineVolumeBounding<br>UdfFindAnchorVolumeDescriptor<br>UdfFindDataInMetadataStream<br>UdfFindDirEntry<br>UdfFindFileSetDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindPrefix<br>UdfFindVolumeDescriptors<br>UdfFlushVolume<br>UdfFreeAllocation<br>UdfGenerateFullNameForLcb<br>UdfInitRmwSupport<br>UdfInitializeAllocationContext<br>UdfInitializeAllocationSupport<br>UdfInitializePcb<br>UdfInitializePowAllocationSupport<br>UdfInitializeUniqueIdTable<br>UdfIsRemount<br>UdfLoadSparingTables<br>UdfLookupActiveIcb<br>UdfMarkVolumeClean<br>UdfMarkVolumeOpenAndQueueCloseDpc<br>UdfMountVolume<br>UdfOpenObjectFromDirContext<br>UdfOpenStreamDirectory<br>UdfPerformVerify<br>UdfPowAssignTrackInfo<br>UdfPowMakeCompatible<br>UdfPowReserveMetaDataBlocks<br>UdfPowTrackInfoUpdate<br>UdfPrepareDeviceForWrite<br>UdfProcessException<br>UdfRecognizeVolume<br>UdfRmwBgFormatWorker<br>UdfRmwExecuteIoRuns<br>UdfRmwFlushCache<br>UdfRmwGetCacheRun<br>UdfRmwMakeCacheRunValid<br>UdfSendSptCdb<br>UdfSeqCacheCloseSession<br>UdfSeqCacheFlushCache<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheInitialize<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetDispositionInfo<br>UdfSetFileAllocationSize<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfSparePacket<br>UdfStopBackgroundFormat<br>UdfTeardownStructures<br>UdfTransitionSpareTableToRo<br>UdfUpdateDirNames<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase1<br>UdfUpdateVolumeLabel<br>UdfValidateAndRemoveStreamSuffix<br>UdfValidateSubtreeForRename<br>UdfVerifyVcb<br>UdfVerifyVolume<br>UdfVerifyVolume$fin$0<br>UdfVmcbLbnToVbn</details>|
|paramcount|3|3|
|address|14000c318|14000c318|
|sig|undefined __fastcall WPP_SF_(undefined8 param_1, undefined2 param_2, undefined8 param_3)|undefined __fastcall WPP_SF_(undefined8 param_1, undefined2 param_2, undefined8 param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## NTOSKRNL.EXE::CcUnpinData

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|CcUnpinData|CcUnpinData|
|fullname|NTOSKRNL.EXE::CcUnpinData|NTOSKRNL.EXE::CcUnpinData|
|`refcount`|23|22|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>UdfCleanupDirContext<br>UdfCleanupIcbContext<br>UdfCommonCreate<br>UdfExtendMetaDataFile<br>UdfFindDirEntry<br>UdfLookupAllocation<br>UdfLookupAllocation$fin$0<br>UdfLookupInitialDirEntry<br>UdfMapViewOfDirectory<br>UdfQueryDirectory<br>UdfUnpinCurrentBitmapPage</summary>UdfUnpinData<br>UdfUnpinView<br>UdfUpdateVatHeader<br>UdfUpdateVcbPhase0<br>UdfWriteVATAndFlushBuffers</details>|<details><summary>Expand for full list:<br>UdfCleanupDirContext<br>UdfCleanupIcbContext<br>UdfCommonCreate<br>UdfExtendMetaDataFile<br>UdfFindDirEntry<br>UdfLookupAllocation<br>UdfLookupAllocation$fin$0<br>UdfLookupInitialDirEntry<br>UdfMapViewOfDirectory<br>UdfQueryDirectory<br>UdfUnpinCurrentBitmapPage</summary>UdfUnpinData<br>UdfUnpinView<br>UdfUpdateVatHeader<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase0$fin$1<br>UdfWriteVATAndFlushBuffers</details>|
|paramcount|0|0|
|address|EXTERNAL:00000005|EXTERNAL:00000005|
|sig|undefined CcUnpinData(void)|undefined CcUnpinData(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::CcUnpinData Calling Diff


```diff
--- NTOSKRNL.EXE::CcUnpinData calling
+++ NTOSKRNL.EXE::CcUnpinData calling
@@ -15,0 +16 @@
+UdfUpdateVcbPhase0$fin$1
```


## NTOSKRNL.EXE::ExAcquireResourceExclusiveLite

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|ExAcquireResourceExclusiveLite|ExAcquireResourceExclusiveLite|
|fullname|NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|NTOSKRNL.EXE::ExAcquireResourceExclusiveLite|
|`refcount`|45|44|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>UdfAcquireDeviceShared<br>UdfAcquireForCacheWrite<br>UdfAcquireForCcFlush<br>UdfAcquireForModWrite<br>UdfAcquireResource<br>UdfCommonCleanup<br>UdfCommonClose<br>UdfCommonClosePrivate<br>UdfCommonCreate<br>UdfCommonFlushBuffers<br>UdfCommonPnp</summary>UdfCommonShutdown<br>UdfCompleteScbOpen<br>UdfDismountVolume<br>UdfFilterCallbackAcquireForCreateSection<br>UdfFindPrefix<br>UdfFlushIcbForScb<br>UdfFlushVolume<br>UdfFspClose<br>UdfInitializeAllocationSupport<br>UdfInvalidateVolumes<br>UdfLookupMetaVsnOfExtent<br>UdfMountVolume<br>UdfPerformVerify<br>UdfPnpCallbackRoutine<br>UdfPnpQueryRemove<br>UdfRmwBgFormatWorker<br>UdfRmwExecuteIoRuns<br>UdfRmwGetCacheRun<br>UdfRmwIssueIoRequest<br>UdfRmwMakeCacheRunValid<br>UdfSeqCacheReserveFileRegion<br>UdfSeqCacheUnReserveFileRegion<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfTeardownStructures<br>UdfVerifyVolume</details>|<details><summary>Expand for full list:<br>UdfAcquireDeviceShared<br>UdfAcquireForCacheWrite<br>UdfAcquireForCcFlush<br>UdfAcquireForModWrite<br>UdfAcquireResource<br>UdfCommonCleanup<br>UdfCommonClose<br>UdfCommonClosePrivate<br>UdfCommonCreate<br>UdfCommonFlushBuffers<br>UdfCommonPnp</summary>UdfCommonShutdown<br>UdfCompleteScbOpen<br>UdfDismountVolume<br>UdfFilterCallbackAcquireForCreateSection<br>UdfFindPrefix<br>UdfFlushIcbForScb<br>UdfFlushVolume<br>UdfFspClose<br>UdfInitializeAllocationSupport<br>UdfInvalidateVolumes<br>UdfLookupMetaVsnOfExtent<br>UdfMountVolume<br>UdfPerformVerify<br>UdfPnpCallbackRoutine<br>UdfPnpQueryRemove<br>UdfRmwBgFormatWorker<br>UdfRmwExecuteIoRuns<br>UdfRmwGetCacheRun<br>UdfRmwIssueIoRequest<br>UdfRmwMakeCacheRunValid<br>UdfSeqCacheReserveFileRegion<br>UdfSeqCacheUnReserveFileRegion<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfTeardownStructures<br>UdfVerifyVolume</details>|
|paramcount|0|0|
|address|EXTERNAL:0000000e|EXTERNAL:0000000e|
|sig|undefined ExAcquireResourceExclusiveLite(void)|undefined ExAcquireResourceExclusiveLite(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## WPP_SF_dD

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|0.94|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|WPP_SF_dD|WPP_SF_dD|
|fullname|WPP_SF_dD|WPP_SF_dD|
|`refcount`|60|61|
|length|71|71|
|called|_guard_dispatch_icall|_guard_dispatch_icall|
|calling|<details><summary>Expand for full list:<br>UdfAddAllocation<br>UdfAddToPcb<br>UdfAddVmcbMapping<br>UdfAllocateAtFileTail<br>UdfAllocateAtFileTail$fin$0<br>UdfCheckForOpenRMedia<br>UdfCommonWrite<br>UdfCompletePcb<br>UdfCreateLink<br>UdfDetermineVolumeBounding<br>UdfFindAnchorVolumeDescriptor</summary>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfFreeAllocation<br>UdfGetConfiguration<br>UdfInitRmwSupport<br>UdfInitializeAllocationSupport<br>UdfInitializeAllocations<br>UdfInitializePcb<br>UdfInitializeScbFromIcbContext<br>UdfLoadSparingTables<br>UdfLookupPsnOfExtent<br>UdfPerformVerify<br>UdfPowAllocateAtFileTail<br>UdfQueryDeviceBufferSize<br>UdfQueryFeature<br>UdfQueryFreeBlocksAndNWA<br>UdfRmwBgFormatWorker<br>UdfSeqCacheAllocate<br>UdfSeqCacheFlushCache<br>UdfSeqCacheForceAllocation<br>UdfSeqCacheIssuePowWriteForBuffer<br>UdfSeqCacheWriteCompletion<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetFileAllocationSize<br>UdfUpdateLvidCounts<br>UdfUpdateVcbPhase0<br>UdfVmcbPurgeSomeMappings<br>UdfVmcbVbnToLbn<br>UdfWriteSparingTable<br>UdfWriteVATAndFlushBuffers</details>|<details><summary>Expand for full list:<br>UdfAddAllocation<br>UdfAddToPcb<br>UdfAddVmcbMapping<br>UdfAllocateAtFileTail<br>UdfAllocateAtFileTail$fin$0<br>UdfCheckForOpenRMedia<br>UdfCommonWrite<br>UdfCompletePcb<br>UdfCreateLink<br>UdfDetermineVolumeBounding<br>UdfFindAnchorVolumeDescriptor</summary>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindVolumeDescriptors<br>UdfFreeAllocation<br>UdfGetConfiguration<br>UdfInitRmwSupport<br>UdfInitializeAllocationSupport<br>UdfInitializeAllocations<br>UdfInitializePcb<br>UdfInitializeScbFromIcbContext<br>UdfLoadSparingTables<br>UdfLookupPsnOfExtent<br>UdfPerformVerify<br>UdfPowAllocateAtFileTail<br>UdfQueryDeviceBufferSize<br>UdfQueryFeature<br>UdfQueryFreeBlocksAndNWA<br>UdfRmwBgFormatWorker<br>UdfSeqCacheAllocate<br>UdfSeqCacheFlushCache<br>UdfSeqCacheForceAllocation<br>UdfSeqCacheIssuePowWriteForBuffer<br>UdfSeqCacheWriteCompletion<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetFileAllocationSize<br>UdfUpdateLvidCounts<br>UdfUpdateVcbPhase0<br>UdfVmcbPurgeSomeMappings<br>UdfVmcbVbnToLbn<br>UdfWriteSparingTable<br>UdfWriteVATAndFlushBuffers</details>|
|paramcount|4|4|
|address|14000f2a4|14000f2a4|
|sig|undefined __fastcall WPP_SF_dD(undefined8 param_1, undefined2 param_2, undefined8 param_3, undefined4 param_4)|undefined __fastcall WPP_SF_dD(undefined8 param_1, undefined2 param_2, undefined8 param_3, undefined4 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## UdfUnpinData

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.92|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfUnpinData|UdfUnpinData|
|fullname|UdfUnpinData|UdfUnpinData|
|`refcount`|12|13|
|length|39|39|
|called|NTOSKRNL.EXE::CcUnpinData|NTOSKRNL.EXE::CcUnpinData|
|`calling`|UdfAllocateBlockForIcb<br>UdfDeEmbedFileData<br>UdfDeEmbedFileData$fin$0<br>UdfLookupPsnOfExtent<br>UdfLookupPsnOfExtent$fin$0<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetDirtyFid<br>UdfSetDirtyFid$fin$0<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase0$fin$1|UdfAllocateBlockForIcb<br>UdfDeEmbedFileData<br>UdfDeEmbedFileData$fin$0<br>UdfLookupPsnOfExtent<br>UdfLookupPsnOfExtent$fin$0<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetDirtyFid<br>UdfSetDirtyFid$fin$0<br>UdfUpdateVcbPhase0|
|paramcount|2|2|
|`address`|140007934|140007094|
|sig|undefined __fastcall UdfUnpinData(undefined8 param_1, longlong * param_2)|undefined __fastcall UdfUnpinData(undefined8 param_1, longlong * param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfUnpinData Calling Diff


```diff
--- UdfUnpinData calling
+++ UdfUnpinData calling
@@ -10 +9,0 @@
-UdfUpdateVcbPhase0$fin$1
```


## wil_details_IsEnabledFallback

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|5|6|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_2146947386__private_IsEnabledFallback<br>Feature_3105867064__private_IsEnabledFallback<br>Feature_3619408187__private_IsEnabledFallback<br>Feature_379829561__private_IsEnabledFallback|Feature_2146947386__private_IsEnabledFallback<br>Feature_2661530937__private_IsEnabledFallback<br>Feature_3105867064__private_IsEnabledFallback<br>Feature_3619408187__private_IsEnabledFallback<br>Feature_379829561__private_IsEnabledFallback|
|paramcount|3|3|
|address|14000fdd8|14000fdd8|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -1,0 +2 @@
+Feature_2661530937__private_IsEnabledFallback
```


## UdfFreePool

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.92|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfFreePool|UdfFreePool|
|fullname|UdfFreePool|UdfFreePool|
|`refcount`|87|88|
|length|44|44|
|called|NTOSKRNL.EXE::ExFreePoolWithTag|NTOSKRNL.EXE::ExFreePoolWithTag|
|`calling`|<details><summary>Expand for full list:<br>UdfCleanupDirContext<br>UdfCleanupReservationStructures<br>UdfCommonCreate<br>UdfCompletePcb<br>UdfCreateScb$fin$0<br>UdfCreateSparseReservationBitmap<br>UdfDeletePcb<br>UdfDeleteScb<br>UdfDeleteVcb<br>UdfDetermineVolumeBounding<br>UdfDetermineVolumeBounding$fin$0</summary>UdfEnumerateIndex<br>UdfFindAnchorVolumeDescriptor<br>UdfFindDirEntry<br>UdfFindFileSetDescriptor<br>UdfFindFileSetDescriptor$fin$0<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor$fin$0<br>UdfFindVolumeDescriptors<br>UdfFindVolumeDescriptors$fin$0<br>UdfFinishBuffers<br>UdfFreeLcb<br>UdfGenerateFullNameForLcb<br>UdfGenerateFullNameForLcb$fin$0<br>UdfInitializeEnumeration<br>UdfInsertAdExtInfo<br>UdfLookupDirEntryPostProcessing$fin$0<br>UdfLookupInitialDirEntry<br>UdfLookupNextDirEntry<br>UdfLookupNextFileIndex<br>UdfMountVolume$fin$0<br>UdfMoveFile<br>UdfMoveFile$fin$0<br>UdfNormalizeFileNames<br>UdfNotifyReportChange<br>UdfPerformDevIoCtrl<br>UdfPowAssignTrackInfo<br>UdfPowTrackInfoAdd<br>UdfPowTrackInfoDestroy<br>UdfProcessHolesInFileRegion<br>UdfQueryNameInfo<br>UdfRecognizeVolume$fin$0<br>UdfResizeLcbBufferForName<br>UdfSeqCacheDeallocate<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheFormatEmptySession$fin$0<br>UdfSeqCacheTearDown<br>UdfSetFsLabelInfo<br>UdfSetFsLabelInfo$fin$0<br>UdfTearDownRmwSupport<br>UdfTransitionSpareTableToRo<br>UdfUpdateVcbPhase0$fin$1<br>UdfVerifyScbBranch<br>UdfVerifyVolume$fin$0</details>|<details><summary>Expand for full list:<br>UdfCleanupDirContext<br>UdfCleanupReservationStructures<br>UdfCommonCreate<br>UdfCompletePcb<br>UdfCreateScb$fin$0<br>UdfCreateSparseReservationBitmap<br>UdfDeletePcb<br>UdfDeleteScb<br>UdfDeleteVcb<br>UdfDetermineVolumeBounding<br>UdfDetermineVolumeBounding$fin$0</summary>UdfEnumerateIndex<br>UdfFindAnchorVolumeDescriptor<br>UdfFindDirEntry<br>UdfFindFileSetDescriptor<br>UdfFindFileSetDescriptor$fin$0<br>UdfFindLogicalVolumeIntegrityDescriptor<br>UdfFindLogicalVolumeIntegrityDescriptor$fin$0<br>UdfFindVolumeDescriptors<br>UdfFindVolumeDescriptors$fin$0<br>UdfFinishBuffers<br>UdfFreeLcb<br>UdfGenerateFullNameForLcb<br>UdfGenerateFullNameForLcb$fin$0<br>UdfInitializeEnumeration<br>UdfInsertAdExtInfo<br>UdfLookupDirEntryPostProcessing$fin$0<br>UdfLookupInitialDirEntry<br>UdfLookupNextDirEntry<br>UdfLookupNextFileIndex<br>UdfMoveFile<br>UdfMoveFile$fin$0<br>UdfNormalizeFileNames<br>UdfNotifyReportChange<br>UdfPerformDevIoCtrl<br>UdfPowAssignTrackInfo<br>UdfPowTrackInfoAdd<br>UdfPowTrackInfoDestroy<br>UdfProcessHolesInFileRegion<br>UdfQueryNameInfo<br>UdfRecognizeVolume$fin$0<br>UdfResizeLcbBufferForName<br>UdfSeqCacheDeallocate<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheFormatEmptySession$fin$0<br>UdfSeqCacheTearDown<br>UdfSetFsLabelInfo<br>UdfSetFsLabelInfo$fin$0<br>UdfTearDownRmwSupport<br>UdfTransitionSpareTableToRo<br>UdfVerifyScbBranch<br>UdfVerifyVolume<br>UdfVerifyVolume$fin$0</details>|
|paramcount|1|1|
|`address`|1400052f0|140004a50|
|sig|undefined __fastcall UdfFreePool(longlong * param_1)|undefined __fastcall UdfFreePool(longlong * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfFreePool Calling Diff


```diff
--- UdfFreePool calling
+++ UdfFreePool calling
@@ -31 +30,0 @@
-UdfMountVolume$fin$0
@@ -52 +50,0 @@
-UdfUpdateVcbPhase0$fin$1
@@ -53,0 +52 @@
+UdfVerifyVolume
```


## NTOSKRNL.EXE::CcPurgeCacheSection

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|CcPurgeCacheSection|CcPurgeCacheSection|
|fullname|NTOSKRNL.EXE::CcPurgeCacheSection|NTOSKRNL.EXE::CcPurgeCacheSection|
|`refcount`|18|17|
|length|0|0|
|called|||
|`calling`|UdfAddVmcbMapping<br>UdfCommonFlushBuffers<br>UdfCommonWrite<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfFlushVolume<br>UdfPurgeAndFreeAllocationForScb<br>UdfTearDownSpecialScb<br>UdfUpdateVcbPhase0<br>UdfVmcbPurgeSomeMappings|UdfAddVmcbMapping<br>UdfCommonFlushBuffers<br>UdfCommonWrite<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfFlushVolume<br>UdfPurgeAndFreeAllocationForScb<br>UdfTearDownSpecialScb<br>UdfVmcbPurgeSomeMappings|
|paramcount|0|0|
|address|EXTERNAL:0000003c|EXTERNAL:0000003c|
|sig|undefined CcPurgeCacheSection(void)|undefined CcPurgeCacheSection(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::CcPurgeCacheSection Calling Diff


```diff
--- NTOSKRNL.EXE::CcPurgeCacheSection calling
+++ NTOSKRNL.EXE::CcPurgeCacheSection calling
@@ -8 +7,0 @@
-UdfUpdateVcbPhase0
```


## memset

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.86|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|memset|memset|
|fullname|memset|memset|
|`refcount`|106|105|
|length|236|236|
|called|||
|`calling`|<details><summary>Expand for full list:<br>DriverEntry<br>UdfAllocIoContext<br>UdfAllocateBlockForIcb<br>UdfBuildScbShortNameIndex<br>UdfCleanVolumeWorker<br>UdfCleanupDirContext<br>UdfCleanupIcbContext<br>UdfCommonCreate<br>UdfCommonRead<br>UdfCommonWrite<br>UdfCreateFcbNonPaged</summary>UdfCreateLink<br>UdfCreateNewIcb<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfCreateScb<br>UdfDeleteFidForLcb<br>UdfDeleteVcb<br>UdfDirectoryIsEmpty<br>UdfFindDirEntry<br>UdfFspClose<br>UdfInitializeCompoundDirContext<br>UdfInitializeDirContext<br>UdfInitializeEnumeration<br>UdfInitializeGlobalData<br>UdfInitializeIcbContext<br>UdfInitializeIcbContextFromScb<br>UdfInitializeStackIrpContext<br>UdfInitializeTelemetry<br>UdfInitializeUniqueIdTable<br>UdfInitializeVcb<br>UdfInitializeVmcb<br>UdfInsertPrefix<br>UdfLookupDirEntryPostProcessing<br>UdfLookupInitialDirEntry<br>UdfNonCachedIo<br>UdfOpenObjectByFileId<br>UdfOpenObjectFromDirContext<br>UdfOpenStreamDirectory<br>UdfPnpCallbackRoutine<br>UdfPowTrackInfoAdd<br>UdfPowTrackInfoDestroy<br>UdfPrepareBuffers<br>UdfProcessHolesInFileRegion<br>UdfQueryAlternateNameInfo<br>UdfQueryDirectory<br>UdfQueryStreamsInfo<br>UdfReadFormattableCapacity<br>UdfRemoveAlternateDataStreams<br>UdfRemoveVpbIfMounted<br>UdfRmwBgFormatWorker<br>UdfRmwFlushCache<br>UdfRmwMakeCacheRunValid<br>UdfRmwReadWriteSectors<br>UdfSendSptCdb<br>UdfSeqCacheAllocate<br>UdfSeqCacheCloseSession<br>UdfSeqCacheFlushCache<br>UdfSeqCacheInsertFlushWaitBlock<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheWriteBlocksForFile<br>UdfSeqCacheWriteCheckPOW<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetFileAllocationSize<br>UdfSetHiddenAttribute<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfUninitializeVmcb<br>UdfUpdateAdsFromScb<br>UdfUpdateTimestampsToIcb<br>UdfUpdateVcbPhase0<br>UdfUpdateVcbPhase1<br>UdfVerifyObjectOnMedia<br>UdfVerifyScbBranch<br>UdfWriteVATAndFlushBuffers<br>WppTraceCallback</details>|<details><summary>Expand for full list:<br>DriverEntry<br>UdfAllocIoContext<br>UdfAllocateBlockForIcb<br>UdfBuildScbShortNameIndex<br>UdfCleanVolumeWorker<br>UdfCleanupDirContext<br>UdfCleanupIcbContext<br>UdfCommonCreate<br>UdfCommonRead<br>UdfCommonWrite<br>UdfCreateFcbNonPaged</summary>UdfCreateLink<br>UdfCreateNewIcb<br>UdfCreateOrResetVatAndVmcbStreams<br>UdfCreateScb<br>UdfDeleteFidForLcb<br>UdfDeleteVcb<br>UdfDirectoryIsEmpty<br>UdfFindDirEntry<br>UdfFspClose<br>UdfInitializeCompoundDirContext<br>UdfInitializeDirContext<br>UdfInitializeEnumeration<br>UdfInitializeGlobalData<br>UdfInitializeIcbContext<br>UdfInitializeIcbContextFromScb<br>UdfInitializeStackIrpContext<br>UdfInitializeTelemetry<br>UdfInitializeUniqueIdTable<br>UdfInitializeVcb<br>UdfInitializeVmcb<br>UdfInsertPrefix<br>UdfLookupDirEntryPostProcessing<br>UdfLookupInitialDirEntry<br>UdfNonCachedIo<br>UdfOpenObjectByFileId<br>UdfOpenObjectFromDirContext<br>UdfOpenStreamDirectory<br>UdfPnpCallbackRoutine<br>UdfPowTrackInfoAdd<br>UdfPowTrackInfoDestroy<br>UdfPrepareBuffers<br>UdfProcessHolesInFileRegion<br>UdfQueryAlternateNameInfo<br>UdfQueryDirectory<br>UdfQueryStreamsInfo<br>UdfReadFormattableCapacity<br>UdfRemoveAlternateDataStreams<br>UdfRemoveVpbIfMounted<br>UdfRmwBgFormatWorker<br>UdfRmwFlushCache<br>UdfRmwMakeCacheRunValid<br>UdfRmwReadWriteSectors<br>UdfSendSptCdb<br>UdfSeqCacheAllocate<br>UdfSeqCacheCloseSession<br>UdfSeqCacheFlushCache<br>UdfSeqCacheInsertFlushWaitBlock<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheWriteBlocksForFile<br>UdfSeqCacheWriteCheckPOW<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetFileAllocationSize<br>UdfSetHiddenAttribute<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfUninitializeVmcb<br>UdfUpdateAdsFromScb<br>UdfUpdateTimestampsToIcb<br>UdfUpdateVcbPhase1<br>UdfVerifyObjectOnMedia<br>UdfVerifyScbBranch<br>UdfWriteVATAndFlushBuffers<br>WppTraceCallback</details>|
|paramcount|3|3|
|`address`|14001c040|14001c100|
|sig|void * __cdecl memset(void * _Dst, int _Val, size_t _Size)|void * __cdecl memset(void * _Dst, int _Val, size_t _Size)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### memset Calling Diff


```diff
--- memset calling
+++ memset calling
@@ -71 +70,0 @@
-UdfUpdateVcbPhase0
```


## NTOSKRNL.EXE::ExRaiseStatus

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|ExRaiseStatus|ExRaiseStatus|
|fullname|NTOSKRNL.EXE::ExRaiseStatus|NTOSKRNL.EXE::ExRaiseStatus|
|`refcount`|96|95|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>UdfAcquireDeviceShared<br>UdfAcquireResource<br>UdfCheckLegalCS0Dstring<br>UdfCommonCleanup<br>UdfCommonClosePrivate<br>UdfCommonCreate<br>UdfCommonQueryInfo<br>UdfCommonQueryVolInfo<br>UdfCompleteScbOpen<br>UdfCreateFileLock<br>UdfCreateIrpContext</summary>UdfFindDataInMetadataStream<br>UdfFindDirEntry<br>UdfFindPrefix<br>UdfFindTargetElements<br>UdfFreeAllocation<br>UdfGetBlocksNeeded<br>UdfGetNextAllocationPostProcessing<br>UdfInitRmwSupport<br>UdfInitializeAllocationContext<br>UdfInitializeAllocationSupport<br>UdfInsertPrefix<br>UdfInsertPrefixTreeEntry<br>UdfIsMediaWriteProtected<br>UdfLockUserBuffer<br>UdfLookupActiveIcb<br>UdfLookupActiveIcbInExtent<br>UdfLookupDirEntryPostProcessing<br>UdfLookupEa<br>UdfLookupFileEntryInEnumeration<br>UdfLookupInitialDirEntry<br>UdfLookupMetaVsnOfExtent<br>UdfLookupPsnOfExtent<br>UdfMapUserBuffer<br>UdfMapViewOfDirectory<br>UdfMountVolume<br>UdfMultipleAsync<br>UdfNotifyReportChange<br>UdfPrepareBuffers<br>UdfPrepareForAllocationChange<br>UdfQueryDirectory<br>UdfQueryFeature<br>UdfRaiseStatusEx<br>UdfReadWriteSectors<br>UdfRmwBgFormatWorker<br>UdfRmwIssueIoRequest<br>UdfSeqCacheFlushCache<br>UdfSeqCacheInitialize<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheReserveFileRegion<br>UdfSeqCacheUnReserveFileRegion<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfTeardownStructures<br>UdfUpdateDirNames<br>UdfUpdateTimestampsFromIcbContext<br>UdfUpdateTimestampsToIcb<br>UdfValidateAndRemoveStreamSuffix<br>UdfVerifyDescriptor<br>UdfVerifyScbBranch<br>UdfVerifyScbOperation<br>UdfVerifyVcb</details>|<details><summary>Expand for full list:<br>UdfAcquireDeviceShared<br>UdfAcquireResource<br>UdfCheckLegalCS0Dstring<br>UdfCommonCleanup<br>UdfCommonClosePrivate<br>UdfCommonCreate<br>UdfCommonQueryInfo<br>UdfCommonQueryVolInfo<br>UdfCompleteScbOpen<br>UdfCreateFileLock<br>UdfCreateIrpContext</summary>UdfFindDataInMetadataStream<br>UdfFindDirEntry<br>UdfFindPrefix<br>UdfFindTargetElements<br>UdfFreeAllocation<br>UdfGetBlocksNeeded<br>UdfGetNextAllocationPostProcessing<br>UdfInitRmwSupport<br>UdfInitializeAllocationContext<br>UdfInitializeAllocationSupport<br>UdfInsertPrefix<br>UdfInsertPrefixTreeEntry<br>UdfIsMediaWriteProtected<br>UdfLockUserBuffer<br>UdfLookupActiveIcb<br>UdfLookupActiveIcbInExtent<br>UdfLookupDirEntryPostProcessing<br>UdfLookupEa<br>UdfLookupFileEntryInEnumeration<br>UdfLookupInitialDirEntry<br>UdfLookupMetaVsnOfExtent<br>UdfLookupPsnOfExtent<br>UdfMapUserBuffer<br>UdfMapViewOfDirectory<br>UdfMultipleAsync<br>UdfNotifyReportChange<br>UdfPrepareBuffers<br>UdfPrepareForAllocationChange<br>UdfQueryDirectory<br>UdfQueryFeature<br>UdfRaiseStatusEx<br>UdfReadWriteSectors<br>UdfRmwBgFormatWorker<br>UdfRmwIssueIoRequest<br>UdfSeqCacheFlushCache<br>UdfSeqCacheInitialize<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheReserveFileRegion<br>UdfSeqCacheUnReserveFileRegion<br>UdfSetLinkInfo<br>UdfSetRenameInfo<br>UdfTeardownStructures<br>UdfUpdateDirNames<br>UdfUpdateTimestampsFromIcbContext<br>UdfUpdateTimestampsToIcb<br>UdfValidateAndRemoveStreamSuffix<br>UdfVerifyDescriptor<br>UdfVerifyScbBranch<br>UdfVerifyScbOperation<br>UdfVerifyVcb</details>|
|paramcount|0|0|
|address|EXTERNAL:0000000a|EXTERNAL:0000000a|
|sig|noreturn undefined ExRaiseStatus(void)|noreturn undefined ExRaiseStatus(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::ExRaiseStatus Calling Diff


```diff
--- NTOSKRNL.EXE::ExRaiseStatus calling
+++ NTOSKRNL.EXE::ExRaiseStatus calling
@@ -36 +35,0 @@
-UdfMountVolume
```


## UdfDeleteInternalStream

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.93|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfDeleteInternalStream|UdfDeleteInternalStream|
|fullname|UdfDeleteInternalStream|UdfDeleteInternalStream|
|`refcount`|5|4|
|length|409|409|
|called|NTOSKRNL.EXE::CcUninitializeCacheMap<br>NTOSKRNL.EXE::ExAcquireFastMutex<br>NTOSKRNL.EXE::ExAcquireFastMutexUnsafe<br>NTOSKRNL.EXE::ExReleaseFastMutex<br>NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>NTOSKRNL.EXE::ObfDereferenceObject|NTOSKRNL.EXE::CcUninitializeCacheMap<br>NTOSKRNL.EXE::ExAcquireFastMutex<br>NTOSKRNL.EXE::ExAcquireFastMutexUnsafe<br>NTOSKRNL.EXE::ExReleaseFastMutex<br>NTOSKRNL.EXE::ExReleaseFastMutexUnsafe<br>NTOSKRNL.EXE::ObfDereferenceObject|
|`calling`|UdfFlushVolume<br>UdfTearDownSpecialScb<br>UdfTeardownStructures<br>UdfUpdateVcbPhase0|UdfFlushVolume<br>UdfTearDownSpecialScb<br>UdfTeardownStructures|
|paramcount|2|2|
|`address`|140055f1c|14005467c|
|sig|undefined __fastcall UdfDeleteInternalStream(undefined8 param_1, longlong param_2)|undefined __fastcall UdfDeleteInternalStream(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfDeleteInternalStream Calling Diff


```diff
--- UdfDeleteInternalStream calling
+++ UdfDeleteInternalStream calling
@@ -4 +3,0 @@
-UdfUpdateVcbPhase0
```


## UdfAcquireResource

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfAcquireResource|UdfAcquireResource|
|fullname|UdfAcquireResource|UdfAcquireResource|
|`refcount`|174|175|
|length|154|154|
|called|NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExAcquireSharedStarveExclusive<br>NTOSKRNL.EXE::ExRaiseStatus|NTOSKRNL.EXE::ExAcquireResourceExclusiveLite<br>NTOSKRNL.EXE::ExAcquireResourceSharedLite<br>NTOSKRNL.EXE::ExAcquireSharedStarveExclusive<br>NTOSKRNL.EXE::ExRaiseStatus|
|`calling`|<details><summary>Expand for full list:<br>UdfAcquireAllFiles<br>UdfAcquireDeviceShared<br>UdfAddAllocation<br>UdfAllocateBlockForIcb<br>UdfCheckForDismount<br>UdfCleanVolumeWorker<br>UdfCommonCleanup<br>UdfCommonDevControl<br>UdfCommonFlushBuffers<br>UdfCommonLockControl<br>UdfCommonRead</summary>UdfCommonSetInfo<br>UdfCommonSetVolInfo<br>UdfCommonShutdown<br>UdfCommonWrite<br>UdfCreateLink<br>UdfDeallocateMetaDataBlock<br>UdfDeleteLinkAndTruncateScbs<br>UdfDismountVolume<br>UdfExtendMetaDataFile<br>UdfFastQueryStdInfo<br>UdfFastUnlockAll<br>UdfFastUnlockAllByKey<br>UdfFindPrefix<br>UdfFlushVolume<br>UdfFreeAllocation<br>UdfFspClose<br>UdfGenerateFullNameForLcb<br>UdfGetRetrievalPointers<br>UdfGetVolumeBitmap<br>UdfInitializeAllocations<br>UdfInvalidateVolumes<br>UdfIsVolumeMounted<br>UdfLockVolume<br>UdfLockVolumeInternal<br>UdfMakeCompatible<br>UdfMarkHandle<br>UdfMarkVolumeClean<br>UdfMarkVolumeCorrupt<br>UdfMarkVolumeDirty<br>UdfMarkVolumeOpenAndQueueCloseDpc<br>UdfMoveFile<br>UdfNotifyChangeDirectory<br>UdfOpenExistingScb<br>UdfOpenObjectByFileId<br>UdfOpenObjectFromDirContext<br>UdfOplockRequest<br>UdfPerformVerify<br>UdfPnpCallbackRoutine<br>UdfPnpCancelRemove<br>UdfPnpQueryRemove<br>UdfPnpRemove<br>UdfPnpSurpriseRemove<br>UdfPowMakeCompatible<br>UdfPowReserveMetaDataBlocks<br>UdfPrepareMediaEjectWorker<br>UdfProcessHolesInFileRegion<br>UdfQueryAlternateNameInfo<br>UdfQueryStreamsInfo<br>UdfSeqCacheCloseSession<br>UdfSeqCacheDeallocate<br>UdfSeqCacheFlushCache<br>UdfSeqCacheForceAllocation<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheIssuePowWriteForBuffer<br>UdfSeqCacheIssueWriteForBuffer<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheReleaseWriteWaiter<br>UdfSeqCacheTransferMcb<br>UdfSeqCacheTruncateDataForFile<br>UdfSeqCacheWriteBlocksForFile<br>UdfSeqCacheWriteCheckPOW<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetAllocationInfo<br>UdfSetDefectManagement<br>UdfSetEndOfFileInfo<br>UdfSetHiddenAttribute<br>UdfSetLinkInfo<br>UdfSetPurgeFailureMode<br>UdfSetRenameInfo<br>UdfSupersedeOrOverwriteFile<br>UdfTearDownAllocationSupport<br>UdfUnlockVolume<br>UdfUpdateMetadataAllocation<br>UdfUpdateVolumeStructures<br>UdfVerifyMcbAllocatedInBitmap<br>UdfVerifyScbBranch<br>UdfVerifyVolume<br>UdfVerifyVolume$fin$0<br>UdfWriteVATAndFlushBuffers</details>|<details><summary>Expand for full list:<br>UdfAcquireAllFiles<br>UdfAcquireDeviceShared<br>UdfAddAllocation<br>UdfAllocateBlockForIcb<br>UdfCheckForDismount<br>UdfCleanVolumeWorker<br>UdfCommonCleanup<br>UdfCommonDevControl<br>UdfCommonFlushBuffers<br>UdfCommonLockControl<br>UdfCommonRead</summary>UdfCommonSetInfo<br>UdfCommonSetVolInfo<br>UdfCommonShutdown<br>UdfCommonWrite<br>UdfCreateLink<br>UdfDeallocateMetaDataBlock<br>UdfDeleteLinkAndTruncateScbs<br>UdfDismountVolume<br>UdfExtendMetaDataFile<br>UdfFastQueryStdInfo<br>UdfFastUnlockAll<br>UdfFastUnlockAllByKey<br>UdfFindPrefix<br>UdfFlushVolume<br>UdfFreeAllocation<br>UdfFspClose<br>UdfGenerateFullNameForLcb<br>UdfGetRetrievalPointers<br>UdfGetVolumeBitmap<br>UdfInitializeAllocations<br>UdfInvalidateVolumes<br>UdfIsVolumeMounted<br>UdfLockVolume<br>UdfLockVolumeInternal<br>UdfMakeCompatible<br>UdfMarkHandle<br>UdfMarkVolumeClean<br>UdfMarkVolumeCorrupt<br>UdfMarkVolumeDirty<br>UdfMarkVolumeOpenAndQueueCloseDpc<br>UdfMountVolume<br>UdfMoveFile<br>UdfNotifyChangeDirectory<br>UdfOpenExistingScb<br>UdfOpenObjectByFileId<br>UdfOpenObjectFromDirContext<br>UdfOplockRequest<br>UdfPerformVerify<br>UdfPnpCallbackRoutine<br>UdfPnpCancelRemove<br>UdfPnpQueryRemove<br>UdfPnpRemove<br>UdfPnpSurpriseRemove<br>UdfPowMakeCompatible<br>UdfPowReserveMetaDataBlocks<br>UdfPrepareMediaEjectWorker<br>UdfProcessHolesInFileRegion<br>UdfQueryAlternateNameInfo<br>UdfQueryStreamsInfo<br>UdfSeqCacheCloseSession<br>UdfSeqCacheDeallocate<br>UdfSeqCacheFlushCache<br>UdfSeqCacheForceAllocation<br>UdfSeqCacheFormatEmptySession<br>UdfSeqCacheIssuePowWriteForBuffer<br>UdfSeqCacheIssueWriteForBuffer<br>UdfSeqCacheReadBlocksForFile<br>UdfSeqCacheReleaseWriteWaiter<br>UdfSeqCacheTransferMcb<br>UdfSeqCacheTruncateDataForFile<br>UdfSeqCacheWriteBlocksForFile<br>UdfSeqCacheWriteCheckPOW<br>UdfSeqCacheWriterWorkerRoutineForPOW<br>UdfSeqCacheWriterWorkerRoutineForVAT<br>UdfSetAllocationInfo<br>UdfSetDefectManagement<br>UdfSetEndOfFileInfo<br>UdfSetHiddenAttribute<br>UdfSetLinkInfo<br>UdfSetPurgeFailureMode<br>UdfSetRenameInfo<br>UdfSupersedeOrOverwriteFile<br>UdfTearDownAllocationSupport<br>UdfUnlockVolume<br>UdfUpdateMetadataAllocation<br>UdfUpdateVolumeStructures<br>UdfVerifyMcbAllocatedInBitmap<br>UdfVerifyScbBranch<br>UdfVerifyVolume<br>UdfVerifyVolume$fin$0<br>UdfWriteVATAndFlushBuffers</details>|
|paramcount|4|4|
|`address`|14004e220|14004c0d0|
|sig|ulonglong __fastcall UdfAcquireResource(longlong param_1, undefined8 param_2, char param_3, int param_4)|ulonglong __fastcall UdfAcquireResource(longlong param_1, undefined8 param_2, char param_3, int param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfAcquireResource Calling Diff


```diff
--- UdfAcquireResource calling
+++ UdfAcquireResource calling
@@ -41,0 +42 @@
+UdfMountVolume
```


## UdfTearDownSpecialScb

### Match Info



|Key|udfs-10.0.26100.8972.sys - udfs-10.0.26100.9168.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.84|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|udfs-10.0.26100.8972.sys|udfs-10.0.26100.9168.sys|
| :---: | :---: | :---: |
|name|UdfTearDownSpecialScb|UdfTearDownSpecialScb|
|fullname|UdfTearDownSpecialScb|UdfTearDownSpecialScb|
|`refcount`|12|13|
|length|165|165|
|called|NTOSKRNL.EXE::CcPurgeCacheSection<br>UdfDeleteInternalStream<br>UdfTeardownStructures|NTOSKRNL.EXE::CcPurgeCacheSection<br>UdfDeleteInternalStream<br>UdfTeardownStructures|
|`calling`|UdfFlushVolume|UdfFlushVolume<br>UdfUpdateVcbPhase0|
|paramcount|3|3|
|`address`|140055d78|1400544d8|
|sig|undefined __fastcall UdfTearDownSpecialScb(undefined8 * param_1, uint * param_2, int * param_3)|undefined __fastcall UdfTearDownSpecialScb(undefined8 * param_1, uint * param_2, int * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### UdfTearDownSpecialScb Calling Diff


```diff
--- UdfTearDownSpecialScb calling
+++ UdfTearDownSpecialScb calling
@@ -1,0 +2 @@
+UdfUpdateVcbPhase0
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-22T12:19:17</sub>