# wev_8328.dll-wev_8521.dll Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
* [Modified](#modified)
	* [ChannelConfigReader::GetMaxSize](#channelconfigreadergetmaxsize)
	* [wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState](#wildetailsfeatureimplstruct___wilfeaturetraits_feature_servicing_windiagevtnullstrgetcachedfeatureenabledstate)
	* [wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState](#wildetailsfeatureimplstruct___wilfeaturetraits_feature_testloc1perfgetcachedfeatureenabledstate)
* [Modified (No Code Changes)](#modified-no-code-changes)

# Visual Chart Diff



```mermaid

flowchart LR

ChannelConfigReaderGetMaxSize-1-old<--Match 97%-->ChannelConfigReaderGetMaxSize-1-new
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStrGetCachedFeatureEnabledState-1-old<--Match 99%-->wildetailsFeatureImplstruct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStrGetCachedFeatureEnabledState-1-new
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_TestLoc1PerfGetCachedFeatureEnabledState-1-old<--Match 99%-->wildetailsFeatureImplstruct___WilFeatureTraits_Feature_TestLoc1PerfGetCachedFeatureEnabledState-1-new

subgraph wev_8521.dll
    ChannelConfigReaderGetMaxSize-1-new
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStrGetCachedFeatureEnabledState-1-new
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_TestLoc1PerfGetCachedFeatureEnabledState-1-new
    
end

subgraph wev_8328.dll
    ChannelConfigReaderGetMaxSize-1-old
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStrGetCachedFeatureEnabledState-1-old
wildetailsFeatureImplstruct___WilFeatureTraits_Feature_TestLoc1PerfGetCachedFeatureEnabledState-1-old
    
end

```


```mermaid
pie showData
    title Function Matches - 100.0000%
"unmatched_funcs_len" : 0
"matched_funcs_len" : 9600
```



```mermaid
pie showData
    title Matched Function Similarity - 99.9688%
"matched_funcs_with_code_changes_len" : 3
"matched_funcs_with_non_code_changes_len" : 0
"matched_funcs_no_changes_len" : 9597
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --max-ram-percent 60.0 --max-section-funcs 200 wev_8328.dll wev_8521.dll
```


#### Verbose Args


<details>

```
--old ['wev_8328.dll'] --new [['wev_8521.dll']] --engine VersionTrackingDiff --output-path wev_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim False --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/wevtsvc.dll/8AF7B23D12D000/wevtsvc.dll -O wevtsvc.dll.x64.10.0.26100.8328
wget https://msdl.microsoft.com/download/symbols/wevtsvc.dll/A6FD6E2812D000/wevtsvc.dll -O wevtsvc.dll.x64.10.0.26100.8521
```


## Binary Metadata Diff


```diff
--- wev_8328.dll Meta
+++ wev_8521.dll Meta
@@ -1,44 +1,44 @@
-Program Name: wev_8328.dll
+Program Name: wev_8521.dll
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
 # of Bytes: 1236368
 # of Memory Blocks: 10
-# of Instructions: 218806
+# of Instructions: 218814
 # of Defined Data: 8985
 # of Functions: 4800
 # of Symbols: 37261
 # of Data Types: 2006
 # of Data Type Categories: 91
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sat Aug 22 11:46:12 SGT 2026
+Date Created: Sat Aug 22 11:46:16 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/wev/wev_8328.dll
-Executable MD5: b6ed3bbc52f94eda9b8883f90092b39e
-Executable SHA256: fe160d5058ae840d4d2c44d4a6e820d3a2387dfaeeed49dfee9dc970163c6740
-FSRL: file:///tmp/wev/wev_8328.dll?MD5=b6ed3bbc52f94eda9b8883f90092b39e
+Executable Location: /tmp/wev/wev_8521.dll
+Executable MD5: c079daa8027ad926e0bd4071e85b9584
+Executable SHA256: 6b5f43fa90fb415e45638ef97b56a03b9039cf3e90026dbb38c23b168e8222ef
+FSRL: file:///tmp/wev/wev_8521.dll?MD5=c079daa8027ad926e0bd4071e85b9584
 PDB Age: 1
 PDB File: wevtsvc.pdb
-PDB GUID: 1f465670-1dcf-dabe-b946-3f655716bdfe
+PDB GUID: 44a31195-29aa-5539-fe13-19ffa91bef6e
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Event Logging Service
-PE Property[FileVersion]: 10.0.26100.8328 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.8521 (WinBuild.160101.0800)
 PE Property[InternalName]: wevtsvc.dll
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: wevtsvc.dll
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.8328
+PE Property[ProductVersion]: 10.0.26100.8521
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra wev_8328.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra wev_8328.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra wev_8328.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra wev_8521.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra wev_8521.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra wev_8521.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|0|
|deleted_funcs_len|0|
|modified_funcs_len|3|
|added_symbols_len|0|
|deleted_symbols_len|0|
|diff_time|5.249670505523682|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 4646, 'ExternalsName': 391, 'BulkInstructionHash': 45, 'ExactBytesFunctionHasher': 44, 'StructuralGraphHash': 42, 'ExactInstructionsFunctionHasher': 16, 'SigCallingCalledHasher': 2})|
|items_to_process|3|
|diff_types|Counter({'code': 3, 'length': 3, 'address': 2})|
|unmatched_funcs_len|0|
|total_funcs_len|9600|
|matched_funcs_len|9600|
|matched_funcs_with_code_changes_len|3|
|matched_funcs_with_non_code_changes_len|0|
|matched_funcs_no_changes_len|9597|
|match_func_similarity_percent|99.9688%|
|func_match_overall_percent|100.0000%|
|first_matches|Counter({'SymbolsHash': 4646, 'BulkInstructionHash': 45, 'ExactBytesFunctionHasher': 44, 'StructuralGraphHash': 42, 'ExactInstructionsFunctionHasher': 16, 'SigCallingCalledHasher': 2})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 4646
"ExternalsName" : 391
"ExactBytesFunctionHasher" : 44
"ExactInstructionsFunctionHasher" : 16
"BulkInstructionHash" : 45
"SigCallingCalledHasher" : 2
"StructuralGraphHash" : 42
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 4646
"ExactBytesFunctionHasher" : 44
"ExactInstructionsFunctionHasher" : 16
"BulkInstructionHash" : 45
"SigCallingCalledHasher" : 2
"StructuralGraphHash" : 42
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 0
"deleted_funcs_len" : 0
"modified_funcs_len" : 3
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 0
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

# Modified


*Modified functions contain code changes*
## ChannelConfigReader::GetMaxSize

### Match Info



|Key|wev_8328.dll - wev_8521.dll|
| :---: | :---: |
|diff_type|code,length|
|ratio|0.23|
|i_ratio|0.8|
|m_ratio|0.98|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|wev_8328.dll|wev_8521.dll|
| :---: | :---: | :---: |
|name|GetMaxSize|GetMaxSize|
|fullname|ChannelConfigReader::GetMaxSize|ChannelConfigReader::GetMaxSize|
|refcount|3|3|
|`length`|383|399|
|called|API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegGetValueW<br>ChannelPolicy::GetProperty<br>EvtException::EvtException<br>WPP_SF_D<br>_CxxThrowException<br>tlx::transform_traits<wchar_t,struct_tlx::ascii_toupper_transform>::compare|API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegGetValueW<br>ChannelPolicy::GetProperty<br>EvtException::EvtException<br>WPP_SF_D<br>_CxxThrowException<br>tlx::transform_traits<wchar_t,struct_tlx::ascii_toupper_transform>::compare|
|calling|ChannelLogConfigData::ChannelLogConfigData<br>EventService::PutChannelConfig|ChannelLogConfigData::ChannelLogConfigData<br>EventService::PutChannelConfig|
|paramcount|1|1|
|address|18007b2f4|18007b2f4|
|sig|__uint64 __thiscall GetMaxSize(ChannelConfigReader * this)|__uint64 __thiscall GetMaxSize(ChannelConfigReader * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ChannelConfigReader::GetMaxSize Diff


```diff
--- ChannelConfigReader::GetMaxSize
+++ ChannelConfigReader::GetMaxSize
@@ -1,58 +1,65 @@
 
 /* public: unsigned __int64 __cdecl ChannelConfigReader::GetMaxSize(void)const __ptr64 */
 
 __uint64 __thiscall ChannelConfigReader::GetMaxSize(ChannelConfigReader *this)
 
 {
   uint uVar1;
   int iVar2;
   ulonglong uVar3;
-  ulonglong uVar4;
-  _EVT_VARIANT *p_Var5;
-  ulonglong uVar6;
-  wchar_t *pwVar7;
+  _EVT_VARIANT *p_Var4;
+  __uint64 _Var5;
+  wchar_t *pwVar6;
   undefined4 local_res8 [2];
   undefined4 local_res10 [2];
   DWORD local_res18 [4];
   EvtException local_48 [48];
   
-  if ((this[0x80] != (ChannelConfigReader)0x0) &&
-     (p_Var5 = ChannelPolicy::GetProperty((ChannelPolicy *)(this + 0x40),8),
-     p_Var5 != (_EVT_VARIANT *)0x0)) {
-    return *(longlong *)p_Var5 << 10;
+  if ((this[0x80] == (ChannelConfigReader)0x0) ||
+     (p_Var4 = ChannelPolicy::GetProperty((ChannelPolicy *)(this + 0x40),8),
+     p_Var4 == (_EVT_VARIANT *)0x0)) {
+    local_res10[0] = 0;
+    local_res8[0] = 0;
+    local_res18[0] = 4;
+    uVar1 = RegGetValueW(*(HKEY *)this,(LPCWSTR)0x0,L"MaxSize",0x10,(LPDWORD)0x0,local_res10,
+                         local_res18);
+    pwVar6 = L"MaxSizeUpper";
+    local_res18[0] = 4;
+    RegGetValueW(*(HKEY *)this,(LPCWSTR)0x0,L"MaxSizeUpper",0x10,(LPDWORD)0x0,local_res8,local_res18
+                );
+    if ((uVar1 & 0xfffffffd) != 0) {
+      if ((((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
+          ((*(byte *)((longlong)WPP_GLOBAL_Control + 0x1c) & 4) != 0)) &&
+         (1 < *(byte *)((longlong)WPP_GLOBAL_Control + 0x19))) {
+        pwVar6 = (wchar_t *)&WPP_80c20e6d3fe432eac0b392ff35643e12_Traceguids;
+        WPP_SF_D(WPP_GLOBAL_Control[2],0x1f,&WPP_80c20e6d3fe432eac0b392ff35643e12_Traceguids,uVar1);
+      }
+      EvtException::EvtException(local_48,uVar1,(char *)pwVar6,399);
+                    /* WARNING: Subroutine does not return */
+      _CxxThrowException(local_48,(ThrowInfo *)&_TI1_AVEvtException__);
+    }
+    _Var5 = CONCAT44(local_res8[0],local_res10[0]);
+    if ((*(longlong *)(this + 0x28) - (longlong)*(wchar_t **)(this + 0x20) == 0x10) &&
+       (iVar2 = tlx::transform_traits<wchar_t,struct_tlx::ascii_toupper_transform>::compare
+                          (*(wchar_t **)(this + 0x20),L"Security",8), iVar2 == 0)) {
+      if (_Var5 == 0) {
+        return 0x2800000;
+      }
+      uVar3 = 0x1400000;
+    }
+    else {
+      uVar3 = 0x101000;
+      if (_Var5 == 0) {
+        return 0x101000;
+      }
+    }
+    if (_Var5 < uVar3) {
+      _Var5 = uVar3;
+    }
   }
-  local_res10[0] = 0;
-  local_res8[0] = 0;
-  local_res18[0] = 4;
-  uVar1 = RegGetValueW(*(HKEY *)this,(LPCWSTR)0x0,L"MaxSize",0x10,(LPDWORD)0x0,local_res10,
-                       local_res18);
-  pwVar7 = L"MaxSizeUpper";
-  local_res18[0] = 4;
-  RegGetValueW(*(HKEY *)this,(LPCWSTR)0x0,L"MaxSizeUpper",0x10,(LPDWORD)0x0,local_res8,local_res18);
-  if ((uVar1 & 0xfffffffd) != 0) {
-    if ((((undefined8 **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
-        ((*(byte *)((longlong)WPP_GLOBAL_Control + 0x1c) & 4) != 0)) &&
-       (1 < *(byte *)((longlong)WPP_GLOBAL_Control + 0x19))) {
-      pwVar7 = (wchar_t *)&WPP_80c20e6d3fe432eac0b392ff35643e12_Traceguids;
-      WPP_SF_D(WPP_GLOBAL_Control[2],0x1f,&WPP_80c20e6d3fe432eac0b392ff35643e12_Traceguids,uVar1);
-    }
-    EvtException::EvtException(local_48,uVar1,(char *)pwVar7,399);
-                    /* WARNING: Subroutine does not return */
-    _CxxThrowException(local_48,(ThrowInfo *)&_TI1_AVEvtException__);
+  else {
+    _Var5 = *(longlong *)p_Var4 << 10;
   }
-  uVar6 = CONCAT44(local_res8[0],local_res10[0]);
-  if (*(longlong *)(this + 0x28) - (longlong)*(wchar_t **)(this + 0x20) == 0x10) {
-    iVar2 = tlx::transform_traits<wchar_t,struct_tlx::ascii_toupper_transform>::compare
-                      (*(wchar_t **)(this + 0x20),L"Security",8);
-    uVar3 = 0x1400000;
-    if (iVar2 == 0) goto LAB_0;
-  }
-  uVar3 = 0x101000;
-LAB_0:
-  uVar4 = uVar3;
-  if ((uVar6 != 0) && (uVar4 = uVar6, uVar6 < uVar3)) {
-    uVar4 = uVar3;
-  }
-  return uVar4;
+  return _Var5;
 }
 

```


## wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState

### Match Info



|Key|wev_8328.dll - wev_8521.dll|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.96|
|i_ratio|0.76|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|wev_8328.dll|wev_8521.dll|
| :---: | :---: | :---: |
|name|GetCachedFeatureEnabledState|GetCachedFeatureEnabledState|
|fullname|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState|
|refcount|3|3|
|`length`|298|302|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::ReportUsage<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::__private_IsEnabled|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::ReportUsage<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::__private_IsEnabled|
|paramcount|1|1|
|`address`|1800aa7c4|1800aa7d4|
|sig|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr> * this)|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState Diff


```diff
--- wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState
+++ wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState
@@ -1,83 +1,83 @@
 
-/* WARNING: Removing unreachable block (ram,0x0001800aa81a) */
-/* WARNING: Removing unreachable block (ram,0x0001800aa820) */
+/* WARNING: Removing unreachable block (ram,0x0001800aa82f) */
+/* WARNING: Removing unreachable block (ram,0x0001800aa834) */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 /* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
    __WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::GetCachedFeatureEnabledState(void)
    __ptr64 */
 
 void __thiscall
 wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr>::
 GetCachedFeatureEnabledState
           (FeatureImpl<struct___WilFeatureTraits_Feature_Servicing_WinDiagEvtNullStr> *this)
 
 {
   uint uVar1;
   uint uVar2;
   uint uVar3;
   uint uVar4;
   uint *in_RDX;
   bool bVar5;
   uint local_res18 [2];
   undefined *local_res20;
   undefined4 local_38;
   undefined4 local_34;
   undefined4 *local_30;
   
   in_RDX[0] = 0;
   uVar3 = Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
   in_RDX[1] = 0;
   *in_RDX = Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
   if (((byte)uVar3 & 6) == 6) {
     return;
   }
   uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
   GetCurrentFeatureEnabledState(this,(int *)local_res18);
   uVar3 = *in_RDX;
   do {
     uVar1 = uVar3;
-    *in_RDX = uVar1;
-    uVar4 = uVar1;
+    uVar4 = uVar1 | 0x40000;
+    *in_RDX = uVar4;
     if ((uVar1 & 4) == 0) {
-      uVar4 = uVar1 & 0xfffffbff | local_res18[0] & 0x400 | 4;
+      uVar4 = uVar1 & 0xfffffbff | 0x40000 | local_res18[0] & 0x400 | 4;
       *in_RDX = uVar4;
     }
     LOCK();
     bVar5 = uVar1 != Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
     uVar3 = uVar1;
     if (bVar5) {
       uVar3 = Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
       uVar4 = Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
     }
     Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState = uVar4;
     UNLOCK();
   } while (bVar5);
   if (((uVar1 & 4) != 0) || (_g_enabledStateManager == 0)) goto LAB_0;
   AcquireSRWLockExclusive((PSRWLOCK)&DAT_1);
   local_res20 = &DAT_1;
   if ((uVar2 == 0) || (uVar2 != DAT_2)) {
 LAB_3:
     LOCK();
     Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState =
          Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState & 0xfffffffb;
     UNLOCK();
   }
   else {
     local_34 = 0;
     local_38 = 3;
     local_30 = &Feature_Servicing_WinDiagEvtNullStr__private_cppFeatureState;
     bVar5 = details_abi::heap_buffer::push_back((heap_buffer *)&DAT_4,&local_38,0x10);
     if (!bVar5) goto LAB_3;
   }
   unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
   ::
   ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
             ((unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
               *)&local_res20);
 LAB_0:
   if ((*in_RDX & 2) == 0) {
     *in_RDX = *in_RDX & 0xfffff63e | local_res18[0] & 0x9c1;
   }
   return;
 }
 

```


## wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState

### Match Info



|Key|wev_8328.dll - wev_8521.dll|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.96|
|i_ratio|0.76|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|wev_8328.dll|wev_8521.dll|
| :---: | :---: | :---: |
|name|GetCachedFeatureEnabledState|GetCachedFeatureEnabledState|
|fullname|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState|
|refcount|2|2|
|`length`|298|302|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCurrentFeatureEnabledState<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::ReportUsage|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::ReportUsage|
|paramcount|1|1|
|`address`|1800aa8f8|1800aa90c|
|sig|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf> * this)|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState Diff


```diff
--- wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState
+++ wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState
@@ -1,81 +1,81 @@
 
-/* WARNING: Removing unreachable block (ram,0x0001800aa94e) */
-/* WARNING: Removing unreachable block (ram,0x0001800aa954) */
+/* WARNING: Removing unreachable block (ram,0x0001800aa967) */
+/* WARNING: Removing unreachable block (ram,0x0001800aa96c) */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 /* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
    __WilFeatureTraits_Feature_TestLoc1Perf>::GetCachedFeatureEnabledState(void) __ptr64 */
 
 void __thiscall
 wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf>::
 GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_TestLoc1Perf> *this)
 
 {
   uint uVar1;
   uint uVar2;
   uint uVar3;
   uint uVar4;
   uint *in_RDX;
   bool bVar5;
   uint local_res18 [2];
   undefined *local_res20;
   undefined4 local_38;
   undefined4 local_34;
   undefined4 *local_30;
   
   in_RDX[0] = 0;
   uVar3 = Feature_TestLoc1Perf__private_cppFeatureState;
   in_RDX[1] = 0;
   *in_RDX = Feature_TestLoc1Perf__private_cppFeatureState;
   if (((byte)uVar3 & 6) == 6) {
     return;
   }
   uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
   GetCurrentFeatureEnabledState(this,(int *)local_res18);
   uVar3 = *in_RDX;
   do {
     uVar1 = uVar3;
-    *in_RDX = uVar1;
-    uVar4 = uVar1;
+    uVar4 = uVar1 | 0x40000;
+    *in_RDX = uVar4;
     if ((uVar1 & 4) == 0) {
-      uVar4 = uVar1 & 0xfffffbff | local_res18[0] & 0x400 | 4;
+      uVar4 = uVar1 & 0xfffffbff | 0x40000 | local_res18[0] & 0x400 | 4;
       *in_RDX = uVar4;
     }
     LOCK();
     bVar5 = uVar1 != Feature_TestLoc1Perf__private_cppFeatureState;
     uVar3 = uVar1;
     if (bVar5) {
       uVar3 = Feature_TestLoc1Perf__private_cppFeatureState;
       uVar4 = Feature_TestLoc1Perf__private_cppFeatureState;
     }
     Feature_TestLoc1Perf__private_cppFeatureState = uVar4;
     UNLOCK();
   } while (bVar5);
   if (((uVar1 & 4) != 0) || (_g_enabledStateManager == 0)) goto LAB_0;
   AcquireSRWLockExclusive((PSRWLOCK)&DAT_1);
   local_res20 = &DAT_1;
   if ((uVar2 == 0) || (uVar2 != DAT_2)) {
 LAB_3:
     LOCK();
     Feature_TestLoc1Perf__private_cppFeatureState =
          Feature_TestLoc1Perf__private_cppFeatureState & 0xfffffffb;
     UNLOCK();
   }
   else {
     local_34 = 0;
     local_38 = 3;
     local_30 = &Feature_TestLoc1Perf__private_cppFeatureState;
     bVar5 = details_abi::heap_buffer::push_back((heap_buffer *)&DAT_4,&local_38,0x10);
     if (!bVar5) goto LAB_3;
   }
   unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
   ::
   ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
             ((unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
               *)&local_res20);
 LAB_0:
   if ((*in_RDX & 2) == 0) {
     *in_RDX = *in_RDX & 0xfffff63e | local_res18[0] & 0x9c1;
   }
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-22T11:47:37</sub>