# pre.exe-post.exe Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [wil::details_abi::SemaphoreValue::Destroy](#wildetails_abisemaphorevaluedestroy)
* [Added](#added)
	* [wil::details::`dynamic_initializer_for_'g_enabledStateManager''](#wildetailsdynamic_initializer_for_g_enabledstatemanager)
	* [wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''](#wildetailsdynamic_initializer_for_g_header_init_initializestagingsrumfeaturereporting)
	* [wil_details_FeatureReporting_RecordUsageInCache](#wil_details_featurereporting_recordusageincache)
	* [wil_details_StagingConfig_QueryFeatureState](#wil_details_stagingconfig_queryfeaturestate)
	* [wil_StagingConfig_QueryFeatureState](#wil_stagingconfig_queryfeaturestate)
	* [wil_QueryFeatureState](#wil_queryfeaturestate)
	* [wil::details::IsFeatureConfigured](#wildetailsisfeatureconfigured)
	* [wil::details::WilApiImpl_GetFeatureEnabledState](#wildetailswilapiimpl_getfeatureenabledstate)
	* [wil::details::WilApi_UnsubscribeFeatureStateChangeNotification](#wildetailswilapi_unsubscribefeaturestatechangenotification)
	* [wil::details::EnabledStateManager::QueueBackgroundUsageReporting](#wildetailsenabledstatemanagerqueuebackgroundusagereporting)
	* [wil::details::EnabledStateManager::OnStateChange](#wildetailsenabledstatemanageronstatechange)
	* [wil::details::EnabledStateManager::RecordCachedUsageUnderLock](#wildetailsenabledstatemanagerrecordcachedusageunderlock)
	* [wil::details::EnsureSubscribedToFeatureConfigurationChanges](#wildetailsensuresubscribedtofeatureconfigurationchanges)
	* [wil::details::SubscribeFeatureStateCacheToConfigurationChanges](#wildetailssubscribefeaturestatecachetoconfigurationchanges)
	* [<lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>](#lambda_aa194dc0bf891154933407eb98fb868alambda_invoker_cdecl)
	* [wil::details::ReportUsageToService](#wildetailsreportusagetoservice)
	* [wil::details::RecordSRUMFeatureUsage](#wildetailsrecordsrumfeatureusage)
	* [wil::details::EnabledStateManager::`scalar_deleting_destructor'](#wildetailsenabledstatemanagerscalar_deleting_destructor)
	* [wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled](#wildetailsfeatureimplstruct___wilfeaturetraits_feature_1207474488__private_isenabled)
	* [wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState](#wildetailsfeatureimplstruct___wilfeaturetraits_feature_1207474488getcachedfeatureenabledstate)
	* [<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>](#lambda_0374aa0a5d1201b2358c6bce99369c58lambda_invoker_cdecl)
	* [`wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0](#wildetailsfeaturestatemanagersubscribetoenabledstatechanges__l1dtor0)
	* [wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''](#wildetailsdynamic_atexit_destructor_for_g_enabledstatemanager)
* [Modified](#modified)
	* [wil::details::ReportFailure_GetLastError](#wildetailsreportfailure_getlasterror)
	* [wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire](#wildetails_abiprocesslocalstoragedataclass_wildetails_abifeaturestatedataacquire)
	* [wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification](#wildetailswilapiimpl_subscribefeaturestatechangenotification)
	* [wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release](#wildetails_abiprocesslocalstoragedatastruct_wildetails_abiprocesslocaldatarelease)
	* [wil::details::GetLastErrorFailHr](#wildetailsgetlasterrorfailhr)
	* [wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''](#wildetailsdynamic_initializer_for_g_header_init_initializestagingheaderinternalapi)
	* [wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release](#wildetails_abiprocesslocalstoragedataclass_wildetails_abifeaturestatedatarelease)
	* [UnregisterPathForCommonUpload](#unregisterpathforcommonupload)
	* [wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire](#wildetails_abiprocesslocalstoragedatastruct_wildetails_abiprocesslocaldataacquire)
	* [wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>](#wildetails_abisemaphorevaluetrygetvalueunsigned___int64)
	* [wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock](#wildetailsfeaturestatemanagerensuresubscribedtostatechangesunderlock)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [__GSHandlerCheck](#__gshandlercheck)
	* [QueueBackgroundSRUMUsageReporting](#queuebackgroundsrumusagereporting)
	* [GetThreadLocalDataCache](#getthreadlocaldatacache)
	* [~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>](#unique_any_tclass_wildetailsunique_storagestruct_wildetailsresource_policystruct__rtl_srwlock___ptr64void___cdeclstruct__rtl_srwlock___ptr64void___cdecl_releasesrwlockexclusivestruct__rtl_srwlock___ptr64struct_wistdintegral_constantunsigned___int641struct__rtl_srwlock___ptr64struct__rtl_srwlock___ptr640stdnullptr_t__)
	* [GetContextAndNotifyFailure](#getcontextandnotifyfailure)
	* [ReportFailure_GetLastErrorHr](#reportfailure_getlasterrorhr)
	* [KERNEL32.DLL::FormatMessageW](#kernel32dllformatmessagew)
	* [UnsubscribeWilWnf](#unsubscribewilwnf)
	* [API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer](#api-ms-win-core-threadpool-l1-2-0dllcreatethreadpooltimer)
	* [API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW](#api-ms-win-core-libraryloader-l1-2-0dllgetmodulehandlew)
	* [EnsureStateData](#ensurestatedata)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive](#api-ms-win-core-synch-l1-1-0dllreleasesrwlockexclusive)
	* [GetValueFromSemaphore](#getvaluefromsemaphore)
	* [__security_check_cookie](#__security_check_cookie)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive](#api-ms-win-core-synch-l1-1-0dllacquiresrwlockexclusive)
	* [push_back](#push_back)
	* [atexit](#atexit)
	* [wil_details_NtUpdateWnfStateData](#wil_details_ntupdatewnfstatedata)
	* [API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree](#api-ms-win-core-heap-l1-1-0dllheapfree)
	* [UnregisterWilFeatureConfigurationChange](#unregisterwilfeatureconfigurationchange)
	* [API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError](#api-ms-win-core-errorhandling-l1-1-0dllsetlasterror)
	* [RtlNtStatusToDosErrorNoTeb](#rtlntstatustodoserrornoteb)
	* [WilApiImpl_RecordFeatureUsage](#wilapiimpl_recordfeatureusage)
	* [Return_Hr](#return_hr)
	* [CreateFromPointer](#createfrompointer)
	* [WilDynamicLoadRaiseFailFastException](#wildynamicloadraisefailfastexception)
	* [reserve](#reserve)
	* [GetFailureLogString](#getfailurelogstring)
	* [EnsureTimerUnderLock](#ensuretimerunderlock)
	* [RtlDisownModuleHeapAllocation](#rtldisownmoduleheapallocation)
	* [API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError](#api-ms-win-core-errorhandling-l1-1-0dllgetlasterror)
	* [`scalar_deleting_destructor'](#scalar_deleting_destructor)
	* [CloseHandle](#closehandle)
	* [API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap](#api-ms-win-core-heap-l1-1-0dllgetprocessheap)
	* [KERNEL32.DLL::GetProcAddress](#kernel32dllgetprocaddress)
	* [RtlDllShutdownInProgress](#rtldllshutdowninprogress)
	* [EnsureSubscribedToStateChangesUnderLock](#ensuresubscribedtostatechangesunderlock)
	* [API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer](#api-ms-win-core-threadpool-l1-2-0dllsetthreadpooltimer)
	* [API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId](#api-ms-win-core-processthreads-l1-1-0dllgetcurrentthreadid)
	* [wil_details_NtQueryWnfStateData](#wil_details_ntquerywnfstatedata)
	* [API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle](#api-ms-win-core-handle-l1-1-0dllclosehandle)
	* [wil_details_StagingConfig_Load](#wil_details_stagingconfig_load)

# Visual Chart Diff



```mermaid

flowchart LR

wildetailsReportFailure_GetLastError-7-old<--Match 99%-->wildetailsReportFailure_GetLastError-7-new
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataAcquire-2-old<--Match 93%-->wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataAcquire-2-new
wildetailsWilApiImpl_SubscribeFeatureStateChangeNotification-3-old<--Match 36%-->wildetailsWilApiImpl_SubscribeFeatureStateChangeNotification-3-new
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataRelease-1-old<--Match 90%-->wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataRelease-1-new
wildetailsGetLastErrorFailHr-0-old<--Match 98%-->wildetailsGetLastErrorFailHr-0-new
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-old<--Match 88%-->wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-new
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataRelease-1-old<--Match 89%-->wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataRelease-1-new
UnregisterPathForCommonUpload-1-old<--Match 87%-->UnregisterPathForCommonUpload-1-new
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataAcquire-2-old<--Match 93%-->wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataAcquire-2-new
wildetails_abiSemaphoreValueTryGetValueunsigned___int64-3-old<--Match 91%-->wildetails_abiSemaphoreValueTryGetPointer-3-new
wildetailsFeatureStateManagerEnsureSubscribedToStateChangesUnderLock-1-old<--Match 71%-->wildetailsFeatureStateManagerSubscribeToEnabledStateChanges-1-new

subgraph post.exe
    wildetailsReportFailure_GetLastError-7-new
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataAcquire-2-new
wildetailsWilApiImpl_SubscribeFeatureStateChangeNotification-3-new
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataRelease-1-new
wildetailsGetLastErrorFailHr-0-new
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-new
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataRelease-1-new
UnregisterPathForCommonUpload-1-new
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataAcquire-2-new
wildetails_abiSemaphoreValueTryGetPointer-3-new
wildetailsFeatureStateManagerSubscribeToEnabledStateChanges-1-new
    subgraph Added
direction LR
wil-details-dynamic_initializer_for_g_enabledStateManager
    wil-details-dynamic_initializer_for_g_header_init_InitializeStagingSRUMFeatureReporting
    wil_details_FeatureReporting_RecordUsageInCache
    wil_details_StagingConfig_QueryFeatureState
    wil_StagingConfig_QueryFeatureState
    wil_QueryFeatureState
    wil-details-IsFeatureConfigured
    wil-details-WilApiImpl_GetFeatureEnabledState
    wil-details-WilApi_UnsubscribeFeatureStateChangeNotification
    wil-details-EnabledStateManager-QueueBackgroundUsageReporting
    wil-details-EnabledStateManager-OnStateChange
    wil-details-EnabledStateManager-RecordCachedUsageUnderLock
    wil-details-EnsureSubscribedToFeatureConfigurationChanges
    wil-details-SubscribeFeatureStateCacheToConfigurationChanges
    lambda_aa194dc0bf891154933407eb98fb868a-lambda_invoker_cdecl
    wil-details-ReportUsageToService
    wil-details-RecordSRUMFeatureUsage
    wil-details-EnabledStateManager-scalar_deleting_destructor
    wil-details-FeatureImplstruct___WilFeatureTraits_Feature_1207474488-__private_IsEnabled
    wil-details-FeatureImplstruct___WilFeatureTraits_Feature_1207474488-GetCachedFeatureEnabledState
    lambda_0374aa0a5d1201b2358c6bce99369c58-lambda_invoker_cdecl
    wil-details-FeatureStateManager-SubscribeToEnabledStateChanges-__l1-dtor0
    wil-details-dynamic_atexit_destructor_for_g_enabledStateManager
end
end

subgraph pre.exe
    wildetailsReportFailure_GetLastError-7-old
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataAcquire-2-old
wildetailsWilApiImpl_SubscribeFeatureStateChangeNotification-3-old
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataRelease-1-old
wildetailsGetLastErrorFailHr-0-old
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-old
wildetails_abiProcessLocalStorageDataclass_wildetails_abiFeatureStateDataRelease-1-old
UnregisterPathForCommonUpload-1-old
wildetails_abiProcessLocalStorageDatastruct_wildetails_abiProcessLocalDataAcquire-2-old
wildetails_abiSemaphoreValueTryGetValueunsigned___int64-3-old
wildetailsFeatureStateManagerEnsureSubscribedToStateChangesUnderLock-1-old
    subgraph Deleted
direction LR
wil-details_abi-SemaphoreValue-Destroy
end
end

```


```mermaid
pie showData
    title Function Matches - 96.8952%
"unmatched_funcs_len" : 24
"matched_funcs_len" : 749
```



```mermaid
pie showData
    title Matched Function Similarity - 92.2563%
"matched_funcs_with_code_changes_len" : 11
"matched_funcs_with_non_code_changes_len" : 47
"matched_funcs_no_changes_len" : 691
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj --project-name wsqmcons-59512 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 pre.exe post.exe
```


#### Verbose Args


<details>

```
--old ['pre.exe'] --new [['post.exe']] --engine VersionTrackingDiff --output-path ./out --summary False --project-location ./proj --project-name wsqmcons-59512 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/wsqmcons.exe/FF53488522000/wsqmcons.exe -O wsqmcons.exe.x64.10.0.19041.6456
wget https://msdl.microsoft.com/download/symbols/wsqmcons.exe/9C0FE7BE23000/wsqmcons.exe -O wsqmcons.exe.x64.10.0.19041.7660
```


## Binary Metadata Diff


```diff
--- pre.exe Meta
+++ post.exe Meta
@@ -1,44 +1,44 @@
-Program Name: pre.exe
+Program Name: post.exe
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 140000000
 Maximum Address: ff0000184f
-# of Bytes: 128352
+# of Bytes: 134192
 # of Memory Blocks: 9
-# of Instructions: 12300
-# of Defined Data: 1515
-# of Functions: 372
-# of Symbols: 3158
-# of Data Types: 494
+# of Instructions: 13722
+# of Defined Data: 1550
+# of Functions: 401
+# of Symbols: 3361
+# of Data Types: 507
 # of Data Type Categories: 43
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sun Aug 16 18:07:51 SGT 2026
+Date Created: Sun Aug 16 18:07:55 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/b-59512/pre.exe
-Executable MD5: 151ca0f30bbeaf41d8141e47bfca0b10
-Executable SHA256: d88eff6ef81ebf40487faf98cf992de40885e156f81eb7cf3eb1f9d34a812c7b
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/b-59512/pre.exe?MD5=151ca0f30bbeaf41d8141e47bfca0b10
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/b-59512/post.exe
+Executable MD5: 19ea20571820d68cd23f8b1e7944213f
+Executable SHA256: 209160f5f287926fac6ce000ace14b19a35e14fa72ab2598f44a7dd743b33360
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/b-59512/post.exe?MD5=19ea20571820d68cd23f8b1e7944213f
 PDB Age: 1
 PDB File: wsqmcons.pdb
-PDB GUID: b1683620-1228-c820-e268-3ab415cb2b54
+PDB GUID: 11f36b1e-a7e5-9166-9992-e746286a227d
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Windows SQM Consolidator
-PE Property[FileVersion]: 10.0.19041.6456 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.19041.7660 (WinBuild.160101.0800)
 PE Property[InternalName]: wsqmcons.exe
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: wsqmcons.exe
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.19041.6456
+PE Property[ProductVersion]: 10.0.19041.7660
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra pre.exe Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra pre.exe Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra pre.exe Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra post.exe Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra post.exe Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra post.exe Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|23|
|deleted_funcs_len|1|
|modified_funcs_len|58|
|added_symbols_len|12|
|deleted_symbols_len|1|
|diff_time|4.9318687915802|
|deleted_strings_len|1|
|added_strings_len|2|
|match_types|Counter({'SymbolsHash': 367, 'ExternalsName': 120, 'BSIM': 2, 'ExactInstructionsFunctionHasher': 1})|
|items_to_process|95|
|diff_types|Counter({'address': 56, 'length': 34, 'called': 33, 'refcount': 26, 'calling': 25, 'code': 11, 'name': 2, 'fullname': 2, 'sig': 2})|
|unmatched_funcs_len|24|
|total_funcs_len|773|
|matched_funcs_len|749|
|matched_funcs_with_code_changes_len|11|
|matched_funcs_with_non_code_changes_len|47|
|matched_funcs_no_changes_len|691|
|match_func_similarity_percent|92.2563%|
|func_match_overall_percent|96.8952%|
|first_matches|Counter({'SymbolsHash': 367, 'BSIM': 2, 'ExactInstructionsFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 367
"ExternalsName" : 120
"ExactInstructionsFunctionHasher" : 1
"BSIM" : 2
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 367
"ExactInstructionsFunctionHasher" : 1
"BSIM" : 2
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 23
"deleted_funcs_len" : 1
"modified_funcs_len" : 58
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 12
"deleted_symbols_len" : 1
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 1
"added_strings_len" : 2
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -1 +1,2 @@
-s_onecore\internal\sdk\inc\wil/St
+s_RtlQueryFeatureConfiguration
+s_onecore\internal\sdk\inc\wil\St

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_onecore\internal\sdk\inc\wil/St|1|_FailFast_Unexpected|

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_onecore\internal\sdk\inc\wil\St|1|_FailFast_Unexpected|
|s_RtlQueryFeatureConfiguration|1|wil_QueryFeatureState|

# Deleted

## wil::details_abi::SemaphoreValue::Destroy

### Function Meta



|Key|pre.exe|
| :---: | :---: |
|name|Destroy|
|fullname|wil::details_abi::SemaphoreValue::Destroy|
|refcount|3|
|length|132|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>wil::details::CloseHandle|
|calling|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release|
|paramcount|1|
|address|140007840|
|sig|void __thiscall Destroy(SemaphoreValue * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details_abi::SemaphoreValue::Destroy
+++ wil::details_abi::SemaphoreValue::Destroy
@@ -1,26 +0,0 @@
-
-/* public: void __cdecl wil::details_abi::SemaphoreValue::Destroy(void) __ptr64 */
-
-void __thiscall wil::details_abi::SemaphoreValue::Destroy(SemaphoreValue *this)
-
-{
-  void *pvVar1;
-  DWORD DVar2;
-  
-  pvVar1 = *(void **)this;
-  if (pvVar1 != (void *)0x0) {
-    DVar2 = GetLastError();
-    details::CloseHandle(pvVar1);
-    SetLastError(DVar2);
-  }
-  *(undefined8 *)this = 0;
-  pvVar1 = *(void **)(this + 8);
-  if (pvVar1 != (void *)0x0) {
-    DVar2 = GetLastError();
-    details::CloseHandle(pvVar1);
-    SetLastError(DVar2);
-  }
-  *(undefined8 *)(this + 8) = 0;
-  return;
-}
-

```


# Added

## wil::details::`dynamic_initializer_for_'g_enabledStateManager''

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|`dynamic_initializer_for_'g_enabledStateManager''|
|fullname|wil::details::`dynamic_initializer_for_'g_enabledStateManager''|
|refcount|2|
|length|12|
|called|atexit|
|calling||
|paramcount|0|
|address|140001d30|
|sig|undefined __fastcall `dynamic_initializer_for_'g_enabledStateManager''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil::details::`dynamic_initializer_for_'g_enabledStateManager''
+++ wil::details::`dynamic_initializer_for_'g_enabledStateManager''
@@ -0,0 +1,8 @@
+
+void wil::details::_dynamic_initializer_for__g_enabledStateManager__(void)
+
+{
+  atexit(_dynamic_atexit_destructor_for__g_enabledStateManager__);
+  return;
+}
+

```


## wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''|
|fullname|wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''|
|refcount|2|
|length|15|
|called||
|calling||
|paramcount|0|
|address|140001d90|
|sig|undefined __fastcall `dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''
+++ wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingSRUMFeatureReporting''
@@ -0,0 +1,9 @@
+
+void wil::details::_dynamic_initializer_for__g_header_init_InitializeStagingSRUMFeatureReporting__
+               (void)
+
+{
+  g_wil_details_RecordSRUMFeatureUsage = RecordSRUMFeatureUsage;
+  return;
+}
+

```


## wil_details_FeatureReporting_RecordUsageInCache

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|wil_details_FeatureReporting_RecordUsageInCache|
|fullname|wil_details_FeatureReporting_RecordUsageInCache|
|refcount|2|
|length|719|
|called||
|calling|wil::details::ReportUsageToService|
|paramcount|3|
|address|140005f90|
|sig|uint * __fastcall wil_details_FeatureReporting_RecordUsageInCache(uint * param_1, uint * param_2, uint param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_RecordUsageInCache
+++ wil_details_FeatureReporting_RecordUsageInCache
@@ -0,0 +1,175 @@
+
+uint * wil_details_FeatureReporting_RecordUsageInCache(uint *param_1,uint *param_2,uint param_3)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  bool bVar6;
+  
+  param_1[0] = 0;
+  param_1[1] = 0;
+  param_1[2] = 0;
+  param_1[3] = 0;
+  param_1[4] = 0;
+  param_1[5] = 0;
+  uVar5 = 1;
+  if (param_3 == 0) {
+LAB_140006186:
+    uVar3 = *param_2;
+    do {
+      uVar2 = uVar3;
+      param_1[1] = 0;
+      uVar1 = uVar2 | 1;
+      if ((uVar2 >> 0xe & 1) != (uint)(param_3 == 4)) {
+        uVar3 = uVar2 >> 5 & 0x1ff;
+        if (uVar3 != 0) {
+          param_1[1] = uVar3;
+          param_1[2] = ~-(uint)(param_3 != 0) & 4;
+          uVar1 = uVar2 & 0xffffc01f | 1;
+        }
+        uVar3 = 0;
+        if (param_3 == 4) {
+          uVar3 = 0x4000;
+        }
+        uVar1 = uVar3 | uVar1 & 0xffffbfff;
+      }
+      uVar3 = uVar1 >> 5 & 0x1ff;
+      uVar4 = uVar3 + 1;
+      if ((0x1ff < uVar4) || (uVar4 < (uVar1 >> 5 & 0x1ff))) {
+        param_1[2] = param_3;
+        param_1[1] = uVar3;
+        uVar4 = uVar5;
+      }
+      LOCK();
+      uVar3 = *param_2;
+      bVar6 = uVar2 == uVar3;
+      if (bVar6) {
+        *param_2 = uVar1 ^ (uVar4 << 5 ^ uVar1) & 0x3fe0;
+        uVar3 = uVar2;
+      }
+      UNLOCK();
+    } while (!bVar6);
+  }
+  else {
+    if (param_3 != 1) {
+      if ((int)param_3 < 2) {
+LAB_14000606d:
+        uVar3 = param_3 - 0x140;
+        if (uVar3 < 0x40) {
+          uVar1 = param_2[1];
+          do {
+            if (((uVar1 & 0x10) == 0) || (uVar2 = uVar5, (uVar1 >> 5 & 0x3f) != uVar3)) {
+              uVar2 = 0;
+            }
+            param_1[4] = uVar2;
+            LOCK();
+            uVar2 = param_2[1];
+            bVar6 = uVar1 == uVar2;
+            if (bVar6) {
+              param_2[1] = uVar1 & 0xfffff81f | (uVar3 & 0x3f) << 5 | 0x10;
+              uVar2 = uVar1;
+            }
+            uVar1 = uVar2;
+            UNLOCK();
+          } while (!bVar6);
+          if (param_1[4] != 0) {
+            return param_1;
+          }
+        }
+        param_1[3] = 0;
+        param_1[2] = param_3;
+        param_1[1] = 1;
+        return param_1;
+      }
+      if ((int)param_3 < 4) {
+LAB_140005ffa:
+        uVar3 = 0;
+        if (param_3 == 2) {
+          uVar3 = 2;
+        }
+        else if (param_3 == 3) {
+          uVar3 = 8;
+        }
+        else if (param_3 == 6) {
+          uVar3 = 4;
+        }
+        else if (param_3 == 7) {
+          uVar3 = 0x10;
+        }
+        uVar1 = *param_2;
+        do {
+          uVar4 = uVar1;
+          uVar1 = uVar3 | uVar4;
+          param_1[4] = (uint)(uVar1 == uVar4);
+          uVar2 = uVar1 | 1;
+          if (uVar1 == uVar4) {
+            uVar2 = uVar1;
+          }
+          LOCK();
+          uVar1 = *param_2;
+          bVar6 = uVar4 == uVar1;
+          if (bVar6) {
+            *param_2 = uVar2;
+            uVar1 = uVar4;
+          }
+          UNLOCK();
+        } while (!bVar6);
+        if (((uVar2 & 1) == 0) || ((uVar4 & 1) != 0)) {
+          uVar5 = 0;
+        }
+        *param_1 = uVar5;
+        return param_1;
+      }
+      if (param_3 == 4) goto LAB_140006186;
+      if (param_3 != 5) {
+        if (1 < param_3 - 6) goto LAB_14000606d;
+        goto LAB_140005ffa;
+      }
+    }
+    uVar3 = *param_2;
+    do {
+      uVar2 = uVar3;
+      param_1[1] = 0;
+      uVar1 = uVar2 | 1;
+      if ((uVar2 >> 0x16 & 1) != (uint)(param_3 == 5)) {
+        uVar3 = uVar2 >> 0xf & 0x7f;
+        if (uVar3 != 0) {
+          param_1[1] = uVar3;
+          uVar3 = uVar5;
+          if (param_3 == 1) {
+            uVar3 = 5;
+          }
+          uVar1 = uVar2 & 0xffc07fff | 1;
+          param_1[2] = uVar3;
+        }
+        uVar3 = 0;
+        if (param_3 == 5) {
+          uVar3 = 0x400000;
+        }
+        uVar1 = uVar3 | uVar1 & 0xffbfffff;
+      }
+      uVar3 = uVar1 >> 0xf & 0x7f;
+      uVar4 = uVar3 + 1;
+      if ((0x7f < uVar4) || (uVar4 < (uVar1 >> 0xf & 0x7f))) {
+        param_1[2] = param_3;
+        param_1[1] = uVar3;
+        uVar4 = uVar5;
+      }
+      LOCK();
+      uVar3 = *param_2;
+      bVar6 = uVar2 == uVar3;
+      if (bVar6) {
+        *param_2 = uVar1 ^ (uVar4 << 0xf ^ uVar1) & 0x3f8000;
+        uVar3 = uVar2;
+      }
+      UNLOCK();
+    } while (!bVar6);
+  }
+  param_1[4] = 0;
+  *param_1 = ~uVar2 & 1;
+  return param_1;
+}
+

```


## wil_details_StagingConfig_QueryFeatureState

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|wil_details_StagingConfig_QueryFeatureState|
|fullname|wil_details_StagingConfig_QueryFeatureState|
|refcount|2|
|length|437|
|called||
|calling|wil_StagingConfig_QueryFeatureState|
|paramcount|4|
|address|140006578|
|sig|undefined8 __fastcall wil_details_StagingConfig_QueryFeatureState(longlong param_1, uint * param_2, int param_3, int param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_StagingConfig_QueryFeatureState
+++ wil_details_StagingConfig_QueryFeatureState
@@ -0,0 +1,109 @@
+
+undefined8
+wil_details_StagingConfig_QueryFeatureState(longlong param_1,uint *param_2,int param_3,int param_4)
+
+{
+  uint uVar1;
+  longlong lVar2;
+  longlong lVar3;
+  undefined8 uVar4;
+  uint uVar5;
+  int *piVar6;
+  ulonglong uVar7;
+  uint uVar8;
+  undefined8 uVar9;
+  undefined8 local_38;
+  uint local_30;
+  
+  lVar2 = *(longlong *)(param_1 + 0x18);
+  lVar3 = *(longlong *)(param_1 + 0x20);
+  uVar8 = 0;
+  uVar1 = 1;
+  uVar9 = 1;
+  uVar7 = 0;
+  if (*(ushort *)(lVar2 + 4) != 0) {
+    do {
+      if (*(int *)(lVar3 + uVar7 * 0xc) == param_3) {
+        if ((param_4 == 0) || (*(int *)(param_1 + 0x30) == 0)) {
+          local_38 = *(undefined8 *)(lVar3 + uVar7 * 0xc);
+          local_30 = *(uint *)(lVar3 + 8 + uVar7 * 0xc);
+          uVar8 = uVar1;
+          if ((*(byte *)(lVar3 + 4 + uVar7 * 0xc) & 1) != 0) break;
+        }
+        else if ((*(byte *)(lVar3 + 4 + uVar7 * 0xc) & 1) == 0) {
+          local_38 = *(undefined8 *)(lVar3 + uVar7 * 0xc);
+          local_30 = *(uint *)(lVar3 + 8 + uVar7 * 0xc);
+          goto LAB_14000661e;
+        }
+      }
+      uVar5 = (int)uVar7 + 1;
+      uVar7 = (ulonglong)uVar5;
+    } while (uVar5 < *(ushort *)(lVar2 + 4));
+  }
+  uVar4 = 0;
+  if (uVar8 != 0) {
+LAB_14000661e:
+    if ((param_4 == 0) || (lVar3 = 0xc, *(int *)(param_1 + 0x30) == 0)) {
+      lVar3 = 8;
+    }
+    uVar8 = *(uint *)(lVar3 + lVar2);
+    uVar5 = local_38._4_4_;
+    if ((uVar8 & 4) != 0) {
+      uVar5 = local_38._4_4_ & 0xffffcfff;
+    }
+    if ((uVar8 & 2) != 0) {
+      uVar5 = uVar5 & 0xfffff3ff;
+    }
+    if ((uVar8 & 1) != 0) {
+      uVar5 = uVar5 & 0xfffffcff;
+    }
+    if ((uVar8 & 8) != 0) {
+      uVar5 = uVar5 & 0xc0ffffff;
+      local_30 = 0;
+    }
+    if ((int)local_38 != 0) {
+      if (((((uVar5 >> 0xc | uVar5 >> 10 | uVar5 >> 8) & 3) != 0) || ((uVar5 & 0x3f000000) != 0)) ||
+         ((uVar5 & 2) != 0)) {
+        param_2[3] = local_30;
+        param_2[2] = uVar5 >> 0x1e;
+        *(byte *)(param_2 + 1) = (byte)(uVar5 >> 0x18) & 0x3f;
+        param_2[5] = uVar5 >> 1 & 1;
+        uVar8 = uVar5 >> 0xc & 3;
+        uVar4 = uVar9;
+        if (uVar8 == 0) {
+          uVar8 = uVar5 >> 10 & 3;
+          if (uVar8 == 0) {
+            uVar8 = uVar5 >> 8 & 3;
+            if (uVar8 != 0) {
+              *param_2 = uVar8;
+            }
+          }
+          else {
+            *param_2 = uVar8;
+          }
+        }
+        else {
+          *param_2 = uVar8;
+        }
+        goto LAB_1400066e5;
+      }
+    }
+    uVar4 = 0;
+  }
+LAB_1400066e5:
+  uVar5 = 0;
+  piVar6 = *(int **)(param_1 + 0x28);
+  uVar8 = 0;
+  if (*(ushort *)(lVar2 + 6) != 0) {
+    do {
+      uVar8 = uVar1;
+      if (*piVar6 == param_3) break;
+      uVar5 = uVar5 + 1;
+      piVar6 = piVar6 + 4;
+      uVar8 = 0;
+    } while (uVar5 < *(ushort *)(lVar2 + 6));
+  }
+  param_2[4] = uVar8;
+  return uVar4;
+}
+

```


## wil_StagingConfig_QueryFeatureState

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|wil_StagingConfig_QueryFeatureState|
|fullname|wil_StagingConfig_QueryFeatureState|
|refcount|2|
|length|346|
|called|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>__security_check_cookie<br>wil_details_StagingConfig_Load<br>wil_details_StagingConfig_QueryFeatureState|
|calling|wil_QueryFeatureState|
|paramcount|5|
|address|1400068e0|
|sig|undefined4 __fastcall wil_StagingConfig_QueryFeatureState(undefined4 param_1, uint * param_2, undefined8 param_3, int param_4, uint * param_5)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_StagingConfig_QueryFeatureState
+++ wil_StagingConfig_QueryFeatureState
@@ -0,0 +1,69 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+
+undefined4
+wil_StagingConfig_QueryFeatureState
+          (undefined4 param_1,uint *param_2,undefined8 param_3,int param_4,uint *param_5)
+
+{
+  ushort uVar1;
+  int iVar2;
+  undefined4 uVar3;
+  undefined8 uVar4;
+  HANDLE hHeap;
+  uint uVar5;
+  uint uVar6;
+  uint uVar7;
+  uint *puVar8;
+  undefined1 auStack_198 [48];
+  undefined4 local_168 [6];
+  longlong local_150;
+  longlong local_148;
+  LPVOID local_130;
+  int local_118;
+  char local_108 [208];
+  ulonglong local_38;
+  
+  local_38 = __security_cookie ^ (ulonglong)auStack_198;
+  uVar3 = 0;
+  iVar2 = wil_details_StagingConfig_Load(local_168,param_1,param_3,local_108);
+  if (iVar2 == 0) {
+    uVar4 = wil_details_StagingConfig_QueryFeatureState
+                      ((longlong)local_168,param_2,(int)param_3,param_4);
+    uVar3 = (undefined4)uVar4;
+    if (param_5 != (uint *)0x0) {
+      uVar5 = 1;
+      uVar7 = 0;
+      uVar1 = *(ushort *)(local_150 + 4);
+      if (uVar1 != 0) {
+        puVar8 = (uint *)(local_148 + 4);
+        do {
+          if ((puVar8[-1] != 0) &&
+             (((((*puVar8 & 0x300) != 0 || ((*puVar8 & 0xc00) != 0)) || ((*puVar8 & 0x3000) != 0))
+              || (((*puVar8 & 0x3f000000) != 0 || ((*puVar8 & 2) != 0)))))) {
+            if ((*puVar8 & 1) != 0) goto LAB_1400069e2;
+            uVar6 = 0;
+            while ((uVar6 == uVar7 || (puVar8[-1] != *(uint *)(local_148 + (ulonglong)uVar6 * 0xc)))
+                  ) {
+              uVar6 = uVar6 + 1;
+              if (uVar1 <= uVar6) goto LAB_1400069e2;
+            }
+          }
+          uVar7 = uVar7 + 1;
+          puVar8 = puVar8 + 3;
+        } while (uVar7 < uVar1);
+      }
+      if (*(short *)(local_150 + 6) == 0) {
+        uVar5 = 0;
+      }
+LAB_1400069e2:
+      *param_5 = *param_5 | uVar5;
+    }
+    if (local_118 != 0) {
+      hHeap = GetProcessHeap();
+      HeapFree(hHeap,0,local_130);
+    }
+  }
+  return uVar3;
+}
+

```


## wil_QueryFeatureState

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|wil_QueryFeatureState|
|fullname|wil_QueryFeatureState|
|refcount|3|
|length|369|
|called|GetModuleHandleW<br>GetProcAddress<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil_StagingConfig_QueryFeatureState|
|calling|wil::details::IsFeatureConfigured|
|paramcount|6|
|address|140006a44|
|sig|int __fastcall wil_QueryFeatureState(uint * param_1, uint param_2, int param_3, undefined4 param_4, uint * param_5, undefined4 * param_6)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_QueryFeatureState
+++ wil_QueryFeatureState
@@ -0,0 +1,60 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* WARNING: Exceeded maximum restarts with more pending */
+
+int wil_QueryFeatureState
+              (uint *param_1,uint param_2,int param_3,undefined4 param_4,uint *param_5,
+              undefined4 *param_6)
+
+{
+  int iVar1;
+  int iVar2;
+  undefined1 auStackY_88 [32];
+  undefined1 local_58 [8];
+  undefined8 local_50;
+  uint local_48;
+  ulonglong local_40;
+  
+  local_40 = __security_cookie ^ (ulonglong)auStackY_88;
+  if (param_5 != (uint *)0x0) {
+    *param_5 = 0;
+  }
+  *param_6 = 1;
+  iVar2 = 0;
+  local_50 = 0;
+  local_48 = 0;
+  if (g_wil_details_pfnRtlQueryFeatureConfiguration == (FARPROC)0x0) {
+    if (g_wil_details_ntdllModuleHandle == (HINSTANCE__ *)0x0) {
+      g_wil_details_ntdllModuleHandle = GetModuleHandleW(L"ntdll.dll");
+    }
+    g_wil_details_pfnRtlQueryFeatureConfiguration =
+         GetProcAddress(g_wil_details_ntdllModuleHandle,"RtlQueryFeatureConfiguration");
+    if (g_wil_details_pfnRtlQueryFeatureConfiguration == (FARPROC)0x0) {
+      iVar1 = -0x3ffffec7;
+      goto LAB_140006b08;
+    }
+  }
+  iVar1 = (*g_wil_details_pfnRtlQueryFeatureConfiguration)(param_2,param_3 == 0,local_58,&local_50);
+LAB_140006b08:
+  if (iVar1 == 0) {
+    iVar2 = 1;
+    param_1[3] = local_48;
+    param_1[2] = local_50._4_4_ >> 0xe & 3;
+    *param_1 = local_50._4_4_ >> 4 & 3;
+    *(byte *)(param_1 + 1) = (byte)((ulonglong)local_50 >> 0x28) & 0x3f;
+    param_1[4] = local_50._4_4_ >> 7 & 1;
+    param_1[5] = local_50._4_4_ >> 6 & 1;
+  }
+  else if (iVar1 == 0x117) {
+    param_1[4] = local_50._4_4_ >> 7 & 1;
+  }
+  if (param_5 != (uint *)0x0) {
+    *param_5 = (uint)(iVar1 != -0x7fffffde);
+  }
+  if (iVar2 == 0) {
+    iVar2 = wil_StagingConfig_QueryFeatureState(param_4,param_1,(ulonglong)param_2,param_3,param_5);
+  }
+  return iVar2;
+}
+

```


## wil::details::IsFeatureConfigured

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|IsFeatureConfigured|
|fullname|wil::details::IsFeatureConfigured|
|refcount|2|
|length|242|
|called|wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::SubscribeFeatureStateCacheToConfigurationChanges<br>wil_QueryFeatureState|
|calling|wil::details::WilApiImpl_GetFeatureEnabledState|
|paramcount|5|
|address|140009ca8|
|sig|bool __cdecl IsFeatureConfigured(wil_FeatureState * param_1, uint param_2, bool param_3, wil_FeatureStore param_4, int * param_5)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::IsFeatureConfigured
+++ wil::details::IsFeatureConfigured
@@ -0,0 +1,51 @@
+
+/* bool __cdecl wil::details::IsFeatureConfigured(struct wil_FeatureState * __ptr64,unsigned
+   int,bool,enum wil_FeatureStore,int * __ptr64) */
+
+bool __cdecl
+wil::details::IsFeatureConfigured
+          (wil_FeatureState *param_1,uint param_2,bool param_3,wil_FeatureStore param_4,int *param_5
+          )
+
+{
+  uint uVar1;
+  uint uVar2;
+  int iVar3;
+  wil_details_FeatureStateCache *pwVar4;
+  bool bVar5;
+  uint local_res20 [2];
+  
+  pwVar4 = &`bool___cdecl_wil::details::IsFeatureConfigured(struct_wil_FeatureState*___ptr64,unsigned_int,bool,enum_wil_FeatureStore,int*___ptr64)'
+            ::__l2::userStoreProbe;
+  if (param_4 == 0) {
+    pwVar4 = &`bool___cdecl_wil::details::IsFeatureConfigured(struct_wil_FeatureState*___ptr64,unsigned_int,bool,enum_wil_FeatureStore,int*___ptr64)'
+              ::__l2::machineStoreProbe;
+  }
+  uVar1 = *(uint *)pwVar4 & 2;
+  if ((uVar1 == 0) || ((*(uint *)pwVar4 & 1) != 0)) {
+    if (uVar1 == 0) {
+      local_res20[0] = 1;
+      uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
+      iVar3 = wil_QueryFeatureState
+                        ((uint *)param_1,param_2,(uint)param_3,param_4,local_res20,param_5);
+      bVar5 = iVar3 != 0;
+      LOCK();
+      uVar1 = *(uint *)pwVar4;
+      *(uint *)pwVar4 = (local_res20[0] != 0) + 6;
+      UNLOCK();
+      if ((local_res20[0] == 0) && ((uVar1 & 4) == 0)) {
+        SubscribeFeatureStateCacheToConfigurationChanges(pwVar4,0,uVar2);
+      }
+    }
+    else {
+      iVar3 = wil_QueryFeatureState
+                        ((uint *)param_1,param_2,(uint)param_3,param_4,(uint *)0x0,param_5);
+      bVar5 = iVar3 != 0;
+    }
+  }
+  else {
+    bVar5 = false;
+  }
+  return bVar5;
+}
+

```


## wil::details::WilApiImpl_GetFeatureEnabledState

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|WilApiImpl_GetFeatureEnabledState|
|fullname|wil::details::WilApiImpl_GetFeatureEnabledState|
|refcount|3|
|length|101|
|called|wil::details::IsFeatureConfigured|
|calling||
|paramcount|3|
|address|140009db0|
|sig|FEATURE_ENABLED_STATE __cdecl WilApiImpl_GetFeatureEnabledState(uint param_1, FEATURE_CHANGE_TIME param_2, int * param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::WilApiImpl_GetFeatureEnabledState
+++ wil::details::WilApiImpl_GetFeatureEnabledState
@@ -0,0 +1,34 @@
+
+/* enum FEATURE_ENABLED_STATE __cdecl wil::details::WilApiImpl_GetFeatureEnabledState(unsigned
+   int,enum FEATURE_CHANGE_TIME,int * __ptr64) */
+
+FEATURE_ENABLED_STATE __cdecl
+wil::details::WilApiImpl_GetFeatureEnabledState
+          (uint param_1,FEATURE_CHANGE_TIME param_2,int *param_3)
+
+{
+  bool bVar1;
+  FEATURE_ENABLED_STATE FVar2;
+  FEATURE_ENABLED_STATE local_28 [10];
+  
+  local_28[0] = 0;
+  local_28[1] = 0;
+  local_28[2] = 0;
+  local_28[3] = 0;
+  local_28[4] = 0;
+  local_28[5] = 0;
+  bVar1 = IsFeatureConfigured((wil_FeatureState *)local_28,param_1,(param_2 & 0xffffff7f) - 2 < 2,
+                              param_2 >> 7 & 1,param_3);
+  FVar2 = 0;
+  if (bVar1) {
+    FVar2 = local_28[0];
+  }
+  if (local_28[4] != 0) {
+    FVar2 = FVar2 | 0x80;
+  }
+  if (local_28[5] != 0) {
+    FVar2 = FVar2 | 0x40;
+  }
+  return FVar2;
+}
+

```


## wil::details::WilApi_UnsubscribeFeatureStateChangeNotification

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|WilApi_UnsubscribeFeatureStateChangeNotification|
|fullname|wil::details::WilApi_UnsubscribeFeatureStateChangeNotification|
|refcount|3|
|length|39|
|called|_guard_dispatch_icall|
|calling|wil::details::EnabledStateManager::`scalar_deleting_destructor'|
|paramcount|1|
|address|14000a098|
|sig|void __cdecl WilApi_UnsubscribeFeatureStateChangeNotification(FEATURE_STATE_CHANGE_SUBSCRIPTION__ * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
+++ wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
@@ -0,0 +1,21 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* void __cdecl wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64) */
+
+void __cdecl
+wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
+          (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *param_1)
+
+{
+  code *pcVar1;
+  
+  pcVar1 = (code *)g_wil_details_internalUnsubscribeFeatureStateChangeNotification;
+  if ((g_wil_details_internalUnsubscribeFeatureStateChangeNotification != 0) ||
+     (pcVar1 = (code *)g_wil_details_apiUnsubscribeFeatureStateChangeNotification,
+     g_wil_details_apiUnsubscribeFeatureStateChangeNotification != 0)) {
+    (*pcVar1)();
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::QueueBackgroundUsageReporting

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|QueueBackgroundUsageReporting|
|fullname|wil::details::EnabledStateManager::QueueBackgroundUsageReporting|
|refcount|2|
|length|344|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer<br>GetLastError<br>_guard_dispatch_icall<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::ReportUsageToService|
|paramcount|3|
|address|14000a0c8|
|sig|void __thiscall QueueBackgroundUsageReporting(EnabledStateManager * this, uint param_1, wil_details_FeatureReportingCache * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::QueueBackgroundUsageReporting
+++ wil::details::EnabledStateManager::QueueBackgroundUsageReporting
@@ -0,0 +1,70 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* WARNING: Exceeded maximum restarts with more pending */
+/* public: void __cdecl wil::details::EnabledStateManager::QueueBackgroundUsageReporting(unsigned
+   int,struct wil_details_FeatureReportingCache * __ptr64) __ptr64 */
+
+void __thiscall
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
+          (EnabledStateManager *this,uint param_1,wil_details_FeatureReportingCache *param_2)
+
+{
+  EnabledStateManager *SRWLock;
+  _TP_TIMER *p_Var1;
+  char cVar2;
+  DWORD dwErrCode;
+  DWORD dwErrCode_00;
+  PTP_TIMER p_Var3;
+  undefined4 in_register_00000014;
+  _FILETIME local_res8;
+  undefined4 local_28 [2];
+  wil_details_FeatureReportingCache *local_20;
+  
+  if (*this == (EnabledStateManager)0x0) {
+    return;
+  }
+  if (g_processShutdownInProgress) {
+    return;
+  }
+  cVar2 = '\0';
+  if (g_pfnDllShutdownInProgress != (_func_uchar *)0x0) {
+    cVar2 = (*g_pfnDllShutdownInProgress)(this,CONCAT44(in_register_00000014,param_1));
+  }
+  if (cVar2 != '\0') {
+    return;
+  }
+  SRWLock = this + 8;
+  AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
+  local_28[0] = 0x37aa04f;
+  local_20 = param_2;
+  details_abi::heap_buffer::push_back((heap_buffer *)(this + 0x30),local_28,0x10);
+  if (this[0x18] == (EnabledStateManager)0x0) {
+    p_Var3 = *(PTP_TIMER *)(this + 0x10);
+    if (p_Var3 == (PTP_TIMER)0x0) {
+      dwErrCode = GetLastError();
+      p_Var3 = CreateThreadpoolTimer
+                         (<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>,this,
+                          (PTP_CALLBACK_ENVIRON)0x0);
+      p_Var1 = *(_TP_TIMER **)(this + 0x10);
+      if (p_Var1 != (_TP_TIMER *)0x0) {
+        dwErrCode_00 = GetLastError();
+        DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(p_Var1);
+        SetLastError(dwErrCode_00);
+      }
+      *(PTP_TIMER *)(this + 0x10) = p_Var3;
+      SetLastError(dwErrCode);
+      p_Var3 = *(PTP_TIMER *)(this + 0x10);
+      if (p_Var3 == (PTP_TIMER)0x0) goto LAB_14000a1f3;
+    }
+    local_res8.dwLowDateTime = 0x4d2fa200;
+    local_res8.dwHighDateTime = 0xffffffff;
+    SetThreadpoolTimer(p_Var3,&local_res8,0,75000);
+    this[0x18] = (EnabledStateManager)0x1;
+  }
+LAB_14000a1f3:
+  if (SRWLock != (EnabledStateManager *)0x0) {
+    ReleaseSRWLockExclusive((PSRWLOCK)SRWLock);
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::OnStateChange

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|OnStateChange|
|fullname|wil::details::EnabledStateManager::OnStateChange|
|refcount|2|
|length|140|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|
|calling||
|paramcount|1|
|address|14000a228|
|sig|void __thiscall OnStateChange(EnabledStateManager * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::OnStateChange
+++ wil::details::EnabledStateManager::OnStateChange
@@ -0,0 +1,33 @@
+
+/* public: void __cdecl wil::details::EnabledStateManager::OnStateChange(void) __ptr64 */
+
+void __thiscall wil::details::EnabledStateManager::OnStateChange(EnabledStateManager *this)
+
+{
+  EnabledStateManager *SRWLock;
+  int *piVar1;
+  int iVar2;
+  int *piVar3;
+  
+  if (*this != (EnabledStateManager)0x0) {
+    SRWLock = this + 8;
+    AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
+    piVar1 = *(int **)(this + 0x58);
+    for (piVar3 = *(int **)(this + 0x50); piVar3 != piVar1; piVar3 = piVar3 + 4) {
+      LOCK();
+      **(uint **)(piVar3 + 2) = **(uint **)(piVar3 + 2) & (-(uint)(*piVar3 != 0) & 0x83a) - 0x83f;
+      UNLOCK();
+    }
+    *(undefined8 *)(this + 0x58) = *(undefined8 *)(this + 0x50);
+    iVar2 = 1;
+    if (*(int *)(this + 0x1c) + 1 != 0) {
+      iVar2 = *(int *)(this + 0x1c) + 1;
+    }
+    *(int *)(this + 0x1c) = iVar2;
+    if (SRWLock != (EnabledStateManager *)0x0) {
+      ReleaseSRWLockExclusive((PSRWLOCK)SRWLock);
+    }
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::RecordCachedUsageUnderLock

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|RecordCachedUsageUnderLock|
|fullname|wil::details::EnabledStateManager::RecordCachedUsageUnderLock|
|refcount|5|
|length|541|
|called|__security_check_cookie<br>_guard_dispatch_icall|
|calling|<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl><br><lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::`scalar_deleting_destructor'<br>wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|paramcount|1|
|address|14000a2cc|
|sig|void __thiscall RecordCachedUsageUnderLock(EnabledStateManager * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::RecordCachedUsageUnderLock
+++ wil::details::EnabledStateManager::RecordCachedUsageUnderLock
@@ -0,0 +1,135 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* private: void __cdecl wil::details::EnabledStateManager::RecordCachedUsageUnderLock(void) __ptr64
+    */
+
+void __thiscall
+wil::details::EnabledStateManager::RecordCachedUsageUnderLock(EnabledStateManager *this)
+
+{
+  undefined4 uVar1;
+  undefined4 *puVar2;
+  uint *puVar3;
+  uint uVar4;
+  ulonglong uVar5;
+  code *pcVar6;
+  uint uVar7;
+  uint uVar8;
+  undefined4 *puVar9;
+  code *pcVar10;
+  uint uVar11;
+  ulonglong *puVar12;
+  bool bVar13;
+  undefined1 auStack_b8 [48];
+  ulonglong local_88;
+  undefined8 local_78;
+  undefined4 local_70;
+  uint local_6c;
+  undefined4 local_68;
+  uint local_64;
+  undefined4 local_60;
+  uint local_5c;
+  undefined4 local_58;
+  uint local_54;
+  undefined4 local_50;
+  uint local_4c;
+  undefined4 local_48;
+  uint local_44;
+  undefined4 local_40;
+  uint local_3c;
+  ulonglong local_38;
+  
+  local_38 = __security_cookie ^ (ulonglong)auStack_b8;
+  puVar2 = *(undefined4 **)(this + 0x38);
+  puVar9 = *(undefined4 **)(this + 0x30);
+  pcVar6 = (code *)g_wil_details_internalRecordFeatureUsage;
+  pcVar10 = (code *)g_wil_details_apiRecordFeatureUsage;
+  if (0xf < (ulonglong)((longlong)puVar2 - (longlong)puVar9)) {
+    for (; puVar9 != puVar2; puVar9 = puVar9 + 4) {
+      puVar3 = *(uint **)(puVar9 + 2);
+      uVar1 = *puVar9;
+      uVar4 = *puVar3;
+      do {
+        LOCK();
+        uVar8 = *puVar3;
+        bVar13 = uVar4 == uVar8;
+        if (bVar13) {
+          *puVar3 = uVar4 & 0xffc0401e;
+          uVar8 = uVar4;
+        }
+        uVar4 = uVar8;
+        UNLOCK();
+      } while (!bVar13);
+      uVar7 = uVar4 >> 1 & 0xf;
+      uVar8 = 0;
+      if (uVar7 != 0) {
+        uVar8 = puVar3[1];
+        do {
+          LOCK();
+          uVar11 = puVar3[1];
+          bVar13 = uVar8 == uVar11;
+          if (bVar13) {
+            puVar3[1] = uVar8 | uVar7;
+            uVar11 = uVar8;
+          }
+          uVar8 = uVar11;
+          UNLOCK();
+        } while (!bVar13);
+        uVar8 = uVar7 & ~uVar8;
+      }
+      puVar12 = &local_78;
+      local_78._0_4_ = 2;
+      local_78._4_4_ = uVar8 & 1;
+      uVar7 = uVar4 >> 5 & 0x1ff;
+      local_70 = 6;
+      local_6c = uVar8 >> 1 & 1;
+      uVar11 = 0;
+      local_68 = 3;
+      local_64 = uVar8 >> 2 & 1;
+      local_5c = uVar8 >> 3;
+      local_60 = 7;
+      local_58 = 0;
+      local_54 = uVar7;
+      if ((uVar4 & 0x4000) != 0) {
+        local_54 = 0;
+      }
+      local_50 = 4;
+      local_48 = 1;
+      local_40 = 5;
+      uVar8 = uVar4 >> 0xf & 0x7f;
+      local_4c = -(uint)((uVar4 & 0x4000) != 0) & uVar7;
+      local_44 = uVar8;
+      if ((uVar4 & 0x400000) != 0) {
+        local_44 = 0;
+      }
+      local_3c = -(uint)((uVar4 & 0x400000) != 0) & uVar8;
+      pcVar10 = (code *)g_wil_details_apiRecordFeatureUsage;
+      pcVar6 = (code *)g_wil_details_internalRecordFeatureUsage;
+      do {
+        local_88 = *puVar12;
+        uVar5 = local_88 >> 0x20;
+        uVar4 = (uint)(local_88 >> 0x20);
+        if (uVar4 != 0) {
+          if (pcVar6 == (code *)0x0) {
+            if (pcVar10 == (code *)0x0) goto LAB_14000a465;
+            uVar5 = (ulonglong)uVar4;
+            pcVar6 = pcVar10;
+          }
+          (*pcVar6)(uVar1,local_88 & 0xffffffff,uVar5,0);
+          pcVar10 = (code *)g_wil_details_apiRecordFeatureUsage;
+          pcVar6 = (code *)g_wil_details_internalRecordFeatureUsage;
+        }
+LAB_14000a465:
+        uVar11 = uVar11 + 1;
+        puVar12 = puVar12 + 1;
+      } while (uVar11 < 8);
+    }
+    *(undefined8 *)(this + 0x38) = *(undefined8 *)(this + 0x30);
+    if ((pcVar6 != (code *)0x0) || (pcVar6 = pcVar10, pcVar10 != (code *)0x0)) {
+      (*pcVar6)(0,0xfe,0,0);
+    }
+  }
+  return;
+}
+

```


## wil::details::EnsureSubscribedToFeatureConfigurationChanges

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|EnsureSubscribedToFeatureConfigurationChanges|
|fullname|wil::details::EnsureSubscribedToFeatureConfigurationChanges|
|refcount|3|
|length|199|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>_guard_dispatch_icall|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState<br>wil::details::IsFeatureConfigured|
|paramcount|0|
|address|14000a4f0|
|sig|uint __cdecl EnsureSubscribedToFeatureConfigurationChanges(void)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnsureSubscribedToFeatureConfigurationChanges
+++ wil::details::EnsureSubscribedToFeatureConfigurationChanges
@@ -0,0 +1,41 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* unsigned int __cdecl wil::details::EnsureSubscribedToFeatureConfigurationChanges(void) */
+
+uint __cdecl wil::details::EnsureSubscribedToFeatureConfigurationChanges(void)
+
+{
+  code *pcVar1;
+  uint uVar2;
+  
+  if (DAT_14001323c != 0) {
+    return DAT_14001323c;
+  }
+  if (g_enabledStateManager == (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0)
+  {
+LAB_14000a5a0:
+    uVar2 = 0;
+  }
+  else {
+    AcquireSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+    if (DAT_140013240 == 0) {
+      DAT_140013240 = 0;
+      pcVar1 = (code *)g_wil_details_internalSubscribeFeatureStateChangeNotification;
+      if ((g_wil_details_internalSubscribeFeatureStateChangeNotification != 0) ||
+         (pcVar1 = (code *)g_wil_details_apiSubscribeFeatureStateChangeNotification,
+         g_wil_details_apiSubscribeFeatureStateChangeNotification != 0)) {
+        (*pcVar1)(&DAT_140013240,<lambda_fee8cea507d2413a58be13acfb66740a>::<lambda_invoker_cdecl>,
+                  &g_enabledStateManager);
+      }
+      if (DAT_140013240 == 0) {
+        ReleaseSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+        goto LAB_14000a5a0;
+      }
+      DAT_14001323c = 1;
+    }
+    uVar2 = DAT_14001323c;
+    ReleaseSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+  }
+  return uVar2;
+}
+

```


## wil::details::SubscribeFeatureStateCacheToConfigurationChanges

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|SubscribeFeatureStateCacheToConfigurationChanges|
|fullname|wil::details::SubscribeFeatureStateCacheToConfigurationChanges|
|refcount|3|
|length|153|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState<br>wil::details::IsFeatureConfigured|
|paramcount|3|
|address|14000a5c0|
|sig|void __cdecl SubscribeFeatureStateCacheToConfigurationChanges(wil_details_FeatureStateCache * param_1, wil_FeatureChangeTime param_2, uint param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::SubscribeFeatureStateCacheToConfigurationChanges
+++ wil::details::SubscribeFeatureStateCacheToConfigurationChanges
@@ -0,0 +1,30 @@
+
+/* void __cdecl wil::details::SubscribeFeatureStateCacheToConfigurationChanges(union
+   wil_details_FeatureStateCache * __ptr64,enum wil_FeatureChangeTime,unsigned int) */
+
+void __cdecl
+wil::details::SubscribeFeatureStateCacheToConfigurationChanges
+          (wil_details_FeatureStateCache *param_1,wil_FeatureChangeTime param_2,uint param_3)
+
+{
+  bool bVar1;
+  wil_FeatureChangeTime local_18 [2];
+  wil_details_FeatureStateCache *local_10;
+  
+  if (g_enabledStateManager != (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0)
+  {
+    AcquireSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+    if (((param_3 == 0) || (param_3 != DAT_14001323c)) ||
+       (local_18[0] = param_2, local_10 = param_1,
+       bVar1 = details_abi::heap_buffer::push_back((heap_buffer *)&DAT_140013270,local_18,0x10),
+       !bVar1)) {
+      LOCK();
+      *(uint *)param_1 = *(uint *)param_1 & (-(uint)(param_2 != 0) & 0x83a) - 0x83f;
+      UNLOCK();
+    }
+    ReleaseSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+    return;
+  }
+  return;
+}
+

```


## <lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|<lambda_invoker_cdecl>|
|fullname|<lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>|
|refcount|3|
|length|75|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>wil::details::EnabledStateManager::RecordCachedUsageUnderLock|
|calling||
|paramcount|1|
|address|14000a660|
|sig|void __cdecl <lambda_invoker_cdecl>(void * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- <lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>
+++ <lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>
@@ -0,0 +1,18 @@
+
+/* private: static void __cdecl
+   <lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>(void * __ptr64) */
+
+void __cdecl <lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>(void *param_1)
+
+{
+  if (wil::details::g_enabledStateManager !=
+      (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0) {
+    AcquireSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+    wil::details::EnabledStateManager::RecordCachedUsageUnderLock
+              ((EnabledStateManager *)&wil::details::g_enabledStateManager);
+    DAT_140013238 = 0;
+    ReleaseSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+  }
+  return;
+}
+

```


## wil::details::ReportUsageToService

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|ReportUsageToService|
|fullname|wil::details::ReportUsageToService|
|refcount|2|
|length|658|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>_guard_dispatch_icall<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled|
|paramcount|8|
|address|14000a6b4|
|sig|void __cdecl ReportUsageToService(wil_details_FeatureReportingCache * param_1, uint param_2, int param_3, int param_4, FEATURE_LOGGED_TRAITS * param_5, int param_6, wil_ReportingKind param_7, __uint64 param_8)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::ReportUsageToService
+++ wil::details::ReportUsageToService
@@ -0,0 +1,118 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* void __cdecl wil::details::ReportUsageToService(struct wil_details_FeatureReportingCache *
+   __ptr64,unsigned int,int,int,struct FEATURE_LOGGED_TRAITS const * __ptr64,int,enum
+   wil_ReportingKind,unsigned __int64) */
+
+void __cdecl
+wil::details::ReportUsageToService
+          (wil_details_FeatureReportingCache *param_1,uint param_2,int param_3,int param_4,
+          FEATURE_LOGGED_TRAITS *param_5,int param_6,wil_ReportingKind param_7,__uint64 param_8)
+
+{
+  undefined8 uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint *puVar5;
+  code *pcVar6;
+  uint uVar7;
+  uint uVar9;
+  undefined4 in_register_0000008c;
+  byte bVar10;
+  int local_38;
+  uint local_30 [6];
+  wil_details_FeatureReportingCache *pwVar8;
+  
+  if (param_6 != 0) {
+    if (param_6 == 1) {
+      uVar9 = ~-(uint)((int)param_5 != 0) & 4;
+      goto LAB_14000a797;
+    }
+    if (param_6 == 2) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xfffffffc) + 5;
+      goto LAB_14000a797;
+    }
+    if (param_6 == 3) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xfffffffc) + 6;
+      goto LAB_14000a797;
+    }
+    if (param_6 == 4) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xfffffffc) + 7;
+      goto LAB_14000a797;
+    }
+    if (param_6 == 5) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xfffffffe) + 10;
+      goto LAB_14000a797;
+    }
+    if (param_6 == 6) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xfffffffe) + 0xb;
+      goto LAB_14000a797;
+    }
+    bVar10 = (char)param_6 + 0x9c;
+    if (bVar10 < 0x32) {
+      uVar9 = (-(uint)((int)param_5 != 0) & 0xffffffce) + 0x96 + (uint)bVar10;
+      goto LAB_14000a797;
+    }
+  }
+  uVar9 = 0xff;
+LAB_14000a797:
+  pwVar8 = param_1;
+  puVar5 = wil_details_FeatureReporting_RecordUsageInCache(local_30,(uint *)param_1,uVar9);
+  uVar7 = (uint)pwVar8;
+  uVar2 = *puVar5;
+  uVar3 = puVar5[1];
+  uVar4 = puVar5[2];
+  uVar1 = *(undefined8 *)(puVar5 + 4);
+  if ((g_wil_details_RecordSRUMFeatureUsage != 0) && ((uVar9 == 0 || (uVar9 - 100 < 0x32)))) {
+    uVar7 = uVar9;
+    (*(code *)g_wil_details_RecordSRUMFeatureUsage)(0x37aa04f,uVar9,1);
+  }
+  if (uVar2 != 0) {
+    EnabledStateManager::QueueBackgroundUsageReporting
+              ((EnabledStateManager *)&g_enabledStateManager,uVar7,param_1);
+  }
+  if ((uVar3 != 0) &&
+     ((pcVar6 = (code *)g_wil_details_internalRecordFeatureUsage,
+      g_wil_details_internalRecordFeatureUsage != 0 ||
+      (pcVar6 = (code *)g_wil_details_apiRecordFeatureUsage,
+      g_wil_details_apiRecordFeatureUsage != 0)))) {
+    (*pcVar6)(0x37aa04f,uVar4,uVar3,0);
+  }
+  local_38 = (int)uVar1;
+  if ((local_38 == 0) &&
+     (g_enabledStateManager != (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0))
+  {
+    AcquireSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+    if (DAT_140013248 == 0) {
+      DAT_140013248 = 0;
+      pcVar6 = (code *)g_wil_details_internalSubscribeFeatureStateChangeNotification;
+      if ((g_wil_details_internalSubscribeFeatureStateChangeNotification != 0) ||
+         (pcVar6 = (code *)g_wil_details_apiSubscribeFeatureStateChangeNotification,
+         g_wil_details_apiSubscribeFeatureStateChangeNotification != 0)) {
+        (*pcVar6)(&DAT_140013248,<lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>,
+                  0xffffffffffffffff);
+      }
+    }
+    ReleaseSRWLockExclusive((PSRWLOCK)&DAT_140013228);
+  }
+  if (param_2 != 0) {
+    uVar2 = uVar9 | 0x80000000;
+    if (param_3 == 0) {
+      uVar2 = uVar9;
+    }
+    pcVar6 = (code *)g_wil_details_internalRecordFeatureUsage;
+    if ((g_wil_details_internalRecordFeatureUsage != 0) ||
+       (pcVar6 = (code *)g_wil_details_apiRecordFeatureUsage,
+       g_wil_details_apiRecordFeatureUsage != 0)) {
+      (*pcVar6)(0x37aa04f,uVar2,0,0);
+    }
+  }
+  if ((local_38 == 0) && (g_wil_details_pfnFeatureLoggingHook != 0)) {
+    (*(code *)g_wil_details_pfnFeatureLoggingHook)
+              (0x37aa04f,CONCAT44(in_register_0000008c,param_4),0,(ulonglong)param_5 & 0xffffffff,
+               &param_6,0,(char)uVar1,1);
+  }
+  return;
+}
+

```


## wil::details::RecordSRUMFeatureUsage

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|RecordSRUMFeatureUsage|
|fullname|wil::details::RecordSRUMFeatureUsage|
|refcount|3|
|length|46|
|called|_guard_dispatch_icall|
|calling||
|paramcount|3|
|address|14000a950|
|sig|void __cdecl RecordSRUMFeatureUsage(uint param_1, uint param_2, uint param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::RecordSRUMFeatureUsage
+++ wil::details::RecordSRUMFeatureUsage
@@ -0,0 +1,18 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* void __cdecl wil::details::RecordSRUMFeatureUsage(unsigned int,unsigned int,unsigned int) */
+
+void __cdecl wil::details::RecordSRUMFeatureUsage(uint param_1,uint param_2,uint param_3)
+
+{
+  code *pcVar1;
+  
+  pcVar1 = (code *)g_wil_details_internalRecordFeatureUsage;
+  if ((g_wil_details_internalRecordFeatureUsage != 0) ||
+     (pcVar1 = (code *)g_wil_details_apiRecordFeatureUsage, g_wil_details_apiRecordFeatureUsage != 0
+     )) {
+    (*pcVar1)(param_1,param_2 | 0x40000000,param_3,0);
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::`scalar_deleting_destructor'

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|`scalar_deleting_destructor'|
|fullname|wil::details::EnabledStateManager::`scalar_deleting_destructor'|
|refcount|2|
|length|228|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>GetLastError<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details::EnabledStateManager::RecordCachedUsageUnderLock<br>wil::details::WilApi_UnsubscribeFeatureStateChangeNotification|
|calling|wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|paramcount|2|
|address|14000bc40|
|sig|void * __thiscall `scalar_deleting_destructor'(EnabledStateManager * this, uint param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::`scalar_deleting_destructor'
+++ wil::details::EnabledStateManager::`scalar_deleting_destructor'
@@ -0,0 +1,53 @@
+
+/* public: void * __ptr64 __cdecl wil::details::EnabledStateManager::`scalar deleting
+   destructor'(unsigned int) __ptr64 */
+
+void * __thiscall
+wil::details::EnabledStateManager::_scalar_deleting_destructor_
+          (EnabledStateManager *this,uint param_1)
+
+{
+  _TP_TIMER *p_Var1;
+  LPVOID pvVar2;
+  DWORD dwErrCode;
+  HANDLE pvVar3;
+  
+  *this = (EnabledStateManager)0x0;
+  p_Var1 = *(_TP_TIMER **)(this + 0x10);
+  if (p_Var1 != (_TP_TIMER *)0x0) {
+    dwErrCode = GetLastError();
+    DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(p_Var1);
+    SetLastError(dwErrCode);
+  }
+  *(undefined8 *)(this + 0x10) = 0;
+  *this = (EnabledStateManager)0x0;
+  RecordCachedUsageUnderLock(this);
+  pvVar2 = *(LPVOID *)(this + 0x68);
+  *(undefined8 *)(this + 0x68) = 0;
+  if (pvVar2 != (LPVOID)0x0) {
+    pvVar3 = GetProcessHeap();
+    HeapFree(pvVar3,0,pvVar2);
+  }
+  pvVar2 = *(LPVOID *)(this + 0x48);
+  *(undefined8 *)(this + 0x48) = 0;
+  if (pvVar2 != (LPVOID)0x0) {
+    pvVar3 = GetProcessHeap();
+    HeapFree(pvVar3,0,pvVar2);
+  }
+  if (*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)(this + 0x28) !=
+      (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *)0x0) {
+    WilApi_UnsubscribeFeatureStateChangeNotification
+              (*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)(this + 0x28));
+  }
+  if (*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)(this + 0x20) !=
+      (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *)0x0) {
+    WilApi_UnsubscribeFeatureStateChangeNotification
+              (*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)(this + 0x20));
+  }
+  if (*(_TP_TIMER **)(this + 0x10) != (_TP_TIMER *)0x0) {
+    DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy
+              (*(_TP_TIMER **)(this + 0x10));
+  }
+  return this;
+}
+

```


## wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|__private_IsEnabled|
|fullname|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled|
|refcount|2|
|length|137|
|called|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState<br>wil::details::ReportUsageToService|
|calling|UnregisterPathForCommonUpload|
|paramcount|1|
|address|14000bf04|
|sig|bool __thiscall __private_IsEnabled(FeatureImpl<struct___WilFeatureTraits_Feature_1207474488> * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled
+++ wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled
@@ -0,0 +1,38 @@
+
+/* public: bool __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_1207474488>::__private_IsEnabled(void) __ptr64 */
+
+bool __thiscall
+wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled
+          (FeatureImpl<struct___WilFeatureTraits_Feature_1207474488> *this)
+
+{
+  undefined8 *puVar1;
+  uint uVar2;
+  __uint64 unaff_RBX;
+  bool bVar3;
+  wil_ReportingKind unaff_EDI;
+  undefined8 local_res8;
+  undefined4 local_res10;
+  undefined2 local_res14;
+  undefined4 in_stack_ffffffffffffffdc;
+  
+  GetCachedFeatureEnabledState(this);
+  uVar2 = *(uint *)this;
+  bVar3 = (bool)((byte)local_res8 & 1);
+  if ((uVar2 & 4) == 0) {
+    puVar1 = (undefined8 *)GetCachedFeatureEnabledState(this);
+    local_res8 = *puVar1;
+    uVar2 = (uint)local_res8;
+  }
+  local_res10 = 0;
+  local_res8 = CONCAT35(local_res8._5_3_,0x200000000);
+  local_res14 = local_res8._4_2_;
+  ReportUsageToService
+            ((wil_details_FeatureReportingCache *)(this + 8),uVar2 >> 10 & 1,uVar2 >> 0xb & 1,
+             (int)&local_res10,
+             (FEATURE_LOGGED_TRAITS *)CONCAT44(in_stack_ffffffffffffffdc,(uint)bVar3),3,unaff_EDI,
+             unaff_RBX);
+  return bVar3;
+}
+

```


## wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|GetCachedFeatureEnabledState|
|fullname|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState|
|refcount|3|
|length|309|
|called|_guard_dispatch_icall<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::SubscribeFeatureStateCacheToConfigurationChanges|
|calling|wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled|
|paramcount|1|
|address|14000bfe0|
|sig|wil_details_FeatureStateCache __thiscall GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_1207474488> * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState
+++ wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState
@@ -0,0 +1,73 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* private: union wil_details_FeatureStateCache __cdecl wil::details::FeatureImpl<struct
+   __WilFeatureTraits_Feature_1207474488>::GetCachedFeatureEnabledState(void) __ptr64 */
+
+void __thiscall
+wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::
+GetCachedFeatureEnabledState(FeatureImpl<struct___WilFeatureTraits_Feature_1207474488> *this)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  code *pcVar5;
+  uint *in_RDX;
+  uint uVar6;
+  uint uVar7;
+  bool bVar8;
+  int local_res8 [2];
+  
+  uVar2 = *(uint *)this;
+  *in_RDX = uVar2;
+  if (((byte)uVar2 & 6) != 6) {
+    uVar2 = EnsureSubscribedToFeatureConfigurationChanges();
+    pcVar5 = (code *)g_wil_details_internalGetFeatureEnabledState;
+    if ((g_wil_details_internalGetFeatureEnabledState == 0) &&
+       (pcVar5 = (code *)g_wil_details_apiGetFeatureEnabledState,
+       g_wil_details_apiGetFeatureEnabledState == 0)) {
+      uVar6 = 0;
+    }
+    else {
+      uVar6 = (*pcVar5)(0x37aa04f,3,local_res8);
+    }
+    uVar3 = 0x40;
+    if (((uVar6 & 0xffffff3f) != 0) && (uVar3 = 0, (uVar6 & 0xffffff3f) == 2)) {
+      uVar3 = 0x40;
+    }
+    uVar4 = *in_RDX;
+    uVar6 = uVar3 >> 6 | (((uVar6 & 3) << 2 | uVar6 & 0x40) << 2 | uVar6 & 0x80) << 3 | uVar3;
+    do {
+      *in_RDX = uVar4;
+      uVar3 = uVar4;
+      if ((local_res8[0] != 0) && ((uVar4 & 2) == 0)) {
+        uVar3 = (uVar6 ^ uVar4) & 0x9c1 ^ uVar4 | 2;
+        *in_RDX = uVar3;
+      }
+      uVar7 = uVar4 & 4;
+      if (uVar7 == 0) {
+        uVar3 = uVar3 ^ (uVar3 ^ uVar6) & 0x400 | 4;
+        *in_RDX = uVar3;
+      }
+      LOCK();
+      uVar1 = *(uint *)this;
+      bVar8 = uVar4 == uVar1;
+      if (bVar8) {
+        *(uint *)this = uVar3;
+        uVar1 = uVar4;
+      }
+      uVar4 = uVar1;
+      UNLOCK();
+    } while (!bVar8);
+    if (uVar7 == 0) {
+      SubscribeFeatureStateCacheToConfigurationChanges
+                ((wil_details_FeatureStateCache *)this,3,uVar2);
+    }
+    if ((*in_RDX & 2) == 0) {
+      *in_RDX = *in_RDX ^ (*in_RDX ^ uVar6) & 0x9c1;
+    }
+  }
+  return;
+}
+

```


## <lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|<lambda_invoker_cdecl>|
|fullname|<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>|
|refcount|3|
|length|80|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>wil::details::EnabledStateManager::RecordCachedUsageUnderLock|
|calling||
|paramcount|2|
|address|14000c380|
|sig|undefined __fastcall <lambda_invoker_cdecl>(undefined8 param_1, EnabledStateManager * param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- <lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>
+++ <lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>
@@ -0,0 +1,19 @@
+
+void <lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>
+               (undefined8 param_1,EnabledStateManager *param_2)
+
+{
+  EnabledStateManager *SRWLock;
+  
+  if (*param_2 != (EnabledStateManager)0x0) {
+    SRWLock = param_2 + 8;
+    AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
+    wil::details::EnabledStateManager::RecordCachedUsageUnderLock(param_2);
+    param_2[0x18] = (EnabledStateManager)0x0;
+    if (SRWLock != (EnabledStateManager *)0x0) {
+      ReleaseSRWLockExclusive((PSRWLOCK)SRWLock);
+    }
+  }
+  return;
+}
+

```


## `wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|dtor$0|
|fullname|`wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0|
|refcount|1|
|length|12|
|called|wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>|
|calling||
|paramcount|2|
|address|14000e9c0|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0
+++ `wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0
@@ -0,0 +1,14 @@
+
+void `wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor_0
+               (undefined8 param_1,longlong param_2)
+
+{
+  wil::
+  unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>
+  ::
+  ~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>
+            ((unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>
+              *)(param_2 + 0x60));
+  return;
+}
+

```


## wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''

### Function Meta



|Key|post.exe|
| :---: | :---: |
|name|`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|fullname|wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|refcount|3|
|length|86|
|called|_guard_dispatch_icall<br>wil::details::EnabledStateManager::RecordCachedUsageUnderLock<br>wil::details::EnabledStateManager::`scalar_deleting_destructor'|
|calling||
|paramcount|2|
|address|14000ec10|
|sig|undefined __fastcall `dynamic_atexit_destructor_for_'g_enabledStateManager''(undefined8 param_1, uint param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''
+++ wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''
@@ -0,0 +1,26 @@
+
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
+/* WARNING: Exceeded maximum restarts with more pending */
+
+void wil::details::_dynamic_atexit_destructor_for__g_enabledStateManager__
+               (undefined8 param_1,uint param_2)
+
+{
+  char cVar1;
+  
+  if (!g_processShutdownInProgress) {
+    cVar1 = '\0';
+    if (g_pfnDllShutdownInProgress != (_func_uchar *)0x0) {
+      cVar1 = (*g_pfnDllShutdownInProgress)();
+    }
+    if (cVar1 == '\0') {
+      EnabledStateManager::_scalar_deleting_destructor_
+                ((EnabledStateManager *)&g_enabledStateManager,param_2);
+      return;
+    }
+  }
+  g_enabledStateManager = (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0;
+  EnabledStateManager::RecordCachedUsageUnderLock((EnabledStateManager *)&g_enabledStateManager);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## wil::details::ReportFailure_GetLastError

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.55|
|i_ratio|0.85|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|ReportFailure_GetLastError|ReportFailure_GetLastError|
|fullname|wil::details::ReportFailure_GetLastError|wil::details::ReportFailure_GetLastError|
|refcount|2|2|
|`length`|183|176|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>wil::details::ReportFailure<br>wil::details::ReportFailure_Hr|GetLastError<br>wil::details::ReportFailure<br>wil::details::ReportFailure_Hr|
|calling|wil::details::in1diag3::_FailFast_GetLastError|wil::details::in1diag3::_FailFast_GetLastError|
|paramcount|7|7|
|`address`|140006d10|140005a48|
|sig|ulong __cdecl ReportFailure_GetLastError(void * param_1, uint param_2, char * param_3, char * param_4, char * param_5, void * param_6, FailureType param_7)|ulong __cdecl ReportFailure_GetLastError(void * param_1, uint param_2, char * param_3, char * param_4, char * param_5, void * param_6, FailureType param_7)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::ReportFailure_GetLastError Called Diff


```diff
--- wil::details::ReportFailure_GetLastError called
+++ wil::details::ReportFailure_GetLastError called
@@ -1 +1 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
+GetLastError
```


### wil::details::ReportFailure_GetLastError Diff


```diff
--- wil::details::ReportFailure_GetLastError
+++ wil::details::ReportFailure_GetLastError
@@ -1,32 +1,32 @@
 
 /* unsigned long __cdecl wil::details::ReportFailure_GetLastError(void * __ptr64,unsigned int,char
    const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType)
     */
 
 ulong __cdecl
 wil::details::ReportFailure_GetLastError
           (void *param_1,uint param_2,char *param_3,char *param_4,char *param_5,void *param_6,
           FailureType param_7)
 
 {
-  DWORD DVar1;
-  uint uVar2;
+  uint uVar1;
+  DWORD DVar2;
   ushort *in_stack_ffffffffffffffe8;
   ReportFailureOptions in_stack_fffffffffffffff0;
   
-  DVar1 = GetLastError();
-  if (DVar1 == 0) {
+  DVar2 = GetLastError();
+  if (DVar2 == 0) {
     ReportFailure_Hr(param_1,param_2,"onecore\\internal\\sdk\\inc\\wil\\opensource\\wil\\resource.h"
                      ,(char *)0x0,(char *)0x0,param_6,2,-0x7ff8fd64);
-    DVar1 = 0x29c;
+    DVar2 = 0x29c;
   }
-  uVar2 = DVar1 & 0xffff | 0x80070000;
-  if ((int)DVar1 < 1) {
-    uVar2 = DVar1;
+  uVar1 = DVar2 & 0xffff | 0x80070000;
+  if ((int)DVar2 < 1) {
+    uVar1 = DVar2;
   }
   ReportFailure(param_1,param_2,"onecore\\internal\\sdk\\inc\\wil\\opensource\\wil\\resource.h",
-                (char *)0x0,(char *)0x0,param_6,3,uVar2,in_stack_ffffffffffffffe8,
+                (char *)0x0,(char *)0x0,param_6,3,uVar1,in_stack_ffffffffffffffe8,
                 in_stack_fffffffffffffff0);
-  return DVar1;
+  return DVar2;
 }
 

```


## wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.66|
|i_ratio|0.63|
|m_ratio|0.96|
|b_ratio|0.93|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|Acquire|Acquire|
|fullname|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire|
|refcount|2|2|
|`length`|827|780|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionEx<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>StringCchPrintfW<br>__security_check_cookie<br>_guard_dispatch_icall<br>memset</summary>wil::details::CloseHandle<br>wil::details::GetLastErrorFailHr<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::details_abi::UsageIndexes::UsageIndexes</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSectionEx<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>GetCurrentProcessId<br>StringCchPrintfW<br>__security_check_cookie<br>_guard_dispatch_icall<br>memset</summary>wil::details::CloseHandle<br>wil::details::GetLastErrorFailHr<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetPointer<br>wil::details_abi::UsageIndexes::UsageIndexes</details>|
|calling|wil::details::FeatureStateManager::EnsureStateData|wil::details::FeatureStateManager::EnsureStateData|
|paramcount|2|2|
|`address`|14000aa48|14000b244|
|sig|long __cdecl Acquire(char * param_1, ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> * * param_2)|long __cdecl Acquire(char * param_1, ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> * * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire Called Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire called
+++ wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire called
@@ -4 +3,0 @@
-API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId
@@ -7,0 +7 @@
+GetCurrentProcessId
@@ -18 +18 @@
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
```


### wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire
+++ wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire
@@ -1,151 +1,143 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: static long __cdecl wil::details_abi::ProcessLocalStorageData<class
    wil::details_abi::FeatureStateData>::Acquire(char const * __ptr64,class
    wil::details_abi::ProcessLocalStorageData<class wil::details_abi::FeatureStateData> * __ptr64 *
    __ptr64) */
 
 long __cdecl
 wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire
           (char *param_1,ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> **param_2
           )
 
 {
   DWORD DVar1;
   long lVar2;
   HANDLE hHandle;
   HANDLE pvVar3;
-  ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *pPVar4;
-  uint uVar5;
-  bool *pbVar6;
-  void *pvVar7;
+  ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *lpMem;
+  uint uVar4;
+  char *pcVar5;
+  void *pvVar6;
   void *unaff_retaddr;
   undefined1 auStack_2b8 [32];
   undefined4 local_298;
   char *local_290;
-  __uint64 local_288;
+  ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *local_288;
   HANDLE local_280;
   void *local_278;
   void *pvStack_270;
   undefined8 local_268;
   void *local_260;
   ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *local_258;
   WCHAR local_248 [264];
   ulonglong local_38;
   
   local_268 = 0xfffffffffffffffe;
   local_38 = __security_cookie ^ (ulonglong)auStack_2b8;
   *param_2 = (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0;
   DVar1 = GetCurrentProcessId();
   local_298 = 0x130;
   local_290 = param_1;
   StringCchPrintfW((ushort *)local_248,0x104,(ushort *)L"Local\\SM0:%d:%d:%hs",(ulonglong)DVar1);
   hHandle = CreateMutexExW((LPSECURITY_ATTRIBUTES)0x0,local_248,0,0x1f0001);
   local_280 = hHandle;
   if (hHandle == (HANDLE)0x0) {
     lVar2 = details::GetLastErrorFailHr();
     goto LAB_0;
   }
-  pbVar6 = (bool *)0x0;
-  uVar5 = 0xffffffff;
+  pcVar5 = (char *)0x0;
+  uVar4 = 0xffffffff;
   DVar1 = WaitForSingleObjectEx(hHandle,0xffffffff,0);
-  pvVar7 = hHandle;
+  pvVar6 = hHandle;
   if (DVar1 == 0x102) {
 LAB_1:
     if ((DVar1 & 0xffffff7f) != 0) {
-      pvVar7 = (void *)0x0;
+      pvVar6 = (void *)0x0;
     }
   }
   else if (DVar1 != 0) {
     if (DVar1 != 0x80) {
                     /* WARNING: Subroutine does not return */
-      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar5,pbVar6);
+      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar4,pcVar5);
     }
     goto LAB_1;
   }
-  pPVar4 = (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0;
-  local_288 = 0;
-  local_260 = pvVar7;
-  lVar2 = SemaphoreValue::TryGetValue<unsigned___int64>((ushort *)local_248,&local_288,pbVar6);
+  local_288 = (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0;
+  local_260 = pvVar6;
+  lVar2 = SemaphoreValue::TryGetPointer((ushort *)local_248,&local_288);
   if (lVar2 < 0) {
-    details::in1diag3::Return_Hr(unaff_retaddr,0x6b,"wil",lVar2);
+    uVar4 = 0x126;
+LAB_2:
+    details::in1diag3::Return_Hr(unaff_retaddr,uVar4,"wil",lVar2);
   }
   else {
-    pPVar4 = (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)(local_288 << 2);
-    lVar2 = 0;
-  }
-  if (lVar2 < 0) {
-    uVar5 = 0x126;
-LAB_2:
-    details::in1diag3::Return_Hr(unaff_retaddr,uVar5,"wil",lVar2);
-  }
-  else {
-    if (pPVar4 == (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0) {
+    if (local_288 == (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0) {
       *param_2 = (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0;
       pvVar3 = GetProcessHeap();
-      pPVar4 = HeapAlloc(pvVar3,8,0x130);
+      lpMem = HeapAlloc(pvVar3,8,0x130);
       if (details::g_pfnRtlDisownModuleHeapAllocation != (_func_long_void_ptr_void_ptr *)0x0) {
         pvVar3 = GetProcessHeap();
-        (*details::g_pfnRtlDisownModuleHeapAllocation)(pvVar3,pPVar4);
+        (*details::g_pfnRtlDisownModuleHeapAllocation)(pvVar3,lpMem);
       }
-      local_258 = pPVar4;
-      if (pPVar4 == (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0) {
+      local_258 = lpMem;
+      if (lpMem == (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *)0x0) {
         lVar2 = -0x7ff8fff2;
         details::in1diag3::Return_Hr(unaff_retaddr,0x142,"wil",-0x7ff8fff2);
       }
       else {
         local_278 = (void *)0x0;
         pvStack_270 = (void *)0x0;
         lVar2 = SemaphoreValue::CreateFromPointer
-                          ((SemaphoreValue *)&local_278,(ushort *)local_248,pPVar4);
+                          ((SemaphoreValue *)&local_278,(ushort *)local_248,lpMem);
         if (lVar2 < 0) {
           details::in1diag3::Return_Hr(unaff_retaddr,0x145,"wil",lVar2);
           if (pvStack_270 != (void *)0x0) {
             details::CloseHandle(pvStack_270);
           }
           if (local_278 != (void *)0x0) {
             details::CloseHandle(local_278);
           }
           pvVar3 = GetProcessHeap();
-          HeapFree(pvVar3,0,pPVar4);
+          HeapFree(pvVar3,0,lpMem);
         }
         else {
-          *(undefined4 *)pPVar4 = 1;
-          *(HANDLE *)(pPVar4 + 8) = hHandle;
+          *(undefined4 *)lpMem = 1;
+          *(HANDLE *)(lpMem + 8) = hHandle;
           hHandle = (HANDLE)0x0;
           local_280 = (HANDLE)0x0;
-          *(void **)(pPVar4 + 0x10) = local_278;
-          *(void **)(pPVar4 + 0x18) = pvStack_270;
-          memset(pPVar4 + 0x28,0,0x108);
-          *(undefined8 *)(pPVar4 + 0x20) = 0;
-          UsageIndexes::UsageIndexes((UsageIndexes *)(pPVar4 + 0x28));
-          InitializeCriticalSectionEx((LPCRITICAL_SECTION)(pPVar4 + 0xe8),0,0);
-          *(undefined8 *)(pPVar4 + 0x110) = 0;
-          *(undefined8 *)(pPVar4 + 0x118) = 0;
-          *(undefined8 *)(pPVar4 + 0x120) = 0;
-          *(undefined8 *)(pPVar4 + 0x128) = 0;
-          *param_2 = pPVar4;
+          *(void **)(lpMem + 0x10) = local_278;
+          *(void **)(lpMem + 0x18) = pvStack_270;
+          memset(lpMem + 0x28,0,0x108);
+          *(undefined8 *)(lpMem + 0x20) = 0;
+          UsageIndexes::UsageIndexes((UsageIndexes *)(lpMem + 0x28));
+          InitializeCriticalSectionEx((LPCRITICAL_SECTION)(lpMem + 0xe8),0,0);
+          *(undefined8 *)(lpMem + 0x110) = 0;
+          *(undefined8 *)(lpMem + 0x118) = 0;
+          *(undefined8 *)(lpMem + 0x120) = 0;
+          *(undefined8 *)(lpMem + 0x128) = 0;
+          *param_2 = lpMem;
           lVar2 = 0;
         }
         if (-1 < lVar2) goto LAB_3;
       }
-      uVar5 = 0x12e;
+      uVar4 = 0x12e;
       goto LAB_2;
     }
-    *param_2 = pPVar4;
-    *(int *)*param_2 = *(int *)pPVar4 + 1;
+    *param_2 = local_288;
+    *(int *)*param_2 = *(int *)local_288 + 1;
     hHandle = local_280;
 LAB_3:
     lVar2 = 0;
   }
-  if (pvVar7 != (void *)0x0) {
-    details::ReleaseMutex(pvVar7);
+  if (pvVar6 != (void *)0x0) {
+    details::ReleaseMutex(pvVar6);
   }
 LAB_0:
   if (hHandle != (void *)0x0) {
     details::CloseHandle(hHandle);
   }
   return lVar2;
 }
 

```


## wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.46|
|i_ratio|0.11|
|m_ratio|0.4|
|b_ratio|0.36|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|WilApiImpl_SubscribeFeatureStateChangeNotification|WilApiImpl_SubscribeFeatureStateChangeNotification|
|fullname|wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification|wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification|
|`refcount`|3|2|
|`length`|177|45|
|`called`|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush|
|calling|||
|paramcount|3|3|
|`address`|14000a8c0|14000a000|
|sig|void __cdecl WilApiImpl_SubscribeFeatureStateChangeNotification(FEATURE_STATE_CHANGE_SUBSCRIPTION__ * * param_1, _func_void_void_ptr * param_2, void * param_3)|void __cdecl WilApiImpl_SubscribeFeatureStateChangeNotification(FEATURE_STATE_CHANGE_SUBSCRIPTION__ * * param_1, _func_void_void_ptr * param_2, void * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification Called Diff


```diff
--- wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification called
+++ wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification called
@@ -1,3 +1 @@
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
+wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
@@ -5 +2,0 @@
-wil::details_abi::SubscriptionList::SubscribeUnderLock
```


### wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification Diff


```diff
--- wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification
+++ wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification
@@ -1,33 +1,20 @@
 
 /* void __cdecl wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification(struct
    FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64 * __ptr64,void (__cdecl*)(void * __ptr64),void *
    __ptr64) */
 
 void __cdecl
 wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification
           (FEATURE_STATE_CHANGE_SUBSCRIPTION__ **param_1,_func_void_void_ptr *param_2,void *param_3)
 
 {
-  bool bVar1;
-  
   if (param_3 == (void *)0xffffffffffffffff) {
     FeatureStateManager::SubscribeToUsageFlush
               ((FeatureStateManager *)&g_featureStateManager,param_1,param_2);
+    return;
   }
-  else {
-    *param_1 = (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *)0x0;
-    if (g_featureStateManager != (shutdown_aware_object<class_wil::details::FeatureStateManager>)0x0
-       ) {
-      AcquireSRWLockExclusive((PSRWLOCK)&DAT_0);
-      bVar1 = FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-                        ((FeatureStateManager *)&g_featureStateManager);
-      if (bVar1) {
-        details_abi::SubscriptionList::SubscribeUnderLock
-                  ((SubscriptionList *)&DAT_1,param_1,param_2,param_3);
-      }
-      ReleaseSRWLockExclusive((PSRWLOCK)&DAT_0);
-    }
-  }
+  FeatureStateManager::SubscribeToEnabledStateChanges
+            ((FeatureStateManager *)&g_featureStateManager,param_1,param_2,param_3);
   return;
 }
 

```


## wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.51|
|i_ratio|0.56|
|m_ratio|0.93|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|Release|Release|
|fullname|wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release|wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release|
|refcount|2|2|
|`length`|425|483|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>_guard_dispatch_icall<br>wil::details::CloseHandle<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details_abi::SemaphoreValue::Destroy<br>wil::details_abi::ThreadLocalData::~ThreadLocalData</summary></details>|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>GetLastError<br>_guard_dispatch_icall<br>wil::details::CloseHandle<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details_abi::ThreadLocalData::~ThreadLocalData|
|calling|wil::details::`dynamic_atexit_destructor_for_'g_processLocalData''|wil::details::`dynamic_atexit_destructor_for_'g_processLocalData''|
|paramcount|1|1|
|`address`|14000b278|14000ba54|
|sig|void __thiscall Release(ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> * this)|void __thiscall Release(ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release Called Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release called
+++ wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -5,0 +5 @@
+GetLastError
@@ -10 +9,0 @@
-wil::details_abi::SemaphoreValue::Destroy
```


### wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release
+++ wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release
@@ -1,88 +1,102 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Exceeded maximum restarts with more pending */
 /* public: void __cdecl wil::details_abi::ProcessLocalStorageData<struct
    wil::details_abi::ProcessLocalData>::Release(void) __ptr64 */
 
 void __thiscall
 wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release
           (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *this)
 
 {
   int iVar1;
-  LPVOID pvVar2;
-  char cVar3;
-  DWORD DVar4;
-  HANDLE pvVar5;
+  void *pvVar2;
+  LPVOID pvVar3;
+  char cVar4;
+  DWORD DVar5;
+  HANDLE pvVar6;
   HANDLE hHeap;
-  uint uVar6;
+  uint uVar7;
   LPVOID lpMem;
-  ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *pPVar7;
-  char *pcVar8;
+  ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *pPVar8;
+  char *pcVar9;
   void *unaff_retaddr;
   
   if (details::g_processShutdownInProgress) {
 LAB_0:
     *(int *)this = *(int *)this + -1;
     return;
   }
-  cVar3 = '\0';
+  cVar4 = '\0';
   if (details::g_pfnDllShutdownInProgress != (_func_uchar *)0x0) {
-    cVar3 = (*details::g_pfnDllShutdownInProgress)();
+    cVar4 = (*details::g_pfnDllShutdownInProgress)();
   }
-  if (cVar3 != '\0') goto LAB_0;
-  pvVar5 = *(HANDLE *)(this + 8);
-  pcVar8 = (char *)0x0;
-  uVar6 = 0xffffffff;
-  DVar4 = WaitForSingleObjectEx(pvVar5,0xffffffff,0);
-  if (DVar4 != 0x102) {
-    if (DVar4 == 0) goto LAB_1;
-    if (DVar4 != 0x80) {
+  if (cVar4 != '\0') goto LAB_0;
+  pvVar6 = *(HANDLE *)(this + 8);
+  pcVar9 = (char *)0x0;
+  uVar7 = 0xffffffff;
+  DVar5 = WaitForSingleObjectEx(pvVar6,0xffffffff,0);
+  if (DVar5 != 0x102) {
+    if (DVar5 == 0) goto LAB_1;
+    if (DVar5 != 0x80) {
                     /* WARNING: Subroutine does not return */
-      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar6,pcVar8);
+      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar7,pcVar9);
     }
   }
-  if ((DVar4 & 0xffffff7f) != 0) {
-    pvVar5 = (void *)0x0;
+  if ((DVar5 & 0xffffff7f) != 0) {
+    pvVar6 = (void *)0x0;
   }
 LAB_1:
   iVar1 = *(int *)this;
   *(int *)this = iVar1 + -1;
   if (iVar1 + -1 == 0) {
-    SemaphoreValue::Destroy((SemaphoreValue *)(this + 0x10));
-    if (pvVar5 != (void *)0x0) {
-      DVar4 = GetLastError();
-      details::ReleaseMutex(pvVar5);
-      SetLastError(DVar4);
+    pvVar2 = *(void **)(this + 0x10);
+    if (pvVar2 != (void *)0x0) {
+      DVar5 = GetLastError();
+      details::CloseHandle(pvVar2);
+      SetLastError(DVar5);
     }
-    for (pPVar7 = this + 0x28; pPVar7 != this + 0x78; pPVar7 = pPVar7 + 8) {
-      lpMem = *(LPVOID *)pPVar7;
+    *(undefined8 *)(this + 0x10) = 0;
+    pvVar2 = *(void **)(this + 0x18);
+    if (pvVar2 != (void *)0x0) {
+      DVar5 = GetLastError();
+      details::CloseHandle(pvVar2);
+      SetLastError(DVar5);
+    }
+    *(undefined8 *)(this + 0x18) = 0;
+    if (pvVar6 != (void *)0x0) {
+      DVar5 = GetLastError();
+      details::ReleaseMutex(pvVar6);
+      SetLastError(DVar5);
+    }
+    for (pPVar8 = this + 0x28; pPVar8 != this + 0x78; pPVar8 = pPVar8 + 8) {
+      lpMem = *(LPVOID *)pPVar8;
       while (lpMem != (LPVOID)0x0) {
-        pvVar2 = *(LPVOID *)((longlong)lpMem + 8);
+        pvVar3 = *(LPVOID *)((longlong)lpMem + 8);
         ThreadLocalData::~ThreadLocalData((ThreadLocalData *)((longlong)lpMem + 0x10));
-        pvVar5 = GetProcessHeap();
-        HeapFree(pvVar5,0,lpMem);
-        lpMem = pvVar2;
+        pvVar6 = GetProcessHeap();
+        HeapFree(pvVar6,0,lpMem);
+        lpMem = pvVar3;
       }
-      *(undefined8 *)pPVar7 = 0;
+      *(undefined8 *)pPVar8 = 0;
     }
-    pvVar5 = (void *)0x0;
+    pvVar6 = (void *)0x0;
     if (*(void **)(this + 0x18) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 0x18));
     }
     if (*(void **)(this + 0x10) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 0x10));
     }
     if (*(void **)(this + 8) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 8));
     }
     hHeap = GetProcessHeap();
     HeapFree(hHeap,0,this);
   }
-  if (pvVar5 == (void *)0x0) {
+  if (pvVar6 == (void *)0x0) {
     return;
   }
-  details::ReleaseMutex(pvVar5);
+  details::ReleaseMutex(pvVar6);
   return;
 }
 

```


## wil::details::GetLastErrorFailHr

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.47|
|i_ratio|0.84|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetLastErrorFailHr|GetLastErrorFailHr|
|fullname|wil::details::GetLastErrorFailHr|wil::details::GetLastErrorFailHr|
|refcount|5|5|
|`length`|92|85|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>wil::details::ReportFailure_Hr|GetLastError<br>wil::details::ReportFailure_Hr|
|calling|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::SemaphoreValue::CreateFromPointer|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::SemaphoreValue::CreateFromPointer|
|paramcount|0|0|
|`address`|14000608c|140004de0|
|sig|long __cdecl GetLastErrorFailHr(void)|long __cdecl GetLastErrorFailHr(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::GetLastErrorFailHr Called Diff


```diff
--- wil::details::GetLastErrorFailHr called
+++ wil::details::GetLastErrorFailHr called
@@ -1 +1 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
+GetLastError
```


### wil::details::GetLastErrorFailHr Diff


```diff
--- wil::details::GetLastErrorFailHr
+++ wil::details::GetLastErrorFailHr
@@ -1,22 +1,22 @@
 
 /* long __cdecl wil::details::GetLastErrorFailHr(void) */
 
 long __cdecl wil::details::GetLastErrorFailHr(void)
 
 {
-  DWORD DVar1;
-  uint uVar2;
+  uint uVar1;
+  DWORD DVar2;
   void *unaff_retaddr;
   
-  DVar1 = GetLastError();
-  if (DVar1 == 0) {
+  DVar2 = GetLastError();
+  if (DVar2 == 0) {
     ReportFailure_Hr((void *)0x0,0,(char *)0x0,(char *)0x0,(char *)0x0,unaff_retaddr,2,-0x7ff8fd64);
-    DVar1 = 0x29c;
+    DVar2 = 0x29c;
   }
-  uVar2 = DVar1 & 0xffff | 0x80070000;
-  if ((int)DVar1 < 1) {
-    uVar2 = DVar1;
+  uVar1 = DVar2 & 0xffff | 0x80070000;
+  if ((int)DVar2 < 1) {
+    uVar1 = DVar2;
   }
-  return uVar2;
+  return uVar1;
 }
 

```


## wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.63|
|i_ratio|0.12|
|m_ratio|0.88|
|b_ratio|0.88|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|
|fullname|wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|
|refcount|2|2|
|`length`|43|57|
|called|||
|calling|||
|paramcount|0|0|
|`address`|140001d30|140001d50|
|sig|undefined __fastcall `dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''(void)|undefined __fastcall `dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi'' Diff


```diff
--- wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''
+++ wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''
@@ -1,15 +1,14 @@
-
-/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void wil::details::_dynamic_initializer_for__g_header_init_InitializeStagingHeaderInternalApi__
                (void)
 
 {
-  _g_wil_details_internalRecordFeatureUsage = WilApiImpl_RecordFeatureUsage;
-  _g_wil_details_internalSubscribeFeatureStateChangeNotification =
+  g_wil_details_internalGetFeatureEnabledState = WilApiImpl_GetFeatureEnabledState;
+  g_wil_details_internalRecordFeatureUsage = WilApiImpl_RecordFeatureUsage;
+  g_wil_details_internalSubscribeFeatureStateChangeNotification =
        WilApiImpl_SubscribeFeatureStateChangeNotification;
-  _g_wil_details_internalUnsubscribeFeatureStateChangeNotification =
+  g_wil_details_internalUnsubscribeFeatureStateChangeNotification =
        WilApiImpl_UnsubscribeFeatureStateChangeNotification;
   return;
 }
 

```


## wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.65|
|i_ratio|0.52|
|m_ratio|0.93|
|b_ratio|0.89|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|Release|Release|
|fullname|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release|
|refcount|3|3|
|`length`|438|498|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>_guard_dispatch_icall<br>wil::details::CloseHandle<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details_abi::FeatureStateData::ProcessShutdown</summary>wil::details_abi::SemaphoreValue::Destroy<br>wil::details_abi::UsageIndexes::~UsageIndexes</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>GetLastError<br>_guard_dispatch_icall<br>wil::details::CloseHandle<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details_abi::FeatureStateData::ProcessShutdown</summary>wil::details_abi::UsageIndexes::~UsageIndexes</details>|
|calling|wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''|wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''|
|paramcount|1|1|
|`address`|14000ad8c|14000b558|
|sig|void __thiscall Release(ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> * this)|void __thiscall Release(ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release Called Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release called
+++ wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -6,0 +6 @@
+GetLastError
@@ -12 +11,0 @@
-wil::details_abi::SemaphoreValue::Destroy
```


### wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release
+++ wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release
@@ -1,88 +1,102 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Exceeded maximum restarts with more pending */
 /* public: void __cdecl wil::details_abi::ProcessLocalStorageData<class
    wil::details_abi::FeatureStateData>::Release(void) __ptr64 */
 
 void __thiscall
 wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release
           (ProcessLocalStorageData<class_wil::details_abi::FeatureStateData> *this)
 
 {
   int iVar1;
+  void *pvVar2;
   LPVOID lpMem;
-  char cVar2;
-  DWORD DVar3;
-  HANDLE pvVar4;
-  uint uVar5;
+  char cVar3;
+  DWORD DVar4;
+  HANDLE pvVar5;
+  uint uVar6;
   HANDLE hHandle;
-  char *pcVar6;
+  char *pcVar7;
   void *unaff_retaddr;
   
   if (details::g_processShutdownInProgress) {
 LAB_0:
     iVar1 = *(int *)this;
     *(int *)this = iVar1 + -1;
     if (iVar1 + -1 == 0) {
       FeatureStateData::ProcessShutdown((FeatureStateData *)(this + 0x20));
     }
     return;
   }
-  cVar2 = '\0';
+  cVar3 = '\0';
   if (details::g_pfnDllShutdownInProgress != (_func_uchar *)0x0) {
-    cVar2 = (*details::g_pfnDllShutdownInProgress)();
+    cVar3 = (*details::g_pfnDllShutdownInProgress)();
   }
-  if (cVar2 != '\0') goto LAB_0;
+  if (cVar3 != '\0') goto LAB_0;
   hHandle = *(HANDLE *)(this + 8);
-  pcVar6 = (char *)0x0;
-  uVar5 = 0xffffffff;
-  DVar3 = WaitForSingleObjectEx(hHandle,0xffffffff,0);
-  if (DVar3 != 0x102) {
-    if (DVar3 == 0) goto LAB_1;
-    if (DVar3 != 0x80) {
+  pcVar7 = (char *)0x0;
+  uVar6 = 0xffffffff;
+  DVar4 = WaitForSingleObjectEx(hHandle,0xffffffff,0);
+  if (DVar4 != 0x102) {
+    if (DVar4 == 0) goto LAB_1;
+    if (DVar4 != 0x80) {
                     /* WARNING: Subroutine does not return */
-      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar5,pcVar6);
+      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar6,pcVar7);
     }
   }
-  if ((DVar3 & 0xffffff7f) != 0) {
+  if ((DVar4 & 0xffffff7f) != 0) {
     hHandle = (void *)0x0;
   }
 LAB_1:
   iVar1 = *(int *)this;
   *(int *)this = iVar1 + -1;
   if (iVar1 + -1 == 0) {
-    SemaphoreValue::Destroy((SemaphoreValue *)(this + 0x10));
+    pvVar2 = *(void **)(this + 0x10);
+    if (pvVar2 != (void *)0x0) {
+      DVar4 = GetLastError();
+      details::CloseHandle(pvVar2);
+      SetLastError(DVar4);
+    }
+    *(undefined8 *)(this + 0x10) = 0;
+    pvVar2 = *(void **)(this + 0x18);
+    if (pvVar2 != (void *)0x0) {
+      DVar4 = GetLastError();
+      details::CloseHandle(pvVar2);
+      SetLastError(DVar4);
+    }
+    *(undefined8 *)(this + 0x18) = 0;
     if (hHandle != (void *)0x0) {
-      DVar3 = GetLastError();
+      DVar4 = GetLastError();
       details::ReleaseMutex(hHandle);
-      SetLastError(DVar3);
+      SetLastError(DVar4);
     }
     hHandle = (void *)0x0;
     FeatureStateData::ProcessShutdown((FeatureStateData *)(this + 0x20));
     lpMem = *(LPVOID *)(this + 0x128);
     *(undefined8 *)(this + 0x128) = 0;
     if (lpMem != (LPVOID)0x0) {
-      pvVar4 = GetProcessHeap();
-      HeapFree(pvVar4,0,lpMem);
+      pvVar5 = GetProcessHeap();
+      HeapFree(pvVar5,0,lpMem);
     }
     DeleteCriticalSection((LPCRITICAL_SECTION)(this + 0xe8));
     UsageIndexes::~UsageIndexes((UsageIndexes *)(this + 0x28));
     if (*(void **)(this + 0x18) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 0x18));
     }
     if (*(void **)(this + 0x10) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 0x10));
     }
     if (*(void **)(this + 8) != (void *)0x0) {
       details::CloseHandle(*(void **)(this + 8));
     }
-    pvVar4 = GetProcessHeap();
-    HeapFree(pvVar4,0,this);
+    pvVar5 = GetProcessHeap();
+    HeapFree(pvVar5,0,this);
   }
   if (hHandle == (void *)0x0) {
     return;
   }
   details::ReleaseMutex(hHandle);
   return;
 }
 

```


## UnregisterPathForCommonUpload

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.57|
|i_ratio|0.63|
|m_ratio|0.97|
|b_ratio|0.87|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|UnregisterPathForCommonUpload|UnregisterPathForCommonUpload|
|fullname|UnregisterPathForCommonUpload|UnregisterPathForCommonUpload|
|refcount|2|2|
|`length`|433|458|
|`called`|API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-DOWNLEVEL-SHLWAPI-L2-1-0.DLL::SHDeleteKeyW<br>StringCchCopyW<br>WPP_SF_SD<br>__security_check_cookie<br>memset|API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-DOWNLEVEL-SHLWAPI-L2-1-0.DLL::SHDeleteKeyW<br>StringCchCopyW<br>WPP_SF_SD<br>__security_check_cookie<br>memset<br>wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled|
|calling|CSqmConsolidator::UnregisterCommonUploaderPaths|CSqmConsolidator::UnregisterCommonUploaderPaths|
|paramcount|1|1|
|`address`|1400048d8|14000ab94|
|sig|long __cdecl UnregisterPathForCommonUpload(ushort * param_1)|long __cdecl UnregisterPathForCommonUpload(ushort * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### UnregisterPathForCommonUpload Called Diff


```diff
--- UnregisterPathForCommonUpload called
+++ UnregisterPathForCommonUpload called
@@ -7,0 +8 @@
+wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::__private_IsEnabled
```


### UnregisterPathForCommonUpload Diff


```diff
--- UnregisterPathForCommonUpload
+++ UnregisterPathForCommonUpload
@@ -1,69 +1,76 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* long __cdecl UnregisterPathForCommonUpload(unsigned short const * __ptr64) */
 
 long __cdecl UnregisterPathForCommonUpload(ushort *param_1)
 
 {
-  uint uVar1;
+  bool bVar1;
   uint uVar2;
-  WCHAR *pWVar3;
-  undefined2 uVar4;
+  uint uVar3;
+  WCHAR *pWVar4;
+  undefined2 uVar5;
   undefined1 auStackY_268 [32];
   HKEY local_238 [2];
   WCHAR local_228 [264];
   ulonglong local_18;
   
   local_18 = __security_cookie ^ (ulonglong)auStackY_268;
+  bVar1 = wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>::
+          __private_IsEnabled(&`private:_static_class_wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_1207474488>&___ptr64___cdecl_wil::Feature<struct___WilFeatureTraits_Feature_1207474488>::GetImpl(void)'
+                               ::__l2::impl);
+  if (bVar1) {
+    return 0;
+  }
   memset(local_228,0,0x208);
   local_238[0] = (HKEY)0x0;
-  uVar1 = StringCchCopyW((ushort *)local_228,0x104,param_1);
-  if ((int)uVar1 < 0) {
+  uVar2 = StringCchCopyW((ushort *)local_228,0x104,param_1);
+  if ((int)uVar2 < 0) {
     if (((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
        ((WPP_GLOBAL_Control[0x1c] & 1) == 0)) goto LAB_0;
-    uVar4 = 0xf;
+    uVar5 = 0xf;
   }
   else {
-    pWVar3 = local_228;
+    pWVar4 = local_228;
     while (local_228[0] != L'\0') {
       if (local_228[0] == L'\\') {
-        *pWVar3 = L'/';
+        *pWVar4 = L'/';
       }
-      pWVar3 = pWVar3 + 1;
-      local_228[0] = *pWVar3;
+      pWVar4 = pWVar4 + 1;
+      local_228[0] = *pWVar4;
     }
-    uVar2 = RegOpenKeyExW((HKEY)0xffffffff80000002,
+    uVar3 = RegOpenKeyExW((HKEY)0xffffffff80000002,
                           L"Software\\Microsoft\\SQMClient\\CommonUploader\\Paths",0,0x20106,
                           local_238);
-    if (uVar2 == 0) {
-      uVar2 = SHDeleteKeyW(local_238[0],local_228);
-      if ((uVar2 == 0) || (uVar2 == 3)) goto LAB_0;
-      uVar1 = uVar2 & 0xffff | 0x80070000;
-      if ((int)uVar2 < 1) {
-        uVar1 = uVar2;
+    if (uVar3 == 0) {
+      uVar3 = SHDeleteKeyW(local_238[0],local_228);
+      if ((uVar3 == 0) || (uVar3 == 3)) goto LAB_0;
+      uVar2 = uVar3 & 0xffff | 0x80070000;
+      if ((int)uVar3 < 1) {
+        uVar2 = uVar3;
       }
       if (((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
          ((WPP_GLOBAL_Control[0x1c] & 1) == 0)) goto LAB_0;
-      uVar4 = 0x11;
+      uVar5 = 0x11;
       param_1 = (ushort *)local_228;
     }
     else {
-      uVar1 = uVar2 & 0xffff | 0x80070000;
-      if ((int)uVar2 < 1) {
-        uVar1 = uVar2;
+      uVar2 = uVar3 & 0xffff | 0x80070000;
+      if ((int)uVar3 < 1) {
+        uVar2 = uVar3;
       }
       if (((undefined **)WPP_GLOBAL_Control == &WPP_GLOBAL_Control) ||
          ((WPP_GLOBAL_Control[0x1c] & 1) == 0)) goto LAB_0;
-      uVar4 = 0x10;
+      uVar5 = 0x10;
       param_1 = (ushort *)L"Software\\Microsoft\\SQMClient\\CommonUploader\\Paths";
     }
   }
-  WPP_SF_SD(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),uVar4,
-            &WPP_824151b15efa3a7a78160e2379ce8534_Traceguids,(wchar_t *)param_1);
+  WPP_SF_SD(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),uVar5,
+            &WPP_dadb87dc66173d1ea8c9c5f538f8273b_Traceguids,(wchar_t *)param_1);
 LAB_0:
   if (local_238[0] != (HKEY)0x0) {
     RegCloseKey(local_238[0]);
   }
-  return uVar1;
+  return uVar2;
 }
 

```


## wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.69|
|i_ratio|0.63|
|m_ratio|0.96|
|b_ratio|0.93|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|Acquire|Acquire|
|fullname|wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|
|refcount|2|2|
|`length`|801|758|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>StringCchPrintfW<br>__security_check_cookie<br>_guard_dispatch_icall<br>memset<br>wil::details::CloseHandle</summary>wil::details::GetLastErrorFailHr<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64></details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObjectEx<br>GetCurrentProcessId<br>StringCchPrintfW<br>__security_check_cookie<br>_guard_dispatch_icall<br>memset<br>wil::details::CloseHandle</summary>wil::details::GetLastErrorFailHr<br>wil::details::ReleaseMutex<br>wil::details::in1diag3::FailFast_Unexpected<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetPointer</details>|
|calling|wil::details_abi::GetThreadLocalDataCache|wil::details_abi::GetThreadLocalDataCache|
|paramcount|2|2|
|`address`|14000af4c|14000b754|
|sig|long __cdecl Acquire(char * param_1, ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> * * param_2)|long __cdecl Acquire(char * param_1, ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> * * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire Called Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire called
+++ wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire called
@@ -4 +3,0 @@
-API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId
@@ -6,0 +6 @@
+GetCurrentProcessId
@@ -17 +17 @@
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
```


### wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire Diff


```diff
--- wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire
+++ wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire
@@ -1,149 +1,141 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* public: static long __cdecl wil::details_abi::ProcessLocalStorageData<struct
    wil::details_abi::ProcessLocalData>::Acquire(char const * __ptr64,class
    wil::details_abi::ProcessLocalStorageData<struct wil::details_abi::ProcessLocalData> * __ptr64 *
    __ptr64) */
 
 long __cdecl
 wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire
           (char *param_1,
           ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> **param_2)
 
 {
   DWORD DVar1;
   long lVar2;
   HANDLE hHandle;
   HANDLE pvVar3;
-  ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *pPVar4;
-  uint uVar5;
-  bool *pbVar6;
-  void *pvVar7;
+  ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *lpMem;
+  uint uVar4;
+  char *pcVar5;
+  void *pvVar6;
   void *unaff_retaddr;
   undefined1 auStack_2b8 [32];
   undefined4 local_298;
   char *local_290;
   void *local_288;
   void *pvStack_280;
-  __uint64 local_278;
+  ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *local_278;
   HANDLE local_270;
   undefined8 local_268;
   void *local_260;
   ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *local_258;
   WCHAR local_248 [264];
   ulonglong local_38;
   
   local_268 = 0xfffffffffffffffe;
   local_38 = __security_cookie ^ (ulonglong)auStack_2b8;
   *param_2 = (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0;
   DVar1 = GetCurrentProcessId();
   local_298 = 0x78;
   local_290 = param_1;
   StringCchPrintfW((ushort *)local_248,0x104,(ushort *)L"Local\\SM0:%d:%d:%hs",(ulonglong)DVar1);
   hHandle = CreateMutexExW((LPSECURITY_ATTRIBUTES)0x0,local_248,0,0x1f0001);
   local_270 = hHandle;
   if (hHandle == (HANDLE)0x0) {
     lVar2 = details::GetLastErrorFailHr();
     goto LAB_0;
   }
-  pbVar6 = (bool *)0x0;
-  uVar5 = 0xffffffff;
+  pcVar5 = (char *)0x0;
+  uVar4 = 0xffffffff;
   DVar1 = WaitForSingleObjectEx(hHandle,0xffffffff,0);
-  pvVar7 = hHandle;
+  pvVar6 = hHandle;
   if (DVar1 == 0x102) {
 LAB_1:
     if ((DVar1 & 0xffffff7f) != 0) {
-      pvVar7 = (void *)0x0;
+      pvVar6 = (void *)0x0;
     }
   }
   else if (DVar1 != 0) {
     if (DVar1 != 0x80) {
                     /* WARNING: Subroutine does not return */
-      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar5,pbVar6);
+      details::in1diag3::FailFast_Unexpected(unaff_retaddr,uVar4,pcVar5);
     }
     goto LAB_1;
   }
-  pPVar4 = (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0;
-  local_278 = 0;
-  local_260 = pvVar7;
-  lVar2 = SemaphoreValue::TryGetValue<unsigned___int64>((ushort *)local_248,&local_278,pbVar6);
+  local_278 = (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0;
+  local_260 = pvVar6;
+  lVar2 = SemaphoreValue::TryGetPointer((ushort *)local_248,&local_278);
   if (lVar2 < 0) {
-    details::in1diag3::Return_Hr(unaff_retaddr,0x6b,"wil",lVar2);
+    uVar4 = 0x126;
+LAB_2:
+    details::in1diag3::Return_Hr(unaff_retaddr,uVar4,"wil",lVar2);
   }
   else {
-    pPVar4 = (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)(local_278 << 2);
-    lVar2 = 0;
-  }
-  if (lVar2 < 0) {
-    uVar5 = 0x126;
-LAB_2:
-    details::in1diag3::Return_Hr(unaff_retaddr,uVar5,"wil",lVar2);
-  }
-  else {
-    if (pPVar4 == (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0) {
+    if (local_278 == (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0) {
       *param_2 = (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0;
       pvVar3 = GetProcessHeap();
-      pPVar4 = HeapAlloc(pvVar3,8,0x78);
+      lpMem = HeapAlloc(pvVar3,8,0x78);
       if (details::g_pfnRtlDisownModuleHeapAllocation != (_func_long_void_ptr_void_ptr *)0x0) {
         pvVar3 = GetProcessHeap();
-        (*details::g_pfnRtlDisownModuleHeapAllocation)(pvVar3,pPVar4);
+        (*details::g_pfnRtlDisownModuleHeapAllocation)(pvVar3,lpMem);
       }
-      local_258 = pPVar4;
-      if (pPVar4 == (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0) {
+      local_258 = lpMem;
+      if (lpMem == (ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData> *)0x0) {
         lVar2 = -0x7ff8fff2;
         details::in1diag3::Return_Hr(unaff_retaddr,0x142,"wil",-0x7ff8fff2);
       }
       else {
         local_288 = (void *)0x0;
         pvStack_280 = (void *)0x0;
         lVar2 = SemaphoreValue::CreateFromPointer
-                          ((SemaphoreValue *)&local_288,(ushort *)local_248,pPVar4);
+                          ((SemaphoreValue *)&local_288,(ushort *)local_248,lpMem);
         if (lVar2 < 0) {
           details::in1diag3::Return_Hr(unaff_retaddr,0x145,"wil",lVar2);
           if (pvStack_280 != (void *)0x0) {
             details::CloseHandle(pvStack_280);
           }
           if (local_288 != (void *)0x0) {
             details::CloseHandle(local_288);
           }
           pvVar3 = GetProcessHeap();
-          HeapFree(pvVar3,0,pPVar4);
+          HeapFree(pvVar3,0,lpMem);
         }
         else {
-          *(undefined4 *)pPVar4 = 1;
-          *(HANDLE *)(pPVar4 + 8) = hHandle;
+          *(undefined4 *)lpMem = 1;
+          *(HANDLE *)(lpMem + 8) = hHandle;
           hHandle = (HANDLE)0x0;
           local_270 = (HANDLE)0x0;
-          *(void **)(pPVar4 + 0x10) = local_288;
+          *(void **)(lpMem + 0x10) = local_288;
           local_288 = (void *)0x0;
-          *(void **)(pPVar4 + 0x18) = pvStack_280;
+          *(void **)(lpMem + 0x18) = pvStack_280;
           pvStack_280 = (void *)0x0;
-          memset(pPVar4 + 0x22,0,0x56);
-          *(undefined2 *)(pPVar4 + 0x20) = 0x58;
-          *(undefined4 *)(pPVar4 + 0x24) = 1;
-          memset(pPVar4 + 0x28,0,0x50);
-          *param_2 = pPVar4;
+          memset(lpMem + 0x22,0,0x56);
+          *(undefined2 *)(lpMem + 0x20) = 0x58;
+          *(undefined4 *)(lpMem + 0x24) = 1;
+          memset(lpMem + 0x28,0,0x50);
+          *param_2 = lpMem;
           lVar2 = 0;
         }
         if (-1 < lVar2) goto LAB_3;
       }
-      uVar5 = 0x12e;
+      uVar4 = 0x12e;
       goto LAB_2;
     }
-    *param_2 = pPVar4;
-    *(int *)*param_2 = *(int *)pPVar4 + 1;
+    *param_2 = local_278;
+    *(int *)*param_2 = *(int *)local_278 + 1;
     hHandle = local_270;
 LAB_3:
     lVar2 = 0;
   }
-  if (pvVar7 != (void *)0x0) {
-    details::ReleaseMutex(pvVar7);
+  if (pvVar6 != (void *)0x0) {
+    details::ReleaseMutex(pvVar6);
   }
 LAB_0:
   if (hHandle != (void *)0x0) {
     details::CloseHandle(hHandle);
   }
   return lVar2;
 }
 

```


## wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,called|
|ratio|0.75|
|i_ratio|0.6|
|m_ratio|0.96|
|b_ratio|0.91|
|match_types|BSIM|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|`name`|TryGetValue<unsigned___int64>|TryGetPointer|
|`fullname`|wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>|wil::details_abi::SemaphoreValue::TryGetPointer|
|refcount|3|3|
|`length`|494|549|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::OpenSemaphoreW<br>StringCchCatW<br>StringCchCopyW<br>__security_check_cookie<br>wil::details::CloseHandle<br>wil::details::in1diag3::Return_GetLastError<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::OpenSemaphoreW<br>GetLastError<br>StringCchCatW<br>StringCchCopyW<br>__security_check_cookie<br>wil::details::CloseHandle<br>wil::details::in1diag3::Return_GetLastError<br>wil::details::in1diag3::Return_Hr<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore|
|calling|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|
|paramcount|3|2|
|`address`|14000b770|140006e60|
|`sig`|long __cdecl TryGetValue<unsigned___int64>(ushort * param_1, __uint64 * param_2, bool * param_3)|long __cdecl TryGetPointer(ushort * param_1, void * * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64> Called Diff


```diff
--- wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64> called
+++ wil::details_abi::SemaphoreValue::TryGetPointer called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -2,0 +2 @@
+GetLastError
```


### wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64> Diff


```diff
--- wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+++ wil::details_abi::SemaphoreValue::TryGetPointer
@@ -1,71 +1,79 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* public: static long __cdecl wil::details_abi::SemaphoreValue::TryGetValue<unsigned
-   __int64>(unsigned short const * __ptr64,unsigned __int64 * __ptr64,bool * __ptr64) */
+/* public: static long __cdecl wil::details_abi::SemaphoreValue::TryGetPointer(unsigned short const
+   * __ptr64,void * __ptr64 * __ptr64) */
 
-long __cdecl
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
-          (ushort *param_1,__uint64 *param_2,bool *param_3)
+long __cdecl wil::details_abi::SemaphoreValue::TryGetPointer(ushort *param_1,void **param_2)
 
 {
   DWORD DVar1;
   long lVar2;
   HANDLE pvVar3;
   HANDLE pvVar4;
-  __uint64 _Var5;
+  ulonglong uVar5;
   void *unaff_retaddr;
   undefined1 auStack_278 [32];
   long local_258;
   long local_254 [3];
   WCHAR local_248 [264];
   ulonglong local_38;
   
   local_38 = __security_cookie ^ (ulonglong)auStack_278;
-  *param_2 = 0;
-  _Var5 = 0;
+  *param_2 = (void *)0x0;
+  uVar5 = 0;
   StringCchCopyW((ushort *)local_248,0x104,param_1);
   StringCchCatW((ushort *)local_248,0x104,(ushort *)L"_p0");
   pvVar3 = OpenSemaphoreW(0x1f0003,0,local_248);
   if (pvVar3 == (HANDLE)0x0) {
     DVar1 = GetLastError();
-    if (DVar1 == 2) goto LAB_0;
-    lVar2 = details::in1diag3::Return_GetLastError(unaff_retaddr,0xc9,"wil");
+    if (DVar1 != 2) {
+      lVar2 = details::in1diag3::Return_GetLastError(unaff_retaddr,0xc9,"wil");
+      goto LAB_0;
+    }
   }
   else {
     local_254[0] = 0;
     local_258 = 0;
     lVar2 = GetValueFromSemaphore(pvVar3,local_254);
     if (lVar2 < 0) {
       details::in1diag3::Return_Hr(unaff_retaddr,0xcf,"wil",lVar2);
     }
     else {
       StringCchCatW((ushort *)local_248,0x104,(ushort *)L"h");
       pvVar4 = OpenSemaphoreW(0x1f0003,0,local_248);
       if (pvVar4 == (HANDLE)0x0) {
         lVar2 = details::in1diag3::Return_GetLastError(unaff_retaddr,0xd5,"wil");
       }
       else {
         lVar2 = GetValueFromSemaphore(pvVar4,&local_258);
         if (-1 < lVar2) {
           details::CloseHandle(pvVar4);
-          _Var5 = (longlong)local_254[0] | (longlong)local_258 << 0x1f;
+          uVar5 = (longlong)local_258 << 0x1f | (longlong)local_254[0];
           details::CloseHandle(pvVar3);
           lVar2 = 0;
-          goto LAB_1;
+          goto LAB_0;
         }
         details::in1diag3::Return_Hr(unaff_retaddr,0xd7,"wil",lVar2);
         details::CloseHandle(pvVar4);
       }
     }
     details::CloseHandle(pvVar3);
+LAB_0:
+    if (lVar2 < 0) {
+      details::in1diag3::Return_Hr(unaff_retaddr,0x62,"wil",lVar2);
+      uVar5 = 0;
+      goto LAB_1;
+    }
   }
+  lVar2 = 0;
 LAB_1:
   if (lVar2 < 0) {
-    details::in1diag3::Return_Hr(unaff_retaddr,0x62,"wil",lVar2);
-    return lVar2;
+    details::in1diag3::Return_Hr(unaff_retaddr,0x6b,"wil",lVar2);
   }
-LAB_0:
-  *param_2 = _Var5;
-  return 0;
+  else {
+    *param_2 = (void *)(uVar5 << 2);
+    lVar2 = 0;
+  }
+  return lVar2;
 }
 

```


## wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,called|
|ratio|0.5|
|i_ratio|0.09|
|m_ratio|0.82|
|b_ratio|0.71|
|match_types|BSIM|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|`name`|EnsureSubscribedToStateChangesUnderLock|SubscribeToEnabledStateChanges|
|`fullname`|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock|wil::details::FeatureStateManager::SubscribeToEnabledStateChanges|
|refcount|2|2|
|`length`|228|321|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|
|calling|wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification|wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification|
|paramcount|1|4|
|`address`|14000a594|140009518|
|`sig`|bool __thiscall EnsureSubscribedToStateChangesUnderLock(FeatureStateManager * this)|void __thiscall SubscribeToEnabledStateChanges(FeatureStateManager * this, FEATURE_STATE_CHANGE_SUBSCRIPTION__ * * param_1, _func_void_void_ptr * param_2, void * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock Called Diff


```diff
--- wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock called
+++ wil::details::FeatureStateManager::SubscribeToEnabledStateChanges called
@@ -1,2 +1,4 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive
+GetModuleHandleW
+GetProcAddress
@@ -4,0 +7 @@
+wil::details_abi::SubscriptionList::SubscribeUnderLock
```


### wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock Diff


```diff
--- wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
+++ wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
@@ -1,53 +1,61 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Exceeded maximum restarts with more pending */
-/* private: bool __cdecl
-   wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock(void) __ptr64 */
+/* public: void __cdecl wil::details::FeatureStateManager::SubscribeToEnabledStateChanges(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64 * __ptr64,void (__cdecl*)(void * __ptr64),void *
+   __ptr64) __ptr64 */
 
-bool __thiscall
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-          (FeatureStateManager *this)
+void __thiscall
+wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
+          (FeatureStateManager *this,FEATURE_STATE_CHANGE_SUBSCRIPTION__ **param_1,
+          _func_void_void_ptr *param_2,void *param_3)
 
 {
+  FeatureStateManager *SRWLock;
   FeatureStateManager *pFVar1;
   int iVar2;
   long lVar3;
-  FARPROC pFVar4;
-  bool bVar5;
   
-  pFVar4 = g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification;
+  *param_1 = (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *)0x0;
+  if (*this == (FeatureStateManager)0x0) {
+    return;
+  }
+  SRWLock = this + 0x20;
+  AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
   pFVar1 = this + 0xa0;
-  bVar5 = false;
   if (*(longlong *)pFVar1 == 0) {
     *(longlong *)pFVar1 = 0;
-    if (pFVar4 == (FARPROC)0x0) {
+    if (g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification == (FARPROC)0x0) {
       if (g_wil_details_ntdllModuleHandle == (HINSTANCE__ *)0x0) {
         g_wil_details_ntdllModuleHandle = GetModuleHandleW(L"ntdll.dll");
       }
-      pFVar4 = GetProcAddress(g_wil_details_ntdllModuleHandle,
-                              "RtlRegisterFeatureConfigurationChangeNotification");
-      g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification = pFVar4;
-      if (pFVar4 == (FARPROC)0x0) {
+      g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification =
+           GetProcAddress(g_wil_details_ntdllModuleHandle,
+                          "RtlRegisterFeatureConfigurationChangeNotification");
+      if (g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification == (FARPROC)0x0) {
         iVar2 = -0x3ffffec7;
         goto LAB_0;
       }
     }
-    iVar2 = (*pFVar4)(<lambda_1ad7ecfab602a777ecf020873216a663>::<lambda_invoker_cdecl>,this,0,
-                      pFVar1);
+    iVar2 = (*g_wil_details_pfnRtlRegisterFeatureConfigurationChangeNotification)
+                      (<lambda_1ad7ecfab602a777ecf020873216a663>::<lambda_invoker_cdecl>,this,0,
+                       pFVar1);
   }
   else {
     iVar2 = 0;
   }
 LAB_0:
-  if (iVar2 == 0) {
-    lVar3 = EnsureSubscribedToStateChangesUnderLock(this + 0x90,0x418a073aa3bc7c75,this);
-    if (lVar3 == 0) {
-      lVar3 = EnsureSubscribedToStateChangesUnderLock(this + 0x98,0x418a073aa3bc88f5,this);
-      if (lVar3 == 0) {
-        bVar5 = true;
-      }
-    }
+  if (((iVar2 == 0) &&
+      (lVar3 = EnsureSubscribedToStateChangesUnderLock(this + 0x90,0x418a073aa3bc7c75,this),
+      lVar3 == 0)) &&
+     (lVar3 = EnsureSubscribedToStateChangesUnderLock(this + 0x98,0x418a073aa3bc88f5,this),
+     lVar3 == 0)) {
+    details_abi::SubscriptionList::SubscribeUnderLock
+              ((SubscriptionList *)(this + 0x48),param_1,param_2,param_3);
   }
-  return bVar5;
+  if (SRWLock != (FeatureStateManager *)0x0) {
+    ReleaseSRWLockExclusive((PSRWLOCK)SRWLock);
+  }
+  return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## __GSHandlerCheck

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|__GSHandlerCheck|__GSHandlerCheck|
|fullname|__GSHandlerCheck|__GSHandlerCheck|
|`refcount`|31|34|
|length|29|29|
|called|__GSHandlerCheckCommon|__GSHandlerCheckCommon|
|calling|||
|paramcount|4|4|
|`address`|14000d384|14000e788|
|sig|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## QueueBackgroundSRUMUsageReporting

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.72|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|QueueBackgroundSRUMUsageReporting|QueueBackgroundSRUMUsageReporting|
|fullname|wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|
|refcount|2|2|
|`length`|385|371|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details_abi::heap_buffer::push_back|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer<br>GetLastError<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::WilApiImpl_RecordFeatureUsage|wil::details::WilApiImpl_RecordFeatureUsage|
|paramcount|4|4|
|`address`|14000a0b4|14000979c|
|sig|void __thiscall QueueBackgroundSRUMUsageReporting(FeatureStateManager * this, uint param_1, ushort param_2, uint param_3)|void __thiscall QueueBackgroundSRUMUsageReporting(FeatureStateManager * this, uint param_1, ushort param_2, uint param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### QueueBackgroundSRUMUsageReporting Called Diff


```diff
--- wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting called
+++ wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -6,0 +6 @@
+GetLastError
```


## GetThreadLocalDataCache

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.73|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetThreadLocalDataCache|GetThreadLocalDataCache|
|fullname|wil::details_abi::GetThreadLocalDataCache|wil::details_abi::GetThreadLocalDataCache|
|refcount|2|2|
|`length`|196|189|
|`called`|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|GetCurrentThreadId<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|
|calling|wil::details::GetContextAndNotifyFailure|wil::details::GetContextAndNotifyFailure|
|paramcount|1|1|
|`address`|140007fc0|140007594|
|sig|ThreadLocalData * __cdecl GetThreadLocalDataCache(bool param_1)|ThreadLocalData * __cdecl GetThreadLocalDataCache(bool param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetThreadLocalDataCache Called Diff


```diff
--- wil::details_abi::GetThreadLocalDataCache called
+++ wil::details_abi::GetThreadLocalDataCache called
@@ -1 +1 @@
-API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId
+GetCurrentThreadId
```


## ~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.8|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>|~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>|
|fullname|wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>|wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>|
|`refcount`|2|3|
|length|39|39|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|
|`calling`|`wil::details::FeatureStateManager::SubscribeToUsageFlush'::__l1::dtor$0|`wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0<br>`wil::details::FeatureStateManager::SubscribeToUsageFlush'::__l1::dtor$0|
|paramcount|1|1|
|`address`|140007810|140006c64|
|sig|void __thiscall ~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>(unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> * this)|void __thiscall ~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>(unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> Calling Diff


```diff
--- wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> calling
+++ wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> calling
@@ -0,0 +1 @@
+`wil::details::FeatureStateManager::SubscribeToEnabledStateChanges'::__l1::dtor$0
```


## GetContextAndNotifyFailure

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.69|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetContextAndNotifyFailure|GetContextAndNotifyFailure|
|fullname|wil::details::GetContextAndNotifyFailure|wil::details::GetContextAndNotifyFailure|
|refcount|3|3|
|`length`|342|328|
|`called`|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId<br>_guard_dispatch_icall<br>wil::details::ThreadFailureCallbackHolder::GetThreadContext<br>wil::details_abi::GetThreadLocalDataCache<br>wil::details_abi::ThreadLocalData::SetLastError|GetCurrentThreadId<br>_guard_dispatch_icall<br>wil::details::ThreadFailureCallbackHolder::GetThreadContext<br>wil::details_abi::GetThreadLocalDataCache<br>wil::details_abi::ThreadLocalData::SetLastError|
|calling|||
|paramcount|3|3|
|`address`|140008190|140007760|
|sig|void __cdecl GetContextAndNotifyFailure(FailureInfo * param_1, char * param_2, __uint64 param_3)|void __cdecl GetContextAndNotifyFailure(FailureInfo * param_1, char * param_2, __uint64 param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetContextAndNotifyFailure Called Diff


```diff
--- wil::details::GetContextAndNotifyFailure called
+++ wil::details::GetContextAndNotifyFailure called
@@ -1 +1 @@
-API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId
+GetCurrentThreadId
```


## ReportFailure_GetLastErrorHr

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.9|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|ReportFailure_GetLastErrorHr|ReportFailure_GetLastErrorHr|
|fullname|wil::details::ReportFailure_GetLastErrorHr|wil::details::ReportFailure_GetLastErrorHr|
|refcount|2|2|
|`length`|187|180|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>wil::details::ReportFailure<br>wil::details::ReportFailure_Hr|GetLastError<br>wil::details::ReportFailure<br>wil::details::ReportFailure_Hr|
|calling|wil::details::in1diag3::Return_GetLastError|wil::details::in1diag3::Return_GetLastError|
|paramcount|7|7|
|`address`|140006dd0|140005b00|
|sig|long __cdecl ReportFailure_GetLastErrorHr(void * param_1, uint param_2, char * param_3, char * param_4, char * param_5, void * param_6, FailureType param_7)|long __cdecl ReportFailure_GetLastErrorHr(void * param_1, uint param_2, char * param_3, char * param_4, char * param_5, void * param_6, FailureType param_7)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ReportFailure_GetLastErrorHr Called Diff


```diff
--- wil::details::ReportFailure_GetLastErrorHr called
+++ wil::details::ReportFailure_GetLastErrorHr called
@@ -1 +1 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
+GetLastError
```


## KERNEL32.DLL::FormatMessageW

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|FormatMessageW|FormatMessageW|
|fullname|KERNEL32.DLL::FormatMessageW|KERNEL32.DLL::FormatMessageW|
|`refcount`|2|3|
|length|0|0|
|called|||
|`calling`|wil::GetFailureLogString||
|paramcount|7|7|
|`address`|EXTERNAL:0000006e|EXTERNAL:0000006f|
|sig|DWORD __stdcall FormatMessageW(DWORD dwFlags, LPCVOID lpSource, DWORD dwMessageId, DWORD dwLanguageId, LPWSTR lpBuffer, DWORD nSize, va_list * Arguments)|DWORD __stdcall FormatMessageW(DWORD dwFlags, LPCVOID lpSource, DWORD dwMessageId, DWORD dwLanguageId, LPWSTR lpBuffer, DWORD nSize, va_list * Arguments)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### KERNEL32.DLL::FormatMessageW Calling Diff


```diff
--- KERNEL32.DLL::FormatMessageW calling
+++ KERNEL32.DLL::FormatMessageW calling
@@ -1 +0,0 @@
-wil::GetFailureLogString
```


## UnsubscribeWilWnf

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.46|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|UnsubscribeWilWnf|UnsubscribeWilWnf|
|fullname|wil::details::UnsubscribeWilWnf|wil::details::UnsubscribeWilWnf|
|refcount|4|4|
|`length`|108|94|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'|
|paramcount|1|1|
|`address`|1400086b0|140007c68|
|sig|void __cdecl UnsubscribeWilWnf(__WIL__WNF_USER_SUBSCRIPTION * param_1)|void __cdecl UnsubscribeWilWnf(__WIL__WNF_USER_SUBSCRIPTION * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### UnsubscribeWilWnf Called Diff


```diff
--- wil::details::UnsubscribeWilWnf called
+++ wil::details::UnsubscribeWilWnf called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|CreateThreadpoolTimer|CreateThreadpoolTimer|
|fullname|API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer|API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer|
|`refcount`|3|4|
|length|0|0|
|called|||
|`calling`|wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|
|paramcount|3|3|
|`address`|EXTERNAL:00000079|EXTERNAL:0000007b|
|sig|PTP_TIMER __stdcall CreateThreadpoolTimer(PTP_TIMER_CALLBACK pfnti, PVOID pv, PTP_CALLBACK_ENVIRON pcbe)|PTP_TIMER __stdcall CreateThreadpoolTimer(PTP_TIMER_CALLBACK pfnti, PVOID pv, PTP_CALLBACK_ENVIRON pcbe)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer Calling Diff


```diff
--- API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer calling
+++ API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer calling
@@ -0,0 +1 @@
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
```


## API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetModuleHandleW|GetModuleHandleW|
|fullname|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW|
|`refcount`|13|4|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>_get_image_app_type<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::RtlDisownModuleHeapAllocation<br>wil::details::RtlDllShutdownInProgress<br>wil::details::RtlNtStatusToDosErrorNoTeb<br>wil::details::UnregisterWilFeatureConfigurationChange<br>wil::details::UnsubscribeWilWnf<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_NtQueryWnfStateData</summary>wil_details_NtUpdateWnfStateData</details>|_get_image_app_type|
|paramcount|1|1|
|`address`|EXTERNAL:00000059|EXTERNAL:00000058|
|sig|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW Calling Diff


```diff
--- API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW calling
+++ API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW calling
@@ -2,11 +1,0 @@
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-wil::details::RtlDisownModuleHeapAllocation
-wil::details::RtlDllShutdownInProgress
-wil::details::RtlNtStatusToDosErrorNoTeb
-wil::details::UnregisterWilFeatureConfigurationChange
-wil::details::UnsubscribeWilWnf
-wil::details::WilApiImpl_RecordFeatureUsage
-wil::details::WilDynamicLoadRaiseFailFastException
-wil_details_NtQueryWnfStateData
-wil_details_NtUpdateWnfStateData
```


## EnsureStateData

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|EnsureStateData|EnsureStateData|
|fullname|wil::details::FeatureStateManager::EnsureStateData|wil::details::FeatureStateManager::EnsureStateData|
|refcount|5|5|
|`length`|216|209|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive<br>GetLastError<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire|
|calling|<lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::WilApiImpl_RecordFeatureUsage|<lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::WilApiImpl_RecordFeatureUsage|
|paramcount|1|1|
|`address`|14000a23c|140009918|
|sig|bool __thiscall EnsureStateData(FeatureStateManager * this)|bool __thiscall EnsureStateData(FeatureStateManager * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### EnsureStateData Called Diff


```diff
--- wil::details::FeatureStateManager::EnsureStateData called
+++ wil::details::FeatureStateManager::EnsureStateData called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -4,0 +4 @@
+GetLastError
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|ReleaseSRWLockExclusive|ReleaseSRWLockExclusive|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive|
|`refcount`|14|22|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe<br>wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_></summary></details>|<details><summary>Expand for full list:<br><lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl><br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges</summary>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::ReportUsageToService<br>wil::details::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe<br>wil::unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_></details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000004a|EXTERNAL:00000045|
|sig|void __stdcall ReleaseSRWLockExclusive(PSRWLOCK SRWLock)|void __stdcall ReleaseSRWLockExclusive(PSRWLOCK SRWLock)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockExclusive calling
@@ -0,0 +1 @@
+<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>
@@ -1,0 +3 @@
+<lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>
@@ -2,0 +5,3 @@
+wil::details::EnabledStateManager::OnStateChange
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
+wil::details::EnsureSubscribedToFeatureConfigurationChanges
@@ -5,0 +11 @@
+wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
@@ -7 +13,2 @@
-wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification
+wil::details::ReportUsageToService
+wil::details::SubscribeFeatureStateCacheToConfigurationChanges
```


## GetValueFromSemaphore

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,calling,called|
|ratio|1.0|
|i_ratio|0.63|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetValueFromSemaphore|GetValueFromSemaphore|
|fullname|wil::details_abi::SemaphoreValue::GetValueFromSemaphore|wil::details_abi::SemaphoreValue::GetValueFromSemaphore|
|refcount|3|3|
|`length`|383|369|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSemaphore<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObject<br>wil::details::in1diag3::Return_GetLastError<br>wil::details::in1diag3::Return_Hr|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSemaphore<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObject<br>GetLastError<br>wil::details::in1diag3::Return_GetLastError<br>wil::details::in1diag3::Return_Hr|
|`calling`|wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>|wil::details_abi::SemaphoreValue::TryGetPointer|
|paramcount|2|2|
|`address`|140007aa8|14000708c|
|sig|long __cdecl GetValueFromSemaphore(void * param_1, long * param_2)|long __cdecl GetValueFromSemaphore(void * param_1, long * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetValueFromSemaphore Called Diff


```diff
--- wil::details_abi::SemaphoreValue::GetValueFromSemaphore called
+++ wil::details_abi::SemaphoreValue::GetValueFromSemaphore called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -3,0 +3 @@
+GetLastError
```


### GetValueFromSemaphore Calling Diff


```diff
--- wil::details_abi::SemaphoreValue::GetValueFromSemaphore calling
+++ wil::details_abi::SemaphoreValue::GetValueFromSemaphore calling
@@ -1 +1 @@
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
```


## __security_check_cookie

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|__security_check_cookie|__security_check_cookie|
|fullname|__security_check_cookie|__security_check_cookie|
|`refcount`|35|38|
|length|30|30|
|called|__report_gsfailure|__report_gsfailure|
|`calling`|<details><summary>Expand for full list:<br>CSqmConsolidator::GetETLFileList<br>CSqmConsolidator::MovePendingUploadFilesTo<br>CSqmConsolidator::Process<br>CSqmConsolidator::UpdateETWResourcesOnOptinStatusChange<br>CleanupAllWinSqmFiles<br>DeleteAllFilesMatchingPattern<br>GetCommonUploaderPaths<br>GetSharedWindowsSqmFolder<br>IsPathEmpty<br>RegisterPathForCommonUpload<br>TraceLoggingRegisterEx_EventRegister_EventSetInformation</summary>UnregisterPathForCommonUpload<br>__GSHandlerCheckCommon<br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<2>,struct__tlgWrapperByVal<1>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<8>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<2>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<2>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<2>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<8>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<8>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>_><br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::details::FeatureLoggingHook<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::details_abi::UsageIndexes::Record<br>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load<br>wil_details_WriteSRUMWnfUsageBuffer</details>|<details><summary>Expand for full list:<br>CSqmConsolidator::GetETLFileList<br>CSqmConsolidator::MovePendingUploadFilesTo<br>CSqmConsolidator::Process<br>CSqmConsolidator::UpdateETWResourcesOnOptinStatusChange<br>CleanupAllWinSqmFiles<br>DeleteAllFilesMatchingPattern<br>GetCommonUploaderPaths<br>GetSharedWindowsSqmFolder<br>IsPathEmpty<br>RegisterPathForCommonUpload<br>TraceLoggingRegisterEx_EventRegister_EventSetInformation</summary>UnregisterPathForCommonUpload<br>__GSHandlerCheckCommon<br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<2>,struct__tlgWrapperByVal<1>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<8>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<2>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<2>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<2>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<8>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<8>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>,struct__tlgWrapSz<unsigned_short>_><br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::details::EnabledStateManager::RecordCachedUsageUnderLock<br>wil::details::FeatureLoggingHook<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::K32GetModuleInformation<br>wil::details::ReportFailure<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetPointer<br>wil::details_abi::UsageIndexes::Record<br>wil_QueryFeatureState<br>wil_StagingConfig_QueryFeatureState<br>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load<br>wil_details_WriteSRUMWnfUsageBuffer</details>|
|paramcount|1|1|
|`address`|14000cc10|14000dfd0|
|sig|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __security_check_cookie Calling Diff


```diff
--- __security_check_cookie calling
+++ __security_check_cookie calling
@@ -19,0 +20 @@
+wil::details::EnabledStateManager::RecordCachedUsageUnderLock
@@ -23 +24 @@
-wil::details::GetModuleInformation
+wil::details::K32GetModuleInformation
@@ -30 +31 @@
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
@@ -31,0 +33,2 @@
+wil_QueryFeatureState
+wil_StagingConfig_QueryFeatureState
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|AcquireSRWLockExclusive|AcquireSRWLockExclusive|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive|
|`refcount`|13|20|
|length|0|0|
|called|||
|`calling`|<lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe|<details><summary>Expand for full list:<br><lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl><br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnsureSubscribedToFeatureConfigurationChanges<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges</summary>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::ReportUsageToService<br>wil::details::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000004b|EXTERNAL:00000046|
|sig|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive calling
@@ -0,0 +1 @@
+<lambda_0374aa0a5d1201b2358c6bce99369c58>::<lambda_invoker_cdecl>
@@ -1,0 +3 @@
+<lambda_aa194dc0bf891154933407eb98fb868a>::<lambda_invoker_cdecl>
@@ -2,0 +5,3 @@
+wil::details::EnabledStateManager::OnStateChange
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
+wil::details::EnsureSubscribedToFeatureConfigurationChanges
@@ -5,0 +11 @@
+wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
@@ -7 +13,2 @@
-wil::details::WilApiImpl_SubscribeFeatureStateChangeNotification
+wil::details::ReportUsageToService
+wil::details::SubscribeFeatureStateCacheToConfigurationChanges
```


## push_back

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.9|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|push_back|push_back|
|fullname|wil::details_abi::heap_buffer::push_back|wil::details_abi::heap_buffer::push_back|
|`refcount`|3|5|
|length|133|133|
|called|MSVCRT.DLL::memcpy_s<br>wil::details_abi::heap_buffer::reserve|MSVCRT.DLL::memcpy_s<br>wil::details_abi::heap_buffer::reserve|
|`calling`|wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|
|paramcount|3|3|
|`address`|140008438|1400079f0|
|sig|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### push_back Calling Diff


```diff
--- wil::details_abi::heap_buffer::push_back calling
+++ wil::details_abi::heap_buffer::push_back calling
@@ -0,0 +1 @@
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
@@ -1,0 +3 @@
+wil::details::SubscribeFeatureStateCacheToConfigurationChanges
```


## atexit

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|atexit|atexit|
|fullname|atexit|atexit|
|`refcount`|6|7|
|length|23|23|
|called|_onexit|_onexit|
|`calling`|`dynamic_initializer_for_'s_consolidator''<br>wil::details::FeatureLogging::Instance<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''<br>wil::details::`dynamic_initializer_for_'g_threadFailureCallbacks''|`dynamic_initializer_for_'s_consolidator''<br>wil::details::FeatureLogging::Instance<br>wil::details::`dynamic_initializer_for_'g_enabledStateManager''<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''<br>wil::details::`dynamic_initializer_for_'g_threadFailureCallbacks''|
|paramcount|1|1|
|`address`|14000ccd4|14000e094|
|sig|int __cdecl atexit(_func_5014 * param_1)|int __cdecl atexit(_func_5014 * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### atexit Calling Diff


```diff
--- atexit calling
+++ atexit calling
@@ -2,0 +3 @@
+wil::details::`dynamic_initializer_for_'g_enabledStateManager''
```


## wil_details_NtUpdateWnfStateData

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.67|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|wil_details_NtUpdateWnfStateData|wil_details_NtUpdateWnfStateData|
|fullname|wil_details_NtUpdateWnfStateData|wil_details_NtUpdateWnfStateData|
|refcount|5|5|
|`length`|180|166|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|wil::details_abi::RecordWnfUsageIndex<br>wil_details_StagingConfig_FireNotification<br>wil_details_WriteSRUMWnfUsageBuffer|wil::details_abi::RecordWnfUsageIndex<br>wil_details_StagingConfig_FireNotification<br>wil_details_WriteSRUMWnfUsageBuffer|
|paramcount|7|7|
|`address`|1400071ec|140005ee0|
|sig|undefined8 __fastcall wil_details_NtUpdateWnfStateData(undefined8 param_1, undefined8 param_2, undefined4 param_3, undefined8 param_4, undefined8 param_5, undefined4 param_6, undefined4 param_7)|undefined8 __fastcall wil_details_NtUpdateWnfStateData(undefined8 param_1, undefined8 param_2, undefined4 param_3, undefined8 param_4, undefined8 param_5, undefined4 param_6, undefined4 param_7)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_NtUpdateWnfStateData Called Diff


```diff
--- wil_details_NtUpdateWnfStateData called
+++ wil_details_NtUpdateWnfStateData called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|HeapFree|HeapFree|
|fullname|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|
|`refcount`|35|38|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>wil::ResultException::~ResultException<br>wil::StoredFailureInfo::SetFailureInfo<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::shared_buffer::create<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::RawUsageIndex::RecordUsage</summary>wil::details_abi::RawUsageIndex::SetBuffer<br>wil::details_abi::RawUsageIndex::Swap<br>wil::details_abi::RawUsageIndex::~RawUsageIndex<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::ThreadLocalData::SetLastError<br>wil::details_abi::ThreadLocalData::~ThreadLocalData<br>wil::details_abi::UsageIndexes::~UsageIndexes<br>wil::details_abi::heap_buffer::reserve<br>wil::details_abi::heap_buffer::~heap_buffer<br>wil_details_StagingConfig_Load</details>|<details><summary>Expand for full list:<br>wil::ResultException::~ResultException<br>wil::StoredFailureInfo::SetFailureInfo<br>wil::details::EnabledStateManager::`scalar_deleting_destructor'<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::shared_buffer::create<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release</summary>wil::details_abi::RawUsageIndex::RecordUsage<br>wil::details_abi::RawUsageIndex::SetBuffer<br>wil::details_abi::RawUsageIndex::Swap<br>wil::details_abi::RawUsageIndex::~RawUsageIndex<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::ThreadLocalData::SetLastError<br>wil::details_abi::ThreadLocalData::~ThreadLocalData<br>wil::details_abi::UsageIndexes::~UsageIndexes<br>wil::details_abi::heap_buffer::reserve<br>wil::details_abi::heap_buffer::~heap_buffer<br>wil_StagingConfig_QueryFeatureState<br>wil_details_StagingConfig_Load</details>|
|paramcount|3|3|
|`address`|EXTERNAL:00000076|EXTERNAL:00000074|
|sig|BOOL __stdcall HeapFree(HANDLE hHeap, DWORD dwFlags, LPVOID lpMem)|BOOL __stdcall HeapFree(HANDLE hHeap, DWORD dwFlags, LPVOID lpMem)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree Calling Diff


```diff
--- API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree calling
+++ API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree calling
@@ -2,0 +3 @@
+wil::details::EnabledStateManager::`scalar_deleting_destructor'
@@ -20,0 +22 @@
+wil_StagingConfig_QueryFeatureState
```


## UnregisterWilFeatureConfigurationChange

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.46|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|UnregisterWilFeatureConfigurationChange|UnregisterWilFeatureConfigurationChange|
|fullname|wil::details::UnregisterWilFeatureConfigurationChange|wil::details::UnregisterWilFeatureConfigurationChange|
|refcount|2|2|
|`length`|108|94|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|wil::details::FeatureStateManager::`scalar_deleting_destructor'|wil::details::FeatureStateManager::`scalar_deleting_destructor'|
|paramcount|1|1|
|`address`|140008724|140007cd0|
|sig|void __cdecl UnregisterWilFeatureConfigurationChange(void * param_1)|void __cdecl UnregisterWilFeatureConfigurationChange(void * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### UnregisterWilFeatureConfigurationChange Called Diff


```diff
--- wil::details::UnregisterWilFeatureConfigurationChange called
+++ wil::details::UnregisterWilFeatureConfigurationChange called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|SetLastError|SetLastError|
|fullname|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError|
|`refcount`|18|23|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::Destroy<br>wil::details_abi::heap_buffer::reserve<br>wil::last_error_context::~last_error_context</summary></details>|<details><summary>Expand for full list:<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::EnabledStateManager::`scalar_deleting_destructor'<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::heap_buffer::reserve</summary>wil::last_error_context::~last_error_context</details>|
|paramcount|1|1|
|`address`|EXTERNAL:00000031|EXTERNAL:0000002f|
|sig|void __stdcall SetLastError(DWORD dwErrCode)|void __stdcall SetLastError(DWORD dwErrCode)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError Calling Diff


```diff
--- API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError calling
+++ API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError calling
@@ -0,0 +1,2 @@
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
+wil::details::EnabledStateManager::`scalar_deleting_destructor'
@@ -9 +10,0 @@
-wil::details_abi::SemaphoreValue::Destroy
```


## RtlNtStatusToDosErrorNoTeb

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.55|
|m_ratio|0.97|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|RtlNtStatusToDosErrorNoTeb|RtlNtStatusToDosErrorNoTeb|
|fullname|wil::details::RtlNtStatusToDosErrorNoTeb|wil::details::RtlNtStatusToDosErrorNoTeb|
|refcount|3|3|
|`length`|121|107|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|||
|paramcount|1|1|
|`address`|140006fb0|140005cd0|
|sig|ulong __cdecl RtlNtStatusToDosErrorNoTeb(long param_1)|ulong __cdecl RtlNtStatusToDosErrorNoTeb(long param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### RtlNtStatusToDosErrorNoTeb Called Diff


```diff
--- wil::details::RtlNtStatusToDosErrorNoTeb called
+++ wil::details::RtlNtStatusToDosErrorNoTeb called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## WilApiImpl_RecordFeatureUsage

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.55|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|WilApiImpl_RecordFeatureUsage|WilApiImpl_RecordFeatureUsage|
|fullname|wil::details::WilApiImpl_RecordFeatureUsage|wil::details::WilApiImpl_RecordFeatureUsage|
|refcount|3|3|
|`length`|472|458|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled</summary>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>GetModuleHandleW<br>GetProcAddress<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled</summary>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load</details>|
|calling|||
|paramcount|4|4|
|`address`|14000a6e0|140009e20|
|sig|void __cdecl WilApiImpl_RecordFeatureUsage(uint param_1, uint param_2, uint param_3, char * param_4)|void __cdecl WilApiImpl_RecordFeatureUsage(uint param_1, uint param_2, uint param_3, char * param_4)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WilApiImpl_RecordFeatureUsage Called Diff


```diff
--- wil::details::WilApiImpl_RecordFeatureUsage called
+++ wil::details::WilApiImpl_RecordFeatureUsage called
@@ -3,2 +3,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## Return_Hr

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.9|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|Return_Hr|Return_Hr|
|fullname|wil::details::in1diag3::Return_Hr|wil::details::in1diag3::Return_Hr|
|`refcount`|14|13|
|length|46|46|
|called|wil::details::ReportFailure_Hr|wil::details::ReportFailure_Hr|
|`calling`|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetPointer|
|paramcount|4|4|
|`address`|140006e94|140005bbc|
|sig|void __cdecl Return_Hr(void * param_1, uint param_2, char * param_3, long param_4)|void __cdecl Return_Hr(void * param_1, uint param_2, char * param_3, long param_4)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### Return_Hr Calling Diff


```diff
--- wil::details::in1diag3::Return_Hr calling
+++ wil::details::in1diag3::Return_Hr calling
@@ -5 +5 @@
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
```


## CreateFromPointer

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.73|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|CreateFromPointer|CreateFromPointer|
|fullname|wil::details_abi::SemaphoreValue::CreateFromPointer|wil::details_abi::SemaphoreValue::CreateFromPointer|
|refcount|3|3|
|`length`|466|452|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateSemaphoreExW<br>StringCchCatW<br>StringCchCopyW<br>__security_check_cookie<br>wil::details::CloseHandle<br>wil::details::GetLastErrorFailHr<br>wil::details::in1diag3::Return_Hr<br>wistd::__throw_bad_function_call|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateSemaphoreExW<br>GetLastError<br>StringCchCatW<br>StringCchCopyW<br>__security_check_cookie<br>wil::details::CloseHandle<br>wil::details::GetLastErrorFailHr<br>wil::details::in1diag3::Return_Hr<br>wistd::__throw_bad_function_call|
|calling|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire|
|paramcount|3|3|
|`address`|1400078cc|140006c94|
|sig|long __thiscall CreateFromPointer(SemaphoreValue * this, ushort * param_1, void * param_2)|long __thiscall CreateFromPointer(SemaphoreValue * this, ushort * param_1, void * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CreateFromPointer Called Diff


```diff
--- wil::details_abi::SemaphoreValue::CreateFromPointer called
+++ wil::details_abi::SemaphoreValue::CreateFromPointer called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -3,0 +3 @@
+GetLastError
```


## WilDynamicLoadRaiseFailFastException

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.71|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|WilDynamicLoadRaiseFailFastException|WilDynamicLoadRaiseFailFastException|
|fullname|wil::details::WilDynamicLoadRaiseFailFastException|wil::details::WilDynamicLoadRaiseFailFastException|
|refcount|3|3|
|`length`|101|87|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|||
|paramcount|3|3|
|`address`|140005fc0|140004d20|
|sig|void __cdecl WilDynamicLoadRaiseFailFastException(_EXCEPTION_RECORD * param_1, _CONTEXT * param_2, ulong param_3)|void __cdecl WilDynamicLoadRaiseFailFastException(_EXCEPTION_RECORD * param_1, _CONTEXT * param_2, ulong param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WilDynamicLoadRaiseFailFastException Called Diff


```diff
--- wil::details::WilDynamicLoadRaiseFailFastException called
+++ wil::details::WilDynamicLoadRaiseFailFastException called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## reserve

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|reserve|reserve|
|fullname|wil::details_abi::heap_buffer::reserve|wil::details_abi::heap_buffer::reserve|
|refcount|4|4|
|`length`|320|313|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>MSVCRT.DLL::memcpy_s<br>_guard_dispatch_icall|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>GetLastError<br>MSVCRT.DLL::memcpy_s<br>_guard_dispatch_icall|
|calling|wil::details_abi::RawUsageIndex::RecordUsage<br>wil::details_abi::heap_buffer::push_back|wil::details_abi::RawUsageIndex::RecordUsage<br>wil::details_abi::heap_buffer::push_back|
|paramcount|2|2|
|`address`|1400082f0|1400078b0|
|sig|bool __thiscall reserve(heap_buffer * this, __uint64 param_1)|bool __thiscall reserve(heap_buffer * this, __uint64 param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### reserve Called Diff


```diff
--- wil::details_abi::heap_buffer::reserve called
+++ wil::details_abi::heap_buffer::reserve called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -5,0 +5 @@
+GetLastError
```


## GetFailureLogString

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.63|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetFailureLogString|GetFailureLogString|
|fullname|wil::GetFailureLogString|wil::GetFailureLogString|
|refcount|3|3|
|`length`|611|597|
|`called`|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId<br>KERNEL32.DLL::FormatMessageW<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::LogStringPrintf|FormatMessageW<br>GetCurrentThreadId<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::LogStringPrintf|
|calling|wil::ResultException::what<br>wil::details::LogFailure|wil::ResultException::what<br>wil::details::LogFailure|
|paramcount|3|3|
|`address`|1400059f4|14000475c|
|sig|long __cdecl GetFailureLogString(ushort * param_1, __uint64 param_2, FailureInfo * param_3)|long __cdecl GetFailureLogString(ushort * param_1, __uint64 param_2, FailureInfo * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### GetFailureLogString Called Diff


```diff
--- wil::GetFailureLogString called
+++ wil::GetFailureLogString called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId
-KERNEL32.DLL::FormatMessageW
+FormatMessageW
+GetCurrentThreadId
```


## EnsureTimerUnderLock

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|EnsureTimerUnderLock|EnsureTimerUnderLock|
|fullname|wil::details::FeatureStateManager::EnsureTimerUnderLock|wil::details::FeatureStateManager::EnsureTimerUnderLock|
|refcount|2|2|
|`length`|218|204|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CreateThreadpoolTimer<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer<br>GetLastError<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy|
|calling|wil::details::FeatureStateManager::RecordFeatureUsage|wil::details::FeatureStateManager::RecordFeatureUsage|
|paramcount|1|1|
|`address`|14000a31c|1400099f0|
|sig|void __thiscall EnsureTimerUnderLock(FeatureStateManager * this)|void __thiscall EnsureTimerUnderLock(FeatureStateManager * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### EnsureTimerUnderLock Called Diff


```diff
--- wil::details::FeatureStateManager::EnsureTimerUnderLock called
+++ wil::details::FeatureStateManager::EnsureTimerUnderLock called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -4,0 +4 @@
+GetLastError
```


## RtlDisownModuleHeapAllocation

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.61|
|m_ratio|0.97|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|RtlDisownModuleHeapAllocation|RtlDisownModuleHeapAllocation|
|fullname|wil::details::RtlDisownModuleHeapAllocation|wil::details::RtlDisownModuleHeapAllocation|
|refcount|3|3|
|`length`|139|125|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|||
|paramcount|2|2|
|`address`|1400070b0|140005dc0|
|sig|long __cdecl RtlDisownModuleHeapAllocation(void * param_1, void * param_2)|long __cdecl RtlDisownModuleHeapAllocation(void * param_1, void * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### RtlDisownModuleHeapAllocation Called Diff


```diff
--- wil::details::RtlDisownModuleHeapAllocation called
+++ wil::details::RtlDisownModuleHeapAllocation called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetLastError|GetLastError|
|fullname|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|
|`refcount`|38|17|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CSqmConsolidator::GetETLFileList<br>CSqmConsolidator::MovePendingUploadFilesTo<br>CTpSampleManager::LoadTransactionLibrary<br>CTpSampleManager::Prune<br>UtilEnsureDirectoryWorker<br>WinMain<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'</summary>wil::details::GetLastErrorFailHr<br>wil::details::ReportFailure_GetLastError<br>wil::details::ReportFailure_GetLastErrorHr<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::Destroy<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::details_abi::heap_buffer::reserve</details>|CSqmConsolidator::GetETLFileList<br>CSqmConsolidator::MovePendingUploadFilesTo<br>CTpSampleManager::LoadTransactionLibrary<br>CTpSampleManager::Prune<br>UtilEnsureDirectoryWorker<br>WinMain|
|paramcount|0|0|
|address|EXTERNAL:0000002e|EXTERNAL:0000002e|
|sig|DWORD __stdcall GetLastError(void)|DWORD __stdcall GetLastError(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError Calling Diff


```diff
--- API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError calling
+++ API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError calling
@@ -7,15 +6,0 @@
-wil::details::FeatureStateManager::EnsureStateData
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-wil::details::FeatureStateManager::EnsureTimerUnderLock
-wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting
-wil::details::FeatureStateManager::`scalar_deleting_destructor'
-wil::details::GetLastErrorFailHr
-wil::details::ReportFailure_GetLastError
-wil::details::ReportFailure_GetLastErrorHr
-wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release
-wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release
-wil::details_abi::SemaphoreValue::CreateFromPointer
-wil::details_abi::SemaphoreValue::Destroy
-wil::details_abi::SemaphoreValue::GetValueFromSemaphore
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
-wil::details_abi::heap_buffer::reserve
```


## `scalar_deleting_destructor'

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.67|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|`scalar_deleting_destructor'|`scalar_deleting_destructor'|
|fullname|wil::details::FeatureStateManager::`scalar_deleting_destructor'|wil::details::FeatureStateManager::`scalar_deleting_destructor'|
|refcount|2|2|
|`length`|438|424|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details::UnregisterWilFeatureConfigurationChange<br>wil::details::UnsubscribeProcessWideUsageFlush<br>wil::details::UnsubscribeWilWnf<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::DeleteCriticalSection<br>GetLastError<br>wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details::UnregisterWilFeatureConfigurationChange<br>wil::details::UnsubscribeProcessWideUsageFlush<br>wil::details::UnsubscribeWilWnf<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release|
|calling|wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''|wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''|
|paramcount|2|2|
|`address`|14000b42c|14000bd2c|
|sig|void * __thiscall `scalar_deleting_destructor'(FeatureStateManager * this, uint param_1)|void * __thiscall `scalar_deleting_destructor'(FeatureStateManager * this, uint param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### `scalar_deleting_destructor' Called Diff


```diff
--- wil::details::FeatureStateManager::`scalar_deleting_destructor' called
+++ wil::details::FeatureStateManager::`scalar_deleting_destructor' called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -5,0 +5 @@
+GetLastError
```


## CloseHandle

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,length,address,calling,called|
|ratio|1.0|
|i_ratio|0.67|
|m_ratio|0.95|
|b_ratio|0.95|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|CloseHandle|CloseHandle|
|fullname|wil::details::CloseHandle|wil::details::CloseHandle|
|`refcount`|22|24|
|`length`|41|34|
|`called`|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>wil::details::in1diag3::_FailFast_GetLastError|CloseHandle<br>wil::details::in1diag3::_FailFast_GetLastError|
|`calling`|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::Destroy<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::unique_any_t<class_wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>_>::~unique_any_t<class_wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>_>|wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::CreateFromPointer<br>wil::details_abi::SemaphoreValue::TryGetPointer<br>wil::unique_any_t<class_wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>_>::~unique_any_t<class_wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>_>|
|paramcount|1|1|
|`address`|140007788|140006be0|
|sig|void __cdecl CloseHandle(void * param_1)|void __cdecl CloseHandle(void * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### CloseHandle Called Diff


```diff
--- wil::details::CloseHandle called
+++ wil::details::CloseHandle called
@@ -1 +1 @@
-API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle
+CloseHandle
```


### CloseHandle Calling Diff


```diff
--- wil::details::CloseHandle calling
+++ wil::details::CloseHandle calling
@@ -6,2 +6 @@
-wil::details_abi::SemaphoreValue::Destroy
-wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64>
+wil::details_abi::SemaphoreValue::TryGetPointer
```


## API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetProcessHeap|GetProcessHeap|
|fullname|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap|
|`refcount`|47|50|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>wil::ResultException::~ResultException<br>wil::StoredFailureInfo::SetFailureInfo<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::shared_buffer::create<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::RawUsageIndex::RecordUsage</summary>wil::details_abi::RawUsageIndex::SetBuffer<br>wil::details_abi::RawUsageIndex::Swap<br>wil::details_abi::RawUsageIndex::~RawUsageIndex<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::ThreadLocalData::SetLastError<br>wil::details_abi::ThreadLocalData::~ThreadLocalData<br>wil::details_abi::UsageIndexes::~UsageIndexes<br>wil::details_abi::heap_buffer::reserve<br>wil::details_abi::heap_buffer::~heap_buffer<br>wil_details_StagingConfig_Load</details>|<details><summary>Expand for full list:<br>wil::ResultException::~ResultException<br>wil::StoredFailureInfo::SetFailureInfo<br>wil::details::EnabledStateManager::`scalar_deleting_destructor'<br>wil::details::FeatureStateManager::`scalar_deleting_destructor'<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::shared_buffer::create<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release</summary>wil::details_abi::RawUsageIndex::RecordUsage<br>wil::details_abi::RawUsageIndex::SetBuffer<br>wil::details_abi::RawUsageIndex::Swap<br>wil::details_abi::RawUsageIndex::~RawUsageIndex<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::ThreadLocalData::SetLastError<br>wil::details_abi::ThreadLocalData::~ThreadLocalData<br>wil::details_abi::UsageIndexes::~UsageIndexes<br>wil::details_abi::heap_buffer::reserve<br>wil::details_abi::heap_buffer::~heap_buffer<br>wil_StagingConfig_QueryFeatureState<br>wil_details_StagingConfig_Load</details>|
|paramcount|0|0|
|`address`|EXTERNAL:00000074|EXTERNAL:00000076|
|sig|HANDLE __stdcall GetProcessHeap(void)|HANDLE __stdcall GetProcessHeap(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap Calling Diff


```diff
--- API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap calling
+++ API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap calling
@@ -2,0 +3 @@
+wil::details::EnabledStateManager::`scalar_deleting_destructor'
@@ -20,0 +22 @@
+wil_StagingConfig_QueryFeatureState
```


## KERNEL32.DLL::GetProcAddress

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetProcAddress|GetProcAddress|
|fullname|KERNEL32.DLL::GetProcAddress|KERNEL32.DLL::GetProcAddress|
|`refcount`|19|10|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CTpSampleManager::LoadTransactionLibrary<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details::RtlDisownModuleHeapAllocation<br>wil::details::RtlDllShutdownInProgress<br>wil::details::RtlNtStatusToDosErrorNoTeb<br>wil::details::UnregisterWilFeatureConfigurationChange<br>wil::details::UnsubscribeWilWnf<br>wil::details::WilApiImpl_RecordFeatureUsage<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_NtQueryWnfStateData</summary>wil_details_NtUpdateWnfStateData</details>|CTpSampleManager::LoadTransactionLibrary|
|paramcount|2|2|
|`address`|EXTERNAL:0000006c|EXTERNAL:0000006d|
|sig|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### KERNEL32.DLL::GetProcAddress Calling Diff


```diff
--- KERNEL32.DLL::GetProcAddress calling
+++ KERNEL32.DLL::GetProcAddress calling
@@ -2,11 +1,0 @@
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
-wil::details::RtlDisownModuleHeapAllocation
-wil::details::RtlDllShutdownInProgress
-wil::details::RtlNtStatusToDosErrorNoTeb
-wil::details::UnregisterWilFeatureConfigurationChange
-wil::details::UnsubscribeWilWnf
-wil::details::WilApiImpl_RecordFeatureUsage
-wil::details::WilDynamicLoadRaiseFailFastException
-wil_details_NtQueryWnfStateData
-wil_details_NtUpdateWnfStateData
```


## RtlDllShutdownInProgress

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.48|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|RtlDllShutdownInProgress|RtlDllShutdownInProgress|
|fullname|wil::details::RtlDllShutdownInProgress|wil::details::RtlDllShutdownInProgress|
|refcount|3|3|
|`length`|108|94|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|||
|paramcount|0|0|
|`address`|140007030|140005d50|
|sig|uchar __cdecl RtlDllShutdownInProgress(void)|uchar __cdecl RtlDllShutdownInProgress(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### RtlDllShutdownInProgress Called Diff


```diff
--- wil::details::RtlDllShutdownInProgress called
+++ wil::details::RtlDllShutdownInProgress called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## EnsureSubscribedToStateChangesUnderLock

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,calling,called|
|ratio|1.0|
|i_ratio|0.67|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|EnsureSubscribedToStateChangesUnderLock|EnsureSubscribedToStateChangesUnderLock|
|fullname|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock|
|refcount|3|3|
|`length`|309|288|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::UnsubscribeWilWnf<br>wil_details_NtQueryWnfStateData|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::SetLastError<br>GetLastError<br>GetModuleHandleW<br>GetProcAddress<br>__security_check_cookie<br>_guard_dispatch_icall<br>wil::details::UnsubscribeWilWnf<br>wil_details_NtQueryWnfStateData|
|`calling`|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock|wil::details::FeatureStateManager::SubscribeToEnabledStateChanges|
|paramcount|3|3|
|`address`|14000a400|140009ac4|
|sig|long __cdecl EnsureSubscribedToStateChangesUnderLock(unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,void_(__cdecl*)(struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64),&void___cdecl_wil::details::UnsubscribeWilWnf(struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,0,std::nullptr_t>_>_> * param_1, __WIL__WNF_STATE_NAME param_2, void * param_3)|long __cdecl EnsureSubscribedToStateChangesUnderLock(unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,void_(__cdecl*)(struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64),&void___cdecl_wil::details::UnsubscribeWilWnf(struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,struct___WIL__WNF_USER_SUBSCRIPTION*___ptr64,0,std::nullptr_t>_>_> * param_1, __WIL__WNF_STATE_NAME param_2, void * param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### EnsureSubscribedToStateChangesUnderLock Called Diff


```diff
--- wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock called
+++ wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError
@@ -3,2 +2,3 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetLastError
+GetModuleHandleW
+GetProcAddress
```


### EnsureSubscribedToStateChangesUnderLock Calling Diff


```diff
--- wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock calling
+++ wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock calling
@@ -1 +1 @@
-wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock
+wil::details::FeatureStateManager::SubscribeToEnabledStateChanges
```


## API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|SetThreadpoolTimer|SetThreadpoolTimer|
|fullname|API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer|API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer|
|`refcount`|4|5|
|length|0|0|
|called|||
|`calling`|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::details::EnabledStateManager::QueueBackgroundUsageReporting<br>wil::details::FeatureStateManager::EnsureTimerUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting|
|paramcount|4|4|
|`address`|EXTERNAL:0000007a|EXTERNAL:0000007c|
|sig|void __stdcall SetThreadpoolTimer(PTP_TIMER pti, PFILETIME pftDueTime, DWORD msPeriod, DWORD msWindowLength)|void __stdcall SetThreadpoolTimer(PTP_TIMER pti, PFILETIME pftDueTime, DWORD msPeriod, DWORD msWindowLength)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer Calling Diff


```diff
--- API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer calling
+++ API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::SetThreadpoolTimer calling
@@ -1,0 +2 @@
+wil::details::EnabledStateManager::QueueBackgroundUsageReporting
```


## API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|GetCurrentThreadId|GetCurrentThreadId|
|fullname|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId|API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId|
|`refcount`|7|4|
|length|0|0|
|called|||
|`calling`|__security_init_cookie<br>wil::GetFailureLogString<br>wil::details::GetContextAndNotifyFailure<br>wil::details::LogFailure<br>wil::details_abi::GetThreadLocalDataCache|__security_init_cookie|
|paramcount|0|0|
|`address`|EXTERNAL:00000051|EXTERNAL:0000004e|
|sig|DWORD __stdcall GetCurrentThreadId(void)|DWORD __stdcall GetCurrentThreadId(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId Calling Diff


```diff
--- API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId calling
+++ API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentThreadId calling
@@ -2,4 +1,0 @@
-wil::GetFailureLogString
-wil::details::GetContextAndNotifyFailure
-wil::details::LogFailure
-wil::details_abi::GetThreadLocalDataCache
```


## wil_details_NtQueryWnfStateData

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.63|
|m_ratio|0.97|
|b_ratio|0.97|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|wil_details_NtQueryWnfStateData|wil_details_NtQueryWnfStateData|
|fullname|wil_details_NtQueryWnfStateData|wil_details_NtQueryWnfStateData|
|refcount|8|8|
|`length`|161|147|
|`called`|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>KERNEL32.DLL::GetProcAddress<br>_guard_dispatch_icall|GetModuleHandleW<br>GetProcAddress<br>_guard_dispatch_icall|
|calling|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details_abi::RecordWnfUsageIndex<br>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load<br>wil_details_WriteSRUMWnfUsageBuffer|wil::details::FeatureStateManager::EnsureSubscribedToStateChangesUnderLock<br>wil::details_abi::RecordWnfUsageIndex<br>wil_details_StagingConfig_FireNotification<br>wil_details_StagingConfig_Load<br>wil_details_WriteSRUMWnfUsageBuffer|
|paramcount|6|6|
|`address`|140007144|140005e44|
|sig|undefined8 __fastcall wil_details_NtQueryWnfStateData(undefined8 param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4, undefined8 param_5, undefined8 param_6)|undefined8 __fastcall wil_details_NtQueryWnfStateData(undefined8 param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4, undefined8 param_5, undefined8 param_6)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_NtQueryWnfStateData Called Diff


```diff
--- wil_details_NtQueryWnfStateData called
+++ wil_details_NtQueryWnfStateData called
@@ -1,2 +1,2 @@
-API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW
-KERNEL32.DLL::GetProcAddress
+GetModuleHandleW
+GetProcAddress
```


## API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|CloseHandle|CloseHandle|
|fullname|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle|
|`refcount`|4|5|
|length|0|0|
|called|||
|`calling`|CTpSampleManager::Prune<br>WinMain<br>wil::details::CloseHandle|CTpSampleManager::Prune<br>WinMain|
|paramcount|1|1|
|address|EXTERNAL:00000032|EXTERNAL:00000032|
|sig|BOOL __stdcall CloseHandle(HANDLE hObject)|BOOL __stdcall CloseHandle(HANDLE hObject)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle Calling Diff


```diff
--- API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle calling
+++ API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle calling
@@ -3 +2,0 @@
-wil::details::CloseHandle
```


## wil_details_StagingConfig_Load

### Match Info



|Key|pre.exe - post.exe|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|pre.exe|post.exe|
| :---: | :---: | :---: |
|name|wil_details_StagingConfig_Load|wil_details_StagingConfig_Load|
|fullname|wil_details_StagingConfig_Load|wil_details_StagingConfig_Load|
|`refcount`|2|3|
|length|776|776|
|called|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>__security_check_cookie<br>memset<br>wil_details_NtQueryWnfStateData|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>__security_check_cookie<br>memset<br>wil_details_NtQueryWnfStateData|
|`calling`|wil::details::WilApiImpl_RecordFeatureUsage|wil::details::WilApiImpl_RecordFeatureUsage<br>wil_StagingConfig_QueryFeatureState|
|paramcount|4|4|
|`address`|1400072a8|140006268|
|sig|int __fastcall wil_details_StagingConfig_Load(undefined4 * param_1, undefined4 param_2, undefined8 param_3, char * param_4)|int __fastcall wil_details_StagingConfig_Load(undefined4 * param_1, undefined4 param_2, undefined8 param_3, char * param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_StagingConfig_Load Calling Diff


```diff
--- wil_details_StagingConfig_Load calling
+++ wil_details_StagingConfig_Load calling
@@ -1,0 +2 @@
+wil_StagingConfig_QueryFeatureState
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-16T18:08:25</sub>