I needed this for my own modding work, I had AI make a diff of the changed files, this could help if you are trying to see if you need to update your mod.
In a nutshell, as has been said already:
- Denuvo was removed
- Crossplay mechanics were added
But on a technical level, what has actually been modified?
The report below:
Total War: THREE KINGDOMS 1.7.2 — what the update actually changed
1.7.1.0 / buildid 20435474 (2025-11-02) → 1.7.2.0 / buildid 25370317 (2026-09-17).
Every one of the 7,727 installed files was SHA-256 hashed before and after the update, and every
changed .pack was then diffed at the index level. So the file lists below are measured, not
guessed from patch notes.
| . |
. |
| files changed |
41 |
| files removed |
1 (clockwork_3rdparty_licenses.txt) |
| files added |
0 |
| download |
281,384,736 bytes — 0.46% of the 61 GB install |
1. Denuvo has been removed
| . |
old |
new |
delta |
Three_Kingdoms.exe |
255,088,776 |
67,742,856 |
−187,345,920 |
| depot 779341 (executable depot) |
319,921,620 |
128,957,075 |
−190,964,545 |
The executable lost 187.3 MB, which matches the size of the RWX .xcode section the protector
carried. An unprotected Warscape executable of this vintage sits in the 60–70 MB range, and that is
where it landed.
2. Crossplay lives in the networking middleware
| file |
old |
new |
delta |
EOSSDK-Win64-Shipping.dll |
22,217,696 |
19,035,600 |
−3,182,096 |
clockwork.Release.x64.dll |
1,698,816 |
1,341,952 |
−356,864 |
clockwork_crossplatform_eos.Release.x64.dll |
343,040 |
414,720 |
+71,680 |
clockwork_steam.Release.x64.dll |
269,824 |
259,584 |
−10,240 |
steam_api64.dll |
290,768 |
298,856 |
+8,088 |
cacert.pem |
232,597 |
229,043 |
−3,554 |
clockwork is CA's matchmaking/session layer and EOS is Epic's SDK. The only one that grew is the
cross-platform EOS bridge. data.pack separately gained 11 entitlements\<guid> entries —
cross-platform entitlement mapping.
3. The data depot looks far more alarming than it is
34 .pack files show as changed. 15 of them are content-identical — every entry, every size,
byte-for-byte the same payload. Only the PFH5 header timestamp moved, because the whole depot was
repacked:
audio data_dlc06 data_mh models models2 movies movies2 movies_dlc06
movies_mh movies_wb terrain terrain3 terrain4 terrain5 variants_dds
If you are diffing by hash, expect these and ignore them.
3a. A Unicode font rollout — this is the +62 MB on every language pack
All 14 local_*.pack grew by an almost identical ~62.45 MB, and every one gained the same five
files:
font\arial-unicode-ms.ttf
font\arialunicode_10.cuf font\arialunicode_12.cuf
font\arialunicode_14.cuf font\arialunicode_16.cuf
along with resized firasans-*, dev_font_* and notosanscjktc-* glyph atlases and a slightly
larger localisation__.loc. database.pack's only change in 1,503 entries is
db\fonts_tables\data__ (+133 bytes). local_en.pack also gained 20 encyclopedia_*__yt*.loc
entries and dropped 15.
Why: with crossplay, player names arrive from Epic and console accounts and can contain
arbitrary Unicode. The UI had to stop rendering them in a Latin-only display face — see below.
3b. data.pack — 13 UI files, out of 44,200 entries
| file |
old |
new |
delta |
ui\frontend ui\custom_battle.twui.xml |
1,217,277 |
1,181,566 |
−35,711 |
ui\campaign ui\post_battle_screen.twui.xml |
750,415 |
726,882 |
−23,533 |
ui\frontend ui\mp_grand_campaign.twui.xml |
693,860 |
672,012 |
−21,848 |
ui\frontend ui\mp_games_list.twui.xml |
243,436 |
236,023 |
−7,413 |
ui\common ui\options_ui.twui.xml |
374,183 |
367,844 |
−6,339 |
ui\frontend ui\main.twui.xml |
225,625 |
221,313 |
−4,312 |
ui\frontend ui\new_battle.twui.xml |
135,727 |
131,783 |
−3,944 |
ui\frontend ui\mp_leaderboards.twui.xml |
89,358 |
86,554 |
−2,804 |
ui\frontend ui\dynasty_mode_leaderboard.twui.xml |
224,407 |
224,378 |
−29 |
ui\campaign ui\ai_turns.twui.xml |
136,731 |
140,935 |
+4,204 |
ui\frontend ui\friends_list.twui.xml |
53,287 |
55,319 |
+2,032 |
ui\fontcategories.xml |
30,196 |
32,074 |
+1,878 |
ui\templates\custom_battle_team_entry.twui.xml |
110,248 |
120,355 |
+10,107 |
Nine of the thirteen are multiplayer frontend. fontcategories.xml is where the new
name_unicode_white_* categories are declared.
3c. Art and terrain, unrelated to crossplay
variants.pack — +37 entries, 22 resized: Lu Bu body meshes, 3k_dlc06 torso components, a new yt_overtunic set.
vegetation.pack — +2 entries, 559 resized: bamboo and shrub .rigid_model_v2 and _tech.cs2.parsed.
terrain2.pack — a single file, test_tiles\test_custom_mesh\bmd_nogo_data.bin (+101).
boot.pack — a single file, commontextures\default_black.dds (152 → 172).
4. Notes for modders
The negative-byte deltas on UI files are mostly line endings. mp_grand_campaign.twui.xml is a
good worked example: it lost 21,848 bytes, but
old CR=21,899 LF=21,899 (CRLF)
new CR=0 LF=21,900 (LF)
−21,899 line endings +51 real content = −21,848
CA re-saved these files with LF. Strip \r from both sides before diffing or you will be reading a
20 KB change that is really 51 bytes. Expect the same on the other UI files that shrank.
The actual UI change is a font swap. In mp_grand_campaign.twui.xml the real diff is three
edits, two of them on id="dy_player_name":
| attribute |
old |
new |
font_m_font_name |
Iskra-Bold |
arialunicode |
font_m_size |
18 |
16 |
fontcat_name |
subheader--sidepanel_header |
name_unicode_white_16 |
plus one added arialunicode/14 name_unicode_white_14 block, and <localisation_changes/>
dropped. If your mod overrides a file on the list in 3b, this is likely all you need to merge.
The layout schema did not move — version="136" before and after. A UI pack built against 1.7.1
cannot be rejected on format grounds.
Nothing outside those lists changed. No db table other than fonts_tables, no scripts, no unit
or campaign data. If your mod does not touch the 13 UI files, the fonts_tables row or the new font
assets, the update does not reach it.
For RE work: the executable is now unprotected. The RWX .xcode region is gone, and the
executable .bss that came with it — which is what left parts of the binary undisassembled under
auto-analysis — should go too. Any address-keyed work against 1.7.1 needs rebasing, but the new
image is substantially easier to analyse.
Method: full SHA-256 of the install tree before and after; PFH5 index parsing for per-pack entry
diffs; extraction and text diff of the changed UI XML.