<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/CryptoPkg/Library/BaseCryptLib/SysCall/CrtWrapper.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2025-07-17T14:45:20+00:00</updated>
<entry>
<title>CryptoPkg/CrtLib: add strpbrk implementation</title>
<updated>2025-07-17T14:45:20+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2025-04-24T10:06:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2a36117d7af2632d15df624074ac650798c247d6'/>
<id>urn:sha1:2a36117d7af2632d15df624074ac650798c247d6</id>
<content type='text'>
Needed by openssl-3.5.1.

Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Resolve CodeQL Errors</title>
<updated>2025-04-21T02:14:50+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2025-04-18T20:51:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2e85d12685b950dc8ff54130f9d623a120f852d6'/>
<id>urn:sha1:2e85d12685b950dc8ff54130f9d623a120f852d6</id>
<content type='text'>
This patch updates several CodeQL errors for potential null pointer
access and unguarded header conclusion across production and test
code that have been flagged in the build/security tab in GitHub.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix BaseCryptLib CrtWrapper strncpy and strcat</title>
<updated>2024-06-07T13:23:04+00:00</updated>
<author>
<name>Sebastian Witt</name>
<email>sebastian.witt@siemens.com</email>
</author>
<published>2024-06-04T11:38:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=948f23417010309a5557d46195eae258f6105025'/>
<id>urn:sha1:948f23417010309a5557d46195eae258f6105025</id>
<content type='text'>
Following https://bugzilla.tianocore.org/show_bug.cgi?id=2817 this
bug could also apply to strncpy and strcat.

For strncpy use count+1 if smaller than MAX_STRING_SIZE. This still
restricts the destination size to MAX_STRING_SIZE as before but allows
a strncpy when the source is close after destination without triggering
the InternalSafeStringNoAsciiStrOverlap check in AsciiStrnCpyS.

For strcat use the destination string length + the size of the source
string including the terminator as destination size if smaller than
MAX_STRING_SIZE.

Also move both functions to CrtWrapper.c as they do not return the
correct return value. AsciiStrnCpyS and AsciiStrCatS return
RETURN_VALUE instead of a char * to the destination buffer.

Signed-off-by: Sebastian Witt &lt;sebastian.witt@siemens.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix BaseCryptLib CrtWrapper strcpy</title>
<updated>2024-06-07T13:23:04+00:00</updated>
<author>
<name>Sebastian Witt</name>
<email>sebastian.witt@siemens.com</email>
</author>
<published>2024-06-04T11:10:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=df8c61e4c071d1c6ab04e3ebeeb07cf97fc893e0'/>
<id>urn:sha1:df8c61e4c071d1c6ab04e3ebeeb07cf97fc893e0</id>
<content type='text'>
strcpy fails when strSource is closer than 4096 bytes after strDest.

This is caused by an overlap check in AsciiStrCpyS:
  //
  // 5. Copying shall not take place between objects that overlap.
  //
  SAFE_STRING_CONSTRAINT_CHECK (InternalSafeStringNoAsciiStrOverlap
  (Destination, DestMax, (CHAR8 *)Source, SourceLen + 1),
  RETURN_ACCESS_DENIED);

Since DestMax is MAX_STRING_SIZE (0x1000) and with a Source
that is in this area behind Destination, AsciiStrCpyS will fail
and strcpy will do nothing.

When called by CRYPTO_strdup in openssl this leads to uninitialzed
memory that gets accessed instead of the copied string.

BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2817

Signed-off-by: Sebastian Witt &lt;sebastian.witt@siemens.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: remove strcmp to syscall</title>
<updated>2023-08-09T07:10:31+00:00</updated>
<author>
<name>Yi Li</name>
<email>yi1.li@intel.com</email>
</author>
<published>2023-08-03T04:37:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=46226fb5d32f6e24eb8f8f48cceb0f67fd8585d4'/>
<id>urn:sha1:46226fb5d32f6e24eb8f8f48cceb0f67fd8585d4</id>
<content type='text'>
In rare cases the platform may not provide the full IntrinsicLib.
But openssl30 build always require strcmp, provide this function by
moving it into CrtWrapper.c.

Signed-off-by: Yi Li &lt;yi1.li@intel.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Xiaoyu Lu &lt;xiaoyu1.lu@intel.com&gt;
Cc: Guomin Jiang &lt;guomin.jiang@intel.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Acked-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
Tested-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
Tested-by: Brian J. Johnson &lt;brian.johnson@hpe.com&gt;
Tested-by: Kenneth Lautner &lt;klautner@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: drop BIO_* dummy functions</title>
<updated>2023-08-09T07:10:31+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2023-08-03T04:37:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2a6dc1211f9b73ca6264ce7c2ab1a8dfeb1f1c0f'/>
<id>urn:sha1:2a6dc1211f9b73ca6264ce7c2ab1a8dfeb1f1c0f</id>
<content type='text'>
openssl 3.0 requires a functional BIO_sprintf() implementation.

Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Xiaoyu Lu &lt;xiaoyu1.lu@intel.com&gt;
Cc: Guomin Jiang &lt;guomin.jiang@intel.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Acked-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
Tested-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
Tested-by: Brian J. Johnson &lt;brian.johnson@hpe.com&gt;
Tested-by: Kenneth Lautner &lt;klautner@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix pem heap-buffer-overflow due to BIO_snprintf()</title>
<updated>2022-09-26T01:39:52+00:00</updated>
<author>
<name>Yi Li</name>
<email>yi1.li@intel.com</email>
</author>
<published>2022-09-26T00:24:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=0e7aa6bf9e0a7a91136353a3d6fe6a90d2047fc0'/>
<id>urn:sha1:0e7aa6bf9e0a7a91136353a3d6fe6a90d2047fc0</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4075

Fake BIO_snprintf() does not actually print anything to buf,
it should return -1 as error.
0 will be considered a correct return value, the consumer may think that
the buf is valid and parse the buffer.
please refer to bugzilla link for details.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Cc: Xiaoyu Lu &lt;xiaoyu1.lu@intel.com&gt;
Cc: Guomin Jiang &lt;guomin.jiang@intel.com&gt;

Signed-off-by: Yi Li &lt;yi1.li@intel.com&gt;
Reviewed-by: Jiewen Yao &lt;Jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/Crt: fix strcpy build on older VS compilers</title>
<updated>2022-04-20T10:56:03+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2022-04-20T06:16:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=532bd4ec384b8e5764d97a62e5bd01fdbae6bd7a'/>
<id>urn:sha1:532bd4ec384b8e5764d97a62e5bd01fdbae6bd7a</id>
<content type='text'>
Drop 'restrict' keyword which older visual studio compiler
versions complain about.

Fixes: fab6285a73c4 ("CryptoPkg/CrtLibSupport: fix strcpy")
Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/CrtLibSupport: fix strcpy</title>
<updated>2022-04-12T14:39:01+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2022-04-11T11:24:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=fab6285a73c4c73bb131792d0afb20be369082d1'/>
<id>urn:sha1:fab6285a73c4c73bb131792d0afb20be369082d1</id>
<content type='text'>
strcpy() returns a pointer to the destination string, AsciiStrCpyS()
does not.  So a simple #define does not work.  Create a function
instead.

Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Reviewed-by: Jiewen Yao &lt;Jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Apply uncrustify changes</title>
<updated>2021-12-07T17:24:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2021-12-05T22:53:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=7c342378317039e632d9a1a5d4cf7c21aec8cb7a'/>
<id>urn:sha1:7c342378317039e632d9a1a5d4cf7c21aec8cb7a</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3737

Apply uncrustify changes to .c/.h files in the CryptoPkg package

Cc: Andrew Fish &lt;afish@apple.com&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
</feed>
