<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/CryptoPkg/Library, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-08T04:05:18+00:00</updated>
<entry>
<title>CryptoPkg: Fix memcpy alias prototype to match the aliasee</title>
<updated>2026-09-08T04:05:18+00:00</updated>
<author>
<name>Sunil Dora</name>
<email>sunilkumar.dora@windriver.com</email>
</author>
<published>2026-08-30T05:39:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=a4610f9cfef179f2013156da9768039f52519f04'/>
<id>urn:sha1:a4610f9cfef179f2013156da9768039f52519f04</id>
<content type='text'>
The memcpy alias in IntrinsicLib declares its count parameter as
unsigned int while the aliasee __memcpy uses size_t. On 64-bit targets
these are different widths. clang 23 diagnoses this through
-Wattribute-alias:

  CopyMem.c:29:17: warning: alias and aliasee have different types
  'void *(void *, const void *, unsigned int)' and
  'void *(void *, const void *, size_t)' [-Wattribute-alias]

and builds that treat warnings as errors fail, e.g. OVMF built with
the CLANGDWARF toolchain in Yocto.

Declare the alias with size_t so both signatures agree.

Signed-off-by: Sunil Dora &lt;sunilkumar.dora@windriver.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix SIZE_MAX, UINTPTR_MAX and intptr_t definitions</title>
<updated>2026-08-31T12:55:20+00:00</updated>
<author>
<name>Doug Cook</name>
<email>dcook@microsoft.com</email>
</author>
<published>2026-08-16T00:10:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=ba43de142c8e9fde9ad2ef4b2fcd1a525e494968'/>
<id>urn:sha1:ba43de142c8e9fde9ad2ef4b2fcd1a525e494968</id>
<content type='text'>
CrtLibSupport.h defines SIZE_MAX and UINTPTR_MAX as 32-bit constants on
every target, even though the types they describe (size_t, uintptr_t) are
typedefs of UINTN and so are 64-bit on X64, AARCH64, IA64, RISCV64 and
LOONGARCH64.

UINTPTR_MAX definition was controlled by "#if (UINT_MAX &gt; 0xFFFFFFFFUL)",
which can never be true, so it was always set to UINT32_MAX.

Fix cannot just use MAX_UINTN because that isn't usable in preprocessor
conditions. Instead, define SIZE_MAX and UINTPTR_MAX based on CPU.

Without this, CryptoPkgMbedTls.dsc fails to build for AArch64:

  library/constant_time.c:58:5: error: invalid 'asm': invalid operand

In addition, the wrong SIZE_MAX silently removes length-overflow checks
that MbedTLS guards with "#if SIZE_MAX &gt; UINT_MAX", including the ASN.1
length check in asn1write.c and the input length check in nist_kw.c, and
selects 32-bit constant-time helper types in constant_time_internal.h.

Also correct intptr_t, which was a typedef of the unsigned UINTN. The
neighbouring ptrdiff_t and ssize_t already use INTN.

TcgTpmPkg/Private/Include/Standard/CrtLibSupport.h is a byte-identical
copy of this header and has the same defects. It is fixed by a separate
patch so that each commit stays within a single package.

Tested by building CryptoPkg/CryptoPkgMbedTls.dsc with GCC for AARCH64,
X64 and IA32. AARCH64 does not build without this change; X64 and IA32
are unaffected.

Signed-off-by: Doug Cook &lt;dcook@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Add Pkcs7Decrypt API</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Cook</name>
<email>dcook@microsoft.com</email>
</author>
<published>2026-07-27T23:15:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=5337420d7c59b446a4ec9f1348bc75e47de8299d'/>
<id>urn:sha1:5337420d7c59b446a4ec9f1348bc75e47de8299d</id>
<content type='text'>
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API.

I expect that the primary use of Pkcs7Decrypt would be for testing the
Pkcs7Encrypt API, but maybe somebody will need it for real work someday.

Signed-off-by: Doug Cook &lt;dcook@microsoft.com&gt;
Committed-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Add Pkcs7Encrypt for BaseCryptLibMbedTls</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Cook</name>
<email>dcook@microsoft.com</email>
</author>
<published>2026-05-07T22:31:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=294f56bcb3b41b733f4b5425e23512ab7a3270cf'/>
<id>urn:sha1:294f56bcb3b41b733f4b5425e23512ab7a3270cf</id>
<content type='text'>
Add CryptPkcs7Encrypt.c with an MbedTLS-based Pkcs7Encrypt()
implementation. Update BaseCryptLibMbedTls INF files
(BaseCryptLib.inf, SmmCryptLib.inf, UnitTestHostBaseCryptLib.inf)
to include the new source file, and update CryptoPkg/Readme.md
accordingly.

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Expose Pkcs7Encrypt via EDKII_CRYPTO_PROTOCOL</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Flick</name>
<email>dougflick@microsoft.com</email>
</author>
<published>2026-04-29T18:50:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=c13d86590220e1cc79d7db0bc34c687b41453c18'/>
<id>urn:sha1:c13d86590220e1cc79d7db0bc34c687b41453c18</id>
<content type='text'>
Add EDKII_CRYPTO_PKCS7_ENCRYPT typedef and Pkcs7Encrypt member to
the EDKII_CRYPTO_PROTOCOL structure. Bump protocol version to 25.
Add CryptoServicePkcs7Encrypt wrapper in the Crypto driver and
Pkcs7Encrypt wrapper in BaseCryptLibOnProtocolPpi. Add Pkcs7Encrypt
PCD bit to PcdCryptoServiceFamilyEnable for independent service
control. Update Readme.md feature table.

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Add Pkcs7Encrypt OpenSSL and null implementations</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Flick</name>
<email>dougflick@microsoft.com</email>
</author>
<published>2026-04-29T18:50:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=8b9b3808e1720f6be3aa2b6410bc817e9cfc62df'/>
<id>urn:sha1:8b9b3808e1720f6be3aa2b6410bc817e9cfc62df</id>
<content type='text'>
Add CryptPkcs7Encrypt.c with OpenSSL-based Pkcs7Encrypt()
implementation using PKCS7_encrypt API. Add null stub
implementations for library instances that do not support
this function (PEI, Runtime, SEC, MbedTLS, Null). Update all
BaseCryptLib INF files to include the new source files.

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Merge CryptoPkgMbedTls into CryptoPkg DSC file</title>
<updated>2026-08-28T07:30:11+00:00</updated>
<author>
<name>Longhaox Lee</name>
<email>longhaox.lee@intel.com</email>
</author>
<published>2026-07-24T06:54:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=f5e1b45e08e7d4949ad1f9482c525cb3bf38a37f'/>
<id>urn:sha1:f5e1b45e08e7d4949ad1f9482c525cb3bf38a37f</id>
<content type='text'>
Merge CryptoPkgMbedTls into CryptoPkg DSC.
Null instances for SlhDsa, MlDsa, EdDsa
since mbebtls not support.
Fixing build error for mbedtls BaseCryptLib.

Signed-off-by: Longhaox Lee &lt;longhaox.lee@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: add AARCH64 host unit test Rand source</title>
<updated>2026-07-31T15:16:47+00:00</updated>
<author>
<name>Jeff Brasen</name>
<email>jbrasen@nvidia.com</email>
</author>
<published>2026-07-02T03:04:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=158c70987bb3c919a3b4e91236e9dd9bd37b8f4b'/>
<id>urn:sha1:158c70987bb3c919a3b4e91236e9dd9bd37b8f4b</id>
<content type='text'>
The host-based BaseCryptLib instance (UnitTestHostBaseCryptLib.inf) built
Rand/CryptRandTsc.c only for IA32/X64.  Add Rand/CryptRand.c for AARCH64 so
the openssl-backed RandomSeed() is available when linking AARCH64 host
tests, and advertise AARCH64 in VALID_ARCHITECTURES.

Signed-off-by: Jeff Brasen &lt;jbrasen@nvidia.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Match OpenSSL's default security level</title>
<updated>2026-07-30T05:30:47+00:00</updated>
<author>
<name>Jean-Tiare Le Bigot</name>
<email>jt@yadutaf.fr</email>
</author>
<published>2026-06-16T09:10:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=b3f19fb5ce9e9214a74c71c1993023977b26c919'/>
<id>urn:sha1:b3f19fb5ce9e9214a74c71c1993023977b26c919</id>
<content type='text'>
`TlsNew()` explicitly sets the default security level to 3. The current
default in OpenSSL is security level 2 which is inherited by Linux
distributions like Ubuntu 26.04. This is also the security level that
was announced in https://edk2.groups.io/g/devel/topic/115039926.

Signed-off-by: Jean-Tiare Le Bigot &lt;jt@yadutaf.fr&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: Add SLH-DSA Support</title>
<updated>2026-07-21T09:17:50+00:00</updated>
<author>
<name>Michael G.A. Holland</name>
<email>michael.holland@intel.com</email>
</author>
<published>2026-07-14T14:34:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2b842a2081613684117fb1f924eb27a05a112e5d'/>
<id>urn:sha1:2b842a2081613684117fb1f924eb27a05a112e5d</id>
<content type='text'>
Created SLH-DSA API functions to configure public and private keys for
SLH-DSA algorithm.  This will allow users to sign and verify with
SLH-DSA.  Unit tests were added to confirm operation of the API.

Signed-off-by: Michael G.A. Holland &lt;michael.holland@intel.com&gt;
</content>
</entry>
</feed>
