<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/SecurityPkg/DeviceSecurity, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-08-03T01:40:40+00:00</updated>
<entry>
<title>SecurityPkg/DeviceSecurity: Update libspdm submodule to 3.8.2</title>
<updated>2026-08-03T01:40:40+00:00</updated>
<author>
<name>Mikey Strauss</name>
<email>mdstrauss91@gmail.com</email>
</author>
<published>2026-07-31T13:29:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=4bd628ce9844c04623ade7b875efaa19a6b57b35'/>
<id>urn:sha1:4bd628ce9844c04623ade7b875efaa19a6b57b35</id>
<content type='text'>
The libspdm submodule was pinned at 3.7.0 (2025-04-03), three releases behind
upstream 3.8.2 (2026-04-03). libspdm processes untrusted responder (device)
data in the SPDM device attestation path, so tracking upstream keeps that
parsing current with fixes and hardening.

Two responder-side advisories were resolved between 3.7.0 and 3.8.2:
  - GHSA-j54w-759w-xj3m: out-of-bounds write in GET_CSR handling.
  - GHSA-m4wc-xmvg-369f: integer overflow / out-of-bounds read in
    GET_MEASUREMENT_EXTENSION_LOG handling.
Both are responder-side. edk2 links SpdmRequesterLib (it acts as the SPDM
Requester that verifies an untrusted device Responder), so these responder
handlers are not built into edk2 images; this update is defense-in-depth
rather than a fix for a path reachable in edk2 today.

The libspdm sources referenced by the SpdmLib INFs are unchanged in 3.8.2
(the only additions are the optional ENDPOINT_INFO capability sources, which
edk2 does not enable), so no INF change is required.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Chris Fernald &lt;chfernal@microsoft.com&gt;

Signed-off-by: Mikey Strauss &lt;mdstrauss91@gmail.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Remove duplicate file name in INF file</title>
<updated>2026-04-29T09:18:10+00:00</updated>
<author>
<name>Qihang Gao</name>
<email>gaoqihang@loongson.cn</email>
</author>
<published>2026-04-23T02:02:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=25540b069f9f78ced4d0611db2bf8fe556453f01'/>
<id>urn:sha1:25540b069f9f78ced4d0611db2bf8fe556453f01</id>
<content type='text'>
In SpdmSecuredMessageLib, libspdm_secmes_encode_decode.c appears twice
in [Sources] section, so remove the duplicate one.

Signed-off-by: Qihang Gao &lt;gaoqihang@loongson.cn&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Replace include guards with #pragma once</title>
<updated>2026-02-23T21:01:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-02-03T19:20:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=9326c0eb0a9b5b82fef335e46fbd85868d318a7d'/>
<id>urn:sha1:9326c0eb0a9b5b82fef335e46fbd85868d318a7d</id>
<content type='text'>
Replace traditional `#ifndef`/`#define`/`#endif` include guards with
`#pragma` once.

`#pragma once` is a widely supported preprocessor directive that
prevents header files from being included multiple times. It is
supported by all toolchains used to build edk2: GCC, Clang/LLVM, and
MSVC.

Compared to macro-based include guards, `#pragma once`:

- Eliminates the risk of macro name collisions or copy/paste errors
  where two headers inadvertently use the same guard macro.
- Eliminate inconsistency in the way include guard macros are named
  (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.).
- Reduces boilerplate (three lines replaced by one).
- Avoids polluting the macro namespace with guard symbols.
- Can improve build times as the preprocessor can skip re-opening the
  file entirely, rather than re-reading it to find the matching
  `#endif` ("multiple-include optimization").
  - Note that some compilers may already optimize traditional include
    guards, by recognzining the idiomatic pattern.

This change is made acknowledging that overall portability of the
code will technically be reduced, as `#pragma once` is not part of the
C/C++ standards.

However, this is considered acceptable given:

1. edk2 already defines a subset of supported compilers in
   BaseTools/Conf/tools_def.template, all of which have supported
   `#pragma once` for over two decades.
2. There have been concerns raised to the project about inconsistent
   include guard naming and potential macro collisions.

Approximate compiler support dates:

- MSVC: Supported since Visual C++ 4.2 (1996)
- GCC: Supported since 3.4 (2004)
  (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html)
- Clang (LLVM based): Since initial release in 2007

Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Update libspdm to 3.7.0</title>
<updated>2025-11-22T08:07:05+00:00</updated>
<author>
<name>Mike Beaton</name>
<email>mjsbeaton@gmail.com</email>
</author>
<published>2025-11-08T08:02:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=8e90e2cbcfd2e5288b31dff097bd7d6f03515486'/>
<id>urn:sha1:8e90e2cbcfd2e5288b31dff097bd7d6f03515486</id>
<content type='text'>
https://github.com/DMTF/libspdm/commit/0f6c6a3e800f487242b973b5858c534186a7db05
fixes incorrectly typed return values in libspdm_hmac_new.

Without this commit XCODE5 refuses to build SecurityPkg, with multiple
errors corresponding to the lines fixed above, each of the form:

libspdm_crypt_hmac.c:31:16: error: expression which evaluates to zero treated as a null pointer constant of type 'void *'

I have updated libspdm to the minimum whole build number which includes
the required commit, though higher releases than 3.7.0, up to 3.8.1, are
available.

Signed-off-by: Mike Beaton &lt;mjsbeaton@gmail.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/SpdmSecurityLib: Fix incompatible pointer types</title>
<updated>2025-11-21T16:33:06+00:00</updated>
<author>
<name>Oliver Steffen</name>
<email>osteffen@redhat.com</email>
</author>
<published>2025-11-05T17:35:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=56f2d5890840aa92e714e056706223f113063cc8'/>
<id>urn:sha1:56f2d5890840aa92e714e056706223f113063cc8</id>
<content type='text'>
GCC 15 enforces stricter type checking for function pointers. When
passing SPDM transport layer callbacks to
libspdm_register_transport_layer_func, the function pointer types are
incompatible due to differences in boolean parameter types.

The EDK2 uses BOOLEAN (UINT8) while libspdm uses C99 bool (_Bool).
Although these types have the same size and representation,
GCC 15 treats them as incompatible.

Add explicit casts to libspdm_transport_encode_message_func and
libspdm_transport_decode_message_func at the call site to resolve
the type mismatch. This is safe as the types have identical binary
representation and the functions are only called through these
pointers by libspdm.

Signed-off-by: Oliver Steffen &lt;osteffen@redhat.com&gt;
(cherry picked from commit aca8f995405b2bdc48997ce5b0daa975225164e6)
</content>
</entry>
<entry>
<title>SecurityPkg/SpdmCryptLib: Fix CLANG 20.1.0 error</title>
<updated>2025-06-13T15:47:59+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2025-05-19T19:22:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=18164e8c697557343092f305fc654de7b7261589'/>
<id>urn:sha1:18164e8c697557343092f305fc654de7b7261589</id>
<content type='text'>
Some of the spdmlib crypto functions return 'false' in
functions that return a pointer to indicate a null
return. false is mapped to FALSE to cover other usages
to return a boolean value.

Add -Wno-non-literal-null-conversion for CLANGPDB and
CLANGDWARF to ignore these types of errors from CLANG
builds within this one library build that uses the
spdmlib git submodule.

Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/Spdm: Use spdmlib enums for spdmlib calls</title>
<updated>2025-06-13T15:47:59+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2025-05-19T19:19:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=cbbd0f747f81acabc744d9f5101a018595062fbd'/>
<id>urn:sha1:cbbd0f747f81acabc744d9f5101a018595062fbd</id>
<content type='text'>
Fix CLANG 20.1.0 enum conversion errors

Address implied conversion between enum types by using
the enum type from spdmlib and remove the enum types
that are never used after this update.

Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Don't define bool type if building in C23 mode</title>
<updated>2025-05-29T23:15:20+00:00</updated>
<author>
<name>Rebecca Cran</name>
<email>rebecca@bsdio.com</email>
</author>
<published>2025-05-26T14:01:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=772fa11ac82579a8f6fa171e6b835f68af3f64be'/>
<id>urn:sha1:772fa11ac82579a8f6fa171e6b835f68af3f64be</id>
<content type='text'>
In C23 bool is a built-in type, so it's not necessary to typedef
bool in LibspdmStdBoolAlt.h.

Signed-off-by: Rebecca Cran &lt;rebecca@bsdio.com&gt;
</content>
</entry>
<entry>
<title>SPDM related fix based on real hardware testing - SecurityPkg</title>
<updated>2025-05-29T06:50:12+00:00</updated>
<author>
<name>Liqi Qi</name>
<email>liqiqi@microsoft.com</email>
</author>
<published>2025-05-15T20:20:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=0321f030ea917acd0b0de689df3b943661bf120a'/>
<id>urn:sha1:0321f030ea917acd0b0de689df3b943661bf120a</id>
<content type='text'>
Implemented SPDM functionality on real hardware, and here is the bug fix in SecurityPkg.

Signed-off-by: Liqi Qi &lt;liqiqi@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Update libspdm</title>
<updated>2024-11-26T02:15:06+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2024-11-22T15:46:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=7eff71fe690a0f5bc0be67b5b83f263d7892f9b6'/>
<id>urn:sha1:7eff71fe690a0f5bc0be67b5b83f263d7892f9b6</id>
<content type='text'>
This patch updates libspdm to pull in various bug fixes,
but primarily commit ca4854be3325bd8fc7f2c714574d17aac2d4e13b
which updates libspdm's MbedTLS submodule to v3.6.2, fixing
CVE https://nvd.nist.gov/vuln/detail/CVE-2023-37920 there.
This CVE does not affect libspdm or edk2, but automatic
CVE scanning tools see the bad version of the certifi
pip module in the edk2/libspdm code trees and flag these
projects as failing.
libspdm has been updated to pull in the newer MbedTLS that
fixes this issue and this patch updates edk2 to pull in
the newer libspdm.

Signed-off-by: Oliver Smith-Denny &lt;osde@linux.microsoft.com&gt;
</content>
</entry>
</feed>
