<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/SecurityPkg/Library/AuthVariableLib, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-08T18:20:17+00:00</updated>
<entry>
<title>SecurityPkg: Fix wider-type comparisons</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-09-01T17:39:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=50381846d4b9853aa3a901d6a4c2b3091d66014e'/>
<id>urn:sha1:50381846d4b9853aa3a901d6a4c2b3091d66014e</id>
<content type='text'>
Makes changes to comply with CodeQL comparison-with-wider-type alerts.

Some of these have safe patterns even with wider type comparisons,
so an explicit cast is used to make the intention clear and
silence the failure.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/AuthVariableLib: harden signature list filtering</title>
<updated>2026-06-30T02:35:17+00:00</updated>
<author>
<name>20000419</name>
<email>lzy20000419@outlook.com</email>
</author>
<published>2026-04-18T14:33:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=4f475ba54293b5da8fe375a9cdf97a5da1464011'/>
<id>urn:sha1:4f475ba54293b5da8fe375a9cdf97a5da1464011</id>
<content type='text'>
Signed-off-by: 20000419 &lt;lzy20000419@outlook.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: AuthVariableLib: Handle empty signature lists</title>
<updated>2026-03-10T06:33:40+00:00</updated>
<author>
<name>Kun Qin</name>
<email>kuqin@microsoft.com</email>
</author>
<published>2026-03-03T00:16:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=b980aa07196a5534581b16563cd78cfc67a74074'/>
<id>urn:sha1:b980aa07196a5534581b16563cd78cfc67a74074</id>
<content type='text'>
The current implementation fails to set authenticated variables when the
signature list is empty. This can legitimately occur for dbx when no
signatures are revoked after a certificate rotation.

Update the logic to explicitly handle empty signature lists, avoiding an
implicit dependency on the variable being absent from variable storage.

Signed-off-by: Kun Qin &lt;kun.qin@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Replace include guards with #pragma once</title>
<updated>2026-02-23T21:01:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-02-03T19:20:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=9326c0eb0a9b5b82fef335e46fbd85868d318a7d'/>
<id>urn:sha1:9326c0eb0a9b5b82fef335e46fbd85868d318a7d</id>
<content type='text'>
Replace traditional `#ifndef`/`#define`/`#endif` include guards with
`#pragma` once.

`#pragma once` is a widely supported preprocessor directive that
prevents header files from being included multiple times. It is
supported by all toolchains used to build edk2: GCC, Clang/LLVM, and
MSVC.

Compared to macro-based include guards, `#pragma once`:

- Eliminates the risk of macro name collisions or copy/paste errors
  where two headers inadvertently use the same guard macro.
- Eliminate inconsistency in the way include guard macros are named
  (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.).
- Reduces boilerplate (three lines replaced by one).
- Avoids polluting the macro namespace with guard symbols.
- Can improve build times as the preprocessor can skip re-opening the
  file entirely, rather than re-reading it to find the matching
  `#endif` ("multiple-include optimization").
  - Note that some compilers may already optimize traditional include
    guards, by recognzining the idiomatic pattern.

This change is made acknowledging that overall portability of the
code will technically be reduced, as `#pragma once` is not part of the
C/C++ standards.

However, this is considered acceptable given:

1. edk2 already defines a subset of supported compilers in
   BaseTools/Conf/tools_def.template, all of which have supported
   `#pragma once` for over two decades.
2. There have been concerns raised to the project about inconsistent
   include guard naming and potential macro collisions.

Approximate compiler support dates:

- MSVC: Supported since Visual C++ 4.2 (1996)
- GCC: Supported since 3.4 (2004)
  (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html)
- Clang (LLVM based): Since initial release in 2007

Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
</content>
</entry>
<entry>
<title>Revert "SecurityPkg: CodeQL Fixes."</title>
<updated>2025-08-12T03:50:30+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2025-08-11T17:47:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=072ab3846c4fd86387dfd5d191dcb91e98202023'/>
<id>urn:sha1:072ab3846c4fd86387dfd5d191dcb91e98202023</id>
<content type='text'>
This reverts commit ba6a8eb045aededbc1472cce7314ab1911f0ea1c.

PR https://github.com/tianocore/edk2/pull/11307 introduced a
logic change that caused regressions in FV verification on
some platforms. This PR is being reverted to restore the prior
logic.

The Code QL fixes in https://github.com/tianocore/edk2/pull/11307
can be resubmitted without the logic change along with one
commit for each type of Code QL issue being addressed.

Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: CodeQL Fixes.</title>
<updated>2025-07-24T01:58:06+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2024-07-30T17:56:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=ba6a8eb045aededbc1472cce7314ab1911f0ea1c'/>
<id>urn:sha1:ba6a8eb045aededbc1472cce7314ab1911f0ea1c</id>
<content type='text'>
Makes changes to comply with alerts raised by CodeQL.

Most of the issues here fall into the following two categories:

1. Potential use of uninitialized pointer.
2. Inconsistent integer width in comparison.

Co-authored-by: Taylor Beebe &lt;31827475+TaylorBeebe@users.noreply.github.com&gt;
Co-authored-by: kenlautner &lt;85201046+kenlautner@users.noreply.github.com&gt;
Co-authored-by: Bret Barkelew &lt;bret@corthon.com&gt;

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>Remove unnecessary RsaFree call in failing path</title>
<updated>2025-04-17T04:11:48+00:00</updated>
<author>
<name>Baraneedharan Anbazhagan</name>
<email>anbazhagan@hp.com</email>
</author>
<published>2025-04-08T18:03:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=5f5cf1c1abd222a39952bce0a884dec44b4fd81e'/>
<id>urn:sha1:5f5cf1c1abd222a39952bce0a884dec44b4fd81e</id>
<content type='text'>
Signed-off-by: Anbazhagan Baraneedharan &lt;anbazhagan@hp.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/AuthVariableLib: Fix memory leak in CheckSignatureListFormat</title>
<updated>2025-04-17T04:11:48+00:00</updated>
<author>
<name>Baraneedharan Anbazhagan</name>
<email>anbazhagan@hp.com</email>
</author>
<published>2025-03-24T15:17:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=fce142fd31b54caae5f5346cdce382ac5a3e044d'/>
<id>urn:sha1:fce142fd31b54caae5f5346cdce382ac5a3e044d</id>
<content type='text'>
RsaGetPublicKeyFromX509  allocates memory for RsaContext parameter
and the memory allocated earlier is not necessary

Signed-off-by: Anbazhagan Baraneedharan &lt;anbazhagan@hp.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/SecureBoot: Support RSA4096 and RSA3072</title>
<updated>2023-09-07T06:12:18+00:00</updated>
<author>
<name>Sheng Wei</name>
<email>w.sheng@intel.com</email>
</author>
<published>2023-09-07T01:57:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=bbf182229587958b17336c114e0a1525c4f90f3d'/>
<id>urn:sha1:bbf182229587958b17336c114e0a1525c4f90f3d</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3413

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Cc: Min Xu &lt;min.m.xu@intel.com&gt;
Cc: Zeyi Chen &lt;zeyi.chen@intel.com&gt;
Cc: Fiona Wang &lt;fiona.wang@intel.com&gt;
Signed-off-by: Sheng Wei &lt;w.sheng@intel.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Update code to be more C11 compliant by using __func__</title>
<updated>2023-04-10T14:19:57+00:00</updated>
<author>
<name>Rebecca Cran</name>
<email>rebecca@bsdio.com</email>
</author>
<published>2023-04-06T19:50:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=dd0b33e3e55957aecbae6aa5cebdc6c14e6e8932'/>
<id>urn:sha1:dd0b33e3e55957aecbae6aa5cebdc6c14e6e8932</id>
<content type='text'>
__FUNCTION__ is a pre-standard extension that gcc and Visual C++ among
others support, while __func__ was standardized in C99.

Since it's more standard, replace __FUNCTION__ with __func__ throughout
SecurityPkg.

Signed-off-by: Rebecca Cran &lt;rebecca@bsdio.com&gt;
Reviewed-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Reviewed-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
</content>
</entry>
</feed>
