<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/SecurityPkg/Library, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-29T06:13:02+00:00</updated>
<entry>
<title>SecurityPkg/FmpAuthenticationLibPkcs7: Use pages for scratch buffer</title>
<updated>2026-09-29T06:13:02+00:00</updated>
<author>
<name>Anandh Krishna U</name>
<email>anandhkrishnau@ami.com</email>
</author>
<published>2026-09-23T10:19:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=75400a462b52c349dd070e6f6d435511cbf7db13'/>
<id>urn:sha1:75400a462b52c349dd070e6f6d435511cbf7db13</id>
<content type='text'>
FmpAuthenticatedHandlerPkcs7() allocates a scratch buffer whose size is
(ImageSize - AuthInfo.Hdr.dwLength): the full firmware payload plus the
8-byte monotonic count, assembled contiguously for Pkcs7Verify().

The library declares support for the DXE and post-memory PEI phases.
In PEI, MemoryAllocationLib's AllocatePool() maps to PeiAllocatePool(),
which builds an EFI_HOB_TYPE_MEMORY_POOL HOB and rejects any request
larger than (0xFFF8 - sizeof (EFI_HOB_MEMORY_POOL)), i.e. just under
64 KiB. PeiAllocatePool() itself notes that a post-memory PEIM wanting a
larger pool should use the AllocatePages service instead.

As a result, authenticating any image whose payload exceeds that limit
fails at allocation with RETURN_OUT_OF_RESOURCES before Pkcs7Verify() is
ever called. Callers that map this to a status code report an
authentication/security failure for an otherwise validly signed image.

Allocate the scratch buffer with AllocatePages (EFI_SIZE_TO_PAGES (Size))
and release it with the matching FreePages (). The data assembled for
Pkcs7Verify() is unchanged, so authentication results are identical for
valid and invalid signatures. The DXE phase is unaffected because its
pool allocator has no comparable size limit.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Chris Fernald &lt;chfernal@microsoft.com&gt;
Signed-off-by: Anandh krishna U &lt;anandhkrishnau@ami.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/TcgEventLogRecordLib: Define LIBRARY_CLASS</title>
<updated>2026-09-24T18:29:59+00:00</updated>
<author>
<name>Vishal Oliyil Kunnil</name>
<email>vishalo@qti.qualcomm.com</email>
</author>
<published>2026-09-16T20:44:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=f002c2859834cd7c5f40bb16e22b2a5f6b07e5be'/>
<id>urn:sha1:f002c2859834cd7c5f40bb16e22b2a5f6b07e5be</id>
<content type='text'>
Set LIBRARY_CLASS to TcgEventLogRecordLib instead of NULL.

The library is already consumed through TcgEventLogRecordLib DSC
mappings and INF dependencies. Defining the library class explicitly
matches its current usage and avoids build warnings.

Signed-off-by: Vishal Oliyil Kunnil &lt;vishalo@qti.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Remove Globals from HashLibTpm2PeilessSec</title>
<updated>2026-09-22T02:10:45+00:00</updated>
<author>
<name>rdiaz</name>
<email>raymonddiaz@microsoft.com</email>
</author>
<published>2026-09-18T20:10:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=a01335df4158c8f9ba9c186e80cb1ed83d05ec3e'/>
<id>urn:sha1:a01335df4158c8f9ba9c186e80cb1ed83d05ec3e</id>
<content type='text'>
Updated the HashLibTpm2PeilessSec library to no longer use globals in
SEC. Changed the code to query the relevant information each time it
was needed either through the TPM or Transfer List.

Signed-off-by: Raymond Diaz &lt;raymonddiaz@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Propagate Cryptographic Operation Failures</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-08-31T17:30:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=58a00ddd494845143667da0d807fa517bc5447b1'/>
<id>urn:sha1:58a00ddd494845143667da0d807fa517bc5447b1</id>
<content type='text'>
Check and propagate failures in HashLibBaseCryptoRouter
and RngDxe.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Fix wider-type comparisons</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-09-01T17:39:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=50381846d4b9853aa3a901d6a4c2b3091d66014e'/>
<id>urn:sha1:50381846d4b9853aa3a901d6a4c2b3091d66014e</id>
<content type='text'>
Makes changes to comply with CodeQL comparison-with-wider-type alerts.

Some of these have safe patterns even with wider type comparisons,
so an explicit cast is used to make the intention clear and
silence the failure.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Guard nullable return values</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2026-09-04T22:11:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=dd18a85cb698612d9d41edd7845ff060145926de'/>
<id>urn:sha1:dd18a85cb698612d9d41edd7845ff060145926de</id>
<content type='text'>
Makes changes to comply with CodeQL unguarded-null-return-dereference
alerts.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Break out the user prompt from Tcg2 PPI</title>
<updated>2026-09-03T23:32:46+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2026-09-03T20:22:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=14efe49266d16185ed73eeff6ba4fb0339a9e0f0'/>
<id>urn:sha1:14efe49266d16185ed73eeff6ba4fb0339a9e0f0</id>
<content type='text'>
Use PromptForUserConfirmation() function from library
so it is abstracted at the platform level.

Signed-off-by: Raymond Diaz &lt;raymonddiaz@microsoft.com&gt;
Signed-off-by: Bret Barkelew &lt;brbarkel@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Add Tcg2PhysicalPresencePromptLib</title>
<updated>2026-09-03T23:32:46+00:00</updated>
<author>
<name>rdiaz</name>
<email>raymonddiaz@microsoft.com</email>
</author>
<published>2026-07-22T20:22:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=8aad8cc081ea5d67c483594a25c2375e042de1d9'/>
<id>urn:sha1:8aad8cc081ea5d67c483594a25c2375e042de1d9</id>
<content type='text'>
Add Tcg2PhysicalPresencePromptLib to support breaking out
the PromptForUserConfirmation() function into a platform
specific library.

Signed-off-by: Raymond Diaz &lt;raymonddiaz@microsoft.com&gt;
Signed-off-by: Bret Barkelew &lt;brbarkel@microsoft.com&gt;
</content>
</entry>
<entry>
<title>Revert "SecurityPkg: Break out the user prompt from Tcg2 PPI"</title>
<updated>2026-09-03T23:32:46+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2026-09-03T20:18:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=acd7bb4c53cea53f450392f222e5ecac15ccc0e7'/>
<id>urn:sha1:acd7bb4c53cea53f450392f222e5ecac15ccc0e7</id>
<content type='text'>
This reverts commit 2c2f74a581473d20b54c4310f27abbd73c8e9687.

Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Break out the user prompt from Tcg2 PPI</title>
<updated>2026-08-26T10:54:45+00:00</updated>
<author>
<name>rdiaz</name>
<email>raymonddiaz@microsoft.com</email>
</author>
<published>2026-07-22T20:22:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2c2f74a581473d20b54c4310f27abbd73c8e9687'/>
<id>urn:sha1:2c2f74a581473d20b54c4310f27abbd73c8e9687</id>
<content type='text'>
Break out the PromptForUserConfirmation() function into a lib
so it can be abstracted at the platform level.

Signed-off-by: Raymond Diaz &lt;raymonddiaz@microsoft.com&gt;
Signed-off-by: Bret Barkelew &lt;brbarkel@microsoft.com&gt;
</content>
</entry>
</feed>
