<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/SecurityPkg/Test, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-06T10:12:38+00:00</updated>
<entry>
<title>SecurityPkg: Test: Use timer based RngLib</title>
<updated>2026-09-06T10:12:38+00:00</updated>
<author>
<name>Kun Qin</name>
<email>kuqin@microsoft.com</email>
</author>
<published>2026-07-27T19:09:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=d9fa44ff53a9f792e87aac1f3bd7a63e60e43130'/>
<id>urn:sha1:d9fa44ff53a9f792e87aac1f3bd7a63e60e43130</id>
<content type='text'>
The current RngLib directly queries the random number from the hardware
register. But this has the limiation on imposing the host hardware
capability to the target test. i.e. for AArch64 unit tests, rndr
instruction is not always available.

This change moves the unit tests to use timer based RngLib for general
testability.

Signed-off-by: Kun Qin &lt;kun.qin@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/Test: add AARCH64 to host test DSC</title>
<updated>2026-07-31T15:16:47+00:00</updated>
<author>
<name>Jeff Brasen</name>
<email>jbrasen@nvidia.com</email>
</author>
<published>2026-07-02T03:05:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=6a4e543b09acb85bf0b4e9e3d075c50950267047'/>
<id>urn:sha1:6a4e543b09acb85bf0b4e9e3d075c50950267047</id>
<content type='text'>
Add AARCH64 to SUPPORTED_ARCHITECTURES so the SecurityPkg
host-based unit tests build and run on an AARCH64 host.  Depends
on the AARCH64 host-test framework enablement
(UnitTestFrameworkPkg/MdePkg).

Signed-off-by: Jeff Brasen &lt;jbrasen@nvidia.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/Test: use BaseRngLibNull for AARCH64 host tests</title>
<updated>2026-07-31T15:16:47+00:00</updated>
<author>
<name>Jeff Brasen</name>
<email>jbrasen@nvidia.com</email>
</author>
<published>2026-07-02T03:04:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=10732648fb0cb6ca6b804910dec92091406694aa'/>
<id>urn:sha1:10732648fb0cb6ca6b804910dec92091406694aa</id>
<content type='text'>
BaseRngLib's AARCH64 backend uses an RNDR instruction path that does not
link in the host environment.  Map RngLib to BaseRngLibNull for AARCH64
host builds (IA32/X64 keep BaseRngLib) and hoist the common RngLib mapping
so the per-component override can be dropped.

Signed-off-by: Jeff Brasen &lt;jbrasen@nvidia.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Add Google Test MockSecureBootVariableLib</title>
<updated>2026-07-16T17:50:01+00:00</updated>
<author>
<name>Joey Vagedes</name>
<email>joey.vagedes@gmail.com</email>
</author>
<published>2026-07-09T15:00:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=3fec6254088b8585e35f660b4fe289b179a15349'/>
<id>urn:sha1:3fec6254088b8585e35f660b4fe289b179a15349</id>
<content type='text'>
Add Google Test Mock library header and implementation for
SecureBootVariableLib to allow simple mocking for host based unit tests
that utilize the Google Test framework.

Signed-off-by: Joey Vagedes &lt;joey.vagedes@gmail.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Replace include guards with #pragma once</title>
<updated>2026-02-23T21:01:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-02-03T19:20:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=9326c0eb0a9b5b82fef335e46fbd85868d318a7d'/>
<id>urn:sha1:9326c0eb0a9b5b82fef335e46fbd85868d318a7d</id>
<content type='text'>
Replace traditional `#ifndef`/`#define`/`#endif` include guards with
`#pragma` once.

`#pragma once` is a widely supported preprocessor directive that
prevents header files from being included multiple times. It is
supported by all toolchains used to build edk2: GCC, Clang/LLVM, and
MSVC.

Compared to macro-based include guards, `#pragma once`:

- Eliminates the risk of macro name collisions or copy/paste errors
  where two headers inadvertently use the same guard macro.
- Eliminate inconsistency in the way include guard macros are named
  (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.).
- Reduces boilerplate (three lines replaced by one).
- Avoids polluting the macro namespace with guard symbols.
- Can improve build times as the preprocessor can skip re-opening the
  file entirely, rather than re-reading it to find the matching
  `#endif` ("multiple-include optimization").
  - Note that some compilers may already optimize traditional include
    guards, by recognzining the idiomatic pattern.

This change is made acknowledging that overall portability of the
code will technically be reduced, as `#pragma once` is not part of the
C/C++ standards.

However, this is considered acceptable given:

1. edk2 already defines a subset of supported compilers in
   BaseTools/Conf/tools_def.template, all of which have supported
   `#pragma once` for over two decades.
2. There have been concerns raised to the project about inconsistent
   include guard naming and potential macro collisions.

Approximate compiler support dates:

- MSVC: Supported since Visual C++ 4.2 (1996)
- GCC: Supported since 3.4 (2004)
  (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html)
- Clang (LLVM based): Since initial release in 2007

Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Added basic DxeImageVerificationLib tests</title>
<updated>2025-08-07T01:18:26+00:00</updated>
<author>
<name>Alexander Gryanko</name>
<email>xpahos@gmail.com</email>
</author>
<published>2025-06-22T12:38:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=057a611ae6e3c4a1b2811220576a6b48be349cb8'/>
<id>urn:sha1:057a611ae6e3c4a1b2811220576a6b48be349cb8</id>
<content type='text'>
Add initial unit test for DxeImageVerificationHandler to
validate signature verification bypass for selected image types.

Signed-off-by: Alexander Gryanko &lt;xpahos@gmail.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763</title>
<updated>2024-01-16T07:56:38+00:00</updated>
<author>
<name>Douglas Flick [MSFT]</name>
<email>doug.edk2@gmail.com</email>
</author>
<published>2024-01-11T18:16:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=4776a1b39ee08fc45c70c1eab5a0195f325000d3'/>
<id>urn:sha1:4776a1b39ee08fc45c70c1eab5a0195f325000d3</id>
<content type='text'>
This commit contains the patch files and tests for DxeTpmMeasureBootLib
CVE 2022-36763.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;

Signed-off-by: Doug Flick [MSFT] &lt;doug.edk2@gmail.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763</title>
<updated>2024-01-16T07:56:38+00:00</updated>
<author>
<name>Douglas Flick [MSFT]</name>
<email>doug.edk2@gmail.com</email>
</author>
<published>2024-01-11T18:16:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=224446543206450ddb5830e6abd026d61d3c7f4b'/>
<id>urn:sha1:224446543206450ddb5830e6abd026d61d3c7f4b</id>
<content type='text'>
This commit contains the patch files and tests for DxeTpm2MeasureBootLib
CVE 2022-36763.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;

Signed-off-by: Doug Flick [MSFT] &lt;doug.edk2@gmail.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Apply uncrustify formatting to relevant files</title>
<updated>2023-10-27T00:50:49+00:00</updated>
<author>
<name>Vivian Nowka-Keane</name>
<email>vnowkakeane@linux.microsoft.com</email>
</author>
<published>2023-08-16T21:15:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=a00f7a355ad8e1a84d8087861020d45d6565a8f1'/>
<id>urn:sha1:a00f7a355ad8e1a84d8087861020d45d6565a8f1</id>
<content type='text'>
Apply uncrustify formatting to GoogleTest cpp and header files.

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Signed-off-by: Vivian Nowka-Keane &lt;vnowkakeane@linux.microsoft.com&gt;
Reviewed-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Add gmock example</title>
<updated>2023-04-10T05:59:02+00:00</updated>
<author>
<name>Chris Johnson</name>
<email>chris.n.johnson@intel.com</email>
</author>
<published>2023-03-24T23:12:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=c28c16e7c447f3f684ab14644dfb201be8c37aa3'/>
<id>urn:sha1:c28c16e7c447f3f684ab14644dfb201be8c37aa3</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4389

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Signed-off-by: Chris Johnson &lt;chris.n.johnson@intel.com&gt;
Acked-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Reviewed-by: Oliver Smith-Denny &lt;osde@linux.microsoft.com&gt;
Reviewed-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
</feed>
