<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/SecurityPkg/VariableAuthenticated/SecureBootConfigDxe/SecureBootConfigImpl.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-08T18:20:17+00:00</updated>
<entry>
<title>SecurityPkg: Fix wider-type comparisons</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-09-01T17:39:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=50381846d4b9853aa3a901d6a4c2b3091d66014e'/>
<id>urn:sha1:50381846d4b9853aa3a901d6a4c2b3091d66014e</id>
<content type='text'>
Makes changes to comply with CodeQL comparison-with-wider-type alerts.

Some of these have safe patterns even with wider type comparisons,
so an explicit cast is used to make the intention clear and
silence the failure.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Guard nullable return values</title>
<updated>2026-09-08T18:20:17+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2026-09-04T22:11:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=dd18a85cb698612d9d41edd7845ff060145926de'/>
<id>urn:sha1:dd18a85cb698612d9d41edd7845ff060145926de</id>
<content type='text'>
Makes changes to comply with CodeQL unguarded-null-return-dereference
alerts.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Add support for LOONGARCH64 and RISCV64 when parsing PE image</title>
<updated>2026-06-24T17:31:06+00:00</updated>
<author>
<name>Qihang Gao</name>
<email>gaoqihang@loongson.cn</email>
</author>
<published>2026-06-22T09:42:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=08258192d44753d79ef15494ab4d7cf671d043ec'/>
<id>urn:sha1:08258192d44753d79ef15494ab4d7cf671d043ec</id>
<content type='text'>
If the machine type of PE/COFF image is LOONGARCH64 or RISCV64, the
LoadPeImage() should return EFI_SUCCESS. This patch is intended as a
preparation for future use of LOONGARCH64 or RISCV64 PE image file.

Signed-off-by: Qihang Gao &lt;gaoqihang@loongson.cn&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/SecureBootConfigDxe: Remove unused variable mImageType</title>
<updated>2026-06-24T17:31:06+00:00</updated>
<author>
<name>Qihang Gao</name>
<email>gaoqihang@loongson.cn</email>
</author>
<published>2026-06-22T08:21:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=d984c9b63c46784485826a1d9636d46af019d22b'/>
<id>urn:sha1:d984c9b63c46784485826a1d9636d46af019d22b</id>
<content type='text'>
Remove mImageType as it is assigned but never used. The definition of
struct IMAGE_TYPE is also removed.

Signed-off-by: Qihang Gao &lt;gaoqihang@loongson.cn&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: fix various typos</title>
<updated>2025-11-21T21:49:59+00:00</updated>
<author>
<name>Philipp Schuster</name>
<email>philipp.schuster@cyberus-technology.de</email>
</author>
<published>2025-11-04T07:25:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=5c6b2b8ba6632c308792f81556997f9173ddec13'/>
<id>urn:sha1:5c6b2b8ba6632c308792f81556997f9173ddec13</id>
<content type='text'>
Signed-off-by: Philipp Schuster &lt;philipp.schuster@cyberus-technology.de&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Drop ARM32 Support</title>
<updated>2025-09-25T22:04:10+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2025-09-15T14:51:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=08ae634ccb4dc5463b3d4473c44269cdd9e0c191'/>
<id>urn:sha1:08ae634ccb4dc5463b3d4473c44269cdd9e0c191</id>
<content type='text'>
edk2 is dropping support for the ARM32 architecture. This
commit removes ARM32 code in SecurityPkg.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>Revert "SecurityPkg: CodeQL Fixes."</title>
<updated>2025-08-12T03:50:30+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2025-08-11T17:47:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=072ab3846c4fd86387dfd5d191dcb91e98202023'/>
<id>urn:sha1:072ab3846c4fd86387dfd5d191dcb91e98202023</id>
<content type='text'>
This reverts commit ba6a8eb045aededbc1472cce7314ab1911f0ea1c.

PR https://github.com/tianocore/edk2/pull/11307 introduced a
logic change that caused regressions in FV verification on
some platforms. This PR is being reverted to restore the prior
logic.

The Code QL fixes in https://github.com/tianocore/edk2/pull/11307
can be resubmitted without the logic change along with one
commit for each type of Code QL issue being addressed.

Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: CodeQL Fixes.</title>
<updated>2025-07-24T01:58:06+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2024-07-30T17:56:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=ba6a8eb045aededbc1472cce7314ab1911f0ea1c'/>
<id>urn:sha1:ba6a8eb045aededbc1472cce7314ab1911f0ea1c</id>
<content type='text'>
Makes changes to comply with alerts raised by CodeQL.

Most of the issues here fall into the following two categories:

1. Potential use of uninitialized pointer.
2. Inconsistent integer width in comparison.

Co-authored-by: Taylor Beebe &lt;31827475+TaylorBeebe@users.noreply.github.com&gt;
Co-authored-by: kenlautner &lt;85201046+kenlautner@users.noreply.github.com&gt;
Co-authored-by: Bret Barkelew &lt;bret@corthon.com&gt;

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg: Improving SecureBootConfigImpl:HashPeImageByType () logic</title>
<updated>2025-04-09T00:13:21+00:00</updated>
<author>
<name>Doug Flick</name>
<email>dougflick@microsoft.com</email>
</author>
<published>2025-01-17T19:30:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=025ab811fb2afac6b4036b0fc2fa46d0b04d1c80'/>
<id>urn:sha1:025ab811fb2afac6b4036b0fc2fa46d0b04d1c80</id>
<content type='text'>
Namely:

(1) The TWO_BYTE_ENCODE check is independent of Index. If it evalutes
    to TRUE for Index==0, then it will evaluate to TRUE for all other
    Index values as well. As a result, the (Index == HASHALG_MAX)
    condition will fire after the loop, and we'll return
    EFI_UNSUPPORTED.

    While this is correct, functionally speaking, it is wasteful to
    keep re-checking TWO_BYTE_ENCODE in the loop body. The check
    should be made at the top of the function, and EFI_UNSUPPORTED
    should be returned at once, if appropriate.

(2) If the hash algorithm selected by Index has such a large OID that
    the OID comparison cannot even be performed (because AuthDataSize
    is not large enough for containing the OID in question, starting
    at offset 32), then the function returns EFI_UNSUPPORTED at once.

    This is bogus; this case should simply be treated as an OID
    mismatch, and the loop should advance to the next Index value /
    hash algorithm candidate. A remaining hash algo may have a shorter
    OID and yield an OID match.

Signed-off-by: Doug Flick &lt;DougFlick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>SecurityPkg/SecureBootConfigDxe: Enhance help in Delete Signature page</title>
<updated>2024-12-17T16:46:29+00:00</updated>
<author>
<name>Phil Noh</name>
<email>Phil.Noh@amd.com</email>
</author>
<published>2024-12-12T01:05:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=30c8a73850b478042cc8e208298f37084940b9e7'/>
<id>urn:sha1:30c8a73850b478042cc8e208298f37084940b9e7</id>
<content type='text'>
Currently "Delete Signature" Setup page lists enrolled signatures and each
signature is shown with signature GUID (prompt) and type (help). It is
possible for some signatures to be shown with same signature GUID and
type. In this case, it is difficult to identify the target signature to
delete. The update enhances help information to distinguish signatures.

Signed-off-by: Phil Noh &lt;Phil.Noh@amd.com&gt;
</content>
</entry>
</feed>
