summaryrefslogtreecommitdiff
path: root/CryptoPkg/Library
AgeCommit message (Collapse)AuthorFilesLines
2026-09-08CryptoPkg: Fix memcpy alias prototype to match the aliaseeSunil Dora1-3/+3
The memcpy alias in IntrinsicLib declares its count parameter as unsigned int while the aliasee __memcpy uses size_t. On 64-bit targets these are different widths. clang 23 diagnoses this through -Wattribute-alias: CopyMem.c:29:17: warning: alias and aliasee have different types 'void *(void *, const void *, unsigned int)' and 'void *(void *, const void *, size_t)' [-Wattribute-alias] and builds that treat warnings as errors fail, e.g. OVMF built with the CLANGDWARF toolchain in Yocto. Declare the alias with size_t so both signatures agree. Signed-off-by: Sunil Dora <sunilkumar.dora@windriver.com>
2026-08-31CryptoPkg: Fix SIZE_MAX, UINTPTR_MAX and intptr_t definitionsDoug Cook1-7/+23
CrtLibSupport.h defines SIZE_MAX and UINTPTR_MAX as 32-bit constants on every target, even though the types they describe (size_t, uintptr_t) are typedefs of UINTN and so are 64-bit on X64, AARCH64, IA64, RISCV64 and LOONGARCH64. UINTPTR_MAX definition was controlled by "#if (UINT_MAX > 0xFFFFFFFFUL)", which can never be true, so it was always set to UINT32_MAX. Fix cannot just use MAX_UINTN because that isn't usable in preprocessor conditions. Instead, define SIZE_MAX and UINTPTR_MAX based on CPU. Without this, CryptoPkgMbedTls.dsc fails to build for AArch64: library/constant_time.c:58:5: error: invalid 'asm': invalid operand In addition, the wrong SIZE_MAX silently removes length-overflow checks that MbedTLS guards with "#if SIZE_MAX > UINT_MAX", including the ASN.1 length check in asn1write.c and the input length check in nist_kw.c, and selects 32-bit constant-time helper types in constant_time_internal.h. Also correct intptr_t, which was a typedef of the unsigned UINTN. The neighbouring ptrdiff_t and ssize_t already use INTN. TcgTpmPkg/Private/Include/Standard/CrtLibSupport.h is a byte-identical copy of this header and has the same defects. It is fixed by a separate patch so that each commit stays within a single package. Tested by building CryptoPkg/CryptoPkgMbedTls.dsc with GCC for AARCH64, X64 and IA32. AARCH64 does not build without this change; X64 and IA32 are unaffected. Signed-off-by: Doug Cook <dcook@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Decrypt APIDoug Cook22-7/+1344
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API. I expect that the primary use of Pkcs7Decrypt would be for testing the Pkcs7Encrypt API, but maybe somebody will need it for real work someday. Signed-off-by: Doug Cook <dcook@microsoft.com> Committed-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Encrypt for BaseCryptLibMbedTlsDoug Cook4-3/+1169
Add CryptPkcs7Encrypt.c with an MbedTLS-based Pkcs7Encrypt() implementation. Update BaseCryptLibMbedTls INF files (BaseCryptLib.inf, SmmCryptLib.inf, UnitTestHostBaseCryptLib.inf) to include the new source file, and update CryptoPkg/Readme.md accordingly. Signed-off-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Expose Pkcs7Encrypt via EDKII_CRYPTO_PROTOCOLDoug Flick1-0/+45
Add EDKII_CRYPTO_PKCS7_ENCRYPT typedef and Pkcs7Encrypt member to the EDKII_CRYPTO_PROTOCOL structure. Bump protocol version to 25. Add CryptoServicePkcs7Encrypt wrapper in the Crypto driver and Pkcs7Encrypt wrapper in BaseCryptLibOnProtocolPpi. Add Pkcs7Encrypt PCD bit to PcdCryptoServiceFamilyEnable for independent service control. Update Readme.md feature table. Signed-off-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Encrypt OpenSSL and null implementationsDoug Flick18-0/+314
Add CryptPkcs7Encrypt.c with OpenSSL-based Pkcs7Encrypt() implementation using PKCS7_encrypt API. Add null stub implementations for library instances that do not support this function (PEI, Runtime, SEC, MbedTLS, Null). Update all BaseCryptLib INF files to include the new source files. Signed-off-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Merge CryptoPkgMbedTls into CryptoPkg DSC fileLonghaox Lee12-6/+471
Merge CryptoPkgMbedTls into CryptoPkg DSC. Null instances for SlhDsa, MlDsa, EdDsa since mbebtls not support. Fixing build error for mbedtls BaseCryptLib. Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2026-07-31CryptoPkg/BaseCryptLib: add AARCH64 host unit test Rand sourceJeff Brasen1-1/+4
The host-based BaseCryptLib instance (UnitTestHostBaseCryptLib.inf) built Rand/CryptRandTsc.c only for IA32/X64. Add Rand/CryptRand.c for AARCH64 so the openssl-backed RandomSeed() is available when linking AARCH64 host tests, and advertise AARCH64 in VALID_ARCHITECTURES. Signed-off-by: Jeff Brasen <jbrasen@nvidia.com>
2026-07-30CryptoPkg: Match OpenSSL's default security levelJean-Tiare Le Bigot1-5/+0
`TlsNew()` explicitly sets the default security level to 3. The current default in OpenSSL is security level 2 which is inherited by Linux distributions like Ubuntu 26.04. This is also the security level that was announced in https://edk2.groups.io/g/devel/topic/115039926. Signed-off-by: Jean-Tiare Le Bigot <jt@yadutaf.fr>
2026-07-21CryptoPkg/BaseCryptLib: Add SLH-DSA SupportMichael G.A. Holland24-9/+1799
Created SLH-DSA API functions to configure public and private keys for SLH-DSA algorithm. This will allow users to sign and verify with SLH-DSA. Unit tests were added to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-20CryptoPkg/BaseCryptLib: ML-DSA updatesMichael G.A. Holland1-0/+4
Include validation check for Context and ContextSize in signature function. Updated ReadMe to show ML-DSA support Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-20CryptoPkg/BaseCryptLib: EdDsa updatesMichael G.A. Holland1-1/+9
Include validation checks for Context and ContextSize in sign and verify functions. Returned FALSE for EdDsaGeneratePubKey. Updated ReadMe to show EdDsa support Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-14CryptoPkg/BaseCryptLib: Add ML-DSA SupportMichael G.A. Holland37-30/+12653
Created ML-DSA API functions to configure public and private keys for ML-DSA algorithm. This will allow users to sign and verify with ML-DSA. Unit tests were add to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-01CryptoPkg/BaseCryptLib: Add ED448 verification and signature fcnsMichael G.A. Holland25-0/+2388
Implemented signature and verification functions for ED448; Updated documentation and unit tests to cover new verification functions Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-01CryptoPkg: Remove VS2015 specific compiler flagsMichael Kubacki7-57/+0
VS2015 support is being removed in edk2 as it is out of service. Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-06-25CryptoPkg: Enable SHA256 hash in SecCryptLibSami Mujawar1-2/+2
Enable CryptSha256 hash in SecCryptLib as this is required by Arm CCA. The hash algorithm used by the Arm CCA Realm Extensible Measurement (REM) registers is either SHA256 or SHA512. To enable measurements in the early boot phase enable SHA256 hash algorithm in SecCryptLib. Signed-off-by: Sami Mujawar <sami.mujawar@arm.com>
2026-06-24CryptoPkg: TlsLib: Fix uninitialized variable warningsTuan Phan1-31/+31
In TlsSetCipherList(), the OpensslCipher variable is initialized inside an inner loop but accessed outside of that loop, which can lead to uninitialized variable warnings. Fix this issue by moving all accesses to OpensslCipher into the inner loop where it is initialized. Signed-off-by: Tuan Phan <tuan.phan@oss.qualcomm.com>
2026-06-22CryptoPkg/OpensslLib: Update generated files for openssl-3.5.7Thamballi Sreelalitha44-6593/+6847
Fixes: #12658 Signed-off-by: Thamballi Sreelalitha <sreelali@qti.qualcomm.com>
2026-06-22CryptoPkg/OpensslLib: Update openssl submodule to openssl-3.5.7 releaseThamballi Sreelalitha1-0/+0
This update includes fixes for the following security vulnerabilities: - CVE-2026-45447 - CVE-2026-34180 - CVE-2026-34181 - CVE-2025-69419 Fixes: #12658 Signed-off-by: Thamballi Sreelalitha <sreelali@qti.qualcomm.com>
2026-06-15CryptoPkg: Added lite version openssl libraryLee LonghaoX10-10/+3768
Lite version OpensslLib base on OpensslLibFull but no-camellia, no -ecx and no-dh. It save the size about ~192KB. REF: Signed-off-by: Lee LonghaoX <longhaox.lee@intel.com>
2026-06-15CryptoPkg: Log TLS handshake certificate verification error reasonJean-Tiare Le Bigot1-0/+16
When the TLS error is `SSL_R_CERTIFICATE_VERIFY_FAILED`, the verification failure reason is reported by `SSL_get_verify_result`. Adding this reason to the debug logs is valuable to pin-point certificate rejection that are specific to EDK II. Signed-off-by: Jean-Tiare Le Bigot <jt@yadutaf.fr>
2026-05-29CryptoPkg: Fix leaks and failure-path mutation of RSA-owned valuesMingjie Shen1-147/+309
RsaSetKey passed RSA-internal BIGNUMs (returned by RSA_get0_key / RSA_get0_factors / RSA_get0_crt_params as const) directly to BN_bin2bn, which mutates its destination in place. This violates the OpenSSL API contract and can leave RsaContext in a partially modified state on failure paths: BN_bin2bn has already overwritten one of n / e / d / p / q / dp / dq / qInv, the function then returns FALSE on a subsequent BN_dup or RSA_set0_* failure, and the caller has no indication that the RSA object was silently changed. The same paths also leaked temporary BIGNUMs allocated by BN_bin2bn or BN_new. This patch splits RsaSetKey into a small input-validating dispatcher plus three static helpers (RsaSetKeyNED, RsaSetKeyFactors, RsaSetKeyCrtParams), one per RSA_set0_* setter. Each helper: - Allocates a fresh BIGNUM for the slot being set via BN_bin2bn(BigNumber, BnSize, NULL); the NULL destination forces BN_bin2bn to allocate so no RSA-owned BIGNUM is mutated. - Reads the current RSA state via RSA_get0_* purely for inspection. - For slots not being set, passes NULL when RSA already has a value (preserves it) or supplies an empty BN_new() placeholder when RSA's slot is still NULL. - Atomically installs via RSA_set0_*, which takes ownership of every non-NULL argument on success and of none on failure. - Routes all exits through a single label that frees any locally held BIGNUM. Memory leaks in the early-return paths are fixed as a consequence. The previous BN_dup calls are no longer needed and are removed. Signed-off-by: Mingjie Shen <shen497@purdue.edu>
2026-04-27CryptoPkg/Library/MbedTlsLib: Update mbedtls submodule to v3.6.6Richard Lyu1-0/+0
Update the mbedtls submodule from v3.6.5 to v3.6.6 to mitigate the CVEs CVE-2026-25833, CVE-2026-25834, CVE-2026-25835 CVE-2026-34874. Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-04-07CryptoPkg: Add digest-based RSA-PSS sign and verify APIsBaraneedharan Anbazhagan9-23/+656
Add RsaPssSignDigest() and RsaPssVerifyDigest() to BaseCryptLib for signing/verifying precomputed digests. Provide OpenSSL/MbedTLS/Null implementations, expose via EDKII_CRYPTO_PROTOCOL (v24), and add PCD controls for independent service enabling. Include unit tests. Signed-off-by: Anbazhagan Baraneedharan <anbazhagan@hp.com>
2026-03-10CryptoPkg: BaseCryptLib: Reject empty X.509 cert when retrieving public keyKun Qin1-0/+16
Explicitly reject zero-length X.509 certificate buffers when retrieving a public key. For this invalid case, the input context pointer is set to NULL as a defensive measure. Signed-off-by: Kun Qin <kun.qin@microsoft.com>
2026-02-26CryptoPkg/Library/OpensslLib: Remove GCC5 build optionsMike Beaton5-10/+0
Signed-off-by: Mike Beaton <mjsbeaton@gmail.com>
2026-02-24CryptoPkg: add EC algorithm for SmmCryptLibLevi Yun1-1/+1
This patch prepares the build infrastructure for the TCG TPM 2.0 implementation [0]. By default, it uses the OpenSSL EC_* APIs. When the TCG TPM 2.0 implementation [0] is used in StandaloneMm, EC algorithm support is required in SmmCryptLib. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add/modify EC interfaces for TPM TCG libraryLevi Yun5-0/+570
This is prepartion patch to build TCG TPM v2.0 Reference Library[0]. TCG TPM v2.0 implementation[0] uses below additional interfaces: - EC_GROUP_new_curve_GFp() - EC_GROUP_set_generator() - EC_POINTs_mul() and require EC_POINT_mul()'s n arguments (Scalar multiplier for the generator G) but EDKII's EcPointMul() interface always fix this value as NULL. For TCG TPM v2.0 implementation, add new interfaces. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add some Bn interfaces to build TCG TPM libraryLevi Yun5-0/+627
This is preparation patch for build TCG TPM v2.0 implementation[0]. To build TCG TPM v2.0 implementation[0], below Bn interfaces are required: - BN_CTX_start() -> BigNumContextStart() - BN_CTX_end() -> BigNumContextEnd() - BN_CTX_get() -> BigNumContextGet() - BN_mul() -> BigNumMul() - BN_Gcd() -> BigNumGcd() and add BigNumDiv2() to receive remain too. Link: https://github.com/TrustedComputingGroup/TPM[0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add CAMELLIA APIs for TCG TPM reference libraryLevi Yun19-0/+662
This is preparation patch to build TCG TPM v2.0 implementation [0]. TCG TPM v2.0 uses below Camellia APIs: - Camellia_set_key() - Camellia_encrypt() - Camellia_decrypt() To support these CAMELLIA interfaces, add related wrapper in BaseCryptLib. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add AES_encrypt/AES_decrpyt for TPM reference libraryLevi Yun6-0/+418
This is preparation patch to build TCG TPM v2.0 implementation [0]. TCG TPM v2.0 uses AES_encrypt()/AES_decrpyt() in openssl library to implement its crypto operation. For this, add wrapper for AES_encrypt()/AES_decrpyt(). Link: https://github.com/TrustedComputingGroup/TPM[0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: preparation to build TPM reference libraryLevi Yun2-9/+19
To build TPM reference library[0] with CryptoPkg, belows are required: - define memcpy as a function instead of a macro because memcpy is used as a function pointer in TPM reference library - definitions of INT16_MAX/UINT16_MAX Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg/OpensslLib: add NULL EC interfaces for TPM TCG libraryLevi Yun1-0/+39
This is prepartion patch to build TCG TPM v2.0 Reference Library[0]. TCG TPM v2.0 implementation[0] uses below additional interfaces: - EC_GROUP_new_curve_GFp() - EC_GROUP_set_generator() - EC_POINTs_mul() To prevent build failure for absent of these extra interfaces, add NULL interfaces. Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg/OpensslLib: add NULL CAMELLIA interfaces for TPM TCG libraryLevi Yun4-0/+48
This is prepartion patch to build TCG TPM v2.0 Reference Library[0]. TCG TPM v2.0 implementation[0] uses below additional interfaces: - Camellia_set_key() - Camellia_encrypt() - Camellia_decrypt() To prevent build failure for absent of these extra interfaces, add NULL interfaces. Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg/OpensslLib: add cmellia and cmac algorithm in OpensslFullLibLevi Yun14-10010/+8988
To build TPM 2.0 Reference Implementation library, OpensslLib requires below features: - camellia - cmac - elliptic curved algorithms For thes, openssl should be configured without below two options: - no-camellia - no-cmac Therefore, remove these two option for OpensslFullLib only since TPM 2.0 Reference Library requires to use openssl built with ec This increases OpensslFullLib size -- around 16K. Except configure.py, other changed files are auto generated by configure.py Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: Replace include guards with #pragma onceMichael Kubacki9-35/+10
Replace traditional `#ifndef`/`#define`/`#endif` include guards with `#pragma` once. `#pragma once` is a widely supported preprocessor directive that prevents header files from being included multiple times. It is supported by all toolchains used to build edk2: GCC, Clang/LLVM, and MSVC. Does not include updates to OpenSSL generated header files checked into the repo. Those in `CryptoPkg\Library\OpensslLib\OpensslGen\`. Compared to macro-based include guards, `#pragma once`: - Eliminates the risk of macro name collisions or copy/paste errors where two headers inadvertently use the same guard macro. - Eliminate inconsistency in the way include guard macros are named (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.). - Reduces boilerplate (three lines replaced by one). - Avoids polluting the macro namespace with guard symbols. - Can improve build times as the preprocessor can skip re-opening the file entirely, rather than re-reading it to find the matching `#endif` ("multiple-include optimization"). - Note that some compilers may already optimize traditional include guards, by recognzining the idiomatic pattern. This change is made acknowledging that overall portability of the code will technically be reduced, as `#pragma once` is not part of the C/C++ standards. However, this is considered acceptable given: 1. edk2 already defines a subset of supported compilers in BaseTools/Conf/tools_def.template, all of which have supported `#pragma once` for over two decades. 2. There have been concerns raised to the project about inconsistent include guard naming and potential macro collisions. Approximate compiler support dates: - MSVC: Supported since Visual C++ 4.2 (1996) - GCC: Supported since 3.4 (2004) (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html) - Clang (LLVM based): Since initial release in 2007 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-01-15CryptoPkg: Add AARCH64-PE Target to OpenSSL GenOliver Smith-Denny34-33/+37109
CLANGPDB does not support the same asm syntax as GCC/CLANGDWARF. As a result, the autogenerated ASM files in CryptoPkg need a new flavor for CLANGPDB, which is supported by OpenSSL. This adds support to the autogeneration script to support the new flavor, as well as running the script and checking in the generated asm files. To reflect the intention better than toolchain name (as AARCH64-GCC is already out of date), the directories are renamed to AARCH64-ELF (the former AARCH64-GCC) and AARCH64-PE (what CLANGPDB uses). In order to support this, a new PCD is introduced in CryptoPkg, gEfiCryptoPkgTokenSpaceGuid.PcdOpensslLibAssemblySourceStylePe which instructs the build system to include the PE target asm files or the ELF target asm files. GCC and CLANGDWARF will use the ELF target files and CLANGPDB uses the PE target files. This matches the X64 behavior to toggle between the asm files. Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2026-01-15CryptoPkg: Add CLANGPDB AArch64 SupportOliver Smith-Denny7-7/+7
CryptoPkg needed various updates to support CLANGPDB AARCH64: - Scope a feature PCD to IA32/X64 only - Ensure that OpenSSL and MbedTls have the Windows defines unset so they don't try to build for Windows instead of UEFI Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2026-01-06CryptoPkg/Library/IntrinsicLib: IA32 CLANGPDB missing functionsMichael D Kinney3-34/+30
Intrinsic functions __aullrem and __alldiv are missing in CLANGPDB IA32 builds due to these functions only being implemented in ASM, and CLANGPDB builds require NASM. * Convert MathLldiv.asm to MathLldiv.nasm * Convert MathUllrem.asm to MathUllrem.nasm * Update IntrinsicLib.inf to use NASM for MSFT and CLANGPDB These missing functions were found with CLANGPDB IA32 build of the EmulatorPkg with -D SECURE_BOOT_ENABLE. Can also be seen with CLANGPDB IA32 build of OpensslLib under Windows and Linux by reviewing the external functions in .lib. Resolves a similar issue with __aulldiv addressed by https://github.com/tianocore/edk2/pull/11266 Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2026-01-05CryptoPkg/Library/OpensslLib: Add -UWIN32 to GCC FamilyMichael D Kinney5-10/+10
Undefine WIN32 for GCC family compilers in OpensslLib INF files to remove use of GetLastError() and SetLastError() in OpensslLib builds. Mingw CLANG compilers have a builtin define called WIN32. When building OpensslLib, this define causes the Windows APIs GetLastError() and SetLastError() to be referenced which causes compilers warnings for undefined functions. Mingw CLANG NOOPT builds generate link errors not finding GetLastError() and SetLastError(). The MSFT family compilers do not define WIN32. As a result, this issue is not observed with VS20xx tool chains. Removing the WIN32 define aligns the GCC family with the MSFT family. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2025-12-24CryptoPkg/Library/MbedTlsLib: Undefined _MSC_VER for GCC FamilyMichael D Kinney2-4/+4
Update GCC Family to undefined _MSC_VER to match settings used by other compilers. This addresses clang compatibility issues for host-based unit test builds. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2025-12-24CryptoPkg/Library/OpensslLib: Undefined _MSC_VER for GCC FamilyMichael D Kinney5-10/+10
Update GCC Family to undefined _MSC_VER to match settings used by other compilers. This addresses clang compatibility issues for host-based unit test builds. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2025-12-03CryptoPkg: Suppress VS2022 warning #4319 when building OpenSSLArd Biesheuvel5-10/+15
CI builds have started to fail with ERROR - Compiler #2220 from D:\a\1\s\CryptoPkg\Library\OpensslLib\openssl\crypto\bn\bn_gcd.c(659): the following warning is treated as an error WARNING - Compiler #4319 from D:\a\1\s\CryptoPkg\Library\OpensslLib\openssl\crypto\bn\bn_gcd.c(659): '~': zero extending 'unsigned int' to 'unsigned __int64' of greater size WARNING - Compiler #4319 from D:\a\1\s\CryptoPkg\Library\OpensslLib\openssl\crypto\bn\bn_gcd.c(671): '~': zero extending 'unsigned int' to 'unsigned __int64' of greater size which was not flagged before. Suppress the warning in CryptoPkg so the builds will succeed again. If this is a real issue, it should be reported to and fixed in the upstream project. Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
2025-11-29CryptoPkg : Added CRT defined for big number support for Mbedtls.Longhaox Lee1-0/+4
defined ULLONG_MAX in CrtLibSupport header file. Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-26CryptoPkg/OpensslLib: Add NDEBUG flag for GCC Release buildsZihan Qi2-0/+2
The OpenSSL build system enables debug information by default unless NDEBUG is defined. This results in debug symbols being included in GCC Release builds. Add the NDEBUG flag to the GCC Release build flags to properly disable debug information and align with standard Release build practices. Signed-off-by: Zihan Qi <zihanqi@amazon.com>
2025-11-24CryptoPkg: Override mbedtls_config headerLonghaox Lee1-1/+9
1.Defended MBEDTLS_PLATFORM_MS_TIME_ALT use alternative implement. 2.Defended MBEDTLS_TEST_SW_INET_PTON use software version INET_PTON, not depend on OS. REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-24CryptoPkg: MbedTls not support content data signature.Longhaox Lee1-72/+1
Pkcs7GetAttachedContent function should always return false. REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-24CryptoPkg: EDK2 code update for Mbedtls 3.6.5.Longhaox Lee9-284/+998
1. mbedtls_config.h header sync with 3.6.5 . 2. Implement mbedtls_ms_time() Get time in milliseconds. 3. Covert some CRT library to EDK Implement and CRT defined. 4. Added and remove file to sync. REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-24CryptoPkg: Update mbedtls submodule for EDKIILonghaox Lee1-0/+0
Update mbedtls submodule from 3.3.0 to 3.6.5 in CryptoPkg. REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-22CryptoPkg: Fix non-idiomatic endless loopMike Beaton1-2/+1
This was found building ArmVirtQemu using CLANGDWARF with unused-but-set-variable warning enabled. Fixes: https://github.com/tianocore/edk2/commit/40fa5cf2995e9de6c9853945428f407f208be1e1 Signed-off-by: Mike Beaton <mjsbeaton@gmail.com>