summaryrefslogtreecommitdiff
path: root/MdeModulePkg/Library/GptLib
AgeCommit message (Collapse)AuthorFilesLines
12 daysMdeModulePkg: Add EFIAPI to GptLib functionsMichael Kubacki1-0/+3
EFIAPI is required on library interface functions to ensure that the correct calling convention is used. Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-07-21MdeModulePkg/GptLib: Add host-based unit tests for malformed GPT inputRichard Lyu2-3/+571
Extend the GptLib host-based tests with negative cases that guard the security hardening in PartitionValidGptTable(), PartitionCheckGptEntry() and PartitionRestoreGptTable() against future regressions. These tests exercise the shared parser, not the specific fix itself. The new cases drive the parser with malformed GPT structures that an attacker may present: bad signature/revision, header-size boundaries, CRC corruption, MyLBA replay, zero/non-power-of-two entry sizes, LBA multiplication overflow, out-of-range and overlapping entries, and restore failure on write-protected media. The INF file header is updated to note the added malformed coverage. Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Add host-based unit tests for valid GPT behaviorRichard Lyu4-0/+925
Add the positive-path host-based tests for the shared GptLib parser (extracted as part of the parser security hardening), ensuring the tightened checks in PartitionValidGptTable(), PartitionCheckGptEntry() and PartitionRestoreGptTable() do not falsely reject well-formed GPTs. The tests run against an in-memory mock disk and cover accepted primary/backup headers, boundary but legal header/entry sizes, correct entry-status flagging on valid entries, and primary/backup restore round-trips. Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Validate GPT header fields before useRichard Lyu1-3/+31
PartitionValidGptTable() checked the signature, header CRC32, MyLBA, the entry-array CRC32 and the entry-array size overflow, but not several other UEFI-mandated GPT header constraints. DxeTpm2MeasureBootLib used to enforce these via Tpm2SanitizeEfiPartitionTableHeader(); once it switched to this shared parser, the checks were lost on the path. Also reject a header unless Header.Revision is GPT_HEADER_REVISION_V1, HeaderSize is at least the 92-byte minimum, NumberOfPartitionEntries is non-zero, SizeOfPartitionEntry is 128 * 2^n, and PartitionEntryLBA * BlockSize cannot overflow. The "entries lie before FirstUsableLBA" rule is intentionally omitted, as this routine also validates the backup header whose entry array follows the usable region. This restores the validation the measurement path lost and, because GptLib is shared, tightens PartitionDxe the same way: malformed headers are now rejected and the parse and measure paths stay identical. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Extract shareable GPT parser into a libraryRichard Lyu2-0/+597
As reported in CVE-2024-13745 via oss-sec, DxeTpm2MeasureBootLib can measure a partition table that differs from the one parsed by the PartitionDxe driver. To address this, the more complete GPT parsing logic from PartitionDxe is extracted into a standalone GptLib library so it can be shared between PartitionDxe and DxeTpm2MeasureBootLib. This ensures that the exact same partition table measured into PCR[5] is the one parsed and used by the system. PartitionDxe behavior is unchanged. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>