summaryrefslogtreecommitdiff
path: root/MdeModulePkg/Universal
AgeCommit message (Collapse)AuthorFilesLines
6 daysMdeModulePkg/SetupBrowserDxe: Fix memory leak in GetQuestionDefault()Qihang Gao1-0/+2
StrValue is obtained from HiiGetString(), which allocates a new string buffer. The buffer is used to set DefaultValue->Buffer but is never released, causing a memory leak each time this code path is executed. Add FreePool (StrValue) after it is no longer needed. No functional change intended. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
10 daysMdeModulePkg: Variable: Log Reclaim() completion statusAbdul Lateef Attar1-0/+2
Adds a DEBUG_INFO message when Reclaim() finishes so platform boot logs show whether reclaim ran and what status it returned. This makes it easier to distinguish reclaims impact on boot measurements. Signed-off-by: Abdul Lateef Attar <AbdulLateef.Attar@amd.com>
2026-09-15MdeModulePkg: Update UI strings to indicate case-insensitive key optionsQihang Gao1-4/+4
Update the prompt strings for save/exit and confirm actions to show both uppercase and lowercase key options (e.g., 'Y(y)' and 'N(n)') to make it clear that the system accepts either case. This improves user experience by avoiding confusion about case sensitivity. Affected strings: - ARE_YOU_SURE (CustomizedDisplayLib) - CONFIRM_OPTION (DisplayEngineDxe) - RECONNECT_CHANGES_OPTIONS (DisplayEngineDxe) French translations are updated accordingly. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-09-03MdeModulePkg/MonotonicCounterRuntimeDxe: Add VarPolicy to the MTC variableMike Turner2-5/+100
Applies a UEFI variable policy to the "MTC" variable to ensure that it is the size of a UINT32 and the variable attributes are restricted to BS, RT, and NV. A protocol dependency on the Variable Policy Protocol is not added to the driver's dependency expression to allow it to be dispatched in firmware that does not have the Variable Policy Protocol installed. Co-authored-by: Michael Kubacki <michael.kubacki@microsoft.com> Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-08-31MdeModulePkg: Improved error handling in RuntimeDxe Variable driversPaddy Deng (AMI US Holdings Inc)7-67/+504
Some platforms may disable `ASSERT_DEADLOOP_ENABLED` in `PcdDebugPropertyMask`. In this case ASSERT won't hang the machine. Replaced those simple ASSERT with proper error returning handling. Signed-off-by: Paddy Deng (AMI US Holdings Inc) <v-dengpaddy@microsoft.com>
2026-08-27MdeModulePkg: Skip deleted vars in PeiVariable index table searchesAnsen Huang1-0/+9
The Variable PEIM's index table optimization search path incorrectly returns deleted variables instead of valid variables when duplicate variables exist with different states. This occurs when: - One variable has deleted state (VAR_IN_DELETED_TRANSITION & VAR_ADDED, value 0x3C) - One variable has valid state (VAR_ADDED, value 0x3F) - Both variables have the same name and GUID The function should prioritize and return the valid variable, but the index table search was returning the first match regardless of state validity. In the FindVariableEx() index table traversal, the function was not properly validating variable states before returning a match. When CompareWithValidVariable() found a matching variable name and GUID, it would return immediately without checking if the variable state was valid (0x3F) or deleted (0x3C). This issue only affects the index table optimization search path and does not impact the linear traversal search path. The Variable PEIM has two main search mechanisms: 1. Linear traversal search - Walks through the entire variable store checking each header sequentially. This path has correct state validation logic and is unaffected by this issue. 2. Index table optimization search - Uses a gEfiVariableIndexTableGuid HOB to quickly jump to variable locations. This optimization is only active when the platform produces this HOB. This is the path affected by the issue. This commit adds explicit state validation in FindVariableEx() to skip variables with deleted state (0x3C). Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop3-6/+18
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-01MdeModulePkg/SmbiosDxe: fix table length checkGerd Hoffmann1-2/+2
In case EntryPointStructure does not exist yet use a length of zero instead of skipping the check altogether. Fixes a heap overflow in the following code flow in case the first smbios table installed is larger than SMBIOS_TABLE_MAX_LENGTH. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-07-31MdeModulePkg/HiiDatabaseDxe: Fix potential intrinsic errorMichael Kubacki1-19/+14
In some VS22 versions, these code patterns (assiging the scalar in a loop) have been found to be converted into calls to the `memcpy` intrinsic. This change updates them to use CopyMem to avoid the potential error. Previous: - MSVC version: 14.31.31103 New: - MSVC version: 14.32.31326 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-07-21MdeModulePkg/PartitionDxe: Abort on primary GPT recovery failureRichard Lyu1-10/+21
When the primary GPT is invalid, PartitionInstallGptChildHandles() restores it from the backup and re-validates it. Both the restore write and the re-validation can fail (e.g. write-protected media, or a backup AlternateLBA pointing beyond the device), yet the existing code only logs the failure and parses partitions from a known-invalid PrimaryHeader. Abort GPT processing when either the restore or the validation fails, so partitions are only ever parsed from a validated primary GPT. The backup recovery branch is left unchanged, as the primary is already validated. A device with an unrecoverable primary GPT now installs no child handles instead of using an invalid header. This keeps the table PartitionDxe uses in sync with the one DxeTpm2MeasureBootLib measures into PCR[5]. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Extract shareable GPT parser into a libraryRichard Lyu3-590/+8
As reported in CVE-2024-13745 via oss-sec, DxeTpm2MeasureBootLib can measure a partition table that differs from the one parsed by the PartitionDxe driver. To address this, the more complete GPT parsing logic from PartitionDxe is extracted into a standalone GptLib library so it can be shared between PartitionDxe and DxeTpm2MeasureBootLib. This ensures that the exact same partition table measured into PCR[5] is the one parsed and used by the system. PartitionDxe behavior is unchanged. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-06-22MdeModulePkg/TerminalDxe: Change print level to eliminate interferenceQihang Gao1-1/+1
The debug message introduced by PR#12282 was printed at DEBUG_INFO level, which caused screen corruption in the UEFI Shell when running in DEBUG mode. Change the print level to DEBUG_VERBOSE to keep the Shell output clean during normal DEBUG builds while still retaining the message for verbose debugging scenarios. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn> Cc: Evgenii Shatokhin <euspectre@gmail.com>
2026-06-17MdeModulePkg/ReportStatusCodeRouter: Prevent recursive entry in PEI phaseJared Pan3-3/+70
Prevent recursive invocation of the PEI Report Status Code (RSC) Router that can lead to system hang or unexpected re-entrancy behavior during early boot. The defect was observed when PEI modules reported status codes while the router was already processing a previous request. This patch aligns PEI behavior with the robust RSC routing mechanisms already used in DXE and Runtime phases by adding a lightweight recursion guard to the PEI router. This ensures consistent behavior across boot stages and improves early-boot stability. Signed-off-by: Jared Pan <jared.pan@dell.com>
2026-06-09MdeModulePkg: Replace manual alignment checks with helper macrosMingjie Shen1-3/+3
Replace manual alignment checks with IS_ALIGNED() and ADDRESS_IS_ALIGNED(). Convert the following bitmask and modulo forms: - ((E & ((PowOf2Expr) - ONE)) == ZERO) - ((E & ((PowOf2Expr) - ONE)) != ZERO) - ((E % (PowOf2Expr)) == ZERO) - ((E % (PowOf2Expr)) != ZERO) to the corresponding helper macro forms: + IS_ALIGNED (E, PowOf2Expr) + !IS_ALIGNED (E, PowOf2Expr) PowOf2Expr is limited to known power-of-two expressions, including SIZE_* and BASE_* macros, EFI_PAGE_SIZE, CPU_STACK_ALIGNMENT, RUNTIME_PAGE_ALLOCATION_GRANULARITY, sizeof() of UEFI integer types (e.g. BOOLEAN, CHAR16, UINT32, UINTN) and pointer types, and 1 << E1 expressions. Address checks that cast the checked value to UINTN are written with ADDRESS_IS_ALIGNED(). The change was generated with the Coccinelle semantic patch below. ```smpl @power_of_2_expr@ expression PowOf2Expr; expression E1; typedef BOOLEAN, CHAR8, CHAR16, INT8, UINT8, INT16, UINT16, INT32, UINT32, INT64, UINT64, INTN, UINTN; type ScalarType = { BOOLEAN, CHAR8, CHAR16, INT8, UINT8, INT16, UINT16, INT32, UINT32, INT64, UINT64, INTN, UINTN }; type AnyType; type PointerType = AnyType *; idexpression ScalarType ScalarValue; idexpression PointerType PointerValue; constant SizeBase =~ "^(SIZE|BASE)_(1|2|4|8|16|32|64|128|256|512)[KMGTPE]B$"; constant NamedPowerOf2 =~ "^(EFI_PAGE_SIZE|CPU_STACK_ALIGNMENT|RUNTIME_PAGE_ALLOCATION_GRANULARITY)$"; constant ONE = {1, 1U, 1u}; @@ ( ( SizeBase | NamedPowerOf2 | ONE << E1 | sizeof (ScalarType) | sizeof (PointerType) | sizeof (ScalarValue) | sizeof (PointerValue) ) & PowOf2Expr ) @aligned depends on power_of_2_expr disable is_zero,isnt_zero@ expression E; expression power_of_2_expr.PowOf2Expr; constant ONE = {1, 1U, 1u}; constant ZERO = {0, 0U, 0u}; @@ ( ((E & (E - ONE)) == ZERO) | - ((E & ((PowOf2Expr) - ONE)) == ZERO) + IS_ALIGNED (E, PowOf2Expr) | ((E & (E - ONE)) != ZERO) | - ((E & ((PowOf2Expr) - ONE)) != ZERO) + !IS_ALIGNED (E, PowOf2Expr) | - ((E % (PowOf2Expr)) == ZERO) + IS_ALIGNED (E, PowOf2Expr) | - ((E % (PowOf2Expr)) != ZERO) + !IS_ALIGNED (E, PowOf2Expr) ) @address_is_aligned@ typedef UINTN; expression *Address; expression Alignment; @@ - IS_ALIGNED ((UINTN) Address, Alignment) + ADDRESS_IS_ALIGNED (Address, Alignment) @normalize_aligned disable paren expression@ expression E, SZ; @@ ( - (IS_ALIGNED (E, SZ)) + IS_ALIGNED (E, SZ) | - (!IS_ALIGNED (E, SZ)) + !IS_ALIGNED (E, SZ) ) @normalize_macro_args disable paren expression@ expression E, SZ; @@ ( - IS_ALIGNED ((E), SZ) + IS_ALIGNED (E, SZ) | - IS_ALIGNED (E, (SZ)) + IS_ALIGNED (E, SZ) ) ``` Signed-off-by: Mingjie Shen <shen497@purdue.edu>
2026-06-09MdeModulePkg: Remove Depex section in UEFI_DRIVER and UEFI_APPLICATIONQihang Gao1-3/+0
According to INF specification, UEFI_DRIVER and UEFI_APPLICATION cannot have Depex section. So remove it. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-06-01MdeModulePkg/Variable: Avoid double VA conversion of FVB protocolArd Biesheuvel1-7/+45
For historical reasons, VariableRuntimeDxe performs virtual address conversion on the FVB protocol member pointers of the protocol instance that backs the EFI variable store. However, the driver that produces the actual instance should be doing this, as it is the owner and provides the actual implementation of those methods. Unfortunately, we cannot simply remove this: existing FVB drivers may rely on the Variable driver performing the conversion on their behalf. So the Variable driver should convert the pointers only when the FVB producer has not already done so. The SetVirtualAddressMap event can be delivered in arbitrary order, so we cannot rely on whether this driver converts its pointers before or after the FVB protocol owner receives the event. Fix this by recording the converted addresses in a shadow FVB protocol rather than converting the live pointers directly. On the first runtime variable access, check whether the FVB producer has performed its own conversion; if not, swap in the shadow copy's converted pointers. Without this fix, platforms where the FVB producer performs its own SetVirtualAddressMap conversion (e.g., OP-TEE StandaloneMm-backed EepromFvb on NXP LX2160A) suffer double pointer conversion, causing runtime variable access to crash. Signed-off-by: Ard Biesheuvel <ardb+tianocore@kernel.org> Tested-by: Liz Fong-Jones <lizf@honeycomb.io> Cc: Liming Gao <gaoliming@byosoft.com.cn>
2026-05-27MdeModulePkg: Enhance the handling of registering hot keyQihang Gao1-4/+8
It's not a proper approach when dealing the return string of HiiGetString function with ASSERT on REALEASE or NOOPT mode. This patch add a check for NewString before calling RegisterHotKey() for the case. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-05-27MdeModulePkg: Add missing FreePool to fix memory leak issueQihang Gao1-2/+9
The return value of HiiGetString function should be freed by using FreePool(). By the way, add a check for NewString before calling RegisterHotKey(). Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-05-27MdeModulePkg: Add support for generation of HEST tableHimanshu Chauhan4-0/+467
Add support for generation of HEST table with the help of a remote RAS agent. The HEST table is generated but the error descriptors (in GHESv2 or other platform specific format) are fetched from the RAS agent. Signed-off-by: Himanshu Chauhan <himanshu.chauhan@oss.qualcomm.com>
2026-05-26MdeModulePkg/TerminalDxe: Fix a typoEvgenii Shatokhin2-10/+10
s/Regsitered/Registered/ Signed-off-by: Evgenii Shatokhin <euspectre@gmail.com>
2026-05-26MdeModulePkg/TerminalDxe: Fix handling of shift state in notificationsEvgenii Shatokhin1-0/+37
Fixes: #12281 Currently, TerminalConInRegisterKeyNotify() allows registering a notification with nonzero KeyShiftState or KeyToggleState. However, IsKeyRegistered() ignores these when checking if the keys match. As a result, some firmware component may successfully register a notification for, say, RCtrl+n, but the notification function will be called each time the user presses 'n', which is wrong. Shift state and toggle state are not transferred via a serial line, so the notification functions for the keys with nonzero KeyShiftState or KeyToggleState will never trigger in this case. TerminalConInRegisterKeyNotify() could reject such notifications but it is unclear if it could break the existing UEFI components. Instead, this patch adds a debug message when someone tries to register a notification with nonzero states, it also updates IsKeyRegistered() to take KeyShiftState and KeyToggleState into account. This way, IsKeyRegistered() will treat the notifications for 'n' and 'RCtrl+n' as different ones. So, the callback function for 'RCtrl+n' will not be called when the user presses 'n'. As it is not prohibited to set only EFI_SHIFT_STATE_VALID flag in the shift state (leaving the remaining bits zeroed), IsKeyRegistered() ignores EFI_SHIFT_STATE_VALID. Signed-off-by: Evgenii Shatokhin <euspectre@gmail.com>
2026-05-08MdePkg,MdeModulePkg: Fix Spelling Error in Udf DefinitionsOliver Smith-Denny1-1/+1
Fix spelling error in definition in Udf.h. Update consumer in MdeModulePkg. A temporary backward-compatible alias is provided for the old misspelled enum name. Continuous-integration-options: PatchCheck.ignore-multi-package Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2026-05-06MdeModulePkg: Cleanup debug print readabilityBenjamin Doron1-1/+1
All debug prints should end in a newline character. Signed-off-by: Benjamin Doron <benjamin.doron00@gmail.com>
2026-03-25MdeModulePkg: VariableSmmRuntimeDxe: Fix MM communicate v3 buffer sizingLiqi Qi1-2/+7
This change updates `VariableSmmRuntimeDxe` to correctly size its runtime communication buffer when `EFI_MM_COMMUNICATION3_PROTOCOL` is present. In the current flow, the runtime variable path may use MM communication v3, but the input size is first validated against the global variable `mVariableBufferPayloadSize`. The size is then validated a second time during communication buffer initialization using the v3 header size, which results in `GetVariable` calls with sufficiently large buffers consistently failing. This update makes the allocation logic v3‑aware so that the runtime variable communication buffer matches the header format actually in use, avoiding failures for larger variable transactions. Signed-off-by: Kun Qin <kun.qin@microsoft.com>
2026-03-19MdeModulePkg: : revert EndofDxeEvent TPLs to TPL_NOTIFY for FPDTYeoreum Yun1-1/+1
commit aa02571 ("MdeModulePkg: Change EndofDxeEvent TPLs to TPL_CALLBACK") changed EndOfDxeEvent TPLs from TPL_NOFIY to TPL_CALLBACK. However this commit makes a boot failure on the FVP platform when FPDT ACPI table generation is enabled: [FirmwarePerformanceDxe] Error when lock variable FirmwarePerformance, Status = Write Protected ASSERT_EFI_ERROR (Status = Write Protected) ASSERT [FirmwarePerformanceDxe] FirmwarePerformanceDxe.c(405): !(((RETURN_STATUS)(Status)) >= 0x8000000000000000ULL) Currently, EVT_NOTIFY_SIGNAL events are managed in FILO order, as new events are inserted using InsertHeadList(). The sequence is as follows: 1. DxeCore initializes DxeCorePerformanceLib, whose constructor creates an EndOfDxe event (gEfiEndOfDxeEventGroupGuid) with the ReportFpdtRecordBuffer() callback. 2. MmCommunicationDxe (in ArmPkg) creates another EndOfDxe event to notify StandaloneMm. This event is inserted ahead of the one created in (1). 3. PlatformBootManagerBeforeConsole() signals EndOfDxe, which triggers the event created in (2) first. 4. When the callback from (2) runs, StandaloneMm calls LockVariablePolicy(). 5. The callback from (1) is then invoked and attempts to update FPDT via InstallFirmwarePerformanceDataTable(). During this process, it tries to register a variable policy for the FirmwarePerformance variable. However, since the Variable Policy interface was locked in (4), the operation fails with EFI_WRITE_PROTECTED. To resolve this issue, revert EndofDxeEvent TPLs to TPL_NOTIFY for FPDT. Fixes: aa02571 ("MdeModulePkg: Change EndofDxeEvent TPLs to TPL_CALLBACK") Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-03-17MdeModulePkg: Change EndofDxeEvent TPLs to TPL_CALLBACKSherry Fan1-1/+1
Change FPDT events at EndOfDxe to TPL_CALLBACK as TPL_NOTIFY is not necessary. Signed-off-by: Sherry Fan <sherryfan@microsoft.com>
2026-02-28MdeModulePkg/TerminalDxe: Fix Backspace key for VT-UTF8 terminal typeDamien-Chen1-1/+8
When QEMU is launched with -nographic, the Backspace key (DEL, 0x7f) doesn't work in the UEFI Shell because the VT-UTF8 terminal type interprets DEL as SCAN_DELETE instead of CHAR_BACKSPACE. Modern terminal emulators (xterm, gnome-terminal, etc.) send DEL (0x7f) for Backspace and are UTF-8 compatible. This patch updates TerminalTypeVtUtf8 to interpret DEL as CHAR_BACKSPACE, consistent with how TerminalTypeTtyTerm already handles it. This approach preserves VT-UTF8 as the default terminal type (which supports full Unicode), while fixing the Backspace functionality for modern terminal environments. Signed-off-by: Damien Chen <inkfan130924783@gmail.com>
2026-02-28MdeModulePkg: Fix PreferMode selection for same-width text modesAshraf Ali S1-2/+2
The current PreferMode selection logic requires both Columns AND Rows to be strictly greater (>) than the current maximum, which fails when a text mode has the same column count but more rows. Example failure case (1920x1200 display): - Mode 5: 240x56 - Selected as PreferMode - Mode 6: 240x63 - Rejected because 240 is not > 240 This mismatch causes ConsplitterSetConsoleOutMode to later request Mode 6, triggering an unnecessary text mode change and clearing the screen during console init. Root Cause: GraphicsConsole used: if ((Col > Max) && (Row > Max)) This fails when only rows increase while columns stay the same. Solution: Change to: if ((Col >= Max) && (Row >= Max)) This aligns with ConSplitter mode selection logic and correctly selects the mode with the highest column and row counts. After fix (1920x1200 display): - Mode 5: 240x56 - Mode 6: 240x63 - Correctly selected as PreferMode This ensures GraphicsConsole and ConSplitter match on the preferred mode preventing unnecessary screen clears during console initialization. Signed-off-by: Ashraf Ali S <ashraf.ali.s@intel.com>
2026-02-24MdeModulePkg: Replace include guards with #pragma onceMichael Kubacki81-323/+85
Replace traditional `#ifndef`/`#define`/`#endif` include guards with `#pragma` once. `#pragma once` is a widely supported preprocessor directive that prevents header files from being included multiple times. It is supported by all toolchains used to build edk2: GCC, Clang/LLVM, and MSVC. Compared to macro-based include guards, `#pragma once`: - Eliminates the risk of macro name collisions or copy/paste errors where two headers inadvertently use the same guard macro. - Eliminate inconsistency in the way include guard macros are named (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.). - Reduces boilerplate (three lines replaced by one). - Avoids polluting the macro namespace with guard symbols. - Can improve build times as the preprocessor can skip re-opening the file entirely, rather than re-reading it to find the matching `#endif` ("multiple-include optimization"). - Note that some compilers may already optimize traditional include guards, by recognzining the idiomatic pattern. This change is made acknowledging that overall portability of the code will technically be reduced, as `#pragma once` is not part of the C/C++ standards. However, this is considered acceptable given: 1. edk2 already defines a subset of supported compilers in BaseTools/Conf/tools_def.template, all of which have supported `#pragma once` for over two decades. 2. There have been concerns raised to the project about inconsistent include guard naming and potential macro collisions. Approximate compiler support dates: - MSVC: Supported since Visual C++ 4.2 (1996) - GCC: Supported since 3.4 (2004) (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html) - Clang (LLVM based): Since initial release in 2007 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-02-10MdeModulePkg/HiiDatabaseDxe: Fix parser issue in GetNameElement()Yang Gang1-2/+0
This commit removes an wrong goto statement which may cause DXE_ASSERT! `ConfigRequest` example: `&NameValueVar0&NameValueVar1&NameValueVar2`. When `*Progress` is `&NameValueVar2`, code will run to `goto Done;`, then return NULL. Signed-off-by: Yang Gang <yanggang@byosoft.com.cn>
2026-02-04MdeModulePkg: MmVariablePei: Populate correct v3 headerKun Qin3-143/+373
When using MM communicate v3 to fetch variable, the header calculation was incorrect, causing the variable driver on the secure environment to have random behavior. This change refactored the original routine by following the current DXE instance (mostly). Signed-off-by: Kun Qin <kun.qin@microsoft.com>
2026-02-02MdeModulePkg/SetupBrowserDxe: Check Form parameter in RuleIdToExpression()Yang Gang1-0/+4
Signed-off-by: Yang Gang <yanggang@byosoft.com.cn>
2026-02-02MdeModulePkg/SetupBrowserDxe: Fix code issue in ParseOpCodes()Yang Gang1-1/+1
`if (CurrentForm != NULL)` and `if (InScopeDisable && (CurrentForm == NULL))`conflict. `if (CurrentForm != NULL)` should be `if (CurrentExpression != NULL)`. Signed-off-by: Yang Gang <yanggang@byosoft.com.cn>
2026-02-02MdeModulePkg: BdsDxe: Introduce infinite boot retriesSherry Fan2-9/+17
This PR introduces a new feature to enable infinite boot retries based on a newly created PCD. When true, the system will continuously loop over all boot options. PCD default is FALSE to match existing functionality. This change is tested on QEMU based virtual platforms and physical platforms. This change is useful for certain server cases. Infinite retries allows a server to continuously attempt boot in case of network failure and recovery, and for such attempts to be accurately recorded in the TCG logs. Co-authored-by: Kun Qin <kun.qin@microsoft.com> Co-authored-by: Aaron Pop <aaron.pop@microsoft.com> Co-authored-by: Michael Kubacki <michael.kubacki@microsoft.com> Signed-off-by: Sherry Fan <sherryfan@microsoft.com>
2026-02-01MdeModulePkg/CapsuleOnDiskLoadPei: fix gcc 16 warningGerd Hoffmann1-3/+0
MdeModulePkg/Universal/CapsuleOnDiskLoadPei/CapsuleOnDiskLoadPei.c:176:11: error: variable ‘Index’ set but not used [-Werror=unused-but-set-variable=] 176 | UINTN Index; | ^~~~~ Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-02-01MdeModulePkg/DisplayEngineDxe: fix gcc 16 warningGerd Hoffmann1-3/+1
MdeModulePkg/Universal/DisplayEngineDxe/ProcessOptions.c: In function ‘CreateSharedPopUp’: MdeModulePkg/Universal/DisplayEngineDxe/ProcessOptions.c:590:11: error: variable ‘Count’ set but not used [-Werror=unused-but-set-variable=] 590 | UINTN Count; | ^~~~~ Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-02-01MdeModulePkg/SmbiosMeasurementDxe: fix gcc 16 warningGerd Hoffmann1-4/+0
MdeModulePkg/Universal/SmbiosMeasurementDxe/SmbiosMeasurementDxe.c: In function ‘GetSmbiosStringById’: MdeModulePkg/Universal/SmbiosMeasurementDxe/SmbiosMeasurementDxe.c:221:10: error: variable ‘Size’ set but not used [-Werror=unused-but-set-variable=] 221 | UINTN Size; | ^~~~ Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-01-23MdeModulePkg/LoadFileOnFv2: Fix typo in Buffer parameter descriptionDongyan Qian1-1/+1
The comment for the Buffer parameter incorrectly said "then no the size" instead of "then the size". This patch fixes the typo only; no functional changes. Reported-by: Yao Zi <ziyao@disroot.org> Signed-off-by: Dongyan Qian <qiandongyan@loongson.cn>
2026-01-21MdeModulePkg/Universal/RegularExpressionDxe: Fix VS2022 NOOPT IA32 __allmulMichael D Kinney2-0/+101
Add implementation of intrinsic __allmul that is generated with VS2022 NOOPT IA32 builds. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2026-01-19MdeModulePkg/AcpiTableDxe:Created EfiACPIReclaimMemory for ACPIHOB RSDPGeorge Liao1-6/+48
The RSDP table come from ACPI HOB which may no store in the EfiACPIReclaimMemory-type memory. Therefore need to reserve an EfiACPIReclaimMemory-type memory for it. Signed-off-by: George Liao <george.liao@intel.com>
2026-01-15MdeModulePkg: StatusCodeHandler Stmm remove assertAaron Pop (from Dev Box)1-4/+5
In StandaloneMM mode, IsStatusCodeUsingSerialPort is expecting to find gMmStatusCodeUseSerialHobGuid, and will assert if it is not found. Change the logic so that if the Guided Hob is not found, to let the function return FALSE and progress to proceed. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-01-08MdeModulePkg: Optimize the process while cleaning dynamic stringQihang Gao1-29/+41
In the current code, the HiiPackageList will be created and destroyed each time the form is closed, which is unneccessary. This patch makes a function that produces the origin HiiPackageList. The function will only be called when the driver is initialized and the HiiPackageList will be directly updated in DriverHealthManagerCleanDynamicString function. This approach can avoid the unneccessary creation and destruction of the HiiPackageList. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-01-08MdeModulePkg: Fix issue that French package is unexpectedly cleanedQihang Gao1-1/+1
The DriverHealthManagerStrings.uni file defines both English and French languages, resulting in the generation of two Unicode string packages: the first for English and the second for French. When cleaning the dynamic strings from the HII package list, the pointer which should point to dynamic string package incorrectly points to the static French package, causing it to be unexpectedly cleaned. This patch fixes the pointer of EFI_HII_PACKAGE_END type PackageHeader. This way, there is no need for concern regarding the number of language packages available. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2025-12-24MdeModulePkg/Universal/DebugServicePei: Correct function and entry pointJeremy Compostella2-2/+2
Correct a typographical error in the DebugServicePei module by renaming the function and entry point from DebugSerivceInitialize to DebugServiceInitialize in both the C source file and the INF configuration file. Signed-off-by: Jeremy Compostella <jeremy.compostella@intel.com>
2025-12-19MdeModulePkg: Fix regressions from 11687, 11689.aaronpop2-22/+28
11687 introduced a null check and break on the orderedlist carriage return input handler. The carriage return is a special case that should result in exiting the menu, but the null check that prevented null pointer access changed the logic to continue in the input wait loop. Removed the break while still preventing null variable access and allow function to exit. 11689 introduced checks on the call to EfiBootManagerGetLoadOptions, but this encounterd a problem with the way that a default platform recovery option was created. The default platform recovery option was attempting to go through existing recovery options to get the next available recovery option number. The introduced null check short circuited these additional calls and resulted in the platform recovery option not being created. Modified the logic to no longer attempt to access recovery options when non exist, and still create the default platform recovery option. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2025-12-06MdeModulePkg: Fix regressions from 11686, 11687, 11688, 11689.Aaron Pop10-26/+40
11686, 11687, 11688, 11689 included some inverted conditionals during the refactor. While the system booted, some behavior was incorrect based on the inverted conditionals. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2025-12-02MdeModulePkg: Fix recently introduced uninitialized variable usage.Aaron Pop3-2/+7
Address the build regressions, introduced in #11724, #11688, #11686 #11685. These build regressions are for uninitialized variables before use. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2025-11-24MdeModulePkg/PCD: Replace VariableLock with VariablePolicySathya Ravichandran4-13/+24
Since VariableLock compromises security in the SMM environment, it is deprecated. Used VariablePolicy instead for stronger and more flexible UEFI variable protection. Ref: [acd66e4] Cc: Sachin Ganesh <sachinganesh@ami.com> Signed-off-by: Sathya Ravichandran <sathyar@ami.com>
2025-11-24MdeModulePkg/EsrtDxe: Replace VariableLock with VariablePolicySathya Ravichandran3-8/+29
Since VariableLock compromises security in the SMM environment, it is deprecated. Used VariablePolicy instead for stronger and more flexible UEFI variable protection. Ref: [acd66e4] Cc: Sachin Ganesh <sachinganesh@ami.com> Signed-off-by: Sathya Ravichandran <sathyar@ami.com>
2025-11-24MdeModulePkg/Capsule: Replace VariableLock with VariablePolicySathya Ravichandran2-10/+21
Since VariableLock compromises security in the SMM environment, it is deprecated. Used VariablePolicy instead for stronger and more flexible UEFI variable protection. Ref: [acd66e4] Cc: Sachin Ganesh <sachinganesh@ami.com> Signed-off-by: Sathya Ravichandran <sathyar@ami.com>