| Age | Commit message (Collapse) | Author | Files | Lines |
|
QuestionName is allocated by HiiGetString() but is not released in
several code path. This causes memory leaks whenever these paths are
taken.
Add FreePool (QuestionName) after it is no longer needed.
No functional change intended.
Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
|
|
StrValue is obtained from HiiGetString(), which allocates a new string
buffer. The buffer is used to set DefaultValue->Buffer but is never
released, causing a memory leak each time this code path is executed.
Add FreePool (StrValue) after it is no longer needed.
No functional change intended.
Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
|
|
Adds a DEBUG_INFO message when Reclaim() finishes so platform boot
logs show whether reclaim ran and what status it returned. This
makes it easier to distinguish reclaims impact on boot measurements.
Signed-off-by: Abdul Lateef Attar <AbdulLateef.Attar@amd.com>
|
|
Raise TPL to TPL_CALLBACK around the ConnectController() call in
UsbBusRecursivelyConnectWantedUsbIo() and restore the original TPL
afterward.
UsbBusRecursivelyConnectWantedUsbIo() is normally reached through the
DriverBinding Start routine invoked by gBS->ConnectController(), which
runs at TPL_APPLICATION. While the wanted UsbIo handle is being
connected, the USB device can be removed. The device removal polling
event in UsbBus runs at TPL_CALLBACK. If the connect runs at
TPL_APPLICATION, that event can preempt the connection and cause
commands to be sent to a stale or non-existent USB device address,
producing a lot of timeout transfers.
This differs from UsbConnectDriver(), which is called from the
enumeration polling event (XHCI async event) and is usually already
at TPL_CALLBACK or TPL_NOTIFY. That function uses RestoreTPL()/
RaiseTPL() to ensure ConnectController() runs at TPL_CALLBACK.
Signed-off-by: Marlboro_Chuang <marlboro.chuang@dell.com>
|
|
Some specific device requires a quirk in the Interface descriptor for
InterfaceNumber to work properly
[Suggested Solution]
Implement the mechanism to ensure the first InterfaceNumber not equal
to zero.
Signed-off-by: Marlboro_Chuang <marlboro.chuang@dell.com>
|
|
EFIAPI is required on library interface functions to ensure that the
correct calling convention is used.
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
Update the prompt strings for save/exit and confirm actions to show both
uppercase and lowercase key options (e.g., 'Y(y)' and 'N(n)') to make it
clear that the system accepts either case. This improves user experience
by avoiding confusion about case sensitivity.
Affected strings:
- ARE_YOU_SURE (CustomizedDisplayLib)
- CONFIRM_OPTION (DisplayEngineDxe)
- RECONNECT_CHANGES_OPTIONS (DisplayEngineDxe)
French translations are updated accordingly.
Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
|
|
Previously EfiBootManagerBoot reported
EFI_SW_DXE_BS_EC_BOOT_OPTION_FAILED when a boot option returned an
error, but reported nothing on success. Report the PI 1.10 status
code EFI_SW_DXE_BS_PC_BOOT_OPTION_COMPLETE when a boot option loads,
executes, and returns success, so status code listeners can tell that
a boot option was attempted and that control returned to firmware.
Signed-off-by: Sachin Ganesh <sachinganesh@ami.com>
|
|
Applies a UEFI variable policy to the "MTC" variable to ensure that it
is the size of a UINT32 and the variable attributes are restricted
to BS, RT, and NV.
A protocol dependency on the Variable Policy Protocol is not added to
the driver's dependency expression to allow it to be dispatched in
firmware that does not have the Variable Policy Protocol installed.
Co-authored-by: Michael Kubacki <michael.kubacki@microsoft.com>
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
Currently, DxeIpl will allocate memory for the new DXE stack,
which creates a memory allocation HOB for that region. It will
then call UpdateStackHob() to find the stack HOB with the old
stack info and update the memory address/length to correspond
to the new stack. It then creates a new memory allocation HOB
for the old stack region as it needs to remain mapped.
This ends up creating two memory allocation HOBs for the new
stack: a regular memory allocation HOB for the AllocatePages()
call and then the stack HOB (which is a memory allocation HOB
with a special name).
When DXE Core ingests these, it will ignore one of the two HOBs
when it goes to allocate memory. However, this is incorrectly
describing handoff state. There never should be overlapping
memory allocation HOBs.
This commit updates DxeIpl behavior to instead find the old
stack HOB, convert it to a regular memory allocation HOB,
then find the memory allocation HOB for the new stack range
and convert it into the stack HOB.
Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
|
|
DumpUicCmdExecResult & DumpQueryResponseResult are called to dump the
result of UIC commands after a failure. Depending on the nature of the
failure, not all information may have been properly initialized. This is
already handled in callers with existing retry logic, but the assert in
the dump command can cause a crash in debug builds for due to hardware
race conditions on first attempt.
Signed-off-by: Chris Fernald <chfernal@microsoft.com>
|
|
Some platforms may disable `ASSERT_DEADLOOP_ENABLED` in
`PcdDebugPropertyMask`. In this case ASSERT won't hang the machine.
Replaced those simple ASSERT with proper error returning handling.
Signed-off-by: Paddy Deng (AMI US Holdings Inc) <v-dengpaddy@microsoft.com>
|
|
In GetFilename(), the post-loop fallback termination used
sizeof (EfiFileName), which is the size of the CHAR8 * pointer
parameter (8 bytes on X64), not the buffer size. Use EfiFileNameSize -
4 to match the bound of the copy loop above so the string is
terminated at the true end of the buffer.
Tested on OvmfPkgIa32X64, DEBUG, GCC: DumpImageRecords() prints all
runtime image names correctly and NUL-terminated, with no ASSERTs.
Signed-off-by: Mingjie Shen <shen497@purdue.edu>
|
|
Set the numeric step to 1 to allow +/- key adjustment.
Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
|
|
The Variable PEIM's index table optimization search path incorrectly
returns deleted variables instead of valid variables when duplicate
variables exist with different states.
This occurs when:
- One variable has deleted state (VAR_IN_DELETED_TRANSITION & VAR_ADDED,
value 0x3C)
- One variable has valid state (VAR_ADDED, value 0x3F)
- Both variables have the same name and GUID
The function should prioritize and return the valid variable, but the
index table search was returning the first match regardless of state
validity.
In the FindVariableEx() index table traversal, the function was not
properly validating variable states before returning a match. When
CompareWithValidVariable() found a matching variable name and GUID, it
would return immediately without checking if the variable state was
valid (0x3F) or deleted (0x3C).
This issue only affects the index table optimization search path and
does not impact the linear traversal search path. The Variable PEIM
has two main search mechanisms:
1. Linear traversal search - Walks through the entire variable store
checking each header sequentially. This path has correct state
validation logic and is unaffected by this issue.
2. Index table optimization search - Uses a gEfiVariableIndexTableGuid
HOB to quickly jump to variable locations. This optimization is only
active when the platform produces this HOB. This is the path affected
by the issue.
This commit adds explicit state validation in FindVariableEx() to skip
variables with deleted state (0x3C).
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
UefiBootManagerLibConstructor() is a constructor function in BmBoot.c
that is missing as the constructor in the INF file.
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
Add interrupt-enable recursion depth tracking using
mInterruptEnableNestDepth and a bounded assertion in
CoreSetInterruptState().
This provides early detection for unintended recursive
interrupt-enable loops.
Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
|
|
Refactor the CoreSetInterruptState(TRUE) flow so EnableInterrupt() is
invoked through a single call site.
Behavior is unchanged: interrupts remain disabled in SMM and are enabled
outside SMM.
Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
|
|
12828 introduced an ASSERT in HiiGetBrowserData() that fires when
InternalHiiBrowserCallback() returns NULL. This is a valid return
value indicating the browser has no data for the requested variable,
and callers already handle this by checking the FALSE return value.
The ASSERT is incorrect because it triggers on a non-error path,
causing a crash when the browser callback legitimately returns no data.
Remove the unnecessary ASSERT while keeping the existing FALSE return
so callers continue to handle this case gracefully.
Cc: Qihang Gao <gaoqihang@loongson.cn>
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp
When a function has a return status, it should
be checked to verify the function completed successfully.
Failing to check the return status can result in null pointer
dereferences or use of uninitialized variables.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type
If the narrow type (smaller range) is compared against a wide type
(larger range), the narrow value may overflow before reaching the wide
value. This can cause unexpected behavior, such as:
Infinite loops (loop condition never becomes false).
Incorrect logic (comparison results are misleading).
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Security/CWE/CWE-457/ConditionallyUninitializedVariable.qhelp
Some local variables, when going through a code path, can
end up uninitialized (using the value they had at the start
of the function). This is generally due to an error path
that can occur based on the library instances, or the
unchecked error (i.e. a allocation failing).
These variables should be initialized with a known value
that will result in the function being able to exit
gracefully.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Security/CWE/CWE-190/ComparisonWithWiderType.qhelp
Switch to using SafeUint16Add for calculating offsets into
block data. The data being used in the calculation comes from
config block strings, and there is no validation of the values
before the calculation occurs.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type
If the narrow type (smaller range) is compared against a wide type
(larger range), the narrow value may overflow before reaching the wide
value. This can cause unexpected behavior, such as:
Infinite loops (loop condition never becomes false).
Incorrect logic (comparison results are misleading).
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp
When a function has a return status, it should
be checked to verify the function completed successfully.
Failing to check the return status can result in null pointer
dereferences or use of uninitialized variables.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp
When a function has a return status, it should
be checked to verify the function completed successfully.
Failing to check the return status can result in null pointer
dereferences or use of uninitialized variables.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type
If the narrow type (smaller range) is compared against a wide type
(larger range), the narrow value may overflow before reaching the wide
value. This can cause unexpected behavior, such as:
Infinite loops (loop condition never becomes false).
Incorrect logic (comparison results are misleading).
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
In case EntryPointStructure does not exist yet use a length of zero instead of
skipping the check altogether. Fixes a heap overflow in the following code
flow in case the first smbios table installed is larger than
SMBIOS_TABLE_MAX_LENGTH.
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
|
|
Dispatch Shutdown Notification to every NVMe first, then polling
every NVMe t omaake sure all NVMe's shutdown processing is
completed.This will help to save a lot time when BIOS trigger
reset for Servers whose have many NVMes. Tested on a platform
with AMD EPYC cpu with 26 NVMes, this method reduce reset time
from 3 minutes to 10 seconds.
Signed-off-by: Theo <theo.tao@foxmail.com>
|
|
MemoryBinGoogleTest.PopulatesFromValidHob asserted fixed page counts for
each memory type. PopulateMemoryTypeInformation, however, rounds the
runtime memory types (EfiReservedMemoryType, EfiACPIMemoryNVS,
EfiRuntimeServicesCode, EfiRuntimeServicesData) up to
RUNTIME_PAGE_ALLOCATION_GRANULARITY. That granularity equals EFI_PAGE_SIZE
on IA32/X64, so the hard-coded values happened to match, but it is 64 KiB
on AArch64, where the same inputs round up to different page counts and the
test failed.
Compute the expected page counts with the same granularity rounding the
production code uses, so the test passes on all host architectures instead
of only x86.
Signed-off-by: Jeff Brasen <jbrasen@nvidia.com>
|
|
This change adds the AArch64 target for host based unit tests.
Signed-off-by: Kun Qin <kun.qin@microsoft.com>
|
|
UsbSelectConfig will introduce the UsbConnectDriver call.
If this UsbPortReset is happened in the Usb device driver Start() routine and the device FW can not be recovered by PortReset, the UsbSelectConfig will introduce the recursive loop.
[Suggested solution]
Since UsbPortReset should not change the Bus Topology, the Reset flow should only SetAddress and reconfigure the device.
Signed-off-by: Marlboro Chuang <marlboro.chuang@dell.com>
Signed-off-by: Jared Pan <jared.pan@dell.com>
|
|
In some VS22 versions, these code patterns (assiging the scalar in
a loop) have been found to be converted into calls to the `memcpy`
intrinsic. This change updates them to use CopyMem to avoid the
potential error.
Previous:
- MSVC version: 14.31.31103
New:
- MSVC version: 14.32.31326
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp
For items which allocate memory, or get a pointer from another
structure, it is important to validate that the pointers
are not null before they are dereferenced.
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type
If the narrow type (smaller range) is compared against a wide type
(larger range), the narrow value may overflow before reaching the wide
value. This can cause unexpected behavior, such as:
Infinite loops (loop condition never becomes false).
Incorrect logic (comparison results are misleading).
Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
|
|
In preparation for the MarkdownLintCheck plugin being added to the
repo, this change defaults the plugin to `AuditOnly` mode in each
package. This allows package maintainers to enable the plugin as they
see fit.
Continuous-integration-options: PatchCheck.ignore-multi-package
Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
|
|
Some SuperSpeed-capable devices may fall back to High-Speed
mode and cause subsequent commands to fail.
[Suggested Solution]
Check the BOS descriptor to verify SuperSpeed support and
trigger a port reset if needed to re-enumerate the device
properly.
Signed-off-by: Marlboro Chuang <marlboro.chuang@dell.com>
Signed-off-by: Jared Pan <jared.pan@dell.com>
|
|
USB devices whose configuration descriptor TotalLength exceeds 1024
bytes (e.g. IR cameras with large descriptor tables) previously hit
an EFI_DEVICE_ERROR hard-limit and failed to enumerate in PEI.
Replace the fixed array with a UINT8 * pointer and dynamically
allocate the exact amount of memory required via
PeiServicesAllocatePool() after the TotalLength is learned from the
initial 4-byte descriptor probe.
Signed-off-by: Damien Chen <damien.chen@dell.com>
|
|
Commit 7f505d377b44aeee59f34b3d898f6caf0a0df538 in 2024 added the
Type 4 field SocketType. Bump the default SMBIOS version to 3.8
in order for the larger table size to be valid.
Signed-off-by: Rebecca Cran <rebecca@bsdio.com>
|
|
Extend the GptLib host-based tests with negative cases that guard the
security hardening in PartitionValidGptTable(), PartitionCheckGptEntry()
and PartitionRestoreGptTable() against future regressions. These tests
exercise the shared parser, not the specific fix itself.
The new cases drive the parser with malformed GPT structures that an
attacker may present: bad signature/revision, header-size boundaries,
CRC corruption, MyLBA replay, zero/non-power-of-two entry sizes, LBA
multiplication overflow, out-of-range and overlapping entries, and
restore failure on write-protected media. The INF file header is
updated to note the added malformed coverage.
Signed-off-by: Richard Lyu <richard.lyu@suse.com>
|
|
Add the positive-path host-based tests for the shared GptLib parser
(extracted as part of the parser security hardening), ensuring the
tightened checks in PartitionValidGptTable(), PartitionCheckGptEntry()
and PartitionRestoreGptTable() do not falsely reject well-formed GPTs.
The tests run against an in-memory mock disk and cover accepted
primary/backup headers, boundary but legal header/entry sizes, correct
entry-status flagging on valid entries, and primary/backup restore
round-trips.
Signed-off-by: Richard Lyu <richard.lyu@suse.com>
|
|
When the primary GPT is invalid, PartitionInstallGptChildHandles()
restores it from the backup and re-validates it. Both the restore write
and the re-validation can fail (e.g. write-protected media, or a backup
AlternateLBA pointing beyond the device), yet the existing code only logs
the failure and parses partitions from a known-invalid PrimaryHeader.
Abort GPT processing when either the restore or the validation fails, so
partitions are only ever parsed from a validated primary GPT. The backup
recovery branch is left unchanged, as the primary is already validated.
A device with an unrecoverable primary GPT now installs no child handles
instead of using an invalid header. This keeps the table PartitionDxe uses
in sync with the one DxeTpm2MeasureBootLib measures into PCR[5].
Ref: https://seclists.org/oss-sec/2026/q2/727
Signed-off-by: Richard Lyu <richard.lyu@suse.com>
|
|
PartitionValidGptTable() checked the signature, header CRC32, MyLBA, the
entry-array CRC32 and the entry-array size overflow, but not several other
UEFI-mandated GPT header constraints. DxeTpm2MeasureBootLib used to enforce
these via Tpm2SanitizeEfiPartitionTableHeader(); once it switched to this
shared parser, the checks were lost on the path.
Also reject a header unless Header.Revision is GPT_HEADER_REVISION_V1,
HeaderSize is at least the 92-byte minimum, NumberOfPartitionEntries is
non-zero, SizeOfPartitionEntry is 128 * 2^n, and PartitionEntryLBA *
BlockSize cannot overflow. The "entries lie before FirstUsableLBA" rule is
intentionally omitted, as this routine also validates the backup header
whose entry array follows the usable region.
This restores the validation the measurement path lost and, because GptLib
is shared, tightens PartitionDxe the same way: malformed headers are now
rejected and the parse and measure paths stay identical.
Ref: https://seclists.org/oss-sec/2026/q2/727
Signed-off-by: Richard Lyu <richard.lyu@suse.com>
|
|
As reported in CVE-2024-13745 via oss-sec, DxeTpm2MeasureBootLib can
measure a partition table that differs from the one parsed by the
PartitionDxe driver.
To address this, the more complete GPT parsing logic from PartitionDxe
is extracted into a standalone GptLib library so it can be
shared between PartitionDxe and DxeTpm2MeasureBootLib. This ensures
that the exact same partition table measured into PCR[5] is the one
parsed and used by the system. PartitionDxe behavior is unchanged.
Ref: https://seclists.org/oss-sec/2026/q2/727
Signed-off-by: Richard Lyu <richard.lyu@suse.com>
|