Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 065be4d9222fa4677e5c4c4efbee9e0c1061bbf3
      
https://github.com/tianocore/edk2/commit/065be4d9222fa4677e5c4c4efbee9e0c1061bbf3
  Author: Doug Flick <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Include/Library/BaseCryptLib.h

  Log Message:
  -----------
  CryptoPkg: Add Pkcs7Encrypt API declaration to BaseCryptLib

Add Pkcs7Encrypt() function declaration and supporting defines
(CRYPTO_NID_AES128CBC, CRYPTO_NID_AES192CBC, CRYPTO_NID_AES256CBC,
CRYPTO_PKCS7_DEFAULT) to BaseCryptLib.h for creating DER-encoded
PKCS#7 envelopedData structures.

Signed-off-by: Doug Flick <[email protected]>


  Commit: 8b9b3808e1720f6be3aa2b6410bc817e9cfc62df
      
https://github.com/tianocore/edk2/commit/8b9b3808e1720f6be3aa2b6410bc817e9cfc62df
  Author: Doug Flick <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Library/BaseCryptLib/BaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/PeiCryptLib.inf
    A CryptoPkg/Library/BaseCryptLib/Pk/CryptPkcs7Encrypt.c
    A CryptoPkg/Library/BaseCryptLib/Pk/CryptPkcs7EncryptNull.c
    M CryptoPkg/Library/BaseCryptLib/RuntimeCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/SecCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/SmmCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/UnitTestHostBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/BaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/PeiCryptLib.inf
    A CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7EncryptNull.c
    M CryptoPkg/Library/BaseCryptLibMbedTls/RuntimeCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/SecCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/SmmCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/TestBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/UnitTestHostBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibNull/BaseCryptLibNull.inf
    A CryptoPkg/Library/BaseCryptLibNull/Pk/CryptPkcs7EncryptNull.c

  Log Message:
  -----------
  CryptoPkg: Add Pkcs7Encrypt OpenSSL and null implementations

Add CryptPkcs7Encrypt.c with OpenSSL-based Pkcs7Encrypt()
implementation using PKCS7_encrypt API. Add null stub
implementations for library instances that do not support
this function (PEI, Runtime, SEC, MbedTLS, Null). Update all
BaseCryptLib INF files to include the new source files.

Signed-off-by: Doug Flick <[email protected]>


  Commit: c13d86590220e1cc79d7db0bc34c687b41453c18
      
https://github.com/tianocore/edk2/commit/c13d86590220e1cc79d7db0bc34c687b41453c18
  Author: Doug Flick <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Driver/Crypto.c
    M CryptoPkg/Include/Pcd/PcdCryptoServiceFamilyEnable.h
    M CryptoPkg/Library/BaseCryptLibOnProtocolPpi/CryptLib.c
    M CryptoPkg/Private/Protocol/Crypto.h
    M CryptoPkg/Readme.md

  Log Message:
  -----------
  CryptoPkg: Expose Pkcs7Encrypt via EDKII_CRYPTO_PROTOCOL

Add EDKII_CRYPTO_PKCS7_ENCRYPT typedef and Pkcs7Encrypt member to
the EDKII_CRYPTO_PROTOCOL structure. Bump protocol version to 25.
Add CryptoServicePkcs7Encrypt wrapper in the Crypto driver and
Pkcs7Encrypt wrapper in BaseCryptLibOnProtocolPpi. Add Pkcs7Encrypt
PCD bit to PcdCryptoServiceFamilyEnable for independent service
control. Update Readme.md feature table.

Signed-off-by: Doug Flick <[email protected]>


  Commit: 294f56bcb3b41b733f4b5425e23512ab7a3270cf
      
https://github.com/tianocore/edk2/commit/294f56bcb3b41b733f4b5425e23512ab7a3270cf
  Author: Doug Cook <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Library/BaseCryptLibMbedTls/BaseCryptLib.inf
    A CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7Encrypt.c
    M CryptoPkg/Library/BaseCryptLibMbedTls/SmmCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/UnitTestHostBaseCryptLib.inf
    M CryptoPkg/Readme.md

  Log Message:
  -----------
  CryptoPkg: Add Pkcs7Encrypt for BaseCryptLibMbedTls

Add CryptPkcs7Encrypt.c with an MbedTLS-based Pkcs7Encrypt()
implementation. Update BaseCryptLibMbedTls INF files
(BaseCryptLib.inf, SmmCryptLib.inf, UnitTestHostBaseCryptLib.inf)
to include the new source file, and update CryptoPkg/Readme.md
accordingly.

Signed-off-by: Doug Flick <[email protected]>


  Commit: 07a37d45eef9972b7fc3deb761d5c24527a17387
      
https://github.com/tianocore/edk2/commit/07a37d45eef9972b7fc3deb761d5c24527a17387
  Author: Doug Flick <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/BaseCryptLibUnitTests.c
    M 
CryptoPkg/Test/UnitTest/Library/BaseCryptLib/BaseCryptLibUnitTestsMbedTls.c
    A CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTestCert.h
    A CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTests.c
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLib.h
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibHost.inf
    M 
CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibHostMbedTls.inf
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibShell.inf

  Log Message:
  -----------
  CryptoPkg: Add Pkcs7Encrypt smoke tests

These don't actually decrypt anything, so calling them "unit tests"
was a stretch. They're smoke tests: build an envelopedData ContentInfo
for a recipient cert, then walk the DER and check the shape looks
right (id-envelopedData, CMSVersion, the right number of
RecipientInfo entries, the expected content-encryption OID).

Covered:

  * AES-128/192/256-CBC happy paths.
  * Two recipients, just to confirm the SET grows.
  * The parameter-validation contract from BaseCryptLib.h
    (NULL stack/InData/output pointers, bogus CipherNid, bogus Flags).

The DER walker is hand-rolled in the test file so we don't have to
pull OpenSSL or mbedtls headers into a unit test that has to compile
against both. It catches obvious shape regressions but won't notice
if the CEK, IV, or PKCS#7 padding are wrong - a real round-trip needs
a Pkcs7Decrypt API we don't have yet.

Signed-off-by: Doug Flick <[email protected]>


  Commit: 5337420d7c59b446a4ec9f1348bc75e47de8299d
      
https://github.com/tianocore/edk2/commit/5337420d7c59b446a4ec9f1348bc75e47de8299d
  Author: Doug Cook <[email protected]>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M CryptoPkg/Driver/Crypto.c
    M CryptoPkg/Include/Library/BaseCryptLib.h
    M CryptoPkg/Include/Pcd/PcdCryptoServiceFamilyEnable.h
    M CryptoPkg/Library/BaseCryptLib/BaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/PeiCryptLib.inf
    A CryptoPkg/Library/BaseCryptLib/Pk/CryptPkcs7Decrypt.c
    A CryptoPkg/Library/BaseCryptLib/Pk/CryptPkcs7DecryptNull.c
    M CryptoPkg/Library/BaseCryptLib/RuntimeCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/SecCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/SmmCryptLib.inf
    M CryptoPkg/Library/BaseCryptLib/UnitTestHostBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/BaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/PeiCryptLib.inf
    A CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7Decrypt.c
    A CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7DecryptNull.c
    M CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7Encrypt.c
    M CryptoPkg/Library/BaseCryptLibMbedTls/Pk/CryptPkcs7Internal.h
    M CryptoPkg/Library/BaseCryptLibMbedTls/RuntimeCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/SecCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/SmmCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/TestBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibMbedTls/UnitTestHostBaseCryptLib.inf
    M CryptoPkg/Library/BaseCryptLibNull/BaseCryptLibNull.inf
    A CryptoPkg/Library/BaseCryptLibNull/Pk/CryptPkcs7DecryptNull.c
    M CryptoPkg/Library/BaseCryptLibOnProtocolPpi/CryptLib.c
    M CryptoPkg/Private/Protocol/Crypto.h
    M CryptoPkg/Readme.md
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/BaseCryptLibUnitTests.c
    M 
CryptoPkg/Test/UnitTest/Library/BaseCryptLib/BaseCryptLibUnitTestsMbedTls.c
    A CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7DecryptTests.c
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTestCert.h
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTests.c
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLib.h
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibHost.inf
    M 
CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibHostMbedTls.inf
    M CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLibShell.inf

  Log Message:
  -----------
  CryptoPkg: Add Pkcs7Decrypt API

Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API.

I expect that the primary use of Pkcs7Decrypt would be for testing the
Pkcs7Encrypt API, but maybe somebody will need it for real work someday.

Signed-off-by: Doug Cook <[email protected]>
Committed-by: Doug Flick <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/edcf8ffa6931...5337420d7c59

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to