Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 4341569230f770736de7eafe70ec37ec491bd8e7
      
https://github.com/tianocore/edk2/commit/4341569230f770736de7eafe70ec37ec491bd8e7
  Author: Amrathesh <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M DynamicTablesPkg/Library/Common/AmlLib/AmlCoreInterface.h
    M DynamicTablesPkg/Library/Common/AmlLib/Serialize/AmlSerialize.c

  Log Message:
  -----------
  DynamicTablesPkg/AmlLib: Fix serialization buffer size handling

AmlSerializeTree uses a reversed buffer size comparison. As a result, it
returns success without serializing when the buffer is larger than needed
and attempts serialization when the buffer is too small.

Return EFI_BUFFER_TOO_SMALL when Buffer is NULL or the supplied buffer is
too small, and always report the required size. Update
AmlSerializeDefinitionBlock to handle the expected size query status.

Signed-off-by: Amrathesh <[email protected]>


  Commit: 89c4bd09bb1860c8b7e8e95f8e8a15f9817348f4
      
https://github.com/tianocore/edk2/commit/89c4bd09bb1860c8b7e8e95f8e8a15f9817348f4
  Author: Amrathesh <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M DynamicTablesPkg/Library/Common/AmlLib/Tree/AmlTree.c

  Log Message:
  -----------
  DynamicTablesPkg/AmlLib: Fix fixed argument bounds check

AmlSetFixedArgument() accepts an index equal to the fixed argument count.
The count is an exclusive upper bound, so this permits an out-of-bounds
write to the FixedArgs array.

Require the index to be strictly less than the fixed argument count.

Signed-off-by: Amrathesh <[email protected]>


  Commit: aaa871e1ab6e3ba714165671ceb1f48a982b8850
      
https://github.com/tianocore/edk2/commit/aaa871e1ab6e3ba714165671ceb1f48a982b8850
  Author: Amrathesh <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M DynamicTablesPkg/Library/Common/AmlLib/Tree/AmlNode.c

  Log Message:
  -----------
  DynamicTablesPkg/AmlLib: Fix data node cleanup leak

AmlCreateDataNode() calls AmlDeleteDataNode() when buffer allocation
fails. However, AmlDeleteDataNode() rejects a NULL buffer and returns
without freeing the data node, leaking the node allocation.

Allow AmlDeleteDataNode() to handle a NULL buffer and always free the
data node.

Signed-off-by: Amrathesh <[email protected]>


  Commit: 5846c662d04ec86a5f3bd56f323dc1c7b779b74b
      
https://github.com/tianocore/edk2/commit/5846c662d04ec86a5f3bd56f323dc1c7b779b74b
  Author: Amrathesh <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M DynamicTablesPkg/Library/Common/AmlLib/Tree/AmlNode.c

  Log Message:
  -----------
  DynamicTablesPkg/AmlLib: Fix root node cleanup leak

AmlCreateRootNode() calls AmlDeleteRootNode() when SDT header
allocation fails. However, AmlDeleteRootNode() rejects a NULL header
and returns without freeing the root node, leaking the node allocation.

Allow AmlDeleteRootNode() to handle a NULL SDT header and always free
the root node.

Signed-off-by: Amrathesh <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/b59c1a498150...5846c662d04e

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to