summaryrefslogtreecommitdiff
AgeCommit message (Expand)Author
2022-05-31shim-15.6~rc215.6-rc2Peter Jones
2022-05-24Also avoid CVE-2022-28737 in verify_image()Peter Jones
2022-05-24Update SBAT generation requirements for 05/24/22Jan Setje-Eilers
2022-05-24Update advertised sbat generation number for shimJan Setje-Eilers
2022-05-24pe: Perform image verification earlier when loading grubChris Coulson
2022-05-24pe: Fix a buffer overflow when SizeOfRawData > VirtualSizeChris Coulson
2022-05-24SBAT Policy latest should be a one-shotJan Setje-Eilers
2022-05-24shim-15.6~rc1Peter Jones
2022-05-23sbat: Make nth_sbat_field() honor the size limitPeter Jones
2022-05-23mok import: handle OOM casePeter Jones
2022-05-23load_cert_file(): don't defererence NULLPeter Jones
2022-05-23Give the Coverity scanner some more GCC blinders...Peter Jones
2022-05-23Fix preserve_sbat_uefi_variable() logicJan Setje-Eilers
2022-05-18mok.c: fix a trivial dead assignmentPeter Jones
2022-05-18load_certs: trust dir->Read() slightly less.Peter Jones
2022-05-18sbat policy: make our policy change actions symbolicPeter Jones
2022-05-18Always initialize data/datasize before calling read_image()Peter Jones
2022-05-18peimage.h: make our signature macros force the typePeter Jones
2022-05-18sbat.h: minor reformatting for legibilityPeter Jones
2022-05-18make: unbreak scan-build again for gnu-efiPeter Jones
2022-05-17SBAT revocation managementJan Setje-Eilers
2022-05-17post-process-pe: set EFI_IMAGE_DLLCHARACTERISTICS_NX_COMPATPeter Jones
2022-05-17Add MokPolicy variable and MOK_POLICY_REQUIRE_NXPeter Jones
2022-05-17PE Loader: support and require NXPeter Jones
2022-05-17Add some missing PE image flag definitionsPeter Jones
2022-05-17post-process-pe: there is no 's' argument.Peter Jones
2022-05-17Load additional certs from a signed binaryEric Snowberg
2022-05-17Abstract out image readingEric Snowberg
2022-05-17Add verify_imageEric Snowberg
2022-05-17SBAT matching: Break out of the inner sbat loop if we find the entry.Peter Jones
2022-05-17shim: use SHIM_DEVEL_VERBOSE when built in devel modePeter Jones
2022-05-17make: don't treat cert.S speciallyPeter Jones
2022-05-17Use ASCII as fallback if Unicode Box Drawing characters failTony Persson
2022-05-13Modernize aarch64Peter Jones
2022-05-05Add code of conductRobbie Harwood
2022-05-04Allow MokListTrusted to be enabled by defaultEric Snowberg
2022-05-04test-str.c: fix gcc warnings with FORTIFY_SOURCE enabledAlexey Kodanev
2022-05-04mock-variables.c: fix gcc warningAlexey Kodanev
2022-05-04tests: also look for system headers in multi-arch directoriesSteve McIntyre
2022-05-04post-process-pe: Fix format string warnings on 32-bit platformsSteve McIntyre
2022-05-04CI: Add f36 and centos9 CI build tests.Peter Jones
2022-05-04Remove aarch64 build tests before f35Peter Jones
2022-05-04CI: remove EOL Fedoras from github actionsRobbie Harwood
2022-05-04CI: don't cancel testing when one failsRobbie Harwood
2022-04-19post-process-pe: Fix a missing return code checkPeter Jones
2022-04-05shim: implement SBAT verification for the shim_lock protocolChris Coulson
2022-03-30MokManager: removed Locate graphic output protocol fail error messageLee, Chun-Yi
2022-02-15Update to version 15.515.5Robbie Harwood
2022-02-03pe: missing perror argumentHeinrich Schuchardt
2022-02-03Remove post-proccess-pe on 'make clean'Peter Jones