From 9858564ebcc61fdea15c9bf6270712d7c302c206 Mon Sep 17 00:00:00 2001 From: Philipp Schuster Date: Mon, 31 Aug 2026 14:53:18 +0200 Subject: [PATCH 1/5] 2026-08: add uefi-rs section Highlight the specification-compliance and soundness work that went into the uefi-raw v0.16.0 and uefi v0.40.0 releases. --- content/this-month/2026-08/index.md | 33 ++++++++++++++++++++++++++++- 1 file changed, 32 insertions(+), 1 deletion(-) diff --git a/content/this-month/2026-08/index.md b/content/this-month/2026-08/index.md index 7b06d587..9a592a7e 100644 --- a/content/this-month/2026-08/index.md +++ b/content/this-month/2026-08/index.md @@ -71,7 +71,38 @@ In this section, we give an overview of notable changes to the projects hosted u <> --> -No content was submitted for this section this month. +### [`uefi-rs`](https://github.com/rust-osdev/uefi-rs) +Maintained by [@nicholasbishop](https://github.com/nicholasbishop) and [@phip1611](https://github.com/phip1611) + +`uefi` makes it easy to develop Rust software that leverages safe, convenient, +and performant abstractions for UEFI functionality. + +This month was all about **specification compliance and soundness**. We audited +large parts of `uefi-raw` and `uefi` against the UEFI and PI specifications. +Users now get correct data where the crates previously returned garbage or read +out of bounds, for example: + +- `boot::set_watchdog_timer` passed the watchdog data size in characters instead + of bytes, so firmware only saw half of the data. +- `ProcessorInformation` was 24 bytes too small, so firmware could write past + its end. +- `UsbIo::supported_languages` reported twice the actual number of language IDs, + where the second half was an out-of-bounds read. + +`MemoryDescriptor` is now portable across x86 targets, so kernels and +bootloaders built for a generic i686 target can finally parse a UEFI memory map. +To keep such bugs away, our ABI tests are now `const` assertions evaluated for +the actual target, instead of unit tests that only ever check the host. + +The new `char16!()` macro builds a `Char16` from a character literal in `const` +context - no `unsafe` needed, and a compile error if the character is not valid +in UCS-2. + +All of this is available in `uefi-raw v0.16.0` and `uefi v0.40.0`. We also +refreshed our `CONTRIBUTING.md`, which now documents our expectations regarding +code style, commit style, and AI/LLM-assisted contributions. + +We merged the following PRs this month: ## Other Projects From 07a7d92fff0dde873006982c9579a764e6875ff6 Mon Sep 17 00:00:00 2001 From: Philipp Schuster Date: Mon, 31 Aug 2026 15:08:29 +0200 Subject: [PATCH 2/5] 2026-08: add multiboot2 section Highlight the UB fixes around unknown specification values and the new tag iteration APIs. --- content/this-month/2026-08/index.md | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/content/this-month/2026-08/index.md b/content/this-month/2026-08/index.md index 9a592a7e..3d3496d4 100644 --- a/content/this-month/2026-08/index.md +++ b/content/this-month/2026-08/index.md @@ -104,6 +104,31 @@ code style, commit style, and AI/LLM-assisted contributions. We merged the following PRs this month: +### [`multiboot2`](https://github.com/rust-osdev/multiboot2) +Maintained by [@phip1611](https://github.com/phip1611) + +_Convenient and safe parsing of Multiboot2 Boot Information (MBI) structures and +the contained information tags. Usable in no_std environments, such as a kernel. +An optional builder feature also allows the construction of the corresponding +structures._ + +We removed a whole class of undefined behavior. Parsing a structure with a value +unknown to the specification - an unknown framebuffer type, VBE memory model, or +header tag type - used to construct an invalid Rust enum. The new `raw_type!` +macro generates an ABI-safe newtype plus an open-set enum with a `Custom` +variant, so unknown values now pass through safely. `multiboot2-common` got +further soundness fixes around size and alignment validation. + +Users also benefit from `BootInformation::get_tags`, which iterates over _all_ +occurrences of a tag. Network and SMBIOS tags may legitimately appear multiple +times, but our API only exposed the first one. The builder gained `add_network` +- and it turned out that `Builder::network` never included the tag at all. + +Released as `multiboot2 v0.26.1`, `multiboot2-header v0.10.0`, and +`multiboot2-common v0.5.0`. The `raw_type!` work follows in the next release. + +We merged the following PRs this month: + ## Other Projects In this section, we describe updates to Rust OS projects that are not directly related to the `rust-osdev` organization. Feel free to [create a pull request](https://github.com/rust-osdev/homepage/pulls) with the updates of your OS project for the next post. From bcd95fc8f36de4fb85433e308fc9089c062739ae Mon Sep 17 00:00:00 2001 From: Philipp Schuster Date: Mon, 31 Aug 2026 15:08:39 +0200 Subject: [PATCH 3/5] 2026-08: add uart_16550 section Highlight the v0.7.0 and v0.8.0 releases, which mainly improve the behavior on real hardware. --- content/this-month/2026-08/index.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/content/this-month/2026-08/index.md b/content/this-month/2026-08/index.md index 3d3496d4..c20e58be 100644 --- a/content/this-month/2026-08/index.md +++ b/content/this-month/2026-08/index.md @@ -129,6 +129,24 @@ Released as `multiboot2 v0.26.1`, `multiboot2-header v0.10.0`, and We merged the following PRs this month: +### [`uart_16550`](https://github.com/rust-osdev/uart_16550) +Maintained by [@phip1611](https://github.com/phip1611) + +_Simple yet highly configurable low-level driver for 16550 UART devices, +typically known and used as serial ports or COM ports._ + +Two releases, `v0.7.0` and `v0.8.0`, make the driver behave better on real +hardware. Sending no longer waits for the `MSR::CTS` line by default, as modern +hardware tends to leave that pin disconnected - which previously meant no output +at all. Those who need hardware flow control can re-enable the check via +`Config::check_cts_before_sending`. + +Further, `Config::default()` now disables _all_ interrupts, and `init()` enables +the configured ones only at the very end. This way, a driver does not receive +interrupts before it is ready to handle them. + +We merged the following PRs this month: + ## Other Projects In this section, we describe updates to Rust OS projects that are not directly related to the `rust-osdev` organization. Feel free to [create a pull request](https://github.com/rust-osdev/homepage/pulls) with the updates of your OS project for the next post. From 2a27c0db2589b0a198f3a5415c47a670990d78fd Mon Sep 17 00:00:00 2001 From: Philipp Schuster Date: Mon, 31 Aug 2026 15:08:57 +0200 Subject: [PATCH 4/5] 2026-08: add tar-no-std section Highlight the stricter archive validation in v0.5.0 and the new fuzzing infrastructure. --- content/this-month/2026-08/index.md | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/content/this-month/2026-08/index.md b/content/this-month/2026-08/index.md index c20e58be..55ff28bc 100644 --- a/content/this-month/2026-08/index.md +++ b/content/this-month/2026-08/index.md @@ -160,7 +160,28 @@ In this section, we describe updates to Rust OS projects that are not directly r ...<>... --> -No project updates were submitted this month. +### [`phip1611/tar-no-std`](https://github.com/phip1611/tar-no-std) +(Section written by [@phip1611](https://github.com/phip1611)) + +[`tar-no-std`](https://github.com/phip1611/tar-no-std) supports a relevant +subset of Tar archives to extract multiple files from a single Tar archive in +`no_std` environments with zero allocations. A typical use case is a kernel +reading an initial ramdisk. + +The new `v0.5.0` release stops trusting the input. `TarArchive[Ref]::new` now +rejects invalid headers, checksums, payload sizes, and missing archive +termination, so a malformed archive fails right away instead of producing +garbage entries. Numeric fields with invalid UTF-8 bytes no longer silently +parse as zero, and `CorruptDataError` became an enum that names the violated +invariant. Additionally, there is now limited support for POSIX PAX archives +that use extended records only for optional metadata, such as high-precision +timestamps. + +To keep it that way, the repository gained `cargo-fuzz` infrastructure, +including structure-aware fuzzing with checksum-valid archives. + +Thanks to [@internetisalie](https://github.com/internetisalie) and +[@fogti](https://github.com/fogti) for their contributions! From 0e96a4dec39c848dce3f8b00c53f6ae10fb5a6f7 Mon Sep 17 00:00:00 2001 From: Philipp Schuster Date: Mon, 31 Aug 2026 15:25:14 +0200 Subject: [PATCH 5/5] 2026-08: uefi-rs: announce Anthropic sponsorship --- content/this-month/2026-08/index.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/content/this-month/2026-08/index.md b/content/this-month/2026-08/index.md index 55ff28bc..d8a6bbaa 100644 --- a/content/this-month/2026-08/index.md +++ b/content/this-month/2026-08/index.md @@ -102,6 +102,13 @@ All of this is available in `uefi-raw v0.16.0` and `uefi v0.40.0`. We also refreshed our `CONTRIBUTING.md`, which now documents our expectations regarding code style, commit style, and AI/LLM-assisted contributions. +#### Sponsorship by Anthropic + +We are glad to announce that [Anthropic](https://www.anthropic.com/) sponsors @phip1611 for six months +as part of their open source program. The sponsorship covers `uefi-rs` and +related crates in the `rust-osdev` space, with a focus on security issues, +undefined behavior, and specification compliance. Thank you! + We merged the following PRs this month: ### [`multiboot2`](https://github.com/rust-osdev/multiboot2)