回复: [edk2-devel] 回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread gaoliming via groups.io
Doug: What’s impact if no EFI_HASH2_PROTOCOL? Does network boot work or not? Thanks Liming 发件人: devel@edk2.groups.io 代表 Doug Flick via groups.io 发送时间: 2024年5月25日 0:51 收件人: gaoliming ; devel@edk2.groups.io 主题: Re: [edk2-devel] 回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 a

Re: [edk2-devel] [PATCH] UefiCpuPkg/MpLib:Do not assume BSP is #0.

2024-05-24 Thread Ni, Ray
I created PR for merge: UefiCpuPkg/MpLib:Do not assume BSP is #0. by niruiyu · Pull Request #5683 · tianocore/edk2 (github.com) But, I cannot set "push" label. @Gao, Liming? Thanks, Ray ___

Re: [edk2-devel] [PATCH] UefiCpuPkg/MpLib:Do not assume BSP is #0.

2024-05-24 Thread Ni, Ray
Reviewed-by: Ray Ni Thanks, Ray From: Feng, Ning Sent: Saturday, May 25, 2024 15:42 To: devel@edk2.groups.io Cc: Feng, Ning ; Ni, Ray Subject: [PATCH] UefiCpuPkg/MpLib:Do not assume BSP is #0. REF:https://bugzilla.tianocore.org/show_bug.cgi?id=4778 MPInitlib h

[edk2-devel] [PATCH] UefiCpuPkg/MpLib:Do not assume BSP is #0.

2024-05-24 Thread Ning Feng
REF:https://bugzilla.tianocore.org/show_bug.cgi?id=4778 MPInitlib have wrong expectation that BSP index should always be 0 in MpInitLibInitialize(), SwitchBsp(),ApWakeupFunction(). That will cause the data mismatch, if the initial BSP is not 0. Cc: Ray Ni Signed-off-by: Ning Feng --- UefiCpuPkg/

Re: [edk2-devel] 回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread Doug Flick via groups.io
To be clear, it requires EFI_RNG_PROTOCOL and EFI_HASH2_PROTOCOL. Both should be mentioned in the release notes -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#119260): https://edk2.groups.io/g/devel/message/119260 Mute This Topic: https:

回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread gaoliming via groups.io
Hi, all Because this patch fixes two CVE, I decide to include them in this stable tag 202405. https://github.com/tianocore/edk2/pull/5582 has been merged. Thanks Liming > -邮件原件- > 发件人: devel@edk2.groups.io 代表 gaoliming via > groups.io > 发送时间: 2024年5月24日 22:51 > 收件人: devel@edk2.groups.

Re: [edk2-devel] [edk2-rfc] Proposal to switch TianoCore Code Review from email to GitHub Pull Requests on 5-24-2024

2024-05-24 Thread Michael Kubacki
The transition now is simpler and more streamlined than what is described there. I'll update the project to reflect the current state so it can serve as a reference and guide related work in the future. Thanks, Michael On 5/24/2024 8:20 AM, Rebecca Cran wrote: There's a GitHub Project for this

回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread gaoliming via groups.io
Gerd and Ard: Thanks for your comments. I understand this CVE fix requires EFI_RNG_PROTOCOL. I will add this requirement in the release note. Thanks Liming > -邮件原件- > 发件人: devel@edk2.groups.io 代表 Gerd Hoffmann > 发送时间: 2024年5月24日 19:49 > 收件人: Ard Biesheuvel > 抄送: devel@edk2.groups.io;

Re: [edk2-devel] [edk2-rfc] Proposal to switch TianoCore Code Review from email to GitHub Pull Requests on 5-24-2024

2024-05-24 Thread Rebecca Cran
There's a GitHub Project for this at https://github.com/orgs/tianocore/projects/5 which it looks like Michael Kubacki created last year. I suspect it's obsolete though, since it looks like the tasks haven't been updated recently. -- Rebecca Cran On 5/1/24 11:43 AM, Michael D Kinney wrote:

Re: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread Gerd Hoffmann
On Fri, May 24, 2024 at 11:41:04AM GMT, Ard Biesheuvel wrote: > On Fri, 24 May 2024 at 11:12, gaoliming via groups.io > wrote: > > > > Ard: > > Here is Doug PR https://github.com/tianocore/edk2/pull/5582 that includes > > 20 commits. You can check them. > > > > This looks fine to me in princip

Re: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread Ard Biesheuvel
On Fri, 24 May 2024 at 11:12, gaoliming via groups.io wrote: > > Ard: > Here is Doug PR https://github.com/tianocore/edk2/pull/5582 that includes > 20 commits. You can check them. > This looks fine to me in principle. Reviewed-by: Ard Biesheuvel However, IIUC, the impact of this series is t

回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread gaoliming via groups.io
Ard: Here is Doug PR https://github.com/tianocore/edk2/pull/5582 that includes 20 commits. You can check them. Thanks Liming > -邮件原件- > 发件人: Ard Biesheuvel > 发送时间: 2024年5月24日 15:07 > 收件人: devel@edk2.groups.io; gaolim...@byosoft.com.cn > 抄送: dougfl...@microsoft.com; kra...@redhat.com;

Re: [edk2-devel] [PATCH v1 1/2] OvmfPkg: Add no hardcode version of FtdNorFlashQemuLib

2024-05-24 Thread Marcin Juszkiewicz
W dniu 17.05.2024 o 09:17, Chao Li via groups.io pisze: This library is copied from ArmVirtPkg, in the Arm version, the value of PcdFlashNvStorageVariableBase, PcdFlashNvStorageFtwWorkingBase and PcdFlashNvStorageFtwSpareBase are hardcoded in INC file. This version will calculate them from FDT r

Re: [edk2-devel] [PATCH v1 0/2] Add a new FdtNorFalshQemuLib and enable it in

2024-05-24 Thread Chao Li
Hi Ard and other maintainers, Could you help to review this patch set? Thanks, Chao On 2024/5/17 15:33, Chao Li wrote: Hi Ard, No, it's just that my email was bounced just now, the groupio didn't receive my email when I send the first time, and I sent them again after it unbounce. On 202

Re: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread Ard Biesheuvel
On Fri, 24 May 2024 at 09:01, gaoliming via groups.io wrote: > > Ard and Gerd: > Doug updated this patch set based on your suggestion. Could you give > reviewed-by or acked-by for the changes in OvmfPkg and ArmVirtPkg if you > have no other comments? > I see ~60 patches from Doug, seemingly 3 c

回复: [edk2-devel] [PATCH v3 00/20] NetworkPkg: CVE-2023-45236 and CVE-2023-45237

2024-05-24 Thread gaoliming via groups.io
Ard and Gerd: Doug updated this patch set based on your suggestion. Could you give reviewed-by or acked-by for the changes in OvmfPkg and ArmVirtPkg if you have no other comments? Thanks Liming > -邮件原件- > 发件人: devel@edk2.groups.io 代表 Doug Flick via > groups.io > 发送时间: 2024年5月24日 13:45 >