Re: [edk2-devel] [PATCH] OvmfPkg: Update VMM Hob list check to support new resource attributes

2024-05-27 Thread Yao, Jiewen
Thanks. Not urgent. Let’s wait. > -Original Message- > From: gaoliming > Sent: Monday, May 27, 2024 3:12 PM > To: devel@edk2.groups.io; Yao, Jiewen ; Lin, Du > > Cc: 'Ard Biesheuvel' ; 'Gerd Hoffmann' > > Subject: 回复: [edk2-devel] [PATCH] OvmfPkg: U

Re: [edk2-devel] [PATCH] OvmfPkg: Update VMM Hob list check to support new resource attributes

2024-05-27 Thread Yao, Jiewen
I have approved it. What is the process to merge? There is no COMMIT button or PUSH label. > -Original Message- > From: Lin, Du > Sent: Monday, May 27, 2024 2:23 PM > To: devel@edk2.groups.io > Cc: Ard Biesheuvel ; Gerd Hoffmann > ; Yao, Jiewen ; Lin, Du > >

Re: [edk2-devel] [PATCH v3 07/20] SecurityPkg: RngDxe: Remove incorrect limitation on GetRng

2024-05-23 Thread Yao, Jiewen
Acked-by: Jiewe Yao BTW: This patch is already got RB from below people. I suggest you can put them in commit directly. Reviewed-by: Pierre Gondois Reviewed-by: Ard Biesheuvel Thank you Yao, Jiewen > -Original Message- > From: Flickdm > Sent: Friday, May 24, 202

Re: [edk2-devel] libspdm Breaking Builds

2024-05-23 Thread Yao, Jiewen
) 1) Keep current libspdm official 3.3.0 release, and update to next release at the beginning of July. 2) Update libspdm immediately with the new cmocka submodule, which is NOT an official release. Thank you Yao, Jiewen > -Original Message- > From: devel@edk2.groups.io On Behalf

Re: [edk2-devel] libspdm Breaking Builds

2024-05-22 Thread Yao, Jiewen
. But that is NOT a reason to disable it. Anyway, I think tianocore project has freedom to choose whatever options, independent with libspdm project. And I hope we have a consistent way to handle all projects. Thank you Yao, Jiewen > -Original Message- > From: Kinney, Michael D

Re: [edk2-devel] [PATCH] OvmfPkg: Update VMM Hob list check to support new resource attributes

2024-05-16 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: devel@edk2.groups.io On Behalf Of Lin, Du > Sent: Thursday, May 9, 2024 1:27 PM > To: devel@edk2.groups.io > Cc: Lin, Du ; Ard Biesheuvel ; > Gerd Hoffmann ; Yao, Jiewen > Subject: [edk2-devel] [PATCH] OvmfPkg

Re: [edk2-devel] [PATCH v2 07/13] SecurityPkg: RngDxe: Remove incorrect limitation on GetRng

2024-05-10 Thread Yao, Jiewen
Thanks to confirm that. I am OK on what you have said. Since the ARM part is added by Pierre Gondois pierre.gond...@arm.com<mailto:pierre.gond...@arm.com>, I will let him comment if there is any concern on the change for ARM. Thank you Yao, Jiewen From: Doug Flick via groups.io

Re: [edk2-devel] [PATCH v2 07/13] SecurityPkg: RngDxe: Remove incorrect limitation on GetRng

2024-05-10 Thread Yao, Jiewen
[Index] ); It seems to me that the EntropyBits is also less than 256, when the input requirement is less than 256 bit. Would you please double check that, to see if the requirement is still satisfied? Please correct me if my understanding is wrong. Thank you Yao, Jiewen >

Re: [edk2-devel] [PATCH v3 00/11] Add more crypt APIs based on Mbedtls

2024-05-09 Thread Yao, Jiewen
Acked-by: Jiewen Yao > -Original Message- > From: Li, Yi1 > Sent: Thursday, May 9, 2024 4:33 PM > To: Hou, Wenxing ; gaoliming > ; devel@edk2.groups.io > Cc: Yao, Jiewen > Subject: RE: [PATCH v3 00/11] Add more crypt APIs based on Mbedtls > > This patch se

Re: [edk2-devel] [PATCH v4 00/14] Add SmmRelocationLib

2024-05-06 Thread Yao, Jiewen
Acked-by: Jiewen Yao From: Wu, Jiaxin Sent: Tuesday, May 7, 2024 11:39 AM To: Ni, Ray ; devel@edk2.groups.io; Ard Biesheuvel ; Yao, Jiewen Cc: Zeng, Star ; Gerd Hoffmann ; Kumar, Rahul R ; Dong, Guo ; Rhodes, Sean ; Lu, James ; Guo, Gua ; Abdul Lateef Attar ; Abner Chang ; Tom Lendacky

Re: [edk2-devel] [PATCH v4 0/3] TCG_Sp800_155_PlatformId_Event3 support

2024-05-06 Thread Yao, Jiewen
Merged https://github.com/tianocore/edk2/pull/5628 > -Original Message- > From: Dionna Glaze > Sent: Tuesday, May 7, 2024 2:08 AM > To: devel@edk2.groups.io > Cc: Dionna Glaze ; Kinney, Michael D > ; Liming Gao ; Liu, > Zhiguang ; Yao, Jiewen ; > Kumar, Rahul R ;

Re: [edk2-devel] [PATCH v3 0/3] TCG_Sp800_155_PlatformId_Event3 support

2024-05-05 Thread Yao, Jiewen
"Reviewed-by". Thank you Yao, Jiewen > -Original Message- > From: Dionna Glaze > Sent: Thursday, May 2, 2024 8:50 AM > To: devel@edk2.groups.io > Cc: Dionna Glaze ; Kinney, Michael D > ; Liming Gao ; Liu, > Zhiguang ; Yao, Jiewen ; > Kumar, Rahul R ; Ard Biesheuv

Re: [edk2-devel] [PATCH v2 1/3] MdePkg: Add TcgSp800155Event3 type info

2024-05-01 Thread Yao, Jiewen
Thanks Dionna. Almost good, except you create a typo below: >EFI_GUIDReferenceManifestGuid; > - // > + // >// Below structure is newly added in TCG_Sp800_155_PlatformId_Event2. With typo fix, reviewed-by: Jiewen Yao Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [PATCH 1/3] MdePkg: Add TcgSp800155Event3 type info

2024-04-30 Thread Yao, Jiewen
I think it is confusing to add "TCG_Sp800_155_PlatformId_Event3" field for "TCG_Sp800_155_PlatformId_Event2" structure. Maybe just create a new "TCG_Sp800_155_PlatformId_Event3" structure? > -Original Message- > From: devel@edk2.groups.io On Behalf Of Dionna Glaze > via groups.io >

Re: [edk2-devel] [PATCH 0/3] TCG_Sp800_155_PlatformId_Event3 support

2024-04-30 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Dionna Glaze > Sent: Wednesday, May 1, 2024 8:53 AM > To: devel@edk2.groups.io > Cc: Dionna Glaze ; Kinney, Michael D > ; Liming Gao ; Liu, > Zhiguang ; Yao, Jiewen ; > Kumar, Rahul R ; Ard Biesheuvel >

Re: [edk2-devel] [PATCH v4 00/10] Add DeviceSecurity feature based on PFP 1.06 spec

2024-04-28 Thread Yao, Jiewen
Hi All It has been 4 work weeks and this V4 patch resolved previous comments and feedbacks. If there is no further objection, I plan to merge it tomorrow. Thank you Yao, Jiewen > -Original Message- > From: Hou, Wenxing > Sent: Friday, April 26, 2024 9:52 AM > To: Yao, Ji

Re: [edk2-devel] [PATCH v4 1/1] OvmfPkg/VirtHstiDxe: do not load driver in confidential guests

2024-04-24 Thread Yao, Jiewen
Thank you very much for the help. https://github.com/tianocore/edk2/pull/5595 merged. > -Original Message- > From: Michael Kubacki > Sent: Thursday, April 25, 2024 7:22 AM > To: devel@edk2.groups.io; Yao, Jiewen ; Kinney, Michael > D ; Sean Brogan > Cc: Gerd Hoffman

Re: [edk2-devel] [PATCH v4 1/1] OvmfPkg/VirtHstiDxe: do not load driver in confidential guests

2024-04-24 Thread Yao, Jiewen
Ah, thank you Mike. Should I close/re-open my PR? Or should I keep waiting? Thank you Yao, Jiewen > -Original Message- > From: Kinney, Michael D > Sent: Thursday, April 25, 2024 7:01 AM > To: Yao, Jiewen ; devel@edk2.groups.io; Sean Brogan > ; Michael Kubacki > &

Re: [edk2-devel] [PATCH v4 1/1] OvmfPkg/VirtHstiDxe: do not load driver in confidential guests

2024-04-24 Thread Yao, Jiewen
Hi Mike/Sean Can someone look at the EDKII CI? My PR has been blocked for 9 hours - https://github.com/tianocore/edk2/pull/5595. Thank you Yao, Jiewen > -Original Message- > From: Ard Biesheuvel > Sent: Thursday, April 25, 2024 1:05 AM > To: Yao, Jiewen > Cc: Gerd H

Re: [edk2-devel] [PATCH v4 1/1] OvmfPkg/VirtHstiDxe: do not load driver in confidential guests

2024-04-24 Thread Yao, Jiewen
Thanks Ard. I have submitted https://github.com/tianocore/edk2/pull/5595 3 hours ago. But it seems the CI stops working... > -Original Message- > From: Ard Biesheuvel > Sent: Thursday, April 25, 2024 12:27 AM > To: Yao, Jiewen > Cc: Gerd Hoffmann ; devel@edk2.gr

Re: [edk2-devel] [PATCH v4 1/1] OvmfPkg/VirtHstiDxe: do not load driver in confidential guests

2024-04-24 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Gerd Hoffmann > Sent: Wednesday, April 24, 2024 2:00 PM > To: devel@edk2.groups.io > Cc: Oliver Steffen ; Gerd Hoffmann > ; Ard Biesheuvel ; Yao, Jiewen > ; Srikanth Aithal > Subject: [PATCH v4 1/1] OvmfPkg/

Re: [edk2-devel] [PATCH v2 0/5] OvmfPkg: Add VirtHstiDxe driver

2024-04-20 Thread Yao, Jiewen
Get32 (PcdOvmfFdBaseAddress))", reviewed-by: Jiewen Yao Thank you Yao, Jiewen > -Original Message- > From: Gerd Hoffmann > Sent: Friday, April 19, 2024 8:31 PM > To: devel@edk2.groups.io > Cc: Oliver Steffen ; Konstantin Kostiuk > ; Ard Biesheuvel ; Yao, > Jiewen ; Gerd H

Re: [edk2-devel] [PATCH v4 00/10] Add DeviceSecurity feature based on PFP 1.06 spec

2024-04-20 Thread Yao, Jiewen
All series: Reviewed-by: Jiewen Yao Dear Steward member Do you have any concern on adding libspdm (https://github.com/DMTF/libspdm) as one more submodule? Thank you Yao, Jiewen > -Original Message- > From: Hou, Wenxing > Sent: Thursday, April 18, 2024 6:16 PM > To

Re: [edk2-devel] [PATCH 0/7] General Updates based on UEFI 2.10 and PI 1.8 Specification

2024-04-20 Thread Yao, Jiewen
7/7, 4/7, 3/7 - reviewed-by: Jiewen Yao > -Original Message- > From: Sachin Ganesh > Sent: Saturday, April 20, 2024 5:46 AM > To: devel@edk2.groups.io > Cc: gaolim...@byosoft.com.cn; Liu, Zhiguang ; Kinney, > Michael D ; ardb+tianoc...@kernel.org; > kra...@re

Re: [edk2-devel] [PATCH 0/4] OvmfPkg: Add VirtHstiDxe driver

2024-04-18 Thread Yao, Jiewen
1) Yes, I highly recommend remove Q35 keyword. 2) Got it. I think we had better add such info in the code as comment as well. Thank you Yao, Jiewen > -Original Message- > From: kra...@redhat.com > Sent: Thursday, April 18, 2024 7:45 PM > To: Yao, Jiewen > Cc: devel@edk2

Re: [edk2-devel] [PATCH 6/6] OvmfPkg: Use newly defined Unaccepted Memory Type

2024-04-18 Thread Yao, Jiewen
Ah. That is good. I did not realize they are in one set. For this one, reviewed-by: Jiewen Yao > -Original Message- > From: Sachin Ganesh > Sent: Thursday, April 18, 2024 9:32 PM > To: Yao, Jiewen ; devel@edk2.groups.io > Cc: gaolim...@byosoft.com.cn; ardb+tianoc...@

Re: [edk2-devel] [PATCH] OvmfPkg: Harden #VC instruction emulation somewhat (CVE-2024-25742)

2024-04-18 Thread Yao, Jiewen
Thanks Adam and Ard. Since this #VC specific hardening, I would rely on AMD people's expertise to fix it. I have no objection for the patch. Thank you Yao, Jiewen > -Original Message- > From: Adam Dunlap > Sent: Thursday, April 18, 2024 1:45 AM > To: Ard Biesheuvel >

Re: [edk2-devel] [PATCH 6/6] OvmfPkg: Use newly defined Unaccepted Memory Type

2024-04-17 Thread Yao, Jiewen
Hi Sachin I like this clean up. Thanks for doing this. I saw this patch is 6/6, but I did not see any other such as 1/6 ~ 5/6 in my mailbox. Not sure what is happening on my side. Just double confirm, have you sent those patches? Thank you Yao, Jiewen > -Original Message- >

Re: [edk2-devel] [PATCH 0/4] OvmfPkg: Add VirtHstiDxe driver

2024-04-17 Thread Yao, Jiewen
_FLASH mean NO write to flash even in SMM mode? Or does it just mean NO write in normal operation mode, but still writable in SMM mode? Thank you Yao, Jiewen > -Original Message- > From: devel@edk2.groups.io On Behalf Of Gerd > Hoffmann > Sent: Wednesday, April 17, 2024 4:18 PM

Re: [edk2-devel] [PATCH V1 0/5] Move Tdx specific lib from SecurityPkg to OvmfPkg

2024-04-16 Thread Yao, Jiewen
I have merged this one https://github.com/tianocore/edk2/pull/5566 Hi Gerd If you prefer that we move all TDX / SEV specific component to IntelTdx and AmdSev, I am OK with that. Personally, I like your idea. Please submit Bugzilla and work on it, if you would like to. Thank you Yao, Jiewen

Re: [edk2-devel] [PATCH V1 0/5] Move Tdx specific lib from SecurityPkg to OvmfPkg

2024-04-16 Thread Yao, Jiewen
https://github.com/tianocore/edk2/tree/master/OvmfPkg/Tcg/TpmMmioSevDecryptPei https://github.com/tianocore/edk2/tree/master/OvmfPkg/Library/BaseMemEncryptSevLib I think we can follow the existing code structure in this patch set. Thank you Yao, Jiewen > -Original Message- > From

Re: [edk2-devel] [PATCH 0/9] Add DeviceSecurity feature based on PFP 1.06 spec

2024-04-16 Thread Yao, Jiewen
Hi Wenxing I just realized that this libspdm submodule does NOT use the latest tag. Since DMTF release 3.3.0 for libspdm https://github.com/DMTF/libspdm/releases/tag/3.3.0, I recommend we update to the latest one. Thank you Yao, Jiewen > -Original Message- > From: devel@edk2.gro

Re: [edk2-devel] [PATCH 0/9] Add DeviceSecurity feature based on PFP 1.06 spec

2024-04-16 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Hou, Wenxing > Sent: Monday, April 15, 2024 10:08 AM > To: Kinney, Michael D ; devel@edk2.groups.io > Cc: Sean Brogan ; Joey Vagedes > ; Liming Gao ; Andrew > Fish ; Liu, Zhiguang ; Kumar, Rahul R > ; Ya

Re: [edk2-devel] [PATCH V1 0/5] Move Tdx specific lib from SecurityPkg to OvmfPkg

2024-04-16 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Xu, Min M > Sent: Monday, April 15, 2024 3:59 PM > To: devel@edk2.groups.io > Cc: Ard Biesheuvel ; Yao, Jiewen > ; Gerd Hoffmann > Subject: RE: [PATCH V1 0/5] Move Tdx specific lib from SecurityPkg to

Re: [edk2-devel] [PATCH v5 0/2] SecurityPkg/OpalPasswordDxe: Update according to UEFI spec

2024-04-16 Thread Yao, Jiewen
Merged https://github.com/tianocore/edk2/pull/5563 > -Original Message- > From: devel@edk2.groups.io On Behalf Of Cindy Kuo > Sent: Tuesday, April 16, 2024 1:03 PM > To: devel@edk2.groups.io > Cc: Kuo, CindyX > Subject: [edk2-devel] [PATCH v5 0/2] SecurityPkg/OpalPasswordDxe: Update >

Re: [edk2-devel] [PATCH v2 1/1] SecurityPkg/Tcg2Config: Hide BIOS unsupported hash algorithm from UI

2024-04-15 Thread Yao, Jiewen
Merged https://github.com/tianocore/edk2/pull/5556 > -Original Message- > From: Xu, Wei6 > Sent: Friday, April 12, 2024 3:15 PM > To: devel@edk2.groups.io > Cc: Xu, Wei6 ; Kumar, Rahul R ; > Yao, Jiewen > Subject: [PATCH v2 1/1] SecurityPkg/Tcg2Config: Hide

Re: [edk2-devel] [PATCH v4 0/1] SecurityPkg/OpalPasswordDxe: Update UI according to UEFI spec

2024-04-15 Thread Yao, Jiewen
I am not sure why patch 0/1 contains the code. It should be the cover letter. Also, if Dandan has already reviewed that, you may add R-B tag. > -Original Message- > From: Kuo, CindyX > Sent: Friday, April 12, 2024 4:31 PM > To: devel@edk2.groups.io > Cc: Kuo, Cindy

Re: [edk2-devel] [PATCH v3] SecurityPkg/OpalPasswordDxe: Update UI according to UEFI spec

2024-04-11 Thread Yao, Jiewen
, or split them into different patch. In each patch, please explain as clear as possible, on why it is needed. That will help reviewer or maintainer to have better understanding. Last but not least, please describe what test you have done for the patch. Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [PATCH v3] SecurityPkg/OpalPasswordDxe: Update UI according to UEFI spec

2024-04-11 Thread Yao, Jiewen
eForm() to force reparsing the IFR binary. Thank you Yao, Jiewen > -Original Message- > From: Bi, Dandan > Sent: Thursday, April 11, 2024 7:15 PM > To: Kuo, CindyX ; devel@edk2.groups.io > Cc: Yao, Jiewen ; Kumar, Rahul R > ; Tan, Ming ; Chen, Arthur G > ; Chen, Xiao X

Re: [edk2-devel] [RFC PATCH] OvmfPkg/SecurityPkg: Add build option for coexistance of vTPM and RTMR.

2024-04-11 Thread Yao, Jiewen
Ard Biesheuvel > Cc: devel@edk2.groups.io; Yao, Jiewen ; Dionna Amalie > Glaze ; Mikko Ylinen ; > James Bottomley ; Tom Lendacky > ; Michael Roth ; qinkun > Bao ; linux-c...@lists.linux.dev; Aktas, Erdem > ; Peter Gonda ; Johnson, > Simon P ; Xiang, Qinglan > > Sub

Re: [edk2-devel] [RFC PATCH] OvmfPkg/SecurityPkg: Add build option for coexistance of vTPM and RTMR.

2024-04-10 Thread Yao, Jiewen
ou think AMD is OK with this coexistence proposal? Are you willing to give "reviewed-by"? Thank you Yao, Jiewen > -Original Message- > From: Dionna Amalie Glaze > Sent: Monday, March 25, 2024 11:29 PM > To: Mikko Ylinen > Cc: Gerd Hoffmann ; Yao, Jiewen ; > qin

Re: [edk2-devel] [PATCH v1 00/13] Add SmmRelocationLib

2024-04-10 Thread Yao, Jiewen
; Hoffmann ; Kumar, Rahul R ; > Dong, Guo ; Rhodes, Sean ; Lu, > James ; Guo, Gua ; Ard Biesheuvel > ; Yao, Jiewen > Subject: [PATCH v1 00/13] Add SmmRelocationLib > > Intel plans to separate the smbase relocation logic from > PiSmmCpuDxeSmm driver, and the related behavi

Re: [edk2-devel] [PATCH v4] SecurityPkg/SecureBootConfigDxe: Update UI according to UEFI spec

2024-04-06 Thread Yao, Jiewen
Thanks.https://github.com/tianocore/edk2/pull/5533 > -Original Message- > From: Bi, Dandan > Sent: Sunday, April 7, 2024 10:07 AM > To: Tan, Ming ; devel@edk2.groups.io > Cc: Xu, Min M ; Yao, Jiewen ; > POLUDOV, FELIX > Subject: RE: [PATCH v4] SecurityPkg/SecureBoo

Re: [edk2-devel] [RFC PATCH] OvmfPkg/SecurityPkg: Add build option for coexistance of vTPM and RTMR.

2024-03-21 Thread Yao, Jiewen
to endorse the runtime co-existence of vTPM and RTMR. Also, I would like to hear the opinions from other companies. BTW: A small comment: In EDKII, we don’t use MACRO. Please change to PCD (default false), after you get endorsement from other compony. Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [PATCH 1/2] OvmfPkg: Add VirtHstiDxe driver

2024-03-14 Thread Yao, Jiewen
it is a right way to provide an *empty* one just to pass the SVVP. That totally looses the value to having HSTI in the SVVP program. I recommend we provide a real HSTI based on the OVMF threat model (without and with configuration computing) and current real implementation. Thank you Yao, Jiewen From

Re: [edk2-devel] [PATCH 1/2] OvmfPkg: Add VirtHstiDxe driver

2024-03-14 Thread Yao, Jiewen
Question: What is the value to provide an *empty* HSTI table? IMHO, If the goal is to perform some security check, I think we need provide a *real* HSTI table. Thank you Yao, Jiewen > -Original Message- > From: Konstantin Kostiuk > Sent: Thursday, March 14, 2024 6:25 PM &g

Re: [edk2-devel] [PATCH V1 1/1] OvmfPkg/QemuBootOrderLib: Measure the etc/boot-menu-wait

2024-03-12 Thread Yao, Jiewen
Thanks for the patch. Is this the only missing configuration data? Or do you have more on the way? > -Original Message- > From: Sun, CepingX > Sent: Wednesday, March 13, 2024 7:52 AM > To: devel@edk2.groups.io > Cc: Sun, CepingX ; Aktas, Erdem > ; Yao, Jiewen ;

Re: [edk2-devel] [PATCH V1 0/3] OvmfPkg: Update TDVMCALL to avoid leaking secrets to the VMM

2024-03-11 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Xu, Min M > Sent: Tuesday, February 27, 2024 2:49 PM > To: Sun, CepingX ; devel@edk2.groups.io > Cc: Liming Gao ; Kinney, Michael D > ; Aktas, Erdem ; James > Bottomley ; Yao, Jiewen ; Tom > Lendacky ; Michae

Re: [edk2-devel] [PATCH] Maintainers.txt: remove Laszlo's entries

2024-03-08 Thread Yao, Jiewen
> ; Gerd Hoffmann ; Yao, Jiewen > ; Leif Lindholm ; Kumar, > Rahul R ; Ni, Ray ; Sami Mujawar > > Subject: Re: [edk2-devel] [PATCH] Maintainers.txt: remove Laszlo's entries > > On Fri, 8 Mar 2024 at 10:14, Laszlo Ersek wrote: > > > > On 3/6/24 23:22, Michael

Re: [edk2-devel] [PATCH v2 00/10] clean up ProcessLibraryConstructorList() declarations in SEC modules

2024-03-05 Thread Yao, Jiewen
; Chiu, Chasel ; Duggapu, > Chinni B ; Aktas, Erdem > ; Gerd Hoffmann ; Guo, Gua > ; Dong, Guo ; Lu, James > ; Yao, Jiewen ; Joey Vagedes > ; Leif Lindholm ; Liming > Gao ; Kinney, Michael D > ; Michael Roth ; Xu, Min > M ; Desimone, Nathaniel L > ; Kumar, Rahul R ; >

Re: [edk2-devel] [RFC PATCH 1/1] ArmPkg,MdePkg: move ArmLib.h to MdePkg

2024-03-01 Thread Yao, Jiewen
Right, if it is only required by ARM, then it should under ARM section. Thank you Yao, Jiewen > -Original Message- > From: Leif Lindholm > Sent: Friday, March 1, 2024 7:45 PM > To: Yao, Jiewen ; Pierre Gondois > ; devel@edk2.groups.io > Cc: Ard Biesheuvel ; Lim

Re: [edk2-devel] [RFC PATCH 1/1] ArmPkg,MdePkg: move ArmLib.h to MdePkg

2024-02-29 Thread Yao, Jiewen
add/remove DSC freely. Having "dependency" in DSC does not matter. Having dependency in INF is something we should care about. Thank you Yao, Jiewen > -Original Message- > From: Leif Lindholm > Sent: Tuesday, February 13, 2024 1:38 AM > To: Pierre Gondois ; d

Re: [edk2-devel] [PATCH v2 00/23] Provide SEV-SNP support for running under an SVSM

2024-02-29 Thread Yao, Jiewen
Below: > -Original Message- > From: Tom Lendacky > Sent: Thursday, February 29, 2024 12:20 AM > To: Yao, Jiewen ; devel@edk2.groups.io > Cc: Ard Biesheuvel ; Aktas, Erdem > ; Gerd Hoffmann ; Laszlo Ersek > ; Liming Gao ; Kinney, Michael > D ; Xu, Min M ; Liu, >

Re: [edk2-devel] [PATCH v2 00/23] Provide SEV-SNP support for running under an SVSM

2024-02-27 Thread Yao, Jiewen
the position of SVSM. If the SVSM interface is AMD specific, the it should be AmdSvsmLib. If the SVSM interface is generic, then we should define everything in a generic way. It is very confusing to mix a generic CcSvsm lib with AMD specific . Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [PATCH v4 3/3] SecurityPkg: Update ReceiveData and SendData function description

2024-02-27 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Shang, Qingyu > Sent: Monday, February 26, 2024 11:06 AM > To: devel@edk2.groups.io > Cc: Yao, Jiewen > Subject: [PATCH v4 3/3] SecurityPkg: Update ReceiveData and SendData function > description > > Refe

Re: [edk2-devel] [PATCH v2] SecurityPkg/SecureBootConfigDxe: Update UI according to UEFI spec

2024-02-27 Thread Yao, Jiewen
is still UEFI 2.9? would that still work? Third, because I am not HII expert, I would like to have HII expert to comment the HII/Browser related change. Thank you Yao, Jiewen > -Original Message- > From: Tan, Ming > Sent: Tuesday, February 27, 2024 10:59 AM > To: devel@ed

Re: [edk2-devel] The API in BaseCryptLib can't seed the pseudorandom number generator properly

2024-02-19 Thread Yao, Jiewen
Thanks Laslo and Eddie. I am just back from Chinese New Year vocation, still checking email. If you can file a Bugzilla (https://bugzilla.tianocore.org/) with source code of your app, that would be very helpful for us to investigate this issue. > -Original Message- > From:

Re: [edk2-devel] [PATCH 00/16] Provide SEV-SNP support for running under an SVSM

2024-01-27 Thread Yao, Jiewen
Thanks Tom. Below is exactly what I am looking for: "the decision to use the SVSM API will be based on the VMPL level at which OVMF is running." OVMF needs to detect SEV-SNP, then make next level decision on VMPL. Makes sense to me. Thank you Yao, Jiewen > -Original Messag

Re: [edk2-devel] [PATCH 00/16] Provide SEV-SNP support for running under an SVSM

2024-01-26 Thread Yao, Jiewen
these mode requires runtime detection. Am I right? If so, where is the flag to set those mode? Please correct me if my understanding is wrong. Thank you Yao, Jiewen > -Original Message- > From: Tom Lendacky > Sent: Saturday, January 27, 2024 6:13 AM > To: devel@edk2.groups.

Re: [edk2-devel] [PATCH 00/11] OvmfPkg: tweak shell builds

2024-01-24 Thread Yao, Jiewen
Always good to reduce duplication! Thanks for doing that. Acked-by: Jiewen Yao > -Original Message- > From: Gerd Hoffmann > Sent: Thursday, January 25, 2024 12:38 AM > To: devel@edk2.groups.io > Cc: Yao, Jiewen ; Ard Biesheuvel > ; Michael Roth ; Gerd > Hoffmann ;

Re: [edk2-devel] [PATCH 0/3] DxeTpm and DxeTpm2MeasureBootLib symbol rename

2024-01-17 Thread Yao, Jiewen
Thank you Doug for the prompt response. Reviewed-by: Jiewen Yao > -Original Message- > From: Douglas Flick [MSFT] > Sent: Thursday, January 18, 2024 6:47 AM > To: devel@edk2.groups.io > Cc: Douglas Flick [MSFT] ; Yao, Jiewen > ; Kumar, Rahul R > Subjec

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-17 Thread Yao, Jiewen
Hi Marc I notice you are reviewer for TPM module in OvmfPkg. Would you please help to test the TPM2.0 feature with patch from Gerd? Thank you Yao, Jiewen > -Original Message- > From: Gerd Hoffmann > Sent: Wednesday, January 17, 2024 10:06 PM > To: devel@edk2.groups.io;

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-17 Thread Yao, Jiewen
. But it does seems a big issue now. Would you please propose a patch to resolve it? Just rename the symbol. Thank you Yao, Jiewen > -Original Message- > From: Li, Yi1 > Sent: Wednesday, January 17, 2024 4:15 PM > To: Yao, Jiewen ; devel@edk2.groups.io; Gerd Hoffmann >

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-17 Thread Yao, Jiewen
Please check https://github.com/tianocore/edk2/pull/5264. It is merged after pass CI. May I know where you see PR CI builds are broken? Thank you Yao, Jiewen > -Original Message- > From: Li, Yi1 > Sent: Wednesday, January 17, 2024 3:21 PM > To: devel@edk2.groups.io; Yao, J

Re: [edk2-devel] [PATCH 0/2] OvmfPkg: drop support for TPM 1.2

2024-01-16 Thread Yao, Jiewen
Gerd I am OK with the patch. Quick question: Have you validated that the TPM2 is still working? > -Original Message- > From: devel@edk2.groups.io On Behalf Of Gerd > Hoffmann > Sent: Tuesday, January 16, 2024 11:42 PM > To: devel@edk2.groups.io > Cc: Oliver Steffen ; Gerd Hoffmann

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-16 Thread Yao, Jiewen
Sure. Let's start from OVMF. We have leaf enough time for feedback, but I see no comment from other people. > -Original Message- > From: Gerd Hoffmann > Sent: Tuesday, January 16, 2024 10:35 PM > To: devel@edk2.groups.io; Yao, Jiewen > Cc: dougfl...@microsoft.com; Doug

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-16 Thread Yao, Jiewen
Gerd I have merged this patch set today. I am fine to remove TPM1.2 in OVMF because of the known security limitation. Thank you Yao, Jiewen > -Original Message- > From: Gerd Hoffmann > Sent: Tuesday, January 16, 2024 8:01 PM > To: devel@edk2.groups.io; dougfl...@micros

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-15 Thread Yao, Jiewen
Merged https://github.com/tianocore/edk2/pull/5264 > -Original Message- > From: Douglas Flick [MSFT] > Sent: Friday, January 12, 2024 2:16 AM > To: devel@edk2.groups.io > Cc: Douglas Flick [MSFT] ; Yao, Jiewen > > Subject: [PATCH 0/6] SECURITY PATCHES TCBZ4117 &

Re: [edk2-devel] When TPM is enabled, Ubuntu doesn't boot

2024-01-12 Thread Yao, Jiewen
need help from Ubuntu people. Thank you Yao, Jiewen From: devel@edk2.groups.io On Behalf Of Hamit Can Karaca Sent: Friday, January 12, 2024 1:39 PM To: Hamit Can Karaca ; devel@edk2.groups.io Subject: Re: [edk2-devel] When TPM is enabled, Ubuntu doesn't boot I still need help on this topic. I have

Re: [edk2-devel] [PATCH 0/6] SECURITY PATCHES TCBZ4117 & TCBZ4118

2024-01-11 Thread Yao, Jiewen
Hi Doug Thanks for the fix. Please remember to CC all SecurityPkg maintainer and reviewer. I will merge after several days to see if there is any additional feedback from the community. Thank you Yao, Jiewen > -Original Message- > From: Douglas Flick [MSFT] > Sent: Friday, J

Re: [edk2-devel] [PATCH v5 2/6] CryptoPkg/CryptoPkg.ci.yaml: Allow dependency upon ArmPkg

2023-11-21 Thread Yao, Jiewen
Cool, thanks for considering that! > -Original Message- > From: Ard Biesheuvel > Sent: Wednesday, November 22, 2023 12:03 AM > To: devel@edk2.groups.io; quic_llind...@quicinc.com > Cc: Yao, Jiewen ; Pierre Gondois > ; Li, Yi1 ; Lu, Xiaoyu1 > ; Jiang, Guomin ; Ar

Re: [edk2-devel] [PATCH v5 2/6] CryptoPkg/CryptoPkg.ci.yaml: Allow dependency upon ArmPkg

2023-11-21 Thread Yao, Jiewen
interface in MdePkg, then your INF can declare that interface. You can still put real implementation in ArmPkg - no requirement to move. That benefit is that you don’t need to add ArmPkg dependency in yaml. Thank you Yao, Jiewen > -Original Message- > From: Leif Lindholm > Sent

Re: [edk2-devel] [PATCH v5 2/6] CryptoPkg/CryptoPkg.ci.yaml: Allow dependency upon ArmPkg

2023-11-21 Thread Yao, Jiewen
to suggest this approach. But I would like to have ARM expert to check if those are really ARM standard, and also have MdePkg owner check if it is acceptable. Thank you Yao, Jiewen > -Original Message- > From: Pierre Gondois > Sent: Tuesday, November 21, 2023 8:59 PM

Re: [edk2-devel] [PATCH v5 2/6] CryptoPkg/CryptoPkg.ci.yaml: Allow dependency upon ArmPkg

2023-11-21 Thread Yao, Jiewen
Why CryptoPkg needs to depend on ArmPkg? Can we move content to MdePkg? > -Original Message- > From: Pierre Gondois > Sent: Tuesday, November 21, 2023 4:47 PM > To: devel@edk2.groups.io > Cc: Yao, Jiewen ; Li, Yi1 ; Lu, > Xiaoyu1 > ; Jiang, Guomin ; Leif Lindho

Re: [edk2-devel] [PATCH 0/3] Maintainers.txt: add Laszlo Ersek as an ArmVirt, Ovmf, UefiCpu Pkg "M"

2023-11-16 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Kinney, Michael D > Sent: Friday, November 17, 2023 6:52 AM > To: Laszlo Ersek ; devel@edk2.groups.io > Cc: Andrew Fish ; Ard Biesheuvel > ; Gerd Hoffmann ; Yao, > Jiewen ; Leif Lindholm ; > Kumar, Rahul R ;

Re: [edk2-devel] [PATCH v1 3/3] OvmfPkg: Format with Uncrustify 73.0.8

2023-11-15 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: mikub...@linux.microsoft.com > Sent: Wednesday, November 15, 2023 4:22 AM > To: devel@edk2.groups.io > Cc: Ard Biesheuvel ; Corvin Köhne > ; Gerd Hoffmann ; Yao, Jiewen > ; Rebecca Cran > Subject: [PATCH

Re: [edk2-devel] [PATCH 00/37] OvmfPkg: remove the CSM (after edk2-stable202311)

2023-11-10 Thread Yao, Jiewen
heuvel ; Corvin Köhne > ; Aktas, Erdem ; Gerd > Hoffmann ; Jianyong Wu ; Yao, > Jiewen ; Michael Roth ; Xu, > Min M ; Rebecca Cran ; Sunil V L > ; Tom Lendacky > Subject: [PATCH 00/37] OvmfPkg: remove the CSM (after edk2-stable202311) > > BZ: https://bugzilla.tianocore.org/

Re: [edk2-devel] [edk2-stable202311] [PATCH V4 0/3] OvmfPkg: Update TdVmCall to handle the retry for MapGPA

2023-11-09 Thread Yao, Jiewen
Thank you. Merged. https://github.com/tianocore/edk2/pull/5026 > -Original Message- > From: gaoliming > Sent: Thursday, November 9, 2023 9:54 PM > To: devel@edk2.groups.io; Yao, Jiewen ; Sun, CepingX > ; Kinney, Michael D ; > 'Leif Lindholm' ; 'Andrew Fish' > Cc:

Re: [edk2-devel] [PATCH V4 0/3] OvmfPkg: Update TdVmCall to handle the retry for MapGPA

2023-11-08 Thread Yao, Jiewen
you Yao, Jiewen > -Original Message- > From: devel@edk2.groups.io On Behalf Of Yao, Jiewen > Sent: Wednesday, November 8, 2023 9:21 PM > To: Sun, CepingX ; devel@edk2.groups.io > Cc: Gao, Liming ; Kinney, Michael D > ; Aktas, Erdem ; James > Bottomley ; Xu, M

Re: [edk2-devel] [PATCH V4 0/3] OvmfPkg: Update TdVmCall to handle the retry for MapGPA

2023-11-08 Thread Yao, Jiewen
All: Reviewed-by: Jiewen Yao > -Original Message- > From: Sun, CepingX > Sent: Wednesday, November 8, 2023 7:38 PM > To: devel@edk2.groups.io > Cc: Sun, CepingX ; Gao, Liming > ; Kinney, Michael D ; > Aktas, Erdem ; James Bottomley > ; Xu, Min M ; Tom Lendack

Re: [edk2-devel] [PATCH V3 2/2] OvmfPkg/BaseMemEncryptTdxLib: Handle retry result of MapGPA

2023-11-08 Thread Yao, Jiewen
Hey Ceping Please don't change two packages in one patch, because it is hard to let the corresponding maintainer to review and give R-B, if he/she only reviews part of them. The patch should be split to MdePkg update and OvmfPkg update. Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [PATCH V2 2/2] OvmfPkg/BaseMemEncryptTdxLib: Handle retry result of MapGPA

2023-11-07 Thread Yao, Jiewen
I think the macro definition (#define TDVMCALL_STATUS_RETRY 0x1) should be in https://github.com/tianocore/edk2/blob/master/MdePkg/Include/IndustryStandard/Tdx.h, together with other TDX definition. Thank you Yao, Jiewen > -Original Message- > From: Sun, CepingX > Sent:

Re: [edk2-devel] [PATCH V2 1/2] MdePkg/BaseLib: Update TdVmcall to always output the value in R11

2023-11-07 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Sun, CepingX > Sent: Thursday, November 2, 2023 5:10 PM > To: devel@edk2.groups.io > Cc: Sun, CepingX ; Gao, Liming > ; Kinney, Michael D ; > Aktas, Erdem ; James Bottomley > ; Yao, Jiewen ; Xu, Min M > ; To

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Remove unused OvmfPkg Confidential Computing path

2023-11-07 Thread Yao, Jiewen
Acked-by: Jiewen Yao > -Original Message- > From: Kinney, Michael D > Sent: Wednesday, November 8, 2023 11:50 AM > To: devel@edk2.groups.io > Cc: Andrew Fish ; Leif Lindholm ; > Aktas, Erdem ; Yao, Jiewen ; > Xu, Min M ; Tom Lendacky > ; Michael Rot

Re: [edk2-devel] [PATCH v1 0/7] CryptoPkg: Enable Openssl native instruction support for AARCH64

2023-11-06 Thread Yao, Jiewen
Hi Leif/Ard/Sami I would expect ARM/AARCH64 maintainers to review the ARM specific files, even they are in CryptoPkg. Please help on that. Thank you Yao, Jiewen > -Original Message- > From: Li, Yi1 > Sent: Tuesday, November 7, 2023 10:39 AM > To: Pierre Gondois ; devel@ed

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Update based on active community members

2023-10-29 Thread Yao, Jiewen
from anyone who can be trusted by the maintainer. That is based upon the current situation - anyone can be a reviewer just because they want to be CCed and has no expectation to review the code. Restricting R-B from a reviewer does not make sense to me. Thank you Yao, Jiewen > -Original Mess

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Update based on active community members

2023-10-29 Thread Yao, Jiewen
iner may ask the reviewer to provide feedback, right? Those are more than just CCed. Thank you Yao, Jiewen > -Original Message- > From: Kinney, Michael D > Sent: Monday, October 30, 2023 1:23 AM > To: Yao, Jiewen ; j...@linux.ibm.com; Laszlo Ersek > ; devel@edk2.groups.io; p

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Update based on active community members

2023-10-29 Thread Yao, Jiewen
is no expectation that he/she would review the patch? I would like to understand more on how that works and what that means. Would you please give a URL for the reviewer definition in Linux Kernel? Thank you Yao, Jiewen > -Original Message- > From: James Bottomley > Sent: Mond

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Update based on active community members

2023-10-29 Thread Yao, Jiewen
about.gitlab.com/topics/version-control/what-is-code-review/ Our definition seems more like *a notification receiver*, instead of a real code reviewer. I would say, it is a very misleading definition. Thank you Yao, Jiewen > -Original Message- > From: Laszlo Ersek > Sent: Sunday,

Re: [edk2-devel] [Patch 1/1] Maintainers.txt: Update based on active community members

2023-10-29 Thread Yao, Jiewen
ot;, although he has no such title. Thank you Yao, Jiewen > -Original Message- > From: devel@edk2.groups.io On Behalf Of Pedro Falcato > Sent: Sunday, October 29, 2023 10:17 AM > To: devel@edk2.groups.io; Kinney, Michael D > Cc: Andrew Fish ; Leif Lindholm ; > Warkentin, A

Re: [edk2-devel] [PATCH 0/7] Support Tdx and sev in BaseIoLibIntrinsic and remove BaseIoLibIntrinsicSev

2023-10-27 Thread Yao, Jiewen
merge, even if it pass review. Otherwise, once the review passed, the maintainer may merge it. I don't think that is the intention. Thank you Yao, Jiewen > -Original Message- > From: Tan, Dun > Sent: Friday, October 27, 2023 2:32 PM > To: Yao, Jiewen ; devel@edk2.groups.

Re: [edk2-devel] [PATCH 0/7] Support Tdx and sev in BaseIoLibIntrinsic and remove BaseIoLibIntrinsicSev

2023-10-26 Thread Yao, Jiewen
HI Since this impact TDX and SEV, would you please let me know what kind of test you have done? Have you validated TDX and SEV before you submit the patch? Please describe that clearly in your patch description. Also please include AMD SEV reviewer in this patch series. Thank you Yao, Jiewen

Re: [edk2-devel] [PATCH v4 04/14] OvmfPkg: Add ImagePropertiesRecordLib Instance

2023-10-23 Thread Yao, Jiewen
Acked-by: Jiewen Yao > -Original Message- > From: Taylor Beebe > Sent: Saturday, August 5, 2023 3:47 AM > To: devel@edk2.groups.io > Cc: Ard Biesheuvel ; Yao, Jiewen > ; Justen, Jordan L ; Gerd > Hoffmann > Subject: [PATCH v4 04/14] OvmfPkg: Add ImageProp

Re: [edk2-devel] [PATCH v1 3/3] OvmfPkg: Add varpolicy shell command

2023-10-23 Thread Yao, Jiewen
Acked-by: Jiewen Yao > -Original Message- > From: mikub...@linux.microsoft.com > Sent: Tuesday, September 19, 2023 10:33 PM > To: devel@edk2.groups.io > Cc: Anatol Belski ; Anthony Perard > ; Gerd Hoffmann ; Jianyong > Wu ; Yao, Jiewen ; Justen, > Jordan L ;

Re: [edk2-devel] [PATCH v5 00/28] Implement Dynamic Memory Protection Settings

2023-10-09 Thread Yao, Jiewen
, a malicious QEMU MAY purposely downgrade the protection in CC use case. In order to detect such scenario, the QEMU configuration MUST be measured. Is that done in this patch set? Thank you Yao, Jiewen > -Original Message- > From: Taylor Beebe > Sent: Monday, October 9, 2023 8:07 AM &g

Re: [edk2-devel] setting TLS ciphers is broken (openssl 3?)

2023-09-27 Thread Yao, Jiewen
cannot nail down shortly, that would be next next week. Thank you Yao, Jiewen > -Original Message- > From: devel@edk2.groups.io On Behalf Of Gerd > Hoffmann > Sent: Wednesday, September 27, 2023 4:39 PM > To: devel@edk2.groups.io > Subject: [edk2-devel] setting TLS

Re: [edk2-devel] [PATCH v1 1/1] RISCV: Fix InternalLongJump to return correct value

2023-09-19 Thread Yao, Jiewen
I am OK for the RISC-V change. Would you please let me know why we need openssl submodule ? > -Original Message- > From: devel@edk2.groups.io On Behalf Of Andrei > Warkentin > Sent: Tuesday, September 19, 2023 12:43 PM > To: devel@edk2.groups.io > Cc: Warkentin, Andrei ; Li, Yong > ;

Re: [edk2-devel] [PATCH] OvmfPkg: raise DXEFV size to 14.5 MB in the traditional platform FDFs

2023-09-13 Thread Yao, Jiewen
Thanks Laszlo for the detail explanation, appreciate that. I hope people will take action when it is close to 16MiB, then. Anyway, I am OK with this so far. Acked-by: Jiewen Yao > -Original Message- > From: Laszlo Ersek > Sent: Tuesday, September 12, 2023 11:36 PM > To:

Re: [edk2-devel] [PATCH v3] Pyrite support - Secure erase is only available if encryption is supported.

2023-09-12 Thread Yao, Jiewen
Reviewed-by: Jiewen Yao > -Original Message- > From: Liu, Linus > Sent: Tuesday, September 12, 2023 9:42 AM > To: devel@edk2.groups.io > Cc: Liu, Linus ; Zhang, Qi1 ; Kumar, > Rahul R ; Yao, Jiewen ; Chen, > Tina ; Chen, Xiao X > Subject: [PATCH v3] Pyrit

Re: [edk2-devel] [PATCH] OvmfPkg: raise DXEFV size to 14.5 MB in the traditional platform FDFs

2023-09-12 Thread Yao, Jiewen
16MiB ? More than 128MiB? Thank you Yao, Jiewen > -Original Message- > From: Ard Biesheuvel > Sent: Tuesday, September 12, 2023 10:59 PM > To: Laszlo Ersek > Cc: devel@edk2.groups.io; Ard Biesheuvel ; Gerd > Hoffmann ; Yao, Jiewen ; Justen, > Jordan L > Subject: Re

  1   2   3   4   5   6   7   8   9   10   >