Re: [edk2-devel][Patch] MdeModulePkg/CapsuleApp: Enhance Capsule-On-Disk related functions.

2019-05-27 Thread Zhang, Chao B
Reviewed-by: Chao Zhang -Original Message- From: devel@edk2.groups.io [mailto:devel@edk2.groups.io] On Behalf Of Xu, Wei6 Sent: Friday, May 24, 2019 5:02 PM To: devel@edk2.groups.io Cc: Wang, Jian J ; Wu, Hao A ; Zhang, Chao B ; Xu, Wei6 Subject: [edk2-devel][Patch] MdeModulePkg

Re: [edk2-devel] [Patch 3/3] SignedCapsulePkg: Update Package DSC to remove unused network libs

2019-05-28 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Gao, Liming Sent: Tuesday, May 28, 2019 7:42 PM To: devel@edk2.groups.io Cc: Yao, Jiewen ; Zhang, Chao B Subject: [Patch 3/3] SignedCapsulePkg: Update Package DSC to remove unused network libs Signed-off-by: Liming Gao Cc: Jiewen Yao

Re: [edk2-devel][Patch 0/7] Implement Capsule On Disk.

2019-05-28 Thread Zhang, Chao B
Yes, will check in after Q2 tag From: Gao, Liming Sent: Wednesday, May 29, 2019 8:34 AM To: Xu, Wei6 ; devel@edk2.groups.io Cc: Wang, Jian J ; Wu, Hao A ; Kinney, Michael D ; Zhang, Chao B Subject: RE: [edk2-devel][Patch 0/7] Implement Capsule On Disk. So, this feature is for next Q3 stable

Re: [edk2-devel][Patch v2 0/7] Implement Capsule On Disk.

2019-06-05 Thread Zhang, Chao B
Sent: Thursday, June 6, 2019 6:37 AM To: Felix Polyudov ; devel@edk2.groups.io; Xu, Wei6 ; Kinney, Michael D Cc: Wang, Jian J ; Wu, Hao A ; Gao, Liming ; Zhang, Chao B Subject: RE: [edk2-devel][Patch v2 0/7] Implement Capsule On Disk. Hi Felix, For (1), this is a limitation of UEFI Capsule

Re: [edk2-devel][Patch v2 0/7] Implement Capsule On Disk.

2019-06-12 Thread Zhang, Chao B
HI Hao: I don't have extra comments for the whole patch From: Wu, Hao A Sent: Wednesday, June 12, 2019 3:48 PM To: devel@edk2.groups.io; Xu, Wei6 ; Zhang, Chao B Cc: Wang, Jian J ; Kinney, Michael D ; Gao, Liming Subject: RE: [edk2-devel][Patch v2 0/7] Implement Capsule On Disk. Hello Chao

Re: [edk2-devel][Patch v2 5/7] MdeModulePkg/CapsuleRuntimeDxe: Introduce PCD to control this feature.

2019-06-18 Thread Zhang, Chao B
; Zhang, Chao B Subject: RE: [edk2-devel][Patch v2 5/7] MdeModulePkg/CapsuleRuntimeDxe: Introduce PCD to control this feature. > -Original Message- > From: devel@edk2.groups.io<mailto:devel@edk2.groups.io> > [mailto:devel@edk2.groups.io] On Behalf Of Xu, > Wei6 > Sen

Re: [edk2-devel][Patch v2 5/7] MdeModulePkg/CapsuleRuntimeDxe: Introduce PCD to control this feature.

2019-06-18 Thread Zhang, Chao B
Hi Hao: OK that is a good point. We will follow up to clean this. Tks From: Wu, Hao A Sent: Wednesday, June 19, 2019 9:00 AM To: Zhang, Chao B ; devel@edk2.groups.io; Xu, Wei6 Cc: Wang, Jian J Subject: RE: [edk2-devel][Patch v2 5/7] MdeModulePkg/CapsuleRuntimeDxe: Introduce PCD to control

Re: [edk2-devel] [PATCH] SecurityPkg/AuthSeriableLib: Always delete variable in certdb

2019-05-13 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Gao, Zhichao Sent: Monday, May 13, 2019 10:55 AM To: devel@edk2.groups.io Cc: Zhang, Chao B ; Yao, Jiewen ; Wang, Jian J ; Zeng, Star ; Gao, Liming Subject: [PATCH] SecurityPkg/AuthSeriableLib: Always delete variable in certdb REF

Re: [edk2-devel] Question about the Protective MBR in RedHat/Ubuntu

2019-04-24 Thread Zhang, Chao B
Hi Andrew: Tks for your explanation. The middle octet of StartingCHS (0x000200) is for Sector. Based on CHS to LBA conversion rule. It should be 0x02. I think it is an spec compliance issue. Partition Dxe driver doesn't apply such check so there is no problem. Partition Pei is in BIOS

Re: [edk2-devel] [PATCH v3 1/3] SecurityPkg: Remove double \r

2019-05-10 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Joe Richey [mailto:joeric...@google.com] Sent: Friday, May 10, 2019 5:37 PM To: devel@edk2.groups.io Cc: Zhang, Chao B ; Yao, Jiewen ; Wang, Jian J Subject: [PATCH v3 1/3] SecurityPkg: Remove double \r Cc: Chao Zhang Cc: Jiewen Yao

[edk2-devel] [Patch] Maintainers.txt: Change SecurityPkg Maintainer Role

2019-07-04 Thread Zhang, Chao B
Change Chao's role to Reviewer Cc: Wang Jian J Signed-off-by: Zhang, Chao B --- Maintainers.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Maintainers.txt b/Maintainers.txt index e52f044bec..2b15cee5c1 100644 --- a/Maintainers.txt +++ b/Maintainers.txt @@ -191,13

[edk2-devel] [Patch] Maintainers.txt: Change SecurityPkg Maintainer Role

2019-07-04 Thread Zhang, Chao B
Change Chao's role to Reviewer Cc: Wang, Jian J Signed-off-by: Zhang, Chao B --- Maintainers.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Maintainers.txt b/Maintainers.txt index e52f044bec..2b15cee5c1 100644 --- a/Maintainers.txt +++ b/Maintainers.txt @@ -191,13

Re: [edk2-devel] [PATCH v4 0/3] Common OBB verification feature

2019-06-26 Thread Zhang, Chao B
Reviewed-by : Chao Zhang From: Wang, Jian J Sent: Wednesday, June 26, 2019 3:44 PM To: Zhang, Chao B ; Yao, Jiewen ; devel@edk2.groups.io Cc: Hernandez Beltran, Jorge ; Han, Harry Subject: RE: [PATCH v4 0/3] Common OBB verification feature Thanks, Chao. You're right your way is better. I'll

Re: [edk2-devel][Patch] MdeModulePkg/DxeCapsuleLibFmp: Add missing NULL pointer check.

2019-06-27 Thread Zhang, Chao B
Reviewed-by: Chao Zhang -Original Message- From: Xu, Wei6 Sent: Friday, June 28, 2019 12:26 AM To: devel@edk2.groups.io Cc: Wang, Jian J ; Wu, Hao A ; Zhang, Chao B Subject: [edk2-devel][Patch] MdeModulePkg/DxeCapsuleLibFmp: Add missing NULL pointer check. Add missing NULL pointer

Re: [edk2-devel][Patch] MdeModulePkg/DxeCapsuleLibFmp: Add missing NULL pointer check.

2019-06-27 Thread Zhang, Chao B
HI Hao: I think the patch is to complete the security check both in info and code logic to ValidateCapsuleNameCapsuleIntegrity . It is OK to keep it in one patch. From: Wu, Hao A Sent: Friday, June 28, 2019 8:54 AM To: Xu, Wei6 ; devel@edk2.groups.io Cc: Wang, Jian J ; Zhang, Chao B Subject

Re: [edk2-devel] [PATCH] SecurityPkg: Don't Verify the enrolled PK in setup mode

2019-07-10 Thread Zhang, Chao B
Presence Asserted. From: Laszlo Ersek [mailto:ler...@redhat.com] Sent: Thursday, July 11, 2019 1:04 AM To: devel@edk2.groups.io; Wang, Jian J ; Zhang, Chao B ; Derek Lin ; Cinnamon Shia Subject: Re: [edk2-devel] [PATCH] SecurityPkg: Don't Verify the enrolled PK in setup mode Hi, On 07/10/19

Re: [edk2-devel] [PATCH] SecurityPkg: Don't Verify the enrolled PK in setup mode

2019-07-09 Thread Zhang, Chao B
Hi Derek: The patch is good to me. Reviewed-by : Chao Zhang From: devel@edk2.groups.io [mailto:devel@edk2.groups.io] On Behalf Of derek.l...@hpe.com Sent: Tuesday, July 2, 2019 1:25 PM To: devel@edk2.groups.io Subject: [edk2-devel] [PATCH] SecurityPkg: Don't Verify the enrolled PK in

Re: [edk2-devel] [PATCH v4 0/3] Common OBB verification feature

2019-06-26 Thread Zhang, Chao B
nesday, June 26, 2019 1:34 PM To: Yao, Jiewen ; devel@edk2.groups.io Cc: Zhang, Chao B ; Hernandez Beltran, Jorge ; Han, Harry Subject: RE: [PATCH v4 0/3] Common OBB verification feature Thanks Jiewen. I'll add it with a few code style corrections. Anyone else has any comments? Regards

Re: [edk2-devel][Patch] MdeModulePkg/CapsuleApp: Enhance Capsule-On-Disk related functions.

2019-06-25 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Xu, Wei6 Sent: Tuesday, June 25, 2019 2:51 PM To: devel@edk2.groups.io Cc: Wang, Jian J ; Wu, Hao A ; Zhang, Chao B Subject: [edk2-devel][Patch] MdeModulePkg/CapsuleApp: Enhance Capsule-On-Disk related functions. BZ: https

Re: [edk2-devel][Patch 0/6] Implement Capsule On Disk.

2019-06-25 Thread Zhang, Chao B
Series reviewed by : Chao Zhang -Original Message- From: devel@edk2.groups.io [mailto:devel@edk2.groups.io] On Behalf Of Xu, Wei6 Sent: Tuesday, June 25, 2019 2:54 PM To: devel@edk2.groups.io Cc: Wang, Jian J ; Wu, Hao A ; Kinney, Michael D ; Gao, Liming ; Zhang, Chao B Subject: [edk2

Re: [edk2-devel] TPM ACPI HID creation

2019-06-25 Thread Zhang, Chao B
; jason.spottsw...@hpe.com Cc: Zhang, Chao B ; Yao, Jiewen Subject: RE: [edk2-devel] TPM ACPI HID creation Thanks Jason. I think we should NOT measure TPM2 table *after* ACPI table patch. The measurement should happen *before* ACPI table patch. Hi Chao Do you agree on that? Thank you Yao Jiewen From

Re: [edk2-devel] [PATCH V2] UefiCpuPkg/MpInitLib: MicrocodeDetect: Ensure checked range is valid

2019-06-25 Thread Zhang, Chao B
Hi All: Is that patch to fix potential overflow in MicroCodeEntryPoint + TotalSize? Is there a clearer way to check it? Like MAX_ADDRESS - TotalSize <= MicroCodeEntryPoint. And I suggest to add check before doing MicrroCodeEntryPoint + TotalSize. From: devel@edk2.groups.io

Re: [edk2-devel] [PATCH] SecurityPkg/SecurityPkg.uni: Add missing strings for new PCDs

2019-08-14 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Wang, Jian J Sent: Wednesday, August 14, 2019 5:01 PM To: devel@edk2.groups.io Cc: Yao, Jiewen ; Zhang, Chao B ; Zhang, Shenglei Subject: [PATCH] SecurityPkg/SecurityPkg.uni: Add missing strings for new PCDs REF: https

Re: [edk2-devel] [PATCH 2/2] SecurityPkg/SecurityPkg.dec: Update TcgPpVendorLib.h to Tcg2PpVendorLib.h

2019-09-16 Thread Zhang, Chao B
Reviewed-by : Chao Zhang From: Wang, Jian J Sent: Monday, September 16, 2019 1:55 PM To: Zhang, Shenglei ; devel@edk2.groups.io Cc: Yao, Jiewen ; Zhang, Chao B Subject: RE: [PATCH 2/2] SecurityPkg/SecurityPkg.dec: Update TcgPpVendorLib.h to Tcg2PpVendorLib.h Reviewed-by: Jian J Wang

Re: [edk2-devel] [Patch v2] SecurityPkg Tcg2Config: Move common definitions to new Tcg2Internal.h

2019-09-16 Thread Zhang, Chao B
Reviewed-by : Chao Zhang From: Wang, Jian J Sent: Monday, September 16, 2019 1:57 PM To: Gao, Liming ; devel@edk2.groups.io Cc: Zhang, Chao B Subject: RE: [Patch v2] SecurityPkg Tcg2Config: Move common definitions to new Tcg2Internal.h Reviewed-by: Jian J Wang mailto:jian.j.w...@intel.com

Re: [edk2-devel] [PATCH] SecurityPkg/Tcg2Smm: Measure the table before patch.

2019-12-09 Thread Zhang, Chao B
Hi Jiewen: Reviewed-by: Chao Zhang -Original Message- From: Yao, Jiewen Sent: Saturday, December 7, 2019 9:44 PM To: devel@edk2.groups.io Cc: Wang, Jian J ; Zhang, Chao B ; Yao, Jiewen Subject: [PATCH] SecurityPkg/Tcg2Smm: Measure the table before patch. REF: https

Re: [edk2-devel] [PATCH 26/35] SecurityPkg: fix UninstallMultipleProtocolInterfaces() calls

2019-10-05 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Zhang, Chao B Sent: 2019年10月4日 21:14 To: edk2-devel-groups-io ; 'ler...@redhat.com' ; Wang, Jian J ; Yao, Jiewen Subject: RE: [edk2-devel] [PATCH 26/35] SecurityPkg: fix UninstallMultipleProtocolInterfaces() calls Hi Laszlo

Re: [edk2-devel] [PATCH 27/35] SecurityPkg: stop abusing EFI_EVENT for protocol notify registration

2019-10-05 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Zhang, Chao B Sent: 2019年10月4日 21:16 To: edk2-devel-groups-io ; 'ler...@redhat.com' ; Wang, Jian J ; Yao, Jiewen Subject: RE: [edk2-devel] [PATCH 27/35] SecurityPkg: stop abusing EFI_EVENT for protocol notify registration Reviewed

Re: [edk2-devel] [PATCH 26/35] SecurityPkg: fix UninstallMultipleProtocolInterfaces() calls

2019-10-04 Thread Zhang, Chao B
Hi Laszlo: Sorry for late response. The fix is good to me. I am also interested in how you find this issue, can you share it? -Original Message- From: Laszlo Ersek [mailto:ler...@redhat.com] Sent: 2019年10月3日 19:07 To: Zhang, Chao B ; Wang, Jian J ; Yao, Jiewen Cc: edk2-devel

Re: [edk2-devel] [PATCH 27/35] SecurityPkg: stop abusing EFI_EVENT for protocol notify registration

2019-10-04 Thread Zhang, Chao B
Reviewed-by : Chao Zhang -Original Message- From: Laszlo Ersek [mailto:ler...@redhat.com] Sent: 2019年10月3日 19:07 To: Zhang, Chao B ; Wang, Jian J ; Yao, Jiewen Cc: edk2-devel-groups-io Subject: Re: [edk2-devel] [PATCH 27/35] SecurityPkg: stop abusing EFI_EVENT for protocol notify

Re: [edk2-devel] [Patch v10 2/2] CryptoPkg/BaseHashApiLib: Implement Unified Hash Calculation API

2020-02-03 Thread Zhang, Chao B
Comply with gEfiSecurityPkgTokenSpaceGuid.PcdTpm2HashMask is better. We can append new definition after existing one. #define HASH_ALG_SHA10x0001 #define HASH_ALG_SHA256 0x0002 #define HASH_ALG_SHA384 0x0004 #define HASH_ALG_SHA512 0x0008 #define HASH_ALG_SM3_256 0x0010

Re: [edk2-devel] [PATCH 9/9] SecurityPkg/DxeImageVerificationLib: Differentiate error and search result in IsSignatureFoundInDatabase(CVE-2019-14575)

2020-02-13 Thread Zhang, Chao B
Ack-by : Chao Zhang -Original Message- From: devel@edk2.groups.io On Behalf Of Wang, Jian J Sent: Thursday, February 6, 2020 10:20 PM To: devel@edk2.groups.io Cc: Yao, Jiewen ; Zhang, Chao B Subject: [edk2-devel] [PATCH 9/9] SecurityPkg/DxeImageVerificationLib: Differentiate error

Re: [edk2-devel] [PATCH V6 6/6] SignedCapsulePkg: Add FMP Capsule Image Header extension

2020-05-13 Thread Zhang, Chao B
, Chao B ; fel...@ami.com; oleks...@ami.com Subject: [PATCH V6 6/6] SignedCapsulePkg: Add FMP Capsule Image Header extension Add bitmask to structure which gives a binary-inspectable mechanism to determine if a capsule contains an authentication section or depex section. (UEFI 2.8 errata a, mantis