|
|
7fdf80 |
ExclusiveArch: x86_64 aarch64
|
|
|
7fdf80 |
|
|
|
1dc609 |
%define GITDATE 20190829
|
|
|
1dc609 |
%define GITCOMMIT 37eef91017ad
|
|
|
7fdf80 |
%define TOOLCHAIN GCC5
|
|
|
1dc609 |
%define OPENSSL_VER 1.1.1c
|
|
|
7fdf80 |
|
|
|
7fdf80 |
Name: edk2
|
|
|
7fdf80 |
Version: %{GITDATE}git%{GITCOMMIT}
|
|
|
7fdf80 |
Release: 4%{?dist}
|
|
|
7fdf80 |
Summary: UEFI firmware for 64-bit virtual machines
|
|
|
7fdf80 |
Group: Applications/Emulators
|
|
|
1dc609 |
License: BSD-2-Clause-Patent and OpenSSL and MIT
|
|
|
7fdf80 |
URL: http://www.tianocore.org
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# The source tarball is created using following commands:
|
|
|
7fdf80 |
# COMMIT=%{GITCOMMIT}
|
|
|
7fdf80 |
# git archive --format=tar --prefix=edk2-$COMMIT/ $COMMIT \
|
|
|
7fdf80 |
# | xz -9ev >/tmp/edk2-$COMMIT.tar.xz
|
|
|
7fdf80 |
Source0: http://batcave.lab.eng.brq.redhat.com/www/edk2-%{GITCOMMIT}.tar.xz
|
|
|
7fdf80 |
Source1: ovmf-whitepaper-c770f8c.txt
|
|
|
1dc609 |
Source2: openssl-rhel-d6c0e6e28ddc793474a3f9234eed50018f6c94ba.tar.xz
|
|
|
7fdf80 |
Source3: ovmf-vars-generator
|
|
|
7fdf80 |
Source4: LICENSE.qosb
|
|
|
1dc609 |
Source5: RedHatSecureBootPkKek1.pem
|
|
|
7fdf80 |
|
|
|
7fdf80 |
Source10: edk2-aarch64-verbose.json
|
|
|
7fdf80 |
Source11: edk2-aarch64.json
|
|
|
7fdf80 |
Source12: edk2-ovmf-sb.json
|
|
|
7fdf80 |
Source13: edk2-ovmf.json
|
|
|
7fdf80 |
|
|
|
1dc609 |
Patch0001: 0001-CryptoPkg-OpensslLib-Update-process_files.pl-to-gene.patch
|
|
|
1dc609 |
Patch0002: 0002-CryptoPkg-Upgrade-OpenSSL-to-1.1.1d.patch
|
|
|
1dc609 |
Patch0006: 0006-advertise-OpenSSL-on-TianoCore-splash-screen-boot-lo.patch
|
|
|
1dc609 |
Patch0007: 0007-OvmfPkg-increase-max-debug-message-length-to-512-RHE.patch
|
|
|
1dc609 |
Patch0008: 0008-OvmfPkg-QemuVideoDxe-enable-debug-messages-in-VbeShi.patch
|
|
|
1dc609 |
Patch0009: 0009-MdeModulePkg-TerminalDxe-add-other-text-resolutions-.patch
|
|
|
1dc609 |
Patch0010: 0010-MdeModulePkg-TerminalDxe-set-xterm-resolution-on-mod.patch
|
|
|
1dc609 |
Patch0011: 0011-OvmfPkg-take-PcdResizeXterm-from-the-QEMU-command-li.patch
|
|
|
1dc609 |
Patch0012: 0012-ArmVirtPkg-QemuFwCfgLib-allow-UEFI_DRIVER-client-mod.patch
|
|
|
1dc609 |
Patch0013: 0013-ArmVirtPkg-take-PcdResizeXterm-from-the-QEMU-command.patch
|
|
|
1dc609 |
Patch0014: 0014-OvmfPkg-allow-exclusion-of-the-shell-from-the-firmwa.patch
|
|
|
1dc609 |
Patch0015: 0015-ArmPlatformPkg-introduce-fixed-PCD-for-early-hello-m.patch
|
|
|
1dc609 |
Patch0016: 0016-ArmPlatformPkg-PrePeiCore-write-early-hello-message-.patch
|
|
|
1dc609 |
Patch0017: 0017-ArmVirtPkg-set-early-hello-message-RH-only.patch
|
|
|
1dc609 |
Patch0018: 0018-OvmfPkg-enable-DEBUG_VERBOSE-RHEL-only.patch
|
|
|
1dc609 |
Patch0019: 0019-OvmfPkg-silence-DEBUG_VERBOSE-0x00400000-in-QemuVide.patch
|
|
|
1dc609 |
Patch0020: 0020-ArmVirtPkg-silence-DEBUG_VERBOSE-0x00400000-in-QemuR.patch
|
|
|
1dc609 |
Patch0021: 0021-OvmfPkg-QemuRamfbDxe-Do-not-report-DXE-failure-on-Aa.patch
|
|
|
1dc609 |
Patch0022: 0022-OvmfPkg-silence-EFI_D_VERBOSE-0x00400000-in-NvmExpre.patch
|
|
|
1dc609 |
Patch0033: 0033-CryptoPkg-OpensslLib-list-RHEL8-specific-OpenSSL-fil.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch34: edk2-MdePkg-Include-Protocol-Tls.h-Add-the-data-type-of-E.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch35: edk2-CryptoPkg-TlsLib-Add-the-new-API-TlsSetVerifyHost-CV.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch36: edk2-CryptoPkg-Crt-turn-strchr-into-a-function-CVE-2019-1.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch37: edk2-CryptoPkg-Crt-satisfy-inet_pton.c-dependencies-CVE-2.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch38: edk2-CryptoPkg-Crt-import-inet_pton.c-CVE-2019-14553.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch39: edk2-CryptoPkg-TlsLib-TlsSetVerifyHost-parse-IP-address-l.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch40: edk2-NetworkPkg-TlsDxe-Add-the-support-of-host-validation.patch
|
|
|
1dc609 |
# For bz#1536624 - HTTPS enablement in OVMF
|
|
|
1dc609 |
Patch41: edk2-NetworkPkg-HttpDxe-Set-the-HostName-for-the-verifica.patch
|
|
|
7fdf80 |
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# python3-devel and libuuid-devel are required for building tools.
|
|
|
7fdf80 |
# python3-devel is also needed for varstore template generation and
|
|
|
7fdf80 |
# verification with "ovmf-vars-generator".
|
|
|
7fdf80 |
BuildRequires: python3-devel
|
|
|
7fdf80 |
BuildRequires: libuuid-devel
|
|
|
7fdf80 |
BuildRequires: /usr/bin/iasl
|
|
|
7fdf80 |
BuildRequires: binutils gcc git
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
# Only OVMF includes 80x86 assembly files (*.nasm*).
|
|
|
7fdf80 |
BuildRequires: nasm
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Only OVMF includes the Secure Boot feature, for which we need to separate out
|
|
|
7fdf80 |
# the UEFI shell.
|
|
|
7fdf80 |
BuildRequires: dosfstools
|
|
|
7fdf80 |
BuildRequires: mtools
|
|
|
7fdf80 |
BuildRequires: genisoimage
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# For generating the variable store template with the default certificates
|
|
|
7fdf80 |
# enrolled, we need qemu-kvm.
|
|
|
1dc609 |
BuildRequires: qemu-kvm >= 2.12.0-89
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# For verifying SB enablement in the above variable store template, we need a
|
|
|
7fdf80 |
# guest kernel that prints "Secure boot enabled".
|
|
|
1dc609 |
BuildRequires: kernel-core >= 4.18.0-161
|
|
|
7fdf80 |
BuildRequires: rpmdevtools
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%package ovmf
|
|
|
7fdf80 |
Summary: UEFI firmware for x86_64 virtual machines
|
|
|
7fdf80 |
BuildArch: noarch
|
|
|
7fdf80 |
Provides: OVMF = %{version}-%{release}
|
|
|
7fdf80 |
Obsoletes: OVMF < 20180508-100.gitee3198e672e2.el7
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# OVMF includes the Secure Boot and IPv6 features; it has a builtin OpenSSL
|
|
|
7fdf80 |
# library.
|
|
|
7fdf80 |
Provides: bundled(openssl) = %{OPENSSL_VER}
|
|
|
1dc609 |
License: BSD-2-Clause-Patent and OpenSSL
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# URL taken from the Maintainers.txt file.
|
|
|
7fdf80 |
URL: http://www.tianocore.org/ovmf/
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%description ovmf
|
|
|
7fdf80 |
OVMF (Open Virtual Machine Firmware) is a project to enable UEFI support for
|
|
|
7fdf80 |
Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU
|
|
|
7fdf80 |
and KVM.
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
%package aarch64
|
|
|
7fdf80 |
Summary: UEFI firmware for aarch64 virtual machines
|
|
|
7fdf80 |
BuildArch: noarch
|
|
|
7fdf80 |
Provides: AAVMF = %{version}-%{release}
|
|
|
7fdf80 |
Obsoletes: AAVMF < 20180508-100.gitee3198e672e2.el7
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# No Secure Boot for AAVMF yet, but we include OpenSSL for the IPv6 stack.
|
|
|
7fdf80 |
Provides: bundled(openssl) = %{OPENSSL_VER}
|
|
|
1dc609 |
License: BSD-2-Clause-Patent and OpenSSL
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# URL taken from the Maintainers.txt file.
|
|
|
7fdf80 |
URL: https://github.com/tianocore/tianocore.github.io/wiki/ArmVirtPkg
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%description aarch64
|
|
|
7fdf80 |
AAVMF (ARM Architecture Virtual Machine Firmware) is an EFI Development Kit II
|
|
|
7fdf80 |
platform that enables UEFI support for QEMU/KVM ARM Virtual Machines. This
|
|
|
7fdf80 |
package contains a 64-bit build.
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%package tools
|
|
|
7fdf80 |
Summary: EFI Development Kit II Tools
|
|
|
7fdf80 |
Group: Development/Tools
|
|
|
1dc609 |
License: BSD-2-Clause-Patent
|
|
|
7fdf80 |
URL: https://github.com/tianocore/tianocore.github.io/wiki/BaseTools
|
|
|
7fdf80 |
%description tools
|
|
|
7fdf80 |
This package provides tools that are needed to
|
|
|
7fdf80 |
build EFI executables and ROMs using the GNU tools.
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%package tools-doc
|
|
|
7fdf80 |
Summary: Documentation for EFI Development Kit II Tools
|
|
|
7fdf80 |
Group: Development/Tools
|
|
|
7fdf80 |
BuildArch: noarch
|
|
|
1dc609 |
License: BSD-2-Clause-Patent
|
|
|
7fdf80 |
URL: https://github.com/tianocore/tianocore.github.io/wiki/BaseTools
|
|
|
7fdf80 |
%description tools-doc
|
|
|
7fdf80 |
This package documents the tools that are needed to
|
|
|
7fdf80 |
build EFI executables and ROMs using the GNU tools.
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%description
|
|
|
7fdf80 |
EDK II is a modern, feature-rich, cross-platform firmware development
|
|
|
7fdf80 |
environment for the UEFI and PI specifications. This package contains sample
|
|
|
7fdf80 |
64-bit UEFI firmware builds for QEMU and KVM.
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%prep
|
|
|
7fdf80 |
%setup -q -n edk2-%{GITCOMMIT}
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%{lua:
|
|
|
7fdf80 |
tmp = os.tmpname();
|
|
|
7fdf80 |
f = io.open(tmp, "w+");
|
|
|
7fdf80 |
count = 0;
|
|
|
7fdf80 |
for i, p in ipairs(patches) do
|
|
|
7fdf80 |
f:write(p.."\n");
|
|
|
7fdf80 |
count = count + 1;
|
|
|
7fdf80 |
end;
|
|
|
7fdf80 |
f:close();
|
|
|
7fdf80 |
print("PATCHCOUNT="..count.."\n")
|
|
|
7fdf80 |
print("PATCHLIST="..tmp.."\n")
|
|
|
7fdf80 |
}
|
|
|
7fdf80 |
|
|
|
7fdf80 |
git init -q
|
|
|
7fdf80 |
git config user.name rpm-build
|
|
|
7fdf80 |
git config user.email rpm-build
|
|
|
7fdf80 |
git config core.whitespace cr-at-eol
|
|
|
7fdf80 |
git config am.keepcr true
|
|
|
7fdf80 |
git add -A .
|
|
|
7fdf80 |
git commit -q -a --author 'rpm-build <rpm-build>' \
|
|
|
7fdf80 |
-m '%{name}-%{GITCOMMIT} base'
|
|
|
7fdf80 |
|
|
|
7fdf80 |
COUNT=$(grep '\.patch$' $PATCHLIST | wc -l)
|
|
|
7fdf80 |
if [ $COUNT -ne $PATCHCOUNT ]; then
|
|
|
7fdf80 |
echo "Found $COUNT patches in $PATCHLIST, expected $PATCHCOUNT"
|
|
|
7fdf80 |
exit 1
|
|
|
7fdf80 |
fi
|
|
|
7fdf80 |
if [ $COUNT -gt 0 ]; then
|
|
|
7fdf80 |
for pf in `cat $PATCHLIST`; do
|
|
|
7fdf80 |
git am $pf
|
|
|
7fdf80 |
done
|
|
|
7fdf80 |
fi
|
|
|
7fdf80 |
echo "Applied $COUNT patches"
|
|
|
7fdf80 |
rm -f $PATCHLIST
|
|
|
7fdf80 |
|
|
|
7fdf80 |
cp -a -- %{SOURCE1} %{SOURCE3} .
|
|
|
7fdf80 |
cp -a -- %{SOURCE10} %{SOURCE11} %{SOURCE12} %{SOURCE13} .
|
|
|
7fdf80 |
tar -C CryptoPkg/Library/OpensslLib -a -f %{SOURCE2} -x
|
|
|
7fdf80 |
|
|
|
1dc609 |
# Format the Red Hat-issued certificate that is to be enrolled as both Platform
|
|
|
1dc609 |
# Key and first Key Exchange Key, as an SMBIOS OEM String. This means stripping
|
|
|
1dc609 |
# the PEM header and footer, and prepending the textual representation of the
|
|
|
1dc609 |
# GUID that identifies this particular OEM String to "EnrollDefaultKeys.efi",
|
|
|
1dc609 |
# plus the separator ":". For details, see
|
|
|
1dc609 |
# <https://bugzilla.tianocore.org/show_bug.cgi?id=1747> comments 2, 7, 14.
|
|
|
1dc609 |
sed \
|
|
|
1dc609 |
-e 's/^-----BEGIN CERTIFICATE-----$/4e32566d-8e9e-4f52-81d3-5bb9715f9727:/' \
|
|
|
1dc609 |
-e '/^-----END CERTIFICATE-----$/d' \
|
|
|
1dc609 |
%{SOURCE5} \
|
|
|
1dc609 |
> PkKek1.oemstr
|
|
|
1dc609 |
|
|
|
7fdf80 |
# Done by %setup, but we do not use it for the auxiliary tarballs
|
|
|
7fdf80 |
chmod -Rf a+rX,u+w,g-w,o-w .
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%build
|
|
|
7fdf80 |
export PYTHON_COMMAND=%{__python3}
|
|
|
7fdf80 |
source ./edksetup.sh
|
|
|
7fdf80 |
make -C "$EDK_TOOLS_PATH" \
|
|
|
7fdf80 |
EXTRA_OPTFLAGS="%{optflags}" \
|
|
|
7fdf80 |
EXTRA_LDFLAGS="%{__global_ldflags}"
|
|
|
7fdf80 |
|
|
|
7fdf80 |
SMP_MFLAGS="%{?_smp_mflags}"
|
|
|
7fdf80 |
if [[ x"$SMP_MFLAGS" = x-j* ]]; then
|
|
|
7fdf80 |
CC_FLAGS="$CC_FLAGS -n ${SMP_MFLAGS#-j}"
|
|
|
7fdf80 |
elif [ -n "%{?jobs}" ]; then
|
|
|
7fdf80 |
CC_FLAGS="$CC_FLAGS -n %{?jobs}"
|
|
|
7fdf80 |
fi
|
|
|
7fdf80 |
|
|
|
7fdf80 |
CC_FLAGS="$CC_FLAGS --cmd-len=65536 -t %{TOOLCHAIN} -b DEBUG --hash"
|
|
|
7fdf80 |
CC_FLAGS="$CC_FLAGS -D NETWORK_IP6_ENABLE"
|
|
|
1dc609 |
CC_FLAGS="$CC_FLAGS -D NETWORK_HTTP_BOOT_ENABLE -D NETWORK_TLS_ENABLE"
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
# Build with neither SB nor SMM; include UEFI shell.
|
|
|
1dc609 |
build ${CC_FLAGS} -D TPM2_ENABLE -D FD_SIZE_4MB -a X64 \
|
|
|
1dc609 |
-p OvmfPkg/OvmfPkgX64.dsc
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Build with SB and SMM; exclude UEFI shell.
|
|
|
7fdf80 |
build -D SECURE_BOOT_ENABLE -D EXCLUDE_SHELL_FROM_FD ${CC_FLAGS} \
|
|
|
7fdf80 |
-a IA32 -a X64 -p OvmfPkg/OvmfPkgIa32X64.dsc -D SMM_REQUIRE \
|
|
|
1dc609 |
-D TPM2_ENABLE -D FD_SIZE_4MB
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Sanity check: the varstore templates must be identical.
|
|
|
7fdf80 |
cmp Build/OvmfX64/DEBUG_%{TOOLCHAIN}/FV/OVMF_VARS.fd \
|
|
|
7fdf80 |
Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_VARS.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Prepare an ISO image that boots the UEFI shell.
|
|
|
7fdf80 |
(
|
|
|
7fdf80 |
UEFI_SHELL_BINARY=Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/X64/Shell.efi
|
|
|
7fdf80 |
ENROLLER_BINARY=Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/X64/EnrollDefaultKeys.efi
|
|
|
7fdf80 |
UEFI_SHELL_IMAGE=uefi_shell.img
|
|
|
7fdf80 |
ISO_IMAGE=UefiShell.iso
|
|
|
7fdf80 |
|
|
|
7fdf80 |
UEFI_SHELL_BINARY_BNAME=$(basename -- "$UEFI_SHELL_BINARY")
|
|
|
7fdf80 |
UEFI_SHELL_SIZE=$(stat --format=%s -- "$UEFI_SHELL_BINARY")
|
|
|
7fdf80 |
ENROLLER_SIZE=$(stat --format=%s -- "$ENROLLER_BINARY")
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# add 1MB then 10% for metadata
|
|
|
7fdf80 |
UEFI_SHELL_IMAGE_KB=$((
|
|
|
7fdf80 |
(UEFI_SHELL_SIZE + ENROLLER_SIZE + 1 * 1024 * 1024) * 11 / 10 / 1024
|
|
|
7fdf80 |
))
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# create non-partitioned FAT image
|
|
|
7fdf80 |
rm -f -- "$UEFI_SHELL_IMAGE"
|
|
|
7fdf80 |
mkdosfs -C "$UEFI_SHELL_IMAGE" -n UEFI_SHELL -- "$UEFI_SHELL_IMAGE_KB"
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# copy the shell binary into the FAT image
|
|
|
7fdf80 |
export MTOOLS_SKIP_CHECK=1
|
|
|
7fdf80 |
mmd -i "$UEFI_SHELL_IMAGE" ::efi
|
|
|
7fdf80 |
mmd -i "$UEFI_SHELL_IMAGE" ::efi/boot
|
|
|
7fdf80 |
mcopy -i "$UEFI_SHELL_IMAGE" "$UEFI_SHELL_BINARY" ::efi/boot/bootx64.efi
|
|
|
7fdf80 |
mcopy -i "$UEFI_SHELL_IMAGE" "$ENROLLER_BINARY" ::
|
|
|
7fdf80 |
mdir -i "$UEFI_SHELL_IMAGE" -/ ::
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# build ISO with FAT image file as El Torito EFI boot image
|
|
|
7fdf80 |
genisoimage -input-charset ASCII -J -rational-rock \
|
|
|
7fdf80 |
-efi-boot "$UEFI_SHELL_IMAGE" -no-emul-boot \
|
|
|
7fdf80 |
-o "$ISO_IMAGE" -- "$UEFI_SHELL_IMAGE"
|
|
|
7fdf80 |
)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Enroll the default certificates in a separate variable store template.
|
|
|
7fdf80 |
%{__python3} ovmf-vars-generator --verbose --verbose \
|
|
|
7fdf80 |
--qemu-binary /usr/libexec/qemu-kvm \
|
|
|
7fdf80 |
--ovmf-binary Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_CODE.fd \
|
|
|
7fdf80 |
--ovmf-template-vars Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_VARS.fd \
|
|
|
7fdf80 |
--uefi-shell-iso UefiShell.iso \
|
|
|
1dc609 |
--oem-string "$(< PkKek1.oemstr)" \
|
|
|
7fdf80 |
--skip-testing \
|
|
|
7fdf80 |
OVMF_VARS.secboot.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
# Build with a verbose debug mask first, and stash the binary.
|
|
|
7fdf80 |
build ${CC_FLAGS} -a AARCH64 \
|
|
|
7fdf80 |
-p ArmVirtPkg/ArmVirtQemu.dsc \
|
|
|
7fdf80 |
-D DEBUG_PRINT_ERROR_LEVEL=0x8040004F
|
|
|
7fdf80 |
cp -a Build/ArmVirtQemu-AARCH64/DEBUG_%{TOOLCHAIN}/FV/QEMU_EFI.fd \
|
|
|
7fdf80 |
QEMU_EFI.verbose.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Rebuild with a silent (errors only) debug mask.
|
|
|
7fdf80 |
build ${CC_FLAGS} -a AARCH64 \
|
|
|
7fdf80 |
-p ArmVirtPkg/ArmVirtQemu.dsc \
|
|
|
7fdf80 |
-D DEBUG_PRINT_ERROR_LEVEL=0x80000000
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%install
|
|
|
7fdf80 |
|
|
|
1dc609 |
cp -a OvmfPkg/License.txt License.OvmfPkg.txt
|
|
|
7fdf80 |
mkdir -p $RPM_BUILD_ROOT%{_datadir}/qemu/firmware
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
mkdir -p \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/OVMF \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# We don't ship the SB-less, SMM-less binary.
|
|
|
7fdf80 |
%if 0
|
|
|
7fdf80 |
install -m 0644 Build/OvmfX64/DEBUG_%{TOOLCHAIN}/FV/OVMF_CODE.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/OVMF_CODE.fd
|
|
|
7fdf80 |
ln -s ../%{name}/ovmf/OVMF_CODE.fd $RPM_BUILD_ROOT%{_datadir}/OVMF/
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
install -m 0644 Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_CODE.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/OVMF_CODE.secboot.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
install -m 0644 Build/OvmfX64/DEBUG_%{TOOLCHAIN}/FV/OVMF_VARS.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/OVMF_VARS.fd
|
|
|
7fdf80 |
install -m 0644 OVMF_VARS.secboot.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/OVMF_VARS.secboot.fd
|
|
|
7fdf80 |
install -m 0644 UefiShell.iso \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/UefiShell.iso
|
|
|
7fdf80 |
|
|
|
7fdf80 |
ln -s ../%{name}/ovmf/OVMF_CODE.secboot.fd $RPM_BUILD_ROOT%{_datadir}/OVMF/
|
|
|
7fdf80 |
ln -s ../%{name}/ovmf/OVMF_VARS.fd $RPM_BUILD_ROOT%{_datadir}/OVMF/
|
|
|
7fdf80 |
ln -s ../%{name}/ovmf/OVMF_VARS.secboot.fd $RPM_BUILD_ROOT%{_datadir}/OVMF/
|
|
|
7fdf80 |
ln -s ../%{name}/ovmf/UefiShell.iso $RPM_BUILD_ROOT%{_datadir}/OVMF/
|
|
|
7fdf80 |
|
|
|
7fdf80 |
install -m 0644 Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/X64/Shell.efi \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/Shell.efi
|
|
|
7fdf80 |
install -m 0644 Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/X64/EnrollDefaultKeys.efi \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/ovmf/EnrollDefaultKeys.efi
|
|
|
7fdf80 |
|
|
|
7fdf80 |
install -m 0644 edk2-ovmf-sb.json \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/qemu/firmware/40-edk2-ovmf-sb.json
|
|
|
7fdf80 |
install -m 0644 edk2-ovmf.json \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/qemu/firmware/50-edk2-ovmf.json
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
mkdir -p \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/AAVMF \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Pad and install the verbose binary.
|
|
|
7fdf80 |
cat QEMU_EFI.verbose.fd \
|
|
|
7fdf80 |
/dev/zero \
|
|
|
7fdf80 |
| head -c 64m \
|
|
|
7fdf80 |
> $RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/QEMU_EFI-pflash.raw
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Pad and install the silent (default) binary.
|
|
|
7fdf80 |
cat Build/ArmVirtQemu-AARCH64/DEBUG_%{TOOLCHAIN}/FV/QEMU_EFI.fd \
|
|
|
7fdf80 |
/dev/zero \
|
|
|
7fdf80 |
| head -c 64m \
|
|
|
7fdf80 |
> $RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/QEMU_EFI-silent-pflash.raw
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# Create varstore template.
|
|
|
7fdf80 |
cat Build/ArmVirtQemu-AARCH64/DEBUG_%{TOOLCHAIN}/FV/QEMU_VARS.fd \
|
|
|
7fdf80 |
/dev/zero \
|
|
|
7fdf80 |
| head -c 64m \
|
|
|
7fdf80 |
> $RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/vars-template-pflash.raw
|
|
|
7fdf80 |
|
|
|
7fdf80 |
ln -s ../%{name}/aarch64/QEMU_EFI-pflash.raw \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/AAVMF/AAVMF_CODE.verbose.fd
|
|
|
7fdf80 |
ln -s ../%{name}/aarch64/QEMU_EFI-silent-pflash.raw \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/AAVMF/AAVMF_CODE.fd
|
|
|
7fdf80 |
ln -s ../%{name}/aarch64/vars-template-pflash.raw \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/AAVMF/AAVMF_VARS.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
chmod 0644 -- $RPM_BUILD_ROOT%{_datadir}/AAVMF/AAVMF_*.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
install -m 0644 QEMU_EFI.verbose.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/QEMU_EFI.fd
|
|
|
7fdf80 |
install -m 0644 Build/ArmVirtQemu-AARCH64/DEBUG_%{TOOLCHAIN}/FV/QEMU_EFI.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/QEMU_EFI.silent.fd
|
|
|
7fdf80 |
install -m 0644 Build/ArmVirtQemu-AARCH64/DEBUG_%{TOOLCHAIN}/FV/QEMU_VARS.fd \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/%{name}/aarch64/QEMU_VARS.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
install -m 0644 edk2-aarch64.json \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/qemu/firmware/60-edk2-aarch64.json
|
|
|
7fdf80 |
install -m 0644 edk2-aarch64-verbose.json \
|
|
|
7fdf80 |
$RPM_BUILD_ROOT%{_datadir}/qemu/firmware/70-edk2-aarch64-verbose.json
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
cp -a CryptoPkg/Library/OpensslLib/openssl/LICENSE LICENSE.openssl
|
|
|
7fdf80 |
|
|
|
7fdf80 |
# install the tools
|
|
|
7fdf80 |
mkdir -p %{buildroot}%{_bindir} \
|
|
|
7fdf80 |
%{buildroot}%{_datadir}/%{name}/Conf \
|
|
|
7fdf80 |
%{buildroot}%{_datadir}/%{name}/Scripts
|
|
|
7fdf80 |
install BaseTools/Source/C/bin/* \
|
|
|
7fdf80 |
%{buildroot}%{_bindir}
|
|
|
7fdf80 |
install BaseTools/BinWrappers/PosixLike/LzmaF86Compress \
|
|
|
7fdf80 |
%{buildroot}%{_bindir}
|
|
|
7fdf80 |
install BaseTools/BuildEnv \
|
|
|
7fdf80 |
%{buildroot}%{_datadir}/%{name}
|
|
|
7fdf80 |
install BaseTools/Conf/*.template \
|
|
|
7fdf80 |
%{buildroot}%{_datadir}/%{name}/Conf
|
|
|
7fdf80 |
install BaseTools/Scripts/GccBase.lds \
|
|
|
7fdf80 |
%{buildroot}%{_datadir}/%{name}/Scripts
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
%files ovmf
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
%files aarch64
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%defattr(-,root,root,-)
|
|
|
1dc609 |
%license License.txt
|
|
|
1dc609 |
%license License.OvmfPkg.txt
|
|
|
1dc609 |
%license License-History.txt
|
|
|
7fdf80 |
%license LICENSE.openssl
|
|
|
7fdf80 |
%dir %{_datadir}/%{name}/
|
|
|
7fdf80 |
%dir %{_datadir}/qemu
|
|
|
7fdf80 |
%dir %{_datadir}/qemu/firmware
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
%doc OvmfPkg/README
|
|
|
7fdf80 |
%doc ovmf-whitepaper-c770f8c.txt
|
|
|
7fdf80 |
%dir %{_datadir}/OVMF/
|
|
|
7fdf80 |
%dir %{_datadir}/%{name}/ovmf/
|
|
|
7fdf80 |
%if 0
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/OVMF_CODE.fd
|
|
|
7fdf80 |
%{_datadir}/OVMF/OVMF_CODE.fd
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/OVMF_CODE.secboot.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/OVMF_VARS.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/OVMF_VARS.secboot.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/UefiShell.iso
|
|
|
7fdf80 |
%{_datadir}/OVMF/OVMF_CODE.secboot.fd
|
|
|
7fdf80 |
%{_datadir}/OVMF/OVMF_VARS.fd
|
|
|
7fdf80 |
%{_datadir}/OVMF/OVMF_VARS.secboot.fd
|
|
|
7fdf80 |
%{_datadir}/OVMF/UefiShell.iso
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/Shell.efi
|
|
|
7fdf80 |
%{_datadir}/%{name}/ovmf/EnrollDefaultKeys.efi
|
|
|
7fdf80 |
%{_datadir}/qemu/firmware/40-edk2-ovmf-sb.json
|
|
|
7fdf80 |
%{_datadir}/qemu/firmware/50-edk2-ovmf.json
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
%dir %{_datadir}/AAVMF/
|
|
|
7fdf80 |
%dir %{_datadir}/%{name}/aarch64/
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/QEMU_EFI-pflash.raw
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/QEMU_EFI-silent-pflash.raw
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/vars-template-pflash.raw
|
|
|
7fdf80 |
%{_datadir}/AAVMF/AAVMF_CODE.verbose.fd
|
|
|
7fdf80 |
%{_datadir}/AAVMF/AAVMF_CODE.fd
|
|
|
7fdf80 |
%{_datadir}/AAVMF/AAVMF_VARS.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/QEMU_EFI.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/QEMU_EFI.silent.fd
|
|
|
7fdf80 |
%{_datadir}/%{name}/aarch64/QEMU_VARS.fd
|
|
|
7fdf80 |
%{_datadir}/qemu/firmware/60-edk2-aarch64.json
|
|
|
7fdf80 |
%{_datadir}/qemu/firmware/70-edk2-aarch64-verbose.json
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%files tools
|
|
|
7fdf80 |
%license License.txt
|
|
|
1dc609 |
%license License-History.txt
|
|
|
7fdf80 |
%{_bindir}/Brotli
|
|
|
7fdf80 |
%{_bindir}/DevicePath
|
|
|
7fdf80 |
%{_bindir}/EfiRom
|
|
|
7fdf80 |
%{_bindir}/GenCrc32
|
|
|
7fdf80 |
%{_bindir}/GenFfs
|
|
|
7fdf80 |
%{_bindir}/GenFv
|
|
|
7fdf80 |
%{_bindir}/GenFw
|
|
|
7fdf80 |
%{_bindir}/GenSec
|
|
|
7fdf80 |
%{_bindir}/LzmaCompress
|
|
|
7fdf80 |
%{_bindir}/LzmaF86Compress
|
|
|
7fdf80 |
%{_bindir}/Split
|
|
|
7fdf80 |
%{_bindir}/TianoCompress
|
|
|
7fdf80 |
%{_bindir}/VfrCompile
|
|
|
7fdf80 |
%{_bindir}/VolInfo
|
|
|
7fdf80 |
%dir %{_datadir}/%{name}
|
|
|
7fdf80 |
%{_datadir}/%{name}/BuildEnv
|
|
|
7fdf80 |
%{_datadir}/%{name}/Conf
|
|
|
7fdf80 |
%{_datadir}/%{name}/Scripts
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%files tools-doc
|
|
|
7fdf80 |
%doc BaseTools/UserManuals/*.rtf
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%check
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%ifarch x86_64
|
|
|
7fdf80 |
# Of the installed host kernels, boot the one with the highest Version-Release
|
|
|
7fdf80 |
# under OVMF, and check if it prints "Secure boot enabled".
|
|
|
7fdf80 |
KERNEL_PKG=$(rpm -q kernel-core | rpmdev-sort | tail -n 1)
|
|
|
7fdf80 |
KERNEL_IMG=$(rpm -q -l $KERNEL_PKG | egrep '^/lib/modules/[^/]+/vmlinuz$')
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%{__python3} ovmf-vars-generator --verbose --verbose \
|
|
|
7fdf80 |
--qemu-binary /usr/libexec/qemu-kvm \
|
|
|
7fdf80 |
--ovmf-binary Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_CODE.fd \
|
|
|
7fdf80 |
--ovmf-template-vars Build/Ovmf3264/DEBUG_%{TOOLCHAIN}/FV/OVMF_VARS.fd \
|
|
|
7fdf80 |
--uefi-shell-iso UefiShell.iso \
|
|
|
7fdf80 |
--kernel-path $KERNEL_IMG \
|
|
|
7fdf80 |
--skip-enrollment \
|
|
|
7fdf80 |
--no-download \
|
|
|
7fdf80 |
OVMF_VARS.secboot.fd
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%else
|
|
|
7fdf80 |
true
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%endif
|
|
|
7fdf80 |
|
|
|
7fdf80 |
%changelog
|
|
|
1dc609 |
* Wed Dec 11 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190829git37eef91017ad-4.el8
|
|
|
1dc609 |
- edk2-redhat-set-guest-RAM-size-to-768M-for-SB-varstore-te.patch [bz#1778301]
|
|
|
1dc609 |
- edk2-redhat-re-enable-Secure-Boot-varstore-template-verif.patch [bz#1778301]
|
|
|
1dc609 |
- Resolves: bz#1778301
|
|
|
1dc609 |
(re-enable Secure Boot (varstore template) verification in %check)
|
|
|
1dc609 |
|
|
|
1dc609 |
* Thu Dec 05 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190829git37eef91017ad-3.el8
|
|
|
1dc609 |
- Update used openssl version [bz#1616029]
|
|
|
1dc609 |
- Resolves: bz#1616029
|
|
|
1dc609 |
(rebuild edk2 against the final RHEL-8.2.0 version of OpenSSL-1.1.1)
|
|
|
1dc609 |
|
|
|
1dc609 |
* Mon Dec 02 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190829git37eef91017ad-2.el8
|
|
|
1dc609 |
- edk2-MdePkg-Include-Protocol-Tls.h-Add-the-data-type-of-E.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-CryptoPkg-TlsLib-Add-the-new-API-TlsSetVerifyHost-CV.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-CryptoPkg-Crt-turn-strchr-into-a-function-CVE-2019-1.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-CryptoPkg-Crt-satisfy-inet_pton.c-dependencies-CVE-2.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-CryptoPkg-Crt-import-inet_pton.c-CVE-2019-14553.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-CryptoPkg-TlsLib-TlsSetVerifyHost-parse-IP-address-l.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-NetworkPkg-TlsDxe-Add-the-support-of-host-validation.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-NetworkPkg-HttpDxe-Set-the-HostName-for-the-verifica.patch [bz#1536624]
|
|
|
1dc609 |
- edk2-redhat-enable-HTTPS-Boot.patch [bz#1536624]
|
|
|
1dc609 |
- Resolves: bz#1536624
|
|
|
1dc609 |
(HTTPS enablement in OVMF)
|
|
|
1dc609 |
|
|
|
1dc609 |
* Fri Nov 29 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190829git37eef91017ad-1.el8
|
|
|
1dc609 |
- Rebase to edk2-stable201908 [bz#1748180]
|
|
|
1dc609 |
- Resolves: bz#1748180
|
|
|
1dc609 |
((edk2-rebase-rhel-8.2) - rebase edk2 to upstream tag edk2-stable201908 for RHEL-8.2)
|
|
|
1dc609 |
|
|
|
1dc609 |
* Mon Aug 05 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190308git89910a39dcfd-6.el8
|
|
|
1dc609 |
- edk2-ArmVirtPkg-silence-DEBUG_VERBOSE-masking-0x00400000-.patch [bz#1714446]
|
|
|
1dc609 |
- edk2-OvmfPkg-QemuRamfbDxe-Do-not-report-DXE-failure-on-Aa.patch [bz#1714446]
|
|
|
1dc609 |
- edk2-ArmPkg-DebugPeCoffExtraActionLib-debugger-commands-a.patch [bz#1714446]
|
|
|
1dc609 |
- Resolves: bz#1714446
|
|
|
1dc609 |
(edk2-aarch64 silent build is not silent enough)
|
|
|
1dc609 |
|
|
|
1dc609 |
* Tue Jul 02 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190308git89910a39dcfd-5.el8
|
|
|
1dc609 |
- edk2-redhat-add-D-TPM2_ENABLE-to-the-edk2-ovmf-build-flag.patch [bz#1693205]
|
|
|
1dc609 |
- Resolves: bz#1693205
|
|
|
1dc609 |
(edk2: Enable TPM2 support)
|
|
|
1dc609 |
|
|
|
7fdf80 |
* Tue Jun 11 2019 Miroslav Rezanina <mrezanin@redhat.com> - 20190308git89910a39dcfd-4.el8
|
|
|
7fdf80 |
- edk2-OvmfPkg-raise-the-PCIEXBAR-base-to-2816-MB-on-Q35.patch [bz#1666941]
|
|
|
7fdf80 |
- edk2-OvmfPkg-PlatformPei-set-32-bit-UC-area-at-PciBase-Pc.patch [bz#1666941]
|
|
|
7fdf80 |
- Resolves: bz#1666941
|
|
|
7fdf80 |
(UEFI guest cannot boot into os when setting some special memory size)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Apr 09 2019 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20190308git89910a39dcfd-2.el8
|
|
|
7fdf80 |
- edk2-redhat-provide-firmware-descriptor-meta-files.patch [bz#1600230]
|
|
|
7fdf80 |
- Resolves: bz#1600230
|
|
|
7fdf80 |
([RHEL 8.1] RFE: provide firmware descriptor meta-files for the edk2-ovmf and edk2-aarch64 firmware images)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Mon Jan 21 2019 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-9.el8
|
|
|
7fdf80 |
- edk2-BaseTools-Fix-UEFI-and-Tiano-Decompression-logic-iss.patch [bz#1662184]
|
|
|
7fdf80 |
- edk2-MdePkg-BaseUefiDecompressLib-Fix-UEFI-Decompression-.patch [bz#1662184]
|
|
|
7fdf80 |
- edk2-IntelFrameworkModulePkg-Fix-UEFI-and-Tiano-Decompres.patch [bz#1662184]
|
|
|
7fdf80 |
- edk2-git-Use-HTTPS-support.patch []
|
|
|
7fdf80 |
- Resolves: bz#1662184
|
|
|
7fdf80 |
(backport fix for (theoretical?) regression introduced by earlier CVE fixes)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Nov 21 2018 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-8.el8
|
|
|
7fdf80 |
- edk2-NetworkPkg-UefiPxeBcDxe-Add-EXCLUSIVE-attribute-when.patch [bz#1643377]
|
|
|
7fdf80 |
- Resolves: bz#1643377
|
|
|
7fdf80 |
(Exception when grubx64.efi used for UEFI netboot)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Nov 06 2018 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-5.el8
|
|
|
7fdf80 |
- edk2-MdeModulePkg-Variable-Fix-Timestamp-zeroing-issue-on.patch [bz#1641436]
|
|
|
7fdf80 |
- edk2-MdePkg-Add-more-checker-in-UefiDecompressLib-to-acce.patch [bz#1641449 bz#1641453 bz#1641464 bz#1641469]
|
|
|
7fdf80 |
- edk2-IntelFrameworkModulePkg-Add-more-checker-in-UefiTian.patch [bz#1641453 bz#1641464 bz#1641469]
|
|
|
7fdf80 |
- edk2-BaseTools-Add-more-checker-in-Decompress-algorithm-t.patch [bz#1641445 bz#1641453 bz#1641464 bz#1641469]
|
|
|
7fdf80 |
- Resolves: bz#1641436
|
|
|
7fdf80 |
(CVE-2018-3613 edk2: Logic error in MdeModulePkg in EDK II firmware allows for privilege escalation by authenticated users [rhel-8])
|
|
|
7fdf80 |
- Resolves: bz#1641445
|
|
|
7fdf80 |
(CVE-2017-5731 edk2: Privilege escalation via processing of malformed files in TianoCompress.c [rhel-8])
|
|
|
7fdf80 |
- Resolves: bz#1641449
|
|
|
7fdf80 |
(CVE-2017-5732 edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c [rhel-8])
|
|
|
7fdf80 |
- Resolves: bz#1641453
|
|
|
7fdf80 |
(CVE-2017-5733 edk2: Privilege escalation via heap-based buffer overflow in MakeTable() function [rhel-8])
|
|
|
7fdf80 |
- Resolves: bz#1641464
|
|
|
7fdf80 |
(CVE-2017-5734 edk2: Privilege escalation via stack-based buffer overflow in MakeTable() function [rhel-8])
|
|
|
7fdf80 |
- Resolves: bz#1641469
|
|
|
7fdf80 |
(CVE-2017-5735 edk2: Privilege escalation via heap-based buffer overflow in Decode() function [rhel-8])
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Sep 04 2018 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-5.el8
|
|
|
7fdf80 |
- edk2-BaseTools-footer.makefile-expand-BUILD_CFLAGS-last-f.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-BaseTools-header.makefile-remove-c-from-BUILD_CFLAGS.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-BaseTools-Source-C-split-O2-to-BUILD_OPTFLAGS.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-BaseTools-Source-C-take-EXTRA_OPTFLAGS-from-the-call.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-BaseTools-Source-C-take-EXTRA_LDFLAGS-from-the-calle.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-BaseTools-VfrCompile-honor-EXTRA_LDFLAGS.patch [bz#1607906]
|
|
|
7fdf80 |
- edk2-redhat-inject-the-RPM-compile-and-link-options-to-th.patch [bz#1607906]
|
|
|
7fdf80 |
- Resolves: bz#1607906
|
|
|
7fdf80 |
(edk2-tools: Does not use RPM build flags)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Aug 08 2018 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-4.el8
|
|
|
7fdf80 |
- edk2-redhat-provide-virtual-bundled-OpenSSL-in-edk2-ovmf-.patch [bz#1607801]
|
|
|
7fdf80 |
- Resolves: bz#1607801
|
|
|
7fdf80 |
(add 'Provides: bundled(openssl) = 1.1.0h' to the spec file)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Jul 24 2018 Danilo Cesar Lemes de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-3.el8
|
|
|
7fdf80 |
- edk2-redhat-Provide-and-Obsolete-OVMF-and-AAVMF.patch [bz#1596148]
|
|
|
7fdf80 |
- edk2-ArmVirtPkg-unify-HttpLib-resolutions-in-ArmVirt.dsc..patch [bz#1536627]
|
|
|
7fdf80 |
- edk2-ArmVirtPkg-ArmVirtQemu-enable-the-IPv6-stack.patch [bz#1536627]
|
|
|
7fdf80 |
- edk2-advertise-OpenSSL-due-to-IPv6-enablement-too-RHEL-on.patch [bz#1536627]
|
|
|
7fdf80 |
- edk2-redhat-add-D-NETWORK_IP6_ENABLE-to-the-build-flags.patch [bz#1536627]
|
|
|
7fdf80 |
- edk2-redhat-update-license-fields-and-files-in-the-spec-f.patch [bz#1536627]
|
|
|
7fdf80 |
- Resolves: bz#1536627
|
|
|
7fdf80 |
(IPv6 enablement in OVMF)
|
|
|
7fdf80 |
- Resolves: bz#1596148
|
|
|
7fdf80 |
(restore Provides/Obsoletes macros for OVMF and AAVMF, from RHEL-8 Alpha)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Jul 10 2018 Danilo C. L. de Paula <ddepaula@redhat.com> - 20180508gitee3198e672e2-2.el8
|
|
|
7fdf80 |
- Rebase edk2 on top of 20180508gitee3198e672e2
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Jun 08 2018 Miroslav Rezanina <mrezanin@redhat.com> - 20180508-2.gitee3198e672e2
|
|
|
7fdf80 |
- OvmfPkg/PlatformBootManagerLib: connect consoles unconditionally [bz#1577546]
|
|
|
7fdf80 |
- build OVMF varstore template with SB enabled / certs enrolled [bz#1561128]
|
|
|
7fdf80 |
- connect Virtio RNG devices again [bz#1579518]
|
|
|
7fdf80 |
- Resolves: bz#1577546
|
|
|
7fdf80 |
(no input consoles connected under certain circumstances)
|
|
|
7fdf80 |
- Resolves: bz#1561128
|
|
|
7fdf80 |
(OVMF Secure boot enablement (enrollment of default keys))
|
|
|
7fdf80 |
- Resolves: bz#1579518
|
|
|
7fdf80 |
(EFI_RNG_PROTOCOL no longer produced for virtio-rng)
|
|
|
7fdf80 |
* Wed Dec 06 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20171011-4.git92d07e48907f.el7
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-Core-Dxe-log-informative-memprotect-msg.patch [bz#1520485]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-BdsDxe-fall-back-to-a-Boot-Manager-Menu.patch [bz#1515418]
|
|
|
7fdf80 |
- Resolves: bz#1515418
|
|
|
7fdf80 |
(RFE: Provide diagnostics for failed boot)
|
|
|
7fdf80 |
- Resolves: bz#1520485
|
|
|
7fdf80 |
(AAVMF: two new messages with silent build)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Dec 01 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20171011-3.git92d07e48907f.el7
|
|
|
7fdf80 |
- ovmf-UefiCpuPkg-CpuDxe-Fix-multiple-entries-of-RT_CODE-in.patch [bz#1518308]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-DxeCore-Filter-out-all-paging-capabilit.patch [bz#1518308]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-Core-Merge-memory-map-after-filtering-p.patch [bz#1518308]
|
|
|
7fdf80 |
- Resolves: bz#1518308
|
|
|
7fdf80 |
(UEFI memory map regression (runtime code entry splitting) introduced by c1cab54ce57c)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Mon Nov 27 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20171011-2.git92d07e48907f.el7
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-Bds-Remove-assertion-in-BmCharToUint.patch [bz#1513632]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-Bds-Check-variable-name-even-if-OptionN.patch [bz#1513632]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-PciBus-Fix-bug-that-PCI-BUS-claims-too-.patch [bz#1514105]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-make-it-a-proper-BASE-library.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-create-a-separate-PlatformDebugLibIoPort-ins.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-save-on-I-O-port-accesses-when-the-debug-por.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-enable-DEBUG_VERBOSE-RHEL-only.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-silence-EFI_D_VERBOSE-0x00400000-in-QemuVide.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-silence-EFI_D_VERBOSE-0x00400000-in-NvmExpre.patch [bz#1488247]
|
|
|
7fdf80 |
- ovmf-Revert-redhat-introduce-separate-silent-and-verbose-.patch [bz#1488247]
|
|
|
7fdf80 |
- Resolves: bz#1488247
|
|
|
7fdf80 |
(make debug logging no-op unless a debug console is active)
|
|
|
7fdf80 |
- Resolves: bz#1513632
|
|
|
7fdf80 |
([RHEL-ALT 7.5] AAVMF fails to boot after setting BootNext)
|
|
|
7fdf80 |
- Resolves: bz#1514105
|
|
|
7fdf80 |
(backport edk2 commit 6e3287442774 so that PciBusDxe not over-claim resources)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Oct 18 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20171011-1.git92d07e48907f.el7
|
|
|
7fdf80 |
- Rebase to 92d07e48907f [bz#1469787]
|
|
|
7fdf80 |
- Resolves: bz#1469787
|
|
|
7fdf80 |
((ovmf-rebase-rhel-7.5) Rebase OVMF for RHEL-7.5)
|
|
|
7fdf80 |
- Resolves: bz#1434740
|
|
|
7fdf80 |
(OvmfPkg/PciHotPlugInitDxe: don't reserve IO space when IO support is disabled)
|
|
|
7fdf80 |
- Resolves: bz#1434747
|
|
|
7fdf80 |
([Q35] code12 error when hotplug x710 device in win2016)
|
|
|
7fdf80 |
- Resolves: bz#1447027
|
|
|
7fdf80 |
(Guest cannot boot with 240 or above vcpus when using ovmf)
|
|
|
7fdf80 |
- Resolves: bz#1458192
|
|
|
7fdf80 |
([Q35] recognize "usb-storage" devices in XHCI ports)
|
|
|
7fdf80 |
- Resolves: bz#1468526
|
|
|
7fdf80 |
(>1TB RAM support)
|
|
|
7fdf80 |
- Resolves: bz#1488247
|
|
|
7fdf80 |
(provide "OVMF_CODE.secboot.verbose.fd" for log capturing; silence "OVMF_CODE.secboot.fd")
|
|
|
7fdf80 |
- Resolves: bz#1496170
|
|
|
7fdf80 |
(Inconsistent MOR control variables exposed by OVMF, breaks Windows Device Guard)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri May 12 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20170228-5.gitc325e41585e3.el7
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-update-SignatureOwner-GUID.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-expose-CertType-parameter-.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-blacklist-empty-file-in-db.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-introduce-the-FD_SIZE_IN_KB-macro-build-flag.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-OvmfPkg.fdf.inc-extract-VARS_LIVE_SIZE-and-V.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-introduce-4MB-flash-image-mainly-for-Windows.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-raise-max-variable-size-auth-non-auth-to-33K.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-PlatformPei-handle-non-power-of-two-spare-si.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-redhat-update-local-build-instructions-with-D-FD_SIZ.patch [bz#1443351]
|
|
|
7fdf80 |
- ovmf-redhat-update-OVMF-build-commands-with-D-FD_SIZE_4MB.patch [bz#1443351]
|
|
|
7fdf80 |
- Resolves: bz#1443351
|
|
|
7fdf80 |
([svvp][ovmf] job "Secure Boot Logo Test" failed with q35&ovmf)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Apr 28 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20170228-4.gitc325e41585e3.el7
|
|
|
7fdf80 |
- ovmf-ShellPkg-Shell-clean-up-bogus-member-types-in-SPLIT_.patch [bz#1442908]
|
|
|
7fdf80 |
- ovmf-ShellPkg-Shell-eliminate-double-free-in-RunSplitComm.patch [bz#1442908]
|
|
|
7fdf80 |
- Resolves: bz#1442908
|
|
|
7fdf80 |
(Guest hang when running a wrong command in Uefishell)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Apr 04 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20170228-3.gitc325e41585e3.el7
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-FdtClientDxe-supplement-missing-EFIAPI-ca.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-ArmVirtPL031FdtClientLib-unconditionally-.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-RamDiskDxe-fix-C-string-literal-catenat.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-EmbeddedPkg-introduce-EDKII-Platform-Has-ACPI-GUID.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-EmbeddedPkg-introduce-PlatformHasAcpiLib.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-EmbeddedPkg-introduce-EDKII-Platform-Has-Device-Tree.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-add-PlatformHasAcpiDtDxe.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-enable-AcpiTableDxe-and-EFI_ACPI_TABLE_PR.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-FdtClientDxe-install-DT-as-sysconfig-tabl.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-PlatformHasAcpiDtDxe-don-t-expose-DT-if-Q.patch [bz#1430262]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-remove-PURE_ACPI_BOOT_ENABLE-and-PcdPureA.patch [bz#1430262]
|
|
|
7fdf80 |
- Resolves: bz#1430262
|
|
|
7fdf80 |
(AAVMF: forward QEMU's DT to the guest OS only if ACPI payload is unavailable)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Mon Mar 27 2017 Miroslav Rezanina <mrezanin@redhat.com> - 20170228-2.gitc325e41585e3.el7
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-Core-Dxe-downgrade-CodeSegmentCount-is-.patch [bz#1433428]
|
|
|
7fdf80 |
- Resolves: bz#1433428
|
|
|
7fdf80 |
(AAVMF: Fix error message during ARM guest VM installation)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Mar 08 2017 Laszlo Ersek <lersek@redhat.com> - ovmf-20170228-1.gitc325e41585e3.el7
|
|
|
7fdf80 |
- Rebase to upstream c325e41585e3 [bz#1416919]
|
|
|
7fdf80 |
- Resolves: bz#1373812
|
|
|
7fdf80 |
(guest boot from network even set 'boot order=1' for virtio disk with OVMF)
|
|
|
7fdf80 |
- Resolves: bz#1380282
|
|
|
7fdf80 |
(Update OVMF to openssl-1.0.2k-hobbled)
|
|
|
7fdf80 |
- Resolves: bz#1412313
|
|
|
7fdf80 |
(select broadcast SMI if available)
|
|
|
7fdf80 |
- Resolves: bz#1416919
|
|
|
7fdf80 |
(Rebase OVMF for RHEL-7.4)
|
|
|
7fdf80 |
- Resolves: bz#1426330
|
|
|
7fdf80 |
(disable libssl in CryptoPkg)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Mon Sep 12 2016 Laszlo Ersek <lersek@redhat.com> - ovmf-20160608b-1.git988715a.el7
|
|
|
7fdf80 |
- rework downstream-only commit dde83a75b566 "setup the tree for the secure
|
|
|
7fdf80 |
boot feature (RHEL only)", excluding patent-encumbered files from the
|
|
|
7fdf80 |
upstream OpenSSL 1.0.2g tarball [bz#1374710]
|
|
|
7fdf80 |
- rework downstream-only commit dfc3ca1ee509 "CryptoPkg/OpensslLib: Upgrade
|
|
|
7fdf80 |
OpenSSL version to 1.0.2h", excluding patent-encumbered files from the
|
|
|
7fdf80 |
upstream OpenSSL 1.0.2h tarball [bz#1374710]
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Aug 04 2016 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20160608-3.git988715a.el7
|
|
|
7fdf80 |
- ovmf-MdePkg-PCI-Add-missing-PCI-PCIE-definitions.patch [bz#1332408]
|
|
|
7fdf80 |
- ovmf-ArmPlatformPkg-NorFlashDxe-accept-both-non-secure-an.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-ArmVirtQemu-switch-secure-boot-build-to-N.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmPlatformPkg-NorFlashAuthenticatedDxe-remove-this-.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-add-FDF-definition-for-empty-varstore.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-redhat-package-the-varstore-template-produced-by-the.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-Re-add-the-Driver-Health-Manager.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-HighMemDxe-allow-patchable-PCD-for-PcdSys.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-ArmVirtQemuKernel-make-ACPI-support-AARCH.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-align-ArmVirtQemuKernel-with-ArmVirtQemu.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-ArmVirtQemu-factor-out-shared-FV.FvMain-d.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-factor-out-Rules-FDF-section.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-add-name-GUIDs-to-FvMain-instances.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-add-a-Name-GUID-to-each-Firmware-Volume.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-PlatformBootManagerLib-remove-stale-FvFile-b.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-MdePkg-IndustryStandard-introduce-EFI_PCI_CAPABILITY.patch [bz#1332408]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-PciBusDxe-look-for-the-right-capability.patch [bz#1332408]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-PciBusDxe-recognize-hotplug-capable-PCI.patch [bz#1332408]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-add-PciHotPlugInitDxe.patch [bz#1332408]
|
|
|
7fdf80 |
- ovmf-ArmPkg-ArmGicLib-manage-GICv3-SPI-state-at-the-distr.patch [bz#1356655]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-PlatformBootManagerLib-remove-stale-FvFil.patch [bz#1353494]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-assign-Status-before-readi.patch [bz#1356913]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-silence-VS2015x86-warning-.patch [bz#1356913]
|
|
|
7fdf80 |
- ovmf-CryptoPkg-update-openssl-to-ignore-RVCT-3079.patch [bz#1356184]
|
|
|
7fdf80 |
- ovmf-CryptoPkg-Fix-typos-in-comments.patch [bz#1356184]
|
|
|
7fdf80 |
- ovmf-CryptoPkg-BaseCryptLib-Avoid-passing-NULL-ptr-to-fun.patch [bz#1356184]
|
|
|
7fdf80 |
- ovmf-CryptoPkg-BaseCryptLib-Init-the-content-of-struct-Ce.patch [bz#1356184]
|
|
|
7fdf80 |
- ovmf-CryptoPkg-OpensslLib-Upgrade-OpenSSL-version-to-1.0..patch [bz#1356184]
|
|
|
7fdf80 |
- Resolves: bz#1332408
|
|
|
7fdf80 |
(Q35 machine can not hot-plug scsi controller under switch)
|
|
|
7fdf80 |
- Resolves: bz#1353494
|
|
|
7fdf80 |
([OVMF] "EFI Internal Shell" should be removed from "Boot Manager")
|
|
|
7fdf80 |
- Resolves: bz#1356184
|
|
|
7fdf80 |
(refresh embedded OpenSSL to 1.0.2h)
|
|
|
7fdf80 |
- Resolves: bz#1356655
|
|
|
7fdf80 |
(AAVMF: stop accessing unmapped gicv3 registers)
|
|
|
7fdf80 |
- Resolves: bz#1356913
|
|
|
7fdf80 |
(fix use-without-initialization in EnrollDefaultKeys.efi)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Jul 12 2016 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20160608-2.git988715a.el7
|
|
|
7fdf80 |
- ovmf-ArmPkg-ArmGicV3Dxe-configure-all-interrupts-as-non-s.patch [bz#1349407]
|
|
|
7fdf80 |
- ovmf-ArmVirtPkg-PlatformBootManagerLib-Postpone-the-shell.patch [bz#1353689]
|
|
|
7fdf80 |
- Resolves: bz#1349407
|
|
|
7fdf80 |
(AArch64: backport fix to run over gicv3 emulation)
|
|
|
7fdf80 |
- Resolves: bz#1353689
|
|
|
7fdf80 |
(AAVMF: Drops to shell with uninitialized NVRAM file)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Jun 9 2016 Laszlo Ersek <lersek@redhat.com> - ovmf-20160608-1.git988715a.el7
|
|
|
7fdf80 |
- Resolves: bz#1341733
|
|
|
7fdf80 |
(prevent SMM stack overflow in OVMF while enrolling certificates in "db")
|
|
|
7fdf80 |
- Resolves: bz#1257882
|
|
|
7fdf80 |
(FEAT: support to boot from virtio 1.0 modern devices)
|
|
|
7fdf80 |
- Resolves: bz#1333238
|
|
|
7fdf80 |
(Q35 machine can not boot up successfully with more than 3 virtio-scsi
|
|
|
7fdf80 |
storage controller under switch)
|
|
|
7fdf80 |
- Resolves: bz#1330955
|
|
|
7fdf80 |
(VM can not be booted up from hard disk successfully when with a passthrough
|
|
|
7fdf80 |
USB stick)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu May 19 2016 Laszlo Ersek <lersek@redhat.com> - ovmf-20160419-2.git90bb4c5.el7
|
|
|
7fdf80 |
- Submit scratch builds from the exploded tree again to
|
|
|
7fdf80 |
supp-rhel-7.3-candidate, despite FatPkg being OSS at this point; see
|
|
|
7fdf80 |
bz#1329559.
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Apr 20 2016 Laszlo Ersek <lersek@redhat.com> - ovmf-20160419-1.git90bb4c5.el7
|
|
|
7fdf80 |
- FatPkg is under the 2-clause BSDL now; "ovmf" has become OSS
|
|
|
7fdf80 |
- upgrade to openssl-1.0.2g
|
|
|
7fdf80 |
- Resolves: bz#1323363
|
|
|
7fdf80 |
(remove "-D SECURE_BOOT_ENABLE" from AAVMF)
|
|
|
7fdf80 |
- Resolves: bz#1257882
|
|
|
7fdf80 |
(FEAT: support to boot from virtio 1.0 modern devices)
|
|
|
7fdf80 |
- Resolves: bz#1308678
|
|
|
7fdf80 |
(clearly separate SB-less, SMM-less OVMF binary from SB+SMM OVMF binary)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Feb 19 2016 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20160202-2.gitd7c0dfa.el7
|
|
|
7fdf80 |
- ovmf-restore-TianoCore-splash-logo-without-OpenSSL-advert.patch [bz#1308678]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-ArmVirtPkg-show-OpenSSL-less-logo-without-Se.patch [bz#1308678]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-simplify-VARIABLE_STORE_HEADER-generation.patch [bz#1308678]
|
|
|
7fdf80 |
- ovmf-redhat-bring-back-OVMF_CODE.fd-but-without-SB-and-wi.patch [bz#1308678]
|
|
|
7fdf80 |
- ovmf-redhat-rename-OVMF_CODE.smm.fd-to-OVMF_CODE.secboot..patch [bz#1308678]
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Feb 2 2016 Laszlo Ersek <lersek@redhat.com> - ovmf-20160202-1.gitd7c0dfa.el7
|
|
|
7fdf80 |
- rebase to upstream d7c0dfa
|
|
|
7fdf80 |
- update OpenSSL to 1.0.2e (upstream)
|
|
|
7fdf80 |
- update FatPkg to SVN r97 (upstream)
|
|
|
7fdf80 |
- drive NVMe devices (upstream)
|
|
|
7fdf80 |
- resize xterm on serial console mode change, when requested with
|
|
|
7fdf80 |
-fw_cfg name=opt/(ovmf|aavmf)/PcdResizeXterm,string=y
|
|
|
7fdf80 |
(downstream)
|
|
|
7fdf80 |
- Resolves: bz#1259395
|
|
|
7fdf80 |
(revert / roll back AAVMF fix for BZ 1188054)
|
|
|
7fdf80 |
- Resolves: bz#1202819
|
|
|
7fdf80 |
(OVMF: secure boot limitations)
|
|
|
7fdf80 |
- Resolves: bz#1182495
|
|
|
7fdf80 |
(OVMF rejects iPXE oprom when Secure Boot is enabled)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Nov 5 2015 Laszlo Ersek <lersek@redhat.com> - ovmf-20151104-1.gitb9ffeab.el7
|
|
|
7fdf80 |
- rebase to upstream b9ffeab
|
|
|
7fdf80 |
- Resolves: bz#1207554
|
|
|
7fdf80 |
([AAVMF] AArch64: populate SMBIOS)
|
|
|
7fdf80 |
- Resolves: bz#1270279
|
|
|
7fdf80 |
(AAVMF: output improvements)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Jun 25 2015 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20150414-2.gitc9e5618.el7
|
|
|
7fdf80 |
- ovmf-OvmfPkg-PlatformPei-set-SMBIOS-entry-point-version-d.patch [bz#1232876]
|
|
|
7fdf80 |
- Resolves: bz#1232876
|
|
|
7fdf80 |
(OVMF should install a version 2.8 SMBIOS entry point)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Sat Apr 18 2015 Laszlo Ersek <lersek@redhat.com> - 20150414-1.gitc9e5618.el7
|
|
|
7fdf80 |
- rebase from upstream 9ece15a to c9e5618
|
|
|
7fdf80 |
- adapt .gitignore files
|
|
|
7fdf80 |
- update to openssl-0.9.8zf
|
|
|
7fdf80 |
- create Logo-OpenSSL.bmp rather than modifying Logo.bmp in-place
|
|
|
7fdf80 |
- update to FatPkg SVN r93 (git 8ff136aa)
|
|
|
7fdf80 |
- drop the following downstream-only patches (obviated by upstream
|
|
|
7fdf80 |
counterparts):
|
|
|
7fdf80 |
"tools_def.template: use forward slash with --add-gnu-debuglink (RHEL only)"
|
|
|
7fdf80 |
"tools_def.template: take GCC48 prefixes from environment (RHEL only)"
|
|
|
7fdf80 |
"OvmfPkg: set video resolution of text setup to 640x480 (RHEL only)"
|
|
|
7fdf80 |
"OvmfPkg: resolve OrderedCollectionLib with base red-black tree instance"
|
|
|
7fdf80 |
"OvmfPkg: AcpiPlatformDxe: actualize QemuLoader.h comments"
|
|
|
7fdf80 |
"OvmfPkg: AcpiPlatformDxe: remove current ACPI table loader"
|
|
|
7fdf80 |
"OvmfPkg: AcpiPlatformDxe: implement QEMU's full ACPI table loader interface"
|
|
|
7fdf80 |
"OvmfPkg: QemuVideoDxe: fix querying of QXL's drawable buffer size"
|
|
|
7fdf80 |
"OvmfPkg: disable stale fork of SecureBootConfigDxe"
|
|
|
7fdf80 |
"OvmfPkg: SecureBootConfigDxe: remove stale fork"
|
|
|
7fdf80 |
"Try to read key strike even when ..."
|
|
|
7fdf80 |
"OvmfPkg: BDS: remove dead call to PlatformBdsEnterFrontPage()"
|
|
|
7fdf80 |
"OvmfPkg: BDS: drop useless return statement"
|
|
|
7fdf80 |
"OvmfPkg: BDS: don't overwrite the BDS Front Page timeout"
|
|
|
7fdf80 |
"OvmfPkg: BDS: optimize second argument in PlatformBdsEnterFrontPage() call"
|
|
|
7fdf80 |
'OvmfPkg: BDS: drop superfluous "connect first boot option" logic'
|
|
|
7fdf80 |
"OvmfPkg: BDS: drop custom boot timeout, revert to IntelFrameworkModulePkg's"
|
|
|
7fdf80 |
"Add comments to clarify mPubKeyStore buffer MemCopy. ..."
|
|
|
7fdf80 |
"MdeModulePkg/SecurityPkg Variable: Add boundary check..."
|
|
|
7fdf80 |
"OvmfPkg: AcpiPlatformDxe: make dependency on PCI enumeration explicit"
|
|
|
7fdf80 |
"MdePkg: UefiScsiLib: do not encode LUN in CDB for READ and WRITE"
|
|
|
7fdf80 |
"MdePkg: UefiScsiLib: do not encode LUN in CDB for other SCSI commands"
|
|
|
7fdf80 |
- merge downstream AAVMF patch "adapt packaging to Arm64", which forces us to
|
|
|
7fdf80 |
rename the main package from "OVMF" to "ovmf"
|
|
|
7fdf80 |
- drop the following ARM BDS specific tweaks (we'll only build the Intel BDS):
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: generate ESP Image boot option if user pref is unset
|
|
|
7fdf80 |
(Acadia)"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: check for other defaults too if user pref is unset
|
|
|
7fdf80 |
(Acadia)"
|
|
|
7fdf80 |
"ArmPlatformPkg/ArmVirtualizationPkg: auto-detect boot path (Acadia)"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: initialize ConIn/ConOut/ErrOut before connecting
|
|
|
7fdf80 |
terminals"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: let FindCandidate() search all filesystems"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: FindCandidateOnHandle(): log full device path"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: fall back to Boot Menu when no default option was found"
|
|
|
7fdf80 |
"ArmPlatformPkg/Bds: always connect drivers before looking at boot options"
|
|
|
7fdf80 |
- drop patch "ArmPlatformPkg/ArmVirtualizationPkg: enable DEBUG_VERBOSE (Acadia
|
|
|
7fdf80 |
only)", obsoleted by fixed bug 1197141
|
|
|
7fdf80 |
- tweak patch "write up build instructions (for interactive, local development)
|
|
|
7fdf80 |
(RHELSA)". The defaults in "BaseTools/Conf/target.template", ie.
|
|
|
7fdf80 |
ACTIVE_PLATFORM and TARGET_ARCH, are set for OVMF / X64. The AAVMF build
|
|
|
7fdf80 |
instructions now spell out the necessary override options (-p and -a,
|
|
|
7fdf80 |
respectively).
|
|
|
7fdf80 |
- extend patch "build FAT driver from source (RHELSA)" to the Xen build as well
|
|
|
7fdf80 |
(only for consistency; we don't build for Xen).
|
|
|
7fdf80 |
- drop the following downstream-only AAVMF patches, due to the 77d5dac ->
|
|
|
7fdf80 |
c9e5618 AAVMF rebase & join:
|
|
|
7fdf80 |
"redhat/process-rh-specific.sh: fix check for hunk-less filtered patches"
|
|
|
7fdf80 |
"redhat/process-rh-specific.sh: suppress missing files in final 'rm'"
|
|
|
7fdf80 |
"ArmVirtualizationQemu: build UEFI shell from source (Acadia only)"
|
|
|
7fdf80 |
"MdePkg: UefiScsiLib: do not encode LUN in CDB for READ and WRITE"
|
|
|
7fdf80 |
"MdePkg: UefiScsiLib: do not encode LUN in CDB for other SCSI commands"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: work around cache incoherence on KVM affecting DTB"
|
|
|
7fdf80 |
"Changed build target to supp-rhel-7.1-candidate"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: VirtFdtDxe: forward FwCfg addresses from DTB to PCDs"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: introduce QemuFwCfgLib instance for DXE drivers"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: clone PlatformIntelBdsLib from ArmPlatformPkg"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: PlatformIntelBdsLib: add basic policy"
|
|
|
7fdf80 |
"OvmfPkg: extract QemuBootOrderLib"
|
|
|
7fdf80 |
"OvmfPkg: QemuBootOrderLib: featurize PCI-like device path translation"
|
|
|
7fdf80 |
"OvmfPkg: introduce VIRTIO_MMIO_TRANSPORT_GUID"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: VirtFdtDxe: use dedicated VIRTIO_MMIO_TRANSPORT_GUID"
|
|
|
7fdf80 |
"OvmfPkg: QemuBootOrderLib: widen ParseUnitAddressHexList() to UINT64"
|
|
|
7fdf80 |
"OvmfPkg: QemuBootOrderLib: OFW-to-UEFI translation for virtio-mmio"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: PlatformIntelBdsLib: adhere to QEMU's boot order"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: identify "new shell" as builtin shell for Intel BDS"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: Intel BDS: load EFI-stubbed Linux kernel from fw_cfg"
|
|
|
7fdf80 |
'Revert "ArmVirtualizationPkg: work around cache incoherence on KVM affecting
|
|
|
7fdf80 |
DTB"'
|
|
|
7fdf80 |
"OvmfPkg: QemuBootOrderLib: expose QEMU's "-boot menu=on[, splash-time=N]""
|
|
|
7fdf80 |
"OvmfPkg: PlatformBdsLib: get front page timeout from QEMU"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: PlatformIntelBdsLib: get front page timeout from QEMU"
|
|
|
7fdf80 |
"ArmPkg: ArmArchTimerLib: clean up comments"
|
|
|
7fdf80 |
"ArmPkg: ArmArchTimerLib: use edk2-conformant (UINT64 * UINT32) / UINT32"
|
|
|
7fdf80 |
"ArmPkg: ArmArchTimerLib: conditionally rebase to actual timer frequency"
|
|
|
7fdf80 |
"ArmVirtualizationQemu: ask the hardware for the timer frequency"
|
|
|
7fdf80 |
"ArmPkg: DebugPeCoffExtraActionLib: debugger commands are not errors"
|
|
|
7fdf80 |
"ArmPlatformPkg: PEIM startup is not an error"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: PlatformIntelBdsLib: lack of QEMU kernel is no error"
|
|
|
7fdf80 |
"ArmVirtualizationPkg: expose debug message bitmask on build command line"
|
|
|
7fdf80 |
- tweak patch "rebase to upstream 77d5dac (Acadia only)": update spec changelog
|
|
|
7fdf80 |
only
|
|
|
7fdf80 |
- tweak patch "spec: build AAVMF with the Intel BDS driver (RHELSA only)":
|
|
|
7fdf80 |
apply "-D INTEL_BDS" to manual build instructions in redhat/README too
|
|
|
7fdf80 |
- tweak patch "spec: build and install verbose and silent (default) AAVMF
|
|
|
7fdf80 |
binaries": apply DEBUG_PRINT_ERROR_LEVEL setting to interactive build
|
|
|
7fdf80 |
instructions in redhat/README too
|
|
|
7fdf80 |
- install OVMF whitepaper as part of the OVMF build's documentation
|
|
|
7fdf80 |
- Resolves: bz#1211337
|
|
|
7fdf80 |
(merge AAVMF into OVMF)
|
|
|
7fdf80 |
- Resolves: bz#1206523
|
|
|
7fdf80 |
([AAVMF] fix missing cache maintenance)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Mar 06 2015 Miroslav Rezanina <mrezanin@redhat.com> - AAVMF-20141113-5.git77d5dac.el7_1
|
|
|
7fdf80 |
- aavmf-ArmPkg-DebugPeCoffExtraActionLib-debugger-commands-a.patch [bz#1197141]
|
|
|
7fdf80 |
- aavmf-ArmPlatformPkg-PEIM-startup-is-not-an-error.patch [bz#1197141]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-PlatformIntelBdsLib-lack-of-QEM.patch [bz#1197141]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-expose-debug-message-bitmask-on.patch [bz#1197141]
|
|
|
7fdf80 |
- aavmf-spec-build-and-install-verbose-and-silent-default-AA.patch [bz#1197141]
|
|
|
7fdf80 |
- Resolves: bz#1197141
|
|
|
7fdf80 |
(create silent & verbose builds)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Feb 10 2015 Miroslav Rezanina <mrezanin@redhat.com> - AAVMF-20141113-4.git77d5dac.el7
|
|
|
7fdf80 |
- aavmf-ArmPkg-ArmArchTimerLib-clean-up-comments.patch [bz#1188247]
|
|
|
7fdf80 |
- aavmf-ArmPkg-ArmArchTimerLib-use-edk2-conformant-UINT64-UI.patch [bz#1188247]
|
|
|
7fdf80 |
- aavmf-ArmPkg-ArmArchTimerLib-conditionally-rebase-to-actua.patch [bz#1188247]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationQemu-ask-the-hardware-for-the-timer.patch [bz#1188247]
|
|
|
7fdf80 |
- aavmf-ArmPkg-TimerDxe-smack-down-spurious-timer-interrupt-.patch [bz#1188054]
|
|
|
7fdf80 |
- Resolves: bz#1188054
|
|
|
7fdf80 |
(guest reboot (asked from within AAVMF) regressed in 3.19.0-0.rc5.58.aa7a host kernel)
|
|
|
7fdf80 |
- Resolves: bz#1188247
|
|
|
7fdf80 |
(backport "fix gBS->Stall()" series)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Mon Jan 19 2015 Miroslav Rezanina <mrezanin@redhat.com> - AAVMF-20141113-3.git77d5dac.el7
|
|
|
7fdf80 |
- aavmf-OvmfPkg-QemuBootOrderLib-expose-QEMU-s-boot-menu-on-.patch [bz#1172756]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-PlatformBdsLib-get-front-page-timeout-from-Q.patch [bz#1172756]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-PlatformIntelBdsLib-get-front-p.patch [bz#1172756]
|
|
|
7fdf80 |
- Resolves: bz#1172756
|
|
|
7fdf80 |
([RFE]Expose boot-menu shortcut to domain via AAVMF)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Jan 14 2015 Miroslav Rezanina <mrezanin@redhat.com> - AAVMF-20141113-2.git77d5dac.el7
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-VirtFdtDxe-forward-FwCfg-addres.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-introduce-QemuFwCfgLib-instance.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-clone-PlatformIntelBdsLib-from-.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-PlatformIntelBdsLib-add-basic-p.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-extract-QemuBootOrderLib.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-QemuBootOrderLib-featurize-PCI-like-device-p.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-introduce-VIRTIO_MMIO_TRANSPORT_GUID.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-VirtFdtDxe-use-dedicated-VIRTIO.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-QemuBootOrderLib-widen-ParseUnitAddressHexLi.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-OvmfPkg-QemuBootOrderLib-OFW-to-UEFI-translation-for.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-PlatformIntelBdsLib-adhere-to-Q.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-identify-new-shell-as-builtin-s.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-ArmVirtualizationPkg-Intel-BDS-load-EFI-stubbed-Linu.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-spec-build-AAVMF-with-the-Intel-BDS-driver-RHELSA-on.patch [bz#1172749]
|
|
|
7fdf80 |
- aavmf-Revert-ArmVirtualizationPkg-work-around-cache-incohe.patch [bz#1172910]
|
|
|
7fdf80 |
- Resolves: bz#1172749
|
|
|
7fdf80 |
(implement fw_cfg, boot order handling, and -kernel booting in ArmVirtualizationQemu)
|
|
|
7fdf80 |
- Resolves: bz#1172910
|
|
|
7fdf80 |
(revert Acadia-only workaround (commit df7bca4e) once Acadia host kernel (KVM) is fixed)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Dec 05 2014 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20140822-7.git9ece15a.el7
|
|
|
7fdf80 |
- ovmf-MdePkg-UefiScsiLib-do-not-encode-LUN-in-CDB-for-READ.patch [bz#1166971]
|
|
|
7fdf80 |
- ovmf-MdePkg-UefiScsiLib-do-not-encode-LUN-in-CDB-for-othe.patch [bz#1166971]
|
|
|
7fdf80 |
- Resolves: bz#1166971
|
|
|
7fdf80 |
(virtio-scsi disks and cd-roms with nonzero LUN are rejected with errors)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Nov 25 2014 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20140822-6.git9ece15a.el7
|
|
|
7fdf80 |
- ovmf-OvmfPkg-AcpiPlatformDxe-make-dependency-on-PCI-enume.patch [bz#1166027]
|
|
|
7fdf80 |
- Resolves: bz#1166027
|
|
|
7fdf80 |
(backport "OvmfPkg: AcpiPlatformDxe: make dependency on PCI enumeration explicit")
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Nov 18 2014 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20140822-4.git9ece15a.el7
|
|
|
7fdf80 |
- ovmf-Add-comments-to-clarify-mPubKeyStore-buffer-MemCopy.patch [bz#1162314]
|
|
|
7fdf80 |
- ovmf-MdeModulePkg-SecurityPkg-Variable-Add-boundary-check.patch [bz#1162314]
|
|
|
7fdf80 |
- Resolves: bz#1162314
|
|
|
7fdf80 |
(EMBARGOED OVMF: uefi: INTEL-TA-201410-001 && INTEL-TA-201410-002 [rhel-7.1])
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Nov 13 2014 Laszlo Ersek <lersek@redhat.com> - AAVMF-20141113-1.git77d5dac
|
|
|
7fdf80 |
- rebased to upstream 77d5dac
|
|
|
7fdf80 |
<https://bugzilla.redhat.com/show_bug.cgi?id=1162314#c1>
|
|
|
7fdf80 |
- patch "ArmVirtualizationPkg: FdtPL011SerialPortLib: support UEFI_APPLICATION"
|
|
|
7fdf80 |
is now upstream (SVN r16219, git edb5073)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Thu Nov 13 2014 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20140822-3.git9ece15a.el7
|
|
|
7fdf80 |
- ovmf-Revert-OvmfPkg-set-video-resolution-of-text-setup-to.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-Try-to-read-key-strike-even-when-the-TimeOuts-value-.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-remove-dead-call-to-PlatformBdsEnterFron.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-drop-useless-return-statement.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-don-t-overwrite-the-BDS-Front-Page-timeo.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-optimize-second-argument-in-PlatformBdsE.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-drop-superfluous-connect-first-boot-opti.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-BDS-drop-custom-boot-timeout-revert-to-Intel.patch [bz#1153927]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-set-video-resolution-of-text-setup-to-640x48.patch [bz#1153927]
|
|
|
7fdf80 |
- Resolves: bz#1153927
|
|
|
7fdf80 |
(set NEXTBOOT to uefi setting failed from Windows Recovery console)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Nov 11 2014 Miroslav Rezanina <mrezanin@redhat.com> - OVMF-20140822-2.git9ece15a
|
|
|
7fdf80 |
- ovmf-redhat-process-rh-specific.sh-suppress-missing-files.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-Revert-RH-only-OvmfPkg-QemuVideoDxe-fix-querying-of-.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-Revert-RH-only-OvmfPkg-AcpiPlatformDxe-implement-QEM.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-Revert-RH-only-OvmfPkg-AcpiPlatformDxe-remove-curren.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-Revert-RH-only-OvmfPkg-AcpiPlatformDxe-actualize-Qem.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-Revert-RH-only-OvmfPkg-resolve-OrderedCollectionLib-.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-QemuVideoDxe-work-around-misreported-QXL-fra.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-resolve-OrderedCollectionLib-with-base-red-b.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-AcpiPlatformDxe-actualize-QemuLoader.h-comme.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-AcpiPlatformDxe-remove-current-ACPI-table-lo.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-AcpiPlatformDxe-implement-QEMU-s-full-ACPI-t.patch [bz#1145784]
|
|
|
7fdf80 |
- ovmf-spec-build-small-bootable-ISO-with-standalone-UEFI-s.patch [bz#1147592]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-allow-exclusion-of-the-shell-from-the-firmwa.patch [bz#1147592]
|
|
|
7fdf80 |
- ovmf-spec-exclude-the-UEFI-shell-from-the-SecureBoot-enab.patch [bz#1147592]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-EnrollDefaultKeys-application-for-enrolling-.patch [bz#1148296]
|
|
|
7fdf80 |
- ovmf-spec-package-EnrollDefaultKeys.efi-on-UefiShell.iso-.patch [bz#1148296]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-disable-stale-fork-of-SecureBootConfigDxe.patch [bz#1148294]
|
|
|
7fdf80 |
- ovmf-OvmfPkg-SecureBootConfigDxe-remove-stale-fork.patch [bz#1148294]
|
|
|
7fdf80 |
- Resolves: bz#1145784
|
|
|
7fdf80 |
(OVMF sync with QXL and ACPI patches up to edk2 7a9612ce)
|
|
|
7fdf80 |
- Resolves: bz#1147592
|
|
|
7fdf80 |
(the binary RPM should include a small ISO file with a directly bootable UEFI shell binary)
|
|
|
7fdf80 |
- Resolves: bz#1148294
|
|
|
7fdf80 |
(drop OvmfPkg's stale fork of SecureBootConfigDxe)
|
|
|
7fdf80 |
- Resolves: bz#1148296
|
|
|
7fdf80 |
(provide a non-interactive way to auto-enroll important SecureBoot certificates)
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Oct 15 2014 Laszlo Ersek <lersek@redhat.com> - AAVMF-20141015-1.gitc373687
|
|
|
7fdf80 |
- ported packaging to aarch64 / AAVMF
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Fri Aug 22 2014 Laszlo Ersek <lersek@redhat.com> - 20140822-1.git9ece15a.el7
|
|
|
7fdf80 |
- rebase from upstream 3facc08 to 9ece15a
|
|
|
7fdf80 |
- update to openssl-0.9.8zb
|
|
|
7fdf80 |
- update to FatPkg SVN r86 (git 2355ea2c)
|
|
|
7fdf80 |
- the following patches of Paolo Bonzini have been merged in upstream; drop the
|
|
|
7fdf80 |
downstream-only copies:
|
|
|
7fdf80 |
7bc1421 edksetup.sh: Look for BuildEnv under EDK_TOOLS_PATH
|
|
|
7fdf80 |
d549344 edksetup.sh: Ensure that WORKSPACE points to the top of an edk2
|
|
|
7fdf80 |
checkout
|
|
|
7fdf80 |
1c023eb BuildEnv: remove useless check before setting $WORKSPACE
|
|
|
7fdf80 |
- include the following patches that have been pending review on the upstream
|
|
|
7fdf80 |
list for a long time:
|
|
|
7fdf80 |
[PATCH 0/4] OvmfPkg: complete client for QEMU's ACPI loader interface
|
|
|
7fdf80 |
http://thread.gmane.org/gmane.comp.bios.tianocore.devel/8369
|
|
|
7fdf80 |
[PATCH] OvmfPkg: QemuVideoDxe: fix querying of QXL's drawable buffer size
|
|
|
7fdf80 |
http://thread.gmane.org/gmane.comp.bios.tianocore.devel/8515
|
|
|
7fdf80 |
- nasm is a build-time dependency now because upstream BuildTools has started
|
|
|
7fdf80 |
to call it directly
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Wed Jul 23 2014 Laszlo Ersek <lersek@redhat.com> - 20140723-1.git3facc08.el7
|
|
|
7fdf80 |
- rebase from upstream a618eaa to 3facc08
|
|
|
7fdf80 |
- update to openssl-0.9.8za
|
|
|
7fdf80 |
- drop downstream-only split varstore patch, rely on upstream's
|
|
|
7fdf80 |
|
|
|
7fdf80 |
* Tue Jun 24 2014 Miroslav Rezanina <mrezanin@redhat.com> - 20140619-1.gita618eaa.el7
|
|
|
7fdf80 |
- Initial version
|