Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

ovmf-tools-201911-7.28.1 RPM for armv7hl

From OpenSuSE Ports Leap 15.5 for armv7hl

Name: ovmf-tools Distribution: openSUSE Step 15
Version: 201911 Vendor: openSUSE
Release: 7.28.1 Build date: Wed Apr 19 18:30:37 2023
Group: System/Emulators/PC Build host: obs-arm-5
Size: 124168 Source RPM: ovmf-201911-7.28.1.src.rpm
Packager: https://bugs.opensuse.org
Url: http://sourceforge.net/apps/mediawiki/tianocore/index.php?title=EDK2
Summary: The BaseTools from edk2
The Open Virtual Machine Firmware (OVMF) project aims to support
firmware for Virtual Machines using the edk2 code base.

This package contains the tools from edk2.

Provides

Requires

License

BSD-2-Clause-Patent

Changelog

* Tue Apr 18 2023 jlee@suse.com
  - Add ovmf-bsc1174246-SecurityPkg-DxeImageVerificationLib-Check-result-of-.patch
    to check result of GetEfiGlobalVariable2 (CVE-2019-14560, bsc#1174246)
* Tue Apr 18 2023 jlee@suse.com
  - Add ovmf-bsc1196741-MdeModulePkg-PiSmmCore-SmmEntryPoint-underflow-CVE-2.patch
    for MdeModulePkg/PiSmmCore: SmmEntryPoint underflow (CVE-2021-38578)
    (bsc#1196741)
* Tue Dec 27 2022 jlee@suse.com
  - Add the following patches to fix insufficient input validation in
    MdeModulePkg:
      ovmf-bsc1188371-MdeModulePkg-Add-new-PCD-to-control-the-evacuate-tem.patch
      ovmf-bsc1188371-MdeModulePkg-PeiCore-Enable-T-RAM-evacuation-in-PeiC.patch
      ovmf-bsc1188371-UefiCpuPkg-CpuMpPei-Add-GDT-migration-support-CVE-20.patch
      ovmf-bsc1188371-UefiCpuPkg-SecMigrationPei-Add-initial-PEIM-CVE-2019.patch
      ovmf-bsc1188371-MdeModulePkg-Core-Create-Migrated-FV-Info-Hob-for-ca.patch
      ovmf-bsc1188371-SecurityPkg-Tcg2Pei-Use-Migrated-FV-Info-Hob-for-cal.patch
      ovmf-bsc1188371-UefiCpuPkg-CpuMpPei-Enable-paging-and-set-NP-flag-to.patch
      ovmf-bsc1188371-UefiCpuPkg-Correct-some-typos.patch
      ovmf-bsc1188371-SecurityPkg-TcgPei-Use-Migrated-FV-Info-Hob-for-calc.patch
      ovmf-bsc1188371-UefiCpuPkg-Move-MigrateGdt-from-DiscoverMemory-to-Te.patch
    (bsc#1188371, CVE-2019-11098)
* Mon Jun 07 2021 glin@suse.com
  - Add ovmf-bsc1186151-fix-iscsi-overflows.patch to fix the possible
    overflows in IScsiDxe (bsc#1186151)
* Fri May 21 2021 glin@suse.com
  - Update ovmf-add-exclude-shell-flag.patch to include Ia32X64
    (bsc#1185812, bsc#1186284)
* Mon May 10 2021 glin@suse.com
  - Build ovmf-x86_64-smm against Ia32X64 to enable S3 support
    (bsc#1185812)
* Thu Mar 18 2021 glin@suse.com
  - Add ovmf-bsc1183578-lzma-catch-4GB.patch to fix the possible
    heap corruption (bsc#1183578, CVE-2021-28211)
  - Add ovmf-bsc1183579-fix-fv-recursion.patch to fix unlimited FV
    recursion (bsc#1183579, CVE-2021-28210)
* Wed Dec 02 2020 glin@suse.com
  - Add ovmf-bsc1177789-cryptopkg-fix-null-dereference.patch to fix
    the potential NULL dereference in AuthenticodeVerify()
    (bsc#1177789, CVE-2019-14584)
* Thu Sep 03 2020 glin@suse.com
  - Add ovmf-bsc1175476-fix-DxeImageVerificationLib-overflow.patch
    to fix overflow in DxeImageVerificationHandler
    (bsc#1175476, CVE-2019-14562)
* Mon Jul 20 2020 glin@suse.com
  - Add ovmf-bsc1119454-additional-scsi-drivers.patch to support more
    SCSI drivers (PvScsi, MptScsi, and LsiScsi) (bsc#1119454)
    + Enable LsiScsi explicitly since it's disabled by default
* Mon Apr 06 2020 glin@suse.com
  - Add ovmf-bsc1163927-fix-ping-and-ip6dxe.patch to fix crash and
    hang in ShellPkg and Ip6Dxe (bsc#1163927, CVE-2019-14559)
* Mon Feb 24 2020 glin@suse.com
  - Add ovmf-bsc1163969-fix-DxeImageVerificationHandler.patch to fix
    dbx signature check (bsc#1163969, CVE-2019-14575)
    + Also change the order of several patches to distinguish the
      openssl patch
  - Add ovmf-bsc1163927-fix-ip4dxe-and-arpdxe.patch to fix memory
    leakage in Ip4Dxe and ArpDxe (bsc#1163927, CVE-2019-14559)
* Tue Feb 18 2020 glin@suse.com
  - Add ovmf-bsc1163959-PiDxeS3BootScriptLib-fix-numeric-truncation.patch
    to fix the numeric truncation to avoid the potential memory
    corruption (bsc#1163959, CVE-2019-14563)
* Mon Feb 03 2020 glin@suse.com
  - Build the unified firmware with preloaded keys for backward
    compatibility (bsc#1159793)
* Fri Dec 20 2019 dmueller@suse.com
  - only build -aarch32 Cortex-A15 EFI on armv7hl
* Tue Dec 03 2019 glin@suse.com
  - Update to edk2-stable201911
    + SecurityPkg: Fix TPM2 ACPI measurement
    + MdeModulePkg: Enable variable runtime cache by default
    + OvmfPkg: Disable variable runtime cache
    + MdeModulePkg/Variable: Add RT GetVariable() cache support
    + CryptoPkg: Upgrade OpenSSL to 1.1.1d
    + MdePkg-UefiSpec.h: Add UEFI 2.8 new memory attributes
    + MdePkg/UefiFileHandleLib: Fix potential NULL dereference
    + NetworkPkg/HttpDxe: Set the HostName for the verification
      (CVE-2019-14553)
    + NetworkPkg/TlsDxe: Add the support of host validation to TlsDxe
      driver (CVE-2019-14553)
    + CryptoPkg/TlsLib: TlsSetVerifyHost: parse IP address literals
      as such (CVE-2019-14553)
    + CryptoPkg/TlsLib: Add the new API "TlsSetVerifyHost"
      (CVE-2019-14553)
    + MdePkg/Include/Protocol/Tls.h: Add the data type of
      EfiTlsVerifyHost (CVE-2019-14553)
    + MdeModulePkg/BdsDxe: Fix PlatformRecovery issue
    + NetworkPkg/SnpDxe: Add PCD to remove ExitBootServices event
      from SNP driver
    + MdeModulePkg: Update to support SmBios 3.3.0
    + UefiCpuPkg/MpInitLib: honor the platform's boot CPU count in AP
      detection
    + SecurityPkg/Tcg2: Add Support Laml, Lasa for TPM2 ACPI
    + OvmfPkg/PlatformDxe: fix EFI_HII_HANDLE parameters of internal
      functions
    + OvmfPkg/VirtioNetDxe: fix SignalEvent() call
    + OvmfPkg/XenBusDxe: fix UninstallMultipleProtocolInterfaces()
      call
    + NetworkPkg/Ip4Dxe: fix NetLibDestroyServiceChild() call
    + MdeModulePkg/ScsiDiskDxe: Support Storage Security Command
      Protocol
    + MdePkg: Implement SCSI commands for Security Protocol In/Out
    + MdeModulePkg/TerminalDxe: Enhance the arrow keys support
    + MdeModulePkg/UefiBootManager: Unload image on
      EFI_SECURITY_VIOLATION
    + MdeModulePkg/DxeCapsuleLibFmp: Unload image on
      EFI_SECURITY_VIOLATION
    + MdeModulePkg: Extend the support keyboard type of Terminal
      console
    + UefiCpuPkg/CpuExceptionHandlerLib: Fix split lock
    + UefiCpuPkg: Fix potential spinLock issue in SmmStartupThisAp
    + UefiCpuPkg/PiSmmCpu: Enable 5L paging only when phy addr line
      > 48
    + OvmfPkg/EnrollDefaultKeys: clean up Base64Decode() retval
      handling
    + ArmVirtPkg/PlatformBootManagerLib: unload image on
      EFI_SECURITY_VIOLATION
    + ShellPkg/ShellPkg.dsc AARCH64: enable stack protector
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: revert to PIE
      linking
    + BaseTools/GenFw AARCH64: fix up GOT based relative relocations
    + ShellPkg/Pci.c: Update supported link speed to PCI5.0
    + PcAtChipsetPkg: add PcdRealTimeClockUpdateTimeout
    + UefiCpuPkg: Add PcdCpuSmmRestrictedMemoryAccess
    + ShellPkg/CommandLib: avoid NULL derefence and memory leak
    + MdePkg/DxeHstiLib: Added checks to improve error handling
    + BaseTools: Support more file types in build cache
    + UefiCpuPkg/SecCore: get AllSecPpiList after SecPlatformMain
  - Update openssl to 1.1.1d
    + Add openssl-fix-syntax-error.patch to fix a syntax error
  - Drop ovmf-bsc1153072-fix-invalid-https-cert.patch
    + Already upstreamed
* Fri Nov 08 2019 glin@suse.com
  - Use the same x86 4MB firmware names as the ones in the previous
    version (< stable201905) for backward compatibility
* Wed Nov 06 2019 glin@suse.com
  - Update to edk2-stable201908
    + Add TLS and IPv6 supports for ArmVirtQemu
    + Various fixes and updates for TPM2
    + Various fixes for OvmfPkg and the underlying infrastructures
    + Drop the build requirement of python2
    + Drop the obsolete IntelFrameworkPkg and IntelFrameworkModulePkg
    + Remove ShellBinPkg and move the platform packages out of edk2
  - Update openssl to 1.1.1b
    + Add berkeley-softfloat-3-b64af41c3276f.tar.xz since arm7 needs
      the softfloat implementation for openssl 1.1.1b
  - Add ovmf-bsc1153072-fix-invalid-https-cert.patch to reject the
    invalid server certificates for HTTPS Boot
    (bsc#1153072, CVE-2019-14553)
  - Build the varstore templates with EnrollDefaultKeys.efi
    + Create the iso files for key enrollment
    - Add gen-key-enrollment-iso.sh to generate the iso file
    + Drop the non-upstream ovmf-embed-default-keys.patch
    - Also drop owner-guid-zero.h
    + Drop the MS keys and dbx since they are already in
      EnrollDefaultKeys.efi: MicCorKEKCA2011_2011-06-24.crt,
      MicCorUEFCA2011_2011-06-27.crt, MicWinProPCA2011_2011-10-19.crt,
      and dbxupdate.zip
    - Also drop the related script strip_authinfo.pl
    + Add ovmf-set-fixed-enroll-time.patch to set the fixed enrolling
      time to make the varstore template reproducible
    + Require qemu 3.0.0 for fw_cfg
  - Enable TLS (HTTPS Boot) and TPM2 support
  - Add the firmware descriptors for QEMU
  - Update README to match the current settings
  - Update the License tag to BSD-2-Clause-Patent
  - Build SecureBoot firmwares for aarch64
  - Add a new "smm" flavor to enable System Management Mode
    + Also add ovmf-add-exclude-shell-flag.patch to exclude shell
      from the resultant SMM firmware files
  - Retire the old openSUSE 4096 bit certificates since all those
    programs are unmaintained.
  - Drop upstreamed patches
    + ovmf-bsc1092943-fix-attributes-table.patch
    + ovmf-bsc1099193-fix-sev-flash-variables.patch
    + ovmf-bsc1115916-fix-timestamp-zeroing.patch
    + ovmf-bsc1115917-bounds-checking-for-ueficompress.patch
    + ovmf-bsc1127820-fix-blockio-buffer-overflow.patch
    + ovmf-bsc1127821-dns-check-packet-size.patch
    + ovmf-bsc1127822-fix-fv-parsing.patch
    + ovmf-bsc1128503-fix-stack-overflow-in-HiiImage-and-HiiDatabase.patch
    + ovmf-bsc1130267-overflow-in-partition-and-udf.patch
    + ovmf-bsc1131361-fix-stack-overflow-xhci.patch
  - Refresh patches:
    + ovmf-add-exclude-shell-flag.patch
    + ovmf-disable-ia32-firmware-piepic.patch
    + ovmf-pie.patch
  - Drop the requirement of xxd
* Tue Apr 09 2019 glin@suse.com
  - Add ovmf-bsc1131361-fix-stack-overflow-xhci.patch to fix stack
    overflow in UsbBusDxe and UsbBusPei (bsc#1131361, CVE-2019-0161)
* Mon Mar 25 2019 glin@suse.com
  - Add ovmf-bsc1130267-overflow-in-partition-and-udf.patch to fix
    buffer overflows in PartitionDxe and UdfDxe (bsc#1130267,
    CVE-2019-0160)
* Mon Mar 11 2019 glin@suse.com
  - Add ovmf-bsc1128503-fix-stack-overflow-in-HiiImage-and-HiiDatabase.patch
    to fix stack overflow in HiiImange and HiiDatabase (bsc#1128503,
    CVE-2018-12181)
* Tue Mar 05 2019 glin@suse.com
  - Add ovmf-bsc1127820-fix-blockio-buffer-overflow.patch to fix
    buffer overflow in BlockIo protocol (bsc#1127820, CVE-2018-12180)
  - Add ovmf-bsc1127821-dns-check-packet-size.patch to check the size
    of the received DNS packet (bsc#1127821, CVE-2018-12178)
  - Add ovmf-bsc1127822-fix-fv-parsing.patch to fix the logic error
    in FV parsing (bsc#1127822, CVE-2018-3630)
* Wed Dec 05 2018 glin@suse.com
  - Update ovmf-embed-default-keys.patch and add owner-guid-zero.h to
    set the default owner of PK/KEK/db/dbx and make the
    auto-enrollment only happen at the very first time. (bsc#1117998)
* Wed Nov 14 2018 glin@suse.com
  - Add ovmf-bsc1115916-fix-timestamp-zeroing.patch to fix Timestamp
    zeroing issue on APPEND_WRITE (bsc#1115916, CVE-2018-3613)
  - Add ovmf-bsc1115917-bounds-checking-for-ueficompress.patch for
    the bound checking of ueficompress (bsc#1115917, CVE-2017-5731,
    CVE-2017-5732, CVE-2017-5733, CVE-2017-5734, CVE-2017-5735)
* Tue Jul 10 2018 glin@suse.com
  - Add ovmf-bsc1099193-fix-sev-flash-variables.patch to fix the
    missing EFI variables when SEV is set (bsc#1099193)
* Wed May 23 2018 glin@suse.com
  - Update openssl to 1.1.0h (bsc#1094289, CVE-2018-0739)
* Mon May 14 2018 glin@suse.com
  - Add ovmf-bsc1092943-fix-attributes-table.patch to avoid sending
    the memory map with invalid attributes (bsc#1092943)
* Wed Jan 24 2018 glin@suse.com
  - Only use SLES-UEFI-CA-Certificate-2048.crt for the suse flavor to
    provide the better compatibility (bsc#1077330)
* Mon Nov 20 2017 glin@suse.com
  - Update to 2017+git1510945757.b2662641d5
    + ArmPlatformPkg/ArmPlatformLibNull: remove bogus PCD dependencies
    + MdeModulePkg/UsbMassStorageDxe: Enhance Request Sense Handling
    + OvmfPkg: save on I/O port accesses when the debug port is not
      in use
    + OvmfPkg: create a separate PlatformDebugLibIoPort instance for
      SEC
    + OvmfPkg: make PlatformDebugLibIoPort a proper BASE library
    + OvmfPkg: restore temporary SEC/PEI RAM size to 64KB
    + OvmfPkg/Sec/X64: seed the temporary RAM with PcdInitValueInTempStack
    + ArmVirtPkg: switch to new PL011UartLib implementation
    + OvmfPkg/XenHypercallLib: enable virt extensions for ARM
    + MdeModulePkg/PiSmmCore: Implement heap guard feature for SMM mode
    + MdeModulePkg/DxeCore: Implement heap guard feature for UEFI
    + ArmVirtPkg/ArmVirtQemu: use non-accelerated CopyMem for
      VariableRuntimeDxe
    + NetworkPkg: Fix incorrect SizeofHeaders returned from
      HttpTcpReceiveHeader()
    + NetworkPkg: Print error message to screen if error occurs
      during HTTP boot
    + MdeModulePkg/PartitionDxe: Fix UDF fs access on certain CD/DVD
      medias
    + MdeModulePkg/UsbMassStorageDxe: Fix USB Mass Storage detection
    + MdeModulePkg SerialDxe: Handle Timeout change more robustly
    + CryptoPkg/BaseCryptLib: Fix mismatched memory allocation/free
    + CryptoPkg/BaseCryptLib: Fix buffer overflow issue in realloc
      wrapper
    + ArmPlatformPkg/PlatformPeim: allow PlatformPeiLib to set the
      boot mode
    + Deprecate EFI_VARIABLE_AUTHENTICATED_WRITE_ACCESS
    + SecurityPkg: Remove Counter Based AuthVariable support
    + BaseTools/tools_def AARCH64 ARM: disable PIE linking
    + NetworkPkg/TlsAuthConfigDxe: Remove the extra FreePool
    + NetworkPkg/HttpBootDxe: Add IPv6 support condition check
    + NetworkPkg/IScsiDxe: Fix the incorrect/needless DHCP process
    + MdeModulePkg/PciBus: Fix bug that PCI BUS claims too much resource
    + UefiCpuPkg/MtrrLib: Use SetMem instead of SetMem64 to fix hang
    + NetworkPkg: Remove ping6 and ifconfig shell application
    + OvmfPkg: fix dynamic default for oprom verification policy PCD
      without SB
    + OvmfPkg/PlatformPei: DENY_EXECUTE_ON_SECURITY_VIOLATION when
      SEV is active
    + SecurityPkg\Tcg2Pei: FV measure performance enhancement
    + SecurityPkg:AuthVariableLib:Implement ECR1707 for Private Auth
      Variable
    + ArmPlatformPkg: Store initial timer value
    + ArmVirtPkg ArmVirtDxeHobLib: Implement BuildFv3Hob
    +  MdeModulePkg/Variable/RuntimeDxe: delete and lock OS-created
      MOR variable
    + ArmPkg/PlatformBootManagerLib: fix bug in ESRT invocation
    + OvmfPkg/PciHotPlugInitDxe: translate QEMU's resource
      reservation hints
    + OvmfPkg/PciHotPlugInitDxe: generalize RESOURCE_PADDING
      composition
    + OvmfPkg/IndustryStandard: define PCI Capabilities for QEMU's
      PCI Bridges
    + MdeModulePkg/BdsDxe: Don't delete "BootNext" until booting it
    + Clarify the usage of HttpConfigData in HTTP protocol
    + SecurityPkg/SecureBootConfigImpl.c: Secure Boot DBX UI
      Enhancement
    + MdeModulePkg/UDF: Fix creation of UDF logical partition
    + CryptoPkg: Add new API to retrieve commonName of X.509 certificate
    + OvmfPkg/VirtioNetDxe: log debug message in VirtioNetExitBoot()
    + OvmfPkg/QemuBootOrderLib: recognize "usb-storage" devices in
      XHCI ports
    + MdeModulePkg/Core: Fix out-of-sync issue in GCD
    + UefiCpuPkg/CpuDxe: Fix out-of-sync issue in page attributes
    + OvmfPkg/QemuVideoDxe/VbeShim: handle PAM1 register on Q35
      correctly
    + OvmfPkg/QemuVideoDxe/VbeShim: rename Status to
      Segment0AllocationStatus
    + OvmfPkg/CsmSupportLib: move PAM register addresses to
      IndustryStandard
    + NetworkPkg/IScsiDxe: Remove redundant call to StrLen
    + BaseTools/tools_def AARCH64: enable frame pointers for RELEASE
      builds
    + ArmPkg/PlatformBootManagerLib: process pending capsules
    + MdeModulePkg/Udf: Avoid declaring and initializing local GUID
      variable
    + MdeModulePkg/UdfDxe: Avoid short (single character) variable name
    + MdeModulePkg/UdfDxe: Use compare operator for non-boolean
      comparisons
    + MdeModulePkg/UdfDxe: Fix operands of different size in bitwise
      OP
    + MdeModulePkg/UdfDxe: Add checks to ensure no possible NULL ptr
      deref
    + MdeModulePkg/SerialDxe: Fix not able to change serial attributes
    + NetworkPkg: Remove the redundant '/' in the end of returned
      ISCSIMacAddr keyword
    + MdeModulePkg/UdfDxe: Fix NULL pointer dereference
    + OvmfPkg/VirtioNetDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioNetDxe: map caller-supplied Tx packet to
      device-address
    + OvmfPkg/VirtioNetDxe: add Tx packet map/unmap helper functions
    + OvmfPkg/VirtioNetDxe: update TechNotes
    + OvmfPkg/VirtioNetDxe: dynamically alloc transmit header
    + OvmfPkg/VirtioNetDxe: alloc RxBuf using AllocateSharedPages()
    + OvmfPkg/VirtioNetDxe: map VRINGs using VirtioRingMap()
    + OvmfPkg/VirtioNetDxe: add helper VirtioNetUninitRing()
  - Update openssl to 1.1.0g
* Mon Oct 16 2017 glin@suse.com
  - Update ovmf-gdb-symbols.patch to avoid some symbols from being
    removed (bsc#1063463)
  - Add needssslcertforbuild back. It's useful for the devel projects.
* Thu Sep 14 2017 glin@suse.com
  - Update to 2017+git1505340320.5afa5b8159
    + MdeModulePkg/UdfDxe: suppress incorrect compiler warning in
      ReadFile()
    + MdeModulePkg/UdfDxe: reject reserved values in ICB.Flags[2:0]
    + MdeModulePkg: Add UdfDxe to the dsc file
    + MdeModulePkg: Update PiDxeS3BootScriptLib Internal function name
    + MdeModulePkg/UdfDxe: Remove negative comparison of unsigned
      number
    + ArmVirtPkg/ArmVirtQemu: port HTTP_BOOT_ENABLE from OvmfPkg
    + ArmVirtPkg: don't build the network stack uselessly for Xen
    + MdeModulePkg/PartitionDxe: remove always false comparison
    + MdeModulePkg/PartitionDxe: don't divide 64-bit values with C
      operators
    + MdeModulePkg/UdfDxe: replace zero-init of local variables with
      ZeroMem()
    + MdeModulePkg/UdfDxe: don't return unset Status if INLINE_DATA
      req succeeds
    + MdeModulePkg/UdfDxe: ASSERT() valid ReadFileInfo Flags for
      INLINE_DATA req
    + MdeModulePkg/UdfDxe: Initialize the array after declaration
    + ShellPkg/Ifconfig6: Update error message and add a new line
    + NetworkPkg/IScsiDxe: Fix the incorrect max length of IP_ADDRESS
    + OvmfPkg/SataControllerDxe: log informative message at
      DEBUG_INFO level
    + OvmfPkg/PlatformBootManagerLib: log informative message at
      DEBUG_INFO lvl
    + OvmfPkg/PlatformPei: log informative message at DEBUG_INFO level
    + UefiCpuPkg/CpuDxe: log informative message at DEBUG_INFO level
    + MdeModulePkg/UsbBusDxe: log warning message at DEBUG_WARN level
    + OvmfPkg/PlatformDebugLibIoPort: write messages with IoWriteFifo8()
    + MdePkg/BaseIoLibIntrinsic: fix SEV (=unrolled) variants of IoWriteFifoXX()
    + MdeModulePkg Xhci: Correct description of Timeout param in XhciReg.h
    + BaseTools/GCC: set -Wno-unused-const-variable on RELEASE builds
    + ArmVirtPkg: Enable UDF file system support
    + OvmfPkg: Enable UDF file system support
    + MdeModulePkg/PartitionDxe: Add UDF file system support
    + OvmfPkg/IoMmuDxe: unmap all IOMMU mappings at ExitBootServices()
    + OvmfPkg/IoMmuDxe: generalize IoMmuUnmap() to IoMmuUnmapWorker()
    + OvmfPkg/IoMmuDxe: track all mappings
    + OvmfPkg/VirtioScsiDxe: don't unmap VRING at ExitBootServices()
    + OvmfPkg/VirtioRngDxe: don't unmap VRING at ExitBootServices()
    + OvmfPkg/VirtioGpuDxe: don't unmap VRING & BackingStore at ExitBootServices
    + OvmfPkg/VirtioBlkDxe: don't unmap VRING at ExitBootServices()
    + MdeModulePkg/AtaAtapiPassThru: disable the device at ExitBootServices()
    + MdeModulePkg/AtaAtapiPassThru: unmap DMA buffers after disabling
      BM DMA
    + MdeModulePkg/AtaAtapiPassThru: cache EnabledPciAttributes
    + OvmfPkg/SecMain: Fix stack switching to permanent memory
    + ArmPkg: add ArmCrashDumpDxe driver
    + MdeModulePkg, NetworkPkg: Fix GCC build error
    + NetworkPkg/Ip6Dxe: fix a bug in IP6 driver for IpSec protocol
      notify
    + MdeModulePkg/Ip4Dxe: fix a bug in IP4 driver for IpSec protocol
      notify
    + MdePkg: Add UEFI 2.7 defined GUID and structure for AIP network
      media type
    + MdeModulePkg/UefiBootManagerLib: Generate boot description for
      SD/eMMC
    + Pkcs7VerifyDxe: Don't allow Pkcs7Verify to install protocols twice
    + SecurityPkg/Pkcs7Verify: Complete the Pkcs7VerifyDxe protocol
    + MdePkg PeiMemoryAllocationLib: Update InternalAllocateAlignedPages
    + MdePkg PeiMemoryAllocationLib: Update Free(Aligned)Pages
    + MdeModule PeiCore: Support pre memory page allocation
    + OvmfPkg/VirtioGpuDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioGpuDxe: map backing store to bus master device address
    + OvmfPkg/VirtioGpuDxe: helpers for backing store (de)allocation+(un)mapping
    + OvmfPkg/VirtioGpuDxe: take EFI_PHYSICAL_ADDRESS in ResourceAttachBacking()
    + OvmfPkg/VirtioGpuDxe: map virtio GPU command objects to device
      addresses
    + OvmfPkg/VirtioGpuDxe: map VRING for bus master common buffer
      operation
    + OvmfPkg/IoMmuDxe: IoMmuFreeBuffer(): clean up DEBUG message
    + OvmfPkg/IoMmuDxe: IoMmuAllocateBuffer(): nicer and more
      informative DEBUGs
    + OvmfPkg/IoMmuDxe: IoMmuUnmap(): clean up DEBUG message
    + OvmfPkg/IoMmuDxe: IoMmuMap(): log nicer and more informative
      DEBUG msgs
    + OvmfPkg/BaseMemEncryptSevLib: clean up upper-case / lower-case
      in DEBUGs
    + OvmfPkg/BaseMemEncryptSevLib: promote DEBUG_WARN levels to
      DEBUG_ERROR
    + OvmfPkg/BaseMemEncryptSevLib: clean up debug logging of
      PhysicalAddress
    + OvmfPkg/BaseMemEncryptSevLib: clean up DEBUG prefixes
    + OvmfPkg/BaseMemEncryptSevLib: break DEBUG calls to multiple lines
    + OvmfPkg/BaseMemEncryptSevLib: unify encrypt/decrypt DEBUG messages
    + ArmPkg: remove ArmDmaLib
    + OvmfPkg/VirtioScsiDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioScsiDxe: map virtio-scsi request and response buffers
    + OvmfPkg/VirtioScsiDxe: add helper to create a fake host adapter error
    + OvmfPkg/VirtioScsiDxe: map VRING using VirtioRingMap()
    + ArmPkg: remove UncachedMemoryAllocationLib
    + BaseTools/Gcc ARM AARCH64: add support for building device tree
      binaries
    + BaseTools: Enable --whole-archive in GCC tool chain as the
      default option
    + UefiCpuPkg/Mplib.c: Perform complete initialization when enable AP
    + OvmfPkg/VirtioBlkDxe: Check the return status of unmap data buffer
    + ArmVirtPkg: remove DmaLib library class resolution
    + ShellPkg: Update CWD and current mapping when commands return
    + ShellPkg: Fix bug that fails to change CWD after "map -r"
    + SecurityPkg: Add ARM/AARCH64 arch to enable RngTest module build
    + OvmfPkg/QemuFwCfgDxeLib: SEV: zero FW_CFG_DMA_ACCESS before
      decrypting it
    + ArmPkg/ArmDmaLib: implement DmaAllocateAlignedBuffer()
    + MdeModulePkg/UefiHiiLib: Fix incorrect check for string length
    + OvmfPkg/VirtioBlkDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + Ovmfpkg/VirtioBlkDxe: map virtio-blk request and response buffers
    + OvmfPkg/VirtioBlkDxe: map VRING using VirtioRingMap()
    + MdePkg/S3PciSegmentLib: Add S3PciSegmentLib class and instance
    + MdePkg/PciSegmentLib: Add instances that consumes PciSegmentInfoLib
    + MdePkg/PciSegmentInfoLib: Add PciSegmentInfoLib class and instance
    + UefiCpuPkg/CpuCommonFeaturesLib: Add CPUID MCA support check
    + UefiCpuPkg: Update default for PcdCpuProcTraceMemSize/PcdCpuProcTraceOutputScheme
    + UefiCpuPkg/CpuCommonFeaturesLib: Use MSR data structure when
      change MSR value
    + UefiCpuPkg/ArchitecturalMsr.h: Add RTIT TOPA table entry
      definition
    + UefiCpuPkg/MpLib: fix potential overflow issue
    + UefiCpuPkg/PiSmmCpuDxeSmm: Fix memory protection crash
    + BaseTools/EfiRom: Add multiple device id support
    + OvmfPkg/VirtioRngDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/Virtio10: define VIRTIO_F_IOMMU_PLATFORM feature bit
    + MdeModulePkg XhciDxe: Fix Map and Unmap inconsistency
    + SecurityPkg/Tcg2Dxe: Properly shutdown TPM before reset
    + OvmfPkg/VirtioRngDxe: map host address to device address
    + OvmfPkg/VirtioLib: change the parameter of VirtioAppendDesc()
      to UINT64
    + OvmfPkg/VirtioLib: alloc VRING buffer with AllocateSharedPages()
    + OvmfPkg/VirtioLib: add function to map VRING
    + OvmfPkg/Virtio10Dxe: add the RingBaseShift offset
    + OvmfPkg/Virtio: take RingBaseShift in SetQueueAddress()
    + OvmfPkg/VirtioLib: take VirtIo instance in VirtioRingInit/VirtioRingUninit
    + OvmfPkg/VirtioLib: add VirtioMapAllBytesInSharedBuffer() helper
      function
    + OvmfPkg/VirtioMmioDeviceLib: implement IOMMU-like member functions
    + OvmfPkg/VirtioPciDeviceDxe: implement IOMMU-like member functions
    + OvmfPkg/Virtio10Dxe: implement IOMMU-like member functions
    + OvmfPkg: introduce IOMMU-like member functions to VIRTIO_DEVICE_PROTOCOL
    + BaseTools: Add the missing -pie link option in GCC tool chain
    + ArmPkg/ArmDmaLib: remove dependency on UncachedMemoryAllocationLib
    + OvmfPkg/QemuVideoDxe: remove AARCH64/ARM support
    + ArmVirtPkg: remove QemuVideoDxe from ArmVirtQemu and ArmVirtQemuKernel
    + BaseTools: Roll back GenFw Change to keep unknown field in RSDS
      debug entry
    + MdeModulePkg/DisplayEngine: Add implementation of HiiPopup protocol
    + MdeModulePkg/Library: Remove the self-reference in
      UdpIoLib/TcpIoLib/IpIoLib
    + ShellPkg/mkdir: support creating nested directories
    + MdeModulePkg/ScsiBusDxe: don't produce ScsiIo for nonexistent LUNs
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add CPUID MCA support check
    + ArmPkg/ArmDmaLib: use double buffering only for bus master write
    + ArmVirtPkg/FdtPL011SerialPortLib: call PL011UartLib in all
      SerialPortLib APIs
    + UefiCpuPkg RegisterCpuFeaturesLib: Fix buffer pointer error usage
    + NetworkPkg/Ip6Dxe: Fix the bug when checking the DataSize
    + MdePkg/BaseLib: Update internal LinkedList verifications
    + MdePkg/BaseLib: Add IsNodeInList() function
    + MdeModulePkg: Delete useless case code
    + MdeModulePkg: Delete never touched code
    + UefiCpuPkg/BaseUefiCpuLib.inf: Remove unnecessary library class
    + UefiCpuPkg RegisterCpuFeaturesLib: Enhance debug messages.
* Mon Aug 28 2017 glin@suse.com
  - Update ovmf-embed-default-keys.patch to handle the empty
    certificate files correctly
* Thu Aug 17 2017 glin@suse.com
  - Update to 2017+git1502826981.a136bc3ccf
    + OvmfPkg/Protocol/VirtioDevice: fix comment style
    + OvmfPkg/VirtioMmioDeviceLib: add missing IN and OUT decoration
    + OvmfPkg/VirtioPciDeviceDxe: add missing IN and OUT decoration
    + OvmfPkg/Virtio10Dxe: supply missing BUS_MASTER attribute
    + OvmfPkg/VirtioPciDeviceDxe: supply missing BUS_MASTER attribute
    + UefiCpuPkg MpInitLib: Save/restore original WakeupBuffer for
      DxeMpLib
    + ShellPkg UefiDpLib: Init CustomCumulativeData.MinDur
    + MdeModulePkg DxeCore: Enhance "ConvertPages: Incompatible
      memory types"
    + MdeModulePkg DxeCore: Fix double free pages on LoadImage
      failure path
    + NetworkPkg/HttpBootDxe: Update device path node to include DNS
      information
    + MdeModulePkg/UefiBootManagerLib: Support DNS device path
      description
    + MdePkg/UefiDevicePathLib: Add DevPathFromTextDns and
      DevPathToTextDns libraries
    + MdePkg/DevicePath.h: Add DNS Device Path definition
    + NetworkPkg/HttpDxe: Handle the HttpVersionUnsupported in the
      HttpConfigData
    + BaseTools: Support TabSpace between section tag in DEC file
    + BaseTools: Don't need to add extra quotes when UI string from
      file
    + BaseTools/UPT: Support Multiple Installation
    + BaseTools/Scripts: Add sample makefile for use with
      RunMakefile.py
    + BaseTools/Scripts: Add python script to run a makefile
    + BaseTools/build: Expand PREBUILD/POSTBUILD DSC actions
    + NetworkPkg/Ip6Dxe: Support SetData interface to clear specific
      configuration
    + MdeModulePkg/Ip4Dxe: Support SetData interface to clear
      specific configuration
    + ShellPkg/drivers: Fix GCC build failure
    + BaseTools/edksetup.sh: fix invalid test for current working
      directory
    + ShellPkg/driver: Show "-" in non-SFO mode
    + ShellPkg/drivers: Show Image Name in non-SFO mode
    + MdeModulePkg: Variable: Fix typo in variable measure
    + MdeModulePkg/NvmExpressDxe: Notify NVME HW when system reset
      happens
    + MdePkg/Nvme: Add NVME shutdown notification related macros
    + NetworkPkg/HttpBootDxe: Refine the coding style.
    + OvmfPkg/AcpiPlatformDxe: short-circuit the transfer of an empty
      S3_CONTEXT
    + MdeModulePkg SerialDxe: Process timeout consistently in
      SerialRead
    + UefiCpuPkg MtrrLib: Remove deprecated micro.
    + UefiCpuPkg CpuDxe: Remove reference deprecated macro.
    + UefiCpuPkg CpuDxe: Enhance get mtrr mask logic.
    + BaseTools/Conf: apply nasmb, asm16 build rule order
    + NetworkPkg/HttpDxe: Support HTTP Patch method
    + OvmfPkg/PlatformPei: support >=1TB high RAM, and discontiguous
      high RAM
    + OvmfPkg/QemuFwCfgLib: Use BusMasterCommonBuffer to map
      FW_CFG_DMA_ACCESS
    + OvmfPkg/IoMmuDxe: Unmap(): recycle MAP_INFO after
      BusMasterCommonBuffer[64]
    + OvmfPkg/IoMmuDxe: abort harder on memory encryption mask
      failures
    + OvmfPkg/IoMmuDxe: implement in-place decryption/encryption for
      Map/Unmap
    + OvmfPkg/IoMmuDxe: rework setup of "MapInfo->PlainTextAddress"
      in Map()
    + OvmfPkg/IoMmuDxe: zero out pages before releasing them
    + OvmfPkg/IoMmuDxe: clean up used library classes
    + OvmfPkg/IoMmuDxe: propagate errors from AmdSevInstallIoMmuProtocol()
    + OvmfPkg/IoMmuDxe: don't initialize local variables
    + OvmfPkg/IoMmuDxe: convert UINTN arguments to UINT64 for the
      %Lx fmt spec
    + OvmfPkg/IoMmuDxe: rename HostAddress to CryptedAddress in
      MAP_INFO
    + OvmfPkg/IoMmuDxe: rename DeviceAddress to PlainTextAddress in
      MAP_INFO
    + OvmfPkg/IoMmuDxe: rewrap source code to 79 characters
    + OvmfPkg/IoMmuDxe: Fix header guard macro
    + MdeModulePkg/DisplayEngine: Fix incorrect display issue
    + BaseTools/VfrCompile: Remove the MAX_PATH limitation
    + BaseTools/VfrCompile: Fix segmentation fault issues
    + NetworkPkg: iSCSI should allow to set 6 or 12 length of ISID
      keyword.
    + UefiCpuPkg: Enable Processor Trace feature.
    + UefiCpuPkg: Add Processor Trace feature definition.
    + UefiCpuPkg: Add Pcds used by processor trace feature.
    + UefiCpuPkg/Msr: Add a missing IvyBridge processor signature
    + MdeModulePkg PeiCore: Install SEC HOB data
    + MdePkg: Add definition for SecHobData PPI
    + UefiCpuPkg PiSmmCpuDxeSmm: Check LMCE capability when wait for
      AP.
    + UefiCpuPkg CpuCommonFeaturesLib: Enable LMCE feature.
    + UefiCpuPkg: Add definition for LMCE feature.
    + NetworkPkg: Display HTTP redirection info to the screen if need.
    + ShellPkg/dblk: Honor the BlockIo alignment requirement.
    + MdeModulePkg/Ufs: Set 'Data Segment Length' field for Write
      Descriptor
    + MdeModulePkg/UfsPassThruDxe: Add impl of UFS Device Config
      Protocol
    + UefiCpuPkg SecCore: Fix operands of different size in bitwise
      operation
    + MdePkg/Ftp4: Fix wrong function pointer declaration
    + NetworkPkg/HttpDxe: Destroy the TLS instance when cleaning up
      the HTTP child
    + CryptoPkg/TlsLib: Remove the redundant free of BIO objects
    + NetworkPkg/Ip6Dxe: Fix the IPv6 PXE boot option goes missing
      issue
    + Fix spelling typo in EFI_HTTP_STATUS_CODE
    + NetworkPkg/HttpDxe: Refine the coding style.
    + MdePkg/Http.h: Refine the coding style.
    + ArmPkg: Move IS_DEVICE_PATH_NODE for sharing
    + MdeModulePkg FirmwarePerfPei: Remove SEC performance data
      getting code
    + UefiCpuPkg SecCore: Add SecPerformancePpiCallBack
    + UefiCpuPkg SecCore: Adjust PeiTemporaryRamBase&Size to be
      8byte aligned
    + MdeModulePkg PeiCore: Handle notification PPI from SEC
    + MdePkg PiPeiCis.h: Add description for notification PPI from
      SEC
    + MdeModulePkg PiSmmCoreMemoryAllocLib: Fix a FreePool()
      assertion issue
    + BaseTools/GenCrc32: Fix a bug to hand empty file for decode
    + BaseTools/EfiLdrImage: Fix a segmentation fault from
      vfprintf()
    + BaseTools/EfiRom: Fix a segmentation fault from
      vsprintf()/vfprintf()
    + BaseTools/GenFfs: Fix a segmentation fault from
      vsprintf()/vfprintf()
    + BaseTools/GenSec: Fix a segmentation fault in main()
    + BaseTools/Split: Fix the segmentation fault in GetSplitValue()
    + BaseTools: Fix the bug to correctly check Pcd type that in FDF
      file
    + MdeModulePkg/PciBus: Avoid hang when BUS pad resource is not
      in top
    + ShellPkg: Avoid buffer out-of-bound access
    + ShellPkg/setvar: Check the duplicate flag
    + ShellPkg/ShellLib: Remove unused macros
    + MdePkg: Follow UEFI 2.7 spec to deprecate SMM Communication
      ACPI Table
    + UefiCpuPkg PiSmmCommunicationSmm: Deprecate SMM Communication
      ACPI Table
    + MdeModulePkg/BMMUiLib: Check reset requirement before exiting
      UiApp
    + MdeModulePkg/BMUiLib: Check reset requirement before exiting
      UiApp
    + MdeModulePkg/SetupBrowser: Record the reset status in all
      SendForm
    + ShellPkg/map: Recognize CDROM change
    + MdeModulePkg Xhci: Also RecoverHaltedEndpoint for BABBLE_ERROR
    + MdeModulePkg SmmLockBoxDxeLib: Get SmmCommRegion for COMM
      buffer
    + MdePkg/ResetNotification: Rename to UnregisterResetNotify
    + MdePkg: Add UEFI 2.7 defined GUID and structure for KMS
      protocol.
    + ShellPkg/ls: Display the file time in local time.
    + BaseTools: Fix the bug that warn() function with only 1
      argument
    + BaseTools: add some comment for .PrebuildEnv file's usage
    + UefiCpuPkg: Update RegisterCpuFeaturesLib to consume
      PcdGetSize with UINTN
    + UefiCpuPkg: Update RegisterCpuFeaturesLib module UNI to match
      it
    + MdeModulePkg: Update NonDiscoverableDeviceRegistrationLib file
      header format
    + MdePkg UsbFunctionIo.h: Update comments for GetDeviceInfo
      return status
    + UefiCpuPkg: Remove deprecated CPU feature.
    + MdeModulePkg SmmAccess: Update comments to follow PI spec.
    + MdePkg SmmAccess2: Update comments to follow PI spec.
    + UefiCpuPkg RegisterCpuFeaturesLib: Add error handling.
    + MdeModulePkg/DxeCore: Avoid accessing non-owned memory
    + MdePkg DxeHstiLib: Fix memory leak issue
    + MdePkg Hsti.h: Update version info to 1.1a
    + ArmPlatformPkg: Support different PL011 reg offset
    + CryptoPkg/OpensslLib AARCH64: clear XIP CC flags
    + BaseTools/tools_def AARCH64: avoid SIMD registers in XIP code
    + BaseTools/tools_def AARCH64: mark register x18 as reserved
    + BaseTools/Build: Support python scripts in PREBUILD/POSTBUILD
    + UefiCpuPkg CpuCommonFeaturesLib: Fix smx/vmx enable logic
      error.
    + UefiCpuPkg RegisterCpuFeaturesLib: Add error handling code.
    + OvmfPkg/QemuFwCfgLib: Suppress GCC49 IA32 build failure
    + MdePkg: Declare _ReturnAddress() in Base.h for MSFT tool chain
    + OvmfPkg: update PciHostBridgeDxe to use PlatformHasIoMmuLib
    + OvmfPkg/QemuFwCfgLib: Add SEV support
    + OvmfPkg: Add IoMmuDxe driver
    + OvmfPkg: Add PlatformHasIoMmuLib
    + OvmfPkg: Add AmdSevDxe driver
    + OvmfPkg/PlatformPei: Set memory encryption PCD when SEV is
      enabled
    + OvmfPkg/BaseMemcryptSevLib: Add SEV helper library
    + OvmfPkg: Update dsc to use IoLib from BaseIoLibIntrinsicSev.inf
    + OvmfPkg/ResetVector: Set C-bit when building initial page table
    + MdeModulePkg/XhciDxe: Make comments align with function
    + MdeModulePkg/PartitionDxe: Add impl of Partition Information
      Protocol
    + MdePkg: Add EFI Partition Information Protocol definitions
    + BaseTools: Report Fd File Path in build log
    + BaseTools: Fix FDF file parse !include file issue
    + BaseTools: Add PCDs conditional operator function
    + BaseTools/Eot: register MM Module types with FFS class.
    + BaseTools/Workspace: check MM module type compatibility with
      PI version.
    + BaseTools/build: register MM module types with build tools.
    + BaseTools/GenFds: register MM Modules and MM FV file types.
    + BaseTools/CommonDataClass: register MM Modules.
    + BaseTools/Common: add support in FDF Parser to parse MM
      Modules.
    + BaseTools/Common: add MM Module data types.
    + BaseTools/AutoGen: auto generate MM template APIs and
      dependencies.
    + BaseTools/GenFw: recognize MM file types as EFI Boot Service
      Drivers.
    + BaseTools/GenFfs: add FFS file types for MM modules.
    + UefiCpuPkg MpInitLib: Update return status to follow spec.
    + UefiCpuPkg CpuMpPei: Update return status to follow spec.
    + UefiCpuPkg CpuDxe: Update return status to follow spec.
    + MdePkg MpServices: Update return status to follow spec.
    + BaseTools/GenFw: disregard payload in PE debug directory entry
      size
    + MdeModulePkg/NvmExpressDxe: Handle timeout for blocking
      PassThru req
    + OvmfPkg: mention the extended TSEG near the PcdQ35TsegMbytes
      declaration
    + OvmfPkg/PlatformPei: honor extended TSEG in PcdQ35TsegMbytes
      if available
    + OvmfPkg/SmmAccess: support extended TSEG size
    + OvmfPkg/IndustryStandard/Q35MchIch9.h: add extended TSEG size
      macros
    + OvmfPkg: make PcdQ35TsegMbytes dynamic
    + OvmfPkg/SmmAccess: prepare for PcdQ35TsegMbytes becoming dynamic
    + OvmfPkg/PlatformPei: prepare for PcdQ35TsegMbytes becoming dynamic
    + OvmfPkg: widen PcdQ35TsegMbytes to UINT16
    + OvmfPkg: update -D E1000_ENABLE from Intel PROEFI v.07 to
      BootUtil v.22
    + OvmfPkg: disable build-time relocation for DXEFV modules
    + ArmVirtPkg: remove status code support
    + ArmPlatformPkg: convert VExpress ResetSystemLib to
      ResetSystemLib
    + MdeModulePkg/XhciDxe: Check timeout URB again after stopping
      endpoint
    + MdeModulePkg/XhciDxe: Separate common logic to XhcTransfer
    + MdeModulePkg/XhciDxe: Dump the CMD/EVENT/INT/BULK ring
      information
    + MdeModulePkg/XhciDxe: Refine IsTransferRingTrb and
      IsAsyncIntTrb
    + BaseTools: suppress usage instructions with rebuild options
    + ArmVirtPkg: switch to generic ResetSystemRuntimeDxe
    + ArmPkg: implement ResetSystemLib using PSCI 0.2 calls
    + MdeModulePkg CapsuleApp: Fix print info in BuildGatherList()
    + MdeModulePkg ResetSystem: Update the comments of ResetSystem()
    + MdeModulePkg/ResetSystem: Implement ResetNotification protocol
    + MdeModulePkg/ResetSystem: Remove unnecessary global variable
    + MdePkg: Add ResetNotification protocol definition
    + MdeModulePkg PeiCore: Correct the comments of PeiResetSystem2
    + MdePkg: Correct the comments of EFI_PEI_RESET2_SYSTEM
    + ShellPkg: Update dh command to reflect correct driver field
      information
    + MdeModulePkg/AtaAtapiPassThru: relax PHY detect timeout
    + MdePkg/IndustryStandard: update ACPI/IORT definitions to
      revision C
    + ShellPkg DmpStore: Make NameSize to be consistent with name
      buffer
    + MdeModulePkg/BdsDxe: Report Status Code when booting from
      BootOrder list
    + MdePkg/PiStatusCode: Add new Status Code for BDS when
      attempting BootOrder
    + Revert "MdeModulePkg/DxeCore: Fixed Interface returned by
      CoreOpenProtocol"
    + UefiCpuPkg: Modify GetProcessorLocationByApicId() to support
      AMD.
    + UefiCpuPkg: Add CPUID definitions for AMD.
    + UefiCpuPkg: Define AMD Memory Encryption specific CPUID and MSR
    + MdeModulePkg DxeCore: Only free ScratchBuffer when it is not
      NULL
    + MdeModulePkg/DxeCore: Fixed Interface returned by
      CoreOpenProtocol
    + BaseTools/PatchCheck.py: Add warning info for new binary files
    + BaseTools/PatchCheck.py: Fix misreport for binary changes in
      patch
    + BaseTools: support building the same INF more than once with
    - m option
    + BaseTools: report error HiiString in HII format PCD must not
      be empty
    + BaseTools: Fix the bug that use '|' or '||' in DSC file's Pcd
      value
    + BaseTools: Enhance the report to not show the empty section
    + BaseTools: Enhance DEC Defines section format check
    + BaseTools: Copy "TianoCore" userextensions into As Built Inf
    + BaseTools: Copy "MODULE_UNI_FILE" file into OUTPUT directory
    + MdePkg/Cper.h: Update Firmware Error Record per UEFI 2.7
    + MdeModulePkg: Enhance the debug message for
      InstallProtocolInterface
    + MdePkg: update Base.h in MdePkg to check the _MSC_VER
    + BaseTools: add /Gw to CC_FLAGS for VS2013 and higher tool
      chain tags
    + NetworkPkg: Fix GCC build issue.
    + BaseTools/tools_def: AARCH64: disable LTO type mismatch
      warnings
    + BaseTools/tools_def GCC: ARM/AARCH64: drop -save-temps from
      command line
    + MdeModulePkg Variable: Add missing change in dd59d95e1994
    + MdeModulePkg: Minor update to the Data parameter for PEI
      GetVariable()
    + MdePkg: Minor update to the Data parameter for PEI
      GetVariable()
    + NetworkPkg/HttpBootDxe: Add HTTP Boot Callback protocol
      support.
    + MdePkg: Add header file for HTTP Boot Callback protocol
      in UEFI 2.7.
    + MdeModulePkg: Return invalid param in LocateProtocol for
      Protocol==NULL
    + MdePkg: Add EFI UFS Device Config Protocol definitions
    + MdeModulePkg: Fix use-after-free error in
      InstallConfigurationTable()
    + MdeModulePkg: Clean ACPI 2.0 characters in UEFI spec
    + MdePkg: Clean ACPI 2.0 characters in UEFI spec
    + UefiCpuPkg/SmmCpuFeatureLib: Add more CPU ID for
      SmmFeatureControl.
    + ShellBinPkg: Ia32/X64 Shell binary update.
    + MdeModulePkg/BMMUiLib: Fix incorrect variable name
    + SecurityPkg TcgDxe: Simplify debug msg when "TPM not working
      properly"
    + ShellPkg: Fix typo errors in ifconfig help output
    + Shell/alias: Print detailed error when deleting alias
    + OvmfPkg/AcpiPlatformDxe: fix spurious uninitialized var warning
    + NetworkPkg/HttpBootDxe: Handle new #define in HttpBootDxe
    + MdeModulePkg/DxeHttpLib: Handle new #define in
      HttpMappingToStatusCode
    + MdePkg/Http.h: Add #define for 308 redirect
    + ShellPkg/ifconfig: Update help message
    + MdeModulePkg/PciHostBridgeDxe: Make bitwise operands of the
      same size
    + OvmfPkg/AcpiPlatformDxe: alloc blobs from 64-bit space unless
      restricted
    + BaseTools: Fix the bug use same FMP_PAYLOAD in different
      capsule file
    + BaseTools: Fix incremental build failure that override file be
      removed
    + ShellBinPkg: Ia32/X64 Shell binary update.
    + ShellPkg/parse: Handle Unicode stream from pipe correctly
    + ShellPkg/alias: Return status for alias deletion
    + MdePkg SmmIoLib: Use NULL pointer check instead of useless
      Status check
    + MdePkg SmmMemLib: Remove ASSERT in SmmIsBufferOutsideSmmValid
    + MdeModulePkg/UefiPxeBcDxe: Refine the PXE boot displayed
      information
    + MdeModulePkg/UefiPxeBcDxe: Fix the PXE BootMenu selection issue
  - Build x86_64 4MB images since upstream switched to 4MB by for a
    larger space for variables. Also update README to reflect the
    change.
  - Remove License-fat-driver.txt since FatPkg uses the same license
    as the root license.
  - Add the OVMF license file
  - Disable the PIE/PIC warning for the debug files since all object
    files will be converted to PE/COFF, so it's pointless to enable
    PIE/PIC.
  - Remove Default_DB_EX and Default_DBX correctly
* Mon Jun 05 2017 glin@suse.com
  - Update to 2017+git1496630893.7ec69844b8
    + ShellPkg/alias: Fix bug to support upper-case alias
    + BaseTools/GCC ARM/AARCH64: Force disable PIE
    + BaseTools/Scripts: discard .gnu.hash section in GCC builds
    + OvmfPkg: make the 4MB flash size the default
    + MdeModulePkg/BDS: Fix a buffer overflow bug
    + CryptoPkg/BaseCryptLib: Add NULL pointer checks in DH and P7Verify
    + UefiCpuPkg/BaseUefiCpuLib: Use NASM read-only data section name
    + OvmfPkg/PlatformPei: align EmuVariableNvStore at any page boundary
    + OvmfPkg/EmuVariableFvbRuntimeDxe: change block size to 4KB
    + OvmfPkg/EmuVariableFvbRuntimeDxe: correct NumOfLba vararg type
      in EraseBlocks()
    + ArmPlatformPkg/NorFlashDxe: correct NumOfLba vararg type in
      EraseBlocks()
    + OvmfPkg/EmuVariableFvbRuntimeDxe: always format an auth
      varstore header
    + MdeModulePkg/PciBus: Add IOMMU support
    + MdeModulePkg/PciHostBridge: Add IOMMU support
    + MdeModulePkg/Include: Add IOMMU protocol definition
    + ShellPkg/HandleParsingLib: Show LoadedImageProtocol file path
      as text
    + NetworkPkg: Fix issue in dns driver when building DHCP packet
    + Addressing TCP Window Retraction when window scale factor is used
    + Add wnd scale check before shrinking window
    + UefiCpuPkg/MtrrLib: Don't report OutOfResource when MTRR is enough
    + MdePkg DxeServicesLib: Handle potential NULL FvHandle
    + OvmfPkg/PlatformPei: handle non-power-of-two spare size for
      emu variables
    + SecurityPkg/Pkcs7VerifyDxe: Add format check in DB list contents
    + OvmfPkg: raise max variable size (auth & non-auth) to 33KB for
      FD_SIZE_4MB
    + OvmfPkg: introduce 4MB flash image (mainly) for Windows HCK
    + OvmfPkg/OvmfPkg.fdf.inc: extract VARS_LIVE_SIZE and
      VARS_SPARE_SIZE macros
    + OvmfPkg: introduce the FD_SIZE_IN_KB macro / build flag
    + ArmVirtPkg: install EdkiiPlatformHasDeviceTree proto in the
      32-bit builds
    + NetworkPkg: Fix PXEv6 boot failure when DhcpBinl offer received
    + NetworkPkg: Fix bug in iSCSI mode ipv6 when enabling target DHCP
    + Fix issue the iSCSI client can not send reset packet
    + CryptoPkg/SmmCryptLib: Enable HMAC-SHA256 support for SMM
    + ShellPkg/Shell: eliminate double-free in RunSplitCommand()
    + ShellPkg/Shell: clean up bogus member types in SPLIT_LIST
    + MdeModulePKg/BDS: Build meaningful description for Wi-Fi boot
      option
    + MdeModulePkg/DeviceManagerUiLib: Fix the network device MAC
      display issue
    + MdeModulePkg/Mtftp4Dxe: Add invalid ServerIp check during MTFTP
      configuration
    + NetworkPkg/TlsAuthConfigDxe: Close and free the file related
      resource
    + NetworkPkg: Correct the proxy DHCP offer handing
    + NetworkPkg/HttpDxe: Fix HTTP download OS image over 4G size
      failure
    + MdeModulePkg/UefiBootManagerLib: Avoid buggy USB short-form
      expanding
    + NetworkPkg: Fix bug related DAD issue in IP6 driver
    + NetworkPkg: Add check logic for iSCSI driver
    + MdeModulePkg PiSmmCore: Enhance SMM FreePool to catch buffer
      overflow
    + UefiCpuPkg/PiSmmCpuDxeSmm: Lock should be acquired
    + MdeModulePkg/BootManagerMenu: Add assertion to indicate no DIV
      by 0
    + CryptoPkg: Correct some minor issues in function comments
    + MdePkg/UefiLib: Avoid mis-calculate of graphic console size
    + MdeModulePkg/PiSmmCore: Fix potentially uninitialized local
      variable
    + MdeModulePkg DxeCore: Fix issue to print GUID value %g without
      pointer
    + ArmVirtPkg/ArmVirtXen: remove ARM BdsLib library class resolution
  - Add ovmf-disable-ia32-firmware-piepic.patch to disable pic/pie
    explicitly since gcc7 in Factory enables pic/pie by default but
    GenFw cannot handle the GOT sections and failed the build.
* Sat May 06 2017 meissner@suse.com
  - ovmf-pie.patch: add -fPIE to the Common build Makefile to
    allow a global PIE build.
* Thu Apr 13 2017 glin@suse.com
  - Update to 2017+git1492060560.b6d11d7c46 (fate#322331, bsc#1032659)
    + MdePkg: BaseIoLibIntrinsic (IoLib class) library
    + MdeModulePkg/IdeBusPei: Fix undefined behavior in signed left
      shift
    + MdeModulePkg/ScsiDiskDxe: Fix undefined behavior in signed left
      shift
    + OvmfPkg/QemuVideoDxe: VMWare SVGA device support
    + MdeModulePkg/UefiBootManagerLib: Enhance short-form expanding
      logic
    + CryptoPkg/BaseCryptLib: Adding NULL checking in time() wrapper
    + CryptoPkg: Fix possible unresolved external symbol issue.
    + CryptoPkg/OpensslLib: Suppress extra build warnings in openssl
      source
    + CryptoPkg: Move openssl and CRT headers to private include
      section
    + BaseTools: Update tools_def.template to add -fno-builtin in GCC
      tool chain
    + SecurityPkg: SecureBootConfigDxe: Support AUTH_2 enrollment to
      DBX
    + MdeModulePkg/UefiHiiLib:Fix incorrect comparison expression
    + ArmVirtPkg/ArmVirtQemuKernel: increase slack space for DTB
    + ArmVirtPkg/FdtClientDxe: honor memory DT node 'status' property
    + NetworkPkg: Fix some bugs related to iSCSI keyword configuration
    + MdeModulePkg/DxeHttpLib: Avoid the pointless comparison of
      UINTN with zero
    + BaseTools: Enhance expression to support some more operation
    + MdePkg/Shell.h: Update Shell version from 2.1 to 2.2
    + UefiCpuPkg/PiSmmCpuDxeSmm: Update saved SMM ranges check in
      SmmProfile
    + ArmVirtPkg/PlatformHasAcpiDtDxe: allow guest level ACPI disable
      override
    + BaseTools/GCC AARCH64: force disable PIC code generation
    + UefiCpuPkg/MtrrLib: Use a better algorithm to calculate MTRR
    + MdeModulePkg/SmmCore: Fix memory leak on Profile unregistered
    + OvmfPkg: Allow multiple add-pointer linker commands to same
      ACPI table
  - Drop upstream patch: ovmf-bsc1031336-fix-hii-gcc7-build.patch
* Wed Apr 05 2017 glin@suse.com
  - Add ovmf-bsc1031336-fix-hii-gcc7-build.patch to fix gcc7 build
    (bsc#1031336)
* Thu Mar 30 2017 glin@suse.com
  - Update to 2017+git1490844769.d3017dd96b
    + MdeModulePkg/DxeHttpLib: Fix the incorrect return status if URI
      port is invalid
    + NetworkPkg/DnsDxe: Fix zero StationIp configuration failure of
      DNSv6
    + CryptoPkg: Clean-up CRT Library Wrapper
    + CryptoPkg: Fix handling of &strcmp function pointers
    + CryptoPkg/OpensslLib: Update INF files to support OpenSSL-1.1.0x
      build
    + ArmVirtPkg/PlatformHasAcpiDtDxe: don't expose DT if QEMU
      provides ACPI
    + ArmVirtPkg: enable AcpiTableDxe and EFI_ACPI_TABLE_PROTOCOL
      dynamically
    + ArmVirtPkg: add XenPlatformHasAcpiDtDxe
    + ArmVirtPkg: add PlatformHasAcpiDtDxe
    + UefiCpuPkg/AcpiCpuData.h: Support >4GB MMIO address
    + NetworkPkg/IScsiDxe: Fix the incorrect error handling in
      DriverEntryPoint
    + Fix potential ASSERT if NetIp4IsUnicast is called
    + ArmPkg/PlatformBootManagerLib: move to BootLogoLib for boot
      splash support
    + UefiCpuPkg: Add CPU Features PEI/DXE drivers
    + ArmVirtPkg/HighMemDxe: use CPU arch protocol to apply memprotect
      policy
    + MdeModulePkg/BootGraphicsResourceTableDxe: don't allocate below
      4 GB
    + MdeModulePkg/DxeCore: deal with allocations spanning several
      memmap entries
    + MdeModulePkg/AcpiTableDxe: Not make FADT.{DSDT,X_DSDT} mutual
      exclusion
    + NetworkPkg: Fix service binding issue in TCP dxe
    + MdeModulePkg: Fix service binding issue in TCP4 and Ip4 dxe
    + MdeModulePkg: Fix bug in DxeHttplib when converting port number
    + MdeModulePkg/Ip4Dxe: Add Ip/Netmask pair check for Ip4Config2
    + ArmPkg/UncachedMemoryAllocationLib: set XP bit via CPU arch
      protocol
    + MdeModulePkg DxeCore: Remove unreferenced symbol for memory
      profile
    + MdeModulePkg PiSmmCore: Remove unreferenced symbol for SMRAM
      profile
    + NetworkPkg: Fix potential bug if the iSCSI use dns protocol
    + MdePkg/UefiDevicePathLib: Fix the wrong MAC address length
    + OvmfPkg/AcpiPlatformDxe: save fw_cfg boot script with QemuFwCfgS3Lib
    + ArmVirtPkg, OvmfPkg: retire QemuFwCfgS3Enabled() from QemuFwCfgLib
    + OvmfPkg: resolve QemuFwCfgS3Lib
    + ArmVirtPkg: resolve QemuFwCfgS3Lib
    + OvmfPkg/QemuFwCfgS3Lib: add initial PEI and DXE fw_cfg library
      instances
    + OvmfPkg: introduce QemuFwCfgS3Lib class
    + MdeModulePkg/SmmCore: Add Context in SmiHandlerProfileUnregister
    + MdeModulePkg/UefiBootManagerLib: Generate boot description for
      NVME
    + ArmVirtPkg/ArmVirtPL031FdtClientLib: unconditionally disable DT
      node
    + ArmVirtPkg/FdtClientDxe: supplement missing EFIAPI calling conv
      specifiers
    + MdeModulePkg/AcpiTableDxe: improve FADT.{DSDT,X_DSDT} mutual
      exclusion
    + ArmPkg/CpuDxe: handle implied attributes in EfiAttributeToArmAttribute
    + ArmVirtPkg: apply PE/COFF memory protection to DxeCore as well
    + ArmPkg/UncachedMemoryAllocationLib: map uncached allocations
      non-executable
    + ArmPkg/UncachedMemoryAllocationLib: use CWG value to align pool
      allocations
    + ArmPkg/UncachedMemoryAllocationLib: restore mapping attributes
      after free
  - Update openssl to 1.1.0e
* Wed Mar 08 2017 glin@suse.com
  - Update to 2017+git1488934948.29e9bf10dc
    + ArmVirtPkg: enable non-executable DXE stack for all platforms
    + ArmVirtPkg: enable PE/COFF image and memory protection for ARM
      platforms
    + ArmPkg/CpuDxe ARM: honour RO/XP attributes in SetMemoryAttributes()
    + ArmPkg/CpuDxe ARM: avoid unnecessary cache/TLB maintenance
    + ArmPkg/CpuDxe ARM: avoid splitting page table sections
      unnecessarily
    + Refine casting expression result to bigger size
    + NetworkPkg/Dhcp6Dxe: Handle the Nil UUID case
    + ArmVirtPkg AARCH64: enable NX memory protection for all platforms
    + ArmVirtPkg/HighMemDxe: preserve non-exec permissions on newly
      added regions
    + SecurityPkg: Fix potential bug in Security Boot dxe
    + MdeModulePkg/EbcDxe: use EfiBootServicesCode memory for thunks
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2k
      (bsc#1030565)
    + ArmVirtPkg: clear PcdPerformanceLibraryPropertyMask PCD
    + Ignore duplicated DNS address check
    + MdeModulePkg/DxeCore: base code protection on permission
      attributes
    + OvmfPkg: exclude libssl functionality from OpensslLib if
      TLS_ENABLE=FALSE
    + CryptoPkg/OpensslLib: introduce OpensslLibCrypto instance
    + ArmVirtPkg/ArmVirt.dsc.inc: AARCH64: enable DXE image
      protection feature
    + OvmfPkg/XenBusDxe: Use EFIAPI for XenStoreVSPrint
    + Update the Ethernet interface name
    + NetworkPkg:Add scriptable configuration to iSCSI driver by
      leveraging x-UEFI
    + ArmPkg/ArmMmuLib: AARCH64: enable stack alignment checking
    + ArmPlatformPkg/ArmPlatformStackLib: use callee preserved
      registers
    + MdeModulePkg/DxeCore: Add UEFI image protection
    + UefiCpuPkg/CpuDxe: Add memory attribute setting
    + OvmfPkg/QemuFwCfg: introduce FW_CFG_IO_SELECTOR, FW_CFG_IO_DATA,
      and FW_CFG_IO_DMA_ADDRESS
    + UefiCpuPkg/ExceptionHandlerAsm.S: Fix code length issue with
      GCC 5.4
    + ArmPkg/ArmMmuLib: AARCH64: add support for modifying only
      permissions
    + ArmPkg/CpuDxe: ARM: ignore page table updates that only change
      permissions
    + ArmPkg/CpuDxe: translate invalid memory types in
      EfiAttributeToArmAttribute
    + ArmPkg/CpuDxe: Correct EFI_MEMORY_RO usage
    + OvmfPkg/AcpiPlatformDxe: implement the QEMU_LOADER_WRITE_POINTER
      command
    + MdeMoudlePkg/DisplayEngine: Fix incorrect index used in array
      "InputText"
    + MdeModulePkg: Add the EFI_PRINT2S_PROTOCOL
    + MdePkg/BasePrintLib: Add safe print functions [A|U]ValueToStringS
    + Refine the SPrint functions
    + SecurityPkg: enhance secure boot Config Dxe & Time Based
      AuthVariable
    + Generate the correct operational state of the interface
    + NetworkPkg/HttpBootDxe: Update to check specified media type
    + NetworkPkg/HttpBootDxe: Request HTTP token notify as a DPC at
      TPL_CALLBACK
    + NetworkPkg/iSCSIDxe: Update the condition for IScsiStart Abort
    + MdePkg ACPI: Incorrect definition name for ACPI IORT Table
      signature
    + MdeModulePkg/PciBus: Accept Spec values as BarIndex and
      Alignment
    + NetworkPkg/NetworkPkg.uni: Define the prompt and help
      information for PcdAllowHttpConnections
    + MdeModulePkg/DxeHttpLib: Correct the return status for the
      HTTP Port/ContentLength
    + MdeModulePkg/UefiBootManagerLib: Initialize Handle before
      using it
    + OvmfPkg/SmmControl2Dxe: select broadcast SMI if available
    + OvmfPkg: dynamic defaults for PcdCpuSmmApSyncTimeout,
      PcdCpuSmmSyncMode
    + ArmVirtPkg/QemuFwCfgLib: implement QemuFwCfgSkipBytes() API
    + ArmVirtPkg/QemuFwCfgLib: use DMA for QemuFwCfgWriteBytes() if
      available
    + ArmVirtPkg/QemuFwCfgLib: extract generic DmaTransferBytes()
      function
    + OvmfPkg/QemuFwCfgLib: add QemuFwCfgSkipBytes()
    + OvmfPkg/QemuFwCfgLib: generalize InternalQemuFwCfgDmaBytes()
      to SKIP op
    + SecurityPkg: Tcg2Dxe: Update PCR[4] measure logic
    + MdePkg: Add definitions for SMBIOS spec 3.1.1
    + OvmfPkg/QemuVideoDxe: Frame buffer config size may change in
      new mode
  - Update openssl to 1.0.2k
* Tue Jan 24 2017 glin@suse.com
  - update to 2017+git1485224553.6671cd7444
    + NetworkPkg: Fix protocol handler service in HttpDxe
    + OvmfPkg: Allow HTTP connections if HTTP Boot enabled
    + NetworkPkg: Add PCD to enable the HTTP connections switch
    + MdePkg: Add definitions for SMBIOS spec 3.1.0
    + ArmPlatformPkg/NorFlashDxe: Change Flash memory attributes
      before writes
    + MdePkg DxeHobLib: Make GetHobList working before Constructor
      is called
    + NetworkPkg: Add dns support for target URL configuration in
      ISCSI
    + MdeModulePkg/FileExplorer: Enable functionality of creating
      new file/folder
    + OvmfPkg: pull in TLS modules with -D TLS_ENABLE (also enabling
      HTTPS)
    + OvmfPkg: correct the IScsiDxe module included for the IPv6 stack
    + OvmfPkg: always resolve OpenSslLib, IntrinsicLib and
      BaseCryptLib
    + OvmfPkg: Modify QemuFwCfgLib to use new IoLib class library
    + OvmgPkg/PlatformBootManagerLib: Add Debug Agent console
    + OvmfPkg/SmmControl2Dxe: correct PCI_CONFIG_READ_WRITE in S3
      boot script
    + OvmfPkg: Install BGRT ACPI table
    + MdeModulePkg/Bds: Fix a bug that may causes S4 fails to resume
    + MdePkg, MdeModulePkg: S3BootScriptSaveMemPoll(): accept 64-bit
      LoopTimes
    + NetworkPkg/HttpDxe: Fix the potential NULL dereference
    + NetworkPkg/HttpDxe: HTTPS support over IPv4 and IPv6
    + NetworkPkg/TlsAuthConfigDxe: Provide the UI to support TLS
      auth configuration
    + NetworkPkg/TlsDxe: TlsDxe driver implementation over OpenSSL
    + MdePkg: Add TLS related protocol definition
    + MdePkg/MemoryLib: Refine InternalMemSetMem16|32|64 functions
      logic
    + NetworkPkg: Replace ASSERT with error return code in PXE and
      HTTP boot driver
    + MdeModulePkg: Replace ASSERT with error return code in PXE
      driver
    + UefiCpuPkg/Cpuid.h: Update CPUID definitions with SDM (Sep.2016)
    + UefiCpuPkg/Include: Update MSR header files with SDM (Sep.2016)
    + UefiCpuPkg/PiSmmCpuDxeSmm: Always initialze PSD
    + MdeModulePkg/PiSmmCore: MemoryAttributeTable need keep non-PE
      record
    + MdeModulePkg/PiSmmCore: AllocatePool should use MemoryType
    + OvmfPkg/XenHypercallLib: Add EFIAPI
    + OvmfPkg/QemuFwCfgLib: support QEMU's DMA-like fw_cfg access
      method
    + ArmVirtPkg/QemuFwCfgLib: rebase lib instance to updated lib
      class header
    + OvmfPkg/QemuFwCfgLib: extend lib class header with more
      definitions
    + ArmVirtPkg, OvmfPkg: QemuFwCfgLib: move DMA-related defs to lib
      class
    + OvmfPkg/QemuFwCfgLib: move InternalQemuFwCfgIsAvailable() to
      lib instances
    + ArmVirtPkg/QemuFwCfgLib: remove superfluous InternalQemuFwCfgIsAvailable()
    + OvmfPkg: Remove use of IntelFrameworkModulePkg legacy libs
    + UefiCpuPkg/PiSmmCpuDxeSmm: Remove MTRRs from PSD structure
    + UefiCpuPkg/PiSmmCpuDxeSmm: Clear some semaphores on S3 boot
      path
    + ArmPkg/ArmDmaLib: add support for fixed host-to-device DMA
      offset
    + ArmPkg/ArmDmaLib: clean up abuse of device address
    + ArmPkg/ArmDmaLib: fix incorrect device address of double buffer
    + ArmPkg/ArmDmaLib: use DMA buffer alignment from CPU arch
      protocol
    + ArmPkg/ArmMmuLib: support page tables in cacheable memory only
    + UefiCpuPkg/PiSmmCpu: relax superpage protection on page split
    + OvmfPkg/PlatformPei: take VCPU count from QEMU and configure
      MpInitLib
    + UefiCpuPkg/MpInitLib: wait no longer than necessary for initial
      AP startup
  - Enable TLS support by default (for HTTPS)
* Tue Nov 29 2016 glin@suse.com
  - update to 2017+git1480394913.2b2efe3:
    + UefiCpuPkg/PiSmmCpuDxeSmm: handle dynamic
      PcdCpuMaxLogicalProcessorNumber
    + SecurityPkg Tcg2ConfigDxe: Align Attempt TPM Device help with
      options
    + SecurityPkg Tcg2ConfigDxe: Remove BlockSID actions and related
      strings
    + SecurityPkg OpalPasswordDxe: Use PP actions to enable BlockSID
    + SecurityPkg Tcg2PPLib: Support BlockSID related actions
    + MdeModulePkg/NetLib: Handle an invalid IPv6 address case
    + UefiCpuPkg/DxeMpLib: Fix bug when getting target C-State from
      eax
    + UefiCpuPkg/DxeMpLib: Make sure APs in safe loop code
    + UefiCpuPkg/DxeMpLib: Allocate new safe stack < 4GB
    + UefiCpuPkg/DxeMpLib: Get safe AP loop handler from global
      variable
    + ArmPlatformPkg: Fix VE RTSM mem map descriptor count
    + ArmPlatformPkg: Reformat VE Memory Map code
    + ArmPkg: remove the LinuxLoader application
    + MdeModulePkg/SetupBrowser:Don't support password without
      interactive flag
    + MdeModulePkg/DisplayEngine: Popup dialogue when password is
      not supported
    + MdeModulePkg/AtaAtapiPassThru: Ensure GHC.AE bit is always set
      in Ahci
    + MdeModulePkg/Xhci: Add 10ms delay before sending SendAddr cmd
      to dev
    + UefiCpuPkg/PiSmmCpu: Correct exception message
    + UefiCpuPkg: fix feature test for Extended Topology CPUID leaf
    + SecurityPkg DxeTcg2PPLib: Lock Tcg2PhysicalPresenceFlags
      variable on S4
    + MdeModulePkg/DxeNetLib: Allow the IPv4/prefix case when
      AsciiStrToIp4
    + ShellPkg: update ping6 to use timer service instead of timer
      arch protocol
    + MdeModulePkg/DisplayEngine: Return the selectable menu
      correctly
    + SecurityPkg Tcg2Dxe: ASSERT to ensure 'VarData' is not NULL
    + SecurityPkg TcgStorageCoreLib: ASSERT to ensure 'ByteSeq' is
      not NULL
    + UefiCpuPkg/PiSmmCpuDxeSmm: dynamic PcdCpuSmmApSyncTimeout,
      PcdCpuSmmSyncMode
    + MdeModulePkg/PiSmmCore: Cache CommunicationBuffer info before
      using it
    + Check for the max DHCP packet length before use it
    + OvmfPkg: Add 4K PE alignment to enable SMM page level
      protection
    + UefiCpuPkg/PiSmmCpu: Check XdSupport before set NX
    + MdeModulePkg/BdsDxe: Avoid overwriting PlatformRecovery####
    + MdeModulePkg/BdsDxe: Fix bug to run non-first
      PlatformRecovery####
    + PcAtChipsetPkg/PcRtc: Handle NULL table entry in RSDT/XSDT
    + UefiCpuPkg/SecCore: Correct print format for stack information
    + MdeModulePkg/PiSmmCpuDxeSmm: Check RegisterCpuInterruptHandler
      status
    + MdeModulePkg/CpuExceptionHanderLibNull:
      RegisterCpuInterruptHandler()
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add volatile to mNumberToFinish
    + UefiCpuPkg/PiSmmCpuDxeSmm: TransferApToSafeState() use UINTN
      params
    + MdePkg/BaseSynchronizationLib: Fix function names in function
      headers
    + MdePkg/BaseSynchronizationLib: Add volatile Interlocked*() APIs
    + MdePkg/Include: Add volatile to SynchronizationLib parameters
    + UefiCpuPkg/MpInitLib: support 64-bit AP stack addresses
    + UefiCpuPkg/MpInitLib/X64/MpFuncs.nasm: fix fatal typo
    + UefiCpuPkg/MpInitLib/X64/MpFuncs.nasm: remove superfluous
      instruction
    + UefiCpuPkg/DxeMpInitLib: remove duplicate HobLib class
      dependency
    + MdeModulePkg/Include: Add PiSmmMemoryAttributesTable.h
    + MdeModulePkg HiiDatabase: Remove extra memory initialization
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add paging protection
    + UefiCpuPkg/dec: Add PcdCpuSmmStaticPageTable
    + MdeModulePkg/PiSmmCore: Add MemoryAttributes support
    + ArmVirtPkg DxeHobLib: Update func header description of
      BuildFv(2)Hob()
    + IntelFrameworkPkg PeiHobLib: Check FV alignment when building
      FV HOB
    + MdePkg HobLib: Check FV alignment when building FV HOB
    + MdeModulePkg DxeCore: Show error message on unaligned FvImage
      issue
    + MdeModulePkg/Ip4Dxe: Correct the return status
    + MdeModulePkg/Ip4Dxe: Add wrong/invalid subnet check
    + OvmfPkg AcpiTables: Use PcdDebugIoPort to describe QEMU debug
      console
    + MdePkg/BaseLib: Add one wrapper on RdRand access for parameter
      check
    + UefiCpuPkg/MpInitLib: Update AP information when BSP switched
    + UefiCpuPkg/MpInitLib: Program AP stack in fixed address
    + UefiCpuPkg/MpInitLib: Add InitFlag and CpuInfo in
      MP_CPU_EXCHANGE_INFO
    + UefiCpuPkg/MpInitLib: Remove CPU information from CPU_AP_DATA
    + UefiCpuPkg/MpInitLib: Force sending INIT-SIPI-SIPI to reset APs
    + UefiCpuPkg/MpInitLib: Fixed offset error on Cr3Location
    + UefiCpuPkg/PiSmmCpuDxeSmm: Free SmramRanges to save SMM space
    + ShellPkg/dmpstore: Support "-sfo"
    + ArmPkg/Library/ArmDmaLib: Deallocate Map buffer in case of
      error
    + UefiCpuPkg/PiSmmCpuDxeSmm: Decrease mNumberToFinish in AP safe
      code
    + UefiCpuPkg/PiSmmCpuDxeSmm: Place AP to 32bit protected mode on
      S3 path
    + UefiCpuPkg/PiSmmCpuDxeSmm: Put AP into safe hlt-loop code on S3
      path
    + UefiCpuPkg/DxeMpLib: Place APs to suitable state on Legacy OS
      boot
    + UefiCpuPkg/DxeMpLib: Allocate below 4GB mem for
      AsmRelocateApLoopFunc
    + CryptoPkg/BaseCryptLib: Make comments consistent with the
      function
    + OvmfPkg/PlatformBds: Dispatch deferred images after EndOfDxe
    + ArmVirPkg/PlatformBds: Dispatch deferred images after EndOfDxe
    + MdeModulePkg/BdsDxe: Check deferred images before booting to OS
    + UefiCpuPkg/MpInitLib: Do not wakeup AP if only one processor
      supported
    + BaseTools/EfiRom: Fix potential memory leak
    + OvmfPkg/ResetVector: Depend on PCD values of the page tables
    + CryptoPkg: Add HMAC-SHA256 cipher support
    + CryptoPkg: Add xxxxHashAll APIs to facilitate the digest
      computation
    + NetworkPkg: Fix the wrong Timer event check
    + NetworkPkg: Update IP4 stack drivers for classless address
      unicast check
    + PcAtChipsetPkg/HpetTimerDxe: Fix race condition in
      SetTimerPeriod()
    + OvmfPkg: Make more use of ARRAY_SIZE()
    + rebase to ARRAY_SIZE()
    + ArmPlatformPkg: remove ARM BDS
    + OvmfPkg/XenConsoleSerialPortLib: don't include
      <Uefi/UefiBaseType.h>
    + NetworkPkg: Support bracketed IPv6 address during a redirection
      in iSCSI
    + NetworkPkg: Enhance the code in DNS driver
    + NetworkPkg: Add dns support for pxe boot based on IPv6
    + disable deprecated interfaces
    + OvmfPkg/QemuVideoDxe: drop useless variables
      QEMU_VIDEO_MODE_DATA.RefreshRate
      QEMU_VIDEO_CIRRUS_MODES.RefreshRate
      QEMU_VIDEO_PRIVATE_DATA.CurrentMode
      QEMU_VIDEO_PRIVATE_DATA.LineBuffer
    + ArmVirtPkg: undo bogus component name and driver diagnostics
      disablement
    + NetworkPkg: Record user configured TargetIP/Port in iBFT
  - Use GCC5 in Tumbleweed
* Thu Oct 13 2016 glin@suse.com
  - update to 2017+git1476331065.08354c3:
    + OvmfPkg: add NOOPT build target for source level debugging
    + OvmfPkg: QemuVideoDxe uses MdeModulePkg/FrameBufferLib
    + BaseTools: support the NOOPT target with the GCC tool chains
    + BaseTools Makefile: Enable O2 option for GCC tool chain
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2j
      (bsc#1013603)
    + MdeModulePkg/Logo: Add LogoDxe module
    + MdeModulePkg/HiiDatabase: Add HiiImageEx implementation
    + MdeModulePkg/PciBusDxe: make OPROM BAR degradation configurable
    + NetworkPkg: Correct the DNS token return status by RCODE
    + BaseTools/EfiRom: supply missing machine type lookup strings
    + ArmVirtPkg: restrict mapping attributes of normal memory to
      EFI_MEMORY_WB
    + OvmfPkg/QemuBootOrderLib: drop too strict "/HD(" suffix from
      vblk prefix (bsc#1009707)
    + NetworkPkg/DnsDxe: Handle CNAME type responded from the name
      server
    + ArmVirtPkg/FdtPciHostBridgeLib: enable 64-bit PCI DMA
    + MdeModulePkg: Support classless IP for DHCPv4 TransmitReceive()
    + ArmVirtPkg: implement FdtPciHostBridgeLib
    + OvmfPkg: Use MdeModulePkg/ResetSystemRuntimeDxe
    + OvmfPkg/VirtioGpuDxe: implement EFI_GRAPHICS_OUTPUT_PROTOCOL
    + include VirtioGpuDxe in the platform DSC/FDF files
    + OvmfPkg/Virtio10Dxe: don't bind virtio-vga
    + OvmfPkg/QemuVideoDxe: don't incorrectly bind virtio-gpu-pci
    + BaseTools/GenFw: ignore dynamic RELA sections
    + Add implementations of API IsZeroBuffer()
    + ArmVirtPkg: Add Ramdisk support to ArmVirtPkg platforms
    + ArmVirtPkg: Move inclusion of AcpiTableDxe.inf to ArmVirt.dsc.inc
  - Drop upstreamed ArmVirtPkg-Enable-PCI-bus-probing-again.patch
* Wed Sep 14 2016 dmueller@suse.com
  - update to 2017+git1472049752.ea2f21e:
    + switches git branch from an (outdated) master tree
    to the UDK2017 branch, which provides an insane amount of
    changes. for details please look at https://github.com/tianocore/edk2/commits/UDK2017
  - unify build flags with aarch64 build for increased compatibility with
    openSUSE installation medias
* Fri Aug 19 2016 glin@suse.com
  - Update to 2015+git1471575292.00bcb5c
    + NetworkPkg/IpSecDxe: Fix UEFI IKE Initial Exchange failure
    + MdeModulePkg: Fix potential failure if UseDefaultAddress
      configured
    + OvmfPkg: Add MpInitLib reference in DSC files
    + SecurityPkg: AuthVariableLib: Fix inconsistent CertDB case
    + OvmfPkg: use StatusCode Router and Handler from MdeModulePkg
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: deal with relaxed
      XIP alignment
    + BaseTools GCC: introduce GCC5 toolchain to support GCC v5.x in
      LTO mode
    + BaseTools GCC: use 'gcc' as the linker command for GCC44 and
      later
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: ignore .hash and
      .note sections
    + OvmfPkg/Sec: Support SECTION2 DXEFV types
    + Preserve hii section in GCC binaries
    + Fix IPv6 HTTPClient vendor class data
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2h
    + NetworkPkg: Fix bug in TCP which not sending out ACK in
      certain circumstance
    + OvmfPkg: include UefiCpuPkg/CpuMpPei
    + OvmfPkg/PlatformPei: rebase and resize the permanent PEI memory
      for S3
    + SecurityPkg SecureBootConfigDxe: Add check for the external
      PE/COFF image
    + ArmVirtPkg/PlatformBootManagerLib: remove stale FvFile boot
      options
    + OvmfPkg/PlatformPei: add missing auto variable initialization
    + OvmfPkg: add PciHotPlugInitDxe
    + MdeModulePkg/PciBusDxe: recognize hotplug-capable PCIe ports
    + OvmfPkg/PlatformBootManagerLib: remove stale FvFile boot
      options
    + OvmfPkg: add a Name GUID to each Firmware Volume
    + CryptoPkg BaseCryptLib: Init the content of struct 'CertCtx'
      before use
    + CryptoPkg BaseCryptLib: Avoid passing NULL ptr to function
      BN_bn2bin()
    + MdeModulePkg/Bds: MemoryTypeInformation excludes boot option
      mem use
    + MdeModulePkg: Fix IPv4 stack potential disappeared issue
    + NetworkPkg: Stop the HTTP Boot service after the boot image
      download complete
    + ArmVirtPkg: Re-add the Driver Health Manager
    + OvmfPkg: Re-add the Driver Health Manager
    + ArmVirtPkg/ArmVirtXen: Add ACPI support for Virt Xen ARM
    + Massive conversion of assembly code to NASM
    + MdeModulePkg/UefiBootManagerLib: Fix data in
      MemoryTypeInformation
    + ArmVirtPkg: add FDF definition for empty varstore
    + ArmVirtPkg/ArmVirtQemu: switch secure boot build to NorFlashDxe
    + NetworkPkg: Handling timeout case in httpboot driver
    + NetworkPkg: HttpDxe response/cancel issue fix
    + NetworkPkg: Support TCP Cancel function
    + MdeModulePkg/RamDiskDxe: Add Memory Type selection support in
      Ramdisk HII
    + MdeModulePkg RamDiskDxe: Do not save 'Size' numeric value by
      varstore
    + MdeModulePkg: Fix IPv4 UseDefaultAddress failure case
    + MdeModulePkg/AtaBusDxe: Fix some ATA hard drives cannot be
      discovered
    + ArmVirtPkg/PlatformBootManagerLib: rebase boot logo display to
      BootLogoLib
    + OvmfPkg: set SMM stack size to 16KB
    + OvmfPkg/PlatformBootManagerLib: Connect the Xen drivers before
      loading NvVars
    + MdeModulePkg: Fix SNP.Initialize() spec conformance issue
    + OvmfPkg: raise DXEFV size to 10 MB
    + MdeModulePkg: Stop the timer before clean IP service
    + OvmfPkg/PlatformBootManagerLib: rebase boot logo display to
      BootLogoLib
    + OvmfPkg/SerializeVariablesLib: Relax check for the read-only
      variable
    + OvmfPkg: prevent 64-bit MMIO BAR degradation if there is no CSM
    + OvmfPkg, ArmVirtPkg: rename QemuNewBootOrderLib to
      QemuBootOrderLib
    + MdeModulePkg/PciBus: do not improperly degrade resource
    + NetworkPkg/HttpDxe: Don't free Wrap in HttpTcpReceiveNotifyDpc
    + NetworkPkg/TcpDxe: Remove the status check of
      SockProcessRcvToken
    + UefiCpuPkg/SmmCpuFeaturesLib: Add SMRR PhysBase/PhysMask
      fields check
    + MdeModulePkg: Skip invalid bus number scanning in PciBusDxe
      driver
    + OvmfPkg/PlatformPei: provide 10 * 4KB of PCI IO Port space on
      Q35
    + OvmfPkg: introduce ICH9_PMBASE_VALUE
    + OvmfPkg: replace PcdAcpiPmBaseAddress with PIIX4_PMBA_VALUE
    + OvmfPkg/AcpiTimerLib: don't use possibly unset PMBA register
      (PEI phase)
    + MdeModulePkg: Refine the code for DxeHttpLib
    + OvmfPkg/XenBusDxe: duplicate twice-iterated VA_LIST in
      XenStoreVSPrint()
    + SecurityPkg: Use PcdGet32() to access PcdPeiCoreMaxFvSupported
    + UefiCpuPkg/PiSmmCpuDxeSmm/SmmProfile: Fix BTS support check bug
    + NetworkPkg:HttpDxe: Code changes to support HTTP PUT/POST
      operations
    + CryptoPkg/SmmCryptLib: Enable AES support for SMM
    + MdePkg: Add NFIT definition from ACPI 6.1
    + BaseTools/GenFw: enhance to use Magic Field to identify the
      image
    + MdeModulePkg-DxeCore: rename CoreGetMemoryMapPropertiesTable
    + MdeModulePkg Variable: return error for empty str VariableName
      to GetVariable
    + PcAtChipsetPkg AcpiTimerLib: Fix a logic error
    + MdeModulePkg UiApp: change code for easy customization
    + MdePkg: Add HII definitions from UEFI 2.6
    + NetworkPkg: Make HttpBootGetBootFile return
      EFI_BUFFER_TOO_SMALL
    + MdeModulePkg:DxeHttpLib: Add checks in HttpGenRequestMessage
      API
    + ArmPkg/ArmLib: don't invalidate entire I-cache on range
      operation
    + OvmfPkg/PlatformBootManagerLib: Postpone the shell registration
    + OvmfPkg/QemuNewBootOrderLib: adapt Q35 SATA PMPN to UEFI spec
      Mantis 1353
    + MdeModulePkg Ata: Use the new (incompatible) PortMultiplierPort
      semantics
    + NetworkPkg: Bug fix of iSCSI to support MPIO
  - Drop upstreamed patches
    + ovmf-dxe-10mb.patch
    + ovmf-bsc976253-postpone-shell.patch
    + ovmf-bsc980635-fix-http-crash.patch
    + ovmf-bsc982193-dont-restore-readonly-var.patch
    + ovmf-bsc982193-connect-xen-drivers.patch
    + ovmf-bsc990612-update-openssl-1.0.2h.patch
    + ovmf-bsc990773-remove-stale-boot-options.patch
  - Update dbxupdate.zip since there are new hashes added into dbx
* Wed Jul 27 2016 glin@suse.com
  - Update openssl to 1.0.2h (bsc#990612)
    + Add the patch: ovmf-bsc990612-update-openssl-1.0.2h.patch
    + Update the openssl tarball
  - Add ovmf-bsc990773-remove-stale-boot-options.patch to remove the
    stale boot options (bsc#990773)
* Tue Jun 14 2016 glin@suse.com
  - Generate the varstore template for AArch64 (bsc#983747,
    bsc#981836)
* Mon Jun 06 2016 jengelh@inai.de
  - Keep %prep minimal to shorten quilt setup run.
    Adjust RPM group. Drop redundant 4th defattr argument.
* Fri Jun 03 2016 glin@suse.com
  - Add ovmf-bsc982193-dont-restore-readonly-var.patch and
    ovmf-bsc982193-connect-xen-drivers.patch to fix the file-based
    NvVars restoring. (bsc#982193)
* Tue May 24 2016 glin@suse.com
  - Add the commands to remove irrelevant packages in %prep to make
    sure those source code will never build. (bsc#973038)
* Fri May 20 2016 glin@suse.com
  - Add ovmf-bsc980635-fix-http-crash.patch to fix the crash when
    downloading files from the http server (bsc#980635)
* Wed May 11 2016 glin@suse.com
  - Update to 2015+git1462940744.321151f
    + BaseTools: Fix bug in GenFds to handle FV image alignment
    + SecurityPkg: SecureBootConfigDxe: Add NULL pointer check
    + OvmfPkg/PciHostBridgeLib: Scan for root bridges when running
      over Xen
    + OvmfPkg/PciHostBridgeLib: Change InitRootBridge prototype
    + MdeModulePkg/PciHostBridgeDxe: Honor ResourceAssigned
    + OvmfPkg/PciHostBridgeLib: Set correct Base/Limit for absent
      resource
    + MdeModulePkg/PciHostBridgeDxe: Fix a Base/Limit comparing bug
    + MdeModulePkg/PciHostBridgeDxe: Don't miss prefetchable MMIO
      aperture
    + ArmVirtPkg: set PcdMaxVariableSize and PcdMaxAuthVariableSize
    + ArmPkg/AArch64Mmu: don't let table entries inherit XN
      permission bits
    + ArmPkg/ArmDmaLib: do not remap arbitrary memory regions as
      uncached
    + ArmPkg/ArmDmaLib: reject consistent DMA mappings of cached
      memory
    + MdeModulePkg/PciSioSerialDxe: Do not flush the UART
    + MdeModulePkg RamDiskDxe: Fix wrong HII behavior for more than 8
      RAM disks
    + OvmfPkg: Modify FDF/DSC files for RamDiskDxe's adding NFIT
      report feature
    + MdeModulePkg RamDiskDxe: Report ACPI NFIT for reserved memory
      RAM disks
    + ArmVirtPkg/ArmVirtQemu: use MdeModulePkg/BDS
    + Ignore BootFileName if it is overloaded (HTTP Boot/PXE)
    + NetworkPkg: Fix a memory leak in HTTP boot driver
    + NetworkPkg/HttpBootDxe: Fix for the issue that the HTTP boot
      option can't be booted more than once
    + deModulePkg NvmExpressDxe: Initialize IoAlign info for an NVMe
      device
    + MdeModulePkg: Refine SNP driver's media status check logic
    + MdeModulePkg: ScsiDiskDxe: cope with broken "Supported VPD Pages"
      VPD page
    + MdeModulePkg FileExplorerLib: Add UefiHiiServicesLib dependency
    + SecurityPkg: SecureBootConfigDxe: Disable SecureBoot
      Enable/Disable in some case
    + Do not use hard coded TTL/ToS in PXE driver
    + NetworkPkg: Use UefiBootManagerLib API to create load option
    + Remove DeployedMode/AuditMode
    + OvmfPkg: Use MdeModulePkg/BDS
    + ArmPlatformPkg/PrePi: allow unicore version to be used on MP
      hardware
    + ArmPkg: implement CpuIo2 protocol driver specific for PCI
    + ArmPlatformPkg: move PCI related PCD definitions to ArmPkg
    + MdeModulePkg/DxeCore: set ImageContext Handle and ImageRead()
      fields
    + MdeModulePkg/PciBusDxe: don't create bogus descriptor if no
      resources needed
    + MdeModulePkg: Add new driver to publish EDKII_PI_SMM_COMMUNICATION_REGION_TABLE
    + SecuritPkg: DxeImageVerificationLib: Fix wrong verification
      logic in DBX & DBT
    + UefiCpuPkg/MtrrLib: Reduce the loop time to get fixed-MTRR MSR
      index
    + MdeModulePkg: PiDxeS3BootScriptLib: honor PcdAcpiS3Enable
    + NetworkPkg: Fix incorrect buffer free in HttpDxe
    + NetworkPkg: Avoid the indefinite wait case in HttpDxe
    + MdeModulePkg: DxeCore MemoryPool Algorithm Update
    + MdeModulePkg: Export ConfigResp only for form Package after
      ReadyToBoot
    + NetworkPkg:HttpDxe:Consume DxeHttpLib API changes
    + MdeModulePkg:DxeHttpLib: Update to DxeHttpLib API
    + NetworkPkg: Allow user to create a HTTP corporate boot option
      in setup page
    + MdePkg:Http11.h: Add defines for "Expect" header
    + BaseTools: Update FMP Capsule support to follow FDF spec
    + OvmfPkg: SataControllerDxe: SataControllerStop: fix use after
      free
    + OvmfPkg: SataControllerDxe: SataControllerStop: remove useless
      null check
    + MdeModulePkg DxeCore: Check free memory type by CoreUpdateProfile()
    + MdeModulePkg/NvmExpress: Fix bug of handling not
      null-terminated strings
    + ShellPkg: Enahance 'dh' command to add more protocols decoding
      support
    + MdeModulePkg/DxeCore: Avoid assertion in CoreLocateProtocol
    + MdeModulePkg: Correct PlatformHookLibSerialPortPpi module type
    + FatPkg: Update License.txt to have the full license text
    + refine codes of iSCSI driver
    + MdeModulePkg DxeCore: Enhance MemoryAttributesTable installation
    + MdeModulePkg DxeCore: Return memory type from internal free
      pool/pages
    + MdeModulePkg DxeCore: Fix a memory leak in
      InstallMemoryAttributesTable()
    + MdeModulePkg DxeCore: Call PeCoffExtraActionLib member after
      Constructor
    + MdeModulePkg/Usb: Fix wrong condition judgment to support
      usb3.1 dev
    + MdeModulePkg/UsbKbDxe: don't assert when the key read is
      invalid
    + BaseTools: Add mixed PCD support feature
    + OvmfPkg: AcpiPlatformDxe: Don't enable unsupported PCI
      attributes
    + MdeModulePkg/HiiDatabaseDxe: Support EfiVarStore to get AltCfg
      from Driver
    + MdeModulePkg/HiiDatabaseDxe: Correct the ReallocatePool size
    + MdeModulePkg/SetupBrowserDxe: Get default from callback for
      orderedList
    + SecurityPkg: AuthVariableLib & SecureBootConfigDxe:
      Fix SecureBootEnable & PK inconsistency issue
    + ShellPkg: Update ping command options to sync with Spec
    + MdeModulePkg NvmExpressDxe: Ensure write-through for NVMe write
      command
    + ShellPkg: Cache the environment variable into memory to enhance
      the performance.
    + BaseTools: Update to handle PE image with .code section only
    + ArmPkg/AArch64Mmu: disable MMU during page table manipulations
    + ArmPkg/AArch64Mmu: Fix XN attribute for device memory
    + NetworkPkg: Fix issue in Ip6Dxe SetData
  - The updated tarball includes the PCI host bridge fix for Xen
    (bsc#976253)
  - Add ovmf-dxe-10mb.patch to raise DXEFV to 10MB to avoid build
    error.
  - Add ovmf-bsc976253-postpone-shell.patch to postpone the creation
    of the shell boot option so that the firmware will try the block
    devices first. (bsc#976253)
  - Update README for Xen debugging.
* Thu Apr 21 2016 agraf@suse.com
  - Add patch to enable PCI BAR probing on ARM again:
    * ArmVirtPkg-Enable-PCI-bus-probing-again.patch
* Fri Apr 15 2016 glin@suse.com
  - Change the fat driver license to the BSD license in FatPkg
    instead of the proprietary license in FatBinPkg since OvmfPkg and
    ArmVirtPkg now use FatPkg (bsc#973038)
* Thu Apr 14 2016 glin@suse.com
  - Update to 2015+git1460599637.f70cfe7
    + MdeModulePkg S3SaveStateDxe: Add protocol usage for gEfiLockBoxProtocolGuid
    + ArmVirtPkg/VirtFdtDxe: remove Xenio handling and rename to VirtioFdtDxe
    + ArmVirtPkg/ArmVirtXen: move from VirtFdtDxe to new XenioFdtDxe driver
    + OvmfPkg/XenIoMmioLib: add missing MemoryAllocationLib dependency to INF
    + ArmVirtPkg/VirtFdtDxe: move FDT config table installation to FdtClientDxe
    + ArmVirtPkg/VirtFdtDxe: remove unused PL011 DT node type
    + ArmVirtPkg: get rid of A PRIORI DXE declarations for VirtFdtDxe
    + ArmVirtPkg/VirtFdtDxe: drop RTC handling
    + ArmVirtPkg: move QEMU based platforms to ArmVirtPL031FdtClientLib
    + ArmVirtPkg: implement ArmVirtPL031FdtClientLib
    + ArmVirtPkg/RelocatableVirtHelper: use correct FindMemNode argument order
    + IntelFrameworkModulePkg: Remove unused PCD/Protocol
    + IntelFrameworkModulePkg/KeyboardDxe: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2Mouse: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2AbsPointer: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2Kbd: use PCD/Protocol in MdeModulePkg
    + MdeModulePkg/MdeModulePkg.uni: Add PS2 related PCD description
    + MdeModulePkg/Ps2MouseDxe: Use a different FILE_GUID
    + MdeModulePkg/Ps2KeyboardDxe: Use a different FILE_GUID
    + MdeModulePkg/Ps2Mouse: Fix potential buffer overflow issue.
    + MdeModulePkg: Update Guid/Protocol usages in INF files.
    + ShellPkg: Update Guid/Protocol usages in INF files.
    + SecurityPkg: Update protocol usage in module INF files.
    + MdePkg: Add EFI Erase Block Protocol definitions
    + MdeModulePkg/Ps2MouseDxe: Fix build failure of GCC tool chain
    + ArmVirtPkg/VirtFdtDxe: drop PCI host bridge handling
    + ArmVirtPkg/PciHostBridgeDxe: move to FDT client protocol
    + ArmVirtPkg/BaseCachingPciExpressLib: depend on PciPcdProducerLib
    + ArmVirtPkg: implement FdtPciPcdProducerLib
    + ArmVirtPkg/VirtFdtDxe: remove handling of fw_cfg DT node
    + ArmVirtPkg/QemuFwCfgLib: move to FDT client protocol
    + BaseTools: use unsigned chars on ARM architectures
    + BaseTools: generate hash value in build report for each output EFI image
    + BaseTools/VolInfo: generate HASH value for each PE image
    + ArmVirtPkg/VirtFdtDxe: remove timer DT node handling
    + ArmVirtPkg: move TimerDxe to FDT client library
    + ArmVirtPkg: implement ArmVirtTimerFdtClientLib
    + ArmVirtPkg/VirtFdtDxe: drop detection of PSCI method
    + ArmVirtPkg/ArmVirtPsciResetSystemLib: move to FDT client protocol
    + ArmVirtPkg/VirtFdtDxe: remove GIC discovery
    + ArmVirtPkg/ArmGicArchLib: move to FdtClient protocol
    + ArmVirtPkg: add FdtClientDxe to the ArmVirtPkg platforms
    + ArmVirtPkg/FdtClientDxe: implement new driver
    + ArmVirtPkg: introduce FdtClientProtocol
    + UefiCpuPkg: CpuIo2Dxe: optimize FIFO reads and writes of IO ports
    + MdeModulePkg: Update PerformanceLib instances not to check Identifier.
    + MdePkg: Update PerformanceLib comments not to check Identifier.
    + Update edksetup.bat to check EDK_TOOLS_PATH before set it.
    + MdeModulePkg/Ps2Keyboard: Add missing PCD and protocol to DEC file
    + UefiCpuPkg/CpuMpPei: Fix potential AP mwait wakeup issue
    + NetworkPkg: Add RAM disk boot support to HTTP Boot driver.
    + ShellPkg: Fix Shell ASSERT when mv file with cwd is NULL.
    + MdeModulePkg BootScriptExecutorDxe: Consume PcdAcpiS3Enable to control the code
    + MdeModulePkg SmmS3SaveStateDxe: Consume PcdAcpiS3Enable to control the code
    + MdeModulePkg: Add new macros and refine codes
    + NetworkPkg: Add new macros and refine codes
    + MdeModulePkg: Add Ps2MouseDxe driver
    + MdeModulePkg: Add Ps2KeyboardDxe driver.
    + MdeModulePkg/UefiBootManagerLib: API BmIsValidLoadOptionVariableName
    + SecurityPkg OpalPasswordDxe: Clean up debug message in OpalHii.c
    + SecurityPkg TcgStorageOpalLib: Fix wrong condition judgment.
    + SecurityPkg OpalPasswordDxe: Suppress option for special device.
    + OvmfPkg: remove PciHostBridgeDxe fork
    + OvmfPkg: remove USE_OLD_PCI_HOST build option
    + OvmfPkg: Convert to using FatPkg in the EDK II tree
    + ArmVirtPkg: Convert to build FatPkg from source
    + ArmVirtPkg: drop dependency on PeiPcdLib for PEI Pcd.inf
    + ArmVirtPkg: drop dependency on DxePcdLib for DXE Pcd.inf
    + IntelFrameworkModulePkg AcpiS3SaveDxe: Remove S3Ready() functional code
    + IntelFrameworkModulePkg AcpiS3SaveDxe: Consume PcdAcpiS3Enable to control the code
    + OvmfPkg: Retire AcpiS3SaveDxe
    + MdeModulePkg S3SaveStateDxe: Move S3Ready() functional code from AcpiS3SaveDxe
    + MdeModulePkg S3SaveStateDxe: Consume PcdAcpiS3Enable to control the code
    + OvmfPkg: Install LockBox protocol in constructor of LockBoxDxeLib
    + OvmfPkg: Set PcdAcpiS3Enable according to QemuFwCfgS3Enabled()
    + MdeModulePkg: Introduce new PCD PcdAcpiS3Enable
    + ArmVirtPkg: drop bogus ArmPlatformSecExtraActionLib resolution
    + ArmVirtPkg: remove linux loader from ARM builds
    + Merge 2-clause BSD licensed FatPkg
    + BaseTools: Add support to merge Prebuild and Postbuild into build Process
    + BaseTools: Enhance --Pcd which override by build option
    + MdeModulePkg/Bds: Fix build failures of VS tool chain
    + OvmfPkg: disable PcdHiiOsRuntimeSupport
    + OvmfPkg: remove PcdMaxHardwareErrorVariableSize from the DSC files
    + ArmVirtPkg: include Virtio10Dxe from OvmfPkg
    + OvmfPkg: include Virtio10Dxe
    + OvmfPkg: Virtio10Dxe: non-transitional driver for virtio-1.0 PCI devices
    + OvmfPkg: VirtioNetDxe: adapt virtio-net packet header size to virtio-1.0
    + OvmfPkg: VirtioScsiDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioRngDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioNetDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioBlkDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioLib: add Virtio10WriteFeatures() function
    + OvmfPkg: IndustryStandard: add definitions from the VirtIo 1.0 spec
    + OvmfPkg: IndustryStandard: factor out Virtio095Net.h
    + OvmfPkg: IndustryStandard: factor out Virtio095.h
    + OvmfPkg: VirtioRngDxe: clear all feature bits more explicitly
    + OvmfPkg: VirtioBlkDxe: don't clear non-negotiable feature bits
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: pass VRING object to SetQueueAddress()
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: remove GetQueueAddress() member
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: widen the Features bitmap to 64 bits
    + MdeModulePkg/Bds: Fix a boot hang due to Ram Disk boot support
    + BaseTools: cache the defined Guid tool to improve the performance
    + MdeModulePkg/Bds: Memory Bins don't count the memory used by RAM Disk
    + MdeModulePkg/Bds: Free resources after ram disk boot finishes
    + MdeModulePkg/Bds: Allocate reserved memory for RAM Disk boot media
    + SecurityPkg OpalPasswordSupportLib: Add comments for the used protocol in inf file.
    + SecurityPkg OpalPasswordSupportLib: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordSupportLib: Fixed gcc build failure.
    + SecurityPkg TcgStorageOpalLib: Fixed gcc build failure.
    + SecurityPkg OpalPasswordDxe: Check the pointer before use it.
    + SecurityPkg TcgStorageOpalLib: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordDxe: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordSmm: Remove the hard code build option.
    + MdePkg Cper.h: Add missing structure for 'Processor Error Record'
    + SourceLevelDebugPkg/SmmDebugAgent: mMailboxPointer is used before set
    + MdePkg/MdePkg.uni: Add description for PcdUartDefaultReceiveFifoDepth
    + MdePkg/BaseSynchronizationLib: Add spin lock alignment for IA32/x64
    + MdePkg/BaseSynchronizationLib: Do not check timeout if lock released
    + BaseTools/GenFds: Fix the bug for wrong alignment generate for RAW file
    + MdeModulePkg/UiApp: Correct the total RAM calculation
    + IntelFrameworkModulePkg/Bds: Correct the total RAM calculation
    + MdeModulePkg: DxeUdpIoLib: fix non-empty payload path in UDP reception
    + OvmfPkg: Add RAM disk support
    + ArmPkg/ArmArchTimerLib: correct typos
    + ArmPkg/ArmArchTimerLib: fix unused variable in RELEASE builds
    + EmbeddedPkg/AcpiLib: fix SBSA Generic Watchdog helper definition
    + ArmPlatformPkg: Add PCD for Pl011 UART Interrupt
    + MdePkg: Add ARM Serial Port Subtypes to DBG2
    + MdePkg: Add ARM Serial Port Subtype definitions
    + ArmVirtPkg: disable PcdHiiOsRuntimeSupport
    + ArmPkg/ArmArchTimerLib: add GetTimeInNanoSecond() to ArmArchTimerLib
    + ArmPkg/ArchArmTimerLib: refactor MultU64xN and TimerFreq definitions
    + NetworkPkg: Check received packet size before use it.
    + MdeModulePkg: Check received packet size before use it.
    + NetworkPkg: Check pointer for NULL before use.
    + Revert "TerminalDxe: select the UART's default receive FIFO depth"
    + ArmVirtPkg/ArmVirtQemu: gate FDT config table install with build option
    + ArmVirtPkg/VirtFdtDxe: make installation of FDT as config table optional
    + MdeModulePkg RamDiskDxe: Fix incorrect RAM disk memory address calculation
    + MdeModulePkg EmmcDxe: Fix GCC build failure with set but unused variables
    + SecurityPkg: Tcg2Dxe: Fix undersized TempBuf
    + MdeModulePkg/UefiBootManagerLib: BmGetActiveConsoleIn code cleanup
    + MdeModulePkg/SdMmc: Add EDKII SD/MMC stack
    + MdePkg/IndustryStandard: Add SD/EMMC common definitions
    + MdePkg/DevicePath: Add EMMC device path definition
    + MdePkg: Add EFI_SD_MMC_PASS_THRU_PROTOCOL definition
    + UefiCpuPkg/Cpuid.h: Display Intel SGX Resource Enumeration Leaves
    + UefiCpuPkg/Cpuid.h: Add CPUID defines and structures for Intel SGX
    + ShellPkg: Refine the comparisons code in ShellPkg.
    + MdeModulePkg PartitionDxe: Add Re-entry handling logic for BindingStop
    + SecurityPkg: Enable Opal password solution build.
    + SecurityPkg: OpalPasswordSmm: Add Opal password Smm driver.
    + SecurityPkg: OpalPasswordDxe: Add Opal password dxe driver.
    + SecurityPkg: OpalPasswordSupportLib: Add Opal password support library.
    + SecurityPkg: TcgStorageOpalLib: Add TCG storage opal library.
    + SecurityPkg: TcgStorageCoreLib: Add TCG storage core library.
    + MdePkg: Add definition for TCG Storage Core and Opal specs.
    + BaseTools: Add two new sections for PCD in the build report
    + MdeModulePkg/SerialDxe: Set FIFO depth with PCD
    + MdePkg: Add PCD for UART default receive FIFO depth
    + MdeModulePkg DiskIoDxe: Media status check not be done at DiskIo level
    + MdeModulePkg PartitionDxe: Some ISO images cannot be recognized properly
    + MdeModulePkg ScsiDiskDxe: Fix hang issue when reconnecting an ISCSI device
    + PcAtChipsetPkg/PciHostBridge: Remove PciHostBridge driver
    + ShellPkg/UefiDpLib: Fix a memory leak issue in Dp.
    + PerformancePkg/Dp_App: Fix a memory leak issue in Dp.
    + BaseTools: Remove the unnecessary check for RAW File
    + BaseTools: generate alignment when the FV content come from the filesystem
    + BaseTools: Extend the RAW format to support multiple binary files
    + ShellPkg AARCH64: remove DEBUG BuildOptions override
    + BaseTools AARCH64: move DEBUG GCC49 to the small code model
    + OvmfPkg: Increase the maximum size for Authenticated variables
    + BaseTools/GCC: set -Wno-unused-but-set-variables only on RELEASE builds
    + UefiCpuPkg: CpuMpPei: remove set but unused variables
    + UefiCpuPkg: PiSmmCpuDxeSmm: remove set but unused variables
    + UefiCpuPkg/MtrrLib: remove unused but set variable
    + NetworkPkg: IpSecDxe: remove set but unused variables
    + MdeModulePkg: DeviceManagerUiLib: remove set but unused variables
    + MdeModulePkg: BootMaintenanceManagerUiLib: remove set but unused variables
    + MdeModulePkg: UfsPassThruDxe: remove set but unused variables
    + MdeModulePkg: BootManagerMenuApp: remove set but unused variables
    + MdeModulePkg/PciHostBridgeDxe: remove unused but set variables
    + IntelFspWrapperPkg: PeiFspHobProcessLibSample: remove set but unused variables
    + IntelFrameworkModulePkg: LegacyBootMaintUiLib: remove set but unused variables
    + IntelFrameworkModulePkg: DxeCapsuleLib: remove set but unused variables
    + IntelFrameworkModulePkg: BiosVideo: remove set but unused variable
    + EmulatorPkg: CpuRuntimeDxe: remove set but unused variables
    + EdkCompatibilityPkg: SmmBaseHelper: remove set but unused variables
    + EdkCompatibilityPkg: EdkIIGlueLib: remove set but unused variables
    + EdkCompatibilityPkg: BsSerialStatusCode: remove set but unused variable
    + EdkCompatibilityPkg: UefiEfiIfrSupportLib: remove set but not used variables
    + ArmPkg|EmbeddedPkg: make PcdCpuVectorBaseAddress 64 bits wide
    + ArmPlatformPkg: fixups for 64-bit pointers
    + ArmPkg: apply Cortex-A57 errata
    + NetworkPkg:Fix bug when parsing the dhcp6 option 16
    + NetworkPkg:Fix Http boot download issue.
    + ShellPkg/UefiHandleParsingLib: Fix GUID reference
    + BaseTools: Updated BuildNotes URLs
    + MdeModulePkg/RamDiskDxe: Fix typo in HII message
    + SecurityPkg/SecureBootConfigDxe: Remove type casting from the ChooseFile handlers
    + SecurityPkg/SecureBootConfigDxe: Declare EFIAPI for the ChooseFile handlers
    + ShellPkg/UefiShellDebug1CommandsLib: remove unused but set variable
    + MdeModulePkg/PciBus: Should reserve enough bus number for HPC
    + MdeModulePkg/Bds: Fix VS2012 build failure.
    + ShellPkg: Modify the 'dh' Shell command to dump the Firmware Management Protocol Image Descriptor Information.
    + MdePkg: Move SMBIOS data into the IndustryStandard header.
    + ShellPkg: Make the USB mouse behavior in 'edit' consistent with 'hexedit'.
    + NetworkPkg: Fix HII related problem in HTTP boot driver.
    + MdeModulePkg/FileExplorerLib.h: Remove the redefinition of typedefs
    + OvmfPkg: PciHostBridgeLib: install 64-bit PCI host aperture
    + OvmfPkg: PlatformPei: determine the 64-bit PCI host aperture for X64 DXE
    + OvmfPkg: PlatformPei: factor out GetFirstNonAddress()
    + OvmfPkg: AcpiPlatformDxe: enable PCI IO and MMIO while fetching QEMU tables
    + OvmfPkg: AcpiPlatformDxe: when PCI is enabled, wait for Platform BDS's cue
    + ArmVirtPkg: PlatformIntelBdsLib: signal gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: PlatformBdsLib: signal gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: introduce gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: OvmfPkg.dec: add horizontal whitespace under Guids and Protocols
    + OvmfPkg/PlatformBdsLib: rebase to EfiEventGroupSignal
    + ArmVirtPkg/PlatformIntelBdsLib: rebase to EfiEventGroupSignal
    + IntelFrameworkPkg/FrameworkUefiLib: implement EfiEventGroupSignal
    + IntelFrameworkPkg/FrameworkUefiLib: move InternalEmptyFunction to UefiLib.c
    + MdePkg/UefiLib: introduce EfiEventGroupSignal
    + MdePkg/UefiLib: move InternalEmptyFunction to UefiLib.c
    + BaseTools: not include the undefined macro in response file
    + MdeModulePkg/BootMaintenanceManagerUiLib: Remove type casting in ChooseFile
    + MdeModulePkg/BootMaintManagerUiLib: Declare EFIAPI for ChooseFile handler
    + MdeModulePkg RamDiskDxe: Remove unnecessary TPL raise operations
    + MdeModulePkg RamDiskDxe: Uninstall DEVICE_PATH_PROTOCOL with correct param
    + MdeModulePkg RamDiskDxe: Remove unnecessary 'DisconnectController' calls
    + MdeModulePkg/Bds: BDS hotkey shouldn't work on inactive consoles
    + ArmPkg/AArch64Mmu: use correct AP[] bits in ArmClearMemoryRegionReadOnly
    + ArmPkg/ArmExceptionLib: reimplement register stack/unstack routines
    + ArmPkg/ArmExceptionLib: avoid indirect call if using vector table in place
    + ArmPkg/ArmExceptionLib: make build time define visible to the compiler
    + ArmPkg/ArmExceptionLib: don't restore ESR and FAR upon exception return
    + ArmPkg/ArmExceptionLib: stack FPSR on common path
    + ArmPkg/ArmExceptionLib: fold exception handler prologue into vector table
    + ArmPkg/AsmMacroIoLibV8: remove undocumented assumption from ELx macros
    + BaseTools: Fix nmake failure due to command-line length limitation
    + MdePkg/Pci22.h: Fix a coding style issue
    + MdeModulePkg DxeCore: Address boundary check for Type AllocateAddress
    + MdeModulePkg DxeCore: Check Start consistently in CoreConvertPagesEx
    + OvmfPkg/PlatformPei: suppress wrong VS2008 warning (use of uninited local)
    + MdeModulePkg PlatformVarCleanupLib: Locate VarCheck protocol when using
    + ArmPkg: update CpuDxe to use CpuExceptionHandlerLib
    + ArmVirtPkg/ArmVirtQemu: move to ARM version of CpuExceptionHandlerLib
    + ShellPkg: Remove the unused local variable.
    + MdeModulePkg: Fixed incorrect return value of MatchString
    + MdeModulePkg: ConSplitterDxe: use U64 mult/div wrappers in AbsPtr scaling
    + ArmPkg: ARM/AArch64 implementation of CpuExceptionHandlerLib
    + ArmPkg/ArmLib: add ArmReadHcr to enable read-modify-write of HCR
    + MdeModulePkg: Rescale ConSplitter Absolute Pointer.
    + ShellPkg: Per UEFI Shell 2.2 SPEC to make Shell supports 'NoNesting'.
    + NetworkPkg: Fix the driver model issue in HTTP Boot driver.
    + MdeModulePkg: Coding style update for DxeHttpLib.inf
    + IntelFrameworkModulePkg/LegacyBootMaintUiLib: Refine the code
    + MdeModulePkg: Refine the UI code
    + MdeModulePkg/DriverSampleDxe: Uninstall the ConfigAccess protocol
    + BaseTools: add new command line option to support override PCD value
  - The fix for bsc#973625 is also included in the update tarball
  - Remove upstreamed patches:
    ovmf-fix-choose-handlers-crash.patch
    ovmf-fix-httpboot-driver-option-16.patch
    ovmf-fix-httpboot-driver-model.patch
* Fri Apr 01 2016 glin@suse.com
  - Add ovmf-fix-httpboot-driver-option-16.patch to fix the parsing
    of DHCPv6 option 16
* Wed Mar 23 2016 glin@suse.com
  - Add ovmf-fix-choose-handlers-crash.patch to fix the crash while
    selecting files from BootMaintenanceManager and SecureBootConfig
* Wed Mar 16 2016 glin@suse.com
  - Update to 2015+git1458029440.db27e9f
    + OvmfPkg/LegacyRegion: Support legacy region manipulation of Q35
    + CryptoPkg: Fix the potential system hang issue
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2g
    + ArmVirtPkg/VirtFdtDxe: set /chosen/linux,pci-probe-only to 1
      in DTB
    + OvmfPkg: match PCI config access to machine type
      (if not USE_OLD_PCI_HOST)
    + OvmfPkg: add DxePciLibI440FxQ35
    + OvmfPkg: Enable Network2 Shell Commands for IPv6
    + MdeModulePkg AcpiTableDxe: Use Rsdt to check against NULL
    + MdePkg: Fix ACPI NFIT GUID definitions
    + NetworkPkg: Add URI configuration form to HTTP boot driver
    + CryptoPkg/OpensslLib: Switch to upstream fix for OpenSSL
      RT#3628, RT#3674, RT#3951, RT#3955, RT#3964, RT#3969, RT#3992,
      RT#4175, RT#4310
    + CryptoPkg/OpensslLib: Include complete copy of opensslconf.h
    + SecurityPkg/SecureBootConfigDxe: Handle allocation failure
      gracefully
    + MdeModulePkg/Bds: Support booting from remote file system
    + MdeModulePkg/Bds: Wide match HTTP boot option
    + MdeModulePkg: Fix IPv4 double free
    + UefiCpuPkg: Add dynamic type for PcdCpuMaxLogicalProcessorNumber
    + ArmPkg: Configure TTBCR register
    + OvmfPkg: switch to MdeModulePkg/Bus/Pci/PciHostBridgeDxe
    + MdeModulePkg: PciHostBridgeDxe: don't assume extended config
      space
    + ShellPkg: Update 'ifconfig -r' implementation
    + NetworkPkg: Change the default IPv6 config policy
    + MdeModulePkg: Change the default IPv4 config policy
    + OvmfPkg: copy log level comments from DebugLib.h
    + ArmVirtPkg: sync log level comments to DebugLib.h
    + MdeModulePkg: DxeCore: fully initialize image context before
      passing it on
    + MdeModulePkg/NvmExpress: Fix uninitialized field used in NVMe
      DiskInfo
    + MdeModulePkg: Add new API HttpUrlGetPath() to HttpLib.h
    + MdeModulePkg: Add RamDiskDxe driver implementation
    + SecurityPkg: Tcg2Smm: Change TPM2.0 MMIO range attribute
    + MdeModulePkg:Fix a robustness issue of Mnp Driver
    + MdeModulePkg: RegularExpressionDxe: support free(NULL)
    + MdeModulePkg/PciHostBridge: Don't assume resources are fully
      NonExistent
    + SecurityPkg: Use FileExplorerLib in SecureBootConfigDxe
    + MdeModulePkg: Add ASSERT to make sure pointer 'OptionalData'
      not be NULL
    + MdeModulePkg: Add ASSERT to make sure pointer 'MemoryMap' is
      not NULL
  - Update openssl to 1.0.2g
  - Add ovmf-fix-httpboot-driver-model.patch to fix the crash caused
    by the httpboot driver.
* Wed Mar 02 2016 glin@suse.com
  - Add ovmf-tools to package EfiRom (FATE#319531)
* Fri Feb 26 2016 glin@suse.com
  - Update to 2015+git1456452471.ba33c80
    + CryptoPkg: RuntimeCryptLib: support realloc(NULL, size)
    + CryptoPkg: support free(NULL)
    + MdePkg: Add EFI RAM Disk Protocol definitions
    + MdePkg: Update Http11 with additional useful definitions
    + NetworkPkg: Use Http11 definitions in HttpDxe and HttpBootDxe
    + Add new HII action type EFI_BROWSER_ACTION_SUBMITTED
    + UefiCpuPkg/Cpuid: Add UEFI CPUID application
    + BaseTools/tools_def.txt: Add -march=i586 for IA32 GCC targets
    + MdeModulePkg: Fix Memory Attributes table type issue
    + MdePkg: Add definition for new warning code
      EFI_WARN_FILE_SYSTEM
    + OvmfPkg: add driver for Virtio-RNG device
    + ArmVirtPkg: ArmVirtQemu: add driver for Virtio-RNG device
    + OvmfPkg: implement UEFI driver for Virtio RNG devices
    + OvmfPkg: VirtioFlush(): return the number of bytes written by
      the host
    + ArmPlatformPkg/IntelBds: call BdsLibConnectAll()
    + ArmVirtPkg/ArmVirtQemu: limit ACPI support to v5.0 and higher
    + MdeModulePkg: AcpiTableDxe: make 4 GB table allocation limit
      optional
    + ShellPkg: Support finding help message embedded in resource
      section
    + MdeModulePkg/UsbBusDxe: Fix memory leak
    + MdePkg: BaseLib: fix AArch64 DAIF interrupt mask definitions
    + ArmPkg: CpuDxe: don't track interrupt state in a global
      variable
    + ArmPkg: CpuDxe: fix AArch64 interrupt read masks
    + MdeModulePkg: Refine the code in BootMaintenanceManagerUiLib
    + MdeModulePkg: HiiDatabaseDxe: HiiStringToImage() should not
      overwrite BltX
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2f
    + UefiCpuPkg/PiSmmCpuDxeSmm: Enable/Restore XD in SMM
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add EFIAPI to CheckFeatureSupported()
    + ArmVirtPkg: ArmVirtQemu: make ACPI support AARCH64 only
    + SecurityPkg: TcgConfigDxe: Move TPM state string update to
      CallBack function
    + MdePkg: Fix incorrect PCIe Extended Capabilities definition
    + MdeModulePkg/Partition: Use proper partition number for MBR
    + MdePkg: Change PcdPropertiesTableEnable default value to FALSE
    + ArmVirtPkg: ArmVirtQemu: expose only 64-bit entry point for
      v3.0+ SMBIOS
    + NetworkPkg: Replace the internal function with exposed one
    + MdeModulePkg: Define a general function to create DNS QName
    + MdePkg: Add invocation register support in SMM Communication
      ACPI Table
    + MdeModulePkg: SNP should check Cdb.StatCode with
      PXE_STATCODE_SUCCESS
    + MdeModulePkg: Make the DEBUG info consistent in SNP driver
    + Add UEFI2.6 MemoryAttributes Table
    + OvmfPkg: simplify VARIABLE_STORE_HEADER generation
    + Minor comments update to AllocatePages() and AllocatePool()
    + MdeModulePkg DxeCore: Missing change for OEM reserved memory
      type at R17460
    + ArmPkg: DefaultExceptionHandler fixes for use with DxeCore
    + BaseTools/GenFw AARCH64: add support for relative data
      relocations
  - Update openssl to 1.0.2f
    Feb 15 09:17:12 UTC 2016 - glin@suse.com
  - edk2 upstream switched the repo from svn to git, so the naming
    has to change to use the git hash. The most recent stable release
    of edk2 is UDK 2015, so the base version changes to 2015.
  - update to ovmf-2015+git1454310736.ed5e386
    + MdePkg: Update the UEFI version to reflect new revision
    + MdePkg: Add EFI Supplicant Protocol definitions
    + MdePkg: Add EFI Wireless MAC Connection II Protocol definitions
    + MdePkg: Add ACPI6.1 definition
    + NetworkPkg: better sanity check on Ipv6 prefix length
    + NetworkPkg: Reword PXE download message
    + ShellPkg: ShellFileHandleReadLine must return UCS2 lines
    + ArmPlatformPkg/Bds: Early Console Initialization
    + ShellBinPkg: Arm/AArch64 Shell binary update
    + ShellPkg: Fix ASCII and UNICODE file pipes
    + ArmVirtPkg: implement ArmVirtQemuKernel
    + ArmVirtPkg: introduce new ArmQemuRelocatablePlatformLib
    + MdeModulePkg: Update DxeCore dispatcher to ignore PEI and SMM
      depex for FV
    + ArmPkg: Add isb when setting SCR
    + MdeModulePkg/PcRtc: Still create timezone variable when
      Daylight != 0
    + MdeModulePkg/UsbAbsPointer:Fix GetState() to return absolute
      value
    + MdeModulePkg: Correct one return status code in SNP Transmit
      function
    + MdeModulePkg: Update the default size of MNP TX buffer pool
    + MdeModulePkg: Update DBsize in SNP GetStatus command
    + NetworkPkg:Add a new error status code EFI_HTTP_ERROR
    + MdePkg:Add a new error status code EFI_HTTP_ERROR
    + NetworkPkg: Fix suspicious dereference of pointer 'Mode.Ia'
    + OvmfPkg: QemuBootOrderLib: recognize NVMe devices
    + OvmfPkg: include NvmExpressDxe driver
    + SecurityPkg: AuthVariableLib: Add new cert database for
      volatile time based Auth variable
    + MdeModulePkg: Add BS+RT+AT variable attribute definition
    + MdePkg: Add new enum EfiPlatformConfigurationActionUnsupportedGuid
    + PcAtChipsetPkg/Rtc: Don't unnecessarily create timezone
      variable
    + Correct inconsistent function descriptions in DNS
    + OvmfPkg: Increase default RELEASE build image size to 2MB
    + Minor update to the Data parameter for GetVariable()
    + MdeModulePkg: NvmExpressDxe: clean up NvmeRead() / NvmeWrite()
      debug msgs
    + MdePkg:Add new traffic statistics definition for Wireless NIC
    + NetworkPkg:Fix Network memory leak when calling GetModeData
      interface
    + SecurityPkg: Correct data copy in Tpm2NvReadPublic
    + SecurityPkg: Add TPM PTP detection in Tpm12SubmitCommand
    + MdeModulePkg DxeCore: Avoid the closed event to be signaled
      wrongly
    + SecurityPkg: SecureBootConfigDxe: Fix potential NULL pointer
      dereference
    + CryptoPkg: Fix function qsort for non 32-bit machines
  - update _service to fetch git repo
* Tue Jan 26 2016 glin@suse.com
  - update to R19743
    + NetworkPkg: Removing or adding some ASSERT statement
    + MdeModulePkg:Fix the potential memory leak issue in Display
      Engine
    + MdeModulePkg: Add error DEBUG statements in ATA passthru driver
    + NetworkPkg: DnsDxe: fix return type of DnsFillinQNameForQueryIp()
    + MdeModulePkg/Ide: return correct status when DRQ is not ready
      for ATAPI
    + MdeModulePkg/ScsiDisk: Increase the value of SCSI_DISK_TIMEOUT
      to 30s
    + OvmfPkg: inherit Image Verification Policy defaults from
      SecurityPkg
    + OvmfPkg: execute option ROM images regardless of Secure Boot
    + Rename TisTpmCommand to avoid name collision
    + MdeModulePkg: update SNP.GetStatus to handle multiple recycled
      TX buffer.
    + MdeModulePkg: Update MNP driver to recycle TX buffer
      asynchronously.
    + Refine error handle code, avoid assert when load this module
      twice.
    + MdeModulePkg: DeleteLoadOptionVariable() removes Boot####
    + MdeModulePkg: Fix GraphicsConsole driver resolution out of
      sync issue
    + SecurityPkg: MOR drivers use Tcg2Protocol instead of TrEE.
    + SecurityPkg: Add Tpm2Startup return code check.
    + SecurityPkg: Clear AuthSession content after use.
    + BaseTools/VfrCompile: honor CC if it is set
    + BaseTools AARCH64: add separate GCC build rule for XIP objects
    + BaseTools AARCH64: build XIP modules with strict alignment
    + SecurityPkg: TcgDxe,Tcg2Dxe,TrEEDxe: New PCD for TCG event log
      and TCG2 final event log area
    + NetworkPkg: Fix some typos in Http boot driver.
    + MdeModulePkg: Add DNS QType and QClass values definition
    + NetworkPkg: Remove DNS QType and QClass definition
    + SecurityPkg: SecureBootConfigDxe: Change
      KEY_TRANS_SECURE_BOOT_MODE value
    + SecurityPkg: SecureBootConfigDxe: Enhance secure boot string
      update logic
    + MdeModulePkg:Fix the potential memory leak issue in Display
      Engine
    + ShellPkg: Update 'dh' command to reflect correct driver handle
      information
    + NetworkPkg: Fix IpSec SPD and SAD mapping issue when SPD is
      updated
    + NetworkPkg: Fix SPD entry edit policy issue in IPSecConfig.
    + MdeModulePkg: Add new library class PciHostBridgeLib
    + MdeModulePkg: Add PciHostBridgeLibNull
    + MdePkg: Add PciSegmentLib instance based on PciLib
    + MdeModulePkg: Add generic PciHostBridgeDxe driver.
    + Add NOOPT target
    + ShellPkg UefiDpLib: Use Image->FilePath to get name for SMM
      drivers
    + MdeModulePkg/.../IdeMode: actualize DRQReady*() comment blocks
    + MdeModulePkg/.../IdeMode: report early finish of packet read
      as success
    + MdeModulePkg: SerialDxe: lay out mSerialIoMode initializer more
      nicely
    + MdeModulePkg: SerialDxe: sync EFI_SERIAL_IO_MODE.Timeout with
      the spec
    + MdeModulePkg: TerminalDxe: select the UART's default receive
      FIFO depth
    + BaseTools: make build report tolerant of FVs specified by name
    + Replace TpmCommLib with Tpm12DeviceLib
    + Add TPM 1.2 commands used by TCG modules
    + SecurityPkg: Update TCG PPI "1.3" for TCG2.
    + Add TPM PTP support
  - Remove upstreamed ovmf-fix-signedness.patch
* Wed Jan 06 2016 glin@suse.com
  - update to R19584
    + NetworkPkg: Support DNS4/6 GeneralLookUp feature
    + SecurityPkg AuthVariableLib: Correct comment/error log about
      CleanCertsFromDb
    + NetworkPkg: Fix suspicious dereference of pointer before NULL
      check
    + NetworkPkg: Update module inf to include the missing uni file
    + NetworkPkg: Remove a CopyMem to speed up the HTTP boot download
    + NetworkPkg: Remove unused EFI_HTTP_PROTOCOL definition
    + MdePkg : Update SPCR to use ACPI5 definition
    + MdeModulePkg ScsiDiskDxe: Raise the Tpl of async IO callback
      to TPL_NOTIFY
    + ScsiDiskDxe: Close event when SCSI command fails
    + MdeModulePkg ScsiBusDxe: Only signal caller event when
      PassThru() succeeds
    + MdeModulePkg DiskIoDxe: Check for MediaPresent in
      DiskIo2ReadWriteDisk()
    + MdeModulePkg ScsiDiskDxe: Modify WriteBlocks(Ex)() to follow
      UEFI spec
    + MdeModulePkg ScsiDiskDxe: Modify FlushBlocksEx() to follow UEFI
      spec
    + MdeModulePkg ScsiDiskDxe: Set block I/O media of SCSI CDROM to
      read-only
    + PcAtChipsetPkg/Rtc: Fix a UEFI Win7 boot hang issue
    + MdeModulePkg:Clear the screen before booting the boot option
    + NetworkPkg : Remove unused local variables to fix gcc build
      errors
    + MdePkg: Add HTTP 1.1 industry standard definitions
    + SecurityPkg: SecureBootConfigDxe: Remove useless code in VFR
    + NetworkPkg:Fix a bug the 2nd httpboot fail issue
    + NetworkPkg: Update iSCSI driver to check existing AIP instances
    + UefiCpuPkg/CpuMpPei: Fix pack(1) issue on x64 arch
    + MdeModulePkg:Fix bug that get the password width info
      incorrectly
    + NetworkPkg:Fix the issue Http boot hang when network failed
    + DxeTpmMeasureBootLib: Change global variable name to avoid
      name conflict
    + ArmVirtPkg/ArmVirtXen: add ARM support
    + ArmVirtPkg/XenRelocatablePlatformLib: rewrite DTB memory node
      retrieval in C
    + OvfmPkg/XenHypercallLib: add missing GCC_ASM_EXPORT to
      XenHypercall2
    + Shell update
    + MdeModulePkg:Fix a bug HttpLib can't parse last chunked data
      well
    + MdeModulePkg/PciSioSerialDxe:add non-null pointer dereference
      assertion
    + ArmPkg: rewrite vector table population macros
    + BootManagerLib: Check the pointer to avoid use NULL pointer
    + MdeModulePkg: Fix RegularExpressionDxe memcpy intrinsic
  - Add ovmf-fix-signedness.patch to fix the build error
* Wed Dec 16 2015 glin@suse.com
  - Update R19289
    + MdePkg: Add missing SMBIOS definitions for SATA and SAS Ports
    + MdePkg: Add GIC version to ACPI 5.1/6 definitions
    + MdePkg: Add Ipmi2.0 definitions head file
    + MdeModulePkg: Add NULL pointer check for RegularExpressionDxe
    + Convert all .uni files to utf-8
    + BaseTools/Scripts: Add ConvertUni.py script
    + Fix >4G issue on IDT not restored correctly
    + MdeModulePkg: Improved SetupBrowser handling to failed GOTO
      callback
    + ArmPlatformPkg/Sec: fix return_from_exception code and comment
    + ArmPlatformPkg/ArmPlatformLibNull: use declared PPI rather than
      module local var
    + ArmVirtPkg RVCT: build DXE_RUNTIME_DRIVER modules with 4 KB
      alignment
    + BaseTools/GenFw RVCT: fix relocation processing of PT_DYNAMIC
      sections
    + BaseTools RVCT: use scatter file to enforce minimum section
      alignment
    + MdePkg/BaseIoLibIntrinsic: Add EBC support
    + MdePkg: Add 3 macro defined in latest TPM2 specification
    + ShellPkg: Initialize the local pointer to avoid potential
      suspicious dereference
    + CryptoPkg/OpensslLib: upgrade OpenSSL version to 1.0.2e
    + MdeModulePkg ScsiDiskDxe: Add BlockIO2 Support
    + MdePkg UefiScsiLib: Add non-blocking support for SCSI
      Read/Write command
    + NetworkPkg: Fix the potential NULL pointer dereferenced issue
    + ShellPkg: Make 'dh' support showing all spec defined protocols
    + BaseTools GCC: avoid the use of COMMON symbols
    + ArmPkg/PrePeiCore: adhere to architectural stack alignment
      requirement
    + UefiCpuPkg/MtrrLib: Add PCD PcdCpuNumberOfReservedVariableMtrrs
    + ArmPkg/BdsLib: Send RemainingDevicePath to PXE Load File
      protocol
    + CryptoPkg/BaseCryptLib: make mVirtualAddressChangeEvent STATIC
    + CryptoPkg ARM: add ArmSoftFloatLib resolution to CryptoPkg.dsc
    + SecurityPkg: AuthVariableLib: Customized SecureBoot Mode
      transition
    + MdePkg: DebugAssert enhancement
    + ArmVirtPkg: HighMemDxe: add memory space for the high memory
      nodes
    + ArmVirtPkg: ArmVirtPlatformLib: find the lowest memory node
  - Update openssl to 1.0.2e
  - Update ovmf-embed-default-keys.patch to include one more db key
  - Add MicWinProPCA2011_2011-10-19.crt, the Windows Product key
* Fri Dec 04 2015 glin@suse.com
  - Update to R19110
    + ShellPkg: Fix wrong return status for Ifconfig.c
    + OvmfPkg: pull in SMM-based variable driver stack
    + OvmfPkg: any AP in SMM should not wait for the BSP for more
      than 100 ms
    + OvmfPkg: use relaxed AP SMM synchronization mode
    + OvmfPkg: SmmCpuFeaturesLib: implement SMRAM state save map
      access
    + OvmfPkg: import SmmCpuFeaturesLib from UefiCpuPkg
    + OvmfPkg: set gUefiCpuPkgTokenSpaceGuid.PcdCpuSmmEnableBspElection
      to FALSE
    + OvmfPkg: LockBox: use SMM stack with -D SMM_REQUIRE
    + OvmfPkg: introduce -D SMM_REQUIRE and PcdSmmSmramRequire
    + ArmVirtPkg: add secure boot support to 32-bit ARM targets
    + MdeModulePkg/BDS: Do not pass unnecessary option to boot option
    + NetworkPkg: Fix a bug in HttpBootDriverBindingStop() when
      destroying child
    + ArmPlatformPkg/PrePiHobListPointerLib: use thread ID register
    + ArmPlatformPkg/PrePeiCore: add missing entries to AArch64
      vector table
  - Refresh ovmf-gdb-symbols.patch
  - Run fdupes on /usr/share/qemu
* Fri Nov 27 2015 glin@suse.com
  - Update to R18975
    + ArmVirtPkg: Use SerialDxe in MdeModulePkg instead of
      EmbeddedPkg
    + OvmfPkg XenConsoleSerialPortLib: Implement
      Get(Set)Control/SetAttributes
    + NetworkPkg:Fix NULL pointer dereference issues
    + Always set WP in CR0
    + ArmPkg/UncachedMemoryAllocationLib: fix warning about
      uninitialized local var
    + UefiCpuPkg/CpuS3DataDxe: Add module to initialize ACPI_CPU_DATA
      for S3
    + Move CommunicationBuffer from stack to global variable
    + Move SmmDebug feature from ASM to C
    + Install LoadedImage protocol for PiSmmCore
    + Uninstall LoadedImage protocol if SMM driver returns error and
      is unloaded
    + ArmLib/ArmV7Mmu: use 64-bit type for mapping region size
    + ArmVirtPkg/ArmVirtPlatformLib: reduce ID map size to GCD region
      size
    + ArmVirtPkg/ArmVirtQemu: limit the (I)PA space to 40 bits
    + MdeModulePkg/UefiBootManagerLib: Always create MemoryTypeInfo
      variable
    + ShellBinPkg: Arm/AArch64 Shell binary update
    + MdeModulePkg:Create Boot Maintenance Manager Library
    + MdeModulePkg:Create Device Manager Library
    + MdeModulePkg:Create Boot Manager Library
    + ArmPkg: Invalidate cache after allocating UC memory
    + MdeModulePkg FileExplorerDxe: Create file explorer Protocol
    + ArmPkg: ArmLib: purge incorrect ArmDrainWriteBuffer () alias
    + UefiCpuPkg/CpuDxe: Don't use gBS->Stall
    + UefiCpuPkg/SmmFeatureLib: Check SmmFeatureControl by
      Code_Access_Chk
    + UefiCpuPkg: Not touch SmmFeatureControl if Code_Access_Chk not
      Set
    + ArmPkg/ArmPlatformPkg: position vectors relative to base
    + ArmPkg: correct TTBR1_EL1 settings in TCR_EL1
    + ShellPkg: Corrected CatSPrint usage to prevent memory leaks
    + ArmPkg/ArmV7Mmu: handle memory regions over 4 GB correctly
    + ArmPkg/ArmV7Lib: take MP extensions into account when
      programming TTBR
    + ArmPkg/ArmV7Lib: fix definition of TTBR_NON_INNER_CACHEABLE
    + ArmPkg/ArmV7Mmu: introduce feature PCD to map normal memory
      non-shareable
    + ArmPkg/ArmV7Mmu: make cached translation table accesses
      shareable
    + ArmPkg/ArmV7Lib: add function to test for presence of MP
      extensions
    + ArmPkg/ArmV7Lib: add support for reading the ID_MMFR0 system
      register
    + ArmPkg/ArmV7Mmu: fix write-through translation table accesses
    + ArmPkg/Mmu: set required XN attributes for device mappings
    + ArmVirtPkg/ArmVirtPlatformLib: map executable NOR region as
      normal memory
    + ArmPkg/AArch64Mmu: remove unused GcdAttributeToArmAttribute()
* Wed Nov 18 2015 glin@suse.com
  - Update to R18868
    + ArmPkg: ensure DebugAgentVectorTable is 2K-aligned
    + MdeModulePkg: Add Platform recovery support
    + MdePkg: Add Platform Recovery definitions
    + MdeModulePkg: SmmLockBoxPeiLib: work without
      EFI_PEI_SMM_COMMUNICATION_PPI
    + NetworkPkg: Httpboot will fail the 2nd time result by wrong
      TCP state
    + MdeModulePkg PeiCore: PEI dispatcher need retry to process
      NOT_DISPATCHED FV
    + ArmPkg/ArmLib: mark all cached mappings as (inner) shareable
    + ArmPlatformPkg: bring DS-5 scripts in line with linker script
      changes
    + MdeModulePkg: Add BootLogoLib to provide interfaces about logo
      display
    + MdeModulePkg: Add ImageDecoderLib to provide image decoding
      service
    + MdeModulePkg: Add PlatformLogo protocol definition
* Thu Nov 12 2015 glin@suse.com
  - Update to R18768
    + MdePkg: Add more DataBits support to Port80 output
    + MdeModulePkg PeiCore: Fix issue AuthenticationStatus is not
      propagated correctly
    + NetworkPkg: Report Http Errors to screen when http layer
      occurs an error
    + Add error handling for TPM in S3 resume failure
    + ArmPkg/ArmDmaLib: use the cache writeback granularity for
      alignment
    + ArmPkg/ArmLib: fix barriers in AArch64 ArmEnableMmu
    + NetworkPkg:Enable Http Boot over Ipv6 stack
    + NetworkPkg:Missing CloseEvent() in HttpResponseWorker
    + CryptoPkg: Add one new API (Pkcs7GetCertificatesList) for certs
      retrieving
    + SourceLevelDebugPkg: DebugAgent: Set Local APIC SoftwareEnable
    + UefiCpuPkg: LocalApicLib: Add API to set SoftwareEnable bit
    + UefiCpuPkg: CpuDxe: Update GDT to be consistent with DxeIplPeim
    + NetworkPkg: HttpDxe sometimes free a pointer twice
    + CryptoPkg/OpensslLib: Move OPENSSL_NO_xxx defines into
      opensslconf.h
    + CryptoPkg/OpensslLib: Eliminate GETPID_IS_MEANINGLESS
      definition
    + CryptoPkg: Fix OpenSSL BN wordsize and OPENSSL_SYS_UEFI
      handling
    + CryptoPkg/OpensslLib: Undefine NO_BUILTIN_VA_FUNCS to fix
      varargs breakage
    + CryptoPkg/BaseCryptLib: Use X509_V_FLAG_NO_CHECK_TIME
    + CryptoPkg/BaseCryptLib: Use X509_V_FLAG_PARTIAL_CHAIN
    + CryptoPkg/BaseCryptLib: Clean up checking of PKCS#7 contents
      type
    + CryptoPkg/BaseCryptLib: Use accessor functions for ASN1_OBJECT
    + CryptoPkg/BaseCryptLib: Use accessor functions for
      X509_ATTRIBUTE
    + CryptoPkg/BaseCryptLib: Use i2d_X509_NAME() instead of abusing
      X509_NAME
    + CryptoPkg/BaseCryptLib: Add missing OpenSSL includes
    + UefiCpuPkg: PiSmmCpuDxeSmm: Replace PcdSet## with PcdSet##S
    + MdePkg/BaseSynchronizationLib: fix AArch64 return values
    + Fix issue that calling GetS3MemoryInfo() with wrong order
    + Do not deadloop if Microcode not found in FspTempRamInit
    + Move Smbios measurement from TCG driver to Smbios driver
    + Add suppressif around TCG hash seleciton checkbox in TCG2
    + UefiCpuPkg: PiSmmCpuDxeSmm: Remove unused references to SmmLib
    + OvmfPkg: QemuFlashFvbServicesRuntimeDxe: split out runtime DXE
      specifics
    + OvmfPkg: QemuFlashFvbServicesRuntimeDxe: no dual addressing
      needed
    + MdeModulePkg Variable: Enhance variable performance by reading
      from existed memory cache
* Thu Oct 22 2015 glin@suse.com
  - Update to R18651
    + OvmfPkg: XenPvBlkDxe: handle empty cdrom drives
    + MdeModulePkg SetupBrowserDxe: Save global variable values
      before nest function called
    + UefiCpuPkg: Add CPU Hot Plug Data include file
    + UefiCpuPkg: Add ACPI CPU Data include file
    + UefiCpuPkg: Add SMM CPU Service Protocol
    + UefiCpuPkg: CpuDxe: broadcast MTRR changes to APs
    + UefiCpuPkg: CpuDxe: Wait for APs to enter idle loop
    + UefiCpuPkg: CpuDxe: Use PCD for AP detection timeout
    + UefiCpuPkg: Update CPU MP drivers to support single CPU
      configuration
    + MdeModulePkg VarCheckLib: R18611 was thoughtless for property
      set
    + SecurityPkg : Fix Rsa2048Sha256GuidedSectionExtractLib issue
    + OvmfPkg: VirtioBlkDxe: reset device at ExitBootServices()
    + OvmfPkg: VirtioScsiDxe: reset device at ExitBootServices()
    + OvmfPkg: Sec: Fix SOURCE_DEBUG_ENABLE ASSERT()
    + MdeModulePkg: SmbiosDxe: soften DEBUG messages about table
      reallocation
    + MdeModulePkg: FaultTolerantWriteDxe: clean up some "success"
      messages
    + MdeModulePkg: FaultTolerantWriteDxe: mellow DEBUGs about
      workspace reinit
    + ArmPlatformPkg: NorFlashDxe: mellow DEBUG messages about flash
      reinit
    + ArmVirtPkg: include BaseStackCheckLib also for AARCH64
    + NetworkPkg: reset DHCP child when leaving PXE LoadFile
    + MdeModulePkg: reset DHCP child when leaving PXE LoadFile
    + SecurityPkg AuthVariableLib: Add the missing
      gEfiAuthenticatedVariableGuid
    + MdeModulePkg VariableRuntimeDxe: Add the missing
      gEfiImageSecurityDatabaseGuid
    + MdeModulepkg VarCheckLib: Return NULL when no property set to
      variable with wildcard name
    + NetworkPkg: remove unnecessary timeout event when setting IPv6
      address
    + ShellPkg: Print error message when Shell set environment
      variable fail
    + BaseTools/PeCoffLoader: fix handling of ARM MOVW/MOVT
      instruction relocs
    + UefiCpuPkg: Add ASSERT to handle local APIC not config properly
    + SecurityPkg: Integrate new RngLib into RngDxe
    + MdePkg: Create GetRandomNumber128 in RngLib
    + ArmVirtPkg/ArmVirtQemu: enable non-exec DXE stack for AARCH64
    + MdeModulePkg/DxeIplPeim: implement non-exec stack for
      ARM/AARCH64
    + ArmPkg/ArmLib MMU: add functions to set/clear RO and XN bits on
      regions
    + ArmPkg/AArch64Mmu: move page table traversal code to separate
      function
    + ArmPkg/AArch64Mmu: use architecturally correct definitions for
      XN/UXN
* Thu Oct 08 2015 glin@suse.com
  - Update to R18577
    + OvmfPkg: raise DXEFV size to 9 MB
    + MdeModulePkg: exit pci function loops early if device is not
      multi-function
    + NetworkPkg: HttpDxe: Remove unused local variables
    + ArmPkg/AArch64Mmu: remove cache maintenance for page tables
    + BaseTools/AARCH64: use large code model for GCC <= 4.8
    + ArmPkg/Mmu: do not configure block translations at level 0
    + ArmVirtPkg: use 4 KB section alignment for
      ARM DXE_RUNTIME_DRIVER modules
    + BaseTools/ARM: move to unified GCC linker script
  - Enable HttpBoot for i586 and x86_64
  - Drop patches since upstream fixes the issues
    + ovmf-use-non-default-gcc48.patch
    + 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
* Thu Oct 01 2015 glin@suse.com
  - Update to R18564
    + OvmfPkg: set 4 KB section alignment for DXE_RUNTIME_DRIVER
      modules
    + MdeModulePkg Ip4Dxe: Ip4Config2 to request DHCP Option6 DNS
      server IP
    + MdeModulePkg: Add SMBIOS 3.0 support in NetLibGetSystemGuid
    + ArmVirtPkg: build the TFTP command into the UEFI shell
    + OvmfPkg: build the TFTP command into the UEFI shell
    + ArmVirtPkg: reduce preallocation of boot services data pages
    + OvmfPkg: enable SATA controller
    + OvmfPkg: QemuBootOrderLib: recognize Q35 SATA disks / CD-ROMs
    + MdePkg: Add RngLib into MdePkg
    + MdeModulePkg: Remove event from protocol database only if
      registered
    + ArmVirtPkg: PlatformIntelBdsLib: signal ReadyToBoot on direct
      kernel boot
    + ShellPkg: Added SMBIOS 2.8 Type 17 changes to smbiosview
    + ShellPkg: Added SMBIOS 3.0 support in dmem
    + MdeModulePkg: Enhance PCI capability looking up logic to avoid
      hang
    + OvmfPkg: disable no-exec DXE stack by default
    + OvmfPkg: make PcdPropertiesTableEnable dynamic
    + OvmfPkg: make PcdSetNxForStack dynamic
    + MdeModulePkg: Change the algorithm in SNP to use the first
      found BAR index
    + NetworkPkg: Update Http driver to use DPC mechanism
    + NetworkPkg: RxToken event not closed in Http.Response()
    + NetworkPkg: Avoid memory allocation for each HTTP message
      exchange
    + NetworkPkg: Update cache management in HTTP boot driver
    + NetworkPkg: Enlarge receive block size of HTTP boot driver
    + PXE Driver's LoadFile protocol should check FilePath
    + ArmVirtPkg: set max physical address width to 40 bits
    + ArmVirtPkg/ArmVirtMemoryInitPeiLib: handle memory above 4 GB
      on 32-bit ARM
    + ArmPkg/Mmu: Fix potential page table memory leak
    + ArmPkg/Mmu: Increase PageLevel when table found at the targeted
      level
    + ArmPkg/Mmu: Fix literal number left shift bug
    + ArmPkg/Mmu: Fix page level calculation bug
    + ArmPkg/Mmu: Fix bug of aligning new allocated page table
    + MdeModulePkg: Fix a performance data buffer overrun issue
    + ShellPkg: Fix 'for' command fail with multiple fields
    + MdeModulePkg: Regular expression protocol
    + NetworkPkg: Fix suspicious dereference of pointer 'FieldCount'
    + Handle extra module patchable PCD variable in Linux map
    + NetworkPkg: Fix the HttpCloseConnection fail issue
    + UefiCpuPkg/MtrrLib: MtrrValidBitsMask and MtrrValidAddressMask
      wrong
  - Add ovmf-use-non-default-gcc48.patch: gcc5 generates the larger
    code size and causes the x86_64 final image exceeds the size
    limit if we enable Secure Boot and IPv6 at the same time. As a
    workaround, we use the non-default gcc48.
  - Drop ovmf-gcc5-conf.patch and use GCC49 as TOOL_CHAIN_TAG for
    the distro with gcc5
  - Limit 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    to the distro with gcc lower than 5
  - Refresh ovmf-embed-default-keys.patch and ovmf-gdb-symbols.patch
* Thu Sep 03 2015 glin@suse.com
  - Update to R18393
    + OvmfPkg: PlatformPei: force 32-bit MMIO aperture above 3 GB
    on Q35
    + OvmfPkg: AcpiTables: serialize control methods that create
      named objects
    + OvmfPkg: PlatformPei: clear CMOS 0xF after setting mBootMode
    + CryptoPkg: Fix one wrong parameter for weak key checking
    + CryptoPkg: Replace string wrapper functions with safe string
      functions
    + ArmPlatformPkg/PlatformIntelBdsLib: add splash screen support
    + ArmPlatformPkg/PlatformIntelBdsLib: fix and clean up error
      handling
    + ArmPlatformPkg/PlatformIntelBdsLib: remove ARM BDS dependency
    + Locate IpSec on IP packet processing only if it's installed
    + ShellPkg: Get media status in ifconfig command
    + OvmfPkg: prevent code execution from DXE stack
    + MdePkg: Modify string expression of Wi-Fi device path to
      follow UEFI spec
    + NetworkPkg: Fix IpSec run into infinite loop issue in some case
    + FatBinPkg: Update EBC/IA32/X64/IPF binaries
    + SecurityPkg: Fix one returned code issue in P7Verify Protocol
    + Add VarCheckLib library
    + BaseTools: Add NULL pointer check in AutoGen code
    + Follow PI spec to update ExtendedSize in EFI_FFS_FILE_HEADER2
    + NetworkPkg: Add HTTP utilities driver
    + OvmfPkg: Add HttpBoot support
    + NetworkPkg: Remove the hostname from the http request URL
    + MdeModulePkg:Full support F10 hot key in UiApp
    + NetworkPkg: Fix DHCP TransmitReceive EFI_NO_MAPPING return in
      DnsDxe
    + MdeModulePkg: Fix default router table and interface missing
      error
    + ShellPkg: Fix 'ifconfig' can't get the address from dhcp in
      some case
    + ArmPkg: remove ARMv6 support code
    + MdeModulePkg: Update UiApp to handle terminal type TtyTerm
    + MdeModulePkg/Xhci: make all timeout values be consistent with
      comments
    + SecurityPkg: Fixed build error due to FixedAtBuild
      PcdTcg2HashAlgorithmBitmap
    + MdeModulePkg: IP4 should re-initiate a DHCP if it detects
      network reconnection
    + NetworkPkg: Stop and release DHCP4 child after boot info is
      ready
    + Add restriction that HashFinal() must be after at least one
      HashUpdate()
    + SecurityPkg: Update SignatureSize to comply UEFI spec
    + NetworkPkg: Fix hang issue after system reconnected when IPSec
      has set up
    + Add TPM2 definition in trusted computing group
    + BaseTools IA32/X64: prevent .eh_frame sections from being
      generated
    + MdeModulePkg:Use safe string functions in UiApp
    + MdeModulePkg: Add codes to support trailer parse in HttpLib
    + OvmfPkg/Xen: use lower case x in hex immediate value
    + ArmVirtPkg: use global section alignment in custom linker
      script
    + ArmVirtPkg: avoid relocated immediates in AARCH64 asm
    + MdeModulePkg: Fix issue about current Ip4Dxe implementation
      for DHCP DORA process
    + BaseTools/GenFw: allow AArch64 tiny and small code model
      relocations
  - Add 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    to use the large model for aarch64 since ld/binutils couldn't
    calculate the sections properly and GenFw would fail due to the
    section offset.
  - Drop arm patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
* Mon Aug 10 2015 glin@suse.com
  - Update to R18191
    + UefiCpuPkg CpuDxe: Sync up the settings of Execute Disable to APs
    + MdeModulePkg DxeIpl: Fix IA32 build failure with GCC 5.1.1
    + ArmPlatformPkg/PlatformPeim: constify EFI_PEI_PPI_DESCRIPTOR
      globals
    + ArmPlatformPkg/PrePeiCore: constify PPI globals
    + MdeModulePkg: Use monotonic count to initialize the NetLib
      random seed
    + OvmfPkg: SmbiosVersionLib: recognize SMBIOS 3.x entry point
    + OvmfPkg: SmbiosPlatformDxe: eliminate duplicate entry point
      validation
    + ArmVirtPkg/ArmVirtQemu.dsc: set default for
      PcdQemuSmbiosValidated
    + OvmfPkg: introduce PcdQemuSmbiosValidated
    + ArmVirtPkg: set SMBIOS version in DetectSmbiosVersionLib
      instead of QemuFwCfgToPcdDxe
    + OvmfPkg: set SMBIOS version in DetectSmbiosVersionLib instead
      of PlatformPei
    + OvmfPkg: SmbiosVersionLib: add "plugin" for detecting SMBIOS
      version
    + OvmfPkg: PlatformDebugLibIoPort: fix AsciiSPrint() format
      string
    + ShellPkg: Fix issue about ping fail with IPv4
    + MdeModulePkg DxeIpl: Add stack NX support
    + NetworkPkg: Fix assert caused by wrong parameter in
      AsciiStrCpyS()
    + ArmVirtPkg/ArmVirtQemu: add LinuxLoader UEFI app to ARM build
    + ArmVirtPkg/ArmVirtXen: remove unused PcdFirmwareVendor PCD
    + ArmVirtPkg/ArmVirtQemu: drop ARM BDS and make Intel BDS the
      default
    + BaseTools GCC: move AutoGen.obj contents to .text section
    + BaseTools GCC: align start of .data to .text alignment
    + BaseTools GCC: add unified GCC linker script for all archs and
      versions
    + BaseTools IA32/X64: get header size and alignment from ld
      commandline
    + BaseTools IA32/X64: move .got contents to the PE/COFF .text
      section
    + BaseTools IA32/X64: drop redundant alignment from linker script
    + BaseTools IA32/X64: move .rodata to PE/COFF .text section
    + BaseTools IA32/X64: remove NOP padding from X86/IA32 GCC linker
      scripts
    + MdeModulePkg PeiCore: Add PCD to specify PEIM Shadow
    + ArmVirtPkg: use 'auto' alignment and FIXED placement for XIP
      modules
    + MdeModulePkg: Enhance PciBusDxe to handle high 32bit of MEM64
      BAR returns 0
  - Refresh ovmf-gcc5-conf.patch
  - Refresh 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
  - Drop upstreamed patch: ovmf-netlib-random-seed.patch
  - Drop 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    since the ARM BDS was dropped
* Wed Jul 29 2015 glin@suse.com
  - Update to R18107
    + NetworkPkg: Fix the issue cannot boot to UEFI Network after
      reset
    + ArmVirtPkg: implement DT-based ArmGicArchLib
    + OvmfPkg: fix conversion specifiers in DEBUG format strings
    + Reduce reserved memory consumption
    + MdeModulePkg: Make boot option description unique
    + NetworkPkg: Fix the issue EfiPxeBcDhcp() may return wrong
      status.
    + ArmVirtPkg/ArmVirtQemu: support SMBIOS
    + ArmVirtPkg: QemuFwCfgToPcdDxe: set SMBIOS entry point version
      dynamically
    + ArmVirtPkg: add QemuFwCfgToPcdDxe
    + OvmfPkg: SmbiosPlatformDxe: restrict current Xen code to
      IA32/X64
    + OvmfPkg: SmbiosPlatformDxe: move IsEntryPointStructureValid()
      to Xen.c
    + OvmfPkg: AcpiS3SaveDxe: drop EFI_ACPI_S3_SAVE_PROTOCOL
    + OvmfPkg: install DxeSmmReadyToLock in PlatformBdsLib
    + IntelFrameworkModulePkg/GenericBdsLib: remove AcpiS3->S3Save()
      call
    + OvmfPkg: PlatformBdsLib: signal End-of-Dxe event group
    + OvmfPkg: AcpiS3SaveDxe: call S3Ready() at End-of-Dxe
    + OvmfPkg: AcpiS3SaveDxe: prepare for End-of-Dxe callback
  - Add ovmf-netlib-random-seed.patch to avoid the DHCPv6 IAID
    collision
* Fri Jul 24 2015 glin@suse.com
  - Update to R18030
    + ArmVirtPkg: Make terminal type consistent
    + NetworkPkg: Add the unspecified address check for DNS6
      StationIp
    + ShellPkg: Add optional 'tftp' EFI Shell command
    + NetworkPkg: Fix bios bootup hang issue when enable network
    + SecurityPkg: Fix DBX Variable Read Error in
      ImageVerificationLib
    + SecurityPkg: Correct BootOrder/Boot#### measurement behavior
    + ArmVirtPkg/ArmVirtQemu.dsc: Remove Linux specific boot path
    + ArmPkg/BdsLib: Remove Linux loader from BdsLib
    + ArmPlatformPkg: Add the LinuxLoader.efi EFI application
    + ArmPkg/BdsLib: Replaced BdsLoadApplication() by
      LocateEfiApplicationInFv()
    + OvmfPkg: QemuBootOrderLib: recognize extra PCI root buses
    + OvmfPkg: QemuBootOrderLib: introduce ExtraRootBusMap
    + OvmfPkg: PciHostBridgeDxe: shorten search for extra root buses
    + OvmfPkg: PciHostBridgeDxe: look for all root buses
    + OvmfPkg: PciHostBridgeDxe: eliminate
      PCI_HOST_BRIDGE_INSTANCE.RootBridgeNumber
    + OvmfPkg: PciHostBridgeDxe: use private buffer in
      RootBridgeIoConfiguration()
    + OvmfPkg: PciHostBridgeDxe: release resources on driver entry
      failure
    + OvmfPkg: PciHostBridgeDxe: factor out InitRootBridge() function
    + OvmfPkg: PciHostBridgeDxe: embed device path in private root
      bridge struct
    + OvmfPkg: PciHostBridgeDxe: kill RootBridgeNumber and
      RootBridgeAttribute
    + OvmfPkg: PciHostBridgeDxe: eliminate nominal support for
      multiple host bridges
    + OvmfPkg: PlatformBdsLib: connect all PCI root buses
  - Refresh patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
* Mon Jul 13 2015 glin@suse.com
  - Update to R17935
    + CryptoPkg: update OpenSSL dependency to version 1.0.2d
    + OvmfPkg: QemuFwCfgLib: avoid "variable set but not used"
      warning from GCC
    + Remove Ip4ConfigDxe module
    + IntelFrameworkPkg FrameworkUefiLib: Fix ASSERT in CatVSPrint
    + BaseTools: aarch64: add -fno-asynchronous-unwind-tables to gcc
      cflags
    + MdePkg/AArch64: use GCC_ASM_EXPORT to export functions
    + MdeModulePkg/FvSimpleFileSystemDxe: Support file opening with
      no '.efi'
    + OvmfPkg: Fix GCC49 build hang in PeiCore
    + Add "TtyTerm" terminal type to TerminalDxe
    + MdeModulePkg AcpiTableDxe: Install config table at ACPI data
      change
  - Remove upstreamed ovmf-remove-old-ip4config.patch
* Wed Jul 08 2015 glin@suse.com
  - Update to R17883
    + MdePkg: Add UEFI2.5 Ramdisk device path definition
    + ArmVirtPkg: use correct ASM decoration for non-function global
      symbols
    + NetworkPkg: Add UEFI HTTP boot driver
    + NetworkPkg: Add HTTP Driver
    + NetworkPkg: Add DNS feature support over IPv4 and IPv6
    + MdeModulePkg: Update Ip4Dxe driver to support Ip4Config2
      protocol
    + ArmVirtPkg: adapt ArmVirtXen build to system memory end global
      variable
    + ArmPkg/CpuDxe: Fixed AArch64 MMU
    + ArmPkg/Application: Add new EFI application to boot Linux
    + ArmVirtPkg: build runtime drivers with 64 KB section alignment
    + Restructure AuthVariableLib
    + Conversion of the safe string functions
    + CryptoPkg: Fix the dereferenced pointer issue
    + SecurityPkg: Add MD5 support to Hash2DxeCrypto
    + OvmfPkg: Increase the maximum size of RAM
    + ArmVirtPkg: signal EndOxDxe event in PlatformBsdInit
    + MdeModulePkg: Add Memory Capabilities for MMIO and Reserved
      Range
  - Add ovmf-remove-old-ip4config.patch to remove the old Ip4Config
  - Refresh patches
    + ovmf-embed-default-keys.patch
    + ovmf-gcc5-conf.patch
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
  - Add the source-level debugging to README
* Wed Jun 24 2015 glin@suse.com
  - Update to R17700
    + OvmfPkg/PlatformDxe: Convert Platform.uni to UTF-8
    + OvmfPkg: QemuVideoDxe: add virtio-vga support
    + CryptoPkg: OpensslLib: reintroduce EFIAPI for
      ERR_add_error_data()
    + SecurityPkg: Provide correct file GUID for Pkcs7VerifyDxe
    + SecurityPkg: Fix wrong calculation of ImageExeInfoEntrySize
    + OvmfPkg: PlatformPei: set SMBIOS entry point version
      dynamically
    + SecurityPkg: Add UEFI-2.5 PKCS7 Verification Protocol Support
    + CryptoPkg: Add one new API for PKCS7 Verification Protocol
      Support
    + MdeModulePkg PiSmmCore: Introduce SMM Exit Boot Services and
      Legacy Boot
    + MdePkg/DxeServicesLib: Return NULL GetFileBufferByFilePath
      reads directory
    + MdeModulePkg: Fix DHCP4 driver hang issue in some case
    + MdeModulePkg: Remove DHCP4.TransmitReceive()and DORA process
      dependency
    + MdeModulePkg:System hangs in setup menu
    + ArmVirtPkg: increase memory preallocations for secure build
    + Update openssl to 1.0.2c
    + Add code to protect the whole BIOS region on SPI flash, except
      UEFI Variable region
    + SecurityPkg/MdeModulePkg: Add PcdMaxAuthVariableSize
      declaration
    + MdePkg: Add EFI REST Protocol definitions
    + OvmfPkg/PlatformPei: Initialise RCBA (B0:D31:F0 0xf0) register
    + OvmfPkg/PlatformPei: Query Host Bridge DID only once
    + ArmPkg: reduce sysreg access count in GIC revision probe
    + SecurityPkg: Fix wrong cert data measurement in DBX path
    + MdeModulePkg/UhciDxe: Update async polling interval to 1ms
    + MdeModulePkg/EhciDxe: Update async polling interval to 1ms
    + MdeModulePkg/XhciDxe: Update async polling interval to 1ms
    + ShellPkg\Application\Shell: Clean start row information after
      the console has been Reset or SetMode
    + Add SysPrepOrder and SysPrep#### to global list
    + MdePkg: Add EFI Capsule Report data structure and GUID
    + Add UEFI 2.5 Properties table definition
    + MdePkg:Add UEFI 2.5 PKCS7 Verification Protocol Definition
    + ShellPkg: Handle escape characters properly for parse command
    + ShellPkg: Add pipe support for parse command
    + ArmVirtPkg: increase memory preallocations to reduce region
      count
  - Add ovmf-gcc5-conf.patch for GCC5 and adjust the spec file for
    gcc5
* Wed Jun 03 2015 glin@suse.com
  - Update to R17553
    + MdeModulePkg/AtaAtapiPassThru: ensure PRDT of IDE is in 64K
      boundary
    + ArmPkg/BdsLib: Fixed TFTP when there are directories in the
      name
    + Renamed ArmPlatformPkg/ArmVirtualizationPkg into ArmVirtPkg
    + ArmPkg: Expand AArch64 address width to 48 bits
    + MdeModulePkg:Support delete key
    + MdeModulePkg/AtaAtapiPassThruDxe: Support 4K bytes block size
      HDDs
    + MdeModulePkg: Fix potential buffer overflow issues
    + Update for OEM reserved memory type
  - Update ArmPlatformPkg patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
  - Remove the prefix of the arm patches
    + ovmf-0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + ovmf-0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + ovmf-0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + ovmf-0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + ovmf-0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + ovmf-0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + ovmf-0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + ovmf-0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + ovmf-0010-avoid-potentially-uninitialized-variable.diff
* Thu May 14 2015 glin@suse.com
  - Update to R17446
    + OvmfPkg: AcpiS3SaveDxe: fix protocol usage hint in the INF file
    + OvmfPkg: extract some bits and port offsets common to Q35 and
      I440FX
    + MdeModulePkg: Add ESRT management module.
    + MdeModulePkg: Add ESRT management protocol definition
    + MdePkg: Add Microsoft UX capsule GUID & layout
    + SecurityPkg: Update SecureBootConfigDxe to support ARM image
    + SecurityPkg Variable: Make PK & SecureBootMode consistent
    + MdeModulePkg DxeCore: Add read only memory support
    + OvmfPkg: QemuBootOrderLib: parse OFW device path nodes of PCI
      bridges
    + MdePkg: Add UEFI 2.5 SD (Secure Digital) Device Path Definitions
    + Hash2 driver to [Components.IA32, Components.X64, Components.IPF]
      section
    + ArmVirtualizationPkg: Enable secure boot for ArmVirtualizationQemu
    + ArmPlatformPkg: enable use of authenticated variables in
      NorFlashDxe
  - Refresh patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
  - Enable Secure Boot for AArch64
  - Remove the workaround for SLE11
* Thu May 07 2015 glin@suse.com
  - Although ovmf-gdb-symbols.patch has been included for a while,
    it's not mentioned in changelog and legal-auto script is not
    happy with it.
* Thu May 07 2015 glin@suse.com
  - Update to R17351
    + BaseTools: Fix build fail issue
    + MdeModluePkg: Enable refresh opcode to refresh the entire form
    + BaseTool: Add refresh form opcode in vfrcompiler
    + MdeModulePkg: Add BootManagerMenuApp
    + MdeModulePkg: Add BdsDxe driver and PlatformBootManagerNull
      library
    + MdeModulePkg: Add UefiBootManagerLib
    + MdePkg: Update the UEFI version to reflect new revision
    + OvmfPkg: Use the new PCDs defined in MdePkg and MdeModulePkg
    + MdePkg: Add UEFI2.5 bluetooth protocol/devicepath definition
    + Add UEFI2.5 HASH protocol implementation
    + MdeModulePkg: Add UEFI2.5 and PI1.4 PersistentMemory feature
    + MdePkg: Add ESRT Interface Definitions
    + Various fixes for Shell
  - Drop ovmf-sle-11-gcc47.patch
    + The NASM version in SLE11 is too old to build the newer ovmf
  - Rename the ARM patches to make the legal-auto script happy
    + ovmf-0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + ovmf-0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + ovmf-0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + ovmf-0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + ovmf-0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + ovmf-0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + ovmf-0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + ovmf-0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + ovmf-0010-avoid-potentially-uninitialized-variable.diff
* Thu Apr 23 2015 glin@suse.com
  - Update ovmf-embed-default-keys.patch to embed the default dbx.
    Also add the dbx list from the UEFI website and enable it in the
    MS flavor. A script, strip_authinfo.pl, was added to strip the
    AuthInfo headers from dbxupdate.bin since those are not necessary
    in dbx.
* Mon Apr 20 2015 glin@suse.com
  - Update to R17187
    + Save initial TSVal from TCP connection initiation packets
    + BaseTools/Ecc: Add ECC (EFI Code Checker) Binary into BaseTools
      bin directory
    + MdePkg: Add ESRT Interface Definitions
    + OvmfPkg: XenConsoleSerialPortLib: deal with output overflow
    + OvmfPkg: Q35: Use correct ACPI PM control register:bit
    + PXE driver bug fix
    + A failed PXEv6 after a success PXEv4 will cause ASSERT
    + MdePkg: BaseSynchronizationLib: fix Increment/Decrement retvals
      for ARM
    + Updated Memory Error Record Per UEFI Specification 2.4a
    + MdeModulePkg BootScriptExecutorDxe: Use ImageContext.ImageSize
      to allocate memory for PE image to handle the case PE file
      alignment is not same as PE section alignment.
    + Fix GCC hang issue: Point should use directly assignment
      instead of IP4_COPY_ADDRESS.
    + SecurityPkg Variable: Update code in ProcessVariable ()
  - Update openssl to 0.9.8zf
* Tue Mar 17 2015 glin@suse.com
  - Update to R17055
    + OvmfPkg: include XHCI driver
    + ArmVirtualizationPkg/ArmVirtualizationQemu: include XHCI driver
    + ArmVirtualizationPkg: build UEFI shell from source
    + SecurityPkg Variable: Allow the delete operation of common auth
      variable at user physical presence
    + Set network boot option to the default last priority
    + MdeModulePkg: improve scalability of memory pools
    + MdeModulePkg: use correct granularity when allocating pool
      pages
* Fri Mar 06 2015 glin@suse.com
  - Update to R17007
    + ArmVirtualizationPkg: PlatformIntelBdsLib: lack of QEMU kernel
      is no error
    + Improve Xen support in Ovmf
    + ArmVirtualizationPkg: PlatformIntelBdsLib: display TianoCore
      logo
    + ArmVirtualizationPkg/ArmVirtualizationQemu: add USB keyboard
      input
    + ArmVirtualizationPkg/ArmVirtualizationQemu: add VGA console
      output
    + ArmVirtualizationPkg/ArmVirtualizationQemu: enable PCI support
    + OvmfPkg/QemuVideoDxe: enable ARM builds
    + Improve ACPI support in Ovmf
    + OvmfPkg/PlatformBdsLib: Signal ReadyToBoot before booting QEMU
      kernel
    + ArmPkg/ArmLib.h: Add CPU Affinity definitions
    + OvmfPkg/SMBIOS: Provide default Type 0 (BIOS Information)
      structure
    + NetworkPkg: Code refine to avoid NULL pointer dereferenced
    + DHCP6 bug fix
    + BaseTools/GenFw: Set the PE/COFF attribute BaseOfData with the
      address of the first '.data' section
    + OvmfPkg: Update PlatformBaseDebugLibIoPort library
    + Various fixes for shell
  - Update ARM patches
* Fri Feb 06 2015 lnussel@suse.de
  - update to R16775
  - add RH patches for ARM
* Tue Jan 06 2015 glin@suse.com
  - Update to R16580
    + MdeModulePkg Variable: Implement VarCheck PROTOCOL and follow
      UEFI spec to check UEFI defined variables
    + ArmVirtualizationPkg: Intel BDS: load EFI-stubbed Linux kernel
      from fw_cfg
    + ArmVirtualizationPkg: identify "new shell" as builtin shell
      for Intel BDS
    + ArmVirtualizationPkg: PlatformIntelBdsLib: adhere to QEMU's
      boot order
    + OvmfPkg: QemuBootOrderLib: OFW-to-UEFI translation for
      virtio-mmio
    + OvmfPkg: QemuBootOrderLib: widen ParseUnitAddressHexList() to
      UINT64
    + ArmVirtualizationPkg: VirtFdtDxe: use dedicated
      VIRTIO_MMIO_TRANSPORT_GUID
    + OvmfPkg: introduce VIRTIO_MMIO_TRANSPORT_GUID
    + OvmfPkg: QemuBootOrderLib: featurize PCI-like device path
      translation
    + OvmfPkg: extract QemuBootOrderLib
    + ArmVirtualizationPkg: PlatformIntelBdsLib: add basic policy
    + ArmVirtualizationPkg: clone PlatformIntelBdsLib from
      ArmPlatformPkg
    + ArmVirtualizationPkg: introduce QemuFwCfgLib instance for DXE
      drivers
    + ArmVirtualizationPkg: VirtFdtDxe: forward FwCfg addresses from
      DTB to PCDs
    + MdeModulePkg/FvSimpleFileSystem:Fix a potential NULL
      dereference issue
    + Correct the Hash Calculation for Revoked X.509 Certificate to
      align with RFC3280 and UEFI 2.4 Spec
    + MdeModulePkg/FvSimpleFileSystem: Add a new module to provide
      access to executable files in FVs
    + OvmfPkg: enable IPv6 support
    + Fix a bug that the gateway is not necessary in a simple PXE
      network
    + ArmPkg/BdsLib: Update the size of the Device Tree before
      booting Linux
    + ArmPkg/BdsLib: Rework TFTP boot
    + MdePkg: UefiScsiLib: do not encode LUN in CDB for SCSI commands
    + Correct the alignment calculation of PE/COFF attribute
      certificate entry
    + OvmfPkg: CsmSupportLib: depend on OvmfPkg.dec explicitly
    + OvmfPkg: AcpiPlatformDxe: make dependency on PCI enumeration
      explicit
    + MdePkg/MdeModulePkg: Implement the missing
      SetMemorySpaceCapabilities function
    + Various fixes for shell
  - Set the flag to enable IPv6 support
  - Refresh ovmf-embed-default-keys.patch
* Tue Nov 18 2014 glin@suse.com
  - Update to R16398
    + OvmfPkg: PlatformBdsLib: Dynamic PCI Interrupt Line register
      setup
    + SecurityPkg: VariableServiceSetVariable(): fix dbt <-> GUID
      association
    + CryptoPkg: OpenSslSupport.h: edk2-ize offsetof() macro for
      gcc-4.8 / X64
    + CryptoPkg: TimestampTokenVerify(): fix gcc-4.8 / Ia32 build
      failure
    + UEFI 2.4 X509 Certificate Hash and RFC3161 Timestamp
      Verification support for Secure Boot
    + OvmfPkg: PlatformBdsLib: Platform dependent
      PCI/IRQ initialization
    + OvmfPkg: AcpiTimerLib: Split into multiple phase-specific
      instances
    + OvmfPkg: PlatformPei: Platform specific ACPI power management
      setup
    + OvmfPkg: Factor out platform detection (q35 vs. piix4)
    + UefiCpuPkg/CpuDxe: install Mp Service protocol
    + UefiCpuPkg/CpuDxe: introduce EFI_MP_SERVICES_PROTOCOL
    + ArmPkg/ArmGicLib: select GICv2 mode if SRE is present but
      unavailable
    + OvmfPkg/XenPvBlkDxe: Don't include system inttypes.h
    + ArmPlatformPkg: fix undefined reference to memcpy
    + CryptoPkg Updates to support RFC3161 timestamp signature
      verification
    + MdeModulePkg DxeCore/PiSmmCore: Add UEFI memory and SMRAM
      profile support
* Tue Nov 11 2014 glin@suse.com
  - Update to R16329
    + ArmPkg/ArmArchTimerLib: Promotes 32bit value to prevent
      overflow
    + ArmPkg/CompilerIntrinsicesLib: Fixed memmove() and memset()
    + ArmPkg: Ensured the stack is always quad-word aligned
    + ArmPlatformPkg: Increase more ARM address Pcd entries to 64-bit
    + Fix execution status & DEBUG message level mismatch
    + OvmfPkg: set video resolution of text setup to 640x480
    + OvmfPkg: BDS: drop custom boot timeout, revert to
      IntelFrameworkModulePkg's
    + OvmfPkg: BDS: drop superfluous "connect first boot option"
      logic
    + OvmfPkg: BDS: optimize second argument in
      PlatformBdsEnterFrontPage() call
    + OvmfPkg: BDS: don't overwrite the BDS Front Page timeout
    + OvmfPkg: BDS: drop useless return statement
    + OvmfPkg: BDS: remove dead call to PlatformBdsEnterFrontPage()
    + BaseTools/GenFw: Fixed R_AARCH64_CALL26/R_AARCH64_JUMP26 when
      referring to start of a section
    + Various fixes for ShellPkg
    + Convert the assembly code in OVMF to NASM
    + MdeModulePkg/SecurityPkg Variable: Add boundary check for
      while (IsValidVariableHeader (Variable))
    + Add Xen support for OVMF
    + OvmfPkg: Add the MIT license to License.txt
    + ArmPkg/ArmLib: Removed duplicated invalidate TLB function
    + ArmPlatformPkg/ArmShellCmdRunAxf: Added 'runaxf' cmd to shell
  - Amend the spec file to use the system gcc version as the tool
    chain tag
* Wed Oct 22 2014 glin@suse.com
  - Update to R16226
    + ArmVirtualizationPkg: FdtPL011SerialPortLib: support
      UEFI_APPLICATION
    + ArmPlatformPkg/ArmVirtualizationPkg: Added support for Intel
      BDS
    + ArmPkg/ArmLib/AArch64: Initialize the new N+1-level page table
      before registering it
    + ArmPkg/UncachedMemoryAllocationLib: Track uncached memory
      allocations
    + ArmPkg/ArmPsciResetSystemLib: Made the library only using SMC
    + ArmPlatformPkg/Bds: Reduce boot device entries
    + Various fixes for ShellPkg
    + OvmfPkg: disable stale fork of SecureBootConfigDxe
  - Drop upstreamed ovmf-use-generic-sb-config.patch

Files

/usr/bin/EfiRom
/usr/share/doc/packages/ovmf-tools
/usr/share/doc/packages/ovmf-tools/EfiRom_Utility_Man_Page.rtf


Generated by rpm2html 1.8.1

Fabrice Bellet, Tue Jul 9 18:42:22 2024