Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

qemu-ovmf-ia32-202008-8.1 RPM for noarch

From OpenSuSE Leap 15.3 for noarch

Name: qemu-ovmf-ia32 Distribution: SUSE Linux Enterprise 15
Version: 202008 Vendor: SUSE LLC <>
Release: 8.1 Build date: Thu Apr 1 01:42:59 2021
Group: System/Emulators/PC Build host: sheep16
Size: 4201661 Source RPM: ovmf-202008-8.1.src.rpm
Summary: Open Virtual Machine Firmware - QEMU rom images (IA32)
The Open Virtual Machine Firmware (OVMF) project aims to support
firmware for Virtual Machines using the edk2 code base.

This package contains UEFI rom images for exercising UEFI secure
boot in a qemu environment (IA32)






* Thu Mar 18 2021
  - Add ovmf-bsc1183578-lzma-catch-4GB.patch to fix the possible
    heap corruption (bsc#1183578, CVE-2021-28211)
  - Add ovmf-bsc1183579-fix-fv-recursion.patch to fix unlimited FV
    recursion (bsc#1183579, CVE-2021-28210)
* Fri Jan 29 2021
  - Add ovmf-jscSLE-16075-SEV-ES-use-physical-address.patch as the
    follow-up patch for SEV-ES to fix the flash writing
  - Update 50-xen-hvm-x86_64.json to add "nvram-template" and change
    the firmware file to ovmf-x86_64-ms-4m.bin
    (bsc#1180050, bsc#1181264)
  - Refresh ovmf-bsc1180079-amd-sev-es-mitigation.patch
    + Use "git format-patch --no-renames" to generate the patch to
      avoid confusing quilt with the renamed files
* Tue Jan 12 2021
  - Add ovmf-bsc1180079-amd-sev-es-mitigation.patch to mitigate the
    potential AMD SEV-ES security issues (bsc#1180079)
  - Add the json descriptor for xen-hvm (bsc#1180050)
* Wed Dec 02 2020
  - Add ovmf-bsc1177789-cryptopkg-fix-null-dereference.patch to fix
    the potential NULL dereference in AuthenticodeVerify()
    (bsc#1177789, CVE-2019-14584)
* Tue Nov 17 2020
  - Add ovmf-jscSLE-16075-SEV-ES-fixes.patch to merge upstream SEV-ES
    fixes (jsc#SLE-16075)
* Thu Nov 05 2020
  - Update the json descriptors to address all x86_64 firmware files
  - Remove the executable bit from brotli source code files
* Fri Oct 30 2020
  - Add _constraints to request at least 6GB disk (bsc#1178244)
  - Remove the build files after finishing the build to reduce the
    disk usage (bsc#1178244)
* Wed Sep 09 2020
  - Update to edk2-stable202008
    + MdeModulePkg/Library: add PEIM and SEC module type to
    + SecurityPkg/DxeImageVerificationLib: catch alignment overflow
      (CVE-2019-14562) (bsc#1175476)
    + OvmfPkg/CpuHotplugSmm: fix CPU hotplug race before and after
      SMI broadcast
    + SecurityPkg/Tcg2: handle PRE HASH and LOG ONLY
    + MdePkg/Include: Add missing definition of SMBIOS type 42h in
    + MdePkg: UefiFileHandleLib: fix buffer overrun in
    + OvmfPkg: Add SEV-ES support (jsc#SLE-16075)
    + MdeModulePkg/PartitionDxe: Fix the incorrect LBA size in child
    + MdeModulePkg/PartitionDxe: Revert changes for the special MBR
    + MdeModulePkg/PartitionDxe: Put the UDF check ahead of MBR
    + ShellPkg: smbiosview - Change some type 17 field values format
    + CryptoPkg/OpensslLib: Upgrade OpenSSL to 1.1.1g
    + MdeModulePkg: Upon BootOption failure, Destroy RamDisk memory
      before RSC.
    + OvmfPkg/LsiScsiDxe: Add support for LSI 53C895A
    + MdeModulePkg/DisplayEngine: Add Debug message to show mismatch
      menu info
    + Add New Memory Attributes
    + MdeModulePkg/PartitionDxe: Add already start check for child
    + MdeModulePkg/PartitionDxe: Skip the MBR that add for CD-ROM
    + MdeModulePkg/PartitionDxe: Correct the MBR last block value
    + MdeModulePkg/Variable/RuntimeDxe: Fix return status from
    + SecurityPkg/Tcg2Pei: Add missing PCRIndex in FvBlob event.
    + SecurityPkg/Tcg2Dxe: Add PcdTcgPfpMeasurementRevision in
      SpecId event.
    + CryptoPkg/BaseCryptLib: Add MARCO to disable the deprecated
      SHA1 and MD5
    + ArmVirtPkg/NorFlashQemuLib: disable NOR flash DT nodes upon
    + UefiCpuPkg/SecCore: Add pre-memory AP vector
    + OvmfPkg: End timer interrupt later to avoid stack overflow
      under load
    + ArmPkg/PlatformBootManagerLib: regenerate boot options on
      boot failure
    + MdeModulePkg/StatusCodeHandler: do not output \n\r for string
    + Revert "OvmfPkg: use generic QEMU image loader for secure boot
      enabled ..."
    + ArmVirtPkg/PrePi: use standard PeCoff routines for
    + ArmVirtPkg: add FDF rule for self-relocating PrePi
    + ArmPkg/ArmExceptionLib: use static buffer for sp_el0
    + MdeModulePkg/SetupBrowserDxe: Do not reconnect driver with
    + OvmfPkg/X86QemuLoadImageLib: handle EFI_ACCESS_DENIED from
    + OvmfPkg/Tcg2ConfigPei: generalize TPM2-only file-top comments
    + ArmPkg: only attempt buildin MmCommunicationDxe for AArch64
    + ArmPkg/PlatformBootManagerLib: don't connect all devices on
      each boot
    + ArmPkg/PlatformBootManagerLib: hide UEFI Shell as a regular
      boot option
    + MdeModulePkg/BootManagerUiLib: show inactive boot options
    + ArmPkg/PlatformBootManagerLib: fall back to the UiApp on
      boot failure
    + ArmPkg/PlatformBootManagerLib: register 's' as UEFI Shell
    + ArmPkg/PlatformBootManagerLib: connect non-discoverable USB
    + ArmPkg/ArmSvcLib: prevent speculative execution beyond svc
    + ArmPkg/PlatformBootManagerLib: reject 'default' parity and
      stop bit count
    + ArmPkg/PlatformBootManagerLib: use static assertion for
      console type
    + RegularExpressionDxe: Use submodule way to access third party
    + BrotliCustomDecompressLib: Use submodule way to access third
      party brotli
    + BaseTools: Use submodule way to access third party brotli
    + RISC-V architecture on EDK2
    + Disabling safe string constraint assertions
    + ArmVirtPkg Implement support for TPM2 measured boot
    + OVMF Implement support for Linux v5.7+ initrd and mixed mode
    + OVMF Use loadimage/startimage for loading the kernel passed
      via the QEMU command line
    + OVMF Support booting from Fusion-MPT SCSI controllers
    + OVMF Support booting from VMware PVSCSI controllers
    + OVMF RFE: VCPU hotplug with SMM
    + OVMF PEI phase variable driver / MemoryTypeInfo tracking
    + ArmVirtPkg, OvmfPkg: Pass parameter from QEMU to control PXE
      IPv4/v6 boot
    + Remove deprecate APIs in BaseCryptLib
    + Add UEFI 2.8/2.8a definition in MdePkg
    + Add PI1.7/PI1.7a definition into MdePkg
    + BaseCryptoLib MD4, ARC4, TDES, AES ECB MODE, HMAC MD5, HMAC
      SHA1 API have been deprecated.
    + SecurityPkg Tcg2PhysicalPresenceLib library class removes two
  - Update openssl to 1.1.1g
  - Add 2 reduced source tarballs from the submodules of edk2:
    + brotli-v1.0.7-17-g666c328-c.tar.xz
    - We only need the "c" directory, not the whole tarball.
    + oniguruma-v6.9.4_mark1-src.tar.xz
    - We only need the "src" directory, not the whole tarball.
  - Build all non-native firmware files on x86_64 and aarch64 with
    cross-compilers (bsc#1159134)
    + Exclude i586 and armv7hl due to the availability of
    + Move some bash functions to
  - Clean up PKG_TO_REMOVE
    + Only EmulatorPkg still exists.
  - Add for building the variable templates
  - Drop upstreamed patches
    + ovmf-bsc1163927-fix-ip4dxe-and-arpdxe.patch
    + ovmf-bsc1175476-fix-DxeImageVerificationLib-overflow.patch
    + ovmf-bsc1119454-additional-scsi-drivers.patch
    + ovmf-bsc1163927-fix-ping-and-ip6dxe.patch
    + ovmf-bsc1163969-fix-DxeImageVerificationHandler.patch
    + ovmf-bsc1163959-PiDxeS3BootScriptLib-fix-numeric-truncation.patch
    + openssl-fix-syntax-error.patch
  - Refresh patches
    + ovmf-disable-ia32-firmware-piepic.patch
    + ovmf-gdb-symbols.patch
    + ovmf-pie.patch
* Thu Sep 03 2020
  - Add ovmf-bsc1175476-fix-DxeImageVerificationLib-overflow.patch
    to fix overflow in DxeImageVerificationHandler
    (bsc#1175476, CVE-2019-14562)
* Mon Jul 20 2020
  - Add ovmf-bsc1119454-additional-scsi-drivers.patch to support more
    SCSI drivers (PvScsi, MptScsi, and LsiScsi) (bsc#1119454)
    + Enable LsiScsi explicitly since it's disabled by default
* Mon Apr 06 2020
  - Add ovmf-bsc1163927-fix-ping-and-ip6dxe.patch to fix crash and
    hang in ShellPkg and Ip6Dxe (bsc#1163927, CVE-2019-14559)
* Mon Feb 24 2020
  - Add ovmf-bsc1163969-fix-DxeImageVerificationHandler.patch to fix
    dbx signature check (bsc#1163969, CVE-2019-14575)
    + Also change the order of several patches to distinguish the
      openssl patch
  - Add ovmf-bsc1163927-fix-ip4dxe-and-arpdxe.patch to fix memory
    leakage in Ip4Dxe and ArpDxe (bsc#1163927, CVE-2019-14559)
* Tue Feb 18 2020
  - Add ovmf-bsc1163959-PiDxeS3BootScriptLib-fix-numeric-truncation.patch
    to fix the numeric truncation to avoid the potential memory
    corruption (bsc#1163959, CVE-2019-14563)
* Mon Feb 03 2020
  - Build the unified firmware with preloaded keys for backward
    compatibility (bsc#1159793)
* Fri Dec 20 2019
  - only build -aarch32 Cortex-A15 EFI on armv7hl
* Tue Dec 03 2019
  - Update to edk2-stable201911
    + SecurityPkg: Fix TPM2 ACPI measurement
    + MdeModulePkg: Enable variable runtime cache by default
    + OvmfPkg: Disable variable runtime cache
    + MdeModulePkg/Variable: Add RT GetVariable() cache support
    + CryptoPkg: Upgrade OpenSSL to 1.1.1d
    + MdePkg-UefiSpec.h: Add UEFI 2.8 new memory attributes
    + MdePkg/UefiFileHandleLib: Fix potential NULL dereference
    + NetworkPkg/HttpDxe: Set the HostName for the verification
    + NetworkPkg/TlsDxe: Add the support of host validation to TlsDxe
      driver (CVE-2019-14553)
    + CryptoPkg/TlsLib: TlsSetVerifyHost: parse IP address literals
      as such (CVE-2019-14553)
    + CryptoPkg/TlsLib: Add the new API "TlsSetVerifyHost"
    + MdePkg/Include/Protocol/Tls.h: Add the data type of
      EfiTlsVerifyHost (CVE-2019-14553)
    + MdeModulePkg/BdsDxe: Fix PlatformRecovery issue
    + NetworkPkg/SnpDxe: Add PCD to remove ExitBootServices event
      from SNP driver
    + MdeModulePkg: Update to support SmBios 3.3.0
    + UefiCpuPkg/MpInitLib: honor the platform's boot CPU count in AP
    + SecurityPkg/Tcg2: Add Support Laml, Lasa for TPM2 ACPI
    + OvmfPkg/PlatformDxe: fix EFI_HII_HANDLE parameters of internal
    + OvmfPkg/VirtioNetDxe: fix SignalEvent() call
    + OvmfPkg/XenBusDxe: fix UninstallMultipleProtocolInterfaces()
    + NetworkPkg/Ip4Dxe: fix NetLibDestroyServiceChild() call
    + MdeModulePkg/ScsiDiskDxe: Support Storage Security Command
    + MdePkg: Implement SCSI commands for Security Protocol In/Out
    + MdeModulePkg/TerminalDxe: Enhance the arrow keys support
    + MdeModulePkg/UefiBootManager: Unload image on
    + MdeModulePkg/DxeCapsuleLibFmp: Unload image on
    + MdeModulePkg: Extend the support keyboard type of Terminal
    + UefiCpuPkg/CpuExceptionHandlerLib: Fix split lock
    + UefiCpuPkg: Fix potential spinLock issue in SmmStartupThisAp
    + UefiCpuPkg/PiSmmCpu: Enable 5L paging only when phy addr line
      > 48
    + OvmfPkg/EnrollDefaultKeys: clean up Base64Decode() retval
    + ArmVirtPkg/PlatformBootManagerLib: unload image on
    + ShellPkg/ShellPkg.dsc AARCH64: enable stack protector
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: revert to PIE
    + BaseTools/GenFw AARCH64: fix up GOT based relative relocations
    + ShellPkg/Pci.c: Update supported link speed to PCI5.0
    + PcAtChipsetPkg: add PcdRealTimeClockUpdateTimeout
    + UefiCpuPkg: Add PcdCpuSmmRestrictedMemoryAccess
    + ShellPkg/CommandLib: avoid NULL derefence and memory leak
    + MdePkg/DxeHstiLib: Added checks to improve error handling
    + BaseTools: Support more file types in build cache
    + UefiCpuPkg/SecCore: get AllSecPpiList after SecPlatformMain
  - Update openssl to 1.1.1d
    + Add openssl-fix-syntax-error.patch to fix a syntax error
  - Drop ovmf-bsc1153072-fix-invalid-https-cert.patch
    + Already upstreamed
* Fri Nov 08 2019
  - Use the same x86 4MB firmware names as the ones in the previous
    version (< stable201905) for backward compatibility
* Wed Nov 06 2019
  - Update to edk2-stable201908
    + Add TLS and IPv6 supports for ArmVirtQemu
    + Various fixes and updates for TPM2
    + Various fixes for OvmfPkg and the underlying infrastructures
    + Drop the build requirement of python2
    + Drop the obsolete IntelFrameworkPkg and IntelFrameworkModulePkg
    + Remove ShellBinPkg and move the platform packages out of edk2
  - Update openssl to 1.1.1b
    + Add berkeley-softfloat-3-b64af41c3276f.tar.xz since arm7 needs
      the softfloat implementation for openssl 1.1.1b
  - Add ovmf-bsc1153072-fix-invalid-https-cert.patch to reject the
    invalid server certificates for HTTPS Boot
    (bsc#1153072, CVE-2019-14553)
  - Build the varstore templates with EnrollDefaultKeys.efi
    + Create the iso files for key enrollment
    - Add to generate the iso file
    + Drop the non-upstream ovmf-embed-default-keys.patch
    - Also drop owner-guid-zero.h
    + Drop the MS keys and dbx since they are already in
      EnrollDefaultKeys.efi: MicCorKEKCA2011_2011-06-24.crt,
      MicCorUEFCA2011_2011-06-27.crt, MicWinProPCA2011_2011-10-19.crt,
    - Also drop the related script
    + Add ovmf-set-fixed-enroll-time.patch to set the fixed enrolling
      time to make the varstore template reproducible
    + Require qemu 3.0.0 for fw_cfg
  - Enable TLS (HTTPS Boot) and TPM2 support
  - Add the firmware descriptors for QEMU
  - Update README to match the current settings
  - Update the License tag to BSD-2-Clause-Patent
  - Build SecureBoot firmwares for aarch64
  - Add a new "smm" flavor to enable System Management Mode
    + Also add ovmf-add-exclude-shell-flag.patch to exclude shell
      from the resultant SMM firmware files
  - Retire the old openSUSE 4096 bit certificates since all those
    programs are unmaintained.
  - Drop upstreamed patches
    + ovmf-bsc1092943-fix-attributes-table.patch
    + ovmf-bsc1099193-fix-sev-flash-variables.patch
    + ovmf-bsc1115916-fix-timestamp-zeroing.patch
    + ovmf-bsc1115917-bounds-checking-for-ueficompress.patch
    + ovmf-bsc1127820-fix-blockio-buffer-overflow.patch
    + ovmf-bsc1127821-dns-check-packet-size.patch
    + ovmf-bsc1127822-fix-fv-parsing.patch
    + ovmf-bsc1128503-fix-stack-overflow-in-HiiImage-and-HiiDatabase.patch
    + ovmf-bsc1130267-overflow-in-partition-and-udf.patch
    + ovmf-bsc1131361-fix-stack-overflow-xhci.patch
  - Refresh patches:
    + ovmf-add-exclude-shell-flag.patch
    + ovmf-disable-ia32-firmware-piepic.patch
    + ovmf-pie.patch
  - Drop the requirement of xxd
* Tue Apr 09 2019
  - Add ovmf-bsc1131361-fix-stack-overflow-xhci.patch to fix stack
    overflow in UsbBusDxe and UsbBusPei (bsc#1131361, CVE-2019-0161)
* Mon Mar 25 2019
  - Add ovmf-bsc1130267-overflow-in-partition-and-udf.patch to fix
    buffer overflows in PartitionDxe and UdfDxe (bsc#1130267,
* Mon Mar 11 2019
  - Add ovmf-bsc1128503-fix-stack-overflow-in-HiiImage-and-HiiDatabase.patch
    to fix stack overflow in HiiImange and HiiDatabase (bsc#1128503,
* Tue Mar 05 2019
  - Add ovmf-bsc1127820-fix-blockio-buffer-overflow.patch to fix
    buffer overflow in BlockIo protocol (bsc#1127820, CVE-2018-12180)
  - Add ovmf-bsc1127821-dns-check-packet-size.patch to check the size
    of the received DNS packet (bsc#1127821, CVE-2018-12178)
  - Add ovmf-bsc1127822-fix-fv-parsing.patch to fix the logic error
    in FV parsing (bsc#1127822, CVE-2018-3630)
* Wed Dec 05 2018
  - Update ovmf-embed-default-keys.patch and add owner-guid-zero.h to
    set the default owner of PK/KEK/db/dbx and make the
    auto-enrollment only happen at the very first time. (bsc#1117998)
* Wed Nov 14 2018
  - Add ovmf-bsc1115916-fix-timestamp-zeroing.patch to fix Timestamp
    zeroing issue on APPEND_WRITE (bsc#1115916, CVE-2018-3613)
  - Add ovmf-bsc1115917-bounds-checking-for-ueficompress.patch for
    the bound checking of ueficompress (bsc#1115917, CVE-2017-5731,
    CVE-2017-5732, CVE-2017-5733, CVE-2017-5734, CVE-2017-5735)
* Tue Jul 10 2018
  - Add ovmf-bsc1099193-fix-sev-flash-variables.patch to fix the
    missing EFI variables when SEV is set (bsc#1099193)
* Wed May 23 2018
  - Update openssl to 1.1.0h (bsc#1094289, CVE-2018-0739)
* Mon May 14 2018
  - Add ovmf-bsc1092943-fix-attributes-table.patch to avoid sending
    the memory map with invalid attributes (bsc#1092943)
* Wed Jan 24 2018
  - Only use SLES-UEFI-CA-Certificate-2048.crt for the suse flavor to
    provide the better compatibility (bsc#1077330)
* Mon Nov 20 2017
  - Update to 2017+git1510945757.b2662641d5
    + ArmPlatformPkg/ArmPlatformLibNull: remove bogus PCD dependencies
    + MdeModulePkg/UsbMassStorageDxe: Enhance Request Sense Handling
    + OvmfPkg: save on I/O port accesses when the debug port is not
      in use
    + OvmfPkg: create a separate PlatformDebugLibIoPort instance for
    + OvmfPkg: make PlatformDebugLibIoPort a proper BASE library
    + OvmfPkg: restore temporary SEC/PEI RAM size to 64KB
    + OvmfPkg/Sec/X64: seed the temporary RAM with PcdInitValueInTempStack
    + ArmVirtPkg: switch to new PL011UartLib implementation
    + OvmfPkg/XenHypercallLib: enable virt extensions for ARM
    + MdeModulePkg/PiSmmCore: Implement heap guard feature for SMM mode
    + MdeModulePkg/DxeCore: Implement heap guard feature for UEFI
    + ArmVirtPkg/ArmVirtQemu: use non-accelerated CopyMem for
    + NetworkPkg: Fix incorrect SizeofHeaders returned from
    + NetworkPkg: Print error message to screen if error occurs
      during HTTP boot
    + MdeModulePkg/PartitionDxe: Fix UDF fs access on certain CD/DVD
    + MdeModulePkg/UsbMassStorageDxe: Fix USB Mass Storage detection
    + MdeModulePkg SerialDxe: Handle Timeout change more robustly
    + CryptoPkg/BaseCryptLib: Fix mismatched memory allocation/free
    + CryptoPkg/BaseCryptLib: Fix buffer overflow issue in realloc
    + ArmPlatformPkg/PlatformPeim: allow PlatformPeiLib to set the
      boot mode
    + SecurityPkg: Remove Counter Based AuthVariable support
    + BaseTools/tools_def AARCH64 ARM: disable PIE linking
    + NetworkPkg/TlsAuthConfigDxe: Remove the extra FreePool
    + NetworkPkg/HttpBootDxe: Add IPv6 support condition check
    + NetworkPkg/IScsiDxe: Fix the incorrect/needless DHCP process
    + MdeModulePkg/PciBus: Fix bug that PCI BUS claims too much resource
    + UefiCpuPkg/MtrrLib: Use SetMem instead of SetMem64 to fix hang
    + NetworkPkg: Remove ping6 and ifconfig shell application
    + OvmfPkg: fix dynamic default for oprom verification policy PCD
      without SB
      SEV is active
    + SecurityPkg\Tcg2Pei: FV measure performance enhancement
    + SecurityPkg:AuthVariableLib:Implement ECR1707 for Private Auth
    + ArmPlatformPkg: Store initial timer value
    + ArmVirtPkg ArmVirtDxeHobLib: Implement BuildFv3Hob
    +  MdeModulePkg/Variable/RuntimeDxe: delete and lock OS-created
      MOR variable
    + ArmPkg/PlatformBootManagerLib: fix bug in ESRT invocation
    + OvmfPkg/PciHotPlugInitDxe: translate QEMU's resource
      reservation hints
    + OvmfPkg/PciHotPlugInitDxe: generalize RESOURCE_PADDING
    + OvmfPkg/IndustryStandard: define PCI Capabilities for QEMU's
      PCI Bridges
    + MdeModulePkg/BdsDxe: Don't delete "BootNext" until booting it
    + Clarify the usage of HttpConfigData in HTTP protocol
    + SecurityPkg/SecureBootConfigImpl.c: Secure Boot DBX UI
    + MdeModulePkg/UDF: Fix creation of UDF logical partition
    + CryptoPkg: Add new API to retrieve commonName of X.509 certificate
    + OvmfPkg/VirtioNetDxe: log debug message in VirtioNetExitBoot()
    + OvmfPkg/QemuBootOrderLib: recognize "usb-storage" devices in
      XHCI ports
    + MdeModulePkg/Core: Fix out-of-sync issue in GCD
    + UefiCpuPkg/CpuDxe: Fix out-of-sync issue in page attributes
    + OvmfPkg/QemuVideoDxe/VbeShim: handle PAM1 register on Q35
    + OvmfPkg/QemuVideoDxe/VbeShim: rename Status to
    + OvmfPkg/CsmSupportLib: move PAM register addresses to
    + NetworkPkg/IScsiDxe: Remove redundant call to StrLen
    + BaseTools/tools_def AARCH64: enable frame pointers for RELEASE
    + ArmPkg/PlatformBootManagerLib: process pending capsules
    + MdeModulePkg/Udf: Avoid declaring and initializing local GUID
    + MdeModulePkg/UdfDxe: Avoid short (single character) variable name
    + MdeModulePkg/UdfDxe: Use compare operator for non-boolean
    + MdeModulePkg/UdfDxe: Fix operands of different size in bitwise
    + MdeModulePkg/UdfDxe: Add checks to ensure no possible NULL ptr
    + MdeModulePkg/SerialDxe: Fix not able to change serial attributes
    + NetworkPkg: Remove the redundant '/' in the end of returned
      ISCSIMacAddr keyword
    + MdeModulePkg/UdfDxe: Fix NULL pointer dereference
    + OvmfPkg/VirtioNetDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioNetDxe: map caller-supplied Tx packet to
    + OvmfPkg/VirtioNetDxe: add Tx packet map/unmap helper functions
    + OvmfPkg/VirtioNetDxe: update TechNotes
    + OvmfPkg/VirtioNetDxe: dynamically alloc transmit header
    + OvmfPkg/VirtioNetDxe: alloc RxBuf using AllocateSharedPages()
    + OvmfPkg/VirtioNetDxe: map VRINGs using VirtioRingMap()
    + OvmfPkg/VirtioNetDxe: add helper VirtioNetUninitRing()
  - Update openssl to 1.1.0g
* Mon Oct 16 2017
  - Update ovmf-gdb-symbols.patch to avoid some symbols from being
    removed (bsc#1063463)
  - Add needssslcertforbuild back. It's useful for the devel projects.
* Thu Sep 14 2017
  - Update to 2017+git1505340320.5afa5b8159
    + MdeModulePkg/UdfDxe: suppress incorrect compiler warning in
    + MdeModulePkg/UdfDxe: reject reserved values in ICB.Flags[2:0]
    + MdeModulePkg: Add UdfDxe to the dsc file
    + MdeModulePkg: Update PiDxeS3BootScriptLib Internal function name
    + MdeModulePkg/UdfDxe: Remove negative comparison of unsigned
    + ArmVirtPkg/ArmVirtQemu: port HTTP_BOOT_ENABLE from OvmfPkg
    + ArmVirtPkg: don't build the network stack uselessly for Xen
    + MdeModulePkg/PartitionDxe: remove always false comparison
    + MdeModulePkg/PartitionDxe: don't divide 64-bit values with C
    + MdeModulePkg/UdfDxe: replace zero-init of local variables with
    + MdeModulePkg/UdfDxe: don't return unset Status if INLINE_DATA
      req succeeds
    + MdeModulePkg/UdfDxe: ASSERT() valid ReadFileInfo Flags for
      INLINE_DATA req
    + MdeModulePkg/UdfDxe: Initialize the array after declaration
    + ShellPkg/Ifconfig6: Update error message and add a new line
    + NetworkPkg/IScsiDxe: Fix the incorrect max length of IP_ADDRESS
    + OvmfPkg/SataControllerDxe: log informative message at
      DEBUG_INFO level
    + OvmfPkg/PlatformBootManagerLib: log informative message at
      DEBUG_INFO lvl
    + OvmfPkg/PlatformPei: log informative message at DEBUG_INFO level
    + UefiCpuPkg/CpuDxe: log informative message at DEBUG_INFO level
    + MdeModulePkg/UsbBusDxe: log warning message at DEBUG_WARN level
    + OvmfPkg/PlatformDebugLibIoPort: write messages with IoWriteFifo8()
    + MdePkg/BaseIoLibIntrinsic: fix SEV (=unrolled) variants of IoWriteFifoXX()
    + MdeModulePkg Xhci: Correct description of Timeout param in XhciReg.h
    + BaseTools/GCC: set -Wno-unused-const-variable on RELEASE builds
    + ArmVirtPkg: Enable UDF file system support
    + OvmfPkg: Enable UDF file system support
    + MdeModulePkg/PartitionDxe: Add UDF file system support
    + OvmfPkg/IoMmuDxe: unmap all IOMMU mappings at ExitBootServices()
    + OvmfPkg/IoMmuDxe: generalize IoMmuUnmap() to IoMmuUnmapWorker()
    + OvmfPkg/IoMmuDxe: track all mappings
    + OvmfPkg/VirtioScsiDxe: don't unmap VRING at ExitBootServices()
    + OvmfPkg/VirtioRngDxe: don't unmap VRING at ExitBootServices()
    + OvmfPkg/VirtioGpuDxe: don't unmap VRING & BackingStore at ExitBootServices
    + OvmfPkg/VirtioBlkDxe: don't unmap VRING at ExitBootServices()
    + MdeModulePkg/AtaAtapiPassThru: disable the device at ExitBootServices()
    + MdeModulePkg/AtaAtapiPassThru: unmap DMA buffers after disabling
      BM DMA
    + MdeModulePkg/AtaAtapiPassThru: cache EnabledPciAttributes
    + OvmfPkg/SecMain: Fix stack switching to permanent memory
    + ArmPkg: add ArmCrashDumpDxe driver
    + MdeModulePkg, NetworkPkg: Fix GCC build error
    + NetworkPkg/Ip6Dxe: fix a bug in IP6 driver for IpSec protocol
    + MdeModulePkg/Ip4Dxe: fix a bug in IP4 driver for IpSec protocol
    + MdePkg: Add UEFI 2.7 defined GUID and structure for AIP network
      media type
    + MdeModulePkg/UefiBootManagerLib: Generate boot description for
    + Pkcs7VerifyDxe: Don't allow Pkcs7Verify to install protocols twice
    + SecurityPkg/Pkcs7Verify: Complete the Pkcs7VerifyDxe protocol
    + MdePkg PeiMemoryAllocationLib: Update InternalAllocateAlignedPages
    + MdePkg PeiMemoryAllocationLib: Update Free(Aligned)Pages
    + MdeModule PeiCore: Support pre memory page allocation
    + OvmfPkg/VirtioGpuDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioGpuDxe: map backing store to bus master device address
    + OvmfPkg/VirtioGpuDxe: helpers for backing store (de)allocation+(un)mapping
    + OvmfPkg/VirtioGpuDxe: take EFI_PHYSICAL_ADDRESS in ResourceAttachBacking()
    + OvmfPkg/VirtioGpuDxe: map virtio GPU command objects to device
    + OvmfPkg/VirtioGpuDxe: map VRING for bus master common buffer
    + OvmfPkg/IoMmuDxe: IoMmuFreeBuffer(): clean up DEBUG message
    + OvmfPkg/IoMmuDxe: IoMmuAllocateBuffer(): nicer and more
      informative DEBUGs
    + OvmfPkg/IoMmuDxe: IoMmuUnmap(): clean up DEBUG message
    + OvmfPkg/IoMmuDxe: IoMmuMap(): log nicer and more informative
      DEBUG msgs
    + OvmfPkg/BaseMemEncryptSevLib: clean up upper-case / lower-case
      in DEBUGs
    + OvmfPkg/BaseMemEncryptSevLib: promote DEBUG_WARN levels to
    + OvmfPkg/BaseMemEncryptSevLib: clean up debug logging of
    + OvmfPkg/BaseMemEncryptSevLib: clean up DEBUG prefixes
    + OvmfPkg/BaseMemEncryptSevLib: break DEBUG calls to multiple lines
    + OvmfPkg/BaseMemEncryptSevLib: unify encrypt/decrypt DEBUG messages
    + ArmPkg: remove ArmDmaLib
    + OvmfPkg/VirtioScsiDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/VirtioScsiDxe: map virtio-scsi request and response buffers
    + OvmfPkg/VirtioScsiDxe: add helper to create a fake host adapter error
    + OvmfPkg/VirtioScsiDxe: map VRING using VirtioRingMap()
    + ArmPkg: remove UncachedMemoryAllocationLib
    + BaseTools/Gcc ARM AARCH64: add support for building device tree
    + BaseTools: Enable --whole-archive in GCC tool chain as the
      default option
    + UefiCpuPkg/Mplib.c: Perform complete initialization when enable AP
    + OvmfPkg/VirtioBlkDxe: Check the return status of unmap data buffer
    + ArmVirtPkg: remove DmaLib library class resolution
    + ShellPkg: Update CWD and current mapping when commands return
    + ShellPkg: Fix bug that fails to change CWD after "map -r"
    + SecurityPkg: Add ARM/AARCH64 arch to enable RngTest module build
    + OvmfPkg/QemuFwCfgDxeLib: SEV: zero FW_CFG_DMA_ACCESS before
      decrypting it
    + ArmPkg/ArmDmaLib: implement DmaAllocateAlignedBuffer()
    + MdeModulePkg/UefiHiiLib: Fix incorrect check for string length
    + OvmfPkg/VirtioBlkDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + Ovmfpkg/VirtioBlkDxe: map virtio-blk request and response buffers
    + OvmfPkg/VirtioBlkDxe: map VRING using VirtioRingMap()
    + MdePkg/S3PciSegmentLib: Add S3PciSegmentLib class and instance
    + MdePkg/PciSegmentLib: Add instances that consumes PciSegmentInfoLib
    + MdePkg/PciSegmentInfoLib: Add PciSegmentInfoLib class and instance
    + UefiCpuPkg/CpuCommonFeaturesLib: Add CPUID MCA support check
    + UefiCpuPkg: Update default for PcdCpuProcTraceMemSize/PcdCpuProcTraceOutputScheme
    + UefiCpuPkg/CpuCommonFeaturesLib: Use MSR data structure when
      change MSR value
    + UefiCpuPkg/ArchitecturalMsr.h: Add RTIT TOPA table entry
    + UefiCpuPkg/MpLib: fix potential overflow issue
    + UefiCpuPkg/PiSmmCpuDxeSmm: Fix memory protection crash
    + BaseTools/EfiRom: Add multiple device id support
    + OvmfPkg/VirtioRngDxe: negotiate VIRTIO_F_IOMMU_PLATFORM
    + OvmfPkg/Virtio10: define VIRTIO_F_IOMMU_PLATFORM feature bit
    + MdeModulePkg XhciDxe: Fix Map and Unmap inconsistency
    + SecurityPkg/Tcg2Dxe: Properly shutdown TPM before reset
    + OvmfPkg/VirtioRngDxe: map host address to device address
    + OvmfPkg/VirtioLib: change the parameter of VirtioAppendDesc()
      to UINT64
    + OvmfPkg/VirtioLib: alloc VRING buffer with AllocateSharedPages()
    + OvmfPkg/VirtioLib: add function to map VRING
    + OvmfPkg/Virtio10Dxe: add the RingBaseShift offset
    + OvmfPkg/Virtio: take RingBaseShift in SetQueueAddress()
    + OvmfPkg/VirtioLib: take VirtIo instance in VirtioRingInit/VirtioRingUninit
    + OvmfPkg/VirtioLib: add VirtioMapAllBytesInSharedBuffer() helper
    + OvmfPkg/VirtioMmioDeviceLib: implement IOMMU-like member functions
    + OvmfPkg/VirtioPciDeviceDxe: implement IOMMU-like member functions
    + OvmfPkg/Virtio10Dxe: implement IOMMU-like member functions
    + OvmfPkg: introduce IOMMU-like member functions to VIRTIO_DEVICE_PROTOCOL
    + BaseTools: Add the missing -pie link option in GCC tool chain
    + ArmPkg/ArmDmaLib: remove dependency on UncachedMemoryAllocationLib
    + OvmfPkg/QemuVideoDxe: remove AARCH64/ARM support
    + ArmVirtPkg: remove QemuVideoDxe from ArmVirtQemu and ArmVirtQemuKernel
    + BaseTools: Roll back GenFw Change to keep unknown field in RSDS
      debug entry
    + MdeModulePkg/DisplayEngine: Add implementation of HiiPopup protocol
    + MdeModulePkg/Library: Remove the self-reference in
    + ShellPkg/mkdir: support creating nested directories
    + MdeModulePkg/ScsiBusDxe: don't produce ScsiIo for nonexistent LUNs
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add CPUID MCA support check
    + ArmPkg/ArmDmaLib: use double buffering only for bus master write
    + ArmVirtPkg/FdtPL011SerialPortLib: call PL011UartLib in all
      SerialPortLib APIs
    + UefiCpuPkg RegisterCpuFeaturesLib: Fix buffer pointer error usage
    + NetworkPkg/Ip6Dxe: Fix the bug when checking the DataSize
    + MdePkg/BaseLib: Update internal LinkedList verifications
    + MdePkg/BaseLib: Add IsNodeInList() function
    + MdeModulePkg: Delete useless case code
    + MdeModulePkg: Delete never touched code
    + UefiCpuPkg/BaseUefiCpuLib.inf: Remove unnecessary library class
    + UefiCpuPkg RegisterCpuFeaturesLib: Enhance debug messages.
* Mon Aug 28 2017
  - Update ovmf-embed-default-keys.patch to handle the empty
    certificate files correctly
* Thu Aug 17 2017
  - Update to 2017+git1502826981.a136bc3ccf
    + OvmfPkg/Protocol/VirtioDevice: fix comment style
    + OvmfPkg/VirtioMmioDeviceLib: add missing IN and OUT decoration
    + OvmfPkg/VirtioPciDeviceDxe: add missing IN and OUT decoration
    + OvmfPkg/Virtio10Dxe: supply missing BUS_MASTER attribute
    + OvmfPkg/VirtioPciDeviceDxe: supply missing BUS_MASTER attribute
    + UefiCpuPkg MpInitLib: Save/restore original WakeupBuffer for
    + ShellPkg UefiDpLib: Init CustomCumulativeData.MinDur
    + MdeModulePkg DxeCore: Enhance "ConvertPages: Incompatible
      memory types"
    + MdeModulePkg DxeCore: Fix double free pages on LoadImage
      failure path
    + NetworkPkg/HttpBootDxe: Update device path node to include DNS
    + MdeModulePkg/UefiBootManagerLib: Support DNS device path
    + MdePkg/UefiDevicePathLib: Add DevPathFromTextDns and
      DevPathToTextDns libraries
    + MdePkg/DevicePath.h: Add DNS Device Path definition
    + NetworkPkg/HttpDxe: Handle the HttpVersionUnsupported in the
    + BaseTools: Support TabSpace between section tag in DEC file
    + BaseTools: Don't need to add extra quotes when UI string from
    + BaseTools/UPT: Support Multiple Installation
    + BaseTools/Scripts: Add sample makefile for use with
    + BaseTools/Scripts: Add python script to run a makefile
    + BaseTools/build: Expand PREBUILD/POSTBUILD DSC actions
    + NetworkPkg/Ip6Dxe: Support SetData interface to clear specific
    + MdeModulePkg/Ip4Dxe: Support SetData interface to clear
      specific configuration
    + ShellPkg/drivers: Fix GCC build failure
    + BaseTools/ fix invalid test for current working
    + ShellPkg/driver: Show "-" in non-SFO mode
    + ShellPkg/drivers: Show Image Name in non-SFO mode
    + MdeModulePkg: Variable: Fix typo in variable measure
    + MdeModulePkg/NvmExpressDxe: Notify NVME HW when system reset
    + MdePkg/Nvme: Add NVME shutdown notification related macros
    + NetworkPkg/HttpBootDxe: Refine the coding style.
    + OvmfPkg/AcpiPlatformDxe: short-circuit the transfer of an empty
    + MdeModulePkg SerialDxe: Process timeout consistently in
    + UefiCpuPkg MtrrLib: Remove deprecated micro.
    + UefiCpuPkg CpuDxe: Remove reference deprecated macro.
    + UefiCpuPkg CpuDxe: Enhance get mtrr mask logic.
    + BaseTools/Conf: apply nasmb, asm16 build rule order
    + NetworkPkg/HttpDxe: Support HTTP Patch method
    + OvmfPkg/PlatformPei: support >=1TB high RAM, and discontiguous
      high RAM
    + OvmfPkg/QemuFwCfgLib: Use BusMasterCommonBuffer to map
    + OvmfPkg/IoMmuDxe: Unmap(): recycle MAP_INFO after
    + OvmfPkg/IoMmuDxe: abort harder on memory encryption mask
    + OvmfPkg/IoMmuDxe: implement in-place decryption/encryption for
    + OvmfPkg/IoMmuDxe: rework setup of "MapInfo->PlainTextAddress"
      in Map()
    + OvmfPkg/IoMmuDxe: zero out pages before releasing them
    + OvmfPkg/IoMmuDxe: clean up used library classes
    + OvmfPkg/IoMmuDxe: propagate errors from AmdSevInstallIoMmuProtocol()
    + OvmfPkg/IoMmuDxe: don't initialize local variables
    + OvmfPkg/IoMmuDxe: convert UINTN arguments to UINT64 for the
      %Lx fmt spec
    + OvmfPkg/IoMmuDxe: rename HostAddress to CryptedAddress in
    + OvmfPkg/IoMmuDxe: rename DeviceAddress to PlainTextAddress in
    + OvmfPkg/IoMmuDxe: rewrap source code to 79 characters
    + OvmfPkg/IoMmuDxe: Fix header guard macro
    + MdeModulePkg/DisplayEngine: Fix incorrect display issue
    + BaseTools/VfrCompile: Remove the MAX_PATH limitation
    + BaseTools/VfrCompile: Fix segmentation fault issues
    + NetworkPkg: iSCSI should allow to set 6 or 12 length of ISID
    + UefiCpuPkg: Enable Processor Trace feature.
    + UefiCpuPkg: Add Processor Trace feature definition.
    + UefiCpuPkg: Add Pcds used by processor trace feature.
    + UefiCpuPkg/Msr: Add a missing IvyBridge processor signature
    + MdeModulePkg PeiCore: Install SEC HOB data
    + MdePkg: Add definition for SecHobData PPI
    + UefiCpuPkg PiSmmCpuDxeSmm: Check LMCE capability when wait for
    + UefiCpuPkg CpuCommonFeaturesLib: Enable LMCE feature.
    + UefiCpuPkg: Add definition for LMCE feature.
    + NetworkPkg: Display HTTP redirection info to the screen if need.
    + ShellPkg/dblk: Honor the BlockIo alignment requirement.
    + MdeModulePkg/Ufs: Set 'Data Segment Length' field for Write
    + MdeModulePkg/UfsPassThruDxe: Add impl of UFS Device Config
    + UefiCpuPkg SecCore: Fix operands of different size in bitwise
    + MdePkg/Ftp4: Fix wrong function pointer declaration
    + NetworkPkg/HttpDxe: Destroy the TLS instance when cleaning up
      the HTTP child
    + CryptoPkg/TlsLib: Remove the redundant free of BIO objects
    + NetworkPkg/Ip6Dxe: Fix the IPv6 PXE boot option goes missing
    + Fix spelling typo in EFI_HTTP_STATUS_CODE
    + NetworkPkg/HttpDxe: Refine the coding style.
    + MdePkg/Http.h: Refine the coding style.
    + ArmPkg: Move IS_DEVICE_PATH_NODE for sharing
    + MdeModulePkg FirmwarePerfPei: Remove SEC performance data
      getting code
    + UefiCpuPkg SecCore: Add SecPerformancePpiCallBack
    + UefiCpuPkg SecCore: Adjust PeiTemporaryRamBase&Size to be
      8byte aligned
    + MdeModulePkg PeiCore: Handle notification PPI from SEC
    + MdePkg PiPeiCis.h: Add description for notification PPI from
    + MdeModulePkg PiSmmCoreMemoryAllocLib: Fix a FreePool()
      assertion issue
    + BaseTools/GenCrc32: Fix a bug to hand empty file for decode
    + BaseTools/EfiLdrImage: Fix a segmentation fault from
    + BaseTools/EfiRom: Fix a segmentation fault from
    + BaseTools/GenFfs: Fix a segmentation fault from
    + BaseTools/GenSec: Fix a segmentation fault in main()
    + BaseTools/Split: Fix the segmentation fault in GetSplitValue()
    + BaseTools: Fix the bug to correctly check Pcd type that in FDF
    + MdeModulePkg/PciBus: Avoid hang when BUS pad resource is not
      in top
    + ShellPkg: Avoid buffer out-of-bound access
    + ShellPkg/setvar: Check the duplicate flag
    + ShellPkg/ShellLib: Remove unused macros
    + MdePkg: Follow UEFI 2.7 spec to deprecate SMM Communication
      ACPI Table
    + UefiCpuPkg PiSmmCommunicationSmm: Deprecate SMM Communication
      ACPI Table
    + MdeModulePkg/BMMUiLib: Check reset requirement before exiting
    + MdeModulePkg/BMUiLib: Check reset requirement before exiting
    + MdeModulePkg/SetupBrowser: Record the reset status in all
    + ShellPkg/map: Recognize CDROM change
    + MdeModulePkg Xhci: Also RecoverHaltedEndpoint for BABBLE_ERROR
    + MdeModulePkg SmmLockBoxDxeLib: Get SmmCommRegion for COMM
    + MdePkg/ResetNotification: Rename to UnregisterResetNotify
    + MdePkg: Add UEFI 2.7 defined GUID and structure for KMS
    + ShellPkg/ls: Display the file time in local time.
    + BaseTools: Fix the bug that warn() function with only 1
    + BaseTools: add some comment for .PrebuildEnv file's usage
    + UefiCpuPkg: Update RegisterCpuFeaturesLib to consume
      PcdGetSize with UINTN
    + UefiCpuPkg: Update RegisterCpuFeaturesLib module UNI to match
    + MdeModulePkg: Update NonDiscoverableDeviceRegistrationLib file
      header format
    + MdePkg UsbFunctionIo.h: Update comments for GetDeviceInfo
      return status
    + UefiCpuPkg: Remove deprecated CPU feature.
    + MdeModulePkg SmmAccess: Update comments to follow PI spec.
    + MdePkg SmmAccess2: Update comments to follow PI spec.
    + UefiCpuPkg RegisterCpuFeaturesLib: Add error handling.
    + MdeModulePkg/DxeCore: Avoid accessing non-owned memory
    + MdePkg DxeHstiLib: Fix memory leak issue
    + MdePkg Hsti.h: Update version info to 1.1a
    + ArmPlatformPkg: Support different PL011 reg offset
    + CryptoPkg/OpensslLib AARCH64: clear XIP CC flags
    + BaseTools/tools_def AARCH64: avoid SIMD registers in XIP code
    + BaseTools/tools_def AARCH64: mark register x18 as reserved
    + BaseTools/Build: Support python scripts in PREBUILD/POSTBUILD
    + UefiCpuPkg CpuCommonFeaturesLib: Fix smx/vmx enable logic
    + UefiCpuPkg RegisterCpuFeaturesLib: Add error handling code.
    + OvmfPkg/QemuFwCfgLib: Suppress GCC49 IA32 build failure
    + MdePkg: Declare _ReturnAddress() in Base.h for MSFT tool chain
    + OvmfPkg: update PciHostBridgeDxe to use PlatformHasIoMmuLib
    + OvmfPkg/QemuFwCfgLib: Add SEV support
    + OvmfPkg: Add IoMmuDxe driver
    + OvmfPkg: Add PlatformHasIoMmuLib
    + OvmfPkg: Add AmdSevDxe driver
    + OvmfPkg/PlatformPei: Set memory encryption PCD when SEV is
    + OvmfPkg/BaseMemcryptSevLib: Add SEV helper library
    + OvmfPkg: Update dsc to use IoLib from BaseIoLibIntrinsicSev.inf
    + OvmfPkg/ResetVector: Set C-bit when building initial page table
    + MdeModulePkg/XhciDxe: Make comments align with function
    + MdeModulePkg/PartitionDxe: Add impl of Partition Information
    + MdePkg: Add EFI Partition Information Protocol definitions
    + BaseTools: Report Fd File Path in build log
    + BaseTools: Fix FDF file parse !include file issue
    + BaseTools: Add PCDs conditional operator function
    + BaseTools/Eot: register MM Module types with FFS class.
    + BaseTools/Workspace: check MM module type compatibility with
      PI version.
    + BaseTools/build: register MM module types with build tools.
    + BaseTools/GenFds: register MM Modules and MM FV file types.
    + BaseTools/CommonDataClass: register MM Modules.
    + BaseTools/Common: add support in FDF Parser to parse MM
    + BaseTools/Common: add MM Module data types.
    + BaseTools/AutoGen: auto generate MM template APIs and
    + BaseTools/GenFw: recognize MM file types as EFI Boot Service
    + BaseTools/GenFfs: add FFS file types for MM modules.
    + UefiCpuPkg MpInitLib: Update return status to follow spec.
    + UefiCpuPkg CpuMpPei: Update return status to follow spec.
    + UefiCpuPkg CpuDxe: Update return status to follow spec.
    + MdePkg MpServices: Update return status to follow spec.
    + BaseTools/GenFw: disregard payload in PE debug directory entry
    + MdeModulePkg/NvmExpressDxe: Handle timeout for blocking
      PassThru req
    + OvmfPkg: mention the extended TSEG near the PcdQ35TsegMbytes
    + OvmfPkg/PlatformPei: honor extended TSEG in PcdQ35TsegMbytes
      if available
    + OvmfPkg/SmmAccess: support extended TSEG size
    + OvmfPkg/IndustryStandard/Q35MchIch9.h: add extended TSEG size
    + OvmfPkg: make PcdQ35TsegMbytes dynamic
    + OvmfPkg/SmmAccess: prepare for PcdQ35TsegMbytes becoming dynamic
    + OvmfPkg/PlatformPei: prepare for PcdQ35TsegMbytes becoming dynamic
    + OvmfPkg: widen PcdQ35TsegMbytes to UINT16
    + OvmfPkg: update -D E1000_ENABLE from Intel PROEFI v.07 to
      BootUtil v.22
    + OvmfPkg: disable build-time relocation for DXEFV modules
    + ArmVirtPkg: remove status code support
    + ArmPlatformPkg: convert VExpress ResetSystemLib to
    + MdeModulePkg/XhciDxe: Check timeout URB again after stopping
    + MdeModulePkg/XhciDxe: Separate common logic to XhcTransfer
    + MdeModulePkg/XhciDxe: Dump the CMD/EVENT/INT/BULK ring
    + MdeModulePkg/XhciDxe: Refine IsTransferRingTrb and
    + BaseTools: suppress usage instructions with rebuild options
    + ArmVirtPkg: switch to generic ResetSystemRuntimeDxe
    + ArmPkg: implement ResetSystemLib using PSCI 0.2 calls
    + MdeModulePkg CapsuleApp: Fix print info in BuildGatherList()
    + MdeModulePkg ResetSystem: Update the comments of ResetSystem()
    + MdeModulePkg/ResetSystem: Implement ResetNotification protocol
    + MdeModulePkg/ResetSystem: Remove unnecessary global variable
    + MdePkg: Add ResetNotification protocol definition
    + MdeModulePkg PeiCore: Correct the comments of PeiResetSystem2
    + MdePkg: Correct the comments of EFI_PEI_RESET2_SYSTEM
    + ShellPkg: Update dh command to reflect correct driver field
    + MdeModulePkg/AtaAtapiPassThru: relax PHY detect timeout
    + MdePkg/IndustryStandard: update ACPI/IORT definitions to
      revision C
    + ShellPkg DmpStore: Make NameSize to be consistent with name
    + MdeModulePkg/BdsDxe: Report Status Code when booting from
      BootOrder list
    + MdePkg/PiStatusCode: Add new Status Code for BDS when
      attempting BootOrder
    + Revert "MdeModulePkg/DxeCore: Fixed Interface returned by
    + UefiCpuPkg: Modify GetProcessorLocationByApicId() to support
    + UefiCpuPkg: Add CPUID definitions for AMD.
    + UefiCpuPkg: Define AMD Memory Encryption specific CPUID and MSR
    + MdeModulePkg DxeCore: Only free ScratchBuffer when it is not
    + MdeModulePkg/DxeCore: Fixed Interface returned by
    + BaseTools/ Add warning info for new binary files
    + BaseTools/ Fix misreport for binary changes in
    + BaseTools: support building the same INF more than once with
    - m option
    + BaseTools: report error HiiString in HII format PCD must not
      be empty
    + BaseTools: Fix the bug that use '|' or '||' in DSC file's Pcd
    + BaseTools: Enhance the report to not show the empty section
    + BaseTools: Enhance DEC Defines section format check
    + BaseTools: Copy "TianoCore" userextensions into As Built Inf
    + BaseTools: Copy "MODULE_UNI_FILE" file into OUTPUT directory
    + MdePkg/Cper.h: Update Firmware Error Record per UEFI 2.7
    + MdeModulePkg: Enhance the debug message for
    + MdePkg: update Base.h in MdePkg to check the _MSC_VER
    + BaseTools: add /Gw to CC_FLAGS for VS2013 and higher tool
      chain tags
    + NetworkPkg: Fix GCC build issue.
    + BaseTools/tools_def: AARCH64: disable LTO type mismatch
    + BaseTools/tools_def GCC: ARM/AARCH64: drop -save-temps from
      command line
    + MdeModulePkg Variable: Add missing change in dd59d95e1994
    + MdeModulePkg: Minor update to the Data parameter for PEI
    + MdePkg: Minor update to the Data parameter for PEI
    + NetworkPkg/HttpBootDxe: Add HTTP Boot Callback protocol
    + MdePkg: Add header file for HTTP Boot Callback protocol
      in UEFI 2.7.
    + MdeModulePkg: Return invalid param in LocateProtocol for
    + MdePkg: Add EFI UFS Device Config Protocol definitions
    + MdeModulePkg: Fix use-after-free error in
    + MdeModulePkg: Clean ACPI 2.0 characters in UEFI spec
    + MdePkg: Clean ACPI 2.0 characters in UEFI spec
    + UefiCpuPkg/SmmCpuFeatureLib: Add more CPU ID for
    + ShellBinPkg: Ia32/X64 Shell binary update.
    + MdeModulePkg/BMMUiLib: Fix incorrect variable name
    + SecurityPkg TcgDxe: Simplify debug msg when "TPM not working
    + ShellPkg: Fix typo errors in ifconfig help output
    + Shell/alias: Print detailed error when deleting alias
    + OvmfPkg/AcpiPlatformDxe: fix spurious uninitialized var warning
    + NetworkPkg/HttpBootDxe: Handle new #define in HttpBootDxe
    + MdeModulePkg/DxeHttpLib: Handle new #define in
    + MdePkg/Http.h: Add #define for 308 redirect
    + ShellPkg/ifconfig: Update help message
    + MdeModulePkg/PciHostBridgeDxe: Make bitwise operands of the
      same size
    + OvmfPkg/AcpiPlatformDxe: alloc blobs from 64-bit space unless
    + BaseTools: Fix the bug use same FMP_PAYLOAD in different
      capsule file
    + BaseTools: Fix incremental build failure that override file be
    + ShellBinPkg: Ia32/X64 Shell binary update.
    + ShellPkg/parse: Handle Unicode stream from pipe correctly
    + ShellPkg/alias: Return status for alias deletion
    + MdePkg SmmIoLib: Use NULL pointer check instead of useless
      Status check
    + MdePkg SmmMemLib: Remove ASSERT in SmmIsBufferOutsideSmmValid
    + MdeModulePkg/UefiPxeBcDxe: Refine the PXE boot displayed
    + MdeModulePkg/UefiPxeBcDxe: Fix the PXE BootMenu selection issue
  - Build x86_64 4MB images since upstream switched to 4MB by for a
    larger space for variables. Also update README to reflect the
  - Remove License-fat-driver.txt since FatPkg uses the same license
    as the root license.
  - Add the OVMF license file
  - Disable the PIE/PIC warning for the debug files since all object
    files will be converted to PE/COFF, so it's pointless to enable
  - Remove Default_DB_EX and Default_DBX correctly
* Mon Jun 05 2017
  - Update to 2017+git1496630893.7ec69844b8
    + ShellPkg/alias: Fix bug to support upper-case alias
    + BaseTools/GCC ARM/AARCH64: Force disable PIE
    + BaseTools/Scripts: discard .gnu.hash section in GCC builds
    + OvmfPkg: make the 4MB flash size the default
    + MdeModulePkg/BDS: Fix a buffer overflow bug
    + CryptoPkg/BaseCryptLib: Add NULL pointer checks in DH and P7Verify
    + UefiCpuPkg/BaseUefiCpuLib: Use NASM read-only data section name
    + OvmfPkg/PlatformPei: align EmuVariableNvStore at any page boundary
    + OvmfPkg/EmuVariableFvbRuntimeDxe: change block size to 4KB
    + OvmfPkg/EmuVariableFvbRuntimeDxe: correct NumOfLba vararg type
      in EraseBlocks()
    + ArmPlatformPkg/NorFlashDxe: correct NumOfLba vararg type in
    + OvmfPkg/EmuVariableFvbRuntimeDxe: always format an auth
      varstore header
    + MdeModulePkg/PciBus: Add IOMMU support
    + MdeModulePkg/PciHostBridge: Add IOMMU support
    + MdeModulePkg/Include: Add IOMMU protocol definition
    + ShellPkg/HandleParsingLib: Show LoadedImageProtocol file path
      as text
    + NetworkPkg: Fix issue in dns driver when building DHCP packet
    + Addressing TCP Window Retraction when window scale factor is used
    + Add wnd scale check before shrinking window
    + UefiCpuPkg/MtrrLib: Don't report OutOfResource when MTRR is enough
    + MdePkg DxeServicesLib: Handle potential NULL FvHandle
    + OvmfPkg/PlatformPei: handle non-power-of-two spare size for
      emu variables
    + SecurityPkg/Pkcs7VerifyDxe: Add format check in DB list contents
    + OvmfPkg: raise max variable size (auth & non-auth) to 33KB for
    + OvmfPkg: introduce 4MB flash image (mainly) for Windows HCK
    + OvmfPkg/ extract VARS_LIVE_SIZE and
      VARS_SPARE_SIZE macros
    + OvmfPkg: introduce the FD_SIZE_IN_KB macro / build flag
    + ArmVirtPkg: install EdkiiPlatformHasDeviceTree proto in the
      32-bit builds
    + NetworkPkg: Fix PXEv6 boot failure when DhcpBinl offer received
    + NetworkPkg: Fix bug in iSCSI mode ipv6 when enabling target DHCP
    + Fix issue the iSCSI client can not send reset packet
    + CryptoPkg/SmmCryptLib: Enable HMAC-SHA256 support for SMM
    + ShellPkg/Shell: eliminate double-free in RunSplitCommand()
    + ShellPkg/Shell: clean up bogus member types in SPLIT_LIST
    + MdeModulePKg/BDS: Build meaningful description for Wi-Fi boot
    + MdeModulePkg/DeviceManagerUiLib: Fix the network device MAC
      display issue
    + MdeModulePkg/Mtftp4Dxe: Add invalid ServerIp check during MTFTP
    + NetworkPkg/TlsAuthConfigDxe: Close and free the file related
    + NetworkPkg: Correct the proxy DHCP offer handing
    + NetworkPkg/HttpDxe: Fix HTTP download OS image over 4G size
    + MdeModulePkg/UefiBootManagerLib: Avoid buggy USB short-form
    + NetworkPkg: Fix bug related DAD issue in IP6 driver
    + NetworkPkg: Add check logic for iSCSI driver
    + MdeModulePkg PiSmmCore: Enhance SMM FreePool to catch buffer
    + UefiCpuPkg/PiSmmCpuDxeSmm: Lock should be acquired
    + MdeModulePkg/BootManagerMenu: Add assertion to indicate no DIV
      by 0
    + CryptoPkg: Correct some minor issues in function comments
    + MdePkg/UefiLib: Avoid mis-calculate of graphic console size
    + MdeModulePkg/PiSmmCore: Fix potentially uninitialized local
    + MdeModulePkg DxeCore: Fix issue to print GUID value %g without
    + ArmVirtPkg/ArmVirtXen: remove ARM BdsLib library class resolution
  - Add ovmf-disable-ia32-firmware-piepic.patch to disable pic/pie
    explicitly since gcc7 in Factory enables pic/pie by default but
    GenFw cannot handle the GOT sections and failed the build.
* Sat May 06 2017
  - ovmf-pie.patch: add -fPIE to the Common build Makefile to
    allow a global PIE build.
* Thu Apr 13 2017
  - Update to 2017+git1492060560.b6d11d7c46 (fate#322331, bsc#1032659)
    + MdePkg: BaseIoLibIntrinsic (IoLib class) library
    + MdeModulePkg/IdeBusPei: Fix undefined behavior in signed left
    + MdeModulePkg/ScsiDiskDxe: Fix undefined behavior in signed left
    + OvmfPkg/QemuVideoDxe: VMWare SVGA device support
    + MdeModulePkg/UefiBootManagerLib: Enhance short-form expanding
    + CryptoPkg/BaseCryptLib: Adding NULL checking in time() wrapper
    + CryptoPkg: Fix possible unresolved external symbol issue.
    + CryptoPkg/OpensslLib: Suppress extra build warnings in openssl
    + CryptoPkg: Move openssl and CRT headers to private include
    + BaseTools: Update tools_def.template to add -fno-builtin in GCC
      tool chain
    + SecurityPkg: SecureBootConfigDxe: Support AUTH_2 enrollment to
    + MdeModulePkg/UefiHiiLib:Fix incorrect comparison expression
    + ArmVirtPkg/ArmVirtQemuKernel: increase slack space for DTB
    + ArmVirtPkg/FdtClientDxe: honor memory DT node 'status' property
    + NetworkPkg: Fix some bugs related to iSCSI keyword configuration
    + MdeModulePkg/DxeHttpLib: Avoid the pointless comparison of
      UINTN with zero
    + BaseTools: Enhance expression to support some more operation
    + MdePkg/Shell.h: Update Shell version from 2.1 to 2.2
    + UefiCpuPkg/PiSmmCpuDxeSmm: Update saved SMM ranges check in
    + ArmVirtPkg/PlatformHasAcpiDtDxe: allow guest level ACPI disable
    + BaseTools/GCC AARCH64: force disable PIC code generation
    + UefiCpuPkg/MtrrLib: Use a better algorithm to calculate MTRR
    + MdeModulePkg/SmmCore: Fix memory leak on Profile unregistered
    + OvmfPkg: Allow multiple add-pointer linker commands to same
      ACPI table
  - Drop upstream patch: ovmf-bsc1031336-fix-hii-gcc7-build.patch
* Wed Apr 05 2017
  - Add ovmf-bsc1031336-fix-hii-gcc7-build.patch to fix gcc7 build
* Thu Mar 30 2017
  - Update to 2017+git1490844769.d3017dd96b
    + MdeModulePkg/DxeHttpLib: Fix the incorrect return status if URI
      port is invalid
    + NetworkPkg/DnsDxe: Fix zero StationIp configuration failure of
    + CryptoPkg: Clean-up CRT Library Wrapper
    + CryptoPkg: Fix handling of &strcmp function pointers
    + CryptoPkg/OpensslLib: Update INF files to support OpenSSL-1.1.0x
    + ArmVirtPkg/PlatformHasAcpiDtDxe: don't expose DT if QEMU
      provides ACPI
    + ArmVirtPkg: enable AcpiTableDxe and EFI_ACPI_TABLE_PROTOCOL
    + ArmVirtPkg: add XenPlatformHasAcpiDtDxe
    + ArmVirtPkg: add PlatformHasAcpiDtDxe
    + UefiCpuPkg/AcpiCpuData.h: Support >4GB MMIO address
    + NetworkPkg/IScsiDxe: Fix the incorrect error handling in
    + Fix potential ASSERT if NetIp4IsUnicast is called
    + ArmPkg/PlatformBootManagerLib: move to BootLogoLib for boot
      splash support
    + UefiCpuPkg: Add CPU Features PEI/DXE drivers
    + ArmVirtPkg/HighMemDxe: use CPU arch protocol to apply memprotect
    + MdeModulePkg/BootGraphicsResourceTableDxe: don't allocate below
      4 GB
    + MdeModulePkg/DxeCore: deal with allocations spanning several
      memmap entries
    + MdeModulePkg/AcpiTableDxe: Not make FADT.{DSDT,X_DSDT} mutual
    + NetworkPkg: Fix service binding issue in TCP dxe
    + MdeModulePkg: Fix service binding issue in TCP4 and Ip4 dxe
    + MdeModulePkg: Fix bug in DxeHttplib when converting port number
    + MdeModulePkg/Ip4Dxe: Add Ip/Netmask pair check for Ip4Config2
    + ArmPkg/UncachedMemoryAllocationLib: set XP bit via CPU arch
    + MdeModulePkg DxeCore: Remove unreferenced symbol for memory
    + MdeModulePkg PiSmmCore: Remove unreferenced symbol for SMRAM
    + NetworkPkg: Fix potential bug if the iSCSI use dns protocol
    + MdePkg/UefiDevicePathLib: Fix the wrong MAC address length
    + OvmfPkg/AcpiPlatformDxe: save fw_cfg boot script with QemuFwCfgS3Lib
    + ArmVirtPkg, OvmfPkg: retire QemuFwCfgS3Enabled() from QemuFwCfgLib
    + OvmfPkg: resolve QemuFwCfgS3Lib
    + ArmVirtPkg: resolve QemuFwCfgS3Lib
    + OvmfPkg/QemuFwCfgS3Lib: add initial PEI and DXE fw_cfg library
    + OvmfPkg: introduce QemuFwCfgS3Lib class
    + MdeModulePkg/SmmCore: Add Context in SmiHandlerProfileUnregister
    + MdeModulePkg/UefiBootManagerLib: Generate boot description for
    + ArmVirtPkg/ArmVirtPL031FdtClientLib: unconditionally disable DT
    + ArmVirtPkg/FdtClientDxe: supplement missing EFIAPI calling conv
    + MdeModulePkg/AcpiTableDxe: improve FADT.{DSDT,X_DSDT} mutual
    + ArmPkg/CpuDxe: handle implied attributes in EfiAttributeToArmAttribute
    + ArmVirtPkg: apply PE/COFF memory protection to DxeCore as well
    + ArmPkg/UncachedMemoryAllocationLib: map uncached allocations
    + ArmPkg/UncachedMemoryAllocationLib: use CWG value to align pool
    + ArmPkg/UncachedMemoryAllocationLib: restore mapping attributes
      after free
  - Update openssl to 1.1.0e
* Wed Mar 08 2017
  - Update to 2017+git1488934948.29e9bf10dc
    + ArmVirtPkg: enable non-executable DXE stack for all platforms
    + ArmVirtPkg: enable PE/COFF image and memory protection for ARM
    + ArmPkg/CpuDxe ARM: honour RO/XP attributes in SetMemoryAttributes()
    + ArmPkg/CpuDxe ARM: avoid unnecessary cache/TLB maintenance
    + ArmPkg/CpuDxe ARM: avoid splitting page table sections
    + Refine casting expression result to bigger size
    + NetworkPkg/Dhcp6Dxe: Handle the Nil UUID case
    + ArmVirtPkg AARCH64: enable NX memory protection for all platforms
    + ArmVirtPkg/HighMemDxe: preserve non-exec permissions on newly
      added regions
    + SecurityPkg: Fix potential bug in Security Boot dxe
    + MdeModulePkg/EbcDxe: use EfiBootServicesCode memory for thunks
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2k
    + ArmVirtPkg: clear PcdPerformanceLibraryPropertyMask PCD
    + Ignore duplicated DNS address check
    + MdeModulePkg/DxeCore: base code protection on permission
    + OvmfPkg: exclude libssl functionality from OpensslLib if
    + CryptoPkg/OpensslLib: introduce OpensslLibCrypto instance
    + ArmVirtPkg/ AARCH64: enable DXE image
      protection feature
    + OvmfPkg/XenBusDxe: Use EFIAPI for XenStoreVSPrint
    + Update the Ethernet interface name
    + NetworkPkg:Add scriptable configuration to iSCSI driver by
      leveraging x-UEFI
    + ArmPkg/ArmMmuLib: AARCH64: enable stack alignment checking
    + ArmPlatformPkg/ArmPlatformStackLib: use callee preserved
    + MdeModulePkg/DxeCore: Add UEFI image protection
    + UefiCpuPkg/CpuDxe: Add memory attribute setting
    + OvmfPkg/QemuFwCfg: introduce FW_CFG_IO_SELECTOR, FW_CFG_IO_DATA,
    + UefiCpuPkg/ExceptionHandlerAsm.S: Fix code length issue with
      GCC 5.4
    + ArmPkg/ArmMmuLib: AARCH64: add support for modifying only
    + ArmPkg/CpuDxe: ARM: ignore page table updates that only change
    + ArmPkg/CpuDxe: translate invalid memory types in
    + ArmPkg/CpuDxe: Correct EFI_MEMORY_RO usage
    + OvmfPkg/AcpiPlatformDxe: implement the QEMU_LOADER_WRITE_POINTER
    + MdeMoudlePkg/DisplayEngine: Fix incorrect index used in array
    + MdeModulePkg: Add the EFI_PRINT2S_PROTOCOL
    + MdePkg/BasePrintLib: Add safe print functions [A|U]ValueToStringS
    + Refine the SPrint functions
    + SecurityPkg: enhance secure boot Config Dxe & Time Based
    + Generate the correct operational state of the interface
    + NetworkPkg/HttpBootDxe: Update to check specified media type
    + NetworkPkg/HttpBootDxe: Request HTTP token notify as a DPC at
    + NetworkPkg/iSCSIDxe: Update the condition for IScsiStart Abort
    + MdePkg ACPI: Incorrect definition name for ACPI IORT Table
    + MdeModulePkg/PciBus: Accept Spec values as BarIndex and
    + NetworkPkg/NetworkPkg.uni: Define the prompt and help
      information for PcdAllowHttpConnections
    + MdeModulePkg/DxeHttpLib: Correct the return status for the
      HTTP Port/ContentLength
    + MdeModulePkg/UefiBootManagerLib: Initialize Handle before
      using it
    + OvmfPkg/SmmControl2Dxe: select broadcast SMI if available
    + OvmfPkg: dynamic defaults for PcdCpuSmmApSyncTimeout,
    + ArmVirtPkg/QemuFwCfgLib: implement QemuFwCfgSkipBytes() API
    + ArmVirtPkg/QemuFwCfgLib: use DMA for QemuFwCfgWriteBytes() if
    + ArmVirtPkg/QemuFwCfgLib: extract generic DmaTransferBytes()
    + OvmfPkg/QemuFwCfgLib: add QemuFwCfgSkipBytes()
    + OvmfPkg/QemuFwCfgLib: generalize InternalQemuFwCfgDmaBytes()
      to SKIP op
    + SecurityPkg: Tcg2Dxe: Update PCR[4] measure logic
    + MdePkg: Add definitions for SMBIOS spec 3.1.1
    + OvmfPkg/QemuVideoDxe: Frame buffer config size may change in
      new mode
  - Update openssl to 1.0.2k
* Tue Jan 24 2017
  - update to 2017+git1485224553.6671cd7444
    + NetworkPkg: Fix protocol handler service in HttpDxe
    + OvmfPkg: Allow HTTP connections if HTTP Boot enabled
    + NetworkPkg: Add PCD to enable the HTTP connections switch
    + MdePkg: Add definitions for SMBIOS spec 3.1.0
    + ArmPlatformPkg/NorFlashDxe: Change Flash memory attributes
      before writes
    + MdePkg DxeHobLib: Make GetHobList working before Constructor
      is called
    + NetworkPkg: Add dns support for target URL configuration in
    + MdeModulePkg/FileExplorer: Enable functionality of creating
      new file/folder
    + OvmfPkg: pull in TLS modules with -D TLS_ENABLE (also enabling
    + OvmfPkg: correct the IScsiDxe module included for the IPv6 stack
    + OvmfPkg: always resolve OpenSslLib, IntrinsicLib and
    + OvmfPkg: Modify QemuFwCfgLib to use new IoLib class library
    + OvmgPkg/PlatformBootManagerLib: Add Debug Agent console
    + OvmfPkg/SmmControl2Dxe: correct PCI_CONFIG_READ_WRITE in S3
      boot script
    + OvmfPkg: Install BGRT ACPI table
    + MdeModulePkg/Bds: Fix a bug that may causes S4 fails to resume
    + MdePkg, MdeModulePkg: S3BootScriptSaveMemPoll(): accept 64-bit
    + NetworkPkg/HttpDxe: Fix the potential NULL dereference
    + NetworkPkg/HttpDxe: HTTPS support over IPv4 and IPv6
    + NetworkPkg/TlsAuthConfigDxe: Provide the UI to support TLS
      auth configuration
    + NetworkPkg/TlsDxe: TlsDxe driver implementation over OpenSSL
    + MdePkg: Add TLS related protocol definition
    + MdePkg/MemoryLib: Refine InternalMemSetMem16|32|64 functions
    + NetworkPkg: Replace ASSERT with error return code in PXE and
      HTTP boot driver
    + MdeModulePkg: Replace ASSERT with error return code in PXE
    + UefiCpuPkg/Cpuid.h: Update CPUID definitions with SDM (Sep.2016)
    + UefiCpuPkg/Include: Update MSR header files with SDM (Sep.2016)
    + UefiCpuPkg/PiSmmCpuDxeSmm: Always initialze PSD
    + MdeModulePkg/PiSmmCore: MemoryAttributeTable need keep non-PE
    + MdeModulePkg/PiSmmCore: AllocatePool should use MemoryType
    + OvmfPkg/XenHypercallLib: Add EFIAPI
    + OvmfPkg/QemuFwCfgLib: support QEMU's DMA-like fw_cfg access
    + ArmVirtPkg/QemuFwCfgLib: rebase lib instance to updated lib
      class header
    + OvmfPkg/QemuFwCfgLib: extend lib class header with more
    + ArmVirtPkg, OvmfPkg: QemuFwCfgLib: move DMA-related defs to lib
    + OvmfPkg/QemuFwCfgLib: move InternalQemuFwCfgIsAvailable() to
      lib instances
    + ArmVirtPkg/QemuFwCfgLib: remove superfluous InternalQemuFwCfgIsAvailable()
    + OvmfPkg: Remove use of IntelFrameworkModulePkg legacy libs
    + UefiCpuPkg/PiSmmCpuDxeSmm: Remove MTRRs from PSD structure
    + UefiCpuPkg/PiSmmCpuDxeSmm: Clear some semaphores on S3 boot
    + ArmPkg/ArmDmaLib: add support for fixed host-to-device DMA
    + ArmPkg/ArmDmaLib: clean up abuse of device address
    + ArmPkg/ArmDmaLib: fix incorrect device address of double buffer
    + ArmPkg/ArmDmaLib: use DMA buffer alignment from CPU arch
    + ArmPkg/ArmMmuLib: support page tables in cacheable memory only
    + UefiCpuPkg/PiSmmCpu: relax superpage protection on page split
    + OvmfPkg/PlatformPei: take VCPU count from QEMU and configure
    + UefiCpuPkg/MpInitLib: wait no longer than necessary for initial
      AP startup
  - Enable TLS support by default (for HTTPS)
* Tue Nov 29 2016
  - update to 2017+git1480394913.2b2efe3:
    + UefiCpuPkg/PiSmmCpuDxeSmm: handle dynamic
    + SecurityPkg Tcg2ConfigDxe: Align Attempt TPM Device help with
    + SecurityPkg Tcg2ConfigDxe: Remove BlockSID actions and related
    + SecurityPkg OpalPasswordDxe: Use PP actions to enable BlockSID
    + SecurityPkg Tcg2PPLib: Support BlockSID related actions
    + MdeModulePkg/NetLib: Handle an invalid IPv6 address case
    + UefiCpuPkg/DxeMpLib: Fix bug when getting target C-State from
    + UefiCpuPkg/DxeMpLib: Make sure APs in safe loop code
    + UefiCpuPkg/DxeMpLib: Allocate new safe stack < 4GB
    + UefiCpuPkg/DxeMpLib: Get safe AP loop handler from global
    + ArmPlatformPkg: Fix VE RTSM mem map descriptor count
    + ArmPlatformPkg: Reformat VE Memory Map code
    + ArmPkg: remove the LinuxLoader application
    + MdeModulePkg/SetupBrowser:Don't support password without
      interactive flag
    + MdeModulePkg/DisplayEngine: Popup dialogue when password is
      not supported
    + MdeModulePkg/AtaAtapiPassThru: Ensure GHC.AE bit is always set
      in Ahci
    + MdeModulePkg/Xhci: Add 10ms delay before sending SendAddr cmd
      to dev
    + UefiCpuPkg/PiSmmCpu: Correct exception message
    + UefiCpuPkg: fix feature test for Extended Topology CPUID leaf
    + SecurityPkg DxeTcg2PPLib: Lock Tcg2PhysicalPresenceFlags
      variable on S4
    + MdeModulePkg/DxeNetLib: Allow the IPv4/prefix case when
    + ShellPkg: update ping6 to use timer service instead of timer
      arch protocol
    + MdeModulePkg/DisplayEngine: Return the selectable menu
    + SecurityPkg Tcg2Dxe: ASSERT to ensure 'VarData' is not NULL
    + SecurityPkg TcgStorageCoreLib: ASSERT to ensure 'ByteSeq' is
      not NULL
    + UefiCpuPkg/PiSmmCpuDxeSmm: dynamic PcdCpuSmmApSyncTimeout,
    + MdeModulePkg/PiSmmCore: Cache CommunicationBuffer info before
      using it
    + Check for the max DHCP packet length before use it
    + OvmfPkg: Add 4K PE alignment to enable SMM page level
    + UefiCpuPkg/PiSmmCpu: Check XdSupport before set NX
    + MdeModulePkg/BdsDxe: Avoid overwriting PlatformRecovery####
    + MdeModulePkg/BdsDxe: Fix bug to run non-first
    + PcAtChipsetPkg/PcRtc: Handle NULL table entry in RSDT/XSDT
    + UefiCpuPkg/SecCore: Correct print format for stack information
    + MdeModulePkg/PiSmmCpuDxeSmm: Check RegisterCpuInterruptHandler
    + MdeModulePkg/CpuExceptionHanderLibNull:
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add volatile to mNumberToFinish
    + UefiCpuPkg/PiSmmCpuDxeSmm: TransferApToSafeState() use UINTN
    + MdePkg/BaseSynchronizationLib: Fix function names in function
    + MdePkg/BaseSynchronizationLib: Add volatile Interlocked*() APIs
    + MdePkg/Include: Add volatile to SynchronizationLib parameters
    + UefiCpuPkg/MpInitLib: support 64-bit AP stack addresses
    + UefiCpuPkg/MpInitLib/X64/MpFuncs.nasm: fix fatal typo
    + UefiCpuPkg/MpInitLib/X64/MpFuncs.nasm: remove superfluous
    + UefiCpuPkg/DxeMpInitLib: remove duplicate HobLib class
    + MdeModulePkg/Include: Add PiSmmMemoryAttributesTable.h
    + MdeModulePkg HiiDatabase: Remove extra memory initialization
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add paging protection
    + UefiCpuPkg/dec: Add PcdCpuSmmStaticPageTable
    + MdeModulePkg/PiSmmCore: Add MemoryAttributes support
    + ArmVirtPkg DxeHobLib: Update func header description of
    + IntelFrameworkPkg PeiHobLib: Check FV alignment when building
      FV HOB
    + MdePkg HobLib: Check FV alignment when building FV HOB
    + MdeModulePkg DxeCore: Show error message on unaligned FvImage
    + MdeModulePkg/Ip4Dxe: Correct the return status
    + MdeModulePkg/Ip4Dxe: Add wrong/invalid subnet check
    + OvmfPkg AcpiTables: Use PcdDebugIoPort to describe QEMU debug
    + MdePkg/BaseLib: Add one wrapper on RdRand access for parameter
    + UefiCpuPkg/MpInitLib: Update AP information when BSP switched
    + UefiCpuPkg/MpInitLib: Program AP stack in fixed address
    + UefiCpuPkg/MpInitLib: Add InitFlag and CpuInfo in
    + UefiCpuPkg/MpInitLib: Remove CPU information from CPU_AP_DATA
    + UefiCpuPkg/MpInitLib: Force sending INIT-SIPI-SIPI to reset APs
    + UefiCpuPkg/MpInitLib: Fixed offset error on Cr3Location
    + UefiCpuPkg/PiSmmCpuDxeSmm: Free SmramRanges to save SMM space
    + ShellPkg/dmpstore: Support "-sfo"
    + ArmPkg/Library/ArmDmaLib: Deallocate Map buffer in case of
    + UefiCpuPkg/PiSmmCpuDxeSmm: Decrease mNumberToFinish in AP safe
    + UefiCpuPkg/PiSmmCpuDxeSmm: Place AP to 32bit protected mode on
      S3 path
    + UefiCpuPkg/PiSmmCpuDxeSmm: Put AP into safe hlt-loop code on S3
    + UefiCpuPkg/DxeMpLib: Place APs to suitable state on Legacy OS
    + UefiCpuPkg/DxeMpLib: Allocate below 4GB mem for
    + CryptoPkg/BaseCryptLib: Make comments consistent with the
    + OvmfPkg/PlatformBds: Dispatch deferred images after EndOfDxe
    + ArmVirPkg/PlatformBds: Dispatch deferred images after EndOfDxe
    + MdeModulePkg/BdsDxe: Check deferred images before booting to OS
    + UefiCpuPkg/MpInitLib: Do not wakeup AP if only one processor
    + BaseTools/EfiRom: Fix potential memory leak
    + OvmfPkg/ResetVector: Depend on PCD values of the page tables
    + CryptoPkg: Add HMAC-SHA256 cipher support
    + CryptoPkg: Add xxxxHashAll APIs to facilitate the digest
    + NetworkPkg: Fix the wrong Timer event check
    + NetworkPkg: Update IP4 stack drivers for classless address
      unicast check
    + PcAtChipsetPkg/HpetTimerDxe: Fix race condition in
    + OvmfPkg: Make more use of ARRAY_SIZE()
    + rebase to ARRAY_SIZE()
    + ArmPlatformPkg: remove ARM BDS
    + OvmfPkg/XenConsoleSerialPortLib: don't include
    + NetworkPkg: Support bracketed IPv6 address during a redirection
      in iSCSI
    + NetworkPkg: Enhance the code in DNS driver
    + NetworkPkg: Add dns support for pxe boot based on IPv6
    + disable deprecated interfaces
    + OvmfPkg/QemuVideoDxe: drop useless variables
    + ArmVirtPkg: undo bogus component name and driver diagnostics
    + NetworkPkg: Record user configured TargetIP/Port in iBFT
  - Use GCC5 in Tumbleweed
* Thu Oct 13 2016
  - update to 2017+git1476331065.08354c3:
    + OvmfPkg: add NOOPT build target for source level debugging
    + OvmfPkg: QemuVideoDxe uses MdeModulePkg/FrameBufferLib
    + BaseTools: support the NOOPT target with the GCC tool chains
    + BaseTools Makefile: Enable O2 option for GCC tool chain
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2j
    + MdeModulePkg/Logo: Add LogoDxe module
    + MdeModulePkg/HiiDatabase: Add HiiImageEx implementation
    + MdeModulePkg/PciBusDxe: make OPROM BAR degradation configurable
    + NetworkPkg: Correct the DNS token return status by RCODE
    + BaseTools/EfiRom: supply missing machine type lookup strings
    + ArmVirtPkg: restrict mapping attributes of normal memory to
    + OvmfPkg/QemuBootOrderLib: drop too strict "/HD(" suffix from
      vblk prefix (bsc#1009707)
    + NetworkPkg/DnsDxe: Handle CNAME type responded from the name
    + ArmVirtPkg/FdtPciHostBridgeLib: enable 64-bit PCI DMA
    + MdeModulePkg: Support classless IP for DHCPv4 TransmitReceive()
    + ArmVirtPkg: implement FdtPciHostBridgeLib
    + OvmfPkg: Use MdeModulePkg/ResetSystemRuntimeDxe
    + OvmfPkg/VirtioGpuDxe: implement EFI_GRAPHICS_OUTPUT_PROTOCOL
    + include VirtioGpuDxe in the platform DSC/FDF files
    + OvmfPkg/Virtio10Dxe: don't bind virtio-vga
    + OvmfPkg/QemuVideoDxe: don't incorrectly bind virtio-gpu-pci
    + BaseTools/GenFw: ignore dynamic RELA sections
    + Add implementations of API IsZeroBuffer()
    + ArmVirtPkg: Add Ramdisk support to ArmVirtPkg platforms
    + ArmVirtPkg: Move inclusion of AcpiTableDxe.inf to
  - Drop upstreamed ArmVirtPkg-Enable-PCI-bus-probing-again.patch
* Wed Sep 14 2016
  - update to 2017+git1472049752.ea2f21e:
    + switches git branch from an (outdated) master tree
    to the UDK2017 branch, which provides an insane amount of
    changes. for details please look at
  - unify build flags with aarch64 build for increased compatibility with
    openSUSE installation medias
* Fri Aug 19 2016
  - Update to 2015+git1471575292.00bcb5c
    + NetworkPkg/IpSecDxe: Fix UEFI IKE Initial Exchange failure
    + MdeModulePkg: Fix potential failure if UseDefaultAddress
    + OvmfPkg: Add MpInitLib reference in DSC files
    + SecurityPkg: AuthVariableLib: Fix inconsistent CertDB case
    + OvmfPkg: use StatusCode Router and Handler from MdeModulePkg
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: deal with relaxed
      XIP alignment
    + BaseTools GCC: introduce GCC5 toolchain to support GCC v5.x in
      LTO mode
    + BaseTools GCC: use 'gcc' as the linker command for GCC44 and
    + ArmVirtPkg/ArmVirtPrePiUniCoreRelocatable: ignore .hash and
      .note sections
    + OvmfPkg/Sec: Support SECTION2 DXEFV types
    + Preserve hii section in GCC binaries
    + Fix IPv6 HTTPClient vendor class data
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2h
    + NetworkPkg: Fix bug in TCP which not sending out ACK in
      certain circumstance
    + OvmfPkg: include UefiCpuPkg/CpuMpPei
    + OvmfPkg/PlatformPei: rebase and resize the permanent PEI memory
      for S3
    + SecurityPkg SecureBootConfigDxe: Add check for the external
      PE/COFF image
    + ArmVirtPkg/PlatformBootManagerLib: remove stale FvFile boot
    + OvmfPkg/PlatformPei: add missing auto variable initialization
    + OvmfPkg: add PciHotPlugInitDxe
    + MdeModulePkg/PciBusDxe: recognize hotplug-capable PCIe ports
    + OvmfPkg/PlatformBootManagerLib: remove stale FvFile boot
    + OvmfPkg: add a Name GUID to each Firmware Volume
    + CryptoPkg BaseCryptLib: Init the content of struct 'CertCtx'
      before use
    + CryptoPkg BaseCryptLib: Avoid passing NULL ptr to function
    + MdeModulePkg/Bds: MemoryTypeInformation excludes boot option
      mem use
    + MdeModulePkg: Fix IPv4 stack potential disappeared issue
    + NetworkPkg: Stop the HTTP Boot service after the boot image
      download complete
    + ArmVirtPkg: Re-add the Driver Health Manager
    + OvmfPkg: Re-add the Driver Health Manager
    + ArmVirtPkg/ArmVirtXen: Add ACPI support for Virt Xen ARM
    + Massive conversion of assembly code to NASM
    + MdeModulePkg/UefiBootManagerLib: Fix data in
    + ArmVirtPkg: add FDF definition for empty varstore
    + ArmVirtPkg/ArmVirtQemu: switch secure boot build to NorFlashDxe
    + NetworkPkg: Handling timeout case in httpboot driver
    + NetworkPkg: HttpDxe response/cancel issue fix
    + NetworkPkg: Support TCP Cancel function
    + MdeModulePkg/RamDiskDxe: Add Memory Type selection support in
      Ramdisk HII
    + MdeModulePkg RamDiskDxe: Do not save 'Size' numeric value by
    + MdeModulePkg: Fix IPv4 UseDefaultAddress failure case
    + MdeModulePkg/AtaBusDxe: Fix some ATA hard drives cannot be
    + ArmVirtPkg/PlatformBootManagerLib: rebase boot logo display to
    + OvmfPkg: set SMM stack size to 16KB
    + OvmfPkg/PlatformBootManagerLib: Connect the Xen drivers before
      loading NvVars
    + MdeModulePkg: Fix SNP.Initialize() spec conformance issue
    + OvmfPkg: raise DXEFV size to 10 MB
    + MdeModulePkg: Stop the timer before clean IP service
    + OvmfPkg/PlatformBootManagerLib: rebase boot logo display to
    + OvmfPkg/SerializeVariablesLib: Relax check for the read-only
    + OvmfPkg: prevent 64-bit MMIO BAR degradation if there is no CSM
    + OvmfPkg, ArmVirtPkg: rename QemuNewBootOrderLib to
    + MdeModulePkg/PciBus: do not improperly degrade resource
    + NetworkPkg/HttpDxe: Don't free Wrap in HttpTcpReceiveNotifyDpc
    + NetworkPkg/TcpDxe: Remove the status check of
    + UefiCpuPkg/SmmCpuFeaturesLib: Add SMRR PhysBase/PhysMask
      fields check
    + MdeModulePkg: Skip invalid bus number scanning in PciBusDxe
    + OvmfPkg/PlatformPei: provide 10 * 4KB of PCI IO Port space on
    + OvmfPkg: introduce ICH9_PMBASE_VALUE
    + OvmfPkg: replace PcdAcpiPmBaseAddress with PIIX4_PMBA_VALUE
    + OvmfPkg/AcpiTimerLib: don't use possibly unset PMBA register
      (PEI phase)
    + MdeModulePkg: Refine the code for DxeHttpLib
    + OvmfPkg/XenBusDxe: duplicate twice-iterated VA_LIST in
    + SecurityPkg: Use PcdGet32() to access PcdPeiCoreMaxFvSupported
    + UefiCpuPkg/PiSmmCpuDxeSmm/SmmProfile: Fix BTS support check bug
    + NetworkPkg:HttpDxe: Code changes to support HTTP PUT/POST
    + CryptoPkg/SmmCryptLib: Enable AES support for SMM
    + MdePkg: Add NFIT definition from ACPI 6.1
    + BaseTools/GenFw: enhance to use Magic Field to identify the
    + MdeModulePkg-DxeCore: rename CoreGetMemoryMapPropertiesTable
    + MdeModulePkg Variable: return error for empty str VariableName
      to GetVariable
    + PcAtChipsetPkg AcpiTimerLib: Fix a logic error
    + MdeModulePkg UiApp: change code for easy customization
    + MdePkg: Add HII definitions from UEFI 2.6
    + NetworkPkg: Make HttpBootGetBootFile return
    + MdeModulePkg:DxeHttpLib: Add checks in HttpGenRequestMessage
    + ArmPkg/ArmLib: don't invalidate entire I-cache on range
    + OvmfPkg/PlatformBootManagerLib: Postpone the shell registration
    + OvmfPkg/QemuNewBootOrderLib: adapt Q35 SATA PMPN to UEFI spec
      Mantis 1353
    + MdeModulePkg Ata: Use the new (incompatible) PortMultiplierPort
    + NetworkPkg: Bug fix of iSCSI to support MPIO
  - Drop upstreamed patches
    + ovmf-dxe-10mb.patch
    + ovmf-bsc976253-postpone-shell.patch
    + ovmf-bsc980635-fix-http-crash.patch
    + ovmf-bsc982193-dont-restore-readonly-var.patch
    + ovmf-bsc982193-connect-xen-drivers.patch
    + ovmf-bsc990612-update-openssl-1.0.2h.patch
    + ovmf-bsc990773-remove-stale-boot-options.patch
  - Update since there are new hashes added into dbx
* Wed Jul 27 2016
  - Update openssl to 1.0.2h (bsc#990612)
    + Add the patch: ovmf-bsc990612-update-openssl-1.0.2h.patch
    + Update the openssl tarball
  - Add ovmf-bsc990773-remove-stale-boot-options.patch to remove the
    stale boot options (bsc#990773)
* Tue Jun 14 2016
  - Generate the varstore template for AArch64 (bsc#983747,
* Mon Jun 06 2016
  - Keep %prep minimal to shorten quilt setup run.
    Adjust RPM group. Drop redundant 4th defattr argument.
* Fri Jun 03 2016
  - Add ovmf-bsc982193-dont-restore-readonly-var.patch and
    ovmf-bsc982193-connect-xen-drivers.patch to fix the file-based
    NvVars restoring. (bsc#982193)
* Tue May 24 2016
  - Add the commands to remove irrelevant packages in %prep to make
    sure those source code will never build. (bsc#973038)
* Fri May 20 2016
  - Add ovmf-bsc980635-fix-http-crash.patch to fix the crash when
    downloading files from the http server (bsc#980635)
* Wed May 11 2016
  - Update to 2015+git1462940744.321151f
    + BaseTools: Fix bug in GenFds to handle FV image alignment
    + SecurityPkg: SecureBootConfigDxe: Add NULL pointer check
    + OvmfPkg/PciHostBridgeLib: Scan for root bridges when running
      over Xen
    + OvmfPkg/PciHostBridgeLib: Change InitRootBridge prototype
    + MdeModulePkg/PciHostBridgeDxe: Honor ResourceAssigned
    + OvmfPkg/PciHostBridgeLib: Set correct Base/Limit for absent
    + MdeModulePkg/PciHostBridgeDxe: Fix a Base/Limit comparing bug
    + MdeModulePkg/PciHostBridgeDxe: Don't miss prefetchable MMIO
    + ArmVirtPkg: set PcdMaxVariableSize and PcdMaxAuthVariableSize
    + ArmPkg/AArch64Mmu: don't let table entries inherit XN
      permission bits
    + ArmPkg/ArmDmaLib: do not remap arbitrary memory regions as
    + ArmPkg/ArmDmaLib: reject consistent DMA mappings of cached
    + MdeModulePkg/PciSioSerialDxe: Do not flush the UART
    + MdeModulePkg RamDiskDxe: Fix wrong HII behavior for more than 8
      RAM disks
    + OvmfPkg: Modify FDF/DSC files for RamDiskDxe's adding NFIT
      report feature
    + MdeModulePkg RamDiskDxe: Report ACPI NFIT for reserved memory
      RAM disks
    + ArmVirtPkg/ArmVirtQemu: use MdeModulePkg/BDS
    + Ignore BootFileName if it is overloaded (HTTP Boot/PXE)
    + NetworkPkg: Fix a memory leak in HTTP boot driver
    + NetworkPkg/HttpBootDxe: Fix for the issue that the HTTP boot
      option can't be booted more than once
    + deModulePkg NvmExpressDxe: Initialize IoAlign info for an NVMe
    + MdeModulePkg: Refine SNP driver's media status check logic
    + MdeModulePkg: ScsiDiskDxe: cope with broken "Supported VPD Pages"
      VPD page
    + MdeModulePkg FileExplorerLib: Add UefiHiiServicesLib dependency
    + SecurityPkg: SecureBootConfigDxe: Disable SecureBoot
      Enable/Disable in some case
    + Do not use hard coded TTL/ToS in PXE driver
    + NetworkPkg: Use UefiBootManagerLib API to create load option
    + Remove DeployedMode/AuditMode
    + OvmfPkg: Use MdeModulePkg/BDS
    + ArmPlatformPkg/PrePi: allow unicore version to be used on MP
    + ArmPkg: implement CpuIo2 protocol driver specific for PCI
    + ArmPlatformPkg: move PCI related PCD definitions to ArmPkg
    + MdeModulePkg/DxeCore: set ImageContext Handle and ImageRead()
    + MdeModulePkg/PciBusDxe: don't create bogus descriptor if no
      resources needed
    + MdeModulePkg: Add new driver to publish EDKII_PI_SMM_COMMUNICATION_REGION_TABLE
    + SecuritPkg: DxeImageVerificationLib: Fix wrong verification
      logic in DBX & DBT
    + UefiCpuPkg/MtrrLib: Reduce the loop time to get fixed-MTRR MSR
    + MdeModulePkg: PiDxeS3BootScriptLib: honor PcdAcpiS3Enable
    + NetworkPkg: Fix incorrect buffer free in HttpDxe
    + NetworkPkg: Avoid the indefinite wait case in HttpDxe
    + MdeModulePkg: DxeCore MemoryPool Algorithm Update
    + MdeModulePkg: Export ConfigResp only for form Package after
    + NetworkPkg:HttpDxe:Consume DxeHttpLib API changes
    + MdeModulePkg:DxeHttpLib: Update to DxeHttpLib API
    + NetworkPkg: Allow user to create a HTTP corporate boot option
      in setup page
    + MdePkg:Http11.h: Add defines for "Expect" header
    + BaseTools: Update FMP Capsule support to follow FDF spec
    + OvmfPkg: SataControllerDxe: SataControllerStop: fix use after
    + OvmfPkg: SataControllerDxe: SataControllerStop: remove useless
      null check
    + MdeModulePkg DxeCore: Check free memory type by CoreUpdateProfile()
    + MdeModulePkg/NvmExpress: Fix bug of handling not
      null-terminated strings
    + ShellPkg: Enahance 'dh' command to add more protocols decoding
    + MdeModulePkg/DxeCore: Avoid assertion in CoreLocateProtocol
    + MdeModulePkg: Correct PlatformHookLibSerialPortPpi module type
    + FatPkg: Update License.txt to have the full license text
    + refine codes of iSCSI driver
    + MdeModulePkg DxeCore: Enhance MemoryAttributesTable installation
    + MdeModulePkg DxeCore: Return memory type from internal free
    + MdeModulePkg DxeCore: Fix a memory leak in
    + MdeModulePkg DxeCore: Call PeCoffExtraActionLib member after
    + MdeModulePkg/Usb: Fix wrong condition judgment to support
      usb3.1 dev
    + MdeModulePkg/UsbKbDxe: don't assert when the key read is
    + BaseTools: Add mixed PCD support feature
    + OvmfPkg: AcpiPlatformDxe: Don't enable unsupported PCI
    + MdeModulePkg/HiiDatabaseDxe: Support EfiVarStore to get AltCfg
      from Driver
    + MdeModulePkg/HiiDatabaseDxe: Correct the ReallocatePool size
    + MdeModulePkg/SetupBrowserDxe: Get default from callback for
    + SecurityPkg: AuthVariableLib & SecureBootConfigDxe:
      Fix SecureBootEnable & PK inconsistency issue
    + ShellPkg: Update ping command options to sync with Spec
    + MdeModulePkg NvmExpressDxe: Ensure write-through for NVMe write
    + ShellPkg: Cache the environment variable into memory to enhance
      the performance.
    + BaseTools: Update to handle PE image with .code section only
    + ArmPkg/AArch64Mmu: disable MMU during page table manipulations
    + ArmPkg/AArch64Mmu: Fix XN attribute for device memory
    + NetworkPkg: Fix issue in Ip6Dxe SetData
  - The updated tarball includes the PCI host bridge fix for Xen
  - Add ovmf-dxe-10mb.patch to raise DXEFV to 10MB to avoid build
  - Add ovmf-bsc976253-postpone-shell.patch to postpone the creation
    of the shell boot option so that the firmware will try the block
    devices first. (bsc#976253)
  - Update README for Xen debugging.
* Thu Apr 21 2016
  - Add patch to enable PCI BAR probing on ARM again:
    * ArmVirtPkg-Enable-PCI-bus-probing-again.patch
* Fri Apr 15 2016
  - Change the fat driver license to the BSD license in FatPkg
    instead of the proprietary license in FatBinPkg since OvmfPkg and
    ArmVirtPkg now use FatPkg (bsc#973038)
* Thu Apr 14 2016
  - Update to 2015+git1460599637.f70cfe7
    + MdeModulePkg S3SaveStateDxe: Add protocol usage for gEfiLockBoxProtocolGuid
    + ArmVirtPkg/VirtFdtDxe: remove Xenio handling and rename to VirtioFdtDxe
    + ArmVirtPkg/ArmVirtXen: move from VirtFdtDxe to new XenioFdtDxe driver
    + OvmfPkg/XenIoMmioLib: add missing MemoryAllocationLib dependency to INF
    + ArmVirtPkg/VirtFdtDxe: move FDT config table installation to FdtClientDxe
    + ArmVirtPkg/VirtFdtDxe: remove unused PL011 DT node type
    + ArmVirtPkg: get rid of A PRIORI DXE declarations for VirtFdtDxe
    + ArmVirtPkg/VirtFdtDxe: drop RTC handling
    + ArmVirtPkg: move QEMU based platforms to ArmVirtPL031FdtClientLib
    + ArmVirtPkg: implement ArmVirtPL031FdtClientLib
    + ArmVirtPkg/RelocatableVirtHelper: use correct FindMemNode argument order
    + IntelFrameworkModulePkg: Remove unused PCD/Protocol
    + IntelFrameworkModulePkg/KeyboardDxe: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2Mouse: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2AbsPointer: Use PCD defined in MdeModulePkg
    + IntelFrameworkModulePkg/Ps2Kbd: use PCD/Protocol in MdeModulePkg
    + MdeModulePkg/MdeModulePkg.uni: Add PS2 related PCD description
    + MdeModulePkg/Ps2MouseDxe: Use a different FILE_GUID
    + MdeModulePkg/Ps2KeyboardDxe: Use a different FILE_GUID
    + MdeModulePkg/Ps2Mouse: Fix potential buffer overflow issue.
    + MdeModulePkg: Update Guid/Protocol usages in INF files.
    + ShellPkg: Update Guid/Protocol usages in INF files.
    + SecurityPkg: Update protocol usage in module INF files.
    + MdePkg: Add EFI Erase Block Protocol definitions
    + MdeModulePkg/Ps2MouseDxe: Fix build failure of GCC tool chain
    + ArmVirtPkg/VirtFdtDxe: drop PCI host bridge handling
    + ArmVirtPkg/PciHostBridgeDxe: move to FDT client protocol
    + ArmVirtPkg/BaseCachingPciExpressLib: depend on PciPcdProducerLib
    + ArmVirtPkg: implement FdtPciPcdProducerLib
    + ArmVirtPkg/VirtFdtDxe: remove handling of fw_cfg DT node
    + ArmVirtPkg/QemuFwCfgLib: move to FDT client protocol
    + BaseTools: use unsigned chars on ARM architectures
    + BaseTools: generate hash value in build report for each output EFI image
    + BaseTools/VolInfo: generate HASH value for each PE image
    + ArmVirtPkg/VirtFdtDxe: remove timer DT node handling
    + ArmVirtPkg: move TimerDxe to FDT client library
    + ArmVirtPkg: implement ArmVirtTimerFdtClientLib
    + ArmVirtPkg/VirtFdtDxe: drop detection of PSCI method
    + ArmVirtPkg/ArmVirtPsciResetSystemLib: move to FDT client protocol
    + ArmVirtPkg/VirtFdtDxe: remove GIC discovery
    + ArmVirtPkg/ArmGicArchLib: move to FdtClient protocol
    + ArmVirtPkg: add FdtClientDxe to the ArmVirtPkg platforms
    + ArmVirtPkg/FdtClientDxe: implement new driver
    + ArmVirtPkg: introduce FdtClientProtocol
    + UefiCpuPkg: CpuIo2Dxe: optimize FIFO reads and writes of IO ports
    + MdeModulePkg: Update PerformanceLib instances not to check Identifier.
    + MdePkg: Update PerformanceLib comments not to check Identifier.
    + Update edksetup.bat to check EDK_TOOLS_PATH before set it.
    + MdeModulePkg/Ps2Keyboard: Add missing PCD and protocol to DEC file
    + UefiCpuPkg/CpuMpPei: Fix potential AP mwait wakeup issue
    + NetworkPkg: Add RAM disk boot support to HTTP Boot driver.
    + ShellPkg: Fix Shell ASSERT when mv file with cwd is NULL.
    + MdeModulePkg BootScriptExecutorDxe: Consume PcdAcpiS3Enable to control the code
    + MdeModulePkg SmmS3SaveStateDxe: Consume PcdAcpiS3Enable to control the code
    + MdeModulePkg: Add new macros and refine codes
    + NetworkPkg: Add new macros and refine codes
    + MdeModulePkg: Add Ps2MouseDxe driver
    + MdeModulePkg: Add Ps2KeyboardDxe driver.
    + MdeModulePkg/UefiBootManagerLib: API BmIsValidLoadOptionVariableName
    + SecurityPkg OpalPasswordDxe: Clean up debug message in OpalHii.c
    + SecurityPkg TcgStorageOpalLib: Fix wrong condition judgment.
    + SecurityPkg OpalPasswordDxe: Suppress option for special device.
    + OvmfPkg: remove PciHostBridgeDxe fork
    + OvmfPkg: remove USE_OLD_PCI_HOST build option
    + OvmfPkg: Convert to using FatPkg in the EDK II tree
    + ArmVirtPkg: Convert to build FatPkg from source
    + ArmVirtPkg: drop dependency on PeiPcdLib for PEI Pcd.inf
    + ArmVirtPkg: drop dependency on DxePcdLib for DXE Pcd.inf
    + IntelFrameworkModulePkg AcpiS3SaveDxe: Remove S3Ready() functional code
    + IntelFrameworkModulePkg AcpiS3SaveDxe: Consume PcdAcpiS3Enable to control the code
    + OvmfPkg: Retire AcpiS3SaveDxe
    + MdeModulePkg S3SaveStateDxe: Move S3Ready() functional code from AcpiS3SaveDxe
    + MdeModulePkg S3SaveStateDxe: Consume PcdAcpiS3Enable to control the code
    + OvmfPkg: Install LockBox protocol in constructor of LockBoxDxeLib
    + OvmfPkg: Set PcdAcpiS3Enable according to QemuFwCfgS3Enabled()
    + MdeModulePkg: Introduce new PCD PcdAcpiS3Enable
    + ArmVirtPkg: drop bogus ArmPlatformSecExtraActionLib resolution
    + ArmVirtPkg: remove linux loader from ARM builds
    + Merge 2-clause BSD licensed FatPkg
    + BaseTools: Add support to merge Prebuild and Postbuild into build Process
    + BaseTools: Enhance --Pcd which override by build option
    + MdeModulePkg/Bds: Fix build failures of VS tool chain
    + OvmfPkg: disable PcdHiiOsRuntimeSupport
    + OvmfPkg: remove PcdMaxHardwareErrorVariableSize from the DSC files
    + ArmVirtPkg: include Virtio10Dxe from OvmfPkg
    + OvmfPkg: include Virtio10Dxe
    + OvmfPkg: Virtio10Dxe: non-transitional driver for virtio-1.0 PCI devices
    + OvmfPkg: VirtioNetDxe: adapt virtio-net packet header size to virtio-1.0
    + OvmfPkg: VirtioScsiDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioRngDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioNetDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioBlkDxe: adapt feature negotiation to virtio-1.0
    + OvmfPkg: VirtioLib: add Virtio10WriteFeatures() function
    + OvmfPkg: IndustryStandard: add definitions from the VirtIo 1.0 spec
    + OvmfPkg: IndustryStandard: factor out Virtio095Net.h
    + OvmfPkg: IndustryStandard: factor out Virtio095.h
    + OvmfPkg: VirtioRngDxe: clear all feature bits more explicitly
    + OvmfPkg: VirtioBlkDxe: don't clear non-negotiable feature bits
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: pass VRING object to SetQueueAddress()
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: remove GetQueueAddress() member
    + OvmfPkg: VIRTIO_DEVICE_PROTOCOL: widen the Features bitmap to 64 bits
    + MdeModulePkg/Bds: Fix a boot hang due to Ram Disk boot support
    + BaseTools: cache the defined Guid tool to improve the performance
    + MdeModulePkg/Bds: Memory Bins don't count the memory used by RAM Disk
    + MdeModulePkg/Bds: Free resources after ram disk boot finishes
    + MdeModulePkg/Bds: Allocate reserved memory for RAM Disk boot media
    + SecurityPkg OpalPasswordSupportLib: Add comments for the used protocol in inf file.
    + SecurityPkg OpalPasswordSupportLib: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordSupportLib: Fixed gcc build failure.
    + SecurityPkg TcgStorageOpalLib: Fixed gcc build failure.
    + SecurityPkg OpalPasswordDxe: Check the pointer before use it.
    + SecurityPkg TcgStorageOpalLib: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordDxe: Remove the hard code debug build option.
    + SecurityPkg OpalPasswordSmm: Remove the hard code build option.
    + MdePkg Cper.h: Add missing structure for 'Processor Error Record'
    + SourceLevelDebugPkg/SmmDebugAgent: mMailboxPointer is used before set
    + MdePkg/MdePkg.uni: Add description for PcdUartDefaultReceiveFifoDepth
    + MdePkg/BaseSynchronizationLib: Add spin lock alignment for IA32/x64
    + MdePkg/BaseSynchronizationLib: Do not check timeout if lock released
    + BaseTools/GenFds: Fix the bug for wrong alignment generate for RAW file
    + MdeModulePkg/UiApp: Correct the total RAM calculation
    + IntelFrameworkModulePkg/Bds: Correct the total RAM calculation
    + MdeModulePkg: DxeUdpIoLib: fix non-empty payload path in UDP reception
    + OvmfPkg: Add RAM disk support
    + ArmPkg/ArmArchTimerLib: correct typos
    + ArmPkg/ArmArchTimerLib: fix unused variable in RELEASE builds
    + EmbeddedPkg/AcpiLib: fix SBSA Generic Watchdog helper definition
    + ArmPlatformPkg: Add PCD for Pl011 UART Interrupt
    + MdePkg: Add ARM Serial Port Subtypes to DBG2
    + MdePkg: Add ARM Serial Port Subtype definitions
    + ArmVirtPkg: disable PcdHiiOsRuntimeSupport
    + ArmPkg/ArmArchTimerLib: add GetTimeInNanoSecond() to ArmArchTimerLib
    + ArmPkg/ArchArmTimerLib: refactor MultU64xN and TimerFreq definitions
    + NetworkPkg: Check received packet size before use it.
    + MdeModulePkg: Check received packet size before use it.
    + NetworkPkg: Check pointer for NULL before use.
    + Revert "TerminalDxe: select the UART's default receive FIFO depth"
    + ArmVirtPkg/ArmVirtQemu: gate FDT config table install with build option
    + ArmVirtPkg/VirtFdtDxe: make installation of FDT as config table optional
    + MdeModulePkg RamDiskDxe: Fix incorrect RAM disk memory address calculation
    + MdeModulePkg EmmcDxe: Fix GCC build failure with set but unused variables
    + SecurityPkg: Tcg2Dxe: Fix undersized TempBuf
    + MdeModulePkg/UefiBootManagerLib: BmGetActiveConsoleIn code cleanup
    + MdeModulePkg/SdMmc: Add EDKII SD/MMC stack
    + MdePkg/IndustryStandard: Add SD/EMMC common definitions
    + MdePkg/DevicePath: Add EMMC device path definition
    + MdePkg: Add EFI_SD_MMC_PASS_THRU_PROTOCOL definition
    + UefiCpuPkg/Cpuid.h: Display Intel SGX Resource Enumeration Leaves
    + UefiCpuPkg/Cpuid.h: Add CPUID defines and structures for Intel SGX
    + ShellPkg: Refine the comparisons code in ShellPkg.
    + MdeModulePkg PartitionDxe: Add Re-entry handling logic for BindingStop
    + SecurityPkg: Enable Opal password solution build.
    + SecurityPkg: OpalPasswordSmm: Add Opal password Smm driver.
    + SecurityPkg: OpalPasswordDxe: Add Opal password dxe driver.
    + SecurityPkg: OpalPasswordSupportLib: Add Opal password support library.
    + SecurityPkg: TcgStorageOpalLib: Add TCG storage opal library.
    + SecurityPkg: TcgStorageCoreLib: Add TCG storage core library.
    + MdePkg: Add definition for TCG Storage Core and Opal specs.
    + BaseTools: Add two new sections for PCD in the build report
    + MdeModulePkg/SerialDxe: Set FIFO depth with PCD
    + MdePkg: Add PCD for UART default receive FIFO depth
    + MdeModulePkg DiskIoDxe: Media status check not be done at DiskIo level
    + MdeModulePkg PartitionDxe: Some ISO images cannot be recognized properly
    + MdeModulePkg ScsiDiskDxe: Fix hang issue when reconnecting an ISCSI device
    + PcAtChipsetPkg/PciHostBridge: Remove PciHostBridge driver
    + ShellPkg/UefiDpLib: Fix a memory leak issue in Dp.
    + PerformancePkg/Dp_App: Fix a memory leak issue in Dp.
    + BaseTools: Remove the unnecessary check for RAW File
    + BaseTools: generate alignment when the FV content come from the filesystem
    + BaseTools: Extend the RAW format to support multiple binary files
    + ShellPkg AARCH64: remove DEBUG BuildOptions override
    + BaseTools AARCH64: move DEBUG GCC49 to the small code model
    + OvmfPkg: Increase the maximum size for Authenticated variables
    + BaseTools/GCC: set -Wno-unused-but-set-variables only on RELEASE builds
    + UefiCpuPkg: CpuMpPei: remove set but unused variables
    + UefiCpuPkg: PiSmmCpuDxeSmm: remove set but unused variables
    + UefiCpuPkg/MtrrLib: remove unused but set variable
    + NetworkPkg: IpSecDxe: remove set but unused variables
    + MdeModulePkg: DeviceManagerUiLib: remove set but unused variables
    + MdeModulePkg: BootMaintenanceManagerUiLib: remove set but unused variables
    + MdeModulePkg: UfsPassThruDxe: remove set but unused variables
    + MdeModulePkg: BootManagerMenuApp: remove set but unused variables
    + MdeModulePkg/PciHostBridgeDxe: remove unused but set variables
    + IntelFspWrapperPkg: PeiFspHobProcessLibSample: remove set but unused variables
    + IntelFrameworkModulePkg: LegacyBootMaintUiLib: remove set but unused variables
    + IntelFrameworkModulePkg: DxeCapsuleLib: remove set but unused variables
    + IntelFrameworkModulePkg: BiosVideo: remove set but unused variable
    + EmulatorPkg: CpuRuntimeDxe: remove set but unused variables
    + EdkCompatibilityPkg: SmmBaseHelper: remove set but unused variables
    + EdkCompatibilityPkg: EdkIIGlueLib: remove set but unused variables
    + EdkCompatibilityPkg: BsSerialStatusCode: remove set but unused variable
    + EdkCompatibilityPkg: UefiEfiIfrSupportLib: remove set but not used variables
    + ArmPkg|EmbeddedPkg: make PcdCpuVectorBaseAddress 64 bits wide
    + ArmPlatformPkg: fixups for 64-bit pointers
    + ArmPkg: apply Cortex-A57 errata
    + NetworkPkg:Fix bug when parsing the dhcp6 option 16
    + NetworkPkg:Fix Http boot download issue.
    + ShellPkg/UefiHandleParsingLib: Fix GUID reference
    + BaseTools: Updated BuildNotes URLs
    + MdeModulePkg/RamDiskDxe: Fix typo in HII message
    + SecurityPkg/SecureBootConfigDxe: Remove type casting from the ChooseFile handlers
    + SecurityPkg/SecureBootConfigDxe: Declare EFIAPI for the ChooseFile handlers
    + ShellPkg/UefiShellDebug1CommandsLib: remove unused but set variable
    + MdeModulePkg/PciBus: Should reserve enough bus number for HPC
    + MdeModulePkg/Bds: Fix VS2012 build failure.
    + ShellPkg: Modify the 'dh' Shell command to dump the Firmware Management Protocol Image Descriptor Information.
    + MdePkg: Move SMBIOS data into the IndustryStandard header.
    + ShellPkg: Make the USB mouse behavior in 'edit' consistent with 'hexedit'.
    + NetworkPkg: Fix HII related problem in HTTP boot driver.
    + MdeModulePkg/FileExplorerLib.h: Remove the redefinition of typedefs
    + OvmfPkg: PciHostBridgeLib: install 64-bit PCI host aperture
    + OvmfPkg: PlatformPei: determine the 64-bit PCI host aperture for X64 DXE
    + OvmfPkg: PlatformPei: factor out GetFirstNonAddress()
    + OvmfPkg: AcpiPlatformDxe: enable PCI IO and MMIO while fetching QEMU tables
    + OvmfPkg: AcpiPlatformDxe: when PCI is enabled, wait for Platform BDS's cue
    + ArmVirtPkg: PlatformIntelBdsLib: signal gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: PlatformBdsLib: signal gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: introduce gRootBridgesConnectedEventGroupGuid
    + OvmfPkg: OvmfPkg.dec: add horizontal whitespace under Guids and Protocols
    + OvmfPkg/PlatformBdsLib: rebase to EfiEventGroupSignal
    + ArmVirtPkg/PlatformIntelBdsLib: rebase to EfiEventGroupSignal
    + IntelFrameworkPkg/FrameworkUefiLib: implement EfiEventGroupSignal
    + IntelFrameworkPkg/FrameworkUefiLib: move InternalEmptyFunction to UefiLib.c
    + MdePkg/UefiLib: introduce EfiEventGroupSignal
    + MdePkg/UefiLib: move InternalEmptyFunction to UefiLib.c
    + BaseTools: not include the undefined macro in response file
    + MdeModulePkg/BootMaintenanceManagerUiLib: Remove type casting in ChooseFile
    + MdeModulePkg/BootMaintManagerUiLib: Declare EFIAPI for ChooseFile handler
    + MdeModulePkg RamDiskDxe: Remove unnecessary TPL raise operations
    + MdeModulePkg RamDiskDxe: Uninstall DEVICE_PATH_PROTOCOL with correct param
    + MdeModulePkg RamDiskDxe: Remove unnecessary 'DisconnectController' calls
    + MdeModulePkg/Bds: BDS hotkey shouldn't work on inactive consoles
    + ArmPkg/AArch64Mmu: use correct AP[] bits in ArmClearMemoryRegionReadOnly
    + ArmPkg/ArmExceptionLib: reimplement register stack/unstack routines
    + ArmPkg/ArmExceptionLib: avoid indirect call if using vector table in place
    + ArmPkg/ArmExceptionLib: make build time define visible to the compiler
    + ArmPkg/ArmExceptionLib: don't restore ESR and FAR upon exception return
    + ArmPkg/ArmExceptionLib: stack FPSR on common path
    + ArmPkg/ArmExceptionLib: fold exception handler prologue into vector table
    + ArmPkg/AsmMacroIoLibV8: remove undocumented assumption from ELx macros
    + BaseTools: Fix nmake failure due to command-line length limitation
    + MdePkg/Pci22.h: Fix a coding style issue
    + MdeModulePkg DxeCore: Address boundary check for Type AllocateAddress
    + MdeModulePkg DxeCore: Check Start consistently in CoreConvertPagesEx
    + OvmfPkg/PlatformPei: suppress wrong VS2008 warning (use of uninited local)
    + MdeModulePkg PlatformVarCleanupLib: Locate VarCheck protocol when using
    + ArmPkg: update CpuDxe to use CpuExceptionHandlerLib
    + ArmVirtPkg/ArmVirtQemu: move to ARM version of CpuExceptionHandlerLib
    + ShellPkg: Remove the unused local variable.
    + MdeModulePkg: Fixed incorrect return value of MatchString
    + MdeModulePkg: ConSplitterDxe: use U64 mult/div wrappers in AbsPtr scaling
    + ArmPkg: ARM/AArch64 implementation of CpuExceptionHandlerLib
    + ArmPkg/ArmLib: add ArmReadHcr to enable read-modify-write of HCR
    + MdeModulePkg: Rescale ConSplitter Absolute Pointer.
    + ShellPkg: Per UEFI Shell 2.2 SPEC to make Shell supports 'NoNesting'.
    + NetworkPkg: Fix the driver model issue in HTTP Boot driver.
    + MdeModulePkg: Coding style update for DxeHttpLib.inf
    + IntelFrameworkModulePkg/LegacyBootMaintUiLib: Refine the code
    + MdeModulePkg: Refine the UI code
    + MdeModulePkg/DriverSampleDxe: Uninstall the ConfigAccess protocol
    + BaseTools: add new command line option to support override PCD value
  - The fix for bsc#973625 is also included in the update tarball
  - Remove upstreamed patches:
* Fri Apr 01 2016
  - Add ovmf-fix-httpboot-driver-option-16.patch to fix the parsing
    of DHCPv6 option 16
* Wed Mar 23 2016
  - Add ovmf-fix-choose-handlers-crash.patch to fix the crash while
    selecting files from BootMaintenanceManager and SecureBootConfig
* Wed Mar 16 2016
  - Update to 2015+git1458029440.db27e9f
    + OvmfPkg/LegacyRegion: Support legacy region manipulation of Q35
    + CryptoPkg: Fix the potential system hang issue
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2g
    + ArmVirtPkg/VirtFdtDxe: set /chosen/linux,pci-probe-only to 1
      in DTB
    + OvmfPkg: match PCI config access to machine type
      (if not USE_OLD_PCI_HOST)
    + OvmfPkg: add DxePciLibI440FxQ35
    + OvmfPkg: Enable Network2 Shell Commands for IPv6
    + MdeModulePkg AcpiTableDxe: Use Rsdt to check against NULL
    + MdePkg: Fix ACPI NFIT GUID definitions
    + NetworkPkg: Add URI configuration form to HTTP boot driver
    + CryptoPkg/OpensslLib: Switch to upstream fix for OpenSSL
      RT#3628, RT#3674, RT#3951, RT#3955, RT#3964, RT#3969, RT#3992,
      RT#4175, RT#4310
    + CryptoPkg/OpensslLib: Include complete copy of opensslconf.h
    + SecurityPkg/SecureBootConfigDxe: Handle allocation failure
    + MdeModulePkg/Bds: Support booting from remote file system
    + MdeModulePkg/Bds: Wide match HTTP boot option
    + MdeModulePkg: Fix IPv4 double free
    + UefiCpuPkg: Add dynamic type for PcdCpuMaxLogicalProcessorNumber
    + ArmPkg: Configure TTBCR register
    + OvmfPkg: switch to MdeModulePkg/Bus/Pci/PciHostBridgeDxe
    + MdeModulePkg: PciHostBridgeDxe: don't assume extended config
    + ShellPkg: Update 'ifconfig -r' implementation
    + NetworkPkg: Change the default IPv6 config policy
    + MdeModulePkg: Change the default IPv4 config policy
    + OvmfPkg: copy log level comments from DebugLib.h
    + ArmVirtPkg: sync log level comments to DebugLib.h
    + MdeModulePkg: DxeCore: fully initialize image context before
      passing it on
    + MdeModulePkg/NvmExpress: Fix uninitialized field used in NVMe
    + MdeModulePkg: Add new API HttpUrlGetPath() to HttpLib.h
    + MdeModulePkg: Add RamDiskDxe driver implementation
    + SecurityPkg: Tcg2Smm: Change TPM2.0 MMIO range attribute
    + MdeModulePkg:Fix a robustness issue of Mnp Driver
    + MdeModulePkg: RegularExpressionDxe: support free(NULL)
    + MdeModulePkg/PciHostBridge: Don't assume resources are fully
    + SecurityPkg: Use FileExplorerLib in SecureBootConfigDxe
    + MdeModulePkg: Add ASSERT to make sure pointer 'OptionalData'
      not be NULL
    + MdeModulePkg: Add ASSERT to make sure pointer 'MemoryMap' is
      not NULL
  - Update openssl to 1.0.2g
  - Add ovmf-fix-httpboot-driver-model.patch to fix the crash caused
    by the httpboot driver.
* Wed Mar 02 2016
  - Add ovmf-tools to package EfiRom (FATE#319531)
* Fri Feb 26 2016
  - Update to 2015+git1456452471.ba33c80
    + CryptoPkg: RuntimeCryptLib: support realloc(NULL, size)
    + CryptoPkg: support free(NULL)
    + MdePkg: Add EFI RAM Disk Protocol definitions
    + MdePkg: Update Http11 with additional useful definitions
    + NetworkPkg: Use Http11 definitions in HttpDxe and HttpBootDxe
    + Add new HII action type EFI_BROWSER_ACTION_SUBMITTED
    + UefiCpuPkg/Cpuid: Add UEFI CPUID application
    + BaseTools/tools_def.txt: Add -march=i586 for IA32 GCC targets
    + MdeModulePkg: Fix Memory Attributes table type issue
    + MdePkg: Add definition for new warning code
    + OvmfPkg: add driver for Virtio-RNG device
    + ArmVirtPkg: ArmVirtQemu: add driver for Virtio-RNG device
    + OvmfPkg: implement UEFI driver for Virtio RNG devices
    + OvmfPkg: VirtioFlush(): return the number of bytes written by
      the host
    + ArmPlatformPkg/IntelBds: call BdsLibConnectAll()
    + ArmVirtPkg/ArmVirtQemu: limit ACPI support to v5.0 and higher
    + MdeModulePkg: AcpiTableDxe: make 4 GB table allocation limit
    + ShellPkg: Support finding help message embedded in resource
    + MdeModulePkg/UsbBusDxe: Fix memory leak
    + MdePkg: BaseLib: fix AArch64 DAIF interrupt mask definitions
    + ArmPkg: CpuDxe: don't track interrupt state in a global
    + ArmPkg: CpuDxe: fix AArch64 interrupt read masks
    + MdeModulePkg: Refine the code in BootMaintenanceManagerUiLib
    + MdeModulePkg: HiiDatabaseDxe: HiiStringToImage() should not
      overwrite BltX
    + CryptoPkg/OpensslLib: Upgrade OpenSSL version to 1.0.2f
    + UefiCpuPkg/PiSmmCpuDxeSmm: Enable/Restore XD in SMM
    + UefiCpuPkg/PiSmmCpuDxeSmm: Add EFIAPI to CheckFeatureSupported()
    + ArmVirtPkg: ArmVirtQemu: make ACPI support AARCH64 only
    + SecurityPkg: TcgConfigDxe: Move TPM state string update to
      CallBack function
    + MdePkg: Fix incorrect PCIe Extended Capabilities definition
    + MdeModulePkg/Partition: Use proper partition number for MBR
    + MdePkg: Change PcdPropertiesTableEnable default value to FALSE
    + ArmVirtPkg: ArmVirtQemu: expose only 64-bit entry point for
      v3.0+ SMBIOS
    + NetworkPkg: Replace the internal function with exposed one
    + MdeModulePkg: Define a general function to create DNS QName
    + MdePkg: Add invocation register support in SMM Communication
      ACPI Table
    + MdeModulePkg: SNP should check Cdb.StatCode with
    + MdeModulePkg: Make the DEBUG info consistent in SNP driver
    + Add UEFI2.6 MemoryAttributes Table
    + OvmfPkg: simplify VARIABLE_STORE_HEADER generation
    + Minor comments update to AllocatePages() and AllocatePool()
    + MdeModulePkg DxeCore: Missing change for OEM reserved memory
      type at R17460
    + ArmPkg: DefaultExceptionHandler fixes for use with DxeCore
    + BaseTools/GenFw AARCH64: add support for relative data
  - Update openssl to 1.0.2f
    Feb 15 09:17:12 UTC 2016 -
  - edk2 upstream switched the repo from svn to git, so the naming
    has to change to use the git hash. The most recent stable release
    of edk2 is UDK 2015, so the base version changes to 2015.
  - update to ovmf-2015+git1454310736.ed5e386
    + MdePkg: Update the UEFI version to reflect new revision
    + MdePkg: Add EFI Supplicant Protocol definitions
    + MdePkg: Add EFI Wireless MAC Connection II Protocol definitions
    + MdePkg: Add ACPI6.1 definition
    + NetworkPkg: better sanity check on Ipv6 prefix length
    + NetworkPkg: Reword PXE download message
    + ShellPkg: ShellFileHandleReadLine must return UCS2 lines
    + ArmPlatformPkg/Bds: Early Console Initialization
    + ShellBinPkg: Arm/AArch64 Shell binary update
    + ShellPkg: Fix ASCII and UNICODE file pipes
    + ArmVirtPkg: implement ArmVirtQemuKernel
    + ArmVirtPkg: introduce new ArmQemuRelocatablePlatformLib
    + MdeModulePkg: Update DxeCore dispatcher to ignore PEI and SMM
      depex for FV
    + ArmPkg: Add isb when setting SCR
    + MdeModulePkg/PcRtc: Still create timezone variable when
      Daylight != 0
    + MdeModulePkg/UsbAbsPointer:Fix GetState() to return absolute
    + MdeModulePkg: Correct one return status code in SNP Transmit
    + MdeModulePkg: Update the default size of MNP TX buffer pool
    + MdeModulePkg: Update DBsize in SNP GetStatus command
    + NetworkPkg:Add a new error status code EFI_HTTP_ERROR
    + MdePkg:Add a new error status code EFI_HTTP_ERROR
    + NetworkPkg: Fix suspicious dereference of pointer 'Mode.Ia'
    + OvmfPkg: QemuBootOrderLib: recognize NVMe devices
    + OvmfPkg: include NvmExpressDxe driver
    + SecurityPkg: AuthVariableLib: Add new cert database for
      volatile time based Auth variable
    + MdeModulePkg: Add BS+RT+AT variable attribute definition
    + MdePkg: Add new enum EfiPlatformConfigurationActionUnsupportedGuid
    + PcAtChipsetPkg/Rtc: Don't unnecessarily create timezone
    + Correct inconsistent function descriptions in DNS
    + OvmfPkg: Increase default RELEASE build image size to 2MB
    + Minor update to the Data parameter for GetVariable()
    + MdeModulePkg: NvmExpressDxe: clean up NvmeRead() / NvmeWrite()
      debug msgs
    + MdePkg:Add new traffic statistics definition for Wireless NIC
    + NetworkPkg:Fix Network memory leak when calling GetModeData
    + SecurityPkg: Correct data copy in Tpm2NvReadPublic
    + SecurityPkg: Add TPM PTP detection in Tpm12SubmitCommand
    + MdeModulePkg DxeCore: Avoid the closed event to be signaled
    + SecurityPkg: SecureBootConfigDxe: Fix potential NULL pointer
    + CryptoPkg: Fix function qsort for non 32-bit machines
  - update _service to fetch git repo
* Tue Jan 26 2016
  - update to R19743
    + NetworkPkg: Removing or adding some ASSERT statement
    + MdeModulePkg:Fix the potential memory leak issue in Display
    + MdeModulePkg: Add error DEBUG statements in ATA passthru driver
    + NetworkPkg: DnsDxe: fix return type of DnsFillinQNameForQueryIp()
    + MdeModulePkg/Ide: return correct status when DRQ is not ready
      for ATAPI
    + MdeModulePkg/ScsiDisk: Increase the value of SCSI_DISK_TIMEOUT
      to 30s
    + OvmfPkg: inherit Image Verification Policy defaults from
    + OvmfPkg: execute option ROM images regardless of Secure Boot
    + Rename TisTpmCommand to avoid name collision
    + MdeModulePkg: update SNP.GetStatus to handle multiple recycled
      TX buffer.
    + MdeModulePkg: Update MNP driver to recycle TX buffer
    + Refine error handle code, avoid assert when load this module
    + MdeModulePkg: DeleteLoadOptionVariable() removes Boot####
    + MdeModulePkg: Fix GraphicsConsole driver resolution out of
      sync issue
    + SecurityPkg: MOR drivers use Tcg2Protocol instead of TrEE.
    + SecurityPkg: Add Tpm2Startup return code check.
    + SecurityPkg: Clear AuthSession content after use.
    + BaseTools/VfrCompile: honor CC if it is set
    + BaseTools AARCH64: add separate GCC build rule for XIP objects
    + BaseTools AARCH64: build XIP modules with strict alignment
    + SecurityPkg: TcgDxe,Tcg2Dxe,TrEEDxe: New PCD for TCG event log
      and TCG2 final event log area
    + NetworkPkg: Fix some typos in Http boot driver.
    + MdeModulePkg: Add DNS QType and QClass values definition
    + NetworkPkg: Remove DNS QType and QClass definition
    + SecurityPkg: SecureBootConfigDxe: Change
    + SecurityPkg: SecureBootConfigDxe: Enhance secure boot string
      update logic
    + MdeModulePkg:Fix the potential memory leak issue in Display
    + ShellPkg: Update 'dh' command to reflect correct driver handle
    + NetworkPkg: Fix IpSec SPD and SAD mapping issue when SPD is
    + NetworkPkg: Fix SPD entry edit policy issue in IPSecConfig.
    + MdeModulePkg: Add new library class PciHostBridgeLib
    + MdeModulePkg: Add PciHostBridgeLibNull
    + MdePkg: Add PciSegmentLib instance based on PciLib
    + MdeModulePkg: Add generic PciHostBridgeDxe driver.
    + Add NOOPT target
    + ShellPkg UefiDpLib: Use Image->FilePath to get name for SMM
    + MdeModulePkg/.../IdeMode: actualize DRQReady*() comment blocks
    + MdeModulePkg/.../IdeMode: report early finish of packet read
      as success
    + MdeModulePkg: SerialDxe: lay out mSerialIoMode initializer more
    + MdeModulePkg: SerialDxe: sync EFI_SERIAL_IO_MODE.Timeout with
      the spec
    + MdeModulePkg: TerminalDxe: select the UART's default receive
      FIFO depth
    + BaseTools: make build report tolerant of FVs specified by name
    + Replace TpmCommLib with Tpm12DeviceLib
    + Add TPM 1.2 commands used by TCG modules
    + SecurityPkg: Update TCG PPI "1.3" for TCG2.
    + Add TPM PTP support
  - Remove upstreamed ovmf-fix-signedness.patch
* Wed Jan 06 2016
  - update to R19584
    + NetworkPkg: Support DNS4/6 GeneralLookUp feature
    + SecurityPkg AuthVariableLib: Correct comment/error log about
    + NetworkPkg: Fix suspicious dereference of pointer before NULL
    + NetworkPkg: Update module inf to include the missing uni file
    + NetworkPkg: Remove a CopyMem to speed up the HTTP boot download
    + NetworkPkg: Remove unused EFI_HTTP_PROTOCOL definition
    + MdePkg : Update SPCR to use ACPI5 definition
    + MdeModulePkg ScsiDiskDxe: Raise the Tpl of async IO callback
      to TPL_NOTIFY
    + ScsiDiskDxe: Close event when SCSI command fails
    + MdeModulePkg ScsiBusDxe: Only signal caller event when
      PassThru() succeeds
    + MdeModulePkg DiskIoDxe: Check for MediaPresent in
    + MdeModulePkg ScsiDiskDxe: Modify WriteBlocks(Ex)() to follow
      UEFI spec
    + MdeModulePkg ScsiDiskDxe: Modify FlushBlocksEx() to follow UEFI
    + MdeModulePkg ScsiDiskDxe: Set block I/O media of SCSI CDROM to
    + PcAtChipsetPkg/Rtc: Fix a UEFI Win7 boot hang issue
    + MdeModulePkg:Clear the screen before booting the boot option
    + NetworkPkg : Remove unused local variables to fix gcc build
    + MdePkg: Add HTTP 1.1 industry standard definitions
    + SecurityPkg: SecureBootConfigDxe: Remove useless code in VFR
    + NetworkPkg:Fix a bug the 2nd httpboot fail issue
    + NetworkPkg: Update iSCSI driver to check existing AIP instances
    + UefiCpuPkg/CpuMpPei: Fix pack(1) issue on x64 arch
    + MdeModulePkg:Fix bug that get the password width info
    + NetworkPkg:Fix the issue Http boot hang when network failed
    + DxeTpmMeasureBootLib: Change global variable name to avoid
      name conflict
    + ArmVirtPkg/ArmVirtXen: add ARM support
    + ArmVirtPkg/XenRelocatablePlatformLib: rewrite DTB memory node
      retrieval in C
    + OvfmPkg/XenHypercallLib: add missing GCC_ASM_EXPORT to
    + Shell update
    + MdeModulePkg:Fix a bug HttpLib can't parse last chunked data
    + MdeModulePkg/PciSioSerialDxe:add non-null pointer dereference
    + ArmPkg: rewrite vector table population macros
    + BootManagerLib: Check the pointer to avoid use NULL pointer
    + MdeModulePkg: Fix RegularExpressionDxe memcpy intrinsic
  - Add ovmf-fix-signedness.patch to fix the build error
* Wed Dec 16 2015
  - Update R19289
    + MdePkg: Add missing SMBIOS definitions for SATA and SAS Ports
    + MdePkg: Add GIC version to ACPI 5.1/6 definitions
    + MdePkg: Add Ipmi2.0 definitions head file
    + MdeModulePkg: Add NULL pointer check for RegularExpressionDxe
    + Convert all .uni files to utf-8
    + BaseTools/Scripts: Add script
    + Fix >4G issue on IDT not restored correctly
    + MdeModulePkg: Improved SetupBrowser handling to failed GOTO
    + ArmPlatformPkg/Sec: fix return_from_exception code and comment
    + ArmPlatformPkg/ArmPlatformLibNull: use declared PPI rather than
      module local var
    + ArmVirtPkg RVCT: build DXE_RUNTIME_DRIVER modules with 4 KB
    + BaseTools/GenFw RVCT: fix relocation processing of PT_DYNAMIC
    + BaseTools RVCT: use scatter file to enforce minimum section
    + MdePkg/BaseIoLibIntrinsic: Add EBC support
    + MdePkg: Add 3 macro defined in latest TPM2 specification
    + ShellPkg: Initialize the local pointer to avoid potential
      suspicious dereference
    + CryptoPkg/OpensslLib: upgrade OpenSSL version to 1.0.2e
    + MdeModulePkg ScsiDiskDxe: Add BlockIO2 Support
    + MdePkg UefiScsiLib: Add non-blocking support for SCSI
      Read/Write command
    + NetworkPkg: Fix the potential NULL pointer dereferenced issue
    + ShellPkg: Make 'dh' support showing all spec defined protocols
    + BaseTools GCC: avoid the use of COMMON symbols
    + ArmPkg/PrePeiCore: adhere to architectural stack alignment
    + UefiCpuPkg/MtrrLib: Add PCD PcdCpuNumberOfReservedVariableMtrrs
    + ArmPkg/BdsLib: Send RemainingDevicePath to PXE Load File
    + CryptoPkg/BaseCryptLib: make mVirtualAddressChangeEvent STATIC
    + CryptoPkg ARM: add ArmSoftFloatLib resolution to CryptoPkg.dsc
    + SecurityPkg: AuthVariableLib: Customized SecureBoot Mode
    + MdePkg: DebugAssert enhancement
    + ArmVirtPkg: HighMemDxe: add memory space for the high memory
    + ArmVirtPkg: ArmVirtPlatformLib: find the lowest memory node
  - Update openssl to 1.0.2e
  - Update ovmf-embed-default-keys.patch to include one more db key
  - Add MicWinProPCA2011_2011-10-19.crt, the Windows Product key
* Fri Dec 04 2015
  - Update to R19110
    + ShellPkg: Fix wrong return status for Ifconfig.c
    + OvmfPkg: pull in SMM-based variable driver stack
    + OvmfPkg: any AP in SMM should not wait for the BSP for more
      than 100 ms
    + OvmfPkg: use relaxed AP SMM synchronization mode
    + OvmfPkg: SmmCpuFeaturesLib: implement SMRAM state save map
    + OvmfPkg: import SmmCpuFeaturesLib from UefiCpuPkg
    + OvmfPkg: set gUefiCpuPkgTokenSpaceGuid.PcdCpuSmmEnableBspElection
      to FALSE
    + OvmfPkg: LockBox: use SMM stack with -D SMM_REQUIRE
    + OvmfPkg: introduce -D SMM_REQUIRE and PcdSmmSmramRequire
    + ArmVirtPkg: add secure boot support to 32-bit ARM targets
    + MdeModulePkg/BDS: Do not pass unnecessary option to boot option
    + NetworkPkg: Fix a bug in HttpBootDriverBindingStop() when
      destroying child
    + ArmPlatformPkg/PrePiHobListPointerLib: use thread ID register
    + ArmPlatformPkg/PrePeiCore: add missing entries to AArch64
      vector table
  - Refresh ovmf-gdb-symbols.patch
  - Run fdupes on /usr/share/qemu
* Fri Nov 27 2015
  - Update to R18975
    + ArmVirtPkg: Use SerialDxe in MdeModulePkg instead of
    + OvmfPkg XenConsoleSerialPortLib: Implement
    + NetworkPkg:Fix NULL pointer dereference issues
    + Always set WP in CR0
    + ArmPkg/UncachedMemoryAllocationLib: fix warning about
      uninitialized local var
    + UefiCpuPkg/CpuS3DataDxe: Add module to initialize ACPI_CPU_DATA
      for S3
    + Move CommunicationBuffer from stack to global variable
    + Move SmmDebug feature from ASM to C
    + Install LoadedImage protocol for PiSmmCore
    + Uninstall LoadedImage protocol if SMM driver returns error and
      is unloaded
    + ArmLib/ArmV7Mmu: use 64-bit type for mapping region size
    + ArmVirtPkg/ArmVirtPlatformLib: reduce ID map size to GCD region
    + ArmVirtPkg/ArmVirtQemu: limit the (I)PA space to 40 bits
    + MdeModulePkg/UefiBootManagerLib: Always create MemoryTypeInfo
    + ShellBinPkg: Arm/AArch64 Shell binary update
    + MdeModulePkg:Create Boot Maintenance Manager Library
    + MdeModulePkg:Create Device Manager Library
    + MdeModulePkg:Create Boot Manager Library
    + ArmPkg: Invalidate cache after allocating UC memory
    + MdeModulePkg FileExplorerDxe: Create file explorer Protocol
    + ArmPkg: ArmLib: purge incorrect ArmDrainWriteBuffer () alias
    + UefiCpuPkg/CpuDxe: Don't use gBS->Stall
    + UefiCpuPkg/SmmFeatureLib: Check SmmFeatureControl by
    + UefiCpuPkg: Not touch SmmFeatureControl if Code_Access_Chk not
    + ArmPkg/ArmPlatformPkg: position vectors relative to base
    + ArmPkg: correct TTBR1_EL1 settings in TCR_EL1
    + ShellPkg: Corrected CatSPrint usage to prevent memory leaks
    + ArmPkg/ArmV7Mmu: handle memory regions over 4 GB correctly
    + ArmPkg/ArmV7Lib: take MP extensions into account when
      programming TTBR
    + ArmPkg/ArmV7Lib: fix definition of TTBR_NON_INNER_CACHEABLE
    + ArmPkg/ArmV7Mmu: introduce feature PCD to map normal memory
    + ArmPkg/ArmV7Mmu: make cached translation table accesses
    + ArmPkg/ArmV7Lib: add function to test for presence of MP
    + ArmPkg/ArmV7Lib: add support for reading the ID_MMFR0 system
    + ArmPkg/ArmV7Mmu: fix write-through translation table accesses
    + ArmPkg/Mmu: set required XN attributes for device mappings
    + ArmVirtPkg/ArmVirtPlatformLib: map executable NOR region as
      normal memory
    + ArmPkg/AArch64Mmu: remove unused GcdAttributeToArmAttribute()
* Wed Nov 18 2015
  - Update to R18868
    + ArmPkg: ensure DebugAgentVectorTable is 2K-aligned
    + MdeModulePkg: Add Platform recovery support
    + MdePkg: Add Platform Recovery definitions
    + MdeModulePkg: SmmLockBoxPeiLib: work without
    + NetworkPkg: Httpboot will fail the 2nd time result by wrong
      TCP state
    + MdeModulePkg PeiCore: PEI dispatcher need retry to process
    + ArmPkg/ArmLib: mark all cached mappings as (inner) shareable
    + ArmPlatformPkg: bring DS-5 scripts in line with linker script
    + MdeModulePkg: Add BootLogoLib to provide interfaces about logo
    + MdeModulePkg: Add ImageDecoderLib to provide image decoding
    + MdeModulePkg: Add PlatformLogo protocol definition
* Thu Nov 12 2015
  - Update to R18768
    + MdePkg: Add more DataBits support to Port80 output
    + MdeModulePkg PeiCore: Fix issue AuthenticationStatus is not
      propagated correctly
    + NetworkPkg: Report Http Errors to screen when http layer
      occurs an error
    + Add error handling for TPM in S3 resume failure
    + ArmPkg/ArmDmaLib: use the cache writeback granularity for
    + ArmPkg/ArmLib: fix barriers in AArch64 ArmEnableMmu
    + NetworkPkg:Enable Http Boot over Ipv6 stack
    + NetworkPkg:Missing CloseEvent() in HttpResponseWorker
    + CryptoPkg: Add one new API (Pkcs7GetCertificatesList) for certs
    + SourceLevelDebugPkg: DebugAgent: Set Local APIC SoftwareEnable
    + UefiCpuPkg: LocalApicLib: Add API to set SoftwareEnable bit
    + UefiCpuPkg: CpuDxe: Update GDT to be consistent with DxeIplPeim
    + NetworkPkg: HttpDxe sometimes free a pointer twice
    + CryptoPkg/OpensslLib: Move OPENSSL_NO_xxx defines into
    + CryptoPkg/OpensslLib: Eliminate GETPID_IS_MEANINGLESS
    + CryptoPkg: Fix OpenSSL BN wordsize and OPENSSL_SYS_UEFI
    + CryptoPkg/OpensslLib: Undefine NO_BUILTIN_VA_FUNCS to fix
      varargs breakage
    + CryptoPkg/BaseCryptLib: Use X509_V_FLAG_NO_CHECK_TIME
    + CryptoPkg/BaseCryptLib: Use X509_V_FLAG_PARTIAL_CHAIN
    + CryptoPkg/BaseCryptLib: Clean up checking of PKCS#7 contents
    + CryptoPkg/BaseCryptLib: Use accessor functions for ASN1_OBJECT
    + CryptoPkg/BaseCryptLib: Use accessor functions for
    + CryptoPkg/BaseCryptLib: Use i2d_X509_NAME() instead of abusing
    + CryptoPkg/BaseCryptLib: Add missing OpenSSL includes
    + UefiCpuPkg: PiSmmCpuDxeSmm: Replace PcdSet## with PcdSet##S
    + MdePkg/BaseSynchronizationLib: fix AArch64 return values
    + Fix issue that calling GetS3MemoryInfo() with wrong order
    + Do not deadloop if Microcode not found in FspTempRamInit
    + Move Smbios measurement from TCG driver to Smbios driver
    + Add suppressif around TCG hash seleciton checkbox in TCG2
    + UefiCpuPkg: PiSmmCpuDxeSmm: Remove unused references to SmmLib
    + OvmfPkg: QemuFlashFvbServicesRuntimeDxe: split out runtime DXE
    + OvmfPkg: QemuFlashFvbServicesRuntimeDxe: no dual addressing
    + MdeModulePkg Variable: Enhance variable performance by reading
      from existed memory cache
* Thu Oct 22 2015
  - Update to R18651
    + OvmfPkg: XenPvBlkDxe: handle empty cdrom drives
    + MdeModulePkg SetupBrowserDxe: Save global variable values
      before nest function called
    + UefiCpuPkg: Add CPU Hot Plug Data include file
    + UefiCpuPkg: Add ACPI CPU Data include file
    + UefiCpuPkg: Add SMM CPU Service Protocol
    + UefiCpuPkg: CpuDxe: broadcast MTRR changes to APs
    + UefiCpuPkg: CpuDxe: Wait for APs to enter idle loop
    + UefiCpuPkg: CpuDxe: Use PCD for AP detection timeout
    + UefiCpuPkg: Update CPU MP drivers to support single CPU
    + MdeModulePkg VarCheckLib: R18611 was thoughtless for property
    + SecurityPkg : Fix Rsa2048Sha256GuidedSectionExtractLib issue
    + OvmfPkg: VirtioBlkDxe: reset device at ExitBootServices()
    + OvmfPkg: VirtioScsiDxe: reset device at ExitBootServices()
    + MdeModulePkg: SmbiosDxe: soften DEBUG messages about table
    + MdeModulePkg: FaultTolerantWriteDxe: clean up some "success"
    + MdeModulePkg: FaultTolerantWriteDxe: mellow DEBUGs about
      workspace reinit
    + ArmPlatformPkg: NorFlashDxe: mellow DEBUG messages about flash
    + ArmVirtPkg: include BaseStackCheckLib also for AARCH64
    + NetworkPkg: reset DHCP child when leaving PXE LoadFile
    + MdeModulePkg: reset DHCP child when leaving PXE LoadFile
    + SecurityPkg AuthVariableLib: Add the missing
    + MdeModulePkg VariableRuntimeDxe: Add the missing
    + MdeModulepkg VarCheckLib: Return NULL when no property set to
      variable with wildcard name
    + NetworkPkg: remove unnecessary timeout event when setting IPv6
    + ShellPkg: Print error message when Shell set environment
      variable fail
    + BaseTools/PeCoffLoader: fix handling of ARM MOVW/MOVT
      instruction relocs
    + UefiCpuPkg: Add ASSERT to handle local APIC not config properly
    + SecurityPkg: Integrate new RngLib into RngDxe
    + MdePkg: Create GetRandomNumber128 in RngLib
    + ArmVirtPkg/ArmVirtQemu: enable non-exec DXE stack for AARCH64
    + MdeModulePkg/DxeIplPeim: implement non-exec stack for
    + ArmPkg/ArmLib MMU: add functions to set/clear RO and XN bits on
    + ArmPkg/AArch64Mmu: move page table traversal code to separate
    + ArmPkg/AArch64Mmu: use architecturally correct definitions for
* Thu Oct 08 2015
  - Update to R18577
    + OvmfPkg: raise DXEFV size to 9 MB
    + MdeModulePkg: exit pci function loops early if device is not
    + NetworkPkg: HttpDxe: Remove unused local variables
    + ArmPkg/AArch64Mmu: remove cache maintenance for page tables
    + BaseTools/AARCH64: use large code model for GCC <= 4.8
    + ArmPkg/Mmu: do not configure block translations at level 0
    + ArmVirtPkg: use 4 KB section alignment for
    + BaseTools/ARM: move to unified GCC linker script
  - Enable HttpBoot for i586 and x86_64
  - Drop patches since upstream fixes the issues
    + ovmf-use-non-default-gcc48.patch
    + 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
* Thu Oct 01 2015
  - Update to R18564
    + OvmfPkg: set 4 KB section alignment for DXE_RUNTIME_DRIVER
    + MdeModulePkg Ip4Dxe: Ip4Config2 to request DHCP Option6 DNS
      server IP
    + MdeModulePkg: Add SMBIOS 3.0 support in NetLibGetSystemGuid
    + ArmVirtPkg: build the TFTP command into the UEFI shell
    + OvmfPkg: build the TFTP command into the UEFI shell
    + ArmVirtPkg: reduce preallocation of boot services data pages
    + OvmfPkg: enable SATA controller
    + OvmfPkg: QemuBootOrderLib: recognize Q35 SATA disks / CD-ROMs
    + MdePkg: Add RngLib into MdePkg
    + MdeModulePkg: Remove event from protocol database only if
    + ArmVirtPkg: PlatformIntelBdsLib: signal ReadyToBoot on direct
      kernel boot
    + ShellPkg: Added SMBIOS 2.8 Type 17 changes to smbiosview
    + ShellPkg: Added SMBIOS 3.0 support in dmem
    + MdeModulePkg: Enhance PCI capability looking up logic to avoid
    + OvmfPkg: disable no-exec DXE stack by default
    + OvmfPkg: make PcdPropertiesTableEnable dynamic
    + OvmfPkg: make PcdSetNxForStack dynamic
    + MdeModulePkg: Change the algorithm in SNP to use the first
      found BAR index
    + NetworkPkg: Update Http driver to use DPC mechanism
    + NetworkPkg: RxToken event not closed in Http.Response()
    + NetworkPkg: Avoid memory allocation for each HTTP message
    + NetworkPkg: Update cache management in HTTP boot driver
    + NetworkPkg: Enlarge receive block size of HTTP boot driver
    + PXE Driver's LoadFile protocol should check FilePath
    + ArmVirtPkg: set max physical address width to 40 bits
    + ArmVirtPkg/ArmVirtMemoryInitPeiLib: handle memory above 4 GB
      on 32-bit ARM
    + ArmPkg/Mmu: Fix potential page table memory leak
    + ArmPkg/Mmu: Increase PageLevel when table found at the targeted
    + ArmPkg/Mmu: Fix literal number left shift bug
    + ArmPkg/Mmu: Fix page level calculation bug
    + ArmPkg/Mmu: Fix bug of aligning new allocated page table
    + MdeModulePkg: Fix a performance data buffer overrun issue
    + ShellPkg: Fix 'for' command fail with multiple fields
    + MdeModulePkg: Regular expression protocol
    + NetworkPkg: Fix suspicious dereference of pointer 'FieldCount'
    + Handle extra module patchable PCD variable in Linux map
    + NetworkPkg: Fix the HttpCloseConnection fail issue
    + UefiCpuPkg/MtrrLib: MtrrValidBitsMask and MtrrValidAddressMask
  - Add ovmf-use-non-default-gcc48.patch: gcc5 generates the larger
    code size and causes the x86_64 final image exceeds the size
    limit if we enable Secure Boot and IPv6 at the same time. As a
    workaround, we use the non-default gcc48.
  - Drop ovmf-gcc5-conf.patch and use GCC49 as TOOL_CHAIN_TAG for
    the distro with gcc5
  - Limit 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    to the distro with gcc lower than 5
  - Refresh ovmf-embed-default-keys.patch and ovmf-gdb-symbols.patch
* Thu Sep 03 2015
  - Update to R18393
    + OvmfPkg: PlatformPei: force 32-bit MMIO aperture above 3 GB
    on Q35
    + OvmfPkg: AcpiTables: serialize control methods that create
      named objects
    + OvmfPkg: PlatformPei: clear CMOS 0xF after setting mBootMode
    + CryptoPkg: Fix one wrong parameter for weak key checking
    + CryptoPkg: Replace string wrapper functions with safe string
    + ArmPlatformPkg/PlatformIntelBdsLib: add splash screen support
    + ArmPlatformPkg/PlatformIntelBdsLib: fix and clean up error
    + ArmPlatformPkg/PlatformIntelBdsLib: remove ARM BDS dependency
    + Locate IpSec on IP packet processing only if it's installed
    + ShellPkg: Get media status in ifconfig command
    + OvmfPkg: prevent code execution from DXE stack
    + MdePkg: Modify string expression of Wi-Fi device path to
      follow UEFI spec
    + NetworkPkg: Fix IpSec run into infinite loop issue in some case
    + FatBinPkg: Update EBC/IA32/X64/IPF binaries
    + SecurityPkg: Fix one returned code issue in P7Verify Protocol
    + Add VarCheckLib library
    + BaseTools: Add NULL pointer check in AutoGen code
    + Follow PI spec to update ExtendedSize in EFI_FFS_FILE_HEADER2
    + NetworkPkg: Add HTTP utilities driver
    + OvmfPkg: Add HttpBoot support
    + NetworkPkg: Remove the hostname from the http request URL
    + MdeModulePkg:Full support F10 hot key in UiApp
    + NetworkPkg: Fix DHCP TransmitReceive EFI_NO_MAPPING return in
    + MdeModulePkg: Fix default router table and interface missing
    + ShellPkg: Fix 'ifconfig' can't get the address from dhcp in
      some case
    + ArmPkg: remove ARMv6 support code
    + MdeModulePkg: Update UiApp to handle terminal type TtyTerm
    + MdeModulePkg/Xhci: make all timeout values be consistent with
    + SecurityPkg: Fixed build error due to FixedAtBuild
    + MdeModulePkg: IP4 should re-initiate a DHCP if it detects
      network reconnection
    + NetworkPkg: Stop and release DHCP4 child after boot info is
    + Add restriction that HashFinal() must be after at least one
    + SecurityPkg: Update SignatureSize to comply UEFI spec
    + NetworkPkg: Fix hang issue after system reconnected when IPSec
      has set up
    + Add TPM2 definition in trusted computing group
    + BaseTools IA32/X64: prevent .eh_frame sections from being
    + MdeModulePkg:Use safe string functions in UiApp
    + MdeModulePkg: Add codes to support trailer parse in HttpLib
    + OvmfPkg/Xen: use lower case x in hex immediate value
    + ArmVirtPkg: use global section alignment in custom linker
    + ArmVirtPkg: avoid relocated immediates in AARCH64 asm
    + MdeModulePkg: Fix issue about current Ip4Dxe implementation
      for DHCP DORA process
    + BaseTools/GenFw: allow AArch64 tiny and small code model
  - Add 0001-Revert-BaseTools-AARCH64-use-tiny-code-model-by-defa.patch
    to use the large model for aarch64 since ld/binutils couldn't
    calculate the sections properly and GenFw would fail due to the
    section offset.
  - Drop arm patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
* Mon Aug 10 2015
  - Update to R18191
    + UefiCpuPkg CpuDxe: Sync up the settings of Execute Disable to APs
    + MdeModulePkg DxeIpl: Fix IA32 build failure with GCC 5.1.1
    + ArmPlatformPkg/PlatformPeim: constify EFI_PEI_PPI_DESCRIPTOR
    + ArmPlatformPkg/PrePeiCore: constify PPI globals
    + MdeModulePkg: Use monotonic count to initialize the NetLib
      random seed
    + OvmfPkg: SmbiosVersionLib: recognize SMBIOS 3.x entry point
    + OvmfPkg: SmbiosPlatformDxe: eliminate duplicate entry point
    + ArmVirtPkg/ArmVirtQemu.dsc: set default for
    + OvmfPkg: introduce PcdQemuSmbiosValidated
    + ArmVirtPkg: set SMBIOS version in DetectSmbiosVersionLib
      instead of QemuFwCfgToPcdDxe
    + OvmfPkg: set SMBIOS version in DetectSmbiosVersionLib instead
      of PlatformPei
    + OvmfPkg: SmbiosVersionLib: add "plugin" for detecting SMBIOS
    + OvmfPkg: PlatformDebugLibIoPort: fix AsciiSPrint() format
    + ShellPkg: Fix issue about ping fail with IPv4
    + MdeModulePkg DxeIpl: Add stack NX support
    + NetworkPkg: Fix assert caused by wrong parameter in
    + ArmVirtPkg/ArmVirtQemu: add LinuxLoader UEFI app to ARM build
    + ArmVirtPkg/ArmVirtXen: remove unused PcdFirmwareVendor PCD
    + ArmVirtPkg/ArmVirtQemu: drop ARM BDS and make Intel BDS the
    + BaseTools GCC: move AutoGen.obj contents to .text section
    + BaseTools GCC: align start of .data to .text alignment
    + BaseTools GCC: add unified GCC linker script for all archs and
    + BaseTools IA32/X64: get header size and alignment from ld
    + BaseTools IA32/X64: move .got contents to the PE/COFF .text
    + BaseTools IA32/X64: drop redundant alignment from linker script
    + BaseTools IA32/X64: move .rodata to PE/COFF .text section
    + BaseTools IA32/X64: remove NOP padding from X86/IA32 GCC linker
    + MdeModulePkg PeiCore: Add PCD to specify PEIM Shadow
    + ArmVirtPkg: use 'auto' alignment and FIXED placement for XIP
    + MdeModulePkg: Enhance PciBusDxe to handle high 32bit of MEM64
      BAR returns 0
  - Refresh ovmf-gcc5-conf.patch
  - Refresh 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
  - Drop upstreamed patch: ovmf-netlib-random-seed.patch
  - Drop 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    since the ARM BDS was dropped
* Wed Jul 29 2015
  - Update to R18107
    + NetworkPkg: Fix the issue cannot boot to UEFI Network after
    + ArmVirtPkg: implement DT-based ArmGicArchLib
    + OvmfPkg: fix conversion specifiers in DEBUG format strings
    + Reduce reserved memory consumption
    + MdeModulePkg: Make boot option description unique
    + NetworkPkg: Fix the issue EfiPxeBcDhcp() may return wrong
    + ArmVirtPkg/ArmVirtQemu: support SMBIOS
    + ArmVirtPkg: QemuFwCfgToPcdDxe: set SMBIOS entry point version
    + ArmVirtPkg: add QemuFwCfgToPcdDxe
    + OvmfPkg: SmbiosPlatformDxe: restrict current Xen code to
    + OvmfPkg: SmbiosPlatformDxe: move IsEntryPointStructureValid()
      to Xen.c
    + OvmfPkg: AcpiS3SaveDxe: drop EFI_ACPI_S3_SAVE_PROTOCOL
    + OvmfPkg: install DxeSmmReadyToLock in PlatformBdsLib
    + IntelFrameworkModulePkg/GenericBdsLib: remove AcpiS3->S3Save()
    + OvmfPkg: PlatformBdsLib: signal End-of-Dxe event group
    + OvmfPkg: AcpiS3SaveDxe: call S3Ready() at End-of-Dxe
    + OvmfPkg: AcpiS3SaveDxe: prepare for End-of-Dxe callback
  - Add ovmf-netlib-random-seed.patch to avoid the DHCPv6 IAID
* Fri Jul 24 2015
  - Update to R18030
    + ArmVirtPkg: Make terminal type consistent
    + NetworkPkg: Add the unspecified address check for DNS6
    + ShellPkg: Add optional 'tftp' EFI Shell command
    + NetworkPkg: Fix bios bootup hang issue when enable network
    + SecurityPkg: Fix DBX Variable Read Error in
    + SecurityPkg: Correct BootOrder/Boot#### measurement behavior
    + ArmVirtPkg/ArmVirtQemu.dsc: Remove Linux specific boot path
    + ArmPkg/BdsLib: Remove Linux loader from BdsLib
    + ArmPlatformPkg: Add the LinuxLoader.efi EFI application
    + ArmPkg/BdsLib: Replaced BdsLoadApplication() by
    + OvmfPkg: QemuBootOrderLib: recognize extra PCI root buses
    + OvmfPkg: QemuBootOrderLib: introduce ExtraRootBusMap
    + OvmfPkg: PciHostBridgeDxe: shorten search for extra root buses
    + OvmfPkg: PciHostBridgeDxe: look for all root buses
    + OvmfPkg: PciHostBridgeDxe: eliminate
    + OvmfPkg: PciHostBridgeDxe: use private buffer in
    + OvmfPkg: PciHostBridgeDxe: release resources on driver entry
    + OvmfPkg: PciHostBridgeDxe: factor out InitRootBridge() function
    + OvmfPkg: PciHostBridgeDxe: embed device path in private root
      bridge struct
    + OvmfPkg: PciHostBridgeDxe: kill RootBridgeNumber and
    + OvmfPkg: PciHostBridgeDxe: eliminate nominal support for
      multiple host bridges
    + OvmfPkg: PlatformBdsLib: connect all PCI root buses
  - Refresh patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
* Mon Jul 13 2015
  - Update to R17935
    + CryptoPkg: update OpenSSL dependency to version 1.0.2d
    + OvmfPkg: QemuFwCfgLib: avoid "variable set but not used"
      warning from GCC
    + Remove Ip4ConfigDxe module
    + IntelFrameworkPkg FrameworkUefiLib: Fix ASSERT in CatVSPrint
    + BaseTools: aarch64: add -fno-asynchronous-unwind-tables to gcc
    + MdePkg/AArch64: use GCC_ASM_EXPORT to export functions
    + MdeModulePkg/FvSimpleFileSystemDxe: Support file opening with
      no '.efi'
    + OvmfPkg: Fix GCC49 build hang in PeiCore
    + Add "TtyTerm" terminal type to TerminalDxe
    + MdeModulePkg AcpiTableDxe: Install config table at ACPI data
  - Remove upstreamed ovmf-remove-old-ip4config.patch
* Wed Jul 08 2015
  - Update to R17883
    + MdePkg: Add UEFI2.5 Ramdisk device path definition
    + ArmVirtPkg: use correct ASM decoration for non-function global
    + NetworkPkg: Add UEFI HTTP boot driver
    + NetworkPkg: Add HTTP Driver
    + NetworkPkg: Add DNS feature support over IPv4 and IPv6
    + MdeModulePkg: Update Ip4Dxe driver to support Ip4Config2
    + ArmVirtPkg: adapt ArmVirtXen build to system memory end global
    + ArmPkg/CpuDxe: Fixed AArch64 MMU
    + ArmPkg/Application: Add new EFI application to boot Linux
    + ArmVirtPkg: build runtime drivers with 64 KB section alignment
    + Restructure AuthVariableLib
    + Conversion of the safe string functions
    + CryptoPkg: Fix the dereferenced pointer issue
    + SecurityPkg: Add MD5 support to Hash2DxeCrypto
    + OvmfPkg: Increase the maximum size of RAM
    + ArmVirtPkg: signal EndOxDxe event in PlatformBsdInit
    + MdeModulePkg: Add Memory Capabilities for MMIO and Reserved
  - Add ovmf-remove-old-ip4config.patch to remove the old Ip4Config
  - Refresh patches
    + ovmf-embed-default-keys.patch
    + ovmf-gcc5-conf.patch
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
  - Add the source-level debugging to README
* Wed Jun 24 2015
  - Update to R17700
    + OvmfPkg/PlatformDxe: Convert Platform.uni to UTF-8
    + OvmfPkg: QemuVideoDxe: add virtio-vga support
    + CryptoPkg: OpensslLib: reintroduce EFIAPI for
    + SecurityPkg: Provide correct file GUID for Pkcs7VerifyDxe
    + SecurityPkg: Fix wrong calculation of ImageExeInfoEntrySize
    + OvmfPkg: PlatformPei: set SMBIOS entry point version
    + SecurityPkg: Add UEFI-2.5 PKCS7 Verification Protocol Support
    + CryptoPkg: Add one new API for PKCS7 Verification Protocol
    + MdeModulePkg PiSmmCore: Introduce SMM Exit Boot Services and
      Legacy Boot
    + MdePkg/DxeServicesLib: Return NULL GetFileBufferByFilePath
      reads directory
    + MdeModulePkg: Fix DHCP4 driver hang issue in some case
    + MdeModulePkg: Remove DHCP4.TransmitReceive()and DORA process
    + MdeModulePkg:System hangs in setup menu
    + ArmVirtPkg: increase memory preallocations for secure build
    + Update openssl to 1.0.2c
    + Add code to protect the whole BIOS region on SPI flash, except
      UEFI Variable region
    + SecurityPkg/MdeModulePkg: Add PcdMaxAuthVariableSize
    + MdePkg: Add EFI REST Protocol definitions
    + OvmfPkg/PlatformPei: Initialise RCBA (B0:D31:F0 0xf0) register
    + OvmfPkg/PlatformPei: Query Host Bridge DID only once
    + ArmPkg: reduce sysreg access count in GIC revision probe
    + SecurityPkg: Fix wrong cert data measurement in DBX path
    + MdeModulePkg/UhciDxe: Update async polling interval to 1ms
    + MdeModulePkg/EhciDxe: Update async polling interval to 1ms
    + MdeModulePkg/XhciDxe: Update async polling interval to 1ms
    + ShellPkg\Application\Shell: Clean start row information after
      the console has been Reset or SetMode
    + Add SysPrepOrder and SysPrep#### to global list
    + MdePkg: Add EFI Capsule Report data structure and GUID
    + Add UEFI 2.5 Properties table definition
    + MdePkg:Add UEFI 2.5 PKCS7 Verification Protocol Definition
    + ShellPkg: Handle escape characters properly for parse command
    + ShellPkg: Add pipe support for parse command
    + ArmVirtPkg: increase memory preallocations to reduce region
  - Add ovmf-gcc5-conf.patch for GCC5 and adjust the spec file for
* Wed Jun 03 2015
  - Update to R17553
    + MdeModulePkg/AtaAtapiPassThru: ensure PRDT of IDE is in 64K
    + ArmPkg/BdsLib: Fixed TFTP when there are directories in the
    + Renamed ArmPlatformPkg/ArmVirtualizationPkg into ArmVirtPkg
    + ArmPkg: Expand AArch64 address width to 48 bits
    + MdeModulePkg:Support delete key
    + MdeModulePkg/AtaAtapiPassThruDxe: Support 4K bytes block size
    + MdeModulePkg: Fix potential buffer overflow issues
    + Update for OEM reserved memory type
  - Update ArmPlatformPkg patches
    + 0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + 0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + 0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + 0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + 0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + 0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + 0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + 0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + 0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + 0010-avoid-potentially-uninitialized-variable.diff
  - Remove the prefix of the arm patches
    + ovmf-0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + ovmf-0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + ovmf-0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + ovmf-0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + ovmf-0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + ovmf-0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + ovmf-0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + ovmf-0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + ovmf-0010-avoid-potentially-uninitialized-variable.diff
* Thu May 14 2015
  - Update to R17446
    + OvmfPkg: AcpiS3SaveDxe: fix protocol usage hint in the INF file
    + OvmfPkg: extract some bits and port offsets common to Q35 and
    + MdeModulePkg: Add ESRT management module.
    + MdeModulePkg: Add ESRT management protocol definition
    + MdePkg: Add Microsoft UX capsule GUID & layout
    + SecurityPkg: Update SecureBootConfigDxe to support ARM image
    + SecurityPkg Variable: Make PK & SecureBootMode consistent
    + MdeModulePkg DxeCore: Add read only memory support
    + OvmfPkg: QemuBootOrderLib: parse OFW device path nodes of PCI
    + MdePkg: Add UEFI 2.5 SD (Secure Digital) Device Path Definitions
    + Hash2 driver to [Components.IA32, Components.X64, Components.IPF]
    + ArmVirtualizationPkg: Enable secure boot for ArmVirtualizationQemu
    + ArmPlatformPkg: enable use of authenticated variables in
  - Refresh patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
  - Enable Secure Boot for AArch64
  - Remove the workaround for SLE11
* Thu May 07 2015
  - Although ovmf-gdb-symbols.patch has been included for a while,
    it's not mentioned in changelog and legal-auto script is not
    happy with it.
* Thu May 07 2015
  - Update to R17351
    + BaseTools: Fix build fail issue
    + MdeModluePkg: Enable refresh opcode to refresh the entire form
    + BaseTool: Add refresh form opcode in vfrcompiler
    + MdeModulePkg: Add BootManagerMenuApp
    + MdeModulePkg: Add BdsDxe driver and PlatformBootManagerNull
    + MdeModulePkg: Add UefiBootManagerLib
    + MdePkg: Update the UEFI version to reflect new revision
    + OvmfPkg: Use the new PCDs defined in MdePkg and MdeModulePkg
    + MdePkg: Add UEFI2.5 bluetooth protocol/devicepath definition
    + Add UEFI2.5 HASH protocol implementation
    + MdeModulePkg: Add UEFI2.5 and PI1.4 PersistentMemory feature
    + MdePkg: Add ESRT Interface Definitions
    + Various fixes for Shell
  - Drop ovmf-sle-11-gcc47.patch
    + The NASM version in SLE11 is too old to build the newer ovmf
  - Rename the ARM patches to make the legal-auto script happy
    + ovmf-0001-ArmPlatformPkg-ArmVirtualizationPkg-enable-DEBUG_VER.patch
    + ovmf-0002-ArmPlatformPkg-Bds-generate-ESP-Image-boot-option-if.patch
    + ovmf-0003-ArmPlatformPkg-Bds-check-for-other-defaults-too-if-u.patch
    + ovmf-0004-ArmPlatformPkg-ArmVirtualizationPkg-auto-detect-boot.patch
    + ovmf-0005-ArmPlatformPkg-Bds-initialize-ConIn-ConOut-ErrOut-be.patch
    + ovmf-0006-ArmPlatformPkg-Bds-let-FindCandidate-search-all-file.patch
    + ovmf-0007-ArmPlatformPkg-Bds-FindCandidateOnHandle-log-full-de.patch
    + ovmf-0008-ArmPlatformPkg-Bds-fall-back-to-Boot-Menu-when-no-de.patch
    + ovmf-0009-ArmPlatformPkg-Bds-always-connect-drivers-before-loo.patch
    + ovmf-0010-avoid-potentially-uninitialized-variable.diff
* Thu Apr 23 2015
  - Update ovmf-embed-default-keys.patch to embed the default dbx.
    Also add the dbx list from the UEFI website and enable it in the
    MS flavor. A script,, was added to strip the
    AuthInfo headers from dbxupdate.bin since those are not necessary
    in dbx.
* Mon Apr 20 2015
  - Update to R17187
    + Save initial TSVal from TCP connection initiation packets
    + BaseTools/Ecc: Add ECC (EFI Code Checker) Binary into BaseTools
      bin directory
    + MdePkg: Add ESRT Interface Definitions
    + OvmfPkg: XenConsoleSerialPortLib: deal with output overflow
    + OvmfPkg: Q35: Use correct ACPI PM control register:bit
    + PXE driver bug fix
    + A failed PXEv6 after a success PXEv4 will cause ASSERT
    + MdePkg: BaseSynchronizationLib: fix Increment/Decrement retvals
      for ARM
    + Updated Memory Error Record Per UEFI Specification 2.4a
    + MdeModulePkg BootScriptExecutorDxe: Use ImageContext.ImageSize
      to allocate memory for PE image to handle the case PE file
      alignment is not same as PE section alignment.
    + Fix GCC hang issue: Point should use directly assignment
      instead of IP4_COPY_ADDRESS.
    + SecurityPkg Variable: Update code in ProcessVariable ()
  - Update openssl to 0.9.8zf
* Tue Mar 17 2015
  - Update to R17055
    + OvmfPkg: include XHCI driver
    + ArmVirtualizationPkg/ArmVirtualizationQemu: include XHCI driver
    + ArmVirtualizationPkg: build UEFI shell from source
    + SecurityPkg Variable: Allow the delete operation of common auth
      variable at user physical presence
    + Set network boot option to the default last priority
    + MdeModulePkg: improve scalability of memory pools
    + MdeModulePkg: use correct granularity when allocating pool
* Fri Mar 06 2015
  - Update to R17007
    + ArmVirtualizationPkg: PlatformIntelBdsLib: lack of QEMU kernel
      is no error
    + Improve Xen support in Ovmf
    + ArmVirtualizationPkg: PlatformIntelBdsLib: display TianoCore
    + ArmVirtualizationPkg/ArmVirtualizationQemu: add USB keyboard
    + ArmVirtualizationPkg/ArmVirtualizationQemu: add VGA console
    + ArmVirtualizationPkg/ArmVirtualizationQemu: enable PCI support
    + OvmfPkg/QemuVideoDxe: enable ARM builds
    + Improve ACPI support in Ovmf
    + OvmfPkg/PlatformBdsLib: Signal ReadyToBoot before booting QEMU
    + ArmPkg/ArmLib.h: Add CPU Affinity definitions
    + OvmfPkg/SMBIOS: Provide default Type 0 (BIOS Information)
    + NetworkPkg: Code refine to avoid NULL pointer dereferenced
    + DHCP6 bug fix
    + BaseTools/GenFw: Set the PE/COFF attribute BaseOfData with the
      address of the first '.data' section
    + OvmfPkg: Update PlatformBaseDebugLibIoPort library
    + Various fixes for shell
  - Update ARM patches
* Fri Feb 06 2015
  - update to R16775
  - add RH patches for ARM
* Tue Jan 06 2015
  - Update to R16580
    + MdeModulePkg Variable: Implement VarCheck PROTOCOL and follow
      UEFI spec to check UEFI defined variables
    + ArmVirtualizationPkg: Intel BDS: load EFI-stubbed Linux kernel
      from fw_cfg
    + ArmVirtualizationPkg: identify "new shell" as builtin shell
      for Intel BDS
    + ArmVirtualizationPkg: PlatformIntelBdsLib: adhere to QEMU's
      boot order
    + OvmfPkg: QemuBootOrderLib: OFW-to-UEFI translation for
    + OvmfPkg: QemuBootOrderLib: widen ParseUnitAddressHexList() to
    + ArmVirtualizationPkg: VirtFdtDxe: use dedicated
    + OvmfPkg: introduce VIRTIO_MMIO_TRANSPORT_GUID
    + OvmfPkg: QemuBootOrderLib: featurize PCI-like device path
    + OvmfPkg: extract QemuBootOrderLib
    + ArmVirtualizationPkg: PlatformIntelBdsLib: add basic policy
    + ArmVirtualizationPkg: clone PlatformIntelBdsLib from
    + ArmVirtualizationPkg: introduce QemuFwCfgLib instance for DXE
    + ArmVirtualizationPkg: VirtFdtDxe: forward FwCfg addresses from
      DTB to PCDs
    + MdeModulePkg/FvSimpleFileSystem:Fix a potential NULL
      dereference issue
    + Correct the Hash Calculation for Revoked X.509 Certificate to
      align with RFC3280 and UEFI 2.4 Spec
    + MdeModulePkg/FvSimpleFileSystem: Add a new module to provide
      access to executable files in FVs
    + OvmfPkg: enable IPv6 support
    + Fix a bug that the gateway is not necessary in a simple PXE
    + ArmPkg/BdsLib: Update the size of the Device Tree before
      booting Linux
    + ArmPkg/BdsLib: Rework TFTP boot
    + MdePkg: UefiScsiLib: do not encode LUN in CDB for SCSI commands
    + Correct the alignment calculation of PE/COFF attribute
      certificate entry
    + OvmfPkg: CsmSupportLib: depend on OvmfPkg.dec explicitly
    + OvmfPkg: AcpiPlatformDxe: make dependency on PCI enumeration
    + MdePkg/MdeModulePkg: Implement the missing
      SetMemorySpaceCapabilities function
    + Various fixes for shell
  - Set the flag to enable IPv6 support
  - Refresh ovmf-embed-default-keys.patch
* Tue Nov 18 2014
  - Update to R16398
    + OvmfPkg: PlatformBdsLib: Dynamic PCI Interrupt Line register
    + SecurityPkg: VariableServiceSetVariable(): fix dbt <-> GUID
    + CryptoPkg: OpenSslSupport.h: edk2-ize offsetof() macro for
      gcc-4.8 / X64
    + CryptoPkg: TimestampTokenVerify(): fix gcc-4.8 / Ia32 build
    + UEFI 2.4 X509 Certificate Hash and RFC3161 Timestamp
      Verification support for Secure Boot
    + OvmfPkg: PlatformBdsLib: Platform dependent
      PCI/IRQ initialization
    + OvmfPkg: AcpiTimerLib: Split into multiple phase-specific
    + OvmfPkg: PlatformPei: Platform specific ACPI power management
    + OvmfPkg: Factor out platform detection (q35 vs. piix4)
    + UefiCpuPkg/CpuDxe: install Mp Service protocol
    + UefiCpuPkg/CpuDxe: introduce EFI_MP_SERVICES_PROTOCOL
    + ArmPkg/ArmGicLib: select GICv2 mode if SRE is present but
    + OvmfPkg/XenPvBlkDxe: Don't include system inttypes.h
    + ArmPlatformPkg: fix undefined reference to memcpy
    + CryptoPkg Updates to support RFC3161 timestamp signature
    + MdeModulePkg DxeCore/PiSmmCore: Add UEFI memory and SMRAM
      profile support
* Tue Nov 11 2014
  - Update to R16329
    + ArmPkg/ArmArchTimerLib: Promotes 32bit value to prevent
    + ArmPkg/CompilerIntrinsicesLib: Fixed memmove() and memset()
    + ArmPkg: Ensured the stack is always quad-word aligned
    + ArmPlatformPkg: Increase more ARM address Pcd entries to 64-bit
    + Fix execution status & DEBUG message level mismatch
    + OvmfPkg: set video resolution of text setup to 640x480
    + OvmfPkg: BDS: drop custom boot timeout, revert to
    + OvmfPkg: BDS: drop superfluous "connect first boot option"
    + OvmfPkg: BDS: optimize second argument in
      PlatformBdsEnterFrontPage() call
    + OvmfPkg: BDS: don't overwrite the BDS Front Page timeout
    + OvmfPkg: BDS: drop useless return statement
    + OvmfPkg: BDS: remove dead call to PlatformBdsEnterFrontPage()
    + BaseTools/GenFw: Fixed R_AARCH64_CALL26/R_AARCH64_JUMP26 when
      referring to start of a section
    + Various fixes for ShellPkg
    + Convert the assembly code in OVMF to NASM
    + MdeModulePkg/SecurityPkg Variable: Add boundary check for
      while (IsValidVariableHeader (Variable))
    + Add Xen support for OVMF
    + OvmfPkg: Add the MIT license to License.txt
    + ArmPkg/ArmLib: Removed duplicated invalidate TLB function
    + ArmPlatformPkg/ArmShellCmdRunAxf: Added 'runaxf' cmd to shell
  - Amend the spec file to use the system gcc version as the tool
    chain tag
* Wed Oct 22 2014
  - Update to R16226
    + ArmVirtualizationPkg: FdtPL011SerialPortLib: support
    + ArmPlatformPkg/ArmVirtualizationPkg: Added support for Intel
    + ArmPkg/ArmLib/AArch64: Initialize the new N+1-level page table
      before registering it
    + ArmPkg/UncachedMemoryAllocationLib: Track uncached memory
    + ArmPkg/ArmPsciResetSystemLib: Made the library only using SMC
    + ArmPlatformPkg/Bds: Reduce boot device entries
    + Various fixes for ShellPkg
    + OvmfPkg: disable stale fork of SecureBootConfigDxe
  - Drop upstreamed ovmf-use-generic-sb-config.patch



Generated by rpm2html 1.8.1

Fabrice Bellet, Sat Sep 9 14:56:11 2023