From nobody Mon Apr 29 02:30:00 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) client-ip=66.175.222.12; envelope-from=bounce+27952+50455+1787277+3901457@groups.io; helo=web01.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50455+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1573552891; cv=none; d=zoho.com; s=zohoarc; b=EBpovTaSYCQtdrl1CowGbrM7vRc/ymOWWP9PqVU6uuVuXCbbdIl53sW3f47VP21oLi1v3RiPCWKNU6iMepTqsVMuX/2SGEGwDjIcYMcUDB4hEm7KTIgYEjAa5MPlYDqiIy4MT98NqXvnL3in5Irs6Gh1dpWgHoXTWuqlgiA3mfg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zoho.com; s=zohoarc; t=1573552891; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Id:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=qB1htBLUV+yK4QfakgfTMM7C3eZMNCz5Prwh/1VhUWI=; b=dNCvvagnGh6VUvitBX40WHOWBNl7qUDxwuGCu4rmcs/C2ulU5+xpS8PLkeKe/6jz+lY7bWtaODM2SS+fmIh7fW8H/la7MhS2TN+zdoovwLEXMQ05iEvOy7G3FfK9k2KokBiaUBMqPQG2J36LUAs7IfVZ5u0iaBXq/8yRDpGsyHI= ARC-Authentication-Results: i=1; mx.zoho.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50455+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) header.from= Received: from web01.groups.io (web01.groups.io [66.175.222.12]) by mx.zohomail.com with SMTPS id 1573552891584367.4169639493422; Tue, 12 Nov 2019 02:01:31 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id iG4EYY1788612xYySkWE2UUM; Tue, 12 Nov 2019 02:01:31 -0800 X-Received: from us-smtp-delivery-1.mimecast.com (us-smtp-delivery-1.mimecast.com [205.139.110.61]) by mx.groups.io with SMTP id smtpd.web11.9963.1573552890403078767 for ; Tue, 12 Nov 2019 02:01:30 -0800 X-Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-346-vlJgWsayOQCGro3jpbECIQ-1; Tue, 12 Nov 2019 05:01:27 -0500 X-Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.phx2.redhat.com [10.5.11.15]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id DADC0107ACC5; Tue, 12 Nov 2019 10:01:26 +0000 (UTC) X-Received: from lacos-laptop-7.usersys.redhat.com (ovpn-116-207.ams2.redhat.com [10.36.116.207]) by smtp.corp.redhat.com (Postfix) with ESMTP id 1B658370E; Tue, 12 Nov 2019 10:01:25 +0000 (UTC) From: "Laszlo Ersek" To: edk2-devel-groups-io Cc: Liming Gao Subject: [edk2-devel] [edk2-wiki PATCH 1/3] Release Planning: fix typo in edk2-stable201911 tag name Date: Tue, 12 Nov 2019 11:01:21 +0100 Message-Id: <20191112100123.7200-2-lersek@redhat.com> In-Reply-To: <20191112100123.7200-1-lersek@redhat.com> References: <20191112100123.7200-1-lersek@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.15 X-MC-Unique: vlJgWsayOQCGro3jpbECIQ-1 X-Mimecast-Spam-Score: 0 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,lersek@redhat.com X-Gm-Message-State: I66wc2ooaiCYYOueIOoE8miIx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1573552891; bh=q64unar8kIqEpfowxxpweZvcWWl824IRp4x98lR9C3Q=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=msWM2IC8O21rqlCs4jpNZN91MWdVfra0VqipZCCbUS8V9mZcnRK0HkJxrgB9rtljIkd 1WN4e/GBw+oillb8YHLyfh5dNYsNheusTA45VFUke2xL/dbZ11ESgys97NcsO1Y8hbzlG 0E60iFnn5RjiUOfuy0hEEjJsF2IXU33rdY8= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Type: text/plain; charset="utf-8" The next stable tag name should be "edk2-stable201911", not "edk2-stable2019011". Cc: Liming Gao Signed-off-by: Laszlo Ersek Reviewed-by: Liming Gao --- EDK-II-Release-Planning.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/EDK-II-Release-Planning.md b/EDK-II-Release-Planning.md index 3cc92cadfe5a..e6148144cd91 100644 --- a/EDK-II-Release-Planning.md +++ b/EDK-II-Release-Planning.md @@ -1,4 +1,4 @@ -# edk2-stable2019011 tag planning +# edk2-stable201911 tag planning =20 ## Proposed Schedule =20 --=20 2.19.1.3.g30247aa5d201 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#50455): https://edk2.groups.io/g/devel/message/50455 Mute This Topic: https://groups.io/mt/54183798/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- From nobody Mon Apr 29 02:30:00 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) client-ip=66.175.222.12; envelope-from=bounce+27952+50457+1787277+3901457@groups.io; helo=web01.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50457+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1573552893; cv=none; d=zoho.com; s=zohoarc; b=SjbTcL7MSJMkhCQ3hlT77SCQlE4+9sRXAhBrePIy0GV+Kl5l341ApyB3SgJMjGECZNuKx0qQOMN+TP+PomhJvH4iKKF2mcKXx4+Banf3/NavnyfXVTBsdi+KjSAoBhZg8g5VpDO91hp748mpK7u1Od/QU2SKPOlQEji9IS5wG1w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zoho.com; s=zohoarc; t=1573552893; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Id:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=uhjpb/5KhTM0JIooykF5LY0hEsEk1v3fEbQyxsgyws4=; b=We2Xik/Bhz/GVdHP5IcJQ+Ewhh0HIw9FdZAOoVpaNmYqSpWdsmAhnBrh4Iju11CvjFrRtmXZFUa5Da+Y94T87Hv1HXqgg7Gjcbip1y3WbMll/jc1hKK942S/ffXTUd0SrnvOGUaY74rhER1P2cNlYDg/FboxK6ald6pJu4U/eLk= ARC-Authentication-Results: i=1; mx.zoho.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50457+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) header.from= Received: from web01.groups.io (web01.groups.io [66.175.222.12]) by mx.zohomail.com with SMTPS id 1573552893451289.86595364044683; Tue, 12 Nov 2019 02:01:33 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id uGucYY1788612xww4w6CwASY; Tue, 12 Nov 2019 02:01:33 -0800 X-Received: from us-smtp-1.mimecast.com (us-smtp-1.mimecast.com [207.211.31.120]) by mx.groups.io with SMTP id smtpd.web09.9933.1573552892457632878 for ; Tue, 12 Nov 2019 02:01:32 -0800 X-Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-255-fM9suYjQO06Zc0FH4IZC_Q-1; Tue, 12 Nov 2019 05:01:29 -0500 X-Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.phx2.redhat.com [10.5.11.15]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 00229801E51; Tue, 12 Nov 2019 10:01:28 +0000 (UTC) X-Received: from lacos-laptop-7.usersys.redhat.com (ovpn-116-207.ams2.redhat.com [10.36.116.207]) by smtp.corp.redhat.com (Postfix) with ESMTP id 3776162671; Tue, 12 Nov 2019 10:01:27 +0000 (UTC) From: "Laszlo Ersek" To: edk2-devel-groups-io Cc: Liming Gao Subject: [edk2-devel] [edk2-wiki PATCH 2/3] Release Planning: clean up CVE reference format Date: Tue, 12 Nov 2019 11:01:22 +0100 Message-Id: <20191112100123.7200-3-lersek@redhat.com> In-Reply-To: <20191112100123.7200-1-lersek@redhat.com> References: <20191112100123.7200-1-lersek@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.15 X-MC-Unique: fM9suYjQO06Zc0FH4IZC_Q-1 X-Mimecast-Spam-Score: 0 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,lersek@redhat.com X-Gm-Message-State: O6SwkUUsU2gIOAKosQI0waC6x1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1573552893; bh=KQfQcFMNSVdAMe2TPhkJ9Wcpcbz/Ywdk45ZnEycv56M=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=R6Ys7D44pCZzVA5tUTxCytl9XOAWFsMrLLUBQk3xafPgHi2VXQdRyLsaXRHKAOZiXRg quHd/rQzOm2kHjhMQ4u6NfUb6UZNS/Bua4cuIgEc6Vo/kz+VaDzwuovbOjxhysgleg79J 1uWsY6hRsG0k6+EPfrTvBJddTXl5UUu9v4Q= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Type: text/plain; charset="utf-8" When referring to the titles of such TianoCore BZs that are CVEs, we should use the following format: Subject (CVE-2019-...) Because in the following format: (CVE-2019-...) - Subject the CVE number is doubly separated from the subject (by parentheses, and by dash). Cc: Liming Gao Signed-off-by: Laszlo Ersek Reviewed-by: Liming Gao --- EDK-II-Release-Planning.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/EDK-II-Release-Planning.md b/EDK-II-Release-Planning.md index e6148144cd91..177cbbebe18c 100644 --- a/EDK-II-Release-Planning.md +++ b/EDK-II-Release-Planning.md @@ -22,7 +22,7 @@ * [Allow PCDs to be used in conditional statements if not referenced in an= INF](https://bugzilla.tianocore.org/show_bug.cgi?id=3D2270) * [Add Support Laml and Lasa for TPM2 ACPI](https://bugzilla.tianocore.org= /show_bug.cgi?id=3D978) * [Add PCI Device Security Support](https://bugzilla.tianocore.org/show_bu= g.cgi?id=3D2303) -* [(CVE-2019-11098) - BootGuard TOCTOU vulnerability](https://bugzilla.tia= nocore.org/show_bug.cgi?id=3D1614) +* [BootGuard TOCTOU vulnerability (CVE-2019-11098)](https://bugzilla.tiano= core.org/show_bug.cgi?id=3D1614) * TBD =20 # [edk2-stable201908 tag](https://github.com/tianocore/edk2/releases/tag/e= dk2-stable201908) --=20 2.19.1.3.g30247aa5d201 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#50457): https://edk2.groups.io/g/devel/message/50457 Mute This Topic: https://groups.io/mt/54183807/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- From nobody Mon Apr 29 02:30:00 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) client-ip=66.175.222.12; envelope-from=bounce+27952+50458+1787277+3901457@groups.io; helo=web01.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50458+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1573552895; cv=none; d=zoho.com; s=zohoarc; b=Nwi8zL9osONDe5YyvDOLVRyhxTytahFu0NQx0+EyYOSxldmY01hh2mohvjJW0p/XXVN2X4MKopDEjymXILa11MKDUeWelBqbGzOYc556rWcc1DwemkPyH1/42vFtECrIIvUbuQvT+0guO6jT547zwSI8xnBH9g40VjOobpyNY44= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zoho.com; s=zohoarc; t=1573552895; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Id:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=IeFJ0pXiv5lbD7EqqSE6hqmGp6CPR7w6TlRbj3ZeIG8=; b=LtUA+RKKsAxERYKjquUjse2EfwtbjC703M1mo8iRWTvT7SyoNmK1dao5qbyRW8HxI7DwE90mgSNHsHYDDliwLbF5o8kaWNJjs0Z94g7smOB66w+qAA7EQlSEtsUfdHa789GBZZqafhDbxreY4Ov1J+kIdQeiyW0j3mFtN7jqNq4= ARC-Authentication-Results: i=1; mx.zoho.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+50458+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) header.from= Received: from web01.groups.io (web01.groups.io [66.175.222.12]) by mx.zohomail.com with SMTPS id 1573552895146712.4625198542938; Tue, 12 Nov 2019 02:01:35 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id 6OOEYY1788612x2sUcqOyEqI; Tue, 12 Nov 2019 02:01:34 -0800 X-Received: from us-smtp-delivery-1.mimecast.com (us-smtp-delivery-1.mimecast.com [207.211.31.81]) by mx.groups.io with SMTP id smtpd.web09.9934.1573552894152719444 for ; Tue, 12 Nov 2019 02:01:34 -0800 X-Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-397-_rVDut7qOOKgWIKikJzrig-1; Tue, 12 Nov 2019 05:01:29 -0500 X-Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.phx2.redhat.com [10.5.11.15]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 2301B477; Tue, 12 Nov 2019 10:01:29 +0000 (UTC) X-Received: from lacos-laptop-7.usersys.redhat.com (ovpn-116-207.ams2.redhat.com [10.36.116.207]) by smtp.corp.redhat.com (Postfix) with ESMTP id 562BF61F58; Tue, 12 Nov 2019 10:01:28 +0000 (UTC) From: "Laszlo Ersek" To: edk2-devel-groups-io Cc: Liming Gao Subject: [edk2-devel] [edk2-wiki PATCH 3/3] Release Planning: reference BZ#960 (CVE-2019-14553) in edk2-stable201911 Date: Tue, 12 Nov 2019 11:01:23 +0100 Message-Id: <20191112100123.7200-4-lersek@redhat.com> In-Reply-To: <20191112100123.7200-1-lersek@redhat.com> References: <20191112100123.7200-1-lersek@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.15 X-MC-Unique: _rVDut7qOOKgWIKikJzrig-1 X-Mimecast-Spam-Score: 0 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,lersek@redhat.com X-Gm-Message-State: emYA6WIKqiSuqqOasyqWIQqWx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1573552894; bh=skNcRyIzgtVzpkYM0XlTreVV6zB9jooyf2W264c6Rt0=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=G0qD1OvrpyvPkt+hIMSEueVFABig2wYoxo/vocI43ptPlfrlaDkt/hFzxk0KEaq83mz 0AeSEDFCp4gM5oggbRPqeOjmNjIdjd0x74D+o0xHNeBO2eFELxSnF+xwfiATKm89RNYJ1 g7MS78AnCDs825zbK81cSBZKf2T44Pui7CA= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Type: text/plain; charset="utf-8" The fix for ticket (CVE-2019-14553) will be released in edk2-stable201911. Reference the ticket in the "Proposed Features" section. Cc: Liming Gao Signed-off-by: Laszlo Ersek Reviewed-by: Liming Gao --- EDK-II-Release-Planning.md | 1 + 1 file changed, 1 insertion(+) diff --git a/EDK-II-Release-Planning.md b/EDK-II-Release-Planning.md index 177cbbebe18c..961b63b0303a 100644 --- a/EDK-II-Release-Planning.md +++ b/EDK-II-Release-Planning.md @@ -23,6 +23,7 @@ * [Add Support Laml and Lasa for TPM2 ACPI](https://bugzilla.tianocore.org= /show_bug.cgi?id=3D978) * [Add PCI Device Security Support](https://bugzilla.tianocore.org/show_bu= g.cgi?id=3D2303) * [BootGuard TOCTOU vulnerability (CVE-2019-11098)](https://bugzilla.tiano= core.org/show_bug.cgi?id=3D1614) +* [Invalid server certificate accepted in HTTPS Boot (CVE-2019-14553)](htt= ps://bugzilla.tianocore.org/show_bug.cgi?id=3D960) * TBD =20 # [edk2-stable201908 tag](https://github.com/tianocore/edk2/releases/tag/e= dk2-stable201908) --=20 2.19.1.3.g30247aa5d201 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#50458): https://edk2.groups.io/g/devel/message/50458 Mute This Topic: https://groups.io/mt/54183813/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-