summaryrefslogtreecommitdiff
path: root/CryptoPkg/Library/BaseCryptLib
AgeCommit message (Collapse)AuthorFilesLines
2026-08-28CryptoPkg: Add Pkcs7Decrypt APIDoug Cook8-0/+305
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API. I expect that the primary use of Pkcs7Decrypt would be for testing the Pkcs7Encrypt API, but maybe somebody will need it for real work someday. Signed-off-by: Doug Cook <dcook@microsoft.com> Committed-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Encrypt OpenSSL and null implementationsDoug Flick8-0/+218
Add CryptPkcs7Encrypt.c with OpenSSL-based Pkcs7Encrypt() implementation using PKCS7_encrypt API. Add null stub implementations for library instances that do not support this function (PEI, Runtime, SEC, MbedTLS, Null). Update all BaseCryptLib INF files to include the new source files. Signed-off-by: Doug Flick <dougflick@microsoft.com>
2026-07-31CryptoPkg/BaseCryptLib: add AARCH64 host unit test Rand sourceJeff Brasen1-1/+4
The host-based BaseCryptLib instance (UnitTestHostBaseCryptLib.inf) built Rand/CryptRandTsc.c only for IA32/X64. Add Rand/CryptRand.c for AARCH64 so the openssl-backed RandomSeed() is available when linking AARCH64 host tests, and advertise AARCH64 in VALID_ARCHITECTURES. Signed-off-by: Jeff Brasen <jbrasen@nvidia.com>
2026-07-21CryptoPkg/BaseCryptLib: Add SLH-DSA SupportMichael G.A. Holland12-1/+1333
Created SLH-DSA API functions to configure public and private keys for SLH-DSA algorithm. This will allow users to sign and verify with SLH-DSA. Unit tests were added to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-20CryptoPkg/BaseCryptLib: ML-DSA updatesMichael G.A. Holland1-0/+4
Include validation check for Context and ContextSize in signature function. Updated ReadMe to show ML-DSA support Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-20CryptoPkg/BaseCryptLib: EdDsa updatesMichael G.A. Holland1-1/+9
Include validation checks for Context and ContextSize in sign and verify functions. Returned FALSE for EdDsaGeneratePubKey. Updated ReadMe to show EdDsa support Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-14CryptoPkg/BaseCryptLib: Add ML-DSA SupportMichael G.A. Holland12-0/+1328
Created ML-DSA API functions to configure public and private keys for ML-DSA algorithm. This will allow users to sign and verify with ML-DSA. Unit tests were add to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-01CryptoPkg/BaseCryptLib: Add ED448 verification and signature fcnsMichael G.A. Holland13-0/+1255
Implemented signature and verification functions for ED448; Updated documentation and unit tests to cover new verification functions Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-06-25CryptoPkg: Enable SHA256 hash in SecCryptLibSami Mujawar1-2/+2
Enable CryptSha256 hash in SecCryptLib as this is required by Arm CCA. The hash algorithm used by the Arm CCA Realm Extensible Measurement (REM) registers is either SHA256 or SHA512. To enable measurements in the early boot phase enable SHA256 hash algorithm in SecCryptLib. Signed-off-by: Sami Mujawar <sami.mujawar@arm.com>
2026-06-15CryptoPkg: Added lite version openssl libraryLee LonghaoX1-0/+3
Lite version OpensslLib base on OpensslLibFull but no-camellia, no -ecx and no-dh. It save the size about ~192KB. REF: Signed-off-by: Lee LonghaoX <longhaox.lee@intel.com>
2026-05-29CryptoPkg: Fix leaks and failure-path mutation of RSA-owned valuesMingjie Shen1-147/+309
RsaSetKey passed RSA-internal BIGNUMs (returned by RSA_get0_key / RSA_get0_factors / RSA_get0_crt_params as const) directly to BN_bin2bn, which mutates its destination in place. This violates the OpenSSL API contract and can leave RsaContext in a partially modified state on failure paths: BN_bin2bn has already overwritten one of n / e / d / p / q / dp / dq / qInv, the function then returns FALSE on a subsequent BN_dup or RSA_set0_* failure, and the caller has no indication that the RSA object was silently changed. The same paths also leaked temporary BIGNUMs allocated by BN_bin2bn or BN_new. This patch splits RsaSetKey into a small input-validating dispatcher plus three static helpers (RsaSetKeyNED, RsaSetKeyFactors, RsaSetKeyCrtParams), one per RSA_set0_* setter. Each helper: - Allocates a fresh BIGNUM for the slot being set via BN_bin2bn(BigNumber, BnSize, NULL); the NULL destination forces BN_bin2bn to allocate so no RSA-owned BIGNUM is mutated. - Reads the current RSA state via RSA_get0_* purely for inspection. - For slots not being set, passes NULL when RSA already has a value (preserves it) or supplies an empty BN_new() placeholder when RSA's slot is still NULL. - Atomically installs via RSA_set0_*, which takes ownership of every non-NULL argument on success and of none on failure. - Routes all exits through a single label that frees any locally held BIGNUM. Memory leaks in the early-return paths are fixed as a consequence. The previous BN_dup calls are no longer needed and are removed. Signed-off-by: Mingjie Shen <shen497@purdue.edu>
2026-04-07CryptoPkg: Add digest-based RSA-PSS sign and verify APIsBaraneedharan Anbazhagan3-0/+286
Add RsaPssSignDigest() and RsaPssVerifyDigest() to BaseCryptLib for signing/verifying precomputed digests. Provide OpenSSL/MbedTLS/Null implementations, expose via EDKII_CRYPTO_PROTOCOL (v24), and add PCD controls for independent service enabling. Include unit tests. Signed-off-by: Anbazhagan Baraneedharan <anbazhagan@hp.com>
2026-03-10CryptoPkg: BaseCryptLib: Reject empty X.509 cert when retrieving public keyKun Qin1-0/+16
Explicitly reject zero-length X.509 certificate buffers when retrieving a public key. For this invalid case, the input context pointer is set to NULL as a defensive measure. Signed-off-by: Kun Qin <kun.qin@microsoft.com>
2026-02-24CryptoPkg: add EC algorithm for SmmCryptLibLevi Yun1-1/+1
This patch prepares the build infrastructure for the TCG TPM 2.0 implementation [0]. By default, it uses the OpenSSL EC_* APIs. When the TCG TPM 2.0 implementation [0] is used in StandaloneMm, EC algorithm support is required in SmmCryptLib. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add/modify EC interfaces for TPM TCG libraryLevi Yun2-0/+232
This is prepartion patch to build TCG TPM v2.0 Reference Library[0]. TCG TPM v2.0 implementation[0] uses below additional interfaces: - EC_GROUP_new_curve_GFp() - EC_GROUP_set_generator() - EC_POINTs_mul() and require EC_POINT_mul()'s n arguments (Scalar multiplier for the generator G) but EDKII's EcPointMul() interface always fix this value as NULL. For TCG TPM v2.0 implementation, add new interfaces. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add some Bn interfaces to build TCG TPM libraryLevi Yun2-0/+277
This is preparation patch for build TCG TPM v2.0 implementation[0]. To build TCG TPM v2.0 implementation[0], below Bn interfaces are required: - BN_CTX_start() -> BigNumContextStart() - BN_CTX_end() -> BigNumContextEnd() - BN_CTX_get() -> BigNumContextGet() - BN_mul() -> BigNumMul() - BN_Gcd() -> BigNumGcd() and add BigNumDiv2() to receive remain too. Link: https://github.com/TrustedComputingGroup/TPM[0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add CAMELLIA APIs for TCG TPM reference libraryLevi Yun8-0/+295
This is preparation patch to build TCG TPM v2.0 implementation [0]. TCG TPM v2.0 uses below Camellia APIs: - Camellia_set_key() - Camellia_encrypt() - Camellia_decrypt() To support these CAMELLIA interfaces, add related wrapper in BaseCryptLib. Link: https://github.com/TrustedComputingGroup/TPM [0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: add AES_encrypt/AES_decrpyt for TPM reference libraryLevi Yun2-0/+156
This is preparation patch to build TCG TPM v2.0 implementation [0]. TCG TPM v2.0 uses AES_encrypt()/AES_decrpyt() in openssl library to implement its crypto operation. For this, add wrapper for AES_encrypt()/AES_decrpyt(). Link: https://github.com/TrustedComputingGroup/TPM[0] Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
2026-02-24CryptoPkg: Replace include guards with #pragma onceMichael Kubacki2-8/+2
Replace traditional `#ifndef`/`#define`/`#endif` include guards with `#pragma` once. `#pragma once` is a widely supported preprocessor directive that prevents header files from being included multiple times. It is supported by all toolchains used to build edk2: GCC, Clang/LLVM, and MSVC. Does not include updates to OpenSSL generated header files checked into the repo. Those in `CryptoPkg\Library\OpensslLib\OpensslGen\`. Compared to macro-based include guards, `#pragma once`: - Eliminates the risk of macro name collisions or copy/paste errors where two headers inadvertently use the same guard macro. - Eliminate inconsistency in the way include guard macros are named (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.). - Reduces boilerplate (three lines replaced by one). - Avoids polluting the macro namespace with guard symbols. - Can improve build times as the preprocessor can skip re-opening the file entirely, rather than re-reading it to find the matching `#endif` ("multiple-include optimization"). - Note that some compilers may already optimize traditional include guards, by recognzining the idiomatic pattern. This change is made acknowledging that overall portability of the code will technically be reduced, as `#pragma once` is not part of the C/C++ standards. However, this is considered acceptable given: 1. edk2 already defines a subset of supported compilers in BaseTools/Conf/tools_def.template, all of which have supported `#pragma once` for over two decades. 2. There have been concerns raised to the project about inconsistent include guard naming and potential macro collisions. Approximate compiler support dates: - MSVC: Supported since Visual C++ 4.2 (1996) - GCC: Supported since 3.4 (2004) (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html) - Clang (LLVM based): Since initial release in 2007 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2025-09-26CryptoPkg: Drop ARM32 SupportOliver Smith-Denny4-18/+3
edk2 is dropping support for the ARM32 architecture. This commit removes ARM32 code from CryptoPkg. This also drops irrelevant VALID_ARCHITECTURES comments from infs that are not arch specific. Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2025-09-19CryptoPkg/BaseCryptLib: Fix MODULE_TYPE for unit testsMichael D Kinney1-2/+2
Update INF for BaseCryptLib used with host based unit tests to use a MODULE_TYPE of HOST_APPLICATION to make sure the correct compiler/linker flags are used. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2025-09-19CryptoPkg/BaseCryptLib: Remove tolower() for unit testsMichael D Kinney1-26/+0
tolower() is always provided by the standard C library. Remove the implementation of tolower() from UnitTestHostCrtWrapper.c that is only used when building host based unit tests. PR https://github.com/tianocore/edk2/pull/11217 attempted to resolve this issue by renaming tolower() to avoid duplicate symbols. This change removes this workaround as well. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2025-08-07CryptoPkg: workaround for MSVC linking tolowerAlexander Gryanko1-0/+13
Currently when building NOOPT tests in MSVC, the linker cannot pick the correct tolower for the host runtime. A small workaround to make the build work in MSVC. Signed-off-by: Alexander Gryanko <xpahos@gmail.com>
2025-07-17CryptoPkg/CrtLib: add strpbrk implementationGerd Hoffmann1-0/+19
Needed by openssl-3.5.1. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2025-05-27SPDM related fix based on real hardware testing - CryptoPkgLiqi Qi2-2/+4
Implemented SPDM functionality on real hardware, and here is the bug fix in CryptoPkg. The changes are ported from DMTF/libspdm@425345b. Signed-off-by: liqiqi@microsoft.com <liqiqi@microsoft.com>
2025-05-25CryptoPkg: Fix memory leak in RsaSetKeyBaraneedharan Anbazhagan1-8/+32
Memory allocated by BN_new calls isn't deallocated within RsaSetKey. Signed-off-by: Anbazhagan Baraneedharan <anbazhagan@hp.com>
2025-04-21CryptoPkg: Resolve CodeQL ErrorsOliver Smith-Denny7-5/+44
This patch updates several CodeQL errors for potential null pointer access and unguarded header conclusion across production and test code that have been flagged in the build/security tab in GitHub. Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2025-01-13CryptoPkg/BaseCryptLib: Fix mktime() coding style issueMichael D Kinney1-9/+9
Move local variable init to C statements to follow coding standard and remove the use of field names in structure initialization to maximize compiler compatibility. This issue was introduced by PR #6185 Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2024-12-06CryptoPkg/BaseCryptLib: add next parameter to SHA3_squeezeGerd Hoffmann2-2/+3
Needed for openssl 3.3. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-11-08CryptoPkg/BaseCryptLib: Fix serial number read overrunMichael D Kinney1-1/+1
Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2024-11-05CryptoPkg: Increase ScratchMemory buffer for openssl 3.0.15Jorge Ramirez-Ortiz1-1/+1
Openssl 3.0.15 has a larger memory footprint. Updating from EDK 2022.2 (openssl 1.1.j) to 2024.2 (openssl 3.0.15) causes our EFI provisioning application[1] to fail due to an out of memory condition. On inspection, at the time of that fault, 2022.2 had an additional 900 pages. This is why this patch proposes the increase of the ScratchMemory buffer by that same ammount. [1] https://git.kernel.org/pub/scm/linux/kernel/git/jejb/efitools.git Signed-off-by: Jorge Ramirez-Ortiz <jorge@foundries.io>
2024-11-01CryptoPkg: Updated the missed architectures.INDIA\kanagavels1-1/+1
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4838 Updated the missed architectures in PeiCryptLib.inf file. Signed-off-by: Kanagavel S <kanagavels@ami.com>
2024-09-27CryptoPkg: Fix unused variable in CryptX509.cMike Beaton1-2/+1
Without this change we get: error: variable 'Index' set but not used when building on XCODE5. Co-authored-by: Savva Mitrofanov <savvamtr@gmail.com> Signed-off-by: Mike Beaton <mjsbeaton@gmail.com>
2024-09-25CrtLibSupport: add timezoneGerd Hoffmann3-1/+6
Will be needed by openssl-3.2.x Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-09-25CrtLibSupport: add mktime()Gerd Hoffmann2-0/+26
Will be needed by openssl-3.2.x Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-09-25CrtLibSupport: factor out EFI_TIME -> time_t calculation to new functionGerd Hoffmann1-19/+32
No functional change. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-09-25CrtLibSupport: fix gettimeofday()Gerd Hoffmann3-0/+33
Turn gettimeofday() into a proper function with return value. Will be needed by openssl-3.2.x Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-09-25CrtLibSupport: add sleep()Gerd Hoffmann3-0/+26
Will be needed by openssl-3.2.x Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2024-08-29CryptoPkg: Support BrainpoolP512r1 algorithmMichael G.A. Holland1-0/+9
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4830 Allow BrainpoolP512r1 to be leveraged when the corresponding curve ID is passed to crypto libraries in EDK2 Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2024-06-26CryptoPkg: Fix wrong comment for CryptoPkgWenxing Hou1-9/+9
Fix the wrong comment. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Yi Li <yi1.li@intel.com> Signed-off-by: Wenxing Hou <wenxing.hou@intel.com>
2024-06-07CryptoPkg: Fix BaseCryptLib CrtWrapper strncpy and strcatSebastian Witt1-1/+40
Following https://bugzilla.tianocore.org/show_bug.cgi?id=2817 this bug could also apply to strncpy and strcat. For strncpy use count+1 if smaller than MAX_STRING_SIZE. This still restricts the destination size to MAX_STRING_SIZE as before but allows a strncpy when the source is close after destination without triggering the InternalSafeStringNoAsciiStrOverlap check in AsciiStrnCpyS. For strcat use the destination string length + the size of the source string including the terminator as destination size if smaller than MAX_STRING_SIZE. Also move both functions to CrtWrapper.c as they do not return the correct return value. AsciiStrnCpyS and AsciiStrCatS return RETURN_VALUE instead of a char * to the destination buffer. Signed-off-by: Sebastian Witt <sebastian.witt@siemens.com>
2024-06-07CryptoPkg: Fix BaseCryptLib CrtWrapper strcpySebastian Witt1-1/+1
strcpy fails when strSource is closer than 4096 bytes after strDest. This is caused by an overlap check in AsciiStrCpyS: // // 5. Copying shall not take place between objects that overlap. // SAFE_STRING_CONSTRAINT_CHECK (InternalSafeStringNoAsciiStrOverlap (Destination, DestMax, (CHAR8 *)Source, SourceLen + 1), RETURN_ACCESS_DENIED); Since DestMax is MAX_STRING_SIZE (0x1000) and with a Source that is in this area behind Destination, AsciiStrCpyS will fail and strcpy will do nothing. When called by CRYPTO_strdup in openssl this leads to uninitialzed memory that gets accessed instead of the copied string. BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2817 Signed-off-by: Sebastian Witt <sebastian.witt@siemens.com>
2024-06-06CryptoPkg: Fix wrong logic in X509GetTBSCertWenxing Hou1-2/+2
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4509 Both return 0x80 value and Asn1Tag != V_ASN1_SEQUENCE are wrong return. Signed-off-by: Wenxing Hou <wenxing.hou@intel.com>
2024-06-03CryptoPkg/BaseCryptLib: Enable more functions for SMM/StandaloneMMNhi Pham1-3/+3
This facilitates RSA extension, PKCS7 sign, and bignum function to broaden the range of algorithms available in SMM/StandaloneMM for platform utilization. Signed-off-by: Nhi Pham <nhi@os.amperecomputing.com>
2024-05-31CryptoPkg: Remove deprecated code related to SHA-1Shang Qingyu2-16/+0
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4698 The default drbg type of randlib has been switched to aes_256_ctr in openssl1.1.1, so sha1 is not really used in RandomSeed(). Remove related code which do SHA-1 support checking in CryptRand.c and CryptRandTsc.c to avoid potential compatibility errors. Cc: Jiewen Yao <jiewen.yao@intel.com> Signed-off-by: Shang Qingyu <qingyu.shang@intel.com> Reviewed-by: Yi Li <yi1.li@intel.com>
2024-05-31CryptoPkg: Fix bug for correct return value checking when get X509CertQingyu1-3/+3
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4509 CryptX509.c file has X509GetTBSCert() funtion and it is added Inf variable to collect the return value of ASN1_get_object(), which return 0x80 in error case. Supplement the return value check during the second function call and correct the check logic. Signed-off-by: Qingyu <qingyu.shang@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Reviewed-by: Yi Li <yi1.li@intel.com>
2024-04-07CryptoPkg/BaseCryptLib: add additional RSAES-OAEP crypto functionsChris Ruffin2-49/+679
Expand the availability of the RSAES-OAEP crypto capability in BaseCryptLib. Applications using RSA crypto functions directly from OpensslLib can transition to BaseCryptLib to take advantage of the shared crypto feature in CryptoDxe. Pkcs1v2Decrypt(): decryption using DER-encoded private key RsaOaepEncrypt(): encryption using RSA contexts RsaOaepDecrypt(): decryption using RSA contexts Fixes: https://bugzilla.tianocore.org/show_bug.cgi?id=4732 Gihub PR: https://github.com/tianocore/edk2/pull/5473 Signed-off-by: Chris Ruffin <v-chruffin@microsoft.com> Cc: Chris Ruffin <cruffin@millcore.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Yi Li <yi1.li@intel.com> Cc: Wenxing Hou <wenxing.hou@intel.com> Reviewed-by: Yi Li <yi1.li@intel.com>
2023-09-07CryptoPkg/BaseCryptLib: add sha384 and sha512 to ImageTimestampVerifySheng Wei1-1/+2
Register and initialize sha384/sha512 digest algorithms for PKCS#7 Handling. REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3413 Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Min Xu <min.m.xu@intel.com> Cc: Zeyi Chen <zeyi.chen@intel.com> Cc: Fiona Wang <fiona.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Cc: Michael D Kinney <michael.d.kinney@intel.com> Signed-off-by: Sheng Wei <w.sheng@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2023-08-09CryptoPkg: remove strcmp to syscallYi Li1-0/+9
In rare cases the platform may not provide the full IntrinsicLib. But openssl30 build always require strcmp, provide this function by moving it into CrtWrapper.c. Signed-off-by: Yi Li <yi1.li@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com> Acked-by: Ard Biesheuvel <ardb@kernel.org> Tested-by: Ard Biesheuvel <ardb@kernel.org> Tested-by: Brian J. Johnson <brian.johnson@hpe.com> Tested-by: Kenneth Lautner <klautner@microsoft.com>
2023-08-09CryptoPkg/BaseCryptLib: drop BIO_* dummy functionsGerd Hoffmann2-52/+0
openssl 3.0 requires a functional BIO_sprintf() implementation. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com> Acked-by: Ard Biesheuvel <ardb@kernel.org> Tested-by: Ard Biesheuvel <ardb@kernel.org> Tested-by: Brian J. Johnson <brian.johnson@hpe.com> Tested-by: Kenneth Lautner <klautner@microsoft.com>