On Thu, Oct 01, 2026 at 08:01:11AM +0200, A. Sverdlin wrote:
> From: Alexander Sverdlin <[email protected]>
> 
> tpm2_probe() reads the protocol version from the response tag and is
> documented to return -errno on failure, but it always returns 0.  A
> transport error (tpm_transmit_cmd() < 0) is thus swallowed together with
> the intentionally ignored TPM response code, leaving TPM_CHIP_FLAG_TPM2
> unset. A transient bus failure on the first command then misdetects a
> TPM 2.0 as a 1.2 and the probe fails on the TPM 1.2 path:
> 
>   tpm_tis_i2c 0-002e: 1.2 TPM (device-id 0x1C, rev-id 22)
>   tpm tpm0: A TPM error (-62) occurred attempting to determine the timeouts
> 
> Return the transport error instead; rc >= 0 still means a valid header was
> received and the TPM's own response code is still ignored.
> 
> Fixes: 94e266ba1fa3 ("tpm: migrate tpm2_probe() to use struct tpm_buf")
> Cc: [email protected]
> Signed-off-by: Alexander Sverdlin <[email protected]>
> ---
>  drivers/char/tpm/tpm2-cmd.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c
> index a94f4395c198a..4b2bb2ddc321a 100644
> --- a/drivers/char/tpm/tpm2-cmd.c
> +++ b/drivers/char/tpm/tpm2-cmd.c
> @@ -483,8 +483,9 @@ int tpm2_probe(struct tpm_chip *chip)
>               out = (struct tpm_header *)buf->data;
>               if (be16_to_cpu(out->tag) == TPM2_ST_NO_SESSIONS)
>                       chip->flags |= TPM_CHIP_FLAG_TPM2;
> +             return 0;
>       }
> -     return 0;
> +     return rc;
>  }
>  EXPORT_SYMBOL_GPL(tpm2_probe);
>  
> -- 
> 2.55.0
> 

Reviewed-by: Jarkko Sakkinen <[email protected]>

Thanks.

Br, Jarkko

Reply via email to