tpm_show_ppi_response() stores its return value in an acpi_status,
a typedef of u32.  Both error paths of the function (-EINVAL on a
malformed _DSM package, -EFAULT on a non-zero operation return
code) end up as huge positive values when returned as ssize_t, so
user space cannot detect the failure with the usual "ret < 0"
check.

Declare the variable as ssize_t to match the show callback's
return type.

Fixes: 84b1667dea23 ("ACPI / TPM: replace open-coded _DSM code with helper 
functions")
Assisted-by: GLM-5.3
Signed-off-by: Pei Xiao <[email protected]>
---
 drivers/char/tpm/tpm_ppi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/char/tpm/tpm_ppi.c b/drivers/char/tpm/tpm_ppi.c
index c9793a3d986d..949fb7055bea 100644
--- a/drivers/char/tpm/tpm_ppi.c
+++ b/drivers/char/tpm/tpm_ppi.c
@@ -234,7 +234,7 @@ static ssize_t tpm_show_ppi_response(struct device *dev,
                                     struct device_attribute *attr,
                                     char *buf)
 {
-       acpi_status status = -EINVAL;
+       ssize_t status = -EINVAL;
        union acpi_object *obj, *ret_obj;
        u64 req, res;
        struct tpm_chip *chip = to_tpm_chip(dev);
-- 
2.25.1


Reply via email to