Re: [PATCH 4/5] tpm: fix zero-length read discarding the pending response

From: Jarkko Sakkinen

Date: Mon Oct 05 2026 - 01:11:44 EST


On Sat, Oct 03, 2026 at 04:27:54PM +0800, Pei Xiao wrote:
> POSIX requires that a read() with a count of zero returns zero and
> has no other effects. tpm_common_read() treats such a call as a
> consumed response: it marks the pending response as read and drops
> it, so the response can never be retrieved; subsequent reads return
> zero and the next write() is allowed to overwrite the response
> buffer, silently breaking the command/response pairing of the TPM
> character devices.
>
> Return early when the caller passes a zero count, leaving any
> pending response untouched for the next read. A zero-length read
> will not report a deferred asynchronous error; POSIX permits read()
> to skip error detection for a zero count.
>
> Fixes: 9488585b21be ("tpm: add support for partial reads")
> Assisted-by: GLM-5.3
> Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
> ---
> drivers/char/tpm/tpm-dev-common.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/char/tpm/tpm-dev-common.c b/drivers/char/tpm/tpm-dev-common.c
> index f942c0c8e402..6569212dc6b8 100644
> --- a/drivers/char/tpm/tpm-dev-common.c
> +++ b/drivers/char/tpm/tpm-dev-common.c
> @@ -134,6 +134,9 @@ ssize_t tpm_common_read(struct file *file, char __user *buf,
> ssize_t ret_size = 0;
> int rc;
>
> + if (!size)
> + return 0;
> +
> mutex_lock(&priv->buffer_mutex);
>
> if (priv->response_length) {
> --
> 2.25.1
>

This look good to me, thanks.

Reviewed-by: Jarkko Sakkinen <jarkko@xxxxxxxxxx>

Br, Jarkko