Re: [PATCH v2 1/2] keys/trusted_keys: return immediately after TPM unseal failure

From: Jarkko Sakkinen

Date: Wed Sep 09 2026 - 18:12:45 EST


On Thu, Sep 03, 2026 at 04:33:04AM +0530, Srish Srinivasan wrote:
> trusted_tpm_unseal() proceeds to pcrlock() when the TPM unseal operation
> fails. If pcrlock() succeeds, its return value overwrites the unseal error,
> causing key instantiation to succeed.
>
> Return immediately when unseal fails to preserve the original error.
>
> Fixes: 5d0682be3189 ("KEYS: trusted: Add generic trusted keys framework")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Srish Srinivasan <ssrish@xxxxxxxxxxxxx>
> ---
> security/keys/trusted-keys/trusted_tpm1.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trusted-keys/trusted_tpm1.c
> index bf0bf7f36970..9cdfeea800a3 100644
> --- a/security/keys/trusted-keys/trusted_tpm1.c
> +++ b/security/keys/trusted-keys/trusted_tpm1.c
> @@ -923,8 +923,10 @@ static int trusted_tpm_unseal(struct trusted_key_payload *p, char *datablob)
> ret = tpm2_unseal_trusted(chip, p, options);
> else
> ret = key_unseal(p, options);
> - if (ret < 0)
> + if (ret < 0) {
> pr_info("key_unseal failed (%d)\n", ret);
> + goto out;
> + }
>
> if (options->pcrlock) {
> ret = pcrlock(options->pcrlock);
> --
> 2.53.0
>


Reviewed-by: Jarkko Sakkinen <jarkko@xxxxxxxxxx>

BR, Jarkko