[PATCH 1/5] tpm: tpm_ppi: fix wrong error code returned to user space
From: Pei Xiao
Date: Sat Oct 03 2026 - 04:31:04 EST
tpm_show_ppi_response() stores its return value in an acpi_status,
a typedef of u32. Both error paths of the function (-EINVAL on a
malformed _DSM package, -EFAULT on a non-zero operation return
code) end up as huge positive values when returned as ssize_t, so
user space cannot detect the failure with the usual "ret < 0"
check.
Declare the variable as ssize_t to match the show callback's
return type.
Fixes: 84b1667dea23 ("ACPI / TPM: replace open-coded _DSM code with helper functions")
Assisted-by: GLM-5.3
Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
---
drivers/char/tpm/tpm_ppi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/char/tpm/tpm_ppi.c b/drivers/char/tpm/tpm_ppi.c
index c9793a3d986d..949fb7055bea 100644
--- a/drivers/char/tpm/tpm_ppi.c
+++ b/drivers/char/tpm/tpm_ppi.c
@@ -234,7 +234,7 @@ static ssize_t tpm_show_ppi_response(struct device *dev,
struct device_attribute *attr,
char *buf)
{
- acpi_status status = -EINVAL;
+ ssize_t status = -EINVAL;
union acpi_object *obj, *ret_obj;
u64 req, res;
struct tpm_chip *chip = to_tpm_chip(dev);
--
2.25.1