Re: [PATCH v2 1/4] tpm: tpm_ppi: fix zero-extension of negative error codes

From: Jarkko Sakkinen

Date: Thu Oct 08 2026 - 13:49:15 EST


On Thu, Oct 08, 2026 at 09:16:20AM +0800, Pei Xiao wrote:
> tpm_show_ppi_response() keeps its return value in an acpi_status,
> a typedef of u32. The two's complement of the error code is stored
> correctly there, but on return the value is converted to ssize_t and
> zero-extended, so the sign is lost: user space receives 0xFFFFFFEA
> (4294967274) instead of -EINVAL, which breaks the usual "ret < 0" error
> check.
> Declare the variable as ssize_t so that negative values survive the
> conversion.
>
> Fixes: 84b1667dea23 ("ACPI / TPM: replace open-coded _DSM code with helper functions")
> Assisted-by: GLM-5.3
> Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
> ---
> drivers/char/tpm/tpm_ppi.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/char/tpm/tpm_ppi.c b/drivers/char/tpm/tpm_ppi.c
> index c9793a3d986d..949fb7055bea 100644
> --- a/drivers/char/tpm/tpm_ppi.c
> +++ b/drivers/char/tpm/tpm_ppi.c
> @@ -234,7 +234,7 @@ static ssize_t tpm_show_ppi_response(struct device *dev,
> struct device_attribute *attr,
> char *buf)
> {
> - acpi_status status = -EINVAL;
> + ssize_t status = -EINVAL;
> union acpi_object *obj, *ret_obj;
> u64 req, res;
> struct tpm_chip *chip = to_tpm_chip(dev);
> --
> 2.25.1
>

OK, cool we went through this so

Reviewed-by: Jarkko Sakkinen <jarkko@xxxxxxxxxx>

Br, Jarkko