Re: [PATCH v2 0/4] tpm: some tpm small fixes.

From: Pei Xiao

Date: Thu Oct 08 2026 - 21:01:29 EST




在 2026/10/9 01:51, Jarkko Sakkinen 写道:
> On Thu, Oct 08, 2026 at 09:16:19AM +0800, Pei Xiao wrote:
>> This series fixes several small issues found during a code review of
>> drivers/char/tpm:
>>
>> 1. tpm_ppi: tpm_show_ppi_response() stores its return value in an
>> acpi_status (a u32 typedef), so error codes such as -EINVAL reach
>> user space as huge positive values. Declare the variable as
>> ssize_t to match the show callback's return type.
>>
>> 2. tpm_nsc: tpm_nsc_remove() doubles as the release callback of the
>> hand-created platform device and dereferences the chip drvdata
>> unconditionally; init failures before tpmm_chip_alloc() crash
>> module load. Return early when the chip has not been created.
>>
>> 3. tpm_nsc: the cleanup runs twice on module exit because
>> tpm_nsc_remove() is both the explicit cleanup and the device
>> release callback; the second run operates on an already freed
>> chip. Stop overriding the release callback, which also stops the
>> platform object allocation from leaking.
>>
>> 4. tpm_dev: a zero-length read() discards a pending response,
>> breaking the command/response pairing of the TPM character
>> devices, although POSIX requires zero-count reads to have no side
>> effects. Return early on a zero count.
>>
>> chhanges in v2:
>> 1.add reviewed-by tag
>> 2.remove patch 5:
>> make the tpm_init() error messages consistently prefixed with "tpm: " and
>> report the actual failure of tpm_dev_common_init().
>> 3.modify patch 1 git commit information.
>>
>> Pei Xiao (4):
>> tpm: tpm_ppi: fix zero-extension of negative error codes
>> tpm: tpm_nsc: fix NULL pointer dereference on init failure
>> tpm: tpm_nsc: stop using the cleanup callback as dev.release
>> tpm: fix zero-length read discarding the pending response
>>
>> drivers/char/tpm/tpm-dev-common.c | 3 +++
>> drivers/char/tpm/tpm_nsc.c | 8 ++++++--
>> drivers/char/tpm/tpm_ppi.c | 2 +-
>> 3 files changed, 10 insertions(+), 3 deletions(-)
>>
>> --
>> 2.25.1
>>
>
> Right, so I've already applied some of the patches so I'm a bit
> confused what to do with this.
>
> See:
>
> https://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd.git/log/
>
> Is there something wrong in the ones that I already applied?
hi Jarkko,
Because this patch ("tpm: tpm_ppi: fix zero-extension of negative
error codes") did not pass review, I resend a v2 version that includes
the patches that have already passed review and carries their
Reviewed-by tags.

Pei.
thanks!>
> Br, Jarkko