From: Jarkko Sakkinen <jarkko@kernel.org>
To: Pei Xiao <xiaopei01@kylinos.cn>
Cc: Jarkko Sakkinen <jarkko.sakkinen@iki.fi>,
peterhuewe@gmx.de, jgg@ziepe.ca, linux-integrity@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/5] tpm: tpm_ppi: fix wrong error code returned to user space
Date: Mon, 5 Oct 2026 10:42:47 +0300 [thread overview]
Message-ID: <asNU92oQXJcolDdy@kernel.org> (raw)
In-Reply-To: <42828ffb-d2c4-4f31-88d0-c4b939631ab8@kylinos.cn>
On Mon, Oct 05, 2026 at 02:17:23PM +0800, Pei Xiao wrote:
>
>
> 在 2026/10/5 12:16, Jarkko Sakkinen 写道:
> > On Sat, Oct 03, 2026 at 04:27:51PM +0800, Pei Xiao wrote:
> >> tpm_show_ppi_response() stores its return value in an acpi_status,
> >> a typedef of u32. Both error paths of the function (-EINVAL on a
> >> malformed _DSM package, -EFAULT on a non-zero operation return
> >> code) end up as huge positive values when returned as ssize_t, so
> >> user space cannot detect the failure with the usual "ret < 0"
> >> check.
> >
> > I have no idea what you mean by huge value and why that would be
> > a problem, and overall this is disconnected from the code change.
> >
> > Two's complement value is correctly stored in status up until the
> > ssize_t cast, which results the value to be zero-extended, and
> > as a result corrupt the negative values.
> How does the following Git commit message look:
>
> tpm: tpm_ppi: fix zero-extension of negative error codes
>
> tpm_show_ppi_response() keeps its return value in an acpi_status,
> a typedef of u32. The two's complement of the error code is stored
> correctly there, but on return the value is converted to ssize_t and
> zero-extended, so the sign is lost: user space receives 0xFFFFFFEA
> (4294967274) instead of -EINVAL, which breaks the usual "ret < 0" error
> check.
> Declare the variable as ssize_t so that negative values survive the
> conversion.
Works for me. It does not have to be perfect as long as it points out
to the right direction.
> >
> >>
> >> Declare the variable as ssize_t to match the show callback's
> >> return type.
> >>
> >> Fixes: 84b1667dea23 ("ACPI / TPM: replace open-coded _DSM code with helper functions")
> >> Assisted-by: GLM-5.3
> >> Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
> >> ---
> >> drivers/char/tpm/tpm_ppi.c | 2 +-
> >> 1 file changed, 1 insertion(+), 1 deletion(-)
> >>
> >> diff --git a/drivers/char/tpm/tpm_ppi.c b/drivers/char/tpm/tpm_ppi.c
> >> index c9793a3d986d..949fb7055bea 100644
> >> --- a/drivers/char/tpm/tpm_ppi.c
> >> +++ b/drivers/char/tpm/tpm_ppi.c
> >> @@ -234,7 +234,7 @@ static ssize_t tpm_show_ppi_response(struct device *dev,
> >> struct device_attribute *attr,
> >> char *buf)
> >> {
> >> - acpi_status status = -EINVAL;
> >> + ssize_t status = -EINVAL;
> >> union acpi_object *obj, *ret_obj;
> >> u64 req, res;
> >> struct tpm_chip *chip = to_tpm_chip(dev);
> >> --
> >> 2.25.1
> >>
> >
> > Br, Jarkko
>
Br, Jarkko
next prev parent reply other threads:[~2026-10-05 7:42 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 8:27 [PATCH 0/5] tpm: assorted fixes and cleanups Pei Xiao
2026-10-03 8:27 ` [PATCH 1/5] tpm: tpm_ppi: fix wrong error code returned to user space Pei Xiao
2026-10-05 4:16 ` Jarkko Sakkinen
2026-10-05 6:17 ` Pei Xiao
2026-10-05 7:42 ` Jarkko Sakkinen [this message]
2026-10-03 8:27 ` [PATCH 2/5] tpm: tpm_nsc: fix NULL pointer dereference on init failure Pei Xiao
2026-10-05 4:18 ` Jarkko Sakkinen
2026-10-03 8:27 ` [PATCH 3/5] tpm: tpm_nsc: stop using the cleanup callback as dev.release Pei Xiao
2026-10-05 4:19 ` Jarkko Sakkinen
2026-10-03 8:27 ` [PATCH 4/5] tpm: fix zero-length read discarding the pending response Pei Xiao
2026-10-05 5:11 ` Jarkko Sakkinen
2026-10-03 8:27 ` [PATCH 5/5] tpm: fix log messages in tpm_init() Pei Xiao
2026-10-05 3:46 ` Jarkko Sakkinen
2026-10-05 4:23 ` Pei Xiao
2026-10-05 6:05 ` Jarkko Sakkinen
2026-10-05 6:10 ` Pei Xiao
2026-10-05 6:11 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asNU92oQXJcolDdy@kernel.org \
--to=jarkko@kernel.org \
--cc=jarkko.sakkinen@iki.fi \
--cc=jgg@ziepe.ca \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=peterhuewe@gmx.de \
--cc=xiaopei01@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.