Page MenuHomeFreeBSD

Fix bug in TPM 2.0 TIS driver.
ClosedPublic

Authored by darrick.freebsd_gmail.com on Jan 8 2020, 2:37 AM.

Details

Summary

tpmtis_go_ready() reads the value of the TPM_STS register and ORs TPM_STS_CMD_READY to the existing value and writes it back to the register. However, the TPM Profile (PTP) specification states that only one bit in the write request value may be set to 1, or else the entire write request is ignored.

Also removed call which clears the TPM_STS_CMD_READY flag in the same call. It was being ignored for the same reasons.

Diff Detail

Lint
Lint OK
Unit
No Unit Test Coverage
Build Status
Buildable 28532
Build 26585: arc lint + arc unit

Event Timeline

cem accepted this revision.Jan 8 2020, 2:55 AM

(I suspect all of these AND4/OR4 constructs are dubious and should be removed in favor of explicit AND/ORing as necessary, but that's a larger cleanup than fixing the bug.)

This revision is now accepted and ready to land.Jan 8 2020, 2:55 AM
cem added a reviewer: takawata.Jan 8 2020, 2:57 AM
vangyzen accepted this revision.Jan 10 2020, 8:00 PM
This revision was automatically updated to reflect the committed changes.