[PATCH v8 04/12] tpm: Change tpm_get_random() opportunistic
Jarkko Sakkinen
jarkko at kernel.org
Tue Dec 16 09:21:38 UTC 2025
hwrng framework does not have a requirement that the all bytes requested
need to be provided. By enforcing such a requirement internally, TPM driver
can cause unpredictability in latency, as a single tpm_get_random() call
can result multiple TPM commands.
Especially, when TCG_TPM2_HMAC is enabled, extra roundtrips could have
significant effect to the system latency.
Thus, send TPM command only once and return bytes received instead of
committing to the number of requested bytes.
Cc: David S. Miller <davem at davemloft.net>
Cc: Herbert Xu <herbert at gondor.apana.org.au>
Cc: Eric Biggers <ebiggers at kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko at kernel.org>
---
v7:
- Given that hwrng is now only caller for tpm_get_random(), remove the
wait parameter.
v4:
- Fixed grammar mistakes.
---
drivers/char/tpm/tpm-interface.c | 28 +++++-----------------------
1 file changed, 5 insertions(+), 23 deletions(-)
diff --git a/drivers/char/tpm/tpm-interface.c b/drivers/char/tpm/tpm-interface.c
index d157be738612..677dcef05dfb 100644
--- a/drivers/char/tpm/tpm-interface.c
+++ b/drivers/char/tpm/tpm-interface.c
@@ -626,10 +626,6 @@ static int tpm2_get_random(struct tpm_chip *chip, u8 *out, size_t max)
*/
int tpm_get_random(struct tpm_chip *chip, u8 *out, size_t max)
{
- u32 num_bytes = max;
- u8 *out_ptr = out;
- int retries = 5;
- int total = 0;
int rc;
if (!out || !max || max > TPM_MAX_RNG_DATA)
@@ -646,28 +642,14 @@ int tpm_get_random(struct tpm_chip *chip, u8 *out, size_t max)
rc = tpm2_start_auth_session(chip);
if (rc)
return rc;
- }
-
- do {
- if (chip->flags & TPM_CHIP_FLAG_TPM2)
- rc = tpm2_get_random(chip, out_ptr, num_bytes);
- else
- rc = tpm1_get_random(chip, out_ptr, num_bytes);
-
- if (rc < 0)
- goto err;
-
- out_ptr += rc;
- total += rc;
- num_bytes -= rc;
- } while (retries-- && total < max);
- tpm_put_ops(chip);
- return total ? total : -EIO;
+ rc = tpm2_get_random(chip, out, max);
+ } else {
+ rc = tpm1_get_random(chip, out, max);
+ }
-err:
tpm_put_ops(chip);
- return rc;
+ return rc != 0 ? rc : -EIO;
}
EXPORT_SYMBOL_GPL(tpm_get_random);
--
2.39.5
More information about the Linux-security-module-archive
mailing list