| From ab64a04d406b52c8cb8d00d6856693f407aa8565 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 26 Dec 2025 15:09:27 +0300 |
| Subject: tpm: st33zp24: Fix missing cleanup on get_burstcount() error |
| |
| From: Alper Ak <alperyasinak1@gmail.com> |
| |
| [ Upstream commit 3e91b44c93ad2871f89fc2a98c5e4fe6ca5db3d9 ] |
| |
| get_burstcount() can return -EBUSY on timeout. When this happens, |
| st33zp24_send() returns directly without releasing the locality |
| acquired earlier. |
| |
| Use goto out_err to ensure proper cleanup when get_burstcount() fails. |
| |
| Fixes: bf38b8710892 ("tpm/tpm_i2c_stm_st33: Split tpm_i2c_tpm_st33 in 2 layers (core + phy)") |
| Signed-off-by: Alper Ak <alperyasinak1@gmail.com> |
| Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/char/tpm/st33zp24/st33zp24.c | 6 ++++-- |
| 1 file changed, 4 insertions(+), 2 deletions(-) |
| |
| diff --git a/drivers/char/tpm/st33zp24/st33zp24.c b/drivers/char/tpm/st33zp24/st33zp24.c |
| index 15b393e92c8ec..71cc97f394b51 100644 |
| --- a/drivers/char/tpm/st33zp24/st33zp24.c |
| +++ b/drivers/char/tpm/st33zp24/st33zp24.c |
| @@ -327,8 +327,10 @@ static int st33zp24_send(struct tpm_chip *chip, unsigned char *buf, |
| |
| for (i = 0; i < len - 1;) { |
| burstcnt = get_burstcount(chip); |
| - if (burstcnt < 0) |
| - return burstcnt; |
| + if (burstcnt < 0) { |
| + ret = burstcnt; |
| + goto out_err; |
| + } |
| size = min_t(int, len - i - 1, burstcnt); |
| ret = tpm_dev->ops->send(tpm_dev->phy_id, TPM_DATA_FIFO, |
| buf + i, size); |
| -- |
| 2.51.0 |
| |