[PATCH 4/5] tpm: fix zero-length read discarding the pending response
From: Pei Xiao
Date: Sat Oct 03 2026 - 04:28:18 EST
POSIX requires that a read() with a count of zero returns zero and
has no other effects. tpm_common_read() treats such a call as a
consumed response: it marks the pending response as read and drops
it, so the response can never be retrieved; subsequent reads return
zero and the next write() is allowed to overwrite the response
buffer, silently breaking the command/response pairing of the TPM
character devices.
Return early when the caller passes a zero count, leaving any
pending response untouched for the next read. A zero-length read
will not report a deferred asynchronous error; POSIX permits read()
to skip error detection for a zero count.
Fixes: 9488585b21be ("tpm: add support for partial reads")
Assisted-by: GLM-5.3
Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
---
drivers/char/tpm/tpm-dev-common.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/char/tpm/tpm-dev-common.c b/drivers/char/tpm/tpm-dev-common.c
index f942c0c8e402..6569212dc6b8 100644
--- a/drivers/char/tpm/tpm-dev-common.c
+++ b/drivers/char/tpm/tpm-dev-common.c
@@ -134,6 +134,9 @@ ssize_t tpm_common_read(struct file *file, char __user *buf,
ssize_t ret_size = 0;
int rc;
+ if (!size)
+ return 0;
+
mutex_lock(&priv->buffer_mutex);
if (priv->response_length) {
--
2.25.1