From: Surendran Kanagaraj <surenkj@amazon.com>
To: Jarkko Sakkinen <jarkko@kernel.org>,
Peter Huewe <peterhuewe@gmx.de>, Jason Gunthorpe <jgg@ziepe.ca>
Cc: <linux-integrity@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<nh-open-source@amazon.com>, Alexander Graf <graf@amazon.de>,
"Gunnar Kudrjavets" <gunnarku@amazon.com>,
Josh Levinson <joshlev@amazon.com>
Subject: [PATCH 2/2] tpm_crb: Raise timeouts for Amazon NitroTPM
Date: Wed, 23 Sep 2026 14:28:34 +0000 [thread overview]
Message-ID: <20260923142834.16786-3-surenkj@amazon.com> (raw)
In-Reply-To: <20260923142834.16786-1-surenkj@amazon.com>
TPM commands need to complete within the command duration defined in
the TPM2 spec or keep answering TPM2_RC_RETRY for at most
TPM2_DURATION_LONG (2s).
In rare scenarios NitroTPM can enter a mode where it either sends
TPM2_RC_RETRY for more than 2s or delays command completion. When
this happens during auth session start, the driver disables the chip
and every subsequent request fails:
tpm tpm0: in retry loop
tpm tpm0: tpm2_load_context: failed with a TPM error 0x0922
Add support for vendor quirks to the CRB driver. The table is keyed by
the vendor ID read from the interface ID register. For NitroTPM, set
busy_timeout_ms to 30s, which covers the longest unavailability time
along with some headroom.
Tested on an EC2 instance with NitroTPM by inducing multiple
unavailability windows with no TPM errors, and in QEMU with swtpm by
holding the TPM in TPM2_RC_RETRY and stalling command completion for
longer than 2s with the quirk applied.
Assisted-by: LLM
Signed-off-by: Surendran Kanagaraj <surenkj@amazon.com>
---
drivers/char/tpm/tpm_crb.c | 54 ++++++++++++++++++++++++++++++++++++++
1 file changed, 54 insertions(+)
diff --git a/drivers/char/tpm/tpm_crb.c b/drivers/char/tpm/tpm_crb.c
index ceb4100ba400..4107203beec9 100644
--- a/drivers/char/tpm/tpm_crb.c
+++ b/drivers/char/tpm/tpm_crb.c
@@ -13,6 +13,7 @@
#include <linux/acpi.h>
#include <linux/highmem.h>
+#include <linux/io-64-nonatomic-lo-hi.h>
#include <linux/rculist.h>
#include <linux/module.h>
#include <linux/platform_device.h>
@@ -26,6 +27,15 @@
#define ACPI_SIG_TPM2 "TPM2"
#define TPM_CRB_MAX_RESOURCES 3
+/* TPM_CRB_INTF_ID_x vendor ID field, bits 47:32 of the 64-bit register */
+#define CRB_INTF_ID_VID(intf_id) (((intf_id) >> 32) & 0xffff)
+
+/* Amazon NitroTPM */
+#define CRB_INTF_VID_AMZN 0x0ec2
+
+/* Longest unavailability seen from NitroTPM */
+#define CRB_AMZN_BUSY_TIMEOUT_MS 30000
+
static const guid_t crb_acpi_start_guid =
GUID_INIT(0x6BBF6CAB, 0x5463, 0x4714,
0xB7, 0xCD, 0xF0, 0x20, 0x3C, 0x03, 0x68, 0xD4);
@@ -783,6 +793,48 @@ static int crb_map_pluton(struct device *dev, struct crb_priv *priv,
return 0;
}
+/*
+ * Read the vendor ID from the interface ID register. Returns -ENODEV when
+ * the head registers are not mapped for this start method.
+ */
+static int crb_vendor_id(struct crb_priv *priv)
+{
+ u64 intf_id;
+
+ if (!priv->regs_h)
+ return -ENODEV;
+
+ intf_id = lo_hi_readq(&priv->regs_h->intf_id);
+
+ return CRB_INTF_ID_VID(intf_id);
+}
+
+static void crb_amzn_quirk(struct tpm_chip *chip)
+{
+ /* NitroTPM requires larger timeouts */
+ chip->busy_timeout_ms = CRB_AMZN_BUSY_TIMEOUT_MS;
+}
+
+static const struct crb_vendor_quirk {
+ u16 vendor_id;
+ void (*apply)(struct tpm_chip *chip);
+} crb_vendor_quirks[] = {
+ { CRB_INTF_VID_AMZN, crb_amzn_quirk },
+};
+
+static void crb_apply_vendor_quirks(struct crb_priv *priv, struct tpm_chip *chip)
+{
+ int vendor_id = crb_vendor_id(priv);
+ unsigned int i;
+
+ if (vendor_id < 0)
+ return;
+
+ for (i = 0; i < ARRAY_SIZE(crb_vendor_quirks); i++)
+ if (crb_vendor_quirks[i].vendor_id == vendor_id)
+ crb_vendor_quirks[i].apply(chip);
+}
+
static int crb_acpi_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
@@ -887,6 +939,8 @@ static int crb_acpi_probe(struct platform_device *pdev)
chip->acpi_dev_handle = device->handle;
chip->flags = TPM_CHIP_FLAG_TPM2;
+ crb_apply_vendor_quirks(priv, chip);
+
rc = tpm_chip_bootstrap(chip);
if (rc)
goto out;
--
2.47.3
prev parent reply other threads:[~2026-09-23 14:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 14:28 [PATCH 0/2] tpm: Handle transient NitroTPM unavailability Surendran Kanagaraj
2026-09-23 14:28 ` [PATCH 1/2] tpm: Add per-chip timeout for transient unavailability Surendran Kanagaraj
2026-09-23 14:28 ` Surendran Kanagaraj [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923142834.16786-3-surenkj@amazon.com \
--to=surenkj@amazon.com \
--cc=graf@amazon.de \
--cc=gunnarku@amazon.com \
--cc=jarkko@kernel.org \
--cc=jgg@ziepe.ca \
--cc=joshlev@amazon.com \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nh-open-source@amazon.com \
--cc=peterhuewe@gmx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®