[PATCH gnupg 1/2] tpm2d: Add GETINFO command to allow concurrent connections.
Aleksei Sviridkin
f at lex.la
Sun Sep 27 23:24:05 CEST 2026
* tpm2d/command.c (hlp_getinfo, cmd_getinfo): New.
(register_commands): Register GETINFO.
* tpm2d/tpm2daemon.h (tpm2d_get_socket_name): Declare.
--
gpg-agent opens extra connections to a busy daemon only after it
learns the socket name via "GETINFO socket_name", as with scdaemon.
tpm2daemon had the socket and an unused accessor, but no GETINFO. A
TPM key used for SSH and signing by several jobs at once thus failed
at random with "daemon is running but won't accept further
connections". The agent needs no change. Connections do not share
TPM state, since each TPM command opens its own ESYS context.
Tested with a firmware TPM via /dev/tpmrm0: 5 of 30 concurrent
signatures before, 30 of 30 after.
Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f at lex.la>
---
tpm2d/command.c | 43 +++++++++++++++++++++++++++++++++++++++++++
tpm2d/tpm2daemon.h | 1 +
2 files changed, 44 insertions(+)
diff --git a/tpm2d/command.c b/tpm2d/command.c
index 8f69a5e1..2cbfccd6 100644
--- a/tpm2d/command.c
+++ b/tpm2d/command.c
@@ -353,6 +353,48 @@ cmd_pkdecrypt (assuan_context_t ctx, char *line)
return rc;
}
+static const char hlp_getinfo[] =
+ "GETINFO <what>\n"
+ "\n"
+ "Multi purpose command to return certain information.\n"
+ "Supported values of WHAT are:\n"
+ "\n"
+ " version - Return the version of the program.\n"
+ " pid - Return the process id of the server.\n"
+ " socket_name - Return the name of the socket.\n"
+ " If there is no socket, GPG_ERR_NO_DATA is returned.";
+static gpg_error_t
+cmd_getinfo (assuan_context_t ctx, char *line)
+{
+ int rc = 0;
+ const char *s;
+
+ if (!strcmp (line, "version"))
+ {
+ s = VERSION;
+ rc = assuan_send_data (ctx, s, strlen (s));
+ }
+ else if (!strcmp (line, "pid"))
+ {
+ char numbuf[50];
+
+ snprintf (numbuf, sizeof numbuf, "%lu", (unsigned long)getpid ());
+ rc = assuan_send_data (ctx, numbuf, strlen (numbuf));
+ }
+ else if (!strcmp (line, "socket_name"))
+ {
+ s = tpm2d_get_socket_name ();
+ if (s)
+ rc = assuan_send_data (ctx, s, strlen (s));
+ else
+ rc = gpg_error (GPG_ERR_NO_DATA);
+ }
+ else
+ rc = set_error (GPG_ERR_ASS_PARAMETER, "unknown value for WHAT");
+ return rc;
+}
+
+
static const char hlp_killtpm2d[] =
"KILLTPM2D\n"
"\n"
@@ -383,6 +425,7 @@ register_commands (assuan_context_t ctx)
{ "IMPORT", cmd_import, hlp_import },
{ "PKSIGN", cmd_pksign, hlp_pksign },
{ "PKDECRYPT", cmd_pkdecrypt, hlp_pkdecrypt },
+ { "GETINFO", cmd_getinfo, hlp_getinfo },
{ "KILLTPM2D", cmd_killtpm2d, hlp_killtpm2d },
{ NULL }
};
diff --git a/tpm2d/tpm2daemon.h b/tpm2d/tpm2daemon.h
index 29db7a86..456cc5d2 100644
--- a/tpm2d/tpm2daemon.h
+++ b/tpm2d/tpm2daemon.h
@@ -96,5 +96,6 @@ int tpm2d_command_handler (ctrl_t, gnupg_fd_t);
void send_client_notifications (app_t app, int removal);
void tpm2d_kick_the_loop (void);
int get_active_connection_count (void);
+const char *tpm2d_get_socket_name (void);
#endif /*TPM2DAEMON_H*/
--
2.53.0
More information about the Gnupg-devel
mailing list