[PATCH gnupg 0/2] tpm2d: Fix concurrent use of a TPM key and a bogus TSS error
Aleksei Sviridkin
f at lex.la
Sun Sep 27 23:24:04 CEST 2026
A TPM-backed key in gpg-agent can serve only one operation at a time. I
use a nistp256 subkey moved there with keytotpm for commit signing and
SSH on a headless box. When several jobs used it at once, signatures
failed at random with "No SmartCard daemon" or "agent refused
operation". Patch 1 fixes that.
Patch 2 drops three false TSS error lines that tpm2daemon printed on
every operation. They were the first thing I suspected in the journal.
I tested on an AMD Ryzen 7 5800H firmware TPM with Ubuntu 26.04, gnupg
2.4.8 and tpm2-tss 4.1.3. Unpatched 2.4.8 and master fail the same way.
My own agent now runs 2.4.8 with both patches, and 140 of 140 concurrent
operations went through with no TSS errors in the journal.
Aleksei Sviridkin (2):
tpm2d: Add GETINFO command to allow concurrent connections.
tpm2d: Do not set session attributes on the password session.
tpm2d/command.c | 43 +++++++++++++++++++++++++++++++++++++++++++
tpm2d/intel-tss.h | 4 ++++
tpm2d/tpm2daemon.h | 1 +
3 files changed, 48 insertions(+)
--
2.53.0
More information about the Gnupg-devel
mailing list