[PATCH gnupg 2/2] tpm2d: Do not set session attributes on the password session.
Aleksei Sviridkin
f at lex.la
Sun Sep 27 23:24:06 CEST 2026
* tpm2d/intel-tss.h (intel_sess_helper): Return early for
ESYS_TR_PASSWORD.
--
TPM2_Load uses the password session, which has no attributes, so
Esys_TRSess_SetAttributes always fails on it. The result was ignored,
but the TSS printed three error lines starting with "Esys invalid ESAPI
handle (ff)" on every operation, which looked like the cause of real
failures. The check is in the helper, so it covers every caller that
may pass the password session.
Tested: no such lines over 100 concurrent operations.
Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f at lex.la>
---
tpm2d/intel-tss.h | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tpm2d/intel-tss.h b/tpm2d/intel-tss.h
index da085fac..78493114 100644
--- a/tpm2d/intel-tss.h
+++ b/tpm2d/intel-tss.h
@@ -246,6 +246,10 @@ intel_auth_helper(TSS_CONTEXT *tssContext, TPM_HANDLE auth, const char *authVal)
static inline void
intel_sess_helper(TSS_CONTEXT *tssContext, TPM_HANDLE auth, TPMA_SESSION flags)
{
+ /* A password session has no attributes to set; ESYS would log an
+ error for it on stderr. */
+ if (auth == ESYS_TR_PASSWORD)
+ return;
Esys_TRSess_SetAttributes(tssContext, auth, flags,
TPMA_SESSION_CONTINUESESSION | flags);
}
--
2.53.0
More information about the Gnupg-devel
mailing list