Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: ba8296810c6c0f411f158955574c8ae8ffe283f0
      
https://github.com/tianocore/edk2/commit/ba8296810c6c0f411f158955574c8ae8ffe283f0
  Author: Liqi Qi <[email protected]>
  Date:   2025-12-11 (Thu, 11 Dec 2025)

  Changed paths:
    M SecurityPkg/Tcg/Tcg2Dxe/Tcg2Dxe.c

  Log Message:
  -----------
  SecurityPkg: Fix Tcg2SubmitCommand in TPM field upgrade scenario

There's a bug that after the device was forced shut down during the tpm
firmware update process, then the TPM will stay in field upgrade mode and
refuse to work properly. This will block TPM startup and cause the device
to bootloop.

Now in the TCG_DXE_DATA struct we don’t have a flag to indicate the
current TPM mode, and we will simply treat the upper Scenario with this
DEVICE_ERROR and set the TPMPresentFlag to FALSE.

Later in Tcg2SubmitCommand we will just return DEVICE_ERROR and skip the
actual TPM recovery.

We should have an extra flag that check for the TPM response code and if
it's TPM_RC_UPGRADE, we knew the device is in field upgrade mode and should
continue the workflow.

We should only return EFI_DEVICE_ERROR when both TPMPresentFlag and
TpmUpdateFlag are false.

The field upgrade is part of TCG spec, and the capsule update/recovery
is part of UEFI spec.
Make this PR to bring in the fix for this corner case.

Signed-off-by: Liqi Qi <[email protected]>



To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to