git: cb2964f840e8 - main - amd64, powerpc: Enable tpm(4) in supported kernels
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 12 Sep 2026 22:01:40 UTC
The branch main has been updated by kbowling:
URL: https://cgit.FreeBSD.org/src/commit/?id=cb2964f840e873d03a0739f41eed5921922f93a0
commit cb2964f840e873d03a0739f41eed5921922f93a0
Author: Kevin Bowling <kbowling@FreeBSD.org>
AuthorDate: 2026-08-28 00:14:02 +0000
Commit: Kevin Bowling <kbowling@FreeBSD.org>
CommitDate: 2026-09-12 22:01:32 +0000
amd64, powerpc: Enable tpm(4) in supported kernels
tpm(4) was removed from amd64 GENERIC because it broke suspend and
resume. The preceding lifecycle, state-save, interrupt, locality, and
teardown fixes address those failures for both TPM 1.2 and TPM 2.0.
Restore the driver to amd64 GENERIC and MINIMAL, where TPM entropy
harvesting remained enabled. Enable the driver and entropy harvesting
in the MPC85XX and QORIQ64 configurations, which already provide FDT,
spibus, and the platform SPI controller required by FDT-attached TPMs.
Leave the generic AIM and POWER configurations unchanged because they
have no TPM attachment bus.
The TPM 1.2 path completed repeated S3 cycles and command tests on
ThinkPad T430 and T440p systems. The TPM 2.0 path completed repeated
device and full-system suspend/resume cycles on a ThinkPad P51. The
PowerPC configuration matrix was checked to retain tpm(4) only where its
FDT SPI attachment path is present.
PR: 291067
Reviewed by: kevans
Tested by: Marek Zarychta <zarychtam_plan-b.pwste.edu.pl> (tpm1.2)
Fixes: 16f8ea6a81b5 ("amd64: Remove tpm(4) from GENERIC for now")
MFC after: 1 month
Relnotes: yes
Sponsored by: BBOX.io
Differential Revision: https://reviews.freebsd.org/D59247
---
sys/amd64/conf/GENERIC | 5 ++---
sys/amd64/conf/MINIMAL | 5 ++---
sys/powerpc/conf/MPC85XX | 2 ++
sys/powerpc/conf/QORIQ64 | 2 ++
4 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/sys/amd64/conf/GENERIC b/sys/amd64/conf/GENERIC
index e53d42c0ac43..61533394a3d0 100644
--- a/sys/amd64/conf/GENERIC
+++ b/sys/amd64/conf/GENERIC
@@ -332,9 +332,8 @@ device bpf # Berkeley packet filter
# random(4)
device padlock_rng # VIA Padlock RNG
device rdrand_rng # Intel Bull Mountain RNG
-# Disabled for now since tpm(4) breaks suspend/resume.
-#device tpm # Trusted Platform Module
-options RANDOM_ENABLE_TPM # enable entropy from TPM 2.0
+device tpm # Trusted Platform Module
+options RANDOM_ENABLE_TPM # enable entropy from TPM devices
options RANDOM_ENABLE_KBD
options RANDOM_ENABLE_MOUSE
diff --git a/sys/amd64/conf/MINIMAL b/sys/amd64/conf/MINIMAL
index 806d0baef9e7..70afb305d66b 100644
--- a/sys/amd64/conf/MINIMAL
+++ b/sys/amd64/conf/MINIMAL
@@ -141,9 +141,8 @@ device bpf # Berkeley packet filter
# random(4)
device padlock_rng # VIA Padlock RNG
device rdrand_rng # Intel Bull Mountain RNG
-# Disabled for now since tpm(4) breaks suspend/resume.
-#device tpm # Trusted Platform Module
-options RANDOM_ENABLE_TPM # enable entropy from TPM 2.0
+device tpm # Trusted Platform Module
+options RANDOM_ENABLE_TPM # enable entropy from TPM devices
options RANDOM_ENABLE_KBD
options RANDOM_ENABLE_MOUSE
diff --git a/sys/powerpc/conf/MPC85XX b/sys/powerpc/conf/MPC85XX
index fccbdbea8342..2d546bccbebf 100644
--- a/sys/powerpc/conf/MPC85XX
+++ b/sys/powerpc/conf/MPC85XX
@@ -28,6 +28,7 @@ options DDB
options DEVICE_POLLING
#options DIAGNOSTIC
options FDT
+options RANDOM_ENABLE_TPM
#makeoptions FDT_DTS_FILE=mpc8555cds.dts
options FFS
options GDB
@@ -103,6 +104,7 @@ device sdhci
device sec
device spibus
device spigen
+device tpm
device tsec
device tuntap
device uart
diff --git a/sys/powerpc/conf/QORIQ64 b/sys/powerpc/conf/QORIQ64
index cbafe1ab2f48..9141c3e72aa5 100644
--- a/sys/powerpc/conf/QORIQ64
+++ b/sys/powerpc/conf/QORIQ64
@@ -31,6 +31,7 @@ options DDB
options DEVICE_POLLING
#options DIAGNOSTIC
options FDT
+options RANDOM_ENABLE_TPM
#makeoptions FDT_DTS_FILE=mpc8555cds.dts
options FFS #Berkeley Fast Filesystem
options SOFTUPDATES #Enable FFS soft updates support
@@ -105,6 +106,7 @@ device scc
device sdhci
device spibus
device spigen
+device tpm
device tuntap
device uart
options USB_DEBUG # enable debug msgs