git: cb2964f840e8 - main - amd64, powerpc: Enable tpm(4) in supported kernels

From: Kevin Bowling <kbowling_at_FreeBSD.org>
Date: Sat, 12 Sep 2026 22:01:40 UTC
The branch main has been updated by kbowling:

URL: https://cgit.FreeBSD.org/src/commit/?id=cb2964f840e873d03a0739f41eed5921922f93a0

commit cb2964f840e873d03a0739f41eed5921922f93a0
Author:     Kevin Bowling <kbowling@FreeBSD.org>
AuthorDate: 2026-08-28 00:14:02 +0000
Commit:     Kevin Bowling <kbowling@FreeBSD.org>
CommitDate: 2026-09-12 22:01:32 +0000

    amd64, powerpc: Enable tpm(4) in supported kernels
    
    tpm(4) was removed from amd64 GENERIC because it broke suspend and
    resume.  The preceding lifecycle, state-save, interrupt, locality, and
    teardown fixes address those failures for both TPM 1.2 and TPM 2.0.
    
    Restore the driver to amd64 GENERIC and MINIMAL, where TPM entropy
    harvesting remained enabled.  Enable the driver and entropy harvesting
    in the MPC85XX and QORIQ64 configurations, which already provide FDT,
    spibus, and the platform SPI controller required by FDT-attached TPMs.
    Leave the generic AIM and POWER configurations unchanged because they
    have no TPM attachment bus.
    
    The TPM 1.2 path completed repeated S3 cycles and command tests on
    ThinkPad T430 and T440p systems.  The TPM 2.0 path completed repeated
    device and full-system suspend/resume cycles on a ThinkPad P51.  The
    PowerPC configuration matrix was checked to retain tpm(4) only where its
    FDT SPI attachment path is present.
    
    PR:             291067
    Reviewed by:    kevans
    Tested by:      Marek Zarychta <zarychtam_plan-b.pwste.edu.pl> (tpm1.2)
    Fixes:          16f8ea6a81b5 ("amd64: Remove tpm(4) from GENERIC for now")
    MFC after:      1 month
    Relnotes:       yes
    Sponsored by:   BBOX.io
    Differential Revision:  https://reviews.freebsd.org/D59247
---
 sys/amd64/conf/GENERIC   | 5 ++---
 sys/amd64/conf/MINIMAL   | 5 ++---
 sys/powerpc/conf/MPC85XX | 2 ++
 sys/powerpc/conf/QORIQ64 | 2 ++
 4 files changed, 8 insertions(+), 6 deletions(-)

diff --git a/sys/amd64/conf/GENERIC b/sys/amd64/conf/GENERIC
index e53d42c0ac43..61533394a3d0 100644
--- a/sys/amd64/conf/GENERIC
+++ b/sys/amd64/conf/GENERIC
@@ -332,9 +332,8 @@ device		bpf			# Berkeley packet filter
 # random(4)
 device		padlock_rng		# VIA Padlock RNG
 device		rdrand_rng		# Intel Bull Mountain RNG
-# Disabled for now since tpm(4) breaks suspend/resume.
-#device		tpm			# Trusted Platform Module
-options 	RANDOM_ENABLE_TPM	# enable entropy from TPM 2.0
+device		tpm			# Trusted Platform Module
+options 	RANDOM_ENABLE_TPM	# enable entropy from TPM devices
 options 	RANDOM_ENABLE_KBD
 options 	RANDOM_ENABLE_MOUSE
 
diff --git a/sys/amd64/conf/MINIMAL b/sys/amd64/conf/MINIMAL
index 806d0baef9e7..70afb305d66b 100644
--- a/sys/amd64/conf/MINIMAL
+++ b/sys/amd64/conf/MINIMAL
@@ -141,9 +141,8 @@ device		bpf			# Berkeley packet filter
 # random(4)
 device		padlock_rng		# VIA Padlock RNG
 device		rdrand_rng		# Intel Bull Mountain RNG
-# Disabled for now since tpm(4) breaks suspend/resume.
-#device		tpm			# Trusted Platform Module
-options 	RANDOM_ENABLE_TPM	# enable entropy from TPM 2.0
+device		tpm			# Trusted Platform Module
+options 	RANDOM_ENABLE_TPM	# enable entropy from TPM devices
 options 	RANDOM_ENABLE_KBD
 options 	RANDOM_ENABLE_MOUSE
 
diff --git a/sys/powerpc/conf/MPC85XX b/sys/powerpc/conf/MPC85XX
index fccbdbea8342..2d546bccbebf 100644
--- a/sys/powerpc/conf/MPC85XX
+++ b/sys/powerpc/conf/MPC85XX
@@ -28,6 +28,7 @@ options 	DDB
 options 	DEVICE_POLLING
 #options 	DIAGNOSTIC
 options 	FDT
+options 	RANDOM_ENABLE_TPM
 #makeoptions	FDT_DTS_FILE=mpc8555cds.dts
 options 	FFS
 options 	GDB
@@ -103,6 +104,7 @@ device  	sdhci
 device		sec
 device  	spibus
 device  	spigen
+device		tpm
 device		tsec
 device		tuntap
 device		uart
diff --git a/sys/powerpc/conf/QORIQ64 b/sys/powerpc/conf/QORIQ64
index cbafe1ab2f48..9141c3e72aa5 100644
--- a/sys/powerpc/conf/QORIQ64
+++ b/sys/powerpc/conf/QORIQ64
@@ -31,6 +31,7 @@ options 	DDB
 options 	DEVICE_POLLING
 #options 	DIAGNOSTIC
 options 	FDT
+options 	RANDOM_ENABLE_TPM
 #makeoptions	FDT_DTS_FILE=mpc8555cds.dts
 options 	FFS			#Berkeley Fast Filesystem
 options 	SOFTUPDATES		#Enable FFS soft updates support
@@ -105,6 +106,7 @@ device		scc
 device  	sdhci
 device  	spibus
 device  	spigen
+device		tpm
 device		tuntap
 device		uart
 options 	USB_DEBUG	# enable debug msgs