Dear Paul,
Is it possible to enforce this situation to ensure your patch works?
Triggering the issue requires interposing the hardware or a MCU to emulate the TPM and send malformed TPM replies, I might be able to test this using Qemu, but that takes some time.
For the rest of your suggestions, I'll send another patch. BR, /shj
