From 2c30af8f1861f09f217097460bfbea5ea691f8b8 Mon Sep 17 00:00:00 2001
From: Che-Liang Chiou <clchiou@chromium.org>
Date: Sun, 10 Nov 2013 10:27:08 -0700
Subject: [PATCH] sandbox: tpm: Fix nvwrite command

The original codes misused recvbuf in source buffer instead of sendbuf,
and read from incorrect offset 14 instead of 22.

Signed-off-by: Che-Liang Chiou <clchiou@chromium.org>

Signed-off-by: Simon Glass <sjg@chromium.org>
Reviewed-by: Simon Glass <sjg@chromium.org>
Tested-by: Che-Liang Chiou <clchiou@chromium.org>
---
 drivers/tpm/tpm_tis_sandbox.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/tpm/tpm_tis_sandbox.c b/drivers/tpm/tpm_tis_sandbox.c
index 80cf734f1c..ed4b039127 100644
--- a/drivers/tpm/tpm_tis_sandbox.c
+++ b/drivers/tpm/tpm_tis_sandbox.c
@@ -190,9 +190,7 @@ int tis_sendrecv(const u8 *sendbuf, size_t send_size,
 		if (seq < 0)
 			return -1;
 		printf("tpm: nvwrite index=%#02x, len=%#02x\n", index, length);
-		memcpy(&tpm->nvdata[seq],
-		       recvbuf + TPM_RESPONSE_HEADER_LENGTH + sizeof(uint32_t),
-		       length);
+		memcpy(&tpm->nvdata[seq], sendbuf + 22, length);
 		*recv_len = 12;
 		memset(recvbuf, '\0', *recv_len);
 		break;
-- 
2.39.5