Site icon EfmSoft

What does HRESULT 0x8028004E (TPM_E_TRANSPORT_NOTEXCLUSIVE) mean?

 
Previous Next
TPM_E_DELEGATE_ADMIN TPM_E_OWNER_CONTROL

TPM_E_TRANSPORT_NOTEXCLUSIVE

Where the failure is raised

TPM_E_TRANSPORT_NOTEXCLUSIVE means an exclusive TPM 1.2 transport session lost exclusivity because another command executed outside it.

The first producer to identify is the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. TBS can virtualize finite TPM resources, but a saved TPM context and a TBS virtual handle are not durable application IDs. Their validity depends on resource type, owning client context, TPM lifecycle and the exact save/load history.

Evidence that changes the diagnosis

QuestionEvidence
What exact state was rejected?an exclusive TPM 1.2 transport session lost exclusivity because another command executed outside it
Which layer owns the result?The TPM resource, context or delegation manager, sometimes mediated by TBS virtualization.
What must be correlated?transport handle and attributes, complete command timeline across processes, TBS context and priority, nested commands, and session termination state
Controlled comparisonrun the transport sequence on an otherwise idle test system and trace every TPM command from start to finish

Record the original command or API call before retry logic for this result mutates its nonces, handles, buffers or state. Also retain the full HRESULT as 0x8028004E; signed decimal logging can obscure the TPM/TBS facility and make searches less precise.

A controlled verification

  1. Establish the baseline with the same device, Windows build, account and TPM generation.
  2. Perform one narrow experiment: run the transport sequence on an otherwise idle test system and trace every TPM command from start to finish.
  3. Compare raw inputs and the first response, not only the final application dialog.
  4. Stop after the first changed result; if a later error replaces this HRESULT, this condition was passed even if the whole workflow still fails.

Related TPM and TBS results

ResultDifferent diagnostic question
TPM_E_OWNER_CONTROLAttempt to context save an owner-evict-controlled key.
TPM_E_DELEGATE_ADMINDelegation table management not enabled.
TPM_E_BAD_HANDLEThe handle is incorrect.

The key distinction is that TPM_E_NO_WRAP_TRANSPORT rejects wrapped transport capability before an exclusive session is established.

Correction and proof

To correct this, serialize TPM access around the exclusive transport or replace the legacy transport design with a supported higher-level API. Do not persist volatile TPM or TBS handles as durable identifiers. A numeric handle can be valid only inside the creating context and lifecycle, even when its value looks unchanged after restart.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version