| Previous | Next |
| TPM_E_INVALID_HANDLE | TPM_E_EMBEDDED_COMMAND_BLOCKED |
TPM_E_DUPLICATE_VHANDLE
Interpret the condition first
TPM_E_DUPLICATE_VHANDLE (0x80280402) belongs to Windows command mediation around the TPM. This result means TBS received a TPM result that would create a virtual handle already present in the client mapping.
Build the command transcript
| Question | Evidence |
|---|---|
| What exact state was rejected? | TBS received a TPM result that would create a virtual handle already present in the client mapping |
| Which layer owns the result? | TBS command blocking, virtual-handle translation, retry or anti-hammering logic. |
| What must be correlated? | returned physical handle, existing virtual mapping, command code, context identity, resubmission history, and preceding resource-load responses |
| Controlled comparison | close the test context, create a new context and submit the command once without replaying a cached response |
Separate caller data from platform state. The caller data includes the command, structures, lengths, handles and flags; platform state includes TPM generation, provisioning, locality, lockout, resource inventory, firmware and the TBS service lifecycle. This result is actionable only after the rejected side is identified.
Test one hypothesis
Use the following verification sequence:
- Capture the unmodified failing input and
0x80280402. - Close the test context, create a new context and submit the command once without replaying a cached response.
- Compare the first divergent field or state transition.
- Repeat the operation only after restoring the same baseline, with a bounded retry policy where the specification permits retry.
Do not merge these conditions
| Other code | Why a different remedy follows |
|---|---|
TPM_E_EMBEDDED_COMMAND_BLOCKED | The command within the transport was blocked. |
TPM_E_INVALID_HANDLE | The specified handle was not found. |
TPM_E_EMBEDDED_COMMAND_UNSUPPORTED | The command within the transport is not supported. |
TBSIMP_E_DUPLICATE_VHANDLE is the internal implementation-layer counterpart. The difference determines whether to change serialization, authorization, resource lifetime, firmware/PPI state, command policy or only retry timing.
A safe recovery path
Correct the original boundary by choosing this direction: discard the inconsistent mapping and resubmit through a fresh context; investigate firmware or duplicate command delivery if it recurs. Do not disable command policy globally to make one test pass. First establish the caller, command code and supported higher-level alternative, because command blocking is a security boundary.
Technical references
Looking for a different code? Search another status or error code.
