Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks
@ 2026-10-02 19:40 Artem Dinaburg
  2026-10-02 19:40 ` [PATCH 6.1.y 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Artem Dinaburg @ 2026-10-02 19:40 UTC (permalink / raw)
  To: stable
  Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
	Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
	Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx, dri-devel,
	linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe

Hi Greg, Sasha, and i915 maintainers,

Patch 1 alone is not enough on 6.1.y: intel_hdcp_info() calls
intel_hdcp_capable() and then intel_hdcp2_capable(), so the debugfs NULL
dereference moves to the second call. Patch 2 is the companion fix that
path needs, a backport of upstream commit d34f4f058edf ("drm/i915/hdcp:
Add encoder check in hdcp2_get_capability") with the guard in the common
intel_hdcp2_capable() helper, where 6.1.y still does the lookup. This
mirrors the 2-patch series picked up for 6.6.y, and both fixes are
already present in 6.12.y, 6.18.y, and 7.2.y. Could you please queue both
patches for 6.1.y?

AI assistance: An LLM helped adapt and validate both patches; I reviewed
the resulting code and validation evidence.

Thanks,
Artem Dinaburg

Series:
  1. drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
  2. drm/i915/hdcp: Add encoder check in hdcp2_get_capability

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH 6.1.y 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
  2026-10-02 19:40 [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
@ 2026-10-02 19:40 ` Artem Dinaburg
  2026-10-02 19:40 ` [PATCH 6.1.y 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Artem Dinaburg @ 2026-10-02 19:40 UTC (permalink / raw)
  To: stable
  Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
	Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
	Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx, dri-devel,
	linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe

From: Suraj Kandpal <suraj.kandpal@intel.com>

[ Upstream commit 31b42af516afa1e184d1a9f9dd4096c54044269a ]

Sometimes during hotplug scenario or suspend/resume scenario encoder is
not always initialized when intel_hdcp_get_capability add
a check to avoid kernel null pointer dereference.

[ Backport to 6.1.y: this tree uses the older intel_hdcp_capable()
  helper name. Apply the same guard there; the code change is otherwise
  unchanged. ]

Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-2-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
Hi Greg, Sasha, and drm i915 maintainers,

I am working through the small CVE backports still missing from 6.1.y.
This one addresses CVE-2024-53051. It rejects the HDCP capability query
when hotplug or resume left the encoder unset.

The 6.6.y backport went out as the same 2-patch series and has been
picked up for 6.6.y. The fix is already present in 6.12.y, 6.18.y, and
7.2.y, but not in 6.1.y.
The target-specific adjustment is recorded in the bracketed note above.

Could you please queue it for 6.1.y?

CVE: CVE-2024-53051
Upstream: 31b42af516afa1e184d1a9f9dd4096c54044269a

AI assistance: An LLM helped identify, adapt, and validate this backport; I
reviewed the resulting code and validation evidence.

Thanks,
Artem Dinaburg

 drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index cb7f86de967a88..507721c94f2fdd 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -182,11 +182,16 @@ int intel_hdcp_read_valid_bksv(struct intel_digital_port *dig_port,
 /* Is HDCP1.4 capable on Platform and Sink */
 bool intel_hdcp_capable(struct intel_connector *connector)
 {
-	struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+	struct intel_digital_port *dig_port;
 	const struct intel_hdcp_shim *shim = connector->hdcp.shim;
 	bool capable = false;
 	u8 bksv[5];
 
+	if (!intel_attached_encoder(connector))
+		return capable;
+
+	dig_port = intel_attached_dig_port(connector);
+
 	if (!shim)
 		return capable;
 
-- 
2.39.5


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 6.1.y 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability
  2026-10-02 19:40 [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
  2026-10-02 19:40 ` [PATCH 6.1.y 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
@ 2026-10-02 19:40 ` Artem Dinaburg
  2026-10-02 20:45 ` ✗ LGCI.VerificationFailed: failure for drm/i915/hdcp: guard both capability checks Patchwork
  2026-10-03 22:33 ` [PATCH 6.1.y 0/2] " Sasha Levin
  3 siblings, 0 replies; 5+ messages in thread
From: Artem Dinaburg @ 2026-10-02 19:40 UTC (permalink / raw)
  To: stable
  Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
	Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
	Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx, dri-devel,
	linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe

From: Suraj Kandpal <suraj.kandpal@intel.com>

[ Upstream commit d34f4f058edf1235c103ca9c921dc54820d14d40 ]

Add encoder check in intel_hdcp2_get_capability to avoid
null pointer error.

[ Backport to 6.1.y: upstream adds the check in the DP shim's
  intel_dp_hdcp2_get_capability(), which does not exist here. This tree
  predates the intel_connector conversion of the shims: its
  intel_dp_hdcp2_capable() takes a digital port, and the
  intel_attached_dig_port() lookup is still done in the common
  intel_hdcp2_capable() helper. Put the same encoder guard there, before
  that lookup, and return false through the bool API when no encoder is
  attached. ]

Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-3-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
Hi Greg, Sasha, and drm i915 maintainers,

I am working through the small CVE backports still missing from 6.1.y.
This one addresses CVE-2024-53050. It adds the same encoder check to the
HDCP2.2 capability query, which the debugfs path calls right after the
HDCP1.4 one.

The 6.6.y backport went out as the same 2-patch series and has been
picked up for 6.6.y. The fix is already present in 6.12.y, 6.18.y, and
7.2.y, but not in 6.1.y.
The target-specific adjustment is recorded in the bracketed note above.

Could you please queue it for 6.1.y?

CVE: CVE-2024-53050
Upstream: d34f4f058edf1235c103ca9c921dc54820d14d40

AI assistance: An LLM helped identify, adapt, and validate this backport; I
reviewed the resulting code and validation evidence.

Thanks,
Artem Dinaburg

 drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index 507721c94f2fdd..d31c1f1f0e5074 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -208,11 +208,16 @@ bool intel_hdcp_capable(struct intel_connector *connector)
 /* Is HDCP2.2 capable on Platform and Sink */
 bool intel_hdcp2_capable(struct intel_connector *connector)
 {
-	struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+	struct intel_digital_port *dig_port;
 	struct drm_i915_private *dev_priv = to_i915(connector->base.dev);
 	struct intel_hdcp *hdcp = &connector->hdcp;
 	bool capable = false;
 
+	if (!intel_attached_encoder(connector))
+		return capable;
+
+	dig_port = intel_attached_dig_port(connector);
+
 	/* I915 support for HDCP2.2 */
 	if (!hdcp->hdcp2_supported)
 		return false;
-- 
2.39.5


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* ✗ LGCI.VerificationFailed: failure for drm/i915/hdcp: guard both capability checks
  2026-10-02 19:40 [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
  2026-10-02 19:40 ` [PATCH 6.1.y 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
  2026-10-02 19:40 ` [PATCH 6.1.y 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
@ 2026-10-02 20:45 ` Patchwork
  2026-10-03 22:33 ` [PATCH 6.1.y 0/2] " Sasha Levin
  3 siblings, 0 replies; 5+ messages in thread
From: Patchwork @ 2026-10-02 20:45 UTC (permalink / raw)
  To: Artem Dinaburg; +Cc: intel-xe

== Series Details ==

Series: drm/i915/hdcp: guard both capability checks
URL   : https://patchwork.freedesktop.org/series/175459/
State : failure

== Summary ==

Series author address 'artem@trailofbits.com' is not on the allowlist, which prevents CI from being automatically triggered.
If you want CI to run for this series, ask Patchwork project owners to click 'retest' on the series in Patchwork.
Exception occurred during validation, bailing out!
Build URL: http://intel-gfx-ci-public.igk.intel.com:8080/job/xe_pw_trigger/1299103/ (on master)



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks
  2026-10-02 19:40 [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
                   ` (2 preceding siblings ...)
  2026-10-02 20:45 ` ✗ LGCI.VerificationFailed: failure for drm/i915/hdcp: guard both capability checks Patchwork
@ 2026-10-03 22:33 ` Sasha Levin
  3 siblings, 0 replies; 5+ messages in thread
From: Sasha Levin @ 2026-10-03 22:33 UTC (permalink / raw)
  To: stable
  Cc: Sasha Levin, Artem Dinaburg, Greg Kroah-Hartman, Suraj Kandpal,
	Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
	Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx, dri-devel,
	linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe

> already present in 6.12.y, 6.18.y, and 7.2.y. Could you please queue both
> patches for 6.1.y?

Queued the series for 6.1, thanks.

-- 
Thanks,
Sasha

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-03 22:38 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 19:40 [PATCH 6.1.y 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
2026-10-02 19:40 ` [PATCH 6.1.y 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
2026-10-02 19:40 ` [PATCH 6.1.y 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
2026-10-02 20:45 ` ✗ LGCI.VerificationFailed: failure for drm/i915/hdcp: guard both capability checks Patchwork
2026-10-03 22:33 ` [PATCH 6.1.y 0/2] " Sasha Levin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox