]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
6.12-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 7 Aug 2026 13:06:33 +0000 (15:06 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 7 Aug 2026 13:06:33 +0000 (15:06 +0200)
added patches:
drm-i915-hdcp-check-streams-bounds-before-overflow.patch
drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch
drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch
drm-xe-stub-out-new-pagefault-layer.patch

queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch [new file with mode: 0644]
queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch [new file with mode: 0644]
queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch [new file with mode: 0644]
queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch [new file with mode: 0644]
queue-6.12/series

diff --git a/queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch b/queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch
new file mode 100644 (file)
index 0000000..a6706b7
--- /dev/null
@@ -0,0 +1,59 @@
+From stable+bounces-294461-greg=kroah.com@vger.kernel.org Sun Aug  2 04:33:28 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Sat,  1 Aug 2026 22:33:17 -0400
+Subject: drm/i915/hdcp: check streams[] bounds before overflow
+To: stable@vger.kernel.org
+Cc: Jani Nikula <jani.nikula@intel.com>, Martin Hodo <martin.hodo@intel.com>, Anshuman Gupta <anshuman.gupta@intel.com>, Suraj Kandpal <suraj.kandpal@intel.com>, Joonas Lahtinen <joonas.lahtinen@linux.intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260802023317.1298318-3-sashal@kernel.org>
+
+From: Jani Nikula <jani.nikula@intel.com>
+
+[ Upstream commit bbb15a6b042d02e5508a02b4847e02d2579ee7bc ]
+
+The data->streams[] overflow check is done after the buffer overflow has
+already happened. Move the overflow check before the write.
+
+Side note, emitting a warning splat with a backtrace might be overkill
+here, but prefer not changing the behaviour other than not doing the
+overrun.
+
+Discovered using AI-assisted static analysis confirmed by Intel Product
+Security.
+
+Reported-by: Martin Hodo <martin.hodo@intel.com>
+Fixes: e03187e12cae ("drm/i915/hdcp: MST streams support in hdcp port_data")
+Cc: stable@vger.kernel.org # v5.12+
+Cc: Anshuman Gupta <anshuman.gupta@intel.com>
+Cc: Suraj Kandpal <suraj.kandpal@intel.com>
+Reviewed-by: Suraj Kandpal <suraj.kandpal@intel.com>
+Link: https://patch.msgid.link/20260625170304.1104723-1-jani.nikula@intel.com
+Signed-off-by: Jani Nikula <jani.nikula@intel.com>
+(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)
+Signed-off-by: Joonas Lahtinen <joonas.lahtinen@linux.intel.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/i915/display/intel_hdcp.c |    5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
+@@ -129,6 +129,9 @@ intel_hdcp_required_content_stream(struc
+               if (!new_conn_state || !new_conn_state->crtc)
+                       continue;
++              if (drm_WARN_ON(display->drm, data->k >= INTEL_NUM_PIPES(display)))
++                      return -EINVAL;
++
+               data->streams[data->k].stream_id =
+                       intel_conn_to_vcpi(state, connector);
+               data->k++;
+@@ -139,7 +142,7 @@ intel_hdcp_required_content_stream(struc
+       }
+       drm_connector_list_iter_end(&conn_iter);
+-      if (drm_WARN_ON(display->drm, data->k > INTEL_NUM_PIPES(display) || data->k == 0))
++      if (drm_WARN_ON(display->drm, !data->k))
+               return -EINVAL;
+       /*
diff --git a/queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch b/queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch
new file mode 100644 (file)
index 0000000..3a7bbf2
--- /dev/null
@@ -0,0 +1,63 @@
+From stable+bounces-294460-greg=kroah.com@vger.kernel.org Sun Aug  2 04:33:25 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Sat,  1 Aug 2026 22:33:16 -0400
+Subject: drm/i915/hdcp: Skip inactive MST connectors when building stream list
+To: stable@vger.kernel.org
+Cc: Suraj Kandpal <suraj.kandpal@intel.com>, Santhosh Reddy Guddati <santhosh.reddy.guddati@intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260802023317.1298318-2-sashal@kernel.org>
+
+From: Suraj Kandpal <suraj.kandpal@intel.com>
+
+[ Upstream commit 0161e2c2016337a2f22ef79dff0aee43c0841bce ]
+
+intel_hdcp_required_content_stream() walks every connector on the
+digital port to populate hdcp_port_data->streams[]. The only filter is
+connector_status_disconnected, which reflects physical presence on the
+MST topology, not whether the connector currently drives a stream.
+On a multi-sink MST setup where only a subset of sinks are modeset,
+the loop can pick a sibling MST connector that is connected but has
+no active CRTC / VC payload. intel_conn_to_vcpi() then logs "MST
+Payload not present" and returns 0, and the bogus StreamID=0 is
+written to the repeater in RepeaterAuth_Stream_Manage (DPCD 0x693F0).
+Authentication completes, but the repeater shortly raises
+LINK_INTEGRITY_FAILURE (RxStatus 0x69493 bit4) because the StreamID
+does not match any stream on its input. The HDCP check work then
+tears the link down, the Content Protection property drops back to
+DESIRED, and userspace observes a spurious HDCP enable failure.
+Filter the connector iteration to only those with a CRTC assigned in
+the new atomic state, so intel_conn_to_vcpi() is called for the
+connector actually being enabled and reads its real VCPI from the MST
+topology state.
+
+Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
+Reviewed-by: Santhosh Reddy Guddati <santhosh.reddy.guddati@intel.com>
+Link: https://patch.msgid.link/20260505094022.4064256-1-suraj.kandpal@intel.com
+Stable-dep-of: bbb15a6b042d ("drm/i915/hdcp: check streams[] bounds before overflow")
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/i915/display/intel_hdcp.c |    6 ++++++
+ 1 file changed, 6 insertions(+)
+
+--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
+@@ -97,6 +97,7 @@ intel_hdcp_required_content_stream(struc
+ {
+       struct intel_display *display = to_intel_display(state);
+       struct drm_connector_list_iter conn_iter;
++      struct drm_connector_state *new_conn_state;
+       struct intel_digital_port *conn_dig_port;
+       struct intel_connector *connector;
+       struct hdcp_port_data *data = &dig_port->hdcp_port_data;
+@@ -123,6 +124,11 @@ intel_hdcp_required_content_stream(struc
+               if (conn_dig_port != dig_port)
+                       continue;
++              new_conn_state = drm_atomic_get_new_connector_state(&state->base,
++                                                                  &connector->base);
++              if (!new_conn_state || !new_conn_state->crtc)
++                      continue;
++
+               data->streams[data->k].stream_id =
+                       intel_conn_to_vcpi(state, connector);
+               data->k++;
diff --git a/queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch b/queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch
new file mode 100644 (file)
index 0000000..9f7a238
--- /dev/null
@@ -0,0 +1,66 @@
+From stable+bounces-294797-greg=kroah.com@vger.kernel.org Mon Aug  3 18:24:14 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Mon,  3 Aug 2026 11:30:42 -0400
+Subject: drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
+To: stable@vger.kernel.org
+Cc: "Zongyao Bai" <zongyao.bai@intel.com>, "Matthew Auld" <matthew.auld@intel.com>, "Matthew Brost" <matthew.brost@intel.com>, "Thomas Hellström" <thomas.hellstrom@linux.intel.com>, "Sasha Levin" <sashal@kernel.org>
+Message-ID: <20260803153043.878690-2-sashal@kernel.org>
+
+From: Zongyao Bai <zongyao.bai@intel.com>
+
+[ Upstream commit 6384271ac1ac0099198d15df79212a19ebdb929d ]
+
+xe_pt_update_ops_init() fails to reset current_op to 0. On the
+vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside
+the xe_validation_guard() / drm_exec_until_all_locked() loop. When
+that loop retries due to lock contention or OOM eviction
+(drm_exec_retry_on_contention() / xe_validation_retry_on_oom()),
+xe_pt_update_ops_prepare() runs again on the same vops, and each
+call to bind_op_prepare() increments current_op without resetting it.
+
+After N retries current_op exceeds the array size allocated by
+xe_vma_ops_alloc(), causing an out-of-bounds write into
+SLUB-poisoned memory and a subsequent UAF crash in
+xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op->bind.
+
+Also reset needs_svm_lock and needs_invalidation which are derived in
+the same prepare pass and would otherwise cause wrong migrate ops
+selection and redundant TLB invalidation on retry.
+
+Fix this by resetting current_op, needs_svm_lock and needs_invalidation
+in xe_pt_update_ops_init().
+
+v2 (Matt):
+   - Add details in commit message.
+   - Add Fixes tag and Cc to stable@vger.kernel.org
+
+Fixes: e8babb280b5e ("drm/xe: Convert multiple bind ops into single job")
+Suggested-by: Matthew Auld <matthew.auld@intel.com>
+Cc: stable@vger.kernel.org
+Assisted-by: GitHub-Copilot:claude-sonnet-4.6
+Signed-off-by: Zongyao Bai <zongyao.bai@intel.com>
+Reviewed-by: Matthew Brost <matthew.brost@intel.com>
+Signed-off-by: Matthew Brost <matthew.brost@intel.com>
+Link: https://patch.msgid.link/20260714232433.2737533-1-zongyao.bai@intel.com
+(cherry picked from commit 046045543e530605c441063535e7dca0075369a6)
+Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/xe/xe_pt.c |    3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/gpu/drm/xe/xe_pt.c
++++ b/drivers/gpu/drm/xe/xe_pt.c
+@@ -1833,8 +1833,11 @@ static void
+ xe_pt_update_ops_init(struct xe_vm_pgtable_update_ops *pt_update_ops)
+ {
+       init_llist_head(&pt_update_ops->deferred);
++      pt_update_ops->current_op = 0;
+       pt_update_ops->start = ~0x0ull;
+       pt_update_ops->last = 0x0ull;
++      pt_update_ops->needs_userptr_lock = false;
++      pt_update_ops->needs_invalidation = false;
+ }
+ /**
diff --git a/queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch b/queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch
new file mode 100644 (file)
index 0000000..337dc9e
--- /dev/null
@@ -0,0 +1,281 @@
+From stable+bounces-294796-greg=kroah.com@vger.kernel.org Mon Aug  3 19:00:29 2026
+From: Sasha Levin <sashal@kernel.org>
+Date: Mon,  3 Aug 2026 11:30:41 -0400
+Subject: drm/xe: Stub out new pagefault layer
+To: stable@vger.kernel.org
+Cc: Matthew Brost <matthew.brost@intel.com>, Lucas De Marchi <lucas.demarchi@intel.com>, Francois Dugast <francois.dugast@intel.com>, Sasha Levin <sashal@kernel.org>
+Message-ID: <20260803153043.878690-1-sashal@kernel.org>
+
+From: Matthew Brost <matthew.brost@intel.com>
+
+[ Upstream commit 620a09fb0bddf387f418663478b48ca4ba62b6d6 ]
+
+Stub out the new page fault layer and add kernel documentation. This is
+intended as a replacement for the GT page fault layer, enabling multiple
+producers to hook into a shared page fault consumer interface.
+
+v2:
+ - Fix kernel doc typo (checkpatch)
+ - Remove comment around GT (Stuart)
+ - Add explaination around reclaim (Francois)
+ - Add comment around u8 vs enum (Francois)
+ - Include engine instance (Stuart)
+v3:
+ - Fix XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION kernel doc (Stuart)
+
+Signed-off-by: Matthew Brost <matthew.brost@intel.com>
+Reviewed-by: Lucas De Marchi <lucas.demarchi@intel.com>
+Tested-by: Francois Dugast <francois.dugast@intel.com>
+Link: https://patch.msgid.link/20251031165416.2871503-2-matthew.brost@intel.com
+Stable-dep-of: 6384271ac1ac ("drm/xe/pt: Reset current_op in xe_pt_update_ops_init()")
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/xe/Makefile             |    1 
+ drivers/gpu/drm/xe/xe_pagefault.c       |   65 +++++++++++++++
+ drivers/gpu/drm/xe/xe_pagefault.h       |   19 ++++
+ drivers/gpu/drm/xe/xe_pagefault_types.h |  136 ++++++++++++++++++++++++++++++++
+ 4 files changed, 221 insertions(+)
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault.c
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault.h
+ create mode 100644 drivers/gpu/drm/xe/xe_pagefault_types.h
+
+--- a/drivers/gpu/drm/xe/Makefile
++++ b/drivers/gpu/drm/xe/Makefile
+@@ -78,6 +78,7 @@ xe-y += xe_bb.o \
+       xe_module.o \
+       xe_oa.o \
+       xe_observation.o \
++      xe_pagefault.o \
+       xe_pat.o \
+       xe_pci.o \
+       xe_pcode.o \
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault.c
+@@ -0,0 +1,65 @@
++// SPDX-License-Identifier: MIT
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#include "xe_pagefault.h"
++#include "xe_pagefault_types.h"
++
++/**
++ * DOC: Xe page faults
++ *
++ * Xe page faults are handled in two layers. The producer layer interacts with
++ * hardware or firmware to receive and parse faults into struct xe_pagefault,
++ * then forwards them to the consumer. The consumer layer services the faults
++ * (e.g., memory migration, page table updates) and acknowledges the result back
++ * to the producer, which then forwards the results to the hardware or firmware.
++ * The consumer uses a page fault queue sized to absorb all potential faults and
++ * a multi-threaded worker to process them. Multiple producers are supported,
++ * with a single shared consumer.
++ *
++ * xe_pagefault.c implements the consumer layer.
++ */
++
++/**
++ * xe_pagefault_init() - Page fault init
++ * @xe: xe device instance
++ *
++ * Initialize Xe page fault state. Must be done after reading fuses.
++ *
++ * Return: 0 on Success, errno on failure
++ */
++int xe_pagefault_init(struct xe_device *xe)
++{
++      /* TODO - implement */
++      return 0;
++}
++
++/**
++ * xe_pagefault_reset() - Page fault reset for a GT
++ * @xe: xe device instance
++ * @gt: GT being reset
++ *
++ * Reset the Xe page fault state for a GT; that is, squash any pending faults on
++ * the GT.
++ */
++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt)
++{
++      /* TODO - implement */
++}
++
++/**
++ * xe_pagefault_handler() - Page fault handler
++ * @xe: xe device instance
++ * @pf: Page fault
++ *
++ * Sink the page fault to a queue (i.e., a memory buffer) and queue a worker to
++ * service it. Safe to be called from IRQ or process context. Reclaim safe.
++ *
++ * Return: 0 on success, errno on failure
++ */
++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf)
++{
++      /* TODO - implement */
++      return 0;
++}
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault.h
+@@ -0,0 +1,19 @@
++/* SPDX-License-Identifier: MIT */
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#ifndef _XE_PAGEFAULT_H_
++#define _XE_PAGEFAULT_H_
++
++struct xe_device;
++struct xe_gt;
++struct xe_pagefault;
++
++int xe_pagefault_init(struct xe_device *xe);
++
++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt);
++
++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf);
++
++#endif
+--- /dev/null
++++ b/drivers/gpu/drm/xe/xe_pagefault_types.h
+@@ -0,0 +1,136 @@
++/* SPDX-License-Identifier: MIT */
++/*
++ * Copyright © 2025 Intel Corporation
++ */
++
++#ifndef _XE_PAGEFAULT_TYPES_H_
++#define _XE_PAGEFAULT_TYPES_H_
++
++#include <linux/workqueue.h>
++
++struct xe_gt;
++struct xe_pagefault;
++
++/** enum xe_pagefault_access_type - Xe page fault access type */
++enum xe_pagefault_access_type {
++      /** @XE_PAGEFAULT_ACCESS_TYPE_READ: Read access type */
++      XE_PAGEFAULT_ACCESS_TYPE_READ   = 0,
++      /** @XE_PAGEFAULT_ACCESS_TYPE_WRITE: Write access type */
++      XE_PAGEFAULT_ACCESS_TYPE_WRITE  = 1,
++      /** @XE_PAGEFAULT_ACCESS_TYPE_ATOMIC: Atomic access type */
++      XE_PAGEFAULT_ACCESS_TYPE_ATOMIC = 2,
++};
++
++/** enum xe_pagefault_type - Xe page fault type */
++enum xe_pagefault_type {
++      /** @XE_PAGEFAULT_TYPE_NOT_PRESENT: Not present */
++      XE_PAGEFAULT_TYPE_NOT_PRESENT                   = 0,
++      /** @XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION: Write access violation */
++      XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION        = 1,
++      /** @XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION: Atomic access violation */
++      XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION       = 2,
++};
++
++/** struct xe_pagefault_ops - Xe pagefault ops (producer) */
++struct xe_pagefault_ops {
++      /**
++       * @ack_fault: Ack fault
++       * @pf: Page fault
++       * @err: Error state of fault
++       *
++       * Page fault producer receives acknowledgment from the consumer and
++       * sends the result to the HW/FW interface.
++       */
++      void (*ack_fault)(struct xe_pagefault *pf, int err);
++};
++
++/**
++ * struct xe_pagefault - Xe page fault
++ *
++ * Generic page fault structure for communication between producer and consumer.
++ * Carefully sized to be 64 bytes. Upon a device page fault, the producer
++ * populates this structure, and the consumer copies it into the page-fault
++ * queue for deferred handling.
++ */
++struct xe_pagefault {
++      /**
++       * @gt: GT of fault
++       */
++      struct xe_gt *gt;
++      /**
++       * @consumer: State for the software handling the fault. Populated by
++       * the producer and may be modified by the consumer to communicate
++       * information back to the producer upon fault acknowledgment.
++       */
++      struct {
++              /** @consumer.page_addr: address of page fault */
++              u64 page_addr;
++              /** @consumer.asid: address space ID */
++              u32 asid;
++              /**
++               * @consumer.access_type: access type, u8 rather than enum to
++               * keep size compact
++               */
++              u8 access_type;
++              /**
++               * @consumer.fault_type: fault type, u8 rather than enum to
++               * keep size compact
++               */
++              u8 fault_type;
++#define XE_PAGEFAULT_LEVEL_NACK               0xff    /* Producer indicates nack fault */
++              /** @consumer.fault_level: fault level */
++              u8 fault_level;
++              /** @consumer.engine_class: engine class */
++              u8 engine_class;
++              /** @consumer.engine_instance: engine instance */
++              u8 engine_instance;
++              /** consumer.reserved: reserved bits for future expansion */
++              u8 reserved[7];
++      } consumer;
++      /**
++       * @producer: State for the producer (i.e., HW/FW interface). Populated
++       * by the producer and should not be modified—or even inspected—by the
++       * consumer, except for calling operations.
++       */
++      struct {
++              /** @producer.private: private pointer */
++              void *private;
++              /** @producer.ops: operations */
++              const struct xe_pagefault_ops *ops;
++#define XE_PAGEFAULT_PRODUCER_MSG_LEN_DW      4
++              /**
++               * @producer.msg: page fault message, used by producer in fault
++               * acknowledgment to formulate response to HW/FW interface.
++               * Included in the page-fault message because the producer
++               * typically receives the fault in a context where memory cannot
++               * be allocated (e.g., atomic context or the reclaim path).
++               */
++              u32 msg[XE_PAGEFAULT_PRODUCER_MSG_LEN_DW];
++      } producer;
++};
++
++/**
++ * struct xe_pagefault_queue: Xe pagefault queue (consumer)
++ *
++ * Used to capture all device page faults for deferred processing. Size this
++ * queue to absorb the device’s worst-case number of outstanding faults.
++ */
++struct xe_pagefault_queue {
++      /**
++       * @data: Data in queue containing struct xe_pagefault, protected by
++       * @lock
++       */
++      void *data;
++      /** @size: Size of queue in bytes */
++      u32 size;
++      /** @head: Head pointer in bytes, moved by producer, protected by @lock */
++      u32 head;
++      /** @tail: Tail pointer in bytes, moved by consumer, protected by @lock */
++      u32 tail;
++      /** @lock: protects page fault queue */
++      spinlock_t lock;
++      /** @worker: to process page faults */
++      struct work_struct worker;
++};
++
++#endif
index 34e79795c4d12a34870bb5b1a35ecf4a4824f679..0b9f8c8b7519a0285f5a0c06eaf3c5597448bb24 100644 (file)
@@ -322,3 +322,7 @@ drm-xe-rename-___xe_bo_create_locked.patch
 drm-xe-hold-a-dma-buf-reference-for-imported-bos.patch
 drm-i915-hdcp-move-to-using-intel_display-in-intel_hdcp.patch
 drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch
+drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch
+drm-i915-hdcp-check-streams-bounds-before-overflow.patch
+drm-xe-stub-out-new-pagefault-layer.patch
+drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch