From: Greg Kroah-Hartman Date: Fri, 7 Aug 2026 13:06:33 +0000 (+0200) Subject: 6.12-stable patches X-Git-Tag: v6.6.151~19 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=5eb0b839762c61eabf33a2ea95a45e76bd70b89c;p=thirdparty%2Fkernel%2Fstable-queue.git 6.12-stable patches added patches: drm-i915-hdcp-check-streams-bounds-before-overflow.patch drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch drm-xe-stub-out-new-pagefault-layer.patch --- diff --git a/queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch b/queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch new file mode 100644 index 0000000000..a6706b7966 --- /dev/null +++ b/queue-6.12/drm-i915-hdcp-check-streams-bounds-before-overflow.patch @@ -0,0 +1,59 @@ +From stable+bounces-294461-greg=kroah.com@vger.kernel.org Sun Aug 2 04:33:28 2026 +From: Sasha Levin +Date: Sat, 1 Aug 2026 22:33:17 -0400 +Subject: drm/i915/hdcp: check streams[] bounds before overflow +To: stable@vger.kernel.org +Cc: Jani Nikula , Martin Hodo , Anshuman Gupta , Suraj Kandpal , Joonas Lahtinen , Sasha Levin +Message-ID: <20260802023317.1298318-3-sashal@kernel.org> + +From: Jani Nikula + +[ Upstream commit bbb15a6b042d02e5508a02b4847e02d2579ee7bc ] + +The data->streams[] overflow check is done after the buffer overflow has +already happened. Move the overflow check before the write. + +Side note, emitting a warning splat with a backtrace might be overkill +here, but prefer not changing the behaviour other than not doing the +overrun. + +Discovered using AI-assisted static analysis confirmed by Intel Product +Security. + +Reported-by: Martin Hodo +Fixes: e03187e12cae ("drm/i915/hdcp: MST streams support in hdcp port_data") +Cc: stable@vger.kernel.org # v5.12+ +Cc: Anshuman Gupta +Cc: Suraj Kandpal +Reviewed-by: Suraj Kandpal +Link: https://patch.msgid.link/20260625170304.1104723-1-jani.nikula@intel.com +Signed-off-by: Jani Nikula +(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd) +Signed-off-by: Joonas Lahtinen +Signed-off-by: Sasha Levin +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/i915/display/intel_hdcp.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +--- a/drivers/gpu/drm/i915/display/intel_hdcp.c ++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c +@@ -129,6 +129,9 @@ intel_hdcp_required_content_stream(struc + if (!new_conn_state || !new_conn_state->crtc) + continue; + ++ if (drm_WARN_ON(display->drm, data->k >= INTEL_NUM_PIPES(display))) ++ return -EINVAL; ++ + data->streams[data->k].stream_id = + intel_conn_to_vcpi(state, connector); + data->k++; +@@ -139,7 +142,7 @@ intel_hdcp_required_content_stream(struc + } + drm_connector_list_iter_end(&conn_iter); + +- if (drm_WARN_ON(display->drm, data->k > INTEL_NUM_PIPES(display) || data->k == 0)) ++ if (drm_WARN_ON(display->drm, !data->k)) + return -EINVAL; + + /* diff --git a/queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch b/queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch new file mode 100644 index 0000000000..3a7bbf22f2 --- /dev/null +++ b/queue-6.12/drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch @@ -0,0 +1,63 @@ +From stable+bounces-294460-greg=kroah.com@vger.kernel.org Sun Aug 2 04:33:25 2026 +From: Sasha Levin +Date: Sat, 1 Aug 2026 22:33:16 -0400 +Subject: drm/i915/hdcp: Skip inactive MST connectors when building stream list +To: stable@vger.kernel.org +Cc: Suraj Kandpal , Santhosh Reddy Guddati , Sasha Levin +Message-ID: <20260802023317.1298318-2-sashal@kernel.org> + +From: Suraj Kandpal + +[ Upstream commit 0161e2c2016337a2f22ef79dff0aee43c0841bce ] + +intel_hdcp_required_content_stream() walks every connector on the +digital port to populate hdcp_port_data->streams[]. The only filter is +connector_status_disconnected, which reflects physical presence on the +MST topology, not whether the connector currently drives a stream. +On a multi-sink MST setup where only a subset of sinks are modeset, +the loop can pick a sibling MST connector that is connected but has +no active CRTC / VC payload. intel_conn_to_vcpi() then logs "MST +Payload not present" and returns 0, and the bogus StreamID=0 is +written to the repeater in RepeaterAuth_Stream_Manage (DPCD 0x693F0). +Authentication completes, but the repeater shortly raises +LINK_INTEGRITY_FAILURE (RxStatus 0x69493 bit4) because the StreamID +does not match any stream on its input. The HDCP check work then +tears the link down, the Content Protection property drops back to +DESIRED, and userspace observes a spurious HDCP enable failure. +Filter the connector iteration to only those with a CRTC assigned in +the new atomic state, so intel_conn_to_vcpi() is called for the +connector actually being enabled and reads its real VCPI from the MST +topology state. + +Signed-off-by: Suraj Kandpal +Reviewed-by: Santhosh Reddy Guddati +Link: https://patch.msgid.link/20260505094022.4064256-1-suraj.kandpal@intel.com +Stable-dep-of: bbb15a6b042d ("drm/i915/hdcp: check streams[] bounds before overflow") +Signed-off-by: Sasha Levin +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/i915/display/intel_hdcp.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +--- a/drivers/gpu/drm/i915/display/intel_hdcp.c ++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c +@@ -97,6 +97,7 @@ intel_hdcp_required_content_stream(struc + { + struct intel_display *display = to_intel_display(state); + struct drm_connector_list_iter conn_iter; ++ struct drm_connector_state *new_conn_state; + struct intel_digital_port *conn_dig_port; + struct intel_connector *connector; + struct hdcp_port_data *data = &dig_port->hdcp_port_data; +@@ -123,6 +124,11 @@ intel_hdcp_required_content_stream(struc + if (conn_dig_port != dig_port) + continue; + ++ new_conn_state = drm_atomic_get_new_connector_state(&state->base, ++ &connector->base); ++ if (!new_conn_state || !new_conn_state->crtc) ++ continue; ++ + data->streams[data->k].stream_id = + intel_conn_to_vcpi(state, connector); + data->k++; diff --git a/queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch b/queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch new file mode 100644 index 0000000000..9f7a2381ca --- /dev/null +++ b/queue-6.12/drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch @@ -0,0 +1,66 @@ +From stable+bounces-294797-greg=kroah.com@vger.kernel.org Mon Aug 3 18:24:14 2026 +From: Sasha Levin +Date: Mon, 3 Aug 2026 11:30:42 -0400 +Subject: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() +To: stable@vger.kernel.org +Cc: "Zongyao Bai" , "Matthew Auld" , "Matthew Brost" , "Thomas Hellström" , "Sasha Levin" +Message-ID: <20260803153043.878690-2-sashal@kernel.org> + +From: Zongyao Bai + +[ Upstream commit 6384271ac1ac0099198d15df79212a19ebdb929d ] + +xe_pt_update_ops_init() fails to reset current_op to 0. On the +vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside +the xe_validation_guard() / drm_exec_until_all_locked() loop. When +that loop retries due to lock contention or OOM eviction +(drm_exec_retry_on_contention() / xe_validation_retry_on_oom()), +xe_pt_update_ops_prepare() runs again on the same vops, and each +call to bind_op_prepare() increments current_op without resetting it. + +After N retries current_op exceeds the array size allocated by +xe_vma_ops_alloc(), causing an out-of-bounds write into +SLUB-poisoned memory and a subsequent UAF crash in +xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op->bind. + +Also reset needs_svm_lock and needs_invalidation which are derived in +the same prepare pass and would otherwise cause wrong migrate ops +selection and redundant TLB invalidation on retry. + +Fix this by resetting current_op, needs_svm_lock and needs_invalidation +in xe_pt_update_ops_init(). + +v2 (Matt): + - Add details in commit message. + - Add Fixes tag and Cc to stable@vger.kernel.org + +Fixes: e8babb280b5e ("drm/xe: Convert multiple bind ops into single job") +Suggested-by: Matthew Auld +Cc: stable@vger.kernel.org +Assisted-by: GitHub-Copilot:claude-sonnet-4.6 +Signed-off-by: Zongyao Bai +Reviewed-by: Matthew Brost +Signed-off-by: Matthew Brost +Link: https://patch.msgid.link/20260714232433.2737533-1-zongyao.bai@intel.com +(cherry picked from commit 046045543e530605c441063535e7dca0075369a6) +Signed-off-by: Thomas Hellström +Signed-off-by: Sasha Levin +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/xe/xe_pt.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/gpu/drm/xe/xe_pt.c ++++ b/drivers/gpu/drm/xe/xe_pt.c +@@ -1833,8 +1833,11 @@ static void + xe_pt_update_ops_init(struct xe_vm_pgtable_update_ops *pt_update_ops) + { + init_llist_head(&pt_update_ops->deferred); ++ pt_update_ops->current_op = 0; + pt_update_ops->start = ~0x0ull; + pt_update_ops->last = 0x0ull; ++ pt_update_ops->needs_userptr_lock = false; ++ pt_update_ops->needs_invalidation = false; + } + + /** diff --git a/queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch b/queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch new file mode 100644 index 0000000000..337dc9e6e3 --- /dev/null +++ b/queue-6.12/drm-xe-stub-out-new-pagefault-layer.patch @@ -0,0 +1,281 @@ +From stable+bounces-294796-greg=kroah.com@vger.kernel.org Mon Aug 3 19:00:29 2026 +From: Sasha Levin +Date: Mon, 3 Aug 2026 11:30:41 -0400 +Subject: drm/xe: Stub out new pagefault layer +To: stable@vger.kernel.org +Cc: Matthew Brost , Lucas De Marchi , Francois Dugast , Sasha Levin +Message-ID: <20260803153043.878690-1-sashal@kernel.org> + +From: Matthew Brost + +[ Upstream commit 620a09fb0bddf387f418663478b48ca4ba62b6d6 ] + +Stub out the new page fault layer and add kernel documentation. This is +intended as a replacement for the GT page fault layer, enabling multiple +producers to hook into a shared page fault consumer interface. + +v2: + - Fix kernel doc typo (checkpatch) + - Remove comment around GT (Stuart) + - Add explaination around reclaim (Francois) + - Add comment around u8 vs enum (Francois) + - Include engine instance (Stuart) +v3: + - Fix XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION kernel doc (Stuart) + +Signed-off-by: Matthew Brost +Reviewed-by: Lucas De Marchi +Tested-by: Francois Dugast +Link: https://patch.msgid.link/20251031165416.2871503-2-matthew.brost@intel.com +Stable-dep-of: 6384271ac1ac ("drm/xe/pt: Reset current_op in xe_pt_update_ops_init()") +Signed-off-by: Sasha Levin +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/xe/Makefile | 1 + drivers/gpu/drm/xe/xe_pagefault.c | 65 +++++++++++++++ + drivers/gpu/drm/xe/xe_pagefault.h | 19 ++++ + drivers/gpu/drm/xe/xe_pagefault_types.h | 136 ++++++++++++++++++++++++++++++++ + 4 files changed, 221 insertions(+) + create mode 100644 drivers/gpu/drm/xe/xe_pagefault.c + create mode 100644 drivers/gpu/drm/xe/xe_pagefault.h + create mode 100644 drivers/gpu/drm/xe/xe_pagefault_types.h + +--- a/drivers/gpu/drm/xe/Makefile ++++ b/drivers/gpu/drm/xe/Makefile +@@ -78,6 +78,7 @@ xe-y += xe_bb.o \ + xe_module.o \ + xe_oa.o \ + xe_observation.o \ ++ xe_pagefault.o \ + xe_pat.o \ + xe_pci.o \ + xe_pcode.o \ +--- /dev/null ++++ b/drivers/gpu/drm/xe/xe_pagefault.c +@@ -0,0 +1,65 @@ ++// SPDX-License-Identifier: MIT ++/* ++ * Copyright © 2025 Intel Corporation ++ */ ++ ++#include "xe_pagefault.h" ++#include "xe_pagefault_types.h" ++ ++/** ++ * DOC: Xe page faults ++ * ++ * Xe page faults are handled in two layers. The producer layer interacts with ++ * hardware or firmware to receive and parse faults into struct xe_pagefault, ++ * then forwards them to the consumer. The consumer layer services the faults ++ * (e.g., memory migration, page table updates) and acknowledges the result back ++ * to the producer, which then forwards the results to the hardware or firmware. ++ * The consumer uses a page fault queue sized to absorb all potential faults and ++ * a multi-threaded worker to process them. Multiple producers are supported, ++ * with a single shared consumer. ++ * ++ * xe_pagefault.c implements the consumer layer. ++ */ ++ ++/** ++ * xe_pagefault_init() - Page fault init ++ * @xe: xe device instance ++ * ++ * Initialize Xe page fault state. Must be done after reading fuses. ++ * ++ * Return: 0 on Success, errno on failure ++ */ ++int xe_pagefault_init(struct xe_device *xe) ++{ ++ /* TODO - implement */ ++ return 0; ++} ++ ++/** ++ * xe_pagefault_reset() - Page fault reset for a GT ++ * @xe: xe device instance ++ * @gt: GT being reset ++ * ++ * Reset the Xe page fault state for a GT; that is, squash any pending faults on ++ * the GT. ++ */ ++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt) ++{ ++ /* TODO - implement */ ++} ++ ++/** ++ * xe_pagefault_handler() - Page fault handler ++ * @xe: xe device instance ++ * @pf: Page fault ++ * ++ * Sink the page fault to a queue (i.e., a memory buffer) and queue a worker to ++ * service it. Safe to be called from IRQ or process context. Reclaim safe. ++ * ++ * Return: 0 on success, errno on failure ++ */ ++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf) ++{ ++ /* TODO - implement */ ++ return 0; ++} +--- /dev/null ++++ b/drivers/gpu/drm/xe/xe_pagefault.h +@@ -0,0 +1,19 @@ ++/* SPDX-License-Identifier: MIT */ ++/* ++ * Copyright © 2025 Intel Corporation ++ */ ++ ++#ifndef _XE_PAGEFAULT_H_ ++#define _XE_PAGEFAULT_H_ ++ ++struct xe_device; ++struct xe_gt; ++struct xe_pagefault; ++ ++int xe_pagefault_init(struct xe_device *xe); ++ ++void xe_pagefault_reset(struct xe_device *xe, struct xe_gt *gt); ++ ++int xe_pagefault_handler(struct xe_device *xe, struct xe_pagefault *pf); ++ ++#endif +--- /dev/null ++++ b/drivers/gpu/drm/xe/xe_pagefault_types.h +@@ -0,0 +1,136 @@ ++/* SPDX-License-Identifier: MIT */ ++/* ++ * Copyright © 2025 Intel Corporation ++ */ ++ ++#ifndef _XE_PAGEFAULT_TYPES_H_ ++#define _XE_PAGEFAULT_TYPES_H_ ++ ++#include ++ ++struct xe_gt; ++struct xe_pagefault; ++ ++/** enum xe_pagefault_access_type - Xe page fault access type */ ++enum xe_pagefault_access_type { ++ /** @XE_PAGEFAULT_ACCESS_TYPE_READ: Read access type */ ++ XE_PAGEFAULT_ACCESS_TYPE_READ = 0, ++ /** @XE_PAGEFAULT_ACCESS_TYPE_WRITE: Write access type */ ++ XE_PAGEFAULT_ACCESS_TYPE_WRITE = 1, ++ /** @XE_PAGEFAULT_ACCESS_TYPE_ATOMIC: Atomic access type */ ++ XE_PAGEFAULT_ACCESS_TYPE_ATOMIC = 2, ++}; ++ ++/** enum xe_pagefault_type - Xe page fault type */ ++enum xe_pagefault_type { ++ /** @XE_PAGEFAULT_TYPE_NOT_PRESENT: Not present */ ++ XE_PAGEFAULT_TYPE_NOT_PRESENT = 0, ++ /** @XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION: Write access violation */ ++ XE_PAGEFAULT_TYPE_WRITE_ACCESS_VIOLATION = 1, ++ /** @XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION: Atomic access violation */ ++ XE_PAGEFAULT_TYPE_ATOMIC_ACCESS_VIOLATION = 2, ++}; ++ ++/** struct xe_pagefault_ops - Xe pagefault ops (producer) */ ++struct xe_pagefault_ops { ++ /** ++ * @ack_fault: Ack fault ++ * @pf: Page fault ++ * @err: Error state of fault ++ * ++ * Page fault producer receives acknowledgment from the consumer and ++ * sends the result to the HW/FW interface. ++ */ ++ void (*ack_fault)(struct xe_pagefault *pf, int err); ++}; ++ ++/** ++ * struct xe_pagefault - Xe page fault ++ * ++ * Generic page fault structure for communication between producer and consumer. ++ * Carefully sized to be 64 bytes. Upon a device page fault, the producer ++ * populates this structure, and the consumer copies it into the page-fault ++ * queue for deferred handling. ++ */ ++struct xe_pagefault { ++ /** ++ * @gt: GT of fault ++ */ ++ struct xe_gt *gt; ++ /** ++ * @consumer: State for the software handling the fault. Populated by ++ * the producer and may be modified by the consumer to communicate ++ * information back to the producer upon fault acknowledgment. ++ */ ++ struct { ++ /** @consumer.page_addr: address of page fault */ ++ u64 page_addr; ++ /** @consumer.asid: address space ID */ ++ u32 asid; ++ /** ++ * @consumer.access_type: access type, u8 rather than enum to ++ * keep size compact ++ */ ++ u8 access_type; ++ /** ++ * @consumer.fault_type: fault type, u8 rather than enum to ++ * keep size compact ++ */ ++ u8 fault_type; ++#define XE_PAGEFAULT_LEVEL_NACK 0xff /* Producer indicates nack fault */ ++ /** @consumer.fault_level: fault level */ ++ u8 fault_level; ++ /** @consumer.engine_class: engine class */ ++ u8 engine_class; ++ /** @consumer.engine_instance: engine instance */ ++ u8 engine_instance; ++ /** consumer.reserved: reserved bits for future expansion */ ++ u8 reserved[7]; ++ } consumer; ++ /** ++ * @producer: State for the producer (i.e., HW/FW interface). Populated ++ * by the producer and should not be modified—or even inspected—by the ++ * consumer, except for calling operations. ++ */ ++ struct { ++ /** @producer.private: private pointer */ ++ void *private; ++ /** @producer.ops: operations */ ++ const struct xe_pagefault_ops *ops; ++#define XE_PAGEFAULT_PRODUCER_MSG_LEN_DW 4 ++ /** ++ * @producer.msg: page fault message, used by producer in fault ++ * acknowledgment to formulate response to HW/FW interface. ++ * Included in the page-fault message because the producer ++ * typically receives the fault in a context where memory cannot ++ * be allocated (e.g., atomic context or the reclaim path). ++ */ ++ u32 msg[XE_PAGEFAULT_PRODUCER_MSG_LEN_DW]; ++ } producer; ++}; ++ ++/** ++ * struct xe_pagefault_queue: Xe pagefault queue (consumer) ++ * ++ * Used to capture all device page faults for deferred processing. Size this ++ * queue to absorb the device’s worst-case number of outstanding faults. ++ */ ++struct xe_pagefault_queue { ++ /** ++ * @data: Data in queue containing struct xe_pagefault, protected by ++ * @lock ++ */ ++ void *data; ++ /** @size: Size of queue in bytes */ ++ u32 size; ++ /** @head: Head pointer in bytes, moved by producer, protected by @lock */ ++ u32 head; ++ /** @tail: Tail pointer in bytes, moved by consumer, protected by @lock */ ++ u32 tail; ++ /** @lock: protects page fault queue */ ++ spinlock_t lock; ++ /** @worker: to process page faults */ ++ struct work_struct worker; ++}; ++ ++#endif diff --git a/queue-6.12/series b/queue-6.12/series index 34e79795c4..0b9f8c8b75 100644 --- a/queue-6.12/series +++ b/queue-6.12/series @@ -322,3 +322,7 @@ drm-xe-rename-___xe_bo_create_locked.patch drm-xe-hold-a-dma-buf-reference-for-imported-bos.patch drm-i915-hdcp-move-to-using-intel_display-in-intel_hdcp.patch drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch +drm-i915-hdcp-skip-inactive-mst-connectors-when-building-stream-list.patch +drm-i915-hdcp-check-streams-bounds-before-overflow.patch +drm-xe-stub-out-new-pagefault-layer.patch +drm-xe-pt-reset-current_op-in-xe_pt_update_ops_init.patch