> bool intel_hdcp_capable(struct intel_connector *connector)
> {
> - struct intel_digital_port *dig_port =
> intel_attached_dig_port(connector);
> + struct intel_digital_port *dig_port;
[...]
> + if (!intel_attached_encoder(connector))
> + return capable;
On 6.6 this doesn't stop the oops. The debugfs intel_hdcp_info() calls
intel_hdcp2_capable() right after intel_hdcp_capable(), and
intel_hdcp2_capable() still starts with intel_attached_dig_port(connector)
without an encoder check, so the NULL deref just moves one call later.
Upstream fixed that half in d34f4f058edf ("drm/i915/hdcp: Add encoder
check in hdcp2_get_capability"), CVE-2024-53050. Its CVE record says the
bug arrived in 6.7, but 130849f8ec14 ("drm/i915/hdcp: Use intel_connector
as argument for hdcp_2_2_capable") only moved the deref into the DP/HDMI
shims. 6.6 still has it in intel_hdcp2_capable() itself.
Could you resend this as a 2-patch 6.6.y series: this backport plus a 6.6
adaptation of the hdcp2 fix that guards intel_hdcp2_capable()?
--
Thanks,
Sasha