Commit 9cc3f93
committed
Do not build HDCP kernel modules
INTEL_MEI_HDCP and DRM_AMD_DC_PDCP are for High-bandwidth Digital
Content Protection (HDCP), and INTEL_MEI_PXP is for Protected Xe Path
(PXP). Since the Intel CSME and AMD Secure Processor must never be
passed through to a VM, these are only usable if there is an Intel or
AMD GPU attached to dom0. However, dom0 does not include any programs
that can use these modules, so the modules are unused. Worse, if HDCP
*was* used, it would, it would allow external displays (which are not
trusted) to communicate with the (closed-source and often out-of-date)
Intel CSME or AMD SP firmware, which is even more privileged than dom0.1 parent 1e3aa87 commit 9cc3f93
1 file changed
+16
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
158 | 158 | | |
159 | 159 | | |
160 | 160 | | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
161 | 177 | | |
162 | 178 | | |
163 | 179 | | |
| |||
0 commit comments