Commit Graph
344662 Commits
Author SHA1 Message Date
savoca 2345c8a1bc video: mdss: Report PCC values from pp registers
Other drivers write to these regs (KCAL, Sony) and other developers may
implement more than one driver. Make sure we are always reporting the correct
PCC values.

Change-Id: Id4a28602d6678d8032f1328c49163b52c15d52b1
2019-08-05 14:21:52 +02:00
Kevin F. Haggerty 238a0fb5ad Merge tag 'v3.4.113' into lineage-16.0
This is the 3.4.113 stable release

Change-Id: I80791430656359c5447a675cbff4431362d18df0
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 14:20:47 +02:00
myfluxi 36738e5d0d arm: vfpmodule: Fix warning procfs vfp_bounce reporting failed
Creation of procfs cpu/vfp_bounce fails because we're initialized too early. Fix
this by creating it on rootfs_initcall as before the NEON patches.

<6>[    0.130770] VFP support v0.3: implementor 51 architecture 64 part 6f varia
nt 2 rev 0
<4>[    0.130795] ------------[ cut here ]------------
<4>[    0.130813] WARNING: at fs/proc/generic.c:323 __xlate_proc_name+0xac/0xcc(
)
<4>[    0.130822] name 'cpu/vfp_bounce'
<4>[    0.130855] [<c010e26c>] (unwind_backtrace+0x0/0x144) from [<c0a20f58>] (d
ump_stack+0x20/0x24)
<4>[    0.130879] [<c0a20f58>] (dump_stack+0x20/0x24) from [<c019b670>] (warn_sl
owpath_common+0x58/0x70)
<4>[    0.130899] [<c019b670>] (warn_slowpath_common+0x58/0x70) from [<c019b704>
] (warn_slowpath_fmt+0x40/0x48)
<4>[    0.130919] [<c019b704>] (warn_slowpath_fmt+0x40/0x48) from [<c02c2ad8>] (
__xlate_proc_name+0xac/0xcc)
<4>[    0.130938] [<c02c2ad8>] (__xlate_proc_name+0xac/0xcc) from [<c02c2b50>] (
__proc_create+0x58/0x100)
<4>[    0.130956] [<c02c2b50>] (__proc_create+0x58/0x100) from [<c02c2ed0>] (pro
c_create_data+0x5c/0xc0)
<4>[    0.130979] [<c02c2ed0>] (proc_create_data+0x5c/0xc0) from [<c0f03484>] (v
fp_init+0x19c/0x200)
<4>[    0.131000] [<c0f03484>] (vfp_init+0x19c/0x200) from [<c0f00c98>] (do_one_
initcall+0x98/0x168)
<4>[    0.131020] [<c0f00c98>] (do_one_initcall+0x98/0x168) from [<c0f00e60>] (k
ernel_init+0xf8/0x1b4)
<4>[    0.131043] [<c0f00e60>] (kernel_init+0xf8/0x1b4) from [<c01081a0>] (kerne
l_thread_exit+0x0/0x8)
<4>[    0.131076] ---[ end trace ea6d9a9b5e947151 ]---
<3>[    0.131086] Failed to create procfs node for VFP bounce reporting

Change-Id: I15b89f46fc357f96513cd03cf60288bd3e0ab84e
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 11:29:10 +02:00
Francescodario Cuzzocrea e20e6a0613 Merge tag 'LA.BF.1.1.3-02310-8x26.0' into lineage-16.0 2019-08-05 11:18:51 +02:00
Kevin F. Haggerty 586ff28144 drivers: fingerprint: Kill FEATURE_SPI_WAKELOCK
* Phone doesn't sleep at all with this "feature" enabled
* FP behavior is seemingly equivalent to cm-13 with this gone
* Yeah, hacky, but so is the driver implementation

Change-Id: Id2be5c6189b0ee18779e03d9d6a62014653c27a8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:27 +02:00
Andrea Arcangeli 09afaae4cf msm8226: Compress the kernel using XZ
This is needed to avoid the recovery going over the size limit.

Change-Id: Iaf6ff4fefbfd21be5d7f466b2397548392394b95
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:26 +02:00
Uwe Kleine-König 32385b90c7 ARM: 8160/1: drop warning about return_address not using unwind tables
The warning was introduced in 2009 (commit 4bf1fa5a34 ([ARM] 5613/1:
implement CALLER_ADDRESSx)). The only "problem" here is that
CALLER_ADDRESSx for x > 1 returns NULL which doesn't do much harm.

The drawback of implementing a fix (i.e. use unwind tables to implement CALLER_ADDRESSx) is that much of the unwinder code would need to be marked as not
traceable.

Change-Id: I40661f7415dffcc6b5421273666a2e9feadce784
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:26 +02:00
Pranav Vashi 91a66eb612 msm: use of swp{b} is deprecated for ARMv6+
Change-Id: I6ac5b459dcdc0b4a8d88df12243dfeb9468bcc0d
Signed-off-by: Pranav Vashi <neobuddy89@gmail.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:26 +02:00
Cal Archer 82ee7cf405 ASoC: ES705: fix mediaserver hang on restart
If mediaserver crashes it might hang in es705_wakeup()
on restart, leading to watchdog killing systemserver
and endless wait for service media.audio_policy.

[10750.498808] kworker/0:3     D c0a354b4     0 19414      2 0x00000200
[10750.498840] [<c0a354b4>] (__schedule+0x590/0x7bc) from [<c0a35790>] (schedule_preempt_disabled+0x24/0x34)
[10750.498862] [<c0a35790>] (schedule_preempt_disabled+0x24/0x34) from [<c0a34814>] (__mutex_lock_slowpath+0x170/0x1c8)
[10750.498884] [<c0a34814>] (__mutex_lock_slowpath+0x170/0x1c8) from [<c0a3488c>] (mutex_lock+0x20/0x40)
[10750.498908] [<c0a3488c>] (mutex_lock+0x20/0x40) from [<c08458f4>] (es705_bootup+0x2c/0xa4)
[10750.498927] [<c08458f4>] (es705_bootup+0x2c/0xa4) from [<c08459a0>] (restore_std_fw+0x34/0x60)
[10750.498946] [<c08459a0>] (restore_std_fw+0x34/0x60) from [<c08465b4>] (es705_sleep+0x84/0x1f4)
[10750.498966] [<c08465b4>] (es705_sleep+0x84/0x1f4) from [<c01b012c>] (process_one_work+0x270/0x434)
[10750.498987] [<c01b012c>] (process_one_work+0x270/0x434) from [<c01b0de4>] (worker_thread+0x198/0x2d8)
[10750.499007] [<c01b0de4>] (worker_thread+0x198/0x2d8) from [<c01b52b0>] (kthread+0x84/0x90)
[10750.499026] [<c01b52b0>] (kthread+0x84/0x90) from [<c0106ef0>] (kernel_thread_exit+0x0/0x8)
[10750.499038] mediaserver     D c0a354b4     0 21682      1 0x00000201
[10750.499068] [<c0a354b4>] (__schedule+0x590/0x7bc) from [<c0a33bd0>] (schedule_timeout+0x28/0x32c)
[10750.499088] [<c0a33bd0>] (schedule_timeout+0x28/0x32c) from [<c0a35d64>] (wait_for_common+0x11c/0x15c)
[10750.499108] [<c0a35d64>] (wait_for_common+0x11c/0x15c) from [<c01b0b14>] (wait_on_work+0xbc/0x108)
[10750.499129] [<c01b0b14>] (wait_on_work+0xbc/0x108) from [<c01b0bd8>] (__cancel_work_timer+0x78/0xec)
[10750.499149] [<c01b0bd8>] (__cancel_work_timer+0x78/0xec) from [<c0845a30>] (es705_wakeup+0x64/0x270)
[10750.499169] [<c0845a30>] (es705_wakeup+0x64/0x270) from [<c08461ac>] (es705_power_control+0x154/0x4d8)
[10750.499188] [<c08461ac>] (es705_power_control+0x154/0x4d8) from [<c0843360>] (es705_read_write_power_control+0x58/0x60)
[10750.499209] [<c0843360>] (es705_read_write_power_control+0x58/0x60) from [<c0843664>] (es705_get_control_enum+0x18/0x64)
[10750.499233] [<c0843664>] (es705_get_control_enum+0x18/0x64) from [<c07fcd8c>] (snd_ctl_ioctl+0x588/0xb1c)
[10750.499258] [<c07fcd8c>] (snd_ctl_ioctl+0x588/0xb1c) from [<c02681fc>] (vfs_ioctl+0x28/0x3c)
[10750.499279] [<c02681fc>] (vfs_ioctl+0x28/0x3c) from [<c0268c4c>] (do_vfs_ioctl+0x488/0x578)
[10750.499297] [<c0268c4c>] (do_vfs_ioctl+0x488/0x578) from [<c0268d84>] (sys_ioctl+0x48/0x74)
[10750.499317] [<c0268d84>] (sys_ioctl+0x48/0x74) from [<c010651c>] (__sys_trace_return+0x0/0x24)

Change-Id: Ibe0750413b59301d0249c2c1a357880fc4dbde0f
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:26 +02:00
ninez 38f1006d11 misc: Fix system_rev type mismatch
* Samsung sources have type mismatches in 3 of their drivers. This was
  uncovered using linaro's toolchain for kernel compilation.

Change-Id: If3a083ffcb2a15185ff208b22976509ffd8af5e8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:25 +02:00
Cal Archer 3a9dd67510 msm_bam_rmnet: fix deadlock during device encryption
During device encrytion vold reboots and afer reboot
sets vold.decrypt to trigger_restart_min_framework
to bringup CryptKeeper's progress bar.
In this scenario the timing between rild starting and
initializing rmnet, and brcmdhd sdio driver initialization
reliably leads to AB-BA deadlock between rtnl_lock
and the platform bus mutex.
Work around it by temporarily dropping the rtnl lock.
A proper fix would probably have to avoid calling
platform_driver_register() from either .ndo_open
or .ndo_do_ioctl.

[  829.661964] rild            D c0af27a8     0   485      1 0x00000200
[  829.661978] [<c0af27a8>] (__schedule+0x5b8/0x848) from [<c0af2ae8>] (schedule_preempt_disabled+0x24/0x34)
[  829.661988] [<c0af2ae8>] (schedule_preempt_disabled+0x24/0x34) from [<c0af1af4>] (__mutex_lock_slowpath+0x150/0x19c)
[  829.661997] [<c0af1af4>] (__mutex_lock_slowpath+0x150/0x19c) from [<c0af1b94>] (mutex_lock+0x54/0x6c)
[  829.662007] [<c0af1b94>] (mutex_lock+0x54/0x6c) from [<c0538630>] (__driver_attach+0x30/0x8c)
[  829.662017] [<c0538630>] (__driver_attach+0x30/0x8c) from [<c0536cf0>] (bus_for_each_dev+0x88/0x9c)
[  829.662026] [<c0536cf0>] (bus_for_each_dev+0x88/0x9c) from [<c05374dc>] (bus_add_driver+0x104/0x260)
[  829.662035] [<c05374dc>] (bus_add_driver+0x104/0x260) from [<c0538e70>] (driver_register+0xa4/0x11c)
[  829.662046] [<c0538e70>] (driver_register+0xa4/0x11c) from [<c0598748>] (__rmnet_open+0x90/0x100)
[  829.662055] [<c0598748>] (__rmnet_open+0x90/0x100) from [<c0598c3c>] (rmnet_ioctl+0x294/0x3d8)
[  829.662066] [<c0598c3c>] (rmnet_ioctl+0x294/0x3d8) from [<c095f1bc>] (dev_ifsioc+0x2bc/0x2cc)
[  829.662074] [<c095f1bc>] (dev_ifsioc+0x2bc/0x2cc) from [<c095f814>] (dev_ioctl+0x648/0x6b8)
[  829.662083] [<c095f814>] (dev_ioctl+0x648/0x6b8) from [<c028b8f8>] (do_vfs_ioctl+0x498/0x590)
[  829.662092] [<c028b8f8>] (do_vfs_ioctl+0x498/0x590) from [<c028ba3c>] (sys_ioctl+0x4c/0x70)
[  829.662101] [<c028ba3c>] (sys_ioctl+0x4c/0x70) from [<c0105da4>] (__sys_trace_return+0x0/0x1c)
[  829.662108] sh              D c0af27a8     0   423      1 0x00000200
[  829.662121] [<c0af27a8>] (__schedule+0x5b8/0x848) from [<c0af2ae8>] (schedule_preempt_disabled+0x24/0x34)
[  829.662131] [<c0af2ae8>] (schedule_preempt_disabled+0x24/0x34) from [<c0af1af4>] (__mutex_lock_slowpath+0x150/0x19c)
[  829.662141] [<c0af1af4>] (__mutex_lock_slowpath+0x150/0x19c) from [<c0af1b94>] (mutex_lock+0x54/0x6c)
[  829.662153] [<c0af1b94>] (mutex_lock+0x54/0x6c) from [<c0a8f578>] (wiphy_register+0x318/0x554)
[  829.662165] [<c0a8f578>] (wiphy_register+0x318/0x554) from [<c06136ac>] (wl_cfg80211_attach+0x404/0x1644)
[  829.662180] [<c06136ac>] (wl_cfg80211_attach+0x404/0x1644) from [<c05c9aa4>] (dhd_attach+0x3a0/0xb58)
[  829.662191] [<c05c9aa4>] (dhd_attach+0x3a0/0xb58) from [<c05d0134>] (dhdsdio_probe+0x468/0xa18)
[  829.662202] [<c05d0134>] (dhdsdio_probe+0x468/0xa18) from [<c05a2504>] (bcmsdh_probe+0xc4/0x108)
[  829.662212] [<c05a2504>] (bcmsdh_probe+0xc4/0x108) from [<c05a48f0>] (bcmsdh_sdmmc_probe+0x144/0x1d8)
[  829.662224] [<c05a48f0>] (bcmsdh_sdmmc_probe+0x144/0x1d8) from [<c07e5914>] (sdio_bus_probe+0x8c/0xfc)
[  829.662234] [<c07e5914>] (sdio_bus_probe+0x8c/0xfc) from [<c0538420>] (driver_probe_device+0xd4/0x270)
[  829.662243] [<c0538420>] (driver_probe_device+0xd4/0x270) from [<c0538668>] (__driver_attach+0x68/0x8c)
[  829.662252] [<c0538668>] (__driver_attach+0x68/0x8c) from [<c0536cf0>] (bus_for_each_dev+0x88/0x9c)
[  829.662261] [<c0536cf0>] (bus_for_each_dev+0x88/0x9c) from [<c05374dc>] (bus_add_driver+0x104/0x260)
[  829.662270] [<c05374dc>] (bus_add_driver+0x104/0x260) from [<c0538e70>] (driver_register+0xa4/0x11c)
[  829.662281] [<c0538e70>] (driver_register+0xa4/0x11c) from [<c0623bb4>] (dhd_wifi_platform_load+0x340/0x54c)
[  829.662292] [<c0623bb4>] (dhd_wifi_platform_load+0x340/0x54c) from [<c0623e7c>] (wifi_plat_dev_drv_probe+0xbc/0xec)
[  829.662302] [<c0623e7c>] (wifi_plat_dev_drv_probe+0xbc/0xec) from [<c0538420>] (driver_probe_device+0xd4/0x270)
[  829.662310] [<c0538420>] (driver_probe_device+0xd4/0x270) from [<c0538668>] (__driver_attach+0x68/0x8c)
[  829.662320] [<c0538668>] (__driver_attach+0x68/0x8c) from [<c0536cf0>] (bus_for_each_dev+0x88/0x9c)
[  829.662329] [<c0536cf0>] (bus_for_each_dev+0x88/0x9c) from [<c05374dc>] (bus_add_driver+0x104/0x260)
[  829.662337] [<c05374dc>] (bus_add_driver+0x104/0x260) from [<c0538e70>] (driver_register+0xa4/0x11c)
[  829.662347] [<c0538e70>] (driver_register+0xa4/0x11c) from [<c06243ac>] (dhd_wifi_platform_register_drv+0x1f8/0x370)
[  829.662359] [<c06243ac>] (dhd_wifi_platform_register_drv+0x1f8/0x370) from [<c1000db4>] (do_one_initcall+0xa0/0x19c)

Change-Id: I0ba12ac927c6dcc278b5fc00b2c0da566ee437e2
Signed-off-by: Cal Archer <carcher002@gmail.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:25 +02:00
Steve Kondik d2d13a9f03 msm8974: Reserve memory for ramconsole
* Samsung's implementation of ramconsole depends on the device
   being at DEBUG_LEVEL_HIGH, which makes collecting crash logs
   from devices in the wild impossible.
 * Enable the standard ramconsole by reserving persistent ram.

Change-Id: I6a6f0afb56ba603e0e4a04bd8ad35ae5876ff73b
Signed-off-by: Kevin F. Haggerty <kevin.f.haggerty@gmail.com>
2019-08-05 09:13:25 +02:00
ninez 6622e3aad7 msm8226_sec_defconfig: enable UTS,IPC,USER,PID,NET namespace support
CONFIG_UTS_NS=y
CONFIG_IPC_NS=y
CONFIG_USER_NS=y
CONFIG_PID_NS=y
CONFIG_NET_NS=y

enable linux namespaces in defconfig, needed for seccomp filters

Change-Id: Ib523316b4c69c5f7d0726dfa9dce50bc9c96b7ae
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:24 +02:00
Steve Kondik 5ad713144c video: mdss: Color temperature interface using PCC
* MDSS5 supports Polynomial Color Correction. Use this to implement
   a simple sysfs API for adjusting RGB scaling values. This can be
   used to implement color temperature and other controls.
 * Why use this when we have KCAL? This code is dead simple, the
   interface is in the right place, and it allows for 128X accuracy.

Change-Id: Ib848d6c9dbdf41f61cc7539a61138d6632ceba94
Ticket: NIGHTLIES-2873
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:24 +02:00
Daniel Rosenberg a7bc024c34 Fix incorrect conflict resolution in
"vfs: Add setns support for the mount namespace"

Change-Id: I554f28a1f92267ea3681d519c8402d983e799186
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:24 +02:00
Jin Qian c414c6544c proc: fix build broken by proc inode per namespace patch
Change-Id: I119e4f31584b4a7ab9d6825499947d59c1293f1b
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:23 +02:00
liping.zhang b6e9659db7 xt_qtaguid: fix a race condition in if_tag_stat_update
Miss a lock protection in if_tag_stat_update while doing get_iface_entry. So if
one CPU is doing iface_stat_create while another CPU is doing if_tag_stat_update,
race will happened.

Change-Id: Ib8d98e542f4e385685499f5b7bb7354f08654a75
Signed-off-by: Liping Zhang <liping.zhang@spreadtrum.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:23 +02:00
Steve Kondik b0babc4332 netfilter: idletimer: Fix trivial lockdep warning
Change-Id: I2a76b1f13cd1d0bb78f626cca3e968dd3608b96d
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:22 +02:00
Patrick Daly d6a9114234 netfilter: xt_HARDIDLETIMER: Fix use after free condition
Force any pending hardidletimer_tg_work() to complete before freeing
the associated work struct.

CRs-Fixed: 814707
Change-Id: I57b2f0dcd24f05ddb472d6007525d1722f9fe0b0
Signed-off-by: Patrick Daly <pdaly@codeaurora.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:22 +02:00
Patrick Daly d11712f680 nf: IDLETIMER: Fix possible use before initialization in idletimer_resume
idletimer_resume() assumes that the PM_SUSPEND_PREPARE notifier is sent
before PM_POST_PREPARE so that timer->last_suspend_time is initialized.
However, it is posible for PM_POST_PREPARE to be sent first if there is an
error returned from another driver's PM_SUSPEND_PREPARE notifier.

Add a flag indicating whether the current value of timer->last_suspend is
valid.

Detected with CONFIG_SLUB_DEBUG & CONFIG_DEBUG_SPINLOCK in arm64. The
timestamp lock is held for more than a minute while
set_normalized_timespec() proceses the poisoned timer->last_suspend_time
argument.

Change-Id: I95328b0ac85dba819ff9cef751c3d07300c232f1
CRs-fixed: 745178
Signed-off-by: Patrick Daly <pdaly@codeaurora.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:22 +02:00
Ruchi Kandoi 92e229c565 nf: IDLETIMER: Adds the uid field in the msg
Message notifications contains an additional uid field. This field
represents the uid that was responsible for waking the radio. And hence
it is present only in notifications stating that the radio is now
active.

Change-Id: I18fc73eada512e370d7ab24fc9f890845037b729
Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com>
Bug: 20264396
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:35 +02:00
JP Abgrall 8d568b6aa2 netfilter: IDLETIMER: fix invalid deference of timer
"timer" was checked for null, but used later without being re-checked.

Change-Id: Ib4d08cd49860c9f157d1cac556705ba85cd44f4e
Reported-by: dan.carpenter@oracle.com
Signed-off-by: JP Abgrall <jpa@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:34 +02:00
Ruchi Kandoi 79b0d3dd63 nf: Remove compilation error caused by
e254d2c28c880da28626af6d53b7add5f7d6afee

Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:34 +02:00
Ruchi Kandoi dc519ed0de nf: IDLETIMER: time-stamp and suspend/resume handling.
Message notifications contains an additional timestamp field in nano seconds.
The expiry time for the timers are modified during suspend/resume.
If timer was supposed to expire while the system is suspended then a
notification is sent when it resumes with the timestamp of the scheduled expiry.

Removes the race condition for multiple work scheduled.

Bug: 13247811

Change-Id: I752c5b00225fe7085482819f975cc0eb5af89bff
Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:34 +02:00
Tom Marshall 2f6898935f kernel: Fix potential refcount leak in su check
Change-Id: I3d241ae805ba708c18bccfd5e5d6cdcc8a5bc1c8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:34 +02:00
Tom Marshall e864a35d26 kernel: Only expose su when daemon is running
It has been claimed that the PG implementation of 'su' has security
vulnerabilities even when disabled.  Unfortunately, the people that
find these vulnerabilities often like to keep them private so they
can profit from exploits while leaving users exposed to malicious
hackers.

In order to reduce the attack surface for vulnerabilites, it is
therefore necessary to make 'su' completely inaccessible when it
is not in use (except by the root and system users).

Change-Id: Ia7d50ba46c3d932c2b0ca5fc8e9ec69ec9045f85
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:33 +02:00
dookiedude f4eb92dcae Remove Samsung implementation of sdcardfs
Remove Samsung version of sdcardfs before we use AOSP source

Change-Id: I33710450b91d8cfde38a27967b0527e6a72fb440
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:33 +02:00
Kevin F. Haggerty 16d4fbdb9f misc: Remove Samsung Secure Data Protection sprinkles
* Will make upstream merges easier

Change-Id: Ie0a5028235996f2bf233dc50489c1a9804b294de
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:33 +02:00
Kevin F. Haggerty ed185d55e9 misc: Remove Samsung Data Loss Prevention sprinkles
* Will make upstream merges easier

Change-Id: I63d31d3c604cadb9515f2f1dfe984824cb80958b
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:32 +02:00
Kevin F. Haggerty 2c9ddf637d misc: Remove Samsung KNOX VPN sprinkles
* Will make upstream merges easier

Change-Id: Iafad6c78f627fed05e6c97e65106a75a285d87b5
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:32 +02:00
Lorenzo Colitti 7fb0e30d17 selinux: nlmsgtab: add SOCK_DESTROY to the netlink mapping tables
Without this, using SOCK_DESTROY in enforcing mode results in:

  SELinux: unrecognized netlink message type=21 for sclass=32

Change-Id: I7862bb0fc83573567243ffa9549a2c7405b5986c

Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:32 +02:00
Paul Moore 507bef0746 selinux: add SOCK_DIAG_BY_FAMILY to the list of netlink message types
commit 6a96e15096da6e7491107321cfa660c7c2aa119d upstream.

The SELinux AF_NETLINK/NETLINK_SOCK_DIAG socket class was missing the
SOCK_DIAG_BY_FAMILY definition which caused SELINUX_ERR messages when
the ss tool was run.

 # ss
 Netid  State  Recv-Q Send-Q  Local Address:Port   Peer Address:Port
 u_str  ESTAB  0      0                  * 14189             * 14190
 u_str  ESTAB  0      0                  * 14145             * 14144
 u_str  ESTAB  0      0                  * 14151             * 14150
 {...}
 # ausearch -m SELINUX_ERR
 ----
 time->Thu Jan 23 11:11:16 2014
 type=SYSCALL msg=audit(1390493476.445:374):
  arch=c000003e syscall=44 success=yes exit=40
  a0=3 a1=7fff03aa11f0 a2=28 a3=0 items=0 ppid=1852 pid=1895
  auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0
  tty=pts0 ses=1 comm="ss" exe="/usr/sbin/ss"
  subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null)
 type=SELINUX_ERR msg=audit(1390493476.445:374):
  SELinux:  unrecognized netlink message type=20 for sclass=32

Bug: 20350607
Change-Id: I22218ec620bc3ee6396145f1c2ad8ed222648309
Signed-off-by: Paul Moore <pmoore@redhat.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:32 +02:00
Stephen Smalley febc119005 UPSTREAM: selinux: fix bug in conditional rules handling
(cherry picked from commit commit f3bef67992e8698897b584616535803887c4a73e)

commit fa1aa143ac4a ("selinux: extended permissions for ioctls")
introduced a bug into the handling of conditional rules, skipping the
processing entirely when the caller does not provide an extended
permissions (xperms) structure.  Access checks from userspace using
/sys/fs/selinux/access do not include such a structure since that
interface does not presently expose extended permission information.
As a result, conditional rules were being ignored entirely on userspace
access requests, producing denials when access was allowed by
conditional rules in the policy.  Fix the bug by only skipping
computation of extended permissions in this situation, not the entire
conditional rules processing.

Change-Id: I6f81765f6cdb9ce72f93c290d7987d93688651a0
Reported-by: Laurent Bigonville <bigon@debian.org>
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
[PM: fixed long lines in patch description]
Cc: stable@vger.kernel.org # 4.3
Signed-off-by: Paul Moore <pmoore@redhat.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:31 +02:00
Lorenzo Colitti 136315f347 net: diag: Add the ability to destroy a socket.
This patch adds a SOCK_DESTROY operation, a destroy function
pointer to sock_diag_handler, and a diag_destroy function
pointer.  It does not include any implementation code.

[Backport of net-next 64be0aed59ad519d6f2160868734f7e278290ac1]

Change-Id: I1d998e1c5f836b2f5638c0f79244c372c8d2d9d9
Signed-off-by: Lorenzo Colitti <lorenzo@google.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:31 +02:00
dcashman b14c867ed7 FROMLIST: arm: mm: support ARCH_MMAP_RND_BITS.
(cherry picked from commit https://lkml.org/lkml/2015/12/21/341)

arm: arch_mmap_rnd() uses a hard-code value of 8 to generate the
random offset for the mmap base address.  This value represents a
compromise between increased ASLR effectiveness and avoiding
address-space fragmentation. Replace it with a Kconfig option, which
is sensibly bounded, so that platform developers may choose where to
place this compromise. Keep 8 as the minimum acceptable value.

Bug: 24047224
Signed-off-by: Daniel Cashman <dcashman@android.com>
Signed-off-by: Daniel Cashman <dcashman@google.com>
Change-Id: I2f6c18a0060e1c21b53200ecdcfde9a8c2e3db98
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:31 +02:00
dcashman c7d1d5e20c FROMLIST: mm: mmap: Add new /proc tunable for mmap_base ASLR.
(cherry picked from commit https://lkml.org/lkml/2015/12/21/337)

ASLR  only uses as few as 8 bits to generate the random offset for the
mmap base address on 32 bit architectures. This value was chosen to
prevent a poorly chosen value from dividing the address space in such
a way as to prevent large allocations. This may not be an issue on all
platforms. Allow the specification of a minimum number of bits so that
platforms desiring greater ASLR protection may determine where to place
the trade-off.

Bug: 24047224
Signed-off-by: Daniel Cashman <dcashman@android.com>
Signed-off-by: Daniel Cashman <dcashman@google.com>
Change-Id: Ic74424e07710cd9ccb4a02871a829d14ef0cc4bc
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:30 +02:00
Jeff Vander Stoep e39af67d19 selinux: Android kernel compatibility with M userspace
NOT intended for new Android devices - this commit is unnecessary
for a target device that does not have a previous M variant.

DO NOT upstream. Android only.

Motivation:

This commit mitigates a mismatch between selinux kernel and
selinux userspace. The selinux ioctl white-listing binary policy
format that was accepted into Android M differs slightly from what
was later accepted into the upstream kernel. This leaves Android
master branch kernels incompatible with Android M releases. This
patch restores backwards compatibility. This is important because:

1. kernels may be updated on a different cycle than the rest of the
   OS e.g. security patching.
2. Android M bringup may still be ongoing for some devices. The
   same kernel should work for both M and master.

Backwards compatibility is achieved by checking for an Android M
policy characteristic during initial policy read and converting to
upstream policy format. The inverse conversion is done for policy
write as required for CTS testing.

Bug: 22846070
Change-Id: I2f1ee2eee402f37cf3c9df9f9e03c1b9ddec1929
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:30 +02:00
Jeff Vander Stoep 32c94286d7 selinux: extended permissions for ioctls
(cherry picked from commit fa1aa143ac4a682c7f5fd52a3cf05f5a6fe44a0a)

Add extended permissions logic to selinux. Extended permissions
provides additional permissions in 256 bit increments. Extend the
generic ioctl permission check to use the extended permissions for
per-command filtering. Source/target/class sets including the ioctl
permission may additionally include a set of commands. Example:

allowxperm <source> <target>:<class> ioctl unpriv_app_socket_cmds
auditallowxperm <source> <target>:<class> ioctl priv_gpu_cmds

Where unpriv_app_socket_cmds and priv_gpu_cmds are macros
representing commonly granted sets of ioctl commands.

When ioctl commands are omitted only the permissions are checked.
This feature is intended to provide finer granularity for the ioctl
permission that may be too imprecise. For example, the same driver
may use ioctls to provide important and benign functionality such as
driver version or socket type as well as dangerous capabilities such
as debugging features, read/write/execute to physical memory or
access to sensitive data. Per-command filtering provides a mechanism
to reduce the attack surface of the kernel, and limit applications
to the subset of commands required.

The format of the policy binary has been modified to include ioctl
commands, and the policy version number has been incremented to
POLICYDB_VERSION_XPERMS_IOCTL=30 to account for the format
change.

The extended permissions logic is deliberately generic to allow
components to be reused e.g. netlink filters

Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Acked-by: Nick Kralevich <nnk@google.com>
Signed-off-by: Paul Moore <pmoore@redhat.com>
Bug: 22846070
Change-Id: I299dc776d2f98d593ecc051707110c92a085350f
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:30 +02:00
Jeff Vander Stoep bf23a14fa3 selinux: remove unnecessary pointer reassignment
(cherry pick from commit 83d4a806ae46397f606de7376b831524bd3a21e5)

Commit f01e1af445 ("selinux: don't pass in NULL avd to avc_has_perm_noaudit")
made this pointer reassignment unnecessary. Avd should continue to reference
the stack-based copy.

Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
[PM: tweaked subject line]
Signed-off-by: Paul Moore <pmoore@redhat.com>
Bug: 22846070
Change-Id: Ie33688d163870705272607309a27fb7c8f870748

Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:29 +02:00
Jeff Vander Stoep be068a2dfd Revert "SELinux: per-command whitelisting of ioctls"
This reverts commit bc84b4adb1469e3d05ad76c304a4c545feaf1f88.

Bug: 22846070
Change-Id: Ib4cb130b2225ea2e22556ff852313e0de7dddcab
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:29 +02:00
Jeff Vander Stoep e2ed20302b Revert "SELinux: use deletion-safe iterator to free list"
This reverts commit c9a8571249fa3a55a0490bd571eaf0cea097fab0.

Bug: 22846070
Change-Id: I85e2b6322f98bd584ed523b0bd0291375dbc35dc
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:29 +02:00
Jeff Vander Stoep a3666d82dc Revert "SELinux: ss: Fix policy write for ioctl operations"
This reverts commit c06168226f5eaaaad93af5b2811f213b01382363.

Bug: 22846070
Change-Id: I665c1f2350e10ce890e7c4be1a06e666929d5d7a
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:29 +02:00
Andrey Vagin 62debffab6 signal: allow to send any siginfo to itself
The idea is simple.  We need to get the siginfo for each signal on
checkpointing dump, and then return it back on restore.

The first problem is that the kernel doesn't report complete siginfos to
userspace.  In a signal handler the kernel strips SI_CODE from siginfo.
When a siginfo is received from signalfd, it has a different format with
fixed sizes of fields.  The interface of signalfd was extended.  If a
signalfd is created with the flag SFD_RAW, it returns siginfo in a raw
format.

rt_sigqueueinfo looks suitable for restoring signals, but it can't send
siginfo with a positive si_code, because these codes are reserved for
the kernel.  In the real world each person has right to do anything with
himself, so I think a process should able to send any siginfo to itself.

This patch:

The kernel prevents sending of siginfo with positive si_code, because
these codes are reserved for kernel.  I think we can allow a task to
send such a siginfo to itself.  This operation should not be dangerous.

This functionality is required for restoring signals in
checkpoint/restart.

Signed-off-by: Andrey Vagin <avagin@openvz.org>
Cc: Serge Hallyn <serge.hallyn@canonical.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Michael Kerrisk <mtk.manpages@gmail.com>
Cc: Pavel Emelyanov <xemul@parallels.com>
Cc: Cyrill Gorcunov <gorcunov@openvz.org>
Cc: Michael Kerrisk <mtk.manpages@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

Change-Id: Ibdd8af9dc6400f42db1e3200db90f36df4fe9cc4
(cherry picked from commit 66dd34ad31e5963d72a700ec3f2449291d322921)
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:28 +02:00
Kevin F. Haggerty 56d4786636 defconfig: Update defconfig
* Disable CONFIG_USB_ANDROID_SAMSUNG_MTP to allow MTP to work
* Enable CONFIG_CRYPTO_DEV_QCEDEV

Change-Id: I00d82d5ae90fcd4eb95f976728dc83d16947aec0
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:12:25 +02:00
Florian Westphal a6c0aa8530 netfilter: xt_rpfilter: skip locally generated broadcast/multicast, too
Alex Efros reported rpfilter module doesn't match following packets:
IN=br.qemu SRC=192.168.2.1 DST=192.168.2.255 [ .. ]
(netfilter bugzilla #814).

Problem is that network stack arranges for the locally generated broadcasts
to appear on the interface they were sent out, so the IFF_LOOPBACK check
doesn't trigger.

As -m rpfilter is restricted to PREROUTING, we can check for existing
rtable instead, it catches locally-generated broad/multicast case, too.

Change-Id: I2d921ac4d53e5b1ca9a5249e489c33e4fa4a4b3a
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:11:32 +02:00
Ethan Chen 906c7a3636 msm8226: Enable RPFILTER
* regen defconfig while we're at it

Change-Id: I13a622d2228e6cd43959dab24d2486216815f933
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:11:32 +02:00
Tom Marshall 4f75368b85 defconfig: Disable vendor security restrictions
Change-Id: I5b9996ba4634d3f7286d9a2a2ae27310969692be
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:11:28 +02:00
Kevin F. Haggerty 33ec490473 scripts: Eliminate implicit delarations in fips_crypto_utils.c
Change-Id: I6e41b31175141d7e2a763cb8f876279820983fcf
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:10:01 +02:00
H. Peter Anvin 43b65e3d63 kernel: Replace timeconst.pl with a bc script
bc is the standard tool for multi-precision arithmetic.  We switched
to Perl because akpm reported a hard-to-reproduce build hang, which
was very odd because affected and unaffected machines were all running
the same version of GNU bc.

Unfortunately switching to Perl required a really ugly "canning"
mechanism to support Perl < 5.8 installations lacking the Math::BigInt
module.

It was recently pointed out to me that some very old versions of GNU
make had problems with pipes in subshells, which was indeed the
construct used in the Makefile rules in that version of the patch;
Perl didn't need it so switching to Perl fixed the problem for
unrelated reasons.  With the problem (hopefully) root-caused, we can
switch back to bc and do the arbitrary-precision arithmetic naturally.

Signed-off-by: H. Peter Anvin <hpa@zytor.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Acked-by: Sam Ravnborg <sam@ravnborg.org>
Signed-off-by: Michal Marek <mmarek@suse.cz>

Change-Id: I8450a919c2d27b6c18561621c0a48a762e46a22d
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:09:45 +02:00
Kevin F. Haggerty ae7675a1bd arm/kernel/setup.c: Add pre-MM bootloader compat shim
* Stop the dying

Change-Id: Ibcb37ecd34f871674e3bdea84f4b8c8de2b82cd8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:09:36 +02:00