Previously I had made the struct device point to the input device, but
after talking with Dmitry, he said that the USB device would make more
sense for this driver to point to. So converted it to use that instead.
CC: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Fix memory corruption in Goodix touchscreen driver, by resetting
the global structure cmd_head to zero (except *data and wr flag)
in goodix_tool_write handler on error case.
CAF-Change-Id: I4f7f8f464b93571627b922b10c10a65826228e42
Signed-off-by: Vevek Venkatesan <vevekv@codeaurora.org>
CVE-2017-0622
Change-Id: I19c78864f8734b68bc6ae1de3e4853de624c7c03
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
commit 162f98dea487206d9ab79fc12ed64700667a894d upstream.
The gtco driver expects at least one valid endpoint. If given malicious
descriptors that specify 0 for the number of endpoints, it will crash in
the probe function. Ensure there is at least one endpoint on the interface
before using it.
Also let's fix a minor coding style issue.
The full correct report of this issue can be found in the public
Red Hat Bugzilla:
https://bugzilla.redhat.com/show_bug.cgi?id=1283385
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
CVE-2016-2187
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I99b9af4d1bf2df3845a6fac7caa3443da8ffb294
[ Upstream commit 9c6ba456711687b794dcf285856fc14e2c76074f ]
The powermate driver expects at least one valid USB endpoint in its
probe function. If given malicious descriptors that specify 0 for
the number of endpoints, it will crash. Validate the number of
endpoints on the interface before using them.
The full report for this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/85
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2186
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ib8a42fc7e0ca5d095c36b34ea328f19d28fe83cc
[ Upstream commit 950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d ]
The ati_remote2 driver expects at least two interfaces with one
endpoint each. If given malicious descriptor that specify one
interface or no endpoints, it will crash in the probe function.
Ensure there is at least two interfaces and one endpoint for each
interface before using it.
The full disclosure: http://seclists.org/bugtraq/2016/Mar/90
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2185
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I9274b674d6aa90617a22930618ab571910444d29
commit 8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 upstream.
The aiptek driver crashes in aiptek_probe() when a specially crafted USB
device without endpoints is detected. This fix adds a check that the device
has proper configuration expected by the driver. Also an error return value
is changed to more matching one in one of the error paths.
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2015-7515
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I3cdae8dd87a002409a5ab9190cfad7d3faa237d4
* Samsung sources have type mismatches in 3 of their drivers. This was
uncovered using linaro's toolchain for kernel compilation.
Change-Id: If3a083ffcb2a15185ff208b22976509ffd8af5e8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
concurrent sysfs calls on the fw updater can cause
ugly race conditions. Return EBUSY on concurrent sysfs calls.
For sysfs calls which generate deferred work, prevent
the deferred work from running concurrently with other
sysfs calls.
Also check that ext_data_source is appropriately sized
and allocated, based on a patch by
Gengjia Chen (chengjia4574@gmail.com).
Signed-off-by: Andrew Chant <achant@google.com>
Change-Id:I5bbe4992f3fd2d23db288296eaeb61f5831098e9
Bug: 30799828
Bug: 31252388
Git-repo: https://android.googlesource.com/kernel/msm.git
Git-commit: 287ce2ccfefe68067c1f9f5175b6664bf7397fe6
Signed-off-by: Srinivasa Rao Kuppala <srkupp@codeaurora.org>
This patch fixes the misplaced endif that could cause some misc input
drivers not being listed when running the kernel configurator.
CRs-Fixed: 663748
Change-Id: I31cb24bd3fa5559b197bc227789c325edda736b0
Signed-off-by: Sahil Kataria <sahilk@codeaurora.org>
Accelerometer data output rate is limited by device ODR register,
no need to configure this register in polling mode.
CRs-Fixed: 641705
Change-Id: If59900b244b31f813dd17e72b19c7fd2ca4b4ba1
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
On some hardware when synaptics_rmi4_detection_work() is called,
exp_fn_list is still empty because module_init of synaptics_fw_update
is called later. As a result of this sysfs files required for firmware
update are not created. This patch changes the link order to ensure
that exp_fn_list is properly initialized before
synaptics_rmi4_detection_work() is called when all Synaptics modules
i.e. synaptics_fw_update, synaptics_rmi_dev and synaptics_i2c_rmi4 are
statically linked into the kernel.
CRs-fixed: 634135
Change-Id: Ib0b8e82ed569ecb18788b8aec6e1c9771e74fd2d
Signed-off-by: maol <maol@codeaurora.org>
Accelerometer mma8x5x driver may struck in disabling procedure due
to deadlock on workqueue flush.
Change-Id: Ibcd6ebe92bc2fece459fde5f76e5bfe1f90586a0
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Upgarde firmware on the touch controller when the new firmware
version is geater than the current firmware version. Update the
version id after successful firmware update. skip firmware
update process when device is in suspend state.
CRs-Fixed: 623803
Change-Id: Ic462f6483887a3654665852e58ae9891de9f5eff
Signed-off-by: Sarada Prasanna Garnayak <c_sgarna@codeaurora.org>
Maintain I2C adapter clocks on when starting Secure Touch
using the synchronous version of pm_runtime_get.
Change-Id: Ie30ea56af9e045239099652124740565428518f8
Acked-by: Christian Bolis <cbolis@qti.qualcomm.com>
Signed-off-by: Keith Fallows <keithf@codeaurora.org>
Accelerometer mma8x5x cannot change data output rate correctly in
interrupt due to wrong configuration value has been used.
Change-Id: I010cdf992267119cc8c54a855a33206920fc08e2
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Accelerometer mma8x5x driver register polling device for data
polling, but polling device only update polling interval on
new polling cycle, this will cause delay on change polling
interval in some case.
Change-Id: I391dc5507a40e6bfc7e8127a0db89cb685eaf192
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Replace the macros that are used inside the driver function
with dtsi entries.
Remove hrtimer calls which is not being used in the current
driver code.
Change-Id: I29b9ea41df467d0092be8005733016843dc26f60
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
This driver provides service to Host Based Touch Processing
in three aspects:
- It serves as an input device driver to send touch events from user
space to the kernel input core.
- It monitors LCD on/off and sends uevent accordingly.
- It performs power management for the touch AFE (Analog Front End).
Change-Id: Ibfb7c6a8d2c895ea0a277b8f0bf810e0263260e6
Signed-off-by: Jing Lin <jinglin@codeaurora.org>
Add sysfs entry for force fw_update support in Goodix
driver.
Change the usage of kstrtoul to sscanf in driver to avoid
portability issues.
CRs-fixed: 579806
Change-Id: I147a3e465170dda7af415ade29c04257d9b11a6b
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
Reorganize the code related to debugfs that allows driver to compile
for different build environments. Remove dead code and also define
dummy functions that are needed when CONFIG_PM is not enabled in defconfig.
Change-Id: I385d194c7463cd06322f1b5124f1dc0ce72fc8a1
Signed-off-by: Abinaya P <abinayap@codeaurora.org>
Possible values of config_area are between 0 and 3. The patch
adds bounds checking in fwu_sysfs_config_area_store() function.
Also use kstrtou16() for parsing the config_area.
Change-Id: Ia0b58f1b5a359c67f420012876431dac920ecfbd
Signed-off-by: Abinaya P <abinayap@codeaurora.org>
Add debugfs entries for address and data to read the registers
of Goodix controller.
Change-Id: I6543d523e39771615d0e1b684780141e108a2aa4
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
%zu is the correct printk format specifier when printing size_t types.
Update printks to use %zu for size_t type variables.
Change-Id: Ie556fd14293ecd36143353e575fd5ef22fab20f7
Signed-off-by: Himanshu Aggarwal <haggarwa@codeaurora.org>
Driver needs dummy functions defined for cases when CONFIG_PM
is not enabled.
Change-Id: I4e9f0885eb9f7a45589b2362e468335a3ca57cba
Signed-off-by: Amy Maloche <amaloche@codeaurora.org>
Allow mma8x5x accelerometer work on interrupt mode and issue
interrupt to wake up application processor when data is ready.
Change-Id: Iadecfa9aeaa8e225098d049659802dcd7f976f48
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Remove code that reads firmware from the header file, since
we don't plan to support this feature.
CRs-fixed: 591376
Change-Id: I6c18e153ddf18667ca83d47df20c71bce6dbfa21
Signed-off-by: Himanshu Aggarwal <haggarwa@codeaurora.org>
Touch screen driver checks finger status when releasing unwanted touch
events. Current status check does not cover an unwanted finger status.
This introduces extraneous events when device goes to suspend.
CRs-Fixed: 595019
Change-Id: I3c230cb98d5866edf2bc2f433765f787e518ac93
Signed-off-by: Chun Zhang <chunz@codeaurora.org>
The bmp18x driver may call regulator_get in resume routine. However,
regulator_get will call the sysfs APIs to create duplicated files
in sysfs. This will trigger the kernel warnings and backtrace.
Change-Id: I758f2866adae69fd8f8a9477c12aa714303ab6f2
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
The unit of min_delay should be in us rather than ms.
Change-Id: I07a0c37232cf8e8b36c30e8be41690e379ad56b1
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>