[ Upstream commit 9c6ba456711687b794dcf285856fc14e2c76074f ]
The powermate driver expects at least one valid USB endpoint in its
probe function. If given malicious descriptors that specify 0 for
the number of endpoints, it will crash. Validate the number of
endpoints on the interface before using them.
The full report for this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/85
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2186
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ib8a42fc7e0ca5d095c36b34ea328f19d28fe83cc
[ Upstream commit 950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d ]
The ati_remote2 driver expects at least two interfaces with one
endpoint each. If given malicious descriptor that specify one
interface or no endpoints, it will crash in the probe function.
Ensure there is at least two interfaces and one endpoint for each
interface before using it.
The full disclosure: http://seclists.org/bugtraq/2016/Mar/90
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2185
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I9274b674d6aa90617a22930618ab571910444d29
This patch fixes the misplaced endif that could cause some misc input
drivers not being listed when running the kernel configurator.
CRs-Fixed: 663748
Change-Id: I31cb24bd3fa5559b197bc227789c325edda736b0
Signed-off-by: Sahil Kataria <sahilk@codeaurora.org>
Accelerometer data output rate is limited by device ODR register,
no need to configure this register in polling mode.
CRs-Fixed: 641705
Change-Id: If59900b244b31f813dd17e72b19c7fd2ca4b4ba1
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Accelerometer mma8x5x driver may struck in disabling procedure due
to deadlock on workqueue flush.
Change-Id: Ibcd6ebe92bc2fece459fde5f76e5bfe1f90586a0
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Accelerometer mma8x5x cannot change data output rate correctly in
interrupt due to wrong configuration value has been used.
Change-Id: I010cdf992267119cc8c54a855a33206920fc08e2
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Accelerometer mma8x5x driver register polling device for data
polling, but polling device only update polling interval on
new polling cycle, this will cause delay on change polling
interval in some case.
Change-Id: I391dc5507a40e6bfc7e8127a0db89cb685eaf192
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
This driver provides service to Host Based Touch Processing
in three aspects:
- It serves as an input device driver to send touch events from user
space to the kernel input core.
- It monitors LCD on/off and sends uevent accordingly.
- It performs power management for the touch AFE (Analog Front End).
Change-Id: Ibfb7c6a8d2c895ea0a277b8f0bf810e0263260e6
Signed-off-by: Jing Lin <jinglin@codeaurora.org>
Allow mma8x5x accelerometer work on interrupt mode and issue
interrupt to wake up application processor when data is ready.
Change-Id: Iadecfa9aeaa8e225098d049659802dcd7f976f48
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
The bmp18x driver may call regulator_get in resume routine. However,
regulator_get will call the sysfs APIs to create duplicated files
in sysfs. This will trigger the kernel warnings and backtrace.
Change-Id: I758f2866adae69fd8f8a9477c12aa714303ab6f2
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
The unit of min_delay should be in us rather than ms.
Change-Id: I07a0c37232cf8e8b36c30e8be41690e379ad56b1
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
Add enable and poll_delay handle functions for the cm36283 light and
proximity sensor driver. The system will create the general enable and
poll_delay handles in the "/sys/class/sensors/xxx/" for each sensor
drvier which is using the sensor class driver.
Change-Id: Ib8503a60991577737b372f512bb07b064319ce35
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
The kernel will create the general enable interface in "/sys/class
/sensors/xxx" for each sensor driver using sensor class interface.
Change-Id: I214f99ba96ff4c1124b277f0f49ca46a4837e202
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
Change polling delay of accelerometer mma8x5x will not take effect
because driver never use this new delay.
Change-Id: I8dcc457de46970b90ffcedd0c76dca4da5010884
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Change the bmp18x sensor poll delay interface name from "delay" to
"poll_delay", because the "poll_delay" is used as uniform interface.
Change-Id: I380c5d32518eacb9f14985424c22c43d7d985658
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
The kernel will create the general enable and poll_delay interfaces
in the "/sys/class/sensors/xxx" for each sensor driver using sensor
class interface.
Change-Id: I17ca9822b759ec16393a184ce6bd16458a51ff65
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
Add enable and poll_delay handle functions for the stk3x1x light and
proximity sensor driver. The system will create the general enable and
poll_delay handles in the "/sys/class/sensors/xxx/" for each sensor
drvier which is using the sensor class driver.
Change-Id: Ib082d3bbc278ef5c75ae38b3e702f84a13bca7a8
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add enable and poll_delay handle functions for the bmp18x pressure
driver. The system will create the general enable and poll_delay handles
in the "/sys/class/sensors/xxx/" for each sensor drvier which is using
the sensor class driver.
Change-Id: I1e24cbc6a63c5e1e5eb4db66049bd7be85b81352
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
The cm36283 sysfs interface path did not follow the sensor sysfs
path conventions, thus lead to the sensor HAL complicated.
Change-Id: Idc0c49a71eddb331736e2fb42eaa198a5bffba95
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
Add enable and poll_delay handle functions for the kxtj9 accelerometer
driver. The system will create the general enable and poll_delay handles
in the "/sys/class/sensors/xxx/" for each sensor drvier which is using
the sensor class driver.
Change-Id: I7ff71bd554f864c62b642791222c7d575d4c6b7f
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Remove unnecessary log message from stk3x1x ALPS driver, driver
should be quiet in normal operation.
Change-Id: I25366c1bf34ed8ef75b83914c0f3cbe3e2fff8ef
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Earlysuspend is gone, remove it from this driver.
Change-Id: Ie7e3006b907c965928dfb50575379cce25f36c3f
Signed-off-by: Stephen Boyd <sboyd@codeaurora.org>
[mengmeng: cherry-picked from kernel/msm-3.10.git 6006e74]
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
The power management logic was not correctly handled and caused
the sensor chip in the wrong state. Fix this issue by add some
restrictions to the runtime power management usage counter.
Change-Id: Ib456137190c295491443b6eadbc4cfbb409b3457
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
The mpu3050_input_open and mpu3050_input_close hold an usage counter
of the device and may prevent the device entering runtime suspend.
So remove the code to save the runtime power consumption for mpu3050.
Change-Id: Idb55b3388c39851291b5330fa7add5d12374cf80
Signed-off-by: Oliver Wang <mengmeng@codeaurora.org>
Add the sensor class device support for the cm36283 light and
proximity sensor. By using the class device, the driver will
create the subfolder in the "/sys/class/sensors/". The userspace
app could detect the sensors by searching this folder.
Change-Id: I4d96ed54ee647069a5f1cf592c4aea1d8636a0f5
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add the sensor class device support for the mma8x5x accelerometer
sensor. By using the class device, the driver will create the
subfolder in the "/sys/class/sensors/" and the userspace app could
detect the sensors by searching this folder.
Change-Id: I6b96c43fa6da78d84a950f67843c62a41e03aa99
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add the sensor class device support for the mpu3050 gyroscope
sensor. By using the class device, the driver will create the
subfolder in the "/sys/class/sensors/". The userspace app
could detect the sensors by searching this folder.
Change-Id: Ieba9cebaa2bb62da223d78290b64865142c945f7
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add the sensor class device support for the bmp18x pressure
sensor. By using the class device, the driver will create the
subfolder in the "/sys/class/sensors/" and the userspace app
could detect the sensors by searching this folder.
Change-Id: Id947e8b7dd101d15bc7ffcbe5a01fa9c6cf28efe
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add the sensor class device support for the stk3x1x light and
proximity sensor. By using the class device, the driver will
create the subfolder in the "/sys/class/sensors/". The userspace
app could detect the sensors by searching this folder.
Change-Id: Id601679ec219ce541e8ee92837185461c9dc74bd
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>
Add the sensor class device support for the kxtj9 accelerometer
sensor.
Change-Id: I4548c6787f8bc4654c1b3e08d65fa4cb1727bef5
Signed-off-by: Jie Cheng <rockiec@codeaurora.org>