Commit Graph
3385 Commits
Author SHA1 Message Date
Dmitry Torokhov 39b4c84f64 Input: add safety guards to input_set_keycode()
commit cb222aed03d798fc074be55e59d9a112338ee784 upstream.

If we happen to have a garbage in input device's keycode table with values
too big we'll end up doing clear_bit() with offset way outside of our
bitmaps, damaging other objects within an input device or even outside of
it. Let's add sanity checks to the returned old keycodes.

Reported-by: syzbot+c769968809f9359b07aa@syzkaller.appspotmail.com
Reported-by: syzbot+76f3a30e88d256644c78@syzkaller.appspotmail.com
Link: https://lore.kernel.org/r/20191207212757.GA245964@dtor-ws
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-20636
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I8f9a462d3fb8a9bb4494adb0e8edfac099a35263
2020-11-16 10:41:22 +01:00
Jackeagle bd80364a0c kmini3g: input: abov_touchkey- Disable Samsung Dual Detect
Samsung has introduced this since Lollipop Release and due to this the Capacitive Keys had issues and stopped working repeatedly once screen is locked.
It only works again after reboot and fails after screen is locked.
Disabling this has fixed Capacitive Key Issue.

Change-Id: Ia7ff76620cdac863289f57ea37459bd5b94ea99e
Signed-off-by: Jackeagle <jackeagle102@gmail.com>
2020-10-27 20:20:43 +02:00
Oliver Neukum e95c2c768b Input: ff-memless - kill timer in destroy()
commit fa3a5a1880c91bb92594ad42dfe9eedad7996b86 upstream.

No timer must be left running when the device goes away.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Reported-and-tested-by: syzbot+b6c55daa701fc389e286@syzkaller.appspotmail.com
Link: https://lore.kernel.org/r/1573726121.17351.3.camel@suse.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-19524
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I98f48deb9af84d551faffa98138384bc5db9ac61
2020-05-20 09:44:33 +02:00
Grant Hernandez e23d52b6b6 Input: gtco - bounds check collection indent level
commit 2a017fd82c5402b3c8df5e3d6e5165d9e6147dc1 upstream.

The GTCO tablet input driver configures itself from an HID report sent
via USB during the initial enumeration process. Some debugging messages
are generated during the parsing. A debugging message indentation
counter is not bounds checked, leading to the ability for a specially
crafted HID report to cause '-' and null bytes be written past the end
of the indentation array. As long as the kernel has CONFIG_DYNAMIC_DEBUG
enabled, this code will not be optimized out.  This was discovered
during code review after a previous syzkaller bug was found in this
driver.

Signed-off-by: Grant Hernandez <granthernandez@google.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-13631
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I0c205755470fa7b9cc83d8b80263c535c272eb18
2020-05-20 09:44:23 +02:00
prototype74 326dadb54c mms144: switched to mms100_reset & added touch angle support
using mms100_reset instead of mms_pwr_on_reset in mms100_ISC_download_mbinary function may fixes unexpected touchscreen freezes.

Change-Id: I1a7de26ac33f3f0a8d004c5e33a697e441f1ea76
2020-03-07 17:53:58 +01:00
Patrick Lower 9673fc4a3c input: synaptics: Disable stylus mode
* Fixes touchscreen bug observed in some games, emulators, and apps.

Change-Id: I7628366d6f7fa8824b1c255031c34d06a9570565
[haggertk: Clarification, this is for klte devices only - K_PROJECT,
 KACTIVE_PROJECT, KSPORTS_PROJECT]
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-08 16:35:52 +02:00
Scott Brissenden 0dc0beb00c input: cypress-touchkey - Add keydisabler
Change-Id: I418f68ae48ed81d789843df16040c777cf030f90
[haggertk]: This updates both the hlte and klte drivers
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-08 15:00:19 +02:00
Kevin F. Haggerty 2e9530077c Revert "wacom: Enable power saving mode by default"
This reverts commit db456f0e45c8a6f117dfe948b7bd0b0aeccb75b0.

* While the interaction is not obvious, the above-referenced commit
  seems to be the cause for the "screen stuck at full brightness"
  problem on hlte* devices.

Change-Id: I046a1ba3d930cbd82430fef7f15114e3f1fa3c8d
2019-08-08 15:00:18 +02:00
Paul Keith ca848228e2 wacom: Send custom keycodes when gestures are detected
* Modeled after the old gesture handling code in fw/b
* This allows us to use device specific code to handle
  s-pen gestures instead of polluting fw/b
* Supports the following gestures:
 - Swipe right
 - Swipe left
 - Swipe down
 - Swipe up
 - Long press
* To trigger the gestures, press the button on
  the s-pen, execute the gesture action, and
  then release the side button of the s-pen
* This patch also blocks touch input from the
  s-pen when the stylus button is pressed, to
  avoid causing unintended touch input

Change-Id: I55651a36d147ba69e6dbd987d1a267f544570ba0
Signed-off-by: Paul Keith <javelinanddart@gmail.com>
2019-08-08 15:00:18 +02:00
Paul Keith a38bb7811d wacom: Report KEY_WAKEUP on s-pen removal
* Wakes device when s-pen is removed

Change-Id: I4d3760385beefdcd9dfd1d84048be35a88c78df8
2019-08-08 15:00:17 +02:00
Paul Keith 01b4f14c8f wacom: Enable power saving mode by default
Change-Id: I350217c4abfda3bc8aad0b460ec885a5190534f3
2019-08-08 15:00:17 +02:00
Andrew Chant 53fd9a72d1 input: synaptics: put offset checks under mutex.
Place file offset validity checks under mutex.

BUG: 33555878
BUG: 33002026

Change-Id: I1945cfc8af7d1a310ae0d7bbb85002d4c448f30b
Signed-off-by: Andrew Chant <achant@google.com>
CVE-2017-0524
CVE-2017-0536
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-08 14:59:30 +02:00
Min Chong 8774e2f3f4 input: synaptics: add bounds checks for firmware id
A series of characters between '0' and '9' with a length more than
MAX_FIRMWARE_ID_LEN causes a heap buffer overflow. This is
mitigated by performing a bounds check.

Bug: 31911920
Signed-off-by: Min Chong <mchong@google.com>
Change-Id: Iaefe92df2610153f2d3e2caa58322ae82cb5b7c2
[razorloves: Backport to 3.4]
CVE-2016-8393
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-08 14:43:03 +02:00
Andrew Chant 9ff1631fd3 input: synaptics: defer sysfs creation during init
sysfs entries are created which reference fwu->fwu_work.
defer the creation of these sysfs entries until the end of the init
function, after fwu->fwu_work has been initialized.

Change-Id: Ib7d5304ec2990454486e2b1d28b640a174c83d12
Bug: 31252388
Signed-off-by: Andrew Chant <achant@google.com>
CVE-2016-6745
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-08 14:41:27 +02:00
Greg Kroah-Hartman 9b773bfbba USB: input: gtco.c: fix up dev_* messages
Previously I had made the struct device point to the input device, but
after talking with Dmitry, he said that the USB device would make more
sense for this driver to point to.  So converted it to use that instead.

CC: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2019-08-08 11:51:26 +02:00
Vevek Venkatesan eebc5790a6 input: touchscreen: gt9xx: fix memory corruption in Goodix driver
Fix memory corruption in Goodix touchscreen driver, by resetting
the global structure cmd_head to zero (except *data and wr flag)
in goodix_tool_write handler on error case.

CAF-Change-Id: I4f7f8f464b93571627b922b10c10a65826228e42
Signed-off-by: Vevek Venkatesan <vevekv@codeaurora.org>
CVE-2017-0622

Change-Id: I19c78864f8734b68bc6ae1de3e4853de624c7c03
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-06 12:26:27 +02:00
Vladis Dronov 5e0aaed929 Input: gtco - fix crash on detecting device without endpoints
commit 162f98dea487206d9ab79fc12ed64700667a894d upstream.

The gtco driver expects at least one valid endpoint. If given malicious
descriptors that specify 0 for the number of endpoints, it will crash in
the probe function. Ensure there is at least one endpoint on the interface
before using it.

Also let's fix a minor coding style issue.

The full correct report of this issue can be found in the public
Red Hat Bugzilla:

https://bugzilla.redhat.com/show_bug.cgi?id=1283385

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
CVE-2016-2187
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>

Change-Id: I99b9af4d1bf2df3845a6fac7caa3443da8ffb294
2019-08-06 12:17:41 +02:00
Josh Boyer a64bb0c26c Input: powermate - fix oops with malicious USB descriptors
[ Upstream commit 9c6ba456711687b794dcf285856fc14e2c76074f ]

The powermate driver expects at least one valid USB endpoint in its
probe function.  If given malicious descriptors that specify 0 for
the number of endpoints, it will crash.  Validate the number of
endpoints on the interface before using them.

The full report for this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/85

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2186
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>

Change-Id: Ib8a42fc7e0ca5d095c36b34ea328f19d28fe83cc
2019-08-06 12:17:40 +02:00
Vladis Dronov 4990546f1e Input: ati_remote2 - fix crashes on detecting device with invalid descriptor
[ Upstream commit 950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d ]

The ati_remote2 driver expects at least two interfaces with one
endpoint each. If given malicious descriptor that specify one
interface or no endpoints, it will crash in the probe function.
Ensure there is at least two interfaces and one endpoint for each
interface before using it.

The full disclosure: http://seclists.org/bugtraq/2016/Mar/90

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2185
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>

Change-Id: I9274b674d6aa90617a22930618ab571910444d29
2019-08-06 12:17:40 +02:00
Vladis Dronov 77a5689da2 Input: aiptek - fix crash on detecting device without endpoints
commit 8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 upstream.

The aiptek driver crashes in aiptek_probe() when a specially crafted USB
device without endpoints is detected. This fix adds a check that the device
has proper configuration expected by the driver. Also an error return value
is changed to more matching one in one of the error paths.

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2015-7515
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>

Change-Id: I3cdae8dd87a002409a5ab9190cfad7d3faa237d4
2019-08-06 11:48:15 +02:00
Kevin F. Haggerty 0fdd45c3ac Merge remote-tracking branch 'google-common/deprecated/android-3.4' into lineage-16.0
Change-Id: I363f9d4d0623906eaffffb3747a162ccbc92ccb0
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-06 11:41:21 +02:00
Kevin F. Haggerty 238a0fb5ad Merge tag 'v3.4.113' into lineage-16.0
This is the 3.4.113 stable release

Change-Id: I80791430656359c5447a675cbff4431362d18df0
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 14:20:47 +02:00
Francescodario Cuzzocrea e20e6a0613 Merge tag 'LA.BF.1.1.3-02310-8x26.0' into lineage-16.0 2019-08-05 11:18:51 +02:00
ninez 38f1006d11 misc: Fix system_rev type mismatch
* Samsung sources have type mismatches in 3 of their drivers. This was
  uncovered using linaro's toolchain for kernel compilation.

Change-Id: If3a083ffcb2a15185ff208b22976509ffd8af5e8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2019-08-05 09:13:25 +02:00
Robert Rozic 841dff7d51 input: cypress-touchkey - Add keydisabler 2019-08-05 09:06:04 +02:00
zeroblade1984 761db8f8c5 drivers: input: Fix DVFS Errors
Signed-off-by: zeroblade1984 <zeroblade1984@gmail.com>
Signed-off-by: Jackeagle <jackeagle102@gmail.com>

Change-Id: I0fa8531917d09cfb08d19d27ac912a9723a92d44
2019-08-03 12:24:42 +02:00
Robert Rozic e8357f64b9 touchscreen: mms114: Fix build when DVFS is disabled
Signed-off-by: Robert Rozic <r.rozic97@gmail.com>
2019-08-03 12:23:57 +02:00
xXPR0T0TYPEXx a3a97f9639 drivers: input: touchscreen: cyttsp4: resolved missing separator on
makefile
2019-08-03 12:21:20 +02:00
Francescodario Cuzzocrea 85baa390bf misc: Import SM-G900H kernel source code
* Samsung Package Version: G800HXXU1CRJ1
    * CAF Tag: LA.BF.1.1.3-00110-8x26.0
2019-08-02 15:14:10 +02:00
Andrew Chant 55158d2c50 Input: synaptics: check input, prevent sysfs races
concurrent sysfs calls on the fw updater can cause
ugly race conditions.  Return EBUSY on concurrent sysfs calls.

For sysfs calls which generate deferred work, prevent
the deferred work from running concurrently with other
sysfs calls.

Also check that ext_data_source is appropriately sized
and allocated, based on a patch by
Gengjia Chen (chengjia4574@gmail.com).

Signed-off-by: Andrew Chant <achant@google.com>
Change-Id:I5bbe4992f3fd2d23db288296eaeb61f5831098e9
Bug: 30799828
Bug: 31252388
Git-repo: https://android.googlesource.com/kernel/msm.git
Git-commit: 287ce2ccfefe68067c1f9f5175b6664bf7397fe6
Signed-off-by: Srinivasa Rao Kuppala <srkupp@codeaurora.org>
2016-12-20 15:06:25 +05:30
chengengjia 6192d9c11e input: synaptics: Add checks of user input data
Add checks of the user input count to avoid possible heap overflow

Bug: 30799828
Change-Id: I896492b18c4ace6565fb9edd5cbf51f363ce157b
Signed-off-by: chengengjia <chengjia4574@gmail.com>
Signed-off-by: Andrew Chant <achant@google.com>
Git-repo: https://android.googlesource.com/kernel/msm.git
Git-commit: f549796fb9da58586c5cfc31d07b243c87dcfbd5
Signed-off-by: Dennis Cagle <d-cagle@codeaurora.org>
2016-11-29 03:25:40 -08:00
Sahil Kataria a110fa2087 input: misc: Kconfig: Fix misplaced endif
This patch fixes the misplaced endif that could cause some misc input
drivers not being listed when running the kernel configurator.

CRs-Fixed: 663748
Change-Id: I31cb24bd3fa5559b197bc227789c325edda736b0
Signed-off-by: Sahil Kataria <sahilk@codeaurora.org>
2014-05-27 11:37:02 -07:00
Bingzhe Cai 24401c06c1 input: sensors: fix accelerometer output data rate issue
Accelerometer data output rate is limited by device ODR register,
no need to configure this register in polling mode.

CRs-Fixed: 641705
Change-Id: If59900b244b31f813dd17e72b19c7fd2ca4b4ba1
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
2014-04-09 17:19:44 +08:00
Mao Li 8ee872fd14 input: touchscreen: change linking order of synaptics_i2c_rmi4
On some hardware when synaptics_rmi4_detection_work() is called,
exp_fn_list is still empty because module_init of synaptics_fw_update
is called later. As a result of this sysfs files required for firmware
update are not created. This patch changes the link order to ensure
that exp_fn_list is properly initialized before
synaptics_rmi4_detection_work() is called when all Synaptics modules
i.e. synaptics_fw_update, synaptics_rmi_dev and synaptics_i2c_rmi4 are
statically linked into the kernel.

CRs-fixed: 634135
Change-Id: Ib0b8e82ed569ecb18788b8aec6e1c9771e74fd2d
Signed-off-by: maol <maol@codeaurora.org>
2014-04-07 14:04:42 +05:30
Linux Build Service Account 164f4b8f32 Merge "input: touchscreen: change the focaltech firmware upgrade method" 2014-03-28 08:18:35 -07:00
Bingzhe Cai 1e18e7d0ca input: sensors: fix deadlock issue during accelerometer disabling.
Accelerometer mma8x5x driver may struck in disabling procedure due
to deadlock on workqueue flush.

Change-Id: Ibcd6ebe92bc2fece459fde5f76e5bfe1f90586a0
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
2014-03-25 21:25:55 +08:00
Sarada Prasanna Garnayak 7674c5911b input: touchscreen: change the focaltech firmware upgrade method
Upgarde firmware on the touch controller when the new firmware
version is geater than the current firmware version. Update the
version id after successful firmware update. skip firmware
update process when device is in suspend state.

CRs-Fixed: 623803
Change-Id: Ic462f6483887a3654665852e58ae9891de9f5eff
Signed-off-by: Sarada Prasanna Garnayak <c_sgarna@codeaurora.org>
2014-03-25 11:46:33 +05:30
Keith Fallows f0655aa6ee input: atmel_mxt_ts: Synchronous PM request starting Secure Touch
Maintain I2C adapter clocks on when starting Secure Touch
using the synchronous version of pm_runtime_get.

Change-Id: Ie30ea56af9e045239099652124740565428518f8
Acked-by: Christian Bolis <cbolis@qti.qualcomm.com>
Signed-off-by: Keith Fallows <keithf@codeaurora.org>
2014-03-20 10:13:33 +00:00
Linux Build Service Account f9afab15d9 Merge "input: sensors: fix mma8x5x interrupt mode output rate issue" 2014-03-05 02:53:31 -08:00
Bingzhe Cai 067bf04977 input: sensors: fix mma8x5x interrupt mode output rate issue
Accelerometer mma8x5x cannot change data output rate correctly in
interrupt due to wrong configuration value has been used.

Change-Id: I010cdf992267119cc8c54a855a33206920fc08e2
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
2014-02-24 16:18:41 +08:00
Bingzhe Cai 393801906b input: sensors: use work queue for mma8x5x data polling
Accelerometer mma8x5x driver register polling device for data
polling, but polling device only update polling interval on
new polling cycle, this will cause delay on change polling
interval in some case.

Change-Id: I391dc5507a40e6bfc7e8127a0db89cb685eaf192
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
2014-02-20 11:17:09 +08:00
Shantanu Jain 76c037f49b input: touchscreen: Replace macros used inside the functions
Replace the macros that are used inside the driver function
with dtsi entries.
Remove hrtimer calls which is not being used in the current
driver code.

Change-Id: I29b9ea41df467d0092be8005733016843dc26f60
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
2014-02-06 19:37:39 +05:30
Linux Build Service Account 0b4e92519e Merge "input: touchscreen: Add force fw_update support via sysfs entry" 2014-02-04 03:44:20 -08:00
Jing Lin e45d040883 input: misc: add input driver for HBTP
This driver provides service to Host Based Touch Processing
in three aspects:
- It serves as an input device driver to send touch events from user
  space to the kernel input core.
- It monitors LCD on/off and sends uevent accordingly.
- It performs power management for the touch AFE (Analog Front End).

Change-Id: Ibfb7c6a8d2c895ea0a277b8f0bf810e0263260e6
Signed-off-by: Jing Lin <jinglin@codeaurora.org>
2014-01-31 11:31:36 -08:00
Linux Build Service Account 51474dd1b1 Merge "input: synaptics_fw_update: fix insufficient bounds checking" 2014-01-30 03:55:35 -08:00
Shantanu Jain 3720edea7a input: touchscreen: Add force fw_update support via sysfs entry
Add sysfs entry for force fw_update support in Goodix
driver.
Change the usage of kstrtoul to sscanf in driver to avoid
portability issues.

CRs-fixed: 579806
Change-Id: I147a3e465170dda7af415ade29c04257d9b11a6b
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
2014-01-29 17:34:38 +05:30
Abinaya P 3a59368aee input: synaptics_i2c_rmi4: Reorganize the code
Reorganize the code related to debugfs that allows driver to compile
for different build environments. Remove dead code and also define
dummy functions that are needed when CONFIG_PM is not enabled in defconfig.

Change-Id: I385d194c7463cd06322f1b5124f1dc0ce72fc8a1
Signed-off-by: Abinaya P <abinayap@codeaurora.org>
2014-01-27 18:05:40 +05:30
Abinaya P 9642997b70 input: synaptics_fw_update: fix insufficient bounds checking
Possible values of config_area are between 0 and 3. The patch
adds bounds checking in fwu_sysfs_config_area_store() function.
Also use kstrtou16() for parsing the config_area.

Change-Id: Ia0b58f1b5a359c67f420012876431dac920ecfbd
Signed-off-by: Abinaya P <abinayap@codeaurora.org>
2014-01-27 17:42:37 +05:30
Linux Build Service Account c94baa834f Merge "input: touchscreen: Add firmware upgrade via sysfs entry" 2014-01-25 16:27:17 -08:00
Linux Build Service Account 9110801293 Merge "input: touchscreen: Add debufs entries for GTP controller" 2014-01-24 21:12:18 -08:00