Samsung has introduced this since Lollipop Release and due to this the Capacitive Keys had issues and stopped working repeatedly once screen is locked.
It only works again after reboot and fails after screen is locked.
Disabling this has fixed Capacitive Key Issue.
Change-Id: Ia7ff76620cdac863289f57ea37459bd5b94ea99e
Signed-off-by: Jackeagle <jackeagle102@gmail.com>
commit 2a017fd82c5402b3c8df5e3d6e5165d9e6147dc1 upstream.
The GTCO tablet input driver configures itself from an HID report sent
via USB during the initial enumeration process. Some debugging messages
are generated during the parsing. A debugging message indentation
counter is not bounds checked, leading to the ability for a specially
crafted HID report to cause '-' and null bytes be written past the end
of the indentation array. As long as the kernel has CONFIG_DYNAMIC_DEBUG
enabled, this code will not be optimized out. This was discovered
during code review after a previous syzkaller bug was found in this
driver.
Signed-off-by: Grant Hernandez <granthernandez@google.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-13631
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I0c205755470fa7b9cc83d8b80263c535c272eb18
using mms100_reset instead of mms_pwr_on_reset in mms100_ISC_download_mbinary function may fixes unexpected touchscreen freezes.
Change-Id: I1a7de26ac33f3f0a8d004c5e33a697e441f1ea76
* Fixes touchscreen bug observed in some games, emulators, and apps.
Change-Id: I7628366d6f7fa8824b1c255031c34d06a9570565
[haggertk: Clarification, this is for klte devices only - K_PROJECT,
KACTIVE_PROJECT, KSPORTS_PROJECT]
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I418f68ae48ed81d789843df16040c777cf030f90
[haggertk]: This updates both the hlte and klte drivers
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This reverts commit db456f0e45c8a6f117dfe948b7bd0b0aeccb75b0.
* While the interaction is not obvious, the above-referenced commit
seems to be the cause for the "screen stuck at full brightness"
problem on hlte* devices.
Change-Id: I046a1ba3d930cbd82430fef7f15114e3f1fa3c8d
* Modeled after the old gesture handling code in fw/b
* This allows us to use device specific code to handle
s-pen gestures instead of polluting fw/b
* Supports the following gestures:
- Swipe right
- Swipe left
- Swipe down
- Swipe up
- Long press
* To trigger the gestures, press the button on
the s-pen, execute the gesture action, and
then release the side button of the s-pen
* This patch also blocks touch input from the
s-pen when the stylus button is pressed, to
avoid causing unintended touch input
Change-Id: I55651a36d147ba69e6dbd987d1a267f544570ba0
Signed-off-by: Paul Keith <javelinanddart@gmail.com>
Place file offset validity checks under mutex.
BUG: 33555878
BUG: 33002026
Change-Id: I1945cfc8af7d1a310ae0d7bbb85002d4c448f30b
Signed-off-by: Andrew Chant <achant@google.com>
CVE-2017-0524
CVE-2017-0536
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
A series of characters between '0' and '9' with a length more than
MAX_FIRMWARE_ID_LEN causes a heap buffer overflow. This is
mitigated by performing a bounds check.
Bug: 31911920
Signed-off-by: Min Chong <mchong@google.com>
Change-Id: Iaefe92df2610153f2d3e2caa58322ae82cb5b7c2
[razorloves: Backport to 3.4]
CVE-2016-8393
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
sysfs entries are created which reference fwu->fwu_work.
defer the creation of these sysfs entries until the end of the init
function, after fwu->fwu_work has been initialized.
Change-Id: Ib7d5304ec2990454486e2b1d28b640a174c83d12
Bug: 31252388
Signed-off-by: Andrew Chant <achant@google.com>
CVE-2016-6745
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Previously I had made the struct device point to the input device, but
after talking with Dmitry, he said that the USB device would make more
sense for this driver to point to. So converted it to use that instead.
CC: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Fix memory corruption in Goodix touchscreen driver, by resetting
the global structure cmd_head to zero (except *data and wr flag)
in goodix_tool_write handler on error case.
CAF-Change-Id: I4f7f8f464b93571627b922b10c10a65826228e42
Signed-off-by: Vevek Venkatesan <vevekv@codeaurora.org>
CVE-2017-0622
Change-Id: I19c78864f8734b68bc6ae1de3e4853de624c7c03
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
commit 162f98dea487206d9ab79fc12ed64700667a894d upstream.
The gtco driver expects at least one valid endpoint. If given malicious
descriptors that specify 0 for the number of endpoints, it will crash in
the probe function. Ensure there is at least one endpoint on the interface
before using it.
Also let's fix a minor coding style issue.
The full correct report of this issue can be found in the public
Red Hat Bugzilla:
https://bugzilla.redhat.com/show_bug.cgi?id=1283385
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
CVE-2016-2187
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I99b9af4d1bf2df3845a6fac7caa3443da8ffb294
[ Upstream commit 9c6ba456711687b794dcf285856fc14e2c76074f ]
The powermate driver expects at least one valid USB endpoint in its
probe function. If given malicious descriptors that specify 0 for
the number of endpoints, it will crash. Validate the number of
endpoints on the interface before using them.
The full report for this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/85
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2186
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ib8a42fc7e0ca5d095c36b34ea328f19d28fe83cc
[ Upstream commit 950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d ]
The ati_remote2 driver expects at least two interfaces with one
endpoint each. If given malicious descriptor that specify one
interface or no endpoints, it will crash in the probe function.
Ensure there is at least two interfaces and one endpoint for each
interface before using it.
The full disclosure: http://seclists.org/bugtraq/2016/Mar/90
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
CVE-2016-2185
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I9274b674d6aa90617a22930618ab571910444d29
commit 8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 upstream.
The aiptek driver crashes in aiptek_probe() when a specially crafted USB
device without endpoints is detected. This fix adds a check that the device
has proper configuration expected by the driver. Also an error return value
is changed to more matching one in one of the error paths.
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2015-7515
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I3cdae8dd87a002409a5ab9190cfad7d3faa237d4
* Samsung sources have type mismatches in 3 of their drivers. This was
uncovered using linaro's toolchain for kernel compilation.
Change-Id: If3a083ffcb2a15185ff208b22976509ffd8af5e8
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
concurrent sysfs calls on the fw updater can cause
ugly race conditions. Return EBUSY on concurrent sysfs calls.
For sysfs calls which generate deferred work, prevent
the deferred work from running concurrently with other
sysfs calls.
Also check that ext_data_source is appropriately sized
and allocated, based on a patch by
Gengjia Chen (chengjia4574@gmail.com).
Signed-off-by: Andrew Chant <achant@google.com>
Change-Id:I5bbe4992f3fd2d23db288296eaeb61f5831098e9
Bug: 30799828
Bug: 31252388
Git-repo: https://android.googlesource.com/kernel/msm.git
Git-commit: 287ce2ccfefe68067c1f9f5175b6664bf7397fe6
Signed-off-by: Srinivasa Rao Kuppala <srkupp@codeaurora.org>
This patch fixes the misplaced endif that could cause some misc input
drivers not being listed when running the kernel configurator.
CRs-Fixed: 663748
Change-Id: I31cb24bd3fa5559b197bc227789c325edda736b0
Signed-off-by: Sahil Kataria <sahilk@codeaurora.org>
Accelerometer data output rate is limited by device ODR register,
no need to configure this register in polling mode.
CRs-Fixed: 641705
Change-Id: If59900b244b31f813dd17e72b19c7fd2ca4b4ba1
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
On some hardware when synaptics_rmi4_detection_work() is called,
exp_fn_list is still empty because module_init of synaptics_fw_update
is called later. As a result of this sysfs files required for firmware
update are not created. This patch changes the link order to ensure
that exp_fn_list is properly initialized before
synaptics_rmi4_detection_work() is called when all Synaptics modules
i.e. synaptics_fw_update, synaptics_rmi_dev and synaptics_i2c_rmi4 are
statically linked into the kernel.
CRs-fixed: 634135
Change-Id: Ib0b8e82ed569ecb18788b8aec6e1c9771e74fd2d
Signed-off-by: maol <maol@codeaurora.org>
Accelerometer mma8x5x driver may struck in disabling procedure due
to deadlock on workqueue flush.
Change-Id: Ibcd6ebe92bc2fece459fde5f76e5bfe1f90586a0
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Upgarde firmware on the touch controller when the new firmware
version is geater than the current firmware version. Update the
version id after successful firmware update. skip firmware
update process when device is in suspend state.
CRs-Fixed: 623803
Change-Id: Ic462f6483887a3654665852e58ae9891de9f5eff
Signed-off-by: Sarada Prasanna Garnayak <c_sgarna@codeaurora.org>
Maintain I2C adapter clocks on when starting Secure Touch
using the synchronous version of pm_runtime_get.
Change-Id: Ie30ea56af9e045239099652124740565428518f8
Acked-by: Christian Bolis <cbolis@qti.qualcomm.com>
Signed-off-by: Keith Fallows <keithf@codeaurora.org>
Accelerometer mma8x5x cannot change data output rate correctly in
interrupt due to wrong configuration value has been used.
Change-Id: I010cdf992267119cc8c54a855a33206920fc08e2
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Accelerometer mma8x5x driver register polling device for data
polling, but polling device only update polling interval on
new polling cycle, this will cause delay on change polling
interval in some case.
Change-Id: I391dc5507a40e6bfc7e8127a0db89cb685eaf192
Signed-off-by: Bingzhe Cai <bingzhec@codeaurora.org>
Replace the macros that are used inside the driver function
with dtsi entries.
Remove hrtimer calls which is not being used in the current
driver code.
Change-Id: I29b9ea41df467d0092be8005733016843dc26f60
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
This driver provides service to Host Based Touch Processing
in three aspects:
- It serves as an input device driver to send touch events from user
space to the kernel input core.
- It monitors LCD on/off and sends uevent accordingly.
- It performs power management for the touch AFE (Analog Front End).
Change-Id: Ibfb7c6a8d2c895ea0a277b8f0bf810e0263260e6
Signed-off-by: Jing Lin <jinglin@codeaurora.org>
Add sysfs entry for force fw_update support in Goodix
driver.
Change the usage of kstrtoul to sscanf in driver to avoid
portability issues.
CRs-fixed: 579806
Change-Id: I147a3e465170dda7af415ade29c04257d9b11a6b
Signed-off-by: Shantanu Jain <shjain@codeaurora.org>
Reorganize the code related to debugfs that allows driver to compile
for different build environments. Remove dead code and also define
dummy functions that are needed when CONFIG_PM is not enabled in defconfig.
Change-Id: I385d194c7463cd06322f1b5124f1dc0ce72fc8a1
Signed-off-by: Abinaya P <abinayap@codeaurora.org>
Possible values of config_area are between 0 and 3. The patch
adds bounds checking in fwu_sysfs_config_area_store() function.
Also use kstrtou16() for parsing the config_area.
Change-Id: Ia0b58f1b5a359c67f420012876431dac920ecfbd
Signed-off-by: Abinaya P <abinayap@codeaurora.org>