Who must create an android security patch?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who must create an android security patch?

Jump to solution
1,490 Views
takayuki_ishii
Contributor IV

Hello community,

In  Android Security Bulletins, it have 3 type of security information.

  • Android platform fixes are merged into AOSP 24–48 hours after the security bulletin is released and can be picked up directly from there.
  • Upstream Linux kernel fixes are linked to directly from the bulletin on release and can be picked up from there.
  • Fixes from SOC manufacturers are available directly from the manufacturers.

My understanding that who must apply patches for this 

About "Fixed from SOC manufacturers" will be released some patches from NXP.

Others, "Android platform fixes" and "Upstream Linux kernel fixes", customer must get fixed code for each 

security Bulletins and apply it by themselves.

Is it correct?

Best regards,

Ishii.

Labels (2)
0 Kudos
1 Solution
1,226 Views
igorpadykov
NXP Employee
NXP Employee

Hi Ishii

I think your understanding is correct.

Best regards
igor
-----------------------------------------------------------------------------------------------------------------------
Note: If this post answers your question, please click the Correct Answer button. Thank you!
-----------------------------------------------------------------------------------------------------------------------

View solution in original post

0 Kudos
3 Replies
1,227 Views
igorpadykov
NXP Employee
NXP Employee

Hi Ishii

I think your understanding is correct.

Best regards
igor
-----------------------------------------------------------------------------------------------------------------------
Note: If this post answers your question, please click the Correct Answer button. Thank you!
-----------------------------------------------------------------------------------------------------------------------

0 Kudos
1,226 Views
richard_anderse
Contributor I

I have a question about this topic, that might be obvious and is more of an AOSP than a NXP question, but I haven't found a answer to it:

If I have a specific branch i.e. android-9.0.0_r1, does it update itself to r2 if I repo sync? 

As I understand it, every time a new security patch is relased a new release version is made (r1, r2, r3...) and if I want to be up to date with the latest security patch, how do I do?

Best regards,

Richard 

0 Kudos
1,226 Views
takayuki_ishii
Contributor IV

Hello Igor,

Thank you for your answer.

I will answer it to my customer.

Best regards,

Ishii.

0 Kudos