Harden /mnt/pass_through permission bits
It previously had 0755 permission bits With such permissive bits, an unauthorized app can access a file using the /mnt/pass_through path for instance even if access via /storage would have been restricted. It is now 0700 TODO: Change ACL for /mnt/user from 0755 to 0700 in vold only when FUSE flag is on. Changing it with FUSE off breaks accessing /sdcard because /sdcard is eventually a symlink to /mnt/user/0/primary Test: adb shell ls -d /mnt/pass_through Bug: 135341433 Change-Id: I3ea9655c6b8c6b4f847b34a2d3b96784a8f4a160
Loading
Please register or sign in to comment