Harden /mnt/pass_through paths
Only the FUSE daemon (with media_rw gid) needs access to paths on /mnt/pass_through. And even then, it only needs execute access on the dirs, since there will always be a bind mount either from sdcardfs or the lower filesystem on it and that bind mount correctly handles ACLs for the FUSE daemon. Test: manual Bug: 135341433 Change-Id: I999451e095da355e6247e9e18fb6fe1ab8fc45d6
Loading
Please register or sign in to comment