Skip to content
Snippets Groups Projects
  • Jeff Sharkey's avatar
    25725b63
    Protect runtime storage mount points. · 25725b63
    Jeff Sharkey authored
    We have a bunch of magic that mounts the correct view of storage
    access based on the runtime permissions of an app, but we forgot to
    protect the real underlying data sources; oops.
    
    This series of changes just bumps the directory heirarchy one level
    to give us /mnt/runtime which we can mask off as 0700 to prevent
    people from jumping to the exposed internals.
    
    Also add CTS tests to verify that we're protecting access to
    internal mount points like this.
    
    Bug: 22964288
    Change-Id: Ic585c4d4381fe51bd764902ef28c38db63b7f2cc
    25725b63
    History
    Protect runtime storage mount points.
    Jeff Sharkey authored
    We have a bunch of magic that mounts the correct view of storage
    access based on the runtime permissions of an app, but we forgot to
    protect the real underlying data sources; oops.
    
    This series of changes just bumps the directory heirarchy one level
    to give us /mnt/runtime which we can mask off as 0700 to prevent
    people from jumping to the exposed internals.
    
    Also add CTS tests to verify that we're protecting access to
    internal mount points like this.
    
    Bug: 22964288
    Change-Id: Ic585c4d4381fe51bd764902ef28c38db63b7f2cc