Skip to content
Snippets Groups Projects
  • dcashman's avatar
    b84c86b2
    DO NOT MERGE. Remove isolated_app's ability to read sysfs. · b84c86b2
    dcashman authored
    untrusted_app lost the ability to read files labeled as sysfs to prevent
    information leakage, but this is trivially bypassable by spawning an
    isolated app, since this was not taken away from isolated app.
    Privileges should not be gained by launching an isolated app, and this
    one directly defeats that hardeneing. Remove this access.
    
    Bug: 28722489
    Change-Id: I61d3678eca515351c9dbe4444ee39d0c89db7a3e
    b84c86b2
    History
    DO NOT MERGE. Remove isolated_app's ability to read sysfs.
    dcashman authored
    untrusted_app lost the ability to read files labeled as sysfs to prevent
    information leakage, but this is trivially bypassable by spawning an
    isolated app, since this was not taken away from isolated app.
    Privileges should not be gained by launching an isolated app, and this
    one directly defeats that hardeneing. Remove this access.
    
    Bug: 28722489
    Change-Id: I61d3678eca515351c9dbe4444ee39d0c89db7a3e