-
- Downloads
untrusted_app: confine filesystem creation to sandbox
untrusted_apps could be allowed to create/unlink files in world
accessible /data locations. These applications could create
files in a way that would need cap dac_override to remove from
the system when they are uninstalled and/or leave orphaned
data behind.
Keep untrusted_app file creation to sandbox, sdcard and media
locations.
Change-Id: Ife680cb9425dad8223651f16b9be8a3179839ec3
Signed-off-by:
William Roberts <william.c.roberts@intel.com>
Please register or sign in to comment