Skip to content
Snippets Groups Projects
Commit bd0768cc authored by William Roberts's avatar William Roberts Committed by Nick Kralevich
Browse files

untrusted_app: confine filesystem creation to sandbox


untrusted_apps could be allowed to create/unlink files in world
accessible /data locations. These applications could create
files in a way that would need cap dac_override to remove from
the system when they are uninstalled and/or leave orphaned
data behind.

Keep untrusted_app file creation to sandbox, sdcard and media
locations.

Change-Id: Ife680cb9425dad8223651f16b9be8a3179839ec3
Signed-off-by: default avatarWilliam Roberts <william.c.roberts@intel.com>
parent eebdb473
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment