Start locking down /data/media access.
The new sdcardfs filesystem requires that we have stricter access controls around /data/media style locations. Start by taking away the "media_rw" GID from apps requesting the WRITE_MEDIA_STORAGE permission. Common use-cases like music playback appear to continue working fine, as clients should only be attempting to use /data/media paths after calling maybeTranslateEmulatedPathToInternal(). Test: builds, boots, music playback works Bug: 35447080 Change-Id: Iba9f3ef41d3277c75497f675a1fe6d3406cf4542
This commit is contained in:
@@ -60,7 +60,6 @@
|
||||
</permission>
|
||||
|
||||
<permission name="android.permission.WRITE_MEDIA_STORAGE" >
|
||||
<group gid="media_rw" />
|
||||
<group gid="sdcard_rw" />
|
||||
</permission>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user