Details
-
Improvement
-
Status: Resolved
-
Minor
-
Resolution: Fixed
-
None
-
None
Description
Sandboxes are currently created with 0755 permissions, which allows anyone with local machine access to inspect their contents. We should make them 0750 to limit access to the owning user and group.
Attachments
Attachments
Issue Links
- causes
-
MESOS-8585 Agent crashes when starting a task with an unknown user.
- Resolved
-
MESOS-9531 chown error handling is incorrect in createSandboxDirectory.
- Resolved