blob: c304b8388b3e3b043b1d691284462d3aa96e0a62 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
|
(version 1)
;; allow everything by default
(allow default)
;; deny all writes EXCEPT under project directory, temp directory, stdout/stderr and /dev/null
(deny file-write*)
(allow file-write*
(subpath (param "TARGET_DIR"))
(subpath (param "TMP_DIR"))
(literal "/dev/stdout")
(literal "/dev/stderr")
(literal "/dev/null")
)
|