Files
tubestation/servo/etc/servo.sb
Jack Moffitt 132ee35633 servo: Merge #3230 - Cargoify servo (from servo:cargoify)
Source-Repo: https://github.com/servo/servo
Source-Revision: b1305bb7d051f83850c51bb0da0ccc86a5e07922
2014-09-09 08:18:18 -06:00

33 lines
535 B
Plaintext

(version 1)
(deny default)
(allow file*
(literal "/dev/dtracehelper")
(literal "/dev/urandom")
(literal "/dev/null"))
(allow file-read*
(subpath ""))
(allow file-write*
(regex #"^/Users/[^/]+/Library/Autosave Information")
(subpath "/private/var"))
; This is unfortunate...
(allow process-exec
(regex #"/servo$"))
(deny file-write*
(regex #"/servo$"))
(allow sysctl-read)
(allow sysctl-write)
(allow ipc-posix-shm)
(allow process-fork)
(allow mach-lookup)
(allow network-outbound)
(debug deny)