Re: Entitlements and specific files/dirs

2011-08-18 Thread Sean McBride
On Wed, 17 Aug 2011 03:17:30 -0600, Michael Vannorsdel said: Apologies if this has been covered in the past but my searches did not turn up anything as specific as I'm looking for. Are you talking about on Lion? If so, there hasn't been much discussion of this new feature here yet. Is there a

Re: Entitlements and specific files/dirs

2011-08-18 Thread Michael Vannorsdel
After lots of playing and reading of obscure documentation, it looks like Lion creates a duplicate library in the Containers folder so even a sandboxed app with no read or write file access still has access to its own Application Support, Caches, and Preferences folders, among others. The file

Entitlements and specific files/dirs

2011-08-17 Thread Michael Vannorsdel
Apologies if this has been covered in the past but my searches did not turn up anything as specific as I'm looking for. Is there a way to refine sandbox entitlements to allow read/write access to specific files and directories instead of just all or none? For instance, only allowing RW to