commit 0c8dc0e6dfbd9272bc22b5476259cd68a1fab35c
parent c61746a15b78bcd22ca473345ff164ff2c9de973
Author: Drew DeVault <sir@cmpwn.com>
Date: Fri, 2 Dec 2016 10:32:08 -0500
Clarify that executable has to be a full path
Diffstat:
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/sway/sway-security.7.txt b/sway/sway-security.7.txt
@@ -104,11 +104,13 @@ access:
**permit** <executable> <features...>::
Permits <executable> to use <features> (each feature seperated by a space).
- <executable> may be * to affect the default policy.
+ <executable> may be * to affect the default policy, or the full path to the
+ executable file.
**reject** <executable> <features...>::
Disallows <executable> from using <features> (each feature seperated by a space).
- <executable> may be * to affect the default policy.
+ <executable> may be * to affect the default policy, or the full path to the
+ executable file.
Note that policy enforcement requires procfs to be mounted at /proc and the sway
process to be able to access _/proc/[pid]/exe_ (see **procfs(5)** for details on