>Also, @cgwalters thinks trying to whitelist file paths is a bad idea given the myriad ways users have to manipulate paths, and the myriad ways in which system administrators may configure a system.
So you either get the entire filesystem or no file access? Isn't this a huge dealbreaker for almost everything?