I'm guessing that (in addition to those entitlements) a mechanism much like chroot might also be employed. E.g., the app will be running chrooted to the user's home... and that affords it no means with which to access (read or write) anything above and beyond that home folder. As far as it knows, the "root" (/) of all available file space is that home folder. It can only reach down within that hierarchy.

Hmm, or perhaps such restrictions are more necessary for writing than reading. Anyway... just guessing there.

Last edited by Hal Itosis; 02/22/12 05:34 PM.