I am new to Tomoyo so please forgive my ignorance. I have learned that it is not possible to use a path_group together with allow_execute. Is there any way to create a sandbox such that a user can create programs in a particular directory, and run them (with the appropriate profile, of course), but not run programs in the rest of the filesystem? Thank you- Lee Worden McMaster University