This seems to be a fairly significant hole in the VMM's sandbox. Various code operates in that directory and isn't secure against symlink attacks. Does the VMM really need write access to that directory? Could it be given access to a subdirectory that is mounted "nosymfollow"? -- Sincerely, Demi Marie Obenour (she/her/hers)