- intact. Also, in order to keep things safe, any option that tells a
- non-chroot daemon to treat some symlinks as their referent (such as
- --copy-links or --keep-dirlinks) now manually checks the symlink chain
- to ensure that the symlinks do not try to escape past the top of the
- module's path. Both these changes make a non-chroot daemon behave the
- same as a chroot daemon with regard to symlinks, and also avoids a
+ intact. Also, in order to keep things safe, all arg paths and any
+ dereferenced symlinks (e.g. via --copy-links or --keep-dirlinks) are
+ manually verified to ensure that no symlinks try to escape past the top
+ of the module's path. These changes make a non-chroot daemon behave the
+ same way as a chroot daemon with regard to symlinks, and also avoids a