> I've run into a slight problem with the lynx pledging. If there's a > ~/.mailcap entry for a mimetype, lynx uses it to try and display the > file, for example I have > > application/pdf; mutt_bgrun mupdf '%s'; nametemplate=%s.pdf > > (mutt_bgrun is the old script from > http://www.spocom.com/users/gjohnson/mutt/mutt_bgrun) > so with this, following a link that ends up in a pdf results in lynx > being killed by pledge.
Same overreach we see elsewhere -- where every program can do anything, everyone forgets it can do so, and the features become indistinguishable from attack surface...