From Ingo's email:
> if (strstr(name, ".."))
> return -EACCESS;
>
> if (!strncmp(name, "/home/sandbox/", 14) &&
> !strncmp(name, "/lib/", 5) &&
> !strncmp(name, "/usr/lib/", 9))
> return -EACCESS;
Those tests are reversed. This will never return -EACCESS unless you give it a ".." filename. Hopefully, in real life someone would catch that in testing.