Description
Type list READ/WRITE
A list of permitted paths for commands. If configured, the agent rejects a command if it is not run from one of these paths, even if the command is authorized by the policy.
Example
# allow commands only from the /bin, /sbin, /usr/bin, and /usr/sbin directories runpaths={"/bin", "/sbin", "/usr/bin", "/usr/sbin"};