clarification for systrace

Hello again misc.

1.  Does order matter, and is it first match or last match?
Ex:  I want to permit access to /home/tedu/* and subdirs, but not

2.  Best way to only match files in a dir, but not subdirs.
Ex:  Permit access to /home/tedu/* but not recursively.

3.  Documentation for the aliases.  Anywhere other than source?

4.  Documentation for the extra options, like permit as root or
Ex: Niels's page says "In combination with dynamic predicates, it is
possible to allow an unprivileged application to bind to a reserved port
exactly once."  How (exactly once)?

