> BTW, 5.0 will also allow (once we commit the MAC framework from the
> TrustedBSD Project) kernel modules to tweak process visibility protections
> in the kernel at runtime.  For example, you can kldload a
> mac_seeotheruids.ko policy module, which can limit what processes can view
> of other processes based on a number of factors, including uids, and
> information it tags onto the processes.  It can also limit access to
> socket information listed in netstat, etc.

When will the TrustedBSD modules commited to current??



An OS is like swiss cheese, the bigger it is, the more holes you get!

