As one of my colleagues pointed out, this is a job for NSS! With an NSS-resident /usr, everyone would get it read-only. The "owner" Linux instance would define a new NSS when needed, fill it with current content, and then 'saveseg', at which point all in-use copies would go CLASS P and be purged upon release.
Nifty, huh? -- R;
