> > 3. Hardest/most flexible: set the appropriate paths through /proc/sys;
> > disable Java binaries unless the paths are set.
> >
> > I'll try to hack up #3.
>
> 4. Add it and other strange similar things to libcs exec() stuff and keep
> it out of the kernel ?
Doesn't allow for secure control of things like whether suid and sgid will
be honored for a particular format.
lilo