A person will stand on the top of a hill for a very long time with
their mouth open before a roast duck will fly in.
-- James Morris
For the purposes of figuring out what is needed you can consider a
random simple user case such as a system which protects you against
the works of Eric S Raymond. Replace the mathematical analysis and
heuristics with a user space tool which spots the various ESR
papers and design it for that if it makes you happier.
SELinux seems to be able to do most of the lifting around the
problem as it can relabel a file into eric_t and constrain further
access to it.
-- Alan Cox
to post comments)