I'm not much of an SELinux fan, but your claim that 'the kernel team has
all but kicked [the SELinux developers? SELinux itself?] out with the
opening of the LSM api' is ludicrous. Providing extra choices doesn't mean
that the existing choices are anathematized!