It's an independent reinvention of MAC, implemented by virtualization. Which is amusing, as the Solaris "zones" virtualization is derived from Trusted Solaris MAC (;-))
I expect two things
- additional similar reinventions both v->m and m->v
- a later realization that they're the same problem
and just perhaps
- a push from Linus to make MAC and KVM converge (;-))