Eric W. Biederman wrote:

 > Have you seen my previous work in this direction?
I know I had a much much more complete implementation.  The only part
I had not completed was iptables support and that was about a days
more work.
No, I didn't see your work, is it possible to send me a pointer on it or
to have a patchset of your code ?
