On Mon, Aug 27, 2007 at 09:08:36 -0700, alan <alan@xxxxxxxxxxxxxx> wrote: > > AppArmor has an additional use that SELinux does not. The ability for the > user to constrain an arbitrary process run by the user. For example, I > could constrain Adobe Acrobat to only be able to read files in a narrowly > defined set of directories and not execute other applications. SELinux can do this.