Hello, smeeld, you wrote: S> the Same that above named crutches, only it is ready more "" as implemented not at level of categories and abstractions of a kernel of OS which are orthogonal to all entities concerning the world of the user applications, and at level of categories and abstractions of the user applications what there can be the infinite set so, and "" there it is necessary indefinitely Yes is not present. The repository with something is same high-grade essence of OS, as well as "file". And same orthogonal to all remaining abstractions." Application type "- just the same essence. There are no categories and abstractions of the user applications. All - at level of entities of OS. In the plan" categories and abstractions of a kernel of OS "- ANY DIFFERENCE that is. The reality can be only in lists of specific types of files and types of applications. But, as I spoke, in OS even is optional is all can quite be adjustment with change possibility through the special administrator. And, by the way (irrespectively to correctness or abnormality of my approach), and what, at us in the modern OS is not enough that ? Megatons only. Both users, and certificates, and IP addresses, and still a devil's abyss. S> the enumerated circuit of demarcations without problems is implemented by such systems, as mentioned above SELinux where is available certain a dial-up of abstractions, orthogonal to the user applications by which the system of demarcation of the access, concerning to to applications is built. Esteem about contexts and policies SELinux. Crutches it, crutches. The system by default should be safe and convenient. That in SELinux is implemented - probably in any sense safely (though and without any warranties as adjusted received), but not by default, is inconvenient for application by the normal user and demands special knowledge in this area. Just because for data security of the user all modern OS do hardly less, than anything, antiviruses in these OS and are necessary. Simply all OS are created, proceeding from others (hopelessly become outdated, in my opinion) principles.