I forgot to reiterate: the above is true *unless* there is another non-DAC, non-
MAC kernel mediation (eg, does the kernel only allow modifying the 'comm' value
of its own threads? If so, then the rule would be safe to add to the default
abstraction (though we should document that it is safe)).