Kaigai is unable to attend. Russell Coker has volunteered to take over the speaking slot.
The aim of the LAPP project is to have a consistent mandatory access control model across the entire stack. The kernel controls file access, Apache has threads running under contexts that match the users, and the PostgreSQL database has SE Linux support to grant access based on the context of the Apache thread.
Also see the SE PostgreSQL talk in the databases mini-conf.