Doesn't liunux have the nosuid,noexec,nosymfollow,nodev options for partitions? With bsd you can apply these options in /etc/fstab to partitions/slices to disallow suid binaries, execution of...