It's something like a two-line kernel mod to make unlink() refuse to work
if the directory has the sticky bit on and the invoker is not the owner
of the file (or the superuser). Then you just sticky-bit /tmp.
--
Henry Spencer @ U of Toronto Zoology
{allegra,ihnp4,linus,decvax}!utzoo!henry