> As far limiting executables launching other executables, you should be
> able to do it with SELinux or AppArmor, though I don't know what tools
> there are make that easier to manage.

SELinux can also limit what ports an application can use, but for now
you'll probably have to get you hands dirty to do so. Graphical tools
for managing SELinux are still being developed.

