A cluster of computer system nodes share direct read/write access to
storage devices via a storage area network using a cluster filesystem. At
least one trusted metadata server assigns a mandatory access control
label as an extended attribute of each filesystem object regardless of
whether required by a client node accessing the filesystem object. The
mandatory access control label indicates the sensitivity and integrity of
the filesystem object and is used by the trusted metadata server(s) to
control access to the filesystem object by all client nodes.