- allow matching on subject: ranges of uid, ranges of gid, jail id and object: ranges of uid, ranges of gid, filesystem, object is suid, object is sgid, object matches subject uid/gid, object type. This involves an ABI change between the kernel module and libugidfw, but no change between applications and ugidfw.