Features:
+* Query Paul Moore about relabelling socket fds while they are open
+
+* log fewer journal internal messages to the kernel kmsg
+
+* move keymaps to /usr/lib/... rather than /usr/lib/udev/...
+
+* journald: check whether it is OK if the client can still modify delivered journal entries
+
+* json: use jensson
+
+* json: properly serialize multiple fields with the same name per entry
+
+* journald: add option to choose between "split up nothing", "split up login user journals", "split up all user journals"
+
+* journal live copy, based on libneon (client) and libmicrohttpd
+
+* document in wiki json serialization
+
+* python-journal merge
+
+* system-wide seccomp filter
+
+* securityfs: don't mount in container
+
+* slave/shared remount root fs in container might clash with CAP_SYS_MOUNTS
+
+* ability to pass fds into systemd
+
+* system.conf should have controls for cgroups
+
+* bind mount read-only the cgroup tree higher than than nspawn
+
+* currently system services appear not to generate core dumps...
+
+* wall messages for shutdown should move to logind
+
+* allow writing multiple conditions in unit files on one line
+
* There's something wrong with escaping unit names: http://lists.freedesktop.org/archives/systemd-devel/2012-August/006292.html
* cleanup ellipsation for log output in journalctl and systemctl status: have a sane way to disable ellipsation, and disable it by default when invoked in less/more
* enforce limits on fds openened by socket units
-* proper service failure code for services which hit the restart limit
-
* explore multiple service instances per listening socket idea
* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server.
-* journald: add symlinks and device names to kernel messages
-
* maybe make systemd-detect-virt suid? or use fscaps?
-* consider using __secure_getenv() instead of getenv() in libs
-
-* journald: automatic rekeying with no log messages doesn't appear to work
-
-* man: document in ExecStart= explicitly that we don't take shell command lines, only executable names with arguments
-
* shutdown: don't read-only mount anything when running in container
* nspawn: --read-only is not applied recursively to submounts
* document that service reload may be implemented as service reexec
-* add option to reconfigure success exit codes/signals for services
-
* remember which condition failed for services, not just the fact that something failed
* use opterr = 0 for all getopt tools
* switch-root: sockets need relabelling
-* segfault in journalctl during /var migration
-
* systemd-analyze post-boot is broken for initrd
* man: clarify that time-sync.target is not only sysv compat but also useful otherwise. Same for similar targets
-* journalctl should complain if run with uid != 0 and no persistent logs exist
-
* .device aliases need to be implemented with the "following" logic, probably.
* refuse taking lower-case variable names in sd_journal_send() and friends.
* systemctl: when stopping a service which has triggres and warning about it actually check the TriggeredBy= deps fields
-* journal: hook up with EFI firmware log, new kmsg logic
+* journal: hook up with EFI firmware log
* handle C-A-Del in logind, like the power/suspend buttons?
- implement .d/ auto includes for unit files
- add syntax to reset ExecStart= lists (and similar)
-* manipulate CPU governor during boot, set it to performance
-
-* steal SBF management from the kernel
-
-* delay journal /var writeout to after boot if SBF is clean
-
* move passno parsing to fstab generator
* improve !/proc/*/loginuid situation: make /proc/*/loginuid less dependent on CONFIG_AUDIT,
* Add pretty name for seats in logind
-* nspawn wants dev_setup() for /dev/fd/ and friends?
-
* selinux: merge systemd selinux access controls (dwalsh)
* ConditionSecurity= should learn about IMA
* dbus: in fedora, make the machine a symlink to /etc/machine-id
+* dbus: move dbus to early boot
+
* journald: reuse XZ context
* logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API
* GC unreferenced jobs (such as .device jobs)
-* when failing to start a service due to ratelimiting, try again later, if restart=always is set
-
* write blog stories about:
- enabling dbus services
- status update
* set_put(), hashmap_put() return values check. i.e. == 0 doesn't free()!
+* use __secure_getenv() instead of getenv() where appropriate
+
Scheduled for removal (or fixing):
* xxxOverridable dependencies