* support transient mount units
-* Imply DevicePolicy=closed and CapabilityBoundingSet=~CAP_SYS_MKNOD when PrivateDevices= is used
+* Imply DevicePolicy=closed when PrivateDevices= is used. Mount
+ pts+kdbus+shm+mqueue into /dev namespace
* add an "input" group to udev logic and add all input devices to it
- see if we can drop more message validation on the sending side
- add API to clone sd_bus_message objects
- systemd-bus-proxyd needs to enforce good old XML policy
- - upload minimal kdbus policy into the kernel at boot
- kdbus: matches against source or destination pids for an "strace -p"-like feel. Problem: The PID info needs to be available in userspace too...
- longer term: priority inheritance
- check sender of response messages