+ - journalctl: instead --after-cursor= maybe have a --cursor=XYZ+1 syntax?
+ - journalctl: support -M to read journal of containers and determine journal directory from root directory of container
+ - tmpfiles: when applying ownership to /run/log/journal, also do this for the journal fails contained in it
+ - when a kernel driver logs in a tight loop, we should ratelimit that too.
+ - journald: optionally, log debug messages to /run but everything else to /var
+ - journald: when we drop syslog messages because the syslog socket is
+ full, make sure to write how many messages are lost as first thing
+ to syslog when it works again.
+ - journald: make sure ratelimit is actually really per-service with the new cgroup changes
+ - change systemd-journal-flush into a service that stays around during
+ boot, and causes the journal to be moved back to /run on shutdown,
+ so that we don't keep /var busy. This needs to happen synchronously,
+ hence doing this via signals is not going to work.