diff --git a/Release_Notes_4.0-alpha2.md b/Release_Notes_4.0-alpha2.md index 8eace69..2d21f5d 100644 --- a/Release_Notes_4.0-alpha2.md +++ b/Release_Notes_4.0-alpha2.md @@ -33,8 +33,16 @@ wip - not in this alpha, not guaranteed to land in 4.0 - replace unconfined - mount, rename, hardlink restrictions, requires tracking +- bpf - ioctl - module +- ns tracking +- pivot root var +- deal with stacked attachment lookup +- optimize stacking name lookup to + - single buffer alloc + - single name lookup +- setns - - audit control flags audit.mode=XXX - prompt, kill, unconfined @@ -45,6 +53,7 @@ wip - not in this alpha, not guaranteed to land in 4.0 - audit.mode flag control - allow all - aa_load + - drop root check - sysv mqueue - debug flags - io_uring @@ -53,8 +62,18 @@ wip - not in this alpha, not guaranteed to land in 4.0 - improved rule prefixes - allow all - policy overlays +- dfa merge in kernel +- - extended xindex - user conditional + - policy + - attachment + - user mediation +- conditionals + - owner + - mac_override (for change_hat, hardlink, mv, bind mount) + - case insensite fs ??? + - - module mediation - boolean ops - raw text in policy