RBAC model as runtime registration module. (1.5?)
SELinux model as runtime registration module. (1.5?)
Helper script to load existing SELinux configs into the SELinux module.
Make
ACL learning mode be triggered by user and/or role.
Backup optimization with per-directory reference counters, if counter == 0, skip full tree.
(Maybe) Exclude option in backup, maybe with regular expressions.
Replace values for ttl'd data, to be used after timeout.
Really delete lists on rsbac_list_destroy().
(Maybe) make AUTH cap ranges (first-from-uid, last-from-uid, first-to-uid, last-to-uid), so you can have different sets depending on the current uid.
Optional RC role and type hierarchy for easier organization.
(Maybe) add jail flags and IP FD attributes to force a jail for a program without chroot.
More sophisticated resource control scheme.
Support more network address families in templates.
Support more network address families with NETDEV and SCD/network/firewall.
PM overhaul and menues.
(maybe) Install trace mode with automatic attribute restore (for software updates).
More learning modes etc., e.g. with automatic setup script generation.
(maybe) Attribute set undo log in menues.
(maybe) Attribute get log in menues.
Use namespaces for symlink redirection, if suitable.