Things that need to be done:
===========================
1.2.10 - parse library
* Make sure there is a way to extract raw records with ausearch
* Look at adding --add, --del to aureport & ausearch. This will select events that involve adding/deleting rules, accounts, groups, etc.
* Group message types in ausearch help.
* If relative file in cwd, need to build also. watch out for (null) and socket
* Look at variadic avc logging patch 
* Add subject information to audit internal messages
* Change ausearch to output name="" unless its a real null. (mount) ausearch-report.c, 523. FIXME
* Consolidate parsing code between libaudit and auditd-conf.c
* add more man pages
* Switch auditctl over to use only new rule structs

1.2.11 - parse library
* make ausearch library for third party parsing API
* Success cb enum w/unset - adjust avc parsing to preserve syscall unless unset
* Avc messages should be linked list in ausearch & aureport
* Aureport range of time in summary maybe should be what's req if -ts or -te
* Add keywords for time: this-week, this-month, last-boot, last-load, last-relabel.
* Add --since to replace -ts & -te. Will set -te to now 
* Change python to allow NULL param passing
* Remove all old rule structs
* Possibly do equivalent of "tail -f"

1.3 - event dispatcher
* Bump soname number ???
* Don't audit the audispd program
* More audit dispatcher program & plugin framework updates
more plugins
* aureport get specific reports working

1.4
auditctl session id, pgid
Add counting semaphore to control internal queue depth
auditctl should ignore invalid arches for rules
Look at supporting binary formats
Remove evil getopt cruft in auditctl

1.5
look at config changed report to see if an action can be added 
Add scheduling options: strict, relaxed, loose (determines user space queueing)
Add exec option to action handlers
Parser should allow more than 1 arg after option - eg EXEC /usr/local/script
Add config option media: syslog, file, socket, dbus
Allow users to specify message types to be kept for logging
Allow users to specify fields to be kept for logging

1.6
Pretty Print ausearch messages
audit explorer gui
create responder to potential security incidents

IN THE DISTANT FUTURE:
Look at modifying kernel rule matcher to do: first match & match all 
Consider creating way to interactively delete rules by menu
Create a rule builder GUI
