Things that need to be done:
===========================
1.2.1 - parse library
* make ausearch library for third party parsing API
* add support for PARTIAL_SYSCALL records to ausearch
* Change ausearch to output name="" unless its a real null
* Change python to allow NULL param passing
* Add keywords for time: today, yesterday, this-week, this-month, now, last-boot, last-load, last-relabel.
* Add --since to replace -ts & -te. Will set -te to now 
* Better label the IPC section of capp.rules & lspp.rules
 
1.2.2
* add more man pages
* Make sure there is a way to extract raw records with ausearch
* Ausearch make listing message types logical
* Aureport range of time in summary maybe should be what's req if -ts or -te

1.2.3
* Success cb enum w/unset - adjust avc parsing to preserve syscall unless unset
* Avc messages should be linked list in ausearch & aureport

1.3 - new interfaces
* Collect USR1 sender and add to the log rotation message
* optional support for ppid in ausearch/aureport
* add support for ppid in auditctl
* auditctl session id, pgid
* Look into making auditctl do a rule update (for use with init reload). This would compare the rules one by one and if they match discard. If there is a difference, either load the new one or delete the old one.

1.4 - event dispatcher
* Remove deprecated functions
* Bump soname number ???
* Don't audit the audispd program
* Add dispatcher to reconfigure
* Add config option for audisp qos - blocking/non-blocking
* More audit dispatcher program & plugin framework updates
more plugins
aureport get specific reports working

1.5
Add counting semaphore to control internal queue depth
auditctl should ignore invalid arches for rules
Look at supporting binary formats
Remove evil getopt cruft in auditctl

1.6
look into way of spotting avc denials related to booleans
look at config changed report to see if an action can be added 
Add scheduling options: strict, relaxed, loose (determines user space queueing)
Add exec option to action handlers
Parser should allow more than 1 arg after option - eg EXEC /usr/local/script
Add config option media: syslog, file, socket, dbus
Allow users to specify message types to be kept for logging
Allow users to specify fields to be kept for logging

1.7
Pretty Print ausearch messages
audit explorer gui
create responder to potential security incidents
Under what circumstances do files have relative name in path record - ausearch may have to combine cwd record with path to do file searches

IN THE DISTANT FUTURE:
Look at modifying kernel rule matcher to do: first match & match all 
Allow users to label syscall event rules in auditctl
Consider creating way to interactively delete rules by menu
Create a rule builder GUI
