From: Lennart Poettering Date: Mon, 21 Nov 2022 14:14:22 +0000 (+0100) Subject: update TODO X-Git-Tag: v253-rc1~483 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=28795f2c138203fb700fc394f0937708af886116;p=thirdparty%2Fsystemd.git update TODO --- diff --git a/TODO b/TODO index cd80d05e7a0..6ad4778ddc9 100644 --- a/TODO +++ b/TODO @@ -121,6 +121,12 @@ Deprecations and removals: Features: +* fix systemd-gpt-auto-generator in case a UKI is spawned from XBOOTLDR without + sd-boot. In that case LoaderDevicePartUUID will point to the XBOOTLDR, and we + should then derive the root disk from that, and then the ESP/XBOOTLDR from + that. Right now we will only mount ESP if it matches LoaderDEvicePartUUID + which isn't quite the same. + * maybe prohibit setuid() to the nobody user, to lock things down, via seccomp. the nobody is not a user any code should run under, ever, as that user would possibly get a lot of access to resources it really shouldn't be getting