From 28795f2c138203fb700fc394f0937708af886116 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Mon, 21 Nov 2022 15:14:22 +0100 Subject: [PATCH] update TODO --- TODO | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/TODO b/TODO index cd80d05e7a..6ad4778ddc 100644 --- a/TODO +++ b/TODO @@ -121,6 +121,12 @@ Deprecations and removals: Features: +* fix systemd-gpt-auto-generator in case a UKI is spawned from XBOOTLDR without + sd-boot. In that case LoaderDevicePartUUID will point to the XBOOTLDR, and we + should then derive the root disk from that, and then the ESP/XBOOTLDR from + that. Right now we will only mount ESP if it matches LoaderDEvicePartUUID + which isn't quite the same. + * maybe prohibit setuid() to the nobody user, to lock things down, via seccomp. the nobody is not a user any code should run under, ever, as that user would possibly get a lot of access to resources it really shouldn't be getting -- 2.25.1