	Add items about clarifiying the interaction of naflags,
	current audit state, and what userspace might need to
	do. Also add item about kernel's audit state indicators.

 kernel event mapping.  Make the synchronization code a library function in
 OpenBSM so that the same code can be used in both auditd and the audit
 test suite.
+- Determine what the correct behavior should be for processes that
+are started before audit is enabled: Should they be audited based
+on naflags AFTER audit is enabled, or do they not get audited.
+- For programs that set the audit masks for authenticated users
+(login, sshd, etc.) need to consider the audit off vs. audit
+disabled (a temporary condition) state. Should the flags for
+the process be set in the disabled state but not the off state?
+- Review the kernel audit_enabled and audit_suspended flags, making
+sure they are used consistently, and they map to the exposed state
+- Clearly document whatever is decided for the three items above.
