Co-mingling two things here:
- Addressing some feedback from Konstantin and Kyle re: jail, capability mode, and a few other things
- Adding audit support as promised.
The audit support change includes a partial refresh of OpenBSM from upstream, where my change to add shm_rename has already been accepted. I won't be working on refreshing anything else to support audit for those new event types.