From: Lennart Poettering Date: Tue, 11 Mar 2014 04:40:36 +0000 (+0100) Subject: README: document that we still encourage people to turn off audit when they want... X-Git-Tag: v211~28 X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=commitdiff_plain;h=a7b1c3971a30546fe633e320d45033aba8b2ca3c;hp=236af516b866473c22f980b556a2d7535cef4d9b README: document that we still encourage people to turn off audit when they want to use containers --- diff --git a/README b/README index 7a227e732..ace13cf07 100644 --- a/README +++ b/README @@ -89,6 +89,13 @@ REQUIREMENTS: runtime using the kernel command line option "audit=0", or turn it off at kernel compile time using: CONFIG_AUDIT=n + If systemd is compiled with libseccomp support on + architectures which do not use socketcall() and where seccomp + is supported (this effectively means x86-64 and ARM, but + excludes 32bit x86!), then nspawn will now install a + work-around seccomp filter that makes containers boot even + with audit being enabled. This works correctly only on kernels + 3.14 and newer though. TL;DR: turn audit off, still. glibc >= 2.14 libcap