From 2aba426ffb345408a461ed0ff6fba46e63ae625b Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Thu, 9 May 2013 15:32:27 +0200 Subject: [PATCH] man: document that the kernel's audit subsystem is currently incompatible with nspawn containers --- man/systemd-nspawn.xml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/man/systemd-nspawn.xml b/man/systemd-nspawn.xml index cab5990a5..d9fb89989 100644 --- a/man/systemd-nspawn.xml +++ b/man/systemd-nspawn.xml @@ -142,6 +142,16 @@ might be necessary to add this file to the container tree manually if the OS of the container is too old to contain this file out-of-the-box. + + Note that the kernel auditing subsystem is + currently broken when used together with + containers. We hence recommend turning it off entirely + when using systemd-nspawn by + booting with audit=0 on the kernel + command line, or by turning it off at kernel build + time. If auditing is enabled in the kernel operating + systems booted in an nspawn container might refuse + log-in attempts. -- 2.30.2