From a7b1c3971a30546fe633e320d45033aba8b2ca3c Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Tue, 11 Mar 2014 05:40:36 +0100 Subject: [PATCH 1/1] README: document that we still encourage people to turn off audit when they want to use containers --- README | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/README b/README index 7a227e732..ace13cf07 100644 --- a/README +++ b/README @@ -89,6 +89,13 @@ REQUIREMENTS: runtime using the kernel command line option "audit=0", or turn it off at kernel compile time using: CONFIG_AUDIT=n + If systemd is compiled with libseccomp support on + architectures which do not use socketcall() and where seccomp + is supported (this effectively means x86-64 and ARM, but + excludes 32bit x86!), then nspawn will now install a + work-around seccomp filter that makes containers boot even + with audit being enabled. This works correctly only on kernels + 3.14 and newer though. TL;DR: turn audit off, still. glibc >= 2.14 libcap -- 2.30.2