From ac6602ac3531ae57603e8a9e5ac2ee1652164b23 Mon Sep 17 00:00:00 2001 From: Raja Grewal Date: Mon, 26 Aug 2024 11:19:20 +1000 Subject: [PATCH] Add detail on disabling user namespaces breaking UPower --- usr/lib/sysctl.d/990-security-misc.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/usr/lib/sysctl.d/990-security-misc.conf b/usr/lib/sysctl.d/990-security-misc.conf index 484761e..d244a01 100644 --- a/usr/lib/sysctl.d/990-security-misc.conf +++ b/usr/lib/sysctl.d/990-security-misc.conf @@ -116,6 +116,7 @@ kernel.sysrq=0 ## Restricting may lead to breakages in numerous software packages. ## Uncomment the second sysctl to entirely disable user namespaces. ## Disabling entirely will reduce compatibility with some AppArmor profiles. +## Disabling entirely is known to break the UPower systemd servince. ## ## https://lwn.net/Articles/673597/ ## https://madaidans-insecurities.github.io/linux.html#kernel