]> git.ipfire.org Git - thirdparty/mkosi.git/commitdiff
docs: Minor correction on enabling unprivileged namespaces
authorssooffiiaannee <h.sousou97@gmail.com>
Sat, 27 Dec 2025 16:02:39 +0000 (17:02 +0100)
committerDaan De Meyer <daan.j.demeyer@gmail.com>
Sat, 27 Dec 2025 16:16:11 +0000 (17:16 +0100)
apparmor_restrict_unprivileged_unconfined should be set to 0 to allow
unprivileged namespaces.

mkosi/resources/man/mkosi.1.md

index c14aea191e443a5ab121fd7556aa99b34a981cc4..affce0c08d163fa14d69b1561c4335d4625da794 100644 (file)
@@ -3278,16 +3278,16 @@ https://ubuntu.com/blog/ubuntu-23-10-restricted-unprivileged-user-namespaces. To
 unprivileged user namespaces on Ubuntu, run the following commands:
 
 ```sh
-sudo sysctl -w kernel.apparmor_restrict_unprivileged_unconfined=1
-sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=1
+sudo sysctl -w kernel.apparmor_restrict_unprivileged_unconfined=0
+sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
 ```
 
 To persist these sysctl settings across reboots, create `/etc/sysctl.d/unprivileged-userns.conf`
 with the following contents:
 
 ```conf
-kernel.apparmor_restrict_unprivileged_unconfined=1
-kernel.apparmor_restrict_unprivileged_userns=1
+kernel.apparmor_restrict_unprivileged_unconfined=0
+kernel.apparmor_restrict_unprivileged_userns=0
 ```
 
 For other systems, try researching the `kernel.unprivileged_userns_clone` or