systemd 257. Bootable rootless nspawn containers can only be run once with the same --machine= name because the related cgroup stuff is not cleaned up properly on shutdown. It is nested pretty deep and annoying to clean up manually.
I noticed there were some commits since 257 that might address this issue but since it is an issue that is fairly easy to reproduce I hope this is addressed in 258. Command I use: 1207 ;; systemd-nspawn \ 1208 ;; -Z sys.id:sys.role:systemd.nspawn.unprivpipecontainer.subj:s0 \ 1209 ;; -L sys.id:sys.role:systemd.nspawn.container.fs:s0 --register=no -b \ 1210 ;; --console=autopipe --volatile=overlay --machine=foo --read-only \ 1211 ;; --network-veth --background="101;97" \ 1212 ;; -i /tmp/mkosi/nspawn-bootable_0.1.raw Sorry, I don't have a Github account. -- gpg --locate-keys dominick.gr...@defensec.nl (wkd) Key fingerprint = FCD2 3660 5D6B 9D27 7FC6 E0FF DA7E 521F 10F6 4098 Dominick Grift Mastodon: @kcini...@defensec.nl