mlock() returns EPERM in systemd-nspawn context Set caps systemd-nspawn --capability=CAP_IPC_LOCK ... Over!