nixos/hardened: build sandbox incompatible with namespaces
Disables the build sandbox by default to avoid incompatibility with defaulting user namespaces to false. Ideally there would be some kind of linux kernel feature that allows us to trust nix-daemon builders to allow both nix sandbox builds and disabling untrusted naemspaces at the same time.
parent
93e8c34e
Please register or sign in to comment