Skip to content
Commit 00ac71ab authored by Kyle Copperfield's avatar Kyle Copperfield
Browse files

nixos/hardened: build sandbox incompatible with namespaces

Disables the build sandbox by default to avoid incompatibility with
defaulting user namespaces to false. Ideally there would be some kind of
linux kernel feature that allows us to trust nix-daemon builders to
allow both nix sandbox builds and disabling untrusted naemspaces at the
same time.
parent 93e8c34e
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment