nixpkgs/nixos/modules/profiles
Kyle Copperfield 00ac71ab19 nixos/hardened: build sandbox incompatible with namespaces
Disables the build sandbox by default to avoid incompatibility with
defaulting user namespaces to false. Ideally there would be some kind of
linux kernel feature that allows us to trust nix-daemon builders to
allow both nix sandbox builds and disabling untrusted naemspaces at the
same time.
2019-11-19 14:56:09 +00:00
..
all-hardware.nix usb-storage -> uas 2018-08-23 01:42:34 +00:00
base.nix Revert "zfs cannot be distributed. Disabling it in the isos." 2018-11-26 17:51:18 -05:00
clone-config.nix ova: add cloneConfigExtra option 2018-10-21 14:52:49 -05:00
demo.nix [bot] nixos/*: remove unused arguments in lambdas 2018-07-20 20:56:59 +00:00
docker-container.nix use closure-info for building system tarball 2018-11-07 12:52:53 +08:00
graphical.nix profiles/graphical.nix: Drop systemWide pulseaudio in iso 2019-11-11 17:07:42 +01:00
hardened.nix nixos/hardened: build sandbox incompatible with namespaces 2019-11-19 14:56:09 +00:00
headless.nix modules/profiles/minimal: sound is disabled by default 2019-01-13 13:47:36 +01:00
installation-device.nix Revert "installer: Disable udisks" 2019-10-16 20:31:24 -04:00
minimal.nix types.optionSet: deprecate and remove last usages 2019-01-31 00:41:10 +02:00
qemu-guest.nix qemu-guest: allow to override security.rngd 2019-09-18 00:35:04 +09:00