nix-super/src/libstore/build/sandbox-minimal.sb
2023-01-04 04:50:45 -08:00

9 lines
154 B
Text

R""(
(allow default)
; Disallow creating setuid/setgid binaries, since that
; would allow breaking build user isolation.
(deny file-write-setugid)
)""