The PrivateDevices=true systemd hardening option was preventing Nix from creating the kernel namespaces required for its build sandbox. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The PrivateDevices=true systemd hardening option was preventing Nix from creating the kernel namespaces required for its build sandbox. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>