The PrivateDevices=true systemd hardening option was preventing Nix from creating the kernel namespaces required for its build sandbox. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
4.7 KiB
4.7 KiB