Nix/src/libstore/sandbox-minimal.sb

6 lines
143 B
Plaintext

(allow default)
; Disallow creating setuid/setgid binaries, since that
; would allow breaking build user isolation.
(deny file-write-setugid)