forkstat: document sandbox limitations

This commit is contained in:
2024-09-03 02:54:27 +00:00
parent 9050d8979e
commit 2d5cb84eef

View File

@@ -598,7 +598,7 @@ in
withWebkit = false;
});
forkstat.sandbox.method = "landlock"; #< doesn't seem to support bwrap
forkstat.sandbox.method = "landlock"; #< doesn't support bwrap unless i do `--sanebox-keep-namespace pid --sanebox-keep-namespace net`
forkstat.sandbox.isolatePids = false;
forkstat.sandbox.extraPaths = [
"/proc"