programs: nvme-cli: sandbox
This commit is contained in:
@@ -651,6 +651,18 @@ in
|
||||
"/proc"
|
||||
];
|
||||
|
||||
# `nvme list` only shows results when run as root.
|
||||
nvme-cli.sandbox.method = "landlock";
|
||||
nvme-cli.sandbox.wrapperType = "wrappedDerivation";
|
||||
nvme-cli.sandbox.extraPaths = [
|
||||
"/sys/devices"
|
||||
"/sys/class/nvme"
|
||||
"/sys/class/nvme-subsystem"
|
||||
"/sys/class/nvme-generic"
|
||||
"/dev"
|
||||
];
|
||||
nvme-cli.sandbox.capabilities = [ "sys_rawio" ];
|
||||
|
||||
# settings (electron app)
|
||||
obsidian.persist.byStore.plaintext = [ ".config/obsidian" ];
|
||||
|
||||
|
Reference in New Issue
Block a user