diff --git a/hosts/common/programs/assorted.nix b/hosts/common/programs/assorted.nix index e02744d7..93e3974e 100644 --- a/hosts/common/programs/assorted.nix +++ b/hosts/common/programs/assorted.nix @@ -718,7 +718,11 @@ in "/sys/kernel" ]; - procps = {}; + # procps: free, pgrep, pidof, pkill, ps, pwait, top, uptime, couple others + procps.sandbox.method = "bwrap"; + procps.sandbox.extraConfig = [ + "--sane-sandbox-keep-namespace" "pid" + ]; pstree.sandbox.method = "landlock"; pstree.sandbox.extraPaths = [