Add --no-sandbox flag to nixos-rebuild command
Fixes kernel namespace sandboxing issues when running as systemd service. The --no-sandbox flag disables Nix build sandboxing which requires kernel namespaces not available in restricted service environments.
This commit is contained in:
parent
2d3844b5dd
commit
f5d2ebeaec
@ -302,6 +302,7 @@ impl Agent {
|
|||||||
tokio::process::Command::new("sudo")
|
tokio::process::Command::new("sudo")
|
||||||
.arg("/run/current-system/sw/bin/nixos-rebuild")
|
.arg("/run/current-system/sw/bin/nixos-rebuild")
|
||||||
.arg("switch")
|
.arg("switch")
|
||||||
|
.arg("--no-sandbox")
|
||||||
.arg("--flake")
|
.arg("--flake")
|
||||||
.arg(".")
|
.arg(".")
|
||||||
.current_dir(working_dir)
|
.current_dir(working_dir)
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user