···
90
-
'bin': Accessibility.WRITABLE,
91
-
'nix': Accessibility.WRITABLE,
92
-
'run': Accessibility.WRITABLE,
90
+
'bin': Accessibility.READABLE,
91
+
'nix': Accessibility.READABLE,
92
+
'run': Accessibility.READABLE,
${lib.optionalString privateTmp "'tmp': Accessibility.STICKY,"}
94
-
${lib.optionalString privateTmp "'var': Accessibility.WRITABLE,"}
94
+
${lib.optionalString privateTmp "'var': Accessibility.READABLE,"}
${lib.optionalString privateTmp "'var/tmp': Accessibility.STICKY,"}
···
123
-
'bin': Accessibility.WRITABLE,
124
-
'nix': Accessibility.WRITABLE,
123
+
'bin': Accessibility.READABLE,
124
+
'nix': Accessibility.READABLE,
${lib.optionalString privateTmp "'tmp': Accessibility.STICKY,"}
'run': Accessibility.WRITABLE,
···
'sys': Accessibility.SPECIAL,
'dev': Accessibility.WRITABLE,
132
-
${lib.optionalString privateTmp "'var': Accessibility.WRITABLE,"}
132
+
${lib.optionalString privateTmp "'var': Accessibility.READABLE,"}
${lib.optionalString privateTmp "'var/tmp': Accessibility.STICKY,"}
···
'proc': Accessibility.SPECIAL,
'sys': Accessibility.SPECIAL,
'dev': Accessibility.SPECIAL,
'dev/shm': Accessibility.STICKY,
'dev/mqueue': Accessibility.STICKY,