summary refs log tree commit diff
path: root/nixos/modules
diff options
context:
space:
mode:
authorGraham Christensen <graham@grahamc.com>2017-02-14 13:57:44 -0500
committerGitHub <noreply@github.com>2017-02-14 13:57:44 -0500
commit3be13889633df6413cea1f2fdeed34ecee01d598 (patch)
treed5f8bb8ea26d3c125ac3189e25e24fb5adca4b95 /nixos/modules
parentd440052b64ef54479299b0ed24c11f078bef5536 (diff)
parentd0a086770a1be8c1f3175c195587052c5a5bfe1c (diff)
downloadnixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar.gz
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar.bz2
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar.lz
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar.xz
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.tar.zst
nixlib-3be13889633df6413cea1f2fdeed34ecee01d598.zip
Merge pull request #22767 from grahamc/sandbox-by-default
nix-daemon: default useSandbox to true
Diffstat (limited to 'nixos/modules')
-rw-r--r--nixos/modules/services/misc/nix-daemon.nix8
1 files changed, 4 insertions, 4 deletions
diff --git a/nixos/modules/services/misc/nix-daemon.nix b/nixos/modules/services/misc/nix-daemon.nix
index 7101cadfeed2..4c7264f4ac83 100644
--- a/nixos/modules/services/misc/nix-daemon.nix
+++ b/nixos/modules/services/misc/nix-daemon.nix
@@ -100,14 +100,14 @@ in
 
       useSandbox = mkOption {
         type = types.either types.bool (types.enum ["relaxed"]);
-        default = false;
+        default = true;
         description = "
           If set, Nix will perform builds in a sandboxed environment that it
           will set up automatically for each build.  This prevents
           impurities in builds by disallowing access to dependencies
-          outside of the Nix store. This isn't enabled by default for
-          performance. It doesn't affect derivation hashes, so changing
-          this option will not trigger a rebuild of packages.
+          outside of the Nix store. It doesn't affect derivation
+          hashes, so changing this option will not trigger a rebuild
+          of packages.
         ";
       };