turnipjs@lemmy.ml to linuxmemes@lemmy.world · 6 months agoHave you tried NixOS?lemmy.mlexternal-linkmessage-square44fedilinkarrow-up195arrow-down14
arrow-up191arrow-down1external-linkHave you tried NixOS?lemmy.mlturnipjs@lemmy.ml to linuxmemes@lemmy.world · 6 months agomessage-square44fedilink
minus-squareivn@jlai.lulinkfedilinkarrow-up0·6 months agoIt build in a sandbox, but it’s not run in a sandbox.
minus-squareVilian@lemmy.calinkfedilinkarrow-up0·6 months agoI don’t understand, if you run a program inside the sandbox and the program ask for a library, the kernel need to map the library from inside the sandbox to the program, that overhead that I’m talking about
minus-squareivn@jlai.lulinkfedilinkarrow-up1·6 months agoBut it’s not run in a sandbox. I’m not sure where you get this from.
minus-squareLaser@feddit.orglinkfedilinkarrow-up1·6 months agoThis is not how NixOS works. Programs directly link against libraries in the store. There is no sandbox by default when running the binaries.
It build in a sandbox, but it’s not run in a sandbox.
I don’t understand, if you run a program inside the sandbox and the program ask for a library, the kernel need to map the library from inside the sandbox to the program, that overhead that I’m talking about
But it’s not run in a sandbox. I’m not sure where you get this from.
This is not how NixOS works. Programs directly link against libraries in the store. There is no sandbox by default when running the binaries.