blob: 743ca69a9e31a9f6b1e7b780d88739f0281f0704 [file] [log] [blame]
# Put this file in /etc/sysctl.d/ to enable Bazel's sandboxing on Debian
# kernels.
# Run `sudo sysctl --system` to load it without rebooting.
kernel.unprivileged_userns_clone = 1