The sandbox expects that the host has a `libseccomp.so` in its global
search-path (usually `/usr/lib`). However, that path doesn't exist on
NixOS. Another standard way of passing lookup paths to `dlopen()` is
using LD_LIBRARY_PATH which is now passed through to the sandbox.
if "TMPDIR" in os.environ:
env["TMPDIR"] = os.environ["TMPDIR"]
- for e in ("SYSTEMD_LOG_LEVEL", "SYSTEMD_LOG_LOCATION"):
+ for e in ("SYSTEMD_LOG_LEVEL", "SYSTEMD_LOG_LOCATION", "LD_LIBRARY_PATH"):
if e in os.environ:
env[e] = os.environ[e]