• rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 hours ago

      Not everything in the config paths are in the store.

      None of the users are in the store

      Any users can run arbitrary binaries as long as they’re not dynamically linked.

      Root can permanently add and remove arbitrary stuff to/from the store at run time.

      It’s pretty good in a lot of ways you can’t modify hosts and you can’t throw stuff into cron, but a great deal of Nixos is mutable.