abi , include include # There’s no point in confining the guix executable, since it can run # any user code and so everything is expected. We just need to # explicitly enable userns for systems with the # kernel.apparmor_restrict_unprivileged_userns sysctl. profile guix @{guix_storedir}/{*-guix-command,*-guix-*/bin/guix} flags=(unconfined) { userns, }