Whether to allow SMT/hyperthreading
Whether to allow creation of user namespaces
Whether to force-enable the Page Table Isolation (PTI)
Disable kernel module loading once the system is fully initialised
Whether to prevent replacing the running kernel image
When disabled, unprivileged users will not be able to create new namespaces
Size limit for the /run/wrappers tmpfs
security.wrappersNixOS option
This option effectively allows adding setuid/setgid bits, capabilities, changing file ownership an…