Full isolation has too much impact to be a default. Even on an almost unloaded machine with a couple of VMs running it results in audio buffer underruns due to the significant scheduling latency. This change is fine because with vmsilo, the trust domain is the VM. There isn't much reason to protect apps from other apps running in the same VM. Better to run those apps in separate VMs in that case. |
||
|---|---|---|
| .. | ||
| configuration.nix | ||
| flake.nix | ||