capabilities
netrw
Filled is granted to every invocation; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
- ~/.config/cabal · writable
- ~/.cache/cabal · writable
- ~/.local/state/cabal · writable
env passed through
12 forwarded
CABAL_BUILDDIRCABAL_FLAGSGHCRTSGHC_ENVIRONMENTGHC_PACKAGE_PATHHASKELL_DIST_DIRHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
per-subcommand
no overrides
Every invocation gets the same boundary. Where a tool
needs more for one subcommand only, kapsl scopes it there
rather than granting it everywhere.