Override the shared mcp.nix sandbox (PrivateDevices) on straylight so the MCP agent can boot Nanos unikernel VMs under QEMU/KVM and manage TAP devices for isolated networking. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Override the shared mcp.nix sandbox (PrivateDevices) on straylight so the MCP agent can boot Nanos unikernel VMs under QEMU/KVM and manage TAP devices for isolated networking. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>