filter-syscalls = false experimental-features = nix-command flakes extra-platforms = x86_64-linux aarch64-linux build-users-group = nixbld trusted-users = root @admin @wheel vscode system-features = kvm big-parallel