/dev in the nix sandbox still includes a lot of device nodes. We should add devfs rules to limit which nodes are in the sandbox