See https://github.com/NixOS/nixpkgs/pull/28261
And add a 116 KiB ash shell from busybox to the release build. This helps to make sandbox builds work out of the box on non-NixOS systems and with diverted stores.