[PATCH 03/18] passt, pasta: Namespace-based sandboxing, defer seccomp policy application