[PATCH] host/rootfs: Set no_new_privs in PID 1