binfmt_misc: enable sandboxed mounts