[libvirt] RFC: extending sVirt to confine host apps which talk to libvirtd