Changes since v2:
- made signal rules broader, as suggested by Jamie Strandboge
<jamie(a)canonical.com> and indeed my tests confirm v2 was too
strict;
- allowed libvirtd "ptrace (read)" on libvirt-* guests, as suggested
by Jamie Strandboge <jamie(a)canonical.com>
- added fine-grained mount rules written by openSUSE's Christian
Boltz