This patch series adds support for sVirt to the LXC driver. In this
series, all LXC guests continue to run unconfined by default. The
app has to explicitly request sVirt confinement for the guest. This
is to ensure backwards compatibility with existing deployments. Since
we won't auto-relabel filesystem trees, it is not possible to turn it
on by default, as we previously did with QEMU