Features:
+ - make sure that our namespace/kuid/pidns creds passing/deny logic
+ is what we want in the long run
+
+ - use/prepare for something like this to manage the pool backing shmemfd:
+ https://git.kernel.org/cgit/linux/kernel/git/minchan/linux.git/commit/?h=vrange-v10-rc5&id=0b40a69d4c5d9eb13352fd357d73a5fab3ee699d
+
+ - figure out/ prepare for priority inheritance like mutexes for the sync call
+
- check guards for all privileged-only operations:
- activation
- monitor