fs: fix safe_canon regression introduced by ac40d86b6
hook: fix setrlimit invocation at startup (take 4)
hook: fix setrlimit invocation at startup (take 3)
hook: fix setrlimit invocation at startup (take 2)
hook: fix safe_bind to correctly handle UNIX abstract and unnamed sockets
hook: fix setrlimit invocation at startup
sandbox: fix serialization of capabilities (thx xiaomiao!)
config: skip caching /tmp and /var/tmp
fs: fix WANT_BASE with proc/dev/sys files
path: fix pid calculation in safe path checker
hook: fix access violation reporting for path hiding
config: deny kill(2) for emulator threads
vim: highlight the new option trace/allow_unsafe_ebpf
lib: improve speculation feature error handling in syd -V
changelog: correct changelog entry about effected arches
unshare: fix negated errno handling for seccomp errors