jail: mount /sys read-only