> OTOH, maybe we should just go ahead without weird games with dup2 and
> see whether any real code gets confused...

Here's some real-world code that would break with this patch
as it stands, though dup2 games wouldn't be the fix in this case:

(it iterates through all fds above 2 closing them, and we don't
protect against the guest being able to perform syscalls on

