nsjail-2.8
- even more C++-isms
- clearer main process loop
- refactored cgroup setting code
- ability to specify noexec/nodev/nosuid in mounts
- updated kafel
- added --macvlan_vs_ma option
- better configs/
- changed behavior of --env - empty var means passing it from parent