- Drop privileges in many commands
- Drop privileges when fetching a file
- Add resource limitation to sandboxes
- Add support for metalog