open the inode via O_PATH first, then validate its type, and then convert to
proper fd via fd_reopen()
-* sd-json: before release figure out what to do about
- SD_JSON_DEBUG+SD_JSON_WARNING. They are probably useless and should be hidden
- in the public API since we don't expose log_json()
-
* rough proposed implementation design for remote attestation infra: add a tool
that generates a quote of local PCRs and NvPCRs, along with synchronous log
snapshot. use "audit session" logic for that, so that we get read-outs and