add support for guarding pipestream with NO_NEW_PRIVS