oci/defaults_linux.go: mask /sys/firmware Upstream-commit: 8d1d9eebe3ded3105216dc9a88cc94d16ac6198c Component: engine