apmanager: run daemon inside minijail

Run apmanager inside a minijail with limited privileges and system calls
through seccomp filter.

BUG=chromium:442186
TEST=Verify AP services with client connectiviy on arm (peach_pit),
     x86 (x86-alex), and amd64 (stumpy) platforms.
CQ-DEPEND=CL:236097

Change-Id: I10b2b0c6943cad134028894505d54e2ca4993a26
Reviewed-on: https://chromium-review.googlesource.com/236098
Tested-by: Zeping Qiu <zqiu@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Commit-Queue: Zeping Qiu <zqiu@chromium.org>
Trybot-Ready: Zeping Qiu <zqiu@chromium.org>
8 files changed