[PATCH v3 7/9] sandbox: Avoid using malloc() for system state