i could imagine the filtering being usefull when cpu'ing to foreign machines,
as a server can easily compromize your system when cpu exports your whole
local namespace
You'd still be better off using a custom nsfile to control it, running that cpu in
a more restricted name space from the start, so leaks are impossible.