libcontainer already manages `/dev`, overriding task_dir - so let's use it for `/proc` as well and remove deadcode.
* Refactor AllocDir to have a TaskDir struct per task. * Drivers expose filesystem isolation preference * Fix lxc mounting of `secrets/`