Restrict access to wayland server, as every application from every container currently has full access

A more isolated way, install wayland compositor in container, use host wayland socket as backend, start the untrusted app in container wayland compositor.