Need to strip setgid and setuid permissions from /usr. sudo and su need to be controlled to be on only during the build. Docker allows privilege escalation even when `--user` is supplied.